SlideShare ist ein Scribd-Unternehmen logo
1 von 18
Downloaden Sie, um offline zu lesen
WSO2 Open Banking
Getting your API Management Strategy on Point for PSD2
Compliance
Lalaji Sureshika
Technical Lead, Financial Solutions
Agenda
● Recap on PSD2
● EBA Mandated Requirements for API Management in a Compliance
Solution
● An API Management Checklist for PSD2 Compliance
● API Management Capabilities of WSO2 Open Banking
● Demo
Payment Services Directive 2
EU Directive that applies to
all Banks operating in the EU
that regulates payment
services throughout the EU,
with a compliance deadline of
January 2018
What does PSD2 change?
Bank A
Bank B
Bank C
Merchant
TPP
(PISP/AISP)
PSD2
Bank A
Bank B
Bank C
Merchant
XS2A - Access to Account
NowNow
EBA Mandated PSD2 Requirements
● Article 27 -
Communication Interface
● Article 28 - Obligations for
dedicated interface
● Article 29 - Certificates
● Article 30 - Security of
communication session
● Article 31 -Data
exchanges
RTS SCA
Assess and notify operational &
security incidents based on ;
● Transactions Affected
● Service Downtime
● Payment Service Users
Affected
● Economic Impact
● Other payment services
affected
more..
GL on Incident
Reporting
Guidelines for Payment Service
Providers [PSPs]
● Risk Assessment
● Protection
○ Data and Systems
Integrity &
Confidentiality
○ Access Control
● Detection
GL on Security
Measures
API Management Checklist for PSD2 Compliance
Implement API
● Integration points with core-banking
system
Design & Manage API
● Design and manage capabilities of an API
● Interactive documentation support
● Analytics on API usage , API availability &
performance measures
● API Security
API Governance
● API lifecycle management
● API versioning
Consume API
● Third Party Provider (TPP) registration
● Secured API access by TPP
● Business insights on usage
● Notifications for TPPs
WSO2 Open Banking provides all the technology requirements that Banks need to create an “Open Banking” platform to
be PSD2 compliant and as a result become a Digitally Transformed Bank.
API Specification
○ API Definitions
○
WSO2 Open Banking
Customer
TPP
(AISP/PISP)
FinTech
Merchants
Core Banking
Internal Payment
Services
Bank Internal Network
ISO 8583
(TCP/IP)
HTTP
HTTPS
Other Banks
HTTPS
WSO2 Open Banking - API Management Capabilities
● API Specifications
Predefined API templates for :
○ Open Banking UK specification
○ STET API specification
○ Berlin Group NextGenPSD2
Or
○ Any custom API specification
WSO2 Open Banking - API Management Capabilities
● Support for Different API Types
○ Private APIs - Within the bank
○ Partner APIs - Establish with the bank and a specific TPP
○ Open APIs - Open APIs to all trusted TPPs
● API Lifecycle Management
● API Security - OAuth2
● Define API Policies - Throttling ,Access Control, Transport, API
resources
● Trigger alerts based on abnormal TPP usage, API health , backend
core banking system issues
WSO2 Open Banking - API Management Capabilities
● TPP Accessible Developer Portal
○ TPP Onboarding
○ Explore APIs
○ Consume APIs with swagger
○ Provide access to sandbox and production API environments
● Integration points with core banking systems and other internal
banking services
○ Supports different message protocols [ HTTP, TCP] , message types [REST/JSON]
and message formats [ISO 8583, ISO 20022]
● API Monetization to create various revenue models
● API Analytics & Business Insights with dashboards
WSO2 Open Banking Offerings for TPPs
● Onboarding Process
● Establish Secure Communication
● Explore and try out bank APIs
● Setting up sandbox testing
● Setting up production
● Acknowledge new API versions
● Business Insights
Demo
Login & Add Bank
Login Page
2 Factor Authentication
Customer Consent
Initiation
account info
1
2
3
4
302
5
Token 6
Get Accounts
Information
AISP
Account Initiation -Process Flow
Payment Initiation -Process Flow
Credits to Dinosoft Labs from Noun Project
Checkout
Item
Login Page
2 Factor Authentication
Customer Consent
Initiation
payment info
1
2
3
4
PISP
302
5
Token 6
Payment
Complete
7
Settlement
WSO2 Open Banking
● API Manager
● API Security + SCA
● API Analytics
● API Monetization
PSD2 Compliance
● API Integration
● Federated Authentication
● Fraud Detection
● API Analytics
● Dashboards
TPP Provider
● Web/Mobile App Suite
● Insight Sales
● Required Integration
Digital
Transformation
Resources
More Information - http://wso2.com/solutions/financial/open-banking/
Try out WSO2 Open Banking - https://openbanking.wso2.com
On Demand Webinars -
https://wso2.com/library/webinars/2017/09/open-banking-moving-banks-beyond-the-norm/
http://wso2.com/library/webinars/2017/08/wso2-open-banking-digital-transformation-through-
psd2/
Open Banking Whitepaper -
http://wso2.com/whitepapers/digital-transformation-through-psd2-and-open-banking/
Thank You!

Weitere ähnliche Inhalte

Was ist angesagt?

PSD2: Open Banking with APIs
PSD2: Open Banking with APIsPSD2: Open Banking with APIs
PSD2: Open Banking with APIs
Jason Bloomberg
 
Conformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
Conformidade & Muito mais - Uma Demo da solução WSO2 Open BankingConformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
Conformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
WSO2
 
2007 12 - gsma - pay-buy - business opportunty analysis
2007 12 - gsma - pay-buy - business opportunty analysis2007 12 - gsma - pay-buy - business opportunty analysis
2007 12 - gsma - pay-buy - business opportunty analysis
Boni
 

Was ist angesagt? (20)

[WSO2 Integration Summit Nairobi 2019] Case Study - Telkom Kenya
[WSO2 Integration Summit Nairobi 2019] Case Study - Telkom Kenya[WSO2 Integration Summit Nairobi 2019] Case Study - Telkom Kenya
[WSO2 Integration Summit Nairobi 2019] Case Study - Telkom Kenya
 
[APIdays Singapore 2019] API Management in a Istio Service Mesh with WSO2 API...
[APIdays Singapore 2019] API Management in a Istio Service Mesh with WSO2 API...[APIdays Singapore 2019] API Management in a Istio Service Mesh with WSO2 API...
[APIdays Singapore 2019] API Management in a Istio Service Mesh with WSO2 API...
 
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
 
API-first Integration for Microservices
API-first Integration for MicroservicesAPI-first Integration for Microservices
API-first Integration for Microservices
 
[WSO2Con EU 2017] How API Management at Suva is Helping in Reducing Costs to ...
[WSO2Con EU 2017] How API Management at Suva is Helping in Reducing Costs to ...[WSO2Con EU 2017] How API Management at Suva is Helping in Reducing Costs to ...
[WSO2Con EU 2017] How API Management at Suva is Helping in Reducing Costs to ...
 
PSD2: Open Banking with APIs
PSD2: Open Banking with APIsPSD2: Open Banking with APIs
PSD2: Open Banking with APIs
 
PSD2 & Open Banking: How to go from standards to implementation and compliance
PSD2 & Open Banking: How to go from standards to implementation and compliancePSD2 & Open Banking: How to go from standards to implementation and compliance
PSD2 & Open Banking: How to go from standards to implementation and compliance
 
[WSO2Con EU 2018] Blockchain in the Business API Ecosystem - API Consumption ...
[WSO2Con EU 2018] Blockchain in the Business API Ecosystem - API Consumption ...[WSO2Con EU 2018] Blockchain in the Business API Ecosystem - API Consumption ...
[WSO2Con EU 2018] Blockchain in the Business API Ecosystem - API Consumption ...
 
PSD2 & Open Banking
PSD2 & Open BankingPSD2 & Open Banking
PSD2 & Open Banking
 
Open Banking Platform - Intro
Open Banking Platform - IntroOpen Banking Platform - Intro
Open Banking Platform - Intro
 
What's New With WSO2 Open Banking
What's New With WSO2 Open BankingWhat's New With WSO2 Open Banking
What's New With WSO2 Open Banking
 
Conformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
Conformidade & Muito mais - Uma Demo da solução WSO2 Open BankingConformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
Conformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
 
Adapting to Change: An Overview of Successful Digital Businesses
Adapting to Change: An Overview of Successful Digital BusinessesAdapting to Change: An Overview of Successful Digital Businesses
Adapting to Change: An Overview of Successful Digital Businesses
 
2007 12 - gsma - pay-buy - business opportunty analysis
2007 12 - gsma - pay-buy - business opportunty analysis2007 12 - gsma - pay-buy - business opportunty analysis
2007 12 - gsma - pay-buy - business opportunty analysis
 
[APIdays Singapore 2019] Managing the API lifecycle with Open Source Technolo...
[APIdays Singapore 2019] Managing the API lifecycle with Open Source Technolo...[APIdays Singapore 2019] Managing the API lifecycle with Open Source Technolo...
[APIdays Singapore 2019] Managing the API lifecycle with Open Source Technolo...
 
apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...
apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...
apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...
 
OAuth and OpenID Connect for PSD2 and Third-Party Access
OAuth and OpenID Connect for PSD2 and Third-Party AccessOAuth and OpenID Connect for PSD2 and Third-Party Access
OAuth and OpenID Connect for PSD2 and Third-Party Access
 
Securing Access to SaaS Apps with WSO2 Identity Server
Securing Access to SaaS Apps with WSO2 Identity ServerSecuring Access to SaaS Apps with WSO2 Identity Server
Securing Access to SaaS Apps with WSO2 Identity Server
 
PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022PSD2: Implementing APIs that interoperate with ISO 20022
PSD2: Implementing APIs that interoperate with ISO 20022
 
Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation
 

Ähnlich wie Getting your API Management Strategy on Point for PSD2 Compliance

Ähnlich wie Getting your API Management Strategy on Point for PSD2 Compliance (20)

Frictionless Adaption of PSD2 with WSO2
Frictionless Adaption of PSD2 with WSO2Frictionless Adaption of PSD2 with WSO2
Frictionless Adaption of PSD2 with WSO2
 
Open Banking and PSD2: Are your APIs ready for external testing?
Open Banking and PSD2: Are your APIs ready for external testing?Open Banking and PSD2: Are your APIs ready for external testing?
Open Banking and PSD2: Are your APIs ready for external testing?
 
Wso2 italia open break session #4 open banking
Wso2 italia open break session #4 open bankingWso2 italia open break session #4 open banking
Wso2 italia open break session #4 open banking
 
Wso2 italia open break session #4 - OPEN BANKING
Wso2 italia open break session #4 - OPEN BANKINGWso2 italia open break session #4 - OPEN BANKING
Wso2 italia open break session #4 - OPEN BANKING
 
PSD2: Latvijas Komercbanku asociācijas pozīcija
PSD2: Latvijas Komercbanku asociācijas pozīcijaPSD2: Latvijas Komercbanku asociācijas pozīcija
PSD2: Latvijas Komercbanku asociācijas pozīcija
 
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
 
What’s New With WSO2 Open Banking?
What’s New With WSO2 Open Banking?What’s New With WSO2 Open Banking?
What’s New With WSO2 Open Banking?
 
API Management within a Microservice Architecture
API Management within a Microservice ArchitectureAPI Management within a Microservice Architecture
API Management within a Microservice Architecture
 
API Management Within a Microservices Architecture
API Management Within a Microservices Architecture API Management Within a Microservices Architecture
API Management Within a Microservices Architecture
 
Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...
Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...
Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...
 
The role of IAM in OpenBanking and where do we stand
The role of IAM in OpenBanking and where do we stand The role of IAM in OpenBanking and where do we stand
The role of IAM in OpenBanking and where do we stand
 
A blueprint for open banking standards in the United Kingdom
A blueprint for open banking standards in the United KingdomA blueprint for open banking standards in the United Kingdom
A blueprint for open banking standards in the United Kingdom
 
Achieving Predictable Success in Digital Transformation with the WSO2 Platform
Achieving Predictable Success in Digital Transformation with the WSO2 PlatformAchieving Predictable Success in Digital Transformation with the WSO2 Platform
Achieving Predictable Success in Digital Transformation with the WSO2 Platform
 
[Workshop] API-driven Integration
[Workshop] API-driven Integration[Workshop] API-driven Integration
[Workshop] API-driven Integration
 
#2 Finance MuleSoft Meetup - SWIFT GPI Use Case & Demo
#2 Finance MuleSoft Meetup - SWIFT GPI Use Case & Demo#2 Finance MuleSoft Meetup - SWIFT GPI Use Case & Demo
#2 Finance MuleSoft Meetup - SWIFT GPI Use Case & Demo
 
[WSO2 Integration Summit Singapore 2019] Achieving Predictable Success in Dig...
[WSO2 Integration Summit Singapore 2019] Achieving Predictable Success in Dig...[WSO2 Integration Summit Singapore 2019] Achieving Predictable Success in Dig...
[WSO2 Integration Summit Singapore 2019] Achieving Predictable Success in Dig...
 
[APIdays NY] Managing the usage of Asynchronous APIs: What does it take?
[APIdays NY] Managing the usage of Asynchronous APIs: What does it take?[APIdays NY] Managing the usage of Asynchronous APIs: What does it take?
[APIdays NY] Managing the usage of Asynchronous APIs: What does it take?
 
Digital Transformation for Karnataka Bank Through API-led Integration
Digital Transformation for Karnataka Bank Through API-led IntegrationDigital Transformation for Karnataka Bank Through API-led Integration
Digital Transformation for Karnataka Bank Through API-led Integration
 
PSD2: Making it actionable
PSD2: Making it actionablePSD2: Making it actionable
PSD2: Making it actionable
 
INTERFACE, by apidays - The UK Open Banking Story
INTERFACE, by apidays -  The UK Open Banking StoryINTERFACE, by apidays -  The UK Open Banking Story
INTERFACE, by apidays - The UK Open Banking Story
 

Mehr von WSO2

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Fueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected ProductsFueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected Products
WSO2
 
A Reference Methodology for Agile Digital Businesses
 A Reference Methodology for Agile Digital Businesses A Reference Methodology for Agile Digital Businesses
A Reference Methodology for Agile Digital Businesses
WSO2
 

Mehr von WSO2 (20)

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Accelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with PlatformlessAccelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with Platformless
 
How to Create a Service in Choreo
How to Create a Service in ChoreoHow to Create a Service in Choreo
How to Create a Service in Choreo
 
Ballerina Tech Talk - May 2023
Ballerina Tech Talk - May 2023Ballerina Tech Talk - May 2023
Ballerina Tech Talk - May 2023
 
Platform Strategy to Deliver Digital Experiences on Azure
Platform Strategy to Deliver Digital Experiences on AzurePlatform Strategy to Deliver Digital Experiences on Azure
Platform Strategy to Deliver Digital Experiences on Azure
 
GartnerITSymSessionSlides.pdf
GartnerITSymSessionSlides.pdfGartnerITSymSessionSlides.pdf
GartnerITSymSessionSlides.pdf
 
[Webinar] How to Create an API in Minutes
[Webinar] How to Create an API in Minutes[Webinar] How to Create an API in Minutes
[Webinar] How to Create an API in Minutes
 
Modernizing the Student Journey with Ethos Identity
Modernizing the Student Journey with Ethos IdentityModernizing the Student Journey with Ethos Identity
Modernizing the Student Journey with Ethos Identity
 
Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...
Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...
Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...
 
CIO Summit Berlin 2022.pptx.pdf
CIO Summit Berlin 2022.pptx.pdfCIO Summit Berlin 2022.pptx.pdf
CIO Summit Berlin 2022.pptx.pdf
 
Delivering New Digital Experiences Fast - Introducing Choreo
Delivering New Digital Experiences Fast - Introducing ChoreoDelivering New Digital Experiences Fast - Introducing Choreo
Delivering New Digital Experiences Fast - Introducing Choreo
 
Fueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected ProductsFueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected Products
 
A Reference Methodology for Agile Digital Businesses
 A Reference Methodology for Agile Digital Businesses A Reference Methodology for Agile Digital Businesses
A Reference Methodology for Agile Digital Businesses
 
Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)
Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)
Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)
 
Lessons from the pandemic - From a single use case to true transformation
 Lessons from the pandemic - From a single use case to true transformation Lessons from the pandemic - From a single use case to true transformation
Lessons from the pandemic - From a single use case to true transformation
 
Adding Liveliness to Banking Experiences
Adding Liveliness to Banking ExperiencesAdding Liveliness to Banking Experiences
Adding Liveliness to Banking Experiences
 
Building a Future-ready Bank
Building a Future-ready BankBuilding a Future-ready Bank
Building a Future-ready Bank
 
WSO2 API Manager Community Call - November 2021
WSO2 API Manager Community Call - November 2021WSO2 API Manager Community Call - November 2021
WSO2 API Manager Community Call - November 2021
 
[API World ] - Managing Asynchronous APIs
[API World ] - Managing Asynchronous APIs[API World ] - Managing Asynchronous APIs
[API World ] - Managing Asynchronous APIs
 
[API World 2021 ] - Understanding Cloud Native Deployment
[API World 2021 ] - Understanding Cloud Native Deployment[API World 2021 ] - Understanding Cloud Native Deployment
[API World 2021 ] - Understanding Cloud Native Deployment
 

Kürzlich hochgeladen

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 

Kürzlich hochgeladen (20)

08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 

Getting your API Management Strategy on Point for PSD2 Compliance

  • 1. WSO2 Open Banking Getting your API Management Strategy on Point for PSD2 Compliance Lalaji Sureshika Technical Lead, Financial Solutions
  • 2. Agenda ● Recap on PSD2 ● EBA Mandated Requirements for API Management in a Compliance Solution ● An API Management Checklist for PSD2 Compliance ● API Management Capabilities of WSO2 Open Banking ● Demo
  • 3. Payment Services Directive 2 EU Directive that applies to all Banks operating in the EU that regulates payment services throughout the EU, with a compliance deadline of January 2018
  • 4. What does PSD2 change? Bank A Bank B Bank C Merchant TPP (PISP/AISP) PSD2 Bank A Bank B Bank C Merchant XS2A - Access to Account NowNow
  • 5.
  • 6. EBA Mandated PSD2 Requirements ● Article 27 - Communication Interface ● Article 28 - Obligations for dedicated interface ● Article 29 - Certificates ● Article 30 - Security of communication session ● Article 31 -Data exchanges RTS SCA Assess and notify operational & security incidents based on ; ● Transactions Affected ● Service Downtime ● Payment Service Users Affected ● Economic Impact ● Other payment services affected more.. GL on Incident Reporting Guidelines for Payment Service Providers [PSPs] ● Risk Assessment ● Protection ○ Data and Systems Integrity & Confidentiality ○ Access Control ● Detection GL on Security Measures
  • 7. API Management Checklist for PSD2 Compliance Implement API ● Integration points with core-banking system Design & Manage API ● Design and manage capabilities of an API ● Interactive documentation support ● Analytics on API usage , API availability & performance measures ● API Security API Governance ● API lifecycle management ● API versioning Consume API ● Third Party Provider (TPP) registration ● Secured API access by TPP ● Business insights on usage ● Notifications for TPPs
  • 8. WSO2 Open Banking provides all the technology requirements that Banks need to create an “Open Banking” platform to be PSD2 compliant and as a result become a Digitally Transformed Bank. API Specification ○ API Definitions ○ WSO2 Open Banking Customer TPP (AISP/PISP) FinTech Merchants Core Banking Internal Payment Services Bank Internal Network ISO 8583 (TCP/IP) HTTP HTTPS Other Banks HTTPS
  • 9. WSO2 Open Banking - API Management Capabilities ● API Specifications Predefined API templates for : ○ Open Banking UK specification ○ STET API specification ○ Berlin Group NextGenPSD2 Or ○ Any custom API specification
  • 10. WSO2 Open Banking - API Management Capabilities ● Support for Different API Types ○ Private APIs - Within the bank ○ Partner APIs - Establish with the bank and a specific TPP ○ Open APIs - Open APIs to all trusted TPPs ● API Lifecycle Management ● API Security - OAuth2 ● Define API Policies - Throttling ,Access Control, Transport, API resources ● Trigger alerts based on abnormal TPP usage, API health , backend core banking system issues
  • 11. WSO2 Open Banking - API Management Capabilities ● TPP Accessible Developer Portal ○ TPP Onboarding ○ Explore APIs ○ Consume APIs with swagger ○ Provide access to sandbox and production API environments ● Integration points with core banking systems and other internal banking services ○ Supports different message protocols [ HTTP, TCP] , message types [REST/JSON] and message formats [ISO 8583, ISO 20022] ● API Monetization to create various revenue models ● API Analytics & Business Insights with dashboards
  • 12. WSO2 Open Banking Offerings for TPPs ● Onboarding Process ● Establish Secure Communication ● Explore and try out bank APIs ● Setting up sandbox testing ● Setting up production ● Acknowledge new API versions ● Business Insights
  • 13. Demo
  • 14. Login & Add Bank Login Page 2 Factor Authentication Customer Consent Initiation account info 1 2 3 4 302 5 Token 6 Get Accounts Information AISP Account Initiation -Process Flow
  • 15. Payment Initiation -Process Flow Credits to Dinosoft Labs from Noun Project Checkout Item Login Page 2 Factor Authentication Customer Consent Initiation payment info 1 2 3 4 PISP 302 5 Token 6 Payment Complete 7 Settlement
  • 16. WSO2 Open Banking ● API Manager ● API Security + SCA ● API Analytics ● API Monetization PSD2 Compliance ● API Integration ● Federated Authentication ● Fraud Detection ● API Analytics ● Dashboards TPP Provider ● Web/Mobile App Suite ● Insight Sales ● Required Integration Digital Transformation
  • 17. Resources More Information - http://wso2.com/solutions/financial/open-banking/ Try out WSO2 Open Banking - https://openbanking.wso2.com On Demand Webinars - https://wso2.com/library/webinars/2017/09/open-banking-moving-banks-beyond-the-norm/ http://wso2.com/library/webinars/2017/08/wso2-open-banking-digital-transformation-through- psd2/ Open Banking Whitepaper - http://wso2.com/whitepapers/digital-transformation-through-psd2-and-open-banking/