SlideShare a Scribd company logo
The Industry Standard for Consumer
Access to Financial Records
FDX API and Security Overview
Dinesh Katyal – 7/20/20
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Agenda
2
Organization Overview
The FDX API Portfolio
- FDX API 4.1
- Control Consideration for Consumer Financial Account Aggregation 3.1
- User Experience Guidelines – Account Information 1.0
- Use Cases
Q & A
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Mission
3
The Financial Data Exchange (FDX) mission is to promote and enhance a
common interoperable standard and operating framework to efficiently
and securely share consumer and business financial data.
FDX operates as an independent subsidiary of the Financial Services
Information Sharing and Analysis Center (FS-ISAC) and took up the work
of the FS-ISAC Aggregation Working Group.
FDX launched on 18 October 2018.
Financial Data Exchange (FDX) The current Board comprises 11 Financial Institutions, 5 Permissioned
Parties, 5 Aggregators, 2 Industry Groups & the FS-ISAC.
The Industry Standard for Consumer Access to Financial Records
Open Membership | ¼ of members are Fin-Tech firms | 2/3 are not banks | FDX is not a policy or lobbying group.
118 Member
Organizations
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
The Industry Standard for Consumer Access to Financial Records
FDX Technical Organization
Security &
Authentication
User
Experience
& Consent
API / Data
Structures
Qualification &
Certification
OFX
Working
Groups
Every Working Group, Committee and the Board are co-chaired by a Financial Institution and a Non-Financial Institution
Technology
Review
Committee
E2E
Encryption
Task
Forces
Cert Model Directory Tax Forms
Intermediary
ID
UX
Guidelines
Taxonomy
Money
Movement
FDX Staff
Director Product
+
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
FDX API
7
• Secure authentication
- Tokenized access to data
- No login credentials used/ held by aggregator/ apps
• Authorization and consent standard
- Owner approves what is shared, its use, and duration
- UX guidelines 1.0 will cover consent for account information services
• API specification
- Replaces screen scraping
- JSON/ REST
- Comprehensive coverage of account information services and tax forms (US)
- Free to access and royalty free to use
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Supported Accounts and Documents
■ Deposit: ■ Lines of Credit:
Checking (DDA) Credit Cards
Savings LOC (retail)
Money Market Accounts LOC (Commercial)
Time Deposits (CD) HELOC
Other Other
■ Loans: ■ Investments
Loans (Installment) IRA
Mortgages TAXABLE
Loans (Commercial) TRUST
Other Other
■ Insurance: ■ Annuities:
● Statements
● Tax Documents: US Tax Forms
● Images (receipts or check images)
The Industry Standard for Consumer Access to Financial Records
• FALL 2020 Release Timeline
• Sep 7 – RFC cutoff for release inclusion
• Sep 21:
• Spec 4.2 (tax ‘20) – 14-day member notice
• Spec 4.5 (non-tax RFCs) – WG notification
• Oct 5 (60 days prior) –
• Spec 4.2 (tax ‘20) - GA
• Spec 4.5 (non-tax RFCs) – 60-day member
notice
• Dec 3 – Spec 4.5 GA
Note: Tax and non-tax will be aligned from Fall 2021
onwards shifting general release schedule up by 2
months
Release Calendar
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Control Considerations
10
• Conceptual security architecture stack
- Federated user authentication interoperability with OpenID Connect 1.0
- Delegated user authorization using OAuth 2.0
- Specific user identification pattern using FIDO 1.2 UAF
• Communication;
- TLS for all communications
- NIST recommended encryption algorithms
- Recommended key lengths and host name verification enabled
• API Security Profile
- Normative references to FAPI part 1 – read only security profile
- FAPI part 2 – read-write security profile
OAuth 2.0
The Industry Standard for Consumer Access to Financial Records
FDX Confidential. All rights reserved.
Questions

More Related Content

Similar to FDX API Overview (Dinesh).pdf

Pistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
Pistoia Alliance European Conference 2015 - Stuart Robertson / ExostarPistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
Pistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
Pistoia Alliance
 
OneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to ManyOneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to Many
ControlCase
 
Continuous Compliance Monitoring
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance Monitoring
ControlCase
 
India’s Most Comprehensive Compliance Management software
India’s Most Comprehensive Compliance Management softwareIndia’s Most Comprehensive Compliance Management software
India’s Most Comprehensive Compliance Management software
LexComply
 
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
FinTechLabs.io
 
First-North - EUSN Presentation (November 16 2016) Final-v1 Yogi Notes 2016-1...
First-North - EUSN Presentation (November 16 2016) Final-v1 Yogi Notes 2016-1...First-North - EUSN Presentation (November 16 2016) Final-v1 Yogi Notes 2016-1...
First-North - EUSN Presentation (November 16 2016) Final-v1 Yogi Notes 2016-1...
Yogi Golle
 
PCI-DSS for IDRBT
PCI-DSS for IDRBTPCI-DSS for IDRBT
PCI-DSS for IDRBT
Shanmugavel Sankaran
 
Enterprise Governance Risk and Compliance (GRC) Management Solution in India
Enterprise Governance Risk and Compliance (GRC) Management Solution in IndiaEnterprise Governance Risk and Compliance (GRC) Management Solution in India
Enterprise Governance Risk and Compliance (GRC) Management Solution in India
LexComply
 
5 Things to Look for in an ELD Provider
5 Things to Look for in an ELD Provider 5 Things to Look for in an ELD Provider
5 Things to Look for in an ELD Provider
Brittany Wooten
 
Trisilco-IT NSRS presentation
Trisilco-IT NSRS presentationTrisilco-IT NSRS presentation
Trisilco-IT NSRS presentation
Hasan Mokaddes
 
IQ3 Group - ISDA August 2012 DF Protocol
IQ3 Group - ISDA August 2012 DF ProtocolIQ3 Group - ISDA August 2012 DF Protocol
IQ3 Group - ISDA August 2012 DF Protocol
IQ3 Solutions Group
 
Vendor Management for PCI DSS, HIPAA, and FFIEC
Vendor Management for PCI DSS, HIPAA, and FFIECVendor Management for PCI DSS, HIPAA, and FFIEC
Vendor Management for PCI DSS, HIPAA, and FFIEC
ControlCase
 
Managing Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust PrinciplesManaging Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust Principles
ControlCase
 
Fido uaf-overview-v1.1-rd-20161005
Fido uaf-overview-v1.1-rd-20161005Fido uaf-overview-v1.1-rd-20161005
Fido uaf-overview-v1.1-rd-20161005
Jaime Ruiz
 
Bank Tech Asia 2012
Bank Tech Asia 2012Bank Tech Asia 2012
Bank Tech Asia 2012
Hasan Mokaddes
 
Global Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationGlobal Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong Authentication
FIDO Alliance
 
20190523 archiver fim
20190523 archiver fim20190523 archiver fim
20190523 archiver fim
Archiver
 
FIDO as Regtech - Addressing Government Requirements
FIDO as Regtech - Addressing Government RequirementsFIDO as Regtech - Addressing Government Requirements
FIDO as Regtech - Addressing Government Requirements
FIDO Alliance
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service Directive
Lac Vuong
 
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Greenlight Guru
 

Similar to FDX API Overview (Dinesh).pdf (20)

Pistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
Pistoia Alliance European Conference 2015 - Stuart Robertson / ExostarPistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
Pistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
 
OneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to ManyOneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to Many
 
Continuous Compliance Monitoring
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance Monitoring
 
India’s Most Comprehensive Compliance Management software
India’s Most Comprehensive Compliance Management softwareIndia’s Most Comprehensive Compliance Management software
India’s Most Comprehensive Compliance Management software
 
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
 
First-North - EUSN Presentation (November 16 2016) Final-v1 Yogi Notes 2016-1...
First-North - EUSN Presentation (November 16 2016) Final-v1 Yogi Notes 2016-1...First-North - EUSN Presentation (November 16 2016) Final-v1 Yogi Notes 2016-1...
First-North - EUSN Presentation (November 16 2016) Final-v1 Yogi Notes 2016-1...
 
PCI-DSS for IDRBT
PCI-DSS for IDRBTPCI-DSS for IDRBT
PCI-DSS for IDRBT
 
Enterprise Governance Risk and Compliance (GRC) Management Solution in India
Enterprise Governance Risk and Compliance (GRC) Management Solution in IndiaEnterprise Governance Risk and Compliance (GRC) Management Solution in India
Enterprise Governance Risk and Compliance (GRC) Management Solution in India
 
5 Things to Look for in an ELD Provider
5 Things to Look for in an ELD Provider 5 Things to Look for in an ELD Provider
5 Things to Look for in an ELD Provider
 
Trisilco-IT NSRS presentation
Trisilco-IT NSRS presentationTrisilco-IT NSRS presentation
Trisilco-IT NSRS presentation
 
IQ3 Group - ISDA August 2012 DF Protocol
IQ3 Group - ISDA August 2012 DF ProtocolIQ3 Group - ISDA August 2012 DF Protocol
IQ3 Group - ISDA August 2012 DF Protocol
 
Vendor Management for PCI DSS, HIPAA, and FFIEC
Vendor Management for PCI DSS, HIPAA, and FFIECVendor Management for PCI DSS, HIPAA, and FFIEC
Vendor Management for PCI DSS, HIPAA, and FFIEC
 
Managing Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust PrinciplesManaging Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust Principles
 
Fido uaf-overview-v1.1-rd-20161005
Fido uaf-overview-v1.1-rd-20161005Fido uaf-overview-v1.1-rd-20161005
Fido uaf-overview-v1.1-rd-20161005
 
Bank Tech Asia 2012
Bank Tech Asia 2012Bank Tech Asia 2012
Bank Tech Asia 2012
 
Global Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationGlobal Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong Authentication
 
20190523 archiver fim
20190523 archiver fim20190523 archiver fim
20190523 archiver fim
 
FIDO as Regtech - Addressing Government Requirements
FIDO as Regtech - Addressing Government RequirementsFIDO as Regtech - Addressing Government Requirements
FIDO as Regtech - Addressing Government Requirements
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service Directive
 
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
 

Recently uploaded

Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
innovationoecd
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Safe Software
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
Chart Kalyan
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
tolgahangng
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
Tatiana Kojar
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
panagenda
 
Digital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying AheadDigital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying Ahead
Wask
 
Project Management Semester Long Project - Acuity
Project Management Semester Long Project - AcuityProject Management Semester Long Project - Acuity
Project Management Semester Long Project - Acuity
jpupo2018
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
DianaGray10
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
Jason Packer
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
Tomaz Bratanic
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
shyamraj55
 
UI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentationUI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentation
Wouter Lemaire
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
akankshawande
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
Daiki Mogmet Ito
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
Zilliz
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
Zilliz
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
panagenda
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
Hiroshi SHIBATA
 

Recently uploaded (20)

Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
 
Digital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying AheadDigital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying Ahead
 
Project Management Semester Long Project - Acuity
Project Management Semester Long Project - AcuityProject Management Semester Long Project - Acuity
Project Management Semester Long Project - Acuity
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
 
UI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentationUI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentation
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
 

FDX API Overview (Dinesh).pdf

  • 1. The Industry Standard for Consumer Access to Financial Records FDX API and Security Overview Dinesh Katyal – 7/20/20
  • 2. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Agenda 2 Organization Overview The FDX API Portfolio - FDX API 4.1 - Control Consideration for Consumer Financial Account Aggregation 3.1 - User Experience Guidelines – Account Information 1.0 - Use Cases Q & A
  • 3. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Mission 3 The Financial Data Exchange (FDX) mission is to promote and enhance a common interoperable standard and operating framework to efficiently and securely share consumer and business financial data. FDX operates as an independent subsidiary of the Financial Services Information Sharing and Analysis Center (FS-ISAC) and took up the work of the FS-ISAC Aggregation Working Group. FDX launched on 18 October 2018.
  • 4. Financial Data Exchange (FDX) The current Board comprises 11 Financial Institutions, 5 Permissioned Parties, 5 Aggregators, 2 Industry Groups & the FS-ISAC. The Industry Standard for Consumer Access to Financial Records Open Membership | ¼ of members are Fin-Tech firms | 2/3 are not banks | FDX is not a policy or lobbying group. 118 Member Organizations
  • 5. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved.
  • 6. The Industry Standard for Consumer Access to Financial Records FDX Technical Organization Security & Authentication User Experience & Consent API / Data Structures Qualification & Certification OFX Working Groups Every Working Group, Committee and the Board are co-chaired by a Financial Institution and a Non-Financial Institution Technology Review Committee E2E Encryption Task Forces Cert Model Directory Tax Forms Intermediary ID UX Guidelines Taxonomy Money Movement FDX Staff Director Product +
  • 7. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. FDX API 7 • Secure authentication - Tokenized access to data - No login credentials used/ held by aggregator/ apps • Authorization and consent standard - Owner approves what is shared, its use, and duration - UX guidelines 1.0 will cover consent for account information services • API specification - Replaces screen scraping - JSON/ REST - Comprehensive coverage of account information services and tax forms (US) - Free to access and royalty free to use
  • 8. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Supported Accounts and Documents ■ Deposit: ■ Lines of Credit: Checking (DDA) Credit Cards Savings LOC (retail) Money Market Accounts LOC (Commercial) Time Deposits (CD) HELOC Other Other ■ Loans: ■ Investments Loans (Installment) IRA Mortgages TAXABLE Loans (Commercial) TRUST Other Other ■ Insurance: ■ Annuities: ● Statements ● Tax Documents: US Tax Forms ● Images (receipts or check images)
  • 9. The Industry Standard for Consumer Access to Financial Records • FALL 2020 Release Timeline • Sep 7 – RFC cutoff for release inclusion • Sep 21: • Spec 4.2 (tax ‘20) – 14-day member notice • Spec 4.5 (non-tax RFCs) – WG notification • Oct 5 (60 days prior) – • Spec 4.2 (tax ‘20) - GA • Spec 4.5 (non-tax RFCs) – 60-day member notice • Dec 3 – Spec 4.5 GA Note: Tax and non-tax will be aligned from Fall 2021 onwards shifting general release schedule up by 2 months Release Calendar
  • 10. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Control Considerations 10 • Conceptual security architecture stack - Federated user authentication interoperability with OpenID Connect 1.0 - Delegated user authorization using OAuth 2.0 - Specific user identification pattern using FIDO 1.2 UAF • Communication; - TLS for all communications - NIST recommended encryption algorithms - Recommended key lengths and host name verification enabled • API Security Profile - Normative references to FAPI part 1 – read only security profile - FAPI part 2 – read-write security profile OAuth 2.0
  • 11. The Industry Standard for Consumer Access to Financial Records FDX Confidential. All rights reserved. Questions