Bank of Ireland (UK) Plc

OB Standards

This Section applies to ASPSPs that have implemented OB Standards

have 

-Have you Implemented OB Standards?
  • Yes
  • No

Open Data - Which version have you Implemented?
  • None
  • V2.2
  • V2.3
  • V2.4

Read/Write API Specification Implemented or planning to implement

(Lowest version = Current, Highest version = Planned)

  • V3.0
  • V3.1
  • V3.1.1
  • V3.1.2
  • V3.1.3
  • V3.1.4
  • V3.1.5
  • V3.1.6
  • V3.1.7
  • V3.1.8
  • V3.1.9
  • V3.1.10
  • V3.1.11
  • V4.0

v.3.0 endpoints are no longer available.

v.3.1.8. AIS, PIS and CBPII endpoints are now available. v.3.1.10 endpoints are available for VRP only.

BOI intends to make v.4.0 endpoints available, but there is no date for when this will be implemented.

Read/Write API - Which date are you planning to implement your latest version?N/AThere are no further updates in plan, although future releases will support further functionality. See Milestones, below.

Have you implemented v4.0 information flows, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 

Dynamic Client Registration - Which version have you Implemented or planning to implement?

(Lowest version = Current, Highest version = Planned)

  • None
  • V3.1
  • V3.2
  • V3.3

Open Banking has modified the SSA parameters with version datatype from decimal to string (TDA decision 247). BOI is currently working to deliver the changes in line with the OB change. Until that time TPPs will be unable to onboard using string datatype. 


DCR - Which date are you planning to implement your latest version?N/A

Have you implemented Trusted beneficiaries, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 
We plan to use this exemption to facilitate VRP sweeping, but have no plans to implement Trusted Beneficiaries for other payment types. This exemption is not used in the bank's online channels.

Have you implemented Reverse Payments, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 

Have you implemented ECA Standard?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 

ECA Implementation details

N/A


Have you implemented Bulk/File Payments?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 

Have you implemented VRP – Sweeping, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 

Have you implemented VRP non-Sweeping, if not date planned to Implement?

  • Already Implemented
  • Planning to implement
  • Not planning to implement 


PISP - Single Payment Limit£20,000PSUs using their 365 online profile are able to set their own payment limit up to the £20,000 daily limit. This limit applies across 365 online payments and Open Banking payments using a 365 profile.
PISP - Daily Payment Limit£20,000PSUs using their 365 online profile are able to set their own payment limit up to the £20,000 daily limit. This limit applies across 365 online payments and Open Banking payments using a 365 profile.
How many months of transaction do you provide?12As per the BOI online channels, BOI provides 12 months of transaction history for PCA and BCA accounts, and the current statement cycle for Credit Cards.
Have you implemented TRIs (Transactional Risk Indicators), if not, date planned to Implement?There are no plans to implement TRIs at this stage.
What is your approach to Implementing TRIs?
  • Accept payload with TRI fields – Process all fields
  • Accept payload with TRI fields – Ignore all fields
  • Reject payload with TRI fields – Error back to TPP
  • Accept payload with TRI fields – Process few fields (Provide list of accepted fields)  
N/A
SCA-RTS 90-day reauth Implementation

Which date are you planning on implementing the SCA reauthentication exemption?

1 October 2022

What is your approach to token management to enable application of the reauthentication exemption? (see link to FCA guidance)

Issue a long-lived refresh token during one final SCA. (BOI UK only).


From the date of the change, all refresh tokens issued at initial consent and access refresh will be long-lived, and not require re-authentication 90 days later. In practice, this means that after 1 October, the first time any PSU needs to refresh access (and had last performed SCA prior to the date) will need to re-authenticate one more time. Any PSU providing initial consent (and SCA) after 8 October will never be asked to re-authenticate with BOI.

NB. For Bank of Ireland ROI: BOI will implement the change under the Commission Delegated Regulation amending RTS with regards to the 90-day exemption for account access to 180 days tonight and the change will be effective from tomorrow morning 26th July.

Article 10A - Endpoints exempt of SCA-RTS
  • Accounts

  • Transactions (90days)

  • Balances

  • Standing orders

  • Direct debits

  • Beneficiaries

  • Products

  • Offers

  • Parties

  • Scheduled Payments

  • Statements


Article 10A - Endpoints not exempt of SCA-RTS
  • Transactions (more than 90days)

  • Standing orders

  • Direct debits

  • Beneficiaries

  • Products

  • Offers

  • Parties

  • Scheduled Payments

  • Statements


Article 10A - Maximum time period after authenticationLong-livedPlease specify the time period in minutes
SCA-RTS implementation status (updated by OBL PS team only)

IMPLEMENTED

Planned / In-progress / Implemented / TBC
Security Profile


-Which Security profile have you Implemented or planning to implement?

(Lowest version = Current, Highest version = Planned)

  • OB Security Profile (Legacy)
  • FAPI (ID2)
  • FAPI 1 Advanced
  • Other (Please define) 
BOI intends to implement FAPI 1 Advanced, but there is no date for when this change will be implemented.
Security Profile - Next Planned Version Implementation DateTBC
CIBA Profile - Implemented or planning to implement

(Lowest version = Current, Highest version = Planned)

  • None
  • CIBA
  • CIBA FAPI Profile

CIBA Profile - Next Planned Version Implementation Date
 N/A

Security Profile Certification date?
 N/A

Token Endpoint Authentication Methods Supported
  • client_secret_post
  • client_secret_basic
  • client_secret_jwt
  • tls_client_auth
  • Private_key_jwt

Planned date to Cease support for client id and client secret token endpoint authentication 


POST-BREXIT POST TRANSITION - Certificates Accepted (from 1st Jul 2021)
  • eIDAS QWAC
  • eIDAS QSealC
  • OB legacy (obtransport, obsigning)
  • OBWAC
  • OBSeal
  • Other (Please define) 

Important Info:

  1. In all cases, BOI (ROI) only accepts eIDAS certificates.
  2. eIDAS QSealC, OBSeal and OB legacy signing are only used for the purposes of message signing.
  3. TPPs who only have OB legacy certificates registered with BOI may be blocked to align with the FCA guidance. If a TPP originally used OB legacy certificates, and did not migrate to OBWAC or OBSeal prior to 1 July 2021, they are advised to contact BOI through the developer portal to ensure they are unblocked. 


Customer Journey

-What is your approach to Implementing OBL Customer Experience Guidelines (CEG)?

(tick all that apply)

  • Already Implemented
  • Planning to implement or upgrade
  • Not planning to implement CEG

Which version have you implemented or planning to implement?

(Lowest version = Current, Highest version = Planned)

  • V3.1.2
  • V3.1.3
  • V3.1.4
  • V3.1.5
  • V3.1.6
  • V3.1.7
  • V3.1.8
  • V3.1.9
  • V3.1.10
  • V3.1.11
  • V4.0

Which date are you planning to implement your latest CEG version?TBCBOI will support the latest CEG for existing endpoints or any new endpoints implemented.
Redirection Model
  • App to App redirection
  • Decoupled authentication
  • Embedded Flow
  • Bespoke User Journeys

PSD2
-Which Directory are you using as your Trust Framework?Open Banking
Are you caching the Directory?No
Transaction IDs SupportedYes - for AIS Current Accounts
  • A unique identifier will be generated based on a set of immutable fields
  • A unique identifier will be provided for every transaction for the account types supported, with the below exception
    • Transaction identifier will not be returned for consumer credit cards.

Are you Seeking Fallback Exemption?

  • Yes
  • No


Article 10 - Maximum time period after authentication90 days
Article 10 - Endpoints exempt of SCA

Exemption will cover all AISP resources.


Major Milestones


There are no major milestones incoming.


Brand(s)

Bank of Ireland UK

Bank of Ireland (Republic of Ireland)


ASPSP Dev Portal and Contact Details

Location of Well Known Endpoints


Modified Customer Interface URL (if applicable)

N/A
Dev Portal URLhttps://developer.bankofireland.com
Test Facility URLhttps://developer.bankofireland.comGo to the Developer Portal (Getting Started page) for well-known and authorisation URLs for the test facility.
Brand Landing Pages URL
[You can use this space to explain your guidance on using Brand logos]

ASPSP Support Desk Email or Phone Number

(including queries about consent success rates) 

https://www.bankofireland.com/api/developer/contact/?developer=developerSubmit all queries through the contact form. This will ensure tickets are raised, can be tracked, and queries are assigned to the correct area.
Key Implementations
Common Error Scenarios

High Cost Credit

BOI - HCC.xlsx