2022-04-27 | CBE12.3

Added · Updated

CBE Regulation Book 12.3 - Rules Regulating The Interoperability Of Cash Deposit And Withdrawal Services Through Service Providers

The Central Bank of Egypt mandates that banks establish contractual, supervisory, and technical controls for cash deposit and withdrawal services provided by third-party service providers, including requirements for electronic fund guarantees, daily settlement within two business days, and strict data security standards. The regulation establishes interoperability rules via the National Switch, requiring banks to align their systems within 12 months, while prohibiting service providers from subcontracting without written consent or contracting with more than three issuing banks. It further enforces specific operational limits, transaction verification protocols, and consumer protection measures to mitigate fraud and ensure the integrity of electronic payment instruments.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Chapter Three: Rules Regulating The Interoperability Of Cash Deposit And Withdrawal Services Through Service Providers

-1 Introduction

These rules have been prepared to regulate cash deposit and withdrawal services through service providers within the Arab Republic of Egypt, and to establish standards aimed at increasing the spread of cash deposit and withdrawal points within the Arab Republic of Egypt, and limiting the associated risks, thereby ensuring tangible steps in the development of the electronic payments field in a secure and effective manner.

-2 General Definitions

TermDefinition
Accepting BankA bank affiliated with the Central Bank of Egypt authorized to accept customers' transactions/deposits/withdrawals.
Issuing BankA bank affiliated with the Central Bank of Egypt authorized to issue electronic payment instruments of various types, including commercial acceptance cards, to customers and to verify transactions and transfers carried out using payment instruments, and to ensure the compliance of these transactions with the regulatory rules issued by the Central Bank of Egypt.
Service ProviderAny of the financial institutions that the bank contracts with after approval by the Central Bank of Egypt to provide services related to the cash deposit and withdrawal mentioned in these rules. For example: Electronic payment instruments (Prepaid, Credit, Debit), Mobile Wallets, Wearable payment instruments.
Payment Instrument CompanyThe entity that grants banks the right to issue and operate electronic payment instruments using the commercial brand, owns the brand, and manages the electronic payment network and private settlement operations for these instruments, in compliance with the rules issued by the Central Bank of Egypt.
CardholderThe unique identifier used for a specific financial transaction using an electronic payment instrument, requested by the user or as a means to confirm the user's identity.
Consumer DeviceThe PIN / and/or method (CDCVM - Consumer Device Cardholder Verification Method) whether the phone PIN or other user authentication biometrics during the transaction. For contactless transactions.
Penetration TestingThe test designed to discover vulnerabilities or weaknesses in the system structure or computer environment, and the tester may be an unauthorized person.
Service Level Agreement (SLA)An agreement between the bank and the service provider that documents the level of services provided, priorities, responsibilities, service level, guarantees, adequacy of providing the service, and commitments of all parties.

-3 Scope of Rules

These rules and controls are the minimum required for banks to provide cash deposit and withdrawal services through service providers. All banks must not rely solely on this and must ensure taking all necessary measures regarding the management of risks associated with providing this type of service, without prejudice to regulatory controls and instructions, especially governance and rules regulating payment services using prepaid cards issued by the Central Bank of Egypt in May 2019 and all its amendments, as well as anti-money laundering and counter-terrorist financing regulatory controls issued in March 2020 and all its amendments.

-4 General Rules for Banks Regarding the Use of Service Providers

1-4 Contractual Controls for Service Providers:

The contract between the accepting bank and service providers must include at least the following:

  • Clear determination of contractual responsibilities of the bank and the service provider, for example, clearly defining responsibilities for providing information to the service provider and receiving it from them.
  • Clauses specifying the bank's ownership of its customers' data and the service provider's commitment to maintain the confidentiality of such data and not disclose or use it except within the scope of the contract with the bank or for legitimate legal reasons.
  • A Non-Disclosure Agreement (NDA) with external parties.
  • A Service Level Agreement (SLA) which includes, for example but not limited to: defining roles and responsibilities, the time required to execute the service, escalation procedures and data, and penalties in case of non-compliance.
  • Clauses preserving the bank's right to audit services periodically or rely on approved audit reports (issued by approved audit entities).
  • Clauses specifying the bank's/Central Bank of Egypt's right to supervise the service provider's performance and the frequency thereof, ensuring the activation of inspection missions at the service provider's premises and systems to verify that the rules of work followed are compatible with the rules issued by the Central Bank of Egypt and the bank, and requiring the inclusion of this in the contract between the bank and service providers.
  • Termination/cancellation procedures must be effective, ensuring the continuity of business, data integrity, transfer, and disposal.
  • Determination of rules and conditions for dispute resolution.

2-4 Supervisory Controls:

  • The accepting bank must activate an electronic system dedicated to the following:

    • The bank must have a system allowing it full control over accepting/rejecting cash deposit transactions based on the service provider's balance with the bank in real-time (Online). The bank must stop the collection/withdrawal service if there is insufficient balance in the service provider's account with the bank from which deductions are made.
    • Deductions/additions to the service provider's balance must occur instantly for each customer collection/cash withdrawal transaction.
    • The bank must reject cash deposit transactions if there is no balance in the service provider's account with the bank.
  • The accepting bank must hold a financial guarantee from deposit service providers to secure transactions executed through them. This guarantee must be equal to or greater than the value collected daily through deposit service providers. This guarantee must be periodically re-evaluated, and under no circumstances should the value of transactions collected by deposit service providers exceed the guarantee held with the bank.

  • Deposit service providers are committed to providing the cash proceeds to the accepting bank within the next business day, and at the latest within two business days from the date of the transaction. The bank must impose late fees on deposit service providers for each additional business day, and this must be stipulated in the contract.

  • The accepting bank must verify the financial standing of the service providers contracted with the bank for cash withdrawal/deposit services to customers, ensuring, for example but not limited to:

    • The service provider does not engage in any fraudulent activities, such as handing over counterfeit paper money to customers.
    • The service provider does not store any data related to electronic payment instruments.
    • The service provider adheres to specified currencies.
  • The bank must set daily, weekly, and monthly maximum limits for the number and value of transactions executed by the service provider according to the bank's risk classification, without conflicting with the limits established for withdrawal and deposit by the Central Bank.

  • Regarding the use of electronic Point of Sale (POS) terminals for verifying electronic payment instruments: The bank must comply with the following:

    • If there is more than one application on electronic POS terminals, there must be a strict separation between applications used by the service provider dealing with electronic payment instrument data and applications dealing with service data, so that the service provider cannot know data of a special nature (e.g., electronic payment card data), while allowing interaction with the electronic payment instrument number in an encrypted manner or via a specific reference. The electronic payment application must be approved by the accepting bank and the National Switch (Egyptian Banks Company for Technological Advancement).
    • The accepting bank is fully responsible for the electronic POS terminal and all operations conducted through it.
    • Ensure that a single electronic POS terminal is responsible for only one accepting bank.
    • If there is only one application on the electronic POS terminals for the service provider, the accepting bank must comply with the necessary tests for the software used and approve it.
    • The accepting bank must ensure that all electronic POS terminals used by the service provider possess the following:
      • Payment Card Industry Data Security Standard (PCI DSS) certification.
      • PIN Transaction Security (PCI PTS) certification according to global standards.
      • Approval by EMVCO.
    • In case of deposit/withdrawal from electronic payment instruments, the identity of the holder of the electronic payment instrument must be verified electronically. This can be done by swiping the electronic payment instrument through the service provider's POS terminal and entering the electronic payment instrument PIN correctly.
    • In case of cash withdrawal, the PIN / verification method for the electronic payment instrument must be entered, whether contact or contactless.
    • The electronic POS machine must display the amount before executing the cash deposit/withdrawal transaction on the bank card on the same screen where the customer enters the PIN for the electronic payment instrument.
    • Compliance with all rules issued by the Central Bank of Egypt regarding electronic POS terminals.

3-4 General Controls:

  • Transactions deposited by customers include, for example but not limited to:

    • Credit card debts.
    • Deposit into Direct Debit and Prepaid cards.
    • Deposit into mobile wallets.
  • In case any transaction is rejected by the bank, the issuing bank of the electronic payment instrument, the bank and service providers are committed to notifying the customer of the rejection and returning the transaction amount via the same method/channel used by the customer.

  • The service provider is not allowed to contract with more than three accepting banks as a maximum limit regarding cash deposit and withdrawal services for electronic payment instruments.

  • All transactions are restricted to the Egyptian Pound currency only.

  • Continuous monitoring by the bank of the number of disputes received on cash withdrawal channels for service providers, and stopping the service in case of repeated disputes on collection/cash withdrawal transactions from a specific merchant.

  • The bank must take necessary measures to verify the customer's identity before starting the deposit/withdrawal process.

  • The bank must match the amounts added through service providers with the transaction details sent by them.

  • Clear rules for the customer regarding all service conditions, limitations, and associated fees.

  • Rules stipulating the acceptance or rejection of partial collection of debts.

  • Printing a receipt/statement (paper/electronic) for the cash deposit/withdrawal transaction containing at least the following data:

    • Transaction amount.
    • Date and time of the transaction.
    • Transaction channel.
    • Success/Failure of the transaction.
  • All issuing and accepting banks of electronic payment instruments must apply interoperability rules for deposit/withdrawal operations using electronic payment instruments (electronic payment cards/mobile wallets) as follows:

    • The Egyptian Banks Company for Technological Advancement acts as the National Switch.
    • The National Switch makes deposit/withdrawal services available for electronic payment instruments and approves the systems used.
    • Withdrawal/deposit operations for electronic payment instruments for customers are executed instantly, and settlements between banks are carried out according to rules issued by the National Switch.
    • Connection with the National Switch using standard messages approved by the National Switch for sending and receiving.
    • Compliance with interoperability rules issued by the National Switch and approved by the Central Bank of Egypt.
    • Compliance with dispute resolution rules issued by the National Switch, noting that the National Switch's records are conclusive evidence provided there is no system failure and complete records of the disputed transactions exist, which are secured and cannot be modified or altered, and have legal authority.
    • Compliance with exchange rates issued by the National Switch regarding these transactions.
    • All banks are committed to aligning their status with the interoperability rules within a grace period not exceeding 12 months from the date of issuance of the rules.
  • Providing necessary support by the bank and service providers to respond to customer complaints and inquiries and raise awareness of their use.

  • Clear rules for dispute resolution to be used with customer complaints according to the instructions for protecting bank customers' rights issued by the Central Bank of Egypt in February 2019.

  • The service provider is not permitted to contract with other companies (third parties) as subcontractors to perform tasks entrusted to them by the bank through this contract, except with the bank's written consent and with a list of tasks assigned by the service provider to third parties.

  • The bank must review all transactions and ensure there are no signs of fraudulent operations / money laundering operations.

  • Compliance with any rules or amendments issued by the Central Bank of Egypt regarding service providers or outsourcing services.

  • Observance of Basel rules related to outsourcing banking services (assigning services to others).

  • Compliance with what is stated in clause 3-2-2-2 of the Rules Regulating the Provision of Payment Services via Mobile Phones in the Banking Sector.

  • The bank must suspend the service(s) provided through service providers in case the service providers violate any service performance conditions.

  • Accepting banks must ensure the training of service provider employees to enhance their competence before engaging in the activity, and providing them with any updates. Training must include at least the following:

    • Products and services assigned by the bank to the service provider.
    • Protection of customer information and handling complaints.
    • Fraud detection mechanisms, including counterfeit money detection.
    • Anti-money laundering and counter-terrorist financing procedures.
    • System operation, error detection, and repair.
    • Dispute processing and settlement.
    • Procedures and mechanism for reporting fraudulent and suspicious operations to the bank.

-5 Information Confidentiality and Integrity

  • The bank must secure the process of exchanging files or data between service providers and the bank, ensuring that files or data are encrypted and the exchange is conducted through one of the following channels:

    • Leased Line.
    • Virtual Private Network (VPN).
  • Providing cash deposit/withdrawal services through service providers involves the exchange of sensitive data - such as card numbers and financial transactions... etc. - through the bank's internal and external networks. Therefore, banks must use appropriate methods to maintain the confidentiality and integrity of information exchanged through the bank's internal and external networks.

  • Encryption technology is used to protect the confidentiality and integrity of sensitive information. Banks must choose encryption technology and protection programs suitable for the sensitivity and importance of the information and the required level of protection. In this context, banks are always advised to adopt encryption technology that uses internationally recognized encryption methods with no known vulnerabilities or weaknesses, as the strengths of these methods are subject to comprehensive tests. Banks should apply best practices for managing the encryption keys necessary to protect these keys.

  • Banks must also ensure... [Text ends abruptly in source]


[RegAlert note: the English text above is a translation of the first 24,000 characters of a 28,200-character original (85% of the document). The remainder was not translated. The complete original-language text is stored with this document.]

More like this from CBE

CBE published 2 documents in the last 30 days. We email you each new one the day it's published.

Share