2023-06-13 | 000044093096Added
The Central Bank of Saudi Arabia establishes the licensing framework, operational requirements, and supervisory powers for payment service providers and payment system operators. The regulations define key terms, mandate customer protection and financial inclusion measures, and set out rules for risk management, outsourcing, and data security. They also grant the Central Bank authority to classify payment systems as critical, enforce compliance, and suspend or revoke licenses for violations.
Get SAMA alerts — same-day email on every new publication.
P.O. Box 2992 Riyadh 11169, Kingdom of Saudi Arabia Tel: +966 11 463 3000
Implementing Regulations of the Payments and Payment Services Law Issued on 24/11/1444 H (13/06/2023)
Contents
Chapter One: General Provisions ............................................................ 3
Chapter Two: Licensing ........................................................................ 10
Chapter Three: Electronic Money Agents and Distributors .................... 20
Chapter Four: Obligations of Licensees ................................................ 23
Chapter One: Risk Management, Review, and Rules ..................... 23
Chapter Two: Structural Changes ................................................. 30
Chapter Three: Requirements for Payment Service Providers ........ 32
Chapter Four: Scope of Application for Licensees .......................... 35
Chapter Five: Customer Protection and Financial Inclusion .................. 36
Chapter One: Customer Protection .............................................. 36
Chapter Two: Financial Inclusion .................................................. 37
Chapter Six: Related Payment Services ................................................ 37
Chapter One: Contract and Information Requirements .................. 37
Chapter Two: Issuance and Redemption of Electronic Cash ........... 43
Chapter Three: Provision of Related Payment Services .................. 44
Chapter Seven: Protection of Protected Funds ...................................... 53
Chapter Eight: Requirements for Payment Account Information Service Providers .................................................................................... 55
Chapter Nine: Payment Systems ........................................................... 59
Chapter One: Classification of Payment Systems .......................... 59
Chapter Two: Infrastructure Principles Requirements ................... 60
Chapter Three: Payment System Powers ...................................... 63
Chapter Four: Finality of Settlement and Insolvency ..................... 66
Chapter Ten: Supervision and Control .................................................. 68
Chapter Eleven: Complaints and Disputes ........................................... 71
Chapter Twelve: Final Provisions .......................................................... 73
Chapter One: General Provisions
Article 1
The meanings and expressions used in these Regulations refer to the meanings indicated before them, unless the context requires otherwise. (1)
For the purpose of applying the provisions of these Regulations, the following words and terms shall have the meanings opposite to them, unless the context requires otherwise. (2)
Article 2
These Regulations aim to: (1) Establish the regulatory framework and requirements for the organization of payment service providers and operators in the Kingdom, including licensing, supervision, and control requirements. (2) Establish the necessary mechanisms for managing the risks affecting the payment services and systems sector, including payment and settlement, and financial and monetary stability. (3) Contribute to enhancing the principles of transparency and fair competition in the payment and settlement systems. (4) Support the efficiency and effectiveness of the financial and monetary system by encouraging and developing the sector of payment systems and services by the Saudi Central Bank.
Article 3
The Saudi Central Bank shall implement the tasks and competencies conferred upon it by the Law, taking into account the related policies, regulations, and best international standards and practices. (1)
The Saudi Central Bank shall exercise supervision and control over related payment services, including: (2) (a) Licensing entities providing more than one related payment service, in accordance with the provisions of the Law and these Regulations. (b) Issuing laws, regulations, rules, directives, and instructions related to the provision of related payment services, and amending them. (c) Supervising and monitoring the obligations of Payment Service Providers in accordance with the provisions of the Law, these Regulations, and all laws, regulations, rules, directives, and instructions issued by the Saudi Central Bank related thereto. (d) Supervising and monitoring the obligations of Payment Service Providers and holders of key management positions to adhere to best governance standards. (e) Taking corrective or executive measures regarding violations of the provisions of the Law, these Regulations, and all laws, regulations, rules, directives, and instructions issued by the Saudi Central Bank related thereto. (f) Handling complaints and their processing mechanism. (g) Establishing and maintaining a general register of Payment Service Providers. (h) Suspending or revoking the licenses of Payment Service Providers, in accordance with the powers granted to the Saudi Central Bank by the Law.
The Saudi Central Bank shall have exclusive jurisdiction over the supervision and control of payment systems, including: (3) (a) Licensing entities to operate payment systems, in accordance with the provisions of the Law and these Regulations. (b) Classifying payment systems according to the "Critical Payment System" criteria. (c) Issuing laws, regulations, rules, directives, and instructions related to the operation of infrastructure principles, taking into account the provisions of the payment systems. (d) Supervising and monitoring the obligations of Payment System Operators in accordance with the provisions of the Law, these Regulations, and all laws, regulations, rules, directives, and instructions issued by the Central Bank related thereto. (e) Exercising the powers related to the implementation of finality of settlement provisions - without prejudice to other causes - and insolvency provisions regarding payment systems and their participants. (f) Supervising the obligations of operators to adhere to best governance standards for holders of key management positions. (g) Taking corrective or executive measures regarding violations of the provisions of the Law, these Regulations, and all laws, regulations, rules, directives, and instructions issued by the Saudi Central Bank related thereto. (h) Handling complaints and their processing mechanism. (i) Maintaining a general register of Payment System Operators. (j) Suspending or revoking the licenses of Payment System Operators, in accordance with the powers granted to the Saudi Central Bank by the Law.
Article 4
The provisions of these Regulations shall apply to all persons who provide related payment services in the Kingdom, provided that any of the following conditions are met: (1) (a) The person provides related payment services in the Kingdom. (b) The person provides a payment service in the Kingdom through any means or form. (c) The person solicits or invites a person present in the Kingdom to conclude an agreement related to a payment service. (d) The person promotes any payment service to a person present in the Kingdom. (e) The person appoints a person working in an establishment located outside the Kingdom to assume any responsibilities on behalf of the Kingdom, including:
(1) The appointed person performs the payment service on behalf of the Kingdom.
(2) The appointed person acts in accordance with the instructions of the appointing person.
(3) The appointed person provides the payment service on behalf of the Kingdom, solicits or invites a person to conclude a contract related to a payment service, or offers it to them.
The provisions of these Regulations shall also apply to all persons who operate payment systems, whether the operator's establishment is inside or outside the Kingdom, and whether the operations are inside or outside the Kingdom, provided that any of the following conditions are met: (2) (a) The system establishes rules for the conditions and procedures for the transfer of funds related to payment operations. (b) The system provides payment system services for processing and settling payment orders or for members resident in the Kingdom, or for employees working in the Kingdom.
Chapter Two: Licensing
Article 5
The Saudi Central Bank shall accept or reject the request for a license to provide related payment services or operate payment systems, taking into account: (1) (1) The compatibility of the services and activities with the objectives of the Law and these Regulations. (2) The compatibility of the services and activities with the customer protection and competition objectives stipulated in the Law and these Regulations. (3) The economic value generated from providing these activities in the Kingdom and their impact on financial stability in the Kingdom. (4) The ability of the applicant to meet the requirements stipulated in the Law and these Regulations. (5) The absence of any factors that may hinder the Saudi Central Bank's ability to supervise and control the applicant effectively.
Article 6
The Saudi Central Bank shall issue a license to a Payment Service Provider when the services are routinely practiced as a commercial activity, involving the provision of more than one of the following services:
(1) Services that allow the deposit of funds in a payment account, in addition to all the required operations to operate the payment account.
(2) Services that allow cash withdrawal operations from the payment account, in addition to all the required operations to operate the payment account.
(3) The implementation of payment transactions, including the transfer of funds to the payment account with the Payment Service Provider or with another Payment Service Provider or the user.
Including:
(a) Direct debit operations.
(b) Payment transactions through a payment card or any similar electronic device.
(c) Execution of fund transfers.
(4) The implementation of payment transactions where the funds are covered through a credit limit for the Payment Service User, including:
(a) Direct debit operations.
(b) Payment transactions through a payment card or any similar payment instrument.
(c) Execution of fund transfers.
(5) Issuance of payment instruments.
(6) Payment services hosting.
(7) Aggregated payment services.
(8) ...
The Central Bank may determine any other service as a payment service:
The applicant for a license to provide payment services, or their representative, must submit the license application to the Central Bank accompanied by the following documents:
The bank guarantee is considered cancelled in the following cases:
a) In the event the Central Bank determines that the entire capital has been paid, or requests a partial or additional precautionary bank guarantee as a licensing requirement. b) Upon withdrawal of the license application. c) Upon rejection of the license application by the Central Bank.
The applicant for a license to operate payment systems, or their representative, must submit the license application to the Central Bank accompanied by the following documents:
Upon receipt of the application:
The licensed entity shall not cease, partially or completely, the practice of any of its services or activities without prior written approval from the Central Bank, unless such cessation leads to the licensed entity’s failure to meet its obligations towards its members, shareholders, creditors, or clients, or affects the stability of the financial sector, according to Article 19 of the Regulation.
The licensed entity may apply to modify the license, including deleting some services or activities, or modifying any conditions, provided that the modification request is supported by reasonable justifications, studies, documents, and information, and is accompanied by any documents, information, or studies requested by the Central Bank to restrict the license.
The licensee must ensure, in accordance with the rules of outsourcing and the Regulations, its ability to fulfill its obligations.
The licensee must obtain the Central Bank's objection if it wishes to conclude a contract with another person to perform core payment services or services related to the operation of the payment system.
When the licensee intends to outsource core tasks, it must observe the following:
(a) First:
(b) Second:
The licensee must ensure that the provisions of the Regulations regarding the delegation of responsibilities to the license holder's leadership positions are fulfilled.
For the purposes of the third paragraph of this Article, "core tasks" refers to any tasks whose failure or defect significantly affects:
(a) The licensee's compliance with the System and the Regulations.
(b) The licensee's financial performance.
(c) The safety or continuity of operations related to payment services or the payment system.
The licensee must notify the Central Bank of any changes in the functions outsourced to them or to the persons to whom they were outsourced.
The licensee is considered responsible to the Central Bank and its clients for the outsourcing it has performed.
The licensee must establish policies, procedures, and controls for risk management, obligation management, and business continuity, which are comprehensive and commensurate with the nature, size, and complexity of the services and activities it provides, as well as the degree of risks and complexities associated with its operations.
The licensee must ensure the updating of its risk management, obligation management, and business continuity policies, procedures, and systems by reviewing them at least once annually and providing the Central Bank with any significant amendments, along with any additional information or actions required by the Central Bank.
The licensee's risk management and obligation management systems and controls must include:
(a) Procedures for the identification, monitoring, reporting, and management of any risks to which the licensee may be exposed.
(b) Necessary internal control mechanisms, including appropriate administrative and risk management procedures and accounting procedures.
(c) Appropriate mechanisms to verify compliance with all requirements of the System, the Regulations, and related decisions, circulars, and directives.
(d) Policies and procedures for detecting and dealing with fraud cases.
(e) Policies and procedures for notifying the Central Bank of fraud incidents involving related parties.
Subject to the third paragraph above, the licensee's risk management and obligation management policies and controls must include:
(a) The establishment of functions for risk management, internal audit and review, and obligation management, with sufficient independence and resources to perform their duties.
(b) The creation of an integrated supervisory framework between internal audit and review, obligation management, and external audit functions.
The licensee must have a sufficient number of qualified employees with appropriate knowledge and expertise to meet its operational needs. The number of employees must be commensurate with the nature, size, and complexity of its activities and the degree of risks and complexities associated with them. Employee compensation and incentives must be consistent with its strategy, risk management principles, and the protection of customers' interests, in accordance with the applicable Systems, Regulations, and decisions. The licensee must comply with the ratio of non-Saudi employees as specified in the Regulations.
The licensee must have governance rules, systems, and controls commensurate with the nature, size, and complexity of its operations. These must include, by way of non-exhaustive examples, organizational structure, separation of duties and independence, roles of directors and board members, appointment of directors and members, conflict of interest controls, compensation and incentive policies, responsibilities of members and directors, confidentiality of information, compliance with applicable Systems, Regulations, and decisions, integrity and transparency, obligation management, and appropriate asset protection. The licensee must apply the standards and principles issued by the Central Bank relevant to its business.
The licensee must establish an internal audit unit under the supervision of the Audit Committee (or equivalent body). The internal audit function must be independent in performing its duties and free from any assignment of responsibilities by the company's directors or management. Its functions and responsibilities are determined as follows:
(1) The internal audit unit is responsible for evaluating the licensee's internal policies, systems, and controls, including the outsourcing of operations, and the implementation of approved procedures and policies, as well as the applicable Regulations, decisions, and circulars. The internal audit unit must have the right to access any documents or information as needed for its work.
(2) The internal audit unit operates according to a comprehensive review plan approved by the Audit Committee, which is updated annually, covering all main activities and operations, including risk management and compliance.
(3) The internal audit unit must prepare a written report to the Audit Committee every three months at minimum, outlining its activities. The report must include all review results, recommendations, and actions taken in each section, along with reasons for any delays in implementation and the results of previous reviews. Additionally, the report must include any other relevant comments.
(4) The internal audit unit must prepare a comparison report for the Audit Committee, showing all review operations performed during the year against the approved review plan, highlighting any deviations or gaps, and comparing them with the previous financial year. The report must be submitted during the first quarter following the end of each financial year.
(5) The licensee must retain documents related to the approved review plan, completed work, reports, and results, as well as evidence of the implementation of recommendations.
The licensee must appoint an external auditor, subject to obtaining a no-objection letter from the Central Bank. The external auditor must be changed every five years. The appointment of the external auditor must not involve a conflict of interest with the licensee's activities or holdings in the relevant authorities. The external auditor must be licensed to operate within the licensee's jurisdiction.
The licensee must verify that the external auditor's commitment includes the terms and conditions of the external audit agreement, including at minimum:
(a) The review of financial statements or consolidated financial statements prepared in accordance with the standards and practices applicable to the licensee for the year in which it was appointed.
(b) A separate review of the licensed services performed by the Central Bank, without reviewing other activities.
(c) Submitting a report to the Central Bank in the form and duration specified by the independent Regulations applicable to the licensee.
By way of non-exhaustive examples, the Central Bank may require the external auditor to:
(a) Provide any additional information related to the review.
(b) Increase the scope of the licensee's review or expand it.
(c) Perform additional auditing or inspection procedures.
In the event of non-acceptance, the Central Bank may direct the licensee to appoint an alternative external auditor at the licensee's expense.
The licensee must attach the external auditor's reports to the Balance Sheet and Profit and Loss Account. Copies of these reports must be submitted to the Central Bank in the form and duration specified, along with the licensee's financial statements or consolidated financial statements.
The licensee must verify that the external auditor's commitment includes the occurrence of any of the following, notifying the Central Bank immediately:
(a) Violation of any provision of the System, Regulations, decisions, circulars, or directives.
(b) Committing a crime related to financial fraud or breach of trust.
(c) Incurring losses leading to the failure to meet the capital requirements specified in the Regulations.
(d) Occurrence of any error that may have a material effect on the licensee's accounts, including any error causing disruption.
(e) If the auditor is unable to verify assets exceeding the licensee's liabilities, or if another applicable jurisdiction's systems are not implemented.
The report submitted under the seventh paragraph is not considered a disclosure of any liability of the external auditor or their employees for any error or misconduct, nor does it waive the applicable contractual terms or regulations, provided that they disclose in good faith:
(a) Any matter they are certain or likely certain to exist in the matters mentioned in this Article.
(b) Any matter they are certain or likely certain to exist upon which they have obtained information during the course of their work.
The licensee must direct the external auditor not to disclose any information obtained during the course of their work under this Article to any other person, the Central Bank, or any other person, unless required by the System, Regulations, or decisions.
The licensee is considered to have committed a violation if any of its employees or agents commit any of the following acts:
(a) Obstructing, delaying, or preventing the review.
(b) Destroying, concealing, or replacing any records, documents, or property related to the licensee's operations.
(c) Sending a record or document that is not original or describing it as such, or possessing or controlling anything that the licensee owns or holds, or transferring it outside the jurisdiction.
The licensee must comply with all decisions and regulations issued by the Central Bank regarding business continuity management decisions, considering the types of activities performed, their nature, complexity, and size.
The licensee must comply with all decisions and regulations issued by the Central Bank regarding cybersecurity requirements, as well as Systems, Regulations, decisions, and circulars issued by the relevant authorities within the Kingdom.
The licensee must comply with all decisions, directives, and rules issued by the Central Bank regarding governance requirements, as well as Systems, Regulations, decisions, and circulars issued by the relevant authorities within the Kingdom, in addition to technical standards and other applicable standards. The licensee must comply with the approved technical standards applicable to it, including payment cards, payment operations, payment systems, and data modifications. The licensee must be a member of the payment system.
The licensee must comply with Systems, Regulations, decisions, and circulars related to combating money laundering and terrorist financing, as well as internal decisions and procedures issued in this regard.
The licensee must adopt a risk assessment approach to identify and mitigate risks related to money laundering and terrorist financing, ensuring the use of appropriate measures to mitigate identified money laundering and terrorist financing risks.
The licensee must comply with Systems, Regulations, decisions, and circulars related to data protection within the Kingdom, as well as directives issued by the Central Bank.
The licensee must protect customer data, including maintaining the confidentiality of stored data, and granting access to such data only to authorized employees. The licensee must comply with regulatory requirements within the Kingdom regarding reporting suspicious crimes, money laundering, or fraud, for financial purposes.
The licensee may disclose customer data in the following cases, without violating relevant Systems:
(a) As required by the Central Bank or relevant authorities within or outside the Kingdom.
(b) Upon obtaining prior written consent from the customer for disclosure purposes.
The licensee must establish policies, procedures, and controls for customer data protection, including awareness and training of employees regarding information security risks.
The licensee must comply with all decisions and regulations issued by the Central Bank regarding data protection within the Kingdom.
The licensee must prepare and maintain records of all operations, processes, and information, enabling the Central Bank to effectively supervise them in accordance with the Regulations.
The records the licensee must maintain include:
(a) Financial information, including financial statements, bank account and customer data, accounting records (including but not limited to electronic fund transfers and check records), bank data (including ledgers, journals, general ledgers, subsidiary books, contracts, invoices, cost allocation schedules, and daily entries and supporting documents), financial data, and disclosures and settlements. (b) Reports related to the activities performed by the licensee, including the volume and value of payment services. (c) Minutes and decisions of the Board of Directors or Management Committee meetings. (d) Information related to any operational or security incidents, whether isolated or aggregated. (e) Records of operations approved for payment services. (f) Security records, including authentication records. (g) Information changes required to be submitted under Article 21 (One Hundred and Twenty). (h) Risk management reports and fraud-related incidents. (i) Data protection and privacy measures reports. (j) Complaints from users of payment services regarding any actions taken. (k) Reports related to any errors, delays, negligence, refunds, or other matters handled. (l) Reports on compliance with protected funds protection and preservation requirements. (m) "Know Your Customer" relationship information regarding the required due diligence towards customers, in accordance with Systems, Regulations, decisions, and circulars related to combating money laundering and terrorist financing. (n) Reports related to the System, Regulations, decisions, circulars, or other than the Regulations. (o) Key legal documents, including employment contracts, external auditor appointments, and agreements related to the company's governance, business continuity, and outsourcing.
The licensee must retain records for a period of at least ten years from the date of their creation or modification, as the Central Bank deems appropriate.
The licensee must establish policies, procedures, and systems regulating electronic storage of records, achieving at minimum:
(a) Creation and storage of records on reliable and secure storage media.
(b) Clear and accessible use and retrieval methods.
(c) Classification and indexing of records and documents.
(d) A secure and reliable system granting access rights and ensuring the absence of unauthorized access to electronic or physical systems.
(e) Backup and protection capabilities providing maximum recovery levels through periodic backup tests, ensuring recovery in case of loss of any original version.
(f) Use of digital certificates and encryption.
(g) Storage of related documents and records in the same coordination as they are received or created, without any modification, deletion, or alteration.
(h) Recording all actions taken on records.
(i) Verifying that authorized employees have access to records and maintaining their confidentiality during their employment with the payment service provider and after their termination.
The licensee must conduct regular reviews to ensure compliance with the provisions of this Article, at least annually.
The licensee must obtain a no-objection letter from the Central Bank before implementing any changes specified in the second paragraph of this Article, providing the reasons for such changes and the information or data required by the Central Bank to implement the proposed changes on the specified date.
The changes include:
(a) Changes to the licensee's information and data, including (by way of non-exhaustive examples):
(b) Changes to the licensee's operations or financing, including (by way of non-exhaustive examples):
(c) The licensee must obtain prior written approval from the Central Bank if it intends to offer or list any of its shares in a public offering.
The licensee must maintain a register of controllers, ensuring that any changes occur within forty days. The register must include all necessary information for the licensee, and the licensee must inform the controller of any changes, including at minimum:
(a) Full name.
(b) Current address of residence.
(c) Date and place of birth.
(d) Nationality.
(e) Copy of the personal identity document.
The licensee must send an annual report to the Central Bank on controllers, in the form and mechanism specified by the Central Bank.
The licensee must notify the Central Bank of any significant changes in the circumstances or actions of the current controllers, as soon as possible, if such changes could affect the licensee's ability to perform its operations or its correctness.
The licensee must obtain prior written approval from the Central Bank if the founder intends to become a controller, or if the controller's percentage increases or becomes a controller.
Upon receiving the request, the Central Bank may approve or reject the request to add the controller or impose conditions on the licensee or the controller.
The Central Bank notifies the licensee of its decision in writing within ninety (90) calendar days from the date of receiving the complete request.
Approval issued by the Central Bank is considered granted if no written rejection is issued by the Central Bank within six months from the date of issuance, unless extended in writing.
The licensee must comply with the conditions of the approval. The person for whom approval was obtained by the Central Bank is prohibited from starting acquisition without prior rejection by the Central Bank.
If the licensee's branch represents an institution outside the Kingdom, the licensee must submit written notification to the Central Bank regarding the institution outside the Kingdom seeking to increase its ownership percentage in the licensee.
A person who was previously a controller and wishes to reduce their control percentage or cease control must notify the Central Bank before taking any action resulting in a reduction of the control percentage.
A payment company is considered a small payment company if it meets all of the following conditions:
(a) It performs more than one related payment service, excluding the issuance of electronic money.
(b) It does not provide international related payment services to persons outside the Kingdom.
(c) The average value of payment operations does not exceed SAR 10 million monthly.
A payment company is considered a large payment company if it performs more than one related payment service, excluding the issuance of electronic money, and the average value of payment operations exceeds SAR 10 million monthly.
An electronic money company is considered a small electronic money company if it meets any of the following conditions:
(a) It does not ensure a total average of SAR 10 million in electronic money.
(b) The average value of payment operations does not exceed SAR 10 million monthly.
(c) It does not allow any user of payment services to hold more than SAR 1,020 in electronic money, considering all accounts operated through electronic money, subject to the third paragraph of this Article.
(d) It does not allow any user of payment services to execute payment operations exceeding SAR 1,000 monthly, excluding cash withdrawal operations, considering all accounts operated through electronic money, subject to the third paragraph of this Article, when electronic money accounts are closed.
An electronic money company is considered a large electronic money company if it exceeds any of the limits specified in the above paragraphs of this Article.
A small electronic money company must ensure:
(a) That it did not start issuing electronic money for a period of less than twelve (12) calendar months, and the total average of electronic money expected for the initial operations period does not exceed SAR 10 million for a period of twelve (12) months. (b) That it did not start providing related payment services for a period of less than twelve (12) calendar months, and the average value of operations expected for the period does not exceed SAR 10 million monthly.
If a small electronic money company increases the limits specified in the first paragraph of this Article or more, it must submit reasons to the Central Bank, specifying the systems and controls required for monitoring, subject to the Central Bank's discretion and additional conditions it deems appropriate.
A large electronic money company must ensure:
(a) That it does not allow any user of payment services to hold electronic money exceeding SAR 100,000, considering all accounts operated through electronic money services.
(b) That it does not allow any user of payment services to execute payment operations exceeding SAR 1,000 monthly, excluding cash withdrawal operations, considering all accounts operated through electronic money, subject to the third paragraph of this Article, when electronic money accounts are closed.
If a large electronic money company increases the limits specified in the fifth paragraph of this Article or more, it must submit reasons to the Central Bank, specifying the systems and controls required for monitoring, subject to the Central Bank's discretion and additional conditions it deems appropriate.
The applicant must demonstrate that they have met the capital requirements for the license as follows:
(a) For a small payment company license: Paid capital in the form of equity not less than SAR 1 million.
(b) For a large payment company license: Paid capital in the form of equity not less than SAR 3 million.
(c) For a small electronic money company license: Paid capital in the form of equity not less than SAR 2 million.
(d) For a large electronic money company license: Paid capital in the form of equity not less than SAR 10 million.
(e) For payment services account information services license or independent establishment in the form of payment services: Paid capital in the form of equity not less than SAR 1 million.
(f) For payment services account information services license: Paid capital in the form of equity not less than SAR 500,000.
The applicant for a license to operate as a payment system operator must demonstrate initial capital requirements based on the proposed payment system's nature, size, and scope, and the systems or systems to be operated by it, and its connections.
The licensee must comply with the continuing capital requirements of this Article.
A small payment company and a small electronic money company must maintain initial capital equal to the requirements specified in Article 44 of the Regulations.
A large payment company must maintain an amount equivalent to the higher of:
(a) The initial capital requirements specified in Article 44 of the Regulations.
(b) 1% of the average value of monthly payment operations for the large payment company.
Article 44
(4) An electronic money company must hold reserves equivalent to the greater of:
(a) The initial capital requirements stipulated in the first paragraph of this Regulation; (b) 2% of the average total liabilities of the electronic money.
(5) A payment service provider must submit to the Central Bank, within the period specified, proof of compliance with the capital requirements through any of the following:
(a) A certified copy of a document issued by the competent authority in the Kingdom indicating its capital; (b) A certified copy of the financial statements audited by a legal accountant licensed to practice in the Kingdom; (c) Any other means acceptable to the Central Bank.
(6) A payment service provider must comply with the accounting standards applicable in the Kingdom as determined by the Central Bank.
Article 45
(1) A payment service provider must maintain at its payment services or account information services:
(a) Professional liability insurance against errors; (b) Any similar guarantee.
(2) Professional liability insurance for providers of payment services and account information services must cover potential liabilities arising from any of the following amounts specified by the Central Bank:
(a) Unauthorized access to account information or payment services, or their use; (b) Non-execution, defective execution, or delay in execution of payment operations authorized by the user, including any associated liability for fees, interest, and the right of recourse.
Article 46
Exemption of providers from the validity of payment services for the Central Bank
(1) The Central Bank may exempt a licensed provider from the requirements of the first paragraph of Article 44, provided that the provider submits a request to obtain such exemption.
(2) The Central Bank shall determine the provisions that the licensed provider must comply with when providing payment services of the relevant type, which must be consistent with its nature and do not conflict with the objectives of this Regulation and the System.
Article 47
Limited Network Service Provider
(1) A limited network service provider must comply with the provisions of this Article, taking into account the definition of limited network as determined by the Central Bank.
(2) A limited network service provider registered with the Central Bank must immediately notify the Central Bank if operations exceed fifty million (50,000,000) Saudi Riyals in total value or volume during any two consecutive months, or two million (2,000,000) Saudi Riyals in any month during that period.
(3) The notification sent to the Central Bank must include a description of the limited network service provider, the reasons, and the nature of the relevant operations.
(4) The notifications referred to in the second paragraph must be submitted to the Central Bank by the end of the tenth month following the end of the two-month period or by the end of the month, as determined by the Central Bank.
(5) The provisions of this Article shall apply to any person seeking a license for validity.
Chapter Five: Customer Protection
Section One: Customer Protection
Article 50
A payment service provider must comply with all principles and requirements issued by the Central Bank regarding customer protection.
Article 51
The provisions determined by the Central Bank may not be waived in the agreement between the payment service provider and the user of payment services. The form taken for providing services to the client may be a natural or legal person, depending on the nature and commercial context.
Section Two: Financial Inclusion
Article 52
(1) When providing payment services, payment service providers must comply with the financial inclusion principles issued by the Central Bank relevant to the matter.
(2) Operators must ensure the principles of fairness and transparency are observed by ensuring participation is available to all members of the payment system.
(3) The Central Bank may, without violating the System and regulations, designate a system operator to achieve fairness and empowerment, or other relevant payment systems. A membership applicant becomes empowered to obtain membership in the important payment system directly without requiring membership.
Chapter Six: Contract Requirements and Information Provision
Section One: Contract Requirements
Article 53
(1) When providing payment services under a framework agreement, the payment service provider must provide the user with the framework agreement before initiating, executing, or completing a payment transaction, and in a manner that allows the user to store it. If providing the framework agreement is impossible, it must include at least:
(a) A table of fees, commissions, and prices applied to payment operations, including withdrawal and transfer fees; (b) The payment service provider's data, including name, address, and contact information; (c) Provisions and procedures related to the creation, authorization, and cancellation of payment orders; (d) Means of communication and data between the payment service provider and the payment service user; (e) A mechanism for the payment service provider to notify the user of any unauthorized payment operation or its execution, including the duration of notification and clarification of the provider's responsibilities for unauthorized operations; (f) A mechanism for amending the terms and conditions and duration of the framework agreement, and the rights of the parties to terminate the agreement; (g) The maximum time within which the payment operations will be executed.
(h) Any other necessary information to comply with the requirements and principles of customer protection.
(2) The payment service provider must provide the user with a copy of the framework agreement for the payment services for the duration of the contractual relationship upon request.
Article 54
(1) The payment service provider must include in the framework agreement the user's right to withdraw from the payment services within a period not exceeding ten working days, without imposing any penalties.
(2) The payment service provider may begin providing the relevant payment services during the withdrawal period, provided that it verifies the completion of all requirements related to providing the service. This does not affect the user's right to terminate the framework agreement during that period.
(3) If the payment service user terminates the framework agreement, they have the right to a full refund of any prepaid fees related to services not yet provided.
Article 55
When creating a single payment transaction under the framework agreement, the payment service provider must notify the payer of the execution details, costs, and applicable fees before execution.
Article 56
The payment service provider must provide the payer with information on payment operations at least once a month, free of charge, including:
(a) The payer's reference number for the payment operation; (b) The amounts of payment operations in the currency used or deducted from the payer's payment account, in the payer's currency; (c) Any fees the payer is liable for in relation to the payment operation, including details of these amounts; (d) The exchange rates used in the payment operations before the payment service provider and before conversion; (e) The date of receipt of the payment service order or the value date of the payment operation.
Article 57
The payment service provider must provide the payee with information on payment operations at least once a month, free of charge, including:
(a) The payee's reference number for the payment operation and any information transferred during the operation; (b) The amounts of payment operations in the currency deposited in the payee's payment account; (c) Any fees the payee is liable for in relation to the payment operation, including details of these amounts; (d) The exchange rates used in the payment operations before the payment service provider and before conversion; (e) The date of deposit of the payment operation value.
Article 58
(1) The user may terminate the framework agreement at any time, subject to an agreement between the parties on the duration, which must not exceed thirty (30) calendar days.
(2) The payment service provider may amend the terms and conditions of the framework agreement, including fees and costs, provided that the framework agreement specifies the requirements for such amendment.
(3) The payment service provider may change fees linked to variable prices, such as exchange rates, provided that the framework agreement specifies this on the basis of a reference price available to the user and on which they have been informed.
(4) The payment service provider must notify the payment service user of any changes at least thirty (30) days before the amendment takes effect, without charge during the notification period. The user retains the right to terminate the payment services under the framework agreement. Fees for termination of the framework agreement are subject to agreement.
Article 59
Upon receipt of a payment order under the payment contract, the payment service provider must immediately provide the payer with the following information:
(a) The payer's reference number for the payment operation, in addition to information related to the payment; (b) The amount of the payment operation in the currency of the payment; (c) Details of the fees due to the payment service user before payment; (d) The actual exchange rate used after currency conversion of the payment operation amount; (e) The date of receipt of the payment service order.
Article 60
When providing relevant payment services under the payment contract, the payment service provider must provide the user with the following information:
(a) The distinguishing information or identifier provided by the user as a means of authorization to create a payment order; (b) The maximum time within which the payment service will be executed; (c) Details of the fees due to the payment service user before payment; (d) The reference or actual exchange rate to be applied to the payment operation.
Article 61
Upon execution of a payment operation under the payment contract, the payment service provider must immediately provide the payer with the following information:
(a) The payer's reference number for the payment operation, in addition to any information transferred during the operation; (b) The amount of the payment operation in the currency constituting the funds available to the payer under their payment; (c) Any fees for the payment operation due to the payer before payment; (d) The exchange rates used in the payment operation before the payment service provider and before conversion; (e) The date of deposit of the payment operation value.
Article 62
When providing any information to the user, the payment service provider must, without prejudice to the provisions of this Chapter, ensure:
(a) The information is provided in a manner that facilitates access to it, whether by electronic mail or electronic messages; (b) The information is written or text-based; (c) The information is clear and easy to understand; (d) The information is provided in Arabic or any other language agreed upon by the parties; (e) Any additional methods specified by the framework agreement for providing the information.
Article 63
(1) The payment service provider may not charge a fee for providing the information required by this Chapter.
(2) The payment service provider and the user may agree that the payment service provider charges a fee for providing any information upon request. Such fees must correspond to the actual costs incurred by the payment service provider for providing the information. Additional information or requirements beyond those specified in the framework agreement may be provided through communication channels other than those specified in the framework agreement, if requested.
Article 64
The payment service provider must execute payment operations in the currency agreed upon by the parties, and in the case of a transfer service, in addition to explaining all fees to the payer before the payment is made to the payee, whether through a sales point or an automated teller machine, the exchange rate to be used for the payment operation before execution.
Article 65
(1) The payment service provider must notify the user of any fees required for the use of a payment tool before creating the payment operation.
(2) The payment service provider may not oblige the user to pay any fees if the user is not notified of the full value in accordance with the provisions of this Article.
Article 66
(1) The payment service provider must notify the payment service user if the payment service order cannot be executed within a reasonable time, specifying the expected time for execution.
(2) The payment service provider must notify all payment service users in advance of any suspension of the service plan for a period not less than five (5) working days before the service provision.
Article 67
The payment service provider must ensure that the rights and obligations of the payment service user are balanced, and that the validity of the conditions does not result from violating other conditions stipulated in the agreement.
Article 68
(1) The payment service provider must ensure that marketing, promotional, or advertising materials for payment services are available in Arabic, clear, and not misleading. All text and numbers contained in these materials must be understandable and clearly displayed. The font size used must be clear and legible.
(2) When providing any marketing, promotional, or advertising material for payment services, the payment service provider must ensure:
(a) The material includes the marketing, promotional, or advertising name of the payment service provider; (b) The material is not focused exclusively on benefits without clarifying the relevant risks; (c) Comparisons in advertisements between services or products provided by the provider or others are based on fairness and balance; (d) Information related to fees is accurate and compliant; (e) Information related to fees, savings, or costs is not misleading or unclear.
(3) The payment service provider must ensure that the marketing, promotional, and advertising materials do not contain phrases such as "subject to availability" unless the material clarifies to any payment service user that it is subject to meeting certain criteria.
(4) The payment service provider must apply approved procedures for reviewing and approving marketing, promotional, and advertising materials.
(5) The payment service provider may not send any marketing, promotional, or advertising material to any individual under the age of eighteen (18) years, unless these materials ensure that they do not contain any risks inappropriate for that category of payment service users.
(6) The Central Bank may order the withdrawal of any marketing, promotional, or advertising material for payment services if it does not meet the minimum standards or if it contains provisions inconsistent with the System or Regulation.
Section Two: Issuance and Redemption of Electronic Money
Article 69
(1) The contract for the provision of services by the electronic money company to the user of payment services must be compliant with the provisions stipulated in this Article for electronic money companies.
(2) The electronic money company must issue electronic money at its nominal value upon receipt of funds.
(3) The electronic money company may not:
(a) Grant interest linked to the duration of holding electronic money; (b) Provide any benefits linked to the duration of holding electronic money; (c) Provide withdrawal facilities on the statement to the payment service user, except through a partnership with a licensed bank or entity before the Central Bank, obtaining the Central Bank's approval for these purposes; (d) Use any protected funds for any purpose other than that stipulated in the Regulation.
(4) The electronic money company must, upon request, refund the value of the funds to the payment service user at their nominal value and at any time.
(5) The electronic money company must ensure that the contract concluded between the payment service user and itself clearly stipulates the conditions for refund and any related fees.
(6) Any fees must be proportional and compliant with the actual costs incurred by the electronic money company for the refund.
(7) The electronic money company must refund the full value of the remaining electronic money held by the user upon termination of the contract between the payment service user and the electronic money company. In cases exceeding this, no zero-yield returns may be deducted from the remaining balance of the electronic money to protect the protected funds.
(8) The electronic money company must clarify to the electronic money holder the method by which the remaining balance was consumed.
Section Three: Provision of Payment Services
Article 70
(1) A payment service provider must have a payment services policy that clarifies the risks and limits of user operations, including limits on electronic money and payment operations.
(2) Before implementing any change to the policy referred to in the above paragraph, the payment service provider must obtain the Central Bank's approval in accordance with Article 39 of this Regulation, and provide the updated policy details to the Central Bank upon request.
(3) The payment service provider must guide the Central Bank in determining the limits of user operations and payment levels, without violating risk management management standards or regulatory requirements related to governance, as determined by the Central Bank.
Article 71
(1) The payment service provider must commit to the issuance of a payment tool by:
(a) Preventing access to personal security characteristics of any person other than the payment service user; (b) Providing means of communication in a permanent manner to enable the payment service user to report any unauthorized use, exploitation, theft, or loss of the payment tool immediately after sending the payment.
(2) The payment service user must take all possible steps to protect the personal authentication data related to the payment account information or payment tool, and notify the payment service provider of the loss, theft, or unauthorized use of the payment tool or payment account information without delay, in accordance with the method agreed upon in the framework agreement.
Article 72
(1) The payment service provider is prohibited from executing any payment operation upon receipt of a payment service order.
(2) If the payment service order is received during working hours specified by the provider before the user, it must be executed at the beginning of the next working day. If received outside working hours on a working day, it must be executed at the beginning of the next working day.
(3) A payment service order may be scheduled for execution on a future date agreed upon between the payer and the provider, such that the payer's funds are available to the payment service provider on that date.
Article 73
(1) The payment service provider may suspend the payment account or reject the payment service order in the following cases:
(a) If the conditions for accepting or executing the payment service order are not met as stipulated in the contract between the provider and the user; (b) If the payment service provider has reasons to doubt that the payment operation is related to money laundering or terrorist financing, or any resulting fraudulent activity; (c) If the payment operation was issued in violation of any systems, regulations, or decisions applicable to the provider and the relationship.
(2) The payment service provider must notify the payment service user of the rejection of the order at the appropriate time, explaining the reasons for rejection and the mechanism for appealing it, taking into account the necessity of correcting the rejection. The rejection ends once the reasons for rejection are resolved or expire.
(3) The payment service user does not bear any fees for the operation in the case of rejection, unless otherwise stipulated in the contract between the provider and the user.
Article 74
(1) The user may not cancel a payment service order after it has been received by the payment service provider for the payer.
(2) The payer may not cancel a payment order after authorizing the provider to create the payment operation.
(3) The payer may not cancel a payment service order for direct debit operations after the end of the working day preceding the agreed day.
(4) The user may not cancel a payment service order after the end of the working day preceding the agreed day.
(5) Unless otherwise agreed between the payment service user and the provider, cancellation of a payment service order is prohibited after the cancellation period referred to in this Article is completed, including direct debit operations.
(6) The payment service user does not bear any fees for the cancelled payment service order, unless otherwise stipulated in the contract between the provider and the user.
Article 75
(1) The payment service provider must ensure the full transfer of the payment operation amount to the payee, in accordance with the provisions of this Article.
(2) The payment service provider must include clear records of the operations.
(3) The payment service provider must notify the payer of any fees or costs applied to the executed operations, taking into account the service agreements signed with them. The provider may not deduct fees or costs related to their services from the transferred amount, unless agreed upon with the payer and clearly included in the statement of the payment account credited to the payee.
(4) The payment service provider must ensure the full receipt of the payment operation amount by the payer upon execution.
(5) The payment service provider must ensure the full receipt of the payment operation amount by the payee upon execution.
Article 76
(1) The payment service provider must verify the addition of the payment operation amount to the payer's account by the end of the working day following the execution of the payment operation in parts or in Saudi Riyals for the payee.
(2) The payment service provider must verify the addition of the payment operation amount to the payer's account in the case of execution in a currency other than Saudi Riyals or outside the Kingdom, by the end of the third working day following the receipt of the payment service order, or any other day agreed upon with the user.
(3) The payment service provider must send the payment operation created by the payee to the payer in a manner that allows the payment service provider and the payer to agree on the time period for executing the direct debit settlement on the agreed due date.
Article 77
The provider may return the funds received by the payment service provider to the payer in the case of non-existence of the payment account, explaining the reason for the return of funds to the payee due to non-existence of the payment account with the payment service provider.
Article 78
(1) The payment service provider must deposit the payment operation amount to the payee on the date of addition to the payee.
(2) The payment service provider must ensure that the payment operation amount is placed under the payee's disposal immediately after depositing the amount in the provider's account, taking into account the time required for currency conversion to execute the service.
(3) The date of deduction of the value from the payer's specific payment account must be the date of deduction of the previous payment operation amount from the payer's specific payment account.
Article 79
(1) Payment operations authorized by the payer in the case of execution by the agreed method upon receipt by the provider are considered executed according to the payment service.
(2) If the payer claims that they did not authorize the payment operation or that it was executed in a defective manner, the payment service provider must prove that the payment operation was not defective and was accurately recorded.
(3) If the payment service provider claims that the payment operation was executed fraudulently, the payer must prove it and provide supporting evidence during the dispute resolution process.
(4) The payment service provider must prove that the payment operation was executed within the scope of its competence, with accurate recording and documentation of the payment operation.
Article 80
(1) The payment service provider does not bear the responsibility for the execution of the payment operation for the payer, unless it is proven before the payer that the payment service provider did not execute the payment operation properly for the payee, and the payer proves that it was executed properly for the payee.
(2) In the case of the responsibility referred to in the previous paragraph, the payment service provider must refund the amount to the payer and restore the payer's payment account to the state it was in before the execution of the incorrect payment operation.
(3) The payment service provider must, upon request from the payer, adjust the date of deposit of the amount similar to the date of execution of the payment operation in the case of delayed execution of the payment operation.
Article Eighty
(1) The payment service provider of the payer is responsible for the payment service provider of the payee to send the payment order in a correct and valid form, and to ensure its immediate receipt in a correct and valid form.
(2) The payment service provider of the payee must ensure the processing of the payment transaction and, at the appropriate time, execute the payment transaction correctly and credit the amount to the payee's payment account on the date of the payment.
(3) If the payer proves that the payment service provider of the payee was unable to prove that the payment transaction was executed correctly and validly, the payment service provider of the payee is not responsible for the payment transaction, whether executed incorrectly or not executed.
(4) If the payer proves that the payment service provider of the payee received the amount of the payment transaction, the payment service provider of the payee may determine the date of the amount in the payer's payment account, provided that the transaction was executed correctly.
Article Eighty-One
(1) The provisions of this article apply when the payer issues a payment order through a payment service.
(2) The payment service provider must refund the amount to the payer's account, and if the defective or non-executed payment transaction is not executed, the payer must be restored to the position they would have been in had the defective payment transaction been executed.
(3) The payment service provider must, upon the payer's request – immediately – compensate the payer for any loss resulting from the non-refund of funds to the payer's account, provided that the payment service provider is unable to prove:
(a) The receipt of the payment order by the payment service provider of the payer pursuant to Article Eighty-One; (b) That the payment transaction was recorded accurately and completely, and that its execution was not affected by a delay or defect within the scope of the payment service provider's work.
Article Eighty-Two
(1) In the event of the discovery or detection of a technical error in the execution of payment transactions, the payment service provider must evaluate the technical error within thirty days from the date of its discovery or detection, and inform all payment service users affected by that technical error of the amount involved.
(2) The payment service provider must, at the earliest possible time, notify the Central Bank through the channels – and communicate with the Central Bank – as soon as possible.
(3) The payment service provider must, at the earliest possible time, correspond with all payment service users affected, informing them of the technical error and the steps taken to correct it, including any amount to be credited to their accounts.
(4) The payment service provider must notify the Central Bank of the reasons for the delay in correcting the error within the specified period, pursuant to the first paragraph.
Article Eighty-Three
The payment service provider bears the responsibility of the payment service user for any fees resulting from the non-execution of the payment transaction, or the incorrect or delayed execution of the payment transaction, in accordance with the provisions of the Regulations.
Article Eighty-Four
In cases where responsibility is assigned to the payment service provider under the provisions of the sixth chapter of the Regulations, the payment service provider bears full responsibility for any unauthorized, incorrect, or delayed payment transactions, or for any payment transactions not permitted, resulting from non-compliance with the Regulations, systems, and instructions.
The payment service provider is obligated to take the verification measures stipulated in the Regulations, systems, regulations, and circulars relating to the relationship with the payment service user, and must compensate the payment service user for any amounts paid or losses incurred in the payment services.
Article Eighty-Five
(1) The payment service provider does not bear any responsibility for any errors committed by the payment service user during the creation of the payment transaction, such as incorrect details of the payee or an incorrect reference number for the payment.
(2) The payment service provider must exercise due diligence to return the funds received from the incorrect recipient of the payment transaction, and may charge the user fees for the payment transaction on the payment account. The payment service provider must also cooperate with the payment service provider of the payer and the payer to recover the funds to the maximum extent possible.
(3) If the payment service provider of the payer is unable to recover the funds, upon the written request of the payer, the payment service provider of the payer must provide the payer with all relevant available information to enable the payer to claim recovery of the funds.
(4) The Central Bank must request the payment service provider to take certain procedures according to the controls it puts in place, to recover the funds for the payer.
Article Eighty-Six
(1) The payment service provider must, in accordance with the provisions of Article Ninety, handle the complaint submitted by the payment service user regarding unauthorized payment transactions, taking into account the provisions of Article Ninety-Two.
(2) When a complaint is submitted regarding unauthorized payment transactions, the payment service provider must, in accordance with the provisions of Article Ninety-Two, handle this complaint.
(3) When submitting this complaint to the Central Bank, the payment service provider must prove that it has met the conditions stipulated in the first paragraph of Article Eighty-Five, and provide evidence to the Central Bank determining the extent of its compliance.
Article Eighty-Seven
(1) The payment service provider may, without prejudice to the provisions of the second, third, and fourth paragraphs of this article, not impose liability on the payer up to a limit of fifty (50) AED, arising from the use of a lost or stolen payment instrument, or losses incurred regarding unauthorized payment transactions.
(2) The provisions of the previous paragraph apply in the following cases:
(a) If the loss of the payment instrument or its theft or exploitation cannot be detected before the payer.
(b) If the loss resulted from the act or negligence of an employee, agent, or representative of the payment service provider, or an establishment engaged in payment services on behalf of the payment service provider.
(3) The payer bears all losses resulting from unauthorized payment transactions in any of the following cases:
(a) If the payer acted in a fraudulent manner.
(b) If the payer intentionally or through gross negligence violated the personal security characteristics of the payment instrument related to their obligations to maintain its safety.
(4) The payer does not bear any liability for losses incurred in cases where the payer acted in a fraudulent manner, except in the following cases:
(a) If unauthorized payment transactions arose after the payment service provider notified the payer of the loss or theft of the payment instrument, or the exploitation or use of the payer's specific payment instrument. (b) If the payment service provider failed to provide the means to enable the payer to notify them at any time. (c) If the payment service provider was not bound by the provisions of the Regulations, or any laws, regulations, circulars, or rules issued by the Central Bank to address certain risks by applying specific verification procedures, and the payment service provider did not apply them on the payer.
(5) If the provisions of the Regulations require the application of verification procedures issued by the Central Bank, or any laws, regulations, circulars, or rules to address certain risks, and the payment service provider did not apply them, or the payer did not accept them, the payment service provider must compensate the payer for any amounts paid or losses incurred, pursuant to the first paragraph of Article Eighty-Five of the Regulations.
Article Eighty-Eight
(1) The payment service provider must, without prejudice to the provisions of the eighth paragraph of this article and the first paragraph of Article Ninety-One, refund the amount of the unauthorized payment transaction to the payer in a correct manner, and restore the amount to the payer's payment account, as the case may be, for the unauthorized payment transaction.
(2) The payment service provider must refund the amount to the payer's account within the shortest possible time, and no later than the end of the working day following the day of receipt of the complaint, pursuant to the provisions of the first paragraph of this article.
(3) The provisions of the first and second paragraphs of this article do not apply if the payment service provider has reasonable grounds to suspect fraudulent behavior by the payment service user before notifying the Central Bank and the competent authorities, and has written the reasons.
(4) The payment service provider must, when refunding the amount from the payer's account, verify the date on which the amount was credited to the payer's payment account, and the date on which the amount was deducted from the unauthorized payment transaction.
(5) In the event of an unauthorized payment transaction, the payment service provider must, upon the request of the payment service provider of the payer, refund the amount to the payer's account, and if the payment service provider of the payer was not responsible for the transaction, the payment service provider of the payer must compensate the payer immediately for the amount of the unauthorized payment transaction, including the amounts paid.
(6) The payment service provider must, without prejudice to the provisions referred to in the first, second, third, and fourth paragraphs of this article, notify the payment service user of the result of the investigation, whether a refund or financial compensation, within seven days from the end of the investigation, and if there is a delay in paying any refund or compensation, the payment service provider must notify the payment service user of the reasons for the delay and the expected time for depositing the due amount.
(7) The payment service provider must maintain records related to the processing of refunds or compensations, including the matters referred to in Articles Eighty-Eight and Eighty-Nine of the Regulations, and submit these records to the Central Bank within a period of ten years from the date of the end of the investigation, taking into account the amounts refunded against the Central Bank's specified limits, and maintaining a sequential number for the original transaction.
(8) If the payment service provider notifies the payment service user of the recovery of funds pursuant to this article, the period during which the unauthorized payment transaction occurred, and any knowledge of it, must not exceed six months from the deduction date, unless the payment service provider failed to present the required information regarding the payment transaction according to the sixth chapter.
Article Eighty-Nine
(1) The payer may, without prejudice to the provisions of the first paragraph of Article Eighty-One, request the full refund of the amount, if the payment service provider of the payer provided the payer with any authorized payment transaction before or during the payment transaction, under the following conditions:
(a) If the authorization issued did not include the exact amount of the payment transaction or the authorization for the payment transaction.
(b) If the amount of the payment transaction exceeded the amount expected by the payer before payment, taking into account the nature of the payment transactions, the specific circumstances, and the contractual conditions of the payer.
(2) The payment service provider must, when refunding the amount from the payer's account, verify the date on which the amount was credited to the payer's payment account, and the date on which the amount was deducted from the unauthorized payment transaction.
(3) Exchange rate changes resulting from the application of the provisions of paragraph (b) of the first paragraph of this article cannot be relied upon by the payer, unless the exchange rate referenced in the contract is applied.
(4) The right to refund funds does not apply in the following cases:
(a) If the payer gave direct authorization to the payment service provider to execute the payment transaction.
(b) If information about the payment transaction was provided to the payer in the agreed manner at least four weeks before the due date of the payment, or before the payment service provider received the payment.
Article Ninety
(1) The payment service provider must, upon the payer's request, refund the funds to the payer before or during any authorized payment transaction, within eight weeks from the date of deduction of the funds.
(2) The payment service provider may request the payer to provide reasonable information to prove compliance with the conditions, and may refuse to refund the funds until it receives such information, as stipulated in the first paragraph of Article Eighty-One of the Regulations.
(3) The payment service provider must refund the full amount of the payment transaction or justify the refund to the payer within ten working days from the date of receiving the request, or within ten working days from the date of receiving any additional information requested, referring to the competent authorities, if the payer does not accept the subject matter.
Article Ninety-One
(1) The payment service provider must, upon the request of the payment service user, make every effort to trace any payment transaction, and must notify the client of the result, whether defective or non-executed, in cases where the payment service provider is responsible for the transaction, without charging any fees, in reasonable cases where the payment service provider is not responsible for the incorrect or non-executed payment transaction, in accordance with the provisions of the Regulations.
Chapter Seven: Protection and Preservation of Protected Funds
Article Ninety-Two
(1) The payment service provider must, in accordance with the following, protect and preserve protected funds:
(a) Preserve protected funds in a separate account at a licensed bank or any other means specified by the Central Bank.
(b) Comply continuously with all regulations, rules, controls, and circulars issued by the Central Bank relating to protected funds.
(2) Without prejudice to the provisions of the first paragraph of this article, if the payment service provider continues to hold protected funds, it must:
(a) Preserve protected funds in a separate account at a licensed bank by the end of the working day following the day of receipt, named "Deposit for Protection of Customers' Funds Belonging to the Payment Service Provider". (b) Invest protected funds in safe and liquid assets, subject to the approval of the Central Bank, and preserve them in an independent account with an approved custodian.
(3) The payment service provider must verify the inclusion of all agreements with the licensed bank regarding the preservation of protected funds, including in particular:
(a) The agreement clearly specifies the roles and responsibilities of the payment service provider and the licensed bank, in accordance with the Regulations.
(b) The account is maintained solely for the purpose of protecting protected funds, and is not used by the payment service provider or any other person, and is not linked to any financial obligations of the payment service provider. (c) The use of the preservation account is limited to preserving protected funds, and does not include the payment of operational expenses, fees, or other received funds, or the execution of any other payment services. (d) No person other than the payment service provider has the right to dispose of the preservation account. (e) The preservation account is subject to a daily settlement mechanism for payment transactions related to electronic money, according to the policies, procedures, and controls of the payment service provider. (f) Obtain a letter of non-objection from the Central Bank before closing or opening the preservation account, or merging or replacing it with another account. (g) Comply continuously with the requirements stipulated in the Regulations and any other requirements specified by the Central Bank.
(4) The payment service provider must obtain the Central Bank's non-objection before applying any policies and procedures related to the preservation of protected funds, and must notify the Central Bank and the payment service provider of any amendments to them.
(5) The policies and procedures related to the preservation of protected funds must include controls and procedures regarding the access mechanism to the protected funds, and the authorities of the employees involved.
(6) The payment service provider must obtain the Central Bank's approval before adopting new methods for preserving protected funds.
Article Ninety-Three
(1) The payment service provider must guarantee the protection of protected funds throughout the retention period, in accordance with the provisions of the Regulations, whether received directly from an electronic money distributor or through an agent.
(2) No person other than the payment service provider may have any interest or right in the protected funds.
(3) The payment service provider must return protected funds to the users of the payment service, without prejudice to the relevant regulations, in the event of the payment service provider's liquidation, suspension, or any insolvency situation.
Chapter Eight: Provision of Payment Account Information Services
Article Ninety-Four
(1) The payment service provider must provide access to payment account information services, in accordance with the relevant decisions, and the guidelines issued by the Central Bank regarding open banking, cyber security, and data privacy, and the competent authorities in the country.
(2) The payment service provider must ensure the achievement of the highest standards of security levels when preserving, transferring, and sharing payment account information services, and when participating in processes related to the payment account information service, including the sharing of customer data.
Article Ninety-Five
(1) The payment service provider must enable the payment service provider of the payer to provide payment account information services to the payer, provided that the payer authorizes access to accounts to another payment service provider, and in a manner that allows the identification of any subject on an objective and fair basis, without obstacles, and in an effective and timely manner.
(2) The payment service provider of the payer must:
(a) Communicate and transfer information securely to the payment service provider of the payer.
(b) Implement policies and procedures to verify the validity and integrity of all payment orders; and obtain the payer's approval for any fees applicable to these fees, in accordance with the Regulations, laws, controls, and circulars issued by the Central Bank and the competent authorities. (c) Provide the payment service provider of the payer immediately upon receipt of all payment transaction information and all information related to the payment transaction. (d) Handle the payment transaction order issued by the payment service provider of the payer in the manner in which it is handled, in accordance with the payment transaction order issued directly by the payer. (e) Respond to the payment transaction order issued by the payment service provider of the payer at an appropriate time. (f) Handle the data request issued by the payment service provider of the payer in the manner in which it is handled, in accordance with the data request issued directly by the payer. (g) Respond to data requests issued by the payment service provider of the payer within a reasonable time. (h) Not be obligated to conclude a commercial contract before providing payment account information services or payment transaction services, unless the requirements referred to in this article are met.
(3) The payment service provider may refuse access to payment account information services or payment transaction services for reasonable, justified, and proven reasons related to access, based on suspicion of fraud or unauthorized transactions. In these cases, the payment service provider must:
(a) Notify the payment service provider of the payer or the payment account information service provider of the refusal.
(b) Take action according to what the Central Bank specifies, including the details of the incident and the reasons for the refusal.
(c) Restore access to the payment service provider of the payer or the payment account information service provider upon the removal of the reasons for refusal.
Article Ninety-Six
(1) The payment service provider of the payer must obtain authorization from the payment service user before providing the service.
(2) The payment service provider of the payer may not retain funds for the payment service user at any time.
(3) The payment service provider of the payer may not modify the amount or modify the payment transaction for any other purpose.
(4) The payment service provider of the payer must protect all payment service users' data, including personal security characteristics, and not allow access to other parties.
(5) The payment service provider of the payer may not use or store any user's payment service data, unless it is necessary to provide the service in accordance with the authorized service.
(6) The payment service provider of the payer may not request additional information from the payment service user, unless authorized by the payment service user.
(7) The payment service provider of the payer may not request any data from the payment service user other than the data necessary for the service, according to the nature of the service provided and what is specified by the Central Bank.
(8) The payment service provider of the payer must communicate securely with the payment service provider of the payer regarding the identification and definition of the account.
Article Ninety-Seven
(1) The payment service provider of the payer must provide comprehensive and clear information to the payer before creating a payment transaction, including at least:
(a) The name of the payment service provider of the payer.
(b) The address of the main office of the payment service provider of the payer.
(c) The address of the main office and branches, or the agent, through which the payment service provider of the payer provides services, as required.
(d) Contact details for communication with the payment service provider of the payer, including the electronic mail address.
(e) Contact details with the Central Bank.
(2) The payment service provider of the payer must provide the payer with the payment transaction order upon creation, as required:
(a) Confirmation of the completion of the payment transaction order with the payment service provider of the payer.
(b) The reference number of the payment transaction for the payer's payment account.
(c) The identity of the payer, if possible.
(d) The amount of the payment transaction, if available.
(e) The payment transaction details.
(f) The payment transaction order issued by the payment service provider of the payer to the payment service provider of the payer.
Article Ninety-Eight
(1) The payment service provider of the payer must obtain authorization from the payment service user before providing the service.
(2) The payment service provider of the payer must delete the relevant data and information related to the payment service user after cancellation or withdrawal of authorization, in accordance with the Regulations and instructions.
(3) The payment service provider of the payer must verify the personal security characteristics of the payment service user, ensuring their transfer securely and effectively through secure channels, and maintaining their confidentiality, and not allowing access to them except by the payment service provider of the payer.
(4) The payment service provider of the payer must communicate securely with the payment service provider of the payer regarding the identification and definition of the account.
(5) The payment service provider of the payer must limit access to the specific payment accounts.
(6) The payment service provider of the payer may not request sensitive data related to payment accounts for use in fraudulent transactions.
(7) The payment service provider of the payer may not use or store any data for other purposes or storage, unless requested by the payment service user for the service.
Article Ninety-Nine
(1) The payment service provider may not provide payment services on the card list, unless the payment service provider provides the payer with confirmation of the availability of funds in the payer's payment account for the purpose of executing the payment transaction related to the service, subject to the commitment to obtain the payer's authorization before providing the service, and applying the verification and connection requirements specified by the Central Bank.
(2) The payment service provider must, upon receiving the request for confirmation of the availability of funds from the payment service provider, respond immediately with "Yes" or "No", provided that:
(a) The payer has access to the payment account through the internet.
(b) The request includes the validity of the responses from the payment service provider of the payer, and the prior authorization of the payer.
(3) The payment service provider must notify the payment service provider of the payer of the request and the answers.
(4) The payment service provider of the payer is prohibited from including information about the account balance or account funds in the response to the request for confirmation of the availability of funds pursuant to this article.
(5) The payment service provider is prohibited from saving any confirmation received pursuant to this article for any service other than the payment transaction on the card list for which the request was made.
(6) The provisions of this article do not apply to payment transactions created through stored and executed electronic money, or using the card list.
Chapter Nine
Payments
Chapter One
Classification of Important Payment Systems
Article (101)
The Central Bank has the authority to classify a payment system as an important payment system or likely to become one, according to the following criteria:
(a) Whether the payment system, in its current state, poses any risk to financial stability or has the potential to cause disruption, or whether it transfers or causes any disruption to other payment systems, considering its size, importance, and linkage to the sector, as well as the absence of alternative payment systems.
(b) The extent of the system's linkage to the financial market infrastructure, whether domestic or outside the Kingdom, including settlement and clearing.
(c) The estimated total or average value of transfers or orders processed, settled, or cleared within one working day, or the nature of the payment system's orders.
(d) The number of direct and indirect members of the payment system.
Article (102)
(1) The operator of a payment system shall notify the Central Bank of the commencement of the evaluation process according to the classification criteria mentioned in this Article, taking into account the possibility of starting the evaluation concurrently with the licensing procedures of the applicant. In cases where the evaluation is repeated more than once – including but not limited to – the Central Bank may determine, or if it becomes evident during the evaluation process that the results indicate a likelihood of the payment system becoming an important payment system, the Central Bank may recommend re-evaluation based on the previous evaluation recommendations.
(2) The operator of a payment system, including its management, board of directors, senior service providers, employees, and agents, must cooperate with the Central Bank and provide all documents, information, and data related to the system's characteristics and clarify the extent of their relevance to the classification criteria.
(3) The Central Bank may request the operator of the payment system, whether domestic or outside the Kingdom, whether an institution, establishment, or entity inside or outside the Kingdom, or a person or entity with which it cooperates, to:
(a) Provide documents, information, or data related to the payment system and its operations, according to what the Central Bank determines.
(b) Enable the Central Bank to access employees of the operator of the payment system or any representatives.
(c) Provide evaluation reports necessary to facilitate the evaluation process, according to what the Central Bank determines.
(4) The Central Bank shall coordinate with any regulatory authority or central bank in other countries or with any other authority to ensure compliance with the applicable regulations, and provide documents, information, or data related to the evaluation process.
(5) The Central Bank shall determine the duration of the evaluation process based on the specific circumstances of each case, considering the nature and degree of the system, the complexity of its operations, and its interconnectivity.
(6) Before making a classification decision, the Central Bank shall coordinate with the official representative of the operator of the payment system and the relevant international supervisory or regulatory authorities.
(7) The Central Bank shall notify the operator of the payment system of the result of the evaluation process, including the date of implementation of the classification, the rules and regulations, and the provisions of the Payment System Law applicable to the system in its capacity as a classified system, and the activities the system is permitted to conduct through it. The system shall not be allowed to operate as an important payment system.
(8) The Central Bank shall publish its decision to classify the system as an important payment system and register it as an important payment system in the public register.
(9) The Central Bank shall register the operators of payment systems subject to its supervision after fulfilling the requirements related to the licensed payment system operators.
(10) The Central Bank may direct the operator of an important payment system to suspend or modify any of its operations according to the regulations and what the Central Bank determines.
Article (103)
The Central Bank shall establish frameworks and controls related to the interconnection of different payment systems inside and outside the Kingdom.
Chapter Two
Principles of Financial Market Infrastructure Requirements
Article (104)
(1) The operator of an important payment system must comply with the guidelines and criteria according to its classification.
(2) The operator of a non-classified payment system may comply with the guidelines and criteria to:
(a) Ensure the alignment of its work with risk management objectives and the verification of its compliance with the relevant guidelines and criteria, to protect financial stability and enhance it.
(b) Align with the principles and criteria in proportion to the nature and size of the system and the degree of interconnection of its operations.
(c) Follow the instructions issued by the Central Bank within the framework of the licensing process or what it follows.
(3) The Central Bank may impose on the operators of payment systems requirements higher than those stipulated in the Principles of Financial Market Infrastructure, based on its assessment of their impact on financial stability and the likelihood of risks.
(4) The operator of a payment system must apply these requirements continuously and in all cases when conducting all its business, including when operating the payment system, providing new services, or reviewing performance-related activities, and in the presence of any changes to control mechanisms regarding risks.
Article (105)
(1) The operator of a payment system must comply with the system's management and operation requirements by:
(a) Ensuring the safety and integrity of the payment system in a manner that enhances financial stability.
(b) Operating the payment system in a secure and effective manner designed to reduce the likelihood of any system failure, maintaining an operational uptime of at least 99.98%.
(c) Establishing operating rules compatible with the requirements specified in paragraph (b) of this Article, and any other requirements determined by the Central Bank related to the operating rules of the system for important payment systems. (d) Establishing appropriate arrangements to monitor the implementation of commitments under the operating rules, including providing the necessary resources for the operator of the payment system. (e) Providing appropriate financial resources for the system to perform its functions and operations correctly. (f) Preparing plans for resolution and termination in accordance with the principles and requirements of international relevance, and updating the financial infrastructure annually.
(2) The operating rules for the system for important payments must include:
(a) Provisions allowing for the exclusion of one of the members from the system in case of insolvency.
(b) Provisions establishing arrangements for managing appropriate defaults for the system, ensuring their comprehensiveness for all circumstances and cases.
(c) Providing appropriate and necessary arrangements to deal with situations where the operator of the system or the provider of the system's services is unable to perform its obligations, or to settle its commitments to the system's clearing center or services. (d) Operating rules for members requiring them to cooperate with the Central Bank by providing any data, documents, or information upon request.
(3) The Central Bank's approval must be obtained before adopting any changes to the operating rules specific to the payment system or making any changes.
(4) The operator of a payment system must verify the execution of all operations related to the payment system in a secure manner, including:
(a) Verifying the execution of transfer or settlement orders for the purposes of the payment system.
(b) The accuracy and robustness of the payment system's operation.
(c) Controlling access to the payment system.
(d) Controlling and safeguarding information and controlling access to it.
(e) Managing risk control and control procedures related to the operation of the payment system.
(f) Ensuring the safety of the payment system, thereby ensuring the safety of the financial system.
(g) Ensuring the safety of the infrastructure services related to the payment system.
(5) The operator of a payment system must verify the execution of all operations related to the payment system efficiently and effectively, including:
(a) The speed and efficiency of executing operations related to transfer orders through the payment system.
(b) The appropriateness of the total cost to the member participating in the payment system in exchange for the services provided by the payment system, for the payment system members.
(c) Appropriate acceptance criteria for payment system members.
(d) Appropriate measures to prevent unfair competition or exploitation of the lack of competition in the functions performed by the system.
(6) The operator of a payment system must ensure the safety and continuity of the operation of the payment system in accordance with all instructions issued by the Central Bank, including principles and international relevance.
Article (106)
(1) The operator of an important payment system must conduct a self-assessment of its compliance with the Principles of Financial Market Infrastructure at least annually or upon any fundamental change in the system's operation, or as requested by the Central Bank.
(2) The operator of a payment system must enable the Central Bank to access the payment system and cooperate with the Central Bank in providing relevant information and data to conduct the evaluation process for the payment system, according to the Central Bank's authority.
(3) The operator of an important payment system must publicly disclose its self-assessment responses in a manner consistent with the disclosure framework issued by the Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) "Framework for Financial Market Infrastructures", after obtaining a letter of non-objection from the Central Bank.
(4) The operator of a non-classified payment system must conduct a self-assessment of its compliance with the Principles of Financial Market Infrastructure periodically, according to what the Central Bank determines or in accordance with the agreement with the Central Bank regarding those licensed to work with it.
Article (107)
(1) The operator of an important payment system must ensure adequate financial resources for its operations, including an assessment of capital adequacy, and maintain the mechanism for operating the payment systems.
(2) The operator of a non-classified payment system must ensure adequate financial resources for its operations, including an assessment of capital adequacy, and maintain it in proportion to the nature of the payment system's work.
(3) The non-classified payment system must retain financial resources equivalent to the cost of operating its system for a period of at least six months, in addition to ten million Saudi Riyals in the form of capital.
Chapter Three
Powers
Article (108)
(1) The Central Bank may request any information or documents from the operator of a payment system or one of its members when exercising its powers under the Law and Regulations.
(2) The operator of a payment system must provide the requested documents or information within the specified period in the request, ensuring the cooperation of the member concerned in providing the requested documents or information, without prejudice to any other powers of the Central Bank.
(3) The Central Bank may inspect any accounts or books of the operator of a payment system or its operations, ensuring the cooperation of all its members in the manner requested.
(4) The Central Bank may request the operator of a payment system or a member to submit a report prepared by one or more external auditors, and the operator must ensure the cooperation of the member concerned in the necessary manner regarding the subjects requested by the Central Bank to perform its duties and exercise its powers under the Law and Regulations.
Article (109)
(1) The operator of a payment system must direct the Central Bank to the operating rules of the payment system, including arrangements for services related to the payment system provided by the operator before requesting to conduct or modify any part of them.
(2) The operators of payment systems must notify the Central Bank of any changes or modifications to the operating rules of the payment system and obtain its approval before implementation.
Article (110)
The operator of a payment system must direct the Central Bank to conduct a verification of compliance with the provisions of the Law and Regulations, including the justifications for the procedures to be adopted or the standards to be established for the services provided or the operation of the system, and the periods the Central Bank deems appropriate.
Article (111)
Without prejudice to any other powers of the Central Bank, the Central Bank may appoint one or more persons to inspect its personnel and the operator of a payment system. The operator of a payment system or the service provider must, with the written permission of the Central Bank and in the manner determined by the Central Bank:
(a) Grant the designated inspector access to any part of the payment system at any time upon request, or to the buildings through which or in which the services are provided, as appropriate.
(b) Cooperate with the inspector by providing all data, information, and documents necessary for him to perform his duties.
Article (112)
The operator of a payment system may request the Central Bank to appoint an expert to prepare reports on the operation of the payment system, specifying the requirements and the duration, as well as the disclosure and publication of the report, its content, and the mechanism for dealing with it, and the expertise and specialization of the required expert, according to the following cases:
(a) If the operator of the payment system fails to comply with the guidelines, standards, and principles stipulated in the Principles of Financial Market Infrastructure.
(b) If there is any other necessity to enable the Central Bank to perform its duties related to the payment system according to the Law and Regulations.
Article (113)
The operator of a payment system may, under the arrangements for managing defaults in the payment system, take measures against any of the members regarding information related to the payment system. The operator must direct the Central Bank to a designated employee in case of default to determine the responsibilities related to the member's default or any issue arising in the payment system, and examine any employee responsible regarding any disputes among the members about responsibilities, any loss resulting from the member's default, and the disputes arising in the system, and the procedures and rules in the default case.
Article (114)
(1) The Central Bank may decide to exempt the cross-border payment system from the provisions of paragraph (2) of this Article, subject to obtaining a license according to the Regulations, and decide not to apply some of the provisions, obligations, or articles, provided that the conditions of the cross-border payment system are as follows:
(a) It will not be subject to the scope of application stipulated in Article (104).
(b) It will operate in countries other than the Kingdom.
(2) When issuing a decision to exempt or grant an exception to the cross-border payment system, the Central Bank shall take into consideration:
(a) The extent of its subject to a regulatory authority or its participation in regulatory roles, and the nature and scope of the jurisdiction of these authorities, considering that it is located in more than one jurisdiction outside the Kingdom, and the basis for appropriate cooperation with them. (b) The existence of an acceptable basis at the Central Bank as an alternative to the Central Bank's licensing and supervision of the system's operations, including the right to issue instructions and apply information in the Kingdom. (c) The extent to which the Central Bank can achieve the objectives of regulating and supervising the payment system, and the extent of its contribution as a basic alternative. (d) The extent of the Central Bank's ability to supervise its compliance with the Principles of Financial Market Infrastructure and its ability to fulfill the responsibilities of the specified regulatory authorities regarding financial market infrastructure principles.
(3) The Central Bank shall announce its decision regarding dealing with the cross-border payment system, clarifying the approach and exceptions, while observing the principles of transparency and disclosure.
(4) If the cross-border payment system was subject to the provisions of paragraphs (a) and (b) of paragraph (1) of this Article, the operator of the payment system must comply with the following in the Kingdom or when conducting additional operations outside the Kingdom:
(a) There is a memorandum of understanding between the Central Bank and the relevant authority in the country concerned regarding supervision.
(b) The Central Bank has established that the country concerned has a similar legal system, and that there is an exchange of information and powers regarding supervision of the important payment system, including implementation.
Chapter Four
Settlement Finality
Article (115)
(1) The operating rules of the important payment system must include procedures and rules to enable the completion of settlement finality, so that it does not exceed the specified time and date for settlement.
(2) The relevant procedures and rules must include verification of settlement finality for all cases in which orders are executed.
(3) The results of all money transfer operations must be final and irrevocable, without prejudice to what is stipulated in Article (106), and the final payments must not be subject to reversal, repayment, or avoidance of application, or conflict with the application of settlement and clearing arrangements and default management arrangements.
(4) The operating rules for the important payment system must clarify the provisions related to all operations and functions, including but not limited to:
(a) Payment orders.
(b) Settlement procedures.
(c) Arrangements related to protection.
(d) Clearing arrangements.
(e) Collateral.
(f) Default management arrangements.
(5) The Central Bank may request any documents or reports proving compliance with all provisions mentioned in this Article.
(6) The operating rules for the important payment system must explicitly and clearly stipulate all related provisions, considering the following from Articles (110), (109), and (106):
(a) The operating rules must not conflict with the requirements of protection, validity, and binding nature of final payment orders and clearing arrangements.
(b) The operating rules must not conflict with procedures for resolution, termination, and winding up, including bankruptcy procedures, and the optional and non-optional decisions and procedures resulting from them, or the administrative procedures equivalent to them, or the regulations and systems governing the relationship with its members or the payment system, which may impose restrictions or suspend their execution, completing the payment operations resulting from payment orders.
(7) The provisions of Article (106) do not apply to final payment orders created at the end of the trading day, if the required notification or order is published or directed to the competent authority to stop operations, restructure the important payment system, or declare bankruptcy or termination, and the day of termination of the voluntary termination procedures is completed.
(8) The Central Bank may exempt a system from some of the provisions of this Article, applying the exception decision from the day following the day it was issued, and published in the manner determined by the Central Bank.
(9) The Central Bank may apply some or all of the provisions of this Article to the operating rules of non-important payment systems.
Article (116)
Without prejudice to the laws and regulations prevailing in the Kingdom:
(1) The operator of a payment system must notify the Central Bank in the event of a serious disruption and take the necessary measures to address it.
(2) The operators of payment systems must prepare policies and procedures for measures to address serious disruption incidents, which include:
(a) Communication procedures with internal and external stakeholders in a timely and appropriate manner.
(b) Steps and procedures to resolve problems resulting from serious disruption, considering their efficiency and effectiveness.
Article (117)
(1) The operating rules of a payment system must obligate the operator to immediately notify the members upon learning of:
(a) The initiation of bankruptcy proceedings against the operator or the likelihood thereof.
(b) The initiation of bankruptcy proceedings against any member or the likelihood thereof.
(2) The operator of a payment system must immediately notify the Central Bank upon learning of the bankruptcy of any member or the likelihood thereof.
Chapter Ten
Supervision and Control
Article (118)
(1) The Central Bank shall monitor the practices of payment service providers and operators, and evaluate their compliance with payments.
(2) The Central Bank shall exercise its supervisory duties through conducting supervisory visits, inspecting licensed premises, branches, and agencies, and requesting reports and risk assessments as it deems necessary to perform its duties, including monitoring and examining cases of suspected violations by payment service providers and operators, in accordance with any instructions, decisions, or circulars issued by the Central Bank, and the regulations.
Article (119)
Payment service providers and system operators may form a committee or more with the approval of the Central Bank to study challenges and recommendations for the development of the payment systems and services sector.
Article (120)
(1) The licensed must periodically provide data and reports to the Central Bank according to what the Central Bank determines.
(2) The licensed must submit financial quarterly statements to the Central Bank, taking into account that the Central Bank determines what is submitted annually, and that these reports include any information determined by the Central Bank, and that they are reviewed by an external auditor before submission. (3) The licensee commits to providing audited and reviewed annual financial data to the Central Bank according to what the Central Bank determines. (4) The Central Bank may modify the list and content of the reports required to be submitted by the licensee, and direct the licensee to submit a report directly to the Central Bank through an external auditor appointed for a specific scope of review; the licensee must appoint the auditor in the manner determined by the Central Bank.
Article (121)
(1) The licensee must notify the Central Bank as soon as possible and within a period not exceeding ten calendar days from the date of knowledge of the occurrence of any of the following:
(a) Any event that disrupts or prevents the operation of more than one payment service or the service it provides.
(b) Any violation of its obligations under the laws, regulations, or regulations related to the relationship.
(c) Any judicial or criminal action taken against any of the members or holders of leadership positions, inside or outside the Kingdom.
(d) The initiation of any bankruptcy, exit, or winding-up procedures from the market, or the appointment of a judicial trustee or liquidator, temporarily under the system of any country.
(e) Any disciplinary action or penalty imposed against it before a regulatory or supervisory authority outside or inside the Kingdom.
(f) Any change in the regulatory or supervisory requirements applicable inside or outside the Kingdom, contrary to the requirements of the Central Bank.
(g) Cases of fraud.
(h) Any other event determined by the Central Bank.
In any case where the Law, Regulations, or rules specify a different period, the licensee must submit the notification within the shortest period specified in the Regulations.
(2) The licensee must comply with the notification obligations stipulated in paragraph (1) of this Article, and immediately notify the Central Bank of any operational incident or any incident classified as "major" according to the instructions related to customers.
Article (122)
(1) The inspectors appointed by decision of the Conservator under paragraph (1) of Article (115) shall:
.. Collect necessary evidence, complete and secure the reports.
(2) The inspectors may resort to the police for arrest if necessary.
(3) The inspectors may resort to specialists at individuals or companies to conduct supervision and inspection of the materials and places that require investigation, and their task is limited to identifying the materials and places related to the violations. (4) The inspectors are subject to any laws, systems, procedures, or rules related to their work.
Article (123)
(1) The Central Bank may request a report on any subject previously requested by the Central Bank, from:
(a) The payment service provider.
(b) The operator of a payment system.
(c) A member who holds a leadership position, agent, employee, or external auditor of the payment system or the operator of a payment system.
(d) The controller.
(2) The person designated to submit the report must be:
(a) Approved or certified by the Central Bank.
(b) Possess the necessary skills to prepare the required report, according to the Central Bank's assessment.
Article (124)
The licensee must close its commercial activities, in the first instance and with priority given to the relevant provisions, without obtaining a letter of non-objection to begin winding-up or termination procedures, or partial or full bankruptcy, and in this case, the Central Bank must request the necessary information and documents from the licensee.
Article (125)
The Central Bank may exempt a person or group of persons from some licensing requirements related to certain regulations to stimulate innovation in the development and operation of payment services, while observing transparency and fairness in the payment system in the Kingdom.
Article (126)
The inspector appointed by decision of the Conservator under paragraph (1) of Article (115) must meet the following:
(1) Be a Saudi national.
(2) Have a good reputation and conduct.
(3) Not have been convicted of any crime involving moral turpitude or dishonesty that would lead to his dismissal.
(4) Hold a university degree or its equivalent.
Article (127)
The Central Bank may direct the licensee to take one or more corrective measures to ensure compliance with the provisions of the Law, Regulations, or Instructions, including:
(a) Taking any procedures to correct the current situation according to the specified method and period.
(b) Closing one of its branches or platforms.
(c) Ceasing to deal with one or more counterparties; (d) Prohibiting, restricting, or suspending specific products or services; (e) Imposing gradual cessation and control restrictions.
The Central Bank shall issue the penalty decision within the powers granted to it by Article (25) of the System, in accordance with the schedule for classifying violations and determining penalties for each violation of the provisions of the System, Regulations, or related decisions or instructions.
(3) Upon the issuance of the Central Bank's decision to cancel the license, the licensee must:
(a) Immediately cease conducting the activity related to the cancelled license, in accordance with the license; (b) Announce the cancellation of the license in the manner specified by the Central Bank, ensuring compliance with any other requirements, and in accordance with the relevant systems, regulations, and decisions; (c) Enter into liquidation procedures within a period not exceeding six months from the date of notification of the license cancellation to the licensee; and the Central Bank has the right to appoint a liquidator to implement the liquidation process in accordance with the relevant systems, provided that everything is done as previously specified; (d) Retain records and data as determined by the Central Bank for the specified period, in a manner that does not conflict with the relevant systems.
(4) The Central Bank shall follow up on the implementation of a corrective action plan according to the time period specified.
(1) Inspectors may be appointed by a decision from the Governor, issued pursuant to the first paragraph of Article (15) of the System. They may not leave their work until they are deemed to have completed their work, and they, along with police officers, experts, and specialists, are prohibited from disclosing any secrets they become aware of in the course of their work, unless required to do so by any implementing regulations or system provisions.
(1) The provider of payment services must handle complaints in a timely and fair manner, ensuring compliance with the provisions of the System, regulations, rules, instructions, and circulars, as well as the terms of the contract with the customer.
(2) The provider of payment services must make every effort to resolve all aspects of any complaint received within a reasonable time, and respond in writing through agreed-upon means and channels with the user of the payment service.
(3) The provider of payment services must, at a minimum:
(a) Establish a system and channels for receiving and managing complaints, including a dedicated function to receive, classify, track, and determine the status of complaints submitted by customers, while ensuring communication details with the Central Bank for complaint resolution; (b) Prepare policies and controls for handling and resolving customer complaints, in accordance with all requirements issued by the Central Bank regarding the regulation of the relationship between the provider of payment services and the users of its services; (c) Provide free contact numbers (landline and mobile) for users of payment services to communicate with the provider, and publish them on all available channels, explaining the services provided and the complaints; (d) Provide additional communication channels, such as internet-based forms or direct contact, to facilitate communication with the provider's representatives; (e) Provide a document outlining the procedures for submitting complaints, enabling customers to access it, and clarifying the required documents and available channels and means for submission; (f) Provide all necessary information to enable users of payment services to follow up on their complaints; (g) Document and retain all complaints and the mechanism used to communicate with users of payment services regarding them; (h) Provide users of payment services with the necessary information if they wish to escalate a complaint to the Central Bank, in case of dissatisfaction with the result of resolving their complaint or the provider's response, and direct them to the relevant party for resolution.
(4) The provider of payment services must handle complaints within the specified period as follows:
(a) Send an acknowledgment of receipt of the complaint to the customer within forty-eight (48) hours; (b) Provide a complete response to the complaint within a suitable period not exceeding ten (10) calendar days from the date of receipt of the complaint; (c) If a complete response cannot be provided due to reasons beyond the provider's control, send a brief response indicating the reasons for the delay and specifying a final deadline for providing the complete response, which must not exceed one-third of the specified period from the date of receipt of the complaint.
(5) The provider of payment services must submit the complaint handling procedures to the Central Bank for approval, and may modify or change them to comply with the requirements of the Systems, Regulations, Rules, Instructions, and Circulars related thereto.
(6) The provider of payment services must provide the Central Bank with an annual report on complaints from users of its payment services, in the format determined by the Central Bank.
(7) In addition to the complaint handling procedures with the payment service provider, the Central Bank shall take the necessary measures to receive, monitor, and consider user complaints regarding the service, and may, when necessary, refer user complaints to the provider for corrective action to resolve their complaints.
The Banking Disputes Committee shall resolve disputes arising between the parties to the payment services system, including ruling on complaints and resolving disputes, and decisions of the Central Bank related thereto.
The Implementing Regulations of Payment Service Providers issued by the Central Bank on 5/6/1441 H (corresponding to 30/1/2020 G) are hereby repealed and replaced.
(1) The licensed provider of payment services is considered a licensed provider of payment services under these Regulations and is subject to them.
(2) The operator of the payment system or the provider of payment services must submit a corrective action plan, including the provisions contained in the Regulations, within a period not exceeding six months from the date of implementation of the Regulations.
These Regulations shall be effective from the date of their issuance.
Read the rest free
Source: Saudi Central Bank — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from SAMA
We email you every new SAMA publication the day it's published.