2022-04-27 | CBE12.3Added · Updated
The Central Bank of Egypt mandates that banks establish contractual, supervisory, and technical controls for cash deposit and withdrawal services provided by third-party service providers, including requirements for electronic fund guarantees, daily settlement within two business days, and strict data security standards. The regulation establishes interoperability rules via the National Switch, requiring banks to align their systems within 12 months, while prohibiting service providers from subcontracting without written consent or contracting with more than three issuing banks. It further enforces specific operational limits, transaction verification protocols, and consumer protection measures to mitigate fraud and ensure the integrity of electronic payment instruments.
These rules have been prepared to regulate cash deposit and withdrawal services through service providers within the Arab Republic of Egypt, and to establish standards aimed at increasing the spread of cash deposit and withdrawal points within the Arab Republic of Egypt, and limiting the associated risks, thereby ensuring tangible steps in the development of the electronic payments field in a secure and effective manner.
| Term | Definition |
|---|---|
| Accepting Bank | A bank affiliated with the Central Bank of Egypt authorized to accept customers' transactions/deposits/withdrawals. |
| Issuing Bank | A bank affiliated with the Central Bank of Egypt authorized to issue electronic payment instruments of various types, including commercial acceptance cards, to customers and to verify transactions and transfers carried out using payment instruments, and to ensure the compliance of these transactions with the regulatory rules issued by the Central Bank of Egypt. |
| Service Provider | Any of the financial institutions that the bank contracts with after approval by the Central Bank of Egypt to provide services related to the cash deposit and withdrawal mentioned in these rules. For example: Electronic payment instruments (Prepaid, Credit, Debit), Mobile Wallets, Wearable payment instruments. |
| Payment Instrument Company | The entity that grants banks the right to issue and operate electronic payment instruments using the commercial brand, owns the brand, and manages the electronic payment network and private settlement operations for these instruments, in compliance with the rules issued by the Central Bank of Egypt. |
| Cardholder | The unique identifier used for a specific financial transaction using an electronic payment instrument, requested by the user or as a means to confirm the user's identity. |
| Consumer Device | The PIN / and/or method (CDCVM - Consumer Device Cardholder Verification Method) whether the phone PIN or other user authentication biometrics during the transaction. For contactless transactions. |
| Penetration Testing | The test designed to discover vulnerabilities or weaknesses in the system structure or computer environment, and the tester may be an unauthorized person. |
| Service Level Agreement (SLA) | An agreement between the bank and the service provider that documents the level of services provided, priorities, responsibilities, service level, guarantees, adequacy of providing the service, and commitments of all parties. |
These rules and controls are the minimum required for banks to provide cash deposit and withdrawal services through service providers. All banks must not rely solely on this and must ensure taking all necessary measures regarding the management of risks associated with providing this type of service, without prejudice to regulatory controls and instructions, especially governance and rules regulating payment services using prepaid cards issued by the Central Bank of Egypt in May 2019 and all its amendments, as well as anti-money laundering and counter-terrorist financing regulatory controls issued in March 2020 and all its amendments.
The contract between the accepting bank and service providers must include at least the following:
The accepting bank must activate an electronic system dedicated to the following:
The accepting bank must hold a financial guarantee from deposit service providers to secure transactions executed through them. This guarantee must be equal to or greater than the value collected daily through deposit service providers. This guarantee must be periodically re-evaluated, and under no circumstances should the value of transactions collected by deposit service providers exceed the guarantee held with the bank.
Deposit service providers are committed to providing the cash proceeds to the accepting bank within the next business day, and at the latest within two business days from the date of the transaction. The bank must impose late fees on deposit service providers for each additional business day, and this must be stipulated in the contract.
The accepting bank must verify the financial standing of the service providers contracted with the bank for cash withdrawal/deposit services to customers, ensuring, for example but not limited to:
The bank must set daily, weekly, and monthly maximum limits for the number and value of transactions executed by the service provider according to the bank's risk classification, without conflicting with the limits established for withdrawal and deposit by the Central Bank.
Regarding the use of electronic Point of Sale (POS) terminals for verifying electronic payment instruments: The bank must comply with the following:
Transactions deposited by customers include, for example but not limited to:
In case any transaction is rejected by the bank, the issuing bank of the electronic payment instrument, the bank and service providers are committed to notifying the customer of the rejection and returning the transaction amount via the same method/channel used by the customer.
The service provider is not allowed to contract with more than three accepting banks as a maximum limit regarding cash deposit and withdrawal services for electronic payment instruments.
All transactions are restricted to the Egyptian Pound currency only.
Continuous monitoring by the bank of the number of disputes received on cash withdrawal channels for service providers, and stopping the service in case of repeated disputes on collection/cash withdrawal transactions from a specific merchant.
The bank must take necessary measures to verify the customer's identity before starting the deposit/withdrawal process.
The bank must match the amounts added through service providers with the transaction details sent by them.
Clear rules for the customer regarding all service conditions, limitations, and associated fees.
Rules stipulating the acceptance or rejection of partial collection of debts.
Printing a receipt/statement (paper/electronic) for the cash deposit/withdrawal transaction containing at least the following data:
All issuing and accepting banks of electronic payment instruments must apply interoperability rules for deposit/withdrawal operations using electronic payment instruments (electronic payment cards/mobile wallets) as follows:
Providing necessary support by the bank and service providers to respond to customer complaints and inquiries and raise awareness of their use.
Clear rules for dispute resolution to be used with customer complaints according to the instructions for protecting bank customers' rights issued by the Central Bank of Egypt in February 2019.
The service provider is not permitted to contract with other companies (third parties) as subcontractors to perform tasks entrusted to them by the bank through this contract, except with the bank's written consent and with a list of tasks assigned by the service provider to third parties.
The bank must review all transactions and ensure there are no signs of fraudulent operations / money laundering operations.
Compliance with any rules or amendments issued by the Central Bank of Egypt regarding service providers or outsourcing services.
Observance of Basel rules related to outsourcing banking services (assigning services to others).
Compliance with what is stated in clause 3-2-2-2 of the Rules Regulating the Provision of Payment Services via Mobile Phones in the Banking Sector.
The bank must suspend the service(s) provided through service providers in case the service providers violate any service performance conditions.
Accepting banks must ensure the training of service provider employees to enhance their competence before engaging in the activity, and providing them with any updates. Training must include at least the following:
The bank must secure the process of exchanging files or data between service providers and the bank, ensuring that files or data are encrypted and the exchange is conducted through one of the following channels:
Providing cash deposit/withdrawal services through service providers involves the exchange of sensitive data - such as card numbers and financial transactions... etc. - through the bank's internal and external networks. Therefore, banks must use appropriate methods to maintain the confidentiality and integrity of information exchanged through the bank's internal and external networks.
Encryption technology is used to protect the confidentiality and integrity of sensitive information. Banks must choose encryption technology and protection programs suitable for the sensitivity and importance of the information and the required level of protection. In this context, banks are always advised to adopt encryption technology that uses internationally recognized encryption methods with no known vulnerabilities or weaknesses, as the strengths of these methods are subject to comprehensive tests. Banks should apply best practices for managing the encryption keys necessary to protect these keys.
Banks must also ensure... [Text ends abruptly in source]
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 28,200-character original (85% of the document). The remainder was not translated. The complete original-language text is stored with this document.]