The Payments Trilogue

Episodes / TPT #10

EUDIW SCA

· 35 min

Video

👍 Like & comment on YouTube Subscribe to the channel

Listen

Open this episode in

Show notes

For this episode, the hosts invited an expert guest, Jan van Vonno, to discuss the EU Digital Identity Wallet (EUDIW), its implications for open banking, and the challenges of compliance and authentication. The panel shares insights on the potential benefits of a unified digital identity system across Europe specifically for the purpose of Strong Customer Authentication (SCA), while also addressing concerns about control, outsourcing, and the realities of implementation. The conversation highlights the importance of understanding the regulatory landscape and the need for banks and payment service providers to adapt to new requirements by 2027.

Chapters

  1. 0:00 Introduction to the EUDI Wallet Discussion
  2. 7:24 SCA using the EUDI wallet
  3. 12:29 SCA Control and Outsourcing
  4. 17:59 Registration Process for the EUDI wallet
  5. 23:21 The Complexity of Authentication Flows
  6. 29:03 Qualified attestation of attributes
  7. 34:07 Conclusion and Key Takeaways

Guest: Jan van Vonno (Digital identity and open banking expert)

Transcript

Michael Salmony 0:13

Hello, my name is Michael Salmony and I would like to welcome you to another episode of the Trilogue. And as you can see, this time we actually have a Quadrilog. We have a guest. And so this is a completely new format. Since I'm completely incapable of imposing any discipline on my other two guys, this is now I have three people to control. So it'll be even worse, but hopefully it'll be a lively debate. And I would like to start off with Jan van Vonno.

who I've known for a while. He's a super expert on all things open banking and identity. And that's the topic we have today. We're talking about the EU ID wallet, if that's even how it's pronounced. So straight off to you, Jan, please tell us who you are, who your company is and what this EU ID wallet is.

Jan Van Vonno 1:01

Sure, Michael, and thanks for having me. I'm super excited to be part of this, I guess, quartet in this podcast with experts like yourself, Ralf and Gijs, of course. And I guess to give you a bit of background in terms of who I am and what I do is...

I'm based in Amsterdam. I have been working in the fintech scene for just over 10 years now. Ever since I started working with fintechs, I started writing about open banking. So I've been following the open banking space quite closely over the course of my career. And in 2018, I...

I decided to take a leap of faith to join a firm, Swedish firm called Tink. Tink is an open banking technology platform that had the ambitions of enabling a new world of finance and doing that through the innovation that is unlocked with account information and payment initiation services. Today, I lead Tink's industry strategy and wallet propositions.

And as part of that work, I have joined the EWC, one of the large scale pilots for the development of the European digital identity wallets, where I get to help design and specify the requirements for strong customer authentication using this future EU digital identity wallets or EUDI wallets, as some people call it.

Yeah, so hopefully that gives you a bit of background in terms of who I am what I do.

Michael Salmony 2:52

That's very good. So EUDI wallet, that's what we'll go with. And Tink, I think, has been acquired by Visa, just to clarify that as well. But maybe you could give us a bit more background on the EUDI wallet. For me, it's one of the most exciting developments that is happening. think at last we're solving, hopefully, this identity problem, which we maybe should have solved before we started building all these digital cathedrals. At last, we actually know who is who, what their rights are.

and which attributes we can verify. Can you tell us a little bit more about what are the ambitions in the EUDI wallet?

Jan Van Vonno 3:26

Of course, yeah.

And I guess maybe give you a bit more history on Tink to allow you to fully appreciate why we care so much about the EUDI wallet. So Tink was found in 2012. But over the course of its history,

It's made four acquisitions. One of these acquisitions was actually of a similar open banking firm that was founded in 2002. So as a business, we have over two decades of open banking experience and customers who've been loyal to us over that period. And what we've seen is that over the course of the years, and in particular with the arrival and introduction of

updated payment services regulations, specifically PSD2, that brought in scope open banking services, suddenly there were significant challenges to how open banking services could be developed. And more importantly, to the authentication of users through the dedicated interfaces and APIs that banks were providing as a substitute to the customer interface.

in relation to PSD2. So this has been an ongoing challenge. I think in the media, people talk about challenges in relation to the functionality of APIs or the performance of APIs from a technical perspective. But the true challenge, the true challenge is the authentication flow. And so when we learned that the following the COVID pandemic, that the

European Council had called for a digital identity or EU wide digital identity that could be accepted across member states and would be compatible across member states. This was of course something that could potentially solve some of the challenges that open banking service providers experience today. So there is already a regulation for this.

It is an amendment to 2014 Electronic Identification, Authentication and Trust Services Regulation, otherwise known as EIDAS. EIDAS 1.0, or the first version of it, was enforced in 2014, and they got updated earlier this year in May 2024. And with that updated regulation, essentially, member states will be required to issue

Gijs Boudewijn 6:04

you

Jan Van Vonno 6:14

a digital identity wallet for their citizens before the end of 2026. And all regulated businesses or large enterprises that have a legal or contractual obligation to identify their users will be required to accept the digital identity wallets by the end of 2027. And with that, of course, regulated businesses

also financial services and payment services. And so with the prospects of a digital identity wallet that may be performing as well as some of the national digital identity services that we see in markets like Bank ID in Sweden or It's Me in Belgium, we of course get excited with the prospects of not finding

improving significantly the conversion rates of users when they try to authenticate themselves towards banks when using Open Banking services.

Michael Salmony 7:24

So you're rightly spotlighting the A in the EIDAS, right? The authentication part of this legislation. And if I understand it right, it means that, for example, the authentication may move from my mobile banking app or from my online banking into this new identity wallet. Maybe we can just ask Gijs to just chip in and what he thinks of that.

Gijs Boudewijn 7:50

What do think of that? Well, customer choice is always good. Better customer journeys are always preferable, of course. So fundamentally, this is a great idea. I recall having conversations with Dave Birch years and years ago. And we agreed, shouldn't we have a digital financial sort of passport thingy, which really is what the EUDI wallet could be to have one thing across Europe.

across the EU for access to your financial services and your data. So I'm fully with you on the concept. Of course, in practice, it's always a little bit more complicated. well, we said that in many times, let's say my constituents are, of course, very busy with becoming compliance with whatever regulation there is out there. there's a little bit of a concern, the concern being

that, and that is where we will talk a lot to young on this, to create awareness at our banks. Guys, please be aware of what is coming at you. You will need to be compliant and don't deny it. You can't wait away this problem. There is something coming up and you need to be compliant by 2027.

and you need to plan for that, you need to budget for that because something is coming, the EUDI wallet that the customers choose, you will have to accept it mandatory as an alternative to your own SCA mechanisms. Of course, that also holds an opportunity. You may want to get rid of your own SCA mechanism, but then all customers would need to have a new ID wallet. And that is, of course, a problem because in an ideal world, you would only have one authentication method to support, but banks will have to support both. They're good old legacy.

stuff if I may call it that way and the new EUDI wallet and that of course is stacking one cost on the other and that's of course the tragic of incumbents that you always have to support everything the old stuff and the new stuff so there is probably a huge cost impact and we're trying to get our heads around what the minimum apart from all the beautiful panoramas one could have and what we're looking at and the large-scale pilots

But just what we try to get our heads around in our association calls with the European Banking Federation, what does just baseline compliance with EIDAS 2.0 mean by when, even if you don't believe in what could be done with the points of what must be done and how do you do that. and it's not defensive, but first you need to have, and we'll recall that we have the PSD2 baseline, the famous what is mandatory on the PSD2 in terms of service.

Here also, first you need to know what is the compliance baseline and then you can start fantasizing what else you could do. But first you have to know what you have to do. And that is the challenge, create awareness for that. Giving clarity to the community doesn't help. There's two silos in the commission, DG Fisma, DG Connect. Let's not go there. I think we're well on our way to cooperate together to make the best of it.

Michael Salmony 11:06

I mean, that's clear, but I was surprised you didn't mention one thing, that sort of loss of control. I remember when the Face ID and biometrics happened, banks were increasingly understandably sensitive that maybe their authentication is going to be based on Apple or Google. Isn't this another step where you're leaving authentication to people like Jan? And doesn't that worry you?

Gijs Boudewijn 11:30

Well, personally, not me, but that doesn't mean that all my constituents are not worrying. This is also about, is it outsourcing? Is it not outsourcing? You get some funny discussions like that using biometric fingerprint from Apple. Is that outsourcing something to a third party for which you need an agreement? You could also have all sorts of complicated, complex discussions on that sort of stuff. I would say, again, I'm not a technical expert. If the government and or private parties

build those beautiful wallets, hey, then I don't have to do it myself anymore. So I'm not sure. But the point is, it's to the choice of the consumer. Consumers are not mandated to use the bloody wallet. again, you have to support both your old SCA mechanism and the new wallet. And that is a little bit tragic. So fundamentally, conceptually, the great thing. But in practice, it's a little bit less beautiful, probably.

Michael Salmony 12:05

Good.

Okay, Jan, do you want to allay any fears, resting fears about cost and outsourcing and dependency or do you think that was fair?

Jan Van Vonno 12:36

Well,

let me first clarify that the work that we're currently doing not at all involves becoming an identity wallet provider at all. And I want to acknowledge many of Gijs' concerns because he's absolutely right. The compliance requirements aren't clearly defined yet. In fact, was only the 4th of December

that the European Commission published the first batch of so-called implementing acts, which will include the requirements for member states in relation to the issuing of, for example, a personal identity document or a qualified attestation of attributes. These are the types of

let's say digital artifacts that can be stored inside of the wallet, as well as rules around the certification of potential identity wallet providers. And that's just on a member state level. If we then take one step down into, for example, the payment services industry, I think we are all aware that in the current draft of the payment services regulation, there is an explicit reference for the European Banking Authority

to write regulatory technical standards around in relation to the acceptance of the digital identity wallets. And that the draft of the RTS won't be published or is unlikely to be published until 12 months after the enforcement of the new PSR. that means that we're going to stretch it in terms of the timelines trying to meet the 2027 target dates or the November 2027.

2027 target dates. If any of these pieces of legislation, whether the implementing act, whether the PSR or the RTS get delayed for any reason.

Michael Salmony 14:36

I'll be assisted.

Gijs Boudewijn 14:37

So we need all

things together and that's the problem here.

Michael Salmony 14:40

Yeah, it's a super

ambitious project from all sorts of dimensions, but I think it's one of the most exciting things that we're doing. Ralf, what do you think? I mean, Jan comes from your side of the world, from the TPPs, and so you must be super happy with everything he said.

Ralf Ohlhausen 14:56

That's right. And it's, of course, not only Tink that is happy about it, but yeah, TPPs in general, I work with many as you know, and when indeed when this was first considered, which is like a four or five years ago, four years, I don't know, when the idea of revising EIDAS into EIDAS 2.0, what where this is part of

was first conceptualized. So we have been involved right from the start there to use the idea of having a an electronic identity for the purpose of authentication because yeah, you mentioned already the SCA and the SCA flow is one of the one of the big headaches that we have from a TPP perspective with many, many, many banks, not all of them. Some are good.

but there are many who are not. so having an alternative here is exactly what we wanted. So there are maybe two other aspects, one on electronic KYC, where this could be very, very helpful too, in addition to payments and...

As I mentioned in our Christmas special on the digital euro, think the timing almost comes closely together here with the ideas on a digital euro. So maybe if that was token based, so I have those in this wallet here to actually go even beyond authentication and actually doing payments with a digital euro. That is, I think, also envisageable. focus today and now is indeed authentication. And we really, really hope that

this will work out maybe, but there's a lot of devil in the detail. So maybe if I could quiz you on one particular concern I'm having is that as far as I understand it, now there are these different large pilots out, I know you're part of EWC, there's also NOBID, which has come up with a number of suggestions on the flow. There is the

I think from a bank side, some expectation that the SCA should use the bank's credentials. Whilst from my expectation, I thought, it would be the government credential. So you get this wallet, a government issued wallet with government issued credentials. And then that is to be accepted by, and by the way, not just banks, but also all the big tech. this is all about, or not all about, but this is a lot also about getting identity sovereignty for Europe.

and not have everyone sign in with Google or Facebook or whatever, but sign in with the EUDI wallet using your government issued credentials yet to a high level standard even of reliability. And yeah, and so there is a bit of I think a controversy there which credentials to be used for payments, isn't it Jan?

Gijs Boudewijn 17:40

Sure.

Hmm?

Jan Van Vonno 17:59

Well, truth is that I think if you're a new user, you open a new bank account, there will be an obligation, of course, for payment service providers to accept the PID, the payment identity documents that is available inside the wallet, as a legitimate identification, proof of identification, government issued identification.

that essentially that process will also create the link required between the identity wallets and the newly provisioned IBAN or payment accounts. However, for the vast majority of banks and their existing customers, the unique identifier that is being used to

for the relationship between the user and the IBAN is not a government issued identifier. This is often unique to the bank itself. can be a login name, can be a code, it can be an email address even. But that unique identifier is not something that is issued by the government. And for that reason,

If you download a digital identity wallet and you go to your bank, they won't be able to recognize you as the user without you first registering that wallet against the bank. And that registration process allows them to make the relationship between you as a user and the IBAN where you hold your savings, for example.

Gijs Boudewijn 19:40

Exactly.

Ralf Ohlhausen 19:41

Hang on, hang on, hang on.

Okay,

okay. Okay. But but hang on. So if I walk in today to my bank branch, with my and I want to make a bank transfer, so it still exists. So I know. Not that I'm doing it often. But if I walk in, and want to do a bank transfer there at the counter, they'll give me a form to fill in and to sign. And they will ask that they will ask for my

Gijs Boudewijn 20:02

passport.

Well, not in my country, Ralf, in Germany maybe.

Ralf Ohlhausen 20:22

they will ask for

my passport, so I or identity, my government identity, which I give to them. And then I can make that payment. So what I've done is I have used my signature, or then it would be electronic signature, I've used my passport, I then my EUDI wallet. And, and I would expect this

Gijs Boudewijn 20:40

hang in there Ralf, hang

in there. There is a visual registration, a visual identification. There's the bank employee and that is not possible in the digital space. That is the difference. This registration needs to be done first because they can't see you if you log in. That's the analogy.

Ralf Ohlhausen 20:57

Well, what if?

Okay, so well, then what if I go to the notary buying a house? And, and I will be able to do this with this. So this this identity wallet is supposed to have the highest level of security, has to the highest level of authenticity or whatever it's called. So so you are

Jan Van Vonno 21:20

Yeah, confidence,

yeah, qualification.

Ralf Ohlhausen 21:21

Yeah, so you

are, you can buy a house, but you can get married with it, can get divorced with it, you can get everything with it. And don't tell me that I can't buy whatever book at Amazon with it.

Gijs Boudewijn 21:28

Mm-hmm.

Jan Van Vonno 21:35

The thing is you will be able to do that. But there needs to be some type of relationship established between the device and the application on the device and your existing accounts. most banks, or many banks, I can't speak on behalf of most banks, but many banks in different jurisdictions within the EU.

are required by the data protection authorities to discard any identity codes or numbers that are not required for the provision of a payment service. So for example, even though in Sweden, where Tink is from, it is very common to use a social security number as a way to identify yourself as a user, in the Netherlands,

Banks typically discard the citizens number, the BSN number. That way, there's no relationship between a digital passport document and the IBAN itself because there may be only the name and the date of birth, but typically that doesn't provide the confidence that payment service providers need to establish that relationship. There's no unique identifier because they do not have.

the citizen number on file. They do not have the social security number on file. And because we need to cater to a market that allows for all banks to be able to accept this digital identity wallet, not just some banks, we need to explore what registration process would be required to do that.

Michael Salmony 23:21

Well, this is getting pretty technical now. Yeah. Can I just pull it up a little bit with one thing that was raised earlier, the flow? I mean, there was some concern when the TPP world emerged that you were at your merchants, then you were rerouted to the TPP and then you're rerouted to your bank. Now you're also going to be rerouted to this EUDI wallet. Isn't that rather a lot of reroutes?

Jan Van Vonno 23:47

Well, the truth is that this is already the case today, right? So typically what happens today, indeed from the merchant checkout page, you are redirected to a gateway or to, in this case, a payment initiation service provider who requests consent for the processing of the, not the processing of the transaction, but of course for the processing of the data in relation to the transaction. And after which,

the user typically identifies from what bank they want to pay. And from that step, the PISP redirects the user to that bank in order to complete an authentication. Now, that bank may or may not support a mobile bank app authentication or redirection, may or may not support a national identity authentication like bank ID, or It's me.

So the reality, there is already a number of different steps. I think the opportunity with the digital identity wallets isn't just an alternative authentication mechanism for a bank led flow where the bank redirects or is in control, say, let me rephrase, where the bank is the relying party towards the identity wallets, but potential opportunities for the merchant.

to become the relying party towards the wallet. And that way the merchant can not just request, for example, from the wallet evidence of the authentication or signature as proof of an authorization, but also potentially a verification of the date of birth for a regulated product, such as purchasing

alcohol at a vending machine or kitchenware online, the ability to request, for example, a coupon for discounts or a loyalty card for rewards. The idea that the digital identity wallet can only be used for identification is actually flawed. It can be used for

a whole range of services. And if we unlock the opportunities for the relying parties to be anyone from the bank to the merchants, you can start to see how the customer experience can be incredibly intuitive and cover many of the steps that currently require minutes of your time into only a couple seconds.

Michael Salmony 26:37

Any of you guys have some comments on this?

Gijs Boudewijn 26:39

Well, the promise is there and I fully concur with Jan, but the concept is one thing and the promise is one thing, the reality is more difficult because we have legacy systems, have legacy stuff and so it's not we are in a big bang entering a brave new world as Jan described.

Ralf Ohlhausen 27:03

If

I think the promise, yeah, I have great hopes, and I always had great hopes on this identity solutions. I very much like the fact that the EU approach here is very much inspired by the self sovereign identity concept of W3C. we're basically giving the customer themselves the power.

Gijs Boudewijn 27:32

Mm-hmm.

Ralf Ohlhausen 27:33

of,

of, of handling the data self custody, to a large extent. Now, I understand that for some credentials, and it's also follows, by the way, you know, this concept of verifiable credentials, verifiable presentations, all this inspired by W3C. Great. But I

What I hope for is that the customers are not just relying on other parties to download whatever authorized, what is it called, authorized credentials like my whatever university diploma or whatever my bank account data. I can do that myself. I can enter my IBAN myself. I can create a QR code with my IBAN myself and I can show that and it can be used. Now I know that

All data I'm using myself is, well, is not authorized, is not countersigned by someone, not by the bank. So if a merchant is scanning my QR code that I created myself, it's not the same as if I was using the IBAN or the credential that was put in by the bank at the sign up onboarding process that you mentioned. So it's maybe a different level.

of security there for the merchant, but it's not a difference for me because you know, I know that the I when I put in is the right one. I did it myself.

Jan Van Vonno 29:03

So a couple things. So you're absolutely right that attestations of attributes can be of different degrees and so-called qualified attestations of attributes will be from, can only be issued from a trusted source that is registered on a trusted list, right? So there is going to be distinction between the level of confidence a relying party

which is the party that's calling on the wallet, the level of confidence that they have in the attestations, the documents that are presented to them, depending on whether they are qualified or not. So if you create an IBAN yourself and you load that into the wallet, you can present that, of course, as a credential. But for the relying party that is looking for a validated

credential that is qualified and issued by the source of that IBAN, by the originator of that IBAN, depending on their requirements, they may or may not accept that at face value. the whole perspective of EIDAS is to create this trusted framework and have different actors within that framework providing

confidence, levels of different levels of confidence towards one another in relation to the services that are unlocked with the wallet. Yeah, and I think I think the the registration process, let me just finish on that, because the registration process doesn't just establish the relationship between the user and and the IBAN. We also believe it overcomes some of the potentially

legal challenges with the current text of the PSR, which is this notion of whether or not the authentication performed by the identity wallets can be categorized as a delegated SCA or not. And so there's a specific article proposed in the PSR that would require

outsourcing agreements for any outsourcing of the SCA or any delegation of the SCA. And we believe that it would be incredibly difficult for even the government issued wallets, which are a couple dozen wallets, to establish outsourcing agreements with the three and a half thousand different payment service providers across the EU.

And so the registration process is more than just creating the linkage, but it is allowing the PSP, the bank to put a unique cryptogram, an attestation, a payment wallet attestation inside the identity wallet that only it can read, only it can recognize. And doing this, we believe that it can qualify as an element of possession.

It can allow for an interpretation that is not interpreted as a delegation of SCA because essentially the ASPSP is in full control of the SCA because only with its own attestation can the SCA be completed. So the registration really addresses two challenges. One is creating the relationship and the other is overcoming the potential interpretation of a requirement for delegated SCA outsourcing agreements.

Gijs Boudewijn 32:54

Now, I'm very happy that Jan explained this one so well, because Ralf would interpret this. so the banks instructed Jan to tell that they need to do that, otherwise they would have to have these outsourcing arrangements, etc. etc. This is just the technical reality, Ralf. this is what it is. This is as good as it gets. And this is what we have to live with.

Michael Salmony 32:54

Can I see where smiling just then, maybe.

Gijs Boudewijn 33:21

But I think especially the beauty on the new customers on the onboarding, course, banks all see the benefit of that. How easy that could be because it will help them too. So the new customers, new IBANs, binding, linking, the stating, registering, whatever, new customers, new IBANs, yay, great. But the vast majority is the installed client base. And that's what we have to work with. You have to make the link and avoid the outsourcing stuff.

And that really is the challenge. And it's difficult enough to think all this through what that really means in practice. And we have to agree on a common interpretation that this is indeed the way it should be because the governments and the regulators are not going to give us that clarity, unfortunately.

Michael Salmony 34:07

Very good. Are there any burning issues left because we're gradually coming to the end of our time?

Ralf Ohlhausen 34:13

No, it's great. It was really great Jan having you explaining this so well. better than I did and better than me and guys arguing about it, some clarity and truth behind around.

Gijs Boudewijn 34:29

Speak for yourself, Ralf.

Ralf Ohlhausen 34:31

Ha!

Michael Salmony 34:32

Really

good. I'm a really subject matter expert here, Jan. Thank you so much for joining this quartet indeed this time. Okay, so thanks to everybody who took part here today and thanks to everybody watching and look forward to seeing you for another trilogue. Not all of them are quite as hardcore geeky as this one. So I hope you enjoyed this one as well. Okay, see you next time.