2022-11-28
Added · Updated
The Central Bank of Jordan mandates that licensed banks and payment companies align their operations with open finance regulations within one year of issuance. The document establishes governance, risk management, and contractual obligations for third-party providers (TPPs), requiring explicit customer consent, secure API access, and strict data protection standards. It defines specific technical and security requirements for Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs) to ensure the safety and integrity of financial data sharing.
[Central Bank of Jordan Logo]
Number: 6/10/18942 Date: 4/5/1444 Corresponding to: 28/11/2022
Regulations on the Procedures for Operating Open Finance Services No. (3/2022)
Issued pursuant to the provisions of Article (65/b) of the Central Bank of Jordan Law No. (23) of 1971 and its amendments, Article (99/b) of the Banks Law No. (28) of 2000 and its amendments, and the provisions of Article (55) of the Electronic Payment and Money Transfer System No. (111) of 2017.
Article (1): a. These Regulations shall be known as "Regulations on the Procedures for Operating Open Finance Services" and shall be effective from the date of their issuance. b. Every company providing open finance services shall regularize its status in accordance with the provisions of these Regulations within one year from the date of their entry into force, and the Central Bank may extend this period.
Article (2): a. The words and phrases appearing in these Regulations shall have the meanings assigned to them below, unless the context or circumstances indicate otherwise:
| Word/Phrase | Meaning |
|---|---|
| Company | Any bank licensed to conduct banking business in the Kingdom according to the provisions of the Banks Law, and any electronic payment and money transfer company licensed to operate in the Kingdom according to the provisions of the Electronic Payment and Money Transfer System No. (111) of 2017. |
| Board | The Board of Directors of the Company and those in its stead. |
| Senior Executive Management | Includes the Company's General Manager or Regional Director, Deputy General Manager or Deputy Regional Director, Assistant General Manager or Assistant Regional Director, Chief Financial Officer, Internal Audit Director, Risk Management Director, and Compliance Director, as well as any employee in the Company who holds executive authority equivalent to any of the aforementioned and is functionally linked directly to the General Manager. |
| Application Programming Interfaces (APIs) | A set of rules, specifications, protocols, and tools necessary to create an intermediary interface between different application programs, allowing them to communicate and facilitating interaction between them. |
| Customer Account | A financial account for the customer with the Company containing the customer's data according to the nature of the Company's business. |
| Customer Data | Any information or data about customers, their accounts, or any of their transactions held by the Company. |
| Open Finance Services | Services aimed at enabling Company customers to securely share their financial data with Third-Party Providers (TPPs) to open the field for providing financial services and products with added value to customers through API technology. |
| Account Information Service Provider (AISP) | The entity that possesses the technical capability and is authorized by the customer (with the customer's explicit consent) to access and use their account data/information with the Company to build and provide value-added services by processing data, and provides an alternative access point to multiple data sources other than those owned by the Company. |
| Payment Initiation Service Provider (PISP) | The entity that possesses the capability and is authorized by the customer (with the customer's explicit consent) either to enable them to pass a payment transaction request only and/or to execute the payment transaction on behalf of the customer. |
| Third-Party Provider (TPP) | The entity that uses the Application Programming Interface (API) to access customer data in order to provide financial services and products with added value to customers through API technology. Examples include, but are not limited to, Payment Initiation Service Providers (PISPs) and/or Account Information Service Providers (AISPs). |
| Participant | The party covered by the open finance services system, namely the Company and the Third-Party Provider (TPPs). |
| Explicit Customer Consent | Prior written consent or its equivalent according to relevant legislation from the account-holding customer authorizing the Company to share their data. |
b. The definitions contained in the Central Bank Law, the Electronic Transactions Law, the Banks Law, the Electronic Payment and Money Transfer System, and any related legislation issued by the Central Bank shall apply wherever mentioned in these Regulations, unless the context indicates otherwise. c. The provisions contained in the Regulations on the Procedures for Know Your Customer and Electronic Dealing (2021/7) are considered additional requirements to those in these Regulations and shall be read with them as a single unit. d. The provisions contained in these Regulations are considered additional requirements to those in the Anti-Money Laundering and Combating the Financing of Terrorism Regulations and shall be read with them as a single unit.
Article (3): Scope, Application Mechanism, and Concerned Parties a. Subject to the provisions of paragraph (b) of this Article, the provisions of these Regulations shall apply to all banks operating in the Kingdom and licensed electronic payment and money transfer companies. b. Branches of foreign banks/electronic payment and money transfer companies operating in the Kingdom shall comply with these Regulations to the extent applicable to them, or with the parent Bank/Company's alternative policies, or the supervisory authority in the home country, whichever best achieves the objectives of these Regulations. If the regulations issued by the parent Bank/Company or the supervisory authority in the home country better achieve the objectives of the Regulations for the branch, then this branch must provide evidence to the Central Bank, ensuring no conflict with the prevailing legislation in the Kingdom. In case of conflict, the branch must inform the Central Bank and the parent Bank/Company thereof and provide the necessary clarification regarding this conflict and obtain the Central Bank's approval on how to address this conflict.
Article (4): Governance a. The Board shall assume the following responsibilities and tasks:
Article (5): Open Finance Services Policy a. The Company is committed to establishing a documented and approved open finance services policy covering all related security elements, based on global best practices, and consistent with the Company's information security and cybersecurity policy. The policy must include, at a minimum:
Article (6): Risk Management The Company shall identify, manage, and monitor any risks that may arise from contracting with a Third-Party Provider (TPP) and include them within the comprehensive risk assessment framework of the financial institution and update it, taking into account the following: a. Determining the sensitivity level of the information assets and data accessed by a Third-Party Provider (TPP). b. Analyzing and evaluating the impact of dealing with a Third-Party Provider (TPP) on the Company's risk profile and achieving its objectives, documenting it, and including it in the Company's risk register. c. Evaluating the overall security and operational risks associated with dealing with a Third-Party Provider (TPP) and determining the Company's role and responsibility in managing them, documenting this evaluation and the acceptable risk level. d. Developing a plan to mitigate security and operational risks that may result from contracting with a Third-Party Provider (TPP). e. Establishing Key Risk Indicators to monitor the level of risks related to dealing with a Third-Party Provider (TPP) to ensure that acceptable risks (Risk Appetite) and risk tolerance levels are not exceeded. f. Developing a methodology for classifying payment transactions based on the risks these transactions may be exposed to and their suitability with the number of authentication categories used to identify the customer when conducting payment transactions.
Article (7): Contracting with a Third-Party Provider (TPP) a. When contracting with a Third-Party Provider (TPP), the Company shall consider the following, at a minimum and within the limits of the contract concluded between them:
Article (8): API Requirements The Company shall allow a Third-Party Provider (TPP) access to customer data and accounts using the Application Programming Interface (API), to enable them to provide open finance services to customers, ensuring the Company provides, at a minimum: a. Providing, developing, maintaining, and configuring at least one API for Third-Party Providers (TPPs), whether dedicated solely to Third-Party Providers (TPPs) or the interface used for the Company's customers. b. Verifying the identity of the Third-Party Provider (TPP) attempting to access the data and accounts made available by the Company. c. The ability to block data and accounts from unauthorized access and provide necessary protection controls against any attempts at cyberattacks or tampering. d. Maintaining the confidentiality and security of the Company's and customers' data. e. Using appropriate and robust encryption mechanisms when exchanging data and information via the Application Programming Interface (API) with a Third-Party Provider (TPP). f. The API's suitability for the nature of the tasks the Third-Party Provider (TPP) will perform. g. Logging the Third-Party Provider (TPP)'s access to customer accounts in the Company's access logs and the Third-Party Provider (TPP)'s access logs, and the operations performed on them, with the ability to refer to them when needed and determining retention periods according to prevailing legislation. h. Ensuring the security of communication sessions between participants and the customer. i. Ensuring the retention of communication session logs between participants and the customer according to relevant legislation. j. Ensuring the duration of communication sessions is minimized as much as possible and terminating sessions immediately upon completion of the required work. k. Ensuring the Company's ability to prevent/stop a Third-Party Provider (TPP) from unauthorized access to data or storing or processing it for purposes other than providing the permitted and agreed-upon services. l. The existence of controls for managing customer access to services provided by a Third-Party Provider (TPP). m. The Company shall determine the key performance indicators and operational objectives for the service to measure the availability and performance of the API provided to the Third-Party Provider (TPP), ensuring transparency and that they are at least at the same level as the indicators, availability, and performance of the interface dedicated to the Company available to the Company's customers. n. Ensuring that services provided by a Third-Party Provider (TPP) do not affect the Company's services and reputation. o. Ensuring that the failure or inefficiency of the performance of the interface dedicated to Third-Party Providers (TPPs) does not affect the provision of services by the Company. p. Ensuring that all technical specifications for any interfaces are documented, specifying a set of procedures, protocols, and tools necessary for Third-Party Providers (TPPs) to allow their programs and applications to interact with the Company's systems. q. Informing and coordinating with the Third-Party Provider (TPP) about any changes to the technical specifications of the API, ensuring no interruption in the services provided by them. r. Providing a testing platform to enable Third-Party Providers (TPPs) to test their programs and applications used to provide open finance services, ensuring no confidential information is shared through this platform. s. Ensuring that customer data cannot be read by any unauthorized employees of the participants. t. When designing the API, the Company shall include strategies and plans to deal with emergencies in case of interface downtime or system failure, considering the following:
Article (9): Third-Party Provider (TPP) Standards and Requirements The Company shall take sufficient due diligence measures to identify and verify the identity of the Third-Party Provider (TPP) in accordance with the risks that may arise from contracting with them and through appropriate methods, according to the open finance services policy and prevailing systems and regulations, and continuous follow-up according to the contractual relationship concluded with them, and the minimum requirements below shall be taken into account when dealing with each of: a. Account Information Service Provider (AISP)
b. Payment Initiation Service Provider (PISP)
Article (10): Security and Technical Standards for Open Finance Services (Open Finance Standards) The Company must identify and document the necessary standards for providing open finance services based on best practices in the field, such that the standards include, at a minimum, the following: a. Open API Standards: These are standards that include communication protocols and architecture type, such that recognized structuring methods in the field of developing these interfaces are adopted. b. Data Standards: These are standards specific to data formats, data structures, and relevant data protection and privacy rules, such that recognized data formats in the field are adopted. c. Security Standards: These are standards that define the minimum security requirements and specifications that participants must meet, including referring to good practices in this field and relevant prevailing laws, and applying necessary security and cyber controls consistent with risks to protect their systems as well as customer data. At a minimum, the participant must apply the latest and strongest authentication and authorization protocols sufficient.
Article (11): Consumer protection and Data Privacy and data protection
a. The Company must take the necessary measures to raise customer awareness at a minimum regarding the following:
b. The Company must disclose to its customers, before commencing any open financial service, all potential risks in a clear, fair, non-misleading, and continuous manner.
c. Each company must publish and continuously update a list of third-party providers (TPPs) with whom it contracts and the related products and services they will provide.
d. Every contract related to the execution or use of open financial services and APIs must include a clause acknowledging by each party that the participants' right to control the use of this data is limited to the boundaries of explicit customer consent.
e. Participants must put in place appropriate mechanisms to ensure that customers' private data and/or information are not used for purposes contrary to the interests of these customers. Explicit customer consent must be continuously obtained regarding how their data is used, and customers must be provided with opt-out mechanisms if they wish to withdraw or modify its scope.
f. The Company must provide a gateway or platform for customer consent management service based on best practices, to record the consents obtained, their duration, the services subscribed to/unsubscribed from, and other related matters.
g. Participants must have an appropriate mechanism or procedure, in accordance with regulations issued by the Central Bank specifically, to handle and resolve disputes related to open financial services (Dispute Resolution Mechanism).
h. The Company must ensure that the third-party provider (TPP) discloses to customers the following:
i. The Company must ensure that the third-party provider (TPP) discloses the following information regarding preventive measures and corrective measures to the customer upon contracting with the customer:
Article (12): Testing
The Company prepares a list of use cases for open financial services, specifying the technical and security standards required from third-party providers, and ensures that the third-party provider (TPP) implements security, technical, and functional tests related to the open financial services provided.
Article (13): General Provisions
a. The Central Bank has the right at any time to request the immediate or appropriate termination of the contract concluded by the Company with the third-party provider (TPP), in whole or in part.
b. The Central Bank may issue orders to determine the minimum and maximum commissions charged by companies in the open financial services system.
c. All companies are committed to making open financial services available by contracting with a third-party provider (TPP) if it meets all the requirements set out in these instructions.
d. Without prejudice to the liability of the third-party provider (TPP), the Company is fully responsible to the Central Bank for all acts of the third-party provider (TPP) within the scope of the open financial services provided by it, including its compliance with the provisions of these instructions and any subsequent instructions or circulars issued specifically regarding this matter.
[Signature] Governor Dr. Adel Al-Sharkas
More like this from CBJ
We email you every new CBJ publication the day it's published.