2026-03-12
Added
The Bank of Lithuania Board approves a new procedure and specific forms (REJECT, FRAUD, BLOCK, ORIS) for payment service providers and credit institutions to report account refusals, suspected fraud, access restrictions, and operational risks. Payment service providers must submit fraud reports within statutory refund deadlines, limit access restrictions to 10 working days, and conduct internal investigations within 15 to 120 days. Credit institutions must report account refusal decisions within five working days, while all relevant entities must submit annual operational and security risk assessments via the Bank's online system.
Get LB alerts — same-day email on every new publication.
BOARD OF THE BANK OF LITHUANIA
RESOLUTION
ON APPROVING THE PROCEDURE FOR NOTIFICATIONS SUBMITTED BY PAYMENT SERVICE PROVIDERS TO THE BANK OF LITHUANIA UNDER THE LAW OF THE REPUBLIC OF LITHUANIA ON PAYMENTS AND INFORMATION SUBMISSION FORMS
12 March 2026 No. 2026/03-19
Vilnius
Guided by Article 42(4)(1) of the Law of the Republic of Lithuania on the Bank of Lithuania, Article 10(4), Article 33(8), Article 38(5), and Article 56(2) of the Law of the Republic of Lithuania on Payments, the Board of the Bank of Lithuania resolves:
1.1. The Procedure for Notifications Submitted by Payment Service Providers to the Bank of Lithuania under the Law of the Republic of Lithuania on Payments;
1.2. The REJECT form for notification of the decision to refuse to open a payment account, restrict its use, or close it;
1.3. The FRAUD form for notification of suspected payer fraud;
1.4. The BLOCK form for notification of a restriction on the access of an account information service provider or payment initiation service provider to a payment account;
1.5. The ORIS form for the Operational and Security Risk Assessment Report.
Chairman of the Board Gediminas Šimkus
APPROVED
By the Resolution of the Board of the Bank of Lithuania of 12 March 2026 No. 2026/03-19
PROCEDURE FOR NOTIFICATIONS SUBMITTED BY PAYMENT SERVICE PROVIDERS TO THE BANK OF LITHUANIA UNDER THE LAW OF THE REPUBLIC OF LITHUANIA ON PAYMENTS
CHAPTER I
GENERAL PROVISIONS
This Procedure (hereinafter – the Procedure) establishes the procedure for submitting notifications to the Bank of Lithuania regarding decisions to refuse to open a payment account for an electronic money institution or payment institution, restrict the use of such a payment account, or close it; notifications regarding suspected payer fraud; notifications regarding a restriction on a payment service provider's access to a payment service user's payment account; and the submission of an operational and security risk assessment report.
This Procedure, except for points 7, 17, and 18, applies to payment service providers (PSPs) providing payment services under the Law of the Republic of Lithuania on Payments (hereinafter – the Payments Act).
The provisions of point 7 of this Procedure apply to banks established in the Republic of Lithuania, branches of banks of foreign states, including Member States of the European Union, and central credit unions (hereinafter – credit institutions).
The provisions of points 17 and 18 of this Procedure apply to PSPs providing payment services under the Payments Act, excluding branches of PSPs licensed in Member States of the European Union.
The terms used in this Procedure are understood as defined in the Payments Act.
CHAPTER II
CONTENT OF INFORMATION SUBMITTED
6.1. information regarding suspected fraud by a payment service user;
6.2. information regarding a restriction on the access of an account information service (AIS) provider or payment initiation service (PIS) provider to a payment account;
6.3. information regarding an operational and security risk assessment.
CHAPTER III
INFORMATION SUBMITTED BY PSPS
If a PSP has reasonable grounds to suspect payer fraud, it must immediately, but no later than the term established in Article 38(1) of the Payments Act, within which the payer must be refunded the amount(s) of unauthorized payment transaction(s) and, where applicable, the balance of the payment account from which the amount(s) was/were debited, notify the payer by the agreed method and the Bank of Lithuania about such refusal to refund the amount(s) of the payment transaction(s) by completing the FRAUD form.
As established in point 8 of this Procedure, a PSP may submit a single general notification to the Bank of Lithuania regarding non-refunded amounts of several unauthorized payment transactions if all of the following conditions are met:
9.1. the payer and the recipient of these payment transaction amounts are the same;
9.2. the PSP learns of or is notified about the unauthorized payment transactions on the same day or the next day;
9.3. submitting a general notification about these transactions will not miss the term specified in point 8 of this Procedure (evaluated separately for each payment transaction about which notification is submitted).
If a PSP does not grant access to payment account(s) to a PIS provider or AIS provider, guided by the procedure and conditions established in Article 33(5) and (7) of the Payments Act, it provides information regarding the refusal to grant access to the payer's account(s) to the payer by their agreed method and to the Bank of Lithuania by completing the BLOCK form.
A PSP removes the restriction on a PIS provider's or AIS provider's access to a payment account when there are no longer grounds for not granting such access, and notifies the Bank of Lithuania immediately. If the restriction on a PIS provider's or AIS provider's access to a payment account is not removed within 10 working days from the date of its application, the PSP must, no later than the next working day, provide the Bank of Lithuania with additional information regarding the details of the access restriction (e.g., newly clarified circumstances, reasons for further restriction of access, actions to be taken by the PIS provider, AIS provider, or payer to remove the access restriction, initiated pre-trial investigation processes, etc.).
The submission of notifications specified in points 8 and 10 of this Procedure to the Bank of Lithuania does not relieve the PSP of its obligation, if there are reasonable suspicions of criminal and/or other illegal actions by a payment service user, PIS provider, or AIS provider, to notify the competent law enforcement authorities about such suspicions in accordance with the procedure established by legal acts.
To thoroughly investigate the circumstances specified in point 8 of this Procedure, regarding which the PSP refused to refund the amount(s) of unauthorized payment transaction(s), and other information related to such circumstances, the PSP conducts an internal investigation. The internal investigation must be started and completed no later than 15 working days from the date the circumstances specified in point 8 of this Procedure became known. The PSP must immediately inform the payer and the Bank of Lithuania about the results of the internal investigation and the PSP's actions taken after the investigation.
If, for reasons beyond the PSP's control, it is impossible to complete the internal investigation within the term specified in point 13 of this Procedure, the PSP must inform the payer, specifying the term within which the investigation will be completed and the reasons for extending the investigation term, except in cases where disclosing such reasons would weaken security measures or is prohibited by legal acts. The PSP must also notify the Bank of Lithuania about the extension of the internal investigation term. The internal investigation completion term must never exceed 35 working days, and if the payment transaction(s) regarding which the internal investigation is conducted was/were conducted using a payment card, 120 days, calculated from the date the circumstances specified in point 8 of this Procedure became known, but only if the participation of an international payment card association is necessary for the internal investigation and it is impossible to complete the internal investigation earlier due to circumstances depending on such an association.
If a PSP, guided by point 12 of this Procedure, contacts law enforcement authorities, which initiate a pre-trial investigation in accordance with legal acts, the internal investigation terms specified in points 13 and 14 of this Procedure are suspended.
If, during the internal investigation, it becomes clear that the PSP's suspicions of payer fraud were unfounded or the grounds for suspending the refund of the payment transaction(s) amount(s) disappear for other reasons (e.g., law enforcement authorities determine that the payer's actions do not have signs of fraud), the PSP must immediately refund to the payer the amount(s) of unauthorized payment transaction(s) whose refund was suspended under the grounds specified in Article 38(1) of the Payments Act.
A PSP must assess the operational and security risk associated with its provided payment services, affecting established and classified by importance operational functions, auxiliary processes, and information resources. Such risk assessment must be conducted and documented no less than once a year. Risk assessment must also be conducted when infrastructure, processes, or procedures affecting operational functions, auxiliary processes, or information resources change essentially, and the valid PSP risk assessment is updated accordingly.
After conducting the operational and security risk assessment associated with its provided payment services specified in point 17 of this Procedure, a PSP must submit an updated Operational and Security Risk Assessment Report to the Bank of Lithuania by completing the ORIS form no later than 14 days from the date of approval of this assessment.
The provisions of points 17 and 18 of this Procedure do not apply to PSPs that have assessed the operational and security risk associated with their provided payment services by conducting a review of the information and communication technology risk management system in accordance with Article 6(5) of Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector, amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014, and (EU) 2016/1011, and submitted the report of such review to the Bank of Lithuania electronically no later than 14 days from the date of its approval.
CHAPTER IV
FINAL PROVISIONS
The PSP or the head of the credit institution's administration is responsible for submitting information to the Bank of Lithuania within the time and procedure established in this Procedure.
The PSP or the head of the credit institution's administration must ensure that processes implementing the information submission requirements established in this Procedure are implemented in the PSP's or credit institution's internal rules.
The PSP or credit institution submits the documents specified in this Procedure to the Bank of Lithuania through the Bank of Lithuania's online system – the Notification Submission Module, except for the case specified in point 19 of this Procedure.
APPROVED
By the Resolution of the Board of the Bank of Lithuania of 12 March 2026 No. 2026/03-19
(REJECT form)
______________________________________________________ (name of the credit institution)
______________________________________________________ (code, address, telephone, email)
NOTIFICATION OF THE DECISION TO REFUSE TO OPEN A PAYMENT ACCOUNT, RESTRICT ITS USE, OR CLOSE IT
(date)
Name of the payment or electronic money institution (PSP)
Country code
Date of decision
Account type
4.1.
Individual (client funds) account
YES / NO
4.2.
Payment account intended for payment transactions on behalf of electronic money and/or payment service users YES / NO
If the account is closed or its use is restricted 5.1.
When was the PSP notified about the decision made?
YYYY.MM.DD
5.2.
What notice period was provided before the decision was made?
If refusing to open an account or grant access to an account 6.1.
Was the decision to refuse to open an account or grant access to an account communicated to the PSP?
YES / NO
6.2.
If yes, specify when the decision was communicated YYYY.MM.DD 6.3.
If no, specify why it was not communicated
Brief description of the reasons for the decision (close account / restrict use or refuse to open account / grant access)
Brief description of the process (e.g., person(s) responsible for making decisions, all applicable terms and procedures taken when considering the decision)
Were the reasons for the decision specified to the PSP?
YES / NO
Was the PSP given the opportunity to respond to the credit institution's decision, eliminate operational deficiencies, before the credit institution made the decision? YES / NO
If no, specify why such an opportunity was not provided
APPROVED
By the Resolution of the Board of the Bank of Lithuania of 12 March 2026 No. 2026/03-19
(FRAUD form)
NOTIFICATION OF SUSPECTED PAYER FRAUD
Suspected fraud by payment service provider
Description of suspected fraud
Information about the payer
Natural person
Legal entity
First name
Name
Surname
Legal entity code
Information about the payment transaction
Payment account number
Date of payment transaction
Amount of payment transaction
Currency of payment transaction
Date of receiving notification about unauthorized payment transaction Date of notifying the payer about refusal to refund the amount of unauthorized payment transaction Recipient's account number
Brief description of suspected fraud and circumstances allowing suspicion of payer fraud
(Briefly describe the suspected payer fraud and specify the circumstances allowing suspicion of payment service user fraud)
Additional information
(Specify other information, in your opinion, significant)
APPROVED
By the Resolution of the Board of the Bank of Lithuania of 12 March 2026 No. 2026/03-19
(BLOCK form)
NOTIFICATION OF RESTRICTION ON ACCESS OF AN ACCOUNT INFORMATION SERVICE (AIS) PROVIDER OR PAYMENT INITIATION SERVICE (PIS) PROVIDER TO A PAYMENT ACCOUNT
Information about the payment service provider handling the account
Description of restriction on payment service provider's access to payment account
Information about the payment service provider to whom access to payment account(s) is restricted
Account information service (AIS) provider
Payment initiation service (PIS) provider
Name of payment service provider
Legal entity code
Information about the payment service user
Natural person
Legal entity
First name
Name
Surname
Legal entity code
Information about restricted access to payment account(s)
Payment service user's account number(s)
Date of restricted access
Amount and currency of payment transaction(s) not executed due to restricted access (not filled if account information service was initiated)
Reason for restriction on payment service provider's access to payment account(s)
Unauthorized payment service provider access
Unfair payment service provider access
Unauthorized initiation of payment transaction Unfair initiation of payment transaction Other (briefly describe)
Circumstances allowing suspicion of unauthorized or unfair access by payment service provider to payment account(s), including unauthorized or unfair initiation of payment transaction(s), fraud, description.
APPROVED
By the Resolution of the Board of the Bank of Lithuania of 12 March 2026 No. 2026/03-19
(ORIS form)
OPERATIONAL AND SECURITY RISK ASSESSMENT REPORT
No.
Operational and security risk threat
Probability of threats
Impact on operations
Inherent risk assessment
Applied risk mitigation control measures
Residual risk assessment
Planned future actions to reduce risk
Read the rest free
Source: Lietuvos Bankas — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works