GR-6.2.3

For the purposes of authentication of the customer, the interfaces referred to in paragraph GR-6.2.1 must allow AISPs and PISPs to rely on the authentication procedures provided by the Islamic retail bank licensee to the customer. In particular, the interface must meet all of the following requirements:

(a) process for instructing and authentication by the Islamic retail bank licensee;
(b) establishing and maintaining authentication of communication sessions between the Islamic retail bank licensee, the AISP, the PISP and the customer(s); and
(c) ensuring the integrity and confidentiality of the personalised security credentials and of authentication codes transmitted by or through the AISP or the PISP.
Amended: July 2021
Added: April 2019