EBA Revises Guidelines on Major Incident Reporting Under PSD2
EBA published revised guidelines on major incident reporting under the Payment Service Directive (PSD2). The revised guidelines are estimated to reduce the reporting burden for payment service providers and will apply as of January 01, 2022. EBA acknowledged the ongoing negotiations on the EC proposal for an EU regulatory framework on digital operational resilience (DORA), which contains a proposal to harmonize and streamline the reporting of information and communication technologies (ICT)‐related incidents across financial sector in EU. Depending on the outcome of these negotiations, EBA guidelines may eventually be repealed when the DORA regulation applies, which is currently estimated to be in 2024 or later.
The revised guidelines optimize and simplify the reporting process and templates, focus on incidents with significant impact on payment service providers, and improve the meaningfulness of information to be reported. In light of the comments received on the consultation on these guidelines (published on October 14, 2020), EBA agreed with some of the proposals and their underlying arguments and introduced the following changes to the guidelines:
- The classification criterion was changed from "Breach of security measures" to "Breach of security of network or information systems." This change, which is the most substantive, is aimed at narrowing down the scope of the criterion, avoiding any overlap with other classification criteria, and providing a more tangible criterion that does not require complex assessment and implementation.
- Unnecessary steps were removed from the reporting process, allowing more time for the submission of final report to reduce the reporting burden on payment service providers.
- EBA further simplified and optimized the standardized reporting template, with these changes expected to lead to a reduction of reportable incidents by more than 10% and to facilitate payment service providers in their reporting of major incidents.
- EBA clarified the process and timeline for classification of major incidents, the meaning of the term duration of an incident, and other aspects in the guidelines, mainly in the instructions on how to fill out the incident reporting template.
The revised guidelines apply in relation to the classification and reporting of major operational or security incidents in accordance with Article 96 of PSD2 and are addressed to payment service providers and the competent authorities under PSD2. The original guidelines on major incident reporting were developed in 2017 in close cooperation with ECB and have applied since January 2018.
Related Links
Effective Date: January 01, 2022
Keywords: Europe, EU, Banking, PSD2, Reporting, Payment Service Providers, Incident Reporting, Cyber Risk, DORA, Operational Resilience, Operational Risk, EBA
Featured Experts

María Cañamero
Skilled market researcher; growth strategist; successful go-to-market campaign developer

Nicolas Degruson
Works with financial institutions, regulatory experts, business analysts, product managers, and software engineers to drive regulatory solutions across the globe.

Scott Dietz
Scott is a Director in the Regulatory and Accounting Solutions team responsible for providing accounting expertise across solutions, products, and services offered by Moody’s Analytics in the US. He has over 15 years of experience leading auditing, consulting and accounting policy initiatives for financial institutions.
Previous Article
Danish FSA to Implement Net Stable Funding Ratio in DenmarkNext Article
EBA Revises List of Validation Rules for ReportingRelated Articles
EBA Finalizes Templates for One-Off Climate Risk Scenario Analysis
The European Banking Authority (EBA) has published the final templates, and the associated guidance, for collecting climate-related data for the one-off Fit-for-55 climate risk scenario analysis.
EBA Mulls Inclusion of Environmental & Social Risks to Pillar 1 Rules
The European Banking Authority (EBA) recently published a report that recommends enhancements to the Pillar 1 framework, under the prudential rules, to capture environmental and social risks.
BCBS Consults on Disclosure of Crypto-Asset Exposures of Banks
As a follow on from its prudential standard on the treatment of crypto-asset exposures, the Basel Committee on Banking Supervision (BCBS) proposed disclosure requirements for crypto-asset exposures of banks.
BCBS and EBA Publish Results of Basel III Monitoring Exercise
The Basel Committee on Banking Supervision (BCBS) and the European Banking Authority (EBA) have published results of the Basel III monitoring exercise.
PRA Updates Timeline for Final Basel III Rules, Issues Other Updates
The Prudential Regulation Authority (PRA) recently issued a few regulatory updates for banks, with the updated Basel implementation timelines being the key among them.
US Treasury Sets Out Principles for Net-Zero Financing
The U.S. Department of the Treasury has recently set out the principles for net-zero financing and investment.
EC Launches Survey on G7 Principles on Generative AI
The European Commission (EC) launched a stakeholder survey on the draft International Guiding Principles for organizations developing advanced artificial intelligence (AI) systems.
ISSB Sustainability Standards Expected to Become Global Baseline
The finalization of the two sustainability disclosure standards—IFRS S1 and IFRS S2—is expected to be a significant step forward in the harmonization of sustainability disclosures worldwide.
IOSCO, BIS, and FSB to Intensify Focus on Decentralized Finance
Decentralized finance (DeFi) is expected to increase in prominence, finding traction in use cases such as lending, trading, and investing, without the intermediation of traditional financial institutions.
BCBS Assesses NSFR and Large Exposures Rules in US
The Basel Committee on Banking Supervision (BCBS) published reports that assessed the overall implementation of the net stable funding ratio (NSFR) and the large exposures rules in the U.S.