2022-12-29
Added · Updated
Payment service providers (PSPs) must submit a standardized PSP ICT Assessment form annually to the CSSF via the eDesk portal, covering the previous calendar year and due no later than 31 March. The assessment must be validated by the PSP's management body, specifically the member responsible for the ICT function, and submitted by a management body member. Institutions whose business models do not include payment services are exempt, as are EEA branches established in Luxembourg that offer such services, while Luxembourg-based PSPs with branches in other EEA countries must include those branches in their assessment. The amended paragraph 4 of Circular CSSF 20/750 entered into force on the publication date of this circular.
CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.
CIRCULAR CSSF 22/828 1/5
Circular CSSF
22/828
Amendment of Circular CSSF
20/750 on requirements regarding information and communication technology (ICT) and security risk management
CIRCULAR CSSF 22/828 2/5
Circular CSSF 22/828
Re: Amendment of Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management Ladies and Gentlemen, The objective of this circular is to amend paragraph 4. “Additional requirement for payment service providers (PSPs)” of Circular CSSF 20/750 to introduce a form regarding the updated and comprehensive risk assessment of the ICT and security risks related to payment services provided by PSPs (named “PSP ICT Assessment”), and to provide further information on the objective, the scope and the submission process and deadline related to this form. The PSP ICT Assessment form shall be used for the first time concerning the calendar year 2022 and submitted to the CSSF no later than 31 March 2023. The amended version of paragraph 4 is presented in “track changes” in the
Annex of the present circular. The revised version of paragraph 4 will enter into
force on the date of publication of the present circular. This circular is applicable as of its publication date. Claude WAMPACH Director Marco ZWICK Director Jean-Pierre FABER Director Françoise KAUTHEN Director Claude MARX Director General
Annex: Amended version of paragraph 4 of the Circular CSSF 20/750
Luxembourg, 29 December 2022
To all credit institutions and to all PFS To all payment institutions and to all electronic money institutions
CIRCULAR CSSF 22/828 3/5
Annex: Amended version of paragraph 4 of Circular CSSF 20/750
4. Additional requirement for payment service
providers (PSPs)1
8. As provided for in paragraph 24 of Guideline “3.3.5. Reporting” and in
accordance with Article 105-1(2) of the LPS, PSPs are required to provide the CSSF with an updated and comprehensive risk assessment related to payment services (hereafter “PSP ICT Assessment”). The form and deadlines are as follows:
a. for credit institutions, this assessment, signed by the management body, must be submitted as soon as possible after the closing of the financial year and no later than 30 April of each year; b. for payment institutions and electronic money institutions, this assessment must be included in a dedicated section of the management report on internal control, which must be published in accordance with the requirements set out in Circular CSSF 15/614, no later than the last day of the third month following the closing date of the financial year; and
c. for POST Luxembourg, this assessment must be included in a
dedicated section of the management report on internal control, to be published in accordance with the requirements set out in Circular CSSF 98/143, at the latest one month after the annual general meeting approving the annual accounts of the PSP. The CSSF has developed a standardised form for the PSP ICT Assessment to be used by all PSPs. The objective of this standardised PSP ICT Assessment form is to give guidance to the PSPs on the CSSF's expectations on the information to be provided via the PSP ICT Assessment, and hence achieve a certain level of harmonisation and comparability among the PSPs' ICT Assessments. Concerning the scope of the PSP ICT Assessment, the following is to be highlighted:
CIRCULAR CSSF 22/828 4/5
CIRCULAR CSSF 22/828
5
/
5
Commission de Surveillance du Secteur Financier 283, route d’Arlon L-2991 Luxembourg (+352) 26 25 1 - 1 direction@cssf.lu www.cssf.lu
Read the rest free
This document amends: Circular CSSF 20/750 on ICT and Security Risk Management Requirements
Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CSSF
CSSF published 3 documents in the last 30 days. We email you each new one the day it's published.