Banking as a service

From HandWiki
"Banking as a service" stack based on the cloud stack by Scholten, derived from Lenk et al.

Banking as a service (BaaS) is the provision of banking products (such as current accounts and credit cards) to non-bank third parties through APIs.[1]

Description

As a value network, BaaS aims at seamlessly integrating as many service providers as needed into one comprehensive process to complete a financial service in an effective and timely manner. It is implied that a BaaS would include certain features in addition to providing a financial service. There must be means for managing, deploying and delivery of the services' environment. The services must of course be in legal compliance with the banking laws in the regions where it is made available, with (at least) one entity within the process possessing a banking license. Of utmost importance is the assurance that proper mechanisms are in place to provide security, such as strong authentication and additional measures to protect sensitive information from unauthorized access throughout the entire process. These security mechanisms must be in compliance with laws of data protection for the jurisdictions involved. With the proliferation and acceptance of BaaS, the emergence and rapid growth of FinTech can be expected. FinTech is “a business that aims at providing financial services by making use of software and modern technology.” [2]

API-based stack

This stack can be used with a licensed bank as foundation, a BaaS as middleware, and an ecosystems of FinTechs on top.

Skinner suggested a 3-layer representation of the BaaS stack.[3] In this stack, the underlying infrastructure-as-a-service is provided by a traditional, licensed and regulated bank. Above this bank would be the centralized Middleware layer that Skinner refers to as "bank as a service". Added on to the bank as a service is a group of decomposed banking services consisting of an ecosystem of FinTech startups and service providers.

With this technology, based on the BaaS-platform, it is possible to create FinTech banks, which could improve banking processes and provide increased convenience for banking clients. In such a constellation, FinTech banks are enabled to compete directly with banks by offering core-banking services without having to build all the products that would be needed. The API-based bank as a service platform serves as the back-end that hosts standalone independent FinTech startups and integrates seamlessly with any existing back-office of traditional banks. This allows non-banks to easily and cost-effectively launch additional financial products and expand into additional markets.[3]

Cloud-based stack

Dynamic development and growth in the world of FinTech have made the API-based Bank-as-a-Service stack obsolete in contexts where tech-companies now own licenses to operate as regulated banks, thus eliminating the reliance on classic banks. Embracing the new developments in financial technology and services, the Banking-as-a-Service stack can be redefined in analogy to the Cloud stack.[1][4]

Infrastructure as a service (IaaS)

The infrastructure as a service (IaaS) layer provides basic infrastructure services through an IaaS provider. A majority of these services would be available on demand and do not necessarily need to be FinTech services (like Amazon Web Services or OVH). This layer would include the server and communication hardware (physical layer).

Banking as a platform (BaaP)

At the top of the IaaS model would be banking as a platform provider (BaaP). The BaaP would be a bank that is fully licensed or use an external regulated bank's licensed banking services. The decomposed banking services (FinTech SaaS) are in essence, plugged into this layer. Data-security plays a crucial role in the BaaP. There is a need for monitoring functions that will enable seamless and secure operations across applications and domains through secure authentication.

FinTech SaaS

FinTech SaaS (software as a service) refers to all atomic or composite software-based financial services that are available on-demand. When these services are provided through a BaaP, they will need to be compliant with the BaaP's API specifications. The services may either be physically deployed in the BaaP's domain or work externally. This gives the potential for the ability to plug financial services from other banks into the BaaP to create new composite application services. The result is that traditional banking services can now be virtualized and dispatched via composite application services. This does, however, present a challenge in verifying that none of the plugged-in services will violate regulations that have been imposed by banking authorities.

HuaaS

Humans as a service [4] represents the top layer of the proposed revision of the BaaS stack. While at the onset this layer may not seem especially important, as FinTech services continue to grow as a segment in the financial service market, services performed by Cloudworkers will take on increased importance. This is a behind the scenes component that end-users will be unable to discern between a complete automated service and one that includes HuaaS.

Potential consequence

The consequence of having a decomposed stack is that there are multiple ways that the customer's front-end could be presented. One way would allow the BaaP provider to appear directly as a bank to its customers. This necessitates the provision of a front-end user interface to the end-customers including user authentication and other features. The bank would appear as any other online bank where all banking services are presented and seamlessly integrated in a single user interface. Another option is that the bank will operate as a white label bank, which will then have a software as a service provider on top of the BaaP operating as the front-end to the end-customer.

White label banking can be an answer to the challenge platform providers face in attaining customers. It can be used to offer banking services in environments where a large group of users already exist, including chains of grocery stores, hypermarkets or existing online portals.[1]

Integrated BaaS structure vs. single service offering

A single service provider is at a greater risk of failure than a provider that offers a larger portfolio of services. Using an integrated BaaS structure efficiently provides an end-to-end value proposition that frees the service provider from having to develop all the needed peripheral services, including authentication and other security services. Those who adopt the BaaS structure are able to provide a higher level of trust than a smaller provider might do.[5]

Security

Cyber-crime remains a constant and serious threat to the banking industry. The introduction of additional entrance gateways by offering increased amounts of composite online services does increase the risk for cyber-crime. It is important that each service be properly firewalled to prevent malicious intrusions. As such, this presents a challenge to a satisfactory user experience if the user needs to constantly be authenticated while performing an online transaction across several domains or applications. Instead, the many domains and apps that are used need to be interwoven in such a way that once a user has been authenticated, this authentication will carry through as he conducts his transaction. This can be accomplished through the 3 degrees of freedom in digital banking, involving:

  • Identity federation across domains
  • Identity propagation across apps
  • Level of authentication [6]

Regulations

Banking is a highly regulated industry throughout the world and online banks utilizing BaaS are no exception.

Europe

In Europe, BaaS for FinTechs is overseen by the Payment Services Directive (PSD, 2007/64/EC) and its 2nd amendment (PSD2) that was adopted in November 2015.[7] Banking licenses are overseen by competent national authorities in accordance to Directive 2013/36/EU and Article 14 of Regulation (EU) No 1024/2013.[8] The eIDAS Regulation provides requirements for authentication and electronic identification and trust services for electronic transactions throughout the entire end-to-end process.[9] Additional oversight for financial and insurance transactions are provided through Directive 2004/39/EC [10] and Directive 2016/97/EU.[11]

United States

In the United States, banks are highly regulated at both the state and federal levels. The Securities and Exchange Commission (SEC) is responsible for much of this regulation.[12]

Asia

Asia has a strong disadvantage because of its high fragmentation of jurisdiction areas compared to Europe. FinTechs can plug into the national Banking-as-a-Service hub to provide their specific regulated and licensed face to their customers.[3]

Africa

FinTechs in Africa have provided an original financing solution in a previously unserved and untapped banking market. Because it is primarily mobile-based, Africa FinTech is subject to national jurisdiction in regards to regulating financial markets and mobile telecommunications.[13]

Australia

Australia's government is behind in regulating FinTech in comparison to the European Payment Services Directive.[14]

Brazil

In Brazil, BaaS is regulated by the Brazilian Central Bank within the rules of a Payment Institution.[15] The best known BaaS' fintechs providers in Brazil are Matera, Zoop, Dock, and S3 Bank.[16]

Russia

Russian banks are actively introducing BaaS, for example, the largest private bank Alfa Bank.

See also

References

  1. 1.0 1.1 1.2 Scholten, Ulrich. "Banking-as-a-Service - what you need to know". VentureSkies. http://www.ventureskies.com/blog/banking-as-a-service-categorizing-the-services. Retrieved 25 December 2016. 
  2. "FinTech Definition". FinTech Weekly. https://www.fintechweekly.com/fintech-definition. Retrieved 16 January 2017. 
  3. 3.0 3.1 3.2 Skinner, Chris. "Overview of APIs and Bank-as-a-Service in FinTech". ASAP Agency Moscow. http://www.bank-as-a-service.com/BaaS.pdf. Retrieved 16 January 2017. 
  4. 4.0 4.1 Lenk, Alexander; Klems, Markus; Nimis, Jens; Tai, Stefan; Sandholm, Thomas (May 23, 2009). "What's inside the Cloud? An architectural map of the Cloud landscape". 2009 ICSE Workshop on Software Engineering Challenges of Cloud Computing. 23–31. doi:10.1109/CLOUD.2009.5071529. ISBN 978-1-4244-3713-9. 
  5. Skinner, Chris (September 7, 2014). Digital Bank: Strategies to Launch or Become a Digital Bank. Singapore: Marshall Cavendish International (Asia) Pte Ltd.. ISBN 978-9814516464. 
  6. Balbas, Luis. "Digital Authentication: Factors, Mechanisms and Schemes". Cryptomathic. https://www.cryptomathic.com/news-events/blog/digital-authentication-factors-mechanisms-schemes. Retrieved 17 January 2017. 
  7. The European Parliament and the Council. "Directive (EU) 2015/2366 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC". Official Journal of the European Union. http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32015L2366&from=EN. Retrieved 17 January 2017. 
  8. The European Parliament and the Council. "Directive 2013/36/EU on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC". Official Journal of the European Union. http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2013:176:0338:0436:En:PDF. Retrieved 17 January 2017. 
  9. Turner, Dawn M.. "Understanding eIDAS". Cryptomathic. https://www.cryptomathic.com/news-events/blog/understanding-eidas. Retrieved 17 January 2017. 
  10. Commission of the European Communities. "Commission Directive implementing Directive 2004/39/EC of the European Parliament and of the Council as regards organisational requirements and operating conditions for investment firms, and defined terms for the purposes of that Directive". European Commission. http://ec.europa.eu/internal_market/securities/docs/isd/dir-2004-39-implement/dir-6-2-06-final_en.pdf. Retrieved 17 January 2017. 
  11. The European Parliament and the Council. "Directive (EU) 2016/97 on insurance distribution (recast)". EUR-Lex. http://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32016L0097. Retrieved 17 January 2017. 
  12. Marino, Jon (6 May 2016). "A wave of regulation is coming for fintech". CNBC. https://www.cnbc.com/2016/05/06/a-wave-of-regulation-is-coming-for-fintech-startups-stocks.html. Retrieved 17 January 2017. 
  13. van der Beek, Wim. "Five factors that differentiate Africa's fintech". CNBCAFRICA. http://www.cnbcafrica.com/news/financial/2016/06/13/factors-that-differentiate-fintech-in-africa/. Retrieved 17 January 2017. 
  14. Lucas, George. "Australia needs to foster FinTech with level playing field". The Australian Business Review. http://www.theaustralian.com.au/business/technology/opinion/australia-needs-to-foster-fintech-with-level-playing-field/news-story/3184e64ee04246c7c817705213030d38. Retrieved 17 January 2017. 
  15. bcb.gov.br/ O que é instituição de pagamento?
  16. globallegalchronicle.com/ Banco BV’s Investment in S3 Bank