{"id":29804,"date":"2021-11-18T13:29:38","date_gmt":"2021-11-18T12:29:38","guid":{"rendered":"https:\/\/stage.dataductus.com\/helping-banks-meet-psd2-and-the-continued-implementation-of-open-banking-regulations\/"},"modified":"2024-09-26T10:12:42","modified_gmt":"2024-09-26T09:12:42","slug":"helping-banks-meet-psd2-and-the-continued-implementation-of-open-banking-regulations","status":"publish","type":"post","link":"https:\/\/ductus.global\/sv\/helping-banks-meet-psd2-and-the-continued-implementation-of-open-banking-regulations\/","title":{"rendered":"Helping banks meet PSD2 and the continued implementation of open banking regulations"},"content":{"rendered":"\n<div class=\"wp-block-cover alignfull is-light\" style=\"min-height:300px;aspect-ratio:unset;\"><span aria-hidden=\"true\" class=\"wp-block-cover__background has-ductus-turquoise-background-color has-background-dim-80 has-background-dim\"><\/span><img decoding=\"async\" width=\"800\" height=\"250\" src=\"https:\/\/ductus.global\/wp-content\/uploads\/2017\/12\/back-7.jpg\" class=\"wp-block-cover__image-background wp-post-image\" alt=\"\" data-object-fit=\"cover\" data-object-position=\"50% 50%\" style=\"object-position:50% 50%;\" srcset=\"https:\/\/ductus.global\/wp-content\/uploads\/2017\/12\/back-7.jpg 800w, https:\/\/ductus.global\/wp-content\/uploads\/2017\/12\/back-7-300x94.jpg 300w, https:\/\/ductus.global\/wp-content\/uploads\/2017\/12\/back-7-768x240.jpg 768w, https:\/\/ductus.global\/wp-content\/uploads\/2017\/12\/back-7-160x50.jpg 160w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><div class=\"wp-block-cover__inner-container is-layout-constrained wp-block-cover-is-layout-constrained\">\n<p class=\"has-text-align-center has-ductus-white-color has-text-color has-link-color wp-elements-852aa93410dfa14fcdebe303b2e41f19\">INSIGHT<\/p>\n\n\n\n<h1 class=\"wp-block-heading has-text-align-center has-ductus-white-color has-text-color has-link-color wp-elements-07dab4c384c1c501c1c298eceadda3ca\" style=\"font-size:42px;font-style:normal;font-weight:600\">Helping banks meet PSD2 and the continued implementation of open banking regulations<\/h1>\n<\/div><\/div>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-preamble-font-size\">With the introduction of Payment Services Directive Two (PSD2) regulations, banks were forced to reassess their architectures and develop new processes and systems to support open banking for secure third-party payments and improve data transparency for users. We speak to Senior IT Security Consultant Per-Gustaf Stenberg<strong> <\/strong>about his experiences from developing PSD2 solutions for Scandinavian banks.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><strong>What is PSD2?<\/strong><br>In a nutshell, it\u2019s an EU regulation for digital payment services that was proposed in 2013, was passed by all member states in 2018 and went live at the end of 2020 \u2013 giving banks the opportunity to roll out solutions. It was developed to promote security and improve data transparency for consumers \u2013 and specifically who can access their data \u2013 while supporting the increased use of APIs from third-party providers. It was also designed to boost innovation in the financial sector. Secure authorization and authentication are a central part of it.<\/p>\n\n\n\n<p><strong>How did the banks react to the planned implementation of PSD2 regulations?<\/strong><br>It depends on a bank\u2019s size, really. Most of the bigger banks put together large-scale, highly-qualified teams to implement the necessary changes. However, many of the small to medium sized banks didn&#8217;t have the inhouse expertise to do this, which is where we could support them \u2013 our first PSD2 started back in 2019. Interestingly, in conjunction with this, a lot of banks took the opportunity to analyze their architectures and see how they could re-invent them and develop new products as part of open banking. After all, it\u2019s no secret that too much reliance on legacy systems is a security concern, especially for older banks and those that have grown through acquisition and as a result have multiple systems to manage.<\/p>\n\n\n\n<p><strong>How have Ductus been helping banks with PSD2?<\/strong><br>At Ductus we have a number of consultants who are experts in exposing APIs and digital services securely online, and having a good understanding of how to implement the PSD2 regulation is essential to this. This is just one part of our larger <a href=\"https:\/\/ductus.global\/secure-your-digital-services\/\">Secure Your Digital Services solution offering<\/a>, that we offer across all industries. When it comes to PSD2, we\u2019ve been focusing on authorization and authentication for open banking, and in particular, the technology and processes that revolve around data owners giving consent to third-party providers. Typically, this has meant deploying the OAuth2 RFC standard and specification with an existing identity solution from our partner <a href=\"http:\/\/www.curity.io\">Curity<\/a>, which involves integrations with API management and API portals.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>&#8221;At Ductus we have a number of consultants who are experts in exposing APIs and digital services securely online, and a good understanding of how to implement the PSD2 regulation is essential to this.&#8221;<\/em><\/p>\n<\/blockquote>\n\n\n\n<p><strong>How close is the collaboration with banks?<\/strong><br>We work closely together, often as part of a bigger PSD2 project involving teams of integrators, API developers, and mainframe support, along with legal experts who have been interpreting the new regulation. In our role, we often bridge the gap between legal\u2019s interpretation of the regulation and the needs of those wanting to onboard new third party payment providers and expose the APIs to the public. This is a complex technical process consisting of multiple components including TLS handshakes, tokenization and certificate verifications \u2013 that must run smoothly. This is further complicated by the fact that it involves the banks, third-party providers, and users who must give their approval for account access to take place, every 90 days.<\/p>\n\n\n\n<p><strong>Has the process been standardized?<\/strong><br>Since it\u2019s a relatively new regulation, the processes are still being refined. The Berlin Group \u2013 A European Standards Initiative \u2013 is developing a PSD2 framework but this is a work in process. What they have published is helpful and it\u2019s regularly updated but it doesn\u2019t answer all the questions. This is something that we are doing while developing and maintaining solutions for our bank customers.<\/p>\n\n\n\n<p><strong>How do Ductus services support the PSD2 and open banking process?<br><\/strong>Essentially, we help ensure that tokens within a bank\u2019s system are issued correctly based on the third-party provider in question. They extract information in certificates including finance institution IDs and roles, as well as TLS fingerprints and compare them with the information in tokens before granting or denying authorization. Much of the work involves tailoring this to fit the specific architecture of a bank.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"597\" src=\"https:\/\/ductus.global\/wp-content\/uploads\/2021\/10\/psd2-1-1024x597.png\" alt=\"\" class=\"wp-image-19948\" srcset=\"https:\/\/ductus.global\/wp-content\/uploads\/2021\/10\/psd2-1-1024x597.png 1024w, https:\/\/ductus.global\/wp-content\/uploads\/2021\/10\/psd2-1-300x175.png 300w, https:\/\/ductus.global\/wp-content\/uploads\/2021\/10\/psd2-1-768x448.png 768w, https:\/\/ductus.global\/wp-content\/uploads\/2021\/10\/psd2-1-86x50.png 86w, https:\/\/ductus.global\/wp-content\/uploads\/2021\/10\/psd2-1-756x441.png 756w, https:\/\/ductus.global\/wp-content\/uploads\/2021\/10\/psd2-1.png 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<p>Ductus is typically involved in supporting banks with steps 3 to 5.<br><br>Step 3 re-directs the PSU (end-user) through a standard oauth2 flow to issue a consent for a given action to be used by the third party provider, such as perform payment-transaction or fetch account information.<\/p>\n\n\n\n<p>In step 4, a third party provider provides a valid certificate (mutual TLS) issued with certain roles AISP\/PISP for a token to be issued with the correct permissions.<\/p>\n\n\n\n<p>The certificate is presented again in step 5. when the third party provider requests the data (open banking) and matches it with the previously issued token.<\/p>\n<\/div>\n<\/div>\n<\/div><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>How many banks have you supported with PSD2?<\/strong><br>We\u2019ve worked with quite a number of banks throughout Scandinavia, for example Collector Bank. For some, it was a question of helping meet compliance, while for others it\u2019s been helping them to use PSD2 as a gamechanger for the types of services they offer customers. This usually comes down to the size of the bank and what their customers require of them. But regardless of their plans, as soon as a bank customer requests a third-party service, the bank is obliged to provide it, which means they most probably require a PSD2 solution.<\/p>\n\n\n\n<p><strong>What can we expect to see in the future?<\/strong><br>Like many regulations, the launch of PSD2 is just the beginning. New financial OAuth2 and Open ID standards are being developed continuously by the community to improve the open banking experience. These standards will need to be implemented in existing PSD2 solutions to ensure compliance. Our long running relationships with our banking customers means we will be ready to help them as and when they need it.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-d-green-light-color has-alpha-channel-opacity has-d-green-light-background-color has-background\"\/>\n\n\n\n<div class=\"wp-block-group alignwide\"><div class=\"wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:16% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"442\" height=\"442\" src=\"https:\/\/ductus.global\/wp-content\/uploads\/2021\/11\/per-gustaf-stenberg.jpg\" alt=\"\" class=\"wp-image-20771 size-full\" srcset=\"https:\/\/ductus.global\/wp-content\/uploads\/2021\/11\/per-gustaf-stenberg.jpg 442w, https:\/\/ductus.global\/wp-content\/uploads\/2021\/11\/per-gustaf-stenberg-150x150.jpg 150w, https:\/\/ductus.global\/wp-content\/uploads\/2021\/11\/per-gustaf-stenberg-300x300.jpg 300w, https:\/\/ductus.global\/wp-content\/uploads\/2021\/11\/per-gustaf-stenberg-50x50.jpg 50w\" sizes=\"(max-width: 442px) 100vw, 442px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<h4 class=\"wp-block-heading\" id=\"h-about-per-gustaf-stenberg-senior-it-security-consultant-at-data-ductus\"><meta charset=\"utf-8\"><strong>About Per-Gustaf Stenberg, Senior IT Security Consultant at Data Ductus<\/strong><\/h4>\n\n\n\n<p>Per-Gustaf has been working at Ductus for six years. Originally working with \u2018classic\u00b4 development, over time he has moved into automating operations with a strong focus on security. He has helped multiple banks implement a successful PSD2 solution.<\/p>\n<\/div><\/div>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div><\/div>\n\n\n<div class=\"cta-button wp-block-button ductus-cta-block aligncenter\">\n\t<div class=\"wp-block-button\"><a href=\"https:\/\/ductus.global\/formpage?d=Zm9ybT0yJnRpdGxlPUhlbHBpbmcgYmFua3MgbWVldCBQU0QyIGFuZCB0aGUgY29udGludWVkIGltcGxlbWVudGF0aW9uIG9mIG9wZW4gYmFua2luZyByZWd1bGF0aW9ucyZidXR0b25fdGV4dD1Db250YWN0IFVzJmJ1dHRvbl9jbGFzcz1oYXMtZHVjdHVzLW9yYW5nZS1iYWNrZ3JvdW5kLWNvbG9yIG1kJnJlc3BvbnNpYmxlJnJlZGlyZWN0X3VybCZzZW5kX3VybD1odHRwczovL2R1Y3R1cy5nbG9iYWwvc3Yvd3AtanNvbi93cC92Mi9wb3N0cy8yOTgwNC8mcmVnaW9uPUhlbHBpbmcgYmFua3MgbWVldCBQU0QyIGFuZCB0aGUgY29udGludWVkIGltcGxlbWVudGF0aW9uIG9mIG9wZW4gYmFua2luZyByZWd1bGF0aW9ucw==\" role=\"button\" title=\"Contact Us\" target=\"_blank\" class=\"ductus-btn-angle has-ductus-orange-background-color md\"  data-gtmtrack=\"true\" data-trackelement=\"form-button\" data-trackvalue=\"Contact Us\">Contact Us<\/a><\/div><\/div>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-group alignfull has-d-mocha-light-background-color has-background\"><div class=\"wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow\">\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<section id=\"post-grid-block_0f0d87adef4cc5c1c81b37ce317dd9ba\" class=\"post-grid aligncenter template-0\">\n\t<div class=\"inner-grid columns-1\">\n\t\t\n\t\t\t\t\n\n<div class=\"grid-item events span-columns span-1-columns\">\n\t<a href=\"https:\/\/ductus.global\/sv\/events\/managing-identities-and-app-security-consistently-in-a-complex-it-environment\/\" class=\"block-link\" title=\"Managing Identities and App Security Consistently in a Complex IT Environment\">\n        \t\t<figura class=\"grid-item-image\">\n            <img decoding=\"async\" src=\"https:\/\/ductus.global\/wp-content\/uploads\/2021\/10\/back-tech.jpg\" alt=\"Managing Identities and App Security Consistently in a Complex IT Environment\">\n        <\/figura>\n                        <span class=\"date-info \"  style=\"color:\"><span class=\"category-name last-cat\">Webinar <\/span><\/span>\n        \t\t<div class=\"inner\">\n\t\t\t<span class=\"item-title alt-heading-font\">Managing Identities and App Security Consistently in a Complex IT Environment<\/span>\n\t\t\t<p class=\"item-text\">Many large organizations face a major security challenge due to the many and varied authentication and authorization solutions deployed across their IT environments. The mix of tools, services and applications, in the cloud and on-premise&#8230;<\/p>\n\t\t<\/div>\n\t<\/a>\n<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t<\/section>\n\n\n\n<p><\/p>\n\n\n\t\t<section id=\"social-share-block_a2409d0ffd72526f204e8f4ff5154f3d\" class=\"ductus-gutenberg ductus-social-share-block\">\n\t\t\t<div class=\"inner\">\n\t\t\t\t<nav class=\"social-share post-29804\" role=\"navigation\" aria-label=\"Social Links Menu\"><div class=\"menu-social-container\"><ul class=\"social-links-menu\"><li class=\"menu-item\"><a class=\"social-share-link social-share-x\" title=\"x\" href=\"https:\/\/twitter.com\/intent\/tweet?text=Helping%20banks%20meet%20PSD2%20and%20the%20continued%20implementation%20of%20open%20banking%20regulations&amp;url=https%3A%2F%2Fductus.global%2Fsv%2Fhelping-banks-meet-psd2-and-the-continued-implementation-of-open-banking-regulations%2F\" target=\"_blank\" rel=\"noopener\" alt=\"Share on X\"><svg class=\"svg-icon\" aria-hidden=\"true\" role=\"img\" focusable=\"false\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M13.982 10.622 20.54 3h-1.554l-5.693 6.618L8.745 3H3.5l6.876 10.007L3.5 21h1.554l6.012-6.989L15.868 21h5.245l-7.131-10.378Zm-2.128 2.474-.697-.997-5.543-7.93H8l4.474 6.4.697.996 5.815 8.318h-2.387l-4.745-6.787Z\"><\/path><\/svg><\/a><\/li><li class=\"menu-item\"><a class=\"social-share-link social-share-facebook\" title=\"facebook\" href=\"https:\/\/www.facebook.com\/sharer\/sharer.php?u=https%3A%2F%2Fductus.global%2Fsv%2Fhelping-banks-meet-psd2-and-the-continued-implementation-of-open-banking-regulations%2F\" target=\"_blank\" rel=\"noopener\" alt=\"Share on Facebook\"><svg class=\"svg-icon\" aria-hidden=\"true\" role=\"img\" focusable=\"false\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M12 2C6.5 2 2 6.5 2 12c0 5 3.7 9.1 8.4 9.9v-7H7.9V12h2.5V9.8c0-2.5 1.5-3.9 3.8-3.9 1.1 0 2.2.2 2.2.2v2.5h-1.3c-1.2 0-1.6.8-1.6 1.6V12h2.8l-.4 2.9h-2.3v7C18.3 21.1 22 17 22 12c0-5.5-4.5-10-10-10z\"><\/path><\/svg><\/a><\/li><li class=\"menu-item\"><a class=\"social-share-link social-share-linkedin\" title=\"linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Fductus.global%2Fsv%2Fhelping-banks-meet-psd2-and-the-continued-implementation-of-open-banking-regulations%2F&amp;title=Helping%20banks%20meet%20PSD2%20and%20the%20continued%20implementation%20of%20open%20banking%20regulations\" target=\"_blank\" rel=\"noopener\" alt=\"Share on Linkedin\"><svg class=\"svg-icon\" aria-hidden=\"true\" role=\"img\" focusable=\"false\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M19.7,3H4.3C3.582,3,3,3.582,3,4.3v15.4C3,20.418,3.582,21,4.3,21h15.4c0.718,0,1.3-0.582,1.3-1.3V4.3 C21,3.582,20.418,3,19.7,3z M8.339,18.338H5.667v-8.59h2.672V18.338z M7.004,8.574c-0.857,0-1.549-0.694-1.549-1.548 c0-0.855,0.691-1.548,1.549-1.548c0.854,0,1.547,0.694,1.547,1.548C8.551,7.881,7.858,8.574,7.004,8.574z M18.339,18.338h-2.669 v-4.177c0-0.996-0.017-2.278-1.387-2.278c-1.389,0-1.601,1.086-1.601,2.206v4.249h-2.667v-8.59h2.559v1.174h0.037 c0.356-0.675,1.227-1.387,2.526-1.387c2.703,0,3.203,1.779,3.203,4.092V18.338z\"><\/path><\/svg><\/a><\/li><li class=\"menu-item\"><a class=\"social-share-link social-share-mail\" title=\"mail\" href=\"mailto:?subject=Share: Helping%20banks%20meet%20PSD2%20and%20the%20continued%20implementation%20of%20open%20banking%20regulations&amp;body=Helping%20banks%20meet%20PSD2%20and%20the%20continued%20implementation%20of%20open%20banking%20regulations%0D%0A%0D%0A%0D%0A%0D%0ARead more: https%3A%2F%2Fductus.global%2Fsv%2Fhelping-banks-meet-psd2-and-the-continued-implementation-of-open-banking-regulations%2F\" target=\"_blank\" rel=\"noopener\" alt=\"Share on Mail\"><svg class=\"svg-icon\" aria-hidden=\"true\" role=\"img\" focusable=\"false\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M20,4H4C2.895,4,2,4.895,2,6v12c0,1.105,0.895,2,2,2h16c1.105,0,2-0.895,2-2V6C22,4.895,21.105,4,20,4z M20,8.236l-8,4.882 L4,8.236V6h16V8.236z\"><\/path><\/svg><\/a><\/li><\/ul><\/div><\/nav>\n\t\t\t<\/div>\n\t\t<\/section>\n\n\n\n<div style=\"height:150px\" aria-hidden=\"true\" class=\"wp-block-spacer is-style-responsive-medium\"><\/div>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>With the introduction of Payment Services Directive Two (PSD2) regulations, banks were forced to reassess their architectures and develop new processes and systems to support open banking for secure third-party payments and improve data transparency for users. We speak to Senior IT Security Consultant Per-Gustaf Stenberg about his experiences from developing PSD2 solutions for Scandinavian [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":30381,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4177,4224],"tags":[4250],"class_list":["post-29804","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insights-sv","category-insights-it-consulting-sv","tag-infrastruktur-sakerhet"],"acf":[],"_links":{"self":[{"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/posts\/29804","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/comments?post=29804"}],"version-history":[{"count":1,"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/posts\/29804\/revisions"}],"predecessor-version":[{"id":32407,"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/posts\/29804\/revisions\/32407"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/media\/30381"}],"wp:attachment":[{"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/media?parent=29804"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/categories?post=29804"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ductus.global\/sv\/wp-json\/wp\/v2\/tags?post=29804"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}