2023-12-22 | POJK 21 Tahun 2023Added
This regulation establishes the licensing, operational, and risk management requirements for general banks providing digital services, either independently or through partnerships with financial or non-financial institutions. It mandates specific IT infrastructure standards, customer identification and verification protocols including multi-factor authentication, and strict governance for third-party collaborations, including data protection and liability limitations. Banks must obtain prior authorization for new digital products, submit implementation and evaluation reports within specified timeframes, and face administrative sanctions such as service suspension or health rating downgrades for non-compliance.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA
EXTRACT
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 21 OF 2023
CONCERNING
DIGITAL SERVICES BY GENERAL BANKS
BY THE GRACE OF THE ALMIGHTY GOD
THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY, Considering:
a. that changes in public expectations for services provided by banks quickly, safely, and efficiently, encourage banks to enhance digital services for customers; b. that with the development of digital services supported by the continuous development of information technology, there is a need for an innovation space for banks to continue developing digital services to provide comprehensive services to customers;
c. that the development of digital services for banks needs to consider risk management aspects, customer data security, and consumer protection, thus it is necessary to replace the Financial Services Authority Regulation Number 12/POJK.03/2018 concerning the Implementation of Digital Banking Services by General Banks;
d. that based on the considerations referred to in letters a, b, and c, it is necessary to establish a Financial Services Authority Regulation concerning Digital Services by General Banks; Recalling:
CHAPTER I
GENERAL PROVISIONS
Article 1
In this Financial Services Authority Regulation, the following terms are defined as:
CHAPTER II
DIGITAL SERVICES BY BANKS
First Section
Scope and Requirements for Digital Services
Article 2
(1) Digital Services are implemented by:
a. Bank; or b. Bank with the Bank's partners based on a cooperation agreement.
(2) Digital Services as referred to in paragraph (1) are carried out in accordance with the Bank's business activities as regulated in statutory regulations.
Article 3
Banks implementing Digital Services as referred to in Article 2 must have IT infrastructure and IT infrastructure management capable of supporting the implementation of Digital Services optimally.
Article 4
Banking services that utilize IT for the purpose of providing public information and communication with customers and/or prospective customers without transactions and/or access to customer accounts are not considered Bank products as referred to in the Financial Services Authority Regulation concerning the implementation of general bank products.
Second Section
Implementation of Digital Services
Article 5
(1) In conducting business relationships with customers or prospective customers through Digital Services, Banks must conduct:
a. identification of customers or prospective customers; and b. verification of:
Third Section
Procedure for Licensing Digital Services
Article 12
In the event that Digital Services meet the criteria for new products, Banks follow the licensing mechanism in accordance with the Financial Services Authority Regulation concerning the implementation of general bank products.
Article 13
(1) Banks submit applications for licenses for the implementation of Digital Services meeting the criteria for new products as referred to in Article 12 by submitting the Application for Implementation of Digital Services License document at least contained in Appendix I, which is an integral part of this Financial Services Authority Regulation. (2) Banks submit the application for the implementation of Digital Services as referred to in paragraph (1) to the Financial Services Authority accompanied by a statement signed by the director overseeing the Bank's compliance function and the director responsible for Digital Services, referring to the Bank's Statement on the Implementation of Digital Services contained in Appendix II, which is an integral part of this Financial Services Authority Regulation. (3) The submission of license applications as referred to in paragraph (1) must be accompanied by the results of examination from an independent party to provide opinions on:
a. product characteristics; b. the adequacy of IT system security related to the product; and
c. compliance with statutory regulations in Indonesia, and/or practices or standards applicable nationally or internationally.
(4) The results of examination from independent parties as referred to in paragraph (3) are conducted by:
a. independent parties outside the Bank, for Digital Services newly issued by the Bank for the first time; and b. independent parties within the Bank, for adding features to existing Digital Services that can increase or increase risk exposure. (5) Banks submit license applications as referred to in paragraph (1) online through the integrated licensing and registration system of the Financial Services Authority. (6) In the event that the submission facility as referred to in paragraph (5) is not yet available, submission is conducted through the Financial Services Authority reporting system for unstructured reports to:
a. the relevant Bank Supervision Department or Financial Services Authority Office in Jakarta, for Banks headquartered in the Special Capital Region of Jakarta or Banten Province; or b. the local Financial Services Authority Office, for Banks headquartered outside the Special Capital Region of Jakarta or Banten Province.
Fourth Section
Cooperation in the Implementation of Digital Services
Article 14
(1) Bank partners as referred to in Article 2 paragraph (1) letter b in cooperation for the implementation of Digital Services can be LJKs or non-LJKs.
(2) Banks must ensure that Bank partners as referred to in paragraph (1) who are IT-based financial service providers have obtained licenses from the Financial Services Authority or other authorized authorities in accordance with statutory regulations.
Article 15
In conducting cooperation with Bank partners as referred to in Article 14 paragraph (1), Banks may open access to customer and/or prospective customer data and/or information to Bank partners based on approval and for the benefit of customers and/or prospective customers through a system or application, while considering statutory regulations concerning personal data protection.
Article 16
(1) Banks as referred to in Article 2 paragraph (1) letter b in implementing Digital Services must have:
a. policies and procedures in determining Bank partners; and b. written cooperation agreements with Bank partners drafted using the Indonesian language.
(2) Policies and procedures in determining Bank partners as referred to in paragraph (1) letter a must contain at least:
a. criteria for Bank partners; b. due diligence processes for prospective Bank partners;
c. selection processes for prospective Bank partners;
d. procedures for establishing cooperative relationships with Bank partners; e. risk management processes in cooperative relationships with Bank partners, including customer data protection aspects in the data exchange process with Bank partners; and f. procedures for terminating cooperative relationships with Bank partners, including mechanisms for deleting previously exchanged customer data. (3) Written cooperation agreements as referred to in paragraph (1) letter b must contain at least:
a. rights and obligations; b. scope of services and products offered;
c. duration of cooperation and renewal mechanisms;
d. utilization of customer data in accordance with statutory regulations concerning personal data protection; e. reciprocal principles in the utilization of customer data; f. responsibility for customer data security; g. clauses stating that the Bank does not bear or jointly bear risks arising from products and/or services offered by Bank partners through Digital Services; h. conditions and procedures for changing cooperation agreements;
i. imposition of sanctions and sanction mechanisms;
j. conditions and procedures for terminating cooperation agreements, including mechanisms for deleting previously exchanged customer data in accordance with customer approval; and k. procedures for dispute resolution. (4) Banks are prohibited from providing access to products and/or services owned by Bank partners other than those listed in the cooperation agreement as referred to in paragraph (1) letter b.
Article 17
(1) Banks are prohibited from bearing or jointly bearing risks arising from products and/or services owned by Bank partners in implementing Digital Services by Banks based on cooperation agreements between Banks and Bank partners. (2) The use of Bank logos and/or attributes in marketing documents is only intended to show cooperation between Banks and Bank partners in accordance with cooperation agreement documents.
Fifth Section
Units and Functions Handling the Implementation of Digital Services
Article 18
(1) Banks implementing Digital Services must form units or functions tasked with handling the implementation of Digital Services.
(2) Units or functions handling the implementation of Digital Services as referred to in paragraph (1) have at least the following tasks:
a. formulating policies, standards, and procedures for the implementation of Digital Services; b. ensuring the relevance between the implementation of Digital Services and the Bank's strategic business plan;
c. monitoring the implementation of cooperation with Bank partners in the implementation of Digital Services;
d. monitoring Digital Services financial transaction data; e. ensuring the effectiveness of steps used in implementing Digital Services; f. monitoring obstacles and problems arising from the implementation of Digital Services; and g. ensuring the adequacy and allocation of resources related to Digital Services owned by the Bank.
Article 19
(1) Banks violating provisions as referred to in Article 5 paragraph (1), paragraph (6), paragraph (7), Article 7 paragraph (2), Article 8, Article 9 paragraph (1), Article 14 paragraph (2), Article 16, Article 17 paragraph (1), and/or Article 18 paragraph (1), are subject to administrative sanctions in the form of written reprimands. (2) In the event that Banks have been subject to administrative sanctions as referred to in paragraph (1) and continue to violate provisions as referred to in Article 5 paragraph (1), paragraph (6), paragraph (7), Article 7 paragraph (2), Article 8, Article 9 paragraph (1), Article 14 paragraph (2), Article 16, Article 17 paragraph (1), and/or Article 18 paragraph (1), Banks are subject to administrative sanctions in the form of:
a. suspension of specific Digital Services; b. prohibition on implementing new Digital Services; and/or
c. downgrade of the Bank's health level.
CHAPTER III
UTILIZATION OF INFORMATION TECHNOLOGY
First Section
General
Article 20
(1) Banks implementing Digital Services must apply IT implementation provisions in accordance with the Financial Services Authority Regulation concerning IT implementation by Banks. (2) Banks that do not fulfill obligations as referred to in paragraph (1) are subject to administrative sanctions in accordance with the Financial Services Authority Regulation concerning IT implementation by Banks.
Article 21
(1) Banks must apply data and transaction security control principles for customers from Digital Services on every electronic system used by the Bank.
(2) The application of data and transaction security control principles for customers as referred to in paragraph (1) must include at least the principles of:
a. confidentiality; b. integrity;
c. availability;
d. authentication; e. non-repudiation; f. authorization control in systems, databases, and applications; g. separation of duties and responsibilities; h. audit trail maintenance; and
i. data retention, including deletion and destruction.
Second Section
Electronic Signatures
Article 22
(1) Banks may utilize the use of electronic signatures in the implementation of Digital Services in accordance with statutory regulations.
(2) In the event that Banks utilize the use of electronic signatures in the implementation of Digital Services, Banks must have policies and procedures for the use of electronic signatures. (3) Policies and procedures for the use of electronic signatures as referred to in paragraph (2) must contain at least:
a. identification and classification of documents and/or transactions that can use electronic signatures; b. procedures for use including verification of electronic signatures; and
c. risk management processes for the use of electronic signatures.
Third Section
Adoption of IT to Support Bank Business Functions
Article 23
(1) Banks conduct IT adoption in the implementation of Digital Services responsibly.
(2) The implementation of IT adoption as referred to in paragraph (1) must consider at least:
a. cyber resilience; b. cybersecurity;
c. transparency;
d. interoperability; e. capability in conducting audits; f. equality; and g. privacy.
Article 24
(1) Banks violating provisions as referred to in Article 21, Article 22 paragraph (2), and/or paragraph (3), are subject to administrative sanctions in the form of written reprimands. (2) In the event that Banks have been subject to administrative sanctions as referred to in paragraph (1) and continue to violate provisions as referred to in Article 21, Article 22 paragraph (2), and/or paragraph (3), Banks are subject to administrative sanctions in the form of:
a. suspension of specific Digital Services; b. prohibition on implementing new Digital Services; and/or
c. downgrade of the Bank's health level.
CHAPTER IV
CUSTOMER PROTECTION AND PERSONAL DATA PROTECTION First Section Customer Protection
Article 25
(1) Digital Service implementing Banks apply consumer protection principles in accordance with statutory regulations concerning consumer and public protection in the financial services sector. (2) Mechanisms and procedures for applying consumer protection principles as referred to in paragraph (1) are carried out in accordance with the Financial Services Authority Regulation concerning consumer and public protection in the financial services sector.
Article 26
Digital Service implementing Banks must have functions and mechanisms capable of responding to questions and/or following up on customer complaints operating 24 (twenty-four) hours a day.
Article 27
Banks must explain to customers the purpose of the use of Bank logos and/or attributes by Bank partners as referred to in Article 17 paragraph (2).
Article 28
Banks must provide education to customers to apply adequate authentication factors.
Second Section
Personal Data Protection
Article 29
(1) Digital Service implementing Banks must apply personal data protection principles in processing personal data in accordance with statutory regulations concerning personal data protection. (2) In processing personal data, Banks must first obtain approval from customers and/or prospective customers for specific purposes as the basis for processing personal data, conducted in accordance with statutory regulations concerning personal data protection. (3) Banks in providing Digital Services must provide features for customers to manage access rights of Bank partners to customer data and information independently.
Article 30
(1) Banks violating provisions as referred to in Article 26, Article 27, Article 28, and/or Article 29, are subject to administrative sanctions in the form of written reprimands. (2) In the event that Banks have been subject to administrative sanctions as referred to in paragraph (1) and continue to violate provisions as referred to in Article 26, Article 27, Article 28, and/or Article 29, Banks are subject to administrative sanctions in the form of:
a. suspension of specific Digital Services; b. prohibition on implementing new Digital Services; and/or
c. downgrade of the Bank's health level.
CHAPTER V
REPORTING
Article 31
Banks must submit lists of Bank partners in conducting Digital Services cooperation as referred to in Article 14 paragraph (1) to the Financial Services Authority as part of the report on the current condition of the Bank's IT implementation.
Article 32
(1) Banks that have obtained licenses to implement Digital Services meeting the criteria for new products must submit reports on the implementation of Digital Services to the Financial Services Authority at the latest 5 (five) working days after implementation accompanied by supporting documents, referring to the Report on the Implementation of Digital Services document contained in Appendix III, which is an integral part of this Financial Services Authority Regulation. (2) Banks must submit reports on the evaluation of the implementation of Digital Services meeting the criteria for new products to the Financial Services Authority at the latest 3 (three) months after implementation, referring to the Report on the Evaluation of Digital Services Implementation document contained in Appendix IV, which is an integral part of this Financial Services Authority Regulation.
Article 33
(1) Banks submit reports on the realization of Digital Services as referred to in Article 32 paragraph (1) online through the integrated licensing and registration system of the Financial Services Authority. (2) In the event that the submission medium as referred to in paragraph (1) is not yet available, submission is conducted through the Financial Services Authority reporting system for unstructured reports addressed to:
a. The Relevant Bank Supervision Department or the Financial Services Authority Office in Jakarta, for Banks headquartered in the Special Capital Region of Jakarta province or Banten province; or b. The local Financial Services Authority Office, for Banks headquartered outside the Special Capital Region of Jakarta province or Banten province.
Article 34
(1) Banks submit reports on the evaluation of Digital Services implementation as referred to in Article 32 paragraph (2) as unstructured reports online through the Financial Services Authority reporting system. (2) The procedure for submitting reports as referred to in paragraph (1) is carried out in accordance with the Financial Services Authority Regulation regarding bank reporting through the Financial Services Authority reporting system. (3) Submission of reports as referred to in paragraph (1) is addressed to:
a. The Relevant Bank Supervision Department or the Financial Services Authority Office in Jakarta, for Banks headquartered in the Special Capital Region of Jakarta province or Banten province; or b. The local Financial Services Authority Office, for Banks headquartered outside the Special Capital Region of Jakarta province or Banten province.
Article 35
Banks that are late in submitting realization reports as referred to in Article 32 paragraph (1) are subject to administrative sanctions in accordance with the Financial Services Authority Regulation regarding the implementation of general bank products.
Article 36
(1) Banks that are late in submitting evaluation reports as referred to in Article 32 paragraph (2) are subject to administrative sanctions in the form of fines of IDR 1,000,000.00 (one million rupiah) per working day of delay per report and a maximum of IDR 50,000,000.00 (fifty million rupiah) per report. (2) The imposition of administrative sanctions as referred to in paragraph (1) does not eliminate the obligation to submit reports for Banks that have not yet submitted reports as referred to in Article 32 paragraph (2). (3) Banks that submit reports as referred to in Article 32 paragraph (2), but:
a. are assessed as incomplete; and/or b. are not accompanied by material documents and information, in accordance with the specified format, are subject to administrative sanctions in the form of written warnings. (4) Banks that do not correct evaluation reports within the time limit specified in the written warning as referred to in paragraph (3) are subject to administrative sanctions in the form of a fine of IDR 50,000,000.00 (fifty million rupiah).
CHAPTER VI
TRANSITIONAL PROVISIONS
Article 37
(1) Banks that have electronic banking services and digital banking services prior to the implementation of this Financial Services Authority Regulation must adjust their IT infrastructure in Digital Services in accordance with the provisions in this Financial Services Authority Regulation within a maximum of 1 (one) year from the implementation of this Financial Services Authority Regulation. (2) Banks must adjust policies, standards, and procedures related to the implementation of Digital Services in accordance with the provisions in this Financial Services Authority Regulation within a maximum of 3 (three) months from the implementation of this Financial Services Authority Regulation.
Article 38
The process for requesting licenses for the implementation of electronic banking services and digital banking services that are being applied for prior to the implementation of this Financial Services Authority Regulation shall continue to be carried out in accordance with the Financial Services Authority Regulation Number 12/POJK.03/2018 concerning the Implementation of Digital Banking Services by General Banks (State Gazette of the Republic of Indonesia Year 2018 Number 127, Supplement to the State Gazette of the Republic of Indonesia Number 6235) and the Financial Services Authority Regulation Number 13/POJK.03/2021 concerning the Implementation of General Bank Products (State Gazette of the Republic of Indonesia Year 2021 Number 164, Supplement to the State Gazette of the Republic of Indonesia Number 6701).
CHAPTER VII
CLOSING PROVISIONS
Article 39
Upon the implementation of this Financial Services Authority Regulation, the Financial Services Authority Regulation Number 12/POJK.03/2018 concerning the Implementation of Digital Banking Services by General Banks (State Gazette of the Republic of Indonesia Year 2018 Number 127, Supplement to the State Gazette of the Republic of Indonesia Number 6235) is revoked and declared invalid.
Article 40
This Financial Services Authority Regulation comes into force on the date of enactment.
A copy of this is in accordance with the original Legal Director 1 Legal Department Mufli Asmawidjaja
So that everyone knows, ordering the enactment of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia. Established in Jakarta on 19 December 2023 CHAIRMAN OF THE COMMISSIONERS FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA, MAHENDRA SIREGAR
Enacted in Jakarta on 22 December 2023
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA,
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2023 NUMBER 39/OJK signed
EXPLANATION
OF
FINANCIAL SERVICES AUTHABILITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 21 OF 2023
CONCERNING
DIGITAL SERVICES BY GENERAL BANKS
I. GENERAL
Rapid IT development has brought society's life into a new era, namely the digital era, characterized by the development of various new technology innovations. Technology innovation triggers structural changes in all economic fields, including banking. Digital transformation has become a necessity for Banks to remain competitive in order to meet the evolving demands of consumers.
Significant changes in the banking industry as a result of IT development can generally be identified in 4 (four) aspects, namely changes in consumer expectations, increased quality of banking products and services through data utilization, the emergence of new partnerships with IT-based companies, and changes in operational models to digital business models.
Consumers expect banking services that can be obtained quickly and securely. This consumer behavior requires banks to continuously innovate in creating products and services that prioritize consumer needs (customer-centric).
In providing services to consumers, banks also need to partner with Financial Institution Providers (LJK) and non-LJK, including digital business actors, to increase collaboration in developing an integrated digital ecosystem.
Generally, banks have developed electronic banking services, including through mobile banking, which allows banking transactions to be conducted without spatial and temporal limitations. Furthermore, banks have also developed digital services, including self-service bank account opening, which can be done through distribution channels owned by the Bank, such as internet banking or mobile banking, supported by data utilization, so that the bank account opening process can be done more quickly. However, with the need for more comprehensive services in one device, there is a need for banks to innovate in digital products and services supported by the adoption of new technologies.
In accordance with the mandate in Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector, in the utilization of IT, Banks can cooperate to open access to customer data and information to other financial providers, including financial technology innovation providers, based on customer consent and for the benefit of customers. The implementation of such cooperation drives digital transformation and builds interlinkages between Banks and financial technology innovations to support openness, interoperability, security, flexibility, consumer protection, independence, and novelty.
In addition to bringing opportunities that can be utilized by the banking industry, digital transformation also presents challenges and risks that need to be guarded against. These challenges include personal data protection, risks related to data leaks, risks related to technology investments that do not align with business strategies, risks related to misunderstandings in cooperation with Bank partners, risks related to the misuse of new technologies, and risks related to cybersecurity. These challenges need to be proactively mitigated by Banks, including by increasing maturity in all aspects related to IT implementation, so that more comprehensive digital services can provide added value for Banks and customers to support the business objectives of Banks. In this regard, it is necessary to formulate regulations regarding digital services by general banks.
II. ARTICLE BY ARTICLE
Article 1
Clear enough.
Article 2
Paragraph (1)
Letter a
IT implementation related to Digital Services implemented by Banks can be done by Banks independently and/or using IT service providers, as referred to in the Financial Services Authority Regulation regarding IT implementation by Banks.
Letter b
What is meant by “Banks with Bank partners based on cooperation agreements” are Digital Services implemented by Banks in cooperation with Bank partners.
Examples of Digital Services implemented by Banks in cooperation with Bank partners based on cooperation agreements are Bank customers can access applications and/or websites owned by Bank partners that are integrated with the Bank's mobile banking application, so that Bank customers can make purchases of products owned by Bank partners through the Bank's application.
Cooperation in the form of IT service provision in the implementation of Digital Services, whether by Bank partners to Banks or by Banks to Bank partners, is not included as Digital Services.
Example:
The use of switching services and application programming interfaces (API) provided by Bank partners as IT service providers.
Paragraph (2)
Regulatory provisions include, among others, Laws regarding banking and Financial Services Authority Regulations regarding the implementation of general bank products.
Article 3
To assess the Bank's IT infrastructure and infrastructure management management capable of supporting the optimal implementation of Digital Services, reference is made to parameters in the Bank's digital maturity assessment (DMAB) and parameters related to the implementation of IT in accordance with the Financial Services Authority Regulation regarding IT implementation by Banks.
Article 4
Public information provided to customers includes, among others, instant messages offering Bank products and public information, without any transactions and/or access to customer accounts.
Communication with customers includes, among others, Bank contact centers and chatbots to receive customer complaints or reports, without any transactions and/or access to customer accounts.
Article 5
Paragraph (1)
Clear enough.
Paragraph (2)
Clear enough.
Paragraph (3)
Letter a
What is meant by “direct face-to-face meeting” is Bank employees conducting direct/physical face-to-face meetings with customers or prospective customers.
Letter b
Clear enough.
Letter c
Clear enough.
Paragraph (4)
Clear enough.
Paragraph (5)
Clear enough.
Paragraph (6)
Authentication factors include:
a. something you know (something you know), something known only by customers and/or prospective customers, such as usernames, passwords, personal identification numbers/PINs, mothers' maiden names, or other comparable forms; b. something you have (something you have), identity documents owned by customers and/or prospective customers accompanied by other things, such as one-time passwords/OTPs, electronic signatures, or other comparable forms; and
c. something you are (something you are) inherent and unique to each person, such as face recognition, fingerprints, and iris/retina.
In addition to the authentication factors as referred to in letters a through c, Banks may consider other authentication factors.
Paragraph (7)
Clear enough.
Article 6
Paragraph (1)
Authorized institutions or agencies include, among others, the Ministry of Home Affairs, the Ministry of Law and Human Rights, the Ministry of Finance, the Ministry of Communication and Information Technology, the Ministry of Education and Culture, the Ministry of Social Affairs, and the National Police of the Republic of Indonesia.
Examples of other sources: telecommunications companies and other data providers, whose data accuracy can be justified.
Paragraph (2)
Supporting infrastructure in the utilization of data and/or information includes, among others, cooperation agreements and the availability of necessary hardware and software.
Article 7
Clear enough.
Article 8
The suitability of data and/or information utilized is carried out through, among others, direct recording, verification against data sources, and techniques that can provide assurance to Banks.
Data and/or information that can be utilized includes, among others, biometrics such as face recognition, fingerprints, and iris/retina, and electronic instruments such as hard tokens and soft tokens.
Article 9
Paragraph (1)
Clear enough.
Paragraph (2)
Customer consent in the processing of financial transactions aims to ensure that customers understand the risks.
Example:
Customers register their mobile devices and then enter a password (two-factor authentication) to approve transactions to be conducted, so that, for example, every transaction under IDR 500,000.00 (five hundred thousand rupiah) does not need to enter a password again. The setting of transaction limits is based on the Bank's risk analysis and prior customer consent.
Article 10
Customer involvement in the development of Digital Services aims to ensure that Digital Services implemented by Banks can meet customer needs and expectations, thereby having a positive impact on the sustainability of the Bank's Digital Services.
Examples of customer involvement in the development of Digital Services:
Article 11
What is meant by "basic Bank products" is basic bank products in accordance with the Financial Services Authority Regulation regarding the implementation of general bank products.
Digital Services whose licensing is fully regulated by the Indonesian payment system authority include, among others, Quick Response Code Indonesian Standard (QRIS) and e-wallets.
Examples:
Article 12
What is meant by "new product criteria" is new product criteria in accordance with the Financial Services Authority Regulation regarding the implementation of general bank products.
Article 13
Paragraph (1)
Clear enough.
Paragraph (2)
Clear enough.
Paragraph (3)
Clear enough.
Paragraph (4)
Letter a
Independent parties outside Banks include, among others, consultants in the field of information technology security.
Examples of new Digital Services first issued by Banks include internet banking that is transactional, both financial transactions such as transfers, payments, and purchases, and non-financial transactions such as balance inquiries and statements.
Letter b
What is meant by “independent parties within Banks” are internal Bank parties who do not participate in the design and development of application systems and decision-making in the implementation of Digital Services.
Paragraph (5)
Clear enough.
Paragraph (6)
Clear enough.
Article 14
Paragraph (1)
Cooperation between Banks and Bank partners, whether Financial Institution Providers (LJK) or non-LJK, is intended to build collaboration and ecosystems that support the development of services to customers.
Paragraph (2)
Clear enough.
Article 15
What is meant by "consent" is consent from customers or prospective customers that can be proven by Banks.
Article 16
Paragraph (1)
Clear enough.
Paragraph (2)
Clear enough.
Paragraph (3)
Letter a
Clear enough.
Letter b
Clear enough.
Letter c
Clear enough.
Letter d
Clear enough.
Letter e
Clear enough.
Letter f
Clear enough.
Letter g
Clauses are required when customers access products and/or services owned by Bank partners in the implementation of Digital Services.
Letter h
Clear enough.
Letter i
Clear enough.
Letter j
Clear enough.
Letter k
Clear enough.
Paragraph (4)
Clear enough.
Article 17
Paragraph (1)
Risks arising from products and/or services owned by Bank partners related to Digital Services include, among others:
Paragraph (2)
Clear enough.
Article 18
Paragraph (1)
Functions tasked with handling the implementation of Digital Services can be carried out by existing work units or work units related to Bank operations, in accordance with the complexity of Bank business.
Paragraph (2)
Letter a
Clear enough.
Letter b
Clear enough.
Letter c
Clear enough.
Letter d
Monitoring of Digital Services financial transaction data includes, among others, monitoring of transaction nominal values, transaction types, transaction frequencies, and obstacles occurring in transactions according to monitoring period groups.
Letter e
This task is performed so that the Bank's investment in the implementation and development of Digital Services contributes significantly to achieving the Bank's business objectives.
Letter f
Clear enough.
Letter g
Clear enough.
Article 19
Clear enough.
Article 20
Clear enough.
Article 21
Paragraph (1)
What is meant by “electronic systems” is electronic systems in accordance with the Financial Services Authority Regulation regarding IT implementation by Banks.
Paragraph (2)
Letter a
Clear enough.
Letter b
Clear enough.
Letter c
Clear enough.
Letter d
Clear enough.
Letter e
Irrefutably known by the term nonrepudiation.
Letter f
Clear enough.
Letter g
Clear enough.
Letter h
Clear enough.
Letter i
Clear enough.
Article 22
Paragraph (1)
Regulatory provisions include, among others:
Paragraph (2)
Clear enough.
Paragraph (3)
Letter a
Example:
Bank “JALAR” classifies certain documents that can use electronic signatures, such as the use of certified electronic signatures on loan agreement documents with certain credit limit caps.
Letter b
Clear enough.
Letter c
Clear enough.
Article 23
Paragraph (1)
The application of responsible IT adoption in accordance with Financial Services Authority regulations regarding Bank digital maturity assessments.
Example of IT adoption implementation: substitution of functions at Bank “JALAR” previously performed by humans and then replaced by using artificial intelligence.
Paragraph (2)
Letter a
What is meant by “cyber resilience” is the Bank's ability to maintain business continuity by taking anticipatory, adaptive, and proactive actions against cyber threats.
Letter b
What is meant by “cybersecurity” is the condition of maintaining the confidentiality, integrity, and availability of information and/or interconnected information systems through cyber media, from cyber attacks.
Letter c
What is meant by “transparency” is the clear disclosure of information to stakeholders regarding IT adoption.
Letter d
What is meant by “interoperability” is the ability of IT systems to connect and exchange information.
Letter e
What is meant by “audit execution capability” is the review of all activities related to IT adoption.
Letter f
What is meant by “equity” is the use of IT and/or data processing that can provide fair results for all individuals.
Letter g
What is meant by “privacy” is personal data security referring to regulatory provisions regarding personal data protection.
Article 24
Clear enough.
Article 25
Paragraph (1)
In applying consumer protection principles, Banks can develop various features, including to facilitate consumers with disabilities.
Paragraph (2)
Clear enough.
Article 26
Functions and mechanisms for handling that can respond to questions and/or follow up on customer complaints can be facilitated through media such as telephones and chatbots.
Functions and handling mechanisms operate every day, including on holidays.
Article 27
Bank explanations are a form of transparency to customers and can be in the form of oral or written explanations.
Article 28
Education for customers regarding the adequate application of authentication factors includes, among others, educating customers to periodically change passwords.
Article 29
Paragraph (1)
Clear enough.
Paragraph (2)
Examples of specific purposes as a basis for processing personal data include, among others, the use of customer data to provide personalized services.
Paragraph (3)
Managing Bank partner access rights, including withdrawing customer data processing consent, which can be done independently by customers.
Article 30
Clear enough.
Article 31
Reports on the current condition of Bank IT implementation in accordance with the Financial Services Authority Regulation regarding IT implementation by Banks.
Article 32
See the explanation of Article 12.
Article 33
Clear enough.
Article 34
Clear enough.
Article 35
Clear enough.
Article 36
Clear enough.
Article 37
Clear enough.
Article 38
Clear enough.
Article 39
Clear enough.
Article 40
Clear enough.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 61/OJK
APPENDIX I
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 21 YEAR 2023
ON
DIGITAL SERVICES BY COMMERCIAL BANKS
APPLICATION FOR LICENSE TO CONDUCT
DIGITAL SERVICES
Digital Service Implementation License Application Document A. GENERAL INFORMATION
This copy is consistent with the original
Legal Director 1
Legal Department
Mufli Asmawidjaja b. Explanation of whether the Digital Service product is a product that did not previously exist at the Bank or is a development/addition of features from existing products.
3) Readiness and limited test results must be submitted in the event that the Digital Service is conducted with a license application process through a limited test project.
4) Examples of detailed specifications of authentication factors:
a. Factor something you know in the form of a password, specifications in the form of password length and complexity. b. Factor something you have in the form of device identification/device ID, specifications in the form of algorithms or types of information used to show device uniqueness.
c. Factor something you are in the form of face recognition, specifications in the form of confidence threshold.
5) Description of the cooperation mechanism is submitted in the event that the Digital Service is conducted by the Bank with Bank partners.
6) Supporting documents include, among others, documents on transparency to customers, agreements, approvals from relevant authorities or copies of proof of approval or licenses from relevant authorities, and documents required in the proof of concept process for test projects. For Sharia commercial banks and Sharia business units, the concept of contracts/agreements/application forms is attached with an opinion from the work unit specializing in law stating that the concept of contracts/agreements/application forms is in accordance with regulations.
Determined in Jakarta on December 19, 2023
CHAIRMAN OF THE COMMISSIONER COUNCIL
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA,
MAHENDRA SIREGAR signed signed
APPENDIX II
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 21 YEAR 2023
ON
DIGITAL SERVICES BY COMMERCIAL BANKS
BANK STATEMENT ON THE CONDUCT OF
DIGITAL SERVICES
We, the undersigned below, Compliance Director and Director …………………… from:
Bank Name : ...............................................
Address : ...............................................
Telephone Number : ...............................................
in the context of conducting Digital Services:
Name of Digital Service : ...............................................
hereby state truthfully that:
This copy is consistent with the original
Legal Director 1
Legal Department
Mufli Asmawidjaja
Notes:
This copy is consistent with the original
Legal Director 1
Legal Department
Mufli Asmawidjaja
APPENDIX III
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 21 YEAR 2023
ON
DIGITAL SERVICES BY COMMERCIAL BANKS
IMPLEMENTATION REPORT
OF DIGITAL SERVICE CONDUCT
A. GENERAL INFORMATION
APPENDIX IV
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 21 YEAR 2023
ON
DIGITAL SERVICES BY COMMERCIAL BANKS
EVALUATION REPORT
OF DIGITAL SERVICE CONDUCT
A. GENERAL INFORMATION
This copy is consistent with the original
Legal Director 1
Legal Department
Mufli Asmawidjaja d. readiness of human resources and organizational infrastructure, including built-in controls from management.
3) In the event that the Digital Service is conducted by the Bank with Bank partners.
Determined in Jakarta on December 19, 2023
CHAIRMAN OF THE COMMISSIONER COUNCIL
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA,
MAHENDRA SIREGAR signed signed
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.