Episodes / TPT #9
OPEN FINANCE & FIDA
Video
👍 Like & comment on YouTube Subscribe to the channel
Listen
Open this episode in
- Spotify
- Apple Podcasts
- Amazon Music
- … AND PLEASE FOLLOW THE SHOW THERE — that is how new listeners find us.
Show notes
In this episode of the Payments Trialogue, Michael Salmony, Gijs Boudewijn, and Ralf Ohlhausen discuss the evolving landscape of open finance, focusing on the FIDA proposal and its implications for data access and collaboration within the financial industry. They explore the importance of customer-centric approaches, the distinction between data access and sharing, and the relevance of existing models like SPAA in fostering cooperation among industry players and minimising regulation. The conversation also addresses global trends in open finance, the challenges of fragmentation, and the need for coordinated efforts to ensure a harmonized approach across sectors.
Chapters
- 0:00 Introduction to Open Finance and Collaboration
- 3:00 Understanding FIDA and Its Implications
- 6:10 The Role of Customer-Centric Data Access
- 9:04 The Importance of Data Access vs. Data Sharing
- 12:06 The SPAA Model and Its Relevance to Open Finance
- 14:50 Global Trends in Open Finance and API Standardisation
- 17:55 Challenges of Fragmentation in Open Finance
- 21:10 Standardisation in Open Finance
Transcript
Michael Salmony 0:02
Welcome to the Payments Trilogue, where three seasoned professionals discuss payments and more, for Europe and beyond.
developments in finance with my good friends, Gijs Boudewijn, who looks at it more from the banking side, and Ralf Ohlhausen, who looks at it more from the fintech side. As you regular listeners of the podcast will know,
We have a common theme running through our trilogue that we think it's good if the industry cooperates, that banks work together and banks and fintechs work together. That's better than fighting because then the winners will just come from other countries and from other areas which you may not be so happy about. And we also advocate for light regulation because we've shown in many instances where the market can solve the problem themselves.
And we've chosen a topic today which I think exemplifies those principles quite nicely, which is open finance. We are beginning to open up the payments industry with open banking, but this is now going to open finance. So that includes insurance and asset management and securities and everything. And the first regulation proposal is out called FIDA. And we want to discuss how maybe our principles can be applied to that.
So maybe I can ask Ralf to start us off on that, explain a little bit what the FIDA thing is about and whether you like it or not. Okay. Yeah. Actually, if you don't mind, let me start not with whatever a year ago when FIDA came out, but 20 years ago when we had the first TPP, actually 21 years now, starting in Europe. And like,
them at the time, most of the TPPs that are active under PSD2, they're also providing services on non-payment accounts, on other finance accounts, other banking accounts. So I think the first thing to really appreciate and understand is that other than in the rest of the world here in Europe, we have like a 20-year history on open finance.
And whatever we do now and whatever we start regulating now, we cannot afford to slow down or bring things back or whatever. So we got to build on what we have and we got to improve on it. that is for us and from my side, from TPP side, from a fintech perspective, the starting point. So we are...
We have been running for a number of years, as I said, some more than a decade. And what we have to make sure is that this is not getting negatively disrupted and that we are not like I alluded to in previous episodes there, like in PSD2 where we have lost our worldwide lead on open banking because similarly there we were the first in the world. But then I think, well, we basically slowed down and now
have been maybe overtaken by some. So anyway, here on open finance or going beyond payments, beyond the regulated, PSD2 regulated payment accounts. Well, I hope that we can learn from those lessons on what PSD2 regulation has brought and what was good and what was not so good so that we focus on the good sides and leave out the not so good ones.
Yeah, so with that in mind, also, I would like to highlight that there have been open finance working groups working together on the FinTech side. There was a so-called open finance manifesto established and published by ETPPA and where we have outlined what we believe
would be the best way forward. Now, we've also participated, of course, in the what's called the European Financial Data Space Expert Group. So one of the Commission's expert groups that is looking into this and which has been well, with many stakeholders from the industry and
So you have banking, not just banking, but also insurance and other finance sectors which are represented there. And with that advice given to the Commission, that's what I guess they have used for creating the proposal, the FIDA proposal that came out last June. And so in there, some of our input has been
taken up or is sort part of that proposal, but there are quite a few things which are not. And hence we have similar to PSR, I mentioned before, a list of improvements that we are suggesting that we hope that the co-legislators will bring in. yeah, happy to tell you more about one or two or three of them. Okay.
But before we go into that, maybe just a quick for those who are not aware of what FIDA is. FIDA proposes that new players come into the markets, right? Just like PISPs and AISPs, which we discovered with PSD2, there are now going to be data access AISPs.
So that's a new player that's coming in. also, the recommendation is to do a scheme, which was something which was also not recommended or wasn't part of PSD2. So that's quite new. It opens up the scope beyond payments. It introduces yet another third party player. And it suggests that the scheme take part. Maybe, Gijs, you can just do a quick reaction, what you think of that. And then we come back to Ralf and see what bits he doesn't like about it.
Well, there's no such thing as an ideal world, of course. I think open finance, open data is an inevitable thing that will happen. And I do believe that the FIDA proposals are an honest attempt of the Commission to try to structure it and help the industry to deliver itself instead of over-regulating. I think the learnings the Commission took from
the European Payments Council's SPAA scheme where Ralf and I sit in a multi-stakeholder Group which builds on top of PSD2 everything that is not in the law and was mistakenly forgotten or else so let's say premium services on top of the law that concept we do the basis in the regulation in the legislation but we leave it up to the market to define what is really fitting the market needs with a lot more flexibility
in terms of a scheme between market participants building on top of the regulatory baseline. And that concept, I think, is very much compelling. I do believe in it. It's not an easy thing, but it provides better results than trying to regulate it at a bid level which doesn't work. And of course, from the donating side, let's say the ASPSP side, the banks side, or the pension funds, or the insurance, let's say the supply side.
it's very important that there is always room for compensation. One of the lessons we learned from PSD2 is that forcing institutions, let's say, to give away their crown jewels for free to somebody else is not a very good incentive. So I think it's, in essence, it's a balanced proposal. Conceptually, it is sound. But of course, that doesn't mean it's going to be easy and that there is no room for improvement. But in basis, I do believe in the general...
So that sounds quite positive, Gijs. So now it's up to you, Ralf, to tell us what went wrong. Well, let me start. I actually fully agree with what Gijs just said. And that is one of our criticisms on FIDA. So in my mind, it should be much more or actually only and solely customer centric. It should be about
allowing or enabling customers to get access to their data 24x7.
That's it. And for me, that could have been everything. Because it is for me that and well, as you know, this is partially already there with GDPR. But I think what we're talking here is what we have under GDPR for private or consumer customers.
should also be available for corporate customers, so any type of customer and their data. And it should be basically online available 24-7. Real time it's called if you have, but what this meant really is that you have ongoing access to it 24-7. So essentially forcing everyone in the finance industry to come to the modern age and provide a user interface.
like what banks already have and have had for many years, it is not standard for everything in the finance industry. know, some insurances have it, many don't. So for me, that is the main purpose that customers, private or corporate, can get around the clock access to their data. That means that the proposal could have been very short, in fact, right?
I do take your point when I read the FIDA proposal, there's a lot of it which talks about the internal plumbings of how the scheme is to work and how the various industry players have to work together instead of just a goal-oriented regulation, say I want to have this effect, I want to have this policy, I want to have this result, rather than again prescribing all the internal stuff, which is something we... Michael, if you do not...
just an abstract, everybody needs access to everything 24x7. Yeah, right. But how? And this is all about the how question. How do you organize that? How do you do that? You have to have agreements, data sharing arrangements. I mean, it's not just because Ralf says I want access, give me access 24x7. Yep. How do you have to organize that? Do you think that should be specified in the regulation? Don't you trust the industry to work that out? Or are you more happy with this prescription?
Maybe it's semantics. Ralf, you would agree without any agreement, just knocking on anyone's door and saying, I want your data, will not work. There has to be pre-agreed ways to do that. You have to standardize it. You have to the right APIs. You have to open finance framework of the Berlin Group and so on. So you need agreements on how to do it. And that is called a scheme. And I think the merit of schemes is that it will lower the barriers and it will foster
harmonization and it will create the network effects we need to make it all work. How else would you organize it? I mean, so I think it's a good approach. I don't see any other way how to do it. Well, you mentioned SPAA before. So in the same way as SPAA is not mandated in PSD2 and yet it has developed because it is the best for banks and TPPs to collaborate and not just, you know, try to
create great services on regulation and on enforcement. So that's why there is a natural interest and incentive to develop that. if and when there are customers have a user interface, then they can.
decide on what they do with it. they use to do they whatever use AI to handle it? Do they do it manually themselves? Do they use a TPP helping them with making more out of the data? It's about unlocking and reusing their data. And by the way, that's another big criticism for me is that FIDA is talking about data sharing, which is really, really, really bad because we have under PSD2, thankfully,
All of PSD2 it talks about data access. There is no word about sharing. The word sharing is being used by those who basically want to fear monger because they know that when it comes to financial data, people don't want to talk, they don't want to share their data. So I think data sharing already, open banking or open finance is already difficult because it sounds like, you know, you're opening up your data there and that's what people are already hesitating. When you now add
sharing on top of that, I think we've lost 50%, 80%, maybe 90 % of people who don't want to consider that. So that was for us one of the proposals we put forward that any occurrence of the word sharing in FIDA should be replaced by data access or by unlocking or reusing and thankfully
the parliament rapporteur who was on the case, he actually adopted that and he made every in the parliament proposal, it was changed sharing to access. For me, this is a very, very important point. But so when people have access to their data, then they can decide what they want to do with it.
whether they want to use a third party or not, or what they did, they just do it themselves or in whatever form. And also, by the way, they should decide what data they then want to use or not. So it should not be down to FIDA or regulation whether my health data or some of my health data is accessible or not. It's my health data. I should be able to access it.
And if I want to use it with someone in some other form, it should be my decision. It should not be a regulator's decision that some customer data is not available, others is. So that's also, think, this whole discussion about the scope of FIDA. I mean, for me, it's obvious it should be any customer data, full stop. No, that makes sense. I mean, it may sound a little bit like semantic nitpicking.
to differentiate between sharing and access, but I think it is important, right? Sharing sort of suggests, I give you my data and I have no idea who you then pass it on to and then that is shared with the whole world and shared with the internet. And that of course, not what we're talking about. Whereas if I have allowed controlled access to my data, if I allow an insurance comparison website to access for this one particular purpose, what I'm currently insured for.
and that is accessing under controlled conditions and that's really what I want to be able to do. I want to allow others to access my data and any data that I feel will add value to me and that's what should be enabled. But Gijs, you had another view. It is semantics. mean, it depends on whose perspective you look from. If I look from the consumer's perspective, I want to share my data with...
anyone I choose to share it with and I give consent to share it. So I don't see that point. For me it's semantics. The TPP wants access because I, as a customer of the TPP, want to share my data with anyone I choose. So for me it is a bit of semantical discussion. I suddenly thought of the book The Circle. You may recall Sharing is Caring, Ralf.
You may remember that one. We all know how that ends. That didn't end well, yes, exactly. No, but for me, have much less negative connotation with the word sharing because it's from the data owners, my perspective is my data and I decide with whom.
I instruct my bank or my pension fund to share. That's the common principle I think we all agree on, right? It's my data and I control it and who and whether. I give somebody access because I want to share my data. Yeah. But maybe you can just comment on this, this SPAA topic because SPAA does look like a nice principle where the industry came up with its own scheme, although it wasn't, was nowhere in the regulation and found a balanced model where all parties get compensated.
And in fact, are already some, one could think that SPAA could be the basis also for an open finance scheme, right? Because why are you restricted to payments? Isn't there an opportunity there? absolutely. That was the idea from the outset, even before the scheme, let's say the substance of the, its basis is an ERPB, the Euro Retail Payments Board report on how can we reap the full benefits of PSD2.
The law isn't good enough, we need to do something on top. And the idea came up, let's have an arrangement, call it a scheme, to give the TPPs what they want, accommodate the wish of the banks to get some form of compensation for their efforts, etc. And that ended up at the European Payments Council to develop such a scheme. already in the ERPB report of June 2019, we had the more holistic approach. This is an arrangement concept we're not just going to develop for...
payments because it was the European retail payments board and European payments council which only have the payments domain in the ring and nothing beyond. we said wouldn't it be great if we build a holistic model and we call it assets, asset holders, i.e. the ASPSPs piece, asset brokers, i.e. the TPPs that access those assets and make a more generic holistic model on how to share data assets.
For us it's payments data assets or transaction assets, but that model can easily be replicated beyond payments. We have to savings to credit cards to mortgage to whatever. The point is we are only responsible for payments and we are not experts on mortgage data or insurance data. So it's up to others and other ecosystem to reuse the model. And I believe that the Commission, at least that's what they reassured us is.
Well, this can work. We have a generic law. The industry comes together and says, okay, what do we need on top of it to make it really work? And that model is maybe in a bit too strict way now enshrined in FIDA. It has to be schemes. And maybe that is where Ralf's problem is that is indeed pretty prescriptive. So you can only share data through a scheme. And if you don't do it as an industry, we'll build one for you, is what the Commission basically says.
Well, that's not going to be that easy, I'm afraid. But do you see any contradiction, Ralf, between what SPAA is and what the FIDA scheme regulation text says? you think that SPAA could to do open finance? No, I would have loved to keep the original scope of SPAA beyond payments. But as I just explained, so this was a...
sort of brought in by a scheme manager becoming the EPC become the scheme manager, but we can expand that as well, or maybe find just a, well, someone else who is running the, an open finance version of SPAA. And I'm sure there is a solution. and I'm sure there will be an interest in that.
So which is exactly why I don't think it should be or must be regulated because it will just come very naturally. And it also is a bit, you know, we have been fighting for technology neutrality now for quite some time, especially under PSD2, but it's the same here. So we should please not define or prescribe any form of technology.
Do it this way, do it that way. know, user interfaces, we all know like 10 years ago, they were done in a way which has then led to the screen scraping thing. Now a user interface, most of them, almost all of them are API based. So it's not a, you know, it's not a difference. There's not a technical difference between a user interface and a data access TPP interface. And so if,
an insurance company that doesn't have a user interface today, if they offered now, if they were now forced by law, FIDA to offer a user 24x7 interface, it would be, it would be most certainly an API based interface, mobile, et cetera. So, and then that interface could easily be used, not just by the consumer themselves, but also by a third party acting on their behalf. And we would,
And we are not talking screens here. We are talking about API access just through a user interface. And we don't need, now, if you enforce an interface on all finance companies, especially those who don't have one, then you don't want to enforce two of them. Why? I mean, one API is enough. And I mentioned before, the more parties use one API, the more likely it is to be good.
So that's for me is the approach which will happen and, but hopefully not by prescription or the regulator saying it must be done this way or that way. And also we were having, I mean, AI coming in here from the side or from wherever. And of course AI is all based on using user interfaces. These all these agents, these bots and chat GPT, bank GPT, whatever. So also have that in mind.
And finally, on a, because what we're doing now for finance, whatever we do, should, it should be the same principles should apply to other industries. So when we're talking about open mobility, open energy, open health, or all those other industries where open data should also, will also come in, then we want to have similar principles. We don't want to have.
finance industry being more whatever strangled than other industries in the concept of opening the data. So we should have similar principles and therefore whatever we apply here we should also consider that the similar thing must be also then accommodated in other industries. Now that makes sense. I mean there are two things that I think are an absolutely inevitable trends.
globally rights the APIification of everything right everything is becoming APIified We see that everywhere and also opening up right from the no closed Nokia phone to the open smartphone The open internet everything is opening up and financial services ahead of the game which is nice Europe is ahead of the game in the regulation of this which is which is also nice. So this opening up
and opening payments and opening finance on the basis of APIs. That's a global trend which is now reaching other industries. In fact, even other countries. Recently, the US, which don't usually have regulators telling the industry what to do, they are now coming up with the CFPB 1033, which means that finance industry has to also provide standard interfaces to open up.
Australia did open finance as one of the early ones. I think this is a global thing. There's no escape and thank God there isn't because that's obviously a good trend or Gijs do you have any reservations? No but it's not so much the principles. The ultimate goals are quite clear. It's more the way how do you get there? One globally unified, harmonized, standardized API for everything, for all industries would of course be
But keep on dreaming, it's not going to happen. So the question is more, how do we do this? Because of course I agree with Ralf, but there's no such thing as an ideal world, so I don't see that happening. There are many different stages of development, of standardization, etc. So I do foresee with all the, despite all the good intentions, that we will have a period of extreme fragmentation. I see it happening in my country. People are trying to develop data sharing schemes.
for financial services in the Netherlands, but it's different for insurance or pensions or mortgage. So it's already fragmenting between verticals, but it's also fragmenting between jurisdictions within jurisdictions. And I foresee a long and painful road to harmonization, which we have sort of been through in payments. mean, PSD2 and where we are now with SPAA, we are already working 25 years since the beginning of SEPA on this.
type of standardization. So the question is, what can we learn from our painful harmonization, standardization experience to speed up the process not fall into the same traps? And I'm not sure if we are having the right discussions there, what the basics should be to avoid that in terms of standardization and harmonization of data sets beyond, across industries, across sectors.
because everybody will have his or her own hobbies or whatever. So there needs to be a bottom layer standardization. I'm not sure if it's there to facilitate this harmonization. I mean, I don't think anybody was suggesting that there's going to be one API which will conquer the world and do everything from health to government to finance.
Don't you think a good starting point would already be for our area, the Berlin Group? They have API standards for all sorts of stuff in that area, right? De facto is the only one, to be honest. Again, Europe leading the world, right? Yeah. If I say so, I fully, agree. And also have been helping their Berlin Group to...
create a good, well, to go beyond the what's called the NextGenPSD2 originally, which was the PSD2 APIs and now in what's called the open finance framework by the Berlin Group. So there are quite a number of extended services they're called, but basically premium APIs that some of which we want to use for SPAA, but
many of which are not falling into the direct payment space, but are more banking. we are here on a bit of a, we could look a bit like a phased approach. So we have open payments under PSD2. And now the Berlin Group has already enlarged this to, they call it open finance, but it is, I think, open banking because their members are banks. So it is going beyond payments, but staying more or less within, in the main
within banking. So we're moving from open payments to open banking, which is already, I guess we, and we have the whole basis, the API standards more or less for most of those services there already. They actually also have already worked on beyond that, some insurance industry work for API standards. But yeah, so for me, that is the way to evolve things. And we are
Well, on the way. And the thing though is that one of the lessons learned from PSD2 is that a standard by itself is not good enough. So the problems, some of the problems we have is by this whole, by all these variations on how the standard, the Berlin Group standard has been implemented. So we have
hundreds of different implementations of the Berlin Group standards in Europe. well, here we have a similar situation. And I think what Gijs is also right is that when you look at different industry sectors like insurance, even within insurance, will have, mean, a car insurance is pretty different from health insurance and whatever other life insurance. So I guess we'll have different APIs.
or maybe API standards for those. So you may need to come to a more, it would be good to have some overall commonality harmonization, like an overall framework. then to say that an overall coordination- But remember, we had this in SPAA. So when we designed the SPAA structure there before we were shrinking it down to payments, we had exactly that. So we thought, okay, well, there is some overall layer.
which would apply to any industry, which is why we've called it asset broker, asset holder. We try to generalize those terms. An overarching scheme with sub-schemes. That's what it basically Although some would say the SPAA restricted itself because under the EPC umbrella, which can only speak about payments, it actually did payments and others like giroAPI
then came along and thought more about the open finance, the broader version. So we not only have diversity of standards, we maybe even have several schemes coming into the market. Sure. OK, I think we've gradually reached the end of our time for this podcast. I think it's been lively and interesting as always. We've not agreed on everything, which is also fun. But we have a lot of common themes, which I think we really do agree on.
So thank you again. If I may, Michael, just sorry to pick up on what Ralf said. It really is perhaps not too late. mean, if we look forward amongst different sectors, insurance, pensions, all the affected parties by FIDA, it may still not be too late. I know there are joint, at least from the financial industry perspective, joint.
lobbying letters, efforts, etc. But it might not be too late perhaps to have a SEPA SPAA-like setup across those sectors to at least try to avoid fragmentation from the outset as much as possible by creating an overall coordination body to foster harmonization in interfaces and data exchange under FIDA. And it's going to be complex because it's so many different sectors.
From a governance perspective, it could take years to organize it, but I really believe there is merit in still trying to think about to have a minimum level of coordination at the industry level together with the FISPs in this respect to really have this joint journey together and have as little fragmentation as possible. Yeah, I think that's a common theme that we developed indeed today.
So unless Ralf has another last word he wants to say. We stand ready to participate here. That's exactly what we want. OK. Then let me try and bring this episode again to a close and thank everybody for their lively participation and thanks for all the listeners and viewers and hope you enjoyed it as much as we did having our debate here. See you next time. Many thanks for watching and listening. We hope you enjoyed this episode. Looking forward to seeing you again next time.