Bank of Ireland (UK) Plc

Bank of Ireland (UK) Plc

OB Standards

This Section applies to ASPSPs that have implemented OB Standards

have 

-Have you Implemented OB Standards?

  • Yes
  • No


Open Data - Which version have you Implemented?

  • None
  • V2.2
  • V2.3
  • V2.4


Read/Write API Specification Implemented or planning to implement

(Lowest version = Current, Highest version = Planned)

  • V3.0
  • V3.1
  • V3.1.1
  • V3.1.2
  • V3.1.3
  • V3.1.4
  • V3.1.5
  • V3.1.6
  • V3.1.7
  • V3.1.8
  • V3.1.9
  • V3.1.10
  • V3.1.11
  • V4.0

v.3.0 endpoints are no longer available.

v.3.1.8. AIS, PIS and CBPII endpoints are now available. v.3.1.10 endpoints are available for VRP only.

BOI intends to make v.4.0 endpoints available, but there is no date for when this will be implemented.

Read/Write API - Which date are you planning to implement your latest version?

N/A

There are no further updates in plan, although future releases will support further functionality. See Milestones, below.

Have you implemented v4.0 information flows, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 


Dynamic Client Registration - Which version have you Implemented or planning to implement?

(Lowest version = Current, Highest version = Planned)

  • None
  • V3.1
  • V3.2
  • V3.3

Open Banking has modified the SSA parameters with version datatype from decimal to string (TDA decision 247). BOI is currently working to deliver the changes in line with the OB change. Until that time TPPs will be unable to onboard using string datatype. 


DCR - Which date are you planning to implement your latest version?

N/A


Have you implemented Trusted beneficiaries, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 

BOI uses this exemption to facilitate VRP sweeping, but have no plans to implement Trusted Beneficiaries for other payment types. This exemption is not used in the bank's online channels.

Have you implemented Reverse Payments, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 


Have you implemented ECA Standard?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 


ECA Implementation details

N/A


Have you implemented Bulk/File Payments?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 


Have you implemented VRP – Sweeping, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 


Have you implemented VRP non-Sweeping, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 


PISP - Single Payment Limit

£20,000

PSUs using their 365 online profile are able to set their own payment limit up to the £20,000 daily limit. This limit applies across 365 online payments and Open Banking payments using a 365 profile.

PISP - Daily Payment Limit

£20,000

PSUs using their 365 online profile are able to set their own payment limit up to the £20,000 daily limit. This limit applies across 365 online payments and Open Banking payments using a 365 profile.

How many months of transaction do you provide?

12

As per the BOI online channels, BOI provides 12 months of transaction history for PCA and BCA accounts, and the current statement cycle for Credit Cards.

Have you implemented TRIs (Transactional Risk Indicators), if not, date planned to Implement?

There are no plans to implement TRIs at this stage.


What is your approach to Implementing TRIs?

  • Accept payload with TRI fields – Process all fields
  • Accept payload with TRI fields – Ignore all fields
  • Reject payload with TRI fields – Error back to TPP
  • Accept payload with TRI fields – Process few fields (Provide list of accepted fields)  

N/A

SCA-RTS 90-day reauth Implementation

Which date are you planning on implementing the SCA reauthentication exemption?

1 October 2022


What is your approach to token management to enable application of the reauthentication exemption? (see link to FCA guidance)

Issue a long-lived refresh token during one final SCA. (BOI UK only).


From the date of the change, all refresh tokens issued at initial consent and access refresh will be long-lived, and not require re-authentication 90 days later. In practice, this means that after 1 October, the first time any PSU needs to refresh access (and had last performed SCA prior to the date) will need to re-authenticate one more time. Any PSU providing initial consent (and SCA) after 8 October will never be asked to re-authenticate with BOI.

NB. For Bank of Ireland ROI: BOI will implement the change under the Commission Delegated Regulation amending RTS with regards to the 90-day exemption for account access to 180 days tonight and the change will be effective from tomorrow morning 26th July.

Article 10A - Endpoints exempt of SCA-RTS

  • Accounts
  • Transactions (90days)
  • Balances
  • Standing orders
  • Direct debits
  • Beneficiaries
  • Products
  • Offers
  • Parties
  • Scheduled Payments
  • Statements


Article 10A - Endpoints not exempt of SCA-RTS

  • Transactions (more than 90days)
  • Standing orders
  • Direct debits
  • Beneficiaries
  • Products
  • Offers
  • Parties
  • Scheduled Payments
  • Statements


Article 10A - Maximum time period after authentication

Long-lived

Please specify the time period in minutes

SCA-RTS implementation status (updated by OBL PS team only)

IMPLEMENTED

Planned / In-progress / Implemented / TBC

Security Profile


-Which Security profile have you Implemented or planning to implement?

(Lowest version = Current, Highest version = Planned)

  • OB Security Profile (Legacy)
  • FAPI (ID2)
  • FAPI 1 Advanced
  • Other (Please define) 

BOI is now live with FAPI 1 Advanced. TPPs must align with the FAPI 1 Advanced standards.

Security Profile - Next Planned Version Implementation Date

TBC


CIBA Profile - Implemented or planning to implement

(Lowest version = Current, Highest version = Planned)

  • None
  • CIBA
  • CIBA FAPI Profile


CIBA Profile - Next Planned Version Implementation Date

 N/A


Security Profile Certification date?

 N/A


Token Endpoint Authentication Methods Supported

  • client_secret_post
  • client_secret_basic
  • client_secret_jwt
  • tls_client_auth
  • Private_key_jwt


Planned date to Cease support for client id and client secret token endpoint authentication

 


POST-BREXIT POST TRANSITION - Certificates Accepted (from 1st Jul 2021)

  • eIDAS QWAC
  • eIDAS QSealC
  • OB legacy (obtransport, obsigning)
  • OBWAC
  • OBSeal
  • Other (Please define) 

Important Info:

  1. In all cases, BOI (ROI) only accepts eIDAS certificates.

  2. eIDAS QSealC, OBSeal and OB legacy signing are only used for the purposes of message signing.

  3. TPPs who only have OB legacy certificates registered with BOI may be blocked to align with the FCA guidance. If a TPP originally used OB legacy certificates, and did not migrate to OBWAC or OBSeal prior to 1 July 2021, they are advised to contact BOI through the developer portal to ensure they are unblocked. 



Customer Journey

-What is your approach to Implementing OBL Customer Experience Guidelines (CEG)?

(tick all that apply)

  • Already Implemented
  • Planning to implement or upgrade
  • Not planning to implement CEG


Which version have you implemented or planning to implement?

(Lowest version = Current, Highest version = Planned)

  • V3.1.2
  • V3.1.3
  • V3.1.4
  • V3.1.5
  • V3.1.6
  • V3.1.7
  • V3.1.8
  • V3.1.9
  • V3.1.10
  • V3.1.11
  • V4.0


Which date are you planning to implement your latest CEG version?

TBC

BOI will support the latest CEG for existing endpoints or any new endpoints implemented.

Redirection Model

  • App to App redirection
  • Decoupled authentication
  • Embedded Flow
  • Bespoke User Journeys


PSD2

-Which Directory are you using as your Trust Framework?

Open Banking


Are you caching the Directory?

No


Transaction IDs Supported

Yes - for AIS Current Accounts

  • A unique identifier will be generated based on a set of immutable fields

  • A unique identifier will be provided for every transaction for the account types supported, with the below exception

    • Transaction identifier will not be returned for consumer credit cards.

Are you Seeking Fallback Exemption?

  • Yes
  • No


Article 10 - Maximum time period after authentication

90 days


Article 10 - Endpoints exempt of SCA

Exemption will cover all AISP resources.


Major Milestones


There are no major milestones incoming.


Brand(s)

Bank of Ireland UK

Bank of Ireland (Republic of Ireland)


ASPSP Dev Portal and Contact Details

Location of Well Known Endpoints


Modified Customer Interface URL (if applicable)

N/A


Dev Portal URL

https://developer.bankofireland.com


Test Facility URL

https://developer.bankofireland.com

Go to the Developer Portal (Getting Started page) for well-known and authorisation URLs for the test facility.

Brand Landing Pages URL


[You can use this space to explain your guidance on using Brand logos]

ASPSP Support Desk Email or Phone Number

(including queries about consent success rates) 

https://www.bankofireland.com/api/developer/contact/?developer=developer

Submit all queries through the contact form. This will ensure tickets are raised, can be tracked, and queries are assigned to the correct area.

Key Implementations

Common Error Scenarios

High Cost Credit

BOI - HCC.xlsx