2023-03-08
Added · Updated
The Central Bank of Egypt mandates that all banks and licensed token service providers operating in Egypt adhere to specific rules for tokenization services on electronic device applications, establishing minimum risk management standards and compliance requirements. The regulations define the roles of key entities, including the Unified Issuer TSP Interface managed by Misr Banks Company, and impose obligations on issuer banks, acquirer banks, and card networks regarding security, anti-money laundering, and operational integrity. Banks are required to implement robust cybersecurity measures, conduct regular penetration testing, and maintain strict controls over token provisioning and transaction verification.
$$\gamma\cdot\gamma\gamma\omega\gamma\lambda\wedge\ldots\lor\lambda\lor\lambda\Delta\phi$$
Dear Professor / Bank Tahya, greetings,
In light of the interest the Central Bank of Egypt attaches to strengthening the banking sector's infrastructure and encouraging the use of new electronic payment instruments for customers to execute various electronic banking transactions, and since card tokenization services on electronic device applications contribute to enabling a large number of citizens to access banking services efficiently and effectively, thereby achieving the independence of national payment systems and keeping pace with the latest technologies used globally in payment systems and services, and thus expanding the umbrella of using payment means and banking channels.
In this regard, please be informed of the approval by the Board of Directors of the Central Bank of Egypt in its session held on February 21, 2023, of the rules regulating card tokenization services on electronic device applications within the Arab Republic of Egypt (attached).
Please be kind enough to alert to take the necessary steps to comply with the aforementioned rules.
Accept the highest regards,
Hassan Abdullah
The Rules Regulating Card Tokenization Services on Electronic Device Applications within the Arab Republic of Egypt Payment Cards Tokenization on Electronic Devices Applications First Edition | February 2023
The Rules Regulating Card Tokenization Services on Electronic Device Applications within the Arab Republic of Egypt Payment Cards Tokenization on Electronic Devices Applications First Edition | February 2023
| 5 | Introduction |
|---|---|
| 6 | General Definitions |
| 8 | Scope of Application 1 |
| 9 | Risk Management 2 |
| 9 | Risks Associated with Card Tokenization Services on Electronic Device Applications 1-2 |
| 9 | Responsibilities and Obligations of the Board of Directors and Senior Management 2-2 |
| 11 | Anti-Money Laundering and Combating the Financing of Terrorism 3-2 |
| 12 | General Rules Regulating Banks to Provide Card Tokenization Services on Electronic Device Applications 3 |
| 12 | Controls Specific to the Unified Issuer TSP Interface 1-3 |
| 12 | Obligations of the Issuer Bank 2-3 |
| 16 | Obligations of the Acquirer Bank 3-3 |
| 18 | Obligations of the Card Network/Brand Owner 4-3 |
| 18 | Obligations of the Token Service Provider (TSP) 5-3 |
| 19 | Responsibilities of the Token Requestor 6-3 |
| 21 | Responsibilities of Misr Banks Company 7-3 |
| 24 | Controls for the Supervisory Authority 4 |
| 24 | Information Security and Confidentiality 1-4 |
| 25 | Infrastructure Security Monitoring 2-4 |
| 27 | Security System Service Evaluation 3-4 |
| 28 | Emergency Response and Contingency Planning 4-4 |
| 29 | Performance Considerations and Continuity of Operations 5-4 |
| 30 | Other Security Controls for Customers and Employees 5 |
| 33 | Procedures for Obtaining Licenses 6 |
AVA 85 7 a 44 4 2 a lar 3 ls f 6 19 -M No p a W 4 | | The Rules Regulating Card Tokenization Services on Electronic Device Applications within the Arab Republic of Egypt
These rules aim to define the operational framework for banks and all parties participating in the infrastructure for providing electronic payment card tokenization services, in order to provide the maximum degree of flexibility and security and provide appropriate banking services for all segments of society, with the goal of spreading electronic payment means and achieving financial inclusion.
5
| Term | Arabic Definition | English Term |
|---|---|---|
| Token | Data representing the actual card data, used to replace the card number and cardholder name, issued by the Issuer Bank on behalf of the Cardholder. | Token |
| Token Service Provider (TSP) | Any entity licensed by the Central Bank of Egypt to issue, manage, and administer tokens within the tokenization system. | Token Service Provider (TSP) |
| Token Requestor | The entities requesting card tokenization services through the Issuer Bank, such as electronic device manufacturers and application providers, or payment service providers or acquirer banks. | Token Requestor |
| Unified Issuer TSP Interface | The unified tokenization interface established for the purpose of managing tokens for all cards issued within the Arab Republic of Egypt by the Issuer Banks. | Unified Issuer TSP Interface |
| Original Equipment Manufacturer (OEM) Wallet | Applications on electronic devices for which the manufacturer has issued the cards, such as Apple Pay, Google Pay, Samsung Pay. | Original Equipment Manufacturer (OEM) Wallet |
| Electronic Payment Instrument | Tools issued by the Issuer Bank for electronic payment services, such as cards. | Electronic Payment Instrument |
| Host Card Emulation (HCE) Wallet | Applications on electronic devices that provide payment services issued by the Issuer Bank or acquirer bank, alongside the Issuer Bank. | Host Card Emulation (HCE) Wallet |
| Acquirer Bank | The bank licensed by the Central Bank of Egypt to provide payment services to merchants using electronic payment instruments, subject to the controls of the Central Bank of Egypt's Supervisory Authority. | Acquirer Bank |
| Card Network/Brand Owner | Various electronic card networks, such as Visa, MasterCard, etc., which provide authentication and settlement services for payment transactions, confirmed by the Central Bank of Egypt's Supervisory Authority. | Card Network/Brand Owner |
| Consumer Device | The means used by the cardholder to verify their identity, such as using one of the following electronic devices: Mobile Phone. | Consumer Device |
| Cardholder | The individual person who uses the device. | Cardholder |
| Verification Method | The method used by the user to create a passcode or biometric authentication (e.g., fingerprint, face, iris). | Verification Method |
| CDCVM | Cardholder Device Verification Method. | CDCVM |
| Near Field Communication (NFC) | Communication technology using short-range radio waves (not exceeding 4 cm) for data exchange between devices or tools. | Near Field Communication (NFC) |
| Inherent Risk | The level of risk before the implementation of controls by the executing bank, consisting of two elements: the processing entity or procedure, and the potential impact. | Inherent Risk |
| Residual Risk | The risk remaining after the bank implements controls to mitigate inherent risks. | Residual Risk |
| Negative Lists | Entities included in the lists pursuant to Law No. 8 of 2015 regarding the prevention of money laundering and terrorist financing, and the United Nations Security Council resolutions on proliferation and terrorist financing, as well as any other lists issued by the Central Bank of Egypt. | Negative Lists |
The following words and phrases shall have the meanings indicated below wherever they appear in these rules:
| Term | Definition |
|---|---|
| Issuer Bank | The bank licensed by the Central Bank of Egypt to issue electronic payment instruments. |
| Consumer Device | The means used by the cardholder to verify their identity, such as using one of the following electronic devices: Mobile Phone. |
| Cardholder | The individual person who uses the device. |
| Verification Method | The method used by the user to create a passcode or biometric authentication (e.g., fingerprint, face, iris). |
| CDCVM | Cardholder Device Verification Method. |
| Near Field Communication (NFC) | Communication technology using short-range radio waves (not exceeding 4 cm) for data exchange between devices or tools. |
| Inherent Risk | The level of risk before the implementation of controls by the executing bank, consisting of two elements: the processing entity or procedure, and the potential impact. |
| Residual Risk | The risk remaining after the bank implements controls to mitigate inherent risks. |
| Negative Lists | Entities included in the lists pursuant to Law No. 8 of 2015 regarding the prevention of money laundering and terrorist financing, and the United Nations Security Council resolutions on proliferation and terrorist financing, as well as any other lists issued by the Central Bank of Egypt. |
1-1 These rules apply to all banks operating in the Arab Republic of Egypt and token service providers on electronic device applications licensed by the Central Bank. These rules and controls constitute the minimum required for banks and token service providers, and they must not rely solely on this and must ensure taking all necessary steps regarding the management of risks associated with providing this type of service.
2-1 These rules apply to the provision of card tokenization services on electronic device applications, taking into account the supervisory controls and instructions previously issued by the Central Bank of Egypt and its amendments, as well as the supervisory controls regarding anti-money laundering issued by the Central Bank of Egypt and the due diligence procedures issued by the Anti-Money Laundering and Combating the Financing of Terrorism Unit, and Law No. 80 of 2002 regarding anti-money laundering and its amendments and executive regulations and their amendments. Also, compliance with the rules and technical specifications for providing these services and their amendments issued by Misr Banks Company and approved by the Central Bank of Egypt.
8 The Rules Regulating Card Tokenization Services on Electronic Device Applications within the Arab Republic of Egypt
1-2 Risks Associated with Card Tokenization Services on Electronic Device Applications
The provision of card tokenization services on electronic device applications is associated with several risks, which are not new to banks, such as operational risks, compliance risks, reputation risks, and strategic risks, as outlined in the instructions for operational risk management according to Basel 3 issued on December 4, 2017, and internal control in banks, as well as controls for conducting electronic banking operations and issuing electronic payment instruments for electronic money. However, the characteristics of tokenization services may increase risk levels in addition to creating new challenges for managing these risks, which must be addressed by all parties involved in providing these services by establishing the necessary frameworks and controls to manage and mitigate these risks. The following are some examples of risks associated with providing the mentioned service:
1-1-2 Compliance Risks, including but not limited to:
2-1-2 Reputation Risks, including but not limited to:
3-1-2 Information Security Risks, including but not limited to:
4-1-2 Fraud Risks
The Board of Directors in the bank is responsible for approving the business strategy for providing tokenization services proposed by senior management, and making a clear strategic decision regarding these services in accordance with the instructions for bank governance issued on August 23, 2011, previously issued by the Central Bank and its amendments, and approving the policy for providing the service, ensuring the following:
1-2-2 Establishing clear policies and procedures to determine the bank's capacity to accept risks associated with transactions arising from card tokenization services on electronic device applications, as well as mitigating these risks. These policies must be evaluated at least annually and updated periodically, including the following points:
2-2-2 The insurance methodology must be based on an analysis of specific risks and threats, taking into account inherent risks and compensating supervisory controls to achieve a level of residual risk that falls within acceptable risk levels.
3-2-2 Supervising the continuous development and maintenance of infrastructure and its security systems, as well as continuous monitoring and surveillance tools for security control that provide appropriate protection for transaction systems and data of cards tokenized on electronic device applications from any internal or external threats. To ensure the adequacy and effectiveness of financial transactions, senior management must ensure the following measures:
1-3-2-2 Defining clear responsibilities for supervising the development and management of the bank's cybersecurity policies.
2-3-2-2 Ensuring the provision of necessary protection to prevent unauthorized persons from accessing infrastructure systems, which include all vital systems, system servers, databases, applications, communications, and service security systems.
3-3-2-2 Reviewing and approving the main aspects of the bank's information technology and cybersecurity systems, including periodic review of infrastructure testing and cybersecurity security systems - for example, conducting penetration testing once a year, including continuous monitoring of developments and updates to infrastructure systems, applications, and cybersecurity systems in this field.
Banks that provide or accept card tokenization services on electronic device applications must comply with the following:
Compliance with the Anti-Money Laundering Law issued by Law No. 80 of 2002 and its amendments and executive regulations and their amendments, and the supervisory controls for banks regarding anti-money laundering and combating the financing of terrorism issued by the Central Bank of Egypt, and the due diligence procedures for bank customers issued by the Anti-Money Laundering and Combating the Financing of Terrorism Unit, and the mechanism for implementing targeted financial sanctions decisions issued by the Anti-Money Laundering and Combating the Financing of Terrorism Unit.
Following the guidelines issued to banks for establishing mechanisms to implement targeted financial sanctions and immediate freezing, as well as guidelines for implementers regarding those listed on prohibition lists according to the updated lists published on the Anti-Money Laundering Unit website under the Negative Lists section.
Having a mechanism to monitor transactions suspected of money laundering or terrorist financing and ensuring the linkage of transaction systems with anti-money laundering and combating the financing of terrorism systems / systems for detecting customers listed on negative lists.
Giving adequate attention to indicators consistent with the nature of the service for identifying transactions suspected of involving money laundering or terrorist financing, as stated in the supervisory controls for banks regarding anti-money laundering and combating the financing of terrorism issued by the Central Bank of Egypt.
In case of suspicion of any transactions using cards tokenized on electronic device applications involving money laundering, proceeds of crime, or terrorist financing, immediate notification must be made to the Anti-Money Laundering and Combating the Financing of Terrorism Unit regarding them, in accordance with the provisions of the Anti-Money Laundering Law issued by Law No. 80 of 2002 and its executive regulations and amendments.
Periodically monitoring the Unit's website to identify updates to negative lists, whether by deletion, addition, or modification.
Maintaining records and documents related to customers and transactions in accordance with the Anti-Money Laundering Law issued by Law No. 80 of 2002 and its amendments and executive regulations and their amendments, and the supervisory controls for banks regarding anti-money laundering and combating the financing of terrorism issued by the Central Bank of Egypt.
1-3 Controls Specific to the Unified Issuer TSP Interface
1-1-3 Misr Banks Company for Technological Progress plays the role of the Unified Issuer Tokenization Interface Provider for Issuer Banks within the Arab Republic of Egypt.
2-1-3 The Unified Issuer TSP Interface securely links all Issuer Banks through which data and information exchanged between all Issuer Banks and card network/brand owners are protected, for the purpose of managing token creation for all cards issued within the Arab Republic of Egypt, taking into account, for example, the following:
Encryption mechanisms used to protect networks and data according to global best practices.
Securing the Application Programming Interface (API) according to global practices to mitigate risks arising from associated vulnerabilities, with conducting specific penetration tests for them.
Conducting penetration tests to ensure the security of linking networks and infrastructure systems against any breach.
3-1-3 The Unified Issuer TSP Interface is responsible for completing the token provisioning process with all approved Token Service Providers (TSPs) from the
Note: The provided text ends abruptly at this point.
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 73,745-character original (33% of the document). The remainder was not translated. The complete original-language text is stored with this document.]