Tomorrow's Transactions » API http://tomorrowstransactions.com Thought leadership from Consult Hyperion Wed, 10 Sep 2014 20:33:30 +0000 en-US hourly 1 http://wordpress.org/?v=4.0 API Blast part 2: ECB, EBA and DAG http://tomorrowstransactions.com/2014/07/api-blast-part-2-ecb-eba-and-dag/ http://tomorrowstransactions.com/2014/07/api-blast-part-2-ecb-eba-and-dag/#respond Thu, 17 Jul 2014 08:57:20 +0000 http://tomorrowstransactions.com/?p=4518 In time, banks are going to be “Amazonised” and will open their APIs both internally and externally. So what should the focus of the API be? The customer, maybe, rather than their money. A couple of years ago at the Intellect/Payments Council conference, I gave a talk that touched on the “triple A play” strategy […]

The post API Blast part 2: ECB, EBA and DAG appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

In time, banks are going to be “Amazonised” and will open their APIs both internally and externally. So what should the focus of the API be? The customer, maybe, rather than their money.

A couple of years ago at the Intellect/Payments Council conference, I gave a talk that touched on the “triple A play” strategy of Authentication, Apps and Application Programming Interfaces (APIs) for payment providers and I said that for most people, most of the time, there will be no “payment experience” because the payments will vanish into the apps. David Marcus, who was then President of PayPal, said the same.

I believe we’re heading very quickly toward a new era in which payments will essentially disappear.

[From State of Payments: Reinventing Money | LinkedIn]

I referred back to this to kick off my talk at the excellent MEETS 2014 conference in Frankfurt. This is the annual event from Sylvia Lukas’ PayComm organisation and my once per year opportunity to catch up payment industry friends from northern, central and eastern Europe. It was as educational, enjoyable and entertaining as always, and for me particularly stimulating this year because of the opportunity to sit in on discussions with banks, schemes, processors and acquirers all developing strategies in response to some significant shifts about to occur in our industry, many of them centred around impending regulatory change. One specific category of interest and importance to our clients is that of the API in banking.

My reason for referring back to my prediction about payments vanishing was to stress the API as the mechanism for it to occur but then to build on this point to consider the impact of API-centric strategies throughout the payments value chain. It was lucky I’d decided to emphasise the “Amazonisation “of the payments industry in my talk, because the best talk of the event, which was Michael Salmony’s (from Equens) opening piece on APIs on the second day, came to similar conclusions from a less technical direction. Michael, as an aside, had the best slide of the entire event, and it wasn’t (directly) to do with payments, but was a comment on European standardisation efforts and how they work out in practice!

Untitled

I must stress that this focus on APIs is not new. It’s been clear for some time that this is way forward. I remember from a study on APIs that Consult Hyperion carried out last year for one of our US financial services customers that API-centric strategies make sense – because it’s a platform game – whether banks are forced to provide them by the regulators or not.

Moyer cites some banks that are already opening up public APIs, like French banks Crédit Agricole and AXA Bank, and others that have announced plans to do so, like Commonwealth Bank of Australia, ING and Capital One. Overall, she believes there is a growing understanding in the sector of the need for transformation. “I think most banks will provide a public API in the next two years,” she says.

[From Interview: Banks must focus on APIs and apps, not applications – Gartner analyst - Ireland’s CIO and strategy news and reports service – Siliconrepublic.com]

Now, after Michael’s excellent talk on the topic, he ran one of the workshop sessions and I was able to join in a fascinating and detailed conversation about the emerging European environment that I commented on in part one of this API Blast series of posts.

The EBA (European Banking Authority) is given the task to develop, in close collaboration with the ECB, ‘common and secure open standards of communication’ (incl. specs for data transmission and how TPPs are to authenticate themselves vis-à-vis AS PSPs). These standards will need a high level of detail and quality (testing) in order to make them usable.

[From Access to the Account (XS2A): accelerating the API-economy for banks? | Innopay]

I did ask a couple of people what the process for the EBA to develop this API is and what input they are seeking from different stakeholders, but I wasn’t able to obtain sufficient clarity to be able to report. Perhaps a correspondent might be able to point me in the right direction?

Anyway, at the workshop session I was in, the delegates were discussing trends in retail payments and they used an interesting classification to drive the debate, exploring how retail payments are changing in all of these areas.

Cards No Cards
Schemes the current situation
Visa/MC EMV 3DS etc
Visa/MC Euro-API
push SCT
FPS Zapp Pingit Paym
No Schemes bilateral Starbucks
prepaid
Bitcoin

It’s not the point of this blog to report the discussions, but I will say that as far as I could tell most of the European banks at the event seemed to agree with Michael’s point about the importance of developing a strategy around APIs, given the inevitability of the regulatory mandate. There are many aspects to this strategy and, as Craig Burton has said about this, many organisations will have to develop entirely new competencies in order to participate in API-based competition.

I think the biggest change is in the area of token and key management. If an organization wants to make sure that its API(s) are not being abused, well managed keys and tokens are essential. Managing developer’s with keys is probably not something most organizations have ever done.

[From 1 Raindrop: Security > 140]

A final point with respect to opportunities for banks. There is another way of looking at the strategy around APIs: not centred on payments, but centred on identity. Suppose the bank stored your personal information (rather as was suggested by the SWIFT Innotribe in their work on the digital asset grid, or DAG). Then the API would allow third-parties (and these could be a wide range of organisations, not only PSPSs) controlled access to support recognition, relationships and reputation transactions, reducing the overall costs to the stakeholders while giving the the customer control over their own data via their bank. Could the bank be the ideal partner to implement what Greg Meyer calls “The API of Me”:

I believe that we as consumers have a right to control the data we share about and between the services and products we use, and that the economic benefit of using and sharing that information by companies should be more transparent. “The API of Me” is the name I’d like to propose for a system of capturing, sharing, and limiting information about consumers

[From The API of Me « Information Maven: Greg Meyer]

As I said at the Wired Money event, perhaps the role of the bank in the future will change from being a place where you store your money (who keeps their money in a bank these days?) to being a place where you store your identity (surely you’d want to store it with a regulated organisation?).

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post API Blast part 2: ECB, EBA and DAG appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/07/api-blast-part-2-ecb-eba-and-dag/feed/ 0
API Blast part 1: PSD, XS2A, TPPs and PSPs http://tomorrowstransactions.com/2014/07/api-blast-part-1-psd-xs2a-tpps-and-psps/ http://tomorrowstransactions.com/2014/07/api-blast-part-1-psd-xs2a-tpps-and-psps/#comments Wed, 16 Jul 2014 09:57:57 +0000 http://tomorrowstransactions.com/?p=4516 It’s important to understand why APIs are so strategically important, not only in the payment space but in the financial sector as a whole. I thought I’d put together a few posts on the European banking API environment because it is rather dynamic at the time of writing. So here we go! The organisers of […]

The post API Blast part 1: PSD, XS2A, TPPs and PSPs appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

It’s important to understand why APIs are so strategically important, not only in the payment space but in the financial sector as a whole. I thought I’d put together a few posts on the European banking API environment because it is rather dynamic at the time of writing. So here we go!

The organisers of the International Payment Summit 2014 decided to take a little bit of a risk by turning over half of the Day One program to Consult Hyperion for a Future of Money Unconference to explore the subject in an interactive and (hopefully) fun way. So we set off for the Hilton Tower Bridge bright and early on April Fools’ Day to test the theory.

Untitled

As you might have expected, mobile phones and social media were the main technologies that the delegates were discussing and I did learn a lot about different kinds of financial services organisations varying approaches and attitudes, but personally the area of discussion I found most engrossing was around third-party access to bank accounts, the so-called “XS2A” consultation. This is rather a hot topic in Europe because of the European Commission consultations underway in this and related areas.

Forum friend Thaer Sabri, the CEO of the EMA, gave a super presentation on “PSD and third-party access to accounts” that provided a valuable update on the situation. He began by pointing out that the European regulatory landscape, over the last decade or so, hasn’t been too constraining and has allowed a reasonable Payment Service Provider (PSP) marketplace to develop and went on to explain how what he called the Technology Service Providers (TSPs) would be developing in the future as well. In the new Payment Services Directive (PSD), PSP’s will be divided into two categories, as I’ve written before, so that there will be the Account-Servicing PSP’s (ASPs) and the Third-Party PSPs (TPPs). The TPPs come in two flavours: Payment Initiation PSP’s (PIPs, that might be someone like Nutmeg) and Account Information PSP’s (AIPs, that might someone like Mint).

Untitled

Thaer went on to talk about some of the additional provisions: that ASPs will be compelled to provide information on funds availability; that PSPs will have to provide a common API under the auspices of the European Banking Authority (EBA) – and we’ll be coming back to this “euro-API” in future posts; and that new payment instruments (e.g., decoupled debit) will allow third parties to create payment products on top of that API.

There are of course a great many unanswered questions about the legislation, as there always are with this sort of thing, and the answers will shape some aspects of the business model. For example: are end-user contracts sufficient or will TPPs be required to have contracts with banks? And the obvious question of where liability rests in the event of unauthorised transfers, which is the sort of thing will need to be sorted out before any of this can go anywhere near consumers. Thaer did the audience (and me) a great favour by sketching out some of the likely business impact of these changes and pointed out something that I think is likely to require some significant thoughts on behalf of participants: what is going to happen when bank apps can use the euro-API to access the bank accounts of competitor banks?

He was kind enough to stay in joining the discussions on the “regulators table” (several people had put regulatory questions on their post-it notes for discussion even before he had started talking so we set aside a whole table just for this) and I’m sure everybody will join me in thanking him for his time.

Untitled

This is the sort of thing that makes unconferences rock, and one of the reasons why I love them so much. I look forward to seeing all of you at our next unconference, which is the 3rd CHYP/NYPAY Tomorrow’s Transaction Unconference at Google in New York on Monday 22nd September where you’ll be able to get round the table with some of the leading thinkers in the FinTech space, including Brett King from Moven and Matt Harris from Bain Capital Ventures. Oh, and I’ll be there too, conference bombing them.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post API Blast part 1: PSD, XS2A, TPPs and PSPs appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/07/api-blast-part-1-psd-xs2a-tpps-and-psps/feed/ 2
APIs and app stores and the future of banking http://tomorrowstransactions.com/2014/05/apis-and-app-stores-and-the-future-of-banking/ http://tomorrowstransactions.com/2014/05/apis-and-app-stores-and-the-future-of-banking/#comments Tue, 06 May 2014 07:43:07 +0000 http://tomorrowstransactions.com/?p=4424 APIs will certainly revolutionise the services the banks provide, but they will also revolutionise the way banks work. The lovely people at Finextra kindly invited me along to their FutureMoney event at Level39 in Canary Wharf this year and asked me to moderate the panel about banking app stores, which I loosely interpreted to mean […]

The post APIs and app stores and the future of banking appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

APIs will certainly revolutionise the services the banks provide, but they will also revolutionise the way banks work.

The lovely people at Finextra kindly invited me along to their FutureMoney event at Level39 in Canary Wharf this year and asked me to moderate the panel about banking app stores, which I loosely interpreted to mean about financial services app stores and APIs. Luckily for me, I had a great panel to work with:

Edward Budd from Deutsche Bank, Udayan Goyal from Anthemis Group, David Pope from Jumio, Simon Redfern from Open Bank and Jose Antonio Gallego Vázquez from BBVA.

[From Finextra: Live: Finextra Future Money, day two]

After some initial confusion about the relationship between the colours of the chairs and the colours of the pictures behind them (!) I made a few introductory comments about APIs in this sector and why I felt this was a strategically important discussion.

#FutureMoney

Picture: Roberta Profeta

Following that, we began to examine some of the questions that I had prepared to challenge the panel and brought in questions and observations from the floor to follow. Though I say so myself, it was a terrific session and I would like to broadcast my sincere thanks to the other people who said so too, including Richard Brown from IBM.

It was a one hour session and we were still going strong with questions and debate at the end, which I think is the only effective barometer of both the moderator and the panel. Modesty forbids me from quoting Zilvinas Bareisis of Celent on the session but… oh, wait, no it doesn’t…

Given that here both his topic (banking apps and APIs) and panelists were genuinely interesting, it is no surprise that it was perhaps the best session over the two days.

[From Celent Banking Blog » A “Shout Out” to Finextra Future Money]

Richard and Zilvinas are very kind. The reason that the session was such a joy, and was much appreciated by the audience, was that the panelists had exactly right mix of expertise and experience to tackle such a hot topic. I had a bit of an inside track as well, since Consult Hyperion carried out an extensive study of the financial services API world for one of our US customers last year, so I had a pretty good overview of the space in my head to help to shape the discussion. You can read the liveblog for yourself at Finextra, but I want to highlight a couple of what I thought were key points here.

First of all, the importance of the app store and APIs was reinforced. As I said in the introduction, this isn’t some obscure technical discussion about parameters and tokens. I think Craig Burton and Steven Willmott capture this nicely with their “Five Axioms of the API Economy”. These are:

  1. Everything and everyone will be API enabled.
  2. APIs are core to every cloud, social and mobile computing strategy.
  3. APIs are an economic imperative.
  4. Organizations must provide their core competence through APIs.
  5. Organizations must consume core competences of others through APIs.

Secondly, APIs are not all about organisations connecting with other organisations. They are also a way of restructuring the way that bank systems connect internally. This was referred to as “Amazonisation”, the idea that every single corporate function should expose its APIs, because other functions within an organisation might be able to do something useful with them. Uday used the excellent example of Fidor Bank as an organisation that has taken those axioms to heart internally.

We decided from the beginning to build our own middleware, because there was no suitable offer in the market. This is what we now call “Fidor operating system”… fOS is an “open” System. Via standard interfaces we integrate 3rd party offerings into our account.

[From FIDOR Bank |]

In our Consult Hyperion “hot five” for 2014, we highlighted the importance of APIs as part of an electronic transaction strategy and this panel confirmed, to me at least, just how central that API strategy should be to organisational strategies. And they also underlined one of my key messages to our clients: this is business strategy, not technology strategy.

APIs are, at their core, not a technical device. Instead, they are a means of delivering or providing access to a service or a product.

[From The Five Axioms of the API Economy, Axiom #3 – APIs are an Economic Imperative | Craig Burton]

So thanks again to Liz and the rest of the Finextra crowd for giving me the opportunity to learn so much from a terrific panel.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post APIs and app stores and the future of banking appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/05/apis-and-app-stores-and-the-future-of-banking/feed/ 1
The “hot five” retail transaction technologies for our clients in 2014 http://tomorrowstransactions.com/2014/01/the-hot-five-retail-transaction-technologies-for-our-clients-in-2014/ http://tomorrowstransactions.com/2014/01/the-hot-five-retail-transaction-technologies-for-our-clients-in-2014/#comments Thu, 02 Jan 2014 16:03:54 +0000 http://tomorrowstransactions.com/?p=2902 It’s traditional in blogs of this kind to have a go at a “top N” set of predictions for the coming year, so I’ll give it a bash and have a go at what I think will be the “hot five” secure electronic transaction technologies that will have our clients updating their roadmaps in 2014. […]

The post The “hot five” retail transaction technologies for our clients in 2014 appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

It’s traditional in blogs of this kind to have a go at a “top N” set of predictions for the coming year, so I’ll give it a bash and have a go at what I think will be the “hot five” secure electronic transaction technologies that will have our clients updating their roadmaps in 2014.

First, some background as to why I started thinking about this topic and ended up with my shortlist of five. A couple of weeks back, as Richard Watson mentioned on his excellent “What’s Next” blog, we had a bit of a catch up, talking about the major trends in and around the technologies, businesses and social memes that we are interested in.

Or it could it be the rather relaxed lunch I had with Dave Birch talking about Bitcoin, identity and steak.

[From Just stuff | What's Next: Top Trends]

We did have a relaxed lunch, it’s true. Richard is a futurist, and the author of The Future Files, which he kindly came and talked about at our Forum a couple of years ago and in a rather spooky coincidence he emailed me about something while I actually had a copy of his book on my desk! I had been looking up something for a book I am writing. But back to lunch.

Untitled

I’m going to be helping Richard update the financial services route on his roadmap (which is what he’s looking at in the restaurant in the picture) and we were discussing the long term significance of Bitcoin and the Bitcoin family of technologies. Richard set me thinking about ways to provide useful input to his roadmap. In our internal roadmap, the one we use to support clients in developing their product and service roadmaps, we divide technology evolution into “now” (1-2 years), “soon” (3-5 years) and “later” (5+ years). One way of using this roadmap is to see business as a way of connecting the technology push and the social pull to deliver sustainable value. With this framing, I looked at the technologies that are reaching the mass market now and that gave me a short list. Then I went and asked around a few of our guys. Since they are, by and large, out working for clients (who are some of the biggest and most important players in the retail transactions space) and since, by and large, they are working on projects around exploring the latest technologies, they are a pretty good barometer.

So, by combining projects that we are working on now with the likely business impact of the technologies, taking away the projects that are confidential (!) and focusing on technologies likely to be of interest to blog readers, I got my “hot five” technologies for 2014! I’m genuinely interested in your feedback on my picks, which are…

Proximity and vicinity interfaces. The arrival of Host Card Emulation (HCE) and Bluetooth Low Energy (BLE) will open up mobile transactions, taking them away from (expensive) secure, controlled infrastructure and out into the open. While security and risk analysis skills will be crucial to delivering operational systems, I think that the overall mobile security environment means that there will be a revolution in app-centric retail. I can well imagine using NFC to “tap in” to Waitrose before being guided around by BLE and then a “tap out” to close and pay. See if you can spot the BLE beacon in this photograph of our CTO hard at work down at CHYP End…

Untitled

Tokenisation. This made the front pages later in the year when the major payment schemes made it a priority and I suppose it was given an end-of-year boost because of the Target breach. I’ll blog about it soon, but one of the key points in the coverage to date is that Target’s own tokenised product was safe from the hackers whereas the untokenised general-purpose card numbers were not. This reinforced the schemes’ determination to make a serious dent in online fraud by moving away from cardholder PANs as the key to payments.

Visa, MasterCard and American Express have announced a proposed framework for a new global standard to enhance the security of digital payments and simplify the purchasing experience when shopping on a mobile phone, tablet, personal computer or other smart device.

[From MasterCard, Visa and American Express Propose New Global Standard to Make Online and Mobile Shopping Simpler and Safer]

This has been reported as being a technology initiative that undermines NFC, whereas I tend to think that it dovetails with it.

My two cents is that this finally puts the stake in the heart of NFC by those who started the whole thing in the first place.

[From 2013 - Networks, The Cloud And Many Open Questions | PYMNTS.com®]

As I said at the time, I’m not sure I agree with Karen about this because there is a positive synergy between tokenisation and proximity interfaces that is mutually beneficial. Tokens don’t need the same kind of security that card details do so they can thrive in the HCE/BLE-driven app.

Recognition. We’ve been using the world “recognition” to mean the combination of good enough identification and good enough authentication to make commerce possible. The mobile phone has an obvious and important role to play here, to the point where downstream tokenisation will shift to recognition (in other words, it will be the customer’s identity that is used to make a payment). I continue to think that making privacy part of the consumer proposition here will be a good strategy. It also seems to me that the tools for creating recognition infrastructure at reasonable cost are becoming standardised (FIDO, OpenIDConnect, OIX, that sort of thing) so organisations will want to use them on a large scale. HCE/BLE give us the convenient interfaces, tokenisation protects privacy and customers benefit from a personalised experience.

2014 will be the year in which you walk into a store and it “knows you” and customizes your visit.

[From Predictions for 2014: Computing Technologies In The Age Of The Customer | Forrester Research]

Small Data. With all the talk about Big Data, I think there is an opportunity for “small data” to make a difference. Giving customers their own data and the tools to manage it seems to me to be a way to balance individual and organisational wants. The relevance of this to payments and identity plays is that the “wallet” of whatever form becomes a place to store and manage this small data — consumer receipts and warranties, spending history, loyalty and so on — as well as the tools that consumers can use to manage that data to their benefit. I saw a nice comment about this in response to Robert X. Cringley’s call for 2014 predictions:

2014 could benefit from a renewed focus on delivering value by sorting out the small data first.

[From I, Cringely Call for 2014 predictions! - I, Cringely]

APIs. The glue that holds all of this together. There is no doubt about the crucial role of APIs in the future business architecture, but what will change in 2014 is that APIs have become a management issue, not a technology issue. I’m fascinated by the nature of API-based competition, but for our clients (who tend to be at the larger end of the scale) the fact that they can start to compete on the basis of APIs is problematic because they have no experience of competing in that way. It’s been a while since the Credit Agricole app store (the CAStore) became the first post-modern (!)bank app and the floodgates haven’t opened yet, but when Consult Hyperion studied financial services APIs for one of our international clients earlier in the year one of the clear conclusions of the work was that APIs will increasing shape the products and services that are delivered through them.

The CAStore uses an open API, or application programming interface, in which technology is shared freely with outside developers so that it can be integrated into new programs, without compromising compatibility.

[From Open API for Bank Apps: Can Credit Agricole s Model Work Here? - American Banker Magazine Article]

When we are helping clients to put together their technology roadmaps we try to find ways for business to link the push of new technology with the pull of social change to identify new products and services in the secure electronic transactions world. I think these five technologies form the basis for a consistent narrative for retail transactions in response to real customer requirements for convenience, security and value. I can’t wait for the next version of my Waitrose app!

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post The “hot five” retail transaction technologies for our clients in 2014 appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/the-hot-five-retail-transaction-technologies-for-our-clients-in-2014/feed/ 3