Open Banking & PSD2 How regulation is shaping the future of banking xCEEd Belgrade Gary Munro 18th May 2017 Please copy and distribute
Please copy and distribute Agenda Drivers for Open Banking Regulation Open Banking through PSD2 Strong Customer Authentication Threats & Opportunities Please copy and distribute
Drivers for Open Banking Regulatory Drivers National & EU More competition Diversity of supply Inclusion of underbanked Customer expectations Data Desire for an alternative to card schemes Please copy and distribute
Drivers for Open Banking PSD2 Mandates Open Banking ASPSP – Account Servicing PSP XS2A – must provide access to accounts TPP – Third Party PSP PISP – Payment Initiation Services Provider AISP – Account Information Services Provider CAF – Confirmation on Availability of Funds GDPR Conflicts with PSD2 in places, impact on data services must be adhered to Please copy and distribute
Please copy and distribute PSD2 to Open Banking Dutch Payments Association 4 tier model Level 1 – PSD2 States the “What” Level 2 – RTS EBA – On SCA & CSC Strong Customer Authentication Common & Secure Communications Level 3 – Multi-stakeholder groups Level 4 – Market Solutions - APIs APIs Working Groups RTS PSD2 Please copy and distribute
Please copy and distribute Open Banking APIs ASPSPs API 1 API 2 API 3 ………………………… API x AISP / PISP Customer Please copy and distribute
Open Banking APIs – Clusters? UK API Dutch API Berlin Group API No Common European API AISP / PISP Customer Please copy and distribute
SCA – key to Open Banking PSP must authenticate the account holder based on 2FA: Knowledge Possession Inherence ASPSP Identify PSPs via qualified certificates eIDAS Explicit consent from account holder for service ASPSP SCA AISP / PISP Please copy and distribute
Reference Fraud Rate (%) Exemptions to SCA? RTS defines a number of exceptions on need for SCA: Contactless <= €50 (€150 cum) UAT – parking / tolls Payments <= €30 (€100 cum) Transaction Risk Assessment Transaction Risk Assessment: Only if Reference Fraud Rates met Reference Fraud Rate (%) Transaction Value Remote Card based Credit Transfers €500 0.01 0.005 €250 0.06 €100 0.13 0.015 Please copy and distribute
Please copy and distribute PSD2 - GDPR PSD2 provides Open Banking through provision of data services GDPR protects individuals data Salary Utility Bill Bob Account Fee Mortgage Alice Credit Card Supermarket ASPSP SCA AISP Please copy and distribute
Please copy and distribute PSD2 - GDPR Only access data from designated payment account and related transactions. Explicit consent required from user. Open Banking APIs need to protect data. Salary Utility Bill Bob Account Fee Mortgage Alice Credit Card Supermarket ASPSP SCA AISP Please copy and distribute
Open Banking opportunities Threats: Competition from Tech titans Competition from Challenger banks / fintechs Opportunities: Consider strategy Operating model – Customer centric not account centric Financial model Become PISP / AISP Federated Identity providers Partner with Fintech Please copy and distribute
Please copy and distribute Questions are welcome Please copy and distribute
About Consult Hyperion Consult Hyperion specialises in working out the opportunities and threats which result from the harmony and collision of security, networks and transactions. We are constantly assessing these factors, as they change continuously, and delivering ideas, solutions and products to our clients. Please copy and distribute
Please copy and distribute Who do we do it for? Please copy and distribute
Please copy and distribute Contact Browse www.chyp.com Follow @chyppings Mail info@chyp.com Comment http://www.chyp.com/media/blog/ Listen http://www.chyp.com/media/podcasts/ Consult Hyperion UK Tweed House, 12 The Mount Guildford, Surrey, GU2 4HN, UK. +44 1483 301793 Consult Hyperion USA 535 Madison Avenue, 19th Floor New York, NY 10022, USA. +1 888 835 6124 Please copy and distribute