2023-11-16 | CBE12.2Added · Updated
The Central Bank of Egypt updates the regulatory framework for mobile payment services, replacing the November 2016 rules and applying to all banks registered with the CBE, including foreign branches. The regulation mandates strict risk management, requiring boards to oversee strategic decisions, maintain security infrastructure, and conduct due diligence on third-party service providers. It establishes specific operational rules for electronic money issuance, limiting issuance to licensed banks holding equivalent Egyptian Pound deposits, and defines permissible activities for service providers, such as cash collection and customer identification. Furthermore, it sets account management constraints, including a limit of three mobile accounts per user across all banks, Egyptian nationality requirements for natural persons, and enhanced anti-money laundering and cybersecurity protocols.
Mobile payment services aim to achieve financial inclusion and provide banking services to all members of society, including the disadvantaged, youth, and those living in remote areas. These services provide a simple bank account that opens the door to expanding the base of bank clients.
Given the increasing orientation of banking services in Egypt towards technology, this requires additional regulatory reforms in this field.
Although the risks and controls are similar across different channels for banking services, these rules specifically concern payment services using mobile phones only.
The scope of the rules does not cover payment services using other execution channels (e.g., ATMs, landline banking, and Mobile/Internet Banking). Detailed rules regulating some of these services have been issued, and the rest will be issued separately.
These rules and controls represent the minimum necessary to provide payment services using mobile phones securely. All banks must not rely solely on this and must ensure they take all necessary steps regarding the management of risks associated with providing this type of banking service.
These rules include some general controls or supervisory objectives related to business continuity, outsourcing of work to third parties, and information system risk management. However, detailed rules regulating these areas will be issued separately later.
These rules apply regarding the provision of payment services using mobile phones, without prejudice to the supervisory controls for electronic banking operations previously issued by the Central Bank of Egypt, as well as the instructions and rules for implementing banking operations and anti-money laundering and counter-terrorism financing controls issued by the Central Bank of Egypt, and the due diligence procedures for customers of mobile payment services issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.
These rules apply to all banks registered with the Central Bank of Egypt, including branches of foreign banks, and replace the "Rules Regulating the Provision of Payment Services Using a Mobile Phone" issued on November 29, 2016, and its amendments.
The provision of payment services using mobile phones is accompanied by many risks and advantages simultaneously. While these risks are not new to banks, the characteristics of mobile payment services may increase risk levels and create new challenges for managing these risks. These risks include, but are not limited to:
Strategic Risks: These involve the decision to provide mobile payment services, the type of services provided, and the timing of their provision. This specifically refers to the economic viability of providing or continuing these services and whether the return on investment will exceed initial investments and ongoing costs. Poor planning for mobile payment services and unconsidered investment decisions can increase the strategic risks banks face.
Operational Risks / Transaction Risks: These involve risks arising from fraud or errors in transaction execution, system malfunction, or other unexpected events that may prevent the bank from providing services or expose the bank or its clients to financial losses. While risks exist in all products and services, the level of transaction risk is affected by the structure of banking procedures and transactions, including the types of services provided, the degree of operational complexity, and the technological aids used.
Compliance Risks / Legal Risks: These risks arise from the spread of mobile payment services and the difference between electronic and manual operations. Regulatory/legal challenges may include:
Reputational Risks: The level of reputational risk increases due to the bank's decision to provide mobile payment services, especially regarding more complex transactions. Some risks that may affect the bank's reputation through mobile payment services include:
Information Security Risks: This type of risk arises from the possibility of unauthorized parties exploiting vulnerabilities in mobile payment service systems to cause harm, resulting in effects related to the integrity, availability, and confidentiality of data.
1-2-2 The Board of Directors and Senior Management are responsible for overseeing the preparation of the bank's business strategy and making a clear strategic decision regarding the bank's desire to provide mobile payment services. Specifically, the Board of Directors must ensure the following:
2-2-2 The Board of Directors and Senior Management must ensure that risks associated with mobile payment services mentioned in Item 1-2 are analyzed and mitigated appropriately, as follows:
2-2-2-1 Establish effective controls on risks associated with providing mobile payment services, including defining responsibilities, policies, and supervisory controls to manage these risks:
3-2-2-2 Review and approve key aspects of the bank's security control process:
4-2-2-2 Establish a comprehensive and continuous mechanism for conducting Due Diligence and supervising outsourcing operations and the bank's relationships with other third parties relied upon to provide mobile payment services. The Board of Directors and Senior Management should focus on the following points, including but not limited to:
5-2-2-2 Compliance officers must conduct periodic reviews - at least annually - to ensure compliance with the provisions of these instructions. According to Item 2-1, detailed rules governing outsourcing activities will be issued separately, including detailed supervisory controls, supervisory objectives, and a list of systems and services permitted to be outsourced. Until these rules are issued, banks must not enter into any agreements related to outsourcing mobile payment services or their applications without prior approval from the Central Bank of Egypt.
1-3-2 Senior Management must ensure that the information security policy is applied at the bank and approved by the Board of Directors, and is updated periodically to cover mobile payment services. This helps define the policies, procedures, and supervisory controls necessary to protect banking operations from breaches and security violations. It also defines individual responsibilities and clarifies implementation mechanisms and procedures to be taken in case of violation of these policies and procedures.
2-3-2 Senior Management is responsible for enhancing and spreading security culture at all levels of the bank by emphasizing their commitment to high information security standards and spreading this culture among all bank employees.
Banks offer a variety of mobile payment services to diverse customer groups, and therefore they do not typically involve the same level of inherent risk.
This diversity in service provision requires banks to adopt comprehensive security methods that are also flexible. The security methodology must be based on an analysis of risks and threats specific to mobile payment services, taking into account inherent risks and compensating controls to reach a residual risk level that falls within the bank's acceptable risk levels.
Banks providing mobile payment services must implement the following:
The right to issue electronic money units is restricted to banks subject to the supervision of the Central Bank of Egypt, after obtaining its approval.
The bank is the issuer of electronic money units and operates a system to manage electronic money records completely, accurately, and continuously. These records show the value of electronic money issued by the bank and service providers, and the account balances of each, as well as the total of these balances. This system monitors the movement of payment orders for electronic money units and issues detailed audit trail reports on payment orders, linking operations to system users and service providers. The system's failure to issue correct reports - whether intentional to violate these rules or unintentional - constitutes a violation.
Each electronic money unit in the mobile payment service must equal a monetary value of one Egyptian Pound.
Electronic money units are not issued unless the bank holds cash deposits (in Egyptian Pounds) with it not less than the value of the electronic money units issued by the bank. The Central Bank of Egypt monitors through inspection the compliance of the unlicensed issuer with this rule and ensures that the value of the issued units by the bank does not exceed the cash deposits in Egyptian Pounds held by it for this purpose.
The bank must, based on its assessment of the risks associated with the service, set a suitable maximum limit for the electronic money units issued, and the Central Bank must be notified of any change to this limit.
Banks have the right to use service providers to reach system users and provide services related to this system after approval from the Central Bank of Egypt, observing all that came in Item 2-2-2-2. The agreement between the bank and the service provider on the operations performed by the service provider must stipulate that the operations do not exceed the following:
1-1-2-3 In the case that the service provider is among the entities mentioned in Item (3) of the due diligence procedures for customers of mobile payment services issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit:
2-1-2-3 In the case that the service provider is an entity other than those mentioned in Item (3):
2-2-3 The service provider must have a good financial status and be reputable.
3-2-3 The service provider opens a credit account with the bank.
4-2-3 The volume of electronic money units granted to the service provider is limited to the amount of cash (Egyptian Pounds) they deposited with the bank, or guarantees held by the bank, to convert into electronic money units for system users in exchange for their cash collections. The service provider is not allowed to receive money from system users without converting electronic money units to them, nor is it allowed to receive electronic money units from them without delivering cash (Egyptian Pounds) to them.
5-2-3 The service provider is committed to sending customer identification documents for account opening applicants to the bank in accordance with the due diligence procedures for customers of mobile payment services issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.
6-2-3 The service provider provides a suitable place to conduct financial transactions related to the system.
7-2-3 The service provider is committed to providing cash liquidity to cover expected cash withdrawal operations.
8-2-3 The bank is fully responsible to system users and to the compliance of service providers with the implementation of these rules, as well as the provisions, controls, rules, and procedures issued regarding anti-money laundering and counter-terrorism financing.
9-2-3 The service provider is not allowed to subcontract the execution of its contract with the bank to others, nor is it allowed to assign its contract with the bank or transfer it to others for their benefit. This must be explicitly stated in the contract between the bank and the service provider.
10-2-3 When the bank uses service providers to identify and verify customers or in deposit and cash withdrawal operations, it must compel them to declare all data related to the merchant network and service outlets of the mechanism specified by the bank. The bank must provide a suitable mechanism for its customers to inquire about the service providers affiliated with them.
1-3-3 The bank is committed, when opening mobile phone accounts, to identifying the identity of the system user applicant and verifying it according to the "Due Diligence Procedures for Customers of Mobile Payment Services" issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit. It is also committed to the Anti-Money Laundering Law issued by Law No. 80 of 2002 and its executive regulations, and the supervisory controls for banks regarding anti-money laundering and counter-terrorism financing issued by the Central Bank of Egypt.
2-3-3 The bank is committed to documenting all data related to the location and time of opening mobile phone accounts, as well as withdrawal and deposit operations.
3-3-3 Banks retain all documents related to the system in a secure manner and for the legally prescribed periods.
4-3-3 Each mobile phone number is linked to only one mobile phone account.
5-3-3 Opening mobile phone accounts for system users who are natural persons is restricted to Egyptian nationals only.
6-3-3 System users are allowed to open more than one mobile phone account, with a maximum of three accounts across all banks providing the service in Egypt.
7-3-3 Banks are committed to applying all supervisory procedures and controls that enable them to identify the identity of anyone conducting any electronic transactions related to bank accounts, in cases where more than one user is authorized to transact on this account.
8-3-3 Banks are committed to obtaining all necessary legal documents to prove the authorization of users to conduct transactions on the accounts of legal entities.
9-3-3 Banks are committed to applying the interoperability controls mentioned in Item 7-3.
10-3-3 An account is opened for each system user or service provider to transact through the system - called a mobile phone account - and the bank is responsible for managing this account. Electronic money units are deposited into it in an amount equal to the cash (Egyptian Pounds) deposited by the system user or service provider with the bank to fund the mobile phone account. Returns may be granted on mobile phone accounts for system users who are natural persons and micro-enterprises only, according to the determinations in the Digital Savings Rules issued by the Central Bank in April 2021 and referred to in Appendix (B).
11-3-3 Banks are committed to periodically verifying that the owner of the mobile phone account possesses the mobile phone number registered on the system.
12-3-3 The bank and the service provider apply the provisions of maintaining account confidentiality as required by the Central Bank and Banking System Law issued by Law No. 194 of 2020 and its amendments.
13-3-3 The service provider is not allowed to grant any credit in any form in exchange for electronic money units.
14-3-3 Banks are committed to using reliable methods to verify the identity of the depositor when funding the mobile phone account.
15-3-3 Banks are committed to using reliable methods to verify the identity and qualifications of customers wishing to subscribe to mobile payment services.
16-3-3 Banks are committed to conducting necessary audits to verify the identity of the system user when they request to modify the data of their mobile payment service account, or modify any data used by the system user to monitor the activities of their mobile phone account. This applies to account reactivation and reissuing a new password for the mobile payment service system, and changing contact data such as email address, landline phone number, and mailing address. Banks must also consider applying the following standards when dealing with these requests:
17-3-3 When closing the account or terminating the contract for a mobile phone number, appropriate procedures must be put in place to ensure the withdrawal of electronic money units existing in the mobile phone account and to verify the identity of the withdrawer and document the account closure.
18-3-3 Banks are committed to providing a suitable immediate mechanism that enables the customer to inquire about their mobile phone accounts and request their closure electronically, through the following channels, without conflicting with Item 17-3-3:
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 97,872-character original (25% of the document). The remainder was not translated. The complete original-language text is stored with this document.]