PaneltitleColor Black borderStyle dashed title OB Standards
This Section applies to ASPSPs that have implemented OB Standards
Page Propertiesicon false id TC-OB Standards 9Standards-Production
Implement Open Data v2.2 N/A Mandated only for the CMA9 Implement Read/Write API Specification v3.1 Implement Customer Experience Guidelines v1.1 29 Feb 2020 Implement App-to-App Redirection N/A Cynergy Bank does not offer a mobile banking app Implement OB Security Profile Implementer's Draft v1.1.2 29 Feb 2020
Implement FAPI Profile Implementers Draft 2 N/a Implement CIBA Profile Implementers Draft 1 N/A Cynergy Bank does not offer a mobile banking app Implement Dynamic Client Registration v1.1 N/A Implement Dynamic Client Registration v3.1 29 Feb 2020 Decommission Read/Write API Specification v1.x/2.x 14 Mar 2019 Decommission OB Security Profile Implementer's Draft v1.x N/A
PaneltitleColor Black borderStyle dashed title Method of Identification
Page PropertiesCommence support for eIDAS QWAC certificates 29 Feb 2020 Commence support for eIDAS QSEAL certificates 29 Feb 2020
Commence support for OBIE QWAC-like certificates
29 Feb 2020 Commence support for OBIE QSEAL-like certificates 29 Feb 2020 Cease support for OBIE non eIDAS-like certificates for transport 29 Feb 2020 Still accepted for previously on-boarded TPPs until 14 Mar 2020 Cease support for OBIE non eIDAS-like certificates for signing 29 Feb 2020 Still accepted for previously on-boarded TPPs until 14 Mar 2020 Support for MTLS token endpoint authentication 14 Mar 2020 Support for private_key_jwt token endpoint authentication 13 Mar 2019 Cease support for client id and client secret token endpoint authentication N/A PaneltitleColor White titleBGColor #6180c3 borderStyle dashed title Post Brexit Certificate Implementation
Page Properties
PRE-BREXIT - Certificates Accepted (until 31st Dec 2020) eIDAS QWAC eIDAS QSealC OB legacy (obtransport, obsigning) OBWAC OBSeal Other (Please define) POST-BREXIT TRANSITION - Certificates Accepted (1st Jan 2021 - 30th Jun 2021) eIDAS QWAC eIDAS QSealC OB legacy (obtransport, obsigning) OBWAC OBSeal Other (Please define) -Have you Implemented OB Standards? Open Data - Which version have you Implemented? Read/Write API Specification Implemented or planning to implement
(Lowest version = Current, Highest version = Planned)
V3.0 V3.1 V3.1.1 V3.1.2 V3.1.3 V3.1.4 V3.1.5 V3.1.6 V3.1.7 V3.1.8 V3.1.9 V3.1.10 V3.1.11 V4.0 Read/Write API - Which date are you planning to implement your latest version? Have you implemented v4.0 information flows, if not date planned to Implement?
Already Implemented Planning to implement Not planning to implement Dynamic Client Registration - Which version have you Implemented or planning to implement?
(Lowest version = Current, Highest version = Planned)
DCR - Which date are you planning to implement your latest version? Have you implemented Trusted beneficiaries, if not date planned to Implement?
Already Implemented Planning to implement Not planning to implement Have you implemented Reverse Payments, if not date planned to Implement?
Already Implemented Planning to implement Not planning to implement Have you implemented ECA Standard?
Already Implemented Planning to implement Not planning to implement ECA Implementation details
Contact: [enter contact details for the relevant person(s) at your organisation]
[You can use this space to provide your status with respect to the Standard] Have you implemented Bulk/File Payments?
Already Implemented Planning to implement Not planning to implement Have you implemented VRP – Sweeping, if not date planned to Implement?
Already Implemented Planning to implement Not planning to implement Have you implemented VRP non-Sweeping, if not date planned to Implement?
Already Implemented Planning to implement Not planning to implement Contact: [enter contact details for the relevant person(s) at your organisation]
[You can use this space to provide implementation details relevant to VRP] PISP - Single Payment Limit £10,000[Personal Account] £50,000[Business Account] PISP - Daily Payment Limit £10,000[Personal Account] £50,000[Business Account] How many months of transaction do you provide? 12 Have you implemented TRIs (Transactional Risk Indicators), if not, date planned to Implement? No Plan at this time What is your approach to Implementing TRIs? Accept payload with TRI fields – Process all fields Accept payload with TRI fields – Ignore all fields Reject payload with TRI fields – Error back to TPP Accept payload with TRI fields – Process few fields (Provide list of accepted fields)
PanelborderStyle dashed title SCA-RTS 90-day reauth Implementation
Page Properties
Which date are you planning on implementing the SCA reauthentication exemption?
Q2 2024[Implementation of 3.1.10] What is your approach to token management to enable application of the reauthentication exemption ? (see li nk to FCA guidance )
Approach to Article 10A implementation work in progress. Planned for Q2 2024. Example approach: Issue a long-lived refresh token during one final SCA, with refresh token rotation implemented.
[ Please use this space to provide more details on your approach ]
Article 10A - Endpoints exempt of SCA-RTS Accounts
Transactions (90days)
Balances
Standing orders
Direct debits
Beneficiaries
Products
Offers
Parties
Scheduled Payments
Statements
Approach to Article 10A implementation work in progress. Planned for Q2 2024. Article 10A - Endpoints not exempt of SCA-RTS Approach to Article 10A implementation work in progress. Planned for Q2 2024. Article 10A - Maximum time period after authentication Implemented 60 minutes SCA-RTS implementation status ( updated by OBL PS team only )
Planned / In-progress / Implemented / TBC
PaneltitleColor Black borderStyle dashed title Security Profile
Page Properties
-Which Security profile have you Implemented or planning to implement?
(Lowest version = Current, Highest version = Planned)
OB Security Profile (Legacy) FAPI (ID2) FAPI 1 Advanced Other (Please define) Security Profile - Next Planned Version Implementation Date CIBA Profile - Implemented or planning to implement (Lowest version = Current, Highest version = Planned)
None CIBA CIBA FAPI Profile CIBA Profile - Next Planned Version Implementation Date
Security Profile Certification date?
Token Endpoint Authentication Methods Supported client_secret_post
client_secret_basic
client_secret_jwt
tls_client_auth
Private_key_jwt Planned date to Cease support for client id and client secret token endpoint authentication N/A POST-BREXIT POST TRANSITION - Certificates Accepted (from 1st Jul 2021) eIDAS QWAC eIDAS QSealC OB legacy (obtransport, obsigning) OBWAC OBSeal Other (Please define)
Planned Implementation Date to Satisfy FCA's Post Transition TPP PSU Migration Outcomes Supported POST-BREXIT Certificate Implementation Status ( updated by OBIE IES team )
PaneltitleColor Black borderStyle dashed title Implementation Customer Journey
Page PropertiesDirectory?
Open Banking Location of Well Known Endpoints?
Open Banking technical directory and Cynergy Bank Developer Portal https://openbanking.cynergybank.co.uk/API/.well-known/openid-configuration API Standard Implemented?
Open Banking v3.1.1 Open Banking v3.0 Name of Account Holder Implementation Date?
29 Feb 2020 Date of Current eIDAS Implementation? 29 Feb 2020 eIDAS, OBWAC/OBSEAL Current Certificates used for Identification? eIDAS, QSEAL/OBSEAL
Current Certificates used for Transport? OBWAC and eIDAS QWAC Current Certificates used for Signing? OBSEAL and QSEAL Date of Future eIDAS Implementation? No future update currently planned. Future Certificates used for Identification? No future update currently planned. Future Certificates used for Transport? No future update currently planned.
Future Certificates used for Signing? No future update currently planned. Major Milestones
Testing interface Open Banking API standard v3.0 13 Mar 2019 Wide usage interface Open Banking API Standard v3.0 13 Mar 2019 Stress testing (Open Banking API standard v3.0) 30 Jun 2019 Open Banking API standard v3.1.1 29 Feb 2020 Infrastructure upgrade 29 Feb 2020
eIDAS 29 Feb 2020
(Inc Other Products, API Updates, API Deprecations, etc) Brand(s) Security Profile? FAPI 14 Mar 2020 Security Profile Certification? FAPI 14 Mar 2020 CIBA
N/A The
-What is your approach to Implementing OBL Customer Experience Guidelines (CEG)?
(tick all that apply)
Already Implemented Planning to implement or upgrade Not planning to implement CEG Which version have you implemented or planning to implement?
(Lowest version = Current, Highest version = Planned)
V3.1.2 V3.1.3 V3.1.4 V3.1.5 V3.1.6 V3.1.7 V3.1.8 V3.1.9 V3.1.10 V3.1.11 V4.0 Which date are you planning to implement your latest CEG version? Redirection Model App to App redirection Decoupled authentication Embedded Flow Bespoke User Journeys Cynergy Bank does not offer a mobile banking app
Using Open Banking as your eIDAS
PaneltitleColor Black borderStyle dashed title PSD2
Page Properties
-Which Directory are you using as your Trust Framework?
No
Next CEG Version? Next Version Implementation Date Implementing Bespoke User Journeys?
No Implementing App to App?
N/A Cynergy Bank does not offer a mobile banking app App to App Implementation Date? N/A Cynergy Bank does not offer a mobile banking app Options on 90 day re-authentication?
90 day consent model as per SCA-RTS Article 10 Support Embedded Flow?
N/A PaneltitleColor Black borderStyle dashed title PSD2
Page PropertiesDispute Management System?
No FCA Adjustment Period - Maintaining Screen Scraping? Yes Until 14 Mar 2020 Cynergy Bank will utilise an independent eIDAS solution provider (Banfico) . Cynergy Bank will also offer OBIE's Dynamic Client Registration Are you caching the Directory? No Transaction IDs Supported Immutable Transaction ID from Cynergy's Core Banking System
PaneltitleColor Black borderStyle dashed title Customer Journey
Page PropertiesImplementing Customer Experience Guidelines?
Yes
Current CEG Version? Are you Seeking Fallback Exemption?
Yes Provisional Exemption provided by FCA. Final decision to be provided by 12 Apr 2020 Adjusted or Fallback Interface?
N/A Adjusted or Fallback URL? N/A Contact Email or Phone Number? obaccadmin@cynergybank.co.uk Dev Portal URL? https://openbanking.cynergybank.co.uk Test Facility Implementation Date? 14 Mar 2019 Production Interface Implementation Date? 14 Mar 2019 Contingency Measures N/A
Article 10 - Maximum time period after authentication
? If 90 days has elapsed since SCA was applied, the customer will need to re-authenticate.
The 90 day period is specific to each AISP and must be distinguished to the 90 day period which applies to customers.
Application of SCA to initiate a payment (via a PISP or customer) does not restart the 90 day period.
Article 10 - Endpoints exempt of SCA
Exemption will cover all AISP resources Authentication Method - Open Banking Channel (Browser)?
AISP: Username + Password (as knowledge factors) + PIN (as knowledge factor) + hard token/soft token (as possession factors)
PISP: Username + Password (as knowledge factors) + PIN (as knowledge factor) + hard token/soft token (as possession factors) One time password to be deprecated 14 Mar 2020 Authentication Method - Open Banking Channel (APP)?
N/A The Bank does not offer a mobile banking app Authentication Method - Private Channel (Browser)?
AISP: Username + Password (as knowledge factors) + PIN (as knowledge factor) + hard token/soft token (as possession factors)
PISP: Username + Password (as knowledge factors) + PIN (as knowledge factor) + hard token/soft token (as possession factors) One time password to be deprecated 14 Mar 2020 Authentication Method - Private Channel (APP)?
N/A The Bank does not offer a mobile banking app Authentication Method Implementation Date (Open Banking Channel)?
14 Mar 2020 One time password to be deprecated 14 Mar 2020 Authentication Method Implementation Date (Private Channel)?
14 Mar 2020 One time password to be deprecated 14 Mar 2020 SCA Implementation Date?
14 Mar 2020 SCA Scope? (will it inhibit non PSD2 accounts)
Applicable for all payment account holders with Customer Channel (Online Banking) access. No
Major Milestones Testing interface Open Banking API standard v3.0 13 Mar 2019 Wide usage interface Open Banking API Standard v3.0 13 Mar 2019 Stress testing (Open Banking API standard v3.0) 30 Jun 2019 Open Banking API standard v3.1.1 29 Feb 2020 Infrastructure upgrade 29 Feb 2020
eIDAS 29 Feb 2020
Brand(s)
PaneltitleColor Black borderStyle dashed title ASPSP Dev Portal and Contact Details
PaneltitleColor Black borderStyle dashed title Key Implementations
Page Properties
High Cost Credit
TBC Implemented 30 Nov 2019
Page PropertiesAfter Waiver 7 Expiry (16/06/20) option supported: Option 1 - The parameter b64 being set to FALSE OR Option 2 - The b64 claim not being in the header
Option 1 - The parameter b64 being set to FALSE