The Role of IAM in Open Banking
&
Where Do We Stand?
Colombo IAM User Group - 2nd Meetup
Pushpalanka Jayawardhana
Financial Solutions Team - WSO2
“Banking is necessary; banks are not”
- (Bill Gates, 1990)
International Financial Industry
Concerns
➢Contribute to a more integrated and
efficient European payments market
➢Improve the level playing field for PSPs
(including new players)
➢Make payments safer and more secure
➢Online shopping without a credit card
➢Better protection against fraud
➢Help lower charges for consumers on
card payments
Ref : https://www.pcisecuritystandards.org/pdfs/webinar_100519pci_pts_3.0.pdf
Payment Card Industry Security Standards
For protection of cardholder payment data,
Payment Services Directive 2
EU Directive that applies to
all Banks operating in the EU
that regulates payment
services throughout the EU,
with a compliance deadline of
January 2018
Open Banking
1 : Possible central view
Banks expose their customer payment and account data, with customer consent, to
Third party Payment Providers (TPPs) via APIs.
TPP
PISP/AISP
Bank A
Bank B
Bank C
Merchant
Now PSD2
Bank A
Bank B
Bank C
Merchant
Open Banking
2 : No Involvement of Card Network
7
➢ Less hops
➢ Lower fees for transactions
➢ Easy to track the path
Aggregated View of Accounts (AISP
Flow)
Payment Flow (PISP)
Credits to Dinosoft Labs from Noun Project
Checkout
Item
Login Page
2 Factor Authentication
Customer Consent
Initiation
payment info
1
2
3
4
PISP
302
5
Token 6
Payment
Complete
7
Settlement
PSD2 Compliance Requirements
➢ API Specification
○ API Definitions
○ Secured API invocation
○ API Usage Monitoring
➢ Strong Customer Authentication
○ 2 Factor Authentication (SMSOTP, FIDO, Duo, MePin)
○ Adaptive Authentication
○ Consent Management
➢ Incident Reporting
○ Security Incident Reporting [Transactions affected,server downtime, Economic
Strong Customer Authentication
Ref : https://cdn-images-1.medium.com/max/1200/1*cqJ3MUF-vOG9IVTLOOQQTQ.gif
Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks
Strong Customer Authentication Ctd..
Adaptive Authentication
➢ Authentication flow is defined by risk level
➢ PSD2 define several exemptions for SCA applications
○ Not to kill user experience for small transactions and bulk transactions
➢ Security level can be decided based on,
○ The amount of transaction
○ Time elapsed from previous SCA
○ Transaction patterns on user
○ Role of user - Cooperate or private
Consent Management
➢ Defined by PSD2 RTS on SCA and secure communication and GDPR
➢ Safeguard right of the user on personal data to,
○ be informed - Inform user of personal data collection
○ access - Validate information processing at any time
○ rectification - When user feels data is incomplete or accurate
○ restrict data processing - Just store, don’t process
○ data portability - Transfer data to another party
○ forgotten - Request removal of personal data
○ be notified on a data breach - Report to user within 72 hours
No Screen Scraping
Technology Requirements
“Draft Regulatory Technical Standards, explicitly mentions to be based on
known standards”
● User authentication (with SSO)
○ SAML 2.0
○ OpenID Connect
● Access delegation - OAuth 2.0
● Fine grained authorization - XACML
● Multifactor authentication - SMSOTP, FIDO, DUO, MePin
16
Ref : https://www.abe-eba.eu/downloads/knowledge-and-research/EBA_May2016_eAPWG_Understanding_the_business_relevance_of_Open_APIs_and_Open_Banking_for_banks.pdf
Other Standards
ISO 27001 - for information security management systems
ISO20022 - remove ambiguity in messages relevant to payments, securities, FX, Trade services & Cards
Inside Story - Open Banking
DEMO
With https://openbanking.wso2.com/
Open Banking: The opportunities
Bank A
Bank B
Bank C
Merchant Bank A
Consolidated
customer account and
payment info across
multiple Banks
TPPTPP
App Development
Ref : Deutsche Bank Global Transaction Banking - Payment Services Directive 2
1. One-leg Out – in EEA currency: EEA currency sent from the EEA to a non-EEA country
e.g. EUR payment from France to Sri Lanka
1. One-leg Out – in non-EEA currency: Non-EEA currency sent from the EEA to a non-EEA country
e.g. LKR payment from UK to Sri Lanka
1. One-leg in – in EEA currency: EEA currency payment sent from a non-EEA country to an EEA country
e.g. EUR payment from Sri Lanka to France
1. One-leg in – in non-EEA currency: Non-EEA currency sent from a non-EEA country to an EEA country
e.g. LKR payment from Sri Lanka to UK
PSD2 Impact
on Us
Banking Industry in Sri Lanka
➢ Sri Lanka Interbank Payment System (SLIPS)
○ Same day electronic fund transfer
○ Established in 2010, being first in South Asia
➢ LankaPay Common Electronic Fund Transfer Switch (CEFTS)
○ For real-time payments
○ Initiated in 2015
➢ JustPay - From LankaClear (pvt) Ltd
○ Applies 2FA
○ For real time retail payments under Rs. 10 000/=
○ Central Bank of Sri Lanka (CBSL) approved security standards
➢ Have already thought on AISP like applications
➢ Have the foundation of collaboration among banks in real time
JustPay© - http://www.lankaclear.com/product_service/42-overview
Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks
Monetization of applications will be made
easy...
Q & A
Twitter : @Pushpalanka
LinkedIn : https://www.linkedin.com/in/pushpalanka/
WSO2 Open Banking : https://openbanking.wso2.com/
Thank You!

More Related Content

PPTX
The Top 5 Apache Kafka Use Cases and Architectures in 2022
PDF
Kafka and Machine Learning in Banking and Insurance Industry
PDF
BigchainDB - Big Data meets Blockchain
PPSX
Elastic-Engineering
PDF
Looking towards an official cassandra sidecar netflix
PDF
Cyber threat intelligence ppt
PDF
The Five Pillars of Customer Identity and Access Management (CIAM)
PPSX
Zero-Trust SASE DevSecOps
The Top 5 Apache Kafka Use Cases and Architectures in 2022
Kafka and Machine Learning in Banking and Insurance Industry
BigchainDB - Big Data meets Blockchain
Elastic-Engineering
Looking towards an official cassandra sidecar netflix
Cyber threat intelligence ppt
The Five Pillars of Customer Identity and Access Management (CIAM)
Zero-Trust SASE DevSecOps

What's hot (20)

PPTX
CLOUD NATIVE SECURITY
PDF
Cassandra at Instagram 2016 (Dikang Gu, Facebook) | Cassandra Summit 2016
PPTX
Splunk Overview
PDF
Massive Data Processing in Adobe Using Delta Lake
PPTX
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
PPTX
cyber-security-reference-architecture
PPTX
Async API and Solace: Enabling the Event-Driven Future
PPTX
Splunk Architecture overview
PPSX
Service Mesh - Observability
PDF
Real-Time Recommendations with Hopsworks and OpenSearch - MLOps World 2022
PPTX
Transparent Encryption in HDFS
PDF
Introducing ELK
PPSX
Domain Driven Design
PDF
Improve Developer Experience with Developer Portal
PPT
Devops at Netflix (re:Invent)
PDF
Running Apache NiFi with Apache Spark : Integration Options
PPTX
Understanding the Cyber Security Vendor Landscape
PDF
Splunk 101
PPTX
Threat Hunting - Moving from the ad hoc to the formal
PDF
Introducing Saga Pattern in Microservices with Spring Statemachine
CLOUD NATIVE SECURITY
Cassandra at Instagram 2016 (Dikang Gu, Facebook) | Cassandra Summit 2016
Splunk Overview
Massive Data Processing in Adobe Using Delta Lake
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
cyber-security-reference-architecture
Async API and Solace: Enabling the Event-Driven Future
Splunk Architecture overview
Service Mesh - Observability
Real-Time Recommendations with Hopsworks and OpenSearch - MLOps World 2022
Transparent Encryption in HDFS
Introducing ELK
Domain Driven Design
Improve Developer Experience with Developer Portal
Devops at Netflix (re:Invent)
Running Apache NiFi with Apache Spark : Integration Options
Understanding the Cyber Security Vendor Landscape
Splunk 101
Threat Hunting - Moving from the ad hoc to the formal
Introducing Saga Pattern in Microservices with Spring Statemachine
Ad

Similar to The role of IAM in OpenBanking and where do we stand (20)

PDF
An Introduction to Open Banking (PSD2)
PDF
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
PPTX
PSD2: The Advent of the New Payments Market in Europe
PDF
DFS22_Main Stage_Laurent Bailly_Visa_041022
PPTX
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
PPTX
Fintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
PPTX
Boot Camp PSD II – Third Party Access To Accounts
PDF
WSO2 Open Banking: Digital Transformation Through PSD2
PPTX
Beyond Money: The Role of Digital Currencies in Financial Inclusion
PDF
Go Beyond PSD2 Compliance with Digital Identity
PDF
Getting your API Management Strategy on Point for PSD2 Compliance
PDF
Cryptocurrencies and AML
PDF
Risk Beyond Acquiring: Merchant Risk Across FinTech
PDF
Master class Fintech
PDF
Psd2 brochure
PDF
(FinPort) TrueLayer deck - Connect Ventures 2016
PDF
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PDF
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
PPTX
The Digital Reserve Pitch Deck v5
PPTX
Finance Presentation
An Introduction to Open Banking (PSD2)
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
PSD2: The Advent of the New Payments Market in Europe
DFS22_Main Stage_Laurent Bailly_Visa_041022
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Fintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
Boot Camp PSD II – Third Party Access To Accounts
WSO2 Open Banking: Digital Transformation Through PSD2
Beyond Money: The Role of Digital Currencies in Financial Inclusion
Go Beyond PSD2 Compliance with Digital Identity
Getting your API Management Strategy on Point for PSD2 Compliance
Cryptocurrencies and AML
Risk Beyond Acquiring: Merchant Risk Across FinTech
Master class Fintech
Psd2 brochure
(FinPort) TrueLayer deck - Connect Ventures 2016
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
The Digital Reserve Pitch Deck v5
Finance Presentation
Ad

More from Pushpalanka Jayawardhana (11)

PDF
Authorization for workloads in a dynamically scaling heterogeneous system
PDF
Frictionless Adaption of PSD2 with WSO2
PDF
Identity mediation for enterprise identity bus
PDF
Threads and Concurrency Identifying Performance Deviations in Thread Pools
PDF
Approximate Protocol for Privacy Preserving Associate Rule Mining
PDF
Leveraging federation capabilities of identity server for api gateway
PPTX
Feedback queuing models for time shared systems
PPTX
Big Data CDR Analyzer - Kanthaka
PDF
Kanthaka - High Volume CDR Analyzer
PDF
Experience at WSO2 as an Intern
PPTX
Cosmology in general
Authorization for workloads in a dynamically scaling heterogeneous system
Frictionless Adaption of PSD2 with WSO2
Identity mediation for enterprise identity bus
Threads and Concurrency Identifying Performance Deviations in Thread Pools
Approximate Protocol for Privacy Preserving Associate Rule Mining
Leveraging federation capabilities of identity server for api gateway
Feedback queuing models for time shared systems
Big Data CDR Analyzer - Kanthaka
Kanthaka - High Volume CDR Analyzer
Experience at WSO2 as an Intern
Cosmology in general

Recently uploaded (20)

PPT
Conventional Financial Instruments 1.ppt
PDF
GVCParticipation_Automation_Climate_India
PPTX
Module5_Session1 (mlzrkfbbbbbbbbbbbz1).pptx
PPTX
Rise of Globalization...................
PPT
Project_finance_introduction in finance.ppt
PPTX
The Impact of Remote Work on Employee Productivity
PPTX
Q1 PE AND HEALTH 5 WEEK 5 DAY 1 powerpoint template
PPTX
balanced_and_unbalanced_growth_theory_ppt.pptx
PPTX
ANALYZE MARKET DEMAND, MARKET SUPPLY AND MARKET.pptx
PDF
Financial discipline for educational purpose
PPTX
Maths science sst hindi english cucumber
PDF
Lundin Gold - August 2025.pdf presentation
PDF
3CMT J.AFABLE Flexible-Learning ENTREPRENEURIAL MANAGEMENT.pdf
PPTX
28 - relative valuation lecture economicsnotes
PDF
Chapterrrrrrrrrrrrrrrrrrrrrrrrr 2_AP.pdf
PPTX
INDIAN FINANCIAL SYSTEM (Financial institutions, Financial Markets & Services)
PPTX
Machine Learning (ML) is a branch of Artificial Intelligence (AI)
DOCX
BUSINESS PERFORMANCE SITUATION AND PERFORMANCE EVALUATION OF FELIX HOTEL IN H...
PDF
In July, the Business Activity Recovery Index Worsened Again - IER Survey
PPT
CompanionAsset_9780128146378_Chapter04.ppt
Conventional Financial Instruments 1.ppt
GVCParticipation_Automation_Climate_India
Module5_Session1 (mlzrkfbbbbbbbbbbbz1).pptx
Rise of Globalization...................
Project_finance_introduction in finance.ppt
The Impact of Remote Work on Employee Productivity
Q1 PE AND HEALTH 5 WEEK 5 DAY 1 powerpoint template
balanced_and_unbalanced_growth_theory_ppt.pptx
ANALYZE MARKET DEMAND, MARKET SUPPLY AND MARKET.pptx
Financial discipline for educational purpose
Maths science sst hindi english cucumber
Lundin Gold - August 2025.pdf presentation
3CMT J.AFABLE Flexible-Learning ENTREPRENEURIAL MANAGEMENT.pdf
28 - relative valuation lecture economicsnotes
Chapterrrrrrrrrrrrrrrrrrrrrrrrr 2_AP.pdf
INDIAN FINANCIAL SYSTEM (Financial institutions, Financial Markets & Services)
Machine Learning (ML) is a branch of Artificial Intelligence (AI)
BUSINESS PERFORMANCE SITUATION AND PERFORMANCE EVALUATION OF FELIX HOTEL IN H...
In July, the Business Activity Recovery Index Worsened Again - IER Survey
CompanionAsset_9780128146378_Chapter04.ppt

The role of IAM in OpenBanking and where do we stand

  • 1. The Role of IAM in Open Banking & Where Do We Stand? Colombo IAM User Group - 2nd Meetup Pushpalanka Jayawardhana Financial Solutions Team - WSO2
  • 2. “Banking is necessary; banks are not” - (Bill Gates, 1990)
  • 3. International Financial Industry Concerns ➢Contribute to a more integrated and efficient European payments market ➢Improve the level playing field for PSPs (including new players) ➢Make payments safer and more secure ➢Online shopping without a credit card ➢Better protection against fraud ➢Help lower charges for consumers on card payments
  • 4. Ref : https://www.pcisecuritystandards.org/pdfs/webinar_100519pci_pts_3.0.pdf Payment Card Industry Security Standards For protection of cardholder payment data,
  • 5. Payment Services Directive 2 EU Directive that applies to all Banks operating in the EU that regulates payment services throughout the EU, with a compliance deadline of January 2018
  • 6. Open Banking 1 : Possible central view Banks expose their customer payment and account data, with customer consent, to Third party Payment Providers (TPPs) via APIs. TPP PISP/AISP Bank A Bank B Bank C Merchant Now PSD2 Bank A Bank B Bank C Merchant
  • 7. Open Banking 2 : No Involvement of Card Network 7 ➢ Less hops ➢ Lower fees for transactions ➢ Easy to track the path
  • 8. Aggregated View of Accounts (AISP Flow)
  • 9. Payment Flow (PISP) Credits to Dinosoft Labs from Noun Project Checkout Item Login Page 2 Factor Authentication Customer Consent Initiation payment info 1 2 3 4 PISP 302 5 Token 6 Payment Complete 7 Settlement
  • 10. PSD2 Compliance Requirements ➢ API Specification ○ API Definitions ○ Secured API invocation ○ API Usage Monitoring ➢ Strong Customer Authentication ○ 2 Factor Authentication (SMSOTP, FIDO, Duo, MePin) ○ Adaptive Authentication ○ Consent Management ➢ Incident Reporting ○ Security Incident Reporting [Transactions affected,server downtime, Economic
  • 11. Strong Customer Authentication Ref : https://cdn-images-1.medium.com/max/1200/1*cqJ3MUF-vOG9IVTLOOQQTQ.gif
  • 12. Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks Strong Customer Authentication Ctd..
  • 13. Adaptive Authentication ➢ Authentication flow is defined by risk level ➢ PSD2 define several exemptions for SCA applications ○ Not to kill user experience for small transactions and bulk transactions ➢ Security level can be decided based on, ○ The amount of transaction ○ Time elapsed from previous SCA ○ Transaction patterns on user ○ Role of user - Cooperate or private
  • 14. Consent Management ➢ Defined by PSD2 RTS on SCA and secure communication and GDPR ➢ Safeguard right of the user on personal data to, ○ be informed - Inform user of personal data collection ○ access - Validate information processing at any time ○ rectification - When user feels data is incomplete or accurate ○ restrict data processing - Just store, don’t process ○ data portability - Transfer data to another party ○ forgotten - Request removal of personal data ○ be notified on a data breach - Report to user within 72 hours
  • 16. Technology Requirements “Draft Regulatory Technical Standards, explicitly mentions to be based on known standards” ● User authentication (with SSO) ○ SAML 2.0 ○ OpenID Connect ● Access delegation - OAuth 2.0 ● Fine grained authorization - XACML ● Multifactor authentication - SMSOTP, FIDO, DUO, MePin 16
  • 17. Ref : https://www.abe-eba.eu/downloads/knowledge-and-research/EBA_May2016_eAPWG_Understanding_the_business_relevance_of_Open_APIs_and_Open_Banking_for_banks.pdf Other Standards ISO 27001 - for information security management systems ISO20022 - remove ambiguity in messages relevant to payments, securities, FX, Trade services & Cards
  • 18. Inside Story - Open Banking
  • 20. Open Banking: The opportunities Bank A Bank B Bank C Merchant Bank A Consolidated customer account and payment info across multiple Banks TPPTPP
  • 22. Ref : Deutsche Bank Global Transaction Banking - Payment Services Directive 2 1. One-leg Out – in EEA currency: EEA currency sent from the EEA to a non-EEA country e.g. EUR payment from France to Sri Lanka 1. One-leg Out – in non-EEA currency: Non-EEA currency sent from the EEA to a non-EEA country e.g. LKR payment from UK to Sri Lanka 1. One-leg in – in EEA currency: EEA currency payment sent from a non-EEA country to an EEA country e.g. EUR payment from Sri Lanka to France 1. One-leg in – in non-EEA currency: Non-EEA currency sent from a non-EEA country to an EEA country e.g. LKR payment from Sri Lanka to UK PSD2 Impact on Us
  • 23. Banking Industry in Sri Lanka ➢ Sri Lanka Interbank Payment System (SLIPS) ○ Same day electronic fund transfer ○ Established in 2010, being first in South Asia ➢ LankaPay Common Electronic Fund Transfer Switch (CEFTS) ○ For real-time payments ○ Initiated in 2015 ➢ JustPay - From LankaClear (pvt) Ltd ○ Applies 2FA ○ For real time retail payments under Rs. 10 000/= ○ Central Bank of Sri Lanka (CBSL) approved security standards ➢ Have already thought on AISP like applications ➢ Have the foundation of collaboration among banks in real time JustPay© - http://www.lankaclear.com/product_service/42-overview
  • 24. Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks
  • 25. Monetization of applications will be made easy...
  • 26. Q & A Twitter : @Pushpalanka LinkedIn : https://www.linkedin.com/in/pushpalanka/ WSO2 Open Banking : https://openbanking.wso2.com/

Editor's Notes

  • #5: PTS DSS - PIN Transaction Security Data Security Standard
  • #7: Open Banking is due to become a regulation in Australia (similar to the enforcement of PSD2 regulation in the EU). Therefore, Banks need to be able to securely expose sensitive data through APIs so that third party providers can build new applications that provide a much better user experience to multi-banked customers.
  • #11: Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  • #12: Upto 80% of attacks are based on stolen user credentials… One proof from ancient stories Ali baba and 40 thieves.
  • #13: Behavioral factors such as walking style, typing are also considered now as another factor
  • #14: Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  • #15: Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  • #21: Exposing APIs can seem to commoditize banks by threatening to take away the sole ownership of customer data that banks so far enjoyed exculsively. However, Banks armed with the correct vision and the technology to achieve that can reap much more benefits from this open banking world. Survey conducted in UK by Accenture showed that consumers prefer Banks to be the ones to provide the 3rd party services as well. If and when Banks can take up that role, they become a rich repository of customer data across multiple banks. They can then use that repository to… Provide better services to their customers (eg:- cashflow management across banks) Provide ‘Insight Sales’ to other businesses. (-> attract new revenue streams)
  • #24: Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  • #25: Core banking solution, Customer Integrated System, usually has • SWIFT terminals • ATM and POS solutions • MICR checks handler • Phone banking (IVR)