2022-04-27 | CBE12.6

Added · Updated

CBE Regulation Book 12.6 - Standards For Issuing And Accepting Contactless Electronic Payments

The Central Bank of Egypt establishes standards for the issuance and acceptance of contactless electronic payments, setting a maximum transaction limit of 300 Egyptian pounds for password-free transactions. The regulation mandates specific risk management, anti-money laundering, and cybersecurity obligations for banks, including mandatory SMS notifications for transactions exceeding 100 Egyptian pounds and strict tokenization security protocols. It further requires that contactless payment devices comply with ISO/IEC 7816 and ISO/IEC 14443 standards, prohibits obtaining customer signatures for transactions, and mandates the use of unique encryption keys and specific consumer device verification methods.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Chapter Six: Standards for Issuing and Accepting Contactless Electronic Payments

1. Introduction

In light of the interest the Central Bank of Egypt attaches to supporting and encouraging the use of electronic payment means and channels, with the aim of reducing reliance on cash, and given the current technological development towards transforming into a cashless society and transforming the financial transaction field into electronic payments, and the emergence of Contactless Payments, and the need to keep pace with this development to ensure safe steps in the field of electronic payments in a manner that benefits all parties involved in the electronic payment process, the following rules have been issued.

TermDefinition
GeneralNear Field Communication (NFC): A technology that enables devices and data to communicate with each other at a distance not exceeding 4 cm.
Contactless PaymentsPayments made without the need to use the power source of the payment device itself, such as the battery of a smart device, or wearable devices.
Secure Code / TokenThe code issued to the merchant, whether it is a static code or a dynamic code, whether it is issued to the merchant or to the device itself (Secure Code Token), and also as an additional security key that can be used in the case of using the device itself for transactions.
Dual Interface EMV NFCRefers to the contactless interface that uses the power source of the payment device.
Dual Interface POS TerminalsRefers to the contactless interface used in the transaction process.
CollisionRefers to the interference between contactless payment devices in the case of the presence of many payment devices in the same space.

1.1 Scope of Rules

  • These rules apply to all public banks in the Arab Republic of Egypt and branches of foreign banks, and constitute the minimum mandatory standard for providing contactless payment services in a secure manner, and to all banks that do not limit themselves to this but ensure taking all necessary measures to manage the risks associated with providing this type of banking services.

  • These rules regulate the issuance and acceptance of contactless payments, without prejudice to the supervisory controls for electronic banking institutions previously issued by the Central Bank of Egypt, as well as the directives and rules regarding the implementation of banking transactions and anti-money laundering and counter-terrorism financing controls issued by the Central Bank of Egypt, and due diligence procedures issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.

1.2 Responsibilities and Obligations of the Board of Directors and Senior Management

  • The Board of Directors is responsible for approving the work strategy prepared by the Bank's senior management, as well as making a clear strategic decision regarding the Bank's desire to provide payment services using contactless electronic payments. In particular, the Board of Directors must ensure the following:
    • The availability of payment service plans using contactless cards aligns with the Bank's strategic objectives.
    • Managing the risks associated with these services.
    • Preparing appropriate procedures to monitor and mitigate risks.
    • Continuous review of the results of providing contactless payment services and their alignment with the specified plans and objectives.
    • The Bank establishing a risk policy regarding participating entities in the service and studying risks associated with:
      • Refunds.
      • Fraud.
      • Disputes.

1.3 Anti-Money Laundering, Counter-Terrorism Financing, and Information Security Rules

  • Banks issuing and accepting contactless payment means must implement the following:
    • Compliance with the Anti-Money Laundering Law No. 80 of 2002 and its executive regulations, and the supervisory controls for banks regarding anti-money laundering and counter-terrorism financing and customer identification rules issued in 2011, and all amendments thereto from the Central Bank of Egypt, as well as due diligence procedures for prepaid card payment services issued in March 2019 by the Anti-Money Laundering and Counter-Terrorism Financing Unit.
    • Exercising sufficient care regarding transactions that may involve money laundering or terrorism financing, in light of the supervisory controls for banks regarding anti-money laundering and counter-terrorism financing issued by the Central Bank of Egypt in 2008.
    • In case of suspicion of transactions conducted through these means, reporting to the Anti-Money Laundering and Counter-Terrorism Financing Unit in accordance with the provisions of the Anti-Money Laundering Law No. 80 of 2002.
    • Compliance with any directives issued subsequently by the Central Bank of Egypt regarding electronic payment cards of all types and means of using/accepting contactless payments.
    • Necessity of notifying the Bank's Information Administration via the email infosec.cbe@eg.org.cbe and the Cybersecurity Administration via team.csirc.eg.org.cbe and the Supervision and Inspection Sector immediately of any data breach incidents concerning the service.

1.4 Rules for Issuing Contactless Payment Means

  • Regarding banks issuing contactless payment means, the maximum limit for a single transaction performed without entering a PIN (Go & Tap) is 300 Egyptian pounds, with each bank setting its own appropriate limit not exceeding the maximum limit authorized by the Central Bank of Egypt for transactions performed without entering a PIN. The Central Bank of Egypt reserves the right to modify the maximum limit for transactions performed without entering a PIN.

  • The bank must establish a mechanism for handling disputes concerning this type of transactions.

  • The bank must set maximum limits for the number of daily and monthly transactions, in light of the Bank's risk management administration.

  • The issuing bank must send an SMS message immediately upon completion of any transaction exceeding 100 Egyptian pounds for contactless payments.

  • Contactless payment devices must not be activated before being delivered to the customer. Activation occurs immediately upon confirming the customer's acceptance of the contactless payment device from the issuing bank, by placing the mechanism for converting the customer's acceptance.

  • It is necessary to have the required awareness campaigns by the bank for customers on how to deal with contactless payment devices provided by the bank.

In the case where the contactless payment tool is an electronic payment card:

  • Such cards (Dual contactless EMV Interface) must be compatible with international standards ISO/IEC 7816 and ISO/IEC 14443.
  • The bank may use card blocking sleeves for this type of card to protect the customer and the bank from fraud resulting from the theft of card data using devices dedicated for that purpose.
  • It is necessary to activate the Secure Code service on transactions performed using such cards via the internet (Card Present Not Card).
  • It is necessary to have a unique signature for contactless cards.
  • The bank must ensure, during the card personalization phase, the existence of a unique encryption key for each issued card, using encryption techniques approved by the card scheme organizations. The Static Data Authentication (SDA) method must not be used. One of the following methods may be used:
    • Dynamic Data Authentication (DDA)
    • Combined Data Authentication (CDA)
  • The validity period of the card is 5 years at most.

In the case of using a mobile phone (NFC Payment) or any other devices (Wearable / non-wearable) containing the Contactless feature:

  • It must be ensured that the issuing bank's systems are capable of handling and distinguishing incoming transactions using different Consumer Device Cardholder Verification Methods (CDCVM).
  • The conversion mechanism for the customer (CDCVM) can be:
    • PIN.
    • Mobile Phone Passcode.
    • User Biometric Authentication (e.g., eye/face/hand/voice fingerprint).
  • It is necessary to contract with a Tokenization Service Provider and a Tokenization Hub in cooperation and under the supervision of the commercial card scheme organizations.
  • In all cases, the Central Bank of Egypt's approval must be obtained before relying on any Tokenization Service Provider or Tokenization Hub.

1.5 Rules for Accepting Contactless Payments

  • Regarding banks accepting contactless payment means (Go & Tap), the maximum limit for a single transaction performed without entering a PIN is 300 Egyptian pounds. The Central Bank of Egypt reserves the right to modify the maximum limit for transactions performed without entering a PIN.

  • It is recommended that Point of Sale (POS) terminals accepting such cards support Dual Interface POS Terminals.

  • It is necessary to follow international standards ISO/IEC 14443 and ISO/IEC 7816 in the communication means for contactless transactions between the contactless payment device and the electronic Point of Sale terminal.

  • It is necessary to have a unique signature for machines accepting payment using contactless devices.

  • It must be ensured that electronic Point of Sale terminals operating with this feature are placed facing the customer and away from any source of electricity or other metal source that may affect the signals, such that the maximum distance between the contactless payment device and the machine to complete the transaction is 4 cm at most.

  • Obtaining the customer's signature on any transaction is not allowed, except for transactions performed using contactless payment devices issued from outside the Arab Republic of Egypt.

  • It is necessary to have the required awareness campaigns by the bank for merchants on how to deal with different types of contactless payment devices.

  • The bank must establish procedures that ensure the non-repetition of transactions with the customer by the merchant's electronic Point of Sale terminals in an incorrect manner.

  • The electronic Point of Sale terminal must refuse the transaction in the case of the presence of more than one contactless payment device close to the machine (Collision), in order to ensure that the holder of the contactless payment device does not pay with the wrong device during the transaction process.


[RegAlert note: the English text above is a translation of the first 24,000 characters of a 29,028-character original (83% of the document). The remainder was not translated. The complete original-language text is stored with this document.]

More like this from CBE

CBE published 2 documents in the last 30 days. We email you each new one the day it's published.

Share