2021-09-28 | Resolução BCB 147Added
This resolution amends the regulation governing the Pix payment arrangement by introducing mandatory risk management obligations for participants, including liability for fraud resulting from risk management failures and requirements for non-discriminatory treatment of participants. It establishes a framework for the precautionary blocking of funds in cases of suspected fraud, limiting such blocks to a maximum of 72 hours and restricting their application to natural person users (excluding individual entrepreneurs). The text also introduces new provisions for security-related key consultations, fraud notification procedures, and the future availability of scheduled Pix and payment initiation services under the Open Banking framework, with specific articles taking effect immediately and others on November 16.
BCB published 18 documents in the last 30 days — get each new one by email the day it lands.
Resolution No. 147
BCB RESOLUTION NO. 147, OF SEPTEMBER 28, 2021
Amends the Regulation attached to BCB Resolution No. 1, of August 12, 2020, which regulates the operation of the Pix payment arrangement.
The Collegiate Board of Directors of the Central Bank of Brazil, in a session held on September 28, 2021, based on Article 10, item IV, of Law No. 4.595, of December 31, 1964, Article 10 of Law No. 10.214, of March 27, 2001, Articles 6, 7, 9, 10, 14, and 15 of Law No. 12.865, of October 9, 2013, Resolution No. 4.282, of November 4, 2013, Communication No. 32.927, of December 21, 2018, and Communication No. 34.085, of August 28, 2019,
RESOLVES:
Article 1. The Regulation attached to BCB Resolution No. 1, of August 12, 2020, shall enter into force with the following amendments:
“Article 32. ..........................................................................................................
.........................................................................................................................
V - be responsible for fraud within the scope of Pix arising from failures in its risk management mechanisms, including the non-observance of risk management measures defined in this Regulation and in complementary normative devices;
VI - provide non-discriminatory treatment for the different Pix participants with whom they establish a relationship for the provision of the service, in terms of service quality and price; and
VII - use information linked to Pix keys for the security of Pix, as provided in §§ 1 and 2 of Article 59, as one of the factors to be considered for the authorization and rejection of transactions within the scope of Pix.” (NR)
“Article 37. ..........................................................................................................
§ 1. The Central Bank of Brazil will publish a specific document with provisions regarding the establishment of limits by participants, including:
I - the payment instruments that can be used as a parameter and benchmark for setting value limits;
II - the offering of functionality for management, by end users, of limits, beneficiaries, and periods for carrying out transactions; and
III - the parameters for requesting changes to the established limits, beneficiaries, and periods for carrying out transactions.
................................................................................................................”
(NR)
“Article 39-B. Funds originating from a transaction within the scope of Pix must be precautionarily blocked by the payment service provider participant of the receiving user when there is suspicion of fraud.
§ 1. The assessment of suspicion of fraud must include:
I - the number of infraction notifications linked to the receiving user, their Pix key, and their transactional account number;
II - the time elapsed since the opening of the transactional account by the receiving user;
III - the time and day the transaction was carried out;
IV - the profile of the paying user, including regarding the recurrence of transactions between users; and
V - other factors, at the discretion of each participant.
§ 2. The precautionary block must be implemented simultaneously with the credit in the transactional account of the receiving user.
§ 3. The payment service provider participant must immediately notify the receiving user of the implementation of the precautionary block.
§ 4. The precautionary block shall last for a maximum of 72 hours.
§ 5. During the period in which the funds are precautionarily blocked, the payment service provider participant of the receiving user must evaluate whether there are indications that substantiate the suspicion of fraud.
§ 6. Upon completion of the assessment referred to in § 5:
I - the funds shall be returned to the paying user, in accordance with the Special Return Mechanism, provided for in Section II of Chapter XI, if a well-founded suspicion of fraud in the transaction is identified; or
II - the precautionary block of the funds shall cease immediately, with the receiving user being promptly notified, in cases where no indications of fraud in the transaction are identified.
§ 7. The precautionary block may only be implemented in transactional accounts of natural person users, excluding individual entrepreneurs.
§ 8. The possibility of carrying out the precautionary block referred to in this article must be included in the contract signed between the receiving user and the corresponding payment service provider, through a prominent clause in the body of the contractual instrument, or by another valid legal instrument.
§ 9. The receiving user may request the return of the Pix in an amount corresponding to the value of the original transaction while the funds are precautionarily blocked.” (NR)
“Article 41-C. .......................................................................................................
I - on its own initiative, if the allegedly fraudulent conduct or operational failure occurred within its systems, or after precautionary block, if the participant assesses that the transaction has a well-founded suspicion of fraud; or
................................................................................................................”
(NR)
“Article 54. ..........................................................................................................
.........................................................................................................................
IX - verification of registered Pix keys: allows verifying if a specific Pix key is registered in the DICT;
X - request for return: allows the request for the return of a Pix transaction; and
XI - consultation of information linked to Pix keys for the security of Pix.” (NR)
“Article 59.
..........................................................................................................
.........................................................................................................................
§ 1. The DICT may, at the discretion of the Central Bank of Brazil, store other information for security and proper functioning purposes of Pix.
§ 2. The information linked to Pix keys for the security of Pix referred to in § 1 will be detailed in the DICT Operational Manual.” (NR)
“Article 60.
..........................................................................................................
Sole Paragraph. ..............................................................................................
.........................................................................................................................
II - suspicion, attempt, or effective use of the Pix key fraudulently; or
III - identification of the need for adjustment after a key synchronization verification process, as provided in Subsection VI of this Section.” (NR)
“Article 78-F. The infraction notification must be requested by the payment service provider participant of the paying user or by the payment service provider participant of the receiving user whenever there is a well-founded suspicion of the use of the arrangement for the practice of fraud.
Sole Paragraph. The infraction notification may be requested for transactions:
I - settled in the SPI;
II - settled in the participant's own systems; or
III - rejected due to well-founded suspicion of fraud.” (NR)
“Subsection XI
Of the consultation of information linked to Pix keys for the security of Pix
Article 78-K. The consultation of information linked to Pix keys for the security of Pix must be carried out for the purpose of feeding the participants' fraud analysis mechanisms, including in processes not directly related to Pix.
Article 78-L. The consultation of information linked to Pix keys for the security of Pix must be carried out exclusively on the initiative of the participant itself, and the availability of the functionality to end users is prohibited.
Article 78-M. The DICT will return exclusively the information registered for the security purposes of Pix.” (NR)
“Article 84-A. Pix participants must maintain mechanisms that prevent reading attacks by their clients to the DICT, which must be, at a minimum, equal to the reading attack prevention mechanisms existing in the DICT and detailed in the DICT Operational Manual.” (NR)
“Article 84-B. Pix participants must establish a procedure for identifying and treating cases of excessive queries of Pix keys by their clients, which:
I - do not result in settlement; and
II - are not registered in the DICT.” (NR)
“Article 95-A.
.......................................................................................................
.........................................................................................................................
§ 4. The precautionary suspension may be applied to a single component of Pix, if the conduct generating the suspension is putting at risk only aspects related to that component.” (NR)
“Article 101-D. The following may be made available, in accordance with the schedule established within the Open Banking regulatory framework:
I - the request for a Scheduled Pix to a participant providing payment transaction initiation services, in accordance with Article 9, item II;
II - the initiation of a Pix through a dynamic QR Code or a static QR Code via a payment transaction initiation service; and
III - the initiation of a Pix through a payment transaction initiation service, in cases where the participant has all the information of the receiving user, as provided in item IV of Article 12.” (NR)
Article 2. The following provisions of the Regulation attached to BCB Resolution No. 1, of 2020, are revoked:
I - the sole paragraph of Article 59;
II - item IV of the sole paragraph of Article 60; and
III - Articles 101-E and 101-F.
Article 3. This Resolution enters into force on the date of its publication, producing effects:
I - immediately, for the alteration in Article 37 of the Regulation attached to BCB Resolution No. 1, of 2020; and
II - from November 16, for the remaining provisions.
João
Manoel Pinho de Mello
Director of Organization of the Financial System and Resolution
Read the rest free
Source: Banco Central do Brasil — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BCB
BCB published 18 documents in the last 30 days. We email you each new one the day it's published.