PSD2 challenges
for open API
Economy
Goran Angelov
CEO, IBS Bulgaria
IBM Platinum BP
Experts in Power,
Storage & Cloud
Integration
Specialists in
30M
Turnover in
2018
Team
of 80+
Establishe
d in 2003
Who we are?
14.03.2019
SANDBOX
14.09.2019
Productio
n
7 Days to Sandbox
6m & 7days to Production
PSD2 – key milestones
• Key milestones for
PSD2 Open API Portals:
–14.03.2019 Sandbox portals
with fully functional test
environment and official
API’s
–14.09.2019 Fully functional
productive API portals
* Bank has to provide notification to TPP at
PSD2 Open API Portals
• API Catalog
• PSD2 API’s
documentation +
code snippets,
and example
operations
• Register TPP App
(get client secret)
• Sign-up for API
with API Plan
(free for PSD2)
• Test you App
• Promote to
Production
Explore https://developer.dskbank.bg
Get manual:
https://developer.dskbank.bg/download/file/fid/29
Intelligent
Counter
Fraud and
SCA
SLA and
fallback
mechanism
TPP
Register
and TPP
certificates
(eIDAS)
Custome
r
Consent
s
manage
ment
PSD2 Challenges and specifics
API
Standards
and local
specifics
Consent
Management for
PSD2
• Onboarding in TPP App requires
customer electronic consent
• Bank should be able to check the
validity of the electronic consent
for each particular transaction
• Bank has to provide the end user
with the opportunity to manage his
electronic consents
OAUTH2 with Redirection
This will be the most popular
process for customer
onboarding and SCA
procedure.
Public Register
Every PSD2 service provider and
bank is authorized in their home
country by the financial
supervisory competent authority to
provide services listed in the PSD2
directive.
Information about this is published
in the public registry and this
registry is the main source of
information.
• Certificates
• Qualified Certificates supporting PSD2
will include information about the
authorization number of the Payment
Service Provider, its home country’s
supervisory competent authority and
its roles
TPP Certification and
Identification
*yet to come in production
Open Banking APIs need
standards
However, there are always local
specifics!
• Provides end-point for all
interactions and AAA
security
• Provides back-end bank
services orchestration
• Provides API Portal, API
Management, API
Policies and Analytics
IBM Integration portfolio
9
+90% of banks in Bulgaria will use IBM
Integration Portfolio for PSD2 infrastructure either
on-premise, either As-a-Service or mixed
AAA Security
- Authentication
- Authorization
- Audit
• All outbound/inbound services
pass through DataPower - for
security and governance
IBM DataPower Gateway
Advanced security appliance
PSD2 requires Intelligent
Counter fraud solution in order
to allow payments under €500
to be secured using transaction
risk analysis without SCA.
Managing payment security for
PSD2 has implications for
consumers who are using
banking and card services to
make payments.
Payment service providers that
don’t manage the customer
communications process well
could lose customers as a
result.
• Intelligent Counter Fraud
• Third generation counter fraud
management which uses interactive
machine learning from past data and
applies behavior based models.
• Should be applied for all transaction
channels in order to get unified
customer experience
Intelligent Counter Fraud
Best of both worlds – use any
open source and any vendor
machine learning and artificial
intelligence platform/product
– without the drawbacks
A specific function provides
training and verification data
for “external” model training
just as it does for the
“internal” model training
The scoring models can be
used in any combination of
other model components
using the virtual simulation
“sandboxes”
• The most open data science platform
for payment fraud prevention in the
marketplace
• Secure by design – The only PCI DSS
compliant solution. PCI PA-DSS
certified (annually) – currently PCI
PA-DSS standard 3.2 on RHEL
IBM Safer Payments
Under PSD2, banks will be
required to put in place a so-
called “fallback mechanism”,
which Third Party Providers
(TPPs) can rely on if
dedicated interfaces are
unavailable for more than 30
seconds for 5 consecutive
requests, or
if they did not meet the
general operational
requirements set out in
the RTS.
• Such a fallback mechanism will
consist of opening up the ASPSP’s
user-facing interface as a secure
communication channel for
payment initiation and account
information services
• However:
• - this does not exclude digital
consent from customer
• - this does not exclude
identification and authorization of
the TPP
SLA and fallback interface
PSD2 API Applications
- to explore
- test
- collaborate
• Swagger API according to Berlin
Group NextGenPSD2 X2A standard
and local standard BISTRA
PSD2 Open API Portal from
IBS
Visit:
https://developer.ibs.bg/psd2/
Simulated test
environment
• TPP Test Application
• Test eIDAS TPP certificates
• Test SCA application
• Fully functional SandBox
with simulated real
operations
Q&A
Goran Angelov
CEO
IBS Bulgaria
Mobile: +359 888 237178
g.angelov@ibs.bg
https://www.linkedin.com/in/goranangelov/
M A K I N G Y O U R D A Y
IBS Bulgaria I ibs.bg
2019

More Related Content

PDF
Holos psd2 open-api
PDF
Get Strong Customer Authentication Ready for PSD2
PDF
Sibos 2016 - Access to Account
PPTX
PSD2 and 3DS2. The impact.
PDF
corp_pymt_whitepaper
PDF
PSD2: Making it actionable
PDF
Psd2 in a nutshell
PPTX
Collaboration between financial institutions and startups after introduction ...
Holos psd2 open-api
Get Strong Customer Authentication Ready for PSD2
Sibos 2016 - Access to Account
PSD2 and 3DS2. The impact.
corp_pymt_whitepaper
PSD2: Making it actionable
Psd2 in a nutshell
Collaboration between financial institutions and startups after introduction ...

What's hot (19)

PPTX
Webinar: Technology Insights - PSD2
PPTX
PSD2: The Advent of the New Payments Market in Europe
PDF
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
PPTX
PSD2 Building Certainty : Payments Knowledge Forum 2015
PPTX
Commodity to Ecosystem - Supporting customer lifestyles beyond banking
PPTX
Open Banking MeetUp_A. Sirtaine_PulseConsult_210909
PDF
EPA PSD2 Presentation 23 February 2016
PPTX
Open Banking MeetUp_P.Lambrechts_OkiOki_210909
PDF
Overview of the UK Open Banking Initiative
PDF
PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...
PDF
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PDF
Payveris_Whitepaper The Case for API in Retail Banking
PDF
Digital banking and its benefits
PDF
CORE banking, a black box explained
PPTX
Open Banking MeetUp_M.Lainez_Ibanity_210909
PPTX
Seamless Customer Onboarding using Digital KYC
PDF
An API Model for Open Banking Eco-Systems
PDF
Digital Money, from a regulatory point of view
PPTX
Time to-market starts with you
Webinar: Technology Insights - PSD2
PSD2: The Advent of the New Payments Market in Europe
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
PSD2 Building Certainty : Payments Knowledge Forum 2015
Commodity to Ecosystem - Supporting customer lifestyles beyond banking
Open Banking MeetUp_A. Sirtaine_PulseConsult_210909
EPA PSD2 Presentation 23 February 2016
Open Banking MeetUp_P.Lambrechts_OkiOki_210909
Overview of the UK Open Banking Initiative
PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
Payveris_Whitepaper The Case for API in Retail Banking
Digital banking and its benefits
CORE banking, a black box explained
Open Banking MeetUp_M.Lainez_Ibanity_210909
Seamless Customer Onboarding using Digital KYC
An API Model for Open Banking Eco-Systems
Digital Money, from a regulatory point of view
Time to-market starts with you
Ad

Similar to Psd2 challenges (20)

PDF
To swipe or not to swipe payment card processing in sap
PPTX
Encap security
PDF
NTGapps DTB Platform.pdf
PPTX
PSD2 & Open Banking: How to go from standards to implementation and compliance
PDF
Open Banking via API Connect & DataPower
PDF
Event-Driven Transformation in Banking and FSI
PPTX
Confluent_Banking_Usecases_Examples.pptx
PDF
Apidays Paris 2023 - Accelerating and Securing Transversal Processes Automati...
PDF
IBM Z for the Digital Enterprise 2018 - Z Keynote
PPTX
Open Banking via APIc 2018
PDF
An Entry Point to Impactful Open Banking Architecture
PDF
PSD2 & Open Banking
PDF
How to Choose Right PCI SAQ for Your Business.pdf
PDF
What’s New With WSO2 Open Banking?
PPTX
VTT RobotDay 5.9. Harri Kuusela: DIH² ja L4MS hankkeiden tuki yrityksille
PDF
WSO2 Open Banking: Digital Transformation Through PSD2
PPTX
IBM API Connect Deployment `Good Practices - IBM Think 2018
PPTX
PCI DSS and Other Related Updates
PPTX
Dynamic Rule-based Real-time Market Data Alerts
PDF
FORFIRM - THE FUTURE, DELIVERED!
To swipe or not to swipe payment card processing in sap
Encap security
NTGapps DTB Platform.pdf
PSD2 & Open Banking: How to go from standards to implementation and compliance
Open Banking via API Connect & DataPower
Event-Driven Transformation in Banking and FSI
Confluent_Banking_Usecases_Examples.pptx
Apidays Paris 2023 - Accelerating and Securing Transversal Processes Automati...
IBM Z for the Digital Enterprise 2018 - Z Keynote
Open Banking via APIc 2018
An Entry Point to Impactful Open Banking Architecture
PSD2 & Open Banking
How to Choose Right PCI SAQ for Your Business.pdf
What’s New With WSO2 Open Banking?
VTT RobotDay 5.9. Harri Kuusela: DIH² ja L4MS hankkeiden tuki yrityksille
WSO2 Open Banking: Digital Transformation Through PSD2
IBM API Connect Deployment `Good Practices - IBM Think 2018
PCI DSS and Other Related Updates
Dynamic Rule-based Real-time Market Data Alerts
FORFIRM - THE FUTURE, DELIVERED!
Ad

Recently uploaded (20)

PDF
Buy Verified Stripe Accounts for Sale - Secure and.pdf
PPTX
Very useful ppt for your banking assignments Banking.pptx
PPTX
28 - relative valuation lecture economicsnotes
PDF
Pension Trustee Training (1).pdf From Salih Shah
PPT
CompanionAsset_9780128146378_Chapter04.ppt
PDF
DTC TRADIND CLUB MAKE YOUR TRADING BETTER
PPTX
Module5_Session1 (mlzrkfbbbbbbbbbbbz1).pptx
PPTX
PROFITS AND GAINS OF BUSINESS OR PROFESSION 2024.pptx
PDF
Fintech Regulatory Sandbox: Lessons Learned and Future Prospects
PDF
3CMT J.AFABLE Flexible-Learning ENTREPRENEURIAL MANAGEMENT.pdf
PDF
2012_The dark side of valuation a jedi guide to valuing difficult to value co...
PDF
Best Accounting Outsourcing Companies in The USA
PPTX
Q1 PE AND HEALTH 5 WEEK 5 DAY 1 powerpoint template
PPTX
Group Presentation Development Econ and Envi..pptx
PDF
The Right Social Media Strategy Can Transform Your Business
PDF
HCWM AND HAI FOR BHCM STUDENTS(1).Pdf and ptts
PDF
Principal of magaement is good fundamentals in economics
PDF
2018_Simulating Hedge Fund Strategies Generalising Fund Performance Presentat...
PDF
Buy Verified Payoneer Accounts for Sale - Secure and.pdf
DOCX
BUSINESS PERFORMANCE SITUATION AND PERFORMANCE EVALUATION OF FELIX HOTEL IN H...
Buy Verified Stripe Accounts for Sale - Secure and.pdf
Very useful ppt for your banking assignments Banking.pptx
28 - relative valuation lecture economicsnotes
Pension Trustee Training (1).pdf From Salih Shah
CompanionAsset_9780128146378_Chapter04.ppt
DTC TRADIND CLUB MAKE YOUR TRADING BETTER
Module5_Session1 (mlzrkfbbbbbbbbbbbz1).pptx
PROFITS AND GAINS OF BUSINESS OR PROFESSION 2024.pptx
Fintech Regulatory Sandbox: Lessons Learned and Future Prospects
3CMT J.AFABLE Flexible-Learning ENTREPRENEURIAL MANAGEMENT.pdf
2012_The dark side of valuation a jedi guide to valuing difficult to value co...
Best Accounting Outsourcing Companies in The USA
Q1 PE AND HEALTH 5 WEEK 5 DAY 1 powerpoint template
Group Presentation Development Econ and Envi..pptx
The Right Social Media Strategy Can Transform Your Business
HCWM AND HAI FOR BHCM STUDENTS(1).Pdf and ptts
Principal of magaement is good fundamentals in economics
2018_Simulating Hedge Fund Strategies Generalising Fund Performance Presentat...
Buy Verified Payoneer Accounts for Sale - Secure and.pdf
BUSINESS PERFORMANCE SITUATION AND PERFORMANCE EVALUATION OF FELIX HOTEL IN H...

Psd2 challenges

  • 1. PSD2 challenges for open API Economy Goran Angelov CEO, IBS Bulgaria
  • 2. IBM Platinum BP Experts in Power, Storage & Cloud Integration Specialists in 30M Turnover in 2018 Team of 80+ Establishe d in 2003 Who we are?
  • 3. 14.03.2019 SANDBOX 14.09.2019 Productio n 7 Days to Sandbox 6m & 7days to Production PSD2 – key milestones • Key milestones for PSD2 Open API Portals: –14.03.2019 Sandbox portals with fully functional test environment and official API’s –14.09.2019 Fully functional productive API portals * Bank has to provide notification to TPP at
  • 4. PSD2 Open API Portals • API Catalog • PSD2 API’s documentation + code snippets, and example operations • Register TPP App (get client secret) • Sign-up for API with API Plan (free for PSD2) • Test you App • Promote to Production Explore https://developer.dskbank.bg Get manual: https://developer.dskbank.bg/download/file/fid/29
  • 5. Intelligent Counter Fraud and SCA SLA and fallback mechanism TPP Register and TPP certificates (eIDAS) Custome r Consent s manage ment PSD2 Challenges and specifics API Standards and local specifics
  • 6. Consent Management for PSD2 • Onboarding in TPP App requires customer electronic consent • Bank should be able to check the validity of the electronic consent for each particular transaction • Bank has to provide the end user with the opportunity to manage his electronic consents OAUTH2 with Redirection This will be the most popular process for customer onboarding and SCA procedure.
  • 7. Public Register Every PSD2 service provider and bank is authorized in their home country by the financial supervisory competent authority to provide services listed in the PSD2 directive. Information about this is published in the public registry and this registry is the main source of information. • Certificates • Qualified Certificates supporting PSD2 will include information about the authorization number of the Payment Service Provider, its home country’s supervisory competent authority and its roles TPP Certification and Identification *yet to come in production
  • 8. Open Banking APIs need standards However, there are always local specifics!
  • 9. • Provides end-point for all interactions and AAA security • Provides back-end bank services orchestration • Provides API Portal, API Management, API Policies and Analytics IBM Integration portfolio 9 +90% of banks in Bulgaria will use IBM Integration Portfolio for PSD2 infrastructure either on-premise, either As-a-Service or mixed
  • 10. AAA Security - Authentication - Authorization - Audit • All outbound/inbound services pass through DataPower - for security and governance IBM DataPower Gateway Advanced security appliance
  • 11. PSD2 requires Intelligent Counter fraud solution in order to allow payments under €500 to be secured using transaction risk analysis without SCA. Managing payment security for PSD2 has implications for consumers who are using banking and card services to make payments. Payment service providers that don’t manage the customer communications process well could lose customers as a result. • Intelligent Counter Fraud • Third generation counter fraud management which uses interactive machine learning from past data and applies behavior based models. • Should be applied for all transaction channels in order to get unified customer experience Intelligent Counter Fraud
  • 12. Best of both worlds – use any open source and any vendor machine learning and artificial intelligence platform/product – without the drawbacks A specific function provides training and verification data for “external” model training just as it does for the “internal” model training The scoring models can be used in any combination of other model components using the virtual simulation “sandboxes” • The most open data science platform for payment fraud prevention in the marketplace • Secure by design – The only PCI DSS compliant solution. PCI PA-DSS certified (annually) – currently PCI PA-DSS standard 3.2 on RHEL IBM Safer Payments
  • 13. Under PSD2, banks will be required to put in place a so- called “fallback mechanism”, which Third Party Providers (TPPs) can rely on if dedicated interfaces are unavailable for more than 30 seconds for 5 consecutive requests, or if they did not meet the general operational requirements set out in the RTS. • Such a fallback mechanism will consist of opening up the ASPSP’s user-facing interface as a secure communication channel for payment initiation and account information services • However: • - this does not exclude digital consent from customer • - this does not exclude identification and authorization of the TPP SLA and fallback interface
  • 14. PSD2 API Applications - to explore - test - collaborate • Swagger API according to Berlin Group NextGenPSD2 X2A standard and local standard BISTRA PSD2 Open API Portal from IBS Visit: https://developer.ibs.bg/psd2/
  • 15. Simulated test environment • TPP Test Application • Test eIDAS TPP certificates • Test SCA application • Fully functional SandBox with simulated real operations
  • 16. Q&A Goran Angelov CEO IBS Bulgaria Mobile: +359 888 237178 g.angelov@ibs.bg https://www.linkedin.com/in/goranangelov/
  • 17. M A K I N G Y O U R D A Y IBS Bulgaria I ibs.bg 2019