So, as we learned, we will have a larger panel. Instead of 20 minutes, we will have full 40 minutes, or 35 now.
But, really looking forward, since we had a little chat on this topic already yesterday to prepare everything, and until everybody is wired up. So, I'm really looking forward for this panel.
And, yeah, having a good time. So, perfect. We will be complete in no time, I think. We left you that seat. You can join us in the middle.
So, maybe just a quick round of introduction of you, starting at the left and go to the right. Okay. My name is Steve Hutchinson, you can call me Hutch. I'm the Director of Security Architecture for MUFG, part of the Mitsubishi Bank of Tokyo. I'm Tom Wijnen, I'm a Senior Product Manager, Marketing Manager within Worldline.
So, Worldline is a payment provider, so I have 20 plus years of experience in payments. So, I saw, for example, the upcoming of CEPA, the Open Banking, the BSD2, that was introduced a couple of years ago. And this year we have the Instant Payments Regulation, so really interesting and exciting.
And, of course, also the schemes that are built on top of that, like EPI is doing now with the Wiro scheme. So, coming from the payments world, for me it's really interesting to have a discussion also between payments and identity.
So, for myself, speaking for myself only the last two years, I really looked at the eHIDES regulation and the impact of it on the payments. So, really interesting to discuss this here. Hey everybody, my name is John Horn. I provide advice for banks and insurance firms in financial services around digital identity. I've been doing this for a long time, as my hairline suggests. Excited to be here. Thanks for having me today.
So, to round this one up, my name is Kai Boschart from Köppinger Kohl. I'm trying to hold everything within those 40 minutes. I was already warned that this is a topic where people can spend more than 40 minutes talking around.
So, maybe we just dig into it with a lightweight question, Tom. What is the connection between identity and payments and why is this connection so important just to get into this topic?
Yeah, like I said, so within Europe at least we have the PSD2, the Payment Service Directive, and we have the eHIDES. And there's an interesting connection because the eHIDES is not limited to identification. It's also about authentication and using very viable credentials in the ecosystem.
So, and there it means that suddenly, and another aspect of eHIDES, it's because the first eHIDES was for public authorities only. And this one says, yeah, but also private companies have to comply to it.
So, suddenly it's coming from public also to private in a case of secure user authentication. So, at least my reading is that also for payments where you have this SEA, which is the Secure Customer Authentication, in the regulation, in the PSD2, you have to accept also the digital identity wallet in this case.
So, that immediately affects the payments landscape. So, the next question is then, yeah, how do you match those two separate ecosystems?
Yeah, and that's where a lot of the work is currently taking place right now. Open banking and PSD2 really kind of forced us to become much more mature in the payment space. For a long time, we've just kind of taken identity and duct taped it on to the rest of the systems. And it's only just recently that we're starting to see some of the technical innovations coming through on the identity side, which are starting to show some promise.
Digital wallets, which I will admit, I was really bearish on the digital wallets for a long time, but starting to see that it's the digital wallets not just holding on to payment information, but also holding on to verifiable credentials, government documents, things to prove your account ownership. Suddenly, we're starting to see that we can start leveraging that as like a common UX platform with some of the things that are going on with the federated credential management, replacing a really fragile third-party cookie process with a true kind of browser native login service.
And I can now kind of see a future where login, consent, payment verification, everything takes place kind of on that one platform. So it's super exciting for me to see that.
Yeah, I'm right there with you, Hutch. I mean, I was not bullish on wallets. But when you think about the verifiable credential being in the same wallet as payment information and perhaps even two credentials, right? Maybe it's a combined wallet. Maybe it's a more unified kind of wallet. But you can see that identity can solve some of the consumer's problems and some of the risk problems in the industry. I'm in the States. I'm not in Europe. I don't get PSD2 or 3. I have FTX, but a market that needs to solve some of these problems. So you put both those things in a wallet.
Now, there's lots of work to do, but there's a great promise associated with putting identity and payments together. So I'm pretty excited about it, too. Great topic.
I mean, you introduced now a lot, and you can call it kind of a new era. And when you think about this new era, what is the challenge you really connect to this and which needs to be overcome?
Yeah, I'll take that one first. Maybe because I come out of the cyber and identity world, fraud prevention has to get better. So the promise of identity and payments can solve some problems. But first and foremost is fraud prevention. Of the banks in the United States and North America, fraud prevention, like through SIAM, is the number one problem they're trying to solve through our research right now. Ninety-five percent say it's their most critical problem to solve in identity.
In some ways, if you're not in that fraud world often, at a conference like this, we talk about decentralized or decoupled identity, siloed, desiloed identity. Fraud and cyber teams aren't even siloed would be a compliment for them. It's like they're playing different sports. It's like the fraud teams playing basketball and the cyber and identity teams are trying to win the World Cup. They have different motivations, different drivers. So fraud rates going up, especially for real-time payments.
As real-time payments grows across the world, all of our research says that fraud growth is kind of tracking along with it. So along the way, it's really about how do we help fraud prevention get better? How do we improve fraud detection rate? How do we improve false positive rate? How do we get the fraud side of the business to stop having 25 different siloed fraud controls that are still getting beat and actually bring identity to the table? So I think fraud prevention improvements is first and foremost. It's on the way to that new era. It's something we've got to solve.
Yeah, and I like that you brought up that your fraud team is not talking to your identity team. And to me, we can see where the technical solution is coming from now.
The W3C, the Federated Identity Group, is really doing some good work. Again, with the FedCM, also with the Digital Credential API. But there's a huge organizational problem. We're starting to see vendors talk to each other and the standards organizations are finally talking to each other. We've got the payment standards teams talking to the identity standards teams, so that's good. But we still need to overcome, within our own enterprises, we need to overcome the organizational boundaries.
So like within my own space, our regulatory teams don't tend to talk to our identity teams, which don't talk to our payment teams until they need to. So right now, it's not a team sport. We're all trying to solve the problems as they're given to us. But we really need to be just like we can see the real progress only came on the technical innovation side when they started talking to each other. We need to do that internally on our enterprise side. I thought that was a really good point that you made. But there's more organizations that are talking to each other within our enterprise.
Or they're talking to each other as like lip service. They're huddling people at incident bridges, but they're not mutually invested in each other's success. If you're on the fraud side at all, again, no shame associated with the fraud side, fraud prevention side or financial crime side, prevention side. But you're mostly using transaction controls. So right at real-time payment time, it's like the first look at the user is when they're walking into your kitchen of your home.
Connecting it to some of the things you've heard at this event, the lack of signaling on the fraud side is a huge problem. So identity is really the best vehicle to solve user-centric 360-degree risk views of how consumers are using digital banking and how they're operating with identity. All that signaling to fill in a real gap that the fraud folks have with the lack of signaling. So they tend to be at transaction time. The person's walking into your kitchen. That's the metaphor.
And then you're throwing some old one-time passcode to their phone as the mitigation step, which is 24 years old and beaten easily by attackers today. So it's really about modern identity being able to fill in that signaling gap. And we'll talk about with the risk fabric associated with all the things that we've talked to hear about at this conference. That's what the fraud side needs if they can get past themselves some days, if they can get past some political boundaries at some banks that we see. But if they can actually just start to solve these problems more together.
But they've got huge problems to solve. So in the cybersecurity track this morning, we spoke a lot about buzzwords and creating all this buzzing and noise around different words, which are just in the mouth of everybody. Now I kind of want to trigger you with the EIDAS and what changes come with this buzzword. Maybe just clarify it a little bit, Tom, maybe. What do you exactly mean? So what exactly will be the change with the EIDAS?
Ah, okay. Yeah, EIDAS, of course, brings the obligation to accept these wallets, these digital identity wallets that have to be issued by different governments. And what is really interesting for me, again, with the payments is how is that going to work?
So, for example, the relying parties, how are they? It's supposed to be all interoperable, but is it really interoperable?
I hope so, but, you know, you never know. Because we have the experience in PSD2 where there was also an idea of EIDAS has to be open banking, it has to be interoperable, but in the end it was not. And it's all about the user experience in the end. The user has to be able to make use of it in a very intuitive and very fluent way. So if you look then at this regulation and if you combine it with payments, how can we make it valuable to the relying parties to use it, to use identity and payments in one go?
And, of course, we can do that with also adding all these attributes. That's also feasible because the regulation doesn't limit it. You can put all kinds of viable credentials in that wallet.
But, yeah, let's first start with a very simple use case where you can make the payment and have a very good user journey. And, yeah, that is what we need to explore in the coming years.
And, yeah, that's what we are trying to do within the different large-scale pilots that are set up to look at the implementation of this regulation, how it should work, what are the specifications needed, what are the rulings. Yeah, it's really to see how we can implement this EIDIS and the payment within it.
Well, it also, for all the background stuff, which is great, when you start thinking about what these new workflows are going to look like. Again, if you had told me two years ago when we were talking about this in this very building that by the end of 2026 everybody in Europe was going to be able to have their own digital wallet, I would have said you were crazy. There's no way it's going to happen that fast. But it is.
But now, again, because it can hold verifiable credentials, because it can hold the payment, because we're designing these federated workflows to make this a single kind of seamless process. Think about a typical open banking situation where if I want to connect one of my budgeting apps at home to my bank account, I can now in a single flow do my authentication, my credential presentation, my account ownership validation, and do that synchronization all in one go. If I do that today, it's like three different UX workflows.
There's a whole bunch of consent things that come up that look like legal agreements. The promise of leveraging, of having a groundswell of people who all possess this UX platform now opens up. I think relying parties and all those things, they're going to have to be able to support it or they're going to be left behind. They're actually going to end up demanding this process because it's so seamless and so easy. And more secure. Just digging a little bit deeper into this, John, open banking can be such a difficult thing, a solution design for banks to implement, right?
How do you see modern identity simplifying this approach? Open banking and making it secure is, again, our research this year, it's the number one challenge. It's of 64 banks in the US, in North America, it's the number one use case that banks feel they're blocked with current controls.
Right now, we've heard at this event just the need for things to become simple, right? But there really aren't many of those red easy buttons sitting around right now.
Right now, a bank has to figure out how to do API security well. Siam has to extend its data well. Some Siam platforms aren't capable of doing that. B2B identity all has to play out. And then consumer consent has to play out. But just at this event, we've talked about how the consumer can allow a genic AI platform to kind of have consent to actually secure it. Those are the kinds of things that are needed. Whether we have EDAS on the European side, which will drive some interoperability, or in the States, it's more mobile driver's license at the state level that are playing out.
And at the state level, and then the big tech vendors saying, we're going to build wallets, we're doing wallets, kind of forcing the banks to have some say in this. But it's the same kinds of things. It's solutions that, you know, the identity fabric that Martin's identity fabric, and I love it. It's a great fabric. But to live that out for the banks is going to be difficult, because along the way, you have to solve the problems of fraud prevention. You have to solve the problems of integrating more together.
And if you'll hear this, I don't mean to ruffle anybody's feathers, but we say things need to be simpler in identity a lot. But that's actually not what happens to identity along the way. To make things simpler for everybody else, identity actually has to become more complex and interwoven in that fabric, right? So identity in some ways has to become a new kind of solutioner at the table to solve these business challenges. And that requires identity people to become more than, I mean, my execs or our bank execs, they don't care about MCP. They don't really care.
They can get on behalf of a little bit, but identity folks actually have to absorb more of the complexity for it to become simpler for everyone else. So that fabric that we've talked about is a tremendous fabric and to work toward that and to achieve it. But it actually means that identity has to take on more of that complexity to make it simple for everyone else. So we talked about or at least a little bit about use cases and simplification.
But, I mean, for banks, this cannot be the only reason to really spend money on it and investigate on this topic, right? Maybe you can give us all a little bit more insight about why should banks really focus on this topic?
Well, banks are going to have to focus on it. I mean, we're already focused on it because of open banking regulations. It's just that identity hasn't caught up to it.
Again, like I said, there's a lot of rigor that we went through in our payment systems because – not because we wanted to, because we were forced to. And it doesn't happen as often in the U.S. as it does in Europe. I was telling somebody just this morning that one of the reasons I like coming to EIC is because Europe always seems to be just a bit ahead of us on the regulatory side, the ability to kind of pass those laws. And we get the advantage of getting to see how our peers in Europe are solving these problems with the new technology.
And then I get to go back home to my leadership and just literally steal words out of other people's presentations. And I look like a genius. Like I've time-traveled a little bit so I can get us ready ahead of time. That's why you come to EIC. Me too. Go on. Go on. So we're behind on identity. And so identity has to change anyway. And it's really that we've been waiting for the solution that we can put in place.
But again, standards organizations are now – payment standards organizations are working with the identity standards organizations. And instead of against each other, so we can provide that streamlined thing. So it's going to have to happen anyway. It's just now we have a way to make that happen.
People, consumers, it's regulatory in Europe. Consumers are going to demand it in the states. If I could add to Hutch's comments. And we come here. It's great to come here. It's always a privilege to come here. I made you laugh, but it's always a privilege to come here and talk about identity. But like the banks have other – they may not have a regulation that forces them to behave like PSD2. We have this thing called Dodd-Frank 1033, which is a bit of a mess. And who knows if it survives and all this other drama going on in the U.S. right now.
But banks have an interest in reducing their run cost basis. They have an interest in getting away from locally coupled identity. There's a cost to doing that. So verifiable credentials and getting to decentralized models. There's card companies that are doing that in the U.S. And the banks will follow. Banks are going to follow because it's financially attractive for them to get out of the identity business. But they're going to have to come to their own conclusions. They come to advisors like me to ask if it's time yet.
But they're driven by run cost efficiencies, and they're driven by growth. And so I think there's other drivers. And there are certainly drivers of banks here in Europe, besides just regulation, to get to open banking. Some banks hate open banking. They won't say it out loud. They won't say it publicly. But they're for it in their investor report, but inside the institution, they're not, obviously. But they do. But most are just trying to grow their business and shave off their run costs. And the identity principles that we talk about a lot at this conference are keys to getting there.
So some banks will be just driven by the normal economics of being a financial institution and trying to show shareholder value. Exactly, like you said. So in Europe, it is mandatory. But that's the wrong reason to go into it, in my opinion. Like you said, look at the cost efficiency that you can get. Look at the improved user experience that you can achieve. And especially if you look at all these different attributes that you can put into this wallet, you can make customer journeys which are really excellent.
And like you said, if you have your driver's license or your address verified, your age verified, etc., etc., you can have really, really good and solid customer journeys. And that should be actually the motivation, not just from the relying parties, but also from the banks to adopt these things.
And yeah, there are many use cases out there. I would say to every bank in Europe, join the large-scale pilots because we are trying to look at these use cases so that we can really make a step forward and really implement those use cases. Absolutely. We spoke a lot now about the regulatory requirements, and this is the reason.
I mean, we know, at least in Europe, regulatory requirements and quite a high maturity in banking is always or was always established. But now like all those digital products like APIs and digital wallets blurring those lines. And looking at this, what is happening in the industry? What makes you hopeful that the identity systems can evolve to meet the same level of the thing to stand those requirements and this regulatory pressure?
Again, I hate to keep saying it, but I think that to me the most surprising thing, the thing that makes me most hopeful about it is to see all the different, to see vendors talking together, to see the standards organizations talking together, to see the different siloed departments within my own company talking together, all working towards that common solution.
I feel like we're at the point where technology is finally meeting up with the organizational requirements, and that's what's going to start driving some of this innovation, at least in places like in the States where we don't have like a sword of Damocles hanging over our heads yet, but where people can actually, like when we adopted open banking and we started working with our development teams to implement a simple thing like FAPI, it was because we needed to, but then it became, it's only after you had like some significant portion of your development teams leveraging it that they realized, oh, this is great.
This is, standardization is a good thing for us, and I can see that happening with our payment systems now. I'll pile onto that. I'm optimistic for similar reasons. Like most in financial services, right? If you're not in financial services, take this as a metaphor, I guess, for your business, but for financial services, most banks are not going to be able to build this themselves. The top banks, yes, but most of them that I advise need vendors to build this fabric or to build an expression of this fabric so they can win with it, and I do see vendors talking together, right?
It's become more and more obvious the last couple of years on identity vendors talking together around this stuff. The second thing I had, there was a session, it was before the kickoff on Tuesday, if you were in it, but there was a use case of, and I'm not saying anything that wasn't publicly shared Tuesday, but the Bank of America decentralized identity use case for the workforce, and so I'm encouraged on the payments and customer front because I think banks, one of the things I've been talking about with banks in the U.S.
is that actually the corporate workforce has a lot of the same needs, and it's actually a safer place perhaps to debut some of these new tools and new capabilities. You want to deploy eugenic AI, do it, do it in the workforce. You want to deploy deepfake capability, do that in the HR process in the workforce. So I'm watching banks in the U.S. begin to embrace their corporate workforce and data breach risk, that's what the risk is in the workforce, to actually deploy some of these techniques, and I think it functions.
They don't call it incubation for the customer space, but I think it kind of functions that way. So I'm encouraged that banks are getting involved in that.
Again, the workforce pursuit, third-party risk is huge for the workforce, and that session before the conference kicked off on Tuesday showed a good use case for that. So I'm encouraged for that. It's really impossible to manage that whole ecosystem by one company or even by one industry, I think. It's really a crossing, and you need to have specialization, for example, in payments. You need to understand payments, you need to understand identity, and those worlds have to come together.
So that's why I think what you mentioned, these vendors talking to each other, it is really needed because it's impossible to be able to manage that all by yourself. So that's great that we perform here and provide this platform that you can really communicate together. But you phrased it kind of simple to just implement these fabrics and having it. It sounded very simple to just like snip with the fingers, and then you have it, and then everything is fine. I assume it won't be that easy, and maybe you can go into a little bit of the challenges, how to go there, how to get there.
I'll give it a first. So I said it was going to be hard. So I think it's going to be hard on the inside. I think events like this help tremendously. But I think if you're an identity leader, like we are, 95% of us are here in the room, I think you hold the key to the success. I think more and more you need to understand what you're trying to build in this fabric, but you actually need to be a translator to the business. Because most businesses don't care about identity, they care about what identity can do.
So the best people I've seen in business the last five, eight years have been risk people, identity people that can convey in terms of the business. Talk about business outcomes. Tie your identity solutions to a business outcome. It seems kind of scary, but that's what we need to do. But to be a translator for identity, you know the inside baseball, so to speak. That's an American term, sorry. But to actually convey business principles.
I think that's what most banks need right now, is they need identity professionals to act like business leaders, to help them get to places, even if they don't know what an identic fabric is. That's a really good point. A good friend of mine who I used to work with at GE, John Lutton, and he just gave a presentation earlier this morning on why do identity governance implementations fail? Why is your IGA project failing?
And the biggest reason that he pointed to was because they didn't involve the business side enough, that they focused more on collecting a huge number of IAM engineers and no business analysts. And it turns out the business analysts were the ones that actually held the key to making those successful.
So one, totally agree with you, John, it is not going to be easy. None of this has been easy. Implementing new systems is not easy. I am happy that it looks like it's possible. So my hope is totally tied on it's not a pipe dream, it's actually something that we can accomplish.
But yeah, there's no overlooking how difficult it's going to be to actually pull it off. Yeah, I totally agree. So the business question is absolutely valid. There has to be a business model for every participant in this ecosystem. So that is really key. But I think all the pieces of the puzzles are there, but we have to start getting them together. So the technical parts of the puzzle, you have the business parts of the puzzle.
And yeah, I think that's what we see what's happening in Europe. So implementing EI, they started these large-scale pilots to really start putting things together and make it work. For example, we are participating in one in the EWC consortium where we really tried or are going to try, not exactly if it's already done, a payment, a card payment that's done in Greece. With a wallet, with a student using a wallet, getting a deducted fare and then it is going to a bank, etc.
So yeah, that is a first try. And then we have the second wave of pilots where we even go further, where we do not only want to make sure that the payment is authenticated with the wallet, but even initiated from the wallet. So that's even going further. It's not in the regulation maybe, but just like we said before, if you want to add value, you have to think beyond the regulation.
And also, yeah, I would say show that it is really bringing some value to it. And if you could do a payment initiation from your wallet, that is I think already one step further than just the authentication of the payment.
Yeah, so John and I are just going to become really good friends with Tom and we are going to see what Tom does between now and the end of 2026. And then we are just going to duplicate all the stuff that works.
Well, and just the beauty of having a verifiable credential in a wallet and the payments information and the simple behavior of a push coming to that wallet to be able to make the payment work with the consumer being able to assert a verifiable credential. There is work underneath all that. But just that alone gives it. I mean it is a great time to be an identity leader in the market right now. There are some hard problems to solve, but just that wallet expression. I am optimistic of what the future looks like. I have one last question.
Maybe it is too big of a question and you are not really prepared for it. Anyway, what do you think is the biggest leverage you can provide to a bank to move in this direction? So what leverage would you suggest to anyone to really go for this one and there you make the fastest and the biggest progress in the right direction? I mean maybe that is a big question to answer. Like in simple English words, just giving a grasp on it, how to go into this direction for everybody. I honestly think it is going to come, that the leverage is not going to come from me as the identity person.
I am going to help them get there, but the leverage is going to come from the pressure that I think our customers and our business partners are going to put on us because they are going to want to see those streamlined work. They are going to hear about the things that are happening over in Europe. They are going to want to duplicate that on our own space. So the best thing I could do would be like to go home on Saturday and starting next. We would start talking to people about we need to be ready for this. We do not need to be reacting to it.
We need to be getting ahead of it because it is not that hard. A lot of plumbing is already there and what we are waiting on is kind of the finalization of especially like the digital certificate API or digital credential API. Once that is solidified though, I think we have got some really cool solutions that we can put in place.
Kai, I think you asked a good question. I think that for banks, financial institutions, sometimes it is just the why do we exist question, existential question. Why are you in business? You are here to grow the business. You are here to gain efficiencies. You are here as a trust vehicle for consumers. Those questions alone, getting an executive to that place and that is what we do, is why do we exist? If that is why we exist, then open banking has to be part of why it is a survival mechanism at minimum and it is a growth mechanism on the other side.
Optimist says it is a growth mechanism, but it is really a survival. It is an existential question for a financial institution, I believe. I agree. It is very, very difficult always to see who is getting the best out of it. I think there are some opportunities also for banks to leverage some of their information which they can also put into the wallet like an IBAN attestation. That could be a way for a bank to go forward. But like you said, the basics is more their consumers, their clients, to offer all kinds of payments, card payments, account-based payments, etc.
And all other services that they have with which they can use actually the wallet as well. So it is also minimizing their costs, which you said before. They can optimize their cost structure for sure.
Okay, great. Thank you. Before I let you off the hook, I want to give you the chance or ask for it. Since it is such a great topic and a big topic, you get not only one sentence, you get two sentences. What do you want to tell all the people here in the room and online to really conclude this topic in one or two sentences, each of you?
For me, it would be that we got very mature very quickly because of open banking on the payment system side. And I finally see that there is promise on the identity side to finally catch up. I think what is really key in this is about payments, it is about identity. It would be great that we can work together, all together, payment specialist, identity specialist, and work together on a new ecosystem. I don't know if it is a combined one or two ones interacting, I don't know exactly. But at least that we work together and make the best value out of it.
Martin gives you five euros if you use the word fabric. Oh, fabric, the fabric. I guess I would say, just to pile on, tough problems, but there has never been a better time to be working on digital identity. And to work, not just to get the business to input, but to be the translator for the business. To think about the business problems you are trying to solve and try to speak in those terms, not your terms, but keep fabric to us, because Martin is going to give us five euros every time we say fabric. But to speak in the business terms, be that translator your business needs.
All right, thank you very much. Thank you for this great panel. It was a great topic and I really want to encourage all of you. They will be here, so go to them, speak to them, and get all those great insights which you couldn't have now after this great panel. Thank you very much for your time and all those great information. Thank you.