Implement OB Security Profile Implementer's Draft v1.1.2
Implement FAPI Profile Implementers Draft 2
Implement CIBA Profile Implementers Draft 1
N/A
Implement Dynamic Client Registration v1.1
N/A
Implement Dynamic Client Registration v3.1
N/A
Decommission Read/Write API Specification v1.x/2.x
N/A
Decommission OB Security Profile Implementer's Draft v1.x
N/A
...
Panel
borderStyle
dashed
title
Method of Identification
Page Properties
id
ID-Production
Commence support for eIDAS QWAC certificates
From Q2 2020
Commence support for eIDAS QSEAL certificates
From Q2 2020
Commence support for OBIE QWAC-like certificates
From 14th September
Commence support for OBIE QSEAL-like certificates
From 14th September
Cease support for OBIE non eIDAS-like certificates for transport
No Plans
Cease support for OBIE non eIDAS-like certificates for signing
No Plans
Support for MTLS token endpoint authentication
From 14th September
Support for private_key_jwt token endpoint authentication
From 14th September
Cease support for client id and client secret token endpoint authentication
No Plans
Alpha FX suggests TPPs to use Private Key JWT but won’t stop the support for client id and secret
Panel
borderStyle
dashed
title
Implementation
Page Properties
id
TC-IMP
Directory?
Open Banking
Location of Well Known Endpoints?
Dev Portal
API Standard Implemented?
Open Banking v3.1
Name of Account Holder Implementation Date?
TBC
Date of Current eIDAS Implementation?
MTLS against OB Certificates, Investigating implementation of eIDAS certificates.
Current Certificates used for Identification?
Current Certificates used for Transport?
Current Certificates used for Signing?
Date of Future eIDAS Implementation?
No future update currently planned.
Future Certificates used for Identification?
Future Certificates used for Transport?
Future Certificates used for Signing?
Major Milestones
Releasing at Version 3.1, no plans for subsequent versions as of yet.
(Inc Other Products, API Updates, API Deprecations, etc)
Brand(s)
Security Profile?
Open Banking
Security Profile Certification?
Yes
CIBA
N/A
Using Open Banking as your eIDAS Trust Framework?
Yes
Are you caching the Directory?
No
Transaction IDs
Option 1
...
Panel
borderStyle
dashed
title
Customer Journey
Page Properties
id
TC-CJ
Implementing Customer Experience Guidelines?
Yes
Current CEG Version?
Next CEG Version?
Next Version Implementation Date
Implementing Bespoke User Journeys?
Implementing Bespoke User Journeys?
No
Implementing App to App?
No
App to App Implementation Date?
No
Options on 90 day re-authentication?
Same as our online journey. PSU needs to re-authenticate as per standard Open Banking AIS journey (TPP will redirect PSU to AlphaFX login screen, select account, re-authenticate, redirected back to app)
Support Embedded Flow?
No
...
Panel
titleColor
Black
borderStyle
dashed
title
PSD2
Page Properties
id
TC-PSD2
Dispute Management System?
No (See notes)
We have our own operational process in place
FCA Adjustment Period - Maintaining Screen Scraping?
No
Seeking Fallback Exemption?
Exemption granted on
Adjusted or Fallback Interface?
We are planning to scope the work required for a fallback interface should the exemption fail so that the interface fallback can be confirmed as possible within the required 2 month window. If exemption is achieved we’ll keep the implementation plan for the fallback in place for the possible revocation of the exemption.