Overview
Authorisations are one-directional. Granting an authorisation lets a counterparty send to you, which is your authorisation to receive. For two-way traffic, each party grants the other. RMA applies only to messages that require authentication, such as MT 103. Unauthenticated messages, such as MT 999, need no authorisation.
You manage authorisations centrally through the RMA Portal, a web application that supports grant, modify, revoke, reciprocate, search, templates, and four-eyes control through role-based access. Bulk actions cover grant, revoke, refuse, add, remove, and replace, each with two-operator control. Central Portal changes take effect within 15 minutes of acknowledgement.
Capability | What it does |
Business profiles | Group message and request types across FIN and FINplus for a business flow, so you authorise a whole flow consistently rather than message by message. |
Distribution files | Export authorisations as XML to synchronise local RMA applications, manually or automated through FileAct. |
RMA Query APIs | Read-only checks of relationship status before sending, to avoid rejected messages. They cannot create or update authorisations. |
Processing timelines are set. Received authorisations must be processed within six business days, an equivalent authorisation returned within six business days where required, and revocations processed within one business day.

