Featured Product

    EBA Proposes to Revise Guidelines on Incident Reporting Under PSD2

    October 14, 2020

    EBA proposed revisions to the guidelines on major incident reporting under the second Payment Service Directive (PSD2). The revisions aim to optimize and simplify the reporting process, decrease the reporting burden on payment service providers, and improve meaningfulness of the incident reports received. The comment period for the proposal ends on December 14, 2020 while the revised guidelines are expected to become applicable in the fourth quarter of 2021.

    The existing guidelines on major incident reporting set out, among others, the criteria, thresholds, and methodology to be used by the payment service providers to determine whether or not an operational or security incident should be considered major and how the said incident should be notified to the competent authorities in the home member state. The consultation paper proposes the following:

    • Introduction of the new incident classification criterion "breach of security measures" to capture security incidents when a breach of the security measures of the payment service provider has an impact on the availability, integrity, confidentiality, and/or authenticity of the payment services data, processes, and/or systems.
    • Introduction of changes to the thresholds for calculation of the criteria "transactions affected" and "payment service users affected"
    • Use of a standardized file for reporting major incident reports, streamlining the reporting template, and adding further granularity to the reported causes of incidents and aligning those incidents to other incident reporting frameworks in EU, to improve quality of the collected reports
    • Removal of the regular updates on the intermediate report from payment service providers to the competent authorities, extension of deadline for submission of the final report, and significant reduction in the fields in the reporting template, with the goal of reducing the reporting burden to payment service providers

    EBA has aligned the taxonomy on the causes of the major incidents to other incident reporting frameworks that had been developed by the European Union Agency for Cybersecurity and the Single Supervisory Mechanism of the Eurozone and has added further granularity to some causes of incidents. EBA mentions that EC has published, on September 24, 2020, a new EU legislative proposal for the EU regulatory framework on digital operational resilience, which contains a proposal for incident reporting that is inspired by PSD2 but goes beyond the payments-related incidents. The final details of that framework will not be known for several years, after which further time is expected to pass before they become legally applicable. However, the revised guidelines proposed in this consultation paper are expected to become applicable in the fourth quarter of 2021. These revised guidelines will remain in force at least until the EU regulatory framework on digital operational resilience requirements enters into force. 

     

    Related Links

    Comment Due Date: December 14, 2020

    Effective Date (expected): Q4 2021

    Keywords: Europe, EU, Banking, PSD2, Reporting, Payment Service Providers, Incident Reporting, Cyber Risk, Operational Resilience, Operational Resilience, Operational Risk, EBA 

    Featured Experts
    Related Articles
    News

    Regulators Fine Goldman Sachs for Risk Management Failures

    FCA and PRA in the UK, FED in the US, and the authorities in Singapore have fined Goldman Sachs for risk management failures in connection with the 1Malaysia Development Berhad (1MDB).

    October 23, 2020 WebPage Regulatory News
    News

    Canada Hosts International Conference of Banking Supervisors

    BCBS announced that OSFI and the Bank of Canada hosted the 21st International Conference of Banking Supervisors (ICBS) virtually on October 19-22, 2020.

    October 22, 2020 WebPage Regulatory News
    News

    FCA Proposes More Measures to Help Insurance Customers Amid Crisis

    FCA proposed guidance on how firms should continue to seek to help customers who hold insurance and premium finance products and may be in financial difficulty because of COVID-19, after October 31, 2020.

    October 21, 2020 WebPage Regulatory News
    News

    EBA Issues Opinion to Address Risk Stemming from Legacy Instruments

    EBA issued an opinion on prudential treatment of the legacy instruments as the grandfathering period nears an end on December 31, 2021.

    October 21, 2020 WebPage Regulatory News
    News

    ESRB Publishes Non-Bank Financial Intermediation Risk Monitor for 2020

    ESRB published the fifth issue of the EU Non-bank Financial Intermediation Risk Monitor 2020 (NBFI Monitor).

    October 21, 2020 WebPage Regulatory News
    News

    HM Treasury Publishes Policy Statement Amending Benchmarks Regulation

    HM Treasury announced that the new Financial Services Bill has been introduced in the Parliament.

    October 21, 2020 WebPage Regulatory News
    News

    APRA Initiates Action Against a Bank for Liquidity Compliance Breach

    APRA announced that it has increased the minimum liquidity requirement of Bendigo and Adelaide Bank for failing to comply with the prudential standard on liquidity.

    October 21, 2020 WebPage Regulatory News
    News

    PRA Consults on Implementation of Certain Provisions of CRD5 and CRR2

    PRA published the consultation paper CP17/20 to propose changes to certain rules, supervisory statements, and statements of policy to implement elements of the Capital Requirements Directive (CRD5).

    October 20, 2020 WebPage Regulatory News
    News

    US Agencies Finalize Rule to Reduce Impact of Large Bank Failures

    US Agencies adopted a final rule that applies to advanced approaches banking organizations and aims to reduce interconnectedness in the financial system as well as to reduce contagion risks associated with the failure of a global systemically important bank (G-SIB).

    October 20, 2020 WebPage Regulatory News
    News

    US Agencies Finalize Rule on Net Stable Funding Ratio Requirements

    US Agencies (FDIC, FED, and OCC) adopted a final rule that implements the net stable funding ratio (NSFR) for certain large banking organizations.

    October 20, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 6004