Nocashevents Nocashevents
  • Home
  • News
  • About
  • NOCASHTV
  • Archive
    • Fintech Banking Summit 2017
      • Venue
      • Schedule
      • Speakers
    • Gala NoCash Spring 2018
      • Premiile Galei NOCASH
      • Competitia FINTECH
      • Agenda
      • Locatie
      • Galerie Video
      • Galerie Foto
    • Banking 4.0 – 2018
    • Open banking workshop
    • Banking 4.0 – 2019
      • Speakers
      • Advisory Board
      • Tickets
      • Locatie
      • Agenda
    • Gala NOCASH Covid 19th Edition
      • Agenda
      • Locatie
    • BANKING 4.0 2021
    • Banking 4.0 – Blockchain edition
  • Contact

EBA publishes clarifications to the fourth set of issues raised by its Working Group on APIs under PSD2

July 30, 2019 / Nocashevents / Comments Off on EBA publishes clarifications to the fourth set of issues raised by its Working Group on APIs under PSD2

The European Banking Authority (EBA) published clarifications to a fourth set of issues that had been raised by participants of its Working Group (WG) on APIs under PSD2. The clarifications respond to issues raised on the confirmation of payment execution, biometrics and authentication on mobile apps, access to non-payment account information, stress testing, qualified eIDAS certificates for Account Servicing Payment Service Providers (ASPSPs), the 4 times per day access by Account Initiation Service Providers (AISPs), and the Sharing of payment account number with Payment Initiation Service Providers (PISPs).

Topic: Biometrics and authentication on mobile apps

Description: Several participants raised concerns that the APIs currently offered or being developed by many banks do not support app-to-app redirection or so-called decoupled authentication (which allows the customer to authenticate using a dedicated authentication application of the ASPSP, such as a banking app on a mobile phone) when the customer is using a TPP, although some of those banks allow their customers to authenticate via the ASPSP’s mobile app or use biometrics to authenticate in the online channels of the ASPSP in order to access account information and/or initiate payments directly.

These participants stressed that ASPSPs should allow AIS and PIS providers to rely on all the authentication procedure(s) provided by the ASPSP to its PSUs. In particular, they highlighted that ASPSPs supporting the use of biometrics in their mobile/online channels should also support authentication via biometrics in their dedicated interfaces. TPPs highlighted that this is essential in order to ensure a seamless customer experience and not to create obstacle to the provision of AIS and PIS.

EBA response: In accordance with Article 97(2) of PSD2 and Article 30(2) of the RTS, ASPSPs should ensure that their dedicated interface does not prevent PISPs and AISPs from relying upon the authentication procedure(s) provided by the ASPSP to its PSUs.

As clarified in paragraph 50 of the EBA Opinion on the implementation of the RTS (EBA-Op-2018-04) and the Final report on the EBA Guidelines on the conditions to benefit from an exemption from the fall-back mechanism (EBA/GL/2018/07) (feedback table, page 68, comment 75 and page 75, comment 89), ASPSPs’ dedicated interfaces should support all authentication methods made available by the ASPSP to its PSUs when an AISP or PISP is used.

Accordingly, the method of access, or combination of methods that the dedicated interface should support, will depend on the authentication procedures that the ASPSP offers to its own PSUs, and whether security credentials are transmittable (such as a passwords) or not (such as biometrics).

This means that, ASPSPs that have implemented a redirection approach and that enable their own PSUs to authenticate via the ASPSP’s mobile app when the PSU directly accesses his/her account should also support app-toapp redirect when the customer uses a TPP. App-to-app redirection should allow the TPP to redirect a PSU from the TPP mobile application to the ASPSP’s mobile application, 3 installed on the PSU’s device, where PSUs can then authenticate using the same credentials/methods as normally used for accessing their account directly. This should not involve additional steps than would be the case when the PSU authenticates with the ASPSP directly (such as being redirected first to the ASPSP’s mobile website).

Finally, ASPSPs that support authentication using biometrics in their direct customer channels should also support these authentication methods when the PSU is using a PIS or AIS provider. In such case, given that biometrics are not transmittable credentials, ASPSPs should support decoupled or app-to-app redirect to the ASPSP authentication app and secure transmission of the ASPSP’s app authentication status to the ASPSP (e.g. using a signed proof that the biometric validation has been performed successfully).

Download the full document here: EBA responses to issues XIV to XX raised by participants of the EBA Working Group on APIs under PSD2

Tags: Account Initiation Service Providers (AISPs)  Account Servicing Payment Service Providers (ASPSPs)  APIs  eIDAS certificates  PSD2  support authentication via biometrics  The European Banking Authority (EBA)
Categories: News
Share:

   
 
 

Recent news

  • Deloitte study: banks’ profitability to decrease over the next year and to return to current levels in 2026. Embedded finance is an opportunity that will generate estimated revenues of USD 230 billion by 2025.
  • New research reveal surge in B2B embedded finance demand. B2B Businesses choose fintechs as their preferred embedded finance provider as use cases expand.
  • The future of finance is embedded
  • „The next phase of the fintech disruption is moving beyond open banking to embedded finance” – KPMG says
  • The trends transforming today’s digital banking. Hyper-personalisation of banking services – from target groups to target person.

Tags

AI APIs artificial intelligence Banking 4.0 Banking 4.0 conference blockchain blockchain technology Central Bank Digital Currencies central bank digital currency central bank digital currency (CBDC) Coinbase Cosmin Cosma - CEO cryptocurrencies digital assets digital banking digital payments embedded finance Ethereum blockchain European Banking Authority European Banking Authority (EBA) Finqware fintech banking iSense Solutions Klarna machine learning Mastercard metaverse National Bank of Romania NFTs NOCASH events open banking open banking in Romania open banking platform open finance Payment Services Directive (PSD2) PSD2 Salt Edge Smart Fintech stablecoins Strong Customer Authentication Strong Customer Authentication (SCA) Third Party Providers (TPP) Tink Tradesilvania Visa

Archives

  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • November 2021
  • October 2021
  • September 2021
  • July 2021
  • June 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • November 2020
  • October 2020
  • September 2020
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • April 2019
  • March 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • May 2018
  • April 2018
  • November 2017
  • August 2017

logo

© 2018 Nocash Events – All rights reserved. Politica de confidentialitate | By Webdesigneuropean.eu
Site-ul nostru utilizează fişiere de tip Cookie pentru a personaliza și îmbunătăți experiența ta. Înainte de a continua navigarea pe Website-ul nostru te rugăm să aloci timpul necesar pentru a citi și înțelege conținutul Politicii de Confidentialitate. Prin continuarea navigării pe Website-ul nostru confirmi acceptarea utilizării fişierelor de tip cookie. Accept Aflati mai multe aici.
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT