iBusiness Banking (iBB) Security Centre


At AIB (NI) we take security seriously. We aim to protect you against the threats associated with internet fraud. 

warning icon

Common Frauds and Threats

how do you prevent fraud

How Do You Prevent Fraud

how we help protect you

How We Help Protect You

back to security centre

Back to Security Centre Home

Third Party Providers (TPPs) 


We always tell you ‘never share your iBB log in details with anyone else’ but with the introduction of new services known as Open Banking you may choose to allow appropriately authorised and/or registered Third Party Providers (TPPs) access to your payment accounts with us.

The Open Banking industry website has practical information and guidance. Further information can also be obtained on the Financial Conduct Authority (FCA) website.

TPPs might ask you for your iBB log in details, if you decide to give them these, you should note that they will have the same access to accounts and information on iBB as you.

 

Whatever you decide

It is up to you whether you choose to use Open Banking.  You must give your consent to a TPP first before they can access your payment account.  We have detailed below how you can make use of and manage the different TPP services available:

 

Services offered by TPPs

Managing this service

Account Information Services

You will need to use your iBB log in details to authenticate yourself to us in order for the TPP to obtain information on your accounts.

You can view and revoke any permissions you’ve given to TPPs through the Manage Shared Account Information.

Payment Initiation Service

If you are making a purchase online you may be provided with an option to pay directly from your bank account instead of using a debit or credit card. You will need to use your iBB log in details to authenticate yourself to us in order for the payment to be made. 

You will see the details of your payment through a broadcast message in iBB.

Alternative

Some TPPs may ask for your iBB log in details to read your iBB account information or initiate a payment on your behalf. In these circumstances the TPP will access your iBB log in details directly in the same way as you would.

Please note:  This means we will not be able to identify that it is a TPP and not you accessing your iBB.  It is therefore very important you are satisfied the TPP is genuine.

Permission to these TPPs can only be removed by changing your Passphrase.

Card Based Payment Instrument Issuer (CBPII)

A CBPII is a payment services provider that can perform an availability of funds check on your online payment account. Before we respond to such a request you must verify with us by using your iBB log in details that you are permitting such requests on your account. You will only need to grant access to each TPP once. The response given to the TPP will be a ‘Yes/No’ answer only and at no time will this type of TPP have access to your actual account balance. 

You can view and revoke any permissions you’ve given to TPPs through the ‘Manage Shared Account Information’.

  • If you do choose to use a TPP, you should safeguard the security of your online account(s):

    By ensuring the TPP is authorised and/or registered by the FCA or another European Regulator by checking the regulator’s website.

    Be aware some the TPPs are not registered but have services you may wish to use. The FCA have given guidance on this.

    By ensuring it is a legitimate site – look for the security padlock icon in the address bar and check to see it has ‘https’ as part of the address.

    If you consent to a TPP accessing your account online that is not appropriately authorised and/or registered you may be liable for any loss you suffer as a result.

  • The FCA have given the following guidance on who can provide these new services and how you can protect yourself.

    From January 2018, companies that are authorised or registered by the Financial Conduct Authority, or another European regulator, can provide AIS or PIS.

    The FCA and other European Regulators will add AIS and PIS providers to the registers they keep of all authorised businesses. These registers are publically available.

    You should be aware that companies that have been providing these services since before 12 January 2016 do not need to be authorised by the FCA until the end of 2019, so may not appear on the FCA’s register until a later date.

    Before you use one of these services be alert, and make sure you are confident that any organisations you share your information with are who they say they are. You should make sure that you understand the service and that you are happy with who will be providing it to you.

  • We want consumers to enjoy the full benefits that these changes can bring, however there are some important things you should be aware of.

    - Be alert - you should be vigilant to fraud when using online payment initiation or account information services. If you don’t know who you are talking to, or there is reason to suspect that the provider is not who they claim to be, don’t disclose your banking security credentials, or other personal or financial information.

    - Read the details - always read the terms and conditions of a provider of financial services carefully before signing up, this includes the terms and conditions of AIS and PIS providers.

    - Be data savvy - make sure you understand and agree with what access you are granting to your account, how the account information will be used and who it may be passed to.

    - Check your statements - keep an eye on your bank statements and get in touch with your bank if you don’t recognise a payment.