2024-12-03 | Circular No. 2 of 2024The Central Bank of Sri Lanka issued Circular No. 2 of 2024 to mandate enhanced customer identification procedures for Mobile Payment Application Providers (MPAPs) and Transaction Acquirers. The directive requires strict verification of user identity documents and confirmation that the mobile number linked to the app matches the bank account holder's registered number before allowing transactions or linking accounts. Compliance with these security measures is mandatory for all new and existing users by 31 March 2025, with Transaction Acquirers responsible for ensuring adherence and reporting status to the regulator.
f.ùï iy mshùï fomd¾;fïka;=j nfhLg;gdTfs;> jPh;g ;gdTfs; jpizf;fsk; Payments and Settlements Department 03 December 2024 Payment and Settlement Systems Circular No. 2 of 2024
To: All Chief Executive Officers of Licensed Banks and Licensed Finance Companies Strengthening Customer Identification Process to Safeguard Funds in Current Accounts/Savings Accounts linked to Mobile Payment Applications This Circular is issued in terms of Section 44 of the Payment and Settlement Systems Act, No. 28 of 2005 (Act) to enhance the safety of digital transactions effected through Mobile Payment Applications (hereinafter referred to as Payment Apps). 2. To safeguard Current Accounts/Savings Accounts (CASA) of customers from unauthorized access through Payment Apps, all Mobile Payment Application Providers (MPAPs) are instructed to adhere to the following procedures when registering customers and/or linking CASA to any Payment App in addition to compliance with the Guidelines on Minimum Compliance Standard for Payment Related Mobile Applications No. 1 of 2020 dated 29 May 2020 and the Payment and Settlement Systems Circular No.1 of 2024 dated 17 January 2024 for JustPay enabled Payment Apps. i. MPAPs shall establish a suitable mechanism to: (a) obtain information to identify the user during the registration process of its Payment App using an acceptable identity document (National Identity Card, Passport or Driving License); (b) verify the above user identity information prior to allowing the user to initiate transactions using a Payment App of a Licensed Financial Institution or prior to linking a CASA to a JustPay enabled Payment App; and (c) ensure that the user of the Payment App and the owner of the CASA is the same, when a CASA is linked to a JustPay enabled Payment App (by using a mechanism to verify that the mobile number of the device on which the Payment App is installed and the mobile number registered with the CASA is the same). ii. For Payment Apps of Licensed Financial Institutions, MPAPs shall adhere to (i) (a) and (i) (b) for the registration of new users with their Payment Apps from 31 March 2025. iii. For JustPay enabled Payment Apps, MPAPs shall adhere to (i) (a) to (i)(c) above for the registration of new users with their Payment Apps and (i) (c) for existing users when linking a new CASA, from 31 March 2025. iv. Transaction Acquirers shall bring the contents of this Circular to the immediate notice of any third-party MPAPs facilitated by them. Contd. 8 jk uy," wxl 30" ckdêm;s udj;" 8 Mk; khb> ,y. 30 rdhjpgjp khtj ;ij nfhOk;G 1 Level 8, No. 30, Janadhipathi Mawatha, Colombo 1 ;e ' fm ' 590" fld<U 01" Ys% ,xldj j. ng. ,y. 590> nfhOk;G 01> ,yq;if P . O. Box. 590, Colombo 01, Sri Lanka. 94 11 2477042 94 11 2387009 psd@cbsl.lk www.cbsl.gov.lk
2 v. Transaction Acquirers shall provide adequate guidance to third-party MPAPs in establishing processes to implement the requirements given under (i) above and shall be responsible for ensuring their compliance. vi. Transaction Acquirers shall not operate or facilitate any Payment App without complying with the requirements of this Circular after 31 March 2025. vii. Transaction Acquirers shall report to the Central Bank of Sri Lanka on the compliance of Payment Apps operated or facilitated by them with the requirements (i) to (vi) above of this Circular, using the format given in Annex 1 by 15 April 2025, and subsequently shall report the compliance with the requirements under (i) above on or before 31 January of each year, along with the compliance status with the Guidelines on Minimum Compliance Standard for Payment Related Mobile Applications No. 1 of 2020, Annex 2. viii. Any costs related to compliance with this Circular shall not be passed on to the users of the Payment Apps. Definitions a) Issuer – The licensed financial institution which maintains CASA of the user. b) Transaction Acquirer – A licensed financial institution providing payment services to Payment Apps. c) Mobile Payment Application Providers (MPAPs) – The party which provides the mobile phone-based payment application to facilitate transactions. This includes third-party MPAPs utilising a service from a Transaction Acquirer. d) Mobile Payment Applications (Payment Apps) – Mobile applications that allow users to make transfer of funds and initiate payments for goods and services. Note: Compliance with this Circular is not required for e-commerce apps, i.e., apps that solely facilitate the purchase of goods and services where the payment is made to the operator of e-commerce app. K V K Alwis Director Payments and Settlements