Slide 1 Independent Advisory Group Giovannini Barrier 1 Meeting 3 August 23rd, 2005.

Slides:



Advertisements
Similar presentations
New EU Rules on Derivatives Trading The EMIR Reporting Technical Standards Victoria Cooley OTC Derivatives & Post Trade Policy Financial Conduct Authority.
Advertisements

Independent Advisory Group Giovannini Barrier 1 Meeting 2
Policy interoperability in electronic signatures Andreas Mitrakas EESSI International event, Rome, 7 April 2003.
© Copyright 2010, The NASDAQ OMX Group, Inc. All rights reserved. STRICTLY PRIVATE AND CONFIDENTIAL GLOBAL TRENDS IN POST TRADE IMPLICATIONS TO CIS AND.
1 The critical challenge facing banks and regulators under Basel II: improving risk management through implementation of Pillar 2 Simon Topping Hong Kong.
Does the Third Package provide the European TSO associations with the tools necessary to find solutions to the European energy challenge ? Pierre BORNARD.
Esmond Lee Hong Kong Monetary Authority 7 April 2011 The Asian Banker Summit 2011 The future of post-trade infrastructure in Asian bond markets The Pan-Asian.
This presentation was prepared exclusively for the benefit and internal use of the J.P. Morgan client to whom it is directly addressed and delivered including.
TARGET2-Securities: Answering Questions Ignacio Terol T2S Project Team ECB.
Data-Sharing and Governance Consultation ANALYSIS OF RESPONSES.
ISO Current status of development
Results of the ESTER project in Slovakia Juraj Poledna Salamanca June 23, 2005.
IS Audit Function Knowledge
TEMPUS ME-TEMPUS-JPHES
Data Seal of Approval Overview Lightning Talk RDA Plenary 5 – San Diego March 11, 2015 Mary Vardigan University of Michigan Inter-university Consortium.
Office of Inspector General (OIG) Internal Audit
ISO 9001:2015 Revision overview - General users
April 2, 2013 Longitudinal Data system Governance: Status Report Alan Phillips Deputy Director, Fiscal Affairs, Budgeting and IT Illinois Board of Higher.
ISO 9001:2015 Revision overview December 2013
ISO 9001:2015 Revision overview - General users
Slide 1 Independent Advisory Group Giovannini Barrier 1 Meeting 1 July 19th, 2005.
Presented by: Heather Ward and Jason Cook Date: October 28, 2011 Presented by: > Proprietary and Confidential. For FAA Use Only. The Value of Private Loan.
The Treatment of “Spare / Sterilised” Capacity – follow up Draft for discussion purposes only.
1 ANSI Conference on U.S. Leadership in ISO and IEC Presented by Mr. Steven P. Cornish Director, International Policy American National Standards Institute.
Imposing access obligations under the new framework Karen Hardy.
Workshop on Implementing Audit Quality Practices March 2006 Building Quality into the Financial Audit Process The NAO’s experience Gareth Caller.
Module N° 8 – SSP implementation plan. SSP – A structured approach Module 2 Basic safety management concepts Module 2 Basic safety management concepts.
Possible elements of the technical standards Pre-sessional consultations on registries Bonn, 2-3 June 2002 Andrew Howard UNFCCC secretariat
1 What’s Next for Financial Management Line of Business (FMLoB)? AGA/GWSCPA 6 th Annual Conference Dianne Copeland, Director, FSIO May 8, 2007.
Annual seminar in Berlin – 27 th May Should EU corporate governance measures take into account the size of listed companies ? How ? Should a.
NEGOTIATING TRADE FACILITATION Kennedy Mbekeani UNDP, RSC.
ISA Setting the Standard for Automation ™ Automation Standards Compliance Institute ISA Security Compliance Institute (ISCI) Prepared by: Andre Ristaino,
Ajh January 2007 CCSDS “Books” Adrian J. Hooke CMC Meeting, Colorado Springs 26 January 2007.
How to deal with the implications of New Regulation 28 Magda Wierzycka CEO SYGNIA ASSET MANAGEMENT.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
© 2003 The MITRE Corporation. All rights reserved For Internal MITRE Use Addressing ISO-RTO e-MARC Concerns: Clarifications and Ramifications Response.
Mapping local market practice to ISO The role of SMPG
Slide 1 ACSDA_ John Falk Securities Market Infrastructures SWIFT A Single Protocol for Clearing and Settlement ACSDA International Seminar, Punta.
International Atomic Energy Agency Roles and responsibilities for development of disposal facilities Phil Metcalf Workshop on Strategy and Methodologies.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
ISO Current status of development ​ ​ ISO development process ​1​1.
1 ISO/PC 283/N 197 ISO Current status of development November 2015.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
1. 2 TARGET2-Securities Washington, May 2007 Denis Beau Deputy Director Payment Systems and Market Infrastructure, Banque de France.
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Pamela Taylor, Head of European Strategy, Ofgem Madrid Forum, March 2011 ERGEG’s draft framework guideline for gas balancing.
Place your chosen image here. The four corners must just cover the arrow tips. For covers, the three pictures should be the same size and in a straight.
Recent Results of JCA-NID and TSAG Byoung Nam LEE HyoungJun KIM ETRI, Korea.
Evaluating Engagement Judging the outcome above the noise of squeaky wheels Heather Shaw, Department of Sustainability & Environment Jessica Dart, Clear.
Working Group # 3 –Settlement: Principles 8 soundness of the settlement, 9 monetary settlements and 10 physical deliveries.
44222: Information Systems Development
Update on ECSDA Activities San Salvador March 2006 European Central Securities Depositories Association ECSDA.
Information Sharing for Integrated Care A 5 Step Blueprint.
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
CONFIDENTIAL© Copyright Seal Software Limited. All Rights Reserved Contract Discovery and Analytics SR14-1: Resolution and Recovery Planning Seal.
Organizations of all types and sizes face a range of risks that can affect the achievement of their objectives. Organization's activities Strategic initiatives.
Enterprise Architectures Course Code : CPIS-352 King Abdul Aziz University, Jeddah Saudi Arabia.
ROMANIA NATIONAL NATURAL GAS REGULATORY AUTHORITY Public Service Obligations in Romanian Gas Sector Ligia Medrea General Manager – Authorizing, Licensing,
Licensing Rules for Communications Networks and Services CONSULTATION DRAFT FEBRUARY 2014.
XML Interoperability & Convergence ISO XML Working Group (WG 10) XML on Wall Street November 20th, 2001 John Goeller.
44th Meeting of the Standing Committee Bonn, Germany, October 2015 Report on activities of the Strategic Plan Working Group Ines Verleye,
REPORT OF THE ELECTRONIC WORKING GROUP UNEP(DEC)/CAR WG.29/INF.12
Global trends in post trade Implications to CIS and CEE region Yerevan, October 2011 STRICTLY PRIVATE AND CONFIDENTIAL.
Alignment of Part 4B with ISAE 3000
Communication and Consultation with Interested Parties by the RB
IESS Agenda point 7.3 DSS Meeting September 2014.
EUROGAS LNG TASK FORCE Bilbao, 13 March 2009 Presentation by
CSDs over SWIFT Current status, challenges and strategy
The SEPA Commitment for banks
Project leader: Richard Morton Lead Editor: Jalal Benhayoun
Presentation transcript:

Slide 1 Independent Advisory Group Giovannini Barrier 1 Meeting 3 August 23rd, 2005

IAG_230805_v1.pptSlide 2 Agenda  Review of 3 rd August minutes  Focus on the Data Layer –Standards –Security –Service  Any other business

IAG_230805_v1.pptSlide 3 Agenda  Review of 3 rd August minutes  Focus on the Data Layer –Standards –Security –Service  Any other business

IAG_230805_v1.pptSlide 4 Review of 3/08 minutes Protocol shelf life recommendation  The protocol will have a fixed ‘shelf-life’ that is made up of 2 periods: –X1 = An agreed implementation period –X2 = A fixed period of general usage to allow amortisation of development cost  Period length will be agreed when the full protocol content is finalised  Fixing content & shelf-life may preclude the use of the latest technology but for all participants, it will provide; –A minimum technical target –A realistic timeframe for implementation –A reasonable period for amortisation of development cost providing a take up incentive based on knowing development cost is not wasted  Protocol content should be reviewed (X1+X2) - 1year to allow continuity

IAG_230805_v1.pptSlide 5 Protocol framework Transfer Data Transfer Data STANDARDSSTANDARDS SECURITYSECURITY SERVICESSERVICES 1414  The proposed 9 element framework should be collapsed into 6 elements and 2 layers

IAG_230805_v1.pptSlide 6 Review of 3/08 minutes Element 4 – Transfer Layer Standards  A Giovannini compliant service must use: –Structured messages and file formats where they exist –Internet Protocol (IP) for communication & routing –Data transfer services based on: – Messages and/or – File and/or – Operator based (GUI)  The selection of the transfer service appropriate to a specific communication is agreed bilaterally between participants  The Giovannini protocol should apply to domestic as well as cross border transactions  The Transfer Layer can be provided by single or multiple providers

IAG_230805_v1.pptSlide 7 Review of 3/08 minutes Element 5 – Transfer Layer Security  A Giovannini compliant service must offer (subject to further incremental cost research) for message/file transfer communication: –Authentication/data integrity (PKI) with liability (from zero to full) –Non-repudiation with liability –Time stamping  If the incremental cost of offering all elements for all communication is considered too high, differentiation between the types of communication will be required to determine the applicability of different types of security  Certificate Registration Authority must implement ISO PKI Public Key Infrastructure Policy and Practices Framework standards for Certificate issuance  Market best practice minimum key strength (to be identified)

IAG_230805_v1.pptSlide 8 Review of 3/08 minutes Element 6 – Transfer Layer Service  Transfer Layer service providers should ensure their services are available during TARGET opening hours as a mandatory minimum  Transfer Layer service providers must satisfy business & regulatory requirements for performance, resilience and network management  In addition to security services listed previously, minimum mandatory Transfer Layer services are: –Message/file audit log –Message/file guaranteed delivery –Message/file delivery once and only once

IAG_230805_v1.pptSlide 9 Review of 3/08 minutes Action Items  ADouglas to research the cost implications of adding all security to all messaging using SWIFT as a proxy for a generic solution  For typical SWIFT services, –PKI cost = –Non-repudiation = 10-20% of transmission cost –Time stamping

IAG_230805_v1.pptSlide 10 Review of 3/08 minutes Action Items  ADouglas to research the current industry best practice in regards of PKI strength. This to form part of the final recommendation  International Standard ISO PKI Public Key Infrastructure Policy and Practices Framework. –Covers control objectives & procedures to ensure that a CA is performing accordingly to its Certificate Practice Statement. –Draft submitted with recommendation to approve, closing date of ballot 30/8 –National Standards bodies to be balloted are: – Czech Republic – France – Germany – Italy – Netherlands – Sweden – Switzerland – United Kingdom

IAG_230805_v1.pptSlide 11 Agenda  Review of 3 rd August minutes  Focus on the Data Layer –Clarification –Standards –Security –Service  Any other business

IAG_230805_v1.pptSlide 12 Focus on the Data Layer Clarification:  Process model vs Business model –A common process model is not a common business model –A process model seeks to define expected input and outputs associated with a particular business process, it does not define how that process should be implemented and used –To achieve a common business model requires an understanding of both market practice and internal participant structure, neither of which are within the scope of this project

IAG_230805_v1.pptSlide 13 Focus on the Data Layer: How far from common data standards are we?  2003, MI’s surveyed on use of key data standards in both Cross Border & Domestic Clearing & Settlement processing –15 CSD’s plus 2 ICSD’s –Responses from 12 countries/ICSD’s  Survey predated inclusion of 10 Accession states into the EU  Responses included intended use as well as actual use. Therefore results should be considered ‘optimistic’

IAG_230805_v1.pptSlide 14 Focus on the Data Layer: How far from common data standards are we? Note, this reflects the position as at the end of 2004 when the current SWIFT migration to IP network architecture will be completed. Available Standard Infrastructure use – Cross border Infrastructure use – DomesticCross Border Community Use* BIC52100% ISIN % Account NumberNo StandardProprietaryNo Standard ISO Currency Code10 100% ISO Country Code11 100% Certificate IDNo StandardProprietaryNo Standard ISO Data Dictionary92100% ISO Message syntax83100% ISO Message Set41100% SMPG (local) Message Set74As Appropriate IP Network11 100% Centrally Managed Architecture11 100% Dedicated Network10 100%

IAG_230805_v1.pptSlide 15 Focus on the Data Layer Element 1: Standards - Consultation Content  Common process model agrees, for a single process: –key players, data elements, how to logically group data elements and when to send data, i.e. identification of business triggers  Common data dictionary: –Common repository accessible by all participants  Common syntax: –Arrangement of data into specific messages  Business and syntax synonyms: –Allows translation between syntaxes and forms part of the data dictionary

IAG_230805_v1.pptSlide 16 Focus on the Data Layer Element 1: Standards - Consultation comments  BVI –‘The protocol needs, at least for a certain period, to provide for the continued use of existing messages’ –‘We would like to stress … the importance that all market participants are required to use ISO standards for the identification of [counter]parties, securities and accounts…in particular ISIN, BIC and MIC as well as working on International Business Entity Identifier, IBEI’ –‘…the use of non ISO compliant national or proprietary identification codes should be discouraged under the protocol’  DESSUG –‘We insist that the proposal for the co-existence of ISO and ISO be applied’

IAG_230805_v1.pptSlide 17 Focus on the Data Layer Element 1: Standards - Consultation comments  Deutsche Bank –‘it is absolutely mandatory that all parties have the same understanding of the data elements and their content’  ECSA –‘translation is an important element of any solution, especially in the context of protecting existing investment in the ISO15022 standards’  Euroclear –‘Investments made by the industry in supporting ISO must be preserved’

IAG_230805_v1.pptSlide 18 Focus on the Data Layer Element 1: Standards - Consultation comments  LSE –‘there is a core set [of processes] that need to be standardised, and others that could remain non-standard’  OMX –‘interpretations of Barrier 1 have simply gone too far when stating that it is necessary to have one common, mandatory business model for all financial post-trade activities’  UBS –‘To fully remove barrier 1, process modelling is only necessary for business processes where no industry accepted message standard exists’

IAG_230805_v1.pptSlide 19 Focus on the Data Layer Element 1: Standards - Consultation responses  Q4.2 generic responses  51 responses in totalAgree –15 EU FI13 – 87% –11 FI EU rep orgs8 – 73% –7 EU C&S Infrastructures5 – 71% –Total (inc above) 34– 67%

IAG_230805_v1.pptSlide 20 Focus on the Data Layer Element 1: Standards - Consultation responses  Q5.5 –What is the industry view on the standards co- existence requirement? –Does such a strategy support the ongoing improvement of the Clearing & Settlement process? –If not, what alternatives exist?

IAG_230805_v1.pptSlide 21 Focus on the Data Layer Element 1: Standards - Consultation responses  Q5.5 Agree with the need for co-existence?  51 responses in totalAgree –15 EU FI14 – 93% –12 FI EU rep orgs11 – 92% –8 EU C&S Infrastructures6 – 75% –Total (inc above) 44– 86%

IAG_230805_v1.pptSlide 22 Focus on the Data Layer Element 1: Standards - Consultation responses  Q5.5 Need to leverage ISO15022?  51 responses in totalAgree –15 EU FI9 – 60% –12 FI EU rep orgs7 – 58% –8 EU C&S Infrastructures4– 50%

IAG_230805_v1.pptSlide 23 Focus on the Data Layer Element 1: Protocol, Standard and Syntax Protocol Standard Syntax

IAG_230805_v1.pptSlide 24 Agreement of terms: ‘Protocol, Standard & Syntax’ Step 1  Cash Equities, Fixed Income inc listed funds –All EU Securities Settlement Systems and Clearing & Settlement infrastructures must provide an ISO15022 and ISO20022 market practice compliant entry and/or exit point for existing messages, with co-existence solutions where relevant, within 2 years, for Clearing, Settlement and Asset Servicing –In parallel, a gap analysis of ISO Standards must be completed by SWIFT Standards for the 25 EU States (plus other countries as necessary) to discover which functionality is missing. The standards must then be extended to include that functionality  Exchange traded derivatives –Relevant expert bodies (e.g Eurex, FIA, CME, LCH Clearnet) should consult on the feasibility and if appropriate recommend a plan to achieve compliance with Step 2

IAG_230805_v1.pptSlide 25 Agreement of terms: ‘Protocol, Standard & Syntax’ Step 2  For EU Cash Equities and Fixed Income Clearing and Settlement plus Asset Servicing, ISO15022/20022 must be implemented in compliance with existing market practices by all participants within 5 years

IAG_230805_v1.pptSlide 26 Focus on the Data Layer Element 1: Standards – Proposed ratification  Where an ISO standard exists,it is the preferred option. Today, this includes: –ISO Country Codes –ISO Currency codes –ISO ISIN –ISO Date/time format –ISO BIC –ISO MIC –ISO CFI –ISO IBAN –ISO IBEI (Provisionally) –ISO Financial services data dictionary = ‘The Standard’  Ultimately, these recommendations must apply to domestic as well as cross border activity

IAG_230805_v1.pptSlide 27 Focus on the Data Layer Element 2: Security – Consultation content  Not application security  Role Based Access Control –Build into application –Build into transfer layer

IAG_230805_v1.pptSlide 28 Focus on the Data Layer Element 2: Security - Consultation comments  ABN –‘It is extremely important that the particpants can rely on the fact that data trhey send is actually received in good order and the messages/data are not interfered with by 3 rd parties’  AFTI –‘According to the level of security required for each message type, different ranges of profiles must be considered to reduce costs. A participant could so have multiple roles according to the type of message exchanged’

IAG_230805_v1.pptSlide 29 Focus on the Data Layer Element 2: Security - Consultation comments  Deutsche Bank –‘It has to be ensured that only the respective parties will have access to their data and their functionality according to their role in the process’  Euroclear –‘We believe that role based access control can only be built at the application level, not at the level of the messaging interface as suggested, because in many cases it required knowledge of the contents of the message and understanding of the business context’

IAG_230805_v1.pptSlide 30 Focus on the Data Layer Element 2: Security – Proposed ratification  The Giovannini protocol concerns the transfer of data between counterparties. The security of data during transfer is the responsibility of the Transfer Layer  Data Security is therefore already covered in the element 5, Transfer Layer Security  Application security is out of scope of the protocol

IAG_230805_v1.pptSlide 31 Focus on the Data Layer Element 3: Service – Consultation content  At the data layer, the key goal of Barrier 1 is the establishment and then maintenance of interoperability of Standards [syntaxes?]  This requires a commitment from application providers and users to implement data standards changes within an agreed timeframe to prevent divergence and ensure continued compliance  Such commitments would form the basis of a mandatory compliance requirement

IAG_230805_v1.pptSlide 32 Focus on the Data Layer Element 3: Service - Consultation responses  Q4.5 –What is your opinion on the need to implement a market wide Data Standards compliance commitment, i.e. when new data standards are published, all participants agree to implement within specific timeframes –If you agree, is a 6 month mandatory compliance window appropriate? i.e. compliance with the standard is mandatory within 6 months of publication

IAG_230805_v1.pptSlide 33 Focus on the Data Layer Element 3: Service - Consultation responses  Q4.5 Agree with the need for mandatory compliance window?  54 responses in totalAgree –15 EU FI13 – 87% –12 FI EU rep orgs9 – 75% –10 EU C&S Infrastructures8 – 80% –Total (inc above) 42– 78% –Explicitly disagree4 – 7%

IAG_230805_v1.pptSlide 34 Focus on the Data Layer Element 3: Service - Consultation responses  Q4.5 If you agree, what is an appropriate timeframe?  Agree –Variable16 – 30% –6 months4 – 7% –>6 months11 – 20% –12 months 2– 4% –> 1yr11 – 20%  Instead of a minimum, should there be a maximum compliance time?

IAG_230805_v1.pptSlide 35 Focus on the Data Layer Element 3: Service - Consultation comments  ABN –‘The implementation of a market wide data standard is a key issue……the period depends on the environment and the complexity of the changes…’  BNP –‘…it is difficult to decide a unique timeframe as the ‘‘gap to fill’’ might be very different in each case…’  Clearstream –We mainly disagree with the proposal to have a mandatory compliance with a new standard within 6 months of publication –Not all business areas justify mandatory compliance at this time, e.g. collateral – New standards should only be produced when there is a business case – Only if a new standard can be justified by issues above, the obligation to support new messages within a given timeframe should be put on MI’s providing the service – Nevertheless, there should be market approval on which standards should be developed and on timeframes in which they become mandatory for MI’s’

IAG_230805_v1.pptSlide 36 Focus on the Data Layer Element 3: Service - Consultation comments  Credit Suisse –‘…the timeframe needs to be specified on a case by case basis…’  Euroclear –‘The final report should include both – a recommendation for the approach, governance and timeframe for the development of new standards – A recommendation and agreed approach to implementation by the industry  Euronext –‘Mandatory compliance is necessary otherwise there is a risk that evolution would be blocked by some participants’

IAG_230805_v1.pptSlide 37 Focus on the Data Layer Element 3: Service - Consultation comments  JP Morgan Chase –‘Without [a market wide compliance commitment] there is the likelihood of diversity around the common standards that effectively erodes efficiency…’  NCSD –‘It is not feasible to to set up one maximum lead time fitting all possible scenarios of change’  UBS –‘Strongly supports the concept of the SWIFT-FIN service which defines 2 usage classes of messaging: – In general use – In closed user groups’

IAG_230805_v1.pptSlide 38 Focus on the Data Layer Element 3: Service - Consultation comments  Virt-X –‘…it is clear that there will not always be a definitive cost benefit for all participants to adopt new standards simultaneously. This could be handled by timelines being set in line with majority adoption…it is unclear at this stage how this could be policed…could create divergence and impose restrictions on interoperability which would be counterproductive to the whole initiative’  Respondent C –‘The word ‘Standard’ implies mandatory compliance otherwise it is not a standard’

IAG_230805_v1.pptSlide 39 Focus on the Data Layer Element 3: Service – Proposed ratification  For innovation of processes and instruments, custom messages can be created using extensibility tools and rules provided by the standards authority, pending incorporation into the Standard

IAG_230805_v1.pptSlide 40 Agenda  Review of 3 rd August minutes  Focus on the Data Layer –Clarification –Standards –Security –Service  Any other business

IAG_230805_v1.pptSlide 41 The next meeting is…..  12 th September at 11.00am  The subjects will be –‘Acid test’ of recommendations –Implementation guidelines