From mid-April to early May, the Department of Finance held its sixth and final set of federal working group meetings on Accreditation, Security, Liability, and Privacy to develop Canada’s Open Banking Framework.
Highlights from each of those meetings can be found below:
Liability WG: Service Levels and Reciprocal Data Access (WG met on April 14th)
- Regarding service level elements that are critical to the success of the framework, most participants agreed that the sector would benefit from the implementation of detailed service level requirements. The reasoning behind this included the potential for enforcement against sector participants that fail to meet them, as well as the importance that such metrics will play as the system evolves to new offerings.
- Participants suggested service level metrics related to availability, latency, and data quality. The importance of publicly reporting these metrics was also stressed. Some participants proposed parity as a service level, meaning third parties can access data on the same terms that consumers enjoy.
- Most participants identified data quality, availability, and latency as challenging to implement while also recognizing their importance in the sector.
- It was also proposed to start by requiring parity with digital channels before outlining other service level requirements.
- There was general consensus that service levels should apply uniformly across participants, with a caveat that certain metrics would have to factor in the size and capabilities of a participant.
- Regarding challenges in implementing reciprocity among sector participants, the major challenges identified included technology and resource limitations for smaller organizations. Participants also warned of the impact on reciprocity where sector scope is not clearly defined.
- Participants did not identify any barriers to entry stemming from reciprocity.
Privacy WG: Common Rules to Protect Vulnerable Consumers (WG met on April 17th)
- On accessibility, participants proposed customer service platforms made available in multiple languages and across different channels, including call-in services or in-person guidance and services.
- Participants recognized that vulnerable populations face systemic barriers that cannot be solved solely by open banking, for example, broadband access in remote communities. Participants discussed the importance of creating a system inclusive of all entity types.
- The activities or types of entities that may need to be limited or restricted for consumer protection included data brokers and organizations that collect information targeting consumers. It was also suggested that a principles-based approach could focus on restricting entities that don’t support positive consumer outcomes instead of specific organizations.
- Participants agreed that strong and consistent accreditation criteria would help ensure sound market conduct from all entities.
- There was consensus that default options should be set to protect consumers and that consent shouldn’t be presumed or implied but should be explicit and by “opt-in”.
- Participants agreed that ongoing consumer education is important though a staged approach was suggested to avoid overwhelming consumers with information.
- Participants agreed that the initial focus should be to provide foundational information with education efforts advancing as the system evolves.
- Examples of consumer education topics provided included fraud, cybersecurity, measures in place to protect consumers, and the value proposition of open banking.
- Participants agreed that consumer education should be a shared responsibility and sought partnership opportunities with consumer agencies.
Security WG: Ongoing Reporting Requirements (WG met on April 18th)
- There was consensus that an organization should attest to the soundness of its security requirements annually. Participants added that this requirement should apply uniformly, regardless of the service provided.
- There was consensus that organizations can self-attest annually with third-party assurance provided at intervals thereafter. Parallels were drawn with the SWIFT model of attestation and third-party assurance.
- Participants agreed that security reporting should apply uniformly to all system entities. The need for transparency, visibility, and the communication of information to build trust among ecosystem participants was also highlighted.
- Regarding how the sector should address instances where a participant reports a finding in the context of its ongoing reporting obligations, there was consensus that automatic suspension may be an overly strict response.
- Participants also discussed the need to assess instances on an individual basis before making a decision on suspension or revocation, with consideration for the severity of the issue, speed of response to address it, and the status of containment and remediation plans in place.
Accreditation WG: Accreditation Process and Maintaining Accreditation (WG met on May 1st)
- While recognizing that clarity on final accreditation requirements would be a factor, participants agreed with a three-month timeline for an accreditation process, noting the precedent set by Australia and the UK.
- It was noted that an initial accreditation could take longer due to an influx of applications. There was consensus that cost should not be an impediment for applicants to join the system.
- In terms of information that should be made publicly available about an accredited entity, participants agreed on the need to focus on the intended policy outcomes of the information being disclosed, as well as how this information would help consumers. There was consensus that only general corporate registry type of information (e.g., ownership structure), accreditation type (if applicable), and status should be made publicly available.
- There was a general consensus that no information on a rejected application should be publicized, and that guidance could clarify expectations and lead to better prepared future applications (though the guidance should be anonymized and not attributable to an organization).
- There was general consensus that an applicant should renew accreditation at defined intervals or at the occurrence of certain events, such as a material change in the business, provided such events are clearly defined. With that said, certain participants did advocate for ongoing reporting obligations.
- In terms of circumstances where accreditation could be revoked or suspended, there was consensus that certain events create a serious risk to the system including, where an organization: fails to meet accreditation requirements following their initial assessment; fails to make information available in accordance with service levels such as availability; makes a misrepresentation in the accreditation process; or is subject to a final finding of unlawful behaviour by a regulator or court on a matter related to open banking.
- There was further consensus that organizations should be given the opportunity to remediate certain events before the revocation or suspension of their accreditation status.
While the federal WGs, and the formal consultation phase of the development of the framework, have now concluded, the Department of Finance will be holding at least one more Steering Committee meeting. All participants of the federal WGs will be invited to attend the Steering Committee, which acts as a body for Canada’s Open Banking Lead to provide general updates and progress. The date of the next Steering Committee meeting has not yet been released.
CCUA's Open Banking Collaboration Committee (OBCC)
The OBCC met in April and, with input from CCUA’s provincial committees, developed positions for the questions posed to the Liability, Privacy, and Accreditation WGs. The meeting outcomes can be found here.
CCUA and LCUC also collaborated in May on a submission to the Department of Finance outlining key credit union policy positions for the Canadian Open Banking Framework. Key recommendations include:
- Providing provincial regulators and credit unions with a draft version of the framework with the opportunity to comment before it is finalized.
- Providing further clarity around the provincial regulator ‘veto’.
You can read the submission here.
Open Banking Webinar Series
Please join us on June 23rd and June 27th for the final episodes of the six-part CCUA-CGI Open Banking Webinar Series. Registration details, as well as the recordings and slide decks of previous episodes, can be found here. If you have any questions on any of the items noted above or on open banking generally, please contact Sabena Sandhu.