2024-02-19 | POJK 3 Tahun 2024Added
Financial Services Authority Regulation Number 3 of 2024 establishes the regulatory framework for Financial Sector Technology Innovation (ITSK), replacing previous digital financial innovation rules. It defines participants as financial service institutions or other entities, mandating adherence to governance, risk management, and consumer protection principles. The regulation introduces a Sandbox mechanism allowing limited testing of innovations for up to one year, with outcomes determining eligibility for full business licenses or mandatory exit within three months. Administrative sanctions, including written warnings, suspension of activities, and license revocation, are imposed for non-compliance with testing, reporting, or association membership requirements.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA
COPY
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 3 OF 2024
CONCERNING
THE IMPLEMENTATION OF FINANCIAL SECTOR TECHNOLOGY INNOVATION BY THE GRACE OF GOD THE ALMIGHTY, THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering:
a. that in order to implement the regulatory and supervisory authority as referred to in Article 216 paragraph (1) of Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector, the Financial Services Authority is authorized to regulate financial sector technology innovation; b. that the provisions regarding digital financial innovation as regulated in Financial Services Authority Regulation Number 13/POJK.02/2018 concerning Digital Financial Innovation in the Financial Services Sector are no longer suitable for current needs and therefore need to be amended;
c. that based on the considerations referred to in letters a and b, it is necessary to establish a Financial Services Authority Regulation concerning the Implementation of Financial Sector Technology Innovation;
Recalling:
DECIDING:
To establish: FINANCIAL SERVICES AUTHORITY REGULATION CONCERNING THE IMPLEMENTATION OF FINANCIAL SECTOR TECHNOLOGY INNOVATION.
CHAPTER I
GENERAL PROVISIONS
Article 1
In this Financial Services Authority Regulation, the following terms are defined as:
CHAPTER II
IMPLEMENTATION OF ITSK
Article 2
The scope of ITSK includes:
a. settlement of securities transactions; b. capital mobilization;
c. investment management;
d. risk management; e. collection and/or disbursement of funds; f. market support; g. activities related to digital financial assets, including crypto assets; and h. other digital financial service activities.
Article 3
(1) Parties implementing ITSK consist of:
a. LJK; and/or b. other parties carrying out activities in the financial sector in accordance with statutory provisions.
(2) ITSK Implementers take the form of:
a. a limited liability company legal entity; or b. other legal entities in accordance with statutory provisions.
(3) ITSK Implementers as referred to in paragraph (1) must apply principles of:
a. governance; b. risk management;
c. information system security and reliability, including cyber resilience;
d. Consumer Protection and personal data protection; and e. compliance with statutory provisions.
Article 4
(1) ITSK Implementers as referred to in Article 3 paragraph (1) are required to fulfill licensing provisions regulated by the Financial Services Authority. (2) The Financial Services Authority conducts regulation and supervision of ITSK implementation in accordance with the Financial Services Authority's scope of authority. (3) Regulation and supervision of ITSK implementation as referred to in paragraph (2) is conducted with the principles of:
a. balance between efforts to encourage innovation and risk mitigation; b. integration of digital economy and finance;
c. efficiency and sound business practices;
d. Consumer Protection; and e. coordination of regulation and supervision among authorities.
(4) The scope of regulation and supervision of ITSK implementation as referred to in paragraph (2) covers:
a. provision of space and/or facilitation for testing/innovation development (sandbox); b. licensing;
c. monitoring and evaluation;
d. financial education; e. Consumer Protection; f. Consumer personal data protection; g. institutional aspects; and h. implementation of ITSK, including activities conducted by third parties supporting ITSK implementation.
Article 5
(1) ITSK can be utilized to support economic and financial activities, including those conducted based on Sharia Principles.
(2) Economic and financial activities using ITSK based on Sharia Principles as referred to in paragraph (1) must follow Sharia Principles issued by institutions having the authority to issue fatwas in the Sharia field.
CHAPTER III
SANDBOX
Section One
Objectives and Scope of Sandbox
Article 6
The objective of providing Sandbox is to ensure that innovation and technology development in the financial sector are conducted responsibly with good risk management.
Article 7
The scope of Sandbox includes:
a. provision of facilities to conduct testing within a limited time frame and environment; b. provision of facilities to obtain explanations regarding applicable provisions in the financial services sector;
c. provision of facilities to develop ITSK in the early stages; and
d. provision of other facilities for the purpose of ITSK testing and development.
Section Two
Participants
Article 8
(1) Participants consist of:
a. LJK; and/or b. other parties intending to conduct activities in the financial sector in accordance with statutory provisions. (2) Participants take the form of:
a. a limited liability company legal entity; or b. other legal entities in accordance with statutory provisions.
(3) Participants as referred to in paragraph (1) must apply principles of:
a. governance; b. risk management;
c. information system security and reliability, including cyber resilience;
d. Consumer Protection and personal data protection; and e. compliance with statutory provisions.
Section Three
Application to Become a Participant
Article 9
(1) Prospective Participants intending to conduct activities within the scope referred to in Article 2 and wishing to participate in Sandbox must submit an application to become a Participant to the Financial Services Authority. (2) Prospective Participants who are LJK as referred to in Article 8 paragraph (1) letter a must obtain a recommendation from the relevant supervisor at the Financial Services Authority. (3) The Financial Services Authority is authorized to require parties implementing ITSK as referred to in Article 3 paragraph (1) to submit an application to become a Participant to the Financial Services Authority. (4) The application as referred to in paragraph (1) and paragraph (3) must be accompanied by a Sandbox participation application form, a Testing Plan, and supporting documents. (5) The Testing Plan as referred to in paragraph (4) must at least cover:
a. an explanation of the product, activity, service, and/or business model innovation to be tested and developed; b. identification of potential risks associated with the product, activity, service, and/or business model innovation to be tested and developed;
c. a risk mitigation implementation plan for the potential risks as referred to in letter b;
d. limitations on the implementation of testing and innovation development, including the required testing duration, target and profile of Consumers, number of Consumers, testing and development partners, number of transactions, and other measurable limitations; e. a Consumer Protection framework covering at least Consumer complaint services and compensation mechanisms; f. capital readiness and resources to conduct testing and innovation development; g. exit policy and transition policy if the tested and developed innovation cannot be continued after the Sandbox process; h. testing and development scenarios for products, activities, services, and/or business models to be tested and developed; and
i. key performance indicators for the testing and development scenarios as referred to in letter h.
(6) In the event that the Financial Services Authority's assessment requires improvements to the Testing Plan, the Participant must make the improvements and resubmit the improved Testing Plan to the Financial Services Authority. (7) Further provisions regarding the application to become a Participant are determined by the Financial Services Authority.
Section Four
Feasibility Criteria and Approval to Become a Participant
Article 10
(1) Feasibility criteria for innovation to participate in Sandbox include:
a. innovation with a scope within the financial services sector to be used by Consumers, partners, and/or the public in Indonesia; b. innovation that meets novelty elements and/or has significant differentiating elements from previous activities in the financial sector;
c. innovation that provides benefits, improves services, and adds value to Consumers, the public, and/or the financial sector ecosystem;
d. innovation that is ready for testing and development; e. innovation that requires testing and development support, and has not been previously regulated and supervised under existing financial sector provisions; and f. other criteria determined by the Financial Services Authority. (2) The Financial Services Authority grants approval or rejection of the application to become a Participant by considering the feasibility criteria as referred to in paragraph (1) and the Testing Plan as referred to in Article 9 paragraph (5), as well as other considerations from the Financial Services Authority. (3) Approval or rejection as referred to in paragraph (2) is conducted after the documents as referred to in Article 9 paragraph (4) are received in complete form. (4) Approval or rejection as referred to in paragraph (2) is communicated to the prospective Participant via a letter issued by the Financial Services Authority. (5) Approval to participate in Sandbox does not constitute a business license to conduct full operational business in the financial services sector. (6) Further provisions regarding feasibility criteria and approval to become a Participant are determined by the Financial Services Authority.
Section Five
Testing and Innovation Development Process
Article 11
(1) The testing and innovation development process in Sandbox begins from the time approval to become a Participant is granted by the Financial Services Authority as referred to in Article 10 paragraph (2). (2) Participants as referred to in paragraph (1) are required to conduct testing and innovation development in accordance with the Testing Plan submitted to the Financial Services Authority. (3) Participants as referred to in paragraph (1) are required to comply with provisions:
a. notifying the Financial Services Authority of any changes related to ITSK and the Participant; b. opening any information and/or documents related to Sandbox implementation to the Financial Services Authority; and
c. participating in any activities related to Sandbox implementation.
(4) Participants as referred to in paragraph (1) may:
a. participate in any coordination and cooperation with authorities, ministries, institutions, and other parties related to Sandbox implementation; and b. conduct coordination and/or cooperation with LJK and/or other parties related to Sandbox implementation under the coordination of the Financial Services Authority. (5) Participants as referred to in paragraph (1) are required to submit reports on the results of testing and innovation development as referred to in paragraph (2) periodically and/or at any time to the Financial Services Authority. (6) The Financial Services Authority monitors the reports submitted by Participants as referred to in paragraph (5). (7) Monitoring as referred to in paragraph (6) is conducted:
a. indirectly; b. directly; and/or
c. other monitoring methods.
(8) Further provisions regarding the submission of periodic and/or ad hoc reports on testing and innovation development results are determined by the Financial Services Authority.
Article 12
(1) Upon the Participant's request, the Financial Services Authority is authorized to grant temporary exemptions from certain Financial Services Authority regulations and provisions to Participants undergoing the Sandbox process. (2) Temporary exemptions as referred to in paragraph (1) may be conducted provided that:
a. the Participant is within the Sandbox; and b. approval is obtained from the relevant supervisory unit at the Financial Services Authority.
Section Six
Sandbox Duration and Final Report
Article 13
(1) Testing and innovation development in Sandbox is implemented for a maximum duration of 1 (one) year from the time approval is granted by the Financial Services Authority as referred to in Article 10 paragraph (2). (2) The Financial Services Authority is authorized to set a different testing and innovation development duration than that referred to in paragraph (1). (3) The Financial Services Authority is authorized to halt the testing and innovation development process before the duration referred to in paragraph (1) and paragraph (2) expires, if there is non-compliance with the criteria as referred to in Article 10 paragraph (1). (4) Participants are required to submit a final report on the implementation of testing and innovation development at least 20 (twenty) working days before the testing and innovation development duration referred to in paragraph (1) or paragraph (2) expires. (5) The final report as referred to in paragraph (4) must at least cover:
a. results of testing and development of the testing and innovation development scenarios as referred to in Article 9 paragraph (5) letter h; b. fulfillment of key performance indicators as referred to in Article 9 paragraph (5) letter i;
c. identification of failed testing and innovation development and incidents occurring during testing and development;
d. Participant's compliance assessment regarding statutory provisions; and e. the Participant's follow-up plan after the expiration of the testing and innovation development duration. (6) Further provisions regarding the final report on testing and innovation development implementation are determined by the Financial Services Authority.
Section Seven
Sandbox Results
Article 14
(1) The Financial Services Authority is authorized to evaluate and/or take follow-up action on Sandbox results.
(2) The Financial Services Authority declares Sandbox results as:
a. passed; or b. failed.
Article 15
(1) The Financial Services Authority issues a pass letter to Participants declared passed as referred to in Article 14 paragraph (2) letter a. (2) Participants declared passed as referred to in Article 14 paragraph (2) letter a must apply for a business license to the Financial Services Authority within the validity period of the pass letter. (3) The pass letter as referred to in paragraph (2) is valid for 6 (six) months and may be extended based on the Financial Services Authority's consideration. (4) Participants may still conduct limited operational business activities as within Sandbox limitations during the validity period of the pass letter as referred to in paragraph (3). (5) The pass letter as referred to in paragraph (1) does not constitute a business license to conduct full operational business in the financial services sector. (6) In the event that Participants as referred to in paragraph (2) do not submit a business license application as referred to in paragraph (2) until the pass letter validity period expires and is not extended by the Financial Services Authority, the pass status automatically ends and is declared invalid. (7) If the validity period of the pass letter as referred to in paragraph (3) has expired, and the Participant has not applied for a business license to the Financial Services Authority, the Participant is required to:
a. cease operational business activities, product innovations, activities, and services using the business model tested and developed in the Sandbox; b. settle all obligations to Consumers and other parties; and
c. implement the exit policy stated in the Testing Plan as referred to in Article 9 paragraph (5) letter g,
within a maximum of 3 (three) months from the expiration of the pass letter validity.
Article 16
(1) The Financial Services Authority may determine that Participants who passed as referred to in Article 14 paragraph (2) letter a may register before applying for a business license based on considerations made by the Financial Services Authority. (2) Participants as referred to in paragraph (1) are required to submit documents at least regarding aspects:
a. institutional and governance; b. business model;
c. information technology; and
d. partnerships.
(3) Parties having the same type of ITSK as the ITSK type of Participants as referred to in paragraph (1) have the same right to submit registration applications to the Financial Services Authority. (4) Provisions regarding the registration mechanism are determined by the Financial Services Authority.
Article 17
(1) The Financial Services Authority issues a fail letter to Participants as referred to in Article 14 paragraph (2) letter b.
(2) Participants declared failed as referred to in paragraph (1) are required to:
a. cease operational business activities, product innovations, activities, and services using the business model tested and developed in the Sandbox; b. settle all obligations to Consumers and other parties; and
c. implement the exit policy stated in the Testing Plan as referred to in Article 9 paragraph (5) letter g,
within a maximum of 3 (three) months from the time the fail letter is issued by the Financial Services Authority.
Article 18
In the event that testing and innovation development results show a connection to the authority of other regulators, the Financial Services Authority coordinates with those authorities.
Article 19
(1) Violations of provisions as referred to in Article 11 paragraph (2), paragraph (3), paragraph (5), Article 13 paragraph (4), Article 15 paragraph (7), Article 16 paragraph (2), and/or Article 17 paragraph (2) are subject to administrative sanctions in the form of:
a. written warnings; b. temporary suspension, partial, or full cessation of activities including cooperation implementation; and/or
c. cancellation of approval.
(2) Administrative sanctions as referred to in paragraph (1) letters b and c may be imposed with or without prior imposition of administrative sanctions in the form of written warnings as referred to in paragraph (1) letter a.
CHAPTER IV
LICENSING
Article 20
(1) Parties having the same type of ITSK as the ITSK type of Participants as referred to in Article 15 paragraph (2) have the same right to apply for business licenses to the Financial Services Authority. (2) The Financial Services Authority issues business license letters to Participants as referred to in paragraph (1) and Article 15 paragraph (2) who have completed the licensing process. (3) The business licensing process follows Financial Services Authority Regulations regarding licensing and supervision of each type of ITSK.
CHAPTER V
ASSOCIATIONS
Article 21
(1) To support the implementation of ITSK, the Financial Services Authority is authorized to appoint and establish associations of ITSK Implementers. (2) Every ITSK Implementer that has been registered and/or obtained a business license is required to become a member of the ITSK Implementer association established by the Financial Services Authority. (3) Every ITSK Implementer that has been registered and/or obtained a business license and has become a member of the ITSK Implementer association is required to comply with membership provisions in the ITSK Implementer association. (4) In carrying out its duties and functions, the ITSK Implementer association refers to provisions determined by the Financial Services Authority. (5) Further provisions regarding ITSK Implementer associations are determined by the Financial Services Authority.
Article 22
(1) Violations of provisions as referred to in Article 21 paragraph (2) and/or paragraph (3) are subject to administrative sanctions in the form of:
a. written warnings; b. temporary suspension, partial, or full cessation of activities including cooperation implementation;
c. cancellation of approval;
d. cancellation of registration; and/or e. revocation of licenses.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without prior imposition of administrative sanctions in the form of written warnings as referred to in paragraph (1) letter a.
CHAPTER VI
SUPERVISION, EVALUATION, AND MONITORING
Section One
Supervision by the Financial Services Authority
Article 23
(1) The Financial Services Authority conducts supervision of ITSK Implementers that have been registered and/or obtained business licenses from the Financial Services Authority.
(2) Supervision as referred to in paragraph (1) includes indirect supervision and direct supervision.
(3) ITSK supervision covers the following principles:
a. risk-based supervision; and b. market conduct supervision.
(4) The risk-based supervision principle as referred to in paragraph (3) letter a includes at least:
a. a balanced approach between prudential aspects and support for innovation; b. emphasis on reliable governance and risk management aspects in utilizing technology and controlling its digital ecosystem; and
c. the application of good processes regarding Customer identification, risk management, and operational supervision carried out by third parties.
(5) Market conduct supervision as referred to in paragraph (3) letter b is implemented in accordance with regulations regarding market conduct supervision.
Article 24
ITSK Providers who are registered and/or have obtained a business license must possess devices that can increase the efficiency and compliance of the supervision process conducted by the Financial Services Authority.
Article 25
(1) Violations of the provisions as referred to in Article 24 are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
Second Section
Self-Evaluation
Article 26
(1) ITSK Providers who have been registered and/or obtained a business license from the Financial Services Authority must implement self-evaluation.
(2) Self-evaluation as referred to in paragraph (1) includes at least:
a. information and communication technology governance principles in accordance with applicable laws and regulations; b. Consumer Protection in accordance with Financial Services Authority Regulations regarding consumer and community protection in the financial services sector;
c. education and socialization to Customers;
d. confidentiality of Customer data and/or information, including transaction data and/or information; e. risk management and prudence principles; f. anti-money laundering, counter-terrorism financing, and counter-proliferation financing of mass destruction weapons principles in accordance with applicable laws and regulations; and g. inclusivity and information openness principles.
(3) To implement self-evaluation as referred to in paragraph (1), ITSK Providers who have been registered and/or obtained a business license from the Financial Services Authority must inventory main risks including at least:
a. strategic risk; b. operational risk;
c. money laundering, counter-terrorism financing, and counter-proliferation financing of mass destruction weapons risks in accordance with applicable laws and regulations;
d. Consumer data protection risk; e. third-party service usage risk; and f. cyber risk.
(4) ITSK Providers who have been registered with the Financial Services Authority must submit self-evaluation to the Financial Services Authority every 3 (three) months concurrently with the submission of monthly reports.
(5) The obligation to submit self-evaluation to the Financial Services Authority for ITSK Providers who have obtained a business license from the Financial Services Authority follows the provisions in Financial Services Authority Regulations regarding licensing and supervision of each type of ITSK.
(6) Further provisions regarding self-evaluation for ITSK Providers who have been registered with the Financial Services Authority as referred to in paragraph (2) and paragraph (3) are determined by the Financial Services Authority.
Article 27
(1) Violations of the provisions as referred to in Article 26 paragraph (1) and/or paragraph (4) are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
Third Section
Association Monitoring Principles
Article 28
(1) Associations as referred to in Article 21 establish standards using a market discipline approach including at least:
a. ensuring compliance with the submission of reports to the Financial Services Authority; b. formulating operational rules, industry standards, market conduct, and codes of ethics, based on the characteristics of ITSK Providers;
c. receiving and forwarding reports and receiving complaints;
d. compiling financial statistics and monitoring risks and research on macro and micro financial issues; e. implementing Financial Services Authority directives to ITSK Providers to support regulatory, supervisory, and information dissemination functions; f. establishing self-assessment mechanisms, including mechanisms for imposing sanctions on members for violations of rules and codes of ethics; g. implementing education and training; h. implementing Consumer Protection; and
i. implementing domestic and international cooperation.
(2) Further provisions regarding ITSK Provider associations are determined by the Financial Services Authority.
CHAPTER VII
PERIODIC AND INCIDENT REPORTING
Article 29
(1) ITSK Providers who have been registered and/or obtained a business license must submit periodic reports and incident reports to the Financial Services Authority.
(2) Periodic reports as referred to in paragraph (1) consist of:
a. monthly reports; and b. annual reports.
(3) ITSK Providers who have been registered and/or obtained a business license must compile reports as referred to in paragraph (1) correctly and completely.
(4) ITSK Providers who have been registered must submit to the Financial Services Authority:
a. monthly reports as referred to in paragraph (2) letter a at the latest 10 (ten) working days after the reporting period ends; and b. annual reports as referred to in paragraph (2) letter b at the latest on April 30 of the following year.
(5) The obligation to submit monthly reports as referred to in paragraph (2) letter a and annual reports as referred to in paragraph (2) letter b for ITSK Providers who have obtained a business license follows Financial Services Authority Regulations regarding licensing and supervision of each type of ITSK.
(6) Further provisions regarding the form, procedures, and reporting mechanisms as referred to in paragraph (4) are determined by the Financial Services Authority.
Article 30
(1) Violations of the provisions as referred to in Article 29 paragraph (1), paragraph (3), and/or paragraph (4) are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
CHAPTER VIII
GOVERNANCE
Article 31
(1) ITSK Providers who have been registered and/or obtained a business license must have an electronic system strategic plan supporting the ITSK Provider's business plan.
(2) ITSK Providers who have been registered and/or obtained a business license must formulate policies, procedures, and standards containing at least:
a. business strategy; b. Consumer Protection;
c. risk and capital;
d. human resource development; e. product and service development and planning; f. information technology operations; g. communication networks; h. information security;
i. disaster recovery plans;
j. user services; and k. use of information technology service providers.
(3) ITSK Providers who have been registered and/or obtained a business license must have human resources with expertise and/or background in information technology and finance.
Article 32
In the event of changes regarding the business model, business processes, institutional structure, and ITSK operations, ITSK Providers who have been registered and/or obtained a business license must submit such changes to the Financial Services Authority.
Article 33
(1) Violations of the provisions as referred to in Article 31 and/or Article 32 are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
CHAPTER IX
DATA CENTERS
Article 34
(1) ITSK Providers who have been registered and/or obtained a business license must have data centers and disaster recovery centers.
(2) Data centers and disaster recovery centers as referred to in paragraph (1) must be located within the territory of Indonesia.
Article 35
(1) Violations of the provisions as referred to in Article 34 are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
CHAPTER X
FINANCIAL EDUCATION
Article 36
The implementation of activities to increase financial literacy, including financial education activities for Customers and/or the community, is carried out in accordance with applicable laws and regulations regarding the improvement of financial literacy and inclusion in the financial services sector for consumers and the community.
CHAPTER XI
CONSUMER AND COMMUNITY PROTECTION
Article 37
Consumer Protection and community protection are implemented in accordance with applicable laws and regulations regarding consumer and community protection in the financial services sector.
CHAPTER XII
PERSONAL DATA PROTECTION
Article 38
(1) ITSK Providers who have been registered and/or obtained a business license must maintain the integrity and availability of personal data, transaction data, and financial data they manage from the time the data is obtained until the data is destroyed.
(2) ITSK Providers who have been registered and/or obtained a business license must maintain the confidentiality and security of Customer data and/or information.
(3) The obligations of ITSK Providers who have been registered and/or obtained a business license as referred to in paragraph (2) are implemented by applying personal data protection as regulated in applicable laws and regulations regarding personal data protection.
(4) In the event that ITSK Providers who have been registered and/or obtained a business license cooperate with other parties to manage Customer data and/or information, ITSK Providers who have been registered and/or obtained a business license must ensure that such other parties maintain the confidentiality and security of Customer data and/or information as referred to in paragraph (2).
(5) The utilization of user data and information obtained by ITSK Providers must meet the following requirements:
a. obtaining consent from users; b. communicating the limits of data and information utilization to Customers;
c. communicating any changes in the purpose of data and information utilization to Customers in the event of changes in the purpose of data and information utilization;
d. the media and methods used in obtaining data and information are guaranteed to be confidential, secure, and intact; and e. other provisions regulated in applicable laws and regulations.
Article 39
(1) Violations of the provisions as referred to in Article 38 paragraph (1), paragraph (2), and/or paragraph (4) are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
CHAPTER XIII
INSTITUTIONAL ASPECTS
Article 40
(1) For the development and strengthening of ITSK management, the Financial Services Authority conducts institutional restructuring of ITSK management.
(2) The institutional aspects of ITSK Providers who have been registered include at least:
a. governance as referred to in Article 8 paragraph (3) letter a; and b. capital readiness and resources for conducting trials and innovation development as referred to in Article 9 paragraph (5) letter f, in supporting the achievement of ITSK Provider objectives.
(3) The institutional aspects of ITSK Providers who have obtained a business license include at least:
a. organizational support; b. resources;
c. governance; and
d. implementation of operational budgets, in supporting the achievement of ITSK Provider objectives.
(4) ITSK Providers who have been registered and/or obtained a business license in managing ITSK must prioritize good institutional governance principles.
(5) Provisions regarding institutional aspects for ITSK Providers who have obtained a business license as referred to in paragraph (3) follow Financial Services Authority Regulations regarding licensing and supervision of each type of ITSK.
Article 41
(1) Violations of the provisions as referred to in Article 40 paragraph (4) are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
CHAPTER XIV
COOPERATION IN ITSK MANAGEMENT
Article 42
(1) In managing ITSK activities, ITSK Providers who have been registered and/or obtained a business license may cooperate with Financial Institution Providers (LJK) and non-financial institutions to create synergy in the digital financial ecosystem.
(2) Cooperation as referred to in paragraph (1) must meet the following criteria:
a. conducted with parties supervised by the Financial Services Authority or other competent authorities; and b. stipulated in an agreement.
(3) ITSK Providers who have been registered and/or obtained a business license must report cooperation as referred to in paragraph (2) to the Financial Services Authority.
(4) In implementing cooperation as referred to in paragraph (1), ITSK Providers who have been registered and/or obtained a business license must comply with applicable laws and regulations.
Article 43
(1) Violations of the provisions as referred to in Article 42 paragraph (2), paragraph (3), and/or paragraph (4) are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
CHAPTER XV
OTHER COMPLIANCE ASPECTS
Article 44
ITSK Providers who are Participants or who have been registered and/or obtained a business license from the Financial Services Authority must implement anti-money laundering, counter-terrorism financing, and counter-proliferation financing of mass destruction weapons programs in the financial services sector in accordance with applicable laws and regulations.
Article 45
(1) Violations of the provisions as referred to in Article 44 are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
CHAPTER XVI
INNOVATION CENTERS
Article 46
(1) The Financial Services Authority manages Innovation Centers as a venue for the development of innovation and guidance for all stakeholders in the digital financial ecosystem.
(2) The management of Innovation Centers as referred to in paragraph (1) includes:
a. mentoring for technology innovators in the financial sector in accelerating the development of technology and business models that can be widely used in the financial sector; b. the development of technology standards in the financial sector;
c. access and use of data for trials and innovation development;
d. the implementation of discussions to ensure compliance with applicable laws and regulations and the development of policies regarding ITSK; and e. other activities in the development of ITSK and the digital financial ecosystem.
CHAPTER XVII
COORDINATION
Article 47
(1) In the context of regulation, supervision, and development of ITSK, the Financial Services Authority may coordinate with ministries, institutions, and other parties.
(2) Ministries, institutions, and other parties as referred to in paragraph (1) consist of:
a. other authorities, ministries, institutions, and other parties within the country; and b. other authorities, ministries, institutions, and other parties outside the country.
(3) Coordination as referred to in paragraph (1) includes:
a. trials/innovation development (sandbox); b. the development of technology-based regulatory ecosystems (regulatory technology) and technology-based supervision (supervisory technology) for ITSK development;
c. the exchange of data and/or information;
d. discussions on emerging issues related to ITSK; e. the improvement of human resource capacity; and/or f. other aspects deemed necessary.
CHAPTER XVIII
PROHIBITIONS
Article 48
(1) Participants and ITSK Providers who have been registered and/or obtained a business license from the Financial Services Authority are prohibited from providing data and/or information regarding Customers to third parties.
(2) The prohibition as referred to in paragraph (1) is excepted if:
a. the Customer provides consent; and/or b. Participants and ITSK Providers who have been registered and/or obtained a business license from the Financial Services Authority are required by applicable laws and regulations to provide data and/or information regarding Customers to third parties.
(3) The cancellation or partial change of consent as referred to in paragraph (2) letter a is done by the Customer in the form of an electronic document or other forms of documents recognized by the ITSK Provider.
Article 49
(1) Violations of the provisions as referred to in Article 48 paragraph (1) are subject to administrative sanctions in the form of:
a. written warning; b. temporary suspension, partial, or total cessation of activities including the implementation of cooperation;
c. revocation of approval;
d. cancellation of registration; and/or e. revocation of license.
(2) Administrative sanctions as referred to in paragraph (1) letters b through e may be imposed with or without being preceded by the imposition of an administrative sanction in the form of a written warning as referred to in paragraph (1) letter a.
CHAPTER XIX
TRANSITIONAL PROVISIONS
Article 50
(1) Digital financial innovation providers who are in the process of applying for recording and regulatory sandbox participants who are still in the implementation of the regulatory sandbox as regulated in Financial Services Authority Regulation Number 13/POJK.02/2018 regarding Digital Financial Innovation in the Financial Services Sector are granted status:
a. recommended with the obligation to register or obtain a business license from the Financial Services Authority; b. recommended without the obligation to register or obtain a business license from the Financial Services Authority; or
c. not recommended,
at the latest 6 (six) months since the implementation of this Financial Services Authority Regulation.
(2) Regulatory sandbox participants granted the result of status recommended with the obligation to register or obtain a business license from the Financial Services Authority as referred to in paragraph (1) letter a are subject to the provisions as referred to in Article 16 and Article 17.
(3) Digital financial innovation providers who have applied for recording but have not undergone processing at the time this Financial Services Authority Regulation takes effect, are subject to the provisions in this Financial Services Authority Regulation.
(4) Violations of Financial Services Authority Regulation Number 13/POJK.02/2018 regarding Digital Financial Innovation in the Financial Services Sector known at the time this Financial Services Authority Regulation takes effect are subject to sanctions based on the provisions in Financial Services Authority Regulation Number 13/POJK.02/2018 regarding Digital Financial Innovation in the Financial Services Sector.
(5) Companies subject to administrative sanctions based on Financial Services Authority Regulation Number 13/POJK.02/2018 regarding Digital Financial Innovation in the Financial Services Sector and unable to rectify the cause of the violation are subject to administrative sanctions in accordance with the provisions in this Financial Services Authority Regulation.
(6) The appointment of associations based on Financial Services Authority Regulation Number 13/POJK.02/2018 regarding Digital Financial Innovation in the Financial Services Sector is declared to remain valid.
CHAPTER XX
CLOSING PROVISIONS
Article 51
At the time this Financial Services Authority Regulation takes effect, Financial Services Authority Regulation Number 13/POJK.02/2018 regarding Digital Financial Innovation in the Financial Services Sector (State Gazette of the Republic of Indonesia Year 2018 Number 135, Supplement to the State Gazette of the Republic of Indonesia Number 6238) and its implementing regulations are revoked and declared invalid.
Article 52
This Financial Services Authority Regulation takes effect on the date of enactment.
This copy is consistent with the original
Legal Director 1
Legal Department
Mufli Asmawidjaja
To ensure that everyone knows it, ordering the enactment of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia.
Established in Jakarta on February 16, 2024
CHAIRMAN OF THE COMMISSIONERS BOARD
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA,
MAHENDRA SIREGAR
Enacted in Jakarta on February 19, 2024
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA,
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2024 NUMBER 5/OJK ttd
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
OF THE REPUBLIC OF INDONESIA
NUMBER 3 OF 2024
CONCERNING
THE MANAGEMENT OF FINANCIAL SECTOR TECHNOLOGY INNOVATION
I. GENERAL
Through the ratification of Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (the P2SK Law), the role of the Financial Services Authority (OJK) is strengthened in its duties to regulate and supervise Financial Sector Technology Innovation (ITSK), while still applying the principle of prudence to maintain financial system stability, market integrity, and Consumer Protection. In addition, the OJK has been given a new mandate to supervise digital financial assets, including crypto assets, particularly those regulated under Article 6 of the P2SK Law.
The strengthening of the OJK's role in the regulation and supervision of ITSK is an effort to realize an integrated fintech ecosystem using an activity-based approach. This is a response to the rapid development of ITSK in Indonesia and the increasingly complex business models and activities. ITSK can be utilized to support conventional economic and financial activities as well as those based on Sharia Principles.
In order to accelerate innovation and ITSK, the OJK plays a role in providing educational facilities, mentoring, discussions, acceleration, and collaboration by involving many elements facilitated through the strengthening of the Innovation Center.
However, rapidly developing technology innovation has two sides: the side that provides benefits and the side that has the potential to pose risks to Consumers. This requires risk mitigation efforts through the obligation of ITSK Organizers to apply principles of governance, risk management, information system security and reliability, including cyber resilience, Consumer Protection and personal data protection, and compliance with statutory regulations.
Financial Services Authority Regulation Number 13/POJK.02/2018 concerning Digital Financial Innovation in the Financial Services Sector (POJK 13/2018) is deemed in need of improvement in accordance with industry developments, technology, and the legal basis related to the management of ITSK. In addition, the P2SK Law contains regulatory and supervisory authority over ITSK that has implications for adjustments to POJK 13/2018.
With the implementation of the P2SK Law and as a response to the development of ITSK, POJK 13/2018 needs to be replaced. Through this Financial Services Authority Regulation, it is hoped that legal certainty can be provided for the regulation and supervision of ITSK management to ensure that innovation and technology development in the financial sector are carried out responsibly with good risk management. The development of such innovation must also be balanced with Consumer Protection aspects. To accommodate this, the Financial Services Authority provides a Sandbox space to facilitate testing and innovation development. This regulation also stipulates the obligation to obtain licensing status for organizers, coordination and/or cooperation among supervisors in regulation and supervision, as well as financial literacy and Consumer Protection.
II. ARTICLE-BY-ARTICLE EXPLANATION
Article 1
Clearly stated.
Article 2
Clearly stated.
Article 3
Paragraph (1)
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
Letter a
Governance includes openness, accountability, responsibility, independence, and fairness.
Letter b
Included in the scope of risk management are active supervision by the board of directors, the availability of policies and procedures, and the fulfillment of adequacy of organizational structure, risk management processes and risk management functions, as well as human resources, and internal controls.
Letter c
Information system security and reliability include the availability of written information system policies and procedures, the use of safe and reliable systems, including data confidentiality security and protection, fraud management, fulfillment of information system security and reliability certification and/or standards, maintenance and improvement of technology security, application of cyber security standards, data and/or information security, and periodic information system audits.
Letter d
Consumer Protection includes education and financial literacy, as well as market conduct supervision.
Letter e
Clearly stated.
Article 4
Clearly stated.
Article 5
Clearly stated.
Article 6
Clearly stated.
Article 7
Letter a
The limited environment includes, among others, the number of Consumers, the number of Financial Institution partners, and the number of transactions.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Article 8
Paragraph (1)
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
See the explanation of Article 3 paragraph (3).
Article 9
Paragraph (1)
Clearly stated.
Paragraph (2)
Recommendations from Financial Institution supervisors can be formulated, among others, in the form of approval letters, recommendation letters, and non-objection letters.
Paragraph (3)
Clearly stated.
Paragraph (4)
The application must be accompanied by at least documents related to the institution, explanations regarding the innovation being developed, and proof of the Participant's readiness to manage ITSK.
Paragraph (5)
Letter a
Clearly stated.
Letter b
Prospective Participants submit an explanation of potential risks covering at least:
a. strategic risk; b. systemic operational risk;
c. individual operational risk;
d. money laundering and terrorism financing risk; e. Consumer data protection risk; f. third-party service usage risk; g. cyber risk; and h. liquidity risk.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
Clearly stated.
Letter f
Clearly stated.
Letter g
Clearly stated.
Letter h
Clearly stated.
Letter i
Clearly stated.
Paragraph (6)
Clearly stated.
Paragraph (7)
Clearly stated.
Article 10
Paragraph (1)
Letter a
Clearly stated.
Letter b
Innovations that meet the element of novelty include, among others, products, activities, services, and business models. Innovations that have a significant differentiating element are measured based on benchmarking with international best practices and cannot be compared with services currently provided by Financial Institutions.
Letter c
Clearly stated.
Letter d
Innovations that are ready include, among others:
a. organizational and human resource readiness; b. Information Technology equipment readiness;
c. infrastructure readiness;
d. control mechanism and risk management framework readiness; and e. testing partner readiness.
Letter e
Clearly stated.
Letter f
Clearly stated.
Paragraph (2)
Other considerations from the Financial Services Authority include risks in the financial services sector and Consumer Protection.
Paragraph (3)
Clearly stated.
Paragraph (4)
Clearly stated.
Paragraph (5)
Clearly stated.
Paragraph (6)
Clearly stated.
Article 11
Paragraph (1)
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
Letter a
Changes related to ITSK and Participants include, among others, changes in business models, changes in Participant institutions, and changes in the Testing Plan.
Letter b
Clearly stated.
Letter c
Clearly stated.
Paragraph (4)
Other parties can include academics, research institutions, and social institutions.
Paragraph (5)
Clearly stated.
Paragraph (6)
Clearly stated.
Paragraph (7)
Letter a
Indirect monitoring is known as off-site monitoring.
Letter b
Direct monitoring is known as on-site monitoring.
Letter c
Clearly stated.
Paragraph (8)
Clearly stated.
Article 12
Paragraph (1)
What is meant by "specific Financial Services Authority regulations and provisions" are regulations and provisions related to testing and innovation development currently being conducted by Participants.
Paragraph (2)
Clearly stated.
Article 13
Paragraph (1)
Clearly stated.
Paragraph (2)
Different testing and innovation development timeframes include acceleration or extension.
In determining the acceleration or extension of the testing and development timeframe, considerations include, among others, the development of testing and development results, the need for improvements, complexity, and the Participant's need for Sandbox timeframe acceleration.
Paragraph (3)
Example:
During the Sandbox process, it is found that there is a mismatch with the eligibility criteria to participate in the Sandbox.
Paragraph (4)
Clearly stated.
Paragraph (5)
Clearly stated.
Paragraph (6)
Clearly stated.
Article 14
Clearly stated.
Article 15
Paragraph (1)
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
Considerations conducted by the Financial Services Authority include, among others:
a. Participant readiness consisting of institutional aspects, capital, and technology infrastructure; b. regulatory framework readiness; and
c. readiness of other supporting market infrastructure.
Paragraph (4)
Clearly stated.
Paragraph (5)
Clearly stated.
Paragraph (6)
Clearly stated.
Paragraph (7)
Clearly stated.
Article 16
Paragraph (1)
See the explanation of Article 15 paragraph (3).
Paragraph (2)
Clearly stated.
Paragraph (3)
What is meant by "type of ITSK" is a series of products, activities, services, and business models in the digital financial ecosystem that have specific characteristics and are generated from the Sandbox process.
Example:
Types of ITSK include alternative credit ratinging known as alternative/innovative credit scoring.
Paragraph (4)
Clearly stated.
Article 17
Clearly stated.
Article 18
Clearly stated.
Article 19
Clearly stated.
Article 20
Clearly stated.
Article 21
Clearly stated.
Article 22
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
What is meant by "revocation of license" is the revocation of licenses related to ITSK activities.
Paragraph (2)
Clearly stated.
Article 23
Paragraph (1)
Clearly stated.
Paragraph (2)
Indirect supervision is known as off-site supervision.
Direct supervision is known as on-site supervision.
Paragraph (3)
Clearly stated.
Paragraph (4)
Clearly stated.
Paragraph (5)
Clearly stated.
Article 24
Clearly stated.
Article 25
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 26
Paragraph (1)
Self-evaluation is intended to complement the supervision mechanism by the Financial Services Authority.
Paragraph (2)
Clearly stated.
Paragraph (3)
Clearly stated.
Paragraph (4)
Clearly stated.
Paragraph (5)
See the explanation of Article 16 paragraph (3).
Paragraph (6)
Clearly stated.
Article 27
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 28
Clearly stated.
Article 29
Paragraph (1)
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
What is meant by "correct" is in accordance with the actual conditions of the ITSK Organizer and does not contain untrue information or facts.
What is meant by "complete" is containing all report elements and does not omit material information or facts.
Paragraph (4)
Clearly stated.
Paragraph (5)
See the explanation of Article 16 paragraph (3).
Paragraph (6)
Clearly stated.
Article 30
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 31
Clearly stated.
Article 32
Clearly stated.
Article 33
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 34
Paragraph (1)
What is meant by "having a data center and disaster recovery center" includes using data centers and disaster recovery centers owned by third parties.
Paragraph (2)
Clearly stated.
Article 35
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 36
Clearly stated.
Article 37
Clearly stated.
Article 38
Clearly stated.
Article 39
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 40
Clearly stated.
Article 41
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 42
Paragraph (1)
Clearly stated.
Paragraph (2)
Letter a
Example:
Other competent authorities include Bank Indonesia and the Commodity Futures Trading Regulatory Agency.
Letter b
Clearly stated.
Paragraph (3)
Clearly stated.
Paragraph (4)
Clearly stated.
Article 43
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 44
Clearly stated.
Article 45
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 46
Clearly stated.
Article 47
Clearly stated.
Article 48
Clearly stated.
Article 49
Paragraph (1)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
See the explanation of Article 22 paragraph (1) letter e.
Paragraph (2)
Clearly stated.
Article 50
Clearly stated.
Article 51
Clearly stated.
Article 52
Clearly stated.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 73/OJK
Read the rest free
This document supersedes: Financial Innovation in the Digital Sector of the Financial Services Industry
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.