SlideShare a Scribd company logo
The Industry Standard for Consumer
Access to Financial Records
FDX API and Security Overview
Dinesh Katyal – 7/20/20
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Agenda
2
Organization Overview
The FDX API Portfolio
- FDX API 4.1
- Control Consideration for Consumer Financial Account Aggregation 3.1
- User Experience Guidelines – Account Information 1.0
- Use Cases
Q & A
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Mission
3
The Financial Data Exchange (FDX) mission is to promote and enhance a
common interoperable standard and operating framework to efficiently
and securely share consumer and business financial data.
FDX operates as an independent subsidiary of the Financial Services
Information Sharing and Analysis Center (FS-ISAC) and took up the work
of the FS-ISAC Aggregation Working Group.
FDX launched on 18 October 2018.
Financial Data Exchange (FDX) The current Board comprises 11 Financial Institutions, 5 Permissioned
Parties, 5 Aggregators, 2 Industry Groups & the FS-ISAC.
The Industry Standard for Consumer Access to Financial Records
Open Membership | ¼ of members are Fin-Tech firms | 2/3 are not banks | FDX is not a policy or lobbying group.
118 Member
Organizations
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
The Industry Standard for Consumer Access to Financial Records
FDX Technical Organization
Security &
Authentication
User
Experience
& Consent
API / Data
Structures
Qualification &
Certification
OFX
Working
Groups
Every Working Group, Committee and the Board are co-chaired by a Financial Institution and a Non-Financial Institution
Technology
Review
Committee
E2E
Encryption
Task
Forces
Cert Model Directory Tax Forms
Intermediary
ID
UX
Guidelines
Taxonomy
Money
Movement
FDX Staff
Director Product
+
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
FDX API
7
• Secure authentication
- Tokenized access to data
- No login credentials used/ held by aggregator/ apps
• Authorization and consent standard
- Owner approves what is shared, its use, and duration
- UX guidelines 1.0 will cover consent for account information services
• API specification
- Replaces screen scraping
- JSON/ REST
- Comprehensive coverage of account information services and tax forms (US)
- Free to access and royalty free to use
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Supported Accounts and Documents
■ Deposit: ■ Lines of Credit:
Checking (DDA) Credit Cards
Savings LOC (retail)
Money Market Accounts LOC (Commercial)
Time Deposits (CD) HELOC
Other Other
■ Loans: ■ Investments
Loans (Installment) IRA
Mortgages TAXABLE
Loans (Commercial) TRUST
Other Other
■ Insurance: ■ Annuities:
● Statements
● Tax Documents: US Tax Forms
● Images (receipts or check images)
The Industry Standard for Consumer Access to Financial Records
• FALL 2020 Release Timeline
• Sep 7 – RFC cutoff for release inclusion
• Sep 21:
• Spec 4.2 (tax ‘20) – 14-day member notice
• Spec 4.5 (non-tax RFCs) – WG notification
• Oct 5 (60 days prior) –
• Spec 4.2 (tax ‘20) - GA
• Spec 4.5 (non-tax RFCs) – 60-day member
notice
• Dec 3 – Spec 4.5 GA
Note: Tax and non-tax will be aligned from Fall 2021
onwards shifting general release schedule up by 2
months
Release Calendar
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Control Considerations
10
• Conceptual security architecture stack
- Federated user authentication interoperability with OpenID Connect 1.0
- Delegated user authorization using OAuth 2.0
- Specific user identification pattern using FIDO 1.2 UAF
• Communication;
- TLS for all communications
- NIST recommended encryption algorithms
- Recommended key lengths and host name verification enabled
• API Security Profile
- Normative references to FAPI part 1 – read only security profile
- FAPI part 2 – read-write security profile
OAuth 2.0
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Questions

More Related Content

PPTX
apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...
PDF
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
PDF
apidays New York 2022 - Discussing the significance of API standardization, D...
PPTX
Secrets of the Enterprise Buyers with Plaid's Global Finance Lead and Laika's...
PPTX
Finance Industry Innovations
PPTX
Data Fraud Analytics Industry
PPTX
TMT SA Presentation
PPT
PCI Compliance 101
apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays New York 2022 - Discussing the significance of API standardization, D...
Secrets of the Enterprise Buyers with Plaid's Global Finance Lead and Laika's...
Finance Industry Innovations
Data Fraud Analytics Industry
TMT SA Presentation
PCI Compliance 101

Similar to FDX API Overview (Dinesh).pdf (20)

PDF
Fintech Software Development: A Comprehensive Guide in 2024
PPTX
What is FinTech- Technology in Finance
PDF
Moving To MicroServices
PDF
CloudCamp Chicago April 2015 - Patrick Kerpan's talk "What Financial Cloud Sh...
PPT
Su10 ceo workshop_supporting slides
PDF
10 Steps To Secure and PCI Compliant Credit Card Processing In Oracle Receiva...
PDF
Unlocking Financial Data: An Introduction to the FIDA Framework
PPTX
Blockchain and the investment industry stack
PDF
ICUL Credit, Debit and Prepaid Services
PDF
Financial server blue print - Blueprints.pdf
PPT
David Whitaker: Managing Your Vendors
PDF
Banking Software
PDF
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
PDF
Fintech Cyber Security Survey Hong Knog 2018
PDF
Financial Services: A Comprehensive Guide
PPTX
IBM Cloud for Financial Services Overview
PPTX
FinTech
PDF
apidays LIVE London 2021 - Tech adoption in finance and banking by Christina ...
PPTX
Sgsits cyber securityworkshop_4mar2017
PDF
Collaborate and Build Solutions for the Bank and Fintech Industry.pdf
Fintech Software Development: A Comprehensive Guide in 2024
What is FinTech- Technology in Finance
Moving To MicroServices
CloudCamp Chicago April 2015 - Patrick Kerpan's talk "What Financial Cloud Sh...
Su10 ceo workshop_supporting slides
10 Steps To Secure and PCI Compliant Credit Card Processing In Oracle Receiva...
Unlocking Financial Data: An Introduction to the FIDA Framework
Blockchain and the investment industry stack
ICUL Credit, Debit and Prepaid Services
Financial server blue print - Blueprints.pdf
David Whitaker: Managing Your Vendors
Banking Software
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
Fintech Cyber Security Survey Hong Knog 2018
Financial Services: A Comprehensive Guide
IBM Cloud for Financial Services Overview
FinTech
apidays LIVE London 2021 - Tech adoption in finance and banking by Christina ...
Sgsits cyber securityworkshop_4mar2017
Collaborate and Build Solutions for the Bank and Fintech Industry.pdf
Ad

Recently uploaded (20)

PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
Hindi spoken digit analysis for native and non-native speakers
PPTX
Tartificialntelligence_presentation.pptx
PPTX
Chapter 5: Probability Theory and Statistics
PDF
A comparative analysis of optical character recognition models for extracting...
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
Hybrid model detection and classification of lung cancer
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
Encapsulation theory and applications.pdf
PDF
A novel scalable deep ensemble learning framework for big data classification...
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
A Presentation on Artificial Intelligence
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Programs and apps: productivity, graphics, security and other tools
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Hindi spoken digit analysis for native and non-native speakers
Tartificialntelligence_presentation.pptx
Chapter 5: Probability Theory and Statistics
A comparative analysis of optical character recognition models for extracting...
Heart disease approach using modified random forest and particle swarm optimi...
cloud_computing_Infrastucture_as_cloud_p
Hybrid model detection and classification of lung cancer
OMC Textile Division Presentation 2021.pptx
Encapsulation theory and applications.pdf
A novel scalable deep ensemble learning framework for big data classification...
SOPHOS-XG Firewall Administrator PPT.pptx
Enhancing emotion recognition model for a student engagement use case through...
Univ-Connecticut-ChatGPT-Presentaion.pdf
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
A Presentation on Artificial Intelligence
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Ad

FDX API Overview (Dinesh).pdf

  • 1. The Industry Standard for Consumer Access to Financial Records FDX API and Security Overview Dinesh Katyal – 7/20/20
  • 2. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Agenda 2 Organization Overview The FDX API Portfolio - FDX API 4.1 - Control Consideration for Consumer Financial Account Aggregation 3.1 - User Experience Guidelines – Account Information 1.0 - Use Cases Q & A
  • 3. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Mission 3 The Financial Data Exchange (FDX) mission is to promote and enhance a common interoperable standard and operating framework to efficiently and securely share consumer and business financial data. FDX operates as an independent subsidiary of the Financial Services Information Sharing and Analysis Center (FS-ISAC) and took up the work of the FS-ISAC Aggregation Working Group. FDX launched on 18 October 2018.
  • 4. Financial Data Exchange (FDX) The current Board comprises 11 Financial Institutions, 5 Permissioned Parties, 5 Aggregators, 2 Industry Groups & the FS-ISAC. The Industry Standard for Consumer Access to Financial Records Open Membership | ¼ of members are Fin-Tech firms | 2/3 are not banks | FDX is not a policy or lobbying group. 118 Member Organizations
  • 5. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved.
  • 6. The Industry Standard for Consumer Access to Financial Records FDX Technical Organization Security & Authentication User Experience & Consent API / Data Structures Qualification & Certification OFX Working Groups Every Working Group, Committee and the Board are co-chaired by a Financial Institution and a Non-Financial Institution Technology Review Committee E2E Encryption Task Forces Cert Model Directory Tax Forms Intermediary ID UX Guidelines Taxonomy Money Movement FDX Staff Director Product +
  • 7. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. FDX API 7 • Secure authentication - Tokenized access to data - No login credentials used/ held by aggregator/ apps • Authorization and consent standard - Owner approves what is shared, its use, and duration - UX guidelines 1.0 will cover consent for account information services • API specification - Replaces screen scraping - JSON/ REST - Comprehensive coverage of account information services and tax forms (US) - Free to access and royalty free to use
  • 8. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Supported Accounts and Documents ■ Deposit: ■ Lines of Credit: Checking (DDA) Credit Cards Savings LOC (retail) Money Market Accounts LOC (Commercial) Time Deposits (CD) HELOC Other Other ■ Loans: ■ Investments Loans (Installment) IRA Mortgages TAXABLE Loans (Commercial) TRUST Other Other ■ Insurance: ■ Annuities: ● Statements ● Tax Documents: US Tax Forms ● Images (receipts or check images)
  • 9. The Industry Standard for Consumer Access to Financial Records • FALL 2020 Release Timeline • Sep 7 – RFC cutoff for release inclusion • Sep 21: • Spec 4.2 (tax ‘20) – 14-day member notice • Spec 4.5 (non-tax RFCs) – WG notification • Oct 5 (60 days prior) – • Spec 4.2 (tax ‘20) - GA • Spec 4.5 (non-tax RFCs) – 60-day member notice • Dec 3 – Spec 4.5 GA Note: Tax and non-tax will be aligned from Fall 2021 onwards shifting general release schedule up by 2 months Release Calendar
  • 10. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Control Considerations 10 • Conceptual security architecture stack - Federated user authentication interoperability with OpenID Connect 1.0 - Delegated user authorization using OAuth 2.0 - Specific user identification pattern using FIDO 1.2 UAF • Communication; - TLS for all communications - NIST recommended encryption algorithms - Recommended key lengths and host name verification enabled • API Security Profile - Normative references to FAPI part 1 – read only security profile - FAPI part 2 – read-write security profile OAuth 2.0
  • 11. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Questions