POST-BREXIT Certificate Implementation Status (updated by OBIE IES team)
Implementation
Directory?
MCI
Location of Well Known Endpoints?
OB Technical Directory
API Standard Implemented?
Open Banking
Name of Account Holder Implementation Date?
TBC
Date of Current eIDAS Implementation?
eIDAS
Current Certificates used for Identification?
2021
Current Certificates used for Transport?
Current Certificates used for Signing?
Date of Future eIDAS Implementation?
No future update currently planned.
Future Certificates used for Identification?
Future Certificates used for Transport?
Future Certificates used for Signing?
Major Milestones
September 2019 – API delivered by Bank ABC development team to ABC International Bank ABC
October 2019 – Testing commences with 3rd party
Brand(s)
Security Profile?
Security Profile Certification?
CIBA
No
Using Open Banking as your eIDAS Trust Framework?
Yes
Are you caching the Directory?
No
Transaction IDs
Option 1
ASPSPs provide a Unique, Immutable TransactionID from their core system
ASPSPs generate a Unique TransactionID from a set of Immutable fields
ASPSPs specify field(s) for TPP to generate a Unique Transaction Identifier
ASPSPs provide neither a TransactionID nor the method by which TPPs can generate one
Customer Journey
Implementing Customer Experience Guidelines?
Yes
Current CEG Version?
Next CEG Version?
Next Version Implementation Date
Implementing Bespoke User Journeys?
No
Implementing App to App?
No
App to App Implementation Date?
N/A
Options on 90 day re-authentication?
90 Day Re-Authentication
After 90 days consent is considered expired. The customer will have to consent again by accessing via the TPP site and authenticating with ABC and selecting accounts
Support Embedded Flow?
No
When customer gives consent through the TPP site the Bank ABC login page (Auth0) is used to authenticate customer consent. The customer provides username, password and OTP during login. The system verifies credentials with the bank.
PSD2
Dispute Management System?
Yes
FCA Adjustment Period - Maintaining Screen Scraping?
Please specify the location of the guidance that explains your strategy and plans for when your dedicated interface is unavailable. This should be a URL to your dev portal or artefact that provides TPPs with the information they require
Article 10 - Maximum time period after authentication?
Please specify how long the AISP has from the time when they receive the access token (after PSU authentication). This is the period the AISP must submit their first request before SCA will be re-applied to endpoints NOT exempt of SCA under Article 10. ASPSPs should consider that this timeline is consistent with the time limit applied by the ASPSP in the existing online PSU interface (i.e. before the PSU is logged out)
Article 10 - Endpoints exempt of SCA
Please specify which AIS endpoints will be exempt from SCA under Article 10. (delete as appropriate): Accounts, Balances, Transactions, Beneficiaries, Direct Debits, Standing Orders, Products, Offers, Parties, Scheduled Payments, Statements
Authentication Method - Open Banking Channel (Browser)?
Username and Password, and two factor authentication provided by users soft token
Authentication Method - Open Banking Channel (APP)?