2021-03-15
Added · Updated
Payment Service Providers (PSPs) with headquarters in Portugal must comply with the European Banking Authority’s Guidelines on ICT and security risk management (EBA/GL/2019/04) regarding operational and security risks. PSPs are required to prepare an annual assessment report of these risks as of June 30 each year and submit it to the Bank of Portugal by July 31 of the same year. The first such report, covering the period ending June 30, 2021, must be submitted by July 31, 2021. This instruction applies exclusively to PSPs and does not extend to investment firms or branches of EU-authorized credit, electronic money, or payment institutions.
BDP published 1 document in the last 30 days — get each new one by email the day it lands.
Instruction No. 4/2021
BO No. 3/2021 • 2021/03/15
..................................................................................................................................................................................................
Topics
Supervision :: Prudential Standards
Mod. 99999940/T – 01/14
Index
Text of the Instruction
Article 1.º Recipients
Article 2.º Operational and security requirements
Article 3.º Annual report on the assessment of operational and security risks
Article 4.º Entry into force and final provision
Text of the Instruction
Subject: Instruction on the management and reporting, by payment service providers, of operational and security risks
In 2017, the European Banking Authority (EBA) published the “Guidelines on security measures to manage operational and security risks under Directive (EU) 2015/2366” (EBA/GL/2017/17), establishing a set of security requirements in Information and Communication Technologies (ICT) for payment service providers (PSPs).
Additionally, also in 2017, the EBA published the “Guidelines on ICT risk assessment within the supervisory review and evaluation process (SREP)” (EBA/GL/2017/05) with the aim of ensuring the convergence of supervisory practices in the assessment of ICT risk, as specified in detail in the “EBA Guidelines on common procedures and methodologies for the SREP” (EBA/GL/2014/13).
In February 2019, the EBA published the “Guidelines on Outsourcing” (EBA/GL/2019/02) which establish procedures and requirements for effective management of ICT outsourcing, for which purpose the Bank of Portugal issued Circular Letter No. CC/2019/000000651.
More recently, on November 28, 2019, the EBA published the “Guidelines on ICT and security risk management” (EBA/GL/2019/04, hereinafter “Guidelines”), addressed to credit institutions, investment firms, and PSPs. These Guidelines incorporate and revoke the previous “Guidelines on security measures to manage operational and security risks under Directive (EU) 2015/2366” (EBA/GL/2017/17). Specifically, the Guidelines specify the measures and procedures that financial institutions must adopt, within the scope of operational risk and internal governance, to manage their ICT and security-related risks (which include, among others, on the one hand cybersecurity risk and, on the other hand, operational and security risks related to payment services).
In this context, the Guidelines provide, by reference to Article 95(2) of Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market (PSD2), that PSPs must communicate to the Bank of Portugal a comprehensive and updated assessment of the operational and security risks related to the payment services they provide, as well as the adequacy of the risk mitigation and control measures implemented in response to these risks. This annual communication aims to collect relevant information on the operational and security risks of payment services, ensuring that the entities concerned control these risks, as well as their exposure to severe operational and security incidents.
The Bank of Portugal communicated to the EBA its intention to comply with the aforementioned Guidelines from June 30, 2020, and in this context published Circular Letter No. CC/2020/00000029, of May 6, disclosing to the entities concerned its intention and the respective compliance date with the Guidelines.
The purpose of this Instruction is to implement the requirements contained in the Guidelines, including the duty to report the annual assessment of operational and security risks of the payment services provided.
It should be noted that the Instruction is addressed exclusively to PSPs, and therefore does not apply to Investment Firms, to branches in Portugal of credit institutions authorized in other European Union (EU) Member States, to branches of electronic money institutions with headquarters in the EU, and to branches of payment institutions with headquarters in the EU.
The Bank of Portugal emphasizes the importance of these Guidelines for strengthening the operational resilience of the financial sector.
Firstly, the Guidelines introduce greater specification of supervisory expectations regarding ICT and security risks and thus strengthen the current prudential requirements, particularly in the ICT risk self-assessment questionnaire of credit institutions whose results are taken into account in the SREP, namely in the capital risk analysis, in the information systems category, and in the context of operational risk.
Secondly, the Guidelines describe with greater clarity the responsibilities of senior management and the second and third lines of defense in the management of ICT strategy and governance model.
Thirdly, the Guidelines strengthen the Bank of Portugal’s recent strategy for strengthening operational resilience in terms of cybersecurity, complementing Instruction No. 1/2019 and Instruction No. 21/2019, which establish duties to report operational and security incidents, and cybersecurity incidents, in Portugal.
Finally, the Guidelines introduce the possibility for institutions to carry out intrusion tests, with greater or lesser scope, intensity, and periodicity, as a way to test potential vulnerabilities in systems and to assess the effectiveness and response capacity of defense mechanisms.
This Instruction was subject to public consultation in accordance with the terms and for the purposes provided for in Articles 100(3)(c) and 101, both of the Administrative Procedure Code.
In this context, the Bank of Portugal, in the exercise of the competence attributed to it by Articles 14 and 17 of its Organic Law, approved by Law No. 5/98, of January 31, as well as by Articles 115-T and 116(f) of the General Regime of Credit Institutions and Financial Companies and by Articles 70(3), 60(3), and 157(1) of the RJSPME, approves the following Instruction:
Article 1.
Recipients
The recipients of this Instruction are payment service providers (hereinafter “PSP”), within the meaning of Article 11(1) of the RJSPME, with headquarters in Portugal, even if operating in other countries through the exercise of the right of establishment or the free provision of services.
Article 2.
Operational and security requirements
PSPs observe the requirements provided for in the Guidelines on ICT and security risk management of the European Banking Authority (EBA/GL/2019/04), in the management of operational and security risks related to the payment services they provide.
Article 3.
Annual report on the assessment of operational and security risks
1 – PSPs prepare, with reference to June 30 of each year, an annual report on the assessment of operational and security risks of the payment services provided, in accordance with the model annexed to this Instruction.
2 – The report referred to in the preceding number is reported to the Bank of Portugal by July 31 of the same year.
3 – The annual risk assessment report aims to collect relevant information on the operational and security risks of payment services, ensuring that PSPs control these risks and are not exposed to a high number of severe operational and security incidents, as well as significant or severe cybersecurity incidents.
4 – With prior authorization requested from the Bank of Portugal, the recipients of this Instruction may delegate the reporting of information to another entity within the same group, without prejudice to remaining responsible for the accuracy and updating of the reported information.
5 – PSPs must fill in the report model contained in “Ad-hoc Reports via correspondence” in the Thematic Area of “Prudential Supervision” on the BPnet Portal (www.bportugal.net), complying with the instructions provided there and submitting it through that portal.
Article 4.
Entry into force and final provision
1 – This Instruction enters into force on the day following its publication.
2 – The first annual report on the assessment of operational and security risks, referring to June 30, 2021, must be sent to the Bank of Portugal by July 31, 2021.
Read the rest free
Source: Banco de Portugal — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BDP
BDP published 1 document in the last 30 days. We email you each new one the day it's published.