2025-09-17
Finansinspektionen has amended its regulations (FFFS 2018:4) to update the operational and security risk management requirements for payment service providers. The revised Chapter 5 mandates that providers implement a tailored framework of documented measures, including risk assessments, continuity planning, and user guidance, while explicitly excluding ICT risks covered by the EU Digital Operational Resilience Act. Additionally, the amendments restructure Chapter 6 to clarify reporting timelines for fee applications and establish procedures for ongoing information submission and potential exemptions.