Bank consortium to explore new customer data-exchange standard
Computerworld -
The Financial Services Technology Consortium (FSTC), a not-for-profit organization that includes banks, research firms and government agencies, is planning to meet June 15 to discuss authentication issues for Web sites that aggregate banking information.
The group has already developed what it calls the Financial Agent Secure Transaction (FAST) model, which allows financial institutions to provide a range of services, from customer authentication to payment guarantees. At the upcoming meeting, consortium members will further develop the technical model and begin readying it for a market trial.
Anatoly Kissen, vice president at New York-based Citigroup Inc. and head of the FSTC's aggregator project, says the main goal of the aggregation committee is to move away from accessing customers' personal financial information via screen scraping. The FSTC wants to move to a common, XML-based platform.
Today, he said, aggregators scrape personal financial information from Web pages -- not exactly the most secure and reliable approach.
"If we provide a direct feed to the aggregators, the quality of the information could be improved," he said.
At the June 15 meeting, financial industry representatives from such organizations as the Washington-based American Bankers Association, Charlotte, N.C.-based Bank of America Corp. and Citigroup will meet to decide the details of a pilot project.
The pilot, according to Kissen, may not necessarily be a full-scale, XML-based platform but would eventually lead to it.
The meeting is a sign that banks and other financial institutions have accepted that aggregator sites are inevitable, said George Barto, an analyst at Stamford, Conn.-based Gartner Group Inc.
"The banks would prefer that this didn't happen, but it did happen," he said. "We've done research and we've asked people about about their ideal financial service Web site and basically what people say is that from a single Web site they want to have access to all their financial services."
Last year, Charlotte, N.C.-based First Union Corp. went to court against Princeton, N.J.-based Paytrust Inc. , which offers the Paytrust.com aggregator Web site. In its lawsuit against Paytrust.com, First Union contended that the aggregator had raised potential security problems by screen scraping customer information from its Web site. However, First Union later dropped the lawsuit.
"Looking at it from the consumer viewpoint, it's good news that they're willing to cooperate to come up with a standard to make that process work better," Barto said. "That is only in the best interest of the consumer."
But it's not going to be a smooth road, he added.
"The technical problem is establishing the standard and everyone agreeing
Additional Resources


White Papers & Webcasts
Mitigating Litigation Risk with Email Management Tools
Does your company have an email retention policy that protects it when litigation occurs? IDC discusses effective email retention policies and the role...
Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....
Protecting Content During Business Disruption: Are You Covered?
Learn how ECM is helping Tulane University and the 13th Judicial Circuit Court implement disaster readiness programs....
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Beyond PCI Checklists: Securing Cardholder Data with Tripwire's Enhanced File Integrity Monitoring
How do organizations pass their PCI DSS audits yet still suffer security breaches? Paying attention to PCI DSS checklists only partially secures the...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
Authentication as a Service by Forrester Research
Authentication-as-a-Service: understand the benefits of two factor authentication and the best ways to implement it....
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
