Number: 10/6/18942
Date: 4/5/1444
Corresponding Date: 28/11/2022
Regulations Governing Open Finance Services Procedures
Number (12/2022)
Issued pursuant to the provisions of Article (65/b) of the Central Bank of Jordan Law No. (23) of 1971 and its amendments, Article (99/b) of the Banks Law No. (28) of 2000 and its amendments, and pursuant to the provisions of Article (55) of the Electronic Payment and Money Transfer System No. (111) of 2017.
Article (1):
These Regulations shall be known as "Regulations Governing Open Finance Services Procedures" and shall be effective from the date of their issuance.
Every company providing Open Finance services must regularize its status in accordance with the provisions of these Regulations within one year from the date of their entry into force, and the Central Bank may extend this period.
Article (2):
The following words and phrases shall have the meanings specified below wherever they appear in these Regulations, unless the context or indication suggests otherwise:
| Word/Phrase | Meaning |
|---|
| Company | Any bank licensed to conduct banking business in the Kingdom according to the provisions of the Banks Law, and any electronic payment and money transfer company licensed to operate in the Kingdom according to the provisions of the Electronic Payment and Money Transfer System No. (111) of 2017. |
| Board | The Board of Directors of the Company and those in its stead. |
| Senior Executive Management | Includes the General Manager or Regional Director, Deputy General Manager or Deputy Regional Director, Assistant General Manager or Assistant Regional Director, Chief Financial Officer, Internal Audit Director, Risk Management Director, Compliance Director, as well as any employee in the Company with executive authority parallel to any of the aforementioned and functionally reporting directly to the General Manager. |
| Application Programming Interfaces (APIs) | Application Programming Interfaces. A set of rules, specifications, protocols, and tools necessary to create an intermediary interface between different application programs, allowing them to communicate and facilitate interaction between them. |
| Customer Account | A financial account for the Customer with the Company containing Customer data according to the nature of the Company's business. |
| Customer Data | Any information or data about Customers or their accounts or any of their transactions held by the Company. |
| Open Finance Services | Services aimed at enabling Company Customers to securely share their financial data with Third-Party Providers (TPPs) to open the door to providing financial products and services with added value for Customers through API technology. |
| Account Information Service Provider (AISP) | The entity that possesses the technical capability and is authorized by the Customer (with explicit Customer consent) to access and use account data/information held by the Company to build and provide value-added services by processing data, and provides an alternative access point to multiple data sources other than those owned by the Company. |
| Payment Initiation Service Provider (PISP) | The entity that possesses the capability and is authorized by the Customer (with explicit Customer consent) either to enable the Customer to pass a payment transaction request only and/or to execute a payment transaction on behalf of the Customer. |
| Third-Party Provider (TPP) | The entity that uses the Application Programming Interface (API) to access Customer data in order to provide financial products and services with added value for Customers through API technology. Among them, by way of example and not limitation, are Payment Initiation Service Providers (PISPs) and/or Account Information Service Providers (AISPs). |
| Participant | The party covered by the Open Finance Services system, namely the Company and the Third-Party Provider (TPPs). |
| Explicit Customer Consent | Prior written consent or its equivalent according to relevant legislation from the account-holding Customer authorizing the Company to share their data. |
The definitions contained in the Central Bank Law, the Electronic Transactions Law, the Banks Law, the Electronic Payment and Money Transfer System, and any related legislation issued by the Central Bank shall apply wherever cited in these Regulations, unless the indication suggests otherwise.
The provisions contained in the Regulations Governing Know Your Customer and Electronic Dealing Procedures (7/2021) are considered additional requirements to those in these Regulations and shall be read with them as a single unit.
The provisions contained in these Regulations are considered additional requirements to those in the Anti-Money Laundering and Combating the Financing of Terrorism Regulations and shall be read with them as a single unit.
Article (3): Scope, Mechanism of Application, and Concerned Parties
Subject to what is stated in paragraph (b) of this Article, the provisions of these Regulations shall apply to all banks operating in the Kingdom and licensed electronic payment and money transfer companies in the Kingdom.
Branches of foreign banks/electronic payment and money transfer companies operating in the Kingdom must comply with these Regulations to the extent applicable to them, or with evidence of policies issued by the parent Bank/Company or the supervisory authority in the home country, whichever best achieves the objectives of these Regulations. In the event that the regulations issued by the parent Bank/Company or the supervisory authority in the home country better achieve the objectives of the Regulations for the branch, the branch must provide evidence of this to the Central Bank, ensuring no conflict with the laws in force in the Kingdom. In the event of a conflict, the branch must inform the Central Bank and the parent Bank/Company thereof and provide the necessary clarification regarding this conflict and obtain the Central Bank's approval on the method of addressing this conflict.
Article (4): Governance
The Board shall assume the following responsibilities and tasks:
- Ensuring the existence of suitable and effective internal control and monitoring systems and following them up by considering the understanding of key risks related to Open Finance Services facing the Company, and ensuring the adoption of necessary measures to identify and monitor these risks.
- Adopting the Open Finance Services policy and its amendments.
Senior Executive Management shall assume the following responsibilities and tasks, each according to their position:
- Supervising the formulation, implementation, and review of the Open Finance Services policy and ensuring its periodic update.
- Ensuring obtaining the opinion of the Company's Compliance Department before contracting with a Third-Party Provider (TPP).
- Ensuring that the Company's Business Continuity and Disaster Recovery plans include potential disruption and breach scenarios related to dealing with Third-Party Providers (TPPs) and testing them periodically.
- Ensuring that the relationship with Third-Party Providers (TPPs) is organized under clear and explicit written contractual agreements that define the roles, tasks, responsibilities, and rights of both parties, as well as confidentiality, privacy, information security, and non-disclosure, and defining termination provisions between them.
- Ensuring obtaining Explicit Customer Consent in accordance with applicable laws and regulations related to Open Finance Services, including:
- When granting Third-Party Provider (TPP) access to their account or any of their data.
- For services that, by their nature, require storing Customer data with the Third-Party Provider (TPP).
- Ensuring the review of all activities and services that a Third-Party Provider (TPP) is entitled to perform or provide, and regularly informing the Board of any risks that may arise from them.
- Ensuring the training, education, and awareness of its employees regarding the business activities to be provided by the Third-Party Provider (TPP) and how they relate to their business.
- Immediately informing the Central Bank of any violation or breach of applicable laws, regulations, or instructions, or any negative developments during the contracting procedures with a Third-Party Provider (TPP) that would negatively affect the Company and its procedures.
Article (5): Open Finance Services Policy
The Company is committed to establishing a documented and approved Open Finance Services policy covering all related security elements, based on global best practices, and consistent with the Company's Information Security and Cybersecurity policy. The policy must include, at a minimum:
- Detailed and clear operating procedures for regulating dealings with Third-Party Providers (TPPs).
- The data, information, processes, and services to be made accessible through Third-Party Providers (TPPs).
- The basis for contracting with Third-Party Providers (TPPs) and the minimum requirements that must be met by the Third-Party Provider (TPP) before entering into any contractual relationship with them.
- The basis for evaluating Third-Party Providers (TPPs) regarding their ability to use technical solutions capable of interacting with the programs and systems used by the Company without any fundamental modifications to their systems.
- The technical, technical, and security standards and controls to be followed when dealing with any Third-Party Provider (TPP).
- A suitable mechanism for continuous monitoring and auditing of Third-Party Providers (TPPs) in accordance with the terms and conditions of the agreement signed between the Company and the Third-Party Provider (TPP).
- The roles and responsibilities of concerned parties within the Company regarding dealing with Third-Party Providers (TPPs).
- The basis for evaluating the risks of dealing with Third-Party Providers (TPPs) and the mechanisms and controls for managing and mitigating them.
The Company is committed to publishing the most important non-confidential clauses of the Open Finance Services policy on its official and approved channels.
Article (6): Risk Management
The Company must identify, manage, and monitor any risks that may arise from contracting with a Third-Party Provider (TPP) and include them within the comprehensive risk assessment framework of the financial institution and update it, taking into account the following:
- Determining the sensitivity level of information assets and data accessed by the Third-Party Provider (TPP).
- Analyzing and evaluating the impact of dealing with the Third-Party Provider (TPP) on the Company's risk profile and achievement of its objectives, documenting them, and including them in the Company's risk register.
- Evaluating the comprehensive security and operational risks associated with dealing with the Third-Party Provider (TPP), determining the Company's role and responsibility in managing them, and documenting this evaluation and the acceptable risk level.
- Developing a plan to mitigate security and operational risks that may result from contracting with the Third-Party Provider (TPP).
- Establishing Key Risk Indicators (KRIs) to monitor the level of risks related to dealing with the Third-Party Provider (TPP) to ensure that acceptable risks (Risk Appetite) and risk tolerance levels are not exceeded.
- Developing a methodology for classifying payment transactions based on the risks these transactions may be exposed to and their suitability with the number of authentication categories used to identify the Customer when conducting payment transactions.
Article (7): Contracting with Third-Party Providers (TPPs)
When contracting with a Third-Party Provider (TPP), the Company must observe the following, at a minimum and within the scope of the contract concluded between them:
- The existence of a clear written contractual relationship between the Customer and the Third-Party Provider (TPP) defining the roles, tasks, responsibilities, and rights of both parties.
- The existence of an information security and protection policy, business continuity plans, and cyber incident response plans for the Third-Party Provider (TPP), and ensuring their effectiveness.
- The Third-Party Provider (TPP) appointing an independent specialized external entity to conduct vulnerability and security flaw assessments at least once every 6 months, and penetration testing at least once a year or after any fundamental change on their part.
- Ensuring the ability to audit and monitor the Third-Party Provider (TPP).
- Ensuring the ability to determine the minimum and maximum commissions charged by the Third-Party Provider (TPP) in accordance with orders issued by the Central Bank.
The Central Bank has the right to inspect Third-Party Providers (TPPs) within the scope of Open Finance Services they provide by employees authorized by the Central Bank or any external party appointed by the Central Bank at the Company's expense. The Company and the Third-Party Provider (TPP) are committed to cooperating with them to enable them to perform their duties fully.
The Company is committed to informing the Central Bank within a maximum of (15) days from the date of contracting with a Third-Party Provider (TPP) and after terminating the contract with them.
Article (8): API Requirements
The Company must allow Third-Party Providers (TPPs) access to Customer data and accounts using Application Programming Interfaces (APIs) to enable them to provide Open Finance Services to Customers, ensuring the Company provides, at a minimum:
- Providing, developing, maintaining, and configuring at least one API for Third-Party Providers (TPPs), whether dedicated solely to Third-Party Providers (TPPs) or the interface used for the Company's Customers.
- Verifying the identity of the Third-Party Provider (TPP) attempting to access the data and accounts made available by the Company.
- The ability to block data and accounts from unauthorized access and provide necessary protection controls against any attempts at cyberattacks or tampering.
- Maintaining the confidentiality and security of the Company's and Customers' data.
- Using appropriate and rigorous encryption mechanisms when exchanging data and information via the Application Programming Interface (API) with Third-Party Providers (TPPs).
- The suitability of the API with the nature of the tasks to be performed by the Third-Party Provider (TPP).
- Recording the Third-Party Provider (TPP)'s access to Customer accounts in the Company's access logs and the Third-Party Provider (TPP)'s access logs, as well as the operations performed on them, and the ability to refer to them when needed, and defining retention periods according to relevant legislation.
- Ensuring the security of communication sessions between Participants and the Customer.
- Ensuring the retention of records of communication sessions between Participants and the Customer according to relevant legislation.
- Ensuring the duration of communication sessions is minimized as much as possible and terminating sessions immediately upon completion of the required work.
- Ensuring the Company's ability to prevent/stop Third-Party Providers (TPPs) from unauthorized access to data or storing or processing it for purposes other than providing the permitted and agreed-upon services.
- The existence of controls for managing Customer access to services provided by Third-Party Providers (TPPs).
The Company must define Key Performance Indicators (KPIs) and operational service objectives to measure the availability and performance of the API provided to Third-Party Providers (TPPs), ensuring transparency and that they are at least at the same level as the indicators, availability, performance, and objectives of the interface dedicated to the Company available to the Company's Customers.
- Ensuring that services provided by Third-Party Providers (TPPs) do not affect the Company's services and reputation.
- Ensuring that the failure or inefficiency of the performance of the interface dedicated to Third-Party Providers (TPPs) does not affect the provision of services by the Company.
- Ensuring that all technical specifications for any interfaces are documented, specifying a set of procedures, protocols, and tools necessary for Third-Party Providers to allow their programs and applications to interact with the Company's systems.
- Informing and coordinating with Third-Party Providers (TPPs) about any changes to the technical specifications of the Application Programming Interface, ensuring no interruption in the services provided by them.
- Providing a sandbox platform to enable Third-Party Providers (TPPs) to test their programs and applications used to provide Open Finance Services, ensuring that no confidential information is shared through this platform.
- Ensuring that Customer data cannot be read by any unauthorized employees of the Participants.
When designing the API, the Company must include strategies and plans to address emergencies in the event of interface downtime or system failure, considering the following:
- Emergency response plans must include communication plans to inform Third-Party Providers (TPPs) of the necessary measures to restore service according to possible and available alternative options, and immediately.
- Agreeing with Third-Party Providers (TPPs) on a mechanism for reporting problems related to the API.
- Notifying Participants in the Open Finance Services system thereof.
The Company must observe the following when exchanging data and/or information with Third-Party Providers (TPPs):
- Providing Account Information Service Providers (AISPs) with the same data and/or information from the specific Customer account and associated payment transactions available to the Customer using Open Finance Services when requested directly.
- Providing Payment Initiation Service Providers (PISPs) with the same data and/or information regarding the initiation and execution of the payment transaction provided to the Customer using Open Finance Services when the transaction is initiated directly by the Company.
- Providing Payment Initiation Service Providers (PISPs) with information on whether the amount required to execute the payment transaction is available in the payer's account.
- In the event of an error or unexpected event during data exchange, the Company must send a notification to the Third-Party Provider (TPP) to explain the cause of the event or unexpected error.
- Designing the API so that Third-Party Provider (TPP) access is limited only to data they are authorized to view or process, and documenting these access rights appropriately, verifying them, and reviewing them periodically (at least twice a year).
Article (9): Third-Party Provider (TPP) Standards and Requirements
The Company must take adequate due diligence measures to identify and verify the identity of the Third-Party Provider (TPP) in accordance with the risks that may arise from contracting with them and through appropriate methods, in accordance with the Open Finance Services policy, systems, instructions, and applicable legislation, and continuous follow-up under the contractual relationship concluded with them. The minimum requirements below must be taken into account when dealing with each of:
Account Information Service Provider (AISP)
- Must be a local company or a branch of a foreign company licensed and registered by the relevant regulatory authorities in Jordan, possessing a good reputation, experience, and technical and professional competence and the ability to meet the requirements of the Company and its Customer.
- Must be able to conduct secure connections to request and receive data and/or information on one or more specific Customer accounts and associated financial transactions.
- Must be able to provide suitable and effective mechanisms to prevent access to information except through specific Customer accounts and associated financial transactions and based on explicit Customer consent.
- Ensuring no error in sending and directing data and/or information in the event of more than one communication session.
- Establishing a mechanism for handling Customer complaints regarding services provided by the Third-Party Provider (TPP), defining tasks and responsibilities based on different scenarios, and making them available to Customers.
- Ensuring the existence of applied internal security and supervisory controls at the Third-Party Provider (TPP) and their suitability with the nature and sensitivity of the data accessible.
- Providing a detailed action plan to the Company for the services to be performed according to the contract concluded between them.
- Ensuring that the Third-Party Provider (TPP)'s external auditor informs the Company of weaknesses in internal control systems or deterioration in the financial performance of the Third-Party Provider (TPP).
- Compliance with applicable legislation in the Kingdom.
- Possessing policies and procedures for detecting and preventing fraud.
- The ability to store data in secure ways that limit attempts at cyberattacks.
- Protecting communication sessions from unauthorized parties accessing sent data and tampering with them.
- Not requesting any additional data and/or information not required by the service provided to Customers.
- Protecting data and/or information to which the Company has access rights and ensuring no access or viewing by unauthorized third parties.
- Not using, storing, or processing data for purposes other than providing the services permitted to them.
- Not storing any sensitive Customer data according to the Company's approved classification of Customer data and information, except within the scope of Open Finance Services that necessitate it and agreed upon with the Company.
- Possessing suitable business continuity and disaster recovery plans consistent with the Company's business continuity and disaster recovery plans, and examining and updating them periodically.
- Possessing an information security and cybersecurity policy consistent with the Company's policies.
- Adhering to Customer identification and authentication policies and procedures, not less than the level of procedures followed by the Company.
- Ensuring the separation of data related to Open Finance Services and its Customers from its own data and/or other Customers' data, and providing the Company with evidence thereof.
- Immediately informing the Company in the event of any breach or any negative events that may affect the Company.
- The Third-Party Provider (TPP) must examine security flaws in their systems regarding the relationship with the Company and provide the Company with the results.
In the event that the Third-Party Provider (TPP) outsources any of its technical operations within the scope of Open Finance Services to external parties (outsourcing), it must ensure the following:
- Informing the Company of the details and scope of this contractual relationship.
- Providing assurances confirming that this external party complies with the terms of the contractual relationship between the Company and the Third-Party Provider (TPP).
- The existence of a business continuity plan and examining it periodically.
- Applying necessary security and cyber controls to protect data and not storing it in any form with them.
- Ensuring their right to monitor and audit the external party.
Payment Initiation Service Provider (PISP)
- The Payment Initiation Service Provider (PISP) must be a licensed entity by the Central Bank to conduct payment and electronic money transfer services activities in the event of providing payment execution services on behalf of the Customer, and the services to be provided must be within the scope of the license granted to them.
- Meeting all the requirements mentioned in Article (9/a) of these Regulations.
- Being able to conduct secure connections to initiate payment for the paying Customer's account and receive all information related to the initiation of the payment transaction and all available information related to the execution of the transaction with the Company.
- Providing the Company with the same information required by the Customer using Open Finance Services when initiating the payment transaction directly.
- Not possessing/holding any funds belonging to the Company's Customers at any time and in any form, except for companies licensed by the Central Bank to hold Customer funds.
- Establishing mechanisms to monitor payment transactions conducted through them to detect unauthorized payments or fraud for the purpose of implementing security measures, and ensuring that monitoring mechanisms consider potential risks.
- Ensuring that all information arising from the provision of the service reaches only the two parties to the payment transaction, with explicit Customer consent.
- Not modifying any data or information obtained to complete the service by the Customer or the Company.
- Not being able to change any information or data regarding the payment transaction request notified to them by the Customer.
Article (10): Security and Technical Standards for Open Finance Services (Open Finance Standards)
The Company must identify and document the necessary standards for providing Open Finance Services based on best practices in the field, such that the standards include, at a minimum:
- Open API Standards: These are standards that include communication protocols and architecture type, such that recognized structuring methods in the development of these interfaces are adopted.
- Data Standards: These are standards specific to data formats, data structures, and data protection and privacy rules, such that recognized data formats in the field are adopted.
- Security Standards: These are standards that define the minimum security requirements and specifications that Participants must meet, including reference to good practices in this field and applicable instructions and laws, and applying necessary security and cyber controls consistent with risks to protect their systems as well as Customer data. At a minimum, Participants must apply the latest and strongest authentication and authorization protocols.
Article (11): Consumer Protection, Data Privacy, and Data Protection
The Company must take necessary measures to educate its Customers, at a minimum, on the following:
- Protection of Open Finance Services information.
- Commissions and actual costs related to accessing data and/or information and executing financial transactions.
- Terms and conditions of Open Finance Services.
- Suitable products and services for them.
- Procedures for resolving problems related to Open Finance Services.
The Company must disclose to its Customers, before commencing any Open Finance Service, all potential risks in a clear, fair, and non-misleading manner, and continuously.
Every Company must publish a list of Third-Party Providers (TPPs) with whom they cooperate and the related products and services they will provide, and update it continuously.
Each contract related to the execution or use of Open Finance Services and the API must contain a clause acknowledging by each party that the Participants' right to control the use of this data is limited to the scope of Explicit Customer Consent.
Participants must establish suitable mechanisms to ensure that Customer data and/or information are not used for purposes contrary to the interests of these Customers. Explicit Customer consent must be continuously obtained regarding how their data is used, and they must be provided with mechanisms to withdraw consent if they wish to withdraw or modify its scope.
The Company must provide a gateway or platform for Customer Consent Management Service based on best practices in the field, to record the consents obtained, their duration, the services subscribed to/unsubscribed to, and other related matters.
Participants must have a suitable mechanism or procedure according to legislation issued by the Central Bank specifically to handle and resolve disputes related to Open Finance Services (Dispute Resolution Mechanism).
The Company must ensure that the Third-Party Provider (TPP) discloses to Customers the following:
- The trade name, address, and contact details of the Third-Party Provider (TPP) as applicable.
- A description of the main characteristics of the Open Finance Service to be provided.
- The information or identifier the Customer must provide to use Open Finance Services.
- The form and procedures for granting Explicit Customer Consent to provide Account Information Service, Payment Initiation Service, and withdrawing/modifying consent.
- Provisions related to the time and maximum duration for executing the payment service to be provided, if any.
- Transaction ceilings, if any.
- Details of all fees and commissions the Customer pays to the Third-Party Provider (TPP).
- Communication means agreed upon between the Customer and the Third-Party Provider (TPP) regarding sending information and notifications.
- The conditions under which the Customer may withdraw from the service provided by the Third-Party Provider (TPP), if any.
The Company must ensure that the Third-Party Provider (TPP) discloses the following information regarding preventive measures and corrective actions for the Customer upon contracting with the Customer:
- A description of the steps the Customer must take to maintain the security of Open Finance Services and how to notify the Third-Party Provider (TPP) regarding loss, theft, and embezzlement.
- Secure procedures through which the Third-Party Provider (TPP) will contact the Customer in the event of suspected or actual fraud or security threats.
- The conditions under which the Third-Party Provider (TPP) stops or prevents the use of Open Finance Services.
- Customer responsibility.
- Responsibility of participating parties regarding the execution, delay in execution, or non-execution of Open Finance Services and in the event of a cyber incident.
- How and within what time period the Customer must notify the Company holding the Customer's account of any unauthorized payment transaction or one that started or was executed incorrectly, and the responsibility, if any, for unauthorized payment transactions falling on the Company holding the Customer's account for unauthorized execution.
- Contract termination provisions.
Article (12): Inspection and Testing
The Company prepares a list of Use Cases for Open Finance Services, specifying the technical and security standards required from Third-Party Providers, and ensures that the Third-Party Provider (TPP) implements security, technical, and functional tests related to the provided Open Finance Services.
Article (13): General Provisions
The Central Bank has the right at any time to request the immediate or appropriate termination of the contract concluded by the Company with the Third-Party Provider (TPP), in whole or in part.
The Central Bank has the right to issue orders to determine the minimum...