[stock-market-ticker symbols="FB;BABA;AMZN;AXP;AAPL;DBD;EEFT;GTO.AS;ING.PA;MA;MGI;NPSNY;NCR;PYPL;005930.KS;SQ;HO.PA;V;WDI.DE;WU;WP" width="100%" palette="financial-light"]

European financial institutions face ‘frightening’ open banking risks, Konsentus warns

9 septembrie 2022

Konsentus, a leading global SaaS company enabling safe and secure data exchange, has issued an urgent warning about the serious risks facing European financial institutions operating in the open banking ecosystem resulting from the increased levels of open banking fraud.  

On 23 June 2022, the European Banking Authority published an Opinion and Report in response to the European Commission’s Call for Advice (CfA) on the review of the Payment Services Directive (PSD2). 


The report identifies significant issues and dangers around proving the identity and current regulatory permissions of Third-Party Providers (TPPs) that deliver open banking services.  

Among the EBA’s 200 proposals are nine proposals for legislative change which will reduce risk and enhance consumer protection by determining the identity and current regulatory permissions of TPPs in real-time.  

It may be several years until any recommendations come into effect, meaning that banks will be exposed to the risks identified by the EBA for some time. 

​​PSD2 enables open banking by requiring financial institutions to share their customers’ accounts with authorised third parties and fintechs. Open banking is now a major phenomenon, with billions of transactions in Europe each month and an expected 63.8 million users by 2024

When data is shared, banks must ensure that they are giving information to the correct entities and are liable for any data given to unauthorised third parties.  

However, the regulatory permissions which allow TPPs to deliver open banking services across the EEA can change at any time. If banks continue to share data with TPPs which do not have the correct regulatory status, they could face regulatory fines and be in breach of GDPR. 

Brendan Jones, CCO, Konsentus, said: “Banks face genuinely frightening possibilities if they fail to check the identity and regulatory status of TPPs adequately. They are liable for both unauthorised access to data and fraudulent transactions, which could result in reputational damage and significant financial losses.  

The damage caused by high-profile regulatory action could dent confidence in the wider open banking ecosystem, potentially hurting all players and slowing down the pace of adoption across Europe.  

We welcome the EBA’s recommendations, but also warn banks that they must take action immediately to mitigate the risks. Legislation will take some time to come into force, so financial institutions must resolve the risk around identity and regulation themselves.” 

Our key takeaways from the EBA’s report can be found here. A summary of the nine key proposals is below:

  1. A Central Machine-Readable Database for all Payment Service Providers (PSPs) currently authorised to deliver Payment Initiation Services (PIS) and Account Information Services (AIS).  
  2. Ongoing Checking to understand if a TPP is authorised to carry out services being requested at the time of a request.  
  3. Going beyond eIDAS certificates to address “uncertainties” and understand the identity of a TPP and its authorisation status, the services it can provide and its passporting permissions.  
  4. Harmonised data to avoid “discrepancies between the information contained on individual national registers and the EBA central register” to avoid error and misuse of personal data.  
  5. Consistent data updates and a common deadline for updates to EBA and national registers so that data is made available immediately to avoid incorrect account access decisions. 
  6. Reliable passporting information and a requirement for banks to check a TPP’s ‘home’ central authority.
  7. A duty of care which ensures banks bear liability for protecting customers’ data and funds to minimise financial and reputational damage. 
  8. A complete picture provided by a single database which offers full visibility of all regulated fintech TPPs and credit institutions authorised to act as TPPs.
  9. Clarity on refusing access to address “uncertainties on the use and reliance of EiDAS certificates for the purpose of identification” to understand the identity of a TPP, its passporting status and the services it can provide.  

_____________

Konsentus help financial institutions make informed, real-time decisions on data sharing and API transaction requests by providing them with consolidated data sourced directly from registers operated by the EBA and National Competent Authorities (NCAs) in European nations. This ensures that data is never handed out to unauthorised third parties, thus avoiding any PSD2 or GDPR non-compliance fines. 

Konsentus is a RegTech company enabling financial institutions to transact safely and securely within the open banking and open finance ecosystems. The company’s award-winning SaaS solution, Konsentus Verify, provides confidence and trust by performing real-time identity & regulatory checking services ensuring that account access is never given to fraudulent third parties. 

Headquartered in the UK, Konsentus has extensive operations across Europe and selected international markets. 

Noutăți
Cifra/Declaratia zilei

Anders Olofsson – former Head of Payments Finastra

Banking 4.0 – „how was the experience for you”

So many people are coming here to Bucharest, people that I see and interact on linkedin and now I get the change to meet them in person. It was like being to the Football World Cup but this was the World Cup on linkedin in payments and open banking.”

Many more interesting quotes in the video below:

Sondaj

In 23 septembrie 2019, BNR a anuntat infiintarea unui Fintech Innovation Hub pentru a sustine inovatia in domeniul serviciilor financiare si de plata. In acest sens, care credeti ca ar trebui sa fie urmatorul pas al bancii centrale?