Featured Product

    EBA Revises Guidelines on Major Incident Reporting Under PSD2

    June 10, 2021

    EBA published revised guidelines on major incident reporting under the Payment Service Directive (PSD2). The revised guidelines are estimated to reduce the reporting burden for payment service providers and will apply as of January 01, 2022. EBA acknowledged the ongoing negotiations on the EC proposal for an EU regulatory framework on digital operational resilience (DORA), which contains a proposal to harmonize and streamline the reporting of information and communication technologies (ICT)‐related incidents across financial sector in EU. Depending on the outcome of these negotiations, EBA guidelines may eventually be repealed when the DORA regulation applies, which is currently estimated to be in 2024 or later.

    The revised guidelines optimize and simplify the reporting process and templates, focus on incidents with significant impact on payment service providers, and improve the meaningfulness of information to be reported. In light of the comments received on the consultation on these guidelines (published on October 14, 2020), EBA agreed with some of the proposals and their underlying arguments and introduced the following changes to the guidelines:

    • The classification criterion was changed from "Breach of security measures" to "Breach of security of network or information systems." This change, which is the most substantive, is aimed at narrowing down the scope of the criterion, avoiding any overlap with other classification criteria, and providing a more tangible criterion that does not require complex assessment and implementation. 
    • Unnecessary steps were removed from the reporting process, allowing more time for the submission of final report to reduce the reporting burden on payment service providers.
    • EBA further simplified and optimized the standardized reporting template, with these changes expected to lead to a reduction of reportable incidents by more than 10% and to facilitate payment service providers in their reporting of major incidents. 
    • EBA clarified the process and timeline for classification of major incidents, the meaning of the term duration of an incident, and other aspects in the guidelines, mainly in the instructions on how to fill out the incident reporting template.

    The revised guidelines apply in relation to the classification and reporting of major operational or security incidents in accordance with Article 96 of PSD2 and are addressed to payment service providers and the competent authorities under PSD2. The original guidelines on major incident reporting were developed in 2017 in close cooperation with ECB and have applied since January 2018. 

     

    Related Links

    Effective Date: January 01, 2022

    Keywords: Europe, EU, Banking, PSD2, Reporting, Payment Service Providers, Incident Reporting, Cyber Risk, DORA, Operational Resilience, Operational Risk, EBA

    Featured Experts
    Related Articles
    News

    APRA Issues Interim Update to Policy Priorities for 2021 and Beyond

    In a letter addressed to the industry, the Australian Prudential Regulation Authority (APRA) set out an updated schedule of policy priorities for the banking, insurance, and superannuation industries.

    September 24, 2021 WebPage Regulatory News
    News

    EBA Publishes Single Rulebook Q&A, Launches Transparency Exercise

    The European Banking Authority (EBA) published answers to 29 questions in the Single Rulebook Question and Answer (Q&A) tool in September.

    September 24, 2021 WebPage Regulatory News
    News

    EC Adopts Solvency II and Resolution Rules Package for Insurers

    The European Commission (EC) adopted a comprehensive review package of Solvency II rules in the European Union.

    September 22, 2021 WebPage Regulatory News
    News

    OCC Issues Booklets on Regulatory Reporting and Earnings

    The Office of the Comptroller of the Currency (OCC) issued Versions 1.0 of the "Earnings" and "Regulatory Reporting" booklets of the Comptroller's Handbook.

    September 22, 2021 WebPage Regulatory News
    News

    ECB Sets Out Results of Economy-Wide Climate Stress Tests

    The European Central Bank (ECB) published results of its economy-wide climate stress test, which aimed to assess the resilience of non-financial corporates and euro area banks to climate risks.

    September 22, 2021 WebPage Regulatory News
    News

    EBA Examines Implications of Increasing Use of Digital Platforms in EU

    The European Banking Authority (EBA) published a report on the use of digital platforms in the banking and payments sector in European Union.

    September 21, 2021 WebPage Regulatory News
    News

    HKMA Issues Updates on Policy Measures Intended to Ease COVID Impact

    The Hong Kong Monetary Authority (HKMA) published updates on the policy measures that were announced in context of the ongoing pandemic.

    September 21, 2021 WebPage Regulatory News
    News

    ISDA Responds to BCBS Proposal on Treatment of Cryptoasset Exposures

    The International Swaps and Derivatives Association (ISDA), along with several other associations, submitted a joint response to the Basel Committee on Banking Supervision (BCBS) consultation on preliminary proposals for the prudential treatment of cryptoasset exposures.

    September 21, 2021 WebPage Regulatory News
    News

    BIS Quarterly Review Discusses Developments in Fintech and ESG Space

    BIS published the September issue of the Quarterly Review, which contains special features that analyze the rapid rise in equity funding for financial technology firms, the effectiveness of policy measures in response to pandemic, and the evolution of international banking.

    September 20, 2021 WebPage Regulatory News
    News

    BCBS to Consult on Supervisory Practices for Climate Risks by Year-End

    The Basel Committee for Banking Supervision (BCBS) met in September 2021 and reviewed climate-related financial risks, discussed impact of digitalization, and welcomed efforts by the International Financial Reporting Standards (IFRS) Foundation to develop a common set of sustainability reporting standards

    September 20, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 7495