Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Production

details
Panel
titleColorBlack
borderStyledashed
titleOBIE OB Standards Calendar

This Section applies to ASPSPs that have implemented OB Standards


Method (delete as appropriate):

  • Existing PSU interface, but with header signed using signing cert
  • Adapted (clone) version of a PSU interface, with TLS secured using transport cert
    Page Properties
    iconfalse
    id9Standards-Production

    ASPSP

    AIB
    Notes
    Implement Open Data v2.2N/AImplement Read/Write API Specification v3.1 Implement Customer Experience Guidelines v1.1 Implement App-to-App Redirection Implement OB Security Profile Implementer's Draft v1.1.2N/AImplement FAPI Profile Implementers Draft 2 Implement CIBA Profile Implementers Draft 1N/AImplement Dynamic Client Registration v1.1N/AImplement Dynamic Client Registration v3.1TBCDecommission Read/Write API Specification v1.x/2.xTBC
    Decommission OB Security Profile Implementer's Draft v1.xN/AAIB supports v1.1.0
    Article 10 SCA Exemption (for 90 days)Resources covered (delete as appropriate): Accounts, Balances, Transactions, Beneficiaries, Direct Debits, Standing Orders, Products, Offers, Parties, Scheduled Payments, StatementsContingency Mechanism (if applicable)
    TC-OB Standards
    titleTC-OB Standards


    -Have you Implemented OB Standards?
    •  Yes
    •  No

    Open Data - Which version have you Implemented?
    •  None
    •  V2.2
    •  V2.3
    •  V2.4

    Read/Write API Specification Implemented or planning to implement

    (Lowest version = Current, Highest version = Planned)

    •  V3.0
    •  V3.1
    •  V3.1.1
    •  V3.1.2
    •  V3.1.3
    •  V3.1.4
    •  V3.1.5
    •  V3.1.6
    •  V3.1.7
    •  V3.1.8
    •  V3.1.9
    •  V3.1.10
    •  V3.1.11
    •  V4.0

    Read/Write API - Which date are you planning to implement your latest version?

    Have you implemented v4.0 information flows, if not date planned to Implement?

    •  Already Implemented
    •  Planning to implement
    •  Not planning to implement 

    Dynamic Client Registration - Which version have you Implemented or planning to implement?

    (Lowest version = Current, Highest version = Planned)

    •  None
    •  V3.1
    •  V3.2
    •  V3.3

    DCR - Which date are you planning to implement your latest version?

    Have you implemented Trusted beneficiaries, if not date planned to Implement?

    •  Already Implemented
    •  Planning to implement
    •  Not planning to implement 

    Have you implemented Reverse Payments, if not date planned to Implement?

    •  Already Implemented
    •  Planning to implement
    •  Not planning to implement 

    Have you implemented ECA Standard?

    •  Already Implemented
    •  Planning to implement
    •  Not planning to implement 

    ECA Implementation details


    Contact: [enter contact details for the relevant person(s) at your organisation]

    [You can use this space to provide your status with respect to the Standard]

    Have you implemented Bulk/File Payments?

    •  Already Implemented
    •  Planning to implement
    •  Not planning to implement 

    Have you implemented VRP – Sweeping, if not date planned to Implement?

    •  Already Implemented
    •  Planning to implement
    •  Not planning to implement 

    Have you implemented VRP non-Sweeping, if not date planned to Implement?

    •  Already Implemented
    •  Planning to implement
    •  Not planning to implement 

    Contact: [enter contact details for the relevant person(s) at your organisation]

    [You can use this space to provide implementation details relevant to VRP]
    PISP - Single Payment Limit£
    PISP - Daily Payment Limit£
    How many months of transaction do you provide?

    Have you implemented TRIs (Transactional Risk Indicators), if not, date planned to Implement?

    What is your approach to Implementing TRIs?
    •  Accept payload with TRI fields – Process all fields
    •  Accept payload with TRI fields – Ignore all fields
    •  Reject payload with TRI fields – Error back to TPP
    •  Accept payload with TRI fields – Process few fields (Provide list of accepted fields)  




    Panel
    borderStyledashed
    titleSCA-RTS 90-day reauth Implementation


    Page Properties
    idSCA-RTS


    Which date are you planning on implementing the SCA reauthentication exemption?


    30/09/2022 

    What is your approach to token management to enable application of the reauthentication exemption? (see link to FCA guidance)


    Issue a long-lived refresh token during one final SCA

    Article 10A - Endpoints exempt of SCA-RTS
    •  

      Accounts

    •  

      Transactions (90days)

    •  

      Balances

    •  

      Standing orders

    •  

      Direct debits

    •  

      Beneficiaries

    •  

      Products

    •  

      Offers

    •  

      Parties

    •  

      Scheduled Payments

    •  

      Statements


    Article 10A - Endpoints not exempt of SCA-RTS
    •  

      Transactions (more than 90days)

    •  

      Standing orders

    •  

      Direct debits

    •  

      Beneficiaries

    •  

      Products

    •  

      Offers

    •  

      Parties

    •  

      Scheduled Payments

    •  

      Statements


    Article 10A - Maximum time period after authentication
    Please specify the time period in minutes
    SCA-RTS implementation status (updated by OBL PS team only)

    Status
    colourGreen
    titleImplemented





    Production
    Panel
    titleColorBlack
    borderStyledashed
    titleMethod of Identification Calendar
    Security Profile


    Page Properties
    id9IDID-Production


    ASPSP

    AIB
    Notes
    Commence support for eIDAS QWAC certificates Commence support for eIDAS QSEAL certificates
      

    Commence support for OBIE QWAC-like certificates

    N/ACommence support for OBIE QSEAL-like certificates Cease support for OBIE non eIDAS-like certificates for transport Cease support for OBIE non eIDAS-like certificates for signing Support for MTLS token endpoint authenticationN/ASupport for private_key_jwt token endpoint authentication

     

    -Which Security profile have you Implemented or planning to implement?

    (Lowest version = Current, Highest version = Planned)

    •  OB Security Profile (Legacy)
    •  FAPI (ID2)
    •  FAPI 1 Advanced
    •  Other (Please define) 

    Security Profile - Next Planned Version Implementation Date



    CIBA Profile - Implemented or planning to implement

    (Lowest version = Current, Highest version = Planned)

    •  None
    •  CIBA
    •  CIBA FAPI Profile

    CIBA Profile - Next Planned Version Implementation Date
     

    Security Profile Certification date?



    Token Endpoint Authentication Methods Supported
    •  
      client_secret_post
    •  
      client_secret_basic
    •  
      client_secret_jwt
    •  
      tls_client_auth
    •  Private_key_jwt

    Planned date to Cease support for client id and client secret token endpoint authentication 
    POST-BREXIT POST TRANSITION - Certificates Accepted (from 1st Jul 2021)
    •  eIDAS QWAC
    •  eIDAS QSealC
    •  OB legacy (obtransport, obsigning)
    •  OBWAC
    •  OBSeal
    •  Other (Please define) 
    TBC




    IMPYes, JWKS for TPP’s and the EC trusted list  for eIDAS QTSP’s
    Panel
    titleColorBlack
    borderStyledashed
    titleCustomer Journey


    Page Properties
    idTC-

    Directory?

    Open Banking

    Location of Well Known Endpoints?

    OB Technical Directory and Dev Portal

    API Standard Implemented?

    Open Banking

    Name of Account Holder Implementation Date?

    Supported identification method?

    QWAC / QSeal

    Major Milestones

    N/A

    FAPI Compliant?

    Yes

    CIBA

    N/AUsing Open Banking as your eIDAS Trust Framework?
    CJ


    -What is your approach to Implementing OBL Customer Experience Guidelines (CEG)?

    (tick all that apply)

    •  Already Implemented
    •  Planning to implement or upgrade
    •  Not planning to implement CEG

    Which version have you implemented or planning to implement?

    (Lowest version = Current, Highest version = Planned)

    •  V3.1.2
    •  V3.1.3
    •  V3.1.4
    •  V3.1.5
    •  V3.1.6
    •  V3.1.7
    •  V3.1.8
    •  V3.1.9
    •  V3.1.10
    •  V3.1.11
    •  V4.0

    Which date are you planning to implement your latest CEG version?TBC
    Redirection Model
    •  App to App redirection
    •  Decoupled authentication
    •  Embedded Flow
    •  Bespoke User Journeys




    Implementing Bespoke User Journeys?

    No
    Panel
    titleColorBlack
    borderStyledashed
    titlePSD2


    Page Properties
    idTC-PSD2


    -Which Directory are you using as your Trust Framework?Open Banking
    Are you caching the Directory?
    Yes
    Page Properties
    idTC-CJ

    Implementing Customer Experience Guidelines?

    Yes

    No

    Implementing App to App?

    YesApp to App Implementation Date? 

    Options on 90 day re-authentication?

    At log in after 90 days the customer will have to re-authenticate.

    Support Embedded Flow?



    Transaction IDs SupportedDate TBC - Option 4 Supported4. ASPSPs provide neither a TransactionID nor the method by which TPPs can generate on

    Are you Seeking Fallback Exemption?

    •  Yes
    •  No

    Allied Irish Bank (AIB) and First Trust Bank are exempt from the requirement to build a contingency mechanism for the “Retail API Channel”

    Article 10 - Maximum time period after authentication90 days
    Article 10 - Endpoints exempt of SCA

    Balances, Transactions

    (last 90 days only)


    Major Milestones

    Brand(s)




    PSD2PSD2
    Panel
    titleColorBlack
    borderStyledashed
    titleASPSP Dev Portal and Contact Details


    Page Properties
    idTC-

    Dispute Management System?

    Yes

    Seeking Fallback Exemption?

    Yes

    Adjusted or Fallback Interface?

    Test Facility Implementation Date?

     Production Interface Implementation Date? 

    Authentication Method - Open Banking Channel (Browser)?

    Authentication Method - Open Banking Channel (APP)?

    Authentication Method - Private Channel (Browser)?

    Authentication Method - Private Channel (APP)?

    Authentication Method Implementation Date (Open Banking Channel)?

    Authentication Method Implementation Date (Private Channel)?

    SCA Implementation Date?

    SCA Scope? (will it inhibit non PSD2 accounts)

    Expand
    title
    C


    Location of Well Known Endpoints

    OB Technical Directory and Dev Portal

    Modified Customer Interface URL (if applicable)



    Dev Portal URL

    https://developer.firsttrustbank.co.uk/ 

    https://developer.aibgb.co.uk/


    Test Facility URL

    Brand Landing Pages URL
    [You can use this space to explain your guidance on using Brand logos]

    ASPSP Support Desk Email or Phone Number

    (including queries about consent success rates) 

    api@aib.ie




    Panel
    titleColorBlack
    borderStyledashed
    titleKey Implementations


    Page Properties
    idTC-HCC


    High Cost Credit

    AIB - HCC.xlsx

    View file
    nameAIB - HCC.xlsx
    height250


    AIB Error Codes 

    View file
    nameAPI Gateway Error Codes 2021.xlsx
    height250