<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Trebuchet MS";
        panose-1:2 11 6 3 2 2 2 2 2 4;}
@font-face
        {font-family:"Open Sans";}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.hoenzb
        {mso-style-name:hoenzb;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style></head><body lang=EN-US link=blue vlink="#954F72"><div class=WordSection1><p class=MsoNormal>Does anyone have any info on the underlying protocols?</p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>thx ..tom</p><p class=MsoNormal><o:p> </o:p></p><div style='mso-element:para-border-div;border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal style='border:none;padding:0in'><b>From: </b><a href="mailto:BCostello@yodlee.com">Brian Costello</a><br><b>Sent: </b>Monday, June 12, 2017 12:16 PM<br><b>To: </b><a href="mailto:thomasclinganjones@gmail.com">Tom Jones</a>; <a href="mailto:openid-specs-fapi@lists.openid.net">Financial API Working Group List</a>; <a href="mailto:dave.tonge@momentumft.co.uk">Dave Tonge</a><br><b>Subject: </b>RE: [Openid-specs-fapi] EBA Regulatory Technical Standards</p></div><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Indeed.  This is the “upgrade” from ClearXchange, with Early Warning (bank owned) as the service provider.<span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p><p class=MsoNormal> <span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p><p class=MsoNormal><b>From:</b> Openid-specs-fapi [mailto:openid-specs-fapi-bounces@lists.openid.net] <b>On Behalf Of </b>Tom Jones via Openid-specs-fapi<br><b>Sent:</b> Monday, June 12, 2017 10:57 AM<br><b>To:</b> Dave Tonge <dave.tonge@momentumft.co.uk>; Financial API Working Group List <openid-specs-fapi@lists.openid.net><br><b>Subject:</b> Re: [Openid-specs-fapi] EBA Regulatory Technical Standards<span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p><div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'>looks like the US banks have build their own payment network.<o:p></o:p></span></p><div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'><a href="https://www.nytimes.com/2017/06/12/business/dealbook/mobile-banking-zelle-venmo-apple-pay.html?module=WatchingPortal&region=c-column-middle-span-region&pgType=Homepage&action=click&mediaId=thumb_square&state=standard&contentPlacement=4&version=internal&contentCollection=www.nytimes.com&contentId=https%3A%2F%2Fwww.nytimes.com%2F2017%2F06%2F12%2Fbusiness%2Fdealbook%2Fmobile-banking-zelle-venmo-apple-pay.html&eventName=Watching-article-click&_r=0">https://www.nytimes.com/2017/06/12/business/dealbook/mobile-banking-zelle-venmo-apple-pay.html?module=WatchingPortal&region=c-column-middle-span-region&pgType=Homepage&action=click&mediaId=thumb_square&state=standard&contentPlacement=4&version=internal&contentCollection=www.nytimes.com&contentId=https%3A%2F%2Fwww.nytimes.com%2F2017%2F06%2F12%2Fbusiness%2Fdealbook%2Fmobile-banking-zelle-venmo-apple-pay.html&eventName=Watching-article-click&_r=0</a><o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div></div><div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p><div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'>On Wed, Jun 7, 2017 at 7:52 AM, Dave Tonge via Openid-specs-fapi <<a href="mailto:openid-specs-fapi@lists.openid.net" target="_blank">openid-specs-fapi@lists.openid.net</a>> wrote:<o:p></o:p></span></p><blockquote style='border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt'><div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>Hi John and FAPI list members,</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'> </span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>Apologies my mic wasn't working on the call, but here is a quick update on the Regulatory Technical Standards on Strong Customer Authentication for PSD2.</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>The EBA's final draft is here:</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'><a href="https://www.eba.europa.eu/documents/10180/1761863/Final+draft+RTS+on+SCA+and+CSC+under+PSD2+%28EBA-RTS-2017-02%29.pdf" target="_blank">https://www.eba.europa.eu/documents/10180/1761863/Final+draft+RTS+on+SCA+and+CSC+under+PSD2+%28EBA-RTS-2017-02%29.pdf</a></span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'> </span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>This draft includes their responses to feedback.</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>FAPI sent the following feedback:</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'><a href="https://www.eba.europa.eu/regulation-and-policy/payment-services-and-electronic-money/regulatory-technical-standards-on-strong-customer-authentication-and-secure-communication-under-psd2?p_p_auth=uy1W7oVC&p_p_id=169&p_p_lifecycle=0&p_p_state=maximized&p_p_col_id=column-2&p_p_col_pos=1&p_p_col_count=2&_169_struts_action=%2Fdynamic_data_list_display%2Fview_record&_169_recordId=1617559" target="_blank">https://www.eba.europa.eu/regulation-and-policy/payment-services-and-electronic-money/regulatory-technical-standards-on-strong-customer-authentication-and-secure-communication-under-psd2?p_p_auth=uy1W7oVC&p_p_id=169&p_p_lifecycle=0&p_p_state=maximized&p_p_col_id=column-2&p_p_col_pos=1&p_p_col_count=2&_169_struts_action=%2Fdynamic_data_list_display%2Fview_record&_169_recordId=1617559</a></span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>You will notice in their feedback they ignore the issue of the confusion between authentication and authorisation.</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>The Commission has recently published a proposed amended version of the RTS:</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'><a href="https://www.eba.europa.eu/documents/10180/1863077/RTSEBA24052017.pdf/0e8f0242-8964-473d-8495-184fec286519" target="_blank">https://www.eba.europa.eu/documents/10180/1863077/RTSEBA24052017.pdf/0e8f0242-8964-473d-8495-184fec286519</a></span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>The changes made in the amendment are detailed in this letter:</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'><a href="https://www.eba.europa.eu/documents/10180/1806975/%28EBA-2017-E-1315%29%20Letter+from+O+Guersent%2C%20FISMA+re+Commission+intention+to+amend+the+draft+RTS+on+SCA+and+CSC+-Ares%282017%292639906.pdf/efbf06e1-b0e9-4481-88e5-b70daa663cb9" target="_blank">https://www.eba.europa.eu/documents/10180/1806975/%28EBA-2017-E-1315%29%20Letter+from+O+Guersent%2C%20FISMA+re+Commission+intention+to+amend+the+draft+RTS+on+SCA+and+CSC+-Ares%282017%292639906.pdf/efbf06e1-b0e9-4481-88e5-b70daa663cb9</a></span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>There is currently uncertainty as to whether the amended draft will be adopted. From a bank and TPP perspective here in the UK we believe that the amendments will have unintended consequences and will publish a letter shortly where we detail our concerns.</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>Further to the RTS (which is more about principles than technical standards) the Euro Retail Payments Board at the European Central Bank is working on actual technical standards to be promoted across the EU for PSD2. Their latest report is attached and it is from this report that we started consideration of CIBA to support "decoupled" flows.</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>FAPI also drafted a letter to the ERPB working group which I've also attached.</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>I'm happy to answer any questions the group may have regarding these documents.</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>It is worth noting that in the UK, the Financial Conduct Authority and Her Majesty's Treasury have both endorsed the work of OpenBanking Ltd on the Open Banking Standard:</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Trebuchet MS",sans-serif'>FCA Approach Doc <a href="https://www.fca.org.uk/publication/consultation/cp17-11-draft-approach-document.pdf" target="_blank">17.66</a>:</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><i><span style='font-family:"Times New Roman",serif'>During the period before the SCA-RTS becomes applicable, the parties may find it helpful to take account of industry standards which are being developed as a result of the Competition and Markets Authority’s Open Banking Remedy</span></i><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'>HMT Consultation on PSD2 <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/589023/implementation_of_revised_EU_directive.pdf" target="_blank">6.10</a>:<o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><i><span style='font-family:"Times New Roman",serif'>The government therefore sees the PSDII implementing regulations as providing the legislative foundations on which the Open Banking API Standard then sits. Although APIs are only one method by which ASPSPs could provide the access to AISPs or PISPs mandated under the PSDII, the government believes a commonly utilised API framework will lead to greater competition in the retail banking and “third party” services market and better outcomes for payers and other end users. </span></i><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'>On a final note, a number of the "CMA9" banks who are mandated to implement the Open Banking Standard have operations in other EU states (e.g. Danske, AIB, BOI) and my understanding is that they want to use the standard not only in the UK but for all their operations.<o:p></o:p></span></p></div></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'>Hopefully we will see increased adoption of FAPI over the coming months.<o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif;color:#888888'> </span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-family:"Times New Roman",serif;color:#888888'> </span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><p class=MsoNormal style='margin-left:4.8pt'><span class=hoenzb><span style='font-family:"Times New Roman",serif;color:#888888'>-- </span></span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p><div><div><div><div><div><div><div><div><div><div><div><p class=MsoNormal style='margin-left:4.8pt'><b><span style='font-size:10.5pt;font-family:"Open Sans";color:#00A4B7'>Dave Tonge</span></b><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-size:8.5pt;font-family:"Open Sans";color:#333333'>CTO</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><a href="http://www.google.com/url?q=http%3A%2F%2Fmoneyhubenterprise.com%2F&sa=D&sntz=1&usg=AFQjCNGUnR5opJv5S1uZOVg8aISwPKAv3A" target="_blank"><span style='font-size:8.5pt;font-family:"Open Sans";color:#835EA5;text-decoration:none'><img border=0 width=200 height=50 style='width:2.0833in;height:.5208in' id="_x0000_i1025" src="http://content.moneyhub.co.uk/images/teal_Moneyhub-Ent_logo_200x50.png" alt="Moneyhub Enterprise"></span></a><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-size:8.5pt;font-family:"Open Sans";color:#00A4B7'>10 Temple Back, Bristol, BS1 6FL</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><p class=MsoNormal style='margin-left:4.8pt'><b><span style='font-size:8.5pt;font-family:"Open Sans";color:#00A4B7'>t: </span></b><span style='font-size:8.5pt;font-family:"Open Sans";color:#333333'><a href="tel:+44%20117%20280%205120" target="_blank">+44 (0)117 280 5120</a></span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-size:10.5pt;font-family:"Open Sans";color:#616161'> </span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p><div><p class=MsoNormal style='margin-left:4.8pt'><span style='font-size:8.0pt;font-family:"Open Sans";color:#333333'>Moneyhub Enterprise is a trading style of Momentum Financial Technology Limited which is authorised and regulated by the Financial Conduct Authority ("FCA"). Momentum Financial Technology is entered on the Financial Services Register (FRN </span><b><span style='font-size:8.0pt;font-family:"Open Sans";color:#00A4B7'>561538</span></b><span style='font-size:8.0pt;font-family:"Open Sans";color:#333333'>) at <a href="http://fca.org.uk/register" target="_blank">fca.org.uk/register</a>. Momentum Financial Technology is registered in England & Wales, company registration number </span><b><span style='font-size:8.0pt;font-family:"Open Sans";color:#00A4B7'>06909772</span></b><span style='font-size:8.0pt;font-family:"Open Sans";color:#333333'> </span><span style='font-size:7.5pt;font-family:"Arial",sans-serif;color:#222222'>©</span><span style='font-size:8.0pt;font-family:"Open Sans";color:#333333'> . Momentum Financial Technology Limited 2016. </span><span style='font-size:8.0pt;font-family:"Open Sans";color:#888888'>DISCLAIMER: This email (including any attachments) is subject to copyright, and the information in it is confidential. Use of this email or of any information in it other than by the addressee is unauthorised and unlawful. Whilst reasonable efforts are made to ensure that any attachments are virus-free, it is the recipient's sole responsibility to scan all attachments for viruses. All calls and emails to and from this company may be monitored and recorded for legitimate purposes relating to this company's business. Any opinions expressed in this email (or in any attachments) are those of the author and do not necessarily represent the opinions of Momentum Financial Technology Limited or of any other group company.</span><span style='font-family:"Times New Roman",serif'><o:p></o:p></span></p></div></div></div></div></div></div></div></div></div></div></div></div><p class=MsoNormal style='mso-margin-top-alt:0in;margin-right:0in;margin-bottom:12.0pt;margin-left:4.8pt'><span style='font-family:"Times New Roman",serif'><br>_______________________________________________<br>Openid-specs-fapi mailing list<br><a href="mailto:Openid-specs-fapi@lists.openid.net">Openid-specs-fapi@lists.openid.net</a><br><a href="http://lists.openid.net/mailman/listinfo/openid-specs-fapi" target="_blank">http://lists.openid.net/mailman/listinfo/openid-specs-fapi</a><o:p></o:p></span></p></blockquote></div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'><br><br clear=all><o:p></o:p></span></p><div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'> <o:p></o:p></span></p></div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'>-- <o:p></o:p></span></p><div><p class=MsoNormal><span style='font-family:"Times New Roman",serif'>..tom<o:p></o:p></span></p></div></div><p class=MsoNormal style='margin-bottom:12.0pt'><span style='font-size:12.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Times New Roman",serif'><o:p> </o:p></span></p></div></body></html>