2021-01-28
Added
The Financial Conduct Authority proposes amendments to the SCA-RTS, including a new exemption from strong customer authentication for account information service providers and a mandate for dedicated interfaces like APIs for third-party provider access. The consultation also seeks to increase single and cumulative contactless payment transaction thresholds from £45 and £130 to £100 and £200 respectively. Additionally, the Authority proposes making temporary prudential risk management and safeguarding guidance permanent and updating the Approach Document and Perimeter Guidance Manual to reflect the UK's withdrawal from the European Union.
FCA published 8 documents in the last 30 days — get each new one by email the day it lands.
Changes to the SCA-RTS and to the guidance in
‘Payment Services and Electronic Money – Our
Approach’ and the Perimeter Guidance Manual
Consultation Paper
CP21/3
January 2021
CP21/3 Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual Sign up for our news and publications alerts See all our latest press releases, consultations and speeches.
How to respond Contents
We are asking for comments on 1 Summary 3 this Consultation Paper (CP) by:
2 The wider context 6 24 February 2021 for questions relating to contactless 3 SCA-RTS 9 4 Changes to the AD – Strong Customer payments (Q5 & Q6) 30 April 2021 for all other aspects of the consultation. Authentication (SCA) 17 5 Changes to the AD – Prudential risk management You can send them to us using 21 the form on our website at: and safeguarding 25 www.fca.org.uk/cp21-03-response-form 6 Other changes to the AD Or in writing to: 7 Changes to the AD reflecting the UK’s 28 Qasim Khan exit from the EU 29 Financial Conduct Authority 8 PERG Amendments 12 Endeavour Square London E20 1JN
Annex 1 30
Email: Questions in this paper cp21-03@fca.org.uk Cost benefit analysis
Annex 2 32
Annex 3 51
Compatibility statement
Annex 4 57
Abbreviations used in this paper
Appendix 1
Proposed amendments to the Approach Document
Appendix 2
Draft Legal Instruments
Appendix 3
Dear Compliance Officers Letter (Safeguarding)
Appendix 4
Dear CEO Letter (ECE)
CP21/3
Chapter 1
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
1 Summary
Why we are consulting
1.1 The payments landscape has grown and evolved in recent years, as business models
adapt to changing user needs and demands – including the continued growth of open banking. The coronavirus (Covid-19) pandemic has been a catalyst, accelerating changes in business models and consumer behaviour. To maintain adequate protections for consumers, and make sure regulatory expectations keep pace with the changing landscape, we regularly review our published guidance and requirements. We are now proposing amendments to our Regulatory Technical Standards, Perimeter Guidance Manual (PERG) and FCA Approach Document (AD).
1.2 We have identified barriers to the future success and adoption of open banking as it
grows in the UK. To address these, we are proposing amendments to the technical standards on strong customer authentication and common and secure methods of communication (the SCA-RTS).
1.3 Further to this, in our 2020/2021 Business Plan, we identified the payments sector as a
priority for the next 3 years. Our work intends to make sure: consumers transact safely with payment firms; payment firms meet their regulatory obligations while competing on quality and value; and consumers and SMEs have access to a variety of payment services. Payments firms refers to Payment Institutions (PIs) and Electronic Money Institutions (EMIs).
1.4 Since we last updated our AD, in June 2019, we have published several statements
clarifying our expectation of firms’ prudential risk management and safeguarding practices. In response to coronavirus pandemic, after a brief consultation, we published temporary guidance to strengthen firms’ resilience through additional prudential risk management and safeguarding requirements. To give the industry clarity and certainty, we are proposing to make our recent temporary guidance permanent and consolidate our expectations of firms.
1.5 Before the completion of the EU‑UK implementation period on 31 December 2020
(IPCD), we considered changes to industry guidance issued by the European Banking Authority (EBA) and European Commission (the Commission). We now propose to update our guidance to reflect the EBA’s and the Commission’s guidance issued prior to IPCD, where we have determined that their guidance remains relevant in the UK.
1.6 In this consultation paper (CP), we are also proposing changes to the AD to reflect the
UK’s withdrawal from the European Union (EU) and the end of the transition period.
CP21/3
Chapter 1
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Who this applies to
1.7 Payment service providers (PSPs) and e-money issuers, as well as trade bodies
representing them, should read this consultation. Our proposals affect credit institutions providing payment services and/or issuing e-money, as well as payment institutions (PIs), e-money institutions (EMIs) and registered account information services providers (RAISPs). It also applies to firms’ subject to the temporary permission regime (TPR) and the financial services contracts regime (FSCR) set out in Schedule 3 of the Electronic Money, Payment Services and Payment Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018 (Exit SI). It also applies to Gibraltar firms providing payment services in the UK.This CP will also be of interest to:
CP21/3
Chapter 1
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
in the AD on SCA. We also propose to amend our safeguarding and prudential risk management guidance. This includes proposing to make permanent the temporary guidance issued in July in response to coronavirus pandemic. We are also proposing updates to our guidance addressing changes required now the UK has left the European Union (EU) and after the end of the transition period.
1.11 We are also updating our guidance in other areas such as to reflect the changes set out
is PS19/3 that applied the Principles for Businesses and parts of the Banking Conduct of Business Sourcebook (BCOBS) to payment services and the issuance of e-money; to provide additional guidance to firms relying on the limited network exclusion (LNE) and the electronic communications exclusions (ECE); updates to reflect changes to e‑money firms’ reporting requirements; on information sharing between ASPSPs and TPPs; and on eIDAS certificates to reflect the changes to Article 34 of the SCA-RTS. Outcome we are seeking
1.12 We want to remove identified barriers to continued growth, innovation and
competition in the payments and e-money sector (including open banking), while making the payments and e-money sector more resilient and protecting consumers if firms fail.
1.13 We also aim to make sure that the AD reflects the changes to legislation made following
the UK’s withdrawal from the EU and the establishment of temporary permission schemes designed to enable European Economic Area (EEA) EMIs, PIs and RAISPs to continue operating in the UK for a limited time after the end of the transition period. Measuring success
1.14 We will evaluate the success of our changes through firm supervision and monitoring
of information provided by firms. Key indicators of success will be:
CP21/3
Chapter 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual 2 The wider context The harm we are trying to address
2.1 The regulatory regime in the payments and e-money sector is intended to make
payments safe and secure for customers while promoting competition. If firms fail to adequately manage prudential risk, the possibility of a disorderly firm failure increases. Inadequate prudential risk management, coupled with poor safeguarding processes and controls, increases the potential for customers to face delays and shortfalls when trying to recover their funds. This can have a significant impact on the lives of those affected. Firm failures can also undermine trust and confidence in the wider sectors.
2.2 Where necessary, we publish guidance to help firms better understand how we
expect the industry to meet its regulatory obligations. We hope that more consistent compliance with the rules will make sure that all customers are protected equally, whichever firm they choose to use. Clearer understanding of our expectations should also reduce compliance costs for the industry.
2.3 The recent regulation of open banking and introduction of SCA aimed to promote
competition, and make payments safer and more secure. Discussions with industry stakeholders have suggested that some requirements may have inadvertently reduced choice and hindered growth, restricting innovation and hindering new entrants. We think there is scope to change existing regulatory requirements to help support increased competition and innovation in the interest of consumers in the sector, while maintaining consumer protection.
2.4 To address these harms, we are proposing to make various changes to the SCA-RTS,
removing regulatory barriers and promoting growth and competition in the sector.
2.5 To reflect the above, we also propose to update our guidance in some areas of the AD
and PERG.
Outcomes we are seeking
Effective competition
2.6 We propose to amend the AD and PERG, including to amend our safeguarding and
prudential risk management guidance by making our temporary guidance permanent. These changes will clarify regulatory obligations and help ensure consistent compliance, enabling firms to compete fairly in the interest of consumers.
2.7 We believe ineffective competition caused by regulatory barriers is leading to poor
outcomes for many customers. Our proposed changes to the SCA-RTS intend to remove these regulatory barriers to help support increased competition and innovation in the sector.
CP21/3
Chapter 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Consumer protection
2.8 Our proposals will help firms comply with their regulatory obligations, strengthening
financial resilience and the safeguarding of customer funds, ultimately improving consumer protection. Our proposals to amend the SCA-RTS should also help protect consumers by making sure data sharing and payments are done securely. Market integrity
2.9 Our proposals to amend the SCA-RTS and issue new guidance in the AD (including
making our temporary guidance permanent) and PERG should strengthen market integrity and improve trust in the financial system, by making data sharing and payments more secure and giving firms more clarity on their regulatory obligations and support the financial stability of firms. What we are doing
2.10 To address the harms identified above, we propose to amend the SCA-RTS, and
amend our guidance in AD and PERG.
2.11 Proposed changes to the SCA-RTS include:
CP21/3
Chapter 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual Equality and diversity considerations
2.15 We have considered the equality and diversity issues that may arise from our
proposals.
2.16 Overall, we do not consider that the proposals adversely impact any of the groups with
protected characteristics under the Equality Act 2010. But we will continue to consider the equality and diversity implications of the proposals during the consultation period, and will revisit them when publishing the final rules.
2.17 In the meantime, we welcome your input on this.
CP21/3
Chapter 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
3 SCA-RTS
3.1 The EU Regulatory Technical Standards for strong customer authentication and
common and secure open standards of communication (EU‑RTS) came into force on 14 March 2018, and applied (in full) from 14 September 2019. It forms part of EU law, and supplements the revised Payment Services Directive (PSD2).
3.2 The EU‑RTS set detailed requirements for the secure communication between
ASPSPs (account providers), and account information service providers (AISPs), payment initiation service providers (PISPs), and card-based payment instrument issuer (CBPIIs) (collectively referred to as TPPs), and SCA. Firms in the UK have been working to comply with the EU‑RTS since it came into force in March 2018.
3.3 Amendments to the PSRs in response to the UK’s withdrawal from the EU require
firms to comply with technical standards made by the FCA (SCA-RTS) instead of the EU‑RTS. The FCA made the SCA-RTS substantially the same as the EU RTS in order to provide certainty for firms and maintain consumer protections. More information can be found in PS19/26
3.4 From discussions with the industry, trade bodies, and responses to our recent Call
for Input on Open Finance, we have identified barriers to successful competition and innovation in the UK payments landscape posed by requirements in the SCA‑RTS.
3.5 We have set out proposals below to amend the SCA-RTS to address these barriers.
Our proposals aim to support competition and innovation in the payments and e‑money sector, while maintaining the safety and security of UK payments. 90-day re-authentication
3.6 SCA was introduced with the intention of making payments more secure and limiting
the risks of fraud. It aims to make sure that the person requesting access to an account, or trying to make a payment, is the account holder or authorised by the account holder to access that account. The PSRs require SCA to be performed each time a payment service user (customer) accesses their account online.
3.7 The SCA-RTS provides an exemption (Article 10) from this requirement where customers
access certain limited payment account information. SCA must still be applied when the customer accesses their data for the first time, and at least every 90 days after that. The exemption also applies where a TPP, acting on a customer’s behalf, accesses account data held by another PSP. Withoutthe customer’s reauthentication every 90 days,the TPP is unable to continue to access the customer’s data held by another PSP.
3.8 The requirement to re-apply SCA every 90 days has proven burdensome for
customers, creating friction in the user experience, and hindering uptake of open banking services. The negative impact is increased for those customers holding multiple accounts with different account providers who are required to complete SCA every 90 days with each account provider they want a TPP to have access to, or where an SME uses an intermediary to manage its accounts.
CP21/3
Chapter 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
3.9
3.10
3.11
3.12
3.13
3.14
3.15
TPPs have reported a significant loss of customers at the point where reauthentication by SCA is required. A TPP has found that a churn rate of over 40% despite almost all of its customers being satisfied with the service. The interruption in a customer’s ongoing access to a TPP service after failing to reauthenticate could cause consumers and SMEs to make decisions based on out-of-date data, potentially resulting in harm. A TPP has reported that this could lead to the risk of three-quarters of the businesses that use the service facing liquidity issues. We understand the potential loss of access to customer data as a result of a customer’s failure to reauthenticate every 90 days has caused firms to delay or stop the launch of new products and services in the UK. As a result, the full benefits of open banking to UK consumers and competition are not being realised. Importantly, we think there is little risk of unauthorised access to data when a TPP accesses information on a customer’s behalf, and that any risk is largely mitigated by other requirements under the PSRs and the SCA-RTS (e.g. the requirement for TPPs to present a certificate to account providers when attempting to access data). We therefore propose to create a new exemption so that ASPSPs do not need to require their customers to apply SCA every 90 days when the customer uses a TPP to provide account information services. SCA will, however, be required when customers first decide to connect their account to a TPP service. This will make sure that it is the legitimate account holder authorising the TPP to access the account on their behalf. We think the new exemption reflects the low level of risk involved, in line with the requirements of the PSRs. We propose to limit the scope of the existing Article 10 exemption to when the customer accesses their information directly. We also propose to introduce new requirements where a TPP accesses account information where the customer does not actively request the information. At present, a TPP is permitted to do so up to four times a day. Where a TPP continues to access data in this way, we propose that it will need to reconfirm the customer’s explicit consent every 90 days. If a customer fails to re-confirm their consent, the TPP will be required to disconnect access and stop collecting data from the customer’s account provider. We think this will make sure that consumers who may not be very active are adequately protected, as data sharing will stop if they do not reconfirm their consent. Account providers may continue to deny a TPP access to a customer’s accounts for reasonably justified and duly evidenced reasons relating to unauthorised or fraudulent access in accordance with regulation 71(7) of the PSRs. We believe these proposals will remove barriers to interested customers continued use of open banking services, while maintaining protection from unauthorised and fraudulent access to accounts and mitigating the risk to customers who
become inactive without cancelling a TPP service. We explore the benefits of this proposed changes, as well as the associated costs, in more detail in the cost benefit analysis (CBA) (paragraphs 39‑41, 46‑48). Q1: Do you agree with our proposal to create a new SCA exemption for when customers access customer information through a TPP and add a new requirement for TPPs to check customers’ consent every 90 days? If not, please explain why.
CP21/3
Chapter 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Changes to requirements for access interfaces
3.16 The SCA-RTS require account providers to establish interfaces through which TPPs
can access customer payment accounts in a secure manner. In accordance with Article 31 SCA-RTS, account providers have the option to enable access via a dedicated interface or a modified customer interface (MCI). The MCI provides access to TPPs via existing customer interfaces, usually the online banking platform. Account providers that have opted for a dedicated interface, typically do so by using an API.
3.17 In practice, the use of MCIs has proven challenging for TPPs, and therefore affected
the customer experience. Many TPPs face difficulties when accessing customers’ payment accounts via MCIs, as they do not have the technology to connect. The few TPPs that have the technology must make considerable adjustments to their systems, incurring extra costs, to be able to access each account provider’s individual MCI. Typically, they cannot access customer payment accounts without the customer being present, as most firms with an MCI do not rely on an exemption, so SCA is required. We understand that the limitations of using MCIs have discouraged TPPs from serving customers who hold accounts with account providers that have chosen to enable access through MCIs. Several firms have told us they have stopped serving tens of thousands of customers as a result. These customers are, therefore, not reaping the full benefits of open banking.
3.18 In comparison, account providers offering dedicated interfaces typically rely on the
Article 10 exemption and are able to permit TPPs to access a customer’s data without
the customer being present. In addition, dedicated interfaces are typically APIs built on the same standards allowing TPPs to connect more easily.
3.19 Moreover, using an MCI is not as secure as using a dedicated interface. MCIs provide
unrestricted access to all data available via the online banking platform. In comparison, APIs only include the information that account providers are required to share.
3.20 The use of MCIs causes inconvenience to customers and significantly reduces the
appeal of the service provided by the TPP. As noted, they can also be less secure.
3.21 We therefore propose to mandate the use of dedicated interfaces for a range of
payment accounts, removing the barriers posed by the use of MCIs. This requirement is only imposed on certain payment accounts where there is a reasonable prospect of TPP demand. Therefore, our proposal applies to personal and SME ‘current accounts’ – payment accounts under the Payment Account Regulations (PARs). They would also apply to accounts that would fall under the definition of payment accounts within the meaning of the PARs but that are held by SMEs, and credit card accounts held by consumers or SMEs.
3.22 Broadly speaking, our proposal will apply to credit institutions, PIs and EMIs offering
these types of payment accounts online. However, we are also proposing to exclude accounts provided by small payment institutions (SPIs) small e-money institutions (SEMIs), firms relying on the TPR or supervised run-off regime (SRO), which is part of the FSCR, and non‑SMEs’ corporate customer accounts from this change, meaning the use of MCIs will remain a compliant alternative for such accounts. We are proposing to exclude firms relying on the TPR or SRO regimes, as it would not be proportionate to require them to build dedicated interfaces where their TPR or SRO status only allows them to provide payment accounts in the UK for a temporary period.
CP21/3
Chapter 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
3.23 Our proposal will only impact those account providers who have not already opted for
a dedicated interface. We acknowledge that the cost for the firms required to make changes will be significant (as per paragraph 43 in our CBA). However, the benefits this change will bring to customers are also substantial. For many customers who have limited or no access to TPP services due to their account provider opting to enable access using MCIs, mandating dedicated interfaces would make it easier and give them access to additional services. In addition, customers will benefit from increased security and better data protection. This is because a dedicated interface is specifically designed for that purpose and access is limited to payment account data. TPPs will also benefit from the mandated use of dedicated interfaces as barriers will be lowered. TPPs will no longer face the same restrictions to the range of products and services they can offer to their customers. This will enable them to innovate, benefiting consumers and, in turn, the overall open banking ecosystem in the UK, especially when considered in conjunction with the proposed changes to the 90‑day reauthentication.
3.24 We appreciate that this proposal would require significant system changes from
some account providers. For this reason, we propose to give firms up to 18 months to implement this change from when the final guidance is published. We welcome feedback on this timeline. Q2: Do you agree with our proposal to mandate the use of dedicated interfaces for TPP access to retail and SME customers’ payment accounts and the timeline for making those changes? If not, please explain why. Technical specifications and testing facilities
3.25 Under Article 31 of the SCA‑RTS, account providers are required to make a testing
facility available and provide interface technical specifications six months before new products and services are launched. This was intended to enable TPPs to test their connectivity and service before the live market transitioned to the new requirements of PSD2.
3.26 The SCA-RTS also contain a requirement for account providers that have chosen
to develop a dedicated interface to adapt their consumer interface for use by TPPs if the dedicated interface becomes unavailable. This adapted interface is known as the fallback interface. However, account providers can request an exemption from this requirement from the FCA, if, among meeting other criteria, they have had a fully functioning API for 3 months prior to that application.
3.27 When PSD2 came into force, these requirements were necessary to make sure
access to existing products could continue, as the changes brought in by PSD2 were happening in a live, active payments and e-money sector. They have subsequently acted as barriers for new products designed and introduced by account providers. This holds back competition and innovation in the market. We understand, in particular, that the requirement to share a testing facility and release technical specifications of concepts 6 months in advance of launching has been burdensome for account providers both in terms of cost and time. Due to challenges posed by these requirements, we understand firms have delayed and in some instances cancelled the launch of new products and services.
CP21/3
Chapter 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
3.28 The impact of these requirements is likely to be more significant for new service
providers in the market, who may choose not to enter the market due to high barriers to entry. As a result, we believe that consumers are not fully benefiting from the potential benefits of competition and innovation within the market.
3.29 The requirements are also likely to provide limited benefits to TPPs, which are
unlikely to use testing facilities and technical specifications to perform functional and connectivity testing in advance of the launch as demand for new products is not known.
3.30 We propose to require that the technical specifications and testing facility only be
made available to TPPs from the launch of new products and services, rather than 6 months in advance. We also propose that the requirement for a fallback interface should only take effect six months after launch. This would allow account providers time to develop such an interface or request an exemption to the requirement to have one.
3.31 We believe these proposals will reduce time and cost associated with launching new
products and services for account providers, while maintaining TPP access and service. These changes should encourage new products and services to market sooner. Consumers should therefore benefit from innovation and more services in the market. We explore the benefits and costs associated with these proposed changes to the SCA-RTS further in the CBA (paragraphs 45 & 50). Q3: Do you agree with our proposals to only require ASPSPs to make the technical specifications and a testing facility available at market launch of the interface, and to delay the need for a fallback interface for six months from the point of launch? If not, please explain why. Changes to SCA-RTS relating to the fallback interface
3.32 The UK left the EU on 31 January 2020 with a Withdrawal Agreement which included a
transition period during which EU law continued to apply. This transition period ended on 31 December 2020 (also referred to as IP Completion Day).
3.33 The UK’s participation in the EU passporting regime ended on IP Completion Day.
To minimise the risk of EEA firms being unable to access the UK market post IP Completion Day and the possible resulting disruption to customers, the Government introduced schemes to grant transitional UK authorisation to such firms. The schemes applicable to incoming EEA EMIs, PIs and RAISPs are set out in Schedule 3 of the Exit SI. The TPR and FSCR schemes applicable to incoming EEA credit institutions are set out set out in the EEA Passport Rights (Amendment etc. and Transitional Provisions) (EU Exit) Regulations 2018.
3.34 Where a firm relies on the TPR or supervised run-off regime (SRO), which is part of
the FSCR, it is treated as having a deemed authorisation or deemed permissions under the relevant legislation (whether this is the EMRs, the PSRs or FSMA). These firms are required to comply with the UK requirements applicable to the business they carry out in the UK (including those set out in the SCA‑RTS), as opposed to home state requirements.
CP21/3
Chapter 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
3.35
3.36
3.37
3.38
3.39
3.40
As explained in the previous section, the SCA-RTS contain a requirement for account providers, that have chosen to develop a dedicated interface, to adapt their consumer interface so that it can be used by TPPs if the dedicated interface becomes unavailable. This adapted interface is known as the fallback interface. However, account providers can request an exemption from this requirement from the FCA, provided it meets the criteria under Article 33 SCA-RTS. EEA account providers continuing to provide services in the UK under the TPR or SRO may previously have benefited from an exemption granted by their home state regulator that would have been applicable in the UK. Following IP Completion Day, these exemptions provided by home state regulators stopped being effective in the UK. Since IP Completion Day, EEA account providers that are continuing providing services in the UK under the TPR have been required to set up a fallback interface unless exempted by the FCA. We propose to treat a home state exemption from setting up the fallback interface as though it were initially granted by the FCA for the purposes of Article 33(6). This means that ASPSPs with a temporary authorisation will not need to apply to us for this exemption while they are within the relevant temporary scheme. When these EEA account providers apply to the FCA or the PRA for authorisation under the EMRs, PSRs or FSMA, if necessary, they will need to apply for and obtain from the FCA an exemption from the obligation to having a fallback in place. We consider the risk of harm to UK consumers and TPPs as result of these proposals to be low for the following reasons. First, we note that any TPR firm currently benefitting from an exemption provided by their home state regulator should have been assessed against the criteria for exemption in Article 33 of the EU‑RTS in accordance with the EBA Guidelines on the conditions to be met to benefit from an exemption from contingency measures under Article 33(6) of Regulation (EU) 2018/389. In addition, we understand that demand from UK TPPs to access interfaces of firms operating under the TPR is low. We are not aware of any issues with the interfaces of TPR firms having previously been raised with the FCA. This proposed change does not affect our supervisory powers. This means that where we identify issues with a TPR/SRO firm’s dedicated interface, including prior to the change being made, we may decide to use our supervisory tools and powers as appropriate. We reserve the right to use the full range of our regulatory tools and powers as appropriate in the event of harm to UK TPPs, and their users, due to problems with a firm’s dedicated interface. Q4: Do you agree with our proposal to treat ASPSPs with exemptions from setting up the fallback interface granted by home state competent authorities, as though they were granted an exemption by the FCA? If not, please explain why.
CP21/3
Chapter 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Contactless payments
3.41 Contactless payments up to the value of £45 per transaction are exempt from the
requirements for SCA where the conditions in Article 11 of the SCA-RTS are satisfied. Under Article 11 of the SCA‑RTS, contactless payments must be subjected to SCA whenever the cumulative transaction value threshold of £130 has been reached, or after 5 contactless transactions have been made in a row without SCA being applied.
3.42 In response to the coronavirus pandemic, we confirmed that we are very unlikely to
take enforcement action where a firm fails to apply SCA when a customer exceeds the cumulative transaction value threshold under Article 11. This is provided that the firm has sufficient controls in place to mitigate the risk of unauthorised transactions and fraud. We understand that card issuers have relied on this statement.
3.43 During the coronavirus pandemic, consumers and merchants have relied more
on contactless payments. They have both shown an appetite for the increased convenience and reduced friction at the point of sale. One card issuer reported an increase in the use of contactless payments since the coronavirus pandemic, with more than 90% of face-to-face transactions occurring through contactless payments. While the use of contactless payments has increased, our discussions with industry participants suggest no evidence of an increase in fraudulent transactions.
3.44 Recognising changing consumer behaviour and merchant expectations, we propose
to increase the cumulative transaction threshold from £130 to £200. We think there is still a low risk of fraud, as we have seen under the forbearance period to date. The proposed change would enable consumers to make more contactless payments before needing to authenticate with SCA. The average value of individual transactions using contactless payments is £10 – meaning on average a customer could complete 20 transactions before being required to provide SCA to reset the transaction counters.
3.45 In the CBA, we set out the benefits the increase in the cumulative threshold will bring,
as well as the minor associated costs (paragraphs 45 & 50).
Q5: Do you agree with our proposed amendment to increase the cumulative threshold of the contactless exemption from £130 to £200? If not, please explain your rationale, including supporting data where applicable.
3.46 In addition, we are considering an increase of the single threshold to £100 (or
potentially a maximum of £120). We think this would further support consumers and merchants during the Covid crisis and acknowledge changing behaviours in how people pay. We note that several countries have increased the single threshold for contactless payments, either temporarily as a response to the Covid pandemic or as an acknowledgment of changing consumer and businesses’ behaviours, without any adverse impact on fraud that we are aware of. Australia has temporarily doubled its contactless limit from AUD$100 (£56) to AUD$200 (£112), to be reviewed every three months during the crisis. In Canada, the contactless limit has increased to CAD$250 (£143), and Singapore has increased its contactless limit from S$100 (£55) to S$200 (£110). Increasing the regulatory threshold would provide the industry with the ability to increase the industry threshold in the future. The CBA referred to in paragraph 3.45 also applies to a potential increase of the single threshold.
CP21/3
Chapter 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual Q6: What is your view on increasing the current regulatory contactless (single) threshold limit of £45 to £100 (or potentially a maximum of £120)Please explain your rationale, including supporting data and new threshold where applicable. If your response identifies potential risks and benefits, please provide evidence in support of your response.
3.47 In light of the current Covid crisis, we plan to respond to feedback received on
questions 5 and 6 on contactless thresholds as soon as possible after 24 February
2021. Appendix 2 contains a draft of the proposed changes in a dedicated legal
instrument. The other proposed changes to the SCA-RTS outlined in paragraphs 3.1 to 3.40 are set out in another draft legal instrument, also in Appendix 2.
CP21/3
Chapter 4
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
4 Changes to the AD – Strong Customer
Authentication (SCA)
4.1 Under the PSRs, PSPs must apply SCA where a customer accesses a payment account
online, initiates an electronic payment transaction (such as when shopping online), or carries out any action through a remote channel that may create a risk of payment fraud. SCA is based on the use of two or more elements, which are categorised as knowledge, possession and inherence. SCA aims to make payments safer and more secure, reducing the risk of fraud when customers access their accounts online, initiate a payment or carry out other actions remotely.
4.2 The EU‑RTS became fully applicable on 14 September 2019 and supplemented the
PSRs in the UK. However, on 31 December 2020, we made the SCA‑RTS and revoked the EU‑RTS following the end of the transition period.
4.3 On 19 December 2018, we updated our AD to provide guidance to UK firms on our
expectations for compliance with requirements for SCA (see PS18/24). Since then, the EBA and the Commission have published various Q&A responses and opinions on SCA published up to 31 December 2020. We are proposing to amend our AD in light of these responses and opinions.
4.4 We also note the recent European Court of Justice judgment on the DenizBank case
and its conclusions on contactless card payments. We are considering the impact it may have, if any. We may issue more guidance on this if appropriate in the future.
4.5 In addition, following engagement with the industry, we propose to make changes to
our guidance on dynamic linking.
4.6 We set out the specific changes below.
Dynamic linking
4.7 Dynamic linking requires a customer’s authentication of a payment instruction to
be linked to a specific payee and a specific amount. This presents difficulties for transactions where the final amount is not known in advance. This affects certain sectors and business models, such as online grocery shopping, where the customer does not always know the final price when authorising the transaction, for example due to products being unavailable or substituted.
4.8 Our current guidance explains that SCA should be reapplied following the point of
sale if the final amount is higher than the price the customer originally authenticated. Additional SCA is not required if the final amount is lower than what was originally agreed.
4.9 The same technical process applies regardless of whether the final amount is higher
or lower. We therefore think the risk of fraud or unauthorised transactions occurring is the same. There is also no evidence to suggest that fraud levels are higher in the instances where the final amount is higher. Given this, we believe there is little benefit
CP21/3
Chapter 4
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
to consumers from this guidance and to comply would require changes imposing significant and unnecessary costs for the industry.
4.10 We are proposing to amend our guidance because it is not clear how dynamic linking
requirement should be understood in the context of transactions where the amount is not known in advance. Therefore, the amended guidance will explain that for transactions where the amount is not known in advance. Our view is that SCA would not need to be reapplied where the final amount is higher than the original amount authorised. To make sure that the final payment is reasonably within the amount the customer agreed to when authorising the payment, the payment should not exceed 20% above the amount originally authorised without further SCA being performed. We believe this to be a reasonable amount. In addition, we expect businesses to have made consumers aware that the price could go up and consumers to have agreed to such a possibility before authorising the original amount.
4.11 We believe the potential for harm to consumers as a result of this change is low. The
industry has reported low levels of fraud and complaints in relation to these types of transactions. In addition, in accordance with Regulation 79 of the PSRs 2017, payers may be entitled to a refund if the final price was not within their reasonable expectations. Liability of for fraudulent or unauthorised transactions
4.12 In July 2019, the Commission clarified its view of the allocation of liability between a
payer’s PSP and a payee, or a payee’s PSP (e.g. a merchant acquirer) for losses arising from a fraudulent or unauthorised transaction in Q&A 2018_4042. The Commissions’ view is that the payee’s PSP should be liable where it triggers an exemption and the transaction is carried out without applying SCA. This means that, other than where the payer has acted fraudulently, the payer’s PSP would refund the customer and would then be entitled to be reimbursed by the payee’s PSP. This reflects existing industry practice for card payments when processing chargebacks. We agree with this view and propose to update the AD to reflect this position. SCA elements
4.13 The EBA published an opinion in June 2019 on SCA, clarifying what constitutes a valid
element for the purposes of SCA. This included clarifying that a device could only be used as evidence of possession where there is a reliable means to confirm possession (i.e. that the device is in the right person’s hands). The EBA opinion also explained that static card data can neither constitute a knowledge factor nor a possession factor. In addition, the EBA gave more detail on inherence factors, stating that behavioural biometrics could constitute inherence and that inherence ‘relates to physical properties of body parts, physiological characteristics and behavioural processes created by the body, and any combination of these’. It clearly stated that inherence excluded other individual properties, such as spending patterns. We agree with the EBA’s views and propose to update the AD to reflect those.
CP21/3
Chapter 4
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Transaction risk analysis
4.14 EBA Q&A 2019_4702 clarified expectations on transaction risk analysis. Fraud rate
calculations for transaction risk analyses, at Article 18 of the EU‑RTS, should only include unauthorised or fraudulent remote electronic transactions for which the PSP was liable, and no other types of transactions. This differs from the calculation of the fraud rates for reporting under REP017 where all types of fraud should be included regardless of whether it is in scope of SCA or not and regardless of whether the reporting PSP was liable. We propose to amend the AD to reflect this clarification. Corporate exemption
4.15 EBA Q&A 2018_4060, on the scope of the corporate exemption under Article 17 of the
EU‑RTS, clarified that the corporate exemption is applicable to (physical or not) card payments (as well as other payment instruments), provided that those cards are ‘only available to payers who are not consumers’. In other words, those cards should only be available to corporate customers. We agree with the EBA’s clarification and propose to amend our guidance to explicitly reflect it. Authentication code
4.16 We propose to include in our guidance a clarification provided by EBA Q&A 2018_4141.
The Q&A clarified that the authentication elements the customer uses at the time they access their payment account online (including via a mobile) may be reused if they then initiate a payment (within the same online session). This means a customer could authenticate a payment with one element only, while the firm relies, for example, on a password the customer used when logging into their account. This applies as long as the dynamic linking element is linked to the SCA element carried out at the time the payment is initiated. We agree with the EBA’s clarification and propose to amend our guidance to explicitly reflect it. Merchant-initiated transactions
4.17 In Q&A 2018_4031, the Commission clarified the position relating to
merchant-initiated transactions. The Commission confirmed that transactions initiated by the payee only, without any involvement from the payer, are not in scope of SCA. Card-based payments imply an action by the payer and are considered as transactions initiated by the payer, through the payee, to which SCA applies. However, where a payer has given a mandate to the payee for a transaction, or series of transactions, made through a card (or other payment instrument) then the payments initiated pursuant to this mandate are merchant initiated transactions and therefore outside of the scope of SCA. This would cover, for example, continuous payment authorities such as a subscription for a streaming service.
4.18 The Commission explained that setting up the mandate with the customer through
a remote channel should be subject to SCA (because it may imply a risk of payment fraud or other abuses). For example, where a customer first subscribes to a streaming
CP21/3
Chapter 4
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual service, agreeing to future regular payments being taken from their account, they will have to authenticate using SCA. All subsequent regular payments will be initiated by the streaming service without any customer action required. We agree with this view and propose to update the AD accordingly. Changes to contactless payments
4.19 As explained in chapter 3, payment firms may choose not to apply SCA to contactless
point-of-sale transactions if specific conditions are met. In addition to meeting other conditions, the exemption only applies where either the cumulative amount of previous contactless transactions does not exceed £130 or the number of consecutive contactless transactions since the last application of SCA is not more than 5. In
Chapter 3, we proposed increasing the cumulative amount being changed from
£130 to £200 in the SCA-RTS. In addition to this, the change mentioned to the single contactless threshold in para 3.46 of this CP will be reflected in the AD under chapter 20, para 20.53.
4.20 There are two main ways of monitoring these thresholds. We propose to clarify these
in the guidance. One is that firms may monitor those thresholds by setting a counter, using a host-based solution that enables them to count all transactions except those made offline. The other option is that firms may use a chip-based solution on the physical card, with compliant chip-based cards being reissued. A chip-based solution enables a count of all transactions, including offline. Whichever method they choose, firms should consider the risk of unauthorised or non-compliant contactless transactions being made and monitor the effects of the option in practice. Q7: Do you agree with the proposed changes to guidance on SCA? If not, please explain why.
CP21/3
Chapter 5
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
5.1
5.2
5.3
5.4
5.5
5.6
5 Changes to the AD – Prudential risk management and safeguarding Robust prudential risk management is essential to enable firms to absorb economic stress and reduce the risk of insolvency. If a firm fails, regulatory capital and wind-down plans also help them and insolvency practitioners make the process as orderly as possible. Safeguarding customer funds provides further, essential consumer protection within the EMRs and PSRs, seeking to make sure that, if a firm becomes insolvent, the wind down process is as orderly as possible. PIs and EMIs are not covered by the Financial Services Compensation Scheme (FSCS). In the absence of this protection, effective safeguarding of customer funds is essential to protect consumers from harm in the event of firm insolvency. As a condition of being authorised, applicant PIs and EMIs must satisfy us that they have effective procedures to identify, manage and control any risks they may be exposed to, and that they have taken adequate steps to safeguard customer funds. The legislation is prescriptive in how firms must manage and maintain their capital adequacy and safeguarding arrangements. Chapters 9 and 10 of our AD provide guidance on these requirements. We have continued to review how well firms are meeting the safeguarding requirements in practice. In 2019 we undertook a multi-firm review of firms’ safeguarding arrangements, culminating in the publication of a Dear CEO letter in July 2019. Our review found that most firms used the segregation method to keep relevant funds separate from other funds. It found significant shortcomings in firms’ safeguarding arrangements. These included firms demonstrating a poor understanding of which funds are relevant and should be segregated; delays in firms segregating funds following receipt; and firms failing to check that the correct amounts are being segregated frequently enough (i.e. through reconciliation processes). In order for consumers to fully benefit from the safeguarding protections in the EMRs and PSRs, firms must comply with the safeguarding requirements. Temporary guidance on safeguarding and prudential risk On 22 May 2020, we published a short consultation on coronavirus and safeguarding customers’ funds. We proposed additional temporary guidance to strengthen payment and e‑money firms’ prudential risk management and arrangements for safeguarding customers’ funds in the exceptional circumstances of coronavirus pandemic. Given our concerns about an increased risk of firms failing due to the impact of the coronavirus pandemic, we felt it was important that we provided our guidance to industry quickly. The consultation closed on 12 June 2020. We received responses from more than 60 organisations, including from payment firms, trade associations and law firms. We summarised and responded to feedback we received on our proposed guidance in FS20/10. The main comments we received were about: customer funds being held by firms on trust; calculating capital
adequacy; 5.7
CP21/3
Chapter 5
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
conducting compliance audits; and the treatment of unallocated funds. On 9 July 2020, we published our temporary guidance taking into account the feedback we received to our consultation.
5.8 We are now proposing to make this temporary guidance on safeguarding and
prudential risk management permanent and incorporate in our AD. This consultation gives stakeholders an opportunity to comment on the effect of adopting these measures on a permanent basis. Below, we have summarised the key sections of the proposed changes to our AD, in paragraphs 5.9‑5.17. Summary of the key sections being made permanent Safeguarding
5.9 We clarified in our temporary guidance that firms should have an acknowledgement
from their safeguarding credit institution or custodian, in the form of a letter, or have other documentation, to demonstrate that the safeguarding credit institution or custodian, has no interest in, recourse against, or right over the relevant funds or assets in the safeguarding account. It should also make clear that the funds in the safeguarding account are held for the benefit of the firm’s customers. An example letter was set out in the annex to the temporary guidance. We also confirmed our view that we consider that a firm holds these funds on trust for its customers.
5.10 A firm’s records should enable it and any third party, such as an insolvency practitioner
or the FCA to distinguish relevant funds from the firm’s own money, and relevant funds held for one customer against those held for another. For the avoidance of doubt, we clarified in our temporary guidance that we expect firms to document their reconciliation process clearly, with accompanying rationale. This will help with the distribution of funds if the firm becomes insolvent.
5.11 The conditions of authorisation for PIs and EMIs require them to satisfy us that they
have robust governance arrangements. We clarified in the temporary guidance that, as part of satisfying us that they have such arrangements, we expect firms that need to arrange audits of their annual accounts under the Companies Act 2006 to arrange specific annual audits of their compliance with the safeguarding requirements under the PSRs/EMRs. We also expect these firms to arrange audits of their compliance with safeguarding arrangements whenever there are any changes to their business model that would materially affect their safeguarding arrangements.
5.12 We expect the auditor to provide an opinion addressed to the firm on:
CP21/3
Chapter 5
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
to help make sure they can continue to meet their conditions of authorisation and own funds requirements. In particular, they should help firms assess whether they have adequate liquidity and capital resources, as well as identifying any changes and improvements to required systems and controls.
5.14 It is essential that firms accurately calculate their capital requirements and resources
on an ongoing basis, and report these correctly to us in regulatory returns, as well as when we request them.
5.15 To reduce exposure to intra‑group risk and as part of a firm’s stress testing and risk
management procedures, we consider it best practice for firms to deduct any assets representing intra-group receivables from their own funds. This is designed to make sure there is an adequate level of financial resources in each regulated entity at all times to absorb losses. It also reflects that a period of financial stress may affect the ability of other members of a firm’s group to repay amounts they owe.
5.16 Also, when firms are assessing whether they have adequate resources to cover
their liquidity risk, we consider it best practice for firms not to include uncommitted intra-group liquidity facilities. We expect firms to consider their own liquid resources and available funding options to meet their liabilities when they are due, and whether they need access to committed credit lines to manage their exposures. Firms should do this as part of their liquidity risk-management procedures. Wind-down plans
5.17 The conditions for being authorised or registered require a firm to satisfy us that
they have effective procedures to manage any risks they might be exposed to. We clarified in our temporary guidance that, as part of satisfying us that they have such procedures, we require firms to have a wind-down plan to manage their liquidity and resolution risks. The plan should consider the winding down of the firm’s business under different scenarios, including a solvent and insolvent scenario. Q8: Do you agree with our proposal to consolidate our temporary guidance in our AD to make the guidance permanent? If not, please explain why. Safeguarding – insurance or comparable guarantee method
5.18 Firms may safeguard customer funds using either the segregation method
of safeguarding or the insurance or guarantee methods of safeguarding, or a combination of these. Different risks are associated with the insurance and guarantee methods compared with the segregation method. In particular, risk of disputed claims where insurance policy or guarantee terms are not clear, or risk of a policy or guarantee not being renewed, which could be exacerbated if the firm does not have an adequate contingency plan.
5.19 We issued a letter to firms’ compliance officers in December 2019 (Appendix 3 to this
CP). In that letter, we provided guidance on risks and controls relating to the insurance method of safeguarding. We propose to consolidate this guidance in the AD, and apply it to the guarantee method of safeguarding.
CP21/3
Chapter 5
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
5.20
5.21
5.22
In the letter, we reminded firms that where a firm safeguards customer funds using insurance, it is important that the arrangements will make sure that, as soon as possible after the firm is subject to an insolvency event, the credit balance on the designated account will be the same as if the firm had segregated the funds all along. This means the insurance policy must pay out for the full amount of any shortfall regardless of how it comes about. It does not matter whether the insolvency event or shortfall is caused by any fraud or negligence on the part of the institution or any of its directors, employees or agents. Also in our letter, we clarified that, to make sure an institution’s relevant funds remain adequately safeguarded:
CP21/3
Chapter 6
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
6 Other changes to the AD
6.1 This chapter will focus on proposed miscellaneous amendments to the AD not
captured in the sections above.
Extension of BCOBS and Principles for Business
6.2 In PS19/3 we confirmed the extension of the FCA’s Principles for Businesses to
the provision of payment services and issuing of e-money by certain PSPs and e-money issuers. We also extended the application of certain communication rules and guidance in the Banking Conduct of Business Sourcebook (BCOBS) to communications with payment service and e-money customers and made new rules and gave guidance on the communication and marketing of currency transfer services.
6.3 We now propose to update the AD to reflect these changes.
Exclusions from the PSRs and the EMRs
6.4 Certain activities are excluded from the scope of the PSRs and the EMRs, subject to
meeting certain conditions. Carrying on excluded activities does not require being authorised by or registered with the FCA. Our proposed amendments relate to the Electronic Communications Exclusion (ECE), and the Limited Network Exclusion (LNE). While firms falling within scope of the ECE and LNE do not require FCA authorisation or registration, they must notify the FCA that they are operating within the scope of an exclusion (in the case of the LNE, this is subject to the business in the scope of the exclusion meeting certain thresholds).
6.5 The ECE applies to payment transactions resulting from services of providers of
electronic communication networks or services for digital content and voice-based services, tickets or donations to charity which are charged to a subscriber’s bill, subject to transaction limits. This includes, for example, mobile networks or online streaming services.
6.6 The notification requirement applies to the provider of the electronic communications
network or service. Such firms are required to make an initial notification including a description of the services they provide before they start providing the service. Then, firms are required to provide an annual audit opinion, testifying that the transactions the service is provided for comply with the applicable financial limits in the exclusion.
6.7 In December 2019, we wrote to the telecoms industry to provide an overview of the
ECE and to set out our expectations. This gave more information about the ECE conditions and how they apply. A copy of the letter is in Appendix 5 of this CP. We are proposing to update our AD to reflect the information in this letter.
6.8 The LNE applies to a firm providing services based on a specific payment instrument
or issuing monetary value that can be used only in a limited way and that falls within
CP21/3
Chapter 6
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
certain other criteria of the exclusion. A firm must complete a notification if the total value of the payment transactions executed through such services in any period exceeds €1m in a 12-month period. We have identified a lack of certainty in the industry on the scope of the LNE, and the information to be provided when submitting notifications. We also understand there is confusion among firms about what is required to ensure they comply with the ECE, and how to respond if they breach transaction thresholds.
6.9 We propose to amend the AD to clarify our expectations on notifications under the
LNE and ECE. This will include adding more detail on the types of information we expect to see as part of a firm’s notification and the types of firms that may be able to benefit from the LNE. We also propose additional guidance on the exclusions, as set out in section 8 of this CP. Reporting requirements
6.10 Under regulation 109 of the PSRs, firms must comply with reporting requirements to
the FCA. Firms are required to report a range of information to the FCA, including data on fraud and operational risk management.
6.11 In March 2020, we made changes to how EMIs should submit regular reporting to the
FCA. EMIs are now required to submit reporting via our Gabriel/RegData system. This change aligns the method of reporting for EMIs with that used by other FCA-regulated firms.
6.12 We have amended Chapter 13 of the AD on reporting requirements to reflect this
change.
6.13 In addition, we are proposing to replace the current FIN060 report, used by both
authorised electronic money institutions (AEMIs) and SEMIs, with separate reports for each firm type. We are proposing the use FIN060a for use by AEMIs, and FIN060b for use by SEMIs. This change is necessary to reflect the migration of reporting for EMIs that previously emailed their reports to the FCA. They are now required to complete these using Gabriel/RegData where applicable. Information sharing from ASPSPs to TPPs
6.14 Discussions with industry have highlighted confusion and disagreements on the data
that ASPSPs with PISPs should share, and in particular whether they should share the name of the account holder as well as their account number and sort code. We propose to clarify that ASPSPs must share the name of the account holder with PISPs, if the name is shown to the customer in their online account. The same applies to the account number and the sort code if these are shown to the customer after they make a payment. This guidance reflect EBA Q&A 2018_4081 and this June 2020 EBA opinion, and follows from regulation 69(2)(b) of the PSRs.
6.15 These changes reflect existing industry practice. We intend to make some changes in
chapter 20 of the AD.
CP21/3
Chapter 6
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
eIDAS certificates
6.16 In November 2020, we published PS20/13. Here, we amended Article 34 of the
SCA-RTS to require account providers to accept at least one other electronic means of identification issued by an independent party, in addition to eIDAS certificates. We propose to amend chapter 17 of the AD to reflect this. Q10: Do you agree with the proposed changes to the sections above? If not, please explain why.
CP21/3
Chapter 7
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
7 Changes to the AD reflecting the UK’s exit from the EU
7.1 From IP Completion Day, EU law ceased to apply in the UK. The UK’s withdrawal from
the EU triggered a significant programme of amending legislation to make sure that the UK continued to have a functioning financial services regulatory regime after IP Completion Day. This has been referred to as onshoring. Effective on IP Completion Day, multiple changes were made to the legislation, regulatory rules and guidance applicable to payment services and the issuance of e-money.
7.2 We have updated the AD to reflect these legal changes, noting that, in some cases,
there are transitional provisions allowing firms to delay complying with certain changes in law made as part of the onshoring exercise. While these changes affect most chapters in our AD, the chapters most substantively affected are Chapters 2 (Scope), 8 (Conduct of business requirements) and 10 (Safeguarding).
7.3 In addition, the UK’s participation in the passporting regime ended on IP Completion
Day. This meant many EEA firms, previously operating in the UK on the basis of a passport, would need to seek authorisation in the UK to continue to access the UK market after the transition period. To minimise disruption, the Government introduced schemes to grant transitional UK authorisation, or exemption from the requirement to be authorised, to such firms. The schemes applicable to incoming EEA EMIs, PIs and RAISPs are set out in Schedule 3 of the Exit SI.
7.4 We have also updated the AD to explain how the PSRs, EMRs, our rules and guidance
apply to firms with transitional authorisation or who are in the regime for contractual run-off. To do so, we have removed the existing Chapter 6, which dealt with passporting, and replaced it with an entirely new chapter setting out guidance on the temporary permission schemes under the Exit SI. We recommend that firms relying on such transitional authorisations or benefiting from the contractual run-off exemptions read
Chapter 6 first, as it contains instructions on how to read the other parts of our AD.
Q11: Do you agree with proposed Brexit-related changes to our AD? If not, please explain why.
CP21/3
Chapter 8
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual 8 PERG Amendments
8.1 As per para 6.4 to 6.9 above, we have identified a lack of clarity in the industry on the
types of products and services within scope of the criteria for exclusion under the LNE and ECE.
8.2 We propose to amend PERG 15 to provide additional guidance on the types of
products that may benefit from the LNE. More details of these changes can be found in appendix 2 of the CP.
8.3 We also propose to amend PERG 15 to give guidance on our expectations of firms that
benefit from the ECE. More details of these changes can be found in appendix 2 of this CP. Q12: Do you agree with our proposed changes to PERG on the scope of the LNE and ECE? If not, please explain why.
CP21/3
Annex 1
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Annex 1
Questions in this paper
Q1: Do you agree with our proposal to create a new SCA exemption for when customers access customer information through a TPP and add a new requirement for TPPs to check customers’ consent every 90 days? If not, please explain why. Q2: Do you agree with our proposal to mandate the use of dedicated interfaces for TPP access to retail and SME customers’ payment accounts and with our proposed timeline for doing so? If not, please explain why. Q3: Do you agree with our proposals to only require ASPSPs to make the technical specifications and a testing facility available at market launch of the interface, and to delay the need for a fallback interface for six months from the point of launch? If not, please explain why. Q4: Do you agree with our proposal to treat exemptions from setting up the contingency mechanism fallback interface granted by home state competent authorities, to ASPSPs with temporary authorisation, as though they were granted by the FCA? If not, please explain why. Q5: Do you agree with our proposed amendment to increase the cumulative threshold of the contactless exemption from £130 to £200? If not, please explain why? Q6: What is your view on increasing the current regulatory contactless (single) threshold limit of £45 to £100 (or potentially a maximum of £120)Please explain your rationale, including supporting data and new threshold where applicable. If your response identifies potential risks and benefits, please provide evidence in support of your response. Q7: Do you agree with the proposed changes to SCA? If not, please explain why. Q8: Do you agree with our proposal to incorporate our temporary guidance in our AD to make the guidance permanent? If not, please explain why. Q9: Do you agree with our proposal to consolidate in our AD, our guidance on safeguarding insurance as set out in our letter of December 2019 to firms’ compliance officers and that we also apply that guidance to the guarantee method of safeguarding? If not, please explain why.
CP21/3
Annex 1
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual Q10: Do you agree with the proposed changes to the sections in chapter 6? If not, please explain why. Q11: Do you agree with proposed Brexit-related changes to our AD? If not, please explain why. Q12: Do you agree with our proposed changes to PERG on the scope of the LNE and ECE? If not, please explain why. If you do not agree with any questions posed within this CP, please explain why.
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Annex 2
Cost benefit analysis
SCA-RTS
Introduction
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Requirements for modified customer interfaces
At present, ASPSPs have the option to develop a dedicated interface (such as an API) or to modify an existing customer interface (MCI). The MCI provides access to TPPs via the existing customer interfaces (typically the online banking platform). MCIs have not worked in practice, because many TPPs do not have the technology to connect via MCIs. Those who do must make considerable adjustments to access individual MCIs due to a lack of standardisation. This process is costly and time consuming. While we have encouraged the use of APIs, many ASPSPs continue to provide access to TPPs using MCIs. The driver of harm in this area can be analysed as an externality. ASPSPs are responsible for the decision to put dedicated interfaces in place. These firms incur a cost from doing so, but may also benefit through attracting more consumers as a result and/or having a higher consumer satisfaction score. The social benefits of putting dedicated interfaces in place exceed those benefits. Dedicated interfaces can not only save time for consumers and improve security, but also bring about better competition among TPPs, better services and innovation in the sector, and a development beyond open banking towards open finance. Firms are unlikely to take the latter effects into account when deciding to develop an MCI, resulting in sub-optimal investment in this area. As a result, the appeal of TPP services is significantly reduced and the type of services TPPs can offer is limited. This can lead to consumers abandoning the use of TPP services, or TPPs discontinuing their products. For example, three well-established TPPs that used to provide services to customers have stopped doing so due to the impracticality and technical restrictions of MCIs. A TPP has reported stopping services to over 35,000 customers as a result. Another large TPP reports that it no longer serves over 11,000 of its customers as a result of customers’ account providers choosing to develop an MCI account. For the minority of TPPs that make use of MCIs, accessing customer information is impractical because in most cases they cannot do so without the customer being logged into their TPP account simultaneously. As a result, customers cannot receive automatic updates or services relying on data refreshing in the background. This causes inconvenience for the customers and significantly reduces the appeal and range of the services provided by TPPs. Another harm is the reduced ability for the open banking ecosystem to become fully inter-operable and interconnected to reap further customer benefits as well as to serve as a basis for the launch of open finance, i.e. data sharing beyond payment accounts data. A final harm associated with MCIs is that access is not as secure as APIs. MCIs provide unrestricted access to all data available via the online banking platform. This often includes information other than payment account data that is required to be shared under the PSRs. This could cause harm to
customers and may reduce confidence in open banking. Technical specifications and testing facilities requirements Account providers must provide a testing facility for and share technical specifications with TPPs at least 6 months before launching a new product. Also, where ASPSPs opt to comply using a dedicated interface, they must have a dedicated interface and adapt
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
the consumer interface in order to support continuity of service for TPPs were the dedicated interface to fail (the adapted interface is known as the fallback interface). This is unless they obtain an exemption from the FCA.
18. The driver of harm here is the requirements of the current regulation. The associated
costs and lead times act as a deterrent to competition and innovation, placing additional burdens on new-to-market initiatives. Apart from the higher costs to firms, this requirement leads to delays in launching new products. We also think this may act as a barrier to competition and innovation in the ASPSP market. Requiring ASPSPs to share a testing facility and specifications could reveal what their product offering is before they have offered it to customers, possibly leading to others copying their idea before release. This requirement is likely to be particularly detrimental to new providers in the market, which may choose not to enter due to the associated risk. Reduced competition then indirectly leads to consumer detriment: consumers lose out on competitive products and lower prices on TPP services. Cumulative and single thresholds for contactless payments
19. At present, consumers can make contactless payments until they reach the
cumulative transaction value threshold of £130 or after making 5 contactless transactions in a row. Once they reach this threshold, they must complete SCA. In practice, this means consumers must insert a card into a card reader and enter their PIN. We understand the industry has generally opted to apply the cumulative transaction value, rather than transaction volumes. The intended effect of this requirement is reduced risk of fraud – for example, requiring customers to complete SCA ensures that if their card is stolen, the potential loss of funds will be limited.
20. After the contactless limit went up to £45, the average number of transactions
before a customer had to reauthenticate naturally decreased. Without changing the cumulative transactions value threshold, the frequency with which customers have to reauthenticate would increase, negating the benefits of having a higher contactless limit, particularly with a further increase of the single threshold from £45 to £100.
21. The harm in this case is that consumers spend more time on reauthenticating. In
addition, not all devices enable customers to conduct SCA (e.g. smart watches) and this can lead to customers abandoning purchases. Due to the coronavirus pandemic, and the health risks associated with touching a keypad, the costs to consumers from more frequent reauthentication are at present even higher. Our intervention
22. We are proposing amendments to the SCA RTS to remove barriers to competition and
innovation in the payments and e-money sector, while maintaining safety and security of UK payments.
23. Our proposed changes include:
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Baseline and key assumptions
27. Below we outline the firms our intervention affects and describe our assumptions. We
note that the sector is growing rapidly – open banking users increased from 1 million to 2 million between January and September 2020 and are expected to exceed 3 million in
2021. This rapid growth makes predicting the market size in the medium term difficult.
Our estimates are therefore based on current numbers. We assume that costs and benefits resulting from our intervention will grow in proportion to the market.
28. The number of firms affected by our proposals is summarised in the below.
Area of update
Article 10A exemption
Firms affected
ASPSPs – number estimated at 272*
105 RAISPs
369 TPR firms with PSD, E‑money and deposit taking permissions Changes to requirements for modified customer interfaces 252 small and medium ASPSPs Amendments to Technical Specifications and Testing Facilities requirements Changes to the cumulative threshold for contactless payments ASPSPs – number estimated at 272 369 TPR firms with PSD, E‑money and deposit taking permissions ASPSPs – number estimated at 272 369 TPR firms with PSD, E‑money and deposit taking permissions
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Summary of costs and benefits
32. We expect that our proposals will result in direct costs to firms, as described below.
Stakeholder
Firms
One‑off/ ongoing
One‑off
Costs
Familiarisation and legal –
£203k
Costs of setting up a dedicated interface–£7.9m‑£36.2m IT changes – £1.6m Change project costs – £1.7m Benefits Ongoing Costs of running a dedicated interface – £11m TPPs able to attract more customers as friction reduces due to APIs TPPs to retain more customers as 90-day reauthentication rule changes Lower costs to ASPSPs when releasing newproducts as they don’t need to publish testing facility before launch Customers Ongoing Less time spent authenticating Better access to TPP services and better variety and quality of TPP services Less time spent authenticating when making contactless payments Total One‑off £11.4m – £39.7m Ongoing £11m
33. We provide detail on the quantification of costs in the paragraphs below. We do not
believe it is reasonably practicable to quantify the benefits of the intervention. To provide such estimates we would need data that allows us to predict the increase in open banking users’ due to our intervention, as well as the reduction in customer churn rates. We are not aware of any such data, especially given the relative infancy of open banking.
34. Nonetheless, two of the interventions are non-binding, i.e. they allow for firms
to continue current practices – the amendments to the technical specifications and testing facilities requirements, and the changes to the single and cumulative thresholds for contactless payments. Therefore, for these elements of the policy, we assume firms will make the changes only if private benefits exceed costs, hence these requirements are net beneficial.
35. Although relying on the new account information exemption is not legally binding, we
encourage ASPSPs to rely on it. We give an explanation below of why we think benefits are likely to exceed costs.
36. The requirements for MCIs as well as the amendments to the 90-day requirement when
ASPSPs decide to use the exemption are binding. We expect that firms will incur costs as a result, and these costs need to be consider against the benefits of the policy. It is not reasonably practicable to quantify the costs, so instead we estimate the minimum amount of benefits that would need to be realised for the policy to break even.
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Costs
We anticipate that affected firms will incur direct costs due to familiarisation, setting up and running dedicated interfaces, adapting to the new exemption, and implementing a new cumulative threshold. We do not expect that firms will incur any indirect costs because of our intervention. Familiarisation and legal costs We use standard assumptions to estimate one-off familiarisation costs. We anticipate that there will be approximately 10 pages of policy documentation, excluding the legal instruments. Assuming 300 words per page and a reading speed of 100 words per minute, it would take around 0.5 hours to read the document. We assume the number of staff that read the document is 20 in large firms, 5 in medium and 2 in small. The hourly compliance staff salary assumption is based on the Willis Towers Watson 2016 Financial Services Report, adjusted for subsequent annual wage inflation and including 30% overheads. We expect all relevant firms to incur familiarisation costs. Hence, for those 746 firms, the total familiarisation cost is estimated to be £59,000. For legal costs, we assume 10 pages of legal text. We anticipate that 4, 2 and 1 legal staff will read the legal instruments in large, medium and small firms respectively, each staff member taking 12 hours. Basing the legal staff salary on the Willis Towers Watson 2016 Financial Services Report, we calculate legal costs of £144,000. The total one-off legal and compliance cost is estimated at £203,000. Changing 90‑day reauthentication We think firms will incur minor project costs to make the changes in relation to the amendment of the article 10 exemption, implementing the new article 10A exemption, and the new requirement for TPPs to reconfirm consent every 90 days. We model these costs based on our SCM. We expect the 746 firms in scope to make changes equivalent to a small IT project taking 46 person days at large firms and 8 person days for medium firms, and 5 days for small firms. We also expect that firms will make governance changes, subject to board and executive oversight, taking 45 person days at large firms, 14 person days at medium firms and 3 person days at small firms. The total one‑off IT cost associated with the Article 10 amendment are estimated to be £1.6m. The total one-off change project costs are estimated to be £1.7m. Setting up and running a dedicated interface Our changes will require some ASPSPs to develop a dedicated interface for certain payment accounts. Within the 252 firms that we expect could have to develop a dedicated interface, 190 are small and 62 are medium. We note that some firms are likely to have developed an API, but we take a conservative approach and apply the costs to all 252 firms. Data from the Open Banking Implementation Entity (OBIE) suggests that small firms could incur one-off costs of between £25,000 and £125,000 to set up a dedicated interface and annual costs of running such an interface of around £25,000. For medium firms, costs are between
£50,000 to £200,000 one-off and £100,000 ongoing.
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Based on these figures, we calculate a lower-bound estimate one-off total cost to the sector of £7.9m and an upper bound of £36.2m. We expect ongoing costs to the sector to be £11m per year. The estimated range for one-off costs is wide because the costs associated with developing a dedicated interface vary with the complexity of a firm’s backend IT systems, making it is difficult to predict the exact cost to the sector. Changing the testing facility and contactless thresholds requirements We do not expect firms to incur any costs beyond familiarisation and small governance change costs in relation to removing the requirement to release a testing facility 6 months before launching a new product, or the change to the contactless payment thresholds. We have included familiarisation costs in the overall familiarisation costs we quantify above, while we consider governance change costs to be insignificant. Benefits Setting up dedicated interfaces We listed the benefits relating to these changes above. These include time saved for both existing and potential customers, improved security, and increasing adoption of TPP services. We do not believe it is reasonably practicable to quantify these benefits. This is because they would require data allowing us to estimate the propensity for consumers to adopt TPP services arising from the reduced time. We estimate the cost of this element of the policy to be between £18.9m and £47.2m in the first year (£7.9m‑£36.2m one‑off and £11m ongoing) and £11m every following year. The net present value of costs over the next 10 years is between £117.9m and £146.2m. At present, there are 2.5 million open banking customers who stand to gain from this intervention, which means that over 10 years, customer benefits have to average between £4.70 and £5.80 per customer per year (in current £) for this element of the policy to break even. We note that open banking customers are expected to increase significantly over the period, which would reduce the break-even figure. To put our break-even figure into perspective, the report by the Independent Consumer and Small Business Representatives for the OBIE estimated consumer benefits from open banking of between £72 and £287 per person per year depending on customers’ financial situation. These figures suggest that the consumer benefits from our intervention are likely to exceed the break‑even figure of £4.70‑£5.80 per customer per year. Amending the article 10 exemption, and creating the new exemption The costs associated with this change amount to IT and governance changes. In our cost estimates, we have assumed full compliance, resulting in a total one-off cost to industry of £3.3m and no ongoing costs. The associated benefits to firms, however, include the ability to attract more customers and retain existing ones, because the time cost associated with accessing TPP services is reduced. We do not think it is reasonably practicable to estimate these benefits but we believe this
element of the intervention is in the interest of both firms and consumers and benefits will therefore exceed costs.
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Changing the testing facility and cumulative threshold requirements
51. As explained above, we do not anticipate costs to firms beyond familiarisation and
small governance changes. However, we consider that the associated benefits, in the form of lower costs to launching new products and saved time for consumers, are likely to be large. Furthermore, these changes are not binding, meaning that firms will only make them if private benefits exceed costs. We therefore believe that this element of our proposals is net beneficial. Guidance in Approach Document and PERG
52. We are not required to carry out a CBA when issuing guidance under the PSRs or EMRs.
However, regulation 106(3) of the PSRs and regulation 47(2) of the EMRs state that we must have regard to (among other things) the principle that a burden or restriction imposed on a person, or on the carrying out of an activity, should be proportionate to the benefits, in general terms, which are expected to result from that burden or restriction being imposed. Given these requirements, and the nature of the changes we propose, we have carried out a CBA.
53. Since the last update to the AD in June 2019, there has been significant innovation in
the way that people and businesses make payments. As the payments and e-money sector continues to evolve, we need to keep our guidance under review. In making changes to our guidance, we intend to provide greater transparency and clarity to the market on our approach.
54. We are bringing together the experience from recent firm failures and using these to
update the guidance in our AD and our PERG manual. The AD describes our approach to the PSRs and EMRs. It sets out our guidance and expectations of firms when applying the regulations to their business models. Amending the AD will help industry comply with the regulations in a more consistent manner, help to improve the financial stability of firms and support consumer protection.
55. The purpose of our PERG manual is to give guidance about the circumstances in which
authorisation is required, including guidance on the activities that are regulated under the PSRs, the EMRs and FSMA, and the exclusions which are available. Updating PERG will be beneficial to firms as they will have clearer examples of what types of firms can benefit from the exclusions in the PSRs and EMRs.
56. The updates to the AD fall into four categories. These are:
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
In the sub-sections below we give an overview of the issues that may lead to these harms. Insufficient liquidity and capital stress testing Our supervisory work has identified concerns about the ability of PSPs to survive a severe but plausible stress event. These are mainly due to the sector being immature and the requirements being absent in regulations with respect to liquidity stress testing (aside from the high-level authorisation conditions). We estimate (based on supervisory experience) that only 16% of non-banking PSPs carry out some stress testing, but even in those cases, the stress-testing scenarios were found to be insufficient. Our work has shown that funding risk is a concern for a large proportion of PSPs that are loss making. These firms tend to be start-ups and/or competing in a saturated market. Many of them are funded by private equity or venture capital. At the same time, most firms do not have access to credit lines. We also found that settlement risk is a material risk arising from timing differences between cash in-flows and out-flows. Some e-money firms may issue e-money before funds are credited to their payment account or otherwise made available to them, leading to liquidity risks. Without guidance on stress testing, these risks are more likely to crystallise, leading to high rates of firm failure. In these events, even if customers can ultimately recover their funds, time and effort they spend in claiming those funds, as well as the stress and financial pressure they incur, are material harms. Furthermore, the overall trust in the PSP sector may be undermined if rates of firm failure are high. Exposure to intra‑group credit risk Our supervisory work shows that a significant proportion of firms have complex structures, which are associated with a high level of intra-group lending. Furthermore, many firms are highly leveraged and have high dividend pay-out rates, which may put financial pressure on the revenue-generating entity (normally the regulated entity within the group). Finally, firms rely on their parent entities in other ways, for example through outsourcing important functions and decisions to the parent and not having an independent board or a business plan. This makes assessing the financial health of the regulated entity difficult, particularly where that entity has not deducted intra-group receivables from its regulatory capital calculations. The main harm in not addressing this problem will be a disorderly failure and potential losses of customer funds. We understand several firms have been including intra-group receivables in their capital adequacy calculations, which exposes them to intra-group credit risk, reducing their financial stability in a group stressed scenario. We found that in a sample of 29 non-banking PSPs, 41% of firms would be pushed into a capital deficit if they deducted intra-group balances. Insufficient safeguarding of customer funds Safeguarding customer funds is a key consumer
protection measure within the EMRs and PSRs. It is vital that all firms have appropriate and well managed safeguarding arrangements to make sure that, if they become insolvent, customers’ funds are returned in a timely way.
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
*Relevant TPR firms are E-money issuers and PSD firms with the following permissions:
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Stakeholder
One‑off/ ongoing Costs Benefits
Customers Ongoing
Reduced risk of financial loss due to firms failing or due to shortfalls in funds owed to customers by insolvent firms The wider system Ongoing Increased financial stability Total cost One‑off £1.6m Ongoing £10.4m
82. We do not believe it is practicable to monetise the benefits of enhanced financial
stability. It is also not reasonably practicable to estimate the benefits of a reduced risk of financial loss to customers, as we would need to quantify the effect on firm failures resulting from our policies. This would require us to estimate the causal impact of higher capital, stress testing and safeguarding audits on the probability of firm failure. We are not aware of any datasets or published studies that can produce this estimate.
83. To analyse whether the costs are proportionate to benefits, we provide a break-even
analysis below.
Costs
84. We anticipate that firms will incur direct costs due to familiarisation, stress testing, and
obtaining an annual audit of compliance with safeguarding requirements. They will also incur the cost of raising additional capital where they have previously not deducted intra-group loans from their capital calculations. There are also indirect costs arising from capital requirements, which we cannot practicably quantify. We give an overview of our approach to estimating these costs in the sections below. Familiarisation and legal costs
85. We use standard assumptions from our SCM to produce an estimate of familiarisation
costs. We anticipate approximately 40 pages of policy documentation excluding the legal instrument. Assuming 300 words per page and a reading speed of 100 words per minute, it would take around 2 hours to read the document. We assume that the number of staff that read the document is 20 in large firms, 5 in medium and 1 in small. The hourly compliance staff salary assumption is based on the Willis Towers Watson 2016 Financial Services Report, adjusted for subsequent annual wage inflation and including 30% overheads. We expect all firms in scope to incur familiarisation costs. Hence, for the 810 firms affected, the total familiarisation cost is estimated to be £156,200.
86. In legal costs, we assume 5 pages of legal text. We note that there are minor changes
throughout the AD, but we estimate that the substantial changes are equivalent to 5 pages of legal text. We anticipate that 4, 2 and 1 legal staff will read the legal instrument in large, medium and small firms respectively, taking 12 hours each. Basing the legal staff salary on the Willis Towers Watson 2016 Financial Services Report, we calculate legal costs of £34,433. The total legal and compliance cost is estimated at £190.7k.
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Stress testing
As a result of the guidance around prudential risk management, we expect firms to carry out liquidity stress testing. An FCA review of 41 firms identified that 95% of the firms in the sample were not carrying out sufficient liquidity stress testing. We therefore assume that, under full compliance, stress testing costs will be incurred by the 619 PIs and EMIs, all SEMIs. We note that more rigorous stress testing may induce firms to hold more liquidity or capital. Raising these additional funds will have an additional cost. However, it is not reasonably practicable to predict the increase in liquidity and capital for each firm resulting from this guidance, so we do not quantify this cost. The SCM captures the estimated cost of such changes through change projects, which principally estimate costs on the basis of time incurred by a project team and project management, including senior staff time. We use existing internal data from research the FCA has undertaken to understand this type of project and estimate these costs. We expect that the larger firms will on average spend 90 days to establish the governance process to perform stress testing. The required person days are 28 and 6 for medium and small firms, respectively. The time is spread across project teams and executive and board oversight. We use information from Willis Towers Watson to estimate salaries, and apply a 30% overhead. We expect the ongoing annual cost of stress testing to halve after the first year once the governance processes are established. We estimate the total costs to firms to be £1.4m in the first year and £697.6k every following year. Calculating capital To assess how our guidance on calculating regulatory capital affects firms, we analysed financial data for a sample of 29 non-banking PSPs, gathered in our supervisory activities. Our findings show that, at the end of 2017, firms in the sample had on average £22.4m capital. The average capital surplus firms had was £13.1m. We also calculated that firms had on average £7m owed to them from other entities in their group. This indicates that, on average, if firms remove intra-group balances from their own funds, they will still have a surplus (assuming that the levels of capital relative to their capital requirement remain relatively stable). However, the position of the firms in our sample varied greatly. For example, we found that 41% of firms would be pushed into a capital deficit if they removed intra-group balances from capital calculations. For this group, the average amount of capital that they would have to raise is £8.6m. However, there are three reasons why we expect that this cost is unlikely to be widespread, will be easily absorbed by affected firms, or won’t arise in the first place. Firstly, having intergroup transactions requires a level of complexity in the operations of a company which is usually present at the larger, more established firms. Our sample consists of data on the largest EMIs and PSPs, so we
expect the percentage of firms who would have to raise additional capital as a result of this requirement to be significantly lower than 41% of the population.
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Secondly, firms with intra-group balances also tend to be profitable, have established business models or funds available in the group to draw on, hence it should be easier for them to absorb the costs and increase capital. Thirdly, we expect firms to respond to the new requirements by putting in place netting agreements which allows them to offset the funds owed to them from other entities in their group against the amounts that they owe. This means firms that are net creditors in their group would not have to subtract these assets from own funds. The only associated cost in this case is the legal cost of setting up the netting agreement. Note that this would not be possible for firms who are net debtors in their group (6 out of 29 firms in our sample). These firms would have to remove net balances from own funds (and would have to raise additional capital if that pushes them into a deficit). Quantifying the total cost to industry is not practicable, however, as we don’t know the exact proportion of firms in the population of firms which will have to raise extra capital. Our final cost calculations do not include the cost of raising this capital, however, we recognise that some proportion of firms may incur such costs. Annual safeguarding audits In accordance with our proposed guidance, we would expect all authorised PIs, authorised EMIs and SEMIs to arrange independent reviews of their compliance with the safeguarding provisions of the EMRs and PSRs on an annual basis. E-money issuers and PSD firms under TPR are also in scope. We have estimated the cost of these reviews based on our supervisory work. As part of our work, we have required some firms to instruct consultants to carry out independent reviews of their compliance with the safeguarding provisions of the EMRs and PSRs. Similarly, we require firms that hold client funds subject to the rules in our Client Asset Sourcebook (CASS), to instruct auditors to audit their compliance with our CASS rules. Based on the costs that firms have incurred in arranging these independent reviews and audits, typically ranging from £6,000 to £12,000, we have assumed that the cost of a safeguarding compliance audit would be £12,000. The costs of carrying out a compliance audit vary by auditor, as well as by the size and complexity of the firm. We are taking a conservative approach by taking the upper bound of costs for similar work that we have observed, and applying it to the 810 affected firms. We estimate the total costs to firms to be £9.7m on an annual basis. Indirect firm costs There may be an indirect cost of reduced leveraging ability due to our guidance on capital requirements. However, we cannot reasonably quantify this cost. By leveraging ability, we mean the ability of firms to use debt to acquire additional assets. Capital requirements mandate that a certain proportion of a firm’s assets are own funds, which limits the firm’s ability to acquire assets. To calculate this cost, we would need to
calculate by how much capital requirements would reduce firms’ assets, as well as a credible estimate of the return on these assets, which we cannot practicably quantify.
CP21/3
Annex 2
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Costs to the FCA
104. There are no expected additional resource implications relating to our activities from
the proposals. Compliance will be monitored through business as usual processes within existing resources. Benefits for consumers
105. Stronger capital and liquidity risk management procedures can benefit consumers
by limiting the probability that they lose money held at EMIs or authorised PIs. Based on regulatory returns, we estimate that the amount of client money held at these firms is more than £10bn. The potential for consumer harm from poor prudential risk management and safeguarding is high as shown by the £40m shortfall owed to customers following the failure of 5 PSPs between October 2018 and March 2020. In comparison, the ongoing cost of our policy for a period of the same length is expected to be £15.6m – two and a half times less than the estimated shortfall. These customer losses are not a counterfactual, but they illustrate the need for better prudential risk management. If implemented, our guidance goes a significant way in this direction.
106. Note that due to the growth of the sector, we expect an annual increase of 30 firms
operating in the market. We expect that the cost of our policy will grow at the same rate as the new firms are subject to the same guidance. Nonetheless, we also expect benefits to grow proportionately.
CP21/3
Annex 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Annex 3
Compatibility statement
CP21/3
Annex 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Compatibility with the principles of good regulation, regulation 106 of the PSRs, and regulation 47 of the EMRs
8. In preparing the proposals set out in this consultation paper, we have considered the
regulatory principles set out in Regulation 106(3) of the PSRs and Regulation 46 of the EMRs. We set out below how our proposals are compatible with each principle.
9. In preparing the proposals set out in this consultation, we have also had regard to the
regulatory principles set out in s. 3B FSMA and incorporated consideration of those principles in the below.
10. The need to use our resources in the most efficient and economical way:
For the proposals in this consultation, we have considered the burden on the FCA of assessing how best to implement them. By providing greater clarity on our expectations in our guidance, we can reduce the need for the FCA to use its resources to encourage better practice in this market. When the guidance is made, this should reduce the resources we use in responding to requests for guidance. Our proposals on the exemption from setting up a fallback interface support the effective use of FCA resource by avoiding the duplication of an assessment already carried out by a competent authority.
11. The principle that a burden or restriction which is imposed on a person, or on the
carrying on of an activity, should be proportionate to the benefits, considered in general terms, which are expected to result from the imposition of that burden or restriction. We believe the proposals in this consultation containing burdens or restrictions are proportionate to the benefits and set out our analysis of the costs and benefits of our proposals in our CBA.
12. The desirability of sustainable growth in the economy of the UK in the medium or
long term.
As our proposals focus on driving better outcomes for customers, and better competition, we expect that they can support growth in the UK economy by encouraging more efficient allocation of resources, and greater consumer trust in the financial services sector. Some of our proposals relate to the improved operation of open banking, which seeks to drive competition in payment services, and improve access for payment services businesses.
13. The general principle that consumers should take responsibility for their own
decisions
We do not propose any requirements that are inconsistent with this principle.
CP21/3
Annex 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
The responsibilities of those who manage the affairs of persons subject to requirements imposed by or under the EMRs and PSRs. We believe the proposals in this consultation are consistent with this principle. Senior managers of payment service providers and e-money issuers will need to ensure compliance with the PSRs, SCA-RTS, the EMRs, the Exit SI and all other relevant requirements in the legislation applicable to payments and the relevant parts of our Handbook (as applicable). The desirability, where appropriate, of the FCA exercising its functions in a way that recognises differences in the nature of, and objectives of, businesses carried on by different persons subject to the requirements imposed by or under the PSRs. We do not believe our proposals discriminate against any business model or approach. We have considered specific requirements for firms conducting different payment services and issuing e-money. In particular, our proposals for the SCA-RTS involved carefully considering the different firms operating to give effect to open banking, recognising the differences between those servicing the payment accounts being accessed and those TPPs proposing to access customer accounts (i.e. AISPs, PISPs and CBPIIs). The desirability in appropriate cases of the FCA publishing information in relation to persons on whom requirements are imposed by or under the PSRs. Our proposals are compatible with this principle. The principle that the FCA should exercise its functions under the PSRs as transparently as possible. We believe that by consulting on our proposals we are acting in accordance with this principle. In particular, our amendments to PERG and the AD as regards the LNE and ECE, if adopted, would make the conditions for relying on these exemptions and process for notifying us more transparent. We are also choosing to set out detailed guidance in our AD to help firms navigate the requirements of the temporary permissions regimes and explain the application of our relevant rules and guidance to activities of those firms in the UK. The desirability of facilitating innovation and competition in connection with the issuance of electronic money and the provision of payment services. Our proposals have the potential to accelerate payment services innovation by making open banking more accessible. This could lead to greater choice for customers, who could benefit from more flexibility around accessing their accounts and making payments. Competition pressures could also mean that customers pay lower prices for their payment services. This innovation and competition could contribute to growth in the payment services sector and in turn the UK economy. The international character of financial services and markets, and the desirability of maintaining the UK’s competitive position. In our view, our proposals would serve to improve the operation and accessibility of open banking and keep it at the forefront of international payments innovation.
CP21/3
Annex 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
By giving guidance on operating the temporary permissions schemes applicable to EEA firms that provided payment services and issued e‑money in the UK before the end of the transition period, we aim to support the continued provision of cross-border services for a limited time. This will help avoid disruption to these firms. The need to minimise adverse effects on competition that may arise from anything done in the discharge of those functions. Our proposals are compatible with this principle. The desirability of enhancing the understanding and knowledge of members of the public of financial matters (including the UK financial system). This principle is not relevant to our proposals Compatibility with regulation 106a of the PSRs
20. In preparing the proposals relating to the SCA-RTS set out in this consultation paper,
we have also considered the regulatory principles set out in Regulation 106A(2) of the PSRs 2017. We set out below how our proposals are compatible with each principle.
21. Ensuring an appropriate level of security for payment service users and payment
service providers through the adoption of effective and risk-based requirements. We believe the proposals we set out in our CP comply with this principle on the basis that the amendments to the SCA-RTS are required to support innovation and secure payments for customers. Our proposals to amend the SCA-RTS should also help protect consumers by making sure data sharing and payments are done securely Our proposals will help firms comply with their regulatory obligations, strengthening financial resilience and the safeguarding of customer funds, ultimately improving consumer protection. Two changes (relating to testing facilities and contactless limit) relate to the need for secure payments with user convenience (when using contactless payments), and to better support innovation. These are a change to the requirement that ASPSPs should release technical specifications on access to accounts six months before launching new products, and an increase in the limit for contactless payments.
22. Ensuring the safety of payment service users’ funds and personal data.
We believe our proposals are aligned with this principle as the amendments are intended to ensure increased levels of security, as far as possible. Our proposals to amend the SCA-RTS, issue new guidance in the AD and PERG should strengthen market integrity and improve trust in the financial system. This is by making data sharing and payments more secure and giving firms more clarity on their regulatory obligations and support the financial stability of firms.
CP21/3
Annex 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
CP21/3
Annex 3
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Legislative and Regulatory Reform Act 2006 (LRRA)
31. We have had regard to the principles in the LRRA and the Regulators’ Code for the
parts of the proposals that consist of general policies, principles or guidance and consider that our proposals are proportionate and result in an appropriate level of consumer protection, when balanced with impacts on businesses and on competition
CP21/3
Annex 4
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Annex 4
Abbreviations used in this paper
AD Approach Document
AEMI Authorised electronic money institutions
AISP Account Information Service Providers
API Application Programme Interface
ASPSPs Account servicing payment service providers BCOBS Banking Conduct of Business Sourcebook CASS Client Assets Sourcebook CBA Cost benefit analysis CBPIIs Card-based payment instrument issuer CBPR2 Second Cross Border Payments Regulations CEO Chief executive officer CP Consultation Paper EBA European Banking Authority ECE Electronic Communications Exclusions EEA European Economic Area eIDAS electronic identification and trust services EMI Electronic money institution EMRs Electronic Money Regulations 2011 EU European Union EU- RTS EU Regulatory Technical Standards FSCR Financial Services Contracts Regime FSCS Financial Services Compensation Scheme
CP21/3
Annex 4
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
FSMA Financial Services Markets Act
IP Completion Implementation Period Completion Day Day LNE Limited Network Exclusion LRRA Legislative and Regulatory Reform Act 2006 MCI Modified customer interface OBIE Open Banking Implementation Entity PERG Perimeter Guidance Manual PI Payment institution PIs Payment institutions PISPs Payment initiation service providers PSD2 Revised Payment Services Directive PSPs Payment service providers PSRs Payment Services Regulations 2017 RAISPs Registered account information services providers SCA-RTS Strong Customer Authentication – Regulatory Technical Standards SAR Special Administration Regime SCA Strong Customer Authentication SCM Standardised cost model SEMI Small electronic money institution SPI Small payment institution SRO Supervised Run-off Regime TPPs Third party providers TPR Temporary permissions regime
CP21/3
Annex 4
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Sign up for our news and publications alerts
We make all responses to formal consultation available for public inspection unless the respondent requests otherwise. We will not regard a standard confidentiality statement in an email message as a request for non-disclosure. Despite this, we may be asked to disclose a confidential response under the Freedom of Information Act 2000. We may consult you if we receive such a request. Any decision we make not to disclose the response is reviewable by the Information Commissioner and the Information Rights Tribunal. All our publications are available to download from www.fca.org.uk. If you would like to receive this paper in an alternative format, please call 020 7066 7948 or email: publications_graphics@fca.org.uk orwrite to: Editorial and Digital team, Financial Conduct Authority, 12 Endeavour Square, London E20 1JN
CP21/3
Appendix 1
Financial Conduct Authority
Changes to the SCA-RTS and to the guidance in ‘Payment Services and Electronic Money – Our Approach’ and the Perimeter Guidance Manual
Appendix 1
Proposed amendments to the
Approach Document
Proposed amendments to the Approach
Document
The FCA’s role under the Payment Services Regulations 2017 and the Electronic Money Regulations Changes to the following chapters:
Preface
Chapter 1 – Introduction
Chapter 2 – Scope
Chapter 3 – Authorisations and registration
Chapter 4 – Changes in circumstances of authorisation or registration
Chapter 5 – Appointments of Agents and use of Distributors
Chapter 6 – Passporting
Chapter 7 – Status disclosure and use of FCA logo
Chapter 8 – Conduct of Business requirements
Chapter 9 – Capital recourse requirements
Chapter 10 – Safeguarding
Chapter 11 – Complaints handling
Chapter 12 – Supervision
Chapter 13 – Reporting and notifications
Chapter 14 – Enforcement
Chapter 15 – Fees
Chapter 16 – Payment service providers’ access to payment account services
Chapter 17 – Payment initiation and account information services and confirmation of
availability of funds
Chapter 18 – Operational and security risks
Chapter 19 – Financial crime
Chapter 20 – Authentication
New chapter
Chapter 6 – Temporary Permission Schemes
Preface
This document will help businesses to navigate the Payment Services Regulations 2017 (PSRs 2017)1 and the Electronic Money Regulations 2011 (EMRs) (together with our relevant rules and guidance), and to understand our general approach in this area. It is aimed at businesses that are, or are seeking to become:
1 Introduction
1.1 Thisdocumentdescribesourapproachtoimplementingthe Payment Services Regulations 2017 (the
PSRs2017),the Electronic Money Regulations 2011 (theEMRs)and thesmallnumberofpayment servicesande‐money‐relatedrulesinourHandbookof Rules and Guidance (theHandbook). It gives readers a comprehensive picture of the paymentservicesande-money regulatory regime in the UK. It also provides guidance forapracticalunderstandingoftherequirements,our regulatory approach,andhow businesses will experience regulatorysupervision and the effect of Brexit on the payment services and e‐money regulatory regime.
1.2 Weuseanumberofsimilartermswithdistinctmeaningsinthisdocument.The glossaryof
terms,abbreviationsandacronymsattheendprovidesafulllist.
The payment services and e‐money regulatory regime
1.4 PSD2requirestheEuropeanBankingAuthority(EBA)toproduceanumberoftechnical standards and
guidelines for the implementation of PSD2. Where relevant, these shouldbereadalongsidethis document.TheEBAwillprovidefurtherclarificationsvia useoftheEBA’sSingleRulebookquestionand answertool.4 The Payment Systems Regulator’s Approach Document
1.3 ThePaymentSystemsRegulatorhaspublishedaseparateApproachDocumentonthe aspectsofthePSRs
2017 for which it is solely responsible, including access to payment systems, and information to be providedbyindependentATMdeployers. The payment services and e‐money regulatory regime
1.4 Theregime implement is set out in the PSRs 2017 and EMRs PSD2 and 2EMD. As with the first
Payment Services Directive (PSD1)5, PSD2 and 2EMD (and their implementing regulations) are closely interlinked.Most e‐money issuers will be carrying on payment services in addition to issuing e‐moneysowillneedtobefamiliarwithboththePSRs2017andtheEMRs,including the changes made as a result of the implementation of PSD2. The Handbook
1.5 TheHandbook–Relevanttobothpaymentservicesande‐money,theHandbooksets out,among
otherrelevantmaterial:
our Principles for Businesses, these set out in high‐level terms how firms should treat their
customers, how they should run their business and how they should interact with the regulator
therequirementsforcertainPSPs,includinge‐moneyissuers,tosubmitreturnsand certain
notifications
complaints handling procedures that PSPs and e-money issuers must have in place
therightofcertaincustomerstocomplaintotheFinancialOmbudsmanService
3 http://www.eba.europa.eu/single‐rule‐book‐qa 3 Directive2007/64/ECoftheEuropeanParliamentandoftheCouncilof13November2007onpaymentservicesintheinternal market amending Directives 97/7/EC, 2002/65/EC, 2005/60/EC and 2006/48/EC and repealing Directive 97/5/EC.
our policy and procedures for taking decisions relatingto enforcement action and when
setting penalties
our ongoing fees
leviesfortheFinancialOmbudsmanServiceandtheMoneyAdviceService
rules about communications (including marketing communications) in our Banking Conduct of Business
Sourcebook (BCOBs)
Payment Services
1.5 PSD2waspublishedintheEuropeanUnion’s(EU)OfficialJournalon23December 2015.Thefulltextof
PSD2canbefoundontheEU’swebsite. PSD2 replaces PSD1 and updatestheregulatory regimeto reflect changesinthemarketandremovebarriersto marketentry.Themainchangesaresummarised below.PSD2’saimsinclude:
contributingtoamoreintegratedandefficientEuropeanpaymentsmarket
levelling the playing field for paymentservice providers(PSPs)
promotingthedevelopmentanduseofinnovativeonlineandmobilepayments
making payments safer and more secure
protecting consumers
encouraging lower prices for payments
1.6 PSD2The PSRs 2017 willcontinuetogoverntheauthorisationandprudentialassociatedrequirements
forPIsauthorised or registered payment institutions (PIs). They alsoand settheconductofbusiness rulesforprovidingpaymentservices.
1.7 The PSRs 2017andpartsoftheHandbookimplementPSD2intheUK.Most payment service
providers (PSPs)are requiredtobeeitherauthorisedorregisteredbyusunderthePSRs2017andto comply withcertainrulesaboutprovidingpaymentservices,includingspecificrequirements for payment transactions.
1.8 ThePSRssetout, amongst other things:
the payment services in scope of the PSRs and a list of exclusions
the personsthatmust be authorised orregistered under the PSRs when theyprovide
payment services
standardsthatmustbemetbyPIsfor authorisationorregistrationtobegranted
capitalrequirementsandsafeguardingrequirementsforPSRs
conduct of business requirements applicable to payment services
our powers and functions in relation to supervision and enforcement in this area
The PSRs 2017 replace the Payment Services Regulations 2009 make the following changes to the regulatory regime. mend the authorisation and prudential regime for PSPs and e-money issuers that arenotbanksorbuilding societies (and so otherwise authorised by us). Such businesses are known as authorised payment institutions (authorised PIs) and authorised e-money institutions (authorised EMIs). Authorised PIs and authorised EMIs can passport their services to
other European EconomicArea (EEA) States. Because of their UK authorisation, they have the right to establish or provide services across the EEA.6 The exercise of passporting rightsis amended through thePSRs2017aswellastheEBARegulatory Technical Standards on passporting under PSD2.7 Further information can be found in Chapters 3 – Authorisation and registration, 6 – Passporting and 9 – Capital resources and requirements. Continue to allow PSPs and e‐money issuers operating beneath certain thresholds to be registered instead of obtaining authorisation (regulation 14 ofthe PSRs 2017 andregulation13oftheEMRs).SuchsmallPIsandsmallEMIsareunabletopassport. See Chapter 3 – Authorisation and registration and Chapter 6 – Passporting for further information. ContinuetoexemptcertainPSPs(e.g.banks)fromPSD2authorisationand registration requirements. Apply requirementstoPIsregarding changesin qualifying holdings,so thatthe requirement(whichalreadyappliedtoEMIs)that individualswishingtoacquireor divestshares–whentheypassagiventhreshold–arerequiredtonotifyus.See Chapter 4 – Changes in circumstances of authorisation and registration for further information. Atthe time of publishing this Approach Document, PSD2 has been adopted underscrutiny by the EEA. It has not yet been incorporated into the EEAAgreement or come into forcein Norway, LiechtensteinorIceland. Forclarity,wewillrefertoPSD2 throughoutthisApproachDocumentasifithasbeenincorporatedintotheEEAAgreementandhas comeintoforcein Norway, Liechtenstein andIceland. Commission Delegated Regulation (EU) 2017/2055 supplementing Directive (EU) 2015/2366 of the European Parliament and of theCouncilwithregardtoregulatorytechnicalstandardsfor the cooperation and exchange ofinformation between competent authoritiesrelating to the exercise of the right of establishment and the freedom to provide services of payment institutionsis available here: https://eur‐lex.europa.eu/legal‐content/EN/TXT/PDF/?uri=CELEX:32017R2055&from=EN Make changes to the appointment of agents. See Chapter 5 – Appointment of agents for further information. Makechangestotheconductofbusinessrequirements.Thismeansrequirements for information to be provided to payment service users, and specific rules on the respective rights and obligations of payment service users and providers. See Chapter 8 – Conduct of business requirements for further information. In addition, banksandbuildingsocietiesneedtocomplywith theBanking:ConductofBusiness Sourcebook (BCOBS). Makechangestotherequirementsregardingsafeguarding.SeeChapter 10– Safeguarding for further information. Make changes to the rules governing the access to payment account services that credit institutions provide to other PSPs. The rules state that access should be proportionate, objective and non‐discriminatory (POND). See Chapter 16 – Payment service providers’ access to payment account services for further information. Introduce two new payment services (account information services (AIS) and
paymentinitiationservices(PIS))andsetout requirements and rights around when and how payment accounts can be accessed. Changesrelating to these new payment services canbefoundthroughoutthisdocument. SeeChapter 17 – Payment initiationand account information services and confirmation of availablefunds for further information. Make changes to the rules governing access to payment systems. The rules state that accessshould be proportionate, objective andnon‐discriminatory (POND), subject to certain exemptions. See the Payment Systems Regulator’s Approach Document for further information. Introduce new requirements for all PSPs to manage the operational and security risks relating to the payment services they provide. Thisincludes establishing and maintaining effective incident management procedures and submitting reportsto us. See Chapter 18 – Operational and security risks and Chapter 13 – Reporting and notifications for further information. Introduce requirements for the security of payments and for communication betweenPSPsinaccordancewiththeRegulatory TechnicalStandardsonstrong customer authentication and common and secure communication (SCA-RTS).8 See
Chapter 17 – Payment initiation and account information services and confirmation of availability of funds and
Chapter 20 – Authentication for further information.
ThePSRs2017requiredvariouschangestobemadetothisApproachDocumentand werecommend thatbusinessesreviewallchaptersthatarerelevanttothem. 8 https://eur‐lex.europa.eu/legal‐content/EN/TXT/PDF/?uri=CELEX:32018R0389&from=EN E-money
2EMDwaspublishedintheEU’sOfficialJournalon10October2009.Thefulltextof 2EMDcanbefound ontheEU’swebsite. 9 2EMD was transposed into UK law in April 2011,throughtheEMRs.ThePSRs 2017containsomeconsequentialamendmentsto the EMRs.
1.9 The EMRs governtheauthorisationandassociatedrequirementselectronic money institutions
(EMIs). They also settheconductofbusinessrulesforissuing e‐money.
1.10 Moste‐money issuersarerequiredtobeeither authorised orregisteredby usandto complywith
rulesaboutissuinge‐moneyandcarryingonpaymentservices.Therules aresetoutintheEMRs,the PSRs2017andpartsoftheHandbook.
1.91.11 EMIs are authorised or registered to issue e-money and undertake payment services under the
EMRs, rather than under the Financial Services and Markets Act 2000 (FSMA).Itshouldbenoted, however,thatissuinge‐moneyremainsaregulatedactivity underarticle9BoftheRegulatedActivities Order2001forcreditinstitutions(i.e.banks andbuildingsocieties),creditunionsandmunicipalbanks, whichmeanstheywillbe authorised to issue e-money under a Part 4A FSMA permission.
1.91.1 Moste‐money issuersarerequiredtobeeither authorised orregisteredby usandto complywith
rulesaboutissuinge‐moneyandcarryingonpaymentservices.Therules aresetoutintheEMRs,the PSRs2017andpartsoftheHandbook.
1.101.12 TheEMRssetout, amongst other things:
Brexit
1.14 The PSRs 2017 and EMRs were amended and supplemented by statutory instruments made under
the European Union (Withdrawal) Act 2018, including the Electronic Money, Payment Services and Payment Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018 (the Exit SI), ensuring that they continue to operate effectively in the UK following the UK’s withdrawal from the EU. The changes they made to the regulatory regime included the following:
regulatory technical standards on the same.
1.19 On IP Completion Day, the FCA’s directions made under its Temporary Transitional Power (TTP)
came into effect. The TTP gives the FCA flexibility in applying post-Brexit requirements and the FCA has applied it broadly. Where it applies firms have until 31 March 2022 to come into full compliance with the new UK regulatory framework. This means that regulatory obligations on the firm will generally remain the same as they were before the end of the transition period, with some exceptions, a key exception being the requirements relating to strong customer authentication and common and secure open standards of communication. The detail of how and to what the TTP applies to is set out in the main FCA transitional directions and the annexes to those directions. Firms in the TPR and SRO should note that the TPP does not apply to these regimes. The Payment Systems Regulator’s Approach Document
1.20 ThePaymentSystemsRegulatorhaspublishedaseparateApproachDocumentonthe aspectsofthe
PSRs2017forwhichitissolelyresponsible,includingaccesstopayment systems,andinformationtobe providedbyindependentATMdeployers. The Payment Systems Regulator has published a separateApproachDocument on the aspects ofthe PSRs 2017 for whichit issolely responsible,including accesstopayment systems, and information tobeprovidedby independent ATMdeployers. The European Banking Authority’s guidelines
1.21 The broad range of non‐legislative material produced by the European Supervisory Authorities, such
as the European Banking Authority (EBA), has not been incorporated into UK law. However, UK law will continue to reflect requirements which derive from the European Union (EU) in the form of UK legislation implementing European requirements and directly applicable European regulations which have largely been retained and amended by operation of the European Union (Withdrawal) Act 2018 (the EUWA). The non‐legislative material produced by the European Supervisory Authorities relates to these EU derived laws. Therefore, we consider that the EU non‐legislative material remains relevant to the FCA and firms, and to our guidance in this Approach Document.
1.22 We expect firms to continue to apply the EBA guidelines to the extent that they remain relevant,
interpreting them in light of the UK’s withdrawal from the EU and the associated legislative changes that have been made to ensure the regulatory framework operates appropriately. More information is available on our website: https://www.fca.org.uk/publication/corporate/brexit‐our‐approach‐to‐ eu‐non‐legislative‐materials.pdf. ProspectivePIsandEMIs,applyingunderthePSRs2017andEMRsrespectively(as amendedtoreflect PSD2),arerequiredtoprovidemoreinformationthanunderthe previous regime, including:
procedures for incident reporting
processesinplacetofile,monitor,trackandrestrictaccesstosensitivepayment data
principlesanddefinitionsappliedforthecollectionofstatisticaldataon
performance,transactionsandfraud
arrangementsforbusinesscontinuityandtheprocedurefortestingandreviewof such plans
a security policy document including a detailed risk assessment and mitigation measures
takentoadequatelyprotectpaymentserviceusersagainstrisksidentified including fraud and illegal use of sensitive and personal data
descriptionofchecksonagentsandbranches
Professional Indemnity Insurance (PII) or a comparable guarantee held (for businesses
thatproposeprovidingAISorPIS)
See Chapter 3 – Authorisation and registration and the relevant EBA guidelines and Regulatory Technical Standards for more details. ThePSRs2017containtransitionalprovisionswhichallowexistingauthorisedPIs and EMIs to continue carrying on payment services activity without applying for authorisationunder theregulationsuntil12July2018.Ifthesebusinesseswishto continue with these services after this date they must provide us with additional information.Thisinformationmustbe submittedbefore12April2018.Thereare separate provisions that apply to existing authorised PIs and authorised EMIs that wish to provide AIS and/or PIS. Please refer to Chapter 3 – Authorisation and registration for further information.
1.14 ThereareseparatetransitionalprovisionsforexistingsmallPIsandsmallEMIs.Small EMIs may carry
on their activities without authorisation or registration until 12 July 2018,andsmallPIsuntil12 January2019.Iftheywishtocontinuesuchactivitybeyond thesedatesthey arerequiredtore‐apply to usbefore13April 2018and13October 2018respectively,andprovideanyrelevantinformation requestedbyus.Small PIs and Small EMIs are not able to provide AIS and/or PIS, and so need to become authorised PIs or EMIs if they wish to provide such services. Please refer to Chapter 3 – Authorisation and registration for further information.
1.14 BusinessesshouldreviewthePSRs2017,particularlyregulations150to154relating totransitional
provisions.PSPsneedtocomplywiththenewrequirementsofPSD2 (introducedthroughthePSRs 2017andtheHandbook)includingconductofbusiness changes,newcomplaintshandling timeframesandnewreportingandnotifications from13January2018.ExistingPIsandEMIsneedto complywiththemajorityofthe new requirements prior to becoming re‐authorised or re‐ registered. PIs and EMIs shouldbeawarethatthereareafewexceptionsandshouldreviewthePSRs 2017and ourHandbook toconfirmthe start date for each requirement.
1.14 The provisions of the PSRs 2017 which relate to authorisation and registration apply
from13October 2017.GuidanceontheseprovisionsissetoutinChapter 3 – Authorisation and registration. Status of this document
1.151.23 The parts of this guidance that relate to payment services are given under regulation 120ofthe
PSRs2017,whilethosethatrelatetoEMIsaregivenunderregulation60of the EMRs.
1.161.24 Thisisa‘live’documentandmaybeupdatedaswereceivefeedbackfrombusinesses, trade
associationsand other stakeholders on additional issues they would like to see covered,or guidancethatneedstobeclarified.Wewillalsoupdatethedocument in the event of changes in the UK regulatory framework, including as a result of any negotiations followingthe UK’s vote to leave the EU.
1.171.25 Thisdocumentsupportsthelegalrequirementswhicharecontainedinthedocuments described
below.ItisessentialtorefertothePSRs2017,theEMRsorrelevantpartsof theHandbookforafull understandingoftheobligationsimposedbytheregime.
1.181.26 GuidanceisnotbindingonthosetowhomthePSRs2017,EMRsandourrulesapply. Rather,guidanceis
intendedtoillustrateways(butnottheonlyways)inwhichaperson can comply with the relevant regulations and rules. Guidance does not set out the minimumstandard of conduct needed to complywith the regulationsorourrules,nor isthereanypresumptionthatdeparting fromguidance
indicatesabreachofthese.Ifa firmhas compliedwiththe regulationsandrules,then itdoesnotmatter whetherithas complied with guidance we have issued.
1.191.27 However,ifapersonactsinaccordancewithgeneralguidanceinthecircumstances contemplatedby
thatguidance,wewillproceedasifthatpersonhas compliedwith the aspects ofthe requirementto whichthe guidance relates. Forthe reliancethat canbeplacedonotherguidance,seeSUP 9.4inthe Handbook(Relianceonindividual guidance).
1.201.28 DEPP 6.2.1G(4)intheHandbooksetsouthowwetakeintoconsiderationguidance andother
publishedmaterialswhendecidingtotakeenforcementaction.Businesses should also refer to
Chapter 2 of our Enforcement Guide forfurtherinformation about thestatusofHandbook
guidanceandsupportingmaterials.
1.211.29 Rights conferred on third parties (such as clients of a PSP or e-money issuer) cannot be
affectedbyourguidance.GuidanceonthePSRs2017,EMRsorotherrequirements representsourview, anddoescommonandsecurecommunicationtobindthecourts, e.g.inrelationtoanactionfor damagesbroughtbyaprivatepersonforbreachofa regulation.A person may needto seek his or her own legal advice. Key documents
1.221.30 Therequirementsforpaymentservices ande‐money regulation,setting outthe rulesforthe
newregime,canbefoundinthefollowingdocuments,whichareall accessible online:
The Payment Services Regulations 2017
The Electronic Money Regulations 2011
1.31 Where these requirements were amended by the Exit SI, the application of those
amendments may be affected by the directions under the TPP. In particular, see paragraph 13 of Annex A to the Transitional Direction.
1.32 The requirements for the TPR, SRO and CRO can be found in Schedule 3 of the Exit SI. .
1.231.33 The requirements for authentication and open access can be found in the Technical
Standards on Strong Customer Authentication and Common and Secure Methods of Communication. The relevant parts of the FCA Handbook
1.241.34 TheHandbook isanextensivedocumentthatsetsoutthe rules andguidance for financial
servicesregulation.AReader’sGuidetotheHandbookisavailableonthe Handbookwebsite togetherwithaUserGuide fortheonline version.Mostofthe HandbookdoesnotapplytoEMIs, PIsorRAISPs(unlesstheyareauthorisedunder FSMAinrelationtootheractivities),.Thereare, however,afewareasthatcontain relevant provisions. These are:
Principles for businesses (PRIN)
These are a general statement of the fundamental obligations of firms under the regulatory system. They derive their authority from the FCA’s rule-making powers as set out in FSMA, including as applied by the PSRs 2017 and EMRs, and reflect the FCA’s statutory objectives.
Glossary
ThisprovidesdefinitionsoftermsusedelsewhereintheHandbook.Clickingonan italicisedtermin theHandbookwillopenuptheglossarydefinition.
GeneralProvisions(GEN)
GEN 2 contains provisions on interpreting the Handbook. GEN 2.2.36G (9‐13) contains guidance on the interpretation of the Handbook for firms in the TPR and SRO.
Banking: Conduct of Businesssourcebook (BCOBS)
Retail deposit takers (including banks and building societies) are also required to complywiththe conductofbusinessrulesforretailbankingcontainedinBCOBS. Other PSPs and e‐money issuers are subject only to the rules set out in BCOBS 2. BCOBSChapter1containsfurtherdetailonwhich provisions apply to which type of business, and which complement the PSRs 2017 and which provisions do not apply toaccountswhereParts6and7ofthePSRs 2017apply.
Consumer Credit sourcebook (CONC)
This is the specialist sourcebook for credit‐related regulated activities and containsdetailed obligationsthatarespecific tocredit‐relatedregulatedactivities andactivities connectedtothose credit‐relatedregulatedactivities.IfPSPsare involvedin suchactivities,theywillneedtocomply withCONCinadditiontoother requirementswhichareimposedbytheConsumerCreditAct1974 andlegislation madeunderit.
Fees manual (FEES)
ThiscontainsfeesprovisionsforfundingusandtheFinancialOmbudsmanService relevant toPSPs.
Supervisionmanual(SUP)
SUP5.3andSUP5.4describeourpolicyontheuseofskilledpersonstocarryout reports (see
Chapter 12 – Supervision for further information).
SUP9describeshowpeoplecanseekindividualguidanceonregulatory requirements andthereliancetheycanplaceonguidancereceived. SUP11.3andSUP11Annex6GprovideguidanceonPart12ofFSMA,relatingto controlover authorisedEMIsandauthorisedPIs. SUP 15.14 sets out the notification requirements under the PSRs 2017. SUP16.13setsoutthe forms, content,reporting periods andduedatesforthe reporting requirementsunderthePSRs2017(includingannualreturns). SUP16.15setsoutthe forms, content,reporting period andduedatesforthe reporting requirementsundertheEMRs.
Senior Management Arrangements, Systems and Controls sourcebook (SYSC). SYSC9.2includes
a recordkeepingrulerelevanttocreditinstitutionsproviding accountinformation servicesor paymentinitiationservices.
Decision procedure and penalties manual(DEPP)
This containstheprocedureswemustfollowfortakingdecisionsinrelationto enforcementaction andsettingpenalties.
Dispute resolution: complaints sourcebook (DISP)
This contains the obligations on PSPs and e‐money issuers for their own complaint handling procedures and complaints reporting. It also sets out the rules concerning customers’ rights to complaintotheFinancialOmbudsmanService.
1.251.35 TheHandbookwebsitealsocontainsthefollowingregulatoryguidesthatarerelevant toPSPs:
Enforcement guide (EG)
Thisdescribesourapproachtoexercisingthemainenforcementpowersgiventous under FSMAand thePSRs2017.
Financial Crime: a guide forfirms(FC)
Thiscontainsguidanceonthestepsbusinessescantaketoreducetheirfinancial crime risk.
Perimeterguidancemanual(PERG)–PERG3AandPERG15
Thiscontainsguidanceaimedathelpingbusinessesconsiderwhethertheyneed to be separately authorised orregisteredforthepurposesofprovidingpayment servicesintheUK.
Unfaircontracttermsandconsumernoticesregulatoryguide(UNFCOG)
ThisguideexplainsourpowersundertheUnfairTermsinConsumerContracts Regulations1999and ourapproachtoexercisingthem.
1.261.36 Thereisalsoguidanceandinformationissuedbyus,theFinancialOmbudsmanService andHMRC
whichislikelytoberelevanttoreadersofthisdocument.Thisisreferenced in the appropriate sections ofthe document and gathered togetherinAnnex1– Useful links. Contacting us
1.271.37 We hope this document will answer all your questions; however, if you have any comments
regardingthisdocumentoranyaspectofthePSRs2017orEMRs,please refertothe contacts page on ourwebsite.
1.281.38 Annex2contains a listofotheruseful contact details.
2 Scope
Part I of this chapter sets out who and what is covered by the Payment Services Regulations 2017
(PSRs 2017). Part II sets out who and what is covered by the ElectronicMoneyRegulations2011(EMRs), includingwhate‐moneyisandinformation about differenttypes of e‐money issuers. Each section setsout where to find further information on scope-related issues.
Part I: PSRs 2017
Who the PSRs 2017 cover
2.1 ThePSRs2017apply,withcertainexceptions,toeveryonewhoprovidespayment servicesasa
regularoccupationorbusinessactivityintheUK(‘paymentservice providers’(PSPs)). They also apply in a limitedway to persons that are not PSPs (see regulations38,39,57,58and61ofthe PSRs2017).
2.2 Chapter 15 of our Perimeter Guidance (PERG)10gives guidance for firms who are unsure
whether their activities fall within the scope of the PSRs 2017.
2.3 ForafullerunderstandingofthescopeofthePSRs2017,theguidanceshouldberead inconjunction
withSchedule1ofthePSRs2017andthedefinitionsinregulation2, and Schedule 3 of the Electronic Money, Payment Services and Payment Systems(Amendment and Transitional Provisions)(EUExit) Regulations 2018 (the Exit SI), which sets out the temporary permission schemes for EEA authorised payment institutions (PIs) and EEA registered account information service providers (RAISPs). These are the Temporary Permissions Regime (TPR), Supervised Run‐Off Regime (SRO) and Contractual Run‐Off Regime (CRO). More detail on these schemes is set out at Chapter 6. Payment institutions (PIs)
2.32.4 The PSRs 2017 establish a class of firms authorised or registered to provide payment
services. These are collectively referred to as payment institutions (PIs) in this document.
Chapter 3 – Authorisation and registration gives details of the proceduresfor
authorisation and registration.
2.42.5 Weexpectthatthefollowingtypesoffirmswillrequireauthorisationorregistrationfor theirpayment
servicesactivities,amongstothers:
Authorised PIs
2.62.7 APSPauthorisedunderthePSRs2017istermedan‘authorisedPI’andreceives the rightto
‘passport’that authorisation to other EEA States(see Chapter6– Passporting). Small PIs
2.72.8 PSPswhichmeetthecriteriaforregistrationunderregulation14ofthePSRs2017,and choosetoapply
forregistrationratherthanauthorisation,arereferredtoassmallPIs. SmallPIscannotpassporttheir registrationtootherEEAStates,normaytheyprovide accountinformationservices(AIS)orpayment initiationservices(PIS).SeeChapter 17 – Payment initiation and account information services and confirmation of availabilityoffundsandChapter15ofPERGformoreinformationaboutAISandPIS.
2.82.9 AllPIs(andmostotherPSPs)mustcomplywiththeconductofbusinessrequirements of the PSRs 2017,
described in Chapter8 –Conduct ofbusinessrequirements.
Registered Account Information Service Providers
2.92.10 BusinessesthatonlyprovideAISareexemptfromfullauthorisationbutaresubject toa registration
requirement.Onceregistered,theyaretermed‘registeredaccount informationserviceproviders (RAISPs)’andcanpassporttheirregistrationtoother EEAStates.
2.102.11 RAISPsareonlyrequiredtocomplywithspecificpartsoftheconductofbusiness requirements.
Theseareidentifiedinparagraphs8.134and8.144ofChapter8– Conduct of business requirements. Temporary authorisations
2.112.12 Firmsin the TPR or SRO(TA firms) have temporary authorisation such thatthey can continue operating in the
UK for a limited period afterIP CompletionDay. Such firms are deemed to be PIs and RAISPsforthe purposes ofthe PSRs 2017.
2.13 As explained in Chapter 6 , inmost casesthe termPI in this documentshould be taken to include a TA firm
thatis an EEA authorised PI and the termRAISP in this documentshould be taken to include a TA firmthatis an EEA registered accountinformation service provider.
2.14 Note thatthe transitional directionsmade by the FCA under Part 7 ofthe Financial Services and Markets
Act 2000 (Amendment) (EU Exit) Regulations 2019 do not apply to the requirements specific to TA firms. These firms must comply with their obligations under the PSRs 2017 and the Exit SI. Agents
2.122.15 PIsmay provide paymentservicesthrough agents,subjectto priorregistration ofthe agent with us.
Chapter5 –Appointment of agents gives details of the processto be followed.
2.132.16 ItisthePI’sresponsibilitytoensuretheagentcomplieswiththeapplicableconductof business
requirementsofthePSRs2017andthatithasthesystemsandcontrolsin placetoeffectivelyoversee theagent’sactivities. Other payment service providers
2.142.17 Thefollowingcanprovidepaymentserviceswithouttheneedforfurtherauthorisation orregistration
bytheFCAunderthePSRs2017:
banks [including those with a temporary permission]
building societies
EEA authorisedPIs
EEA RAISPs
authorised e-money institutions (Authorised EMIs) [including TA firms]
registered e-money institutions (small EMIs)
EEA authorisedEMIs EEA authorised PIs and EEA RAISPs [including TA firms]
PostOfficeLimited
certain public bodies
2.152.18 These entities must, however, comply with the applicable conduct of business requirements of
the PSRs 2017 described in Chapter 8 – Conduct of business requirements and the reporting and notification requirements described in Chapter 13 – Reporting and Notifications.
2.162.19 In the case of credit institutions, the relevant application or certification procedures remain those
in the Financial Services and Markets Act 2000 (FSMA). Credit institutions are also subject to our rules and guidance in our Banking: Conduct of Business Sourcebook (BCOBS) –seeChapter 8 – Conduct of business requirements. References to credit institutions include persons with deemed Part 4A permissions for deposit‐taking and/or issuance of electronic money (as relevant) under Part 3 (temporary permission) or Part 6 (supervised run off) of the EEA Passport Rights (Amendment, etc., and Transitional Provisions) (EU Exit) Regulations 2018.
2.172.20 CreditinstitutionswillneedtonotifyusiftheywishtoprovideAISorPIS,andexisting EMIswillneed
toapplytoremovetheany requirementontheirpermissionimposedby regulation 78A of the EMRs, see Chapter 3 – Authorisation and registration, and Chapter 13 – Reporting and Notifications. Exemptions
2.182.21 ThefollowingbodiesarespecificallyexemptfromthescopeofthePSRs2017:
credit unions
municipal banks
TheNational Savings Bank
2.192.22 Municipal banks and theNational Savings Bank are also exemptfromBCOBS. Municipal banks must
nevertheless notify us if they are providing, or propose to provide, paymentservices.Creditunions aresubjecttoBCOBS.
2.23 EEA authorised PIs, EEA authorised EMIs and EEA RAISPs exercising passport rights in the UK
immediately before IP Completion Day (as defined in the European Union (Withdrawal Agreement) Act 2020) on a services passport basis are also exempt from the prohibition in regulation 138(1) of the PSRs 2017, subject to the requirements of Schedule 3, Part 3, paragraph 36 of the Exit SI. We referto this as “contractualrun‐off”. Exclusions
2.1 Moregenerally,thereisabroadrangeofactivitieswhichdonot constitutepayment servicesunder
Schedule1Part2ofthePSRs2017.Amongsttheseexcludedactivities are:
payment transactionsthroughcommercialagentsactingonbehalfofeitherthe payerorthe
payee;
cashtocashcurrencyexchangeactivities(e.g.bureauxdechange);
paymenttransactionslinkedtosecuritiesassetservicing(e.g.dividendpayments, sharesalesor
unitredemptions);
certain services provided by technical service providers;
paymentservicesbasedoninstrumentsusedwithinalimitednetworkofservice providers or
for a very limited range of goods or services (“limited network exclusion”);and
payment transactionsforcertaingoodsorservicesuptocertainvaluelimits, resulting from
servicesprovidedbyaproviderofelectroniccommunication networksorservices (“electroniccommunicationsexclusion”).
2.1 Chapters 3A11 and15ofPERGprovidemoreinformationontheseexclusions.Chapter 13 –
Reporting and Notifications provides information about notifications required from businesses operating under the limited network exclusion and the electronic communications exclusion. Registers
2.222.24 TheFinancialServicesRegister,publishedonourwebsiteincludesinformationrelating to various types
of PSP, together with details of the payment services that they are entitledtoprovide.Theregister includesdetailsrelatingto:
UKauthorisedPIsandEMIs,theirEEAbranchesandtheiragents
UKregistered small PIs and small EMIs and their agents
UK registered RAISPs and their agents
TA firms and their agents
persons providing a service falling within the limited network exclusion or the electronic
communicationsexclusionwhohavenotifiedusinlinewithregulation38 or39 of the PSRs 2017
creditunions,municipalbanksandtheNationalSavingsBanks,wheretheyprovide payment
services
2.232.25 TheEuropeanBankingAuthority(EBA)willalsomaintainaregisterwhichincludesthe information
coveredinourpublic register,togetherwith informationprovidedby the competentauthoritiesin otherEEAStates.Thiswillbeavailablefreeofchargeonthe EBA’swebsite. Payment services
2.242.26 ThepaymentservicescoveredbythePSRs2017(Part1ofSchedule1)aresetoutin thetablebelow,
alongwithsomeexamplesofactivitieslikelytobepaymentservices. Thetableishigh‐leveland indicativeinnature.Iffirmsareinanydoubtastowhether theiractivitiesconstitutepayment services,theyshouldrefertoChapter15ofPERG.
2.252.27 In addition to questions and answers providing further information on payment services, PERG
also explains a number of exclusions in the PSRs 2017. These exclusionsaresetoutinPart2of Schedule1tothePSRs2017(Activitieswhichdonot constitutepaymentservices).Forbusinessesthat intendtorelyonparagraphs2(k)or 2(l)ofPart2ofSchedule1tothePSRs2017(i.e.thelimitednetwork exclusionorthe electroniccommunicationnetworkexclusion),certainnotificationrequirements apply. See Chapter 13 – Reporting and Notifications. 11 https://www.handbook.fca.org.uk/handbook/PERG/3A/?view=chapter Examples (PERG 15 provides further details about what activities constitute payment What is a payment service? services) Servicesenabling cashto be placed on a payment • payments of cash into a payment account over the counter and through an ATM operating a payment account account and all of the operations required for Services enabling cash withdrawals from a payment • withdrawals of cash from payment accounts, account and all of the operations required for e.g. through an ATM or over the counter operating a payment account
Execution of the following types of payment transaction:
merchant acquiring services (rather than
merchants themselves)
Money remittance. • money transfer/remittances that do not involve creation of payment accounts. Payment initiation services. • services provided by businesses that contract with online merchants to enable customers to purchase goods or services through their online banking facilities, instead of using a payment instrument or other payment method. Account information services. • businesses that provide users with an electronic “dashboard” where they can view information from various payment accounts in a singleplace
businesses that use account data to provide
users with personalised comparison services supported by the presentation of account information
businesses that, on a user’s instruction, provide
information from the user’s various payment accounts to both the user and third party service providers such as financial advisors or credit reference agencies Exclusions
2.28 Thereisabroadrangeofactivitieswhichdonot constitutepayment services. These are set out in
Schedule1Part2ofthePSRs2017.Amongsttheseexcludedactivities are:
payment transactionsthroughcommercialagentsactingonbehalfofeitherthe payerorthe
payee;
cashtocashcurrencyexchangeactivities(e.g.bureauxdechange);
paymenttransactionslinkedtosecuritiesassetservicing(e.g.dividendpayments, sharesalesor
unitredemptions);
certain services provided by technical service providers;
paymentservicesbasedoninstrumentsusedwithinalimitednetworkofservice providers or
for a very limited range of goods or services (“limited network exclusion”);and
payment transactionsforcertaingoodsorservicesuptocertainvaluelimits, resulting from
servicesprovidedbyaproviderofelectroniccommunication networksorservices (“electroniccommunicationsexclusion”).
2.29 Chapters 3A11 and15ofPERGprovidemoreinformationontheseexclusions.Chapter 13 –
Reporting and Notifications provides information about notifications required from businesses operating under the limited network exclusion and the electronic communications exclusion. Scope of the PSRs 2017: jurisdiction and currency
2.30 ThetablebelowshowsthejurisdictionalscopeofdifferentpartsofthePSRs2017and their scope in
terms of the currency of the payment transaction. We refer to a few different types of transactions:
‘IntraUK transactions’: transactions whereboththepayer’sandthepayee’s PSPs are (or the sole
PSP is) located in the UK.
‘One leg transactions’: transactions where either the payer’s or the payee’s PSP (rather than
the payer or payee) is located outside the UK.
‘Qualifying area transactions’: transactions where the PSP (including EEA payment
service providers subject to PSD2) of both the payer and payee are located within the qualifying area (the UK and the EEA) and the transaction is in euro and executed under a payment scheme which operates across the qualifying area.
2.1 The‘corporateopt‐out’mayapplytocertainoftheconductofbusinessprovisions– seePart 1 of
Chapter 8 – Conductof business requirements for further details.
Where we refer to ‘one leg transactions’ below, we mean those where either the payer’s or the payee’s PSP (rather than the payer or payee) is located outside the EEA. Wherewereferto‘intra EEA’,wemeanthosewhereboththepayer’sandthepayee’s PSPs are (or the sole PSP is) located in the EEA. Payment services – jurisdictional and currency scope PSRs 2017 Authorisation/Registration (including meeting capital and safeguarding requirements). Jurisdiction Firms providing payment services, as a regular occupation or business activity in the UK including one leg out transactions and qualifying area transactions, unless the firm is in the list of ‘other payment service providers’ Currency All currencies. Complaints that can be considered by the Financial Ombudsman Service (see
Chapter 11 for full details of
eligibility).
All payment services provided from a UK establishment, including the UK end of one leg out transactions and qualifying area transactions. All currencies.
Part 6–Conduct of business
requirements (information requirements)
In general, Part 6 applies to payment services provided from a UK establishment including the UK end of one leg out and intra EEA transactions, in any currency and qualifying area transactions. For one leg out transactions and transactions (other than qualifying area transactions) in non-EEA currenciesnot in sterling, Part 6 only applies in respect of those parts of a transaction that are carried out in the EEAUK. We set out other exceptions to this in a separate table below.
Part 7–Conduct of business
requirements (rights and obligations in relation to the provision of payment services) In general, Part 7 applies to payment services provided from a UK establishment including the UK end of one leg and intra EEA transactions, in any currency and qualifying area transactions. For one leg transactions and transactions (other than qualifying area transactions) in non-EEA currenciesnot in sterling, Part 7 only applies in respect of those parts of a transaction that are carried out in the EEAUK. We set out below other exceptions to this in a separate table.
Part 6 – Exceptions towhere Part6 applies toone andtwo legtransactions inany
currency. Does the regulation apply?
PSRs 2017
One leg/
EEAany
Ccurrency
One legIntra
UK/ nonEEA currency nonsterling/ euro
Intra
EEAUK
/ EEA
Currencyst erling
Intra
EEAQualif ying area/ euro nonEEA currency
Regulation 43(2)
(b) – Pre-contractual information about execution times for single payment contracts No No Yes NoY es Regulation 52(a) – Information about execution times prior to execution of individual No No Yes NoY es transactions under a framework contract Paragraph 2(e) of
Schedule 4 – Precontractual information No No Yes NoY
about execution times es for framework contracts Paragraph 5(g) of
Schedule 4 – Precontractual information
about the conditions for the payment of any refund under regulation 79.
No NoYes
Part 7 – Exceptions to where Part 7 applies to one and two leg transactions in any currency.
Does the regulation apply?
PSRs 2017
Regulation 66(2) – charges paid by payer and payee One leg/ any currency One leg/ EEA currency No Intra UK/ nonsterling/ euro One leg/ nonEEA NoYes Intra UK/ sterling Intra EEA/ EEA currency Yes Qualifying area/ euro Intra EEA/ non-EEA currency Yes Regulation 79 – Refunds for transactions initiated by or through a payee No NoYes Regulation 80 – Requests for refunds for transactions initiated by or through a payee No NoYes Regulation 84 – Amounts transferred and received No No Yes No Regulation 85 – Application of Regulations 86 – 88 Yes YesNo Yes NoYes Regulation 86(1)-(3) – Payment transactions to a payment account No* No* Yes (subject to regulation 85) No*Yes (subject to regulation 85) Regulation 86(4)-(5) – Payment transactions to a payment account Yes (subject to regulation 85) Yes (subject to regulation 85)No Yes (subject to regulation 85) NoYes (subject to regulation
85) Regulation 87 – Absence
of payee’s payment account with payment service provider Yes (subject to regulation 85) Yes (subject to regulation 85)No Yes (subject to regulation 85) NoYes (subject to regulation
85) Regulation 88 – Cash
placed on a payment account
Yes
(subject to regulation 85)
Yes
(subject to regulation
85)No
Yes
(subject to regulation 85)
NoYes
(subject to regulation
85) Regulation 91 – nonexecution or late
execution of payment transaction initiated by the payer No NoYes Regulation 92 – nonexecution or late execution of payment transaction initiated by the payee No NoYes
Regulation 94 – Liability of service providers for charges and interest No NoYes Regulation 95 – right of recourse No NoYes *Thismeansthatwhenmakingtransactionstoapaymentaccountthetimelimitsforcreditingapayee’sPSP’s account will not apply to one leg in transactions or tofor intra-UK transactions innon-EEAcurrencies other than sterling and euro. Corporate opt-out
2.31 The‘corporateopt‐out’mayapplytocertainoftheconductofbusinessprovisions– seePart 1 of
Chapter 8 – Conductof business requirements for further details.
PartII:EMRs
Who the EMRs cover
2.272.32 TheEMRsapply,withcertainexceptions,toeveryonewhoissuese‐moneyintheUK. They also apply in
a limited way to persons that are not e-money issuers (see regulation 3(a)and3(b)oftheEMRs).
2.282.33 Chapter 3A of PERG gives guidance for firms who are unsure whether theiractivities fall
within thescope of the EMRs.
2.292.34 ForafullerunderstandingofthescopeoftheEMRsthisguidanceshouldbereadin conjunction
withthedefinitionsinregulation2oftheEMRs and Schedule 3 of the Exit SI, which sets out the TPR, SRO and CRO for EEA authorised EMIs. More detail on these schemes is set out at Chapter
6. .
How e-money is defined
2.302.35 Regulation2oftheEMRsdefinese‐moneyasmonetaryvaluerepresentedbyaclaim ontheissuerthat
is:
issuersbelow).
2.352.41 An EMI which receives authorisation under the EMRs is termed an ‘authorised EMI’. and receives
the right to ‘passport’ that authorisation to other EEA States (see Chapter 6 – Passporting).
2.362.42 EMIs that meet the criteria for registration under regulation 12 of the EMRs, and choose to apply
for registration rather than authorisation, are referred to as ‘small EMIs’. Chapter 3 – Authorisation and registration gives details of the procedures for authorisation and registration.
2.372.43 AllEMIsmustcomplywiththeconductofbusinessrequirementsofthePSRs2017and EMRs described in
Chapter 8 – Conduct of business requirements and the reporting and notification requirements
described in Chapter 13 – Reporting and Notifications.
Temporary authorisations
2.44 TA firms have temporary authorisation such thatthey can continue operating in theUK for a limited period
afterIP CompletionDay. Such firms are deemed to be EMIsforthe purposes ofthe EMRs and PSRs 2017.
2.45 As explained in Chapter 6, inmost casesthe termEMI in this documentshould be taken to include a TA firm
thatis an EEA authorised EMI.
2.46 Note thatthe transitional directionsmade by the FCA under Part 7 ofthe Financial Services and Markets
Act 2000 (Amendment) (EU Exit) Regulations 2019 do not apply to the requirements specific to TA firms. These firms must comply with their obligations under the EMRs, the PSRs 2017 and the Exit SI. EEA authorised EMIs Persons authorised in an EEA State other than the UK to issue e-money and provide payment servicesmayexercisepassportrightstoissue,distributeorredeeme‐money or provide payment services in the UK in accordance with the second Electronic MoneyDirective(2EMD).The competentauthorityofthehomestateisresponsiblefor prudentialregulationand,wherepassporting isonanestablishmentbasisratherthana cross‐borderserviceprovisionbasis,we(asthehoststate competentauthority)willbe responsible for conduct of business regulation (see Chapter 6 – Passporting) and antimoney laundering supervision (see Chapter 19 – Financial Crime). E-money issuers who require Part 4A permission under FSMA
2.392.47 Creditinstitutions,creditunionsandmunicipalbanksdonotrequireauthorisationor registration
undertheEMRsbutiftheyproposetoissuee‐moneytheymusthave a Part 4A permission under FSMA for the activity of issuing e‐money (or be deemed to have such a permission by virtue of the EEA Passport Rights (Amendment, etc., and Transitional Provisions) (EU Exit) Regulations 2018). When issuing e‐money,theyaresubjecttotheprovisionsonissuanceandredeemabilityofe‐money in the EMRs (see Chapter 8 – Conduct of business requirements). In addition, credit unions are subjecttothe safeguarding requirements(seeChapter 10 – Safeguarding). Other e-money issuers
2.402.48 The following can issue e-money and do not need to apply for authorisation or
registrationunderthe EMRsbuttheymustgiveusnoticeifthey issueorproposeto issuee‐money:
2.412.49 TheywillbesubjecttotheconductofbusinessrequirementsoftheEMRs,theconduct ofbusiness
requirementsofthePSRs2017forthepaymentserviceaspect,andthey willhavetoreporttoustheir averageoutstandinge‐moneyonayearlybasis.Certain customers will have accessto the Financial Ombudsman Service.
2.50 PERG3Agivesguidanceforbusinessesthatareunsurewhethertheiractivitiesfall within the scope
of the EMRs.
Exemptions
2.51 EEA authorised EMIs exercising passport rights in the UK immediately before IP Completion Day on
a services basis are exempt from the prohibition in regulation 138(1) of the PSRs 2017 and in regulation 63(1) of the EMRs, subject to the requirements of Schedule 3, Part 1A, paragraph 12L of the Exit SI. We referto this as “contractualrun‐off”. Use of Agents and Distributors
2.422.52 EMIs may distribute and redeem e‐money and provide payment services through agents,subject
to priorregistration ofthe agent by us. Chapter 5 – Appointment of agents givesdetailsofthe processtobefollowed.
2.432.53 EMIs may engage distributors to distribute and redeem e‐money. An EMI cannot provide
paymentservicesthroughadistributor, anddistributors donothavetobe registeredbyusbut applicantswillhavetoidentifytheirproposeduseofdistributors and, where they intend to distribute e‐money in another EEA State by engaging distributors, EMIs will need to provide details of distributors in their passporting notification (see Chapter 6 – Passporting). EMIs providing payment services
2.442.54 AllEMIsmayprovidepaymentservices,includingthosethatarenotrelatedto theissuingofe‐money
(unrelatedpaymentservices).EMIsmust,however,tellus aboutthetypesofpaymentservicesthey wishtoprovide,andEMIswhowishto offer unrelated payment services may have to provide additional information at the point of authorisation (see Chapter 3 – Authorisation and Registration for further information). This will primarily be relevant where the EMI wishes to offer payment servicesthatareindependentfromits e‐moneyproducts.WheretheEMIproposes simply totransferfundsfrome‐moneyaccounts,suchaswhereacustomerusestheir e‐moneytopaya utilitybill,thispaymentservicewouldrelatetotheactivityofissuing e-money.
2.452.55 Small EMIs can only provide unrelated payment services if the average monthly total of
payment transactions does not exceed €3 million on a rolling 12‐month basis (see Chapter 3 – Authorisation and registration). EMIs providing AIS and PIS
2.56 Regulation78AoftheEMRshastheeffectofplacingarequirementonEMIsauthorised in the UK before
13January2018preventingthemfromprovidingAISorPIS.AuthorisedEMIs subject to this requirement will need toapply tousiftheywishtohave thisrequirementitremoved(seeChapter 3 – Authorisation and Registration). Small EMIs cannot provide AIS or PIS. Corporate opt-outThe‘corporateopt‐out’mayapplytocertainoftheconductofbusiness provisions– see Part 1 ofChapter 8 – Conduct of business requirements for further details.
3 Authorisationandregistration
3.1 This chapter sets out how we will apply the Payment Services Regulations 2017 (PSRs 2017) and
Electronic Money Regulations 2011 (EMRs) dealing with:
3.7 AgentscanbeappointedbyaPI,RAISPorEMI(theprincipal)toprovidepayment servicesonthe
principal’sbehalf.Theprincipalacceptsresponsibilityfortheacts and omissions of the agent and must apply for the agent to be registered on the Financial Services Register. More information on agents is contained in Chapter 5 – Appointment of agents.
3.8 EMIsmayalsoengagedistributorstodistributeandredeeme‐money.Adistributor cannot provide
payment services, and does not have to be registered by us – but applicantswillhavetoidentify theirproposeduseofdistributorsatauthorisationand, wheretheyengagedistributorstodistribute or redeeme‐moneyinotherEEAStates, provide their details in passporting applications (see
Chapter 6 – Passporting).
3.9 TheFinancialServicesRegisterisapublicrecordoffirms,individualsandotherbodies that are, or have
been, regulated by the PRA and/or FCA. The Register includes informationaboutPIs,RAISPsand EMIsandtheiragentsandtheEEAbranchesofPIs andEMIs.Thisinformationisalsoincludedona registermaintainedbytheEuropean Banking Authority (EBA), together with information provided by the competent authoritiesinotherEEAStates.ThisisavailablefreeofchargeontheEBA’swebsite. Making an application for authorisation or registration
3.10 Anyonewishingtobecomeauthorisedorregisteredneedstocompleteanapplication form and
submit it to us along with the required information and the application fee (moreinformationis available inChapter 15 – Fees). Applicants that wish to operate throughagentswillbechargedan additionalapplicationfee.
3.11 ApplicationformsareavailableafterregisteringonConnect.Noworkwillbedoneon processingthe
applicationuntilthefullfeeisreceived.Thefeeisnon‐refundableand mustbepaidviaConnect. Information to be provided and EBA Guidelines
3.12 TheEBAhasissued‘Guidelinesontheinformationtobeprovidedforauthorisationof payment
institutions and e-money institutions and registration as account information serviceproviders’ (EBAGuidelines).12TheEBAGuidelinesspecifytheinformationthat applicantsforauthorisationasaPI oranEMIorregistrationasaRAISPwillberequired tosubmit.Detailsontheserequirementsaresetout belowinPartIforauthorised PIs and authorised EMIs and in Part III for RAISPs. Following the UK’s exit from the EU we continue to expect businesses that are seeking authorisation or registration to apply the EBA Guidelines to the extent that they remain relevant1 . In some cases, we will also applyconsider relevantguidelineswhenspecifyingtheinformationtobeprovidedbyapplicantsfor registrationassmallPIsorsmallEMIs.Moredetailontheserequirementsissetoutin Part II.
3.13 Wherewe do not prescribe the formatofinformation thatmust be given tous,wewill need tohave
enough informationtobesatisfied thatthe applicantmeetsthe relevant conditions. This does not mean that the applicant needs to enclose full copies of all the procedures and manuals with their application; a summary of what they cover maybeenough,aslongasthemanualsand proceduresthemselvesareavailableif we want to investigate further. Note that supplying the information requested on the applicationformwillnotnecessarilybeenoughfortheapplicationtobe ‘complete’.We mayneedtoaskadditionalquestionsorrequestadditionaldocumentationtoclarify theanswersalreadygiven.Itisonlywhenthisadditionalinformationhasbeenreceived and considered alongside the existing information that we will be able to determine whether the application is complete.
3.14 AssetoutintheEBAGuidelines,tTheinformationprovidedbytheapplicantshouldbe true, complete,
1 See our approach to EU non‐legislative materials ‐ https://www.fca.org.uk/publication/corporate/brexit‐our‐approach‐to‐eu‐non‐legislative‐materials.pdf 12Available at: https://www.eba.europa.eu/regulation‐and‐policy/payment‐services‐and‐electronic‐money/guidelines‐on‐ authorisation-and-registrationunder-psd2
accurateanduptodate.Thelevelofdetailshouldbeproportionateto theapplicant’ssizeandinternal organisation,andtothenature,scope,complexityand riskinessoftheparticularservice(s)the applicantintendstoprovide.Wewouldexpect applicantstoanswerquestionsinfullintheapplication form,whichincludesproviding therequestedinformationinbulletsundereachquestion.
3.15 WewillassesstheinformationprovidedagainsttherequirementssetoutinthePSRs 2017,EMRsand
with regard to theEBAGuidelines(whereapplicable).
3.16 Applicants should note that under regulation 142 of the PSRs 2017 and regulation 66 of the
EMRs it is a criminal offence to knowingly or recklessly give information that is materially false or misleading in their application. Requests for further information (regulations 5(4), 13(4) and 17(2) PSRs 2017 and 5(4) and 12(4) EMRs)
3.17 At any time after receiving an application for authorisation or registration (or a variationof
eitherofthese)andbeforedeterminingit,wecanrequiretheapplicantto providesuchfurther informationaswereasonablyconsidernecessarytoenableusto determinetheapplication.Where applicationsareincomplete(whentheydonothave alltheinformationweneed),wewillaskinwriting formoreinformation.Wewill then confirmthe date fromwhichweconsiderthe application tobe complete. Thetimings set out in Part IV of this chapter will run from that date. Duty to advise of material changes in an application (regulations 20 PSRs 2017 and 17 EMRs)
3.18 We attach considerable importance to the completeness and accuracy of the information provided
to us. If there is, or is likely to be, any material change in the information provided for an application before we have made our decision on it, the applicantmustnotifyus.Thisalsoappliesif itbecomesapparenttotheapplicantthat thereisincorrectorincomplete informationinthe application. The requirements also apply tochanges tosupplementary information already provided.Ifanapplicant fails to provide accurate andcomplete information it will takelonger to assess the application. Insomecases,itcouldleadtotheapplicationbeingrejected.
3.19 The applicant should notify the case officer assigned to the application of details of the
change and provide the complete information or a correction of the inaccuracy (as thecasemay be)withoutunduedelay.Iftheapplicantexpectsachangeinthefuture they must provide details as soon as they become aware of it. When providing this information,the applicant will be asked to confirmthatthe rest ofthe information in the applicationremainstrue,accurateandcomplete.
Part I: Becoming an authorised PI or authorised EMI
3.20 ThissectionappliestobusinessesthatwishtobecomeanauthorisedPIoran authorised
EMI.
3.21 The conditionsthatmust bemetin orderto become an authorised PI are set outin regulation6of
the PSRs2017andthose thatmustbemettobecome anauthorised EMIaresetoutinregulation6of theEMRshavebeenmet.
3.22 The information requirementsfor applications can be found in Schedule 2 of the PSRs 2017andwith
relevant guidance at section 4.1 of the EBA Guidelines (the API Guidelines) for authorised PIs and
Schedule 1 of the EMRs and with relevant guidance at section 4.3 of the EBA Guidelines (the EMI
Guidelines)for authorised EMIs.
3.23 ThereisanapplicationfeeforfirmslookingtobecomeanauthorisedPIoran authorised
EMI(moreinformationisavailableinChapter 15 – Fees).
3.24 For authorised PIs and authorised EMIs, the application must be signed by the person(s)
responsibleformakingtheapplicationonbehalfoftheapplicantfirm.The appropriateperson(s) dependsontheapplicantfirm’stype.Theseareasfollows:
Type of applicant
Company with one director
Appropriate signatory
The director
Company with more than one director Two directors Limited liability partnership Two members Limited partnership The general partner or partners Information to be provided and conditions for authorisation
3.25 Authorisationwillnotbegrantedunlesswearesatisfiedthattheconditionsspecified inregulation6of
thePSRs2017orregulation6oftheEMRs(asapplicable)havebeen met.
3.26 ThissectionneedstobereadalongsidetheAPIGuidelinesortheEMIGuidelines,as appropriate.
Together,thePSRs2017,APIGuidelines, EMRs andEMIGuidelines explain the information that you must supply with the application and the conditions that must be satisfied. Programme of operations (paragraph 1, Schedule 2 PSRs 2017 and paragraph 1,
Schedule 1 EMRs)
3.27 For authorised PIs, API Guideline 3 sets explainsout the information and documentation which we
require needs to be provided for the programme of operations. For authorised EMIs, this is set explainedout in EMI Guideline 3.
3.28 Inbothcases,Guideline3werequirestheprogrammeofoperationstobeprovidedby theapplicantto
containadescriptionofthepaymentservicesenvisaged,including an explanation of how the activities and the operations fit into the list of payment services set out in Part 1 of Schedule 1 to the PSRs 2017. Some examples of the sorts of activities expected tofallwithin the scopeof eachare describedinChapter2 – Scope, with further guidance in Chapter 15 of our Perimeter Guidance manual (PERG). Applicants for authorisation as an EMI must also provide an indication of the e‐ moneyservicestheapplicantintendstoprovide(issuance,redemption,distribution). Guidanceone‐ moneyactivities canbefoundinChapter3AofPERG.Theapplicant shouldalsodescribeanyother businessactivitiesitprovides.
3.29 Theapplicantisalsorequiredtostatewhethertheywill enterintothepossessionof customers’
funds.Inourview,beinginpossessionoffundsincludesanentitlementto fundsinabankaccountin theapplicant’sname,fundsinanaccountintheapplicant’s name at another PI or EMI and funds held on trust for the applicant.
3.30 The applicant is required to provide details of how transactions will be executed (includingdetails
ofallthepartiesinvolvedintheprovisionoftheservices).Wemayask forfurtherinformation, which may include a requesttosee copiesofdraft contracts betweentheapplicantandotherparties involvedintheprovisionoftheservices,as well as copies of draft framework contracts. See
Chapter 8 – Conduct of business requirements for more information on framework
contracts and other conduct requirements.
3.31 WheretheapplicantintendstoprovideAISorPIS,wewouldexpecttheinformation on the
programme of operationsto coverthe nature ofthe service being provided to the customer, how their data will be used, and how the applicant will obtain appropriate consent(s) from the customer. See Chapter 17 – Payment initiation and account information services and confirmation of availability of funds for more information. Business plan (regulation 6(7)(c) and paragraph 2, Schedule 2 of the PSRs 2017 and regulation 6(6)(c) and paragraph 2, Schedule 1 of the EMRs)
3.32 API Guideline 4 and EMI Guideline 4 set outexplain the information and documentation which
needswe require tobeprovidedinthebusinessplan.
3.33 The business plan needs to explain how the applicant intends to carry out its business.Itshould
provideenoughdetailtoshowthattheproposalhasbeencarefully thoughtoutandthattheadequacy
offinancial andnon‐financialresourceshasbeen considered.
3.34 Inaccordancewithregulation7(4)ofthePSRs2017andregulation7(4)oftheEMRs, wherean
applicantwishestocarryonbusinessactivitiesotherthantheprovisionof paymentservicesand,in thecaseofEMIs,issuinge‐money,andwethinkthatthe carryingonofthisbusinesswill,orislikely to,impairourabilitytosuperviseitorits financialsoundness,wecanrequiretheapplicanttoforma separatelegalentityto providepaymentservicesand,forEMIs,issuee‐money.
3.35 As per EBA Guideline 4.2, the business plan should contain information on, and calculation of,
own funds requirements. Guidance can be found on own funds in Chapter 9 – Capital resources and requirements. Applicants should refer to the EBAGuidelinesforother businessplanrequirements,includingincomeinformation, marketingplanandbudgetforecasts.
3.36 Applicants wishing to become authorised EMIs that intend to provide unrelated paymentservices
arerequiredtosubmitaseparatebusinessplanfortheseactivities.
3.37 WheretheapplicantintendstoprovideAIS,theinformationprovidedshouldinclude howtheuseof
customerdatafitsintotheapplicant’sbusinessmodel.
Structural organisation (paragraph 12 Schedule 2 of the PSRs 2017, paragraph 7Schedule1EMRs)andcloselinks(regulation6(9)and(10)ofthe PSRs2017and regulation6(8)and(9)oftheEMRs)
3.38 Wewillrequireadescriptionoftheapplicant’sstructuralorganisation,whichistheplan for how the
work of the business will be organised including through any branches, agentsanddistributors.API Guideline5andEMIGuideline5setexplainouttheinformation anddocumentationwhichmustwe require tobeprovidedinrelationtothestructuralorganisation.
3.39 The information must include a description of the applicant’s relevant outsourcing
arrangements(ifany) taking into account the EBA’s guidelines on outsourcing arrangements2 .We mayaskforfurtherinformation,whichmayincludearequest to see draft contracts with parties to whom operational functions are outsourced (see section 18.9 on outsourcing). The PSRs 2017 (regulation 25) and EMRs (regulation 26) make specific provisions in relation to the outsourcing to third parties of ‘important’ operationalfunctionsbyauthorisedPIsandauthorised EMIsincludingtheprovisionto itofaninformationtechnologysystem.Theseprovisionsare:
3.40 Regulation 25(3) of the PSRs 2017 and regulation of the 26 of the EMRs indicate what is
consideredan‘importantoperationalfunction’.Itisafunctionwhich,ifitfailedor wasdefective, wouldmateriallyimpairanauthorisedPI’sorauthorisedEMI’sability tocomplywiththePSRs2017 and/orEMRsandanyrequirementsofauthorisation, itsfinancial performance,orsoundness or continuity ofits paymentservices and/ or e‐money issuance. In practice, which of an authorised PI’s or authorised EMI’s operationalfunctions areimportantwill vary frombusinesstobusiness, according tothenatureandscaleofthebusiness.Wewilltakethesefactorsintoconsideration when assessinganauthorisationapplicationwherethebusinessintendstooutsource important operational functions.
3.41 Applicants must also satisfy us that any ‘close links’ they have are not likely to prevent the
effectivesupervisionofthefirmor,whereacloselinkislocatedoutsideoftheEEAUK, the laws of the foreign territory would not prevent effective supervision (in accordance with regulation 6(9) and (10)of the PSRs 2017 and regulation 6(8) and (9) of the EMRs).
3.42 Acloselinkisdefinedas:
Initial capital (regulation 6(3) and paragraph 3, Schedule 2 of the PSRs 2017 and regulation 6(3) and paragraph 3, Schedule 1 of the EMRs)
3.45 Applicants are required to provide information on their own funds, including the amountand
detailedbreakdownbypaid‐upcapital,reservesandretainedearnings aspartoftheirbusinessplan (seeAPIGuideline4andEMIGuideline4).Bythetimeof authorisation,theapplicantmustprovide evidencethattheyholdinitialcapitalatthe levelrequiredbyPart1ofSchedule3ofthePSRs2017or Part1ofSchedule2ofthe EMRsasthecasemaybe.APIGuideline6andEMIGuideline6setexplainout theinformation anddocumentationtobeprovidedasevidenceofinitialcapital.
3.46 TheinitialcapitalrequirementforauthorisedEMIsis€350,000.Applicantswishingto become
authorisedEMIsthatintendtoprovideunrelatedpaymentservicesshould notethatthereisno additionalinitialcapitalrequirement.
3.47 ForapplicantstobecomeauthorisedPIsthelevelofinitialcapitalrequireddependson thepayment
servicestobeprovided,andisthegreaterofthefollowing:
Payment services
(see Schedule 3 to the PSRs 2017)
AIS (paragraph 1(h), Schedule 1 to the PSRs 2017) Initial capital required None Money remittance (paragraph 1(f) of Part 1, Schedule 1 to the PSRs 2017) €20,000 PIS (paragraph 1(g) of Part 1, Schedule 1 to the PSRs 2017) €50,000 Payment institutions providing services in Schedule 1 Part 1(1)(a) to (1)(e) to the PSRs 2017. €125,000
3.48 The evidence needed will depend on the type of firm and its source of funding. For example,ifan
applicantwasalimitedcompanyandusingpaid‐upsharecapital,we would expect to see a copy of the SH01 form submitted to Companies House and abank statement, inthe business’name,showing the monies being paid in. If an applicant has already been trading and hassufficient reservesto meet the initial capital requirement, then a copy of the most recent financial statements or accounts may be enough (or interim accounts if appropriate). Businesses may wish to capitalise nearer to the time of authorisation,so this evidence can be provided at a later date butwill be requiredbeforeauthorisation isgranted. Location of offices and where business is carried out (regulation 6(4) and (5), paragraph 17, Schedule 2 of the PSRs 2017, regulation 6(4) and (5) paragraph 12,
Schedule 1 of the EMRs
3.49 AnapplicanttobeanauthorisedPImustbeabodycorporate(e.g.alimitedcompany orlimited
liabilitypartnership) constitutedunderthelawoftheUKandwhosehead office(and,where relevant,itsregisteredoffice)isintheUK.
3.50 AnapplicanttobeanauthorisedEMImustbeeither:
3.52 Forthepurposeofregulation6(4)ofthePSRs2017,a‘virtualoffice’intheUKdoesnot satisfy this
condition.
3.53 Inordertoobtainauthorisation,foraPIapplicant,itisarequirementthatitcarrieson, orwillcarryon,
atleastpartofitspaymentservicebusinessintheUKand,foranEMI applicant,thatit carrieson,or will carry on, atleastpart ofits e‐moneyandpayment service businessin the UK. 3.54 Safeguarding measures (regulation 6(7)(d) and paragraph 4, Schedule 2, of the PSRs 2017 and regulation 6(6)(d) and paragraph 4, Schedule 1 of the EMRs) Applicants arerequiredtosatisfyusthattheyhavetakenadequatemeasuresforthe purposeof safeguardingusers’funds.ForapplicantstobecomeauthorisedEMIsthat intendtoprovideunrelated paymentservices,thisincludesthesafeguardingmeasures theyintendtousetosatisfy regulation23of thePSRs2017(asmodifiedbyregulation 20(6) of the EMRs) in respect of those funds.API Guideline 7 and EMI Guideline 7 set out explain the information and documentation which needs to be provided in relation to safeguarding.
3.55 This requirement does not apply to applicants that will not receive funds from or on behalfof
paymentserviceusers,orinexchangefore‐money,suchasthosethatintend to provide PIS and AIS only.
3.56 There is more information in Chapter 10 – Safeguarding on safeguarding measures
includingguidanceonwhatwewouldexpecttoseebywayoforganisational arrangements. Professional indemnity insurance (PII) (regulation 6(7)(e) and (f)) and paragraph 19,
Schedule 2 of the PSRs 2017 and regulation 6(6)(e) and (f) and paragraph 14 of the
EMRs
3.57 WhereanapplicantforauthorisationasaPIseekspermissiontoprovidePISorAIS,it mustsatisfyus
thatitholdsappropriatePIIoracomparableguarantee.
3.58 Authorised EMIs who intend to provide either PIS or AIS will also need to hold the requiredPII
oracomparableguarantee.Iftheapplicantdoesnotintendtoprovide theseservicesitmuststateso initsapplication.Inthesecases,authorisationwillbe subjecttoarequirementunderregulation7of the EMRsthatthe applicantwillnot undertake theseactivities. The applicant can apply to vary its authorisation at a later date (see Chapter 4 – Changes in circumstances of authorisation orregistration).
3.59 API Guideline 18 and EMI Guideline 18 set outexplain the information and documentation
thatisrequiredforthisPIIorcomparableguarantee.TherequiredPIIorcomparable guarantee must meet or exceed the minimum monetary amount directed by us from time to time. For this purpose, we direct that the minimum monetary amount is the amount calculated in accordance with the “Guidelines on the criteria on how to stipulate the minimum monetary amount of the professional indemnity insurance or othercomparableguaranteeunderarticle 5(4)ofDirective(EU)2015/2366(PSD2)” publishedbytheEBAunderarticle5(4)ofPSD2on7July2016 (EBA‐GL‐2017‐08).
3.60 Applicants should provide the PII calculations and a copy of the terms of the policy proposed,
whichmustcomplywiththerequirementsofthePSRs2017andEMRs.We wouldexpectthepolicyto bespecificallytailoredtoaddresstheliabilitiessetoutin regulation 6(7)(e) and (f) of the PSRs 2017 as regards provision of AIS and PIS. It should coverliability tothirdparties arisingnotonly from externalattacks,butalsofromany act or omission, including where dishonest, fraudulent or malicious, committed by employees,includingdirectors,officersandpartners(intheircapacityas employees), and sub‐contractors or outsourcers for whose conduct the applicant is legally responsible. Governance arrangements, internal controls and risk management (regulation 6(6) and paragraphs 5 to 11, Schedule 2 of the PSRs 2017 and regulation 6(5) and paragraphs 5 to 6 Schedule 1 of the EMRs)
3.61 Applicants must satisfy us that their governance arrangements, internal control mechanisms and
risk management procedures meet the conditions set out in regulation 6(6) of the PSRs 2017 or regulation 6(5) of the EMRs. API Guideline8 and EMI Guideline 8 setoutexplain the information and documentation that needsto be provided for governance arrangements and internal controls.
3.62 We will assess if the applicant’s arrangements, controls and procedures are appropriate,sound
andadequatetakingaccountofanumberoffactors,suchasthe:
3.673.68 When the applicant is assessing whether it has adequate liquidity to ensure that it can meet
its liabilities as they fall due, we consider it best practice to exclude any uncommitted intragroup liquidity facilities. This is to reduce exposure to intra-group risk. If the applicant does not apply this approach, it still needs to be able to demonstrate to us how it will adequately manage its liquidity risk and group risk to comply with its conditions for authorisation.
3.69 The applicant should explain its approach to stress testing to us. Once authorised, the
applicant should carry out stress testing to analyse its exposure to a range of severe business disruptions, or the failure of one or more of its major counterparties. It should show how it will assess whether these events would cause its business to fail, and assess their potential impact, using internal and/or external data and scenario analysis. The applicant should use the results of these tests to help ensure it can continue to meet its conditions of authorisation and own funds requirements. In particular, it should show how these results will inform its decisions around adequate liquidity and capital resources, as well as identifying any changes and improvements to required systems and controls.
3.683.70 Stress testing should be appropriate to the nature, size and complexity of the applicant's business and the risks
it bears. Business failure in the context of stress testing should be understood as the point at which the market loses confidence in a firm and this results in the firm no longer being able to carry out its business activities. Examples of this would be the point at which all or a substantial portion of the applicant's counterparties are unwilling to continue transacting with it or seek to terminate their contracts, or when the applicant’s existing investors are unwilling to provide new capital to continue operating its existing business. Such a point may be reached well before the applicant’s financial resources are exhausted.
3.71 The applicant’s senior management or governing body should document, review and approve
– at least annually – the design and results of the firm’s stress testing. It should also carry out stress testing more frequently if it is appropriate to do so in the light of substantial changes in the market or in macroeconomic conditions.
3.693.72 If the applicant is a member of a group, it should carry out stress testing on a solo basis,
taking into account risks posed by its membership of its group.
3.73 Applicants should include wind-down plans to show how they will manage liquidity,
operational and resolution risks. A wind-down plan should consider the winding-down of the applicant’s business under different scenarios, including a solvent and insolvent scenario. Where relevant, the wind-down plan should be based on reliable, stress-tested financial data (see paragraphs 3.69 – 3.72). In particular, the winddown plan should include/address the following:
sufficient detailed information to quickly identify customer funds and the customers for whom they are held, and return the funds promptly funding to cover the solvent wind-down of the applicant, including the return of all customer funds realistic triggers to start a solvent wind-down, and a strategy for monitoring those triggers operational resilience and cyber controls during a wind-down period the need for any counterparties (eg merchants and customers) to find alternative providers termination of all products and services
wind-down or other arrangements for any subsidiaries or affiliates relevant to the applicant’s regulated activity non-financial resources (eg people, and co-operation from third parties) required for the winddown a stakeholder communication plan, and realistic triggers to seek advice on entering an insolvency process, including a strategy for monitoring those triggers.
3.74 We expect the complexity of wind-down plans to be proportionate to the size and nature of the
applicant’s business. An applicant should review its wind-down plans at least annually, and when there is a change to its operations which may materially change the way in which it can wind-down. An applicant should explain to us its approach to reviewing its wind-down plan.
3.75 An applicant which is a member of a group should ensure that its wind-down plan
considers how it would manage its liquidity, operational and resolution risks in a solvent and insolvent scenario, on a solo basis. The plan should also take into account risks posed by the applicant’s membership of its group. The applicant should also have a contingency plan to maintain key operational services which are provided by another member of the group in a group stressed scenario.
3.753.76 Internal controls are the systems, procedures and policies used to safeguard the business from
fraud and error, and to ensure accurate financial information. They should include sound administrative and accounting procedures so the applicantcan give us financial reports that reflect a true and fair view of its financial position and that willallowthemtocomplywiththe requirementsofthePSRs2017andEMRsinrelation to its customers.
3.763.77 An applicant’s senior management should ensure that it regularly reviews its systems and controls,
including its governance arrangements. It should also ensure that the its governance functions, procedures and controls appropriately reflect the applicant’s business model, its growth and relevant risks.
3.78 Ourassessmentoftheapplicationwillconsiderifthesystemsandcontrolsdescribed inthe
informationsuppliedareadequateandappropriatetothepaymentservicesand e-money activities that the applicant intends to carry on. Security incident and security-related customer complaint procedures (paragraph 6 Schedule 2 of the PSRs 2017 and paragraph 5A Schedule 2 of the EMRs)
3.773.79 API Guideline 9 and EMI Guideline 9 set outexplain the information and documentation
requiredwithrespecttoproceduresformonitoring,handlingandfollowingupsecurity incidentsand security‐relatedcustomercomplaints.Theinformationrequiredshould include details of how the applicant will comply with its obligation to report major operational or security incidents under regulation 99 of the PSRs 2017 – see Chapter 13 – Reporting and notifications for more information on the incident reporting RequirementsandEBAGuidelinesonmajorincident reporting.13
3.783.80 Applicantsshouldprovideadescriptionoftheproceduresinplacetomonitor,handle and follow up on
security incidents and security-relatedcustomer complaints including theindividualsandbodies responsibleforassistingcustomersinthecasesoffraud, technical issues and/or claim management. The applicant’s complaints procedures must demonstrate compliance with regulation 101 of the PSRs 2017 for non‐eligible complainantsandourDisputeResolutionSourcebook(DISP)foreligible complainants. See Chapter 11 – Complaintshandling. Sensitive payment data processes (paragraph 7 Schedule 2 of the PSRs 2017 and
paragraph 5B Schedule 2 of the EMRs)
3.793.81 API Guideline 10 and EMI Guideline 10set outexplain the information and documentation
whichisrequiredinrelationtotheapplicant’sprocessestofile,monitor,trackand restrict access to sensitive payment data. See also Chapter 18 – Operational and security risks. Business continuity arrangements (paragraph 8 of Schedule 2 of the PSRs 2017 and paragraph 5C Schedule 1 of the EMRs)
3.803.82 API Guideline 11 and EMI Guideline 11set outexplain the information and documentation
whichisrequiredinrelationtotheapplicant’sbusinesscontinuityarrangements.
3.813.83 Applicantsmustprovidetheirbusiness continuity anddisasterrecoveryplanswhich shouldinclude
failureofkeysystems,thelossofkeydata,inaccessibilityofpremises and loss of key persons. The principles and definitions used by the applicant in collecting statistical data on performance, transactions and fraud (paragraph 9 of Schedule 2 PSRs 2017 and paragraph 5D of Schedule 1 EMRs)
3.823.84 API Guideline 12 and EMI Guideline 12set outexplain the information and documentation
requiredinrelationtothecollectionofstatisticaldataonperformance,transactions and fraud. This should demonstrate how the applicant will ensure it can meet its obligation to report to us on fraud (see Chapter 13 – Reporting). Security policy (paragraph 10 Schedule 2 of the PSRs 2017 and paragraph 5E
Schedule 1 of the EMRs)
3.833.85 API Guideline 13 and EMI Guideline 13set outexplain the information and documentation
which is required in relation to the applicant’s security policy. The security policy must include a detailed risk assessment of the services to be provided (including risks of fraud) and the mitigation measures to protect users from the risks identified. It must also describe how applicants will maintain the security of e-money and payment processes, including customer authentication procedures (see Chapter 20 – Authentication). Applicants should additionally include a description of the IT systems and the security measures that govern access to these systems. As part of the information required under EBA Guideline 13.1 wWe would expect the security policy to take into account the security of data at rest and in transit. If the data is held off-site by a third party, we would expect details on how it is encrypted and regular due diligence carried out.
3.843.86 Applicantsshouldalsodemonstratehowtheywillcomplywiththeirobligationunder regulation
98(1) of the PSRs 2017 (management of operational and security risk). Applicants may wish to consider the use of security training, accreditation and/or certificationtosupporttheir application(inparticulargovernment‐backedschemes, e.g.CyberEssentials,asecuritycertification schemethatsetsoutabaselineofcyber security for organisations).14
3.853.87 More information on security can be found in Chapter 18 – Operational and security risks.
Money laundering and other financial crime controls (Paragraph 11 Schedule 2 of the PSRs 2017 and paragraph 6 Schedule 1 of the EMRs)
3.863.88 AllPIsandEMIsmustcomplywithlegalrequirementstodeteranddetectfinancial crime, which
includes money laundering and terrorist financing. We give more detailontheserequirements inChapter 19 – Financial crime. API Guideline 14 and EMIGuideline14setoutexplainthe informationanddocumentationwerequiredformoney launderingandotherfinancialcrime controls.Weexpectapplicantstoexplainhowthey proposetomeettheirobligationsunderthe relevantlegislation. 13 http://www.eba.europa.eu/documents/10180/1914076191FINAL/Guidelines+on+incident+reporting+under+PSD2+%28EBA‐ GL‐2017‐ 10%29.pdf/3902c3db‐c86d‐40b7‐b875‐dd50eec87657 14 https://www.cyberaware.gov.uk/cyberessentials/
3.873.89 As part ofthis,we expectfirmstodemonstrate thatthey establish andmaintain appropriate
and risk-sensitive policies and procedures to counter the risk that they maybeusedto furtherfinancial crime.Thesepoliciesandproceduresshouldbe proportionatetothenature, scalecomplexityofthefirm’sactivitiesandenable ittoidentify,manage,monitorandreport any financial crimeriskstowhichitmay beexposed.Firmsshouldensuretheyestablishaclear organisationalstructure whereresponsibilityforensuringcompliancewithanti‐moneylaundering and counterterrorismobligationsisclearlyallocated(seealsoGovernancearrangements andrisk managementcontrolsatparagraph3.157).
3.883.90 Aspartoftheinformationprovidedbyapplicants,andinaccordancewiththeMLRs,we expect details
on the risk‐sensitive anti‐money laundering policies, procedures and internal controlsrelatedto:
registrationisrequired.ThiswillbethecaseforallEMIsand(generally speaking) all PIs (unless the application only relates to the provision of money remittance services).Thesefirms only need tocomplete the ‘Authorised Payment Institution’or‘AuthorisedE‐money Institution’form, asthesecombinebothMLR registration and PSRs 2017/EMRauthorisation. Qualifying holdings (regulation 6(7) (a), paragraph 13 Schedule 2 PSRs 2017 and regulation 6(6)(a) and paragraph 8 Schedule 1 EMRs)
3.953.97 AconditionforauthorisationunderboththePSRs2017andEMRsisthattheapplicant must satisfy us
that any persons having a qualifying holding in it are fit and proper persons having regard to the need to ensure the sound and prudent conduct of the affairsoftheapplicant.Thiscomprisestwo elements:first,theapplicantwillneedto assesswhetheranypersons(orentities)haveaqualifying holdingintheapplicantand notifyusoftheiridentity;andsecondly,wewillassessthefitnessand proprietyofany such persons (or entities). Assessment of qualifying holdings
3.88 A ‘qualifying holding’ is defined by reference to article 4(1)(36) of the Capital Requirements
Regulation (EU) 575/2013onprudentialrequirementsfor creditinstitutions andinvestmentfirms, as onshored by the European Union (Withdrawal) Act 2018 amended by Capital Requirements (Amendment) (EU Exit) Regulations 2019.We refertopeoplewithaqualifyingholdingas ‘controllers’.
3.963.98 Acontrollerisanindividualorfirmthatdoesoneofthefollowing:
Assessment of suitability of controllers
3.1003.102 The term ‘fit and proper’ is used frequently in the context of individuals approved under
FSMA.Wehaveinterpretedthisterm,whichisusedinregulation6ofthePSRs 2017andregulation6of the EMRsinrelationtocontrollers,tomeaninsubstancethe sameforPIsandEMIsasitdoesfor individualsapprovedinFSMAfirms,subjectto differencesintroducedbyexplained intheEBA Guidelines.Wehavesetoutextensiveguidanceon what might fall within our consideration of fitness and propriety in the section of the Handbook entitled ‘The Fit and Proper test for Approved Persons‘. Applicants who requiremoreinformationmayfindthisguidance,aswellasthe EBAGuidelines,helpful.
3.1013.103 In Schedule 2 to the PSRs 2017 and Schedule 1 to the EMRs,the word ‘suitability’ is used to
describewhatisrequiredofcontrollers,ratherthan‘fit andproper’,whichis used in regulation 6 of the PSRs 2017 and regulation 6 of the EMRs. Although these terms are different, they incorporatethesameessentialfactors,namely the:
honesty,integrityandreputation;
competence and capability; and
financialsoundnessofthepersonwithaqualifyingholding,havingregardtotheneed toensurethe
soundandprudentmanagementofaPIorEMI(asapplicable). For more detail on our assessment of controllers’ fitness and propriety, see section 3.101 ‘Assessing fitness and propriety’. Directors and persons responsible for payment services (regulation 6(7) (b), and paragraph 14, Schedule 2 of the PSRs 2017, regulation 6(6)(b) and paragraph 9,
Schedule 1 of the EMRs)
3.1023.104 Theapplicantmustsatisfyusthatitsdirectorsandanyotherpersonswhoareorwillbe
responsibleforthemanagementoftheapplicant anditspaymentservicesactivities ande‐money issuance,areofgoodreputeandhavetheappropriateknowledgeand experiencetoperformpayment servicesandissuee‐money.
3.1033.105 This incorporates two elements: first, identification by the applicant of those with
responsibility for the payment service or e‐money activities of the applicant. All theseindividuals needtobeincludedintheapplication(theyarereferredtoasa‘PSD Individual’oran‘EMDIndividual’as appropriate).Secondly,theapplicant,togetherwith thePSDIndividualorEMDIndividual,mustprovide fullandcompleteinformationtous aboutallPSDIndividualsorEMDIndividualsinordertosatisfyusasto thereputation, knowledgeandexperienceoftheseindividuals.Thismustbedonebycompletingthe PSDIndividualformorEMDIndividualformforeachindividual.APIGuideline16and EMIGuideline16set outexplaintheinformationanddocumentationrequiredinrelationtothe identity andsuitabilityof directorsandpersonsresponsibleforthemanagementofthe applicant.Please seeourwebpagesfor thenotesandthefactsheettocompletingthe PSDIndividualformorEMDIndividualform.Weattach considerableimportancetothe completenessandaccuracyofthePSDIndividualformorEMD Individualform.Ifthe applicantisinanydoubtastowhetherornotany informationisrelevant,itshould be included. Identification of those with responsibility for the payment service or e-money activities of the applicant
3.1043.106 Inthecaseofanapplicantthatonlyprovidespaymentservices,oranEMIthatonly issuese‐moneyand
providespaymentservices,theapplicantislikelytoberequired to complete the relevant PSD Individual or EMD Individual forms for each and every manager ofthe applicant, butonly tothe extentthattheirrole isdirectly relevant to payment services or e‐money issuance. For example, we would not expect a procurement manager, whose responsibility is limited to sourcing and purchasing goodsandservicesfortheapplicant,toseekapproval. However,examplesofdirectors and persons likely to be responsible for payment services or e‐money issuance (in additiontodirectorswithqualifyingholdingsasdiscussedabove)include,butarenot limitedto:
personswithinthe payment or e‐money institution that are responsible foreach of the
outsourced activities
personsresponsiblefortheinternalcontrolfunctions(includingforperiodic, permanent
andcompliancecontrol)e.g.ComplianceOfficer
persons in charge of ensuring the applicant’s compliance with anti-money
laundering and counter‐terrorism obligations e.g. MLRO.
3.1053.107 Inthecaseofapplicantsthatcarryonbusinessactivitiesotherthansolelypayment services
and/orissuanceofe‐money,theapplicantislikelytoberequiredtocomplete the relevant PSD Individual or EMD Individual forms only for those Directors and personswithresponsibilityfor runningthefirm’spaymentservicesactivitiesand e-money issuance activities. Assessment of good repute, knowledge and experience of identified individuals
3.1063.108 We considerthe term‘of good repute’to include the same essentialfactorsrelating to
fitness andpropriety setoutbelowinrelationtocontrollers. Thismeansthatwewill considerthe sameessentialfactorssetoutinparagraph3.95above(anddescribed inthenextsection)inrespect ofalldirectorsandallindividualswhoareorwhowill beresponsibleforthemanagementofthePI orEMIoritspaymentservicesand/or e-money issuance activities. Assessing fitness and propriety
3.1073.109 We will assess the fitness and propriety of a controller or an individual on the information
provided in the application form, including PSD or EMD Individual forms and other information available to usfrom our own and externalsources. We may ask formore information ifrequired.We require the disclosure of convictions and investigations.Additionally,werequirethedisclosureofall spentandunspentcriminal convictions and cautions (other than those criminal convictions and cautions that are protected).15
3.1083.110 Duringtheapplicationprocess,wemaydiscusstheassessmentofthecontroller’sor
individual’s fitness and propriety informally with the firm and may retain any notes of those discussions.
3.1093.111 Examples of the matters we will consider for each factor are set out below. It is not possible,
however,tolistallthemattersthatwouldberelevanttoaparticular controller or individual. Honesty, integrity and reputation
3.1103.112 Indeterminingthehonesty,integrityandreputationofacontrolleroranindividual,the
followingareexamplesoffactorsthatwewillconsider.Whether:
anassessmentofthereputationofthecontrollerorindividualhasalreadybeen conducted by
a competent authority;
thepersonhasbeenconvictedofanycriminaloffenceparticularlyofdishonesty, fraud, or
financial crime;
thepersoniscurrentlybeinginvestigatedforanycriminaloffence.Thiswouldinclude wherean
individualhasbeenarrestedorcharged;
thepersonhasbeenthesubjectof anyadversefindingorany settlementincivil proceedings,
particularlyinconnectionwithinvestmentorotherfinancialbusiness, misconduct,fraudorthe formationormanagementofa firm,particularly aPI oranEMI.Thiswouldincludeanyfindingsby us,byotherregulatoryauthorities (including a previous regulator), clearing houses and exchanges, professional bodies,orgovernmentbodiesoragencies(suchasHMRC,theSerious Organised CrimeAgency,theSeriousFraudOffice,etc.)thattheindividualhasbreachedor contravenedanyfinancialserviceslegislation.Theregulatoryhistoryofthefirmor individualis thereforelikelytoberelevant; 15 The relevant legislation: the Rehabilitation of Offenders Act 1974 (Exceptions) Order 1975, the Rehabilitation of Offenders (Exceptions) Order(Northern Ireland) 1979 and the Rehabilitation of Offenders Act 1974 (Exclusions and Exceptions)(Scotland) Order 2013.
the person has been the subject of any existing investigation or disciplinary proceedings,by
us,byotherregulatoryauthorities(includingapreviousregulator), clearing houses and exchanges, professional bodies, or government bodies or agencies(suchasHMRC,theSerious OrganisedCrimeAgency,theSeriousFraud Office, etc.);
the person has been refused membership, registration or authorisation of a professional
organisationorhashadthatregistration,authorisation,membership orlicencerevoked, withdrawnorterminated,orhasbeenexpelledbyaregulatoryor governmentbody;
the person has been a director, partner, or concerned in the management, of a businessthathas
goneintoinsolvency,liquidationoradministrationwhiletheperson hasbeenconnectedwiththat organisation;
thepersonhasbeensubjecttorelevantdisciplinaryaction(includingdisqualification as company
director);
inthepast,thepersonhasbeencandidandtruthfulinalltheirdealingswithany regulatorybody
andwhetherthepersondemonstratesareadinessandwillingness tocomplywiththe requirementsandstandardsoftheregulatory systemandwith otherlegal,regulatoryand professionalrequirementsandstandards.
3.1113.113 WewillconsidermattersthatmayhavearisenintheUKorelsewhere.
3.1123.114 The‘relevant’matterswerefertoabovewillincludeoffencesunderlegislationrelating to
companies, banking or other financial services, serious tax offences or other dishonesty, insolvency,insurance,moneylaundering,marketabuse,misconductor fraud.
3.1133.115 The applicant firm should tell us of all relevant matters, but we will consider the
circumstancesinrelationtothe requirementsandstandardsofthePSRs2017or EMRs.For example,aconvictionforacriminaloffencewillnotautomaticallymean anapplicationisrejected. Wetreateachcontroller’sorindividual’sapplicationona case‐by‐casebasis,takingintoaccount theseriousnessof,andthecircumstances surrounding, the offence, the explanation offered by the convicted controller or individual,the relevanceoftheoffencetotheproposedrole,the passageoftime since the offence was committed and evidence of the controller’s or individual’s rehabilitation.
3.1143.116 Ifafirmisnotsurewhethersomethingmayhaveanimpactonacontroller’soran
individual’sfitnessandpropriety,theinformationshouldbedisclosed.Wetakethe non‐disclosure ofmaterialfactsveryseriouslyasitisseenasevidenceofcurrent dishonesty.Ifindoubt,disclose. Competence, capability and experience
3.1153.117 Indeterminingacontroller’soranindividual’scompetence,capabilityandexperience, wewill
haveregardtowhethertheindividualhasthe:
knowledge
experience
training
to be able to perform the activity of providing payment services.
Financial soundness (only relevant for assessment of controllers)
3.1163.118 Indeterminingthesuitabilityofacontrollerwewilltakeintoaccountacontroller’s
financialsoundnessandwewillconsideranyfactorsincluding,butnotlimitedto:
whether the controller has been the subject of any judgement, debt or award in the UK or
elsewhere,thatremainsoutstandingorwasnotsatisfiedwithinareasonable period;or
whether the controller has made any arrangements with their creditors, filed for bankruptcy,
hadabankruptcypetitionservedonthem,beenanadjudgedbankrupt, beenthesubjectofa bankruptcyrestrictionsorder(includinganinterimbankruptcy restriction order), offered a bankruptcy restrictions undertaking, had assets sequestrated,orbeeninvolvedinproceedings relatingtoanyofthese. Auditors and audit arrangements (paragraphs 15 and 18 Schedule 2 of the PSRs 2017, paragraph 10 and 13 Schedule 1 of the EMRs)
3.1173.119 Applicants are required to provide a description of the audit and organisational
arrangements that have been set up in relation to the safeguarding measures, governance arrangements, risk management procedures, internal control mechanisms, security incidents and security‐related customer complaints and organisational structure described in the application. These should show that the applicantistaking allreasonable stepstoprotectthe interestsofits customers andto ensurethecontinuityandreliabilityofperformanceofpaymentservicesand issuance ofe‐money.Seeparagraph3.40above.
3.1183.120 Depending on the nature, scale and complexity of its business, to comply with the
requirement of the PSRs 2017 and EMRs for sound accounting procedures and adequateinternal controlmechanisms,itmaybeappropriatefora firmtomaintain an internal audit function which is separate and independent from the other functions and activitiesofthe firm.Wewouldexpect the internalauditfunction tohavethe following responsibilities:
establish, implement and maintain an audit plan to examine and evaluate the adequacyand
effectivenessofthefirm’ssystems,internalcontrolmechanismsand arrangements
issuerecommendationsbasedontheresultofworkcarriedout
verifycompliance with those recommendations
reportin relation to internal auditmatterstosenior personnel and/orseparate supervisory
function(e.g.asupervisoryboardinatwo‐tierboardstructureor nonexecutivecommitteein a one‐tierstructure)
3.1193.121 Aswellasanyinternalauditfunction, we require, explained by APIGuideline17andEMI
Guideline17,require APIs and EMIs to provide information on the identity of its statutory auditor or audit firm.
Part II: Becoming a small PI or a small EMI
3.1203.122 BusinessescanapplyforregistrationasasmallPIandbeexemptfromthe
authorisationandprudentialrequirementsofthePSRs2017ifthey:
donotintendtoprovidepaymentservicesonacross‐borderbasisorinanotherEEA State;
haveanaveragemonthlypaymentvalueofnotmorethan€3millionovertheperiod of twelve
months preceding their application (or, where the applicant has yet to commencepayment services,orhasbeenprovidingpaymentservicesforlessthan 12 months, the monthly average may be based on the projected total amount of paymenttransactionsovera12monthperiod); and
do not intend to carry on AIS or PIS.
3.1213.123 BusinessescanapplyforregistrationasasmallEMIandbeexemptfromthe
authorisationandprudentialrequirementsoftheEMRsif:
theydonotintendtoprovidepaymentservicesonacross‐borderbasisorin another EEA
State;
theirtotalbusinessactivitiesareprojectedtogenerateaverageoutstanding e‐money that
doesnotexceed€5million;
their monthly average turnover in respect of relevant unrelated payment service
transactions over the period of 12 months preceding the application does not exceed€3 million(or,wheretheapplicanthasyettocommencetheprovisionof paymentserviceswhich arenotrelatedtotheissuanceofe‐money,orhasbeen providingsuchpaymentservicesforless than12months,themonthlyaverage maybebasedontheprojectedtotalamountofthe relevanttransactionsovera 12monthperiod);and
they do not intend to carry out AIS or PIS.
3.1223.124 The conditionsthatmustbemetin ordertobecome a registeredsmall PIorsmall EMI are
set out in regulation 14 of the PSRs 2017 and regulation 13 of the EMRs respectively. We provide guidance in relation to each of the conditions, and the associatedinformationwhichwe willrequesttoassesstheseconditions,below.We also set out other information that applicants will need to provide when applying for registration. Making an application
3.1233.125 Applicants to become a small PI or small EMI must pay a fee (see Chapter 15 – Fees for more
information).No work will be done on processing an application untilthe full fee is received.Thefeeis non‐refundable.
3.1243.126 For small PIs and small EMIs, the application must be signed by the person(s) responsiblefor
makingtheapplicationonbehalfoftheapplicantfirm.Theappropriate persons(s)dependsonthe applicantfirm’stype,asfollows:
Type of applicant
Sole trader (small PIs only)
Appropriate signatory
The sole trader
Partnership (small PIs only) Two partners
Unincorporated association (not a limited partnership) (small PIs only) All members of the unincorporated association or one person authorised to sign on behalf of them all (supported by a resolution of the committee of management or equivalent) Company with one director The director Company with more than one director Two directors Limited liability partnership Two members Limited partnership The general partner or partners Information to be provided and conditions of registration – both small PIs and small EMIs
3.1253.127 WemayrefusetoregisteranapplicantasasmallPIorsmallEMIifanyoftheconditions specifiedin
regulation14ofthePSRs2017orregulation13oftheEMRs(asapplicable) havenotbeenmet.Weprovide guidanceontheinformationwhichwewillrequestfrom applicantsbelow,includingreferencestothe PSRs2017orEMRswhererelevant.This informationwillberequestedfrombothsmallPIsandsmallEMIs. Valueofpayment transactions – regulation 14(3) of the PSRs 2017 and regulation 13(4) of theEMRs
3.1263.128 Tobe eligible for registration as a small PI, the average monthly value of payment
transactions (or, where applicable, projected monthly average) carried out by the applicant
(including by agents on its behalf) must not exceed €3 million. In their applicationforregistration, applicantswillberequiredtoself‐certifythatthebusiness willmeetthemonthlyvalueofpayment transactionscondition.If,however,wesuspect thatthismightnotbethecase,wemayask forprojected financialstatements.Wealso asktheapplicanttodescribehowitwillmonitorthemonthlyaverage valueofpayment transactionsonceitisregistered.Weexpectapplicantstohaveaclearandestablished processformonitoring thisso thatthey knowifthe requirementto become authorised (monthly averagepaymenttransactionsvalueexceeding€3million)istriggered.
3.1273.129 ForsmallEMIs,ifthebusinessplanstoundertakepaymentservicesnotconnected withthe
issuingofe‐money(unrelatedpaymentservices),thenthemonthlyaverage ofrelevantpayment transactions(or,whereapplicable,projectedmonthlyaverage) mustnotexceed€3m.Toregisterasa smallEMI,anapplicantmustalsonothavetotal business activities that generate (or, where applicable, are projected to generate) averageoutstandinge‐moneythatexceeds€5m.SmallEMIs arerequiredtoprovide financialforecastswiththeirbusinessplansandmoredetailisprovidedbelow.
3.1283.130 Applicantswillneedtotakeaccountofchangesinexchangerateswheretheycarryout
transactionsindifferentcurrencies.Inourview,itwouldbereasonableforapplicants tousethe Commission’smonthlyaccountingrateoftheeuro(whichisavailableonthe InforEurowebsite)to calculateturnoverineuroforaparticularcalendarmonth.16 Business must not include the provision of account information services or payment initiation services – regulation 14(4)of the PSRs 2017 and regulation 13(4A) of the EMRs
3.1293.131 SmallPIsandsmallEMIsarenotpermittedtocarryoutAISorPIS.Businessesthat wishtocarryout
theseserviceswillneedtoapplyforauthorisationor,inthecaseofa businessonlywishingtoprovideAIS, thebusinesswillneedtoapplytobecomeaRAISP and cease providing other payment servicesor issuing e-money. Convictions by management – regulation 14(5) of the PSRs 2017 and regulation 13(8) of the EMRs
3.1303.132 Noneoftheindividualsresponsibleforthemanagementoroperationoftheapplicant canhave
beenconvictedofoffencesrelatingtomoneylaundering,terroristfinancing orotherfinancial crimes. Wewillasktheapplicanttoconfirmontheapplicationform that this is the case.
3.1313.133 Financialcrimeincludesfraudordishonesty,offencesunderFSMA,thePSRs2017 ortheEMRs,
andactsoromissionsthatwouldbeanoffenceifthey tookplaceinthe UK.Werequirethedisclosureof spentandunspentcriminalconvictionsandcautions unless the relevant conviction or caution is protected. Qualifying holdings – regulation 14(6) of the PSRs 2017 and regulation 12(1) paragraph 4 of Schedule 3 of the EMRs
3.1323.134 Where the applicant is a partnership, an unincorporated association or a body corporate,it
mustprovideevidencethatanypersonshavingaqualifyingholding17in it (a‘controller’)aresuitable havingregardtotheneedtoensurethesoundandprudent conductoftheaffairsofthesmallPIor smallEMI.ForsmallPIs,theapplicantmust satisfy us that any controller is fit and proper.
3.1333.135 The information that we will require about qualifying holdings for an application for
registration as a small PI is the same as for an application for authorisation as an authorisedPI(setoutinPartIabove)andsmallPIswillneedtosubmitcontrollerforms forpersonswitha qualifyingholding.SmallEMIswillneedtoidentifytheircontrollersin the application formbut are not required to submitseparate formsfor personswith a qualifyingholding. 16 http://ec.europa.eu/budget/contracts_grants/info_contracts/inforeuro/index_en.cfm 17 Qualifyingholding’isdefinedbythe( CapitalRequirementsRegulation)asadirectorindirectholdinginan undertakingwhichrepresents10 %ormoreofthecapitalorofthevotingrightsorwhichmakesitpossibletoexerciseasignificant influence overthe management of that undertaking.
Directors, managers and persons responsible for payment services – regulation 14(7) of thePSRs 2017 and regulation 13(7)(a) of the EMRs
3.1343.136 The requirements for the directors, managers and persons responsible for the management
ofe‐moneyand/orpaymentservices(asapplicable)ofthesmallPIor smallEMIarethesameasthosefor anauthorisedPIorauthorisedEMI.Wewilltakethe sameapproachtoassessmentofindividualsasset outinPartIabove.Thisincludes applyingthesame‘fitnessandpropriety’testdescribedabove(section 3.101). Close links – regulation 14(8) of the PSRs 2017 and regulation 12(1) of the EMRs
3.1353.137 Forapplicantsthatarebodies corporatetheinformationwewillrequireabout‘close links’ for
applications as a small PI or small EMI is the same as those for an authorised PI (seePartIabove). Location of head office, registered office or place of residence – regulation 14(10) of the PSRsand regulation 13(9) of the EMRs
3.1363.138 ForapplicantstobeeitherasmallPIorasmallEMI,theirheadoffice,registeredoffice orplaceof
residence,asthecasemaybe,mustbeintheUK.
3.1373.139 Onlybodiescorporate(e.g.alimitedcompanyorLimitedLiabilityPartnership(LLP)) canapply
tobecomeasmallEMI.AnapplicanttobecomeasmallPImaybeanatural person,inwhichcasetheir placeofresidencemustbeintheUK.
3.1383.140 Thelocationoftheheadoffice,registeredoffice andprincipalplaceofbusinessisto be
suppliedaspartofthecontactdetails.Inassessingthelocationoftheheadoffice, we willtake the approach set outin section 3.49–3.53 above. Money Laundering registration – regulation 14(11) of the PSRs 2017 and regulation 13(10) of the EMRs
3.1393.141 Theapplicantmust complywiththeregistrationrequirementsoftheMLRs,where those
requirements apply to it (see 3.84‐3.87 in Part I above for more on MLR registration requirements).
3.1403.142 Wherewewillberesponsibleformoneylaunderingsupervisionoftheapplicant, noseparate
registrationisrequired.ThiswillbethecaseforallsmallEMIsand (generallyspeaking)allPIs(unlessthe applicationonlyrelatestotheprovisionof moneyremittanceservices).Thesefirmsonlyneedto completethe‘SmallPayment Institution’ or ‘Small E‐money Institution’ form, as these combine both MLR registration and PSRs 2017/EMRregistration.
3.1413.143 Applicantsarerequiredtoprovideadescriptionoftheanti‐moneylaunderingpolicies,
procedures and controls in place.
Programme of operations
3.1423.144 Applicants to become small PIs and small EMIs will need to provide a description of theirmain
businessandthepaymentservicesenvisaged,includinganexplanationof howthe activities andthe operationsfitintothe listofpaymentservicessetoutinPart 1ofSchedule1ofthePSRs2017.Some examplesofthesortsofactivitiesexpectedto fallwithin the scopeof eacharedescribedinChapter2– Scope,with further guidance inChapter3andChapter15ofPERG. Security incidents and customer complaints
3.1433.145 ForsmallPIsandsmallEMIs,theinformationrequiredintheregistrationapplication includes
details of how the applicant will comply with its obligation to report major operationalor securityincidentsunderregulation99ofthePSRs2017–seeChapter 13 – Reporting and notifications for more information on the incident reporting requirements.
3.1443.146 Applicantswillalsoneedtodescribethecomplaintsproceduresinplaceforcustomers that
comply with regulation 101 of the PSRs 2017 for non‐eligible complainants and ourDispute ResolutionSourcebook(DISP)foreligiblecomplainants.SeeChapter11– Complaints handling.
3.1453.147 The requirements for reporting of security incidents and customer complaints
expectedforsmallPIsorsmallEMIsarethesameasthoseforanauthorisedPIor authorised EMI (seePartI above). Sensitive payment data
3.1463.148 For small PIs and small EMIs, the application form requests a description of the applicant’s
processtofile,monitor,trackandrestrictaccesstosensitivepaymentdata. Therequirementsfor handlingsensitivepaymentdataexpectedforsmallPIsorsmall EMIsarethesameasthoseforan authorisedPIorauthorisedEMI(seePartIabove). Statistical data on performance, transactions and fraud
3.1473.149 ForsmallPIsandsmallEMIs,applicantsarerequiredtoprovideadescriptionof the
procedures they have in place for collecting statistical data on fraud (including themeans of collecting collected). This should demonstratehow the applicantwill ensure it canmeet its obligationsto report to us(see Chapter 13 – Reporting and notifications). Security policy
3.1483.150 Applicants will need to provide a description of theirsecurity policywhich must include a
detailedriskassessmentoftheservicestobeprovided,includingrisksoffraud and illegal use of sensitive and personal information and the mitigation measures to protect users from the risks identified. Applicants should also demonstrate how they willcomplywiththeirobligationunder regulation98(1)ofthePSRs2017(management of operational and security risk). They may wish to consider the use of security training, accreditation and/or certification to support their application (in particular government‐backedschemes,e.g.CyberEssentials,asecuritycertification scheme thatsetsoutabaselineofcybersecurityfororganisations).18 For small PIs and small EMIs, applicants must provide a description of the key IT systems in use which will support the provision of payment services, including off‐the‐shelf and bespoke packages. Applicants will also need to confirm whether they are already using these systems.Therequirementsforsecurityexpectedfor smallPIsorsmallEMIsarethe sameasthoseforanauthorisedPIorauthorisedEMI(seePartIabove)and includethe physical security of applicants’ premises.
3.1493.151 AssmallEMIsareinherentlyreliantonITsystemstoensuretheyoperatesoundly,we intend to
assess IT systems during the approval process. Applicants must satisfy us thattheiroverallIT strategy isproportionate tothenature,scale, andcomplexity ofthe businessandissufficientlyrobust tofacilitate,onanongoingbasis,theircompliance with the conditions of registration. Safeguarding Small EMIs – regulation 13(7)(c) EMRs
3.1503.152 SmallEMIsaresubjecttothesamesafeguardingobligationswithrespecttofundsthat havebeen
receivedinexchangefore‐moneyasauthorisedEMIs,andtheinformation that we require is the same (please refer to the information on safeguarding for authorised EMIsin PartI above).
3.1513.153 Small EMIs that provide unrelated payment services may choose to safeguard funds
received forthe execution ofpaymenttransactionsthat arenotrelated tothe issuance of e‐money. Where they choose to comply, the requirements are the same as those for an authorised EMI or authorised PI (please refer to the information on safeguarding forauthorisedEMIsinPartIabove). Small PIs
3.1523.154 SmallPIs canchoosetocomplywith safeguarding requirementsinordertoofferthe same
protections over customer funds as authorised PIs must provide. Where they choosetocomply,the requirementsarethesameasthoseforanauthorisedPI(please refertotheinformationon safeguardingforauthorisedPIsinPartIabove).
3.1533.155 There is more information on safeguarding in Chapter 10 – Safeguarding, including
guidanceonwhatwewouldexpecttoseebywayoforganisationalarrangements.
18 https://www.cyberaware.gov.uk/cyberessentials/
Additionalinformationtobeprovidedandconditionsofregistration–small EMIsonly
3.1543.156 There are conditions of registration set out in regulation 13 of the EMRs which must be
metbysmallEMIsbutdonotapplytosmallPIs.Belowwesetoutinformationwewill onlyrequestfrom applicantstobecomesmallEMIs. Business plan – regulation 13(7)(b) of the EMRs
3.1553.157 Thebusinessplanhastoexplainhowtheapplicantintendstocarryoutitsbusiness.It should
provideenoughdetailtoshowthattheproposalhasbeencarefullythoughtout andthattheadequacy offinancialandnon‐financialresourceshasbeenconsidered.
3.1563.158 Theplanmustinclude aforecastbudgetforthe firstthreefinancial years.Thebudget hasto
demonstratethatthe applicantisable toemploy appropriateandproportionate systems, resources and procedures to operate soundly, and that it will be able to continuetomeettheinitial capital requirementsandtheongoing capital(ownfunds) requirement, if applicable.
3.1573.159 Thebusinessplanshouldalsoinclude,butnotbelimitedto,thefollowing:background tothe
application;
3.1623.164 SmallEMIsthatarerequiredbytheEMRstoholdinitialcapitalarealsorequiredto maintain
adequateownfundsonanongoingbasis,byreferencetoparagraph14of Schedule 2 of the EMRs. See Chapter 9 – Capital resources and requirements for moreinformation. Governance arrangementsand risk management controls – regulation 13(6) EMRs
3.1633.165 Applicants to become a small EMI are required to provide descriptions of the governance
arrangements and risk management procedures they will use when issuing e‐moneyand providingpaymentservices.Wewillassesswhetherthearrangements, controlsandproceduresare appropriate,soundandadequate,taking intoaccounta numberoffactors,suchasthe:
typesofpaymentservicesande‐moneyenvisaged;
nature,scaleandcomplexityofthebusiness;
diversityofitsoperations,includinggeographicaldiversity;
volumeandsizeofitstransactions;and
degree of risk associated with each area of its operations.
Governance arrangements
3.1643.166 Governance arrangementsare theprocedures used in the decision-making and
controlofthebusinessthatprovideitsstructure,directionandaccountability.
3.1653.167 The description of the governance arrangements must include a clear organisational
structure with well‐defined, transparent and consistent lines of responsibility (regulation13(6)(a)of theEMRs).Ifapplicable,thisshouldcovertheunrelatedpayment servicesbusinessaswellasthee‐ moneybusiness.Wewouldalsoexpecttoreceive information on:
decision‐making procedures;
accounting procedures for monitoring that the average outstanding e-money and payment
servicestransactionsdonotexceedthethresholdsforauthorisation(see paragraphs 3.120‐3.122);
reporting lines;
internalreportingandcommunicationprocesses;
thearrangementsforregularmonitoringofinternalcontrolsandprocedures;and
measuresthatwouldbetakentoaddressanydeficiencies.
Risk management
3.1663.168 The description of therisk management procedures provided in the application should
showhowthebusinesswilleffectivelyidentify,manage,monitorandreportanyrisksto whichthe applicantmightbeexposed(regulation13(6)(b)oftheEMRs).Suchrisksmay include risks in relation to both the e‐money business and any payment services business:
settlement risk (settlement of a payment transaction does not take place as
expected);
operationalrisk(lossfrominadequateorfailedinternalprocesses,peopleor systems);
counterparty risk (thatthe other party to a transaction does notfulfil its obligations);
liquidityrisk(inadequatecashflowtomeetfinancialobligations);
marketrisk(riskresultingfrommovementinmarketprices);
financialcrimerisk(theriskthattheEMIoritsservicesmightbeusedforapurpose connectedwith
financialcrime);and
foreignexchangerisk(fluctuationinexchangerates).
Depending on the nature and scale of the business and any payment services beingprovided, itmaybeappropriate forthesmallEMItooperateanindependent riskmanagementfunction. Wherethisisnotappropriate,thesmallEMIshould nevertheless be able to demonstrate that the risk management policies and proceduresitwilladoptareeffective. PartIII:Becoming a RAISP
3.1673.169 ThissectionappliestoabusinessthatwishestobecomeaRAISP.Theinformation
requirementsrelevanttosuchapplicationscanbefoundinregulation17ofthePSRs 2017 and the conditions of registration are set out in regulation 18 of the PSRs 2017.
3.1683.170 RAISPs may not provide any payment services other than AIS.
3.1693.171 ApplicantstobecomeRAISPsmustpay a fee(seeChapter 15 – Fees for more
information).Noworkwillbedoneonprocessinganapplicationuntilthefullfeeis received.The feeisnon‐refundable.
3.1703.172 Theapplicationmustbesignedbytheperson(s)responsibleformakingtheapplication onbehalf
oftheapplicantfirm.Theappropriatepersons(s)dependsontheapplicant firm’stype,asfollows:
Type of applicant
Sole trader
Appropriate signatory
The sole trader
Partnership Two partners
Unincorporated association (not a limited partnership) All members of the unincorporated association or one person authorised to sign on behalf of them all (supported by a resolution of the committee of management or equivalent) Company with one director The director Company with more than one director Two directors Limited liability partnership Two members Limited partnership The general partner or partners Information to be provided and conditions of registration
3.1713.173 WemayrefusetoregisteranapplicantasaRAISPiftheconditionsinregulation18of thePSRs
2017arenotmet.Thisincludeswhere,ifregistered,thegroundsinregulation 10ofthePSRs2017 (cancellationofauthorisation)asappliedbyregulation19ofthe PSRs2017wouldbemetiftheapplicant wasregistered.Thismeansthatwewilltake account of those grounds (such as threats to the stability of, or trust in, a payment system,ortheprotectionofthe interestsof consumers)inconsideringan application. 19 https://www.eba.europa.eu/regulation-and-policy/payment-services-and-electronic-money/guidelines-on-authorisation-and- registration-underpsd2
3.1723.174 This section needs to be read alongside section 4.2 (“Guidelines on information required
fromapplicantsforregistration forthe provisionofonly service 8ofAnnex1 of PSD2 (account information services)) of the EBA Guidelines(the RAISP Guidelines).19 Together, these documents explain the information that we require to be supplied with the applicationandtheconditionsthat mustbesatisfied. Programme of operations (paragraph 1, Schedule 2 of the PSRs 2017)
3.1733.175 The information anddocumentation whichneedstobeprovided in the programmeof
operations for RAISP applications is set outexplained in RAISP Guideline 3. These are similar to those for an authorised PI (see Part I).
3.1743.176 Theprogrammeofoperationstobeprovidedby the applicantmustdescribetheAIS tobe
providedandexplainhowthisfitsthedefinitionofAISinthePSRs2017.Asthis servicecannotinvolve comingintopossessionoffunds,adeclarationtothiseffectis required.Inourviewbeingin possessionoffundsincludesanentitlementtofundsin abankaccountintheapplicant’sname,funds inanaccountintheapplicant’snameat another PI and funds held on trust for the applicant.
3.1753.177 Theapplicantisalsorequiredtoprovidecopiesofdraft contractsbetweenallparties involved,
andtermsandconditionsoftheprovisionoftheAIS.Wewouldexpect thisinformation to coverthe nature ofthe service being provided to the customer, howtheirdatawillbeused,andhowthe applicantwillobtainappropriateconsent(s) from the customer. See Chapter 17 – Payment initiation and account information services and confirmation of availability of fundsfor more information. Business plan (paragraph 2, Schedule 2 of the PSRs 2017)
3.1763.178 Theinformationanddocumentationwhichneedstobeprovidedinthebusinessplan for RAISP
applications is set outexplained in RAISPGuideline 4. These are similar to those for an authorisedPI(seePartI).Thisshouldcontainaforecastbudgetcalculationforthefirst 3 years. Structural organisation (Paragraph 12 of Schedule 2 of the PSRs 2017)
3.1773.179 Wewillrequireadescriptionoftheapplicant’sstructuralorganisation,whichistheplan forhow
theworkofthebusinesswillbeorganised.Theinformationanddocumentation tobeprovidedonthe structuralorganisationofapplicantsasRAISPsaredetailedin RAISPGuideline 5. Thisshould include details of outsourcing arrangements, as RAISPs will need to demonstrate that these arrangements allow them to fulfil the conditions of registration. These are similar to those for an authorised PI (see Part I). Governance arrangements, internal controls and risk management (paragraph 5 of
Schedule 2 of the PSRs 2017)
3.1783.180 Thegovernancearrangements,internalcontrolsandriskmanagementrequirements for
applicationsasRAISPsareoutlinedinRAISPGuideline6.Thesearesimilartothose foranauthorisedPI (seePartI).
3.1793.181 Dependingonthenature,scopeandcomplexityofthebusinessitmaybeappropriate for the
RAISP to operate an independent risk management function. Where this is notappropriate,the RAISPshouldbeabletodemonstratethattheriskmanagement policies andproceduresithas adoptedareeffective. SeeChapter18–Operational and security risks. Security incidents and security-related customer complaints (paragraph 6
Schedule 2of the PSRs2017)
3.1803.182 The information and documentation which needs to be provided for security incidents and
security‐relatedcustomercomplaintsrequirementsforapplicationsasRAISPsare set outexplained in RAISP Guideline 7. These are similar to those for an authorised PI (see Part I). Sensitive payment data (paragraph 7, Schedule 2 of the PSRs 2017)
3.1813.183 The information and documentation relating to sensitive payment data applicants are
requiredtoprovidearesetoutexplainedinRAISPGuideline8.Applicantsmustprovide a description of the process in place to file, monitor, track, and restrict access to sensitivepaymentdataincluding, forexample,alistofthedataclassifiedassensitive payment data in the context of the RAISP’s
business model and the procedures in place to authorise access to the sensitive payment data. These are similar to those for an authorised PI (see Part I). See also Chapter 18 – Operational and security risks. Business continuity arrangements (paragraph 8, Schedule 2 of the PSRs 2017).
3.1823.184 Theinformationanddocumentationwhichneedstobeprovidedwith respectto business
continuityrequirementsforapplicationsasRAISPsaresetoutexplained inRAISP Guideline 9. These are similar to those for an authorised PI (see Part I). Security policy document (paragraph 10 of Schedule 2 of the PSRs 2017)
3.1833.185 The information that should be provided in a security policy document is set ouexplainedt in
RAISP Guideline 10. These are similar to those for an authorised PI (see Part I). Directors and persons responsible for payment services (Paragraph 14 of Schedule 2 of the PSRs 2017)
3.1843.186 The information requirements relating to the directors and persons responsible for the
payment services of RAISPs are set outexplained in RAISP Guideline11. These information requirementsincludepersonaldetails,informationrelatingtofinancialandnonfinancial interests and information on any other professional activities carried out.
3.1853.187 PSD Individual forms should be provided as set out in Part I for authorised PIs. In assessing
whether the information relating to directors and managers indicates that that the conditions in regulation 18 of the PSRs 2017 are met (eg registration would not be contrary to the interests of consumers) we will take a similar approach to that we take to assess the fitness and propriety of directors and persons responsible for the management of authorised PIs and EMIs(see Part I above). Audit arrangements (Paragraph 18 of Schedule 2 of the PSRs 2017)
3.1863.188 RAISPGuideline6Werequiresthatanapplicantprovidestheidentityofanyauditorthatis not a
statutory auditor.
3.1873.189 Paragraph 18 of Schedule 2 of the PSRs 2017 requires the applicant to provide a description
of the audit and organisational arrangements that have been set up in relation to the governance arrangements, risk management procedures, internal controlmechanisms,securityincidentand securityrelatedcustomercomplaintsand organisationalstructuredescribedintheapplication. Professional Indemnity insurance (PII) (paragraph 19, Schedule 2 of the PSRs 2017)
3.1883.190 TheapplicantmustsatisfyusthatitholdsappropriatePIIoracomparableguarantee. RAISP
Guideline12setsoutexplainstheinformationanddocumentationwhichisrequiredin relationtothis PIIorcomparableguarantee.TherequiredPIIorcomparableguarantee must meet or exceed the minimum monetary amount directed by us from time to time.Thisdirectionhasbeenmadein paragraph3.59. Address of the head office (paragraph 17, Schedule 2 of the PSRs 2017)
3.1893.191 Theapplicantmustprovidetheaddressofitsheadoffice.Thereisnorequirement inthe
PSRs2017forthistobeintheUKalthoughwemustbeable toeffectively supervisetheapplicantonceit isregistered.Wewilljudgeeachapplicationona case‐by‐casebasis.Asabove,wemayrefusetoregister anapplicantasaRAISPifany of the conditions in regulation 18(1) of the PSRs 2017 applies. One of those conditions is that, if the applicant were registered, there would be grounds for cancellation (under regulation10,asappliedbyregulation19ofthePSRs2017). PartIV:Decision‐makingprocess
3.1903.192 This section relates to the decision-making process for all applications for
authorisation and registration under the PSRs 2017 and the EMRs.
3.1913.193 Havingassessedtheapplicationandalltheinformationprovided,wewillmakea decisionto
eitherapproveorrejectit.Thisdecisionwillbenotifiedtotheapplicant, alongwithinstructions
fortheappealprocess,ifrelevant.
Timing (regulation 9(1) and (2) of the PSRs 2017, regulation 9(1) and (2) of the EMRs)
3.1923.194 Wehavetomakeadecisiononacompleteapplicationwithinthreemonthsofreceiving it. An
application is only complete when we have received all the information and evidenceneeded forustomakeadecision.Wewilllettheapplicant knowifweneed moreinformationandwhenyour applicationbecomescomplete.
3.1933.195 Our commitment20 to dealing with applications for authorisation or registration areas
follows:
not to deal with a particular categoryofcustomer).Therequirementmaybeimposedbyreference to anapplicant’srelationshipwithitsgrouporothermembersofitsgroup.Wemayalso specify the timethatarequirementexpires.
3.1983.200 Whereanapplicant carriesonbusinessactivitiesotherthan theissuanceofe‐money and/or
provisionofpaymentservices(asthecasemaybe)andwefeelthatthecarrying onofthisbusinesswill, orislikelyto,impairourability tosupervisetheapplicantorits financial soundness, we can require the applicant to form a separate legal entity to issuethee‐moneyand/orperformpaymentservices. 20 https://www.fca.org.uk/publication/corporate/our‐approach‐authorisation.pdf p. 21
3.1993.201 WewillupdatetheFinancialServicesRegisterassoonaspossibleaftergrantingthe
authorisation or registration. The Financial Services Registerwill show the contact details of thebusiness,thepaymentservicesitispermitted toundertake, andthe names of any agents. If the firm isauthorised and has takenuppassporting rights to performpaymentservicesin anotherEEAState,thenthesewillalsobeshown. Refusal (regulation 9(7) to (9) of the PSRs 2017, regulation 9(6) to (8) of the EMRs)
3.2003.202 Wecanrefuseanapplicationwhentheinformationandevidenceprovideddoes notsatisfythe
requirementsofthePSRs2017orEMRs.Whenthishappensweare requiredtogivethe applicant a warningnoticesettingoutthereasonforrefusingthe application and allowing them 28 days to make a representation on the decision.
3.2013.203 Applicants can make oral or written representations. If oral representations are
required,weshouldbenotifiedwithintwoweeksofthewarningnotice,sothat arrangements canbemadeforameetingwithinthe28‐daydeadline.
3.2023.204 If no representations are made, or following them we still decide to refuse the application,
wewillgivetheapplicantadecisionnotice.Ifafirmwishestocontest thedecision,theymayreferthe mattertotheUpperTribunal(FinancialServices),an independentjudicialbody.Ifnoreferralhasbeen madewithin28dayswewillissuea finalnotice.IfthematterisreferredtotheTribunal,wewilltake actioninaccordance withanydirectionsgivenbyit(includingtoauthorise/registerthefirm) andwill then issue thefinal notice.
3.2033.205 On issuing the final notice, we are required to publish such information about the matterto
whichafinalnoticerelatesasweconsiderappropriate.Wemaynot,however, publish information if we believe it would be unfair to the firm or prejudicial to the interests of consumers. PartV:Transitionalprovisions(regulations151to154ofthePSRs 2017, regulation78AoftheEMRs) Inordertocontinueprovidingpaymentservices,PIsandEMIsauthorisedorregistered underthePSRs 2009ortheEMRsmustbere‐authorisedorre‐registered.Theymust also pay a fee (see Chapter 15 – Fees for more information).
3.204 Existing PIs and EMIs must comply with the new requirements of PSD2 (introduced throughthe PSRs
2017 and our Handbook), including conduct of business changes, new complaints handling timeframes and new reporting and notifications from 13 January 2018, prior to becoming re‐ authorisedorre‐registered.Businessesshould reviewthe start date for each requirement asthere are someexceptions,inparticular in relation to changes in control.
3.204 TherearealsotransitionalprovisionsforfirmsthathavebeenprovidingAISorPIS priorto12
January2016,whichdeterminewhentheywillneedtogetauthorisedor registered.
Authorised EMIs
3.204 Underregulation78A(2)(b)oftheEMRs,EMIsauthorisedbefore13January2018are subject to an
automatic requirement on their authorisation, preventing them from providingAISorPIS.If
authorisedEMIswishtoprovidetheseservices,theywillneedto applytoustohavethisrequirement removed.SmallEMIscannotprovideAISorPIS. Businesses providing AIS or PIS BusinessesthatstartedprovidingPISorAISonorafter12January2016hadto beauthorisedto providetheseservices(orregistered,ifonlyprovidingAIS)by 13January2018tocontinueproviding theseservices.Forexistingauthorised payment institutions this means that they will need to have successfully applied for re‐authorisationandavariationtoaddAISorPIS.Forexisting authorisedEMIs,they will need to have successfully applied for re-authorisation that permits them to provide AIS or PIS or for the requirement imposed by regulation 78A(2)(b) of the EMRs to be removed. Existing small PIs and small EMIs will have to cease providing these services, or become authorised.
3.205 ProvidersofAISandPISwhichwereprovidingthoseservicesbefore12January2016 andwhichcontinue
toprovidesuchservicesimmediatelybefore13January2018will be able to continue to do so until 14 September 2019 (when the Regulatory Technical Standards on strong customer authentication and secure communication (SCA-RTS) come into effect).21 Thismeans:
21 https://eur‐lex.europa.eu/legal‐content/EN/TXT/PDF/?uri=CELEX:32018R0389&from=EN
4 Changes in circumstances of Authorisation or registration Thischapterdescribesthenotificationsthatauthorisedandsmallpaymentinstitutions (PIs) and emoney institutions (EMIs) need to make to us as part of their ongoing authorisation or registration It is divided into three parts.
4.84.9 Regulation 37 of the PSRs 2017 and regulation 37 of the EMRs also requires that, in the case of a
substantial changewhichhasnotyettakenplace,thePIorEMImustprovidedetailsofthechangein a ‘reasonableperiod’beforethechangetakesplace.A‘substantialchange’is,inour view, one that could impact on eitherthe firm’s ability tomeetthe conditionsfor remainingauthorisedorregistered,or thewaywewouldsupervisethefirm.Inrelation toEMIs,this couldincludechangestotheway thate‐ moneyisissuedortotherange ofpaymentservicesprovided.Wewillneedtoassesssubstantial changesagainst the initial conditions for authorisation or registration. Togive us time to do this, we considerthataperiodof28daysbeforethechangetakesplacewouldgenerallybe‘a reasonable period’.Insomecircumstances,however,wewouldexpecttobenotified further in advance. The notification period will depend on the circumstances of the changeandfirmsshouldmakeefforts tonotifyusassoonaspossible.TheCustomer Contact Centre can provide further guidance. How to notify us
4.94.10 NotificationsmustbemadeusingConnect,or,whereaformisnotprovided,bywritten confirmation
to our Customer Contact Centre.
Different notifications for authorised and small PIs and EMIs
4.11 NotallnotificationrequirementsapplytobothauthorisedandsmallPIsandauthorised and small
EMIs. This is mostly due to authorised PIs and authorised EMIs having to meetmoreinitial conditionsthat couldchangeoverthe lifeofthebusiness.Although mostofthenotification requirementsthatapplytoasmallPIandsmallEMIalsoapply toanauthorisedPIandauthorisedEMI, somedonot.
4.104.12 Not all notification requirements apply to firms in a temporary permission regimes (TA Firms). See
Chapter 6 for more information.
Part I: Notifications applicable to authorised and small PIs and
EMIs
4.114.13 Changesintheinformationsetoutbelowwillrequireanotificationtous.
Name, contact details and firm data (including firm name and contact details)
4.124.14 PIsandEMIsshouldgiveusreasonableadvancenoticeofchangestotheirnameand contact details,
which includes:
Significant changes to the programme of operations
4.144.16 We would expect to be notified by the PI or EMI of any significant changes to the business. This
may include proposed restructuring, reorganisation or business expansionthatcouldhavea significantimpactonthefirm’sriskprofileorresources. ForEMIsthiscouldincludechangestothe EMI’sdistributors.Asnotedabove,PIsand EMIs must notify us of certain significant changes that are covered in Chapter 5 – Appointment of agents and Chapter 6 – Passporting.
4.154.17 Wewouldalsoexpecttobeadvisedofanyproposedactionthatislikelytoresultinan EMIorPIbeing
unabletomeetitscapitalrequirements,includingbutnotlimitedto:
4.214.23 Section178(1)ofFSMA(asmodifiedbySchedule3oftheEMRsandSchedule6ofthePSRs 2017,respectively)
requiresapersonwhodecidestoacquireorincreasecontroloveran EMIorPItonotifyusinwriting,and obtainourapprovalbeforeproceedingwiththechange incontrol.Thisnoticeisreferredtoasa‘section178’ andcanbefoundonourwebsite. The notice can be submitted electronically to cicnotifications@fca.org.uk or sent by post. Section 191D(1) of FSMA (as modified) provides that a person who decides to reduce or cease to have control over an EMI or PI must give us written notice before making the disposition.
4.224.24 Whereapersonintendstoacquire,increaseorreducecontrol,ortoceasetohave controloveraPI
oranEMI,andthiscausesthemtocrossacontrolthreshold(10%, 20%, 30% or 50%, or to acquire a holding that makes it possible to exercise a significantinfluenceoverthemanagementofthe authorisedPIorEMI),thatperson mustnotify usbefore the proposedtransaction.
4.234.25 Ourapprovalisrequiredbeforeanyacquisitionoforincreaseincontrolcantakeplace. Wehave60
workingdays(whichcanbeinterruptedandputonhold foruptoanother 30workingdays)todecide whethertoapprove, approvewithconditionsorobjectto the proposed changes in control.24
4.244.26 Whenconsideringaproposedacquisitionorincreaseincontrol,wemustconsiderthe suitability of the
person and the financial soundness of the acquisition of control to ensure the continued sound and prudent management of the EMI or PI.25 Wemustalso considerthelikely influence thatthe personwillhaveontheEMIorPIbutwecannot consider the economic needs of the market (see
Chapter 3 – Authorisation and registration, especially regarding qualifying holdings).
4.254.27 Wemayonlyobjecttoanacquisitionoforincreaseincontroliftherearereasonable groundsfordoing
sobasedonthe criteriainsection186ofFSMA, orifthe information providedbythepersonproposing toacquireorincreasecontrolisincomplete.
4.264.28 Ifweconsiderthattherearereasonablegroundstoobjecttotheproposedchange,we mayissuea
warningnotice,whichmaybefollowedbyadecisionnoticeandfinalnotice. Thereisaprocessformaking representationsandreferringthemattertothe Tribunal. Wherewehavegivenawarningnotice,a decisionnoticeorafinalnotice,wemayalso give a notice imposing one or more restrictions on shares or voting power (a restriction notice). Under the EMRs and PSRs 2017, when issuing a restriction notice we must directthatthe voting powersubjectto the restriction notice issuspended until further notice(thisdiffersfromtheFSMAregime,underwhichthesuspensionofvotingrights is within our discretion).
4.274.29 Personsthatacquireorincreasecontrolwithoutpriorapproval,orincontraventionofa warning,
decisionorfinalnotice,mayhavecommittedacriminaloffence.Forexample, apersonwhogivesnotice, andmakestheacquisitiontowhichthenoticerelatesbefore the expiry date of the assessment period is guilty of an offence unless we have approvedtheacquisitionorsection190AofFSMAapplies.We mayprosecuteandif foundguiltythepersonmaybeliabletoanunlimitedfineorgivenaprison sentence.
4.284.30 The formofnotice thatmustbe givenby apersonwhodecidestoacquireorincrease controloveran
EMIorPI,andthe informationthatmustbeincluded inthenotice andthedocumentsthatmust accompany it,willbethe sameasapply toasection 178noticeinrespectofanacquisitionoforincrease incontroloveranauthorised personunderFSMA.Noticegiventousbyapersonwhodecidestoacquire orincrease controloveranEMIandPImustcontaintheinformationandbeaccompaniedbysuch documentsasarerequiredbythe relevantFCAcontrollersform.Alink tothe formsis availableontheemoney section ofourwebsite.
4.294.31 There is no form to notify us of a reduction or disposal of control in an EMI or PI. A notice
shouldbegiving inwritingwherethisisgoingtooccur.Anemailisacceptable (cicnotifications@fca.org.uk).Thisnotificationshouldincludethenameofanacquirer, andpercentageof control tobedisposed of. 23 See section 178 to 191 of FSMA. 24 Also see regulation 6(6)(a) of the EMRs.
Notifications from firms subject to changes in control
4.304.32 InrelationtoPIsandEMIs,weconsiderchangesincontroltobe‘significant’inrelation tochangesin
thecircumstancesofauthorisationorregistration.Therefore,weexpect to be notified where it becomes apparentto an institution thattherewill be a change incontrol,ingoodtimebeforethe changetakesplace.Itissufficienttoprovidea notification via email to cicnotifications@fca.org.uk,orsendalettertous.Underthe PSRs 2017 there are no notification forms for institutions to complete. Notification formsaresubmittedbyprospectivecontrollers,as describedabove.PIsauthorised orregisteredunderPSRs2017willcontinuetosubmittheappropriate ‘Applicationfor aChangeinQualifyingHolding’form,whichisavailableonthepayment institutions
section of our website,untiltheyarere‐authorisedorre‐registeredunder thePSRs 2017D2.
Other changes affecting controllers and close links
4.314.33 Aconditionforauthorisationandregistrationisthatanyonewithaqualifyingholding inan
authorisedorsmallEMIorPI(acontroller)mustbea‘fit andproper’person.A further condition for authorisationorregistration isthat, ifthe applicant has close linkswith anotherperson,itmust satisfy usthatthoselinks arenotlikely toprevent oureffectivesupervision.Weexpectthe authorisedorsmallEMIorPItonotifyus if there are or will be significant changes likely to affect these conditions (whether under the PSRs 2017 or EMRs, or for TA Firms the relevant home state’s implementation of PSD2 or EMD), without unduedelay,underregulation37ofthePSRs 2017orregulation37oftheEMRs.This is in addition tothe annualreporting requirements(see
Chapter 13 – Reporting and notifications for further information).
Directors and persons responsible for management Appointment and removal
4.324.34 Changestothedirectorsorpersonsresponsibleformanagementofeitherthe PIor EMI,orthe
activitiesofthePIorEMI,areregardedasasignificantchange.TheEMIor PIshouldnotifyusof appointmentsbeforethechangetakesplace,andremovalsno later than seven working days after the event.
4.334.35 For TA Firms, notification should be made bywritten confirmation to our Customer Contact
Centre. Paragraphs 4.35-41 do not apply to TA Firms.
4.344.36 For PIs, notification of a new appointment should be made using Connect, and
shouldincludealltheinformationrequiredforustoassesstheindividualagainsttherequirementin regulations6and13ofthePSRs2017 tobeofgoodreputeandpossess appropriate knowledge (see
Part I, Chapter 3 – Authorisation and registration). An individual who is a member of the
management staff who moves from being a non‐ boardmembertoaboardmemberwill need to resubmitthe relevantformonConnect.
4.354.37 ForEMIs,notificationofanewappointmentshouldbeonthe‘EMDIndividualform’, whichis
availableonourwebsite,andshouldincludealltheinformationrequiredfor ustoassesstheindividual againsttherequirementsinregulation6(6)(b)orregulation 13(7)(a) (as appropriate) to be of good repute and possess appropriate knowledge (see Chapter 3 – Authorisation and registration).
4.364.38 PIs and EMIs must also notify us of any changes in the details of existing PSD IndividualsorEMD
Individuals,suchasnamechangesandmattersrelatingtofitness andpropriety.PIsshoulddothis usingthe‘NotificationofchangestoPSDIndividual’ form,whichisavailableonourwebsite. EMIs should do this using the ‘Amend an EMD Individual’ form, which is available on our website.
4.374.39 If we consider that the proposed change has an adverse impact on the PI or EMI we willadvise
thefirmofourconcerns.Wherewebelievetheproposedchangewillhave an adverse impact on a PI or EMI, we have the power under regulations 12 of the PSRs 2017 and regulation 11of the EMRs to vary the PI’s or EMI’s authorisation or registrationbyimposingsuchrequirementsasweconsider appropriate.Ifthechange thengoesaheadandwebelievethatanyofthe relevant conditionsof regulation10of the PSRs 2017 and regulation 10 of the EMRs relating to cancellation of authorisation orregistrationaremet,wemay takeactiontocanceltheauthorisationorregistration ofthe PIorEMI andremoveitfromthe register,orseek toimposerequirementson a PI’s or EMI’s authorisationor registration underregulation 12 of the PSRs 2017 and regulation 11of the
EMRs.
4.384.40 Informationabouttheremovalof‘directors/personsresponsible’shouldinclude the reason for
the departure and provide further information if the individual was dismissed for reasons potentially relating to criminal or fraudulentactivities.
4.394.41 Notification for PIs should be on the ‘Notice to remove PSD Individual(s)’ form whichisavailable
onourwebsite.ForEMIsitmustbemadeonthe‘RemoveanEMD Individual’form,whichisavailable onthee-money sectionofourwebsite.Formore information on the fit and properrequirement for directors and personsresponsible for management of the PI or EMI see Chapter 3 – Authorisation and registration. Changes affecting the fitness and propriety of individuals
4.404.42 WhenaPIorEMIbecomesawareofinformationthatmayhaveanimpactonthefit and proper
condition applying to ‘directors/persons responsible’ for management of the PI/EMIand/orits paymentservicesand/ore‐moneyissuanceactivities(asapplicable), thePIshouldnotifyususingthe ‘NotificationofchangestoPSDindividual’form and the EMI should notify us using the ‘Amend an EMD Individual form’, as detailed above. For PIs and EMIs we authorise, Wwe will examine the information, assess it against the fitness and propriety requirements explained in Chapter 3 – Authorisation and registration, and notify the PI or EMI of the action that we intend to take. Variation ofauthorisation
4.414.43 WhenaPIintendstochangethepaymentservicesitisprovidingitneedstoapplytousforapproval.. Both
PIs and EMIs also need toapply tousfor approval iftheywanttohave anewrequirementimposedoran existingrequirementvariedorremoved.
4.424.44 The variation of authorisation provisions (paragraphs 4.44‐49) are not relevant to TA firms. Where a
firm has a temporary permission under the TPR and wants to undertake further regulated activities, the firm (or the relevant UK subsidiary) will have to apply for permission for new activities as part of its overall application for authorisation in the UK.
4.434.45 Regulations5and13ofthePSRs2017andregulations5and12oftheEMRsrequire thatanapplication
forvariationinauthorisationorregistration(respectively)must:
Determining a variation – PIs and EMIs
4.474.49 The process for determining a variation is the same as for initial authorisation/ registration (see
Parts I and II, Chapter 3 – Authorisation and registration) and the time allowedforustodothis isthreemonths.Weexpect,however,tobeable toprocesscompleteapplicationsforvariation quickerthananinitialauthorisation/ registration,andourexpectedturnaroundtimeswillinmost casesbequickerthan this.Wherefirmswanttoincreasetherangeofservicestheyprovidetheywill needto factor in the time needed for approval. MLR registration
4.484.50 PIs and EMIs should notify the Customer Contact Centre immediately if there isa
changeinthestatusoftheirMLRregistrationwithHMRC.SeeChapter 3 – Authorisation and registration for more details of MLR registration requirements. Cancellation of authorisation/registration
4.51 PIs and EMIs can request to cancel their authorisation or registration (regulations
10 and 14 of the PSRs 2017 and regulations 10 and 15 of the EMRs, respectively). They should use the ‘Cancellation of Authorisation or Registration’ form, which is available on Connect. We will remove the PI or EMI from the Financial Services Register once we have established that: there are no outstanding fees to either us or the Financial Ombudsman Service; any liabilities to customers have either been paid or are covered by arrangements explained to us; and there is no other reason why the PI or EMI should remain on the Register.
4.494.52 Regulation 10(1) of the EMRs and regulation 10(1) of the PSRs 2017 do not apply
to TA firms so paragraphs 4.52-55 are not relevant. Cancellation of temporary permissions is covered in Chapter 6.
4.504.53 We can cancel an EMI’s or PI’s authorisation or registration on our own initiative
when:
4.514.54 WhereweproposetocancelanEMI’sorPI’sauthorisationorregistrationotherthanat theEMI’sorPI’s
request,theEMIorPIwillbeissuedwithawarningnoticeforwhichit canmakerepresentations.Ifthe cancellationgoesahead,theEMIorPIwillbeissued with a decision notice (see Chapter 14 – Enforcement).
4.55 Ourfee yearrunsfrom1 April until 31March,so if a PI or an EMI appliesto cancel after 31March,full
annualfeeswillbecomepayableastherearenopro‐rataarrangements or refunds of fees. Change in legal status
4.524.56 Achangeinlegalstatus(e.g.limitedliabilitypartnership(LLP)tolimitedcompany)isa significant change
totheauthorisation/registrationofthePIorEMI.Suchachangeis effectedbycancellingtheexisting legalentityauthorisation/registrationandarranging for the authorisation/registration of the new legal entity. PIs should apply using the appropriate‘ChangeofLegalStatus’form,whichareavailable onourwebsite. EMIs shouldusethe‘ChangeofLegalStatus’formthatisavailableonourwebsite.
Part II: Notifications applicable only to authorised PIs and EMIs
4.534.57 This part gives examples of changes that are likely to impact the conditions for authorisation of an
authorised PI or EMI (whether under the PSRs 2017 or EMRs, or for TA Firms the relevant home state’s implementation of PSD2 or EMD). As noted in the introduction, the duty to notifychanges incircumstancesisgeneralandwewillexpectbusinessestonotifyusof anysignificantchangein circumstances,includingchangesnotsetoutinthischapter, which are relevant to the continued fulfilment of the conditions for authorisation. Outsourcing arrangements
4.544.58 An authorised PI must inform us when it intends to enter into an outsourcing contract whereit
willberelyingonathirdparty toprovidean‘operationalfunction relating toits provision of payment services’ (regulation 25(1) of the PSRs 2017). The corresponding requirementfor EMIsrelatesto anEMI’sintentiontoenterintoanoutsourcing contract whereitwillberelyingonathirdparty to providean‘operationalfunction relatingtothe issuance,distribution orredemptionofe‐moneyorthe provisionofpaymentservices (outsourcing)’ (regulation 26(1) of the EMRs).
4.554.59 Inourview,‘operationalfunctionsrelatingtoprovisionofpaymentservices’forPIsand ‘operational
functionsrelating tothe issuance,distribution or redemptionof e‐money or the provision of payment services’ for EMIs does not include the provision of any services that do not form part of the payment services or e-money issuance (e.g. legal advice,trainingorsecurity)orthe purchaseofstandardisedservices,includingmarket information services.
4.564.60 A proposed outsourcing arrangement, relating to both PIs and EMIs,thatis classified as ‘important’
(pursuant to regulations 25(2) and (3) of the PSRs 2017 and regulations 26(2)and(3)oftheEMRsas applicable) is more likely to be relevant to a PI or an EMI’s compliance with the authorisation conditions than a proposed outsourcing arrangement that is not ‘important’. Where an authorised PI or EMI changes its important outsourcing arrangements without entering into a new outsourcing contract, it will need to consider whetherthe change isrelevantto the conditions for authorisation and so needsto be notified underregulation 37ofthe PSRs 2017or regulation 37 of the EMRs.
4.574.61 Notification of changestooutsourcing requirementsshould bemadetotheCustomer Contact
Centre.Depending onthenatureofthe arrangement,wemay requestfurther information. Changes in outsourcing functions or the persons to which the functions areoutsourcedmustbe notifiedwithoutunduedelay.
4.584.62 Registered Account Information Service Providers (RAISPs)will alsoneed to ensure that any
changes to their outsourcing arrangements do not cause them to stop meeting the conditions of registration. RAISPs may wish to notify usif they consider suchchangestobe important. Auditors
4.594.63 WhereanauthorisedPIorEMIhasanauditor,andisawarethatavacancyintheoffice ofauditorwill
ariseorhasarisen,itshould:
5 Appointmentofagentsanduse of distributors
Thischapterdescribestheapplicationprocessforpaymentinstitutions(PIs),e‐money institutions (EMIs) and registered account information service providers (RAISPs) to registertheiragents withus.ItalsocoverstheappointmentofdistributorsbyEMIs. Other chapters in this Approach Document are also relevant to the appointment of agents and distributors. These include
Chapter 4 – Changes in circumstances of authorisation, especially paragraphs 4.6to4.11, and
registration and Chapter 6 – PassportingTemporary permission schemes, especially paragraphs 4.6to4.11and6.7to6.10,6.14to6.18and6.24to6.47.6.22‐24. Introduction PIs and EMIs
5.1 AllPIs,EMIsandRAISPsmayprovidepaymentservices in the UK throughagents,aslongasthey register
themwithusfirst.AnagentisanypersonwhoactsonbehalfofaPI,EMIor RAISP (i.e. a principal) in theprovision of payment services (see the definitionof agent in regulation 2 of the Payment Services Regulations 2017(PSRs 2017)and regulation 2 ofthe Electronic Money Regulations 2011 (EMRs) as applicable).
5.2 Regulation 34 of the PSRs 2017 and regulation 33 of the EMRs set out the requirementsfor
theuseofagents in the UK.Inaddition,regulation36(2)ofthePSRs2017and regulation36(2)ofthe EMRsconfirmthatPIs,EMIsandRAISPsareresponsiblefor anythingdoneoromittedbyanagent.PIs, EMIsandRAISPsareresponsiblefortheir agents’ acts oromissionstothe same extent asiftheyhad expressly permitted the act oromission.WeexpectPIs,EMIsandRAISPstohaveappropriatesystemsand controls in place to oversee their agents’ activities effectively.
Chapter 6 – Passporting). This is not relevant to small PIs or small EMIs, as they are not
5.45.2 permitted to passport into other EEA States.
5.3 Regulation33oftheEMRsstatesthatanEMImaydistributeor redeeme‐money through an
agentor a distributor, butmay notissue e‐money through an agent or distributor.
5.65.4 Unlike agents, distributors cannot provide payment services,so itisimportantto understand
the difference betweenthe two.Inourview, apersonwhosimply loadsorredeemse‐moneyon behalfofanEMIwould,inprinciple,beconsideredtobeadistributor.
5.75.5 Aswithagents,anEMIisresponsibleforanythingdoneoromittedbyadistributor. Anauthorised
EMImayengageadistributorintheexerciseofitspassportingrights, subjecttoregulation28ofthe EMRs. Provision of account information services (AIS) and payment initiation services through agents. Registered account information service providers (RAISPs) RAISPS are also subject to the requirements relating to agents in regulations 34 and 36(2) of the PSRs 2017. A RAISP wanting to use an agent to provide payment services in another EEA State must provide details of their EEA agents as part of their passporting notification, and these agents will be added to the Financial Services Register.
5.6 RAISPs and PISPs are responsible for services agent(s) provides on their behalf and must have the
correct level of professional indemnity insurance to cover services provided directly as well as those provided through agents.
5.7 The agreement to provide AIS (or PIS) is between the regulated or authorised AISP/PISP and the
consumer and should make clear that the agent is providing AIS or PIS on the AISP’s or PISP’s
behalf. In addition, the AISP must get explicit consent from the consumer to access their accounts to provide AIS.
5.8 The role of an agent is different to the role of a third party. An authorised/ registered AIS/PIS may
pass information on to a third party for that third party to use to provide a (different) service to customers (subject to the customer’s agreement), such as credit scoring or loan application. The third party does not need to be authorised or registered as a RAISP/AISP or PISP as it is not performing either regulated activity.
5.9 The role of an agent is also different to the role of a 'technical service provider' (TSP) that supports an
authorised or registered account information service provider by using its technology to access relevant payment accounts on behalf of the RAISP/AISP or PISP does not provide the information to the user itself and there is no direct relationship between the TSP and the consumer. As set out in PERG 15 Q25A, when providing technical services for a RAISP/AISP or PISP, the TSP does not need to be registered or authorised as an AISP/PISP. Applying to register an agent
5.10 PIs,EMIsandRAISPswhowanttoregisteranagentmustdosothroughConnect.The sameConnect
formisusedforagentsofauthorisedandsmallPIs,EMIsandRAISPs.
5.11 Thefollowinginformationisrequired fortheregistrationofanagentinaccordancewith regulation34of
thePSRs2017orregulation34oftheEMRs:
application form. The PI or EMI must provide an updated version of its internal control mechanisms without undue delay if there are significant changes to the details communicated at the initial notification stage.
5.16 PIs and EMIs should take reasonable measures to satisfy themselves that the agent’s antimoney laundering internal controls and mechanisms remain appropriate throughout the
agency relationship.
Directors and persons responsible for the management of the agent
5.17 Wemustbeprovidedwithdetailsofthedirector(s)andperson(s)responsibleforthe managementof
theagent. Forincorporatedagentsthesearetheboardmembers,or for unincorporated agentsthe partners orsole trader,togetherwith any other person thathasday‐to‐day responsibility forthe managementofthe agent.
5.18 Toverifyidentity,werequirethenameandnationalinsurancenumberforUKresidents (or taxation
insurance number for non‐UK residents) and date and place of birth for each person.
5.19 WheretheagentisnotitselfaPSP(e.g.aPI,EMIorRAISP)wealsoneedevidence thattherelevant
individualsarefitandproperpersons.WeaskPIs,EMIsandRAISPs toprovideinformationaboutthe individuals(includinganyadverseinformation)and certifythattheyhavebeenassessedasfitand properpersons.PIs,EMIsandRAISPs shouldcarryouttheirownfitness andproprietychecksontheir agents,onthe basis of a ‘due and diligent’ enquiry before making the application. The assessment should be proportionate to the nature, complexity and scale of risk in the distribution, redemption, payment services or other activities being carried out by the agent.
5.20 We expect PIs, EMIs and RAISPs to consider the following factors when making enquiries about
thefitness andproprietyofthedirectorsandpersonsresponsiblefor themanagementofanagent:
exchange‐of‐information‐for‐passporting‐under‐psd2. These RTS will take effect as a Commission Delegated Regulation once publishedintheEU’sOfficialJournal.WewillupdatethisApproachDocumentasnecessaryaftertheRTScomeintoforce. Additional information and changes to information supplied
5.25 Atanytimeafterreceivinganapplicationandbeforedeterminingit,wemayrequirethe applicantto
provideuswithfurtherinformationasweconsiderreasonablynecessary to determine their application (regulation 34(5) of the PSRs 2017 and regulation 34(5) of the EMRs). This can include documents to support the fitness and propriety checks carried out on agents.
5.26 Once an application has been submitted, before it has been determined and on an ongoingbasis,
applicantsmustwithoutunduedelaytellusaboutsignificantchanges in circumstances relating to the fitness and propriety of an agent’s management or of anything relating to money laundering or terrorist financing. Decisionmaking
5.27 We are required to make a decision on applications to registering an agent within two months of
receiving acomplete applicationwhere the agent is engaged in relation to theprovision of payment services or e-money issuance in the UK. WithservicesprovidedthroughanEEAagentusingpassportingrights,ourdecision willtake into accountinformation given to us by the hoststate competent authority (See Chapter 6 – Passporting).WearerequiredtomakeadecisiononEEAagent registration within three months of receiving a complete application.
5.295.28 An application to appoint an agent may be combined with an application for authorisationor
registration–inwhichcaseitwillbedeterminedinaccordancewith the timetable forthat application. Approval
5.29 WeupdatetheFinancialServicesRegisterwhenweapproveanagentapplication, usuallywithinone
businessday.WealsocommunicatetheapplicationresulttothePI, EMIorRAISP.If the TPR Notification contains all the required information on the TA firms agent(s) then we will register these agents with effect from IP Completion Day (as defined in the European Union (Withdrawal Agreement) Act 2020) or as soon as practicable thereafter.
5.30 If the agent does not appear on the Register as expected (i.e.,aftertwomonths or after IP
Completion Day)(or,foranagentinanotherEEAState,threemonths (see Chapter 6 – Passporting) the agentdoesnot appearontheRegister,the PI,EMI or RAISP should contact the Customer Contact Centre.PIs,EMIsandRAISPscannot provide payment services through an agent until the agent is included on the Register.
5.29 Underregulation34(14)ofthePSRs2017andregulation34(12A)oftheEMRs,PIs,EMIs and RAISPsmust
notify us of the date when they startto provide payment services in another EEAStatethrougha registered EEA agent.PIs,EMIsand RAISPsshould notify us using Connect. Wemust notify such date to the relevant hoststate competent authority. Refusal
5.305.31 The PSRs 2017 and the EMRs only allow us to refuse to include the agent in theregister where:
a. wehavenotreceivedalltheinformationrequiredintheapplication(seeMaking an application above) or we are notsatisfied thatthe information is correct b. wearenotsatisfiedthatthedirectorsandpersonsresponsibleforthemanagement ofthe agent are fit and properpersons
c. wehavereasonablegroundstosuspectthat,inconnectionwiththeprovisionof services
through the agent
– money laundering or terrorist financing within the meaning of the Money Laundering Directive(orMLRsintheUK)istakingplace,hastakenplaceorhas been attempted – the provision of services through the agent could increase the risk of money launderingorterroristfinancing
5.315.32 Where the application relates to the provision of payment services in exercise of passport rights
through an EEA agent, we will take into account any information received from the host state competent authority and notify the host state competent authorityofourdecision,providing reasonsifwedonotagreewiththeirassessment.
5.325.33 Chapter 14 – Enforcement provides more information on what we will do if we
propose to refuse to include an agent on the Financial Services Register. Cancellation of agents
5.335.34 Tocancel an agent registration the principal must submit a Remove PSD agent or RemoveEMD
agentapplicationthroughConnect.WewillupdatetheFinancialServices Register to show that the agent is no longer registered to act for the principal once we have finishedprocessing the notification.
5.345.35 If an agent is being used to perform payment services in another EEA State, the principal may also
need to amend the details of the passport, and must submit a Change in passport details application through Connect (see Chapter 6 – Passporting). PleasenotethatifaPI,EMIorRAISP removesitslastEEAagentwithinoneEEAState anddoesnothaveabranchinthatState,therelevant PSD2or2EMDestablishment passportmustbecancelled. Changes to agent details
5.355.36 The principalmustsubmit an Amend PSD agent or Amend EMD agent application through
Connect to amend the details of an agent.
5.365.37 Wewillassesstheimpactofthechangeagainsttheagentregistrationrequirements. If the change is
approved we will update the Financial Services Register as soon as possible.Ifweneedmore informationwewillcontactthePSP,andifthechangeisnot approvedwewillfollowtherefusal processsetoutabove. Notifying HMRC ThePIorEMIshouldmakesurethatHerMajesty’sRevenueandCustoms’(HMRC’s) MoneyServiceBusinessRegisterisuptodate andthatanyagentsubmissionsmadeto ushavebeenincluded in the list of premises notified to HMRC.
6 Temporary permission schemes
6.1 This chapter sets out who and what is covered by the temporary permission schemes relevant to incoming EEA
authorised electronic money institutions (EMIs), EEA authorised payment institutions (PIs) and EEA registered account information service providers (RAISPs). It is also a guide to the requirements applicable to EEA authorised credit institutions, EEA authorised EMIs, EEA authorised PIs and EEA RAISPs in temporary permission schemes, with signposts to where to find further information on the requirements under the Payment Services Regulations 2017 (PSRs 2017) and the Electronic Money Regulations 2011 (EMRs). What are the temporary permissions schemes?
6.2 The UK left the EU on 31 January 2020 with a Withdrawal Agreement. The Withdrawal Agreement included a
transition period, which ended on 31 December 2020 (referred to as Implementation Period Completion Day, or IP Completion Day). During this period EU law continued to apply in the UK, including the EU’s passporting regime.
6.3 Under the passporting regime, financial services firms specified in the relevant directives (including the
electronic money directive and second payment services directive) in any EEA country have access to the single market for financial services. This means that they can provide regulated financial services, within the scope of the directives, in other EEA countries without the need for further authorisation.
6.4 The UK’s participation in the passporting regime ended on 31 December 2020. This meant that many EEA
financial services firms, previously operating in the UK on the basis of a passport, would need to seek permission to continue to access the UK market at the end of the transition period or, alternatively, wind‐up their UK business.
6.5 To minimise disruption to firms, the Government introduced schemes to enable such firms to continue to
operate in the UK for a transitional period. The schemes applicable to incoming EEA authorised EMIs, EEA authorised PIs and EEA RAISPs are set out in Schedule 3 of the Electronic Money, Payment Services and Payment Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018 (the Exit SI).
6.6 Parts 1 and 2 of Schedule 3 of the Exit SI establish the ‘Temporary Permissions Regime’ or ‘TPR’. This enables
firms that passported into the UK immediately before IP Completion Day to operate in the UK as though authorised / registered by us. This is limited to the scope of the previously passported permissions and is for a limited period after IP Completion Day. To be in the TPR, firms had to meet the criteria in the Exit SI and have notified us before IP Completion Day. Firms that did are now shown in the Financial Services Register.
6.7 Parts 1A and 3 of Schedule 3 of the Exit SI establish the ‘Financial Services Contracts Regime’ or ‘FSCR’. This is
split into two separate regimes.
6.8 The first is the ‘Supervised Run‐Off Regime’ or ‘SRO’ set out in Parts 1A and 3 of Schedule 3 (excluding
paragraphs 12L and 36). This enables firms that provided services passported through a branch or agent in exercise of a passport right and either did not enter the TPR, or who later exit the TPR without a UK authorisation / registration, to continue to operate in the UK as though authorised by us for a limited purpose. This transitional authorisation is limited to the scope of the previously passported permissions, for the specific purpose of performing pre‐existing contracts and/or redeeming outstanding e‐money, and is for a limited period after IP Completion Day.
6.9 The second is the ‘Contractual Run‐Off Regime’ or ‘CRO’ established set out in paragraphs 12L and 36 of
Schedule 3 of the Exit SI. This enables firms that passported into the UK on a services basis and did not enter the
TPR, or who later exit the TPR without a UK authorisation / registration, to continue operating in order to perform pre‐existing contracts or redeem outstanding e‐money, without breaching the prohibitions in Regulation 61(1) of the EMRs and Regulation 138(1) of the PSRs 2017 which prohibit such activities without UK authorisation / registration.
6.10 A pre‐existing contract for the purposes of the SRO is a contract entered into before IP Completion Day or, if the
firm has exited the TPR without a UK authorisation / registration, the date the firm exits the TPR and under which the firm is obliged to issue e‐money or provide payment services. We consider that a similar definition is applicable for the purposes of the CRO.
6.11 Before IP Completion Day, incoming EEA credit institutions were able to provide payment services and issue e‐
money in the UK under the passporting provisions of Directive 2013/36/EU (the Capital Requirements Directive). After IP Completion Day, these passporting rights were not available to EEA credit institutions. Part 3 (temporary permission) and Part 6 (supervised run off) of the EEA Passport Rights (Amendment, etc., and Transitional Provisions) (EU Exit) Regulations 2018 (EEA Passport Regulations) establish a temporary permission regime and supervised run‐off regime applicable to credit institutions. The EEA Passport Regulations also establish a contractual run‐off regime. What provisions of the EMRs and PSRs 2017 apply to firms in the TPR and SRO?
6.12 Firms in the TPR and SRO (TA firms) will be deemed to have a temporary authorisation / registration:
Regulation 25 of the EMRs,
Regulation 24 of the PSRs 2017– accounting and Not applicable Not applicable Not applicable Applies
Schedule 3,
paragraph 4 of the
EMRs, Schedule 6, paragraph 5 of the
PSRs 2017 – control
Not applicable Not applicable Not applicable
Applies
Schedule 6,
paragraph 6 of the
PSRs 2017– incoming firms:
intervention by FCA
Not applicable Not applicable Not applicable
Applies
Regulation 63(1) of the EMRs,
Regulation 138(1) of the PSRs – prohibition
Not applicable Not applicable Not applicable
N/A
6.16 The conduct of business requirements at Parts 6, 7 and 8 of the PSRs 2017 apply to all TA firms and to EEA
authorised credit institutions with temporary authorisation under the EEA Passport Regulations.
6.17 The rules and guidance in the FCA Handbook applicable to payment service providers also applies to TA firms
and EEA authorised credit institutions with temporary authorisation under the EEA Passport Regulations. Guidance on how the FCA Handbook applies to firms with temporary authorisations can be found in the General Provisions Chapter 2.2.36G.
6.18 This The Approach dDocument sets out our guidance on the provisions of the EMRs and PSRs 2017. Some of this
guidance will be relevant to TA firms while operating in the TPR and/or the SRO, some will only be relevant to TA firms going through a UK authorisation / registration process. How to read the Approach Document as a TA firm Chapters
Introduction
Does it apply to a
TA firm
Yes
Comments
This chapter is relevant to TA firms. References EMIs, PIs and RAISPs in this chapter are deemed to include TA firms and references to credit institutions are deemed to include those
Scope Yes This chapter is relevant to TA firms. References EMIs, PIs and
RAISPs in this chapter are deemed to include TA firms and references to credit institutions are deemed to include those with temporary authorisation.
Authorisation
and registration
No This chapter is not relevant to TA firms, but it will be of interest to such firms making an authorisation or registration application under the EMRs or PSRs 2017.
Changes in
circumstances
Yes This chapter is relevant to TA firms. References to EMIs, PIs and RAISPs in this chapter are deemed to include TA firms except where stated otherwise. Note that some of the notification requirements do not apply to TA firms and that there are additional notification requirements set out in this
Chapter 6.
Appointment of
agents and use of distributors
Yes This chapter is relevant to TA firms when appointing new agents. References to EMIs, PIs and RAISPs in this chapter are deemed to include TA firms.
Status disclosure
and use of the FCA logo
Yes This chapter is relevant to TA firms. References to EMIs, PIs and RAISPs in this chapter are deemed to include TA firms.
Conduct of
business requirements
Yes This chapter is relevant to TA firms. References EMIs, PIs and RAISPs in this chapter are deemed to include TA firms and references to credit institutions are deemed to include those with temporary authorisation.
Capital resources
and requirements
No This chapter is not relevant to TA firms, but it will be of interest to such firms making an authorisation application under the EMRs or PSRs 2017.
Safeguarding Yes This chapter is relevant to TA firms. References to EMIs, PIs
and RAISPs in this chapter are deemed to include TA firms except where stated otherwise.
Complaints
handling
Yes This chapter is relevant to TA firms. References EMIs, PIs and RAISPs in this chapter are deemed to include TA firms and references to credit institutions are deemed to include those with temporary authorisation.
Supervision Yes This chapter is relevant to TA firms. References to EMIs, PIs
and RAISPs in this chapter are deemed to include TA firms except where stated otherwise.
Reporting and
notifications
Yes This chapter is relevant to TA firms. References EMIs, PIs and RAISPs in this chapter are deemed to include TA firms and references to credit institutions are deemed to include those with temporary authorisation.
Enforcement Yes This chapter is relevant to TA firms. References to EMIs, PIs
and RAISPs in this chapter are deemed to include TA firms.
Fees No This chapter is not relevant to TA firms, Iinformation on fees
applicable to TA firms is set out in this Chapter 6.
Payment
service providers access to payment account services Yes This chapter is relevant to TA firms. References EMIs, PIs and RAISPs in this chapter are deemed to include TA firms and references to credit institutions are deemed to include those with temporary authorisation.
Payment
initiation and account information services and confirmation of availability of funds Yes This chapter is relevant to TA firms. References EMIs, PIs and RAISPs in this chapter are deemed to include TA firms and references to credit institutions are deemed to include those with temporary authorisation. Note that rReferences to ASPSPs include credit institutions, PIs and EMIs that are TA firms where they are the account provider.
Operational and
security risks
Yes This chapter is relevant to TA firms. References EMIs, PIs and RAISPs in this chapter are deemed to include TA firms and references to credit institutions are deemed to include those with temporary authorisation.
Financial crime Yes This chapter is relevant to TA firms. References to EMIs, PIs
and RAISPs in this chapter are deemed to include TA firms.
Authentication Yes This chapter is relevant to TA firms. References EMIs, PIs and
RAISPs in this chapter are deemed to include TA firms and references to credit institutions are deemed to include those with temporary authorisation.
6.19 The UK’s decision to withdraw from the EU triggered a significant programme of amending legislation to ensure
that the UK continued to have a functioning financial services regulatory regime after IP Completion Day. This has been referred to as “onshoring”. Effective on IP Completion Day, multiple changes were made to the legislation, regulatory rules and guidance applicable to payment services and the issuance of e‐money.
6.20 This onshoring process meant that there are some areas wheresome of the requirements on firms changed. To
help firms adapt to their new requirements, the Treasury gave UK financial regulators (including the FCA) the power to make transitional provisions to for financial services legislation for a temporary period. We applied this power in a Transitional Direction on a broad basis from IP Completion Day until 31 March 2022. In summary, tThis allows firms to delay phase in compliance with the changes in law made as part of the onshoring exercise over a longer period, up to 31 March 2022.
6.21 However, the Transitional Direction has limited application to TA firms. It does not apply to the requirements of
the temporary permission schemes, including the application of the EMRs and PSRs 2017 to TA firms. TA firms must comply with the applicable obligations under the EMRs, PSRs 2017 (as amended by the Exit SI or, relying on the Transitional Direction, as were in force immediately pre‐IP Completion Day) . In respect of the parts of the FCA Handbook applicable to TA firms, the Transitional Direction has no effect on DISP or PRIN. In respect of the parts of BCOBs that apply to PIs, EMIs and RAISPs, to the extent the amendments in BCOBS result in BCOBS applying differently, we have applied the direction, so firms will have the option of continuing to comply with the pre‐IP completion day regime if they wish. Certain changes to SUP are also in scope of the direction. There is more detail on this in Annex B to our Transitional Direction. Requirements on TA firms Notification of intention
6.22 By the end of 31 December 2021, TA firms in the TPR must notify the FCA of their plans for the UK business. In
this notice, a firm must tell us whether it or a UK subsidiary (whichever is applicable) intends to apply for authorisation or whether it intends to apply for registration, or whether it is intending to cease issuing e‐money or providing payment services in the UK.
6.23 Once this notification has been submitted, if the TA firm’s intention changes it must notify us of this change
within a reasonable time. We considerthataperiodof28daysafterthe decision changing this intention is made wouldgenerallybe‘a reasonabletime’. Other notifications under the Exit SI
6.24 In addition to certain notifications required under the EMRs and PSRs 2017, TA firms have additional
notification obligations. These differ depending on whether the firm is in the TPR, or whether the firm is in the SRO or the CRO . Unless otherwise specified, notifications by firms in the TPR must be made by email to TPQueries@fca.org.uk and notifications by firms in the SRO must be made by email to FSCRNotifications@fca.org.uk. We expect these notifications to be made to us within 28 days of the notifiable event occurring, at the latest.
6.25 A TA firms in the TPR must notify us of any material changes to the information provided in the notification it
made to enter into the TPR (the TPR Notification). This includes changes to the TA firm’s name and address,
changes to agents, providers of operational functions relating to the provision of payment services and, if an EMI, changes to distributors.
6.26 All TA firms must notify us about certain actions taken in its the home state. Although treated as an authorised
PI, EMI or RAISP, a TA firm is not, in fact, authorised / registered by the FCA but by its home state competent authority. We expect that the home state competent authority is responsible for ongoing supervision of the TA firm against local requirements implementing the electronic money directive (EMD) and the second payment services directive (PSD2), including the conditions forof authorisation and capital requirements. TA firms must notify us of any regulatory action taken against themit by the home state competent authority. This could include, amongst other things, the imposition of requirements, requests for information and the carrying out of onsite inspections. TA firms must also notify us of any cancellation or variation of its the home state authorisation / registration to provide payment services or issue e‐money and any other regulatory action.
6.27 TA firms must also notify us of any adverse judgments made against it by its home state competent authority
acting under legislation implementing the EU Money Laundering Directive. Details on how to make this notification can be found in this Direction.
6.28 Firms in the SRO or the CRO must notify the FCA of that fact as soon as becoming (and no later than one month
after becoming) aware of an obligation to perform a pre‐existing contract. This notification must be made in accordance with our direction (which can be found here).
6.29 A firm in the SRO must notify us once it no longer has any obligations under pre‐existing contracts i.e. when its
regulated payments/e‐money business in the UK has been completely wound down. On considering that notification, we will notify the firm of the date the authorisation / registration for the purposes of the SRO expires and remove the firm from the FCA Register on that date. Safeguarding
6.286.30 TA firms are required to safeguard relevant funds in accordance with the EMRs or and/or PSRs 2017. We may
ask TA Ffirms which hold safeguarding accounts outside the UK to explain what measures they are taking so that the UK customer relevant funds held by the firm are insulated in the interest of customers against the claims of other creditors in the event of the insolvency of the firm. Agents and distributors
6.306.31 Where a TA firm included details of its agent(s) in its TPR Notification, or notification under the SRO, we will
include these agents on the Financial Services Register; the TA firm will not need to separately apply to register that agent. However, if the details of such agents change following submission of that notification the TA firm must notify us of this.
6.316.32 Similarly, TA firms must notify us of existing distributors in the TPR Notification. This means that TA firms must
then notify us of any changes to the details on distributors provided in this notification, see Chapter 4 – Changes in Circumstances. TA firms in the TPR must notify us of any intention to engage further distributors.
6.326.33 Where a TA firm wishes to appoint additional agents (additional to those included in the TPR Notification) it
must follow the application process outlined in Chapter 5. There is no requirement to register distributors. Permitted services under the SRO
6.336.34 The SRO provides a temporary authorisation / registration for a specific and limited purpose. It may only be
used for services necessary to performing a pre‐existing contract.
6.35 However, the wind‐down of business operations can be complex and the Exit SI allows for firms to enter into
new contracts for the purposes of winding down the business (subject to approval of the relevant wind‐down plan by the FCA). [We expect a wind‐down plan to address the solvent wind‐down of the business, including the return of all customer funds in a timely manner.…..] Fees
6.346.36 TA fFirms’ fees are calculated using the same designations as authorised PIs, EMIs and RAISPs.
6.356.37 FEES 4A provides information on periodic fees for TA firms.
6.366.38 In addition to the annual fees mentioned above, firms will also need to pay a fee when you submit your
application for authorisation / registration. There is more information on authorisation application fees here. Requirements for firms in the CRO
6.376.39 Where a firm relies on the CRO to issue e‐money or provide payment services under a pre‐existing contact it
must make specific disclosures to the relevant customer. This disclosure must notify the customer:
Exiting the SRO
6.42 The aim of the SRO is to allow certain firms that do not enter the TPR, or that exit the TPR without full UK
authorisation / registration, time to allow for the orderly wind‐down of their UK regulated activities. An SRO firm’s deemed permission will end on the earliest of the following:
7 StatusdisclosureanduseoftheFCAlogo
7.1 Thischapterexplainswhatpaymentinstitutions(PIs)ande‐moneyinstitutions(EMIs) may sayabout
theirregulatory statusandthe restrictionontheuseofourlogo.
7.2 WehavedecidednottoallowanyfirmtousetheFCAlogoinanycircumstances.Our reasonsareset
outinFSAPolicy Statement13/5ofMarch2013atsection2.3and incorporatedintotheFCA HandbookinChapter5oftheGeneralProvisionsChapter (GEN 5).
7.3 ThisdoesnotpreventanyPI,EMIorregisteredaccountinformationserviceprovider (RAISP)from
makingafactualstatementaboutitsregulatorystatus(asisrequiredin theinformationrequirements inPart6ofthePaymentServicesRegulations2017). Annex3setsoutsomesamplestatementsforPIs, EMIsandRAISPstodescribetheir regulatoryrelationshipwithus.
7.37.4 Firms in the contractual run‐off regime set out in paragraphs 12L and 36 of Schedule 3 of the
Electronic Money, Payment Services and Payment Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018 should also be mindful of the additional disclosure obligations set out in Chapter 6 – Temporary Permission Schemes.
8 Conductofbusinessrequirements
8.1 This chapter describes the conduct of business requirements. The Payment Services Regulations 2017 (PSRs
2017) conduct requirements apply to all payment service providers (PSPs) — including e‐money institutions
(EMIs) when providing payment services. This excludes credit unions, municipal banks and the National Savings Bank. The Electronic Money Regulations 2011 (EMRs) conduct requirements apply to all e‐money issuers.
8.2 Thechapterissetoutasfollows:
8.8 Definitionsforthe termsusedinthis chapter canbefoundinregulation2ofthePSRs 2017.
Application of the conduct of business requirements
8.9 TheconductrequirementsinthePSRs2017applytopaymentservicesprovided from an
establishmentintheUK,irrespectiveofthelocationofanyotherPSPinvolvedor thecurrencyofthe transaction.Thereare,however,exceptionstothis.
8.10 WhereoneofthePSPsislocatedoutsidetheEuropeanEconomicArea(EEA)UK,Parts6 and 7 of the
PSRs 2017 apply only to the parts of a transaction which are carried out in the EEAUK. Certain requirements only apply to transactions where the PSPs of both the payer and the payee are located in the EEA UK or where the payment transaction is in eurosterling, or the currency of a member state that has not adopted the euro. Parts 6 and 7 of the PSRs 2017 also apply to transactions where the PSPs (which includes EEA PSPs subject to PSD2) of both the payer and payee are located within the UK or and EEA (the qualifying area) where the payment transaction is in euro and executed under a payment scheme which operates across the qualifying area (a Qualifying Area Transaction).
8.11 We have added guidance in Chapter 2 – Scope to assist PSPs with establishing whethera
particularconductofbusinessrequirementappliestoapaymentservice/ transaction. Interaction with other legislation
8.12 InadditiontocomplyingwiththePSRs2017,PSPs and e‐money issuers willneedtocomplywith
other relevant legislation.
FSMA and the FCA Handbook
8.13 Firms which are regulated under the Financial Services and Markets Act 2000 (FSMA) (e.g.
because they are accepting deposits, carrying on credit‐related regulated activitiesorregulated investmentbusiness)PSPsande‐moneyissuersmustcomplywith any relevantobligationsin theHandbook that apply to them.Forexample,whereapplicable,theymustcomplywiththePrinciplesfor Businesses aslongasthesedonotconflictwiththePSRs2017orEMRs3 .
8.14 WedescribebelowsomeotherHandbookandlegislativerequirementsthat FSMA authorised
firms may need to betaken into account.
Consumer Credit Act 1974 (CCA) and The Consumer Credit Sourcebook (CONC)
8.15 Generallyspeaking,businessesthatlendmoneytoretailconsumersarerequiredtobe authorisedbyus
under FSMA unlesstheyareexemptoranexclusionapplies.
8.16 The CONC sets out the detailed obligations that are specific to credit‐related regulated activities
and activities connected to those credit-related regulated activitiescarriedonbyfirms.Other conductofbusinessrequirementsareimposedby the Consumer Credit Act 1974 (CCA)and legislation made under it.
8.17 Underregulation32(2)ofthePSRs2017,PIsandunderregulation32(2)oftheEMRs, EMIsmaygrant
credit,subjecttotheconditionsoutlinedinregulation32(2)ofthePSRs 2017 and regulation 32(2) of the EMRs. These include that the credit is not granted fromthe fundsreceivedorheld forthe 3 in 2019 we extended the application of the Principles for Business and some provisions of the Banking Conduct of Business Sourcebook (BCOBS) to PIs and EMIs and to the provision of payment services and issuance of e‐money (to the extent they did not already apply). See PS19/3.
purposesofexecutingpaymenttransactions orinexchangefore‐money.Wherethegrantingofthe creditisregulatedbyFSMA,the firmisalsorequiredtohaveauthorisationunderthatAct.
8.18 IfaPSPgrantscredit,thegeneralprincipleisthat,whereaPSPprovidesapayment serviceandgrants
credit,thetworegulatoryregimesapplycumulatively.Thereare, however,someexceptionstothis andthePSPneedstobeawareofhowthetwo regimesinteract.Wesetoutmoredetailin paragraphs8.64–8.68. The Banking: Conduct of Business sourcebook (BCOBS)
8.19 Retaildeposittakers,e.g.banks,buildingsocietiesandcreditunions—arerequiredto comply with
theBCOBS. In addition, Chapter 2 of BCOBS applies to banks and building societies, EMIs, PIs and registered account information providers (RAISPs) with respect to the provision of payment services or issuance or redemption of electronic money.
8.20 Broadly speaking, BCOBS does not apply where conduct in relation to a service is alreadyregulated
underthePSRs2017.Chapter1ofBCOBSsetsoutwhichprovisions ofBCOBSapplycumulativelyto paymentservicesalongsideParts6and7ofthePSRs 2017(e.g.BCOBS2relatingtocommunicationsand financialpromotionsandBCOBS 6relatingtocancellation).ItalsosetsoutwhichprovisionsofBCOBS do notapply to paymentserviceswhereParts6and7ofthePSRs2017apply(e.g.mostofBCOBS4 relatingtoinformationrequirements).
8.21 Forpaymentaccountsprovidedbybanksandbuildingsocietiesinconnectionwith accepting
deposits, the provisions in Parts 6 and 7 of the PSRs 2017 about the disclosure of specified items of information at the pre-contract and post contract stages,liabilityforunauthorised payments,executionofpaymentsandsecurityand authentication of payments will always apply. This means that the corresponding provisionsofBCOBSthatregulatethesamemattersdo notapply.
8.218.22 For provision of accounts that are not payment accounts (e.g. some savings accounts) the
requirementsinParts6and7ofthePSRs2017donotgenerallyapply toconduct thatrelatestothe accounttakenasawhole, andsothePSPwillneedtocomplywith therequirementsinBCOBS.The effectofthisis,forexample,thatifa PSPwishesto changetheinterestratesonanaccountwhichisnota paymentaccount,thePSPwill needtoapplytherelevantnoticeperiodunderBCOBS,notthePSRs2017. Provisions inthePSRs2017thatapplytopaymenttransactionswill,however,applytoindividual payment transactions within the scope of the PSRs 2017 that are made to and from accounts which are not payment accounts. This means, for example, that the PSRs 2017information requirementsmustbecompliedwithinrelationtosuchtransactions, and if the PSP failed to execute a transaction from such an account correctly, regulations91and92ofthePSRs2017wouldapply becausethePSRs2017applyto that payment transaction. Provisions in the PSRs 2017 that apply only to payment accounts (e.g. regulation 89(1)) will not apply to non-payment accounts and the relevantprovisionsinBCOBSwillapplyinstead.Guidanceonthemeaningof payment account is set out in PERG 15.
8.228.23 BecausecreditunionsareexemptfromthePSRs2017,theconductprovisionsof BCOBSwillapply
to them in respect oftheirretail banking services, except where expresslydisapplied(seeBCOBS 1.1.5R).
8.238.24 BCOBS includesrulesrelating to:
communicationswithbankingcustomersandfinancialpromotions
communication with payment services and electronic money customers and payment services and
electronic money promotions
currency transfer services
distancecommunications,includingtherequirementsofthefordDistanceMarketing marketing
Directive andEe-commerce Directive
informationtobecommunicatedtobankingcustomers,includingappropriate information
and statements of account
post‐salerequirementsonprompt,efficientandfairservice,movingaccounts,and lost or
dormant accounts
cancellation,includingtherighttocancelandtheeffectsofcancellation
However, in PS19/3 we confirmed an extension of the Principles for Business and some provisions of the Banking Conduct of Business Sourcebook (BCOBS) to payment institutions and Electronic Money Institutions. This included the issuance of electronic money and provision of payment services by banks and building societies. The change has extended the application of certain communication rules and guidance in the BCOBS to communications with payment service and e‐money customers and we also introduced new rules that relate to services that involve currency conversions. For more information regarding these changes, please see PS19/3. Distance Marketing marketing Directive
8.25 The DistanceMarketing marketing Directive (DMD)requirements provides protection for
consumers whenever theyenterintoafinancialservicescontractbydistancemeans,includingfor payment services.BoththePSRs2017andtheDMDdistance marketing requirementsapplyto contractsforpaymentservices. In particular,PSPs should be aware of the information requirements in the DMDrelated to distance marketing which apply in addition to the information requirements in the PSRs 2017.
8.26 For credit institutions, tTherulesimplementingtheDMDinrelationto distance marketing ofretail
bankingservices canbefound intheHandbookinBCOBS.ForPSPsande‐moneyissuersthatarenot undertaking aFSMAregulatedactivity,theserulesimplementingtheDMDarefoundintheFinancial Services (Distance Marketing) Regulations 2004 (DMRs) and, for regulated credit agreements, theyarefoundintheHandbookinCONC. Cross-border payments and Single Euro Payments Area (SEPA) legislation
8.27 Regulation 924/2009 as amended by Regulation 2019/518 (referred to as CBPR2) wais a directly
applicable European Union (EU) regulation, on‐shored by the European Union (Withdrawal) Act 2018 (EUWA) and amended by the Securities Financing Transactions, Securitisation and Miscellaneous Amendments (EU Exit) Regulations 2020. It that prohibitsPSPsfromchargingmorefor across‐borderpaymentineuro,Swedishkronor orRomanianlei any currency of the European Economic Area (EEA)thanforacorrespondingdomesticpaymentinthesamecurrency sets out disclosure requirements relating to cross‐border payments with a currency conversion.We arethe competentauthority andtheFinancialOmbudsmanServiceistheout‐of‐court redress providerfor this regulation.
8.28 Regulation260/2012 on‐shored by the EUWA and amended by the Credit Transfers and Direct Debits in
Euro (Amendment) (EU Exit) Regulations 2018(SEPARegulation)laysdownrulesforcredittransferand direct debittransactionsineurowhereboththepayer’sPSPandthepayee’sPSParelocated inthe EEAqualifying area,orwherethesolePSPinthepaymenttransactionislocatedintheEEAUK.The SEPA Regulationisalsodirectlyapplicable,andwearetheUKcompetentauthority. The E-Commerce commerce Directive (2000/31/EC)requirements
8.29 The E‐Commerce Directive establishes harmonisedUK e‐commerce requirements govern rules
on issues such as the transparencyandinformationrequirementsforonlineserviceproviders, commercial communications and electronic contracts.
8.30 The rules implementing the E-Commerce Directive in relation toThe rules related to e‐
commerce deposit taking and activitiesassociatedwiththatactivitycanbefoundintheHandbookin BCOBS3.2.For e‐commerce credit‐related regulated activity, the rules implementing the E‐ Commerce Directive canbefoundintheHandbookinCONC2.8.
8.31 Forotherpaymentservicesandtheissuanceofe‐money,therulesimplementing the ECommerce Directiverelating to e‐commerce are found in the Electronic Commerce (EC
Directive) Regulations 2002.
Unfair Contract Terms – The Unfair Terms in Consumer Contracts Regulations 1999 (UTCCRs) and the ConsumerRights Act 2015 (CRA)
8.32 The CRA applies to contracts between consumers and PSPs or e‐money issuers enteredinto on or
after 1October 2015(theUTCCRs continue to apply tocontracts concludedbeforethatdate).
8.33 TheCRArequirestermsusedbybusinessesintheircontractsandnoticestobefair. Further
informationabouttheCRAandUTCCRscanbefoundinTheUnfairTerms andConsumerNotices RegulatoryGuide(UNFCOG),onourwebsiteandontheCMA website. PSPs and e‐money issuers must ensure that their consumer contracts complywithboththeconductofbusinessprovisionsof thePSRs2017andEMRsand the unfair contract terms provisions of theCRA(or UTCCRs). The Consumer Protection from Unfair Trading Regulations 2008 (CPRs)
8.34 PSPs and e-money issuers should note that the CPRs apply to their payment service ande‐
moneybusinesswithconsumers.TheCPRsareintendedtoprotectconsumers fromunfaircommercial practicesbybusinesses.“Commercialpractices”include advertising and marketing or other commercial communications directly connect withthesale,promotionorsupplyofaproduct. FurtherinformationabouttheCPRs canbefoundonourwebsite.TheCMAhasalsopublished guidancerelatingtothe CPRs.
8.35 Inprovidingcustomerswithdetailsoftheirservice,PSPsande‐moneyissuersmust avoid giving
customers misleading impressions or marketing in a misleading way, e.g.:
The Payment Account Regulations 2015 (PARs)
8.40 The PARs , which implement the Payment Accounts Directive, introduced greater transparencyof
feesandcharges,easieraccountswitchingandbetteraccesstobasic bank accounts.
8.41 TherequirementsofthePARsapplyvis‐a‐visconsumers,whereastherequirements ofthePSRs2017
applyvis‐a‐visallpaymentserviceusers(whichincludesbusiness customers).
8.42 The PARs apply to “payment accounts” but they have their own definition of this, which is narrower
than the definition of “payment account” under the PSRs2017. This means thatsomeaccountswill be classed as “payment accounts” underthe PSRs 2017, but will not be classed as “payment accounts” underthe PARs(e.g. certain savings accounts).PSPsshould becareful toapply the correctdefinition of “paymentaccount” depending on which regime they are applying.
8.43 WhereboththeprovisionsinthePARsandthePSRs2017applytoaccounts,PSPs must comply with
both sets of requirements. For example, the PSRs 2017 require charges information to be provided to customers pre‐contractually. The PARs will require a fee information documenttobe provided pre‐ contractually. The requirement under the PARs applies in addition to the requirements in the PSRs 2017 (see regulation8(1)(a)ofthePARs).PSPscould,however,usethefeeinformationdocument to providedetailsofchargesunderthePSRs2017,providedtherequirements of both pieces of legislation are met.
8.44 Similarly,wheretheprovisionsinthePARsandthePSRs2017applytoabasicbank account,regulation
51ofthePSRs2017will apply totheterminationofthe account. This is, however, subject to the specific list of termination conditions set out in regulation26(1)ofthePARswhichlimitthereasons thatapaymentaccountwithbasic featurescanbeterminatedbythePSP.
8.45 FurtherguidanceonthePARscanbefoundonourwebsite.
ISA Regulations and COBS
8.46 WherePSPsareprovidingISAs,theyalsoneedtobeawareoftheirobligationsunder theISA
RegulationsandtheConductofBusinessSourcebookintheHandbook.
The Security of Network & Information Systems Regulations (NIS Regulations)Directive on security of network and information systems
8.47 Directive(EU)2016/1148oftheEuropeanParliamentandoftheCouncilof6July2016 concerning
measures for a high common level of security of network and information systemsacrossthe Union(NIS) The NIS Regulations includesprovidemeasuresonthereliabilityandsecurityof critical networkandinformationsystems,includingincidentreportingrequirements. NIS came into force in August 2016 and is to be implemented by member states by May 2018.
8.48 UndertheNIS regulations,operatorsofessentialservicesarerequiredtoprovidenotificationtotheir
competent authority in the event “of incidents having a significant impact on the continuity of essential services they provide.”
8.49 CreditinstitutionsaredefinedasoperatorsofessentialservicesunderNIS Regulations,insofar as
theymeetthecriteriasetoutinArticle5(2)8ofNIS.TheEBA’sguidelinesonMajor Incident Reporting confirmthatthe requirementsfornotification ofincidents under PSD2areconsidered tobeatleastequivalenttotheobligationsin the European Directive (EU) 2016/1148 which the NIS Regulations originally implemented4NIS.Therefore iIncidents affecting creditinstitution’s paymentservicesshouldbereportedunder PSD2 rather thanNIS. The Interchange Fee Regulation (IFR)
8.50 Regulation (EU) 2015/751, on‐shored by the EUWA and amended by the Interchange Fee
(Amendment) (EU Exit) Regulations 2019 (the IFR), TheIFRisadirectlyapplicableEUregulation32 , whichintroducedsets outobligationsforPSPs dealingincard‐basedpaymentswhichare 4 Following the UK’s exit from the EU we continue to expect firms we regulate to apply the EBA Guidelines to the extent that they remain relevant4.
complementarytotherequirementsunder PSD2. We are jointly competent with the Payment Systems Regulator for some of theseprovisions.ThemajorityofIFRrulesrelatingtobusiness obligationsforPSPs conductingbusinessincard‐basedpaymentstookeffecton9June2016.
8.51 The Payment Systems Regulator has producedguidance setting out its approach in relation
to its functions under the IFR.
Data protection legislation
8.52 PSPsneedtobeawareoftheirobligationsundertheDataProtectionAct19982018,as well as the
upcoming changes to the data protection regime under the General Data Protection Regulation((EU)2016/679)whichcame omesintoeffecton25May2018, as on‐shored by the EUWA and amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (the GDPR). .
8.53 ThereareanumberofareasinthePSRs2017whichrelatetouserinformation. Any requirements in the PSRs 2017
relating to user information are distinct from requirementsunderdataprotectionlaw.PSPswillneedtoput appropriateprocedures in place to ensure that they comply with their obligations under the PSRs 2017 and theirobligationsunderdataprotectionlegislationcumulatively.
8.54 There are various requirements in the PSRs 2017 for PSPs to have or obtain the user’s“consent”
or “explicit consent” inrelationtotheprovisionofpaymentservices (e.g. consent to a payment transaction). “Consent” and “explicit consent” must be interpretedinthe contextthey areused, andinlinewith the purpose andscopeof PSD2.Where“consent”or“explicitconsent”isrequired underthePSRs2017,we include guidance in this chapter regarding the nature of such consent.
8.55 “Consent” and “explicit consent” are also concepts under data protection law, where they are
interpreted in a specific way. For more detail regarding the way explicit consent is interpreted under data protection law, PSPs should have regard to the InformationCommissioner’sOffice guidanceon“explicit consent”.Theinterpretation of “consent”and“explicit consent”underdata protectionlawshouldnotbereadacross intotherequirementsunderthePSRs2017. 32 Regulation(EU)2015/751oftheEuropeanParliamentandoftheCouncilof29April2015oninterchangefeesforcard‐based payment transactions http://eur‐lex.europa.eu/legal‐content/EN/TXT/PDF/?uri=CELEX:32015R0751&from=en
8.56 Similarly,“sensitivepaymentdata”isreferredtointhePSRs2017andthisisadifferent concept to
“sensitive personal data” under data protection law.
Anti-money laundering and terrorist financing legislation
8.57 AllPSPsande‐moneyissuersmustcomplywiththeMoneyLaundering,Terrorist Financingand
TransferofFunds(InformationonthePayer)Regulations2017(MLRs) to counter the risk that they are misused for the purposes of money laundering andterroristfinancing.Theobligations includeidentifyingcustomers,monitoring transactions and identifying and reporting suspicious transactions.
8.58 EU Regulation 2015/847, on‐shored by the EUWA and amended by the Money Laundering and
Transfer of Funds(Information) (Amendment) (EU Exit) Regulations 2019, on information accompanying transfers of funds (Funds TransferRegulation)isadirectlyapplicableEUregulationthat specifiestheinformation on the payee or payer to be included in a payment message (or made available on request)andthecircumstancesthataPSPisrequiredtoverifythatinformation.
8.59 For businesses supervised by us under the MLRs, the Joint Money Laundering Steering Group has
providedguidanceoninterpretingtheseobligationsand wehave a financialcrime guide.For businessessupervisedbyHMRCundertheMLRs(e.g.those only undertaking the payment service of money transmission) HMRC has provided guidance on complying with AML and CFT obligations.
8.60 Chapter 19 – Financial Crime containsfurther details about these requirements.
Part I: Information requirements
8.61 TheinformationthatPSPsarerequiredbythePSRs2017toprovidetocustomersis separatedinto
twoscenarios:
customer under the PSRs 2017 and the consumer credit regime, informationwhichhasbeen providedincompliancewiththeconsumercreditregime doesnotneedtobeprovidedagaininorder tocomplywiththePSRs2017.
8.68 The requirements of the PSRs 2017 and the consumer credit regime apply cumulatively,however,
thisisonlythecaseiftheinformationwasprovidedinamanner whichcomplieswiththe requirements ofthePSRs2017.Thismeansthatinformation doesnotneedtobeduplicatedunnecessarily,butPSPs stillneedtobesatisfied thattheyaremeeting the informationrequirementsunderboththe PSRs2017 and consumercreditregime.Forexample,anypre‐contractualinformationprovidedin a SECCI (Standard European Consumer Credit Information)the Pre-Contract Credit Informationfor a credit card would notneed tobeduplicated tomeetrequirementsunderregulation48ofthe PSRs 2017.However,anyinformationnotincluded in theSECCI Pre-Contract Credit Information or other pre-contractual documentationwould still need tobeprovidedtothe customerinaccordance with regulation 48 of the PSRs 2017. Communication of information (regulation 55)
8.69 Theinformationmustbeprovidedormadeavailable:
8.75 ThedefinitionofdurablemediumhasbeenconsideredrecentlybytheCJEUinthe contextof
internetsites.ItwastheCJEU’sfinding that,forane‐bankingportal or otherwebsiteitselftobea durablemedium, itmust:
Details of the payment service(s)to be provided Description of the main characteristics. Specification of the information or unique identifier to be provided by the customer for a payment order to be properly initiated or executed. For example, for a UK bank transfer, the payee bank’ssort code and account number might be specified as the unique identifier. The importance of providing the correct unique identifier (and the potential for loss/delay if an incorrect unique identifier isprovided) should be explained to the customer. What the PSP will take as consent for the initiation of a payment order or the execution of a payment transaction, and the procedure by which such consent may be given. For example, consent could be given in writing, verified by a signature, by means of a payment card and PIN number, over a secure password-protected website, by telephone or by use of a password. Whatever means are to be used, including any allowable alternative methods (e.g. signature in place of chip and PIN), must be detailed in the framework contract. The contract must also set out the procedure by which the customer may withdraw consent. These processes must be in linewith therequirements of regulation 67 (consent and withdrawal of consent) and regulation 100 (authentication) of the PSRs 2017 although, in our view, this does not require PSPs to set out details of their technical solutions relating to authentication in the framework contract. Details of when a payment order will be deemed to have been received in accordance with regulation 81 of the PSRs 2017 (including details of deemed receipt for future dated and recurring transactions). If the PSP has a cut-off time near the end of the business day after which payment orders are deemed to have been received on the next business day, this must be specified. This is very important because of the requirements in the PSRs 2017 on execution time of payments. It is recognised that there may be different cut-off times for different payment channels. The maximum time after receipt of a payment order, by which the funds will have been credited to the payee’s PSP’s account. This must be in line with the requirements of regulation 86 of the PSRs 2017.
Charges and interest
Where applicable, the fact that a spending limit may beagreed for a payment instrument attached to the account (e.g. a maximum daily withdrawal limit on an ATM card), although the spending limit itself (e.g. £250) does not form part of the Schedule 4 information. To avoid doubt, a spending limit differs from a credit limit. In relation to co-badged card-based payment instruments, details of the customer’s rights under Article 8 of the Interchange Fee Regulation (EU 2015/751)IFR. This means PSPs need to provide details of the customer’s right to require two or more different payment brands on a card-based payment instrument (provided that such a service is offered by the PSP). Details of all charges payable by the customer to the PSP and, where applicable, a breakdown of them. The customer should be able to understand what the payment services to be provided under the contract will cost them. We take “where applicable” in this context to mean that, where charges are capable of being broken down into constituent parts to provide more transparency to customers, they should be broken down. A PSP only needs to provide details of the amount that it will charge the customer (i.e. where a payment is initiated through a payment initiation service provider (PISP), details of the amounts charged by that PISP do not need to be provided by the account servicing payment service provider (ASPSP)). Where accounts are in scope of the Payment Account Regulations 2015, PSPs will need to consider their obligations to provide a fee information document in addition to their requirements under the PSRs 2017. If the PSP will make a charge for notifying the customer that a payment order has been refused under regulation 82 of the PSRs 2017, this must be specified here. If the PSP will make a charge for providing or making information available in accordance with regulation 56(2) of the PSRs 2017 (e.g. a charge for additional or more frequent information or information transmitted in a different manner), this must be specified here aswell. Details of the interest or exchange rates to be used (where relevant). This will include changes to interest rates on the underlying payment account unless the use of reference rates has been agreed (as set out below). If a reference exchange or interest rate is to be used, details of where the reference rate can be found and how the actual rate will be calculated must be given (including the relevant date and index or base for determining the reference rate). The aim is to enable the customer to verify that the interest charged or paid is correct or that the exchange rate applied to a transaction is correct. In practice, this means that a PSP would need to include details of when it will actually apply the rate to the account or transaction (e.g. for exchange rates with an externally set reference rate and margin, the PSP will need to provide details of when it actually converts the monies so that the customer can look at the
appropriate date on the website for the externally set rate to verify whether the amount charged is correct).
Reference exchange rates may be set by the PSP itself, but the customer must be told where they can find out what they are. Reference interest rates cannot be set by the PSP and need to be publicly available. Agreement, if relevant, that changes in reference interest or exchange rates will take effect immediately (otherwise they will take effect in line with regulation 50(1) of the PSRs 2017). This information requirement will not be relevant where a payment service is provided in relation to payment transactions that consist of the placing, transferring or withdrawal of funds covered by a credit line provided under a regulated agreement for the purposes of Chapter 14A of Part 2 of the Regulated Activities Order (as regulations 50 and 51 do not apply in such circumstances). Where reference interest rates are being used, agreement, of how, and with what frequency changes in actual interest rates will be notified, in line with regulation 50(5). If no alternative method or frequency is agreed, notification will be required as soon as possible. Transmission of How information relating to the account will be transmitted (e.g. information in writing, to an agreed email address or using a secure website), how often it will be provided or made available and what language will be used. Any technical requirements for the customer’s equipment and software to receive information or notices must be stated. The contract must also include the customer’s right to obtain a copy of the contract at any time during its term. Information about safeguards and corrective measures Where relevant, what steps the customer must take to keep a payment instrument safe. (Note that “payment instrument” has a wide definition and will include payment cards, e-banking and telephone banking arrangements.) Details of how to notify the PSP of the loss, theft or misappropriation of the payment instrument. Details of the secure procedure which the PSP will follow to contact the customer in the event of suspected or actual fraud or security threats. Where relevant, in what circumstances the PSP would be able to stop or block the payment instrument. These are limited to reasons related to:
In what circumstances and to what extent the customer might be liable for unauthorised payment transactions. That the customer must notify the PSP of any unauthorised or incorrectly initiated or executed payment transactions as soon as they become aware of them, how such notification should be made and that the notification should be no later than 13 months after the debit date in order to be entitled to have the error corrected (no such limit will apply unless the customer has received this information). It is open to the PSP to offer better terms in this area. The PSP’s liability for unauthorised or incorrectly initiated or executed payment transactions (e.g. that the PSP will be liable for unauthorised or incorrectly initiated or executed payment transactions, as long as, where applicable, the claim is made within the time limits specified above) under regulation 76 of the PSRs 2017 or, as the case may be, section 83 of the Consumer Credit Act 1974, and regulations 91 and 92of the PSRs 2017.If UK Direct Debits are offered as a payment service on the account, reference should be made to the rights under the Direct Debit Guarantee scheme. The conditions under which a refund is payable in relation to a transaction initiated by or through a payee (e.g. a direct debit or card transaction). Information about the length of the contract, variation of terms and termination The duration of the contract and, where relevant, customer and PSP termination rights, and the terms under which the PSP can unilaterally vary the contract. The information requirements relating to variation and termination will not be relevant where a payment service is provided in relation to payment transactions that consist of the placing, transferring or withdrawal of funds covered by a credit line provided under a regulated agreement (as regulations 50 and 51 of the PSRs 2017 do not apply in such circumstances). Information on applicable Details of the law applicable to the contract, the competent law and disputes courts, the availability of the Financial Ombudsman Service or (for users that would not be eligible to complain to Financial Ombudsman Service) another dispute resolution service if the PSP usessuch a service, any other alternative dispute resolution procedures available to the customer (e.g. under the Online Dispute Resolution Regulation (EU 524/2013), how to access them (see Chapter 11 - Complaints handling) and the possibility to submit complaints to us. Information during period of contract (regulation 49)
8.82 ThecustomerisentitledtorequesttheinformationspecifiedinSchedule4ofthe PSRs 2017 and
the terms of the framework contract at any time during the course ofits contractwith aPSP.If the customer requests this, it must be provided to the customer (sent or given directly to the customer)onpaperoranotherdurablemedium free of charge.
Changes to the framework contract (regulation 50) 8.83 8.84 8.85 8.86 8.87 8.88 8.89 8.90 Whereapaymentserviceisprovidedinrelationtopaymenttransactionsthatconsist oftheplacing, transferringorwithdrawaloffunds coveredbyacreditlineprovided underaregulatedagreement, regulation50ofthePSRs2017doesnotapply.See paragraph 8.64 for further details. For most changes to the framework contract, or to the information that has to be disclosedbefore theframework contractisenteredinto(i.e.theinformationdetailedin paragraph8.80),PSPsmust provideanyproposedchangesatleasttwomonthsbefore they are due to take effect. This principle applies irrespective of whether the changes are favourable or unfavourable to the customer (although see below for changes to interestorexchangerates).PSPswillalsoneedtoensurethattheir variationtermsand theirproposedvariationscomplywiththeCRAorUTCCRsasapplicable. Some account terms and conditions will contain provisions relating to other services which are not “payment services” as defined by the PSRs 2017. In such cases the obligationtonotify changesunderregulation50ofthePSRs2017doesnotextend to non-payment services that are outside the scope of the pre-contract disclosure requirement.Forbanksandbuildingsocieties, however,theBCOBSrequirementson appropriate information and makingchanges may apply to such services. The framework contract may contain a provision that changes are to be made unilaterally unless thecustomer notifies the PSP to thecontrary (although PSPs will also need to take account of unfair contract terms legislation when including such a provision).Itmayalsostatethatrejection ofproposedchangeswillamounttorejection ofthe contract and notice oftermination. Ifthe contract containssuch a provision,the adviceofchangemuststate:
agreedwiththecustomer.
8.91 Theapplicationofinterestrateorexchangeratechangesmustbeimplementedand calculated in a
neutral manner that does not discriminate against customers. In our view,thismeansthat customersshouldnotbeunfairlydisadvantaged;e.g.byusinga calculationmethodthatdelayspassing onchangesinratesthatfavour customersbut more quickly passes on changesin the PSP’sfavour.
8.92 Recital 54 of PSD2 makes clear that the intent of the information provisions in the directive,
andthereforeintheregulations,istoenablepaymentserviceuserstomake well‐informedchoices, andtoenableconsumerstoshoparoundwithintheEU.Inlight ofthis,andthestipulationinregulation 50(1)(a)ofthePSRs2017thatchangesinthe specifiedinformationinSchedule4alsorequirepre‐ notification,wewouldexpectthat where,forexample, anintroductory interestrateonapayment account comestoan end,PSPsshouldprovidenoticeofthechangeintheinterestrate,asspecifiedin the table in paragraph 8.81.
8.93 Relying on a framework contract term stating that the interest rate will change at the end
of the introductory period, is not, in our view, sufficient. The notification requirementdoesnot, however,necessarilyextendtoallotherinterestratechanges agreedintheframeworkcontract.For example,whereanaccounthasatieredinterest ratestructure,underwhichhigherbalancesattract higherrates,changeswithinthat structureduetochangesintheunderlyingbalancewouldnot requirepre‐notification. Similarly,itwouldnotbenecessary togivepre‐notificationofthe endofa bonusrateif it was clearfromthe customerinformation provided atthe outset thatthe bonusrate lasted less than two months.
8.94 Wewouldexpectthat,innormalcircumstances,whereachangeinUKorEUlegislation orregulation
requiresachangetobemadeintheframeworkcontract,businesseswill besufficientlyawareof forthcomingchangesinlegislationorregulationandtherefore able to provide the required two months’ notice set out above. It is recognised, however, that there may be exceptional occasions where this may not be possible. Wherethisisthecase,customersshouldbegivenasmuchnoticeof thechangesas possible. Termination of the framework contract (regulation 51)
8.95 Whereapaymentserviceisprovidedinrelationtopaymenttransactionsthatconsist oftheplacing,
transferringorwithdrawaloffunds coveredbyacreditlineprovided underaregulatedagreement, regulation51ofthePSRs2017doesnotapply.See paragraph 8.64 for further details.
8.96 The framework contract may be terminated by the customer at any time, unless a periodofnotice
(notexceedingonemonth)hasbeenagreed.Ifthecontracthasbeen running for six months or more, no charge may be made for termination. Regular service charges for the running of the payment services may be charged, but any advancepaymentsinrespectofsuchservicechargesmustbe returnedonapro‐rata basis. Any charge that is made for termination must reasonably correspond to the PSP’s actualcosts.
8.97 Ifagreedintheframeworkcontract(andsubjecttotheUTCCRsorCRA),thePSPmay terminate a
framework contract that is not for a defined term by giving at least two months’ notice of termination to the customer.
8.98 Thepartiesretaintheirusuallegalrightstotreattheframeworkasunenforceable,void ordischarged,in
linewithusualcontractlawprinciples.
Transaction information under a framework contract Before execution (regulation 52)
8.99 WherethepaymentorderisgivendirectbythepayercustomertohisPSP,thePSP must, atthe
customer’srequest, inform the customer of:
themaximumexecution time forthe transaction concerned
any charges payable (including a breakdown of those charges where applicable)
After execution (regulations 53 and 54)
8.100 Under regulations 53 and 54 of the PSRs 2017 thePSP must provide its customer with certain
information on transactions.
8.101 This information must be provided on paper or on another durable medium at leastonceamonth,
freeofcharge.Aswehavedescribedatparagraph8.70,asthe informationneedstobeprovided, it must be sent or given tothe customer.Wehave setoutinparagraph8.74somedetailsrelatingtothe meaningofdurablemedium.
8.102 WhereaPSP’scustomeristhepayer,theframeworkcontractmayincludeacondition that the
customer may require the information to instead be provided or made availableatleastoncea month,freeofchargeandinanagreedmannerwhichenables the payer to store and reproduce the information unchanged.
8.103 It is our view that this means that the contract may provide for the customer to choose toreceive
information in an alternative manner, but that the customer cannot exercise this option simply by agreeing to the terms and conditions. A separate agreement to the alternative provision of the information will need to be actively made by the customer.Withoutthis,the PSPwill need toprovide theinformationatleastoncea monthonpaperoranotherdurablemedium.
8.104 WhereaPSP’scustomeristhepayee,aPSPmayprovideinitsframeworkcontractthat the information
will insteadbeprovidedormadeavailable atleastonceamonth,free ofchargeandinanagreed mannerwhichenablesthepayertostoreandreproducethe information unchanged.
8.105 Inbothcasesthewaythattheinformationwillbeprovidedormadeavailablemust be agreed with the
customer and it must be in a form which allows it to be stored and reproducedunchanged.Ourview isthatdocumentsuploadedtoabank’se‐banking portalmaymeetthisrequirementiftheymayeasily bedownloadedorprinted,anditis explainedclearlytocustomerswhytheyshoulddoso.Wewould,for example,expect PSPstomakecustomersawareofhowlongtheinformationwillremainavailable.The portal should not give the impression that it provides independent permanent storage ifthisis not,infact,thecase.
8.106 It is important to note that these provisions do not require monthly statements to be provided for
all accounts. Where there are no transactions (or the only transactions relatetothepaymentof interest)thereisnoobligationunderthePSRs2017toprovide theinformation(although,where relevant,PSPswillneedtosatisfy themselvesthat theyarecomplyingwiththerequirementtoprovide statementsunders78(4)CCA).
8.107 Thisisthe informationrequiredforthepayer:
areferenceenablingthecustomertoidentifythepaymenttransactionand,where appropriate,
informationrelatingtothepayee.Thisinformationshouldassistthe customerinhelpingtocheck thatapaymenthasnotbeenmisdirected
the amount of the transaction in the currency in which the payer’s payment account is
debitedorinthecurrencyusedforthepaymentorder,alongwithdetailsof any exchangerateused by thePSPandtheamountofthepaymenttransactionafterit was applied
the amount and, where applicable, breakdown of any transaction charges and interest payable
in respect ofthe transaction,so thatthe customer knowsthe total chargetobepaid.Wewouldalso expectthebreakdownprovidedbyPSPsunderthis regulation to correspond with the breakdown provided pre‐contractually, so that customersareabletoverify thatthechargesappliedtoa transaction arecorrect. The PSRs 2017 allow the inclusion of a reference exchange rate in framework contracts where the actual exchange rate used in a transaction is based on that publishedrateplusamarginalsosetoutintheframeworkcontract.Whilethere is no requirement in the PSRs 2017 for this margin to be separately listed in the transactioninformationthereisa requirementthatany feesbelisted.Therefore, whereadjustmentstothereferenceexchangerate
areexpressedintheframework contractasafee,theamountofthisfeeshouldbedisclosed separately
8.112 It may also be agreed that rather than full post‐execution information on payment transactions
thePSPmayprovideormakeavailableareferencethatwillenablethe customertoidentifythe individualtransaction,theamountandanychargespayable in respect of the transaction. If there are several payment transactions of the same kindtothesamepayee,thePSPmustprovideor makeavailableinformationonthe total amount of the transactions concerned and any charges for those payment transactions.
8.113 Ifthepaymentinstrumentconcernedisusedanonymouslyor,fortechnicalreasons thePSPisnotable
toprovideormakeavailableeventhislimitedpost‐execution information,itdoesnotneedtobe provided.ThePSPmust,however,enablethe customer to check the amount of funds stored.
8.114 The PSP and the customer may also agree that changes to the framework contract relating to
the low value payment instrument do not have to be communicated in theformandmanner requiredforotherframeworkcontractchanges(i.e.theycan agreethatthereisnoneed to communicatethe changesonpaperoranotherdurable medium).
8.115 We recognise that fluctuations in exchange rates between euro and sterling may cause
difficulties over time indetermining whether aparticular payment instrument is alowvalue paymentinstrument.WeexpectPSPstotakeareasonableandconsistent approach to dealing with such fluctuations to ensure they are compliant with the requirements. B. Singlepaymenttransactions Before the transaction (regulation 43 and Schedule 4)
8.116 Before the contract is concluded (or immediately after the execution of the transaction if the
contract has been concluded by some means of distance communication(e.g.bytelephone)whereit isnotpracticabletodosobeforehand),the PSPmustprovideormakeavailable tothe customerthe informationsetoutbelowin relationtotheservice.Thismaybedone,forexample,byprovidingthe customerwith a copy of the draft contract or payment order:
the information (or unique identifier)the customer needsto provide forthe payment ordertobe
properly initiatedorexecuted(thepaymentrouting information)
themaximumtimethepaymentservicewilltaketobeexecuted(thatis,howlong untilthefunds
arereceived).Thismustbeinlinewiththerequirementsofregulation 86 of the PSRs 2017
details of any charges, including a breakdown where applicable
ifapplicabletheexchangeratetobeused(orthereferenceexchangerateonwhich theactual
exchangeratewillbebased)
8.117 Inaddition,there is a listofinformationinSchedule 4ofthe PSRs2017thatmust bedisclosedpriorto
entering intoa framework contract. Itemsonthe listmust also beprovidedormadeavailableifthey arerelevanttothesinglepaymentcontractinquestion.Whatis“relevant”willdependonthenatureof thepaymentserviceandthe circumstances.Weconsider,however,thatthefollowinginparticularwill alwaysbe relevantinformation:
detailsofthePSPanditsregulators(Schedule4,paragraph(1))
a description of the main characteristics of the payment service to be provided (Schedule4,
paragraph(2)(a)).Wheretheserviceispaymentinitiationwewould expectadescriptionofthe servicetoinclude,asaminimum,detailsof(i)howthe payment initiation service works alongside the customer’s account and (ii) how the PISPaccessesthecustomer’saccountwith theASPSP.Thisinformationshouldbe presented in a way which is easy for customers to understand.
anycontractualclauseongoverninglawandjurisdiction(Schedule4,paragraph (7)(a))
forcustomerswhoareeligibletotakecomplaintstotheFinancialOmbudsman Service,
notificationoftheavailabilityoftheFinancialOmbudsmanService(or, forusersthatwouldnot beeligibletocomplaintotheFinancialOmbudsman Service,anotherdisputeresolution serviceifthePSPusessuchservices),any otheralternativedisputeresolutionprocedures availabletothecustomer(e.g. undertheOnlineDisputeResolutionRegulation(EU524/2013)) andhowtoaccess them(Schedule4,paragraph(7)(b)).Seeparagraphs11.9to11.15on providing informationaboutcomplaintsprocedures.
8.118 WhereaPSPoperatesasawholesaler(providingapaymentservicetosmallermoney transfer
operators but without having a contractual relationship with the payment serviceuser)and providesitsclientPSPswithadvertisingmaterialsandstationery, they must make it clear to the payment service users, before any transaction is enteredinto,thattheclientPSPisprovidingthe service,andistheuser’sPSP.Afailure todosoislikelytoconstituteabreachofthePSRs2017.
8.119 Advertisingandmarketingmaterialorbusinessstationerythatislikelytomisleadthe customer into
believing the PSP with whom they are contracting is the wholesaler ratherthanthe client,may alsopotentially constituteanunfair commercialpractice under the CPRs. Where it appears to us that a PSP’s business model has been changed from an agency to a wholesaler model purely as a matter of form rather than substancetoavoiditsregulatoryobligationsforits agents,thiswould beseenasa matter of concern.
8.120 Beforeapaymentisinitiated,inadditiontotheaboveinformation,PISPsmustprovide ormake
availabletothepayerclearandcomprehensiveinformationcovering:
thenameandheadofficeaddressofthePISP
ifthePISPusesanagentorbranchtoprovideservicesintheUK,theaddressofthat agentorbranch
anyothercontactdetailstobeusedtocommunicatewiththePISPincludingan email address
our contact details
After the initiation of a payment order (regulation 44)
8.121 APISPhastoprovideormakeavailabletothepayertheinformationbelowimmediately afterthe
paymentorderisinitiatedand,whereapplicable,tothepayee.
8.122 Theinformationisasfollows:
confirmationthatthepaymentorderhasbeensuccessfullyinitiatedwiththepayer’s ASPSP
a referenceenablingthepayerandthepayeetoidentifythepaymenttransaction and, where
appropriate, the payee to identify the payer, and any information transferred with the payment order
the amount of the payment transaction
theamountofanychargespayabletothePISPinrelationtothepayment transaction
and,whereapplicable,abreakdownofthecharges
8.123 The PISP must also provide or make available the reference for the payment transactiontothe
customer’sASPSP.Thisislikelytobethesamereferenceprovided bythePISPtothepayerandpayee underregulation44(1)(b)ofthePSRs2017.The ASPSPisnotobligatedtoprovideormakeavailablethis referencetothecustomer. After the receipt of the payment order (regulation 45)
8.124 The payer’s PSP must immediately after receipt of the payment order, provide or makeavailable
tohis customerthe following informationinrelationtothe service it is providing (regulation 81 of the PSRs 2017 sets out when payment orders for future datedpaymentsaredeemedtobe
received):
disclosure risks committing a criminal offence under regulation 141 of the PSRs 2017. Information on additional charges or reductions (regulation 58)
8.129 Ifapayee(typicallyashop,websiteoperatororothermerchant)leviesanadditional charge or offers a
reduction in cost for usingaparticular means of payment (e.g. anadditional chargeforusinga creditcard)thisinformationmustbeadvisedtothe customer before the start ofthe payment transaction.
8.130 Similarly,ifaPSPoranyotherparty involvedinatransactionchargesfortheuseof particular payment
instrument, itmustinformthe customer ofsuch chargesbefore the payment transaction is initiated. A third party that fails to do so risks committing acriminaloffenceunderregulation141 ofthePSRs2017andmayalsobeinbreachof the Consumer Protection from Unfair Trading Regulations.
8.131 The customer is not obligated to pay the chargesif they have not been informed of the full amount of
the chargesinaccordancewith the requirementsofregulation58ofthe PSRs 2017.
8.132 Wherepayeesarelevyingadditionalcharges,theyneedtobeawareoftheirobligations under other
legislation (e.g. the ConsumerRights (Payment Surcharges) Regulations 2012). Burden of proof (regulation 59)
8.133 The burden of proof is on the PSP to show that it has met the information requirements in Part 6
of the PSRs 2017. PSPs will need to ensure that they keep appropriate records to demonstrate the provision of information to customers in the appropriate way. This provision also appliesto RAISPs. Information requirements for RAISPs (regulation 60)
8.134 RAISPs do not have to provide as much information to their customers as other PSPs.
8.135 RAISPsmustalwaysprovidedetailsofallchargespayablebythecustomertothe RAISP and, where
applicable, a breakdown ofthose charges.
8.136 RAISPs must also provide any information specified in Schedule 4 of the PSRs 2017 whichis
relevanttotheserviceprovided.Whatis‘relevant’willdependonthenature oftheserviceandthe circumstances.Weconsider,however,thatthefollowingin particular will always be relevant information:
8.137 The burden ofproofisonthe RAISP toshowthatithasmetthe relevantinformation requirements.
8.138 RAISPsalsoneedtobeawareofanyobligationsunderdataprotectionlawwhichapply tothem,
including requirementstobetransparentabouthowdatawillbeusedandto give customers appropriate privacy notices when collecting personal data.
Part II: Rights and obligationsin relation to the provision of payment services
8.139 TheCOBprovisionsonrightsandobligationscontainruleson:
toanycreditcardsandoverdraftswhichareregulatedbytheCCA below.Thistabledoesnotsetout otherlegalrequirementswhichmayapply(e.g.under CONCortheConsumerRightsAct2015). Current account with an overdraft regulated by the CCA Credit card regulated by the CCA Regulation of the PSRs 2017 Do the PSRs 2017 apply? (1) Regulation 71(2) to (5) - limits on the use of payment instruments Regulation 71(2)-(5) of the PSRs 2017 applies to overdrafts. This is because Regulation 71(2) - (5) is only disapplied where s98A(4) of the CCA applies. Section 98A(4) of the CCA does not apply to overdrafts. Regulation 71(2)-(5)does not apply to credit cards. Section 98A(4) of the CCA applies. (2) Regulations 76(1)-(4) and 77(1)-(5) - rectification of and liability for unauthorised transactions - and regulation 74 (as it applies to regulation 76) For current accounts with overdrafts, the PSRs 2017 regime will apply in relation to transactions or parts of transactions which occur when the customer is in a credit position and the CCA in relation to transactions or parts of transactions which occur when the customer is in a debit position. Where transactions occur when the customer is in a debit position, regulations 76(1)-(4) and 77(1)-(5) will not apply and the notification requirements under regulation 74 will also not apply in respect of unauthorised transactions. Where an unauthorised transaction takes an account from a credit position to an overdrawn position, both regimes will apply (i.e. the PSRs 2017 will apply to the amount that was taken from the credit position and the consumer credit regime will apply to the amount that was taken from the overdraft). For credit cards, regulations 76(1)- (4) and 77(1)- (5) will not apply and the equivalent regime in the CCA will apply. The notification requirements in regulation 74 will also not apply in respect of unauthorised transactions.
Current account with an overdraft regulated by the CCA Credit card regulated by the CCA Regulation of the PSRs 2017 Do the PSRs 2017 apply? (3) regulations 76(5) and 77(6) Yes,they apply as if (i) Yes,they apply as if (i)
rectification of and liability in regulation 76(5), the in regulation 76(5), the
for unauthorised transactions reference to an unauthorised payment transaction were to a payment transaction initiated by use of a credit facility in the circumstances described in section 83(1) of the Consumer Credit Act 1974 (liability for misuse of credit facilities) and (ii) the references to complying with regulation 76(1) were to compensating the payer for loss arising as described in section 83(1) of the Consumer Credit Act 1974 reference to an unauthorised payment transaction were to a payment transaction initiated by use of a credit facility in the circumstances described in section 83(1) of the Consumer Credit Act 1974 (liability for misuse of credit facilities) and (ii) the references to complying with regulation 76(1) were to compensating the payer for loss arising as described in section 83(1) of the Consumer Credit Act 1974 Requirements for RAISPs (regulation 63(4))
8.144 The following regulations apply toRAISPs:
regulation 70 (access to payment accounts for account information services)
regulation 71(7)-71(10) (denial of access to an AISP)
regulation72(3)(paymentserviceuser’sobligationtokeeppersonalisedsecurity credentials
safe)
regulation 98 (risk management)
regulation 99 (incident reporting)
regulation 100 (authentication)
RAISPs do not need to comply with any other provisions in Part 7 of the PSRs 2017. Charges (regulation 66)
8.145 PSPsmayonly chargetheir customersfor carrying outtheirobligations assetout inPart7ofthePSRs
2017(thoseconcerningrightsandobligations)wherethePSRs 2017specificallyallowit.Thosecharges mustbeagreedwiththecustomerandmust reasonablycorrespondtoaprovider’sactual costs. The corporateoptoutappliesto this provision (see under “General” at the start of Part II).
8.146 Wherethepayer’sPSPandthepayee’sPSP(ortheonlyPSP)arelocatedwithinthe EEAUK,
irrespectiveofthecurrencyofthetransaction or carrying out a Qualifying Area Transaction, irrespectiveofthecurrencyofthetransaction,theruleonchargingisthat:
payeesmustpayanychargesleviedbytheirPSP
payersmustpayanychargesleviedbytheirPSP Thisis also
known as a SHARE arrangement.
8.147 Theeffectofthisisthat,fortwoleg transactionsinanycurrencythose types of transactions,
arrangementswhere thepayerpaysboththeirownandthepayee’sPSPs’charges(knowninSWIFT terms as‘OUR’),orconverselywherethepayeepaysboththeirownandthepayer’sPSPs’ charges (knowninSWIFTtermsas‘BEN’)arenotpermitted.
8.148 Anychargesleviedwillbesubjecttotheagreementonchargesbetweenthecustomer and the PSP, in
the framework contract or single payment service contract for the payment typeconcerned. Charges or reductions for the use of a particular payment instrument (regulation 66(3))
8.149 Thepayee’sPSPmaynotpreventthepayeefromrequestingpaymentofachargeby thepayerfor,or
offering a reduction tothepayerfor,orotherwise steering thepayer towards,theuseofaparticular paymentinstrument(e.g. credit card,debit cardor pre-paid card).
8.150 Wherepayeesarelevyingadditionalcharges,theyneedtobeawareoftheirobligations under other
legislation (e.g. the ConsumerRights (Payment Surcharges) Regulations 2012). Authorisation of payment transactions Consent (regulation 67) and revocation of consent (regulation 83)
8.151 The formand procedure for consentfor execution of a transaction to be given by the payermust be
set outin the information provided before entering into a framework contract. This should cover both individual transactions and a series of payment transactions(egastandingorder,directdebit mandateorrecurringtransactionona paymentcard).ThePSRs2017allowthat,whereagreedwiththe customer,consent maybegivenafterthepaymenttransferhasbeenexecuted.Otherwiseitmust be giveninadvance.ConsentmaybegivenviathepayeeoraPISP.Theprocedure for giving consentto executeapaymenttransactioncouldbeinwriting, byusing apaymentcardandPINnumber,througha website,bytelephoneorbyuseofa password.Forconsenttobevaliditmustbeclear,specificand informed.Regulation 100ofthePSRs2017setsrequirementsregardingtheapplicationofstrong customer authentication in certain circumstances. Chapter 20 – Authentication provides further information.
8.152 Regulation 83 sets out the rules on the point from which consent for a particular transaction(as
opposedtoaseriesoftransactions)maynotberevokedbythe customer. This will depend on the particular circumstances of the payment transaction inquestion (e.g.whetherit isaninstruction forafuturedatedpaymentoranimmediate payment). For future dated transactions, up to the agreed point, the customer has a righttowithdrawconsent toa transaction,
8.153 Ifconsenthasbeengiventoaseriesofpaymenttransactions(e.g.astandingorder, direct debit
mandate or recurring transaction on a payment card) the customer has the right, at any time,to withdrawconsentforfuturetransactionsinthe series.While thePSRs2017donotspecifyhowsuch withdrawalofconsentshouldbegiven,inour viewforpaymentordersoriginatedbyorthroughthe payee(directdebits orrecurring transactions),withdrawalofconsentnotifiedtoeitherthepayer’s PSPortothepayee isvalid.The time limits for revocationset out in regulation 83(3) to (5)of the PSRs apply to any payment transaction due within that time period.
8.154 Whereconsentwasgivenviathepayee,itisnotacceptableforthepayer’sPSPtoinsist thatconsentmay
onlybewithdrawninthesamemanner.Inourview,anynotification to the payer’s PSP that the customer wishes to stop payments to a particular payee should be taken as withdrawal of
consent to future payments. The PSP may seek clarification ofthe particular paymentstobe stopped(ifthere ismore than one tothe same payee) and request written confirmation if appropriate, but consent must be takentohave beenwithdrawn fromthe time offirst notification by the customer.
8.155 Inaddition,inourview,theclosureofanaccountwillamounttowithdrawalofconsent for any future
direct debits or recurring transactions on that account. While it is reasonableforaPSPtosayinits termsandconditionsthatthecustomerwillbeliable for any “in flight” transactions (e.g. those that have been pre‐authorised) that are presentedafterthe closurenotification hasbeenreceivedfrom the customer,wecan seenojustification fortermsthatpurporttoallowPSPstoeithereffectively keepopen anaccountorre‐openpreviously closedaccountstopay subsequenttransactionsin the series.
8.156 UnlessthePSPcanshowthatconsenthasbeengiven,ithasnoauthority tomake the payment orto
debitthe customer’s account and any such transactionmust be regardedasunauthorised.Wherea paymentordercanberevokedunderregulations 83(3)or83(4)ofthePSRs2017,atransactionmust alsoberegardedasunauthorised afterconsenthasbeenwithdrawn.
8.157 Thecorporateoptoutappliestoregulations67(3)and(4)ofthePSRs2017,which relate to the
withdrawal ofconsent (seeunder ‘General’ at the start of Part II).
Confirmation of availability of funds for card-based payment transactions (regulation 68)
8.158 Regulation68ofthePSRs2017providesamechanismwherebyPSPsthatissuecard‐ basedpayment
instrumentsthat can beusedtoinitiate a paymenttransaction froma paymentaccountheldwith anotherPSP(knownastheASPSP)canobtainconfirmation oftheavailabilityoffunds.Theseissuersare knownascard‐basedpaymentinstrument issuers(CBPIIs).
8.159 Under regulation 68 of the PSRs 2017, CBPIIs can request confirmation from an ASPSPwhethera
customerhasfundsavailableinitspaymentaccounttocomplete atransactionatagivenpointin time.Regulation68ofthePSRs2017,however,only governs theconfirmation process (i.e. where the ASPSP confirmswhether funds are available).Itdoesnotgovernsubsequentsettlementof thetransactionbetweenthe payee,CBPIIandthepayer,whichmayvarybetweendifferentbusiness models.CBPIIs are therefore free to agree with their customers whichever model of settlement they choose.CBPIIswillrequirepermissionforissuingpaymentinstruments,and further permissionsandauthorisationsmayberequireddependingonhowexactlytheservice is structured.
8.160 CBPIIsareonlypermittedtorequestconfirmationofavailabilityoffundsiftheymeet three
conditions:
cause any material delay in the payment transaction,andthereforethisislikelytomeanreal time.
8.162 On request by the customer,the ASPSPmustinformthe customer ofthe identity of thePSPwhich
madetherequestforconfirmationandtheanswergiven.
8.163 Whenprovidingayesornoanswer,theASPSPshoulddosobasedonwhetherfunds fortheexecution
ofthetransactionareavailable.Inourview,availablefundswould includefundscoveredbyan agreedoverdraftfacility.
8.164 TheASPSPonlyhastoprovideconfirmationwhere:
legislation – see guidance at paragraph 19.20 in Chapter 19 - Financial crime), this requirement does not apply.
8.171 The PSP is required to unblock the payment instrument, or replace it with a new payment
instrument,assoonaspracticableafterthereasonsforblockingitceaseto apply.
8.172 Where a payment instrument is blocked pursuant to regulation 71(2) of the PSRs 2017,andaPISP
orAISPcannotaccessthecustomer’spaymentaccountasaresult, this does not amount to a denial of access underregulations 71(7)– (10) of the PSRs 2017. See Chapter 17 – Payment initiation and account information services and confirmation of availability of funds for further details regarding denial of access.
8.173 The parties can also agree to a spending limit on a specific payment instrument. This
does not affect the right of a PSP to apply other limits on payments in pursuit ofcompliance withlegislationrelatingtoanti‐moneylaundering, fraud,etc.ifsetout in the framework contract that spending limits may apply. This also does not affect thePSPfromapplyinglimitsontypes oftransaction(suchaslimitsimposedbythe relevantpaymentscheme),ifsetoutinthe framework contractthatspending limits may apply. Obligations of the customer in relation to payment instruments and personalised security details (regulation 72)
8.174 ThecustomerisobligatedbythePSRs2017toabidebythetermsandconditionsfor the use of the
payment instrument. A customer does not, however, need to abide byanytermunlessitis objective,non‐discriminatoryandproportionate.Wewould considertermsandconditionswhich,for example,requirecustomerstoopenand destroyaPINnotificationimmediatelyorwhichprohibit customersfromwritingdown orrecording their PINinany formnottobepermitted.
8.175 Termsrequiringpersonalisedsecuritydetailstobekeptsafeshouldnotbedraftedina waythat
preventsusersfromusingAISorPIS,whetherexpresslyorbyseekingtoshift liabilitytothecustomer wheresuchservicesareused.APSPcannotuseanyfailureby the customer to abide by such terms as a justification for the customer’s liability for unauthorisedtransactionsunder regulation 77ofthe PSRs 2017. Such terms may also beunfairundertheCRAorUTTCRs.
8.176 ThecustomerisobligatedtonotifythePSP,intheagreedmannerandwithoutundue delay,should
theydiscoverthatthepaymentinstrumenthasbeenlostorstolen, or that someone else has used (or attempted to use) the payment instrument without the customer’s authority.
8.177 The requirement to notify will not apply for low value payment instruments if the nature of the
instrument means that it is not possible for the PSP to stop it from beingused.(SeePartI,section Aofthischapterforadefinitionoflowvaluepayment instruments.)
8.178 ThePSRs2017alsoobligatethecustomertotakeallreasonablestepstokeepthe personalised
security credentials relating to a payment instrument or an account informationservicesafe. ThiswouldincludethePINorpasswordfortheinstrument or other piece of information known only to the issuing PSP and the customer. It does notinclude,forexample,acredit cardnumber itself,asthiswouldbeknowntoany businesswherethecardwasused.
8.179 What constitutes reasonable steps will depend on the circumstances, but PSPs mustsay what
stepsthey expect customersto take in their pre‐contract disclosure information. In line with our view on “proportionate” contract terms (see paragraph 8.174),we considerthatsaying thatthe customermust notwritedown orrecord a passwordorPINinanyformgoesbeyond“reasonable steps”. Obligations of the PSP in relation to payment instruments (regulation 73)
8.180 ThePSPissuingapaymentinstrumentmustdothefollowing:
makesurethatanypersonalisedsecuritycredentialscannotbeaccessedbyanyone other than the
customer involved
notsendanyunsolicitedpaymentinstrumentstothecustomer,exceptasa replacement
forthe existingpaymentinstrument
haveappropriatemeansavailableatalltimes(subjecttotheforcemajeureprovisions of regulation
96 of the PSRs 2017) to allow the customer to notify them if the paymentinstrumentislost, stolen,misappropriatedorhasbeenusedwithout the customer’s authority, or to request that an instrument be unblocked. This requirementwillnot apply forlowvaluepaymentinstrumentsifthe natureofthe instrumentmeansthatit isnot possible forthe PSP tostop itfrombeingused (see Part I,sectionAofthischapterforadefinitionofalowvaluepaymentinstrument).
be able to provide the customer on request with some way of proving that the customer has
made the notification under regulation 72(1)(b) of the PSRs 2017 for 18 months after it has been made (e.g. this could be by means of providing a referenceandbyconfirmingreceiptin writing).Thisrequirementwillnotapplyfor low value payment instruments if the nature of the instrument means that it is not possibleforthePSPtostopitfrombeingused (seePartI, sectionAofthis chapter foradefinitionofalowvaluepaymentinstrument).
provide thecustomerwithaway tonotify thePSPthat apaymentinstrumentislost, stolen,
misappropriatedorhasbeenusedwithouttheconsumer’sauthoritywhichis free of charge and it must ensure that any costs charged for a replacement payment instrumentaredirectly attributabletoreplacement.Thisrequirementwillnotapply for low value payment instruments if the nature of the instrument means that it isnotpossibleforthePSPtostopitfrombeingused (seePartI,sectionAofthis chapterforadefinitionofalowvaluepaymentinstrument).
prevent alluseofthepaymentinstrument afterhavingbeennotifiedthatithasbeen lost,stolenor
misappropriatedorusedwithoutthecustomer’sauthority.Whereit isnotpracticallypossibleinthe circumstancestopreventalluseoftheinstrument, transactions generated through the use ofthe paymentinstrumentshould not be debitedtotheunderlyingaccount.
8.181 PSPsmustmaintainadequatesecuritymeasurestoprotecttheconfidentialityand integrity of
customers’ personalised security credentials in linewithregulation 100(3) of the PSRs 2017 and SCA-RTS Article 22. SCA-RTS Articles 23 to 27 set specific requirements concerning the creation and transmission of credentials and their secureassociationwiththepaymentserviceuser, aswellasthedeliveryandrenewal of credentials, authentication devices and software and subsequent destruction, deactivationorrevocation.IfthePSPsendsapaymentinstrument,PIN, password, etc.tothe customer, any risk involvedinthe sendingofthe itemwillremainwiththe PSP. So,ifacardandpasswordwereinterceptedbeforetheywerereceivedbythe customer,anylosses arisingfromtheirmisusewouldliewiththePSPratherthanthe customer. Notification and rectification of unauthorised or incorrectly executed payment transaction (regulation 74)
8.182 Thenotificationrequirements relatingtounauthorisedtransactionsinregulation74of the PSRs
2017 do not apply in circumstances where a payment service is provided in relationtopayment transactionsthat consistoftheplacing,transferringorwithdrawal offundscoveredbyacreditline providedunderaregulatedagreement.Seeparagraph 8.141 for further details.
8.183 Ifacustomerbecomesawareofanunauthorisedorincorrectlyexecutedpayment transaction,they
mustnotifythePSPconcernedwithoutunduedelayandnolater than 13months afterthe date ofthe transaction, or else they will not be entitled to redress under the PSRs 2017.
8.184 Inlightofthis, andinlinewiththeobligationtoprovideinformationunderparagraph 5(e)ofSchedule
4ofthePSRs2017,weexpectASPSPstomakeitcleartocustomers thatnotificationshouldbemadeto theASPSPinallcircumstances(i.e.irrespectiveof whetheraPISPisinvolvedinthetransaction).Wherea customernotifiesaPISPrather thanitsASPSP,thePISPmayprovidearefunddirectly tothecustomerif itwishesto doso.Ifitdoesnotwishtoprovide a refund,wewould expectthe PISPtoreferthe customer to the ASPSP.
8.185 Itshould benotedthatPSPshavethe ability tograntmorefavourable termstotheir customers,and
thereforetooffer alongerperiod(e.g.theUKDirectDebitGuarantee Schemewouldnotbe
preventedfromcontinuing toofferalongerperiodforrefunds).
8.186 ThetimelimitabovewillnotapplywherethePSPhasfailedtocomplywithanyofthe information
requirements imposed by the PSRs 2017 in respect of the transaction concerned.
8.187 The corporate opt out applies to the time period for notification in this regulation (see under
‘General’ at the start of Part II of this chapter).
Evidence on authentication and execution of payment transactions (regulation 75)
8.188 Wherethecustomerdeniesthattheyhaveauthorisedapaymenttransaction(e.g. claims that a
card transaction was not made by them), or claims that a payment transactionhasnotbeen correctlyexecuted(e.g.iftheamountiswrongorhasbeen senttothewrongplace),theobligation lieswiththePSPtoprovethatthepayment transaction was:
launderinglegislation.
8.194 Regulation75 of the PSRs2017 applies incircumstances where a payment service is providedin
relation to payment transactions that consist of the placing, transferring or withdrawal of funds covered by a credit line provided under a regulated agreement and the PSP should also note the provisions of section 171 of the CCA (onus of proof in variousproceedings).Ourunderstanding is that this means that unless or until the PSP can provide the evidence to show liability on the part ofthe customer,the customer isnotliable,meaningthatnointerestshouldbechargedonthedisputed amount,and the PSP is not entitled to demand repayment of that sum.
8.195 Under the Consumer Credit Act 1974, customers cannot be held liable for an unauthorised
transactiononthebasisofgrossnegligence.Assuch,referencesto grossnegligenceinregulation75 ofthePSRs2017wouldnotbeapplicablewherea payment service is provided in relation to payment transactions that consist of the placing,transferringorwithdrawaloffundscoveredby acreditlineprovidedundera regulated agreement.
8.196 Forlowvalue paymentinstruments, ifthenatureofthe instrumentissuchthatit isnot possiblefor
thePSPtoprovethatitwasauthorised(e.g.ifitwasusedanonymously) thisprovisionwillnotapply. (SeePartI,SectionAofthischapterforadefinitionoflow value payment instrument.)
8.197 The corporate opt out applies to this provision (see under ‘General’ at the start of Part IIofthis
chapter).
PSP’s liability for unauthorised transactions (regulation 76)
8.198 Ifapaymentserviceisprovidedinrelationtofunds coveredbyacreditlineprovided underan
agreementregulatedbytheCCAthenregulations76(1)–(4)ofthePSRs2017 will not apply and consumer credit provisions will apply instead. See paragraph 8.141 for furtherdetails.
8.199 For CCA regulated credit cards the PSP must apply the consumer credit regime to all
unauthorisedtransactionsinsteadofregulations74,76(1)‐(4)and77(1)‐(5)ofthePSRs 2017(although regulation75applies).Forcurrentaccountswithoverdrafts,thePSRs 2017regime will apply in relation to transactions or parts of transactions which occur when the customer is in a credit position and the consumer credit regime in relation totransactionsorparts oftransactionswhich occurwhenthe customeris inadebit position.
8.200 Where an unauthorised transaction takes an account from a credit position to an overdrawn
position,bothregimeswillapply(i.e.thePSRs2017willapplytotheamount that was taken from the credit position and the consumer credit regime will apply to the amount that was taken from the overdraft). In practice this means that PSPs may need to have a different operational process for unauthorised transactions depending on whether the customer is in a credit or debit position, or adopt a process that complieswiththeminimumstandardsofbothregimes.
8.201 If a payment transaction was not properly authorised by the customer, the PSP concernedmust
refundtheamountofthetransactiontothepayerand,ifapplicable, restore the relevant payment account to the state it would have been in had the transaction not been made (i.e. refund any charges and any interest which the customerhaspaidand/or creditinterestwhichthe customer haslost).
8.202 The PSP must also ensure that the credit value date is no later than the date on which the
unauthorised amount was debited. We take this to mean that, when the PSP is calculatingthe amountofinterestthatshouldberefunded,thecalculationshouldrun fromno laterthan the date the unauthorised amount was debited fromthe customer’s account.
8.203 A transaction should be treated as unauthorised unless the PSP has the consent of thecustomeras
setoutinregulation67ofthePSRs2017.Whereanamounthasbeen deducted froma customer’s account by a PSP in error,the customer did not consent tothissothisshould be treatedas an unauthorised transaction forthe purposesofthe PSRs 2017.
8.204 Similarly, where consent has been withdrawn by the customer for either a specific payment
transaction or a series of payment transactions, including the payment transaction in question, it should be treated as unauthorised. Unauthorised transactions,however,canbedistinguishedfrom misdirectedtransactions,wherethe customerhas authorised the transaction butthemoneyhas beenpaidtothewrong recipient. This couldbe duetothe customerproviding the incorrectunique identifier (see regulation90)oritcouldbethePSP’serror(inwhichcaseitshouldbetreatedas an incorrectlyexecutedtransactionunderregulations91and92).
8.205 Theobligationtoprovidearefundissubjecttoanyresponsibilitywhichthecustomer may have for
the unauthorised transaction under regulation 77.
8.206 Arefundmustbeprovidedtothecustomerassoonaspracticableandinanyeventby theendofthe
businessdayfollowingthedayonwhichthePSPbecomesawareofthe unauthorisedtransaction(i.e. ifacustomernotifiesthePSPonMondaymorning,the refundmustbemadeassoonaspracticable and,inanyevent,bytheendofTuesday). TheonlyexceptiontothisiswherethePSPhasreasonable groundsforsuspecting fraudulent behaviour by the customer and it has notified a person mentioned in s333A(2)oftheProceedsofCrimeAct2002(e.g.aconstable,anofficerofHMRC,a nominatedofficeroranauthorisedNationalCrimeAgencyofficer)inwriting.
8.207 The effect of this is that, in cases where PSPs do not have reasonable grounds to suspect
fraudulent behaviour by the customer (e.g. where the customer may have beengrosslynegligent), PSPswillneverthelessneedtoprovidearefundbytheendof thenextbusinessdayatthelatestand continueany investigationafterthe refundhas been provided.
8.208 It is not appropriate for the PSP to purport to make a refund for an unauthorised
transaction conditional onthe customer signing a declaration.
8.209 If the results of an investigation enable it to prove either that the customer did authorise
thetransactionorwasotherwiseliable,thePSPcanreversetherefund. Wherethisoccurs,we wouldexpecttheprovidertogivereasonablenoticeof thereversaltothecustomer.Whatis “reasonable”willdependontheparticular circumstances of the case.
8.210 WherethePSPhasreasonablegroundstosuspectfraudandhasmadeanotification toaperson
mentionedins333A(2)oftheProceedsofCrimeAct 2002,thereisstill a balance tobe struck between a customer’s righttobeprovidedwith a refundfor an unauthorised payment transaction quickly, and the need to determine whether the paymenttransactionwasfraudulent.WeexpectPSPsto takeareasonableapproach tothis.Thisdoesnot,however,requireaPSPtoprovidearefundwhereitis prohibited fromdoing soby laworby anybody thatithasnotified undersection 333A(2)ofthe Proceeds of Crime Act 2002.
8.211 Whereaninvestigationisjustified,itneedstobecarriedoutasquicklyaspossiblein light of the
circumstances. In no circumstances should the investigation be used to discouragethecustomer frompursuingtheclaim.Clearly,ifsuchaninvestigationis carried out and the customeris notfound to be atfault, an immediate refundmust be made,andbackvaluedsothatthecustomerdoesnot sufferanyloss.
8.212 Forlowvalue paymentinstruments, ifthenatureofthe instrumentissuchthatit isnot possiblefor
thePSPtoprovethatitwasauthorised(e.g.ifitwasusedanonymously) thisprovisionwillnotapply (seePartI,sectionAofthis chapterforadefinitionoflow value payment instrument).
8.213 Where an unauthorised, non‐executed or defectively executed transaction is initiatedthrougha
PISP,itistheASPSP’sresponsibilitytoprovidearefundinlinewith regulation 76 and regulation 93 of the PSRs 2017 and this guidance. If the PISP is liableunderregulation76orregulation93of thePSRs2017,theASPSPcanthenseek compensation from the PISP which must, on request, provide that compensation immediately. The amount of compensation should cover the full amount which the ASPSPwasrequiredtorefundtothecustomer.Wenote thatPSPsmayputinplace voluntaryarrangementsforthesettlementofsuchliabilitiesbetweenthemselves.
8.214 WhereanASPSPhasbeenrequiredtocompensatethecustomerforanunauthorised transaction
underregulation76ofthePSRs2017,butthatliabilityisattributableto anAISP,theASPSPmayexercise itsrightofrecoursetoseekcompensationfromthe AISP (see paragraph 8.331).
8.215 Whereacustomerexperiencesdetriment,otherthan inrelationtoanunauthorisedor misdirected
payment,asaresultofaserviceprovidedbyanAISP,thecustomershould, in the first instance, complain to the AISP and escalate any issues to the Financial OmbudsmanService(SeeChapter11– ComplaintHandling).
8.216 PSPs are at liberty to offer increased protections to customers in relation to unauthorised
transactions and other areas, e.g. through participation in industry schemessuchastheDirect DebitGuaranteeScheme.Anysuchprotectionsapply inadditiontotheminimumprotectionsthat PSPsareobligatedtoprovideunderthe PSRs 2017. Customer’s liability for unauthorised payment transactions (regulation 77)
8.217 Ifapaymentserviceisprovidedinrelationtofunds coveredbyacreditlineprovided under a regulated
agreement then regulations 77(1)– (5) of the PSRs 2017 will not apply and consumer credit provisions will apply instead. See paragraph 8.141 for further details.
8.218 A PSPmaymakeits customerliableforlossesuptoamaximumof£35resulting from unauthorised
transactions from the use of a lost or stolen payment instrument, or fromthe misappropriation of the paymentinstrument. Itshould be noted thatthe £35 liabilitylimitisapplicabletoeachinstanceof loss,theftormisappropriation,andnotto eachtransaction.Thisdoes,however,notapplyif:
orto stop the paymentinstrumentfrom beingused.SeePartI,SectionAofthischapterfora definitionoflowvaluepayment instrument)
If the amount of the payment transactionexceedstheamountthepayercouldreasonablyhave expectedinallthe circumstances,the payeris entitled toa refund ofthe full amount ofthe transaction from their PSP. Those circumstances include the customer’s previous spending pattern and the terms of the framework contract, but do not include fluctuations in thereference exchangerate.Whenprovidingarefund,thePSPmustalsoensurethat the credit value date is no later than the date on which the payment transaction was debited.Inpractice,wetakethisto meanthat,whenthePSPisprovidingarefundto the customerofinterestlost orpaid,the calculation should run fromno laterthan the datethe transactionwasdebited fromthe customer’saccount.
8.231 Itmaybeagreedinthe framework contractthat, ifthepayerhas giventheir consent directlyto
theirPSPand,ifapplicable,detailsoftheamountofthetransactionhave beenprovidedormade availabletothematleastfourweeksbeforethedebitdate, they will not have the right to a refund.
8.232 The corporate opt out applies to this provision (see under “General” at the start of Part II).
8.233 For direct debit transactions which fall within the scope of the SEPA Regulation (EU) 260/2012(i.e.
SEPAdirectdebits),thepayerisentitledtoanunconditionalrefundfrom itsPSPofthefullamountof anydirectdebittransaction.
8.234 PSPscanagreemorefavourabletermswiththeircustomers(e.g.undertheUKDirect Debit Scheme).
Requests for refunds for payment transactions initiated by or through a payee (regulation 80)
8.235 The PSRs 2017 provide that to obtain the refund set out in “Refunds for payment transactions
initiated by or through the payee” above, the payer must make their requesttothePSPwithin eightweeksofthedebitdate.PSPsmay,however,offer bettertermstotheir customersthanthose specified inthePSRs2017.Forexample, thismeansthattheUKDirectDebit Scheme is atliberty to continue to offer a longer periodtorequestrefunds.
8.236 Onreceiptofaclaimforarefund,thePSPmay requestadditional informationfromthe payer,ifit is
reasonablyrequiredtoprovewhethertheconditionshavebeenmet.The PSP must either make the refund, or justify refusal within the later of ten days of the claim,oroftheadditionalinformation beingprovided.Refusalmustbeaccompaniedby information on how to take the matter further if the customer is not satisfied with the justificationprovided.IfthePSPhasrequestedfurther information,itmustnotrefuse the refund until it has received the information from the customer.
8.237 The corporate opt out applies to this provision (see under “General” at the start of Part IIofthis
chapter).
Execution of payment transactions
Receipt of payment orders (regulation 81)
8.238 The point in time of receipt of a payment order, from which the execution time requirementsof
thePSRs2017mustbecalculated,willgenerallybethetimeatwhich thepaymentorderisreceived (whetherdirectlyorindirectly)bythepayer’sPSP.The exceptionsareasfollows:
Thattimeisnotonabusinessday forthatPSPinrespectoftheparticularpayment service
concerned, in which case the payment order is deemed to have been receivedonthefollowing businessday
ThePSPhassetatimetowardstheendofthebusinessdayafterwhichanypayment orderreceived
willbedeemedtohavebeenreceivedonthefollowingbusinessday (notice ofthis must be given to the customer). Itisrecognised thatthis cut‐offtime maybedifferent,dependinguponthe requirementsofdifferentpaymentproducts, butPSPsshouldtakeareasonableapproachinsetting suchcut‐offtimes
ThecustomerhasagreedwiththePSPthatthepaymentorderwillbeexecuted:
– onaspecificday inthefuture
– at the end of a certain period
– onthedaywhenthepayerprovidestherequiredfundstothePSP
8.239 Whereoneoftheaboveapplies(i.e.forfuturedatedpayments),theagreeddate(or,ifit isnota
businessdayforthePSP,thenextbusinessday)willbedeemedtobethetime ofreceipt. Thismeans thatthe clock startsrunning forthe purposes ofthe execution timeprovisionsontheagreeddate(or, ifitisnotabusinessdayforthePSP,thenext businessday).Toavoiddoubt, itisnotpossible to“contract out”ofthisrequirement, witheitherbusinesscustomersorconsumers.
8.240 Theaimoftheprovisionsinrespectofexecutiontimesistomandateandharmonise thespeedingupof
payments,sothemaximumtimetakenwhenneitherthepayernor thepayeehasaccesstothefunds shouldbeonebusinessday.Thismeans,inourview, thatingeneralwhere“earmarking”offundstakes place,sothatthefundsremaininthe customer’saccountfor value‐datingpurposesbut are unavailable tothe customerto spend,the time ofreceiptforthe purposes of calculating the execution timemust be thepoint atwhichthe fundsbecomeunavailable tothe customer(i.e.the clock starts running for the purpose of the execution time provisions at the point funds become unavailable).
8.241 Inourview,anexceptiontothiscanbemadewhereapromiseorguaranteeofpayment hasbeengiven
bythepayer’sPSPtothepayee,e.g.inthecaseofpre‐authorisation of card‐based payment transactions where the amount is not known in advance (seeregulation78ofthePSRs2017).Insuch casesitmaybeacceptable,onthebasis ofrecital77toPSD2andprovidedthePSPhas compliedwith the requirementsof regulation78ofthePSRs2017,forthefundstobeearmarkedpending receiptof the actual payment order.
8.242 Withoutsuchapromiseorguarantee tothepayee(e.g.inthe caseofadirectdebit orstandingorder),
wecanseenojustificationforearmarkingsuchfundsanditis reasonableforthepayertoassumethey haveaccesstotheirfundsuntilthedate they instructed the direct debit or standing order to be actioned (e.g. the first of themonth).Similarly,ifwhensendingaBacscreditthebankearmarkedthe fundsin thepayer’saccountonthedaythefilewassubmittedbutdelayedthedebituntilthe business daybeforethefundsarecreditedtothepayee’sPSP’saccount,theexecution time would be longer than “next day” and therefore in breach of the requirements of regulation 86(1) of the PSRs 2017.
8.243 Thepayer’sPSPmustnotdebitthe customer’spayment accountbefore the receiptof a payment
order.
8.244 Where the payee’s PSP is not reachable by a payment system which enables paymentstobemade
withintheprescribedmaximumexecutiontimes(suchasFaster Payments),theproviderwillneedto makealternativearrangements,andclearlyexplain thepositiontotheir customers.Possibleoptions include:
making the payment through an alternative payment system (e.g. CHAPS) if available.Thismust
bewiththeagreementofthecustomer,whomustbeadvisedof (and agree to) any additional charges involved
UsingBacs,butdelayingthedebittothecustomer’saccountuntil,attheearliest, thebusinessday
beforetheBacspaymentwillbereceivedbythepayee’sPSP.This wouldbeclassedasa“futuredated payment”andtheprovisionsofregulation81(5) of the PSRs 2017 regarding customer agreement will apply. PSPs should also take note of paragraphs 8.240 and 8.242 in respect of “earmarking”.
8.245 In exceptional circumstances where, in spite of all efforts, it is not possible for the paymenttobe
madewithinthe specifiedtime limit,PSPsmay feelitnecessary to refusethepaymentorder concerned.Therequirementsofregulation82ofthePSRs 2017(assetoutbelow)wouldneedtobe
metinthisregard,andwhereaprovider believesthatsuchrefusalsmaybenecessary itwillneedto ensureitsframework contractsallowrefusalonthesegrounds.Wewouldnotexpectthatanysuch refusal would attract a charge.
8.246 ItisexpectedthatPSPswillhavemadethenecessaryarrangementstoenabletheir customers to
receive payments within the one business day timescale. Any PSP whosecustomeraccountsare notreachablebyFasterPayments,however,should considerhowtheywill explaintotheir customersthedifficultiesthattheyarelikelyto experienceinreceivingpaymentsfortheiraccounts asaresult. Refusal of payment orders (regulation 82)
8.247 A PSPmayonly refusetoexecuteapaymentorderorinitiateapaymenttransaction ifthe conditionsin
the framework contract have not beenmet or execution would be unlawful (e.g. in line with antimoney laundering legislation). In linewith the recitals to PSD2, customersshouldbeable torelyon theproperexecutionofthepaymentorder unless the PSP has a contractual or statutory ground for refusal. For ASPSPs, this appliesirrespectiveofwhetherthepaymentorderisinitiatedbythe customer,through aPISPorbyorthroughapayee.
8.248 WhereaPSPrefusestoexecuteapaymentorderortoinitiate apaymenttransaction, it must notify
the customer of the refusal, unless it is unlawful to do so (e.g. due to restrictionsontipping‐off). Thenotificationmust, ifpossible,include the reasonsfor therefusal.Whereitispossibletoprovide reasonsfortherefusalandthosereasons relate tofactualmatters(e.g. ifthe customer has not provided the required detailsto allow the payment to be processed or did not have available funds) the notification must also include what the customer needs to do to correct any errors that led to the refusal.Thenotificationmustbeprovidedormadeavailableinthewayagreedinthe framework contract (e.g. online) at the earliest opportunity and no later than the end of thenext businessdayfollowingreceiptofthepaymentorder.
8.249 Notification need not be provided for low value payment instruments if the non‐ executionis
apparentfromthe context(e.g.thepurchaseisrefusedatpointofsale) (seePartI,sectionAofthis chapterforadefinitionoflowvaluepaymentinstrument).
8.250 Iftherefusalisreasonablyjustifiedandtheframeworkcontractsoallows,thePSP may levya charge for
the refusal (unless the circumstance set out in paragraph 8.245 applies). This charge must reasonably correspond to the PSP’s actual costs. We believe this means that the provider must separately identify any such charge for refusal in the framework contract and separately charge this to the underlying account.
8.251 Recital77ofthePaymentServicesDirectivePSD2statesthat,whereaframeworkcontract provides
thatthePSPmaychargeafeeforrefusal,suchafeeshouldbeobjectively justifiedandshouldbekept aslowaspossible.Whensettingthelevelofthefeethe PSP should take an evidence based approach and:
8.253 Coststhataredirectlyattributabletotherefusalofaparticularpaymentmayinclude itemssuchas:
productlines.Whereanaggregatedapproachistaken,thePSPshould be satisfied that the resulting fee continues to reasonably correspond to the actual costs of refusing payments in each product line.
8.259 APSPthat choosestosetafeebelowthe costreflective levelforaparticularproduct shouldnot
recoverthe costsincurredasaresultofrefusingpaymentsby customers ofthat productfrom customers of other products, if this would result in a fee that no longerreasonably correspondsto the costsofrefusingpaymentsforthatproduct. Revocation of a payment order (regulation 83)
8.260 Thebasic rule isthatthe customer cannotrevokeapaymentorderafterithasbeen receivedbythe
payer’sPSP.Thereare,however,someexceptionstothisrule:
the agreement of the payee will also be needed to cancel a specific payment where revocation is sought after the end of the businessdayprecedingtheday thatthespecificpaymentisduetobe taken(butsuch agreement is not needed to withdraw consent to later payments in the series).
8.266 Achargemaybemadeforrevocation,ifagreedintheframeworkcontract.
8.267 The corporate opt out applies to this provision (see under “General” at the start of Part IIofthis
chapter).
8.268 For low value payment instruments, the PSP can agree with the customer that the customer
cannot revoke the payment order after transmitting it or after giving consenttothe payeefor the paymenttransaction (seePartI,sectionAofthis chapter for a definition of low value payment instrument). Amounts transferred and amounts received – deduction of charges (regulation 84)
8.269 Ingeneral,theruleisthatthepayerandthepayeemusteachpaythechargesleviedby theirownPSP
andthatnochargescanbedeductedfromtheamounttransferred.
8.270 Thepayeecanagreewithits PSPthatit candeductits chargesbeforecrediting the payee,aslongasthe
fullamountofthepaymenttransactionanddetailsofthecharges deducted are clearly set out in the information provided to the payee. If other charges are deducted, responsibility for rectifying the position and ensuring that the payee receivesthecorrectsum,lieswith:
paragraph2.272.30),themaximumperiodthatmaybeagreed between the payer’s PSP and its customer is the end of the fourth business day following the day on which the payment order was received (i.e. if the payment order wasreceivedonMonday,thepaymentwouldneedtoreachthe payee’sPSPbytheend ofFriday).Thismeans,forexample,thatforapaymentinSwedishkronersent fromwithinthe UK toSweden,the default position isthatthe paymentwould need tobe credited to thepayee’sPSPbytheendofthefollowingbusinessday.Thepayer’sPSPcanagree with its customer a different timescale although as the payment is to be executed whollywithintheEEAUK,this cannot belongerthanthe endofthefourth businessday following the time of receipt or deemed receipt of the payment order.
8.276 Fordirectdebittransactions andotherpayments ordersinitiated byorthroughthe payee, the
payee’s PSP should transmit the payment order within the time limits agreedbetweenthepayee andthePSPsoastoallowsettlementontheagreeddate.
8.277 Formerchantacquiringtransactionswehaveincludeddiagramsandanexplanatory note setting out
one model of how the time limit provisions might work for a four-party card scheme in Annex 4.
8.278 Whileothermodelsofacquiringmaybepossible,thePSRs2017definethe‘acquiring ofpayment
transactions’asapaymentservice“providedbyaPSPcontractingwitha payeetoacceptandprocess paymenttransactions,whichresultsinatransferoffunds tothe payee,” and thisis in linewith our viewthatthe contractbetween themerchant and the merchant acquirer to which the definition refers involves the execution of paymenttransactions.Adoptionofaparticularbusinessmodel shouldnotdeprive PSD2 of its utility in achieving the protection of merchants who receive transfers of fundsfromacquirers,asreferredtoinrecital10ofPSD2.Thereforeacquirersshould ensuretheircustomersreceivetheprotectionenvisagedbyPSD2–inparticularwith respectto safeguardsintheeventoftheacquirer’sinsolvency,executiontimesand informationrequirements.
8.279 Thepayee’sPSPmustvaluedateandcreditthepayee’saccountfollowingreceipt ofthe fundsin its own
account atthe paymentsystem(irrespective ofsettlement obligations) orifit doesnot havedirect accesstothe paymentsystem, in its account withitsbankorPSPinaccordancewithregulation89ofthe PSRs2017.Seeparagraphs 8.288 to 8.297 for further details.
8.280 For low value payment instruments, the PSP can agree with the customer that the executiontimes
inregulation86ofthePSRs2017donotapply(seePartI,sectionAof this chapter for a definition of low value payment instrument). Absence of payee’s payment account with the PSP (regulation 87)
8.281 Where the payee does not hold a payment account with the PSP (e.g. in money remittance
services) the PSP to which the payment has been sent must make the fundsavailableimmediately aftertheyhavebeencreditedtoitsaccount.Thisprovision shouldnotbeseenasrequiringbankswhich receivefundsaddressedtoapayeefor whom they do not hold an account to hold funds pending collection by the payee. In our view it is perfectly acceptable for these funds to be returned to the payer’s PSP withtheexplanation,“Noaccountheld”.
8.282 For low value payment instruments, the PSP can agree with the customer that the executiontimes
inregulation87ofthePSRs2017donotapply(seePartI,sectionAof this chapter for a definition of low value payment instrument). Cash placed on a payment account (regulation 88)
8.283 Cashplacedbyaconsumer,micro‐enterpriseorsmall charity (seeGlossary ofTerms) with a PSP for
credit to its payment account with that PSP must be credited to the account,valuedatedandmade availableimmediatelyafterreceiptbythePSP.For othercustomersanextrabusinessdayisallowed. Therequirementsinregulation88 of the PSRs 2017 only apply if the account is denominated in the same currency as the cash.
8.284 These time limits apply when cash is paid in at a branch or agent, and whether or not the branch or
agentwherethecashispaidinistheaccountholdingbranch.Theywill therefore apply,for example, to cash paid in to settle a credit card bill where the card wasissuedbythebankwherethepayinwas made.
8.285 Note that where cash is paid to a PSP with instructions for it to be transferred to the customer’s
accountwithanotherPSP,andthefirstPSPisprovidingaservicetothe customer itself — rather than acting as agent for the second PSP — the transaction wouldbesubjecttothenormalexecution timeprovisionsunderregulation86.Inthese circumstances, the use of the paper based credit clearing for such payments would therefore allow an additional day for the credit of the cash to the payee’s account.
8.286 Inour view,whenidentifying thepointintime atwhichthecash isdeemedtohave been received,
similar principles to those used in identifying the ‘point in time of receipt’forapaymentordermay beused.Thismeansthat,aslongasthePSPmakes it cleartothe customer,the point atwhich cash is deemed tobe receivedwhennot takenoverthecounterbyacashier(e.g.leftinanightsafe,orina depositboxinthe branch(“adaysafe”))canbespecifiedinlinewithreasonablecustomerexpectations asbeingthepointatwhichtheboxisopened(e.g.theendofthebusinessday for a daysafe and next business day for a nightsafe). In this regard, cash should be distinguished fromothertypes of payments. Forothertypesofpayments,thepointin timethatpaymentsarereceived(triggeringthe immediateavailabilityandvaluedating requirements)shouldbeconsideredinaccordancewith regulation89ofthePSRs2017.
8.287 Whereadiscrepancyinacashdepositisdiscoveredafterthefundshavebeencredited (e.g.
counterfeitednotes,orthecashhasbeenmiscounted) corrections canbemade, but corrected post‐ transaction informationwill alsoneed tobeprovided. Value date and availability of funds (regulation 89)
8.288 ThePSRs2017ineffectprohibitvaluedating thatisdetrimentaltothecustomer.This meansthatthe
value date of a credittoa payment account can be nolaterthan the business day on which the payment transaction was credited to the payee’s PSP’s account.
8.289 There are also requirements to make funds available immediately in certain circumstances
dependingonwhetheracurrencyconversionisinvolved(seethetable below). Where the requirement applies, the funds must be at the payee’s disposal immediatelyaftertheyhavebeen creditedtothepayee’sPSP’saccount. Type of transaction Transaction with no currency conversion Requirement to give immediate availability Yes Transaction with a currency conversion between euro and sterling Yes Transaction with a currency conversion between two EEA currencies (including sterling and another EEA currency) Yes Transaction only involving one PSP Yes Any other type of transaction No requirement to give immediate availability. We expect, however, PSPs to act reasonably in the time that it takes to make the funds available. What is reasonable will depend on the currency of the payment that needs to be converted as some currencies take longer to convert than others.
8.290 Assoonasthefundsarereceivedinthepayee’sPSP’saccount,itmustmakesurethat the payee can
get access to the funds immediately and credit value date them no later thanthebusinessdayon whichthePSP’saccountwascredited(whichincludesany account in the PSP’s name). In practice this means that PSPs’ systems must identify the funds immediately they are received in their own account and credit them to the payee’s account immediately.
8.291 Ifthetimethefundsare receivedisnotonabusinessday,theaboverequirements will apply atthe
start ofthenextbusinessday.APSPcannotseta“cut‐off” time for thereceiptoffundsthatisearlier
thantheendofabusinessday.A PSPmustalso not, whether by contractual terms or otherwise, specify that a day that meets the definitionofbusinessdayisnottobetreatedasabusinessday.A businessdayisany dayonwhichthePSPisopenforbusinessasrequiredfortheexecutionofapayment transaction.Whetheradayisabusinessdaymustbeconsideredfromthecustomer’s point of view, and will depend upon the individual circumstances of the PSP and is dependent upon the service it provides to its customers.
8.292 Forexample,withrespecttoacustomerwithonlinebankingwherethecustomer can makeandreceive
paymentsatanytimeusingFasterPayments,thePSPisinourview “openforbusiness”24hoursaday, sevendaysaweek.Withrespecttoacustomerwith anaccountwhichcanonlybeaccessedduring branchopeninghours,thoseopening hoursarelikelytorepresentthe“businessday”.
8.293 Itisrecognisedthatinpracticesomeprocessingofthepaymentbythepayee’sPSP may be needed
before the customer can access the funds. The requirement for “immediate”availability,however, meansthatthetimetakenforthisprocessingmust bekepttoaminimumandweseenoreasonwhy,in normalcircumstances,thisshould belongerthantwohours.Fortheavoidanceofdoubt,unlessthe paymentconcerned isreceivedoutofbusinesshours, “immediate”cannevermeanthenextbusiness day (andwhetherthepaymentisreceivedoutsideofbusinesshoursmustbeconsideredin accordance with paragraphs 8.290 – 8.292).
8.294 Paymenttransactionswhereboththepayer’sandthepayee’saccountsarewiththe same PSP are
within the scope of the PSRs 2017, and as such the execution time provisions will apply. This includes transactions where the payer and the payee are the same person.
8.295 WhereaPSPisusingitsowninternalprocessestoexecutethetransfer(i.e.thePSP actsforboththe
payerandpayee),webelievethattheprinciplesandaimsunderlying theexecutiontimeprovisionsin PSD2andPSRs2017mustapply,thatis,theavoidance of “float” and the efficient processing of payment transactions. We would therefore expectthatinsuchtransactionsvaluewillbegiventothe payeeonthesamedayasthe payer’saccountisdebitedandthatthefundswillbeputatthedisposalof thepayee immediately.
8.296 Wherethepayee’saccountisnota“paymentaccount”andthepayee’sPSPisacredit institution,the
ruleinBCOBS5.1.13willapply,sothatthetransactionmustbevalue datedonthebusinessdayreceived, butavailabilitymustbewithinareasonableperiod.
8.297 Similarly, debit transactions must not be value dated before the date on which the amount of the
debit was debited to the payer’s account. For example, in a card transaction,the cardissuer cannot value date thedebittothe accountbefore the date onwhichitreceivesthepaymentorderthroughthe merchantacquiring process(see Annex 4). Liability Incorrect unique identifiers (regulation 90)
8.298 Aspart ofthe informationthePSPisrequiredtoprovideaheadofprovisionofthe paymentservice,it
willspecifythe‘uniqueidentifier’,whichisthekeyinformation thatwill beusedtoroutethepayment tothe correctdestination andpayee. ForUK paymentsinsterling,thisislikelytobethesort code numberandaccountnumber ofthepayee’saccount.ForSEPApaymentsitwillbetheIBANofthe payee.Other information,suchasthepayee’snameorinvoicenumber,maybeprovidedbythe payer, butwillnotbepartoftheuniqueidentifier,unlessithasbeenspecifiedassuch bythePSP.
8.299 ThePSRs2017provide that, aslong asthe PSPsprocessthepaymenttransaction in accordancewith
the unique identifier provided by the paymentservice user, they will not be liable under the non‐ execution or defective execution provisions of the PSRs 2017 for incorrect execution if the unique identifier providedisincorrect.
8.300 The effect of this is if the sort code and account number are quoted as the unique identifier and
the account numberisincorrect butthe account name quoted is correct (sothatthefunds gotothe wrongaccount),thebank concernedwillnotbeliableunder those provisions.
8.301 PSPsarerequiredtomakereasonableeffortstorecoverthefundsinvolvedevenwhere theyarenot
liable,buttheymay,ifagreedintheframeworkcontract,makeachargefor such recovery. The payee’s PSP mustco-operate with the payer’s PSP in its efforts to recoverthefunds,inparticular byprovidingallrelevantinformationtothepayer’sPSP. Thisco‐operationbetweenPSPscouldinvolve participatinginindustryarrangements relating to the recovery of funds (such as the credit payment recovery process).
8.302 Ifthepayer’sPSPisunabletorecoverthefundsandthecustomerprovidesawritten request, the PSP
must, under regulation 90(4) of the PSRs 2017, provide to the customerallavailablerelevant informationinorderforthepayertofilealegalclaimfor repayment of the funds.
8.303 Wewouldexpecttherelevantinformationprovidedpursuanttoregulations90(3)and (4) of the PSRs
2017 to include the payee’s name and an address at which documents canbe effectively served onthatperson.Whenproviding informationtoits customers toensurefairandtransparentprocessing ofpersonaldata (eginaprivacynotice),as required by applicable data protection legislation, a PSP should take account of its potentialobligationsunderregulations90(3)and(4)ofthePSRs2017.
8.304 Wewouldalsoconsideritbestpracticeforthepayer’sPSP,afterreceivingtherelevant information from
the payee’s PSP but before providing such information to the payer underregulation90(4)ofthe PSRs2017,tonotify thepayeethatthisinformationwillbe provided to the payer.
8.305 In some cases of ‘authorised push payment (APP) fraud’ the payer intends to transfer the
fundstoa legitimatepayee,butisdeceivedintoproviding the accountnumber andsort codeof an accountheld by adifferent person, andsotransfersthe fundsto afraudster.Inourview,thisisalso provisionofanincorrectuniqueidentifierandPSPs must cooperate and make reasonable efforts to assist the payer in recovering the fundsasrequiredunderregulation90ofthePSRs2017.
8.306 PSPsareunderanobligationtocomplywithlegalrequirementstodeteranddetect financial
crime as detailed in Chapter 19 – Financial Crime.
Non-execution or defective or late execution of payment transactions initiated by the payer (regulation 91)
8.307 This provision covers situations where the payer has instructed their PSP to make a payment
andthe instructionhaseithernotbeencarriedout,orhasbeencarriedout incorrectly.
8.308 Inthesecircumstances,thepayer’sPSPwillbeliabletoitscustomerunlessitcanprove tothepayer(and,
whererelevant,tothepayee’sPSP),thatthecorrectamount,and thebeneficiary’sdetailsasspecified bythepayer,werereceivedbythepayee’sPSPon time.
8.309 If it could prove this, the failure to credit the intended payee would then lie with the payee’s PSP
rather than with itself. If the payer’s PSP is liable, it must refund the amount of the defective or non‐executed transaction (if such amount has been debited from the payer’s account) to the payer without undue delay, and, where applicable, restore the debited payment account to the state it would have been in hadthetransactionnotoccurredatall.Thismay,forexample,involvethe refundingof chargesandadjustmentofinterest.ThePSPmustensurethatthecreditvaluedateis no laterthanthedateonwhichthepaymenttransactionwasdebited.Inpractice,we takethistomean that, whenthe PSP isproviding a refundtothe customerofinterest lostorpaid,the calculationmust run fromnolaterthan thedate the transactionwas debited fromthe customer’s account.
8.310 Theeffectofthisprovisionisthatif,duetothe errorofthepayer’sPSP,the fundshave beensenttothe
wrongplaceorthewrongamounthasbeensent,asfarasthepayeris concerned the whole transaction iscancelled. The PSP will either have to stand the lossorseekreimbursementfrom theotherPSP.
8.311 Inlinewithrecital86ofPSD2,whichreferstothePSP’sobligationto “correctthe payment
transaction” our view is that to avoid undue enrichment, where an over paymenthasbeenmade andtheexcesscannotberecoveredfromthepayee’sPSP, itwouldbeappropriatetorefundthe excessincorrectlydeducted fromthepayer’s account where this is sufficient to avoid the payer
suffering a loss.
8.312 If the payer’s PSP can prove that the payee’s PSP received the correct amount and beneficiary
details on time, the payee’s PSP is liable to its own customer. It must immediatelymakethefunds availabletoitscustomerand,whereapplicable,creditthe amount to the customer’s payment account.
8.313 Thecredit valuedatemustbenolaterthan thedateonwhichthe amountwouldhave beenvalue
datedifthetransactionhadbeenexecutedcorrectly.Inpractice,wetake this to mean that when the PSP is providing a refund to the customer of interest lost or paid,the calculationmustrun fromno laterthanthedatethatthe amountwould have beenvaluedatedifthetransactionhadbeenexecuted correctly.
8.314 Whereapaymenttransactionisexecutedlate,thepayer’sPSPcanrequest,onbehalf ofthepayer,that
thepayee’sPSPappliesacreditvaluedateforthepayee’spayment accountwhichisnolaterthan the date thatthe amountwould havebeenvaluedated ifthe transactionhadbeenexecutedcorrectly.In our view,the aimofthisrequirement istoensurethatapayeeisinthesamepositionastheywouldhave beenhadthe transactionbeenexecutedontime(includinginrespectofcharges)andsonoclaimfor latepaymentwillariseagainstthepayer.Thepayee’sPSPcanseekrecoursefromthe payer’sPSPunder regulation95ofthePSRs2017.
8.315 Liabilityunderthisprovisionwillnotapply ifthefailuregiving risetoitwasdueto abnormaland
unforeseeablecircumstancesbeyondthecontroloftherelevantPSP, theconsequencesofwhich wouldhavebeenunavoidabledespitealleffortstothe contrary,orifitarosebecauseofthePSP havingtocomplywithotherEUorUKlaw.
8.316 Regardless of liability, if the payer makes a request for information regarding the executionof a
paymenttransaction, its PSPmustmakeimmediate effortstotracethe transaction and notify the customer of the outcome. The PSP cannot charge for this.
8.317 The corporate opt out applies to this provision (see under “General” at the start of Part IIofthis
chapter).
Non-execution or defective or late execution of payment transactions initiated by the payee (regulation 92)
8.318 This provision covers situations where the payment order has been initiated by the payee (e.g.
creditordebit cardpayments,ordirectdebits),andtheinstructionhas either not beencarried out or carried outincorrectly.
8.319 Inthesecircumstancesthepayee’sPSPisliabletoits customerunlessitcanproveto thepayee(and,
whererelevant,tothepayer’sPSP),thatithascarriedoutits endof thepaymenttransaction properly. Thatis, ithassentthepaymentinstruction (inthe correctamount andwithinthe agreed timescale), andthecorrectbeneficiary details tothepayer’sPSP,sothatthe failure toreceivethe correct amount offundswithinthe timescalelieswith the payer’s PSP rather thanwith itself.
8.320 If it has failed to do this it must immediately re-transmit the payment order. The payee’s
PSP must also ensure that the transaction is handled in accordance with regulation 89 of the PSRs 2017 so that the amount of the transaction is at the payee’s disposal immediately after it is credited to the payee’s PSP’s account and the credit valuedateisnolaterthanthe dateonwhichtheamountwouldhavebeenvaluedated if the transaction had been executed correctly. In practice, we take this to mean that thepayee’sPSPneedstoprovidearefundtothe customerofinterestlostorpaidand, in doing so, itmust ensure thatthe calculation runsfromno later than the date thatthe amountwouldhavebeenvaluedatedifthetransactionhadbeenexecuted correctly.
8.321 Ifthepayeemakesarequestforinformationregardingthe executionofapayment transaction,
their PSPmustmakeimmediate effortstotrace the transaction and notify the customer of the outcome. The PSP cannot charge for this.
8.322 Ifthepayer’sPSPisliable,itsliabilityistoitsowncustomerratherthan thepayee,andit must,
immediately,andasappropriate:
executing the payment transaction late, that customer would be entitled to a refund for any charges and interest applied to their credit card account. This liability will not be incurredifthecircumstances giving risetoitwereduetoabnormalandunforeseeable circumstancesbeyondthecontrolofthePSP.
8.332 The corporate opt-out applies to this provision (see under “General” at the start of Part IIofthis
chapter).
Right of recourse (regulation 95) and right of action (regulation 148)
8.333 IfaPSPhasincurredalossorbeenrequiredtomakeapaymentwithrespectto unauthorised
transactions, or the non‐execution, defective execution, or late executionofapayment transaction,butthatliability isattributabletoanotherPSP oranintermediary,theotherPSPor intermediarymustcompensatethefirstPSP. This includes compensation where any of the PSPs fail to use strong customer authenticationwhereitisrequiredpursuanttoregulation 100ofthePSRs2017.
8.334 Inthesecircumstances,thefirstPSPalsohasarightofactionagainsttheotherPSP. Thisentitlesthe
first PSPtobring anactionagainsttheotherPSPfor compensation throughthecourtsonthebasisof theotherPSP’sfailure tocompensatethe first PSP under regulation 95 of the PSRs 2017 (regulation 148(4) of the PSRs 2017). Force majeure (regulation 96)
8.335 Liability under the conduct of business requirements in Part 7 of the PSRs 2017 relating to rights
and obligations(but notto the information requirementsin Part 6 of thePSRs2017)willnotapply wheretheliabilityisdueto:
establishandmaintaineffective incident management procedures, including for the detection and classification of major operational and security incidents. Chapter 18 – Operational and security risks and Chapter 13 – Reporting and notifications contain more information. Authentication (regulation 100)
8.340 From14September2019,allPSPsmustcomplywithregulation100ofthePSRs2017 and with SCARTS.34 Chapter 20 – Authentication provides further information.
8.341 Under regulation 100(3) of the PSRs 2017, PSPs must maintain adequate security measures to
protect the confidentiality and integrity of payment service users’ personalisedsecurity credentials.SCA‐RTSArticles22to27specifytherequirements, which include thecreation and transmission of credentials and their secure association with the payment service user, as well as the delivery and renewal of credentials, authentication devices and software, and subsequent destruction, deactivation or revocation.
Part III: Additional conduct of business requirements for e‐money
issuers
8.342 Thissectionincludessomeadditionalconductofbusinessrulesapplicabletoall e‐moneyissuers,
includingthoseauthorisedunderFSMA.Theyapplytotheissuance andredemptionofe‐moneycarried onfromanestablishmentintheUK.
8.343 Weareawarethatanumberofpre‐paidcardshavebeenissuedintheUKby “programmemanagers”
whichutilisee‐moneyissuedbyacreditinstitutionor e‐moneyissuer.Underthesearrangements,the programmemanagermanagesthe cardandtakestransactionandotherfeesfromthecarduser,butthe underlying funds areheldbythee‐moneyissuinginstitution.Inourviewthee‐moneyissuerwillusually be the PSP for the purposes of the PSRs 2017, given that the programme manager doesnotholdany customerfunds.
8.344 The arrangement will fall under the outsourcing provision in regulation 26 of the EMRsor
underSYSC8forcreditinstitutionsissuinge‐money,andmay,depending onthebusinessmodel, involveagencyordistributionarrangements.Inthesituation described,the e‐money issueris thereforeresponsibleforensuringthattheconduct ofbusinessrequirementssetoutinthis chapter arecompliedwith. 34 The Commission Delegated Regulation (EU) 2018/389 (the SCA‐RTS) is available here https://eur‐lex.europa.eu/legal‐content/EN/ TXT/PDF/?uri=CELEX:32018R0389&from=EN The conduct of business requirements in the EMRs
8.345 Part 5ofthe EMRssetsoutobligationsthat apply tothe conduct of e‐moneybusiness whereit is
carriedoutfromanestablishmentmaintainedbyane‐money issuerorits agentordistributorinthe UK. Thesearetypically referredtoas conductofbusiness requirements. They relate to issuing and redeeming e‐money and the prohibition on the payment of interest or other benefits linked to the length of time that e‐money is heldandareapplicable toalle‐money issuers(seeChapter 2 – Scope for the definition ofe-moneyissuers). Issuing e‐money
8.346 Regulation39oftheEMRsrequirese‐moneyissuerstoissuee‐moneyatparvalue (thee‐money
issuedmustbeforthe sameamount asthe fundsreceived)whenthey receive the fundsand without delay.
8.347 Itisimportanttorecognise thatif an agentof an e‐money issuerreceivesfunds,the funds are
considered to have been received by the issuer itself. It is not, therefore, acceptable for an e‐ money issuer to delay in enabling the customer to begin spendingthee‐moneybecausetheissuer iswaiting toreceivefundsfromitsagentor distributor. Redeeming e‐money
8.348 Under the EMRs, e‐money holders have the right to redeem the monetary value of their e-money
(i.e. the payment from the e-money issuer to the e-money holder of an amountequivalenttothe remainingbalance)atanytimeandatparvalue(regulation39 of the EMRs).
8.349 Thismeansthat, inour view, it isnot acceptabletohavea termina contractwith an e-money holder
under which the e-money holder’s right to redeem the remaining balanceceasestoapplyaftera specifiedperiodofvalidity(althoughthecontract can still provide for the e-money holder’s right to use the e-money for the purpose ofmakingpaymenttransactionstoceaseafteraspecified period).Thisisqualified byregulation43oftheEMRswhichallowse‐moneyissuerstorefusea redemption requestwhenthe requestismademorethan six yearsafterthedateoftermination in the contract.
8.350 The contractbetweenthe e‐money issuer andthe e‐moneyholdermust, clearly and prominently,set
outthe conditionsofredemption(orpartthereof), including any fees thatmaybepayable.E‐money holdersmustbeadvisedabouttheseconditionsbefore theyareboundby the contract. Redemption fees
8.351 Ifit isagreedandtransparentinthe contract,e‐money issuersmay chargeafeefor redemptionin
thefollowingcircumstances:
moneyfunds(asthereisnoutility inrequiringissuerstosafeguard dormant e‐money funds that can no longer be spent or redeemed). The issuer would,however,havetobeabletoshowtothee‐ moneyholderthatthisishowthe e‐moneybalancehasbeenusedup,intheeventofthee‐money holderlaterseeking redemption.
8.357 The above guidance on redemption does not apply to a person (other than a consumer) who
accepts e-money (e.g. a merchant who has accepted e-money in paymentforgoodsor services).Forsuchpersons,redemptionrightswillbesubjectto thecontractual agreementbetween theparties. Prohibition of interest
8.358 E‐money issuers are not allowed to grant interest or any other benefits related to the length oftime
the e‐money isheld. Inour viewthiswould notprohibitbenefitsrelated to spending levels.
9 Capitalresourcesandrequirements
9.1 Thischaptersetsouthowauthorisedpaymentinstitutions(PIs),authorisede‐money institutions
(EMIs), and small EMIs should use their capital resources to meet their initial and ongoing capital requirements. It is not relevant to small PIs or registered account information service providers (RAISPs). The professional indemnity insurance (PII)requirementsthatwillapplytofirmscarryingon accountinformationservices(AIS) and payment initiation services (PIS) are covered in Chapter 3 – Authorisation and registration. This chapter covers:
9.6 Authorised PIs can undertake activities that are unrelated to providing payment services.
Thesefirmsarecalled‘hybrid’firms.ThePSRs2017donotimposeanyinitial orongoing capital requirementsinrelationtobusiness carriedonby suchfirmsthat doesnotinvolvepaymentservices. Anyothercapitalrequirementsimposedbecause ofotherlegislationhavetobemetseparatelyand cumulatively(e.g.iftheauthorisedPI is undertaking an activity regulated under the Financial Services and Markets Act 2000 (FSMA)).WheretheauthorisedPIcarriesoutactivitiesotherthan providingpayment services, it must not include in its capital calculation any items used in carrying out those other activities. Initialcapitalrequirements
9.7 The initial capitalrequirementis one ofthe conditionstobemet atthe application stage in order for
the applicant to become authorised by us. The PSRs 2017 set outthattheinitialcapitalrequirement of authorised PIswill be€20,000, €50,000 or €125,000dependingonthebusinessactivitiesitcarries out(seetablebelow).Where morethan oneinitial capitalrequirementappliestothe authorised PI, it mustholdthe greater amount.
9.8 Theminimuminitialcapitalrequiredisasfollows:
Payment Services
(see Schedule 1 of the PSRs 2017)
Money remittance (paragraph 1(f) of Part 1, Schedule 1 of the PSRs 2017) Initial Capital Required (Minimum) €20,000 Payment initiation services (paragraph 1(g) of Part 1, Schedule 1 of the PSRs 2017) €50,000 Account information services (paragraph 1(h) of Part 1, Schedule 1 of the PSRs 2017) None Payment institutions providing services in (paragraphs 1 (a) to (e) of Part 1,
Schedule 1 of the PSRs 2017)
€125,000
Ongoing capital (or ‘own funds’) requirements for PIs
9.9 AuthorisedPIsarerequiredtoholdatalltimesownfundsequaltoorinexcessofthe greaterof:
UnlikeotherauthorisedPIs,thesefirmsaresimplyrequiredtocontinuetoholdthe amountofinitial capitalrequiredfortheirbusinessactivitiesatalltimes. Calculation of ongoing capital (or ‘own funds’) requirements for PIs
9.11 Thissectionexplainsthethreecalculationmethods forthedifferentownfunds
requirements:methodsA,BandC.
9.12 Theapplicantwillbeasked,intheauthorisationapplicationpack,toindicatewhich calculation
methoditwishestouse.Ultimately,however,wewilldirectwhichmethod itmustuse.Wewilldothis basedon ourevaluationoftheapplicantfirm,taking into account its preference as stated in the application pack. Method A
9.13 MethodAisbasedonthefirm’sfixedoverheads.Thecalculationisnormally10%of thefirm’sfixed
overheadsinthepreviousfinancialyear.If,however,thereisamaterial changeinthefirm’sbusiness sincethepreviousfinancialyear,wemaydecidethatthe requirementishigherorlowerthan10%. Examplesofamaterialchangeincludethe saleofpartsofthefirm,abusinessacquisitionandrapid growth(typicallyofanew firm).
9.14 Fixed overheads are defined as including expenses that do not vary as a result of outputvolume
orsalesrevenue.Forexample,rent,insuranceandofficeexpenses. Generalaccountingstandards shouldbefollowedinvaluingthespecificexpensesto betakenintoaccount.Onlyexpensesthatare relatedtopaymentservicesshouldbe takenintoaccountwhencalculatingthefixedoverheadsof firmswhichalsoprovide servicesotherthanpaymentservices(hybridfirms). Method B
9.15 Method B is based on a scaled amount representing the firm’s average monthly payment volume
and then applying a scaling factor relevant to the type of payment servicescarriedout(seethe tableatparagraph9.18fortherelevantscalingfactor). Under this calculation method, the firm’s ongoing capital requirement is the product of this scaling factor and the scaled average monthly payment volume. The scaled average monthly payment volume is the total amount of the firm’s payment transactionsexecutedinthepreviousfinancialyeardividedbythenumberof months inthatyearandscaledinthefollowingmanner:
Method C
10.19.16 MethodCisbasedonthefirm’sincomeoverthepreviousfinancialyearwithascaling factor applied.
The firm’s income is derived by applying a multiplication factor to incomedescribedasthe ‘relevantindicator’inthePSRs2017.Thisisthesumofthe firm’sinterestincome,interestexpenses, commissionandfeesreceivedaswellas otheroperatingincome,definedasfollows:
oradoptedbyFinancialReportingCouncilLimited;
Initial capital requirements for EMIs and small EMIs
10.149.29 The initial capitalrequirementisoneofthe conditionstobemet atthe application stage.
TheEMRsspecifythefollowinginitialcapitalrequirements:
10.249.39 AnauthorisedEMIthatundertakesbusinessotherthanissuinge‐moneyandproviding related
paymentservicesmustnotuse:
following(assetoutinparagraph25ofSchedule2oftheEMRs):
amounts owed under different agreements between the same parties, and be legally enforceable in all relevant jurisdictions. In addition, where a firm chooses to apply this best practice, the deduction of intra‐group receivables from own funds should be reflected in the firm’s reporting of its regulatory capital position to the FCA. The deducted amount should be included in the Capital resources section ‐ field ‘Deductions from CET1 items’ in the FSA056 or FIN060a return (as applicable). This is designed to ensure an adequate level of financial resources within each individual regulated entity at all times to absorb losses. It also reflects the risk that a period of financial stress may affect the ability of other members of the firm’s group to repay any amounts owed.5
10.379.54 An authorised PI, authorised EMI, or small EMI should carry out capital adequacy
assessments at least annually. They should also undertake them if there is a substantial change in their business model or circumstances, that would result in a material increase in capital required under the PSRs/EMRs. ‘Ownfunds’tomeetongoingcapitalrequirementsforauthorisedPIs, authorisedEMIsand smallEMIs
10.389.55 TheongoingcapitalrequirementistobemetbytheauthorisedPI,authorisedEMI,or smallEMI’s
capitalresources,whichisformedofownfunds.Theongoingcapitalheld mustnotfallbelowthelevel oftheinitial capitalrequirementfortheservicesprovided.
10.399.56 Regulation 2of the PSRs 2017 and regulation 2 of theEMRs set out that own funds has
thedefinitiongiveninArticle4(1)(118)oftheCapitalRequirementsRegulation.Own funds consist of Tier 1andTier 2items.Tier 1isformedofCommonEquity Tier 1and AdditionalTier1.Atleast75%of Tier1capitalmustbeheldasCommonEquityTier1 capitalandTier2capitalmustbeequaltoorless thanonethirdofTier1capital.
10.409.57 Theprocessbelowshowshowownfundscanbecalculated.Weonlyincludethe relevantpartsof
theCapitalRequirementsRegulationthatapplytoauthorised PIs,authorisedEMIs,orsmallEMIs.We excludethoseelementsoftheCapital RequirementsRegulationthatonlyapplytobanks(e.g.those relatingtointernal ratings‐basedmodels).TheflowchartshouldbeusedintandemwiththeCapital Requirements Regulation and does not replace it and does not replace the Capital Requirements Regulation, which can be read on the EurLex website. 5 Also see guidance on stress testing set out in paragraphs 3.67 – 3.72.
Figure 1 – Overview of ‘own funds’
(see Figure 2) (see Figure 3) (see Figure 4)
100% 33⅓% ofCET1 33⅓% of T1
Tier 2 capital
Figure 2 – Common Equity Tier 1 (CET1) capital
CET1 (Common Equity Tier 1) Items
[CRR 26, 27, 28, 29 & 30]
(a) Capital instruments (e.g. ordinary shares) (b) Sharepremiumaccounts (c) Retained earnings (d) Accumulated other comprehensive income (e) Other reserves Prudential filters:
[CRR 32, 33, 34 & 35]
(a) Securitised assets including future margin income (b) Cashflowhedgesandchangesinthevalueofownliabilities (c) Additional value adjustments CET1 deductions:
[CRR 36(1), 37, 38, 40, 41, 43, 44, 45, 46, 47, 48 & 49] (a) Lossesforthecurrentfinancialyear (b) Intangible assets (c) Deferredtax assetsthatrelyonfutureprofitability – { (d) Notapplicable } – (e) Definedbenefitpensionfundassets (f) Own CET1 instruments (g) Reciprocal FSE CET1 cross-holdings (h) Non‐significant FSE CET1holdings (i) Significant FSE CET1 holdings (j) Excess AT1 deductions – { (k) Notapplicable} – (l) Foreseeable tax charges relating to CET1 CET1 Temporary waiver [CRR 79] CET1 capital [CRR 50]
Figure3 –Additional Tier 1 capital
AT1 (Additional Tier 1) Items
[CRR 51, 52, 53, 54 & 55]
Capital instruments and share premium accounts AT1 deductions:
[CRR 56, 57, 58, 59 & 60]
Own AT1 instruments
ForeseeableAT1taxchargesthatreduceAT1
The FCA’s role under the Payment ServicesRegulations 2017 and the Electronic Money Regulations 2011 Chapter 13
Figure 4 – Tier 2 capital
T2 (Tier 2) Items
[CRR 62, 63, 64 & 65]
Capitalinstrumentsandsubordinatedloanswithoriginalmaturity of at least 5 years and share premium accounts T2 deductions:
[CRR 66, 67, 68, 69 & 70]
Own T2 instruments
10.419.58 AdditionalsourcesofinformationabouttheCapitalRequirementsRegulationcanbe found at:
10.42 EuropeanCommission:CapitalRequirements–CRDIV/CRR–FrequentlyAsked Questions:andthe
generalwebpageonCRD/CRR
10.42
10.42 European Banking Authority: SingleRulebook
The FCA’sCRDIVweb page
The FCA’s role under the Payment ServicesRegulations 2017 and the Electronic Money Regulations 2011 Chapter 13 10 Safeguarding Introduction
10.1 This chapter explains the safeguarding requirements for authorised payment institutions
(Authorised PIs), authorised e‐money institutions (Authorised EMIs), small e-money institutions (small EMIs) and credit unions that issue e-money and theirresponsibilitytoensureappropriate organisationalarrangementsareinplace to protect the safeguarded funds. These businesses are reminded that adequate safeguarding measures are a pre‐requisite for being granted and retaining an authorisation for the provision of payment and e- money services. This chapter also setsout theobligationsthatsmallpaymentinstitutions(smallPIs)mustcomplywith,if they choose to voluntarily safeguard.
10.2 Theobligation tosafeguardstartsimmediately on receipt of funds (‘relevant funds’ see
paragraphs 10.14 18-10.1721).
Safeguarding funds from payment services under the Payment Services Regulations 2017 (PSRs 2017)
10.3 AllauthorisedPIsarerequiredtocomplywiththesafeguardingrequirementsin regulation 23
of the PSRs 2017.
10.4 While small PIs are not required to safeguard customer funds under the PSRs
2017, Principle 10 of our Principles for Businesses requires all firms, including small PIs to arrange adequate protection for clients' assets when they are responsible for them. While this does not mean that small PIs must safeguard customer funds, they must consider what protections would be adequate in relation to the business they are conducting.
10.5 SmallPIscanchoosetocomplywiththesafeguardingrequirementsinthePSRs2017 in order to offer
the same protections over customer funds as authorised PIs must provide.. We view this as best practice and would encourage these institutions to consider safeguarding their customers’ money voluntarily. If a small PI does choose to safeguard it will need to apply the same level ofprotectionsasareexpectedofanauthorisedPI,asdescribedinthischapter. We expect a small PI to tell us if it is choosing to safeguard funds, both in its application for registration and in annual reporting returns.
10.410.6 If a small PI decides to begin safeguarding funds after it has been registered, or alternatively,ifa
smallPIwhichhasadvisedusthatithaschosentosafeguardatthe timeofregistrationdecidesthatit will ceasedoingso,itshouldadviseusofthisas soonaspossiblethroughtheCustomer Contact Centre.
10.7 If a small PI has opted to protect its customers funds using an alternative method, it should be
prepared to provide a rationale for this decision. When complying with Principle 10 of our Principles for Businesses small PIs, should keep a record of the customer funds that they hold. Safeguarding funds received in exchange for e-money under the Electronic Money Regulations 2011 (EMRs)
10.510.8 AllauthorisedEMIsandsmallEMIsarerequiredbyregulation20oftheEMRsto safeguardfunds
receivedinexchangefore‐moneythathasbeenissued.
10.610.9 A credit union that issues e-money willhave a Part 4A permission under theFinancial Services
andMarketsAct2000(FSMA)toissuee‐moneybutisrequiredunderthe EMRs to safeguard funds received in exchange for e‐money as if it were an EMI (regulation 20(5) of the EMRs). Safeguarding funds from unrelated payment services under the EMRs
10.710.10 EMIs and credit unions that issue e-money are also entitled to provide payment
services that are unrelated to the issuance of e-money (regulation 20(6) of the EMRs).
The FCA’s role under the Payment ServicesRegulations 2017 and the Electronic Money Regulations 2011 Chapter 13
10.810.11 Authorised EMIs that provide unrelated payment services are subject to the
safeguarding provisions of the PSRs 2017(regulation 23 of the PSRs 2017) as if they were authorised PIs.
10.12 Small EMIs that provide unrelated payment services are in thesame position as small PIs with
respect to safeguarding. They .are not required to safeguard funds received for the execution of payment transactions that are unrelated to the issuing of e-money, but under Principle 10 of our Principles for Businesses they are required to arrange adequate protection for clients' assets when they are responsible for them. Like small Underthe PSRs 2017 small PIs they. Under the PSRs 2017 small PIs can choose to comply withthe safeguardingrequirementsinthePSRs2017forfundsreceivedforpayment services in order to offer the same protection over customer funds as authorised EMIs and authorisedPIs must provide. We view this as best practice and would encourage these institutions to consider safeguarding their customers’ money voluntarily. If a small EMI chooses to safeguard funds received for unrelated payment services it will have to deliver the same level of protection as is expectedofanauthorisedEMIandauthorisedPI,asdescribedinthischapter.
10.910.13 We require businesses applying to become small EMIs that provide unrelated payment
services to tell us if they will safeguard these funds. If a small EMI decides to begin safeguarding funds after it has been registered, or alternatively, if a small EMI which has advised us that it has chosen to safeguard at the time of registration decides that it will cease doing so, it should advise us of this as soon as possible through the Customer Contact Centre. Those that opt to safeguard funds receivedforunrelatedpaymentserviceswillhavetoprovideinformationabouttheir safeguardingarrangements in annual reporting returns. If a small EMI that provides unrelated payment services, has opted to protect its customers’ funds using an alternative method, it should be prepared to provide a rationale for this decision. When complying with Principle 10 small EMIs should keep a record of the customer funds that they hold.
10.1010.14 Creditunionsthatissuee‐moneyandprovideunrelatedpaymentservicesaresubject to
regulation23ofthePSRs2017onthesamebasisassmallEMIs, and accordingly our guidance in paragraphs 10.12 and 10.13 relating to small EMIs also applies to credit unions.
10.1110.15 WerefertoauthorisedPIs,authorisedEMIs,smallEMIs,creditunionsthatissue e‐money
andsmallPIs(whensubjecttovoluntarysafeguardingrequirements)as “institutions” throughout this chapter. Purpose of safeguarding
10.1210.16 The PSRs 2017 and EMRs impose safeguarding requirements to protect customers where
funds(seeparagraphparagraphs10.1418to10.1721)areheldbyaninstitution.Theydothisby ensuring that those funds are either placed in a separate account from the institution’s working capitalandotherfunds,orarecoveredbyanappropriateinsurancepolicyor comparableguarantee.On theinsolvencyofaninstitution, claimsofe‐moneyholders or payment service users are paid from the asset pool formed from these funds in priority to all other creditors(otherthan in respect of the costs of distributing the asset pool). Disclosing information on treatment of funds on insolvency to customers
10.1310.17 Institutions will need to be careful to avoid giving customers misleading impressions about
how much protection they will get from safeguarding requirements, for example, by implying that customer protections arising from safeguarding extend to an institution’s non‐regulated business. Institutions should also avoid suggesting to customers that the relevant funds they hold for them are protected by the Financial Services Compensation Scheme. What funds need to be safeguarded?
10.1410.18 Therequirementtosafeguardappliesto‘relevantfunds’inboththePSRs2017and EMRs.
The FCA’s role under the Payment ServicesRegulations 2017 and the Electronic Money Regulations 2011 Chapter 13
10.1510.19 UndertheEMRs,relevantfundsarefundsthathavebeenreceivedinexchangefor e‐moneythat
hasbeenissued.Relevantfundsreceivedintheformofpaymentbya paymentinstrumentonlyhaveto besafeguardedwhentheyarecreditedtotheEMI’s orcreditunion’spaymentaccountorareotherwise madeavailabletotheEMIorcredit union,subjecttotherequirementthattheyaresafeguardedbythe endoffivebusiness days after the date on which the e-money was issued. This relates to emoney paid for by apaymentinstrumentsuchas a creditordebit cardandnot e‐money thatispaidfor by cash.
10.1710.20 Authorised EMIs must also separately safeguard relevant funds received in relation to
unrelated payment services. Small EMIs and credit unions may choose to safeguard relevant funds received in relation to unrelated payment services. Regulation 23 of the PSRs 2017 applies to these funds.
10.1810.21 Under the PSRs 2017,relevant funds are:
Read the rest free
Source: Financial Conduct Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from FCA
FCA published 8 documents in the last 30 days. We email you each new one the day it's published.