EBA欧洲银行-Issues-I-to-III-raised-by-EBA-WG-API_4页_291kb
报告摘要
EBA Clarifications on Issues I to III from the Working Group on APIs under PSD2
Core Content Overview
The European Banking Authority (EBA) published clarifications on three key issues raised by participants in the Working Group on APIs under the second Payment Services Directive (PSD2). These clarifications aim to provide guidance on the implementation of technical and operational requirements for Account Servicing Payment Service Providers (ASPSPs) and Third Party Providers (TPPs), particularly in the context of testing, alignment of functionalities, and the availability of qualified trust service providers (QTSPs) issuing PSD2 eIDAS certificates.
Issue I: Testing Environment
Main Concern
Participants expressed concerns regarding the reliability, depth, and ease of testing for third party providers (TPPs), including account information service providers (AISPs), payment initiation service providers (PISPs), and card-based payment instrument issuers (CBPIIs).
Key Points
- Article 30(5) of the Commission Delegated Regulation (EU) 2018/389 requires ASPSPs to provide a testing facility and support for TPPs.
- The documentation must include technical specifications of the dedicated interface, specifying routines, protocols, and tools for interoperability.
- While automatic testing is not mandatory, ASPSPs are encouraged to enable it to reduce support burden and improve testing outcomes.
- Machine-readable format for documentation is recommended to streamline the testing process and support the exemption process from the fallback mechanism.
- The competent authority (CA) must be informed of TPP usage and any issues encountered during testing.
- The exemption process considers the wide usage of the production interface, which is linked to the testing phase.
Recommendations
- ASPSPs should ensure the testing environment is functionally aligned with the production interface.
- TPPs are encouraged to participate in testing and report issues to ASPSPs to ensure a high-performing interface.
Issue II: Alignment of Functionalities and Data Requirements
Main Concern
Participants highlighted disparities in functionalities and data requirements across different API initiatives, suggesting the need for a survey to standardise and clarify these aspects.
Key Points
- Article 30(3) of the RTS on SCA & CSC mandates ASPSPs to provide technical documentation at least 6 months before the application date of the RTS (i.e., by 14 March 2019).
- This documentation is crucial for market transparency and helps TPPs understand the functionalities available through APIs.
- The EBA recommends that API initiatives survey ASPSPs to compare and publish the functionalities supported.
- This will help market participants, especially TPPs, to identify differences and align their systems accordingly.
Issue III: Qualified Trust Service Providers (QTSPs) Issuing PSD2 eIDAS Certificates
Main Concern
Industry participants raised concerns about the lack of clarity on which QTSPs issue PSD2 eIDAS certificates, and that the list on the European Commission's website is not machine-readable.
Key Points
-
The EBA understands that the QTSP list on the European Commission website is in machine-readable format, but it does not specify whether a QTSP provides PSD2 eIDAS certificates.
-
QTSPs must contact national supervisory bodies and undergo a national accreditation process to become authorised.
-
The EBA has approached QTSPs to determine if they issue or intend to issue eIDAS certificates for PSD2 and test certificates.
-
The following QTSPs are confirmed to issue eIDAS certificates for PSD2 purposes:
- Aruba Posta Elettronica Certificata S.p.A. (Italy)
- Buypass AS (Norway)
- Evrotrust Technologies JSC (Bulgaria)
- First certification authority, a.s. (Czech Republic)
- InfoCert S.p.A. (Italy)
- Krajowa Izba Rozliczeniowa S.A. (Poland)
- LuxTrust S.A. (Luxembourg)
- Microsec Micro Software Engineering & Consulting Private Company Limited by Shares (Hungary)
- MULTICERT - Serviços de Certificação Electrónica S.A. (Portugal)
- NETLOCK Informatics and Network Privacy services Limited Company (Hungary)
-
Additional QTSPs issue test certificates but have not yet started issuing PSD2 eIDAS certificates:
- Bundesdruckerei GmbH (D-Trust GmbH) (Germany)
- FINA - Financijska agencija (Croatia)
- CERTSIGN S.A. (Romania)
- Bank-Verlag (Germany)
Notes
- The list is not exhaustive and may change.
- Several other QTSPs are expected to start issuing eIDAS certificates in the near future.
- The EBA encourages market participants to monitor the list and contact QTSPs for more details.
Summary of EBA's Position
The EBA emphasizes that:
- ASPSPs have a legal obligation to provide testing support and technical documentation.
- Machine-readable formats and automated testing are encouraged to enhance efficiency and transparency.
- QTSPs are central to the PSD2 compliance process, and the EBA is working to clarify their status and certification capabilities.
- Market alignment and standardization are key to ensuring smooth API integration and interoperability.
试读结束,高清完整版pdf/doc/ppt,请点下载