Featured Product

    EBA Proposes to Revise Guidelines on Incident Reporting Under PSD2

    October 14, 2020

    EBA proposed revisions to the guidelines on major incident reporting under the second Payment Service Directive (PSD2). The revisions aim to optimize and simplify the reporting process, decrease the reporting burden on payment service providers, and improve meaningfulness of the incident reports received. The comment period for the proposal ends on December 14, 2020 while the revised guidelines are expected to become applicable in the fourth quarter of 2021.

    The existing guidelines on major incident reporting set out, among others, the criteria, thresholds, and methodology to be used by the payment service providers to determine whether or not an operational or security incident should be considered major and how the said incident should be notified to the competent authorities in the home member state. The consultation paper proposes the following:

    • Introduction of the new incident classification criterion "breach of security measures" to capture security incidents when a breach of the security measures of the payment service provider has an impact on the availability, integrity, confidentiality, and/or authenticity of the payment services data, processes, and/or systems.
    • Introduction of changes to the thresholds for calculation of the criteria "transactions affected" and "payment service users affected"
    • Use of a standardized file for reporting major incident reports, streamlining the reporting template, and adding further granularity to the reported causes of incidents and aligning those incidents to other incident reporting frameworks in EU, to improve quality of the collected reports
    • Removal of the regular updates on the intermediate report from payment service providers to the competent authorities, extension of deadline for submission of the final report, and significant reduction in the fields in the reporting template, with the goal of reducing the reporting burden to payment service providers

    EBA has aligned the taxonomy on the causes of the major incidents to other incident reporting frameworks that had been developed by the European Union Agency for Cybersecurity and the Single Supervisory Mechanism of the Eurozone and has added further granularity to some causes of incidents. EBA mentions that EC has published, on September 24, 2020, a new EU legislative proposal for the EU regulatory framework on digital operational resilience, which contains a proposal for incident reporting that is inspired by PSD2 but goes beyond the payments-related incidents. The final details of that framework will not be known for several years, after which further time is expected to pass before they become legally applicable. However, the revised guidelines proposed in this consultation paper are expected to become applicable in the fourth quarter of 2021. These revised guidelines will remain in force at least until the EU regulatory framework on digital operational resilience requirements enters into force. 

     

    Related Links

    Comment Due Date: December 14, 2020

    Effective Date (expected): Q4 2021

    Keywords: Europe, EU, Banking, PSD2, Reporting, Payment Service Providers, Incident Reporting, Cyber Risk, Operational Resilience, Operational Resilience, Operational Risk, EBA 

    Featured Experts
    Related Articles
    News

    OSFI Outlines Prudential Policy Priorities for Coming Months

    OSFI has set out the near-term priorities for federally regulated financial institutions and federally regulated private pension plans for the coming months until March 31, 2022.

    May 06, 2021 WebPage Regulatory News
    News

    BIS Announces TechSprint on Innovative Green Finance Solutions

    Under the Italian G20 Presidency, BIS Innovation Hub and the Italian central bank BDI launched the second edition of the G20 TechSprint on the lookout for innovative solutions to resolve operational problems in green and sustainable finance.

    May 06, 2021 WebPage Regulatory News
    News

    EBA Proposed Regulatory Standards for Central Database on AML/CFT

    EBA proposed the regulatory technical standards on a central database on anti-money laundering and countering the financing of terrorism (AML/CFT) in EU.

    May 06, 2021 WebPage Regulatory News
    News

    ECB Responds to EC Consultation on Crisis Management Framework

    ECB published its response to the targeted EC consultation on the review of the bank crisis management and deposit insurance framework in EU.

    May 06, 2021 WebPage Regulatory News
    News

    ACPR Publishes Version 1.0.0 of RUBA Taxonomy

    ACPR published Version 1.0.0 of the RUBA taxonomy, which will come into force from the decree of January 31, 2022.

    May 06, 2021 WebPage Regulatory News
    News

    BCBS, CPMI, and IOSCO to Survey Market Participants on Margin Calls

    BCBS, CPMI, and IOSCO (the Committees) are inviting entities that participate in market infrastructures and securities markets through an intermediary as well as non-bank intermediaries to complete voluntary surveys on the use of margin calls.

    May 05, 2021 WebPage Regulatory News
    News

    ECB Amends Decision on TLTRO III

    ECB published Decision 2021/752 to amend Decision 2019/1311 on the third series of targeted longer-term refinancing operations or TLTRO III.

    May 05, 2021 WebPage Regulatory News
    News

    Central Bank of Ireland Issues Draft Template for AnaCredit Reporting

    The Central Bank of Ireland published Version 2.7 of the draft credit data template and rules for monthly AnaCredit reporting by banks.

    May 05, 2021 WebPage Regulatory News
    News

    OSFI Consults on Revisions to BCAR and Leverage Requirements Returns

    OSFI proposed revisions to the Basel Capital Adequacy Reporting (BCAR) and leverage requirements returns for the 2023 reporting, with the comment period ending on July 09, 2021.

    May 04, 2021 WebPage Regulatory News
    News

    EBA Seeks Views on Revisions to Nonperforming Loan Data Templates

    EBA published a discussion paper on review of the standardized nonperforming loans (NPL) transaction data templates, along with the proposed revised NPL data templates.

    May 04, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 6936