Implement OB Security Profile Implementer's Draft v1.1.2
Implement FAPI Profile Implementers Draft 2
Implement CIBA Profile Implementers Draft 1
N/A
Implement Dynamic Client Registration v1.1
Live
Implement Dynamic Client Registration v3.1
Decommission Read/Write API Specification v1.x/2.x
AIS v1.1
Planning to decommission v1 APIs will commence once v3.1 are live and we can work with TPPs to migrate onto a later version, date is draft at the moment.
Decommission OB Security Profile Implementer's Draft v1.x
Complete
Article 10 SCA Exemption (for 90 days)
Resources covered (delete as appropriate): Transactions & Statements
Method of Identification
Commence support for eIDAS QWAC certificates
Planning to support from November 2019
Commence support for eIDAS QSEAL certificates
Planning to support from November 2019
Commence support for OBIE QWAC-like certificates
Commence support for OBIE QSEAL-like certificates
Cease support for OBIE non eIDAS-like certificates for transport
Cease support for OBIE non eIDAS-like certificates for signing
Support for MTLS token endpoint authentication
TBC
Support for private_key_jwt token endpoint authentication
TBC
Cease support for client id and client secret token endpoint authentication
Implementation
Directory?
Open Banking
Location of Well Known Endpoints?
OB Technical Directory
API Standard Implemented?
Open Banking
Name of Account Holder Implementation Date?
14 June 2019 (single account holder)
November 2019 (multiples account holders)
Supported identification method?
Current view is OBWAC/OBSEAL via agency arrangement
Client Secret until Sep 2019, then MTLS as the token auth method
Major Milestones
V3.1 target date 14 June 2019
Offers endpoint target date 14 Sep 2019
(Inc Other Products, API Updates, API Deprecations, etc)
FAPI Compliant?
No
CIBA
No
Using Open Banking as your eIDAS Trust Framework?
Yes
Are you caching the Directory?
Yes
Transaction IDs
March 2019 - Option 1 Supported
ASPSPs provide a Unique, Immutable TransactionID from their core system
Customer Journey
Implementing Customer Experience Guidelines?
Yes
Implementing Bespoke User Journeys?
No
Implementing App to App?
Yes
App to App Implementation Date?
End March 2019
Options on 90 day re-authentication?
OBIE Standard until 13 September, then in line with A10 SCA RTS.
Support Embedded Flow?
No
PSD2
Dispute Management System?
Yes
FCA Adjustment Period - Maintaining Screen Scraping?