SlideShare a Scribd company logo
The Industry Standard for Consumer
Access to Financial Records
CATTS out of the bag.
Bringing uniformity to financial industry APIs
Jean-Paul LaClair, Sr Director of Product
May 16, 2023
In our quest for more convenience in our
financial lives, our financial lives have
become more complex to manage.
CATTS out of the bag. So what?
The Industry Standard for Consumer Access to Financial Records
3
FDX Confidential. All rights reserved.
An end consumer’s desires begins to disintermediate
financial services
The situation with data sharing
Plus...
Insurance
Borrowing (student loans,
car loans, mortgages…)
The Industry Standard for Consumer Access to Financial Records
Where it all started…
5
FDX Confidential. All rights reserved.
Software was developed in the 1990s that
could log in for you, gather the data (screen
scrape), and combine all the data into a
single interface; but required consumers to
share their IDs and Passwords
Consumers with accounts at multiple
banks had to manually combine the data.
The situation with data sharing
The Industry Standard for Consumer Access to Financial Records
And where it’s likely to go
6
FDX Confidential. All rights reserved.
The situation with data sharing
Volume of data created, captured, copied,
and consumed worldwide from 2010 to
2020, with forecasts from 2021 to 2025
© Statista 2023
(in zettabytes)
More options to manage finances
More complex financial lives
More creation, consumption, and storage of data
More data sharing
RED ALERT
Things are getting complicated
The Industry Standard for Consumer Access to Financial Records
Screen scraping requires sharing credentials
9
FDX Confidential. All rights reserved.
Red alert… that situation is causing complications
Customer provides
credentials to a 3rd party
3rd party uses the credentials to log-in and scrape data.
They can see ANY data the customer can see today.
The Industry Standard for Consumer Access to Financial Records
Credential-based data sharing
10
FDX Confidential. All rights reserved.
Red alert… that situation is causing complications
Consider the impact to the Banking Industry’s Infrastructure, Cyber Posture, and Privacy Posture
Rules of Thirds
• Approximately 1/3 of financial
institution customers share their
financial data with third parties1
• This equates to at least 100 million
U.S. consumers
Financial institution online traffic is,
on average1,2:
Just how big is it…?
11
Popular FinTech app breached.
Millions of member IDs and PWs in
paste bins all over the dark web.
- June 1, 2023
…Chief Privacy Officer is on Line 1
…Board Risk Committee Chair is on Line 2
…60 Minutes is on Line 3
…Brian Krebs is calling your cell
How many of our customers were affected? We don’t know, maybe as much as 15-20%. Customer data has been confirmed in multiple
paste bins and call center call volume is intensifying.
What data was at risk? Anything the customer’s eye can see, including PII and full account numbers.
Are we seeing an increase in ATO and Fraud? There is an uptick, but attribution is not certain.
What are we doing about it? We have blocked that app with our WAF, our SOC is monitoring things closely, and we are in contact with our
peers and industry groups for signals and signature sharing and will reset compromised accounts and offer a year of privacy monitoring.
How many of our customers were affected? None. We converted from credentials-based access to token based last year using FDX.
Should the app itself become an issue, exactly nn,nnn customers use the app and we can revoke one or all tokens at any time with no
impact to their access to our online bank or our mobile app.
What data was at risk? Only the following fields were permissioned to the app: xx, yy, zz,
Are we seeing an increase in ATO and Fraud? No. No credentials were lost, and customer data was limited to the minimum the app
needed to function.
What are we doing about it? We have blocked that app from our API using our ACL and WAF, our SOC is monitoring things closely, and we
are in contact with our peers and industry groups for signals and signature sharing. Any tokens lost are unusable by external actors. Our
Fraud and Info Sec teams are engaged with the app for forensic review and remediation steps as we are both FDX members.
Which of these two conversations do you want to have with the callers?
Future
FICTIONAL
Headline
The Industry Standard for Consumer Access to Financial Records
Lack of interoperability
12
FDX Confidential. All rights reserved.
Red alert… that situation is causing complications
Let the CATTS out of the bag
The Industry Standard for Consumer Access to Financial Records
FDX is an international, nonprofit technical standards body dedicated to unifying the financial
industry around a common, interoperable, royalty-free standard for the secure access of
permissioned consumer and business financial data, the FDX API.
© FDX, all rights reserved
FDX does not comment on policy or engage in lobbying.
User Experience
Security
Certification
API & Data Structures
FDX Specifications v5.2.1
FDX is a subsidiary of FS-ISAC.
Financial Data Exchange – A Standard
Our Members
> 230 members | ¼ of members are Fin-Tech firms | 2/3 are not banks | 1/3 are Canadian
Our Leadership
Our Board comprises 12 Financial Institutions, 5 Permissioned Parties, 5 Aggregators, 2
Industry Groups, FS-ISAC, 1 Canadian Fintech, 1 Canadian Financial Institution and 1
Consumer Advocacy Group observer.
Our Adoption
53 Million Consumer Accounts using FDX API as of Spring 2023
The Industry Standard for Consumer Access to Financial Records
A Market Standard
15
FDX Confidential. All rights reserved.
Technology Regulation
Standardized
Payload
Connectivity
Security
& Auth
User Experience
Industry (the How) Government (the What)
80 kph
50 mph
Technology Regulation
User
Experience
Connectivity
(TLS)
Security &
Authentication
(FAPI & FIDO)
Payload
(JSON)
JSON just tells us the type of object the truck is carrying – e.g., a shipping container.
The contents can be anything the sender and receiver agree on:
FDX format, ISO 20022 Format, IRS Tax (FIRE), or proprietary.
Components of the FDX Standard
Security & Authentication Stack
The Industry Standard for Consumer Access to Financial Records
Principles for Consumer-Permissioned Data Sharing
18
FDX Confidential. All rights reserved.
AKA: CATTS C
A
T
T
S
The Industry Standard for Consumer Access to Financial Records
FDX Specifications
19
FDX Confidential. All rights reserved.
API and Data Structures
1. Components
2. Core information – Accounts
and Transactions
3. Customer Information
4. Consent, Recipient Registration
5. Tax, Money Movement,
Metrics, Events, Fraud, and
Registry
User Experience
1. UX Guidelines – Consent Grant,
Notification, Viewing, and
Revocation
2. Data Clusters Mapping
3. Taxonomy
Security
1. Security Model (AuthN &
AuthZ), Security for Sensitive
Data, Secure App Onboarding
2. Control Consideration
3. Recipient Registration
Guidelines
Certification
1. Provider Requirements
2. Recipient Requirements
3. Data Access Platform
Requirements
4. Certification Use Cases
5. Certification Model
What else…
Join us
The Industry Standard for Consumer Access to Financial Records
22
FDX Confidential. All rights reserved.

More Related Content

Similar to apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX

FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in EuropeFIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO Alliance
 
Karza Technologies
Karza TechnologiesKarza Technologies
Karza Technologies
KarzaTechnologies
 
Log Management for PCI Compliance [OLD]
Log Management for PCI Compliance [OLD]Log Management for PCI Compliance [OLD]
Log Management for PCI Compliance [OLD]
Anton Chuvakin
 
apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...
apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...
apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...
apidays
 
Solving the Encryption Conundrum in Financial Services
Solving the Encryption Conundrum in Financial ServicesSolving the Encryption Conundrum in Financial Services
Solving the Encryption Conundrum in Financial Services
Echoworx
 
Growing trend of finding2013-11 Growing Trend of Finding Regulatory and Tort ...
Growing trend of finding2013-11 Growing Trend of Finding Regulatory and Tort ...Growing trend of finding2013-11 Growing Trend of Finding Regulatory and Tort ...
Growing trend of finding2013-11 Growing Trend of Finding Regulatory and Tort ...
Raleigh ISSA
 
New regulations and the evolving cybersecurity technology landscape
New regulations and the evolving cybersecurity technology landscapeNew regulations and the evolving cybersecurity technology landscape
New regulations and the evolving cybersecurity technology landscape
Ulf Mattsson
 
Payment Security Market by Product Type, Distribution Channel, End User 2024-...
Payment Security Market by Product Type, Distribution Channel, End User 2024-...Payment Security Market by Product Type, Distribution Channel, End User 2024-...
Payment Security Market by Product Type, Distribution Channel, End User 2024-...
IMARC Group
 
apidays New York 2022 - Discussing the significance of API standardization, D...
apidays New York 2022 - Discussing the significance of API standardization, D...apidays New York 2022 - Discussing the significance of API standardization, D...
apidays New York 2022 - Discussing the significance of API standardization, D...
apidays
 
Breached! The First 48
Breached! The First 48Breached! The First 48
Breached! The First 48
Resilient Systems
 
20 Questions to ask your Cyber Carrier - Wis Banker 12-2015
20 Questions to ask your Cyber Carrier - Wis Banker 12-201520 Questions to ask your Cyber Carrier - Wis Banker 12-2015
20 Questions to ask your Cyber Carrier - Wis Banker 12-2015
Jeff Otteson
 
George Gavras 2010 Fowler Seminar
George Gavras 2010 Fowler SeminarGeorge Gavras 2010 Fowler Seminar
George Gavras 2010 Fowler Seminar
Don Grauel
 
United States Lawful Interception Market PPT: Demand, Trends and Business Opp...
United States Lawful Interception Market PPT: Demand, Trends and Business Opp...United States Lawful Interception Market PPT: Demand, Trends and Business Opp...
United States Lawful Interception Market PPT: Demand, Trends and Business Opp...
IMARC Group
 
Global Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationGlobal Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong Authentication
FIDO Alliance
 
FTC Protecting Info A Guide For Business Powerpoint
FTC  Protecting  Info A  Guide  For  Business  PowerpointFTC  Protecting  Info A  Guide  For  Business  Powerpoint
FTC Protecting Info A Guide For Business Powerpoint
Bucacci Business Solutions
 
About Data Quality And Regulatory Compliance at FI - Shield
About Data Quality And Regulatory Compliance at FI - ShieldAbout Data Quality And Regulatory Compliance at FI - Shield
About Data Quality And Regulatory Compliance at FI - Shield
Shield
 
Corporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber SecurityCorporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber Security
Joan Weber
 
Legal issues in technology
Legal issues in technologyLegal issues in technology
Legal issues in technology
EzraGray1
 

Similar to apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX (18)

FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in EuropeFIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
 
Karza Technologies
Karza TechnologiesKarza Technologies
Karza Technologies
 
Log Management for PCI Compliance [OLD]
Log Management for PCI Compliance [OLD]Log Management for PCI Compliance [OLD]
Log Management for PCI Compliance [OLD]
 
apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...
apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...
apidays LIVE New York 2021 - Security Design Patterns that Protect Sensitive ...
 
Solving the Encryption Conundrum in Financial Services
Solving the Encryption Conundrum in Financial ServicesSolving the Encryption Conundrum in Financial Services
Solving the Encryption Conundrum in Financial Services
 
Growing trend of finding2013-11 Growing Trend of Finding Regulatory and Tort ...
Growing trend of finding2013-11 Growing Trend of Finding Regulatory and Tort ...Growing trend of finding2013-11 Growing Trend of Finding Regulatory and Tort ...
Growing trend of finding2013-11 Growing Trend of Finding Regulatory and Tort ...
 
New regulations and the evolving cybersecurity technology landscape
New regulations and the evolving cybersecurity technology landscapeNew regulations and the evolving cybersecurity technology landscape
New regulations and the evolving cybersecurity technology landscape
 
Payment Security Market by Product Type, Distribution Channel, End User 2024-...
Payment Security Market by Product Type, Distribution Channel, End User 2024-...Payment Security Market by Product Type, Distribution Channel, End User 2024-...
Payment Security Market by Product Type, Distribution Channel, End User 2024-...
 
apidays New York 2022 - Discussing the significance of API standardization, D...
apidays New York 2022 - Discussing the significance of API standardization, D...apidays New York 2022 - Discussing the significance of API standardization, D...
apidays New York 2022 - Discussing the significance of API standardization, D...
 
Breached! The First 48
Breached! The First 48Breached! The First 48
Breached! The First 48
 
20 Questions to ask your Cyber Carrier - Wis Banker 12-2015
20 Questions to ask your Cyber Carrier - Wis Banker 12-201520 Questions to ask your Cyber Carrier - Wis Banker 12-2015
20 Questions to ask your Cyber Carrier - Wis Banker 12-2015
 
George Gavras 2010 Fowler Seminar
George Gavras 2010 Fowler SeminarGeorge Gavras 2010 Fowler Seminar
George Gavras 2010 Fowler Seminar
 
United States Lawful Interception Market PPT: Demand, Trends and Business Opp...
United States Lawful Interception Market PPT: Demand, Trends and Business Opp...United States Lawful Interception Market PPT: Demand, Trends and Business Opp...
United States Lawful Interception Market PPT: Demand, Trends and Business Opp...
 
Global Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationGlobal Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong Authentication
 
FTC Protecting Info A Guide For Business Powerpoint
FTC  Protecting  Info A  Guide  For  Business  PowerpointFTC  Protecting  Info A  Guide  For  Business  Powerpoint
FTC Protecting Info A Guide For Business Powerpoint
 
About Data Quality And Regulatory Compliance at FI - Shield
About Data Quality And Regulatory Compliance at FI - ShieldAbout Data Quality And Regulatory Compliance at FI - Shield
About Data Quality And Regulatory Compliance at FI - Shield
 
Corporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber SecurityCorporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber Security
 
Legal issues in technology
Legal issues in technologyLegal issues in technology
Legal issues in technology
 

More from apidays

Apidays Helsinki 2024 - Sustainable IT and API Performance - How to Bring The...
Apidays Helsinki 2024 - Sustainable IT and API Performance - How to Bring The...Apidays Helsinki 2024 - Sustainable IT and API Performance - How to Bring The...
Apidays Helsinki 2024 - Sustainable IT and API Performance - How to Bring The...
apidays
 
Apidays Helsinki 2024 - APIs ahoy, the case of Customer Booking APIs in Finn...
Apidays Helsinki 2024 -  APIs ahoy, the case of Customer Booking APIs in Finn...Apidays Helsinki 2024 -  APIs ahoy, the case of Customer Booking APIs in Finn...
Apidays Helsinki 2024 - APIs ahoy, the case of Customer Booking APIs in Finn...
apidays
 
Apidays Helsinki 2024 - From Chaos to Calm- Navigating Emerging API Security...
Apidays Helsinki 2024 -  From Chaos to Calm- Navigating Emerging API Security...Apidays Helsinki 2024 -  From Chaos to Calm- Navigating Emerging API Security...
Apidays Helsinki 2024 - From Chaos to Calm- Navigating Emerging API Security...
apidays
 
Apidays Helsinki 2024 - What is next now that your organization created a (si...
Apidays Helsinki 2024 - What is next now that your organization created a (si...Apidays Helsinki 2024 - What is next now that your organization created a (si...
Apidays Helsinki 2024 - What is next now that your organization created a (si...
apidays
 
Apidays Helsinki 2024 - There’s no AI without API, but what does this mean fo...
Apidays Helsinki 2024 - There’s no AI without API, but what does this mean fo...Apidays Helsinki 2024 - There’s no AI without API, but what does this mean fo...
Apidays Helsinki 2024 - There’s no AI without API, but what does this mean fo...
apidays
 
Apidays Helsinki 2024 - Security Vulnerabilities in your APIs by Lukáš Ďurovs...
Apidays Helsinki 2024 - Security Vulnerabilities in your APIs by Lukáš Ďurovs...Apidays Helsinki 2024 - Security Vulnerabilities in your APIs by Lukáš Ďurovs...
Apidays Helsinki 2024 - Security Vulnerabilities in your APIs by Lukáš Ďurovs...
apidays
 
Apidays Helsinki 2024 - Data, API’s and Banks, with AI on top by Sergio Giral...
Apidays Helsinki 2024 - Data, API’s and Banks, with AI on top by Sergio Giral...Apidays Helsinki 2024 - Data, API’s and Banks, with AI on top by Sergio Giral...
Apidays Helsinki 2024 - Data, API’s and Banks, with AI on top by Sergio Giral...
apidays
 
Apidays Helsinki 2024 - Data Ecosystems Driving the Green Transition by Olli ...
Apidays Helsinki 2024 - Data Ecosystems Driving the Green Transition by Olli ...Apidays Helsinki 2024 - Data Ecosystems Driving the Green Transition by Olli ...
Apidays Helsinki 2024 - Data Ecosystems Driving the Green Transition by Olli ...
apidays
 
Apidays Helsinki 2024 - Bridging the Gap Between Backend and Frontend API Tes...
Apidays Helsinki 2024 - Bridging the Gap Between Backend and Frontend API Tes...Apidays Helsinki 2024 - Bridging the Gap Between Backend and Frontend API Tes...
Apidays Helsinki 2024 - Bridging the Gap Between Backend and Frontend API Tes...
apidays
 
Apidays Helsinki 2024 - API Compliance by Design by Marjukka Niinioja, Osaango
Apidays Helsinki 2024 - API Compliance by Design by Marjukka Niinioja, OsaangoApidays Helsinki 2024 - API Compliance by Design by Marjukka Niinioja, Osaango
Apidays Helsinki 2024 - API Compliance by Design by Marjukka Niinioja, Osaango
apidays
 
Apidays Helsinki 2024 - ABLOY goes API economy – Transformation story by Hann...
Apidays Helsinki 2024 - ABLOY goes API economy – Transformation story by Hann...Apidays Helsinki 2024 - ABLOY goes API economy – Transformation story by Hann...
Apidays Helsinki 2024 - ABLOY goes API economy – Transformation story by Hann...
apidays
 
Apidays New York 2024 - The subtle art of API rate limiting by Josh Twist, Zuplo
Apidays New York 2024 - The subtle art of API rate limiting by Josh Twist, ZuploApidays New York 2024 - The subtle art of API rate limiting by Josh Twist, Zuplo
Apidays New York 2024 - The subtle art of API rate limiting by Josh Twist, Zuplo
apidays
 
Apidays New York 2024 - RESTful API Patterns and Practices by Mike Amundsen, ...
Apidays New York 2024 - RESTful API Patterns and Practices by Mike Amundsen, ...Apidays New York 2024 - RESTful API Patterns and Practices by Mike Amundsen, ...
Apidays New York 2024 - RESTful API Patterns and Practices by Mike Amundsen, ...
apidays
 
Apidays New York 2024 - Putting AI into API Security by Corey Ball, Moss Adams
Apidays New York 2024 - Putting AI into API Security by Corey Ball, Moss AdamsApidays New York 2024 - Putting AI into API Security by Corey Ball, Moss Adams
Apidays New York 2024 - Putting AI into API Security by Corey Ball, Moss Adams
apidays
 
Apidays New York 2024 - Prototype-first - A modern API development workflow b...
Apidays New York 2024 - Prototype-first - A modern API development workflow b...Apidays New York 2024 - Prototype-first - A modern API development workflow b...
Apidays New York 2024 - Prototype-first - A modern API development workflow b...
apidays
 
Apidays New York 2024 - Post-Quantum API Security by Francois Lascelles, Broa...
Apidays New York 2024 - Post-Quantum API Security by Francois Lascelles, Broa...Apidays New York 2024 - Post-Quantum API Security by Francois Lascelles, Broa...
Apidays New York 2024 - Post-Quantum API Security by Francois Lascelles, Broa...
apidays
 
Apidays New York 2024 - Increase your productivity with no-code GraphQL mocki...
Apidays New York 2024 - Increase your productivity with no-code GraphQL mocki...Apidays New York 2024 - Increase your productivity with no-code GraphQL mocki...
Apidays New York 2024 - Increase your productivity with no-code GraphQL mocki...
apidays
 
Apidays New York 2024 - Driving API & EDA Success by Marcelo Caponi, Danone
Apidays New York 2024 - Driving API & EDA Success by Marcelo Caponi, DanoneApidays New York 2024 - Driving API & EDA Success by Marcelo Caponi, Danone
Apidays New York 2024 - Driving API & EDA Success by Marcelo Caponi, Danone
apidays
 
Apidays New York 2024 - Build a terrible API for people you hate by Jim Benne...
Apidays New York 2024 - Build a terrible API for people you hate by Jim Benne...Apidays New York 2024 - Build a terrible API for people you hate by Jim Benne...
Apidays New York 2024 - Build a terrible API for people you hate by Jim Benne...
apidays
 
Apidays New York 2024 - API Secret Tokens Exposed by Tristan Kalos and Antoin...
Apidays New York 2024 - API Secret Tokens Exposed by Tristan Kalos and Antoin...Apidays New York 2024 - API Secret Tokens Exposed by Tristan Kalos and Antoin...
Apidays New York 2024 - API Secret Tokens Exposed by Tristan Kalos and Antoin...
apidays
 

More from apidays (20)

Apidays Helsinki 2024 - Sustainable IT and API Performance - How to Bring The...
Apidays Helsinki 2024 - Sustainable IT and API Performance - How to Bring The...Apidays Helsinki 2024 - Sustainable IT and API Performance - How to Bring The...
Apidays Helsinki 2024 - Sustainable IT and API Performance - How to Bring The...
 
Apidays Helsinki 2024 - APIs ahoy, the case of Customer Booking APIs in Finn...
Apidays Helsinki 2024 -  APIs ahoy, the case of Customer Booking APIs in Finn...Apidays Helsinki 2024 -  APIs ahoy, the case of Customer Booking APIs in Finn...
Apidays Helsinki 2024 - APIs ahoy, the case of Customer Booking APIs in Finn...
 
Apidays Helsinki 2024 - From Chaos to Calm- Navigating Emerging API Security...
Apidays Helsinki 2024 -  From Chaos to Calm- Navigating Emerging API Security...Apidays Helsinki 2024 -  From Chaos to Calm- Navigating Emerging API Security...
Apidays Helsinki 2024 - From Chaos to Calm- Navigating Emerging API Security...
 
Apidays Helsinki 2024 - What is next now that your organization created a (si...
Apidays Helsinki 2024 - What is next now that your organization created a (si...Apidays Helsinki 2024 - What is next now that your organization created a (si...
Apidays Helsinki 2024 - What is next now that your organization created a (si...
 
Apidays Helsinki 2024 - There’s no AI without API, but what does this mean fo...
Apidays Helsinki 2024 - There’s no AI without API, but what does this mean fo...Apidays Helsinki 2024 - There’s no AI without API, but what does this mean fo...
Apidays Helsinki 2024 - There’s no AI without API, but what does this mean fo...
 
Apidays Helsinki 2024 - Security Vulnerabilities in your APIs by Lukáš Ďurovs...
Apidays Helsinki 2024 - Security Vulnerabilities in your APIs by Lukáš Ďurovs...Apidays Helsinki 2024 - Security Vulnerabilities in your APIs by Lukáš Ďurovs...
Apidays Helsinki 2024 - Security Vulnerabilities in your APIs by Lukáš Ďurovs...
 
Apidays Helsinki 2024 - Data, API’s and Banks, with AI on top by Sergio Giral...
Apidays Helsinki 2024 - Data, API’s and Banks, with AI on top by Sergio Giral...Apidays Helsinki 2024 - Data, API’s and Banks, with AI on top by Sergio Giral...
Apidays Helsinki 2024 - Data, API’s and Banks, with AI on top by Sergio Giral...
 
Apidays Helsinki 2024 - Data Ecosystems Driving the Green Transition by Olli ...
Apidays Helsinki 2024 - Data Ecosystems Driving the Green Transition by Olli ...Apidays Helsinki 2024 - Data Ecosystems Driving the Green Transition by Olli ...
Apidays Helsinki 2024 - Data Ecosystems Driving the Green Transition by Olli ...
 
Apidays Helsinki 2024 - Bridging the Gap Between Backend and Frontend API Tes...
Apidays Helsinki 2024 - Bridging the Gap Between Backend and Frontend API Tes...Apidays Helsinki 2024 - Bridging the Gap Between Backend and Frontend API Tes...
Apidays Helsinki 2024 - Bridging the Gap Between Backend and Frontend API Tes...
 
Apidays Helsinki 2024 - API Compliance by Design by Marjukka Niinioja, Osaango
Apidays Helsinki 2024 - API Compliance by Design by Marjukka Niinioja, OsaangoApidays Helsinki 2024 - API Compliance by Design by Marjukka Niinioja, Osaango
Apidays Helsinki 2024 - API Compliance by Design by Marjukka Niinioja, Osaango
 
Apidays Helsinki 2024 - ABLOY goes API economy – Transformation story by Hann...
Apidays Helsinki 2024 - ABLOY goes API economy – Transformation story by Hann...Apidays Helsinki 2024 - ABLOY goes API economy – Transformation story by Hann...
Apidays Helsinki 2024 - ABLOY goes API economy – Transformation story by Hann...
 
Apidays New York 2024 - The subtle art of API rate limiting by Josh Twist, Zuplo
Apidays New York 2024 - The subtle art of API rate limiting by Josh Twist, ZuploApidays New York 2024 - The subtle art of API rate limiting by Josh Twist, Zuplo
Apidays New York 2024 - The subtle art of API rate limiting by Josh Twist, Zuplo
 
Apidays New York 2024 - RESTful API Patterns and Practices by Mike Amundsen, ...
Apidays New York 2024 - RESTful API Patterns and Practices by Mike Amundsen, ...Apidays New York 2024 - RESTful API Patterns and Practices by Mike Amundsen, ...
Apidays New York 2024 - RESTful API Patterns and Practices by Mike Amundsen, ...
 
Apidays New York 2024 - Putting AI into API Security by Corey Ball, Moss Adams
Apidays New York 2024 - Putting AI into API Security by Corey Ball, Moss AdamsApidays New York 2024 - Putting AI into API Security by Corey Ball, Moss Adams
Apidays New York 2024 - Putting AI into API Security by Corey Ball, Moss Adams
 
Apidays New York 2024 - Prototype-first - A modern API development workflow b...
Apidays New York 2024 - Prototype-first - A modern API development workflow b...Apidays New York 2024 - Prototype-first - A modern API development workflow b...
Apidays New York 2024 - Prototype-first - A modern API development workflow b...
 
Apidays New York 2024 - Post-Quantum API Security by Francois Lascelles, Broa...
Apidays New York 2024 - Post-Quantum API Security by Francois Lascelles, Broa...Apidays New York 2024 - Post-Quantum API Security by Francois Lascelles, Broa...
Apidays New York 2024 - Post-Quantum API Security by Francois Lascelles, Broa...
 
Apidays New York 2024 - Increase your productivity with no-code GraphQL mocki...
Apidays New York 2024 - Increase your productivity with no-code GraphQL mocki...Apidays New York 2024 - Increase your productivity with no-code GraphQL mocki...
Apidays New York 2024 - Increase your productivity with no-code GraphQL mocki...
 
Apidays New York 2024 - Driving API & EDA Success by Marcelo Caponi, Danone
Apidays New York 2024 - Driving API & EDA Success by Marcelo Caponi, DanoneApidays New York 2024 - Driving API & EDA Success by Marcelo Caponi, Danone
Apidays New York 2024 - Driving API & EDA Success by Marcelo Caponi, Danone
 
Apidays New York 2024 - Build a terrible API for people you hate by Jim Benne...
Apidays New York 2024 - Build a terrible API for people you hate by Jim Benne...Apidays New York 2024 - Build a terrible API for people you hate by Jim Benne...
Apidays New York 2024 - Build a terrible API for people you hate by Jim Benne...
 
Apidays New York 2024 - API Secret Tokens Exposed by Tristan Kalos and Antoin...
Apidays New York 2024 - API Secret Tokens Exposed by Tristan Kalos and Antoin...Apidays New York 2024 - API Secret Tokens Exposed by Tristan Kalos and Antoin...
Apidays New York 2024 - API Secret Tokens Exposed by Tristan Kalos and Antoin...
 

Recently uploaded

Template xxxxxxxx ssssssssssss Sertifikat.pptx
Template xxxxxxxx ssssssssssss Sertifikat.pptxTemplate xxxxxxxx ssssssssssss Sertifikat.pptx
Template xxxxxxxx ssssssssssss Sertifikat.pptx
TeukuEriSyahputra
 
writing report business partner b1+ .pdf
writing report business partner b1+ .pdfwriting report business partner b1+ .pdf
writing report business partner b1+ .pdf
VyNguyen709676
 
一比一原版多伦多大学毕业证(UofT毕业证书)学历如何办理
一比一原版多伦多大学毕业证(UofT毕业证书)学历如何办理一比一原版多伦多大学毕业证(UofT毕业证书)学历如何办理
一比一原版多伦多大学毕业证(UofT毕业证书)学历如何办理
eoxhsaa
 
一比一原版英国赫特福德大学毕业证(hertfordshire毕业证书)如何办理
一比一原版英国赫特福德大学毕业证(hertfordshire毕业证书)如何办理一比一原版英国赫特福德大学毕业证(hertfordshire毕业证书)如何办理
一比一原版英国赫特福德大学毕业证(hertfordshire毕业证书)如何办理
nyvan3
 
Jio cinema Retention & Engagement Strategy.pdf
Jio cinema Retention & Engagement Strategy.pdfJio cinema Retention & Engagement Strategy.pdf
Jio cinema Retention & Engagement Strategy.pdf
inaya7568
 
一比一原版英属哥伦比亚大学毕业证(UBC毕业证书)学历如何办理
一比一原版英属哥伦比亚大学毕业证(UBC毕业证书)学历如何办理一比一原版英属哥伦比亚大学毕业证(UBC毕业证书)学历如何办理
一比一原版英属哥伦比亚大学毕业证(UBC毕业证书)学历如何办理
z6osjkqvd
 
Cell The Unit of Life for NEET Multiple Choice Questions.docx
Cell The Unit of Life for NEET Multiple Choice Questions.docxCell The Unit of Life for NEET Multiple Choice Questions.docx
Cell The Unit of Life for NEET Multiple Choice Questions.docx
vasanthatpuram
 
原版一比一爱尔兰都柏林大学毕业证(UCD毕业证书)如何办理
原版一比一爱尔兰都柏林大学毕业证(UCD毕业证书)如何办理 原版一比一爱尔兰都柏林大学毕业证(UCD毕业证书)如何办理
原版一比一爱尔兰都柏林大学毕业证(UCD毕业证书)如何办理
tzu5xla
 
Sample Devops SRE Product Companies .pdf
Sample Devops SRE  Product Companies .pdfSample Devops SRE  Product Companies .pdf
Sample Devops SRE Product Companies .pdf
Vineet
 
Building a Quantum Computer Neutral Atom.pdf
Building a Quantum Computer Neutral Atom.pdfBuilding a Quantum Computer Neutral Atom.pdf
Building a Quantum Computer Neutral Atom.pdf
cjimenez2581
 
Beyond the Basics of A/B Tests: Highly Innovative Experimentation Tactics You...
Beyond the Basics of A/B Tests: Highly Innovative Experimentation Tactics You...Beyond the Basics of A/B Tests: Highly Innovative Experimentation Tactics You...
Beyond the Basics of A/B Tests: Highly Innovative Experimentation Tactics You...
Aggregage
 
一比一原版(Sheffield毕业证书)谢菲尔德大学毕业证如何办理
一比一原版(Sheffield毕业证书)谢菲尔德大学毕业证如何办理一比一原版(Sheffield毕业证书)谢菲尔德大学毕业证如何办理
一比一原版(Sheffield毕业证书)谢菲尔德大学毕业证如何办理
1tyxnjpia
 
一比一原版兰加拉学院毕业证(Langara毕业证书)学历如何办理
一比一原版兰加拉学院毕业证(Langara毕业证书)学历如何办理一比一原版兰加拉学院毕业证(Langara毕业证书)学历如何办理
一比一原版兰加拉学院毕业证(Langara毕业证书)学历如何办理
hyfjgavov
 
在线办理(英国UCA毕业证书)创意艺术大学毕业证在读证明一模一样
在线办理(英国UCA毕业证书)创意艺术大学毕业证在读证明一模一样在线办理(英国UCA毕业证书)创意艺术大学毕业证在读证明一模一样
在线办理(英国UCA毕业证书)创意艺术大学毕业证在读证明一模一样
v7oacc3l
 
一比一原版爱尔兰都柏林大学毕业证(本硕)ucd学位证书如何办理
一比一原版爱尔兰都柏林大学毕业证(本硕)ucd学位证书如何办理一比一原版爱尔兰都柏林大学毕业证(本硕)ucd学位证书如何办理
一比一原版爱尔兰都柏林大学毕业证(本硕)ucd学位证书如何办理
hqfek
 
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
nuttdpt
 
一比一原版美国帕森斯设计学院毕业证(parsons毕业证书)如何办理
一比一原版美国帕森斯设计学院毕业证(parsons毕业证书)如何办理一比一原版美国帕森斯设计学院毕业证(parsons毕业证书)如何办理
一比一原版美国帕森斯设计学院毕业证(parsons毕业证书)如何办理
asyed10
 
Experts live - Improving user adoption with AI
Experts live - Improving user adoption with AIExperts live - Improving user adoption with AI
Experts live - Improving user adoption with AI
jitskeb
 
A presentation that explain the Power BI Licensing
A presentation that explain the Power BI LicensingA presentation that explain the Power BI Licensing
A presentation that explain the Power BI Licensing
AlessioFois2
 
Predictably Improve Your B2B Tech Company's Performance by Leveraging Data
Predictably Improve Your B2B Tech Company's Performance by Leveraging DataPredictably Improve Your B2B Tech Company's Performance by Leveraging Data
Predictably Improve Your B2B Tech Company's Performance by Leveraging Data
Kiwi Creative
 

Recently uploaded (20)

Template xxxxxxxx ssssssssssss Sertifikat.pptx
Template xxxxxxxx ssssssssssss Sertifikat.pptxTemplate xxxxxxxx ssssssssssss Sertifikat.pptx
Template xxxxxxxx ssssssssssss Sertifikat.pptx
 
writing report business partner b1+ .pdf
writing report business partner b1+ .pdfwriting report business partner b1+ .pdf
writing report business partner b1+ .pdf
 
一比一原版多伦多大学毕业证(UofT毕业证书)学历如何办理
一比一原版多伦多大学毕业证(UofT毕业证书)学历如何办理一比一原版多伦多大学毕业证(UofT毕业证书)学历如何办理
一比一原版多伦多大学毕业证(UofT毕业证书)学历如何办理
 
一比一原版英国赫特福德大学毕业证(hertfordshire毕业证书)如何办理
一比一原版英国赫特福德大学毕业证(hertfordshire毕业证书)如何办理一比一原版英国赫特福德大学毕业证(hertfordshire毕业证书)如何办理
一比一原版英国赫特福德大学毕业证(hertfordshire毕业证书)如何办理
 
Jio cinema Retention & Engagement Strategy.pdf
Jio cinema Retention & Engagement Strategy.pdfJio cinema Retention & Engagement Strategy.pdf
Jio cinema Retention & Engagement Strategy.pdf
 
一比一原版英属哥伦比亚大学毕业证(UBC毕业证书)学历如何办理
一比一原版英属哥伦比亚大学毕业证(UBC毕业证书)学历如何办理一比一原版英属哥伦比亚大学毕业证(UBC毕业证书)学历如何办理
一比一原版英属哥伦比亚大学毕业证(UBC毕业证书)学历如何办理
 
Cell The Unit of Life for NEET Multiple Choice Questions.docx
Cell The Unit of Life for NEET Multiple Choice Questions.docxCell The Unit of Life for NEET Multiple Choice Questions.docx
Cell The Unit of Life for NEET Multiple Choice Questions.docx
 
原版一比一爱尔兰都柏林大学毕业证(UCD毕业证书)如何办理
原版一比一爱尔兰都柏林大学毕业证(UCD毕业证书)如何办理 原版一比一爱尔兰都柏林大学毕业证(UCD毕业证书)如何办理
原版一比一爱尔兰都柏林大学毕业证(UCD毕业证书)如何办理
 
Sample Devops SRE Product Companies .pdf
Sample Devops SRE  Product Companies .pdfSample Devops SRE  Product Companies .pdf
Sample Devops SRE Product Companies .pdf
 
Building a Quantum Computer Neutral Atom.pdf
Building a Quantum Computer Neutral Atom.pdfBuilding a Quantum Computer Neutral Atom.pdf
Building a Quantum Computer Neutral Atom.pdf
 
Beyond the Basics of A/B Tests: Highly Innovative Experimentation Tactics You...
Beyond the Basics of A/B Tests: Highly Innovative Experimentation Tactics You...Beyond the Basics of A/B Tests: Highly Innovative Experimentation Tactics You...
Beyond the Basics of A/B Tests: Highly Innovative Experimentation Tactics You...
 
一比一原版(Sheffield毕业证书)谢菲尔德大学毕业证如何办理
一比一原版(Sheffield毕业证书)谢菲尔德大学毕业证如何办理一比一原版(Sheffield毕业证书)谢菲尔德大学毕业证如何办理
一比一原版(Sheffield毕业证书)谢菲尔德大学毕业证如何办理
 
一比一原版兰加拉学院毕业证(Langara毕业证书)学历如何办理
一比一原版兰加拉学院毕业证(Langara毕业证书)学历如何办理一比一原版兰加拉学院毕业证(Langara毕业证书)学历如何办理
一比一原版兰加拉学院毕业证(Langara毕业证书)学历如何办理
 
在线办理(英国UCA毕业证书)创意艺术大学毕业证在读证明一模一样
在线办理(英国UCA毕业证书)创意艺术大学毕业证在读证明一模一样在线办理(英国UCA毕业证书)创意艺术大学毕业证在读证明一模一样
在线办理(英国UCA毕业证书)创意艺术大学毕业证在读证明一模一样
 
一比一原版爱尔兰都柏林大学毕业证(本硕)ucd学位证书如何办理
一比一原版爱尔兰都柏林大学毕业证(本硕)ucd学位证书如何办理一比一原版爱尔兰都柏林大学毕业证(本硕)ucd学位证书如何办理
一比一原版爱尔兰都柏林大学毕业证(本硕)ucd学位证书如何办理
 
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
 
一比一原版美国帕森斯设计学院毕业证(parsons毕业证书)如何办理
一比一原版美国帕森斯设计学院毕业证(parsons毕业证书)如何办理一比一原版美国帕森斯设计学院毕业证(parsons毕业证书)如何办理
一比一原版美国帕森斯设计学院毕业证(parsons毕业证书)如何办理
 
Experts live - Improving user adoption with AI
Experts live - Improving user adoption with AIExperts live - Improving user adoption with AI
Experts live - Improving user adoption with AI
 
A presentation that explain the Power BI Licensing
A presentation that explain the Power BI LicensingA presentation that explain the Power BI Licensing
A presentation that explain the Power BI Licensing
 
Predictably Improve Your B2B Tech Company's Performance by Leveraging Data
Predictably Improve Your B2B Tech Company's Performance by Leveraging DataPredictably Improve Your B2B Tech Company's Performance by Leveraging Data
Predictably Improve Your B2B Tech Company's Performance by Leveraging Data
 

apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX

  • 1. The Industry Standard for Consumer Access to Financial Records CATTS out of the bag. Bringing uniformity to financial industry APIs Jean-Paul LaClair, Sr Director of Product May 16, 2023
  • 2. In our quest for more convenience in our financial lives, our financial lives have become more complex to manage. CATTS out of the bag. So what?
  • 3. The Industry Standard for Consumer Access to Financial Records 3 FDX Confidential. All rights reserved. An end consumer’s desires begins to disintermediate financial services The situation with data sharing
  • 5. The Industry Standard for Consumer Access to Financial Records Where it all started… 5 FDX Confidential. All rights reserved. Software was developed in the 1990s that could log in for you, gather the data (screen scrape), and combine all the data into a single interface; but required consumers to share their IDs and Passwords Consumers with accounts at multiple banks had to manually combine the data. The situation with data sharing
  • 6. The Industry Standard for Consumer Access to Financial Records And where it’s likely to go 6 FDX Confidential. All rights reserved. The situation with data sharing Volume of data created, captured, copied, and consumed worldwide from 2010 to 2020, with forecasts from 2021 to 2025 © Statista 2023 (in zettabytes)
  • 7. More options to manage finances More complex financial lives More creation, consumption, and storage of data More data sharing
  • 8. RED ALERT Things are getting complicated
  • 9. The Industry Standard for Consumer Access to Financial Records Screen scraping requires sharing credentials 9 FDX Confidential. All rights reserved. Red alert… that situation is causing complications Customer provides credentials to a 3rd party 3rd party uses the credentials to log-in and scrape data. They can see ANY data the customer can see today.
  • 10. The Industry Standard for Consumer Access to Financial Records Credential-based data sharing 10 FDX Confidential. All rights reserved. Red alert… that situation is causing complications Consider the impact to the Banking Industry’s Infrastructure, Cyber Posture, and Privacy Posture Rules of Thirds • Approximately 1/3 of financial institution customers share their financial data with third parties1 • This equates to at least 100 million U.S. consumers Financial institution online traffic is, on average1,2: Just how big is it…?
  • 11. 11 Popular FinTech app breached. Millions of member IDs and PWs in paste bins all over the dark web. - June 1, 2023 …Chief Privacy Officer is on Line 1 …Board Risk Committee Chair is on Line 2 …60 Minutes is on Line 3 …Brian Krebs is calling your cell How many of our customers were affected? We don’t know, maybe as much as 15-20%. Customer data has been confirmed in multiple paste bins and call center call volume is intensifying. What data was at risk? Anything the customer’s eye can see, including PII and full account numbers. Are we seeing an increase in ATO and Fraud? There is an uptick, but attribution is not certain. What are we doing about it? We have blocked that app with our WAF, our SOC is monitoring things closely, and we are in contact with our peers and industry groups for signals and signature sharing and will reset compromised accounts and offer a year of privacy monitoring. How many of our customers were affected? None. We converted from credentials-based access to token based last year using FDX. Should the app itself become an issue, exactly nn,nnn customers use the app and we can revoke one or all tokens at any time with no impact to their access to our online bank or our mobile app. What data was at risk? Only the following fields were permissioned to the app: xx, yy, zz, Are we seeing an increase in ATO and Fraud? No. No credentials were lost, and customer data was limited to the minimum the app needed to function. What are we doing about it? We have blocked that app from our API using our ACL and WAF, our SOC is monitoring things closely, and we are in contact with our peers and industry groups for signals and signature sharing. Any tokens lost are unusable by external actors. Our Fraud and Info Sec teams are engaged with the app for forensic review and remediation steps as we are both FDX members. Which of these two conversations do you want to have with the callers? Future FICTIONAL Headline
  • 12. The Industry Standard for Consumer Access to Financial Records Lack of interoperability 12 FDX Confidential. All rights reserved. Red alert… that situation is causing complications
  • 13. Let the CATTS out of the bag
  • 14. The Industry Standard for Consumer Access to Financial Records FDX is an international, nonprofit technical standards body dedicated to unifying the financial industry around a common, interoperable, royalty-free standard for the secure access of permissioned consumer and business financial data, the FDX API. © FDX, all rights reserved FDX does not comment on policy or engage in lobbying. User Experience Security Certification API & Data Structures FDX Specifications v5.2.1 FDX is a subsidiary of FS-ISAC. Financial Data Exchange – A Standard Our Members > 230 members | ¼ of members are Fin-Tech firms | 2/3 are not banks | 1/3 are Canadian Our Leadership Our Board comprises 12 Financial Institutions, 5 Permissioned Parties, 5 Aggregators, 2 Industry Groups, FS-ISAC, 1 Canadian Fintech, 1 Canadian Financial Institution and 1 Consumer Advocacy Group observer. Our Adoption 53 Million Consumer Accounts using FDX API as of Spring 2023
  • 15. The Industry Standard for Consumer Access to Financial Records A Market Standard 15 FDX Confidential. All rights reserved. Technology Regulation Standardized Payload Connectivity Security & Auth User Experience Industry (the How) Government (the What)
  • 16. 80 kph 50 mph Technology Regulation User Experience Connectivity (TLS) Security & Authentication (FAPI & FIDO) Payload (JSON) JSON just tells us the type of object the truck is carrying – e.g., a shipping container. The contents can be anything the sender and receiver agree on: FDX format, ISO 20022 Format, IRS Tax (FIRE), or proprietary. Components of the FDX Standard
  • 18. The Industry Standard for Consumer Access to Financial Records Principles for Consumer-Permissioned Data Sharing 18 FDX Confidential. All rights reserved. AKA: CATTS C A T T S
  • 19. The Industry Standard for Consumer Access to Financial Records FDX Specifications 19 FDX Confidential. All rights reserved. API and Data Structures 1. Components 2. Core information – Accounts and Transactions 3. Customer Information 4. Consent, Recipient Registration 5. Tax, Money Movement, Metrics, Events, Fraud, and Registry User Experience 1. UX Guidelines – Consent Grant, Notification, Viewing, and Revocation 2. Data Clusters Mapping 3. Taxonomy Security 1. Security Model (AuthN & AuthZ), Security for Sensitive Data, Secure App Onboarding 2. Control Consideration 3. Recipient Registration Guidelines Certification 1. Provider Requirements 2. Recipient Requirements 3. Data Access Platform Requirements 4. Certification Use Cases 5. Certification Model
  • 22. The Industry Standard for Consumer Access to Financial Records 22 FDX Confidential. All rights reserved.