Toward a "Super-Community" of Trust"

Bill Orr · ABA banking journal · 2001

A banker/technology team will start with the hotly disputed practice of aggregating customer account data across financial institutions Trust is the coin of the financial-services realm. Community bankers how to assess the trustworthiness of their neighbors. Regulators require all bankers to know your customers. Centuries ago, bankers invented Letters of Credit to enable banks to trust distant, unknown parties--by asking banks that did them to vouch for them. Today, the internet has brought banking around to that same point of needed innovation: how to inject trust into financial services throughout the virtual world--electronically, at the lowest cost, at the Lowest risk. For several years, bankers have been told that the solution to this problem is encryption enabled by a global public key infrastructure (PKI). So far, so good. PKI seems to work as advertised--at least technically. Using PKI, a bank and its customers can be reasonably sure that they are really talking to each other and not imposters. They do this by requiring that all parties obtain and store their identities in a central place managed by a certification authority (CA) who takes on itself the risks implicit in vouching for the validity of those identities. This in turn gave rise to isolated communities of trust, each of which agreed to play by the rules of a given certification system. Thus we now have such systems for individual banks, financial service bureaus, governments, automobile manufacturers, industry supply chain management, and so on. Not only do these communities work through common CAs, but each, necessarily, has its own rules for identifying members, authorizing privileged transactions, setting dollar limits on deals, resolving disputes, assuring privacy, and handling financial requests in a suitable manner for that community. The problem these communities now face is that they aren't tight little virtual islands of trusted--even though widely dispersed--compadres. Each community shares members with other communities. And when it comes to invoicing, payments, and other money matters, everybody uses the same global financial system. Getting away from screen scraping Indeed, it was in banking that the most acute problems of trust sharing appeared over the past year. The issue was account aggregation -- enabling one bank (or nonbank) to access all the accounts that a consenting customer has in other institutions and then give the customer a consolidated picture of her financial status. Nonbank portals and some big banks offer this service using a much-reviled technique called screen scraping--a slow, inefficient, error-prone method chock full of risks and uncertainties. What is the risk in multiplying the number of customer IDs, passwords, and primary personal credentials that swirl around the internet? Should applications service providers (ASPs) be centrally registered? Should the system require audit trails for dispute resolution? BITS, the technology arm of the Financial Services Roundtable, looked into the situation with an eye to coming up with an interoperable system that would reduce risks and bring sound business and technology practices to account aggregation, with the least disruption to existing models of service. …

Read the paper · More papers on PaperTik