BIS published a report that explores the development of an identification and authentication application program interface (API) that could be used to implement privately and publicly administered open finance solutions with seamless scalability. This report is intended to serve as a general reference for individual countries that want to develop their own payments initiatives. However, the decision on which type of API architecture should be implemented depends on the characteristics of each jurisdiction. Comments on this report should be sent, preferably, by January 31, 2021.
The report highlights the importance of open finance for the development of the financial system, lists the trade-offs regarding implementation schemes for open finance, and serves as background for the other, more technical documents; these documents include a technical flow diagram of identity validation based on a centralized API architecture (unpublished), general hardware requirements to implement the centralized solution (Annex A), and technical requirements for third parties on the central validator API architecture (Annex B). The Technical Task Force of the Consultative Group on Innovation and the Digital Economy (CGIDE TTF) has been analyzing an API scheme based on mobile devices to support the remote, secure, and efficient identification and authentication of users of financial institutions. The analyzed scheme is based on the establishment of a central validator that allows secure relationships to be created between financial institutions and third parties, without the need for them to come into direct contact with each other. This is accomplished by establishing secure connections between the central validator and third parties on the one hand, and between the financial institutions and the central validator on the other. The security schemes used by the central validator would ensure that all connections in the scheme are established between previously certified entities for the orderly provision of financial services through third parties.
The report describes and proposes in detail the technical requirements for the key elements of the analyzed API scheme (that is, the central validator, third-party apps and servers, authentication app and servers). It also details the technical requirements for the third parties interested in participating in an API scheme like the one analyzed in this report. While the CGIDE TTF considers that the analyzed implementation is viable, this is not the only possible scheme and the ideal solution for each jurisdiction will depend on several factors, such as the level of involvement of the industry in the design of the API architecture, the powers given by law to the authority leading its implementation, the target use cases that the open finance ecosystem expects to cover, or the desired user experience. In this regard, the report discusses the open finance models supported by different API architectures, including those in Brazil, EU (revised Payment Services Directive), India, UK, and Singapore. Thus, this document should only serve as a general reference for individual countries that want to develop their own payments initiatives and, consequently, no member is endorsing the adoption of open banking or the analyzed identification and authentication API and central validator scheme.
Related Link: Report
Keywords: International, Banking, PMI, API, Open Finance, Fintech, Regtech, BIS
Previous ArticleBank of Finland Updates Instructions for AnaCredit Reporting
The Hong Kong Monetary Authority (HKMA) revised the Supervisory Policy Manual module CG-5 that sets out guidelines on a sound remuneration system for authorized institutions.
The European Banking Authority (EBA) published the final guidelines on the monitoring of the threshold and other procedural aspects on the establishment of intermediate parent undertakings in European Union (EU), as laid down in the Capital Requirements Directive (CRD).
In a recent Market Notice, the Bank of England (BoE) confirmed that green gilts will have equivalent eligibility to existing gilts in its market operations.
The Financial Conduct Authority (FCA) published the policy statement PS21/9 on implementation of the Investment Firms Prudential Regime.
The European Banking Authority (EBA) proposed regulatory technical standards that set out criteria for identifying shadow banking entities for the purpose of reporting large exposures.
The Board of the International Organization of Securities Commissions (IOSCO) proposed a set of recommendations on the environmental, social, and governance (ESG) ratings and data providers.
The European Securities and Markets Authority (ESMA) published recommendations from the Working Group on Euro Risk-Free Rates (RFR) on the switch to risk-free rates in the interdealer market.
The European Central Bank (ECB) published a paper as well as an article in the July Macroprudential Bulletin, both of which offer insights on the assessment of the impact of Basel III finalization package on the euro area.
The International Swaps and Derivatives Association (ISDA) published a paper that explores the impact of the Fundamental Review of the Trading Book (FRTB) on the trading of carbon certificates.
The Prudential Regulation Authority (PRA) published the remuneration policy self-assessment templates and tables on strengthening accountability.