Federal WGs - Meeting Four Outcomes
During the weeks of September 12th and 19th, the Department of Finance held its fourth set of federal working group meetings on Accreditation, Liability, Privacy, and Security to develop Canada’s Open Banking Framework.
Highlights from each of those meetings can be found below:
Accreditation (WG met on September 20th):
Meeting Topic: Certification
- There was consensus that technical standards, security, scope, consent, and revocation flows should form part of the certification process.
- There was consensus that all ecosystem participants (including financial institutions that aren’t subject to accreditation) should require certification.
- Most participants stated that certification tests should apply uniformly for simplicity and consistency and maintain a level playing field.
- Some participants noted that it could vary on the role of the participants in the ecosystems, the size, the nature of participants (data providers vs. data recipients), and the type of services provided.
- There was agreement that an independent third-party attesting conformance to certification is preferred.
- There was consensus that certification should occasionally be refreshed. Reasons provided included a change in business model, accreditation revocation, changes to a participant’s technology stack, and if a certain amount of time had passed (i.e., 2-3 years).
Liability (WG met on September 14th):
Meeting Topic: Public Accountability
- There was consensus among participants to disclose complaints in line with the Financial Consumer Protection Framework. This would be uniformly applied.
- Participants agreed that the proactive reporting metrics for API performance captured by the UK and Australian regimes were sufficient. Additional areas where proactive reporting should be introduced include the health and efficiency of the ecosystem, number of users, number of complaints, and number of parties with accreditation revoked.
- The UK’s regime periodically reports on API call performance to provide consumers with information on the effectiveness of open banking platforms offered by data providers. Key metrics include average call response time, number of failed, rejected, and successful calls, and average API availability.
Privacy (WG on September 22nd):
Meeting Topic: Consent Standardization
- For the proposed customer wireframe journey, participants agreed that consent, authentication, and authorization should be standardized. There was also an emphasis on ensuring clear and easy-to-understand language.
- Participants noted that there should be flexibility for authentication methods as many organizations have their own process of authenticating customers.
- While participants were generally supportive of the customer journey, participants did suggest some changes (e.g., additional considerations may be given to cases with joint accounts).
- It was raised that small and medium-sized clients completing the journey would require additional time and consideration to be included in the framework. Cases of shared credentials or how to ensure appropriate access rights for different users were given as examples.
Security (WG met on September 15th):
Meeting Topic: Operational Risk
- In regards to governance requirements in relation to operation risk, participants listed requirements such as board oversight and visibility, assigning risk management responsibility to a senior leadership team member, documenting policies, and an independent audit function.
- While the Department of Finance initially proposed the three lines of defense model to manage operation risk, participants instead suggested the segregation of duties in a manner that considers proportionality and an organization’s capability and resources.
- Participants suggested baseline requirements based on risks posed by use cases instead of a prescribed approach (reasoning that the model would be short-lived given the constant evolution of use cases).
- Participants also noted that existing legislation and guidelines on operational risks, including the Retail Payments Activities Act, should be leveraged.
- Internal and external fraud, third-party risk, data and cyber security, consumer awareness, and technological threats were listed as operational risks that could threaten the open banking system.
- To demonstrate the appropriateness of their operational risk framework, participants suggested independent assurance from a third party and periodic self-assessment attested by senior leadership. Directive guidelines were noted to support self-assessments and penalties if it was carried on improperly.
- Challenges in implementing an operational risk framework included the size and resources of an organization, its maturity, the adequacy of implemented controls, and ensuring proper oversight risk.
The next federal working group meetings have not yet been scheduled. It is expected that they will wrap up early next year.
OBCC
On October 13th , the OBCC, with input from CCUA’s provincial committees, met to discuss questions posed to the fifth set of meetings for the Accreditation, Liability, and Privacy WGs. The meeting outcomes can be found here. The OBCC will be meeting next on November 3rd to discuss areas of the federal framework that haven’t yet been covered and areas that still need to be fleshed out (e.g., governance entity, cost to participate).
Open Banking Webinar Series
Thank you to those that joined CCUA’s two-part webinar series on Open Banking, which included speakers from CGI and FICANEX.
We have made the recording and slide deck of the first installment, Open Banking 101, available to our members. Due to limited time, some questions during the Q&A portion of the webinar went unanswered. The answers to those questions can be found here. The second installment of the series featured FICANEX presenting on Open Banking in Practice. We have also made the recording and slide deck available. We have also prepared answers to questions that went unanswered during the webinar. This can be accessed here.
If you have any questions on any of the items noted above or on open banking generally, please get in touch with Sabena Sandhu.
