Featured Product

    EBA Proposes to Revise Guidelines on Incident Reporting Under PSD2

    October 14, 2020

    EBA proposed revisions to the guidelines on major incident reporting under the second Payment Service Directive (PSD2). The revisions aim to optimize and simplify the reporting process, decrease the reporting burden on payment service providers, and improve meaningfulness of the incident reports received. The comment period for the proposal ends on December 14, 2020 while the revised guidelines are expected to become applicable in the fourth quarter of 2021.

    The existing guidelines on major incident reporting set out, among others, the criteria, thresholds, and methodology to be used by the payment service providers to determine whether or not an operational or security incident should be considered major and how the said incident should be notified to the competent authorities in the home member state. The consultation paper proposes the following:

    • Introduction of the new incident classification criterion "breach of security measures" to capture security incidents when a breach of the security measures of the payment service provider has an impact on the availability, integrity, confidentiality, and/or authenticity of the payment services data, processes, and/or systems.
    • Introduction of changes to the thresholds for calculation of the criteria "transactions affected" and "payment service users affected"
    • Use of a standardized file for reporting major incident reports, streamlining the reporting template, and adding further granularity to the reported causes of incidents and aligning those incidents to other incident reporting frameworks in EU, to improve quality of the collected reports
    • Removal of the regular updates on the intermediate report from payment service providers to the competent authorities, extension of deadline for submission of the final report, and significant reduction in the fields in the reporting template, with the goal of reducing the reporting burden to payment service providers

    EBA has aligned the taxonomy on the causes of the major incidents to other incident reporting frameworks that had been developed by the European Union Agency for Cybersecurity and the Single Supervisory Mechanism of the Eurozone and has added further granularity to some causes of incidents. EBA mentions that EC has published, on September 24, 2020, a new EU legislative proposal for the EU regulatory framework on digital operational resilience, which contains a proposal for incident reporting that is inspired by PSD2 but goes beyond the payments-related incidents. The final details of that framework will not be known for several years, after which further time is expected to pass before they become legally applicable. However, the revised guidelines proposed in this consultation paper are expected to become applicable in the fourth quarter of 2021. These revised guidelines will remain in force at least until the EU regulatory framework on digital operational resilience requirements enters into force. 


    Related Links

    Comment Due Date: December 14, 2020

    Effective Date (expected): Q4 2021

    Keywords: Europe, EU, Banking, PSD2, Reporting, Payment Service Providers, Incident Reporting, Cyber Risk, Operational Resilience, Operational Resilience, Operational Risk, EBA 

    Featured Experts
    Related Articles

    EFRAG Proposes XBRL Taxonomy and Standard for Listed SMEs Under ESRS

    The European Financial Reporting Advisory Group (EFRAG), which plays a crucial role in shaping corporate reporting standards in European Union (EU), is seeking comments, until May 21, 2024, on the Exposure Draft ESRS for listed SMEs.

    February 23, 2024 WebPage Regulatory News

    ECB to Expand Climate Change Work in 2024-2025

    Banking regulators worldwide are increasingly focusing on addressing, monitoring, and supervising the institutions' exposure to climate and environmental risks.

    February 23, 2024 WebPage Regulatory News

    BIS Bulletin Examines Cognitive Limits of Large Language Models

    The use cases of generative AI in the banking sector are evolving fast, with many institutions adopting the technology to enhance customer service and operational efficiency.

    January 25, 2024 WebPage Regulatory News

    ECB is Conducting First Cyber Risk Stress Test for Banks

    As part of the increasing regulatory focus on operational resilience, cyber risk stress testing is also becoming a crucial aspect of ensuring bank resilience in the face of cyber threats.

    January 24, 2024 WebPage Regulatory News

    EBA Continues Momentum Toward Strengthening Prudential Rules for Banks

    A few years down the road from the last global financial crisis, regulators are still issuing rules and monitoring banks to ensure that they comply with the regulations.

    January 24, 2024 WebPage Regulatory News

    EU and UK Agencies Issue Updates on Final Basel III Rules

    The European Commission (EC) recently issued an update informing that the European Council and the Parliament have endorsed the Banking Package implementing the final elements of Basel III standards

    December 19, 2023 WebPage Regulatory News

    Industry Agency Expects Considerable Uptake for Swiss Climate Scores

    The Swiss Federal Council recently decided to further develop the Swiss Climate Scores, which it had first launched in June 2022.

    December 18, 2023 WebPage Regulatory News

    BCBS Consults on Disclosure of Climate Risks, Issues Other Updates

    The Basel Committee on Banking Supervision (BCBS) launched consultation on a Pillar 3 disclosure framework for climate-related financial risks, with the comment period ending on February 29, 2024.

    December 18, 2023 WebPage Regulatory News

    US Government Moves to Regulate Development and Use of AI Models

    The U.S. President Joe Biden signed an Executive Order, dated October 30, 2023, to ensure safe, secure, and trustworthy development and use of artificial intelligence (AI).

    December 18, 2023 WebPage Regulatory News

    MAS Launches Gprnt Digital Platform for ESG Reporting for SMEs

    The Monetary Authority of Singapore (MAS) launched an integrated digital platform, Gprnt, also known as “Greenprint.”

    November 29, 2023 WebPage Regulatory News
    RESULTS 1 - 10 OF 8949