2022-06-01 | 29/2022Added · Updated
The Bank of Albania’s Supervisory Council has approved a regulation mandating payment service providers to implement strong customer authentication and establish common, open, and secure communication standards for digital payments. The framework requires PSPs to deploy risk-based transaction monitoring mechanisms, utilize multi-factor authentication elements (knowledge, possession, inherence), and ensure dynamic linking of transaction amounts and payees. It outlines specific exemptions for contactless, low-value, and trusted beneficiary transactions while mandating periodic independent audits to verify compliance with fraud rate thresholds and security protocols.
Get BOA alerts — same-day email on every new publication.
R E P U B L I C O F A L B A N I A
BANK OF ALBANIA
SUPERVISORY COUNCIL
DECISION
No. 29, dated 1.6.2022
APPROVAL OF REGULATION
“ON STRONG CUSTOMER AUTHENTICATION AND COMMON, OPEN AND SECURE STANDARDS OF COMMUNICATION” In accordance with article 3, paragraph 3, article 12, letter “a”, and article 43, letter “c” of the law no. 8269, dated 23.12.1997 “On the Bank of Albania”, as amended; articles 90 and 91 of the law no. 55/2020, dated 30.4.2020 “On payment services”; the Supervisory Council of the Bank of Albania, having regard to the proposal from the Supervision Department, DECIDED:
CHAPTER I
GENERAL PROVISIONS
Article 1
Object
This Regulation establishes the requirements to be fulfilled by payment service providers, for the purpose of implementing security measures for:
a) the application of the procedure of strong customer authentication, in accordance with article 90 of Law “On payment services”; b) the exemption from the application of the security requirements of strong customer authentication, based on the level of risk, the amount and the recurrence of the payment transaction and of the payment channel used for its execution; c) the protection of the confidentiality and the integrity of the payment service user's personalised security credentials; d) the establishment of common, open and secure standards for the communication between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers in relation to the provision and use of payment services in application of Title IV of law “On payment services”.
Article 2
Subjects
This regulation shall apply on payment service providers, as referred to in article 3, paragraph 2 of law no.55, dated 30.04.2020 “On payment services”, which herein shall be referred to as law “On payment services”.
Article 3
Legal basis
This regulation is issued in compliance with article 3, paragraph 3, article 12, letter “a”, and article 43, letter “c” of law no. 8269, dated 23.12.1997 “On the Bank of Albania”, as amended; and articles 90 and 91 of law “On payment services”.
Article 4
Definitions
The terms used in this regulation shall have the same meaning as those defined in the law “On payment services”, law no. 9662, dated 18.12.2006 “On banks in the Republic of Albania”, as amended, which herein shall be referred to as the law “On banks”, and the law no. 107/2015 “On electronic identification and trust services”, as amended.
CHAPTER II
GENERAL REQUIREMENTS ON AUTHENTICATION
Article 5
General requirements on authentication
CHAPTER III
SECURITY MEASURES FOR THE APPLICATION OF STRONG CUSTOMER AUTHENTICATION
Article 7
Authentication code
Article 8
Dynamic linking
Article 10
Requirements of the elements categorised as “possession”
CHAPTER IV
EXEMPTIONS FROM STRONG CUSTOMER AUTHENTICATION
Article 13
Access to the payment account information directly with the account servicing payment service provider
to unauthorised or fraudulent access to the payment account. In such a case, the payment service provider shall document and duly justify to the Bank of Albania, upon to its request, the reasons for applying strong customer authentication.
4. Account servicing payment service providers that offer a dedicated interface as referred
to in article 35 of this regulation, shall not be required to implement the exemption referred to in paragraph 1 of this article for the purpose of the contingency mechanism referred to in article 37, paragraph 4, where they do not apply the exemption in article 13 of this regulation, in the direct interface used for authentication and communication with their payment service users.
Article 15
Contactless payments at point of sale
Article 18
Recurring transactions
Payment service providers shall apply strong customer authentication when a payer
creates, amends, or initiates for the first time, a series of recurring transactions with the same amount and with the same payee.
Payment service providers may not apply strong customer authentication, subject to
compliance with the general authentication requirements, for the initiation of all subsequent payment transactions included in the series of payment transactions referred to in paragraph 1 of this article.
Article 19
Credit transfers between accounts held by the same natural or legal person Payment service providers may not apply strong customer authentication, subject to compliance with the requirements laid down in article 5, where the payer initiates a credit transfer in circumstances where the payer and the payee are the same natural or legal person and both payment accounts are held by the same account servicing payment service provider.
Article 20
Low-value transactions
Payment service providers may not apply strong customer authentication, where the
payer initiates a remote electronic payment transaction, provided that the following conditions are met:
a) the amount of the remote electronic payment transaction does not exceed the equivalent amount in lek of 30 euros; and b) the cumulative amount of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication, does not exceed the equivalent amount in lek of 100 euros; or c) the number of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication, does not exceed five consecutive individual remote electronic payment transactions.
Article 21
Secure corporate payment processes and protocols Payment service providers may not apply strong customer authentication, in respect of legal persons initiating electronic payment transactions through the use of dedicated payment processes or protocols, that are only made available to payers who are not consumers, where the Bank of Albania assesses that those processes or protocols guarantee at least equivalent levels of security to those provided for by law “On payment services”.
Article 22
Transaction risk analysis
Payment service providers may not apply strong customer authentication, when the
payer initiates a remote electronic payment transaction identified by the payment service provider as posing a low level of risk according to the transaction monitoring mechanisms referred to in article 5 and in paragraph 2, letter “c” of this article.
An electronic payment transaction referred to in paragraph 1 of this article shall be
considered as posing a low level of risk, where all the following conditions are met:
a) the fraud rate for that type of transaction, reported by the payment service provider and calculated in accordance with article 23 of this regulation, is equivalent to or below the reference fraud rates specified in the table set out in the Annex 1 of this regulation for “remote electronic card-based payments” and “remote electronic credit transfers”; b) the amount of the transaction does not exceed the relevant exemption threshold value (“ETV”) specified in Annex 1 of this regulation; c) payment service providers as a result of performing a real time risk analysis have not identified any of the following:
i. abnormal spending or behavioural pattern of the payer;
ii. unusual information about the payer's device/software access;
iii. signs of malware infection in any session of the authentication procedure;
iv. known fraud scenario in the provision of payment services;
v. abnormal location of the payer;
vi. high-risk location of the payee.
Payment service providers that intend to exempt electronic remote payment
transactions from strong customer authentication on the ground that they pose a low risk, shall take into account at a minimum, the following risk-based factors:
a) the previous spending patterns of the individual payment service user; b) the payment transaction history of each of the payment service provider's payment service users; c) the location of the payer and of the payee at the time of the payment transaction in cases where the access device or the software is provided by the payment service provider; d) the identification of abnormal payment patterns of the payment service user in relation to the user's payment transaction history.
The payment service provider shall combine all those risk-based factors, as provided
in paragraph 3 of this article, into an aggregated risk assessment for each individual transaction, to determine whether a specific payment should be allowed without strong customer authentication.
Article 23
Calculation of fraud rates
The payment service provider, for each type of transaction provisioned in Annex 1 of
this regulation, shall ensure that the overall fraud rates covering both payment transactions authenticated through strong customer authentication and those executed under any of the exemptions referred to in articles 17 to 22 of this regulation, are equivalent to, or lower than, the reference fraud rate for the same type of payment transaction indicated in Annex 1 of this regulation.
The overall fraud rate for each type of transaction shall be calculated as the total value
of unauthorised or fraudulent remote electronic transactions, whether the funds have been recovered or not, divided by the total value of all remote transactions for the same type of transactions, whether authenticated with the application of strong customer
authentication or executed under any exemption referred to in articles 17 to 22 of this regulation, on a rolling quarterly basis (90 days).
3. The calculation of the fraud rates and resulting figures shall be assessed by the audit
review, referred to in article 6, paragraph 3 of this regulation, which shall ensure that they are complete and accurate.
4. The methodology and any model, used by the payment service provider to calculate the
fraud rates, as well as the fraud rates themselves, shall be adequately documented and made available to the Bank of Albania, upon its request.
Article 24
Cessation of exemptions based on transaction risk analysis
b) the average transaction value, including a breakdown of payment transactions initiated through strong customer authentication and under each of the exemptions; c) the number of payment transactions where each of the exemptions was applied and their percentage in respect of the total number of payment transactions.
2. Payment service providers shall make available to the Bank of Albania, upon its
request, the results of the monitoring in accordance with paragraph 1 of this article.
CHAPTER V
CONFIDENTIALITY AND INTEGRITY OF THE PAYMENT SERVICE USERS’ PERSONALISED SECURITY CREDENTIALS
Article 26
General requirements
Article 28
Association with the payment service user
Payment service providers shall ensure that only the payment service user is associated,
in a secure manner, with the personalised security credentials, the authentication devices and software.
For the purposes of paragraph 1 of this article, payment service providers shall ensure
that each of the following requirements is met:
a) the association of the payment service user's identity with personalised security credentials, authentication devices and software is carried out in secure environments under the payment service provider's responsibility, comprising at least the payment service provider's premises, the internet environment provided by the payment service provider or other similar secure websites used by the payment service provider and its automated teller machine (ATM) services, and taking into account risks associated with devices and underlying components used during the association process that are not under the responsibility of the payment service provider; b) the association by means of a remote channel of the payment service user's identity with the personalised security credentials and with authentication devices or software is performed using strong customer authentication.
Article 29
Delivery of credentials, authentication devices and software
Payment service providers shall ensure that the delivery of personalised security
credentials, authentication devices and software to the payment service user is carried out in a secure manner, designed to address the risks related to their unauthorised use due to their loss, theft or copying.
For the purposes of paragraph 1 of this article, payment service providers shall at least
apply the following measures:
a) effective and secure delivery mechanisms, ensuring that the personalised security credentials, authentication devices and software are delivered to the legitimate payment service user; b) mechanisms that allow the payment service provider to verify the authenticity of the authentication software delivered to the payment services user, by means of the internet; c) arrangements ensuring that, where the delivery of personalised security credentials is executed outside the premises of the payment service provider or through a remote channel:
i. no unauthorised party can obtain more than one feature of the personalised
security credentials, the authentication devices or software when delivered through the same channel;
ii. the delivered personalised security credentials, authentication devices or
software require activation before usage; d) arrangements ensuring that, in cases where the personalised security credentials, the authentication devices or software have to be activated before their first use, the activation shall take place in a secure environment in accordance with the association procedures referred to in article 28 of this regulation.
Payment service providers shall inform the legitimate payment service user on the
importance of personalised security credentials confidentiality from third parties.
Article 30
Renewal of personalised security credentials
Payment service providers shall ensure that the renewal or re-activation of personalised security credentials are in compliance with the procedures for the creation, association and delivery of the credentials and of the authentication devices, as provisioned in articles 27, 28 and 29 of this regulation.
Article 31
Destruction, deactivation and revocation
Payment service providers shall ensure that they have effective processes in place to apply each of the following security measures:
a) the secure destruction, deactivation or revocation of the personalised security credentials, authentication devices and software; b) where the payment service provider distributes reusable authentication devices and software, the secure re-use of a device or software is established, documented and implemented before making it available to another payment services user; c) the deactivation or revocation of information related to personalised security credentials stored in the payment service provider's systems and databases and, where relevant, in public repositories.
CHAPTER VI
COMMON, OPEN AND SECURE STANDARDS OF COMMUNICATION
SECTION I
GENERAL REQUIREMENTS FOR COMMUNICATION
Article 32
Requirements for secure electronic identification procedures
Payment service providers shall ensure secure electronic identification, in accordance
with the stipulations laid down in the legislation on electronic identification and trust services, when communicating between the payer's device and the payee's acceptance devices for electronic payments, including but not limited to payment terminals.
Payment service providers shall ensure that the risks of misdirection of communication
to unauthorised parties in mobile applications and other payment services users’ interfaces offering electronic payment services are effectively mitigated.
Article 33
Traceability
Payment service providers shall have processes in place which ensure that all payment
transactions and other interactions with the payment services user, with other payment service providers and with other entities, including merchants, in the context of the
provision of the payment service are traceable, ensuring knowledge ex post of all events relevant to the electronic transaction in all the various stages.
2. For the purposes of paragraph 1 of this article, payment service providers shall ensure
that any communication session established with the payment services user, other payment service providers and other entities, including merchants, relies on each of the following:
a) a unique identifier of the session; b) security mechanisms for the detailed logging of the transaction, including transaction number, timestamps and all relevant transaction data; c) qualified timestamps, as provided for in the legislation on electronic identification and trust services, which shall be based on a unified time-reference system and which shall be synchronised according to an official time signal.
SECTION II
SPECIFIC REQUIREMENTS FOR THE COMMON, OPEN AND SECURE STANDARDS OF COMMUNICATION
Article 34
General obligations for access interfaces
and any payment service user concerned, shall be established and maintained throughout the authentication; c) the integrity and confidentiality of the personalised security credentials and of authentication codes transmitted by or through the payment initiation service provider or the account information service provider, shall be ensured.
4. Account servicing payment service providers shall ensure that their interfaces follow
standards of communication applicable in the European Union.
5. Account servicing payment service providers shall also ensure that the technical
specification of any of the interfaces is documented specifying a set of protocols and tools needed by payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments for allowing their software and applications to interoperate with the systems of the account servicing payment service providers.
6. Account servicing payment service providers, at least 6 months before the target date
for the market launch of the access interface, shall make the documentation available, at no charge, upon request by licenced or registered payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments, or payment service providers that have applied to the Bank of Albania for the relevant licence or registration, and shall make a summary of the documentation publicly available on their website.
7. In addition to paragraphs 4-6 of this article, account servicing payment service
providers shall ensure that, except for emergency situations, arising out of natural disasters, human error or intended interventions, any change to the technical specification of their interface is made available to licenced or registered payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments, or payment service providers that have applied to the Bank of Albania for the relevant licence or registration, in advance as soon as possible and not less than 3 months before the change is implemented.
8. Payment service providers shall document emergency situations where changes were
implemented and make the documentation available to the Bank of Albania, upon its request.
9. Account servicing payment service providers shall make available a testing facility,
including support, for connection and functional testing, to enable licenced or registered payment initiation service providers, payment service providers issuing cardbased payment instruments and account information service providers, or payment service providers that have applied to the Bank of Albania for the relevant licence or registration, to test their software and applications used for offering a payment service to users. This testing facility should be made available at least 6 months before the target date for the market launch of the access interface. However, no sensitive information shall be shared through the testing facility.
10. The Bank of Albania monitors the account servicing payment service providers to
comply at all times with the obligations included in these standards in relation to the interface(s) that they put in place. In the event that an account servicing payment services provider fails to comply with the requirements for interfaces laid down in these standards, the Bank of Albania shall monitor that the provision of payment initiation service and account information service is not prevented or disrupted, to the extent that
the respective providers of such services comply with the conditions defined under
article 37, paragraph 5 of this regulation.
Article 35
Access interface options
Account servicing payment service providers shall establish the interface(s) referred to in
article 34 of this regulation, by means of a dedicated interface or by allowing the use by
the payment service providers referred to in article 34, paragraph 1 of this regulation, of the interfaces used for authentication and communication with the account servicing payment service provider's payment services users.
Article 36
Obligations for a dedicated interface
there is unplanned unavailability of the interface or that there is a systems’ breakdown. Unplanned unavailability or a systems’ breakdown may be presumed to have arisen when five consecutive requests for access to information for the provision of payment initiation services or account information services, are not replied to within 30 seconds.
2. Contingency measures shall include communication plans to inform payment service
providers making use of the dedicated interface of measures to restore the system and a description of the immediately available alternative options payment service providers may have during this time.
3. Both the account servicing payment service provider and the payment service providers
referred to in article 34, paragraph 1 of this regulation, shall report to the Bank of Albania without delay, problems with dedicated interfaces as described in paragraph 1 of this article.
4. As part of a contingency mechanism, payment service providers referred to in article
34, paragraph 1 of this regulation, shall be allowed to make use of the interfaces made available to the payment service users for the authentication and communication with their account servicing payment service provider, until the dedicated interface is restored to the level of availability and performance provided for in article 36 of this regulation.
5. Referred to the mechanism provided in paragraph 4 of this article, account servicing
payment service providers shall ensure that the payment service providers referred to in article 34, paragraph 1 of this regulation, can be identified and can rely on the authentication procedures, provided by the account servicing payment service provider to the payment service users. Where the payment service providers referred to in article 34, paragraph 1 of this regulation, make use of the interface referred to in paragraph 4 of this article, they shall:
a) take the necessary measures to ensure that they do not access, store or process data for purposes other than for the provision of the service as requested by the payment service user; b) continue to comply with the obligations following from article 59, paragraph 3 and
article 60, paragraph 2 of law “On payment services”;
c) log the data that are accessed through the interface operated by the account servicing payment service provider for its payment service users, and provide the log files to the Bank of Albania, upon its request and without undue delay; d) make available to the Bank of Albania, upon its request and without undue delay, the reasons on the use of the interface made available to the payment service users for directly accessing its payment account online; e) inform the account servicing payment service provider accordingly.
6. The Bank of Albania, may exempt the account servicing payment service providers
that have opted for a dedicated interface from the obligation to set up the contingency mechanism described under paragraph 4 of this article, where the dedicated interface meets all of the following conditions:
a) it complies with all the obligations for dedicated interfaces as set out in article 36 of this regulation; b) it has been designed and tested in accordance with article 34, paragraph 9 to the satisfaction of the payment service providers referred to therein;
c) it has been widely used for at least 3 months by payment service providers to offer account information services, payment initiation services and to provide confirmation on the availability of funds for card-based payments; d) any problem related to the dedicated interface has been resolved without undue delay.
7. The Bank of Albania shall revoke the exemption referred to in paragraph 6 of this
article, where the conditions provisioned in letters “a” and “d” are not met by the
account servicing payment service providers for more than 2 consecutive calendar weeks. The Bank of Albania shall ensure that the account servicing payment service providers establish, within the shortest possible time and at the latest within 2 months, the contingency mechanism referred to in paragraph 4 of this article.
Article 38
Qualified electronic certificates
Article 39
Security of communication session
b) they shall, immediately after receipt of the payment order, provide payment initiation service providers with the same information on the initiation and execution of the payment transaction, provided or made available to the payment service user, when the transaction is initiated directly by the latter; c) they shall provide immediately upon request, payment service providers with a confirmation in a simple “yes” or “no” format, whether the amount necessary for the execution of a payment transaction is available on the payment account of the payer.
2. In case of an unexpected error or cybernetic incident occurring during the process of
identification, authentication, or the exchange of the data elements, the account servicing payment service provider shall send a notification message to the payment initiation service provider or the account information service provider and the payment service provider issuing card-based payment instruments, which explains the reason for the unexpected error or cybernetic incident.
3. Where the account servicing payment service provider offers a dedicated interface in
accordance with article 36 of this regulation, the interface shall provide for notification messages concerning unexpected errors or cybernetic incident to be communicated by any payment service provider that detects the error or incident, to other payment service providers participating in the communication session.
4. Account information service providers shall have in place suitable and effective
mechanisms that prevent access to information other than from designated payment accounts and associated payment transactions, in accordance with the user’s explicit consent.
5. Payment initiation service providers shall provide account servicing payment service
providers with the same information as requested from the payment service user, when initiating the payment transaction directly.
6. Account information service providers shall be able to access information from
designated payment accounts and associated payment transactions held by account servicing payment service providers, for the purposes of performing the account information service in either of the following circumstances:
a) whenever the payment service user is actively requesting such information; b) where the payment service user does not actively request such information, no more than four times in a 24-hour period, unless a higher frequency is agreed between the account information service provider and the account servicing payment service provider, with the payment service user’s consent.
CHAPTER VII
SUPERVISORY REQUIREMENTS
Article 41
Supervisory measures
The Bank of Albania, in case of failure to comply with the obligations laid down in this regulation, shall implement the supervisory and/or punishing measures, laid down in articles 25 and chapter I of Title V of the law “On payment services”.
Article 42
Entry into force
This regulation shall enter into force on 1 January 2024.
CHAIRMAN OF THE SUPERVISORY COUNCIL
Gent SEJKO
Annex 1
Exemption threshold value (‘ETV’)
Reference fraud rate (%) for:
Remote electronic cardbased payments
Remote electronic credit transfers
Equivalent value in lek of the amount 500 euros
0.01 0,005
Equivalent value in lek of the amount 250 euros
0.06 0.01
Equivalent value in lek of the amount 100 euros
0.13 0,015
Read the rest free
Source: Bank of Albania — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works