2022-11-28

Added · Updated

Regulations on the Procedures for Operating Open Finance Services No. (3/2022)

The Central Bank of Jordan mandates that licensed banks and payment companies align their operations with open finance regulations within one year of issuance. The document establishes governance, risk management, and contractual obligations for third-party providers (TPPs), requiring explicit customer consent, secure API access, and strict data protection standards. It defines specific technical and security requirements for Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs) to ensure the safety and integrity of financial data sharing.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

[Central Bank of Jordan Logo]

Number: 6/10/18942 Date: 4/5/1444 Corresponding to: 28/11/2022

Regulations on the Procedures for Operating Open Finance Services No. (3/2022)

Issued pursuant to the provisions of Article (65/b) of the Central Bank of Jordan Law No. (23) of 1971 and its amendments, Article (99/b) of the Banks Law No. (28) of 2000 and its amendments, and the provisions of Article (55) of the Electronic Payment and Money Transfer System No. (111) of 2017.

Article (1): a. These Regulations shall be known as "Regulations on the Procedures for Operating Open Finance Services" and shall be effective from the date of their issuance. b. Every company providing open finance services shall regularize its status in accordance with the provisions of these Regulations within one year from the date of their entry into force, and the Central Bank may extend this period.

Article (2): a. The words and phrases appearing in these Regulations shall have the meanings assigned to them below, unless the context or circumstances indicate otherwise:

Word/PhraseMeaning
CompanyAny bank licensed to conduct banking business in the Kingdom according to the provisions of the Banks Law, and any electronic payment and money transfer company licensed to operate in the Kingdom according to the provisions of the Electronic Payment and Money Transfer System No. (111) of 2017.
BoardThe Board of Directors of the Company and those in its stead.
Senior Executive ManagementIncludes the Company's General Manager or Regional Director, Deputy General Manager or Deputy Regional Director, Assistant General Manager or Assistant Regional Director, Chief Financial Officer, Internal Audit Director, Risk Management Director, and Compliance Director, as well as any employee in the Company who holds executive authority equivalent to any of the aforementioned and is functionally linked directly to the General Manager.
Application Programming Interfaces (APIs)A set of rules, specifications, protocols, and tools necessary to create an intermediary interface between different application programs, allowing them to communicate and facilitating interaction between them.
Customer AccountA financial account for the customer with the Company containing the customer's data according to the nature of the Company's business.
Customer DataAny information or data about customers, their accounts, or any of their transactions held by the Company.
Open Finance ServicesServices aimed at enabling Company customers to securely share their financial data with Third-Party Providers (TPPs) to open the field for providing financial services and products with added value to customers through API technology.
Account Information Service Provider (AISP)The entity that possesses the technical capability and is authorized by the customer (with the customer's explicit consent) to access and use their account data/information with the Company to build and provide value-added services by processing data, and provides an alternative access point to multiple data sources other than those owned by the Company.
Payment Initiation Service Provider (PISP)The entity that possesses the capability and is authorized by the customer (with the customer's explicit consent) either to enable them to pass a payment transaction request only and/or to execute the payment transaction on behalf of the customer.
Third-Party Provider (TPP)The entity that uses the Application Programming Interface (API) to access customer data in order to provide financial services and products with added value to customers through API technology. Examples include, but are not limited to, Payment Initiation Service Providers (PISPs) and/or Account Information Service Providers (AISPs).
ParticipantThe party covered by the open finance services system, namely the Company and the Third-Party Provider (TPPs).
Explicit Customer ConsentPrior written consent or its equivalent according to relevant legislation from the account-holding customer authorizing the Company to share their data.

b. The definitions contained in the Central Bank Law, the Electronic Transactions Law, the Banks Law, the Electronic Payment and Money Transfer System, and any related legislation issued by the Central Bank shall apply wherever mentioned in these Regulations, unless the context indicates otherwise. c. The provisions contained in the Regulations on the Procedures for Know Your Customer and Electronic Dealing (2021/7) are considered additional requirements to those in these Regulations and shall be read with them as a single unit. d. The provisions contained in these Regulations are considered additional requirements to those in the Anti-Money Laundering and Combating the Financing of Terrorism Regulations and shall be read with them as a single unit.

Article (3): Scope, Application Mechanism, and Concerned Parties a. Subject to the provisions of paragraph (b) of this Article, the provisions of these Regulations shall apply to all banks operating in the Kingdom and licensed electronic payment and money transfer companies. b. Branches of foreign banks/electronic payment and money transfer companies operating in the Kingdom shall comply with these Regulations to the extent applicable to them, or with the parent Bank/Company's alternative policies, or the supervisory authority in the home country, whichever best achieves the objectives of these Regulations. If the regulations issued by the parent Bank/Company or the supervisory authority in the home country better achieve the objectives of the Regulations for the branch, then this branch must provide evidence to the Central Bank, ensuring no conflict with the prevailing legislation in the Kingdom. In case of conflict, the branch must inform the Central Bank and the parent Bank/Company thereof and provide the necessary clarification regarding this conflict and obtain the Central Bank's approval on how to address this conflict.

Article (4): Governance a. The Board shall assume the following responsibilities and tasks:

  1. Ensuring the existence of appropriate and effective internal control and monitoring systems and following them up by considering understanding the main risks related to open finance services facing the Company, while ensuring the necessary measures are taken to identify and monitor these risks.
  2. Approving the open finance services policy and its amendments. b. Senior Executive Management shall assume the following responsibilities and tasks, each according to their position:
  3. Supervising the formulation, implementation, and review of the open finance services policy and ensuring its periodic update.
  4. Ensuring obtaining the opinion of the Company's Compliance Department before contracting with a Third-Party Provider (TPP).
  5. Ensuring that the Company's business continuity and disaster recovery plans include potential disruption and breach scenarios related to dealing with a Third-Party Provider (TPP) and testing them periodically.
  6. Ensuring that the relationship with a Third-Party Provider (TPP) is organized under clear and explicit written contractual agreements that define the roles, tasks, responsibilities, rights, confidentiality, privacy, security, and non-disclosure of information of both parties, and define the termination provisions of their contract.
  7. Ensuring obtaining explicit customer consent in accordance with the laws and regulations in force related to open finance services, including: a. When allowing a Third-Party Provider (TPP) access to their account or any of their data. b. For services that, by their nature, require storing customer data with the Third-Party Provider (TPP).
  8. Ensuring the review of all activities and services that a Third-Party Provider (TPP) is entitled to perform or provide, and regularly informing the Board of any risks that may arise from them.
  9. Ensuring the training and education of its employees regarding the business activities that a Third-Party Provider (TPP) will provide and how they relate to their business.
  10. Immediately informing the Central Bank of any violation or breach of prevailing laws and regulations or any negative developments during the contracting procedures with a Third-Party Provider (TPP) that would negatively affect the Company and the Company's procedures.

Article (5): Open Finance Services Policy a. The Company is committed to establishing a documented and approved open finance services policy covering all related security elements, based on global best practices, and consistent with the Company's information security and cybersecurity policy. The policy must include, at a minimum:

  1. Detailed and clear operating procedures for regulating dealing with a Third-Party Provider (TPP).
  2. The data, information, and processes to be made accessible through a Third-Party Provider (TPP).
  3. The basis for contracting with a Third-Party Provider (TPP) and the minimum requirements that must be met by a Third-Party Provider (TPP) before entering into any contractual relationship with them.
  4. The basis for evaluating a Third-Party Provider (TPP) regarding their ability to use technological solutions capable of interacting with the programs and systems used by the Company without any fundamental modifications to their systems.
  5. The technical standards and security controls to be followed when dealing with any Third-Party Provider (TPP).
  6. An appropriate mechanism for monitoring and auditing a Third-Party Provider (TPP) according to the terms and conditions of the agreement signed between the Company and the Third-Party Provider (TPP).
  7. The roles and responsibilities of concerned parties within the Company regarding dealing with a Third-Party Provider (TPP).
  8. The basis for evaluating the risks of dealing with a Third-Party Provider (TPP) and the mechanisms and controls for managing and mitigating them. b. The Company is committed to publishing the most important non-confidential clauses of the open finance services policy on its official and approved channels.

Article (6): Risk Management The Company shall identify, manage, and monitor any risks that may arise from contracting with a Third-Party Provider (TPP) and include them within the comprehensive risk assessment framework of the financial institution and update it, taking into account the following: a. Determining the sensitivity level of the information assets and data accessed by a Third-Party Provider (TPP). b. Analyzing and evaluating the impact of dealing with a Third-Party Provider (TPP) on the Company's risk profile and achieving its objectives, documenting it, and including it in the Company's risk register. c. Evaluating the overall security and operational risks associated with dealing with a Third-Party Provider (TPP) and determining the Company's role and responsibility in managing them, documenting this evaluation and the acceptable risk level. d. Developing a plan to mitigate security and operational risks that may result from contracting with a Third-Party Provider (TPP). e. Establishing Key Risk Indicators to monitor the level of risks related to dealing with a Third-Party Provider (TPP) to ensure that acceptable risks (Risk Appetite) and risk tolerance levels are not exceeded. f. Developing a methodology for classifying payment transactions based on the risks these transactions may be exposed to and their suitability with the number of authentication categories used to identify the customer when conducting payment transactions.

Article (7): Contracting with a Third-Party Provider (TPP) a. When contracting with a Third-Party Provider (TPP), the Company shall consider the following, at a minimum and within the limits of the contract concluded between them:

  1. The existence of a clear written contractual relationship between the customer and the Third-Party Provider (TPP) defining the roles, tasks, responsibilities, and rights of both parties.
  2. The existence of an information security and protection policy, business continuity plans, and cyber incident response plans with the Third-Party Provider (TPP) and ensuring their effectiveness.
  3. The Third-Party Provider (TPP) appointing an independent specialized external entity to conduct vulnerability and security flaw assessments at least once every 6 months, and penetration testing at least once a year or after any fundamental change in their systems.
  4. Ensuring the ability to audit and monitor the Third-Party Provider (TPP).
  5. Ensuring the ability to determine the minimum and maximum commissions charged by the Third-Party Provider (TPP) according to orders issued by the Central Bank.
  6. The Central Bank has the right to inspect the Third-Party Provider (TPP) within the limits of the open finance services provided by authorized employees of the Central Bank or any external party appointed by the Central Bank at the Company's expense. The Company and the Third-Party Provider (TPP) are committed to cooperating with them to enable them to perform their duties fully. b. The Company is committed to informing the Central Bank within a maximum of (15) days from the date of contracting with a Third-Party Provider (TPP) and after terminating the contract with them.

Article (8): API Requirements The Company shall allow a Third-Party Provider (TPP) access to customer data and accounts using the Application Programming Interface (API), to enable them to provide open finance services to customers, ensuring the Company provides, at a minimum: a. Providing, developing, maintaining, and configuring at least one API for Third-Party Providers (TPPs), whether dedicated solely to Third-Party Providers (TPPs) or the interface used for the Company's customers. b. Verifying the identity of the Third-Party Provider (TPP) attempting to access the data and accounts made available by the Company. c. The ability to block data and accounts from unauthorized access and provide necessary protection controls against any attempts at cyberattacks or tampering. d. Maintaining the confidentiality and security of the Company's and customers' data. e. Using appropriate and robust encryption mechanisms when exchanging data and information via the Application Programming Interface (API) with a Third-Party Provider (TPP). f. The API's suitability for the nature of the tasks the Third-Party Provider (TPP) will perform. g. Logging the Third-Party Provider (TPP)'s access to customer accounts in the Company's access logs and the Third-Party Provider (TPP)'s access logs, and the operations performed on them, with the ability to refer to them when needed and determining retention periods according to prevailing legislation. h. Ensuring the security of communication sessions between participants and the customer. i. Ensuring the retention of communication session logs between participants and the customer according to relevant legislation. j. Ensuring the duration of communication sessions is minimized as much as possible and terminating sessions immediately upon completion of the required work. k. Ensuring the Company's ability to prevent/stop a Third-Party Provider (TPP) from unauthorized access to data or storing or processing it for purposes other than providing the permitted and agreed-upon services. l. The existence of controls for managing customer access to services provided by a Third-Party Provider (TPP). m. The Company shall determine the key performance indicators and operational objectives for the service to measure the availability and performance of the API provided to the Third-Party Provider (TPP), ensuring transparency and that they are at least at the same level as the indicators, availability, and performance of the interface dedicated to the Company available to the Company's customers. n. Ensuring that services provided by a Third-Party Provider (TPP) do not affect the Company's services and reputation. o. Ensuring that the failure or inefficiency of the performance of the interface dedicated to Third-Party Providers (TPPs) does not affect the provision of services by the Company. p. Ensuring that all technical specifications for any interfaces are documented, specifying a set of procedures, protocols, and tools necessary for Third-Party Providers (TPPs) to allow their programs and applications to interact with the Company's systems. q. Informing and coordinating with the Third-Party Provider (TPP) about any changes to the technical specifications of the API, ensuring no interruption in the services provided by them. r. Providing a testing platform to enable Third-Party Providers (TPPs) to test their programs and applications used to provide open finance services, ensuring no confidential information is shared through this platform. s. Ensuring that customer data cannot be read by any unauthorized employees of the participants. t. When designing the API, the Company shall include strategies and plans to deal with emergencies in case of interface downtime or system failure, considering the following:

  1. Emergency response plans must include communication plans to inform Third-Party Providers (TPPs) of the necessary measures to restore service according to possible and available alternative options, immediately.
  2. Agreeing with Third-Party Providers (TPPs) on a mechanism for reporting problems related to the API.
  3. Notifying participants in the open finance services system thereof. u. The Company shall consider the following when exchanging data and/or information with a Third-Party Provider (TPP):
  4. Providing Account Information Service Providers (AISPs) with the same data and/or information about the specific customer account and associated payment transactions available to the customer using open finance services when requested directly.
  5. Providing Payment Initiation Service Providers (PISPs) with the same data and/or information regarding the initiation and execution of the payment transaction provided to the customer using open finance services when the transaction is initiated directly from the Company.
  6. Providing Payment Initiation Service Providers (PISPs) with information on whether the amount required to execute the payment transaction is available in the payer's account.
  7. In the event of an error or unexpected event during data exchange, the Company shall send a notification to the Third-Party Provider (TPP) to explain the cause of the event or unexpected error.
  8. Designing the API so that the Third-Party Provider (TPP) has access only to the data they are authorized to view or process, and these access rights are appropriately documented, verified, and reviewed periodically (at least twice a year).

Article (9): Third-Party Provider (TPP) Standards and Requirements The Company shall take sufficient due diligence measures to identify and verify the identity of the Third-Party Provider (TPP) in accordance with the risks that may arise from contracting with them and through appropriate methods, according to the open finance services policy and prevailing systems and regulations, and continuous follow-up according to the contractual relationship concluded with them, and the minimum requirements below shall be taken into account when dealing with each of: a. Account Information Service Provider (AISP)

  1. Must be a local company or a branch of a foreign company licensed and registered by the relevant regulatory authorities in Jordan, possessing a good reputation, experience, and technical and professional competence and the ability to meet the requirements of the Company and its customer.
  2. Must be able to conduct secure communication to request and receive data and/or information on one or more specified customer accounts and associated financial transactions.
  3. Must be able to provide appropriate and effective mechanisms to prevent access to information except through specified customer accounts and associated financial transactions and based on explicit customer consent.
  4. Ensuring no error in sending and directing data and/or information in case of more than one communication session.
  5. Establishing a mechanism for handling customer complaints regarding the services provided by the Third-Party Provider (TPP), defining tasks and responsibilities based on different scenarios, and making them available to customers.
  6. Ensuring the existence of internal security and supervisory controls applied by the Third-Party Provider (TPP) and their suitability with the nature and sensitivity of the data accessible.
  7. Providing a detailed work plan to the Company for the services they will perform according to the contract concluded between them.
  8. Ensuring that the Third-Party Provider (TPP)'s external auditor informs the Company of weaknesses in internal control systems or a decline in the financial performance of the Third-Party Provider (TPP).
  9. Compliance with relevant legislation in force in the Kingdom.
  10. Possessing policies and procedures for detecting and preventing fraud.
  11. The ability to store data in secure ways that limit cyberattack attempts.
  12. Protecting communication sessions from unauthorized parties accessing sent data and tampering with them.
  13. Not requesting any additional data and/or information not required by the service provided to customers.
  14. Protecting the data and/or information they have access to from the Company and ensuring no access or viewing by other unauthorized parties.
  15. Not using, storing, or processing data for purposes other than providing the services they are permitted to provide.
  16. Not storing any sensitive customer data according to the Company's approved data classification related to customer data, except within the limits of open finance services that necessitate it and agreed upon with the Company.
  17. Possessing appropriate business continuity and disaster recovery plans consistent with the Company's business continuity and disaster recovery plans, and examining and updating them periodically.
  18. Possessing an information security and cybersecurity policy consistent with the Company's policies.
  19. Adhering to customer identification and authentication policies and procedures, not less than the level of procedures followed by the Company.
  20. Ensuring the separation of data related to open finance services and their customers from their own data and/or other customers' data, and providing the Company with evidence thereof.
  21. Immediately informing the Company in the event of any breach or any negative events that may affect the Company.
  22. The Third-Party Provider (TPP) shall examine security flaws in their systems regarding the relationship between them and the Company and provide the Company with the results.
  23. In the event that the Third-Party Provider (TPP) outsources any of their technical operations within the scope of open finance services to external parties (outsourcing), they must ensure the following: a. Informing the Company of the details and scope of this contractual relationship. b. Providing guarantees confirming that this external party complies with the terms of the contractual relationship between the Company and the Third-Party Provider (TPP). c. The existence of a business continuity plan and examining it periodically. d. Applying the necessary security and cyber controls to protect data and not storing it in any form with them. e. Ensuring their right to monitor and audit the external party.

b. Payment Initiation Service Provider (PISP)

  1. The Payment Initiation Service Provider (PISP) must be a licensed entity by the Central Bank to conduct payment and electronic money transfer services activities if providing payment execution services on behalf of the customer, and the services they will provide must be within the scope of the license granted to them.
  2. Achieving all the requirements contained in Article (9/a) of these Regulations.
  3. Being able to conduct secure communication to initiate payment for the payer customer's account and receive all information related to the initiation of the payment transaction and all available information related to the execution of the transaction with the Company.
  4. Providing the Company with the same information required by the customer using open finance services when initiating the payment transaction directly.
  5. Not possessing/holding any funds belonging to the Company's customers at any time or in any form, except for companies licensed by the Central Bank to hold customer funds.
  6. Establishing mechanisms to monitor payment transactions conducted through them to detect unauthorized payments or fraud for the purpose of implementing security measures, and ensuring that monitoring mechanisms consider potential risks.
  7. Ensuring that all information arising from providing the service is accessible only to the two parties of the payment transaction, with explicit customer consent.
  8. Not modifying any data or information obtained to complete the service by the customer or their Company.
  9. Not being able to change any information or data regarding the payment transaction request notified to them by the customer.

Article (10): Security and Technical Standards for Open Finance Services (Open Finance Standards) The Company must identify and document the necessary standards for providing open finance services based on best practices in the field, such that the standards include, at a minimum, the following: a. Open API Standards: These are standards that include communication protocols and architecture type, such that recognized structuring methods in the field of developing these interfaces are adopted. b. Data Standards: These are standards specific to data formats, data structures, and relevant data protection and privacy rules, such that recognized data formats in the field are adopted. c. Security Standards: These are standards that define the minimum security requirements and specifications that participants must meet, including referring to good practices in this field and relevant prevailing laws, and applying necessary security and cyber controls consistent with risks to protect their systems as well as customer data. At a minimum, the participant must apply the latest and strongest authentication and authorization protocols sufficient.

Article (11): Consumer protection and Data Privacy and data protection

a. The Company must take the necessary measures to raise customer awareness at a minimum regarding the following:

  1. Information protection.
  2. Open financial services.
  3. Commissions and actual costs related to accessing data and/or information and executing financial transactions.
  4. Provisions and terms of open financial services.
  5. Suitable products and services for them.
  6. Procedures for resolving problems related to open financial services.

b. The Company must disclose to its customers, before commencing any open financial service, all potential risks in a clear, fair, non-misleading, and continuous manner.

c. Each company must publish and continuously update a list of third-party providers (TPPs) with whom it contracts and the related products and services they will provide.

d. Every contract related to the execution or use of open financial services and APIs must include a clause acknowledging by each party that the participants' right to control the use of this data is limited to the boundaries of explicit customer consent.

e. Participants must put in place appropriate mechanisms to ensure that customers' private data and/or information are not used for purposes contrary to the interests of these customers. Explicit customer consent must be continuously obtained regarding how their data is used, and customers must be provided with opt-out mechanisms if they wish to withdraw or modify its scope.

f. The Company must provide a gateway or platform for customer consent management service based on best practices, to record the consents obtained, their duration, the services subscribed to/unsubscribed from, and other related matters.

g. Participants must have an appropriate mechanism or procedure, in accordance with regulations issued by the Central Bank specifically, to handle and resolve disputes related to open financial services (Dispute Resolution Mechanism).

h. The Company must ensure that the third-party provider (TPP) discloses to customers the following:

  1. The commercial name, address, and contact details of the third-party provider (TPP), as applicable.
  2. A description of the main characteristics of the open financial service to be provided.
  3. The information or identifier the customer must provide to use open financial services.
  4. The form and procedures for granting explicit customer consent to provide account information service, payment initiation service, and withdrawing/modifying consent.
  5. Provisions regarding the time and maximum duration for executing the payment service, if applicable.
  6. Transaction caps, if any.
  7. Details of all fees and commissions paid by the customer to the third-party provider (TPP).
  8. The agreed communication means between the customer and the third-party provider (TPP) regarding the sending of information and notifications.
  9. The terms under which the customer may withdraw from the service provided by the third-party provider (TPP), if any.

i. The Company must ensure that the third-party provider (TPP) discloses the following information regarding preventive measures and corrective measures to the customer upon contracting with the customer:

  1. A description of the steps the customer must take to maintain the security of open financial services and how to notify the third-party provider (TPP) regarding loss, theft, and embezzlement.
  2. Secure procedures through which the third-party provider (TPP) will contact the customer in case of suspected or actual fraud or security threats.
  3. The terms under which the third-party provider (TPP) stops or prevents the use of open financial services.
  4. Customer liability.
  5. Participant liability regarding the execution, delay in execution, or non-execution of open financial services and in the event of a cyber incident.
  6. How and within what time period the customer notifies the company holding the customer's account of any unauthorized payment transaction that was initiated or executed incorrectly, and the liability, if any, for unauthorized payment transactions falling on the company holding the customer's account for unauthorized execution.
  7. Contract termination provisions.

Article (12): Testing

The Company prepares a list of use cases for open financial services, specifying the technical and security standards required from third-party providers, and ensures that the third-party provider (TPP) implements security, technical, and functional tests related to the open financial services provided.

Article (13): General Provisions

a. The Central Bank has the right at any time to request the immediate or appropriate termination of the contract concluded by the Company with the third-party provider (TPP), in whole or in part.

b. The Central Bank may issue orders to determine the minimum and maximum commissions charged by companies in the open financial services system.

c. All companies are committed to making open financial services available by contracting with a third-party provider (TPP) if it meets all the requirements set out in these instructions.

d. Without prejudice to the liability of the third-party provider (TPP), the Company is fully responsible to the Central Bank for all acts of the third-party provider (TPP) within the scope of the open financial services provided by it, including its compliance with the provisions of these instructions and any subsequent instructions or circulars issued specifically regarding this matter.

[Signature] Governor Dr. Adel Al-Sharkas

More like this from CBJ

We email you every new CBJ publication the day it's published.

Topics
open-banking
privacy
Share