@Edent we proposed direct access for the customer in the original report, but I can absolutely understand why that's not been a big focus of the standard that's emerged; security is hard, and the API could be easily subverted to use customer access as an attack vector.

@floppy yeah, it is a tough one. And banks don't have the customer service resources to deal with it.

