Version 4
Date
Version
4
Change Description
The changes to this version of the calendar are:
- Clarification around 'documentation of the contingency measures' from the EBA API WG 5th set of clarifications published 14 Aug 2019 and
- Clarification on ASPSPs implementation of RTS Article 10 SCA Exemption
- Revision of the 'FAPI Compliant' question in order to provide greater clarity to TPPs. The 'FAPI Compliant' question has been replaced by 'Security Profile' and 'Security Profile Certification'.
Below is an extract from the EBA Working Group. For the full set of questions and clarifications, please see eba.europa.eu/-/eba-publishes-clarifications-to-the-fifth-set-of-issues-raised-by-its-working-group-on-apis-under-psd2?doAsGroupId=10180
EBA responses to issues XXI to XXVI raised by participants of the EBA Working Group on APIs under PSD2
Published on 14 August 2019
Disclaimer: The information contained in the table below is of an informational nature and has no binding force in law. Only the Court of Justice of the European Union can provide definitive
interpretations of EU legislation. The information may factually reflect a given challenge faced by the industry, reiterate the European Banking Authority’s views that have been previously
published, reflect discussions that have been held on the practical implementation of legal requirements, or may include examples of industry practices. The information is also without prejudice
to any future decisions made or views expressed by the European Banking Authority.
ID | Topic | Description | EBA Response |
---|---|---|---|
XXV | Documentation of the contingency mechanism in Art. 33(4) RTS | Several API-WG participants requested clarifications whether ASPSPs are TPPs expressed concerns that many ASPSPs have not yet documented how the | Article 33(1) RTS provides that “Account servicing payment service providers shall include, in the design of the dedicated interface, a strategy and plans for contingency measures for the event that the interface does not perform in compliance with Article 32, that there is unplanned unavailability of the interface and that there is a systems breakdown”.
|
Article 10
RTS Article 10
RTS Article 10 states:
1. Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2 and to paragraph 2 of this Article and, where a payment service user is limited to accessing either or both of the following items online without disclosure of sensitive payment data:
(a) the balance of one or more designated payment accounts;
(b) the payment transactions executed in the last 90 days through one or more designated payment accounts.
2. For the purpose of paragraph 1, payment service providers shall not be exempted from the application of strong customer authentication where either of the following condition is met:
(a) the payment service user is accessing online the information specified in paragraph 1 for the first time;
(b) more than 90 days have elapsed since the last time the payment service user accessed online the information specified in paragraph 1(b) and strong customer authentication was applied.
Please is /wiki/spaces/DZ/pages/1009778990 for further clarification
Questionnaire Section | Question | Q&A |
---|---|---|
PSD2 | Contingency Measures | Please specify the location of the guidance that explains your strategy and plans for when your dedicated interface is unavailable. This should be a URL to your dev portal or artefact that provides TPPs with the information they require. |
PSD2 | Maximum time period after authentication? (Article 10) | Please specify how long the AISP has from the time when they receive the access token (after PSU authentication). This is the period the AISP must submit their first request before SCA will be re-applied to endpoints NOT exempt of SCA under Article 10. ASPSPs should consider that this timeline is consistent with the time limit applied by the ASPSP in the existing online PSU interface (i.e. before the PSU is logged out) Please specify the time period. (For example, 1 hour) |
PSD2 | Endpoints exempt of SCA under Article 10 | Please specify which AIS endpoints will be exempt from SCA under Article 10. (delete as appropriate): Accounts, Balances, Transactions, Beneficiaries, Direct Debits, Standing Orders, Products, Offers, Parties, Scheduled Payments, Statements |
Implementation | Question removed. | |
Implementation | Security Profile? | Please specify where you support the Open Banking Security Profile or OIDC. Please respond 'Open Banking', 'FAPI' or 'Other'. |
Implementation | Security Profile Certification? | Please specify where you have achieved certification with the Security Profile authority. Please respond, 'Yes' or 'No'. |
Questionnaire