2023-11-16 | CBE12.2

Added · Updated

CBE Regulation Book 12.2 - The Rules Regulating The Provision Of Payment Services Using A Mobile Phone

The Central Bank of Egypt updates the regulatory framework for mobile payment services, replacing the November 2016 rules and applying to all banks registered with the CBE, including foreign branches. The regulation mandates strict risk management, requiring boards to oversee strategic decisions, maintain security infrastructure, and conduct due diligence on third-party service providers. It establishes specific operational rules for electronic money issuance, limiting issuance to licensed banks holding equivalent Egyptian Pound deposits, and defines permissible activities for service providers, such as cash collection and customer identification. Furthermore, it sets account management constraints, including a limit of three mobile accounts per user across all banks, Egyptian nationality requirements for natural persons, and enhanced anti-money laundering and cybersecurity protocols.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Chapter Two: Rules Regulating the Provision of Payment Services

1. Using a Mobile Phone

-1 Introduction

1-1 Purpose

Mobile payment services aim to achieve financial inclusion and provide banking services to all members of society, including the disadvantaged, youth, and those living in remote areas. These services provide a simple bank account that opens the door to expanding the base of bank clients.

Given the increasing orientation of banking services in Egypt towards technology, this requires additional regulatory reforms in this field.

2-1 Scope of the Rules

  • Although the risks and controls are similar across different channels for banking services, these rules specifically concern payment services using mobile phones only.

  • The scope of the rules does not cover payment services using other execution channels (e.g., ATMs, landline banking, and Mobile/Internet Banking). Detailed rules regulating some of these services have been issued, and the rest will be issued separately.

  • These rules and controls represent the minimum necessary to provide payment services using mobile phones securely. All banks must not rely solely on this and must ensure they take all necessary steps regarding the management of risks associated with providing this type of banking service.

  • These rules include some general controls or supervisory objectives related to business continuity, outsourcing of work to third parties, and information system risk management. However, detailed rules regulating these areas will be issued separately later.

  • These rules apply regarding the provision of payment services using mobile phones, without prejudice to the supervisory controls for electronic banking operations previously issued by the Central Bank of Egypt, as well as the instructions and rules for implementing banking operations and anti-money laundering and counter-terrorism financing controls issued by the Central Bank of Egypt, and the due diligence procedures for customers of mobile payment services issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.

These rules apply to all banks registered with the Central Bank of Egypt, including branches of foreign banks, and replace the "Rules Regulating the Provision of Payment Services Using a Mobile Phone" issued on November 29, 2016, and its amendments.

3-1 Appendices

  • Appendix (A): Cases and rules regarding the use of service providers for customer identification as stated in the "Due Diligence Procedures for Customers of Mobile Payment Services" issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit in 2020.
  • Appendix (B): Rules Regulating the Provision of Digital Lending and Savings issued by the Central Bank of Egypt in April 2021.
  • Appendix (C): Definitions.

-2 Management of Risks Associated with Mobile Payment Services

1-2 Risks Associated with Mobile Payment Services

The provision of payment services using mobile phones is accompanied by many risks and advantages simultaneously. While these risks are not new to banks, the characteristics of mobile payment services may increase risk levels and create new challenges for managing these risks. These risks include, but are not limited to:

  • Strategic Risks: These involve the decision to provide mobile payment services, the type of services provided, and the timing of their provision. This specifically refers to the economic viability of providing or continuing these services and whether the return on investment will exceed initial investments and ongoing costs. Poor planning for mobile payment services and unconsidered investment decisions can increase the strategic risks banks face.

  • Operational Risks / Transaction Risks: These involve risks arising from fraud or errors in transaction execution, system malfunction, or other unexpected events that may prevent the bank from providing services or expose the bank or its clients to financial losses. While risks exist in all products and services, the level of transaction risk is affected by the structure of banking procedures and transactions, including the types of services provided, the degree of operational complexity, and the technological aids used.

  • Compliance Risks / Legal Risks: These risks arise from the spread of mobile payment services and the difference between electronic and manual operations. Regulatory/legal challenges may include:

    • Entering into a legal agreement electronically with customers to use mobile payment services.
    • The methods banks use to identify and verify customers, which constitute a source of legal risk that requires adequate controls to mitigate.
    • In light of banks' commitment to the Central Bank and Banking System Law No. 194 of 2020, banks must establish procedures and controls to maintain data privacy and account confidentiality to manage the increasing risks associated with providing mobile payment services. This also includes the legal liability of banks towards customers resulting from potential breaches of data privacy or other problems due to hacking, fraud, or other technological failures, and to protect this data from theft.
    • Banks providing mobile payment services bear a higher degree of compliance risk due to the changing nature of technology and regulatory amendments aimed at addressing issues specific to providing this type of service.
    • Retaining required compliance documents related to records, applications, account statements, disclosures, and notifications.
    • Identifying and assessing money laundering and terrorism financing risks that may arise from mobile payment services. This assessment must be completed before launching mobile payment services. If the service is already operational at the bank, this assessment must be redone immediately upon the issuance of these rules, in light of the supervisory requirements contained therein and the due diligence procedures for customers of mobile payment services issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.
  • Reputational Risks: The level of reputational risk increases due to the bank's decision to provide mobile payment services, especially regarding more complex transactions. Some risks that may affect the bank's reputation through mobile payment services include:

    • Lack of trust due to unauthorized transactions on a system user's account.
    • Disclosure or theft of confidential information about system users to unauthorized parties.
    • Failure to provide reliable services due to repeated service outages or long downtime.
    • System user complaints regarding the difficulty of using mobile payment services or the inability of bank technical support staff to resolve these issues.
  • Information Security Risks: This type of risk arises from the possibility of unauthorized parties exploiting vulnerabilities in mobile payment service systems to cause harm, resulting in effects related to the integrity, availability, and confidentiality of data.

2-2 Responsibilities and Obligations of the Board of Directors and Senior Management

1-2-2 The Board of Directors and Senior Management are responsible for overseeing the preparation of the bank's business strategy and making a clear strategic decision regarding the bank's desire to provide mobile payment services. Specifically, the Board of Directors must ensure the following:

  • Mobile payment service plans align with the bank's strategic objectives.
  • Analysis of risks associated with proposed mobile payment services.
  • Preparation of appropriate procedures to monitor and mitigate risks identified.
  • Continuous review of the results of mobile payment services according to specified plans and objectives.

2-2-2 The Board of Directors and Senior Management must ensure that risks associated with mobile payment services mentioned in Item 1-2 are analyzed and mitigated appropriately, as follows:

2-2-2-1 Establish effective controls on risks associated with providing mobile payment services, including defining responsibilities, policies, and supervisory controls to manage these risks:

  • The Board of Directors and Senior Management must be aware of mobile payment operations, which may present challenges different from traditional risk management as described in Item 1-2.
  • The Board of Directors and Senior Management must ensure that the bank does not provide new mobile payment services or adopt new technological means unless the bank possesses the necessary expertise to manage risks efficiently. Employee and management expertise should match the technical nature and complexity of applications and technologies for mobile payment services.
  • The Board of Directors and Senior Management must determine the bank's risk appetite regarding mobile payment services, ensuring that risk management processes for these services are included in the bank's general risk management methodology. Existing policies and processes for risk management must be reviewed to ensure they are sufficient to cover new risks arising from mobile payment services.
  • Internal Audit Management must provide the Board of Directors, the Audit Committee, and Senior Management with an independent and objective assessment of the effectiveness of supervisory controls applied to mitigate risks resulting from providing mobile payment services, including technology risks.

3-2-2-2 Review and approve key aspects of the bank's security control process:

  • The Board of Directors and Senior Management must oversee the continuous development and maintenance of the security control infrastructure that provides appropriate protection for mobile payment service systems and data from any internal or external threats. To ensure the effectiveness of securing mobile payment services, the Board of Directors and Senior Management must ensure the following actions are taken:
    • Define clear responsibilities for overseeing the establishment and management of the bank's security policies.
    • Provide necessary protection to prevent unauthorized persons from entering the computing environment, which includes all vital systems, network servers, databases, applications, communications, and security systems for mobile payment services.
    • Provide necessary electronic controls to prevent any unauthorized internal or external parties from accessing applications and databases for mobile payment services.
    • Periodically review security procedure and system testing processes - for example, conducting periodic penetration testing as shown in Item 11-3 - including continuous monitoring of developments in security systems in this field, downloading and preparing appropriate software updates and service packs, and necessary measures after conducting required tests.

4-2-2-2 Establish a comprehensive and continuous mechanism for conducting Due Diligence and supervising outsourcing operations and the bank's relationships with other third parties relied upon to provide mobile payment services. The Board of Directors and Senior Management should focus on the following points, including but not limited to:

  • Full awareness of the risks resulting from any arrangements for subcontracting, partnership, or agency regarding mobile payment service systems or applications, in addition to providing necessary resources to supervise these arrangements.
  • Conducting necessary due diligence regarding the competence, system infrastructure, and financial capacity of the partner or external service provider before entering into any agreements for subcontracting, partnership, or agency.
  • Clearly defining contractual responsibilities for all parties to subcontracting, partnership, or agency agreements. For example, responsibilities for providing and receiving information from the service provider are clearly defined.
  • Subcontracting or agency service contracts include a non-disclosure agreement for confidential information to external parties and a service level agreement, which includes, but is not limited to: defining roles and responsibilities, time required to execute the service, escalation procedures and data, and penalties for non-compliance. This also includes clauses preserving the bank's right to audit service providers or rely on audits issued by approved audit firms.
  • All systems and processes for mobile payment services conducted through subcontracting or agency are subject to the bank's risk management system and privacy and information security policies that align with the bank's standards.
  • Internal and/or external audits are conducted periodically on operations conducted through subcontracting or agency. The scope of audit work should not be less than that applied at the internal level within the bank.
  • Provide all audit and evaluation reports to the inspectors of the Supervision and Oversight Sector of the Central Bank of Egypt.
  • Establish appropriate emergency plans for mobile payment services conducted through subcontracting or agency.
  • Termination/cancellation procedures must be effective and must ensure the preservation of business continuity, data integrity, as well as its transfer and disposal.
  • Despite the bank outsourcing some services to third parties, the bank remains fully responsible to system users and to the compliance of external parties with these rules.

5-2-2-2 Compliance officers must conduct periodic reviews - at least annually - to ensure compliance with the provisions of these instructions. According to Item 2-1, detailed rules governing outsourcing activities will be issued separately, including detailed supervisory controls, supervisory objectives, and a list of systems and services permitted to be outsourced. Until these rules are issued, banks must not enter into any agreements related to outsourcing mobile payment services or their applications without prior approval from the Central Bank of Egypt.

3-2 Establishing an Information Security Policy

1-3-2 Senior Management must ensure that the information security policy is applied at the bank and approved by the Board of Directors, and is updated periodically to cover mobile payment services. This helps define the policies, procedures, and supervisory controls necessary to protect banking operations from breaches and security violations. It also defines individual responsibilities and clarifies implementation mechanisms and procedures to be taken in case of violation of these policies and procedures.

2-3-2 Senior Management is responsible for enhancing and spreading security culture at all levels of the bank by emphasizing their commitment to high information security standards and spreading this culture among all bank employees.

4-2 Classification of Risks for Mobile Payment Services

Banks offer a variety of mobile payment services to diverse customer groups, and therefore they do not typically involve the same level of inherent risk.

This diversity in service provision requires banks to adopt comprehensive security methods that are also flexible. The security methodology must be based on an analysis of risks and threats specific to mobile payment services, taking into account inherent risks and compensating controls to reach a residual risk level that falls within the bank's acceptable risk levels.

5-2 Anti-Money Laundering and Counter-Terrorism Financing Rules

Banks providing mobile payment services must implement the following:

  • Compliance with the Anti-Money Laundering Law issued by Law No. 80 of 2002 and its executive regulations, and the supervisory controls for banks regarding anti-money laundering and counter-terrorism financing issued by the Central Bank of Egypt, as well as the due diligence procedures for customers of mobile payment services issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.
  • Paying sufficient attention to the indicative indicators in Item Seven (Indicative Indicators for Identifying Transactions Suspected of Involving Money Laundering or Terrorism Financing) of the supervisory controls for banks regarding anti-money laundering and counter-terrorism financing issued by the Central Bank of Egypt in 2008, consistent with the nature of the service.
  • In case of suspicion of any transactions conducted through mobile applications, notify the Anti-Money Laundering and Counter-Terrorism Financing Unit regarding them, in accordance with the provisions of the Anti-Money Laundering Law issued by Law No. 80 of 2002.

-3 Issuance of Electronic Money and System Management

1-3-1

The right to issue electronic money units is restricted to banks subject to the supervision of the Central Bank of Egypt, after obtaining its approval.

2-3-1

The bank is the issuer of electronic money units and operates a system to manage electronic money records completely, accurately, and continuously. These records show the value of electronic money issued by the bank and service providers, and the account balances of each, as well as the total of these balances. This system monitors the movement of payment orders for electronic money units and issues detailed audit trail reports on payment orders, linking operations to system users and service providers. The system's failure to issue correct reports - whether intentional to violate these rules or unintentional - constitutes a violation.

3-3-1

Each electronic money unit in the mobile payment service must equal a monetary value of one Egyptian Pound.

4-3-1

Electronic money units are not issued unless the bank holds cash deposits (in Egyptian Pounds) with it not less than the value of the electronic money units issued by the bank. The Central Bank of Egypt monitors through inspection the compliance of the unlicensed issuer with this rule and ensures that the value of the issued units by the bank does not exceed the cash deposits in Egyptian Pounds held by it for this purpose.

5-3-1

The bank must, based on its assessment of the risks associated with the service, set a suitable maximum limit for the electronic money units issued, and the Central Bank must be notified of any change to this limit.

-3-2 Use of Service Providers

1-2-3

Banks have the right to use service providers to reach system users and provide services related to this system after approval from the Central Bank of Egypt, observing all that came in Item 2-2-2-2. The agreement between the bank and the service provider on the operations performed by the service provider must stipulate that the operations do not exceed the following:

1-1-2-3 In the case that the service provider is among the entities mentioned in Item (3) of the due diligence procedures for customers of mobile payment services issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit:

  • Identify the identity of the system user applicant and verify it according to the procedures issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit in this regard.
  • Receive and register account opening request forms or any other requests related to the service.
  • Provide awareness and informational guidance on using the system.
  • Obtain cash (Egyptian Pounds) from system users within the service provider's balance of electronic money units at the bank.
  • Deliver cash (Egyptian Pounds) to the system user in exchange for receiving electronic money units from them.

2-1-2-3 In the case that the service provider is an entity other than those mentioned in Item (3):

  • Provide awareness and informational guidance on using the system.
  • Obtain cash (Egyptian Pounds) from system users within the service provider's balance of electronic money units at the bank.
  • Deliver cash (Egyptian Pounds) to the system user in exchange for receiving electronic money units from them.

2-2-3 The service provider must have a good financial status and be reputable.

3-2-3 The service provider opens a credit account with the bank.

4-2-3 The volume of electronic money units granted to the service provider is limited to the amount of cash (Egyptian Pounds) they deposited with the bank, or guarantees held by the bank, to convert into electronic money units for system users in exchange for their cash collections. The service provider is not allowed to receive money from system users without converting electronic money units to them, nor is it allowed to receive electronic money units from them without delivering cash (Egyptian Pounds) to them.

5-2-3 The service provider is committed to sending customer identification documents for account opening applicants to the bank in accordance with the due diligence procedures for customers of mobile payment services issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.

6-2-3 The service provider provides a suitable place to conduct financial transactions related to the system.

7-2-3 The service provider is committed to providing cash liquidity to cover expected cash withdrawal operations.

8-2-3 The bank is fully responsible to system users and to the compliance of service providers with the implementation of these rules, as well as the provisions, controls, rules, and procedures issued regarding anti-money laundering and counter-terrorism financing.

9-2-3 The service provider is not allowed to subcontract the execution of its contract with the bank to others, nor is it allowed to assign its contract with the bank or transfer it to others for their benefit. This must be explicitly stated in the contract between the bank and the service provider.

10-2-3 When the bank uses service providers to identify and verify customers or in deposit and cash withdrawal operations, it must compel them to declare all data related to the merchant network and service outlets of the mechanism specified by the bank. The bank must provide a suitable mechanism for its customers to inquire about the service providers affiliated with them.

-3-3 Management of Mobile Payment Service Accounts

1-3-3 The bank is committed, when opening mobile phone accounts, to identifying the identity of the system user applicant and verifying it according to the "Due Diligence Procedures for Customers of Mobile Payment Services" issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit. It is also committed to the Anti-Money Laundering Law issued by Law No. 80 of 2002 and its executive regulations, and the supervisory controls for banks regarding anti-money laundering and counter-terrorism financing issued by the Central Bank of Egypt.

2-3-3 The bank is committed to documenting all data related to the location and time of opening mobile phone accounts, as well as withdrawal and deposit operations.

3-3-3 Banks retain all documents related to the system in a secure manner and for the legally prescribed periods.

4-3-3 Each mobile phone number is linked to only one mobile phone account.

5-3-3 Opening mobile phone accounts for system users who are natural persons is restricted to Egyptian nationals only.

6-3-3 System users are allowed to open more than one mobile phone account, with a maximum of three accounts across all banks providing the service in Egypt.

7-3-3 Banks are committed to applying all supervisory procedures and controls that enable them to identify the identity of anyone conducting any electronic transactions related to bank accounts, in cases where more than one user is authorized to transact on this account.

8-3-3 Banks are committed to obtaining all necessary legal documents to prove the authorization of users to conduct transactions on the accounts of legal entities.

9-3-3 Banks are committed to applying the interoperability controls mentioned in Item 7-3.

10-3-3 An account is opened for each system user or service provider to transact through the system - called a mobile phone account - and the bank is responsible for managing this account. Electronic money units are deposited into it in an amount equal to the cash (Egyptian Pounds) deposited by the system user or service provider with the bank to fund the mobile phone account. Returns may be granted on mobile phone accounts for system users who are natural persons and micro-enterprises only, according to the determinations in the Digital Savings Rules issued by the Central Bank in April 2021 and referred to in Appendix (B).

11-3-3 Banks are committed to periodically verifying that the owner of the mobile phone account possesses the mobile phone number registered on the system.

12-3-3 The bank and the service provider apply the provisions of maintaining account confidentiality as required by the Central Bank and Banking System Law issued by Law No. 194 of 2020 and its amendments.

13-3-3 The service provider is not allowed to grant any credit in any form in exchange for electronic money units.

14-3-3 Banks are committed to using reliable methods to verify the identity of the depositor when funding the mobile phone account.

15-3-3 Banks are committed to using reliable methods to verify the identity and qualifications of customers wishing to subscribe to mobile payment services.

16-3-3 Banks are committed to conducting necessary audits to verify the identity of the system user when they request to modify the data of their mobile payment service account, or modify any data used by the system user to monitor the activities of their mobile phone account. This applies to account reactivation and reissuing a new password for the mobile payment service system, and changing contact data such as email address, landline phone number, and mailing address. Banks must also consider applying the following standards when dealing with these requests:

  • If the system user submits a request to modify their data at one of the branches or at one of the service provider's outlets, the necessary procedures must be applied to verify their identity.
  • In the case of modification requests submitted through payment systems via mobile phones, authentication means shown in Item 1-5-4-3 must be used, with ensuring the existence of effective monitoring mechanisms.
  • Banks apply necessary procedures to verify the identity of the system user in the case of delivering information, tools, or devices that allow them to access their mobile payment account (e.g., PIN number, security tokens, etc.).
  • In the absence of similar standards to those mentioned above, banks should avoid sending important documents or tools (e.g., alternative security tokens, etc.) to customers who have recently changed their mailing addresses, receiving these documents or tools specifically. The system user is committed in this case to personally collect them from one of the bank branches after verifying their identity according to the prevailing rules.
  • Conduct additional verification and inspection operations to verify the identity of the system user, regarding requests conducted via phone - calls received from customers only - to send new security tokens or any other important documents. An example of additional verification: asking the system user about information that changes from time to time, in addition to questions related to personal details in general (e.g., approximate account balances and the last transactions executed on the account).

17-3-3 When closing the account or terminating the contract for a mobile phone number, appropriate procedures must be put in place to ensure the withdrawal of electronic money units existing in the mobile phone account and to verify the identity of the withdrawer and document the account closure.

18-3-3 Banks are committed to providing a suitable immediate mechanism that enables the customer to inquire about their mobile phone accounts and request their closure electronically, through the following channels, without conflicting with Item 17-3-3:

  • The electronic application for the service.
  • The unregulated supplementary service data feature.


[RegAlert note: the English text above is a translation of the first 24,000 characters of a 97,872-character original (25% of the document). The remainder was not translated. The complete original-language text is stored with this document.]

More like this from CBE

CBE published 2 documents in the last 30 days. We email you each new one the day it's published.

Share