2019-05-08 | NBB_2019_09Added
Belgian credit institutions must integrate the reporting required under Article 50, § 2 of the PSD2 law and Circular NBB_2018_13 into their internal control reports, specifically within chapters C.4, D, and E.3 of the schema recommended in Circular NBB_2011_09. This integration addresses the parallel nature of the two reporting obligations and ensures coordinated supervision of operational and security risks, with particular attention to IT and cyber risks. The circular is immediately applicable and copies are sent to the statutory auditors of the affected establishments.
NBB published 1 document in the last 30 days — get each new one by email the day it lands.
NBB_2019_09 – 08 May 2019 Circular – Page 1/2
14 Berlaimont Boulevard – BE-1000 Brussels tel. +32 2 221 24 33 company number: 0203.201.340 RPM Brussels www.bnb.be
Circular
Brussels, 08 May 2019
Reference: NBB_2019_09 your contact:
Thomas Bodequin tel. +32 2 221 53 65 thomas.bodequin@nbb.be
Reporting under Circular NBB_2018_13 concerning the EBA guidelines on security measures for operational and security risks related to payment services
Scope
Belgian credit institutions, branches of credit institutions subject to the law of another Member State, branches of credit institutions subject to the law of a third country
Summary/Objective
This circular defines the reporting modalities imposed on credit institutions in Circular NBB_2018_13.
Circular – Page 2/2 NBB_2019_09 – 08 May 2019
Madam,
Sir,
Pursuant to Article 50, § 2, of the Law of 11 March 2018 (hereinafter the "PSD2 Law"), it is required to submit reporting to the supervisory authority concerning "a current and comprehensive assessment of the operational and security risks related to payment services provided by credit institutions and information on the adequacy of the risk mitigation measures and the control mechanisms implemented to address these risks". The content of this reporting is specified by the guidelines of the European Banking Authority (EBA) on security measures for operational and security risks related to payment services under Directive (EU) 2015/2366 (PSD2), as these guidelines are implemented by the NBB via Circular NBB_2018_13.
Furthermore, it is already expected that the institution transmits, via the "report of the senior management concerning the assessment of internal control" (hereinafter the "internal control report") 1, an extended description of the institution's internal processes and the risks associated with them, as well as a description and own assessment of the internal control mechanisms aimed at mastering or mitigating these risks, and a list of measures envisaged to improve internal control.
Given that, on the one hand, these two reportings are partly parallel and both require a listing of risks related to (payment) activities and the measures taken to master them, and, on the other hand, with a view to coordinated and structured supervision of credit institutions, both under the Law of 25 April 2014 (Banking Law) and under the PSD2 Law (insofar as payment services are provided), the NBB expects the concerned credit institutions to appropriately integrate the reporting referred to in Article 50, § 2, of the PSD2 Law and the provisions of Circular NBB_2018_13 into the internal control report, notably in chapters C.4, D and E.3 of the recommended schema communicated in the annex of Circular NBB_2011_09, taking into account the particular attention requested for IT and cyber risks.
This circular is immediately applicable.
A copy is sent to the statutory auditor(s) of your institution.
Please accept, Madam, Sir, the assurance of my distinguished consideration.
Pierre Wunsch
Governor
1 Circular NBB_2011_09 of 20 December 2011: "The report of the senior management concerning the assessment of internal control, the report of the senior management concerning the assessment of internal control in the matter of investment services and activities, and the declaration of the senior management concerning periodic prudential reporting".
Read the rest free
Source: National Bank of Belgium — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works