SlideShare una empresa de Scribd logo
1 de 17
© RAIDIAM 2018.All Rights Reserved.
RAiDiAM
TrustFrameworks and Open Banking
July2018 Information Classification: Confidential © RAIDIAM 2018. All Rights reserved.
© RAIDIAM 2018.All Rights Reserved.
About RAiDiAM
Strictly Confidential 2
Created to help with identity focused aspects of Open Banking and PSD2
regulatory challenges.
Provides business and technology consulting and project delivery services
focused on customer identity using an architecture that is modular and
scalable.
We have delivered services to Open Banking, other regulatory bodies,
various large UK financial services organizations, and a number of
software vendors.
RAiDiAM is engaged with various clients and the wider ecosystem to
promote understanding of what Open Banking and PSD2 mean to
businesses and how best to deliver technical solutions to those business
challenges.
© RAIDIAM 2018.All Rights Reserved. 3
Ralph Bragg
CTO, Founder
IAM Consultant
Standardsspecialist
Barry
O’Donohoe
CIO, Founder
IAM Consultant
Mark Haine
CEO, Founder
IAM Consultant
Daryl Searle
OperationsDirector and
ProgrammeManager
© RAIDIAM 2018.All Rights Reserved.
What’s Changing – European context
4
Financial Services APIs
Open Banking & PSD2
• The banking services landscape is being radically transformed to promote increased
competition and innovation.
• This transformation is being driven by industry and regulatory directives that envisions
Open Banking APIs – UK CMA & EBA
• Third Party Providers (TPPs) will consume standard banking APIs to provide Account
Information and Payment Initiation Services
• TPP access to accounts (XS2A) must be secured by Banks’ using Strong Customer
Authentication (SCA) per technical standard, RTS
• With traditional security perimeters dissolving, a new approach is needed to ensure
security postures remain within risk appetite.
• Enabling this vision Open Banking has delivered identity-centric security model
underpinned by open international standards - OAuth2 & OIDC
• PSD2 solutions are emerging
Data privacy
EU - General Data Protection
Regulation
• The GDPR in full force since 25th May 2018 for all
EU countries, including the UK despite Brexit being
underway.
• This will present major implications for Consumer
IAM platforms in dealing with customer (data
subject) consent.
• Consents need to be ‘freely given, specific,
informed and unambiguous’ – IAM will be on the
front line in dealing with this.
• Fine-grained consent management and its
enforcement is non-trivial.
© RAIDIAM 2018.All Rights Reserved.
What’s Changing – Globally
5
• Breaches and perceived abuse of customer data is becoming a
topic of wider interest e.g. Facebook and Cambridge Analytica
• As a result, being a “good custodian” of customer data is of
more interest to companies as it could give a competitive
advantage
• The on-going arms race between attackers and defenders has
been moving to more and more complex layers of the
application
• Identity and associated context is one of the next “battlefields”
• The number of identities interacting has been continuing to
increase partly due to APIs and IoT
Financial Services APIs Data privacy
• Various jurisdictions are looking to achieve similar opening up
of banking services and are at different levels of maturity
• Europe
• Australia
• Japan
• New Zealand
• Singapore
• Mexico
• The interplay between the various laws, regulations,
implementations and standards will mean that there will be
significant complexity to deal with particularly between
jurisdictions
© RAIDIAM 2018.All Rights Reserved.
Identity and Authorization
6
• Individual FSCustomers
• Corporate FS Customers
• Agents of Customers
• Account & Payments services companies
• Merchants
• People who work for companies
• Technicalcomponentsbelonging to FS
companies
• Technology providersto companies
While there are
significant benefits to
opening up access to
financial services, we
must look after customer
data and must not share it
with unauthorized
parties.
The consumer wantsto understand
when they areinteracting with
their bank, and when they are
interacting with a third party.
Who are we interacting with?
What are they permitted to do?
Ecosystem Actors
Customers
© RAIDIAM 2018.All Rights Reserved.
Trust Framework
Strictly Confidential 7
We need a quick cost effective way of establishing who a
request is coming from and whether they are authorized
Clearly specified and standardised
interfaces are easier to useand result in:
• Quicker integration
• Better interoperability
• Cheaper for everyone
• Better for customers
Standardization
A Trustframework can beimplemented in
many ways butthe topology is an
important consideration.
The choices are hub-and spoke, full mesh
or a hybrid
Ecosystem Topology
© RAIDIAM 2018.All Rights Reserved.
Open Banking
Strictly Confidential 8
An independent company “Open Banking Implementation Entity” was created by the banks but
driven by CMA order to deliver the “Open Banking remedies”.
The primary objective was to increasecompetition by opening up access to data and services that
werepreviously exclusiveto the UK banks.
There werea number of parallel workstreams on topics such as legal framework, customer
experience, functional APIs and Security
The technical workstreamsresulted in a decision to focus on a modern API based ecosystemin a
standardized fashion (screen scraping would notdo).
The security workstream agreed OAuth2 & OpenID Connectstandards as thebasis for the ecosystem
interactions .
The legal and security workstreamsagreed a trust framework forcompanies in the ecosystemwould
be required to underpin the security standards implementation. This was a good startbecause it
allowed focus on a subsetof the identities involved in the whole ecosystem.
© RAIDIAM 2018.All Rights Reserved.
Open Banking Trust Framework topology choice
Strictly Confidential 9
• The complexities of a full mesh topology meant that it
was unlikely to result in success.
• The level of trustrequired meant that robust
processes would berequired
• Each entity involved in the ecosystemwould need to
manage links of somesort to many other entities
• Maintenance of those links would be onerous on all
parties
• A hub-and-spoketopology requires an a hub entity, but in
the caseof Open Banking the Implementation entity was
already in place and could performthat role
• The Open Banking trustmodel is transitive as the sourceis
the regulators
• All banks and authorized third parties can have their status
validated by the Open Banking Directory
• Open Banking regularly runs the verification processes on
behalf or all participants in the ecosystem
© RAIDIAM 2018.All Rights Reserved.
Open Banking Trust Framework value
Strictly Confidential 10
• Runs regular process to ensure up-to-dateinformation about companies and
their attributes
• It means each company does not need to validateidentityand authorization
for each other entity in the ecosystem
• Provides a single pointof integrationfor all parties
• Provides informationvia variousstandardinterfaces
• Additionallyprovidesan strongly authenticatedIdentityprovider for
authorised people in the ecosystem
© RAIDIAM 2018.All Rights Reserved.
The Open Banking Directory – Actors
11
Open Banking ecosystem Actors:
• Regulators
• Authorised Companies(Banks
and third parties)
• People representing those
companies
• Technicalcomponents
belonging to those companies
Entity Relationships in
the directory
Open Banking ecosystem
Actors:
© RAIDIAM 2018.All Rights Reserved.
The Open Banking Directory – a trust framework
Strictly Confidential 12
Key concept
• The FS customer does not interact directly with Open Banking
• Open Banking systems are NOT in the transaction flow
2 Phases
• On-Boarding – prior to customer engagement
• Transacting – after customer is engaged
© RAIDIAM 2018.All Rights Reserved.
The Open Banking Directory – On-Boarding
Strictly Confidential 13
For on-boarding each authorized company must go through
a process to create the necessary records, credentials and
certificates required to interact with other members of the
ecosystem. These credentials are issued by OB.
The on-boarding process checks the identity of the human
actors and the status of them and the claimed organization.
The OB credentials and certificates provided need to be
configured in the technical components belonging to the
company in question.
Additionally Fintechs must then also use their OB
credentials to register their applications with each of the
banks that they wish to transact. This would result in
credentials for Fintech -> Bank interactions.
© RAIDIAM 2018.All Rights Reserved.
The Open Banking Directory – Transacting
Strictly Confidential 14
Once the onboarding has been performed the
Fintech will be able to engage with customers who
wish to share their data and permit a fintech to
transact on their behalf.
There is detailed documentation of how that flow
works but from the perspective of the directory
the only involvement is checking the authorization
of entities and their associated credentials.
In practice this means that a Bank can check the validity of claims presented by a
Fintech and visa-versa.
Customer identity claims, consent and authorization are primarily handled by each
Bank and do not involve the Open Banking Directory.
© RAIDIAM 2018.All Rights Reserved.
The Directory – Future changes
15
eIDAS certificates as
identity source
New journey for
on-boardinga
new company
basedon eIDAS
identity
Directory providing
attributesfor eIDAS
identities
Changesthattighten
up the OpenBanking
security profile in
line with FAPI
PSD2
alignment
API only on-
boarding
Directory as
attribute provider
• With the challengingtimescales, Open Banking hadto consider thatsome requirementscouldnotbe achieved by
the original CMA deadline
• The following itemsare some of the changes that are planned for the OpenBankingDirectory and ecosystem
Next steps
FAPI-OB
convergence
© RAIDIAM 2018.All Rights Reserved.
Reference materials
Strictly Confidential 16
https://www.openbanking.org.uk/providers/directory/
https://openbanking.atlassian.net/wiki/spaces/DZ/overview
© RAIDIAM 2018.All Rights Reserved. 17
www.raidiam.com
+44 (0) 203 504 6440
50 Brook Street,
Mayfair,London.
W1K 5DR
info@raidiam.com
Get in touch

Más contenido relacionado

La actualidad más candente

OpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking UpdateOpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking UpdateMikeLeszcz
 
Open Banking in Australia - An Open Forum
Open Banking in Australia - An Open Forum Open Banking in Australia - An Open Forum
Open Banking in Australia - An Open Forum WSO2
 
Understanding Users at Scale with Product Analytics
Understanding Users at Scale with Product AnalyticsUnderstanding Users at Scale with Product Analytics
Understanding Users at Scale with Product AnalyticsHannah Flynn
 
What’s new in WSO2 Open Banking
What’s new in WSO2 Open BankingWhat’s new in WSO2 Open Banking
What’s new in WSO2 Open BankingWSO2
 
The Power Of Open Banking Coupled With Artificial Intelligence
The Power Of Open Banking Coupled With Artificial IntelligenceThe Power Of Open Banking Coupled With Artificial Intelligence
The Power Of Open Banking Coupled With Artificial IntelligenceIndusNetMarketing
 
The State of Blockchains Q1 2018
The State of Blockchains Q1 2018The State of Blockchains Q1 2018
The State of Blockchains Q1 2018Outlier Ventures
 
Webinar: The Future of FinTech: Insights for 2021 | Intellectsoft
Webinar: The Future of FinTech: Insights for 2021 | IntellectsoftWebinar: The Future of FinTech: Insights for 2021 | Intellectsoft
Webinar: The Future of FinTech: Insights for 2021 | IntellectsoftIntellectsoft
 
PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022XMLdation Ltd
 
Webinar: Technology Insights - PSD2
Webinar: Technology Insights - PSD2 Webinar: Technology Insights - PSD2
Webinar: Technology Insights - PSD2 Ulla Kenttä
 
UKCCC: Open Banking Introduction
UKCCC: Open Banking IntroductionUKCCC: Open Banking Introduction
UKCCC: Open Banking IntroductionFreddy Kelly
 
FABRIC - Open Banking Teaser
FABRIC - Open Banking TeaserFABRIC - Open Banking Teaser
FABRIC - Open Banking TeaserGavin Payne
 
Financial Services: exchanges, settlements, payments and embedded finance
Financial Services: exchanges, settlements, payments and embedded financeFinancial Services: exchanges, settlements, payments and embedded finance
Financial Services: exchanges, settlements, payments and embedded financeEY
 
Chances of open banking
Chances of open banking Chances of open banking
Chances of open banking Netcetera
 
BizDay: B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
BizDay:  B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...BizDay:  B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
BizDay: B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...R3
 
2017 Feb 3rd Malta - NPF2017 - APIs in context of PSD2
2017 Feb 3rd Malta - NPF2017 - APIs in context of PSD22017 Feb 3rd Malta - NPF2017 - APIs in context of PSD2
2017 Feb 3rd Malta - NPF2017 - APIs in context of PSD2Dennis Van Allemeersch
 
Άσπα Παλημέρη, 5th Digital Banking Forum
Άσπα Παλημέρη, 5th Digital Banking ForumΆσπα Παλημέρη, 5th Digital Banking Forum
Άσπα Παλημέρη, 5th Digital Banking ForumStarttech Ventures
 
ASEAN FinTech Census 2018
ASEAN FinTech Census 2018ASEAN FinTech Census 2018
ASEAN FinTech Census 2018Varun Mittal
 
Open Banking Working Group - SE Asia
Open Banking Working Group - SE AsiaOpen Banking Working Group - SE Asia
Open Banking Working Group - SE AsiaMatthew Argent
 
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, CapgeminiBizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, CapgeminiR3
 
A regulator’s view of virtual currencies as the first use-case of blockchain...
 A regulator’s view of virtual currencies as the first use-case of blockchain... A regulator’s view of virtual currencies as the first use-case of blockchain...
A regulator’s view of virtual currencies as the first use-case of blockchain...thebitcoinconference
 

La actualidad más candente (20)

OpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking UpdateOpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking Update
 
Open Banking in Australia - An Open Forum
Open Banking in Australia - An Open Forum Open Banking in Australia - An Open Forum
Open Banking in Australia - An Open Forum
 
Understanding Users at Scale with Product Analytics
Understanding Users at Scale with Product AnalyticsUnderstanding Users at Scale with Product Analytics
Understanding Users at Scale with Product Analytics
 
What’s new in WSO2 Open Banking
What’s new in WSO2 Open BankingWhat’s new in WSO2 Open Banking
What’s new in WSO2 Open Banking
 
The Power Of Open Banking Coupled With Artificial Intelligence
The Power Of Open Banking Coupled With Artificial IntelligenceThe Power Of Open Banking Coupled With Artificial Intelligence
The Power Of Open Banking Coupled With Artificial Intelligence
 
The State of Blockchains Q1 2018
The State of Blockchains Q1 2018The State of Blockchains Q1 2018
The State of Blockchains Q1 2018
 
Webinar: The Future of FinTech: Insights for 2021 | Intellectsoft
Webinar: The Future of FinTech: Insights for 2021 | IntellectsoftWebinar: The Future of FinTech: Insights for 2021 | Intellectsoft
Webinar: The Future of FinTech: Insights for 2021 | Intellectsoft
 
PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022
 
Webinar: Technology Insights - PSD2
Webinar: Technology Insights - PSD2 Webinar: Technology Insights - PSD2
Webinar: Technology Insights - PSD2
 
UKCCC: Open Banking Introduction
UKCCC: Open Banking IntroductionUKCCC: Open Banking Introduction
UKCCC: Open Banking Introduction
 
FABRIC - Open Banking Teaser
FABRIC - Open Banking TeaserFABRIC - Open Banking Teaser
FABRIC - Open Banking Teaser
 
Financial Services: exchanges, settlements, payments and embedded finance
Financial Services: exchanges, settlements, payments and embedded financeFinancial Services: exchanges, settlements, payments and embedded finance
Financial Services: exchanges, settlements, payments and embedded finance
 
Chances of open banking
Chances of open banking Chances of open banking
Chances of open banking
 
BizDay: B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
BizDay:  B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...BizDay:  B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
BizDay: B3i: A Real Blockchain Solution for a Real Business Problem, Sylvain...
 
2017 Feb 3rd Malta - NPF2017 - APIs in context of PSD2
2017 Feb 3rd Malta - NPF2017 - APIs in context of PSD22017 Feb 3rd Malta - NPF2017 - APIs in context of PSD2
2017 Feb 3rd Malta - NPF2017 - APIs in context of PSD2
 
Άσπα Παλημέρη, 5th Digital Banking Forum
Άσπα Παλημέρη, 5th Digital Banking ForumΆσπα Παλημέρη, 5th Digital Banking Forum
Άσπα Παλημέρη, 5th Digital Banking Forum
 
ASEAN FinTech Census 2018
ASEAN FinTech Census 2018ASEAN FinTech Census 2018
ASEAN FinTech Census 2018
 
Open Banking Working Group - SE Asia
Open Banking Working Group - SE AsiaOpen Banking Working Group - SE Asia
Open Banking Working Group - SE Asia
 
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, CapgeminiBizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
BizDay: Trusted Data Exchange for Corp and Supplier Onboarding, Capgemini
 
A regulator’s view of virtual currencies as the first use-case of blockchain...
 A regulator’s view of virtual currencies as the first use-case of blockchain... A regulator’s view of virtual currencies as the first use-case of blockchain...
A regulator’s view of virtual currencies as the first use-case of blockchain...
 

Similar a Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs Summit 2018 - July 25, 2018

Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...FinTechLabs.io
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service DirectiveLac Vuong
 
ce-digital-banking-maturity-study-emea.pdf
ce-digital-banking-maturity-study-emea.pdfce-digital-banking-maturity-study-emea.pdf
ce-digital-banking-maturity-study-emea.pdfAnuradhaTulsyan1
 
Chapter 5 the kyc utility
Chapter 5   the kyc utilityChapter 5   the kyc utility
Chapter 5 the kyc utilityQuan Risk
 
DATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDataSecretariat
 
Initio at World Blockchain & Cryptocurrency Summit 2018
Initio at World Blockchain & Cryptocurrency Summit 2018Initio at World Blockchain & Cryptocurrency Summit 2018
Initio at World Blockchain & Cryptocurrency Summit 2018Initio
 
SuperCharger Hong Kong 2018 Cohort Description
SuperCharger Hong Kong 2018 Cohort DescriptionSuperCharger Hong Kong 2018 Cohort Description
SuperCharger Hong Kong 2018 Cohort DescriptionBrandon Chung
 
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in EuropeFIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in EuropeFIDO Alliance
 
Natural language processing for smart contracts in blockchain
Natural language processing for smart contracts in blockchain Natural language processing for smart contracts in blockchain
Natural language processing for smart contracts in blockchain Capgemini
 
Trust exchange webinar nov 2020
Trust exchange webinar nov 2020Trust exchange webinar nov 2020
Trust exchange webinar nov 2020Trust Exchange
 
Insurance Round Table
Insurance Round TableInsurance Round Table
Insurance Round TableR3
 
Custody Banking and Emerging KYC Needs
Custody Banking and Emerging KYC NeedsCustody Banking and Emerging KYC Needs
Custody Banking and Emerging KYC NeedsTodd Breeden
 
lendingQB: A Mortgage Loan Origination System by MeridianLink
lendingQB: A Mortgage Loan Origination System by MeridianLinklendingQB: A Mortgage Loan Origination System by MeridianLink
lendingQB: A Mortgage Loan Origination System by MeridianLinkKristina Quinn
 
Rental, HOA, Insurance, Consumer Loans Markets Overview
Rental, HOA, Insurance, Consumer Loans Markets OverviewRental, HOA, Insurance, Consumer Loans Markets Overview
Rental, HOA, Insurance, Consumer Loans Markets OverviewChristopher "Dain" Hall
 
Fintech New York: Partnerships, Platforms and Open Innovation
Fintech New York: Partnerships, Platforms and Open InnovationFintech New York: Partnerships, Platforms and Open Innovation
Fintech New York: Partnerships, Platforms and Open Innovationaccenture
 

Similar a Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs Summit 2018 - July 25, 2018 (20)

Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service Directive
 
ce-digital-banking-maturity-study-emea.pdf
ce-digital-banking-maturity-study-emea.pdfce-digital-banking-maturity-study-emea.pdf
ce-digital-banking-maturity-study-emea.pdf
 
Chapter 5 the kyc utility
Chapter 5   the kyc utilityChapter 5   the kyc utility
Chapter 5 the kyc utility
 
Latest Trends Payments Industry
Latest Trends Payments IndustryLatest Trends Payments Industry
Latest Trends Payments Industry
 
DATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best Practices
 
Initio at World Blockchain & Cryptocurrency Summit 2018
Initio at World Blockchain & Cryptocurrency Summit 2018Initio at World Blockchain & Cryptocurrency Summit 2018
Initio at World Blockchain & Cryptocurrency Summit 2018
 
SuperCharger Hong Kong 2018 Cohort Description
SuperCharger Hong Kong 2018 Cohort DescriptionSuperCharger Hong Kong 2018 Cohort Description
SuperCharger Hong Kong 2018 Cohort Description
 
ENTITY EXCHANGE FOR SELL-SIDE FIRMS
ENTITY EXCHANGE FOR SELL-SIDE FIRMSENTITY EXCHANGE FOR SELL-SIDE FIRMS
ENTITY EXCHANGE FOR SELL-SIDE FIRMS
 
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in EuropeFIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
 
Fintech 4.0
Fintech 4.0Fintech 4.0
Fintech 4.0
 
Natural language processing for smart contracts in blockchain
Natural language processing for smart contracts in blockchain Natural language processing for smart contracts in blockchain
Natural language processing for smart contracts in blockchain
 
Trust exchange webinar nov 2020
Trust exchange webinar nov 2020Trust exchange webinar nov 2020
Trust exchange webinar nov 2020
 
Insurance Round Table
Insurance Round TableInsurance Round Table
Insurance Round Table
 
Custody Banking and Emerging KYC Needs
Custody Banking and Emerging KYC NeedsCustody Banking and Emerging KYC Needs
Custody Banking and Emerging KYC Needs
 
MTBiz January 2018
MTBiz January 2018MTBiz January 2018
MTBiz January 2018
 
Kantara Workshop at CIS
Kantara Workshop at CISKantara Workshop at CIS
Kantara Workshop at CIS
 
lendingQB: A Mortgage Loan Origination System by MeridianLink
lendingQB: A Mortgage Loan Origination System by MeridianLinklendingQB: A Mortgage Loan Origination System by MeridianLink
lendingQB: A Mortgage Loan Origination System by MeridianLink
 
Rental, HOA, Insurance, Consumer Loans Markets Overview
Rental, HOA, Insurance, Consumer Loans Markets OverviewRental, HOA, Insurance, Consumer Loans Markets Overview
Rental, HOA, Insurance, Consumer Loans Markets Overview
 
Fintech New York: Partnerships, Platforms and Open Innovation
Fintech New York: Partnerships, Platforms and Open InnovationFintech New York: Partnerships, Platforms and Open Innovation
Fintech New York: Partnerships, Platforms and Open Innovation
 

Más de FinTechLabs.io

Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...FinTechLabs.io
 
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...FinTechLabs.io
 
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...FinTechLabs.io
 
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...FinTechLabs.io
 
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...FinTechLabs.io
 
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...FinTechLabs.io
 
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...FinTechLabs.io
 
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...FinTechLabs.io
 
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...FinTechLabs.io
 
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...FinTechLabs.io
 

Más de FinTechLabs.io (10)

Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
Open Banking: The View from a Japanese Startup (Authlete) #fapisum - Japan/UK...
 
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
FAPI / Open Banking Test Suite #fapisum - Japan/UK Open Banking and APIs Summ...
 
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
Banking API Trends in Japan #fapisum - Japan/UK Open Banking and APIs Summit ...
 
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
FAPI / Open Banking Conformance #fapisum - Japan/UK Open Banking and APIs Sum...
 
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
The Great British API Client Bake Off #fapisum - Japan/UK Open Banking and AP...
 
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
Authlete FAPI Implementation Part 1 #fapisum - Japan/UK Open Banking and APIs...
 
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
FAPI and Beyond: From an specification author's point of view #fapisum - Japa...
 
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
Basics: OAuth and OpenID Connect #fapisum - Japan/UK Open Banking and APIs Su...
 
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
Trends in Banking APIs #fapisum - Japan/UK Open Banking and APIs Summit 2018 ...
 
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
Open Banking for Developers #fapisum - Japan/UK Open Banking and APIs Summit ...
 

Último

Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableSeo
 
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...SUHANI PANDEY
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...roncy bisnoi
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"growthgrids
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdfMatthew Sinclair
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfJOHNBEBONYAP1
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceDelhi Call girls
 
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrStory Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrHenryBriggs2
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445ruhi
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubaikojalkojal131
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...kajalverma014
 
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...tanu pandey
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...singhpriety023
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...SUHANI PANDEY
 
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋nirzagarg
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftAanSulistiyo
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtrahman018755
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查ydyuyu
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...nirzagarg
 

Último (20)

Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrStory Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
 
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck Microsoft
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
 

Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs Summit 2018 - July 25, 2018

  • 1. © RAIDIAM 2018.All Rights Reserved. RAiDiAM TrustFrameworks and Open Banking July2018 Information Classification: Confidential © RAIDIAM 2018. All Rights reserved.
  • 2. © RAIDIAM 2018.All Rights Reserved. About RAiDiAM Strictly Confidential 2 Created to help with identity focused aspects of Open Banking and PSD2 regulatory challenges. Provides business and technology consulting and project delivery services focused on customer identity using an architecture that is modular and scalable. We have delivered services to Open Banking, other regulatory bodies, various large UK financial services organizations, and a number of software vendors. RAiDiAM is engaged with various clients and the wider ecosystem to promote understanding of what Open Banking and PSD2 mean to businesses and how best to deliver technical solutions to those business challenges.
  • 3. © RAIDIAM 2018.All Rights Reserved. 3 Ralph Bragg CTO, Founder IAM Consultant Standardsspecialist Barry O’Donohoe CIO, Founder IAM Consultant Mark Haine CEO, Founder IAM Consultant Daryl Searle OperationsDirector and ProgrammeManager
  • 4. © RAIDIAM 2018.All Rights Reserved. What’s Changing – European context 4 Financial Services APIs Open Banking & PSD2 • The banking services landscape is being radically transformed to promote increased competition and innovation. • This transformation is being driven by industry and regulatory directives that envisions Open Banking APIs – UK CMA & EBA • Third Party Providers (TPPs) will consume standard banking APIs to provide Account Information and Payment Initiation Services • TPP access to accounts (XS2A) must be secured by Banks’ using Strong Customer Authentication (SCA) per technical standard, RTS • With traditional security perimeters dissolving, a new approach is needed to ensure security postures remain within risk appetite. • Enabling this vision Open Banking has delivered identity-centric security model underpinned by open international standards - OAuth2 & OIDC • PSD2 solutions are emerging Data privacy EU - General Data Protection Regulation • The GDPR in full force since 25th May 2018 for all EU countries, including the UK despite Brexit being underway. • This will present major implications for Consumer IAM platforms in dealing with customer (data subject) consent. • Consents need to be ‘freely given, specific, informed and unambiguous’ – IAM will be on the front line in dealing with this. • Fine-grained consent management and its enforcement is non-trivial.
  • 5. © RAIDIAM 2018.All Rights Reserved. What’s Changing – Globally 5 • Breaches and perceived abuse of customer data is becoming a topic of wider interest e.g. Facebook and Cambridge Analytica • As a result, being a “good custodian” of customer data is of more interest to companies as it could give a competitive advantage • The on-going arms race between attackers and defenders has been moving to more and more complex layers of the application • Identity and associated context is one of the next “battlefields” • The number of identities interacting has been continuing to increase partly due to APIs and IoT Financial Services APIs Data privacy • Various jurisdictions are looking to achieve similar opening up of banking services and are at different levels of maturity • Europe • Australia • Japan • New Zealand • Singapore • Mexico • The interplay between the various laws, regulations, implementations and standards will mean that there will be significant complexity to deal with particularly between jurisdictions
  • 6. © RAIDIAM 2018.All Rights Reserved. Identity and Authorization 6 • Individual FSCustomers • Corporate FS Customers • Agents of Customers • Account & Payments services companies • Merchants • People who work for companies • Technicalcomponentsbelonging to FS companies • Technology providersto companies While there are significant benefits to opening up access to financial services, we must look after customer data and must not share it with unauthorized parties. The consumer wantsto understand when they areinteracting with their bank, and when they are interacting with a third party. Who are we interacting with? What are they permitted to do? Ecosystem Actors Customers
  • 7. © RAIDIAM 2018.All Rights Reserved. Trust Framework Strictly Confidential 7 We need a quick cost effective way of establishing who a request is coming from and whether they are authorized Clearly specified and standardised interfaces are easier to useand result in: • Quicker integration • Better interoperability • Cheaper for everyone • Better for customers Standardization A Trustframework can beimplemented in many ways butthe topology is an important consideration. The choices are hub-and spoke, full mesh or a hybrid Ecosystem Topology
  • 8. © RAIDIAM 2018.All Rights Reserved. Open Banking Strictly Confidential 8 An independent company “Open Banking Implementation Entity” was created by the banks but driven by CMA order to deliver the “Open Banking remedies”. The primary objective was to increasecompetition by opening up access to data and services that werepreviously exclusiveto the UK banks. There werea number of parallel workstreams on topics such as legal framework, customer experience, functional APIs and Security The technical workstreamsresulted in a decision to focus on a modern API based ecosystemin a standardized fashion (screen scraping would notdo). The security workstream agreed OAuth2 & OpenID Connectstandards as thebasis for the ecosystem interactions . The legal and security workstreamsagreed a trust framework forcompanies in the ecosystemwould be required to underpin the security standards implementation. This was a good startbecause it allowed focus on a subsetof the identities involved in the whole ecosystem.
  • 9. © RAIDIAM 2018.All Rights Reserved. Open Banking Trust Framework topology choice Strictly Confidential 9 • The complexities of a full mesh topology meant that it was unlikely to result in success. • The level of trustrequired meant that robust processes would berequired • Each entity involved in the ecosystemwould need to manage links of somesort to many other entities • Maintenance of those links would be onerous on all parties • A hub-and-spoketopology requires an a hub entity, but in the caseof Open Banking the Implementation entity was already in place and could performthat role • The Open Banking trustmodel is transitive as the sourceis the regulators • All banks and authorized third parties can have their status validated by the Open Banking Directory • Open Banking regularly runs the verification processes on behalf or all participants in the ecosystem
  • 10. © RAIDIAM 2018.All Rights Reserved. Open Banking Trust Framework value Strictly Confidential 10 • Runs regular process to ensure up-to-dateinformation about companies and their attributes • It means each company does not need to validateidentityand authorization for each other entity in the ecosystem • Provides a single pointof integrationfor all parties • Provides informationvia variousstandardinterfaces • Additionallyprovidesan strongly authenticatedIdentityprovider for authorised people in the ecosystem
  • 11. © RAIDIAM 2018.All Rights Reserved. The Open Banking Directory – Actors 11 Open Banking ecosystem Actors: • Regulators • Authorised Companies(Banks and third parties) • People representing those companies • Technicalcomponents belonging to those companies Entity Relationships in the directory Open Banking ecosystem Actors:
  • 12. © RAIDIAM 2018.All Rights Reserved. The Open Banking Directory – a trust framework Strictly Confidential 12 Key concept • The FS customer does not interact directly with Open Banking • Open Banking systems are NOT in the transaction flow 2 Phases • On-Boarding – prior to customer engagement • Transacting – after customer is engaged
  • 13. © RAIDIAM 2018.All Rights Reserved. The Open Banking Directory – On-Boarding Strictly Confidential 13 For on-boarding each authorized company must go through a process to create the necessary records, credentials and certificates required to interact with other members of the ecosystem. These credentials are issued by OB. The on-boarding process checks the identity of the human actors and the status of them and the claimed organization. The OB credentials and certificates provided need to be configured in the technical components belonging to the company in question. Additionally Fintechs must then also use their OB credentials to register their applications with each of the banks that they wish to transact. This would result in credentials for Fintech -> Bank interactions.
  • 14. © RAIDIAM 2018.All Rights Reserved. The Open Banking Directory – Transacting Strictly Confidential 14 Once the onboarding has been performed the Fintech will be able to engage with customers who wish to share their data and permit a fintech to transact on their behalf. There is detailed documentation of how that flow works but from the perspective of the directory the only involvement is checking the authorization of entities and their associated credentials. In practice this means that a Bank can check the validity of claims presented by a Fintech and visa-versa. Customer identity claims, consent and authorization are primarily handled by each Bank and do not involve the Open Banking Directory.
  • 15. © RAIDIAM 2018.All Rights Reserved. The Directory – Future changes 15 eIDAS certificates as identity source New journey for on-boardinga new company basedon eIDAS identity Directory providing attributesfor eIDAS identities Changesthattighten up the OpenBanking security profile in line with FAPI PSD2 alignment API only on- boarding Directory as attribute provider • With the challengingtimescales, Open Banking hadto consider thatsome requirementscouldnotbe achieved by the original CMA deadline • The following itemsare some of the changes that are planned for the OpenBankingDirectory and ecosystem Next steps FAPI-OB convergence
  • 16. © RAIDIAM 2018.All Rights Reserved. Reference materials Strictly Confidential 16 https://www.openbanking.org.uk/providers/directory/ https://openbanking.atlassian.net/wiki/spaces/DZ/overview
  • 17. © RAIDIAM 2018.All Rights Reserved. 17 www.raidiam.com +44 (0) 203 504 6440 50 Brook Street, Mayfair,London. W1K 5DR info@raidiam.com Get in touch