Panel |
---|
titleColor | Black |
---|
borderStyle | dashed |
---|
title | OB Standards |
---|
|
This Section applies to ASPSPs that have implemented OB Standards
Page Properties |
---|
icon | false |
---|
id | TC-OB Standards-Production |
---|
| Implement Open Data v2.2 | N/A | Not Implemented |
---|
Implement Read/Write API Specification v3.1 | | Implement Customer Experience Guidelines v1.1 | | Implement App-to-App Redirection | TBC | Implement OB Security Profile Implementer's Draft v1.1.2 | TBC | Implement FAPI Profile Implementers Draft 2 | TBC | Implement CIBA Profile Implementers Draft 1 | N/A | Not Implemented |
---|
Implement Dynamic Client Registration v1.1 | N/A | Not Implemented |
---|
Implement Dynamic Client Registration v3.1 | TBC | Decommission Read/Write API Specification v1.x/2.x | N/A | Not Implemented |
---|
Decommission OB Security Profile Implementer's Draft v1.x | N/A | Not Implemented |
-Have you Implemented OB Standards? | |
|
---|
Open Data - Which version have you Implemented? | |
|
---|
Read/Write API Specification Implemented or planning to implement (Lowest version = Current, Highest version = Planned) | - V3.0
- V3.1
- V3.1.1
- V3.1.2
- V3.1.3
- V3.1.4
- V3.1.5
- V3.1.6
- V3.1.7
- V3.1.8
- V3.1.9
- V3.1.10
- V3.1.11
- V4.0
| We have only implemented the following API's: AISP: Account Access Consents v3.1.9 Accounts v3.1.9 Balances v3.1.9 Transactions v3.1.9 Beneficiaries v3.1.9 Direct Debits v3.1.9 Standing Orders v3.1.9 Party v3.1.9 Scheduled Payments v3.1.9 Statements v3.1.9 PISP: Domestic Payments v3.1.9 Domestic Scheduled Payment v3.1.9 Domestic Standing Orders v3.1.9 CPBII: Funds Confirmation Consent v3.1.9 Funds Confirmation v3.1.9 DCR: Dynamic Client Registration v3.2 |
---|
Read/Write API - Which date are you planning to implement your latest version? |
| Currently reviewing v3.1.11, possible implementation 2024 |
---|
Have you implemented v4.0 information flows, if not date planned to Implement? | - Already Implemented
- Planning to implement
- Not planning to implement
|
|
---|
Dynamic Client Registration - Which version have you Implemented or planning to implement? (Lowest version = Current, Highest version = Planned) | |
|
---|
DCR - Which date are you planning to implement your latest version? |
| Currently reviewing v3.3 possible implementation 2024 |
---|
Have you implemented Trusted beneficiaries, if not date planned to Implement? | - Already Implemented
- Planning to implement
- Not planning to implement
|
|
---|
Have you implemented Reverse Payments, if not date planned to Implement? | - Already Implemented
- Planning to implement
- Not planning to implement
|
|
---|
Have you implemented ECA Standard? | - Already Implemented
- Planning to implement
- Not planning to implement
|
|
---|
ECA Implementation details |
| Contact: [enter contact details for the relevant person(s) at your organisation] [You can use this space to provide your status with respect to the Standard] |
---|
Have you implemented Bulk/File Payments? | - Already Implemented
- Planning to implement
- Not planning to implement
|
|
---|
Have you implemented VRP – Sweeping, if not date planned to Implement? | - Already Implemented
- Planning to implement
- Not planning to implement
|
|
---|
Have you implemented VRP non-Sweeping, if not date planned to Implement? | - Already Implemented
- Planning to implement
- Not planning to implement
| Contact: [enter contact details for the relevant person(s) at your organisation] [You can use this space to provide implementation details relevant to VRP] |
---|
PISP - Single Payment Limit | £ |
|
---|
PISP - Daily Payment Limit | £ |
|
---|
How many months of transaction do you provide? | 90 days |
|
---|
Have you implemented TRIs (Transactional Risk Indicators), if not, date planned to Implement? |
| Currently reviewing requirement possible implementation 2024 |
---|
What is your approach to Implementing TRIs? | - Accept payload with TRI fields – Process all fields
- Accept payload with TRI fields – Ignore all fields
- Reject payload with TRI fields – Error back to TPP
- Accept payload with TRI fields – Process few fields (Provide list of accepted fields)
|
|
---|
|
|
Panel |
---|
borderStyle | dashed |
---|
title | Method of IdentificationSCA-RTS 90-day reauth Implementation |
---|
|
Page Properties |
---|
| Commence support for eIDAS QWAC certificates | | Commence support for eIDAS QSEAL certificates | | Commence support for OBIE QWAC-like certificates | | Commence support for OBIE QSEAL-like certificates | | Cease support for OBIE non eIDAS-like certificates for transport | TBC | Cease support for OBIE non eIDAS-like certificates for signing | TBC | Support for MTLS token endpoint authentication | |
---|
Support for private_key_jwt token endpoint authentication | TBC | Currently being investigated |
---|
Cease support for client id and client secret token endpoint authentication | N/A |
|
Panel |
---|
borderStyle | dashed |
---|
title | Implementation |
---|
|
Page Properties |
---|
|
Page Properties |
---|
|
Directory? | Open Banking | Location of Well Known Endpoints? | OB Technical Directory | API Standard Implemented? | Open Banking | Name of Account Holder Implementation Date? | TBC | Date of Current eIDAS Implementation? | TLS 1.2 | Current Certificates used for Identification? | Current Certificates used for Transport? | Current Certificates used for Signing? | Date of Future eIDAS Implementation? | No future update currently planned. | Future Certificates used for Identification? | Future Certificates used for Transport? | Future Certificates used for Signing? | Major Milestones | TBC | Brand(s) | Security Profile? | Security Profile Certification? | CIBA | No | Using Open Banking as your eIDAS Trust Framework? | TBC | Currently being investigated by our TSP | Are you caching the Directory? | No | Transaction IDs | TBC | Panel |
---|
|
Which date are you planning on implementing the SCA reauthentication exemption? | Implemented Nov '22 |
|
---|
What is your approach to token management to enable application of the reauthentication exemption? (see link to FCA guidance) | Consent provided unless life event requires revocation. | Example approach: Issue a long-lived refresh token during one final SCA, with refresh token rotation implemented. [Please use this space to provide more details on your approach] |
---|
Article 10A - Endpoints exempt of SCA-RTS | Accounts -
Transactions (90days) -
Balances -
Standing orders -
Direct debits -
Beneficiaries -
Products -
Offers -
Parties -
Scheduled Payments -
Statements
|
|
---|
Article 10A - Endpoints not exempt of SCA-RTS | |
|
---|
Article 10A - Maximum time period after authentication | 10 | Please specify the time period in minutes |
---|
SCA-RTS implementation status (updated by OBL PS team only) | Status |
---|
colour | Green |
---|
title | Implemented |
---|
|
| Planned / In-progress / Implemented / TBC |
---|
|
|
Panel |
---|
titleColor | Black |
---|
borderStyle | dashed |
---|
title | Security Profile |
---|
|
Page Properties |
---|
|
-Which Security profile have you Implemented or planning to implement? (Lowest version = Current, Highest version = Planned) | - OB Security Profile (Legacy)
- FAPI (ID2)
- FAPI 1 Advanced
- Other (Please define)
|
|
---|
Security Profile - Next Planned Version Implementation Date |
|
|
---|
CIBA Profile - Implemented or planning to implement (Lowest version = Current, Highest version = Planned) | - None
- CIBA
- CIBA FAPI Profile
|
|
---|
CIBA Profile - Next Planned Version Implementation Date |
|
|
---|
Security Profile Certification date? | |
|
---|
Token Endpoint Authentication Methods Supported | -
client_secret_post -
client_secret_basic -
client_secret_jwt -
tls_client_auth - Private_key_jwt
|
|
---|
Planned date to Cease support for client id and client secret token endpoint authentication |
|
|
---|
POST-BREXIT POST TRANSITION - Certificates Accepted (from 1st Jul 2021) | - eIDAS QWAC
- eIDAS QSealC
- OB legacy (obtransport, obsigning)
- OBWAC
- OBSeal
- Other (Please define)
|
|
---|
|
|
Panel |
---|
titleColor | Black |
---|
borderStyle | dashed |
---|
title | Customer Journey |
---|
|
Page Properties |
---|
|
-What is your approach to Implementing OBL Customer Experience Guidelines (CEG)? |
---|
Yes | Current CEG Version? | Next CEG Version? | Next Version Implementation Date | Implementing Bespoke User Journeys? | No | Implementing App to App? | Nov 2020 | App to App Implementation Date? | TBC | Currently being investigated by our TSP |
---|
Options on 90 day re-authentication? | 90 day Re-authentication | Support Embedded Flow? | No | (tick all that apply) | - Already Implemented
- Planning to implement or upgrade
- Not planning to implement CEG
|
|
---|
Which version have you implemented or planning to implement? (Lowest version = Current, Highest version = Planned) | - V3.1.2
- V3.1.3
- V3.1.4
- V3.1.5
- V3.1.6
- V3.1.7
- V3.1.8
- V3.1.9
- V3.1.10
- V3.1.11
- V4.0
|
|
---|
Which date are you planning to implement your latest CEG version? | TBC |
|
---|
Redirection Model | - App to App redirection
- Decoupled authentication
- Embedded Flow
- Bespoke User Journeys
|
|
---|
|
|
Panel |
---|
titleColor | Black |
---|
borderStyle | dashed |
---|
title | PSD2 |
---|
|
Page Properties |
---|
|
Dispute Management System? | Yes | FCA Adjustment Period - Maintaining Screen Scraping-Which Directory are you using as your Trust Framework? | Open Banking |
|
---|
Are you caching the Directory? | No |
|
---|
Transaction IDs Supported | TBC |
|
---|
Are you Seeking Fallback Exemption? |
---|
Yes | Adjusted or Fallback Interface? | No | Adjusted or Fallback URL? | N/A | Contact Email or Phone Number? | TPPsupport@arbuthnot.co.uk | Please use this contact for any queries, issues or support requests. |
---|
Dev Portal URL? | https://www.arbuthnotlatham.co.uk/developers/ | Test Facility Implementation Date? | | Production Interface Implementation Date? | - Currently Live Proving (Whitelisting in Place) | Contingency Measures |
| Article 10 - Maximum time period after authentication |
---|
? | Open ended |
|
---|
Article 10 - Endpoints exempt of SCA |
---|
Not applying Article 10 SCA Exemption | Authentication Method - Open Banking Channel (Browser)? | User Name, Password, OTP on mobile phone | Authentication Method - Open Banking Channel (APP)? | User Name, Password, OTP on mobile phone | Authentication Method - Private Channel (Browser)? | User Name, Password, Memorable word | Authentication Method - Private Channel (APP)? | Biometric or PIN and Registered device | Authentication Method Implementation Date (Open Banking Channel)? | Live | Authentication Method Implementation Date (Private Channel)? | Live | Moving to OTP in line with Adjustment Period |
---|
SCA Implementation Date? | To Align with Adjustment Period | SCA Scope? (will it inhibit non PSD2 accounts) | Yes in Online Banking but Non PSD2 accounts wil not be available for Open Banking. Major Milestones | App2App - Feb 2021 |
|
---|
Brand(s) | Arbuthnot Latham |
|
---|
|
|
Panel |
---|
titleColor | Black |
---|
borderStyle | dashed |
---|
title | ASPSP Dev Portal and Contact Details |
---|
|
|
Panel |
---|
titleColor | Black |
---|
borderStyle | dashed |
---|
title | Key Implementations |
---|
|
Page Properties |
---|
|
| Page Properties |
---|
| | After Waiver 7 Expiry (16/06/20) option supported: Option 1 - The parameter b64 being set to FALSE OR Option 2 - The b64 claim not being in the header | -
---|
|