Blog Posts Business Management

Screen scraping: a balancing act for banks

Blog: Capgemini CTO Blog

APIs vs. screen scraping

With the introduction of PSD2, it has become possible for non-banks to initiate payments and retrieve transaction data, after a customer’s consent. This enables TTPs to develop innovative services such as money management apps. Banks were steered to develop APIs to give TPPs with a PSD2 license controlled and safe access to their customers’ bank accounts. However, due to various reasons (e.g., migration costs, lack of internal expertise and the unrestricted amount of data that can be collected), the practice of screen scraping is still continuing.

Screen scraping is a technology by which a customer provides its banking app login credentials to a TPP. The TPP then sends a software robot to the bank’s app or website to log-in on behalf of the customer and retrieve data and/or initiative a payment. Banks have less control over the data retrieved, which may go beyond account data regulated under PSD2 and may include any customer data available. While with an API, banks have greater control to share only the necessary data for the TTP’s service and customers do not need to share any credentials with TPPs.

Banks must pick their battles

On the one hand, banks benefit from enabling TPP’s to access their customers’ data and providing innovative services. Some banks may also practice screen scraping themselves. On the other hand, banks may want to be in greater control of knowing who is logging in to their bank accounts and don’t want to share more data with TPPs than needed. Data is the new oil and banks might not want to give it away too easily. Next to that, even though customers must give their consent to TPP’s, they might not always be aware of what they consent to. If personal data is shared unintentionally, this could hamper customers’ trust in banks.

As long as screen scraping remains common practice, banks should define a strategy to get control over it. We identified three types of strategies:

screen scraping

What’s next? A cat-and-mouse game.

Each screen scraping prevention strategy comes with its own benefits and concerns. But before banks start thinking about which one to implement, they should first and foremost earn the right to do so, by having a PSD2 API that is on-par with market standards and meets local requirements. The next step is to assess current measures taken to prevent screen scraping. From there, it is needed to assess the channels and data sources where it is desirable to start preventing screen scraping, as well as identifying certain parties that might be prevented for using the approach. Once a strategy is chosen and implemented, the cat-and-mouse game starts. TPPs may look to overcome measures taken by banks to block screen scraping – hence it is necessary to build an organizational capability with the ability to respond to counter measures initiated by TPPs. Combining this technical capability with legal and regulatory affairs will be vital.

Find out more

Do you want to continue this conversation to learn more on the latest developments in Open Banking and how banks can respond to stay relevant? Get in contact with our experts here.

Authors

Alexander Eerdmans

Alexander Eerdmans   

Alexander Eerdmans is Vice President and Head of Financial Services (FS) at Capgemini Invent Netherlands. With a background in Finance, he has a wide experience in leading projects on Open Banking, FinTechs, and Financial Services. Alexander is always working on “What’s Next” in FS and encourages global collaboration, which enables unlimited possibilities.

Joost van Putten

Joost van Putten

Joost van Putten is a senior manager at Capgemini Invent Netherlands Financial Services. He has a background in innovation & strategy and has completed extensive work in the area of Open Banking and Payments. He has supported pan-European banks implement the Payment Services Directive 2 (PSD2) and has led multiple research studies into related market developments.

Titia Meijburg

Titia Meijburg

Titia Meijburg is a senior consultant at Capgemini Invent Netherlands in the Data, Finance, Risk & Compliance team. She has a background in banking and innovation. Titia has experience in projects on Open Banking strategy, Sustainable Finance Regulations and Risk reporting.

Colja Maser

Colja Maser

Colja Maser is a Senior Consultant Enterprise Data & Analytics at Capgemini Invent Germany.

 

Leave a Comment

Get the BPI Web Feed

Using the HTML code below, you can display this Business Process Incubator page content with the current filter and sorting inside your web site for FREE.

Copy/Paste this code in your website html code:

<iframe src="https://www.businessprocessincubator.com/content/screen-scraping-a-balancing-act-for-banks/?feed=html" frameborder="0" scrolling="auto" width="100%" height="700">

Customizing your BPI Web Feed

You can click on the Get the BPI Web Feed link on any of our page to create the best possible feed for your site. Here are a few tips to customize your BPI Web Feed.

Customizing the Content Filter
On any page, you can add filter criteria using the MORE FILTERS interface:

Customizing the Content Filter

Customizing the Content Sorting
Clicking on the sorting options will also change the way your BPI Web Feed will be ordered on your site:

Get the BPI Web Feed

Some integration examples

BPMN.org

XPDL.org

×