Skip links

Brazilians Welcome Open Banking

In the two years since open banking was approved by Brazil’s Central Bank, there has been a great deal of progress, despite a few set backs. Here, we look at how CIP, in partnership with Banfico, is helping spearhead the change. Originally due to be

Deadline Extension for Strong Customer Authentication

Strong Customer Authentication (SCA) is a key part of the Second Payment Services Directive (PSD2) and a vital measure to counteract the rise in online fraud. As the new security framework for digital payments, SCA has been a long time coming – and now the

Confirmation of Payee: Why It Should Be Mandatory

The growth of online banking and payments has seen a corresponding rise in fraud. Scammers have become increasingly adept at exploiting vulnerabilities in digital transactions, and one of the most alarming trends over the past decade has been the increase in Authorized Push Payment (APP)

Brexit and eIDAS Revocation

eIDAS & ETSI TS 119 495 Standard & PSD2 RTS The eIDAS Regulation is Regulation (EU) 910/2014 on electronic identification and trust services for electronic transactions in the internal market. The Regulation applies from 1 July 2016 for most part of its articles. The Directive

SMS OTP – PSD2 SCA Compliant or Not?

This is probably simple topic but banks have put lot of efforts into its discussion of whether SMS/OTP is RTS-SCA compliant or not. Arguments still carries on from two perspectives - authentication element (possession) & secure channel. For now EBA (5th Oct) has clarified that

Separation of Concerns – IAM and API Management

Often PSD2 Implementation is focused around API Management. Identity & Access Management (IAM) is much more critical to PSD2 Implementation. Below post justifies importance to handling IAM functionalities in such regulatory program. PSD2 Implementation Two major aspects of the program are: Identity & Access Management