Okay, thanks for the opportunity to talk about Open Finance in Brazil. I have been working on this ecosystem for the last four years together with the Central Bank of Brazil and today I would like to share some of the reasons we believe this has become the largest data sharing ecosystem in the world. My name is Erick, I work at Raidiam. Raidiam is responsible for implementing the technical services that are used in the Open Finance Brazil ecosystem.
And I'm Fabi, I work at the Open Finance organization itself and I'm responsible for making sure the new products are being released well and everyone is properly certified and all the indicators are good. And that's it.
So, with that in mind, I'd like to just go straight to the presentation. So, everything started with the Central Bank of Brazil innovation agenda. And in this innovation agenda, the Central Bank of Brazil defined three things that he would like to advance and that was set around seven years ago. First thing was payment initiation.
So, we wanted to have a centralized instant payment system set in Brazil. Second one was around Open Finance, so a data sharing ecosystem in the country. And finally, the Central Bank Digital Currency, CDBC, called DREX, which would facilitate smart contracts in the country.
So, Open Finance was part of this big innovation agenda that the Central Bank did. And that's also one of the reasons why the Central Bank of Brazil leader got the award for the best Central Bank in the world for three years in a row. It's because he was driving not only regulation, but also technology from the center. When setting up the Open Finance Brazil implementation, we understood we shouldn't reinvent the wheel.
And so, the first thing we did was look at international examples. So, where was Open Finance being done externally? And we had three good examples to use.
So, United Kingdom with the OBIE, Europe with PSG2, and Australia with Customer Data Rights. And those three were used as a base, but mainly the UK was used as a base for what we should do.
So, let's not create everything from scratch. Let's take what the UK did and let's improve over that structure.
So, we use a very similar concept flow to the UK one. The security standards, the UK used FAPI. We saw it as important.
So, we just say, let's use FAPI. Not only let's use FAPI, but let's use a newer version of FAPI. And for testing and certification, we saw that in the UK, the Open Aid Foundation was doing security certification.
So, we understood we should also not only do that, but also go beyond and do even testing and production. Also, another thing that was very important was around the regulations.
So, the central bank agenda, they came up and said, well, let's set up a regulation. And what is very important and valid on the central bank regulation, everything is very well defined.
So, for example, we have some countries where they say, oh, the central bank comes and say, you have to implement Open Finance by 2025 or 2026. But there is no clarity around what needs to be done. The banks say, okay, I need to do Open Finance. What is Open Finance? That was not the case in Brazil.
So, in Brazil, the regulation was clear around who needs to share data, what data needs to be shared. So, the data sets. How are you expected to participate in the program? How the project governance is going to be set?
And also, what are the technical requirements? So, the central bank gives a clear indication of this is what an Open Finance implementation is. And that's our expectation. And after setting up this regulation, then we can go with the enablers.
So, the enablers that were set by the central governance structure that allowed the banks to not only implement good products, but also make sure their products were being implemented correctly in production. The first pillar that I want to talk about was the collaborative standards development.
And here, the idea about collaborative is we want the industry to get together and agree on what should be the details of the data that's going to be shared, what are going to be the new use cases that we're going to be creating. So, there was a direction set by the central bank, but ultimately, who decides or who defines how the data fields are going to be set, what constitutes an account, how a payment is going to be set is done by the industry.
And what was done is the central bank defined multiple groups or associations that should come together and discuss the use cases, the data fields, and the details that were to be implemented. And that got defined and then set inside the regulation. Second thing we had was a centralized directory and also a service desk.
So, by talking about a centralized directory, we... Use this slide.
So, here, it's a thing that we like to show around the difference between a centralized directory or a trust issue or a trust framework and the lack of. So, in some ecosystems, there is no common trust framework, meaning you need to bilaterally agree with someone if you want to obtain data. What it means is a TPP, a fintech, if you want to get data from a bank, you need to set a bilateral agreement. It needs to create credentials with each single bank inside this ecosystem. That's not the case in Brazil.
So, in Brazil, we register all the providers inside a centralized directory. We define what they can do inside this ecosystem and all the providers, they also publish their APIs inside this platform.
So, if you are a new joiner on the ecosystem, for example, you're a new fintech, you got authorized to join Open Finance Brazil, the first thing that happens is you're included inside the directory. And from there, you're going to get accreditation in terms of what you can do, as well as be able to see all the products that are being offered and who offers those products. And with the credentials that you get on the ecosystem, you're able to just connect with the banks.
So, there is really a very low effort from new fintechs to connect with new banks, which also makes one thing that's very interesting in Brazil is there are no aggregators. So, if you look at the United States, for example, where there's no central directory, it's very hard to connect with the different banks in the US.
So, you end up creating those aggregators like a plaid-like institution, where they create the connections to the banks. And you, if you want to connect with the bank, you first need to connect with plaid.
In Brazil, you don't need to do that. You can connect directly with the bank, because the path and the way to connect with them are well set, not only in the standards, but also in the directory. And the third enabler, I'd like to pass over to Fabi, as I spoke too much already.
Yeah, thank you, Eric. So, in Brazil, one of our strongest side is the testing.
So, we started testing security like with the FAPI standards and the functional tasks on sandbox only. But then we realized that after implementing all the in-production, things are really different.
So, you have the integration with all the different parts. So, we start testing on production as well.
So, it's a set of the test part, both of security and functional, that we test on production. We also test the user experience. And we also have like a centralized data platform.
So, we can get any data that is shared, passes through the directory, but we have a way to get part of the data to get the metrics. So, we can understand how each institution is doing, how each product is doing.
So, that's a very strong part that we have. So, how the process works.
So, we release as OpenFinance the standards that institutions should develop. The institutions start developing the APIs and also the software side. We test them, we certify, they go, they publish their APIs on the directory, and then we test on production.
Now, we have this new process like going on pilot. So, every new release, we get like a few months testing on production before releasing to all the users.
So, just restricted user database to make sure everything is going well before releasing to the public. Just a small comment here.
So, that's a change that we had in relation to the UK. So, in the UK, you do test everything in sandbox, but you're not testing production. And feedback that we got from the UK was the banks were not working in production. They do certify in sandbox. They prove, oh, everything is working as expected. When you start calling, so when the fintechs start calling the banks, the things don't work as expected.
So, from there, we said we need to do production testing. And that gave us a lot of speed in comparison to the UK. And with that, we enable four main kind of categories in Brazil.
So, we have open data. Open data is just like data from the banks. Generic one.
So, not user-specific. We have the data sharing. That's our most, the strongest we have. I'm going to go into details later. But it's basically, I have data in one bank. I want to share that with another, with a fintech, with a data aggregator. Then I can do that just like with my consent. And that's been huge. We have APIs for personal data. For account information. For investments. For credit operations. For insurance.
So, that's the most used one in Brazil. We have the payment initiation.
So, it allows the payment initiators to do the PIX. That's the instant payment in Brazil. And we have a very interesting user case. Because now we just launched one at the end of the year. That allows this instant payment to happen through a wallet.
So, you give consent once. And then you can do the payment without having to open your bank every time. And we are developing now the credit portability.
So, if I have a loan in one bank. I can go to another one and say, hey, check my data. Use the data sharing one. See what I have. The conditions I have there. Can you give me a better offer?
If yes, then you can accept. And then your loan is transferred from bank one to bank two.
So, that's something that already happens. But not in a standardized way between all the banks. And that's something we are launching at the end of this year. And it could also move from credit to investment portability. Like everything you can imagine that could be portable.
So, for data sharing, a few big numbers for you. Like we have 74 million active consents from 43 million clients. We have 66 data providers and 53 data receivers. About the 43 million clients. That represents 20% of the Brazilian population. And it allowed a few banks from, you could reduce the time for opening accounts.
So, from one institution, the time to open an account went from 32 hours to two hours. And also, like, especially it's used with credit.
So, you can, banks can offer better savings, increase the credit limit. And offer new credit cards for their users. And now we have, like, here is to share with you the journey.
So, you go to your bank. You choose to share your data. And then you choose, okay, from which bank do you want to bring your data?
And then, Erick here chose... Yeah, I'm choosing NewBank here on the flow.
So, I want to get data from NewBank to this bank that you're seeing on the screen. I see the data on the screen that I'm going to bring. It sends me to NewBank where the data is going to come from. I need to log into my NewBank app. On my screen, I already see the data that I'm going to be sharing. Click on authorize. Then I'm now going to be sent back to my original bank. And from there, there's a confirmation that the data is now available from Mercado Pago, which is this institution here, to see. And this flow is standardized across all the providers.
So, if you go to any bank in Brazil, you see an Open Finance logo. And it's repeating, but you see an Open Finance logo. And you will be able to follow this exact same flow across all the institutions. Because we standardized everything. And we tested that everybody follows the same standard. And similarly, like for payments.
So, payments is much less used. And I forgot one number.
So, for data sharing, we have over 10 billion API calls per month. And when we go to payments to growing, we have 18 million API calls per month. But we have 11 account providers, over 100 account providers.
Almost 50, 30 TPPs participating. And I'm going to show you the case.
Oh, another information, sorry. The non-redirect payment, the journey I'm about to show you, we also rely on the FIDO specification to...
No, no. I'm just going to comment about the non-redirect payments, which is going to be the example that we're going to be showing. And this use case, which is quite new in the Open Finance world, it's based on, you don't need to go back to authorize each transaction on your original bank. It's similar to a variable recurring payments. But this time, you use a flow where you can just do how many payments of how many values to any type of provider, to any other bank or receiving account that you want to do directly on your wallet.
So you do payments on your wallet after you have authorized this once. Yeah. And in two months of this flow, two months after the launch, we already have over a million consents. So that's been very used in Brazil. So basically, here is the Google Wallet. You choose to link an account to enroll. I'm selecting here the Itaú account to be linked. So same flow as the Open Finance we saw. So here I'm providing my password to go into my bank, which I want to link with Google Pay. I will see on my screen directly if I want to really authorize payments to be executed by Google Pay on my behalf.
Now I have authorized this and now I can just do a payment. So now I'm going back to Google Pay, so my wallet. And my account has been successfully linked. Let's do a payment now. So I'm selecting who is going to be receiving this payment. So I selected someone and I'm selecting the value I want to pay. It's using passkeys to authenticate me on the passkeys file to authenticate myself on the wallet. And anytime I want to do a new payment, restarting the flow.
But anytime I want to do a new payment on my Google Wallet, I'm able to do this without going back to the Itaú, which is the original bank app. And that could be used for contactless payments. So like you go to the store and then you can pay. But also you can link your account to your Google Chrome, for example. So every time you're shopping and you want to use PIX, you don't have to get the data, like go to the bank to make each payment. You just save that on your Google Chrome and then you can instantly pay.
So one thing that we're starting to see in Brazil and start to intensify is how people are stopping using credit cards. So with PIX, which is instant payment, we already have more PIX payments executed than credit cards. And now with this method, which is as seamless as paying with your credit card, we expect to see even more migration from credit cards to instant payment. And the best part is there is no cost to the user. So it will lower the transaction costs. And also being much more secure. You don't need to be sharing your credit card details or your data.
You authorize exactly how much you want to be sending on a monthly basis to a specific provider. And as next steps for open finance in Brazil. So now you're in the middle of the pilot of automatic payments. So it's basically an automatic tab, but using this PIX payment. We are with the pilot running right now. We have the credibility that I mentioned previously. And we are also focusing on improving our monitoring and our data metric system. So that's been very interesting. And I'd like to thank everyone for being here. And also nothing of that would be possible without our partners.
So like everyone from region, thank you. And also OpenID, especially Joseph here. It's been like a long journey, but none of that would have been possible without you. So I remember the first days where we didn't understand anything about FAPI. And we're like on a daily basis asking questions to Joseph and the OpenID Foundation team around. What is this? How does this work? How wide is it secure? And they were always there to answer questions to us. So thank you. We can actually have one question if there is one.
Yeah, just one final. Okay, any plans to open the ecosystem for other type of organizations consume like authentication services similar to what the Nordic countries do? The authentication or data sharing, but not specifically a financial organization. So the challenge we have in Brazil is given it's very regulated. So the central bank led this initiative. You need to be a regulated financial entity to be able to participate in the scheme. They are trying to make it easier for institutions to start being regulated. But as you know, it's not that easy to get there.
Like currently, I think it takes from 6 to 12 months to become a PISP in Brazil. Yeah, but one of the things is you can get a partnership with one of the data consumers or with the TPPs. So they are regulated. You can get a partnership with them like as a banking as a service, the TPP as a service. All right. Thank you very much, guys. Thank you.