Strong Customer Authentication in Practice

Size: px
Start display at page:

Download "Strong Customer Authentication in Practice"

Transcription

1 Strong Customer Authentication in Practice A Signicat whitepaper June

2 This white paper has been produced on behalf of Signicat by Norfico ( and Consult Hyperion (

3 Table of content Foreword 4 From PSD1 to PSD2 5 PSD2 5 Definitions of roles in PSD2 6 PSD2 timeline 7 Strong Customer Authentication 8 what and why? Strong Customer Authentication 14 in practice How Signicat can assist 16 Conclusion 19 Get in touch 20 About Signicat 20

4 Foreword The clear majority of reports and white papers written about PSD2 up until now have been focused on how Article 66 and 67 (relating to Access to Account) will potentially cause new challenges for the banks, but will also represent exciting opportunities, providing the banks embrace PSD2 proactively. The regulation will also enable the fintechs of the world to tap into one of the bank s most sacred areas the customer accounts and to start competing with the banks in a whole new way. These topics are important and exciting, but for the opportunities presented by PSD2 to be realised, some important questions must be answered and some basic problems must be solved. Especially within the area of identity and authentication, and this white paper discusses those questions and problems. This white paper tackles a number of questions relating to another very important part of PSD2, which is the directive s requirements for Strong Customer Authentication (SCA). Why is the directive putting so much emphasis on SCA? How are the new SCA requirements going to work in practice? Who will perform SCA? And who has the competencies to assist them and ensure the best possible user experience? Since the SCA requirements are not going to go away, it is necessary to discuss how to handle this new situation going forward. In this whitepaper, Signicat puts forward its view on this and as well as some tangible suggestions on adoption of this new regulation. Before going into the discussion about identity and authentication in connection with PSD2 in depth, we would like to give a quick introduction to the new directive and an overview of the major news, the most important roles and their definitions, and the basic timeline for the enforcement of the directive. 4 A Signicat whitepaper June 2017

5 From PSD1 to PSD2 PSD1 The first Payment Service Directive - Directive 2007/64/EC - from the European Commission became effective in 2007 and was transposed to the national laws throughout the European Union two years later in November The primary aims of the PSD were to start opening the European payment market and increase competition. Furthermore, PSD created the legal platform for SEPA 1. An European Commission press release in December 2007 said this about the aims of the directive: The aim of the PSD is to ensure that electronic payments within the EU in particular, credit transfer, direct debit and card payments become as easy, efficient, and secure as domestic payments within a Member State, by providing the legal foundation to make the Single Euro Payments Area (SEPA) possible. The PSD will reinforce the rights and protection of all users of payment services (consumers, retailers, large and small companies and public authorities). 2 PSD2 1. The overall gains expected from SEPA for all stakeholders has been evaluated at 21.9 billion per year by PWC in 2014 confirming a Cap Gemini study of 2008 evaluating these benefits at 123 billion cumulated over 6 years. payments/sepa/index_en.htm 2. press-release_ip _ en.htm?locale=en Recognising that significant market changes and rapid new technological developments had made the first PSD insufficient, in 2013 the EU Commission proposed a Revised Directive on Payment Services - now known as PSD2 (Directive (EU) 2015/2366). PSD2 was adopted by the European Parliament in October 2015 and by the Council of The European Union one month later, and in January 2016 it was published in the Official Journal of the EU (OJEU). PSD2 should be implemented as national law in all European Union member states by 13 January While the first payment service directive had its focus on harmonising the operational side of payments, PSD2 is set out to radically change the foundation of financial services, as it is set to drive innovation and competition by enforcing open access to the core part of the banking and payments infrastructure. 5

6 The introductory recitals 4 and 5 of PSD2 explain the reasons and background of the revised directory by saying that: (4) Significant areas of the payments market, in particular card, internet and mobile payments, remain fragmented along national borders. Many innovative payment products or services do not fall, entirely or in large part, within the scope of Directive 2007/64/EC. (5) The continued development of an integrated internal market for safe electronic payments is crucial in order to support the growth of the Union economy and to ensure that consumers, merchants and companies enjoy choice and transparency of payment services to benefit fully from the internal market. 3 Definitions of roles in PSD eu/legal-content/en/ TXT/PDF/?uri=CE- LEX:32015L2366&from=- DA, p eu/legal-content/en/ TXT/PDF/?uri=CE- LEX:32015L2366&from =en, p eu/legal-content/en/ TXT/PDF/?uri=CE- LEX:32015L2366&from =DA, Definitions, (14), s. 57 AISP Account Information Service Provider An AISP is a Third-Party Provider (TPP) who, with access via a standardised interface (e.g. an API), can draw information from a customer s bank account in a bank. This could be for instance Personal Finance Management (PFM) tools or lending companies who will use the access to create a precise credit scoring of a customer. ASPSP Account Servicing Payment Service Provider An ASPSP is a payment service provider providing and maintaining a payment account for a payer. 4 In most cases this will be a bank, but in the PSD2 there is a consistent division of roles and players. PII Payment Instrument Issuer Not only ASPSPs issue payment instruments. There is an increasing number of merchant issued payment instruments like the Amazon credit card. PII can utilise AISP or PISP (see below) to conduct fund check and/ or transactions. PI - Payment Instrument The directive defines the PI as a personalised device(s) and/or set of procedures agreed between the payment service user and the payment service provider and used in order to initiate a payment order. 5 PISP Payment Initiation Service Provider A PISP is a Third-Party Provider (TPP) with access via a standardised interface (e.g. an API) can carry out payments directly from a customer s account through the banks own Account to Account (A2A) infrastructure. Examples of this kind of services are Sofort (owned by Klarna) and Trustly, who already today offer this type of payment directly from consumers accounts. However, these services are currently not regulated and in their current form, bank cannot tell the difference between a consumer initiated payment and one initiated by a third party. 6 A Signicat whitepaper June 2017

7 PSP Payment Service Provider The Directive explains that a payment service provider means a body referred to in Article 1(1) or a natural or legal person benefiting from an exemption pursuant to Article 32 or 33; Article 32 under Section 4 about exemption explains that the body or natural or legal person do not have to be a Payment Service Provider if: the monthly average of the preceding 12 months total value of payment transactions executed by the person concerned, including any agent for which it assumes full responsibility, does not exceed a limit set by the Member State but that, in any event, amounts to no more than EUR 3 million eu/legal-content/en/ TXT/PDF/?uri=CE- LEX:32015L2366&from=- DA, Section 4, Exemption, Article 32, p eu/legal-content/en/ TXT/HTML/?uri=CE- LEX:32015L2366&from=- DA, Article 4, Definitions, (10) PSU Payment Service User A PSU is a legal entity e.g. an individual or a corporation with an ASPSP account making use of a payment service in the capacity of payer, payee, or both. 7 Again an example of a role based definition as this in most cases will mean a consumer. TPP Third Party Provider A TPP is a third party, who is granted access to a bank account either as an AISP or a PISP. This is not to be confused with the role of Trusted Third Party (TTP) used in cryptography. PSD2 timeline PSD2 enters into force in the EU Deadline for responses to EBA s consultation paper on RTSs for SCA Final draft on RTSs for SCA from EBA Deadline for all EU member states to adopt PSD2 on a national level Appliance of PSD Deadline for responses to EBA s discussion paper on RTSs for SCA Q (expected) Publication of the EBA Guideline for SCA and XS2A Q (expected) Application of the RTSs for SCA and XS2A 8. eu/legal-content/en/ TXT/?uri=uriserv%3AOJ.L_ ENG 9. Still possible to surcharge: Three-party schemes like American Express and Diners Visa and MC in case the underlying account is a corporate account. The most important news PSD2 along with the Interchange Fee Regulation (IFR) 8 introduces a long list of changes and news within areas such as liability (Article 74), capping of interchange rates and a general ban of surcharge (Article 62 paragraph 4). But the most important and talked about news relates to two other areas, Access to Account and Strong Customer Authentication: 1) The so-called Access To Account (XS2A) including a couple of new roles Payment Initiation Services Providers (PISP) and Account 7

8 10. eu/legal-content/en/ TXT/PDF/?uri=CE- LEX:32015L2366&from=- DA, p. 92 and p. 93 Information Service Providers (AISP) introduces a new requirement for banks to allow these new service providers access to customers bank accounts as described in the directive s Articles Article 66. Rules on access to payment account in the case of payment initiation services. 1. Member States shall ensure that a payer has the right to make use of a payment initiation service provider to obtain payment services as referred to in point (7) of Annex I. The right to make use of a payment initiation service provider shall not apply where the payment account is not accessible online. And: Article 67: Rules on access to and use of payment account information in the case of account information services. 1. Member States shall ensure that a payment service user has the right to make use of services enabling access to account information as referred to in point (8) of Annex I. That right shall not apply where the payment account is not accessible online. 10 This demand for the banks to open up their accounts has been described and analysed many times already and is not the main subject for this whitepaper. But tightly attached to the Access To Account requirement is obviously a deep concern about security, which leads us to the heart of the matter of the following chapters: 2) The new requirements for Strong Customer Authentication or SCA (article 97, article 98, and article 74 paragraph 2), In the following, we are going to analyse the Strong Customer Authentication requirement further and discuss how this is going to play out in practice going forward. Strong Customer Authentication what and why? The basic reason for the European Union s requirement of Strong Customer Authentication - Two Factor Authentication - in PSD2 is to protect consumers against fraud. The PSD2 aims to ensure that all payment services offered electronically are carried out in a secure manner, adopting technologies able to guarantee the safe authentication of the user and to reduce, as much as possible, the risk of fraud. That is why the need for Strong Customer Authentication in payments is central to PSD2 as defined in Article 97 (see next page). 8 A Signicat whitepaper June 2017

9 Article 97 in PSD2 Authentication 1. Member States shall ensure that a payment service provider applies strong customer authentication where the payer: (a) accesses its payment account online; (b) initiates an electronic payment transaction; (c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses. 2. With regard to the initiation of electronic payment transactions as referred to in point (b) of paragraph 1, Member States shall ensure that, for electronic remote payment transactions, payment service providers apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee. 3. With regard to paragraph 1, Member States shall ensure that payment service providers have in place adequate security measures to protect the confidentiality and integrity of payment service users personalised security credentials. 4. Paragraphs 2 and 3 shall also apply where payments are initiated through a payment initiation service provider. Paragraphs 1 and 3 shall also apply when the information is requested through an account information service provider. 5. Member States shall ensure that the account servicing payment service provider allows the payment initiation service provider and the account information service provider to rely on the authentication procedures provided by the account servicing payment service provider to the payment service user in accordance with paragraphs 1 and 3 and, where the payment initiation service provider is involved, in accordance with paragraphs 1, 2 and 3. Article 4 of PSD2 lists all definitions applicable for the directive. Definition number 30 concerns Strong Customer Authentication: (30) strong customer authentication means an authentication based on the use of two or more elements categorised as knowledge (something only the user knows), possession (something only the user possesses) and inherence (something the user is) that are independent, in that the breach of one does not compromise the reliability of the others, and is designed in such a way as to protect the confidentiality of the authentication data; Knowledge can be a PIN or static password. Possession can be a payment card, a key fob, or a phone as a receiver for a one-time password (OTP). And Inherence can be a biometric element like iris scan or fingerprint used in a solution like Apple s Touch ID. Two of these elements in combination constitutes a strong customer authentication. Main Authentication Methods are: Passwords and PINs (Knowledge) Mobile banking login (Knowledge and Possession) One Time Passwords via SMS or Mobile Banking or Telephone Call back (Possession) Fingerprint, e.g. Apple Touch ID (Inherence) Voice Recognition (Inherence) Time-based One Time Password hardware devices e.g. Key fob (Possession) 9

10 11. documents/10180/ / Final draft+rts+on+ SCA+and+CSC+under +PSD2+%28EBA-RTS %29.pdf, p. 3 And SCA must be performed for all relevant remote access requests: PSD2 Push Payments Card Payments Electronic Funds Transfer (EFT) Remote Direct Debit Initiation Internet/Mobile Payments 3rd Party Account Queries Changing Account Details Anything else that creates risk Final SCA RTS Article 98 of the directive requires the development of a set of Regulatory Technical Standards (RTS): EBA shall develop, in close cooperation with the ECB, draft Regulatory Technical Standards specifying the requirements of the strong customer authentication (SCA). Since EBA received 226 comments to its SCA Consultation Paper published in August 2016 and were obliged to take all of them into consideration and give back written replies to everyone, it comes as no surprise that the final Draft Regulatory Technical Standards on Strong Customer Authentication and common and secure communication under Article 98 of Directive 2015/2366 (PSD2) was released with some delay when it arrived on 23 February And in the Executive Summary of the RTS, EBA explains how they have had to make difficult trade-offs between the various, at times competing, objectives of PSD2, including enhancing security, promoting competition, ensuring technology and business-model neutrality, contributing to the integration of payments in the EU, protecting consumers, facilitating innovation and enhancing customer convenience. 11 Original exemptions from SCA The August 2016 EBA Consultation Paper on the draft SCA RTS lists four exemptions for the use of SCA. The exemptions are in cases where: 1. the payer accesses exclusively the information of its payment account online, or the consolidated information on other payment accounts held, without disclosure of sensitive payment data. [e.g. accessing an aggregated spending overview in a PFM tool]. 2. The payer initiates a contactless electronic payment transaction at a point of sale within the limits of both the following conditions: i. the individual amount of contactless electronic payment transaction does not exceed the maximum amount of 50 EUR; ii. the cumulative amount of previous non-remote electronic payment transactions initiated via the payment instrument offering a contactless functionality without application of strong customer authentication does not exceed 150 EUR 10 A Signicat whitepaper June 2017

11 3. the payer initiates online a credit transfer where the payer and the payee is the same natural or legal person and the payee s payment account is held by the payer s account servicing payment services provider; 4. the payer initiates a remote electronic payment transaction where all the following conditions are met: i. the individual amount of the remote electronic payment transaction does not exceed the maximum amount of 10 EUR; and ii. the cumulative amount of previous remote electronic payment transactions initiated by the payer without application of strong customer authentication does not exceed 100 EUR. 12 The intention behind Article 97 is to battle fraud in e-commerce which is certainly a noble cause since the European level of fraud has increased rapidly in recent years. The problem with introducing Strong Customer Authentication as default for all online payment transactions is that it takes away the flexibility of a risk-based fraud security that allows the entity performing SCA to judge by themselves and differentiate in security level between different purchase scenarios. For instance, the organisation Ecommerce Europe explained the problem in this way: documents/10180/ / Consultation+Paper+on+ draft+rts+on+sca+and+ CSC+(EBA-CP ).pdf, p com/hubfs/white_papers/ Web%20Fraud%20Prevention%20and%20Online%20 Authentication%20Mar- ket%20guide% pdf, p There were also a large number of responses on other existing exemptions, seeking clarification, pointing out technical unfeasibility, and requesting further exemptions to accommodate existing situations. The EBA has reflected on these, concurs with the views expressed in relation to a number of the comments and has made some amendments accordingly in some areas. documents/10180/ / Final+draft+RTS+ on+sca+and+csc+un- der+psd2+%28e- BA-RTS %29.pdf, p. 10. Ecommerce Europe believes that this too strict and burdensome rigid focus on strong customer authentication would have a damaging impact on the future competitiveness of the European e-commerce sector, as it fails to strike a balance between ensuring customers security and checkout convenience. 13 Additional exemptions in the final RTS In the final draft RTS, EBA has taken into consideration some of the concerns expressed in the many responses to the SCA Consultation Paper 14 and made some adjustments and amendments to the list of exemptions. One of the adjustments is that EBA has raised the SCA limit for payment transactions from EUR 10 to EUR 30, which corresponds to what we know from contactless POS payments today. Furthermore, the cumulative amount has been raised from 100 to 150 EUR. This means that for transactions of 30 EUR or less, risk-based authentication is acceptable under certain restrictions. In the former edition of the RTS, risk-based authentication was not an option at all. Another update or amendment to the list of exemptions concerns payment transactions via unattended transport and parking terminals, which were not mentioned in the previous draft version of the RTS: 11

12 The EBA has added a new exemption for unattended terminals for fares related to transport and parking services, since it may not be proportionate and may also not be in the general public interest for operational (e.g. to avoid queues and potential accidents at toll gates) or security reasons (e.g. the risk of shoulder surfing) Rationale 25: Final+draft+RTS+on +SCA+and+CSC+un- der+psd2+%28e- BA-RTS %29. pdf, p. 10 Obviously, these new exemptions reduce the total number of future SCA transactions to some extent, but compared to the number of SCA transactions performed today the increase will be significant nonetheless. And the entities handling the SCAs could very well be facing some serious challenges when it comes to performing a smooth, efficient and userfriendly SCA execution towards the consumers (or PSUs to stay in PDS2 terminology). We will come back to that later in this white paper when we discuss the complex questions that the SCA requirements trigger, but before that, we will look at another important part of SCA liability. A new option for SCA liability shift As described earlier, PSD2 creates four new business entities known as Payment Service Providers: ASPSP (Account Servicing PSP accountholding institution i.e. a bank), PISP (Payment Initiating Services Provider - can initiate push payment from a bank customer account to 3rd-party account), AISP (Account Information Services Provider - can query bank customer account details), and card issuing PSPs (who can issue cards and use a bank customer account as the funding source). In the first edition of the PSD2 SCA RTS, the SCA liability was entirely with the banks. But the final RTS seems to allow for a possible liability shift from the banks to the TPPs and allows both payer PSP (ASPSP or a card issuing PSP) and payee PSP (an acquirer, PISP or AISP) to perform SCA (or risk based authentication if the TPP or PSP assume full liability). Even though the RTS text does not state this in a very precise and clear way this is our interpretation based on hints and indications throughout the text. We and others are seeking clarification on this point. For instance, in comment 55 and comment 295 it says that the payee PSP can trigger the risk-based exemption, which would not be possible if the liability were not with the payee PSP that is an acquirer, a PISP or an AISP. Comment 295 says: 12 A Signicat whitepaper June 2017

13 The EBA also explains in rationale 24 that its interpretation of PSD2 suggests that the transaction-risk analysis (TRA) exemption from SCA can be applied by the payee s and payer s PSPs, but not by the payer or the payee themselves. The liability rules also suggest that the payer s PSP should have the last say on whether or not the TRA exemption is used for a specific transaction documents/10180/ / Final+draft+RTS+on +SCA+and+CSC+un- der+psd2+%28e- BA-RTS %29.pdf, p documents/10180/ / Final+draft+RTS+on +SCA+and+CSC+un- der+psd2+%28e- BA-RTS %29pdf, p ecommerce-checkout-abandonment-rate/ The reasoning in this interpretation is also supported by other passages in the RTS for instance, in Rationale 14, which states that the ASPSP must provide SCA, but by inference implies that it could be done by another PSP: In relation to how Article 97(1)(b) should be applied by PSPs for the provision of payment initiation services (PIS), the EBA understands, as stated in the CP, that PIS Providers have the right to rely on the authentication procedures provided by the ASPSP to the user. In such cases, the authentication procedure will remain fully in the sphere of competence of the ASPSP. 17 The underlined phrase implies a right to rely on ASPSP authentication, but not an obligation. This possible shift of SCA liability is important for several reasons. Allowing the TPPs provided that they meet the security demands from the banks to take on the liability triggers new dynamics in the market. While performing SCA might be a potentially interesting opportunity for some categories of TPPs, seen from the banks perspective this may introduce new risks both in terms of data security and the ability to keep and develop trust based relationships with the end customers. But who would want to take over the SCA liability and why? A typical example would be a large web shop that wants to make sure it gives its customers the best possible user experience. The highest possible conversion rate is what all web shops aim for, and one of the most costly problems in today s e- and m-commerce is high checkout abandonment rates perhaps because of lack of trust or too complicated a checkout process. A 2016 analysis by American Compass found that the average checkout abandonment rate in e-commerce was as high as 25%: Stores operating in the Food and Drinks segment have the lowest abandonment rates, with an average of 19%. Top Food and Drinks performers have an abandonment rate of 7% or less. In contrast, Electronics stores experience a much higher abandonment rate (28% on average), while top performers have an 18% average. 18 Taking full control of the SCA part of the checkout process would enable international e-commerce businesses to design their own SCA solutions 13

14 and deliver the same smooth or as smooth as possible - SCA user experience to all customers across Europe. And as the option for the shift of liability shows, PSD2 SCA is not just a compliance issue, and it could and probably will - have significant business impact. Strong Customer Authentication in practice Despite the RTS s exemptions from SCA - as described above - PSD2 will most likely result in an explosion of transactions requiring SCA as soon as the APIs enabling Access to Account are fully implemented in the banks and the TPPs have had some time to promote their new services (AIS and PIS) in the markets across Europe. But have the banks in Europe started preparing for this? Will they be ready meaning SCA compliant in time? And will they be able to handle possibly millions of new SCA-based transactions from AISPs and PISPs? And how about the TPPs who might want to take on the SCA liability, are they capable of doing so, do they have the necessary technical abilities to develop SCA solutions themselves and handle the transactions? Banks will also have to assess their customer care processes, services and systems to support the more frequent use of the bank s SCA solution and the likely increase in need for identity reassurance and credentials resetting. Banks under time pressure If we start with the banks, they have some tough deadlines ahead of them. PSD2 must be implemented in national law in all European Union member states by January of next year (2018). And no later than eighteen months after the approval of the RTSs from EBA, all European banks must comply with these. The compliance task for the banks focuses on two parts; SCA, and the much-discussed Access to Account (XS2A). The largest European banks are already preparing for PSD2 and have been doing so for a while. They know that PSD2 is one of the most disrupting, almost revolutionary, pieces of regulation in recent years and they have dedicated teams working PSD2. But the large banks represent only the very tip of the iceberg, and below we will find the majority of European banks have either done nothing at all so far, or have only just started sketching a PSD2 strategy. This large group of several thousand small and medium European banks lack both resources and knowledge about how to comply with the PSD2 requirements. They have too much on their plate already just taking care of business and what their capabalities in terms of PSD2 will be limited. For most of these banks to be PSD2 compliant in time both in terms of 14 A Signicat whitepaper June 2017

15 Access to Account for TPPs and regarding SCA, they will need assistance from their solution providers, which will be data centres or PSPs. They will not be able to cope with the requirements and the deadlines and the necessary technical setups on their own. Regional differences That being said, we do see significant regional differences within the Europe Union regarding digital readiness and as part of that ability to handle the SCA challenge. In general, the Eastern and Southern part of Europe lack behind the Northern part of Europe, and in particular the Nordic countries take the European lead on digitisation including digital infrastructure and SCA solutions like the national e-id schemes NemID in Denmark and BankID in Norway and Sweden. But even in the Nordic countries, PSD2 represents a considerable challenge for small and medium banks. Even though they are familiar with SCA through their national eids, they are not necessarily prepared for the huge increase of SCA required transactions that PSD2 is expected to trigger. Flexible timeline for the TPPs For the TPPs who would like to take on the SCA liability because it might enable them to offer a smoother user experience at the SCA part of the checkout process, there are no deadlines as such. They do not have to be ready at any particular date like the banks, but we believe that a group of the largest and most ambitious TPPs, who want to take on the SCA liability might decide to move fast, because they have the resources and know the importance of steadily optimizing the online user experience and decreasing the checkout abandonment rates as much as possible. Some of these will probably be large e-commerce merchants who want to be PISPs themselves. For a merchant like Amazon, becoming a PISP would be an obvious choice and securing the best possible checkout user experience by taking on the SCA liability would most likely also be a highly tempting option. The largest TPPs might want to develop their own SCA solution and SCA process, but the vast majority of the TPPs who decide to take on the SCA liability will need and want a trusted service provider to handle the practical part of the SCA on their behalf. They lack skills and experience in the authentication field, but they still see a purpose in taking control rather than leaving it up to the banks to decide the SCA process and solution. This control over the flow is important to ensure the smoothest possible onboarding and authorisation process. 15

16 How Signicat can assist As underlined several times already in this whitepaper, the number of transactions requiring strong customer authentication is expected to grow significantly going forward as a direct consequence of PSD2. This will be a challenge for a very large section of the approximately 4,000 European banks, and for an unknown number of TPPs, who want to make use of opportunity in the final RTS on SCA to take over the SCA liability. TPPs could probably have a number of reasons for doing so, but one obvious reason for a large e-commerce merchant acting as a TPP could be to create a better user experience than the merchant s bank would be able to offer. All these parties within the PSD2 ecosystem share the same challenge, which is to handle SCA in the most efficient, flexible, user-friendly and inexpensive way - and none of them has SCA as a core competency. This scenario obviously creates an opportunity for a specialist to step in and offer a cross-european Authentication as a Service solution, which will effectively ease the banks and the TPPs PSD2 SCA pains and enable them to focus on their core businesses. And this is exactly what Signicat intends to do. Based on ten years of experience working with two-factor national eid schemes, Signicat has developed a new platform for ID-service - an online identity hub - called a Digital Identity Service Provider (DISP), and through the DISP Signicat offers Identity On Demand services for customers, regardless of geography or e-id. Signicat today has more than 200 European customers among banks, financial companies, insurance companies and government agencies connected to its identity hub or DISP, customers trust Signicat with the responsibility of authenticating users, providing electronic signing, identity proofing and document preservation. And since strong customer authentication is an integrated part of the DISP-platform services, Signicat already has the ideal base for scaling its services to European banks and TPPs in need for SCA assistance. Basic DISP services to banks In the future, Europe s 4,000 banks are mandated by PSD2 to offer SCA services to all authorised TPPs, which requires the banks themselves, or their current platform or service providers, to implement and maintain these SCA services. Or they can choose to outsource the SCA task to Signicat, make use of Signicat s DISP platform and Authentication as a Service solution, and free up time and resources to focus on their core business instead. 16 A Signicat whitepaper June 2017

17 PSD2 ARCHITECTURE (PAYMENT) Request purchase (value, payee) Token for payment Request purchase (value, payee, token) PISP ASPSP (Bank) Request purchase (value, payee, ASPSP) e-tailer Identification DISP Request purchase (value, payee, ASPSP) Authentication Confirmation (payee + value) (*) Identification (*) Confirmation can happen on other channels: but the payer must confirm thepayment value and payee on a channel that is different from the one they initiated on The DISP platform will be providing identification and authentication of individual customers and even allow siloed information to be accessed by other banking areas. The DISP also opens the possibility of banks offering identity services to third parties e.g. to AISPs and PISPs. Furthermore, the penalties for ASPSPs who fail to meet fraud levels for transactions are heavy, and if a DISP helps reduce this threat, then it will be hugely valuable. Finally, since the banks by default will hold the key to SCA under PSD2, the banking customers will be highly dependent on the bank s ability to offer a satisfying user experience whenever SCA is necessary which could easily be several times a week or more for each customer. Being able to deliver a smooth SCA user experience could easily become an important competitive parameter for banks in the near future, and a reason for a customer to choose one bank over another. Basic DISP services to TPPs As described earlier in this white paper the new PSD2 SCA RTS allows the TPPs to perform SCA both payer PSP (ASPSP or a card issuing PSP) and payee PSP (an acquirer, PISP or AISP). PSD2 ARCHITECTURE Request purchase (value, payee) Token for payment Request purchase (value, payee, token) PISP ASPSP (Bank) Authentication Confirmation (payee + value) (*) Request purchase (value, payee, ASPSP) Identification DISP Request purchase (value, payee, ASPSP) Identification e-tailer (*) Confirmation can happen on other channels: but the payer must confirm thepayment value and payee on a channel that is different from the one they initiated on The most obvious reason for a TPP to choose to take on the SCA responsibility and liability would probably be to optimise the user 17

18 experience for the end customers. The challenge, though, for the intermediaries, especially new TPPs, will be that they have limited capability and reach in this area of digital identity, and therefore the DISP platform will support their needs and help them scale. Furthermore, the fraud level restriction applies to any TPP providing customer authentication, so once again enhanced identity services will be extremely valuable if they reduce or help manage fraud levels. Aggregated DISP services The Signicat DISP platform provides easy access for banks and third parties to identity services. The DISP platform will significantly increase both banks and TPPs ability and flexibility in terms of using digital identity in their business applications and processes. This is an extension of the existing identity services that Signicat offers already e.g. a private sector equivalent of using e-id solutions like the national solutions BankID or NemID from the Nordics. And it will allow merchants or PSPs to use Signicat s solutions to authorise PSD2 push payments even where they are not directly connected to a bank. 18 A Signicat whitepaper June 2017

19 Conclusion The requirement for Strong Customer Authentication in the PSD2 is made with the best intention from the Commission s side to improve security and reduce fraud in digital transactions to the benefit of the European consumers. The requirements in the directive will make it necessary for all European banks to initiate a process to assess the impact and possibilities in the realm of PSD2 in general, and SCA in particular. There is no option of doing nothing. The fact that authentication will play a much more central role in the banks services with the implementation of PSD2 changes the choice of solution from a purely technical choice to a strategic choice. A flexible platform for identification, authentication and authorisation will be essential to realise the intentions and possibilities within PSD2. 9 STRATEGIC PSD2 ISSUES TO CONSIDER Banks (ASPSPs) should: Analyse their current SCA and eid solutions in light of PSD2 Are the solutions PSD2 compliant? Do they have the capacity needed in case of a future massive scale of SCA transactions following PSD2? Do the designs of the solutions offer a smooth user experience? Analyse and assess SCA requirements and options Analyse their security setup related to API access Third Party Providers (TPPs) should: Assess the integration options towards ASPSPs Ensure authentication processes towards ASPSPs Asses how different ASPSPs SCA solutions fit into the flow of the service the TPPs want to provide All players should: Map the requirements of PSD2 to their existing and future business Conduct thorough risk analysis Assess potential suppliers and partners 19

20 Get in touch Lars Møller Kristensen Mobile: Web: About Signicat Signicat is one of the leading providers of electronic identity and electronic signature solutions in Europe. The company, founded in 2007, delivers online trust based services to the public and private sector globally. The solutions fulfill operational capabilities in line with international standards and requirements, such as Privacy, Anti-Money Laundering (AML) and Anti-Terrorist legislation and regulations, as well as Know Your Customer (KYC) requirements for onboarding of new users.

PSD2 IMPLICATIONS OF THE REGULATION August 8, Regina Lau, Chief Strategy Officer, Ingenico epayments Zainab Mir, Counsel Payments, Netflix

PSD2 IMPLICATIONS OF THE REGULATION August 8, Regina Lau, Chief Strategy Officer, Ingenico epayments Zainab Mir, Counsel Payments, Netflix PSD2 IMPLICATIONS OF THE REGULATION August 8, 2017 Regina Lau, Chief Strategy Officer, Ingenico epayments Zainab Mir, Counsel Payments, Netflix OVERVIEW 1. PSD2 Overview Regina Lau 2. Strong Customer Authentication

More information

COMMISSION DELEGATED REGULATION (EU) No /.. of XXX

COMMISSION DELEGATED REGULATION (EU) No /.. of XXX EUROPEAN COMMISSION Brussels, XXX [ ](2017) XXX draft COMMISSION DELEGATED REGULATION (EU) No /.. of XXX supplementing Directive 2015/2366 of the European Parliament and of the Council with regard to regulatory

More information

Review of Priviti PSD2 Use Case and its positioning compared to alternative marketplace offerings

Review of Priviti PSD2 Use Case and its positioning compared to alternative marketplace offerings Review of Priviti PSD2 Use Case and its positioning compared to alternative marketplace offerings The revised Payment Service Directive (PDS2) is a directive focused on better integration of an internal

More information

The Second Payment Services Directive: Scoping out the impacts of the Regulatory Technical Standards

The Second Payment Services Directive: Scoping out the impacts of the Regulatory Technical Standards The Second Payment Services Directive: Scoping out the impacts of the Regulatory Technical Standards TABLE OF CONTENTS INTRODUCTION: A CRITICAL MOMENT FOR PSD2 KEY ASPECTS OF THE FINAL DRAFT RTS IMPACTS

More information

PAYMENT SERVICES DIRECTIVE 2 WHAT IS ALL THE FUSS ABOUT ANYWAY?

PAYMENT SERVICES DIRECTIVE 2 WHAT IS ALL THE FUSS ABOUT ANYWAY? PAYMENT SERVICES DIRECTIVE 2 WHAT IS ALL THE FUSS ABOUT ANYWAY? An extract from the Scandinavian financial services newsletter Winter 2016 Newsletter 2 SCANDINAVIAN FINANCIAL SERVICES 2016 WINTER EDITION

More information

RESPONSES TO CONSULTATION PAPER

RESPONSES TO CONSULTATION PAPER RESPONSES TO CONSULTATION PAPER re: for: Consultation Paper on the draft Regulatory Technical Standards specifying the requirements on strong customer authentication and common and secure communication

More information

Market environment and implementation timeline PSD2 in a nutshell

Market environment and implementation timeline PSD2 in a nutshell www.pwc.com/psd2 Market environment and implementation timeline PSD2 in a nutshell Why do we need a new Payment Services Directive (PSD)? By 13 th January 2018, Member States will have to implement the

More information

Trending: How does PSD2 trigger innovation?

Trending: How does PSD2 trigger innovation? Trending: How does PSD2 trigger innovation? Speakers: Nils Jung, Managing Partner, Innopay Germany Hakan Eroglu, Senior Manager Digitization in Payments & Banking, Accenture Trending: How does PSD2 trigger

More information

PSD2 TAS Open Banking

PSD2 TAS Open Banking PSD2 A challenge for Banks but a huge opportunity at the same time for new services TAS Group 2017 Some highlights on PSD2 driven changes PSD2 introduces a new legal structure to payments in the EU, challenging

More information

The communication between Third Party Providers and Banks. PSD2 in a nutshell

The communication between Third Party Providers and Banks. PSD2 in a nutshell www.pwc.ch The communication between Third Party Providers and Banks. What will the impact of technology be? PSD2 in a nutshell Summary The banking system is at a turning point, under the pressure of the

More information

BEUC RESPONSE TO EUROPEAN BANKING AUTHORITY DISCUSSION PAPER

BEUC RESPONSE TO EUROPEAN BANKING AUTHORITY DISCUSSION PAPER The Consumer Voice in Europe BEUC RESPONSE TO EUROPEAN BANKING AUTHORITY DISCUSSION PAPER on future draft Regulatory Technical Standards on strong customer authentication and secure communication under

More information

1. Analysis of the factual situation presented in the Green Paper

1. Analysis of the factual situation presented in the Green Paper Response of the Government of the Federal Republic of Germany to the European Commission s Green Paper Towards an integrated European market for card, internet and mobile payments I. Introduction The Government

More information

NextGen PSD2. A European Standard for PSD2 XS2A

NextGen PSD2. A European Standard for PSD2 XS2A NextGen PSD2 A European Standard for PSD2 XS2A Berlin Group and NextGenPSD2 The NextGenPSD2 Initiative is a dedicated Task Force of the Berlin Group with the goal to create an open, common and harmonised

More information

WHITE PAPER. Encouraging innovation in payments through the PSD2 initiative. Abstract

WHITE PAPER. Encouraging innovation in payments through the PSD2 initiative. Abstract WHITE PAPER Encouraging innovation in payments through the PSD2 initiative Abstract Revised Directive on Payment Services (PSD2) is primarily aimed at bringing new, online modes of payments initiation

More information

Payment Services Directive 2 and other European Laws on Payments Systems Ayse Zoodsma-Sungur

Payment Services Directive 2 and other European Laws on Payments Systems Ayse Zoodsma-Sungur Payment Services Directive 2 and other European Laws on Payments Systems Ayse Zoodsma-Sungur Seventh Conference on Payment and Securities Settlement Systems, Ohrid 7-10 July 2014 Outline Regulation, yes

More information

SecuRe Pay recommendations for the security of mobile payments

SecuRe Pay recommendations for the security of mobile payments ECB-PUBLIC FINAL SecuRe Pay recommendations for the security of mobile payments Stephanie Czák Senior Market Infrastructure Expert European Central Bank ETSI/EC Collaborative Ecosystem for M-Payments Workshop

More information

DEFINING NEW CUSTOMER JOURNEYS

DEFINING NEW CUSTOMER JOURNEYS DEFINING NEW CUSTOMER JOURNEYS Payment Services Directive 2 (PSD2) Scoping out the impacts of the Regulatory Technical Standards (RTS) on Strong Customer Authentication and Common and Secure Open Standards

More information

FINAL REPORT ON THE DRAFT RTS AND ITS ON THE EBA REGISTER UNDER THE PSD2 EBA/RTS/2017/10 EBA/ITS/2017/ December 2017.

FINAL REPORT ON THE DRAFT RTS AND ITS ON THE EBA REGISTER UNDER THE PSD2 EBA/RTS/2017/10 EBA/ITS/2017/ December 2017. EBA/RTS/2017/10 EBA/ITS/2017/07 13 December 2017 Final Report on Draft Regulatory Technical Standards setting technical requirements on development, operation and maintenance of the electronic central

More information

The Open Banking PSD2 Implementation Strategies

The Open Banking PSD2 Implementation Strategies The Open Banking PSD2 Implementation Strategies How to meet the challenge of Open Banking Introduction Open Banking is the next step in a technology evolution driven by the API economy. Technology giants

More information

Turning PSD2 Challenges into Business Opportunities.

Turning PSD2 Challenges into Business Opportunities. Turning PSD2 Challenges into Business Opportunities www.ebankit.com PSD2 in a nutshell Perfect Competition Payment Services Directive 2 (PSD2) The PSD2 updates and complements the EU rules put in place

More information

Edgar, Dunn & Company A Closer Look at the Payment Regulations. Webinar 25 th June 2015

Edgar, Dunn & Company A Closer Look at the Payment Regulations. Webinar 25 th June 2015 Edgar, Dunn & Company A Closer Look at the Payment Regulations Webinar 25 th June 2015 Edgar, Dunn & Company, 2015 Introduction This webinar will focus on two key regulatory topics: Multilateral Interchange

More information

Implementation of the revised Payment Services Directive (PSD2): draft Approach Document and draft Handbook changes

Implementation of the revised Payment Services Directive (PSD2): draft Approach Document and draft Handbook changes Implementation of the revised Payment Services Directive (PSD2): draft Approach Document and draft Handbook changes The Building Societies Association response to FCA CP17/11 Restricted 8 June 2017 Introduction

More information

How PSD2 impacts marketplaces and platforms

How PSD2 impacts marketplaces and platforms How PSD2 impacts marketplaces and platforms A Stripe guide for navigating the European regulatory changes By Michael Cocoman & David Schreiber The new European payments law, known as the second Payment

More information

Nordea webinar 29/ : PSD2 Access to Accounts a game changer

Nordea webinar 29/ : PSD2 Access to Accounts a game changer Nordea webinar 29/11-2017: PSD2 Access to Accounts a game changer Brief intro setting the scene Some practicalities: 9.00-9.45 CET Webinar is being recorded - material will be uploaded to www.nordea.com/vendors

More information

Consultation Paper. Draft Regulatory Technical Standards

Consultation Paper. Draft Regulatory Technical Standards EBA/CP/2017/09 29 June 2017 Consultation Paper Draft Regulatory Technical Standards on the criteria for determining the circumstances in which the appointment of a central contact point pursuant to Article

More information

Fintech: Assessment of Opportunities Created for Fintechs by PSD2. Valerio Mariani ( ) Axel Pillard ( ) Amanda Tan An Ping ( )

Fintech: Assessment of Opportunities Created for Fintechs by PSD2. Valerio Mariani ( ) Axel Pillard ( ) Amanda Tan An Ping ( ) Fintech: Assessment of Opportunities Created for Fintechs by PSD2. Valerio Mariani (000458743) Axel Pillard (000458804) Amanda Tan An Ping (000458590) 1.0. Introduction FinTech, which stands for Financial

More information

ECB-PUBLIC REGULATION OF THE EUROPEAN CENTRAL BANK. of 28 November on payments statistics (ECB/2013/43)

ECB-PUBLIC REGULATION OF THE EUROPEAN CENTRAL BANK. of 28 November on payments statistics (ECB/2013/43) EN ECB-PUBLIC REGULATION OF THE EUROPEAN CENTRAL BANK of 28 November 2013 on payments statistics (ECB/2013/43) THE GOVERNING COUNCIL OF THE EUROPEAN CENTRAL BANK, Having regard to the Statute of the European

More information

EBA/RTS/2017/ December Final Report. Draft regulatory technical standards. on central contact points under Directive (EU) 2015/2366 (PSD2)

EBA/RTS/2017/ December Final Report. Draft regulatory technical standards. on central contact points under Directive (EU) 2015/2366 (PSD2) EBA/RTS/2017/09 11 December 2017 Final Report Draft regulatory technical standards on central contact points under Directive (EU) 2015/2366 (PSD2) FINAL REPORT ON CENTRAL CONTACT POINTS UNDER THE PSD2

More information

PSD2 & Instant Payment

PSD2 & Instant Payment PSD2 & Instant Payment Presentation to Investors June 2017 Agenda Introduction PSD2/Instant Payment Impacts for Banks Worldline offering for Banks PSD2/Instant Payment Impacts for Merchants Worldline offering

More information

SEPA for public administrations

SEPA for public administrations Contents: 1 Introduction 2 Background to SEPA 3 Key role of public sector 4 First wave benefits 5 Benefits from market developments 6 Next steps SEPA for public administrations Creating critical mass for

More information

EMV in the U.S. Liability shift; what does this mean for the U.S.?

EMV in the U.S. Liability shift; what does this mean for the U.S.? EMV in the U.S. Liability shift; what does this mean for the U.S.? Questions and answers What the liability shift really means with regards to costs, risks and benefits. Fraud is on the rise in the U.S.

More information

Payment Services Directive 2: What it Means for Banks, Customers, and Payment Service Providers

Payment Services Directive 2: What it Means for Banks, Customers, and Payment Service Providers Payment Services Directive 2: What it Means for Banks, Customers, and Payment Service Providers Abstract The Payment Services Directive 2 (PSD2) can have a significant impact on customers, banks, and payment

More information

Input to Members of the European Parliament on the PSD2 RTS proposal covering banks obligations

Input to Members of the European Parliament on the PSD2 RTS proposal covering banks obligations Input to Members of the European Parliament on the PSD2 RTS proposal covering banks obligations ESBG (European Savings and Retail Banking Group) Rue Marie-Thérèse, 11 - B-1000 Brussels ESBG Transparency

More information

Industry Briefing Strong authentication of Internet Payments in Europe - the new PSD2

Industry Briefing Strong authentication of Internet Payments in Europe - the new PSD2 Industry Briefing Strong authentication of Internet Payments in Europe - the new PSD2 Copyright 2015 VASCO Data Security. All rights reserved. No part of this publication may be reproduced, stored in a

More information

Final Report. Guidelines on the security measures for operational and security risks of payment services under Directive (EU) 2015/2366 (PSD2)

Final Report. Guidelines on the security measures for operational and security risks of payment services under Directive (EU) 2015/2366 (PSD2) EBA/GL/2017/17 12/12/2017 Final Report Guidelines on the security measures for operational and security risks of payment services under Directive (EU) 2015/2366 (PSD2) Final Report on Guidelines on Security

More information

PSD2 ACCELERATOR CAPTURE OPPORTUNITIES, ADDRESS CHALLENGES, AND DRIVE SUCCESS THROUGH PROVEN EXPERTISE

PSD2 ACCELERATOR CAPTURE OPPORTUNITIES, ADDRESS CHALLENGES, AND DRIVE SUCCESS THROUGH PROVEN EXPERTISE PSD2 ACCELERATOR CAPTURE OPPORTUNITIES, ADDRESS CHALLENGES, AND DRIVE SUCCESS THROUGH PROVEN EXPERTISE INTRODUCING OLIVER WYMAN S PSD2 ACCELERATOR PSD2 will have profound implications for the participation

More information

The Future of Retail Banking

The Future of Retail Banking The Future of Retail Banking Navigating the digital banking revolution The digital banking landscape Market trends Challenges & opportunities Digital transformation with HID Global 43% Mobile phone users

More information

Remote e-identification and e-signatures Trusting someone you have never seen

Remote e-identification and e-signatures Trusting someone you have never seen Remote e-identification and e-signatures Trusting someone you have never seen Stéphane Hurtaud Partner Cybersecurity Leader Deloitte Irina Hedea Director Risk Advisory Deloitte Ismaël Cissé Senior Manager

More information

Shaping the future of payments

Shaping the future of payments Helmut Wacket Head of Market Integration Division Shaping the future of payments QED Brussels, 29 March 2017 Changes in the retail payments landscape Classical payment instruments innovative payment solutions

More information

PSD2 DATA FINTECH MARKETPLACE AISP CUSTOMER AWARENESS ALLIANCES MOBILE ECONOMY PISP API DIGITAL COMPLY REVENUE RTS SCORING BANKING STRATEGIC

PSD2 DATA FINTECH MARKETPLACE AISP CUSTOMER AWARENESS ALLIANCES MOBILE ECONOMY PISP API DIGITAL COMPLY REVENUE RTS SCORING BANKING STRATEGIC DISRUPTION FINTECH DATA OPEN STRATEGIC CORPORATE CHANGE BIGTECH PSD2 IMPACT INSTANT PAYMENTS RISK INTERNET INNOVATION REVENUE RTS ALLIANCES PISP SCA ECOSYSTEM AUTHENTICATION ANALYTICS MARKETPLACE MOBILE

More information

THE RISE OF DIGITAL IDENTITIES: Plugging the digital gap in financial services onboarding

THE RISE OF DIGITAL IDENTITIES: Plugging the digital gap in financial services onboarding SIGNICAT INNOPAY REPORT THE RISE OF DIGITAL IDENTITIES: Plugging the digital gap in financial services onboarding onboarding WHITE PAPER JUNE 2017 The drive towards digital onboarding For many financial

More information

THE FUTURE OF BANKING: Innovation & Disruption in light of the revised European Payment Services Directive (PSD2)

THE FUTURE OF BANKING: Innovation & Disruption in light of the revised European Payment Services Directive (PSD2) THE FUTURE OF BANKING: Innovation & Disruption in light of the revised European Payment Services Directive (PSD2) KuppingerCole Study March 2017 2017 Kuppinger Cole Ltd. All rights reserved. Reproduction

More information

When the hard-to-reach become your preferred customers. Finc / the offering which addresses financial inclusion challenges

When the hard-to-reach become your preferred customers. Finc / the offering which addresses financial inclusion challenges When the hard-to-reach become your preferred customers Finc / the offering which addresses financial inclusion challenges Powering the Financial Inclusion revolution Today, 75% of the world s population

More information

On the Way to a Europe-wide FinTech Regulatory Sandbox?

On the Way to a Europe-wide FinTech Regulatory Sandbox? Europe-wide FinTech briefing The European Banking Federation ( EBF ) recently issued a paper recommending the creation of a sandbox, which would let companies experiment with new cross-border financial

More information

Welcoming a new phase of Everyday Payments in Europe

Welcoming a new phase of Everyday Payments in Europe Accenture Payment Services Welcoming a new phase of Everyday Payments in Europe How the revised Payment Services Directive (PSD2) and other regulatory changes enable Everyday Payments to move to the next

More information

How will you manage the impact of the Payment Services Directive 2?

How will you manage the impact of the Payment Services Directive 2? How will you manage the impact of the Payment Services Directive 2? By Edwin van der Molen, Michal Kalina, Bert Bouwmeester and Bernard Juffermans April 2017 What is your strategy? The topic of this white

More information

OBP at the heart of your PSD2 strategy

OBP at the heart of your PSD2 strategy OBP at the heart of your PSD2 strategy API Days Nov 2017 Simon Redfern Open Banking Open APIs for every bank.! Open Standards! Open Source! Open Data! Open Innovation! Why do we need a Web site?! Of course

More information

PSD2: An Open Banking Catalyst

PSD2: An Open Banking Catalyst PSD2: An Open Banking Catalyst Leverage Open APIs to unlock new business opportunities It is short-sighted to treat the European Union s second Payment Services Directive (PSD2) and other European regulations

More information

The Changing Landscape of Card Acceptance

The Changing Landscape of Card Acceptance The Changing Landscape of Card Acceptance Troy Byram Vice-President Sr. E-Receivables Consultant February 6, 2015 Agenda EMV (Chip and Pin) PCI Compliance and Data Security New Regulations for Municipalities

More information

OPEN BANKING: THE ART OF THE POSSIBLE MAKING OPEN BANKING WORK FOR YOUR ORGANISATION. An NCR white paper

OPEN BANKING: THE ART OF THE POSSIBLE MAKING OPEN BANKING WORK FOR YOUR ORGANISATION. An NCR white paper OPEN BANKING: THE ART OF THE POSSIBLE MAKING OPEN BANKING WORK FOR YOUR ORGANISATION An NCR white paper TABLE OF CONTENTS 1 OPEN BANKING AT A GLANCE 2 UNDERSTAND THE CONTEXT: WHY HERE, WHY NOW? 3 WHAT

More information

Current Version: June 9, 2017 DIGITAL WALLET AGREEMENT. This Agreement is between you and Coast Capital Savings Credit Union ( CCS ).

Current Version: June 9, 2017 DIGITAL WALLET AGREEMENT. This Agreement is between you and Coast Capital Savings Credit Union ( CCS ). Current Version: June 9, 2017 DIGITAL WALLET AGREEMENT This Agreement is between you and Coast Capital Savings Credit Union ( CCS ). Your use of any eligible third party mobile payment or digital wallet

More information

Dates Visa MasterCard Discover American Express. Acquirers, subprocessors. support EMV. International ATM liability shift 2

Dates Visa MasterCard Discover American Express. Acquirers, subprocessors. support EMV. International ATM liability shift 2 Network Updates Winter 2015 We are committed to working closely with you on achieving your business goals. As a part of this commitment, we carefully monitor Network changes and summarize them for your

More information

In this Document: EMV Payment Tokenisation Payment Account Reference (PAR) FAQ EMV Payment Tokenisation Technical FAQ

In this Document: EMV Payment Tokenisation Payment Account Reference (PAR) FAQ EMV Payment Tokenisation Technical FAQ In this Document: EMV Payment Tokenisation General FAQ EMV Payment Tokenisation Payment Account Reference (PAR) FAQ EMV Payment Tokenisation Technical FAQ EMV Payment Tokenisation General FAQ 1. What is

More information

EXECUTIVE SUMMARY Future of payments 2017

EXECUTIVE SUMMARY Future of payments 2017 Future of payments 2017 2017/V1 Exploring the future of corporate payments Nordea s pioneering Future of payments study explores some of the important innovations in recent years, and emerging solutions

More information

EPAYSUITE INTEGRATED MODULAR CORE PLATFORM SOLUTION FOR:

EPAYSUITE INTEGRATED MODULAR CORE PLATFORM SOLUTION FOR: EPAYSUITE INTEGRATED MODULAR CORE PLATFORM SOLUTION FOR: canopuslab.com AUTHORISED PAYMENT INSTITUTIONS ELECTRONIC MONEY INSTITUTIONS REMITTANCE AND MONEY TRANSFERS COMPANIES FUNCTIONALITY Client onboarding,

More information

The Future of EU Payments

The Future of EU Payments The Future of EU Payments What s next? 4 February 2015, Brussels Memorandum Panel 1 Regulating EU mobile, internet and card payments what s next? Liz Oakes Principal Advisor, KPMG (Moderator) Ms Oakes

More information

EMV and Educational Institutions:

EMV and Educational Institutions: October 2014 EMV and Educational Institutions: What you need to know Mike English Executive Director, Product Development Heartland Payment Systems 2014 Heartland Payment Systems, Inc. All trademarks,

More information

Terms and Conditions for using BEA Credit Card in Digital Wallet

Terms and Conditions for using BEA Credit Card in Digital Wallet Terms and Conditions for using BEA Credit Card in Digital Wallet These Terms and Conditions for using your BEA Credit Card in Digital Wallet ("Terms and Conditions") apply when you choose to add a BEA

More information

Committee on Industry, Research and Energy Committee on the Internal Market and Consumer Protection

Committee on Industry, Research and Energy Committee on the Internal Market and Consumer Protection European Parliament 2014-2019 Committee on Industry, Research and Energy Committee on the Internal Market and Consumer Protection 28.2.2017 2016/2276(INI) DRAFT REPORT on online platforms and the digital

More information

Remote IDV & Due Diligence:

Remote IDV & Due Diligence: Remote IDV & Due Diligence:. Embracing Technology as a Tool to Optimise KYC/AML Compliance Procedures whilst Minimising Costs. isignthis Ltd (ASX:ISX / FRA : TA8) (SWIFT BIC : ISEMCY21) N J (John) Karantzis

More information

A step towards cashless economy - Unified Payments Interface (UPI)

A step towards cashless economy - Unified Payments Interface (UPI) A step towards cashless economy - Unified Payments Interface (UPI) What is Unified Payment Interface? Objective of a unified payments system is to offer an architecture and a set of APIs on top of existing

More information

Transforming Payments in an assembly game

Transforming Payments in an assembly game Open Banking API for Payments Transforming Payments in an assembly game Jean-François Delorme Partner Paiements, DXC Technology The World of Yesterday The classic French Garden style 2 Payment Industry

More information

Corporate Presentation. Author: DIMPAY Foundation

Corporate Presentation. Author: DIMPAY Foundation Corporate Presentation Author: DIMPAY Foundation Table of Contents Table of Contents What is DIMPAY? 01 DIMPAY Foundation 02 DIMPAY Features 04 DIMPAY ICO 06 ICO Funds 08 DEPOTWALLET 10 DIMPAY Applications

More information

PSD2 & Open Banking The Future of Payments

PSD2 & Open Banking The Future of Payments PSD2 & Open Banking The Future of Payments A White Paper (abridged) by Brendan Jones Bryan Cave, a global firm, is uniquely well-positioned to serve fintech companies. We work closely with several fintech

More information

Ensuring the Safety & Security of Payments. Faster Payments Symposium August 4, 2015

Ensuring the Safety & Security of Payments. Faster Payments Symposium August 4, 2015 Ensuring the Safety & Security of Payments Faster Payments Symposium August 4, 2015 Problem Statement: The proliferation of live consumer account credentials Bank issues physical card Plastic at point

More information

Technology Innovation Exchange 2017

Technology Innovation Exchange 2017 1 2 3 Significant period of change in the next 9 months Between PSD2, OBWG and CMA alone, there is significant, directionally aligned, activity aimed at transforming the landscape. The timing and degree

More information

Horizontal Integration in the Payments Industry

Horizontal Integration in the Payments Industry Horizontal Integration in the Payments Industry Gerard Hartsink Senior Executive Vice President 2007 Payments Conference Santa Fe, 3 May 2007 Content European landscape Restructuring of functions Impact

More information

Euronet s Dynamic Currency Conversion Solution Increase Your Revenue as an Acquirer with a Value Added Service

Euronet s Dynamic Currency Conversion Solution Increase Your Revenue as an Acquirer with a Value Added Service Serving millions of people worldwide with electronic payment convenience. Euronet s Dynamic Currency Conversion Solution Increase Your Revenue as an Acquirer with a Value Added Service Copyright 2010 Euronet

More information

Aktualitātes no Berlin Group NextGen PSD2 konferences. Māris Ozoliņš

Aktualitātes no Berlin Group NextGen PSD2 konferences. Māris Ozoliņš Aktualitātes no Berlin Group NextGen PSD2 konferences. Māris Ozoliņš Rīga, 2017. gada 15. novembris THE Berlin GROUP A EUROPEAN STANDARDS INITIATIVE ««««««««««««««««««««««««NextGenPSD2 Conference 2017

More information

FINGERPRINTS BIOMETRICS THE MISSING PIECE OF THE PAYMENT CARD PUZZLE?

FINGERPRINTS BIOMETRICS THE MISSING PIECE OF THE PAYMENT CARD PUZZLE? FINGERPRINTS BIOMETRICS THE MISSING PIECE OF THE PAYMENT CARD PUZZLE? 2018 On-card biometrics is the final piece of the puzzle to bring trust and security to contactless payments, without compromising

More information

CP ON DRAFT GL ON SUPPORT MEASURES EBA/CP/2014/17. 9 July Consultation Paper

CP ON DRAFT GL ON SUPPORT MEASURES EBA/CP/2014/17. 9 July Consultation Paper EBA/CP/2014/17 9 July 2014 Consultation Paper Draft Guidelines On the types of tests, reviews or exercises that may lead to support measures under Article 32(4)(d)(iii) of the Bank Recovery and Resolution

More information

The Bank of Elk River: Digital Wallet Terms and Conditions

The Bank of Elk River: Digital Wallet Terms and Conditions The Bank of Elk River: Digital Wallet Terms and Conditions These Terms of Use ("Terms") govern your use of any eligible debit card issued by The Bank of Elk River (a "Payment Card") when you add, attempt

More information

You know the destination. We know the way.

You know the destination. We know the way. You know the destination. We know the way. AGES Your partner for pathbreaking toll and vignette systems in Europe If you would like to head for new horizons as far toll and vignette systems are concerned,

More information

GSMA comments on the Draft BEREC Report on OTT services (BoR (15) 142)

GSMA comments on the Draft BEREC Report on OTT services (BoR (15) 142) BoR PC06 (15) 19 GSMA comments on the Draft BEREC Report on OTT services (BoR (15) 142) About the GSMA The GSMA represents the interests of mobile operators worldwide, uniting nearly 800 operators with

More information

Gertrude Tumpel-Gugerell: Corporates in the Single Euro Payments Area business as usual?

Gertrude Tumpel-Gugerell: Corporates in the Single Euro Payments Area business as usual? Gertrude Tumpel-Gugerell: Corporates in the Single Euro Payments Area business as usual? Speech by Ms Gertrude Tumpel-Gugerell, Member of the Executive Board of the European Central Bank, at the Panel

More information

EBA/CP/2013/12 21 May Consultation Paper

EBA/CP/2013/12 21 May Consultation Paper EBA/CP/2013/12 21 May 2013 Consultation Paper Draft Regulatory Technical Standards On Passport Notifications under Articles 35, 36 and 39 of the proposed Capital Requirements Directive Consultation Paper

More information

- PAYMENT SERVICES. EC-Serbia Explanatory Screening meeting Chapter 4 FREE. 13 October 2014

- PAYMENT SERVICES. EC-Serbia Explanatory Screening meeting Chapter 4 FREE. 13 October 2014 EC-Serbia Explanatory Screening meeting Chapter 4 FREE MOVEMENT OF CAPITAL - PAYMENT SERVICES 13 October 2014 Directorate General Internal Market and Services Retail Financial Services and Consumer Policy

More information

EMV: The Journey Begins October 1st

EMV: The Journey Begins October 1st 221 NORTH LASALLE ST. CHICAGO, IL 60601 312-873-3300 INFO@WCAPRA.COM EMV: The Journey Begins October 1st An Examination of the History, Impact, Best Practices, Pitfalls of EMV Implementations, and What

More information

COMMISSION STAFF WORKING PAPER

COMMISSION STAFF WORKING PAPER EN EN EN EUROPEAN COMMISSION Brussels, 22 January 2010 COMMISSION STAFF WORKING PAPER INTERPRETATIVE NOTE ON DIRECTIVE 2009/72/EC CONCERNING COMMON RULES FOR THE INTERNAL MARKET IN ELECTRICITY AND DIRECTIVE

More information

DIGITAL FINANCIAL SERVICES BASIC TERMINOLOGY

DIGITAL FINANCIAL SERVICES BASIC TERMINOLOGY INCLUDING ACRONYMS FOR DFS TRANSACTIONS THIS GUIDELINE NOTE WAS DEVELOPED BY THE AFI DIGITAL FINANCIAL SERVICES (DFS) WORKING GROUP TO PROVIDE UNIVERSAL DEFINITIONS OF KEY DIGITAL FINANCIAL SERVICES TERMS.

More information

Aconite Smart Solutions

Aconite Smart Solutions Aconite Smart Solutions PIN Management Services Contents PIN MANAGEMENT... 3 CURRENT CHALLENGES... 3 ACONITE PIN MANAGER SOLUTION... 4 OVERVIEW... 4 CENTRALISED PIN VAULT... 5 CUSTOMER PIN SELF SELECT

More information

EMV is coming. Here s how to stay ahead of the trend. Presented by CO-OP Financial Services

EMV is coming. Here s how to stay ahead of the trend. Presented by CO-OP Financial Services EMV is coming. Here s how to stay ahead of the trend. Presented by CO-OP Financial Services October 25, 2012 Agenda What EMV is and how it works U.S. and global adoption Impact to the payments ecosystem

More information

RuPay Contactless Ideathon (1.2)

RuPay Contactless Ideathon (1.2) RuPay Contactless Ideathon (1.2) Table of Contents CONTACTLESS PAYMENTS... 3 EXECUTIVE SUMMARY... 3 2.1 Objectives of RuPay Contactless... 4 2.2 Product Description... 4 2.3 Benefits Of RuPay Contactless...

More information

Prepare for GDPR today with Microsoft 365

Prepare for GDPR today with Microsoft 365 Prepare for GDPR today with Microsoft 365 2 Table of contents 01. 02. 03. 04. 05. Executive Sumary Landscape Assess and manage your compliance risk Protect your most sensitive data Closing 3 01. Executive

More information

INSTANT PAYMENTS. The right time to share investments.

INSTANT PAYMENTS. The right time to share investments. INSTANT PAYMENTS The right time to share investments. INSTANT PAYMENTS: THE RIGHT TIME TO SHARE INVESTMENTS. European authorities have seen instant payments as being essential to support the Digital Single

More information

WHO S GOT IT? WHO GETS IT?

WHO S GOT IT? WHO GETS IT? 3D SECURE 2.0: WHO S GOT IT? WHO GETS IT? An Outlook on Merchant Adoption BUSINESS-DRIVEN SECURITY SOLUTIONS 3D SECURE AUTHENTICATION 2.0: MERCHANTS WHO GOT IT ARE GETTING IT Online merchants whose experience

More information

A WHITE PAPER FROM RAPHAELS BANK APRIL 2016 DIRECT BENEFITS: HOW FINTECHS CAN LEVERAGE OPEN ACCESS FOR PAYMENTS INNOVATION

A WHITE PAPER FROM RAPHAELS BANK APRIL 2016 DIRECT BENEFITS: HOW FINTECHS CAN LEVERAGE OPEN ACCESS FOR PAYMENTS INNOVATION A WHITE PAPER FROM RAPHAELS BANK APRIL 2016 DIRECT BENEFITS: HOW FINTECHS CAN LEVERAGE OPEN ACCESS FOR PAYMENTS INNOVATION CONTENTS 01 FOREWORD... 3 02 INTRODUCTION... 4 03 WHAT ARE THE BARRIERS TO COMPETITION

More information

on remuneration policies and practices related to the sale and provision of retail banking products and services

on remuneration policies and practices related to the sale and provision of retail banking products and services EBA/GL/2016/06 13/12/2016 Guidelines on remuneration policies and practices related to the sale and provision of retail banking products and services 1. Compliance and reporting obligations Status of these

More information

The Future of Payment Security in Canada

The Future of Payment Security in Canada The Future of Payment Security in Canada October 2017 1 Visa Canada Public The Future of Payment Security in Canada Notices Forward-Looking Statements This presentation contains forward-looking statements

More information

THE ARRIVAL OF PIN ON MOBILE. An Introduction to the Next Generation of Face-to-Face Mobile Payment Acceptance

THE ARRIVAL OF PIN ON MOBILE. An Introduction to the Next Generation of Face-to-Face Mobile Payment Acceptance THE ARRIVAL OF PIN ON MOBILE An Introduction to the Next Generation of Face-to-Face Mobile Payment Acceptance MYPINPAD Ltd 01 INTRODUCTION For most organisations, growing bottom-line profit is a crucial

More information

PSD2 Strategy. Comply, Compete or Innovate? November kpmg.nl

PSD2 Strategy. Comply, Compete or Innovate? November kpmg.nl PSD2 Strategy Comply, Compete or Innovate? November 2017 kpmg.nl The Dutch market view on PSD2 Will PSD2 determine the future of payments and banking? Account Servicing Payment Service Providers (AS-PSPs,

More information

PSD2. a directive of possibilities. Whitepaper by

PSD2. a directive of possibilities. Whitepaper by PSD2 a directive of possibilities Whitepaper by INTRODUCTION European banks are facing a game-changing 2018. With the new PSD2-directive from EU banks need to rethink their business model and how they

More information

Secure Remote Payment Council (SRPc) White Paper Discussion: EMV Enhancements Post Implementation September 13, 2016

Secure Remote Payment Council (SRPc) White Paper Discussion: EMV Enhancements Post Implementation September 13, 2016 Secure Remote Payment Council (SRPc) White Paper Discussion: EMV Enhancements Post Implementation September 13, 2016 Objective This white paper is the fifth in the series developed by the Secure Remote

More information

European Commission Consultation Document on Transparency and Fees in Cross-Border Transactions in the EU

European Commission Consultation Document on Transparency and Fees in Cross-Border Transactions in the EU European Commission Consultation Document on Transparency and Fees in Cross-Border Transactions in the EU ESBG (European Savings and Retail Banking Group) Rue Marie-Thérèse, 11 - B-1000 Brussels EU Transparency

More information

ORGALIME 1 Reflection Paper Brussels, 27 February Why assessing the definition of the producer in Directive 2002/96/EC?

ORGALIME 1 Reflection Paper Brussels, 27 February Why assessing the definition of the producer in Directive 2002/96/EC? Assessing the Interpretation of the Producer Definition under Directive 2002/96/EC (WEEE) for the Purpose of Transposition in National Laws and for the Purpose of Enforcement at National Levels ORGALIME

More information

Moving Towards a SEPA-compliant Infrastructure

Moving Towards a SEPA-compliant Infrastructure Moving Towards a SEPA-compliant Infrastructure JAN WILLEM MARS GTNEWS, NOVEMBER 22, 2007 Moving Towards a SEPA-compliant Infrastructure Author: Jan Willem Mars This article was published at GTNews, November

More information

Legal Aspects of Identity Management

Legal Aspects of Identity Management Legal Aspects of Identity Management Luca Castellani Secretary, Working Group IV (Electronic Commerce) Traditional approach to identity management Need to identify physical persons to establish trust,

More information

Implementing Regulatory Change with Speed and Absolute Certainty

Implementing Regulatory Change with Speed and Absolute Certainty WHITE PAPER Implementing Regulatory Change with Speed and Absolute Certainty GDPR BASEL III IFRS17 PSD2 A framework for reducing the time and cost of change projects, while mitigating risk, for the financial

More information

Fed Consultation Paper Association for Financial Professionals (AFP) Response

Fed Consultation Paper Association for Financial Professionals (AFP) Response Fed Consultation Paper Association for Financial Professionals (AFP) Response Q1: Are you in general agreement with the payment system gaps and opportunities identified? What other gaps or opportunities

More information

Council of the European Union Brussels, 19 February 2015 (OR. en)

Council of the European Union Brussels, 19 February 2015 (OR. en) Council of the European Union Brussels, 19 February 2015 (OR. en) 6197/15 MI 82 COMPET 40 MAP 5 TELECOM 37 NOTE From: Permanent Representatives Committee (Part 1) To: Council Subject: Draft Council Conclusions

More information