EBA proposed revisions to the guidelines on major incident reporting under the second Payment Service Directive (PSD2). The revisions aim to optimize and simplify the reporting process, decrease the reporting burden on payment service providers, and improve meaningfulness of the incident reports received. The comment period for the proposal ends on December 14, 2020 while the revised guidelines are expected to become applicable in the fourth quarter of 2021.
The existing guidelines on major incident reporting set out, among others, the criteria, thresholds, and methodology to be used by the payment service providers to determine whether or not an operational or security incident should be considered major and how the said incident should be notified to the competent authorities in the home member state. The consultation paper proposes the following:
- Introduction of the new incident classification criterion "breach of security measures" to capture security incidents when a breach of the security measures of the payment service provider has an impact on the availability, integrity, confidentiality, and/or authenticity of the payment services data, processes, and/or systems.
- Introduction of changes to the thresholds for calculation of the criteria "transactions affected" and "payment service users affected"
- Use of a standardized file for reporting major incident reports, streamlining the reporting template, and adding further granularity to the reported causes of incidents and aligning those incidents to other incident reporting frameworks in EU, to improve quality of the collected reports
- Removal of the regular updates on the intermediate report from payment service providers to the competent authorities, extension of deadline for submission of the final report, and significant reduction in the fields in the reporting template, with the goal of reducing the reporting burden to payment service providers
EBA has aligned the taxonomy on the causes of the major incidents to other incident reporting frameworks that had been developed by the European Union Agency for Cybersecurity and the Single Supervisory Mechanism of the Eurozone and has added further granularity to some causes of incidents. EBA mentions that EC has published, on September 24, 2020, a new EU legislative proposal for the EU regulatory framework on digital operational resilience, which contains a proposal for incident reporting that is inspired by PSD2 but goes beyond the payments-related incidents. The final details of that framework will not be known for several years, after which further time is expected to pass before they become legally applicable. However, the revised guidelines proposed in this consultation paper are expected to become applicable in the fourth quarter of 2021. These revised guidelines will remain in force at least until the EU regulatory framework on digital operational resilience requirements enters into force.
Comment Due Date: December 14, 2020
Effective Date (expected): Q4 2021
Keywords: Europe, EU, Banking, PSD2, Reporting, Payment Service Providers, Incident Reporting, Cyber Risk, Operational Resilience, Operational Resilience, Operational Risk, EBA
Previous ArticleEBA Finalizes Standards for Prudential Treatment of Software Assets
The Australian Prudential Regulation Authority (APRA) has published the findings of its latest climate risk self-assessment survey conducted across the banking, insurance, and superannuation industries.
The French Prudential Supervisory Authority (ACPR) published a notice related to the methods for calculating and publishing prudential ratios under the Capital Requirements Directive (CRD IV) and the minimum requirement for own funds and eligible liabilities (MREL).
The Financial Stability Institute (FSI) of the Bank for International Settlements recently published a paper proposing a framework for classifying financial stability regulation as either entity-based or activity-based.
The European Insurance and Occupational Pension Authority (EIOPA) published the risk dashboard based on Solvency II data and the final version of the application guidance on climate change materiality assessments and climate change scenarios in the Own Risk and Solvency Assessment (ORSA).
The European Banking Authority (EBA) and the European Central Bank (ECB) published their responses to the consultations of the International Sustainability Standards Board (ISSB) and the European Financial Reporting Advisory Group (EFRAG) on sustainability-related disclosure standards.
A Consultative Group on Risk Management (CGRM) at the Bank for International Settlements (BIS) published a report that examines incorporation of climate risks into the international reserve management framework.
The European Banking Authority (EBA) published the final guidelines on liquidity requirements exemption for investment firms, updated version of its 5.2 filing rules document for supervisory reporting, and Single Rulebook Question and Answer (Q&A) updates in July 2022.
The European Insurance and Occupational Pensions Authority (EIOPA) published Version 2.8.0 of the Solvency II data point model (DPM) and XBRL taxonomy.
The European Union published, in the Official Journal of the European Union, an opinion from the European Economic and Social Committee (EESC); the opinion is on the proposal for a regulation to amend the Capital Requirements Regulation (CRR).
HM Treasury published a draft statutory instrument titled “The Financial Services (Miscellaneous Amendments) (EU Exit) Regulations 2022,” along with the related explanatory memorandum and impact assessment.