Featured Product

    HKMA Outlines Consumer Protection Measures for Open API Framework

    October 29, 2019

    HKMA published a circular to clarify its expectations on the consumer protection measures of authorized institutions in respect of the Open Application Programming Interface (Open API) framework. The Annex to the circular lists sound consumer protection practices for Open API Phase II and beyond. To strike a balance between innovation and consumer protection, HKMA emphasizes that authorized institutions should adopt a risk-based approach and implement the consumer protection measures that are commensurate with the risks involved.

    The circular also clarifies the requirements about engagement of intermediaries by the authorized institutions, as the use of third-party service providers under Open API Framework may constitute the use of intermediaries by authorized institutions. For the avoidance of doubt, Simple Redirection Model is not considered as use of intermediaries by authorized institutions and the authorized institutions should still comply with the HKMA-issued applicable requirements for engagement of intermediaries. Authorized institutions should establish clear liability and settlement arrangement with the partnering third-party service providers for compensating customers’ loss arising from unauthorized transactions, with clear upfront communication to customers. They should also and adhere to the principle that a bank customer should not be responsible for any direct loss suffered by him/her as a result of unauthorized transactions conducted through his/her account attributable to the services offered by the third-party service providers using the Open API of authorized institutions, unless the customer acts fraudulently or with gross negligence.

    Authorized institutions are expected to put in place consumer protection measures when implementing the Open API framework. These institutions are expected to uphold consumer protection principles set out in the Code of Banking Practice and comply with other applicable regulatory requirements; this is expected regardless of the underlying technology adopted for the banking products and services and regardless of whether the authorized institutions provide the products and services themselves or in partnership with the third-party service providers.

    Keywords: Asia Pacific, Hong Kong, Banking, Open API Framework, Fintech, Open API Phase II, HKMA

    Related Articles
    News

    EBA Finalizes Remuneration Standards for Investment Firms in EU

    EBA finalized the two sets of draft regulatory technical standards on the identification of material risk-takers and on the classes of instruments used for remuneration under the Investment Firms Directive (IFD).

    January 21, 2021 WebPage Regulatory News
    News

    ECA Recommends Actions to Enhance Resolution Planning for Banks

    EC published, in the Official Journal of the European Union, a notification that the European Court of Auditors (ECA) has published a special report on resolution planning in the Single Resolution Mechanism.

    January 20, 2021 WebPage Regulatory News
    News

    BoE Publishes Key Elements of the 2021 Stress Testing for Banks in UK

    BoE published a scenario against which it will be stress testing banks in 2021, in addition to setting out the key elements of the 2021 stress test, guidance on the 2021 stress test, and the variable paths for the 2021 stress test.

    January 20, 2021 WebPage Regulatory News
    News

    PRA Proposes Rules on Identity Verification of Depositor Protection

    PRA published a consultation paper (CP3/21) proposes rules regarding the timing of identity verification required for eligibility of depositor protection under the Financial Services Compensation Scheme (FSCS).

    January 20, 2021 WebPage Regulatory News
    News

    FSB Publishes Work Program for 2021

    FSB published the work program for 2021, which reflects a strategic shift in priorities in the COVID-19 environment.

    January 20, 2021 WebPage Regulatory News
    News

    FCA Issues Update on Move to New Data Collection Platform

    FCA announced that 50% firms have started using the new data collection platform RegData, which is slated to replace the existing platform known Gabriel.

    January 20, 2021 WebPage Regulatory News
    News

    Bundesbank Publishes Derivation Rules for Reporting by Banks

    Bundesbank published Version 5.0 of the derivation rules for completeness check at the form level, with respect to the data quality of the European harmonized reporting system.

    January 19, 2021 WebPage Regulatory News
    News

    FED Revises Capital Planning and Stress Testing Requirements for Banks

    FED finalized a rule that updates capital planning requirements to reflect the new framework from 2019 that sorts large banks into categories, with requirements that are tailored to the risks of each category.

    January 19, 2021 WebPage Regulatory News
    News

    ECB Releases Results of Bank Lending Survey for Fourth Quarter of 2020

    ECB published results of the quarterly lending survey conducted on 143 banks in the euro area.

    January 19, 2021 WebPage Regulatory News
    News

    ESAs Publish Reporting Templates for Financial Conglomerates

    ESAs published the final draft implementing technical standards on reporting of intra-group transactions and risk concentration of financial conglomerates subject to the supplementary supervision in EU.

    January 18, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 6484