2024-03-28

Added · Updated

Circular dated March 28, 2024 regarding controls for updating customer data

The Central Bank of Egypt mandates that banks standardize customer data update procedures, requiring notification via at least two channels three times before and after the deadline, while prohibiting the suspension of specific services such as check cashing, deposits, and transfers during this process. Banks are forbidden from charging fees for late updates, must allow updates at any branch, permit home visits for elderly or disabled customers, and are granted a three-month grace period to implement these measures.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Dear Sir / Chairman of the Board of Directors

Tahya Misr Bank and after,

With reference to the Circular Letter dated December 24, 2023, regarding the regulatory controls for banks concerning the fight against money laundering and terrorist financing, which included a clause requiring the bank to continuously update customer data, information, and documents obtained when applying due diligence procedures, with a maximum period of five years, and in the context of monitoring the procedures implemented by banks when updating their customers' data, it became necessary to unify these procedures across the banking sector to enhance the protection of customers' rights.

In light of the above and working to establish a unified regulatory framework for the procedures taken by banks when updating their customers' data, the Board of Directors of the Central Bank of Egypt, in its meeting held on March 19, 2024, approved the following decision:

Banks must adhere to the following when updating the data, information, and documents obtained when applying due diligence procedures for individuals and companies:

  1. Include in the bank's internal policies the procedures to be taken in accordance with these controls, which must include at a minimum the maximum time period for the bank to update its customers' data after collecting the required data, information, and documents, as well as reactivating products and services that were suspended.

  2. Notify customers of the update date before and after its due date using the various communication channels prescribed by the customer, as follows:

    1. Use at least two different channels from the following to notify customers, while observing information security controls and operational risk assessment:
      1. Short messages via mobile phone in Arabic and English.
      2. Notifications used on mobile phone applications (Push notifications), as well as other electronic channels such as internet banking and ATMs.
      3. Email.
      4. Phone calls through the bank's call centers.
      5. Registered letters.
    2. Notify customers three times before the update due date, over three consecutive months (once a month), regarding the update date.
    3. Notify customers three times after the update due date, over three consecutive months (once a month), regarding the procedure to be taken after the expiration of that period and its implementation date in case customers fail to perform the required update.
    4. Notify customers of the measures taken after the expiration of the period mentioned in item 3.
  3. In all cases, the following products and services must not be suspended:

    1. Cashier and collection of checks.
    2. Cash deposit operations on customers' accounts by third parties within the branch.
    3. Incoming transfers to customers' accounts.
    4. Cash withdrawal or electronic purchases using direct debit cards.
    5. Standing instructions.
    6. Repayment of obligations for credit facilities granted to customers by the bank itself.
    7. Balance inquiries.
    8. Internet banking services, mobile payment services, and other electronic channels, within the scope of items 6 and 7.
  4. Do not charge customers any expenses or fees in case of their delay in updating.

  5. If customers are present at the bank branch, the update must be performed before conducting any transactions.

  6. Do not send any links to customers except for updating their data or notifying them of the update to avoid fraud operations.

  7. Update the bank's database system to reflect the customer data update date, so that customer service employees can notify customers of the update date.

  8. The bank must apply to the Central Bank of Egypt for approval before activating technical solutions for updating customer data via electronic means.

  9. Customers must be able to update their data through any of the bank's branches - including its branches abroad (if any) - without being required to go to their dealing branch.

  10. Allow home visits for people with disabilities and the elderly (65 and above) by bank employees to perform the update, with the necessity of establishing controls and procedures for these visits.

  11. Banks may put in place incentive programs and procedures for customers to encourage them to update at the prescribed dates.

  12. Banks are granted a grace period of no more than three months from the date of issuance of these instructions to regularize their status.

Please be so kind as to direct compliance with the above.

Accept our highest regards,

Hassan Abdallah