2011-02-23 | BPS/DIR/GEN/CIR/02/007

RE:CIRCULAR ON THE NEED TO COMBAT CARD FRAUD

The Central Bank of Nigeria has issued a circular to all deposit money banks, directing them to implement additional measures to combat card fraud. The measures include proper KYC for cash card issuance, setting limits and authentication for transfers, and restricting card usage for service payments. Banks are also required to name all terminals with identification numbers and location addresses within 60 days.

CENTRAL BANK OF NIGERIA Central Business District P.M.B. 0187 Garki, Abuja 09-46238455 (Fax) 09-46238445 Tel REF: BPSIDIRIGENICIRI02I007 February 23, 2011 TO: ALL DEPOSIT MONEY BANKS (DMBS) RE: CIRCULAR ON THE NEED TO COMBAT CARD FRAUD Further to our circular dated August 30, 2010 on the above subject, it has become necessary for all Deposit Money Banks (DMBs) to apply additional measures to the existing controls to stem the menace of card fraud in the market.

Consequently, all DMBs are hereby directed to implement the following: · Apply proper KYC for issuance of cash cards Set limit and ensure second level authentication for card o to card transfers, POS and web payments o Cardholders should be given options to choose channels (ATM, POS, Web, etc) for which their cards will be applied.

This process should be completed within the next 60 days from the date of this circular.

Restrict cash card usage for payment of services .

specifically to the agreed schemes.

o Comply with the attached standard convention of naming all terminals with identification numbers and location addresses within the next 60 days from the date of this circular.

This circular takes immediate effect.

Appropriate sanctions will be imposed for non-compliance in line with the recent circular on penalties.

A. S. I ATOLOYE Director, Banking & Payments System Department

Standard Naming Convention Of Temrminal Ids For All Atms

ISO Message fields 41, 42, and 43 are standardized as follows: o Field 41 contains the Card Acceptor Terminal ID (8 characters) and should have its content breakdown as follows: a.

1BNKBRNX where 1 connotes ATM transaction; BNK for Bank CBN code; BRN for Bank Branch Code; while X stands for ATM number at the Branch.

i. For example: 10630161 implies ATM Terminal (1) from xxx Bank (063) situated at Branch 016 and it's the first ATM deployed at the Branch location (1).

ii. Another example: 10990502 implies ATM Terminal (1) from xxx Bank (099) situated at Branch 050 and it's the second ATM deployed at the Branch location (2).

o Field 42 contains the Card Acceptor ID Code (15 characters) and should have its content breakdown as follows: a.

BANKNAME - Here we will have xxxxxxx Bank_Plc o Field 43 contains the Card Acceptor Name (40 characters) and should have this four (4) elements in its content breakdown as follows: a.

b.

c.

The location information (positions 1 - 23), exclusive of city, state and country The city (positions 24 - 36) in which the Terminal/Point-of-Service is located The state (positions 37 - 38) in which the Terminal/Point-of-Service is located The country (positions 39 - 40) in which the Terminal/Point-of-Service is located d.

STANDARD STATE CODES

STATECODE
ANAMBRAAN
ABIAAB
ADAMAWAAD
AKWAIBOMAK
BAUCHIBA
BENUEBE
BORNUBO
BAYELSABY
CROSS
RIVERCR
DELTADE
EBONYIEB
EDOED
EKITIEK
ENUGUEN
FCT(ABUJA)FC
GOMBEGM
IMOIM
JIGAWAJG
KADUNAKD
KASTINAKT
KWARAKW
KANOKN
KOGIKO
KEBBIKB
LAGOSLA
NIGERNG
NASARRAWANA
OYOOY
OSUNos
OGUNOG
ONDOON
PLATEAUPL
RIVERSRV
SOKOTOSK
TARABATA
YOBEYB
ZAMFARAZA
Tags
fraud
kyc
payments
infosec