Open Finance Framework
BANGKO SENTRALNG PILIPINAS
OFFICEOF THE GOVERNOR
CIRCULAR NO.1122
Series of 2021
Subject: Open Finance Framework
incorporated as Section 154 of the Manual of Regulations for Banks (MORB) and Sections 152-Q/149-S/146-P/130-N/129-T/123-CC of the Manual approved the adoption of the Open Finance Framework,which shall be The Monetary Board, in its Resolution No. 730 dated 10 June 2021, of Regulations for Non-Bank Financial Institutions (MORNBFI)
N/129-T/123-CC of the MORNBFI is hereby created, to read as follows: Section1.Section 154of the MORB and Sections152-Q/149-S/146-P/130.
"Section 154/152-Q/149-S/146-P/130-N/129-T/123-CC. GUIDELINESFOR THE ADOPTION OF OPEN FINANCE FRAMEWORK
to promote an enabling Policy Statement. It is the thrust of the Bangko Sentral environment that fosters innovation, encourages coopetition, system. In line with safeguarding the integrity this, and advances the and Bangko stability financial Sentral of inclusion while is introducing the financial
the Open Finance Framework that aims to empower customers by giving them better control over their personal and financial data catalyzing the development of products and services that are responsive to their needs.
The Open Finance Framework espouses consent-driven data
Under portability, among leverage financial institutions and third-party providers the on framework, permissioned-access interoperability, financial and customer financial institutions collaborative and partnerships information TPPS (TPPs) can
customers. the consent of the customers to transaction data" principle develop that bespoke The "customers hence, information shall only be shared with Open financial Finance are Framework the products owners subscribes and of services personal to the and for
products, Coverage. services, The Open Finance Framework covers technology, information, and policies that enable customers to securely share their financial data with qualified parties, either BSP-supervised financial institutions (BSFIs) Or. TPPs.
Definition of Terms. The terms used in this Section shall be defined as follows:
a. Account Information Service Provider (AIsP) refers to an provider that processes data and provides an alternative access point to multiple sources of data other than payment information technology service and/or software solution transactions;
b. Application Programming Interfaces (APIs) refer to a set of rules and specifications for software programs to
different programs to faciiitate interaction; communicate with each other, forming an interface between
c. Customer-permissioned data identification data, and customer financial history) that are permissioned by the Participants' customer to be Participants accessed by a third party (and possibly shared onwards with (e.g.. customer refers transactions, to data held personal by
fourth parties if covered by the customer's consent):
d. Open Finance refers to ieveraging on and sharing of
holders, solutions, such as among others, those that provide real- TPPS; customer-permissioned data among banks, other financial institutions, and TPPs to develop innovative financial time payments, opportunities to banks, other financial institutions: and and promote provide greater marketing transparency to account and cross-selling
e. Open Finance Standards refer to the recommended standards in implementing the Open Finance Framework that takes into account various factors, including the financial
the overall benefits arising from such standardization; industry's level of readiness to adopt such standards and
f. Open API, also known as external or public API. refers to a software technology interface that provides a means of accessing data based on a public standard;
g. Open Data refers to publicly obtainable data that is published by Participants, including, but not limited to information; financial products, service information, and other pubiic
h. Open Access refers to allowing authorized third parties to access consented data without needing to establish e
business relationship with the Open API publisher;
i. Payment Initiation Service Provider (PIsP) registered operator of payment systems (ops), as defined refers to a
Page 2 of 9
Systems Act and clarified in Part I, Section iol of the under Republic Act (R.A.) No. 1ll27 - The National Payments
Manual of Regulations for Payment Systems (MORPs): that carries out payment orders at the request of payment service users in connection with payment accounts held at other payment service providers;
j. Third party providers or TPPs refers to any external legal as entity such as service providers, integrators, solutions vendors, and/or infrastructure support that interact with BsFIs to provide services to customers. They are classified either AIsp and/or PIsP, however, other TPP
classification may be created by the Open Finance Oversight Committee (OFOC). as deemed applicable;
k. Participant refers to the entities covered by the Open Finance Framework such as the BsFIs and TPPs;
i. Open APr publisher refers to the Participant that keeps/is the custodian of customer data;
m. Third party refers to the Participant who has open access to customer-permissioned data residing in another
Participant (publisher) through the Open API; and
n. Fourth party refers to an outsourcing partner or a service provider of a third party.
OFOC shall be subject to the regulation and supervision of the an Open Finance Oversight Committee (oFoC), an industry-led Bangko Sentral. self-governing body, that shall exercise governance over the activities and Participants of the Open Finance Ecosystem. Governance Framework. The Bangko Sentral shall recognize The
The Bangko Sentral shall facilitate the establishment of the OFoc in coordination with industry stakeholders. For this purpose, the initial set of members of the OFOC shall be comprised of representatives from each bank classification, non- bank financial institutions. electronic money issuers.
as may be determined by the Bangko Sentral. The OFoc shall: operators of payment systems, TPPs, and other reievant sectors,
a. Adopt membership and participation rules that are non-
and consistently. financial industry are adequately represented and that all members and applicants for membership are treated fairly discriminatory to ensure that key areas of interest of the
b. Define the functions, roles, and responsibilities of the
Committee and the Participants. It shall adopt policies
Page 3 of 9
in monitoring Participants' compliance with the established policies and in handling non-compliance
for non-compliance. thereto inciuding the corresponding sanctions or penalties
c. Adopt standards, agreements, policies, and guidelines (Conventions) governing the Open Finance Framework which
shall be consistent with relevant laws, rules and
these shall cover the following: regulations and regional/global standards. At the minimum,
(i) Registration/On-boarding of non-BsFI Participants; (2) API (3) Authorization, (4) Disclosure and transparency requirements as prescribed documentation; S/702-N/115-CC of the MORNBFI; requirements for each product/service tier; under Section 1002 of the MORB and Sections 1002-Q/702- standards authentication, reference 1r other and equivalent encryption
{5) Consent management; 6) 7) (8) Economic model; and (9) Consumer Protection of ciient information including responsible Reciprocity arrangement among Participants; data handiing as well as data privacy and protection; protection and effective recourse as
prescribed under Part Ten of the MORB, Parts Ten of the
Regulations/Seven of the N-Regulations, and Section Q-Regulations/Seven of the S-Regulations/six of the P- 117-CC of the MORNBFI.
d. Cooperate with and extend fullest assistance permissible applicable iaws and regulations, in promoting adherence to to the Bangko Sentral and other regulators in enforcing this Framework.
Consistent with the provisions of Section 002 of the MORB and Sections 002-Q/002-S/002-P/001-N/002-T/121-CC of MORNBFI the Bangko Sentral reserves the right to deploy its range of supervisory tools to promote adherence to the requirements and expectation set forth in this Framework. Bangko Sentral may issue directives against the OFoC, such as suspension to Qr or In this regard, the revocation of any impose sanctions
authority of the OFoc (including any or all of its generally authorized activities), without prior notice, safety and soundness of the financial system and/or to protect Participants, its customers, or the general public. to promote the
at least "3" under the Supervisory Assessment Framework (sAFr), or its equivalent, are automatically eligible to become Participants of the Open Finance Ecosystem. On the other hand, Registration Standards. BsFIs with a composite rating of
Page 4 of 9
Ecosystem. Participants which are not under the regulation and to pertinent laws, rules and regulations of the Bangko Sentral responsible for ensuring fourth party compliance with applicable supervision of the Bangko Sentral laws, rules and regulations. Bangko Sentral approval applicable registration requirements set by the OFoC, pursuant those that do not meet the minimum rating must secure prior and other relevant authorities. to participate Participants shall in the Open Finance comply with the shall be
aimed at ensuring that: b. the standards development process is transparent; and Open Finance Standards. The OFOc shall issue guidelines a. access to and participation in the standard-setting c. the Open Finance standards will be accessible to all activities, is non-discriminatory; process, qualified parties. including any planning and consultation
documentation that shall be developed by the OFOc shali meet adoption, and shall cover, at a minimum, the following: the recommended technical standards to facilitate industry-wide The API standards reference or other equivalent
APr Architecture Standards. These shall comprise, among others, reference for Open API specifications, types. including communication protocols, and architecture Participants are encouraged to adopt
Object Access Protocol (sOAP); Representational State Transfer (REsT) and Simple recognized industry-wide architectural styles such as
Data Standards. These shall include data formats, data structures, and related data protection and privacy shall adopt data formats which are recognized by the industry such as, information accurately rules to enable Participants but and efficiently. Participants not limited to, JavaScript to share data and
published online, with sufficient level of detail to Object Notation (JsON), Query Language (sQL). The "data dictionary" shall be facilitate third party understanding and adoption; (XML), Comma Separated Values (csv), and structured Extensible Markup Language
Security security compliance requirements, Standards. These shall guidelines, cover minimum and
internal requirements, and apply holistic controls on including specifications that encryption. industry sound practices, authentication, Participants must should be met relevant authorization, always by Participants, regulatory, refer and and to
G
Page 5 of 9
authorization and authentication protocols that are Standard (AEs)/Hashed Message secure methods for sharing data, authentication through APIs. The API must be designed information and cybersecurity based on a risk-- and principles-based approach to protect their systems as well as financial and consumer data. At a minimum, adequate for the risks presented by Open Access, such as. but not limited to, multi-factor authentication, Transport Layer Security authentication standard. in such limited to data that the Participants shall (HMAC) a way encryption that adopt the standards Participants should use more end-user (TLs)/Advanced Encryption end-user the Authentication latest and robust such as has and access permission OAuth token-based shall Code 2.0 be to
audited. In terms of secure hosting, appropriately 27001 are most desired; and see Or process. recorded. These verified, access rights PCI DSS measured, must and ISO and be
(3 activities Outsourcing disclosure protection, accessing and processing data, management and confidentiality, data management such Of Standards. particularly risks These arising those shall obtaining as procedures data from involving refer privacy outsourcing consent. to data for the and
and business continuity, among others. contract management, security, performance monitoring
ApIs. All Participants that intend to provide Open Access shali adopt the Open Finance Standards and shall comply with relevant Outsourcing, Operational Risk Management, IT Risk Management, Financing of Terrorism, Financial Consumer Protection, and sound corporate governance principles, among others. laws and pertinent Bangko Sentral regulations particularly on Internal Adoption of Open Finance Standards and Publication of Open Control, Anti-Money Laundering/Countering the
functionalities. address Open Finance emerging Standards may be To issues facilitate or to revised third improve party periodically the Open adoption, API to
Participants shall publish detaiied Open API documentation and ensure consistency with the iatest version of Open Finance Standards.
Open Finance Standards shall be classified into five (5) tiers based on data sensitivity, data type, and data holder type. tiers implementations may occur simultaneously. Tiered Approach towards Open Finance standards Adoption. are not necessarily sequential, and multiple The Q
Page 6 of 9
a. Tier l - Product and Service Information. Refers to "read- by any entity such as deposit/lending rates, credit card offerings, service charges and other public data. only" information on financial data and other details of online and can be freely used, reused, and redistributed financial products/services that is readily accessible
b. Tier 2 - Subscription and New Account Applications.
products are covered under this category. processes, along with facilitating digital application and deposits, loans, debit/credit cards, and other financial submission of supporting documents. Applications for Includes customer acquisition and account opening
c. Tier 3 - Account Information. Refers to personal views. This consists of, but are not limited to, data types authenticated customers such as account balance, credit card outstanding balance, transaction records, credit limit change, and credit score. time name. financial information provided by a customer at any given or registered address, other details pertaining for stand-alone or aggregated phone numbers, totheaccount etc.) (e.g.. and of
d. Tier 4 - Transactions. Covers payments and other financial transactions such as scheduled payments and transfers initiated by customers.
e. Tier5 products or use cases and those that are not covered by tiers l-4. Others. Covers other more complex financiai
to the implementation of the Open Finance Framework. recognizes that other regulatory/supervisory authorities may be involved in the Open Finance Framework as this would involve other Participants that are not under the supervisory ambit of coordinate with the concerned the Bangko Sentral Cooperative Regulatory Oversight. The Bangko Sentral duly In this regard, the Bangko Sentral shall regulatory authority with respect
Regulatory Sandbox
environment that is conducive for the deployment of innovative development of an industry API sandbox, in which Open APIs can be deployed and tested in a live environment and within Open Finance. In line with this, the Bangko Sentral will permit innovation in Open Finance, such as, but not iimited to, the specified parameters and timeframes. financial services, including the development of standards for The Bangko Sentral seeks to provide a regulatory
Page 7 of 9
providers will be encouraged recognized that Recommendation to Build a Central ApI Sandbox. While API costs may to develop local sandboxes, it is present a barrier and further incentives may be required. the OFOC to establish a centr Thus. sandbox the Bangko Sentral encourages for testing developers and for other purposes related C local sandbox development
OFoc shall provide the executable tests to developers free of levels of security for APIs and (ii) tests that API developers can use to validate compliance. The OFOc shall ensure that the charge so that barriers to entry are avoided. (e.g.: outsourcing sandbox development to trusted parties). The central contains a set of executable sandbox (i) implements all
API service is a list that will Sentral or other relevant governing body. Servicesi with defined technical and security standards. This list shall include clear mechanisms and guidelines for providing the Account new API API The OFOC shall maintain a list of approved Use Case API Information, innovations that have services (e.g., basic APIs such as Authentication, Transfers, be regularly updated based on been reviewed by etc.). The Use Case list per the Bangko
Consumer Protection
awareness measures to, at the minimum, educate their customers access of information and performance of transactions; (iv) fair and equitable terms and conditions; (v) products and services on the following: (i) safeguarding of information; (ii) use of the Open API; (iii) actual fees and charges related to the appropriate to the capacity and risk appetite of the consumer; and (vi) Consumer Protection. Participants shall adopt customer problem resolution procedures. Participants shall disclose prior 0 enterind 1 initial transaction and on an ongoing basis. all materi risks f0 their clients in a manner that is clear Out initiatives fair and to give not misleading. consumers the knowledge, skills, Participants shall carry and
receive and empower them to make informed financial decisions. confidence to understand and evaluate the information they
to the implementation or use of Open API shall contain a clause for the recognition Data Privacy and Data Protection. Each contract relating bv each party that the customers have
the transaction, and that they have all the rights enumerated under R.A. No. 10l73 (Data Privacy Act of 20l2). This views that ownership over their data being collected and processed through while customer and transaction data are in the custody of the Open API publisher, their rights to control the use of such data
with the applicable requirements prescribed herein within one 1 All existing API arrangements prior to the issuance of this Circular shall comply effectivity of this Circular. clarifications, compliance timetable shall be further determined by the OFoc. Incases awaiting policy-setting (l) year Qr further from
Page 8 of 9
provided. is iimited to the boundaries of the consent the requirements of the Data Privacy Act of 20i2, its Implementing Rules and Regulations, and other National Privacy Commission issuances. All Participants shall comply with customer relevant
prompt, and effective mechanism or procedure for handling and agreed Conventions, as applicable. resolving disputes covering Open Finance issues aligned with Dispute Mechanism. Participants shall have an adequate,
mechanisms if and when they want to withdraw or modify the scope how the Proper mechanisms shall be in place to ensure customers' private educated and informed but of their consent. within information is not interests. data is being User Consent and access to opt-in and opt-out mechanisms. a Participants given The used customers period. Customers must be periodically informed as to used for and have be Proper they must also consent to how their should, provided with utilized purposes that mechanisms at their all times. opt-in and opt-out based on industry are against their permissioned not only be data
portal/service that duration, standards information structure Others. shall timestamp be in is for and place interoperable, open, recording obtained consents, consent opted-in/opted-out in providing a consent management and has extensible services, among
shall be incorporated as a footnote in Section 1: Section 2. Transitory Provision. The following transitory provision
year from effectivity of this Circular. In cases awaiting policy-setting or further clarifications, compliance timetable shall be further determined by comply with the applicable requirements prescribed herein within one (1) the OFOc. All existing APl arrangements prior to the issuance of this Circular shall
following its publication in the Official Gazette or any newspaper of general circulation. Section 3. This Circular shall take effect fifteen (15) calendar days
FOR THE MONETARY BOARD:
G C0
f7_ June 2027 BENJAMIN E. DIOKNO Governor
Page 9 of 9
同类文件 BSP Circulars
- Foreign currency deposit units of local commercial banks authorized to operate under the expanded foreign currency deposit system(BSP Circular No. 1342)
- Opening of Currency Exchange Facility (CEF) Program of the Bangko Sentral ng Pilipinas (BSP) for Overseas Filipinos (OFs) returning from Ukraine(BSP Circular No. 1145)
- Guidelines in Strengthening Corporate Governance in BSP Supervised Financial Institutions(BSP Circular No. 749)
- Guidelines on Living Trust Accounts(BSP Circular No. 521)
- Participation in the Global Bond Offering of the Republic of the Philippines(BSP Circular No. 546)
- Amendments to the Ceiling on Interest or Finance Charges for Credit Card Receivables(BSP Circular No. 1165)
- Marketing, Sale and Servicing of Microinsurance Products(BSP Circular No. 683)
- CONSOLIDATED RULES AND REGULATIONS ON CURRENCY NOTES AND COINS(BSP Circular No. 61)
想要这份文件的分析?
让 ASG 法律 AI 为你总结、与其他判例对比,或说明它如何适用于你的情形 — 它检索的正是同一个数据库。