2021-10-15
Added
This instruction amends Instruction No. 54/2012, which governs TARGET2-PT, in response to ECB Guideline BCE/2021/30. The changes primarily introduce modifications to TARGET Instant Payment Settlement (TIPS) accessibility measures and strengthen data protection rules. It also alters accessibility for payment module account holders, indirect participants, and addressable BICs in TIPS, and establishes new security requirements and control procedures allowing Banco de Portugal to impose sanctions for non-compliance. A transitional provision permits Banco de Portugal to provide fund transfer services to ancillary systems settling instant payments via the ancillary system interface until February 25, 2022.
Instruction No. 13/2021 Official Bulletin No. 10/2021 • 2021/10/15 .................................................................................................................................................................................................. Topics Payment Systems :: Large-Value Payment System Mod. 99999940/T – 01/14 Index Instruction Text Instruction Text Subject: Amendment to Instruction No. 54/2012 - TARGET2-PT Regulation The regulatory framework for TARGET2-PT – the Portuguese component of the Eurosystem's Real-Time Gross Settlement System (SLBTR) – is set out in Instruction No. 54/2012, of January 15, 2013 – TARGET2-PT Regulation, published in compliance with European Central Bank Guideline ECB/2012/27, which reformulated Guideline ECB/2007/2, establishing TARGET2. Following the publication of ECB Guideline BCE/2021/30, of July 20, 2021, it becomes necessary to amend Instruction No. 54/2012, of January 15, 2013. This amendment primarily aims to: (i) introduce changes to TARGET Instant Payment Settlement (TIPS) accessibility measures; (ii) strengthen data protection rules; (iii) alter the accessibility of payment module (MP) account holders, indirect participants, and addressable BICs in TIPS; and (iv) introduce new security requirements and control procedures that enable Banco de Portugal to impose a sanctioning regime allowing for the determination of remedial measures in case of non-compliance with the said requirements and procedures. Thus, in the exercise of the competence attributed to it by Article 14 of its Organic Law, which confers upon it powers to regulate, supervise, and promote the proper functioning of payment systems, namely within the scope of its participation in the European System of Central Banks (SEBC), and in order to regulate the functioning of the national component system of TARGET2 – TARGET2-PT –, Banco de Portugal determines the following:
Instruction No. 13/2021 BO No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14
«3. TARGET2 allows for gross real-time settlement of euro payments, carried out in central bank money between MP, CND T2S and CND TIPS accounts. TARGET2 is established and operates based on the PUP, through which the transmission and processing of payment orders and the final receipt of payments are carried out in a technically identical manner. Regarding the technical operation of CND T2S, TARGET2 is technically established and operates based on the T2S platform. Regarding the technical operation of CND TIPS and SP TIPS technical accounts, TARGET2 is technically established and operates based on the TIPS platform.»
«Article 5 Direct Participants
MP account holders in TARGET2-PT are direct participants and must comply with the requirements set out in Article 8, paragraphs 1 and 2. They must hold at least one MP account at the Banco de Portugal. MP account holders who have joined the SEPA Instant Credit Transfer mechanism by subscribing to the SEPA Instant Credit Transfer Adherence Agreement must be contactable at all times on the TIPS Platform, whether as a holder of a CND TIPS or as a contactable party through a holder of a CND TIPS.
MP account holders may designate addressable BIC holders, regardless of where they are established. MP account holders may only designate addressable BIC holders who have joined the SEPA Instant Credit Transfer mechanism by subscribing to the SEPA Instant Credit Transfer Adherence Agreement if such entities are contactable on the TIPS Platform, whether as a holder of a CND TIPS or as a contactable party through a holder of a CND TIPS.
MP account holders may designate entities as indirect participants in the MP, provided that the conditions set out in Article 6 are observed. MP account holders may only designate as indirect participants entities that have joined the SEPA Instant Credit Transfer mechanism by subscribing to the SEPA Instant Credit Transfer Adherence Agreement if such entities are contactable on the TIPS Platform, whether as a holder of a CND TIPS or as a contactable party through a holder of a CND TIPS.
Access for multiple recipients through branches may be provided as follows: a) A credit institution within the meaning of Article 4(1)(a) or (b) of this Annex that has been admitted as an MP account holder may grant access to its MP account to one or more of its branches established in the Union or in the EEA in order to allow them to directly submit payment orders and/or receive payments, provided that the Banco de Portugal has been informed of this fact; b) Whenever a branch of a credit institution has been admitted as an MP account holder, the other branches of the legal entity and/or its head office, in both cases provided they are established in the Union or in the EEA, may access the MP account of that branch, provided that this has informed the Banco de Portugal of the fact.»
In Annex II, Article 12, paragraph 3 shall be amended to read as follows:
«3. MP accounts and their sub-accounts shall be remunerated at a rate of zero percent or at the deposit facility rate, whichever is lower, except if they are used for the holding of mandatory minimum reserves or excess reserves. In the case of minimum reserves, the calculation and payment of remuneration for held minimum reserves shall be governed by the provisions of Council Regulation (EC) No 2531/98() and European Central Bank Regulation (EU) 2021/378 (ECB/2021/1)(). In the case of excess reserves, the calculation and payment of remuneration for held reserves shall be governed by the provisions of Decision (EU) 2019/1743 (ECB/2019/31)(). () Council Regulation (EC) No 2531/98 of 23 November 1998 concerning the application of minimum reserves by the European Central Bank (OJ L 318 of 27.11.1998, p. 1). () European Central Bank Regulation (EU) 2021/378 of 22 January 2021 on the application of minimum reserve requirements (ECB/2021/1) (OJ L 73 of 3.3.2003, p. 1). (). European Central Bank Decision (EU) 2019/1743 of 15 October 2019 on the remuneration of excess reserves and certain deposits (ECB/2019/31) (OJ L 267 of 21.10.2019, p. 12.)»
«Article 28 Security requirements and control procedures
Instruction No. 13/2021 BO No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14
4-A. The Banco de Portugal evaluates the participant's self-certification declaration(s) based on the level of compliance with each of the requirements established in the TARGET2 self-certification requirements. These requirements are listed in Appendix VIII, which, in addition to the appendices listed in Article 2(1), constitutes an integral part of these conditions. 4-B. The participant's level of compliance with the TARGET2 self-certification requirements must be classified as follows, in increasing order of severity: "full compliance"; "minor non-compliance"; or, "major non-compliance". The following criteria apply: "full compliance" is achieved whenever participants satisfy 100% of the requirements; "minor non-compliance" occurs whenever the participant satisfies less than 100% but at least 66% of the requirements and "major non-compliance" occurs whenever the participant satisfies less than 66% of the requirements. If a participant demonstrates that a certain requirement is not applicable to them, they shall be considered in compliance with the requirement in question for classification purposes. A participant who fails to achieve "full compliance" must submit an action plan demonstrating how they intend to achieve full compliance. The Banco de Portugal must inform the competent supervisory authorities about the participant's compliance status. 4-C. If the participant refuses permanent access to their declaration of adherence to the security requirements of the terminals of the chosen network service providers or fails to provide the TARGET2 self-certification, the participant's level of compliance shall be classified as "major non-compliance". 4-D. The Banco de Portugal must re-evaluate the compliance of participants annually. 4-E. The Banco de Portugal may impose the following remedial measures on participants whose level of compliance has been assessed as minor or major non-compliance, in increasing order of severity: i) enhanced monitoring: the participant must submit a monthly report to the Banco de Portugal, signed by a senior manager, on the progress made in resolving the non-compliance. In addition, the participant incurs a monthly penalty for each affected account equivalent to its respective monthly fee, as established in point 1 of Appendix VI, excluding transaction fees. This remedial measure may be imposed if the participant receives a second consecutive minor non-compliance assessment or a major non-compliance assessment; ii) suspension: participation in TARGET2-PT may be suspended under the circumstances described in Article 34(2)(b) and (c) of this Annex. In derogation of Article 34 of this Annex, the participant must be notified of the suspension three months in advance. The participant incurs a monthly penalty for each suspended account equivalent to double its respective monthly fee, as established in point 1 of Appendix VI, excluding transaction fees. This remedial measure may be imposed if the participant receives a second consecutive major non-compliance assessment; iii) termination: participation in TARGET2-PT may be terminated under the circumstances described in Article 34(2)(b) and (c) of this Annex. In derogation of the provisions of Article 34 of this Annex, the participant must be notified of the termination three months in
Instruction No. 13/2021 BO No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14
advance. The participant incurs an additional penalty of 1,000 EUR for each closed account. This remedial measure may be imposed if the participant has not corrected the major non-compliance to the satisfaction of the Banco de Portugal after three months of suspension. 5. Participants who allow third-party access to their MP account, as provided for in Article 5, paragraphs 2, 3 and 4, must treat the risk arising from such access in accordance with the security requirements defined in paragraphs 1 to 4-E of this Article. The self-certification referred to in paragraph 4 must specify that the participant imposes the TARGET2 network service provider terminal security requirements on third parties with access to their MP account.»
«8. The obligations of the Banco de Portugal established in paragraphs 1 to 7 above are equally applicable in the event of suspension or cessation of use of the Peripheral System Interface/Ancillary System Interface (ASI) or the TIPS platform by peripheral systems.»
«1. Participants are presumed to have knowledge of, comply with and be able to demonstrate to the competent authorities compliance with all obligations incumbent upon them under data protection legislation. Participants are presumed to know and comply with all obligations imposed on them under legislation on anti-money laundering and counter-terrorist financing, nuclear non-proliferation and the development of nuclear weapon vectors, especially regarding the adoption of appropriate measures regarding any payments debited or credited to their MP accounts. Participants must ensure that they are informed about the data recovery policy of the network service provider before establishing a contractual relationship with them.»
«Article 45-A Transitional Provisions
Instruction No. 13/2021 BO No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14
«b) User-to-Application (U2A) mode The U2A mode allows direct communication between a participant and the MIC. The information is displayed in a browser program installed on a PC system (SWIFT Alliance WebStation or another interface possibly required by SWIFT). For U2A access, the IT infrastructure must be capable of supporting cookies. The MIC user manual contains more detailed information.»
«g) Participants must provide eligible assets as collateral assets for the processing of payment order contingencies. During contingency processing, received contingency payments may be used to finance paid contingency payments. The Banco de Portugal may not take into account the available liquidity of participants for the purposes of contingency processing.»
«Appendix VIII Requirements relating to information security management and business continuity management Information Security Management These requirements are applicable to each participant, unless the participant demonstrates that a certain requirement is not applicable to them. In defining the scope of these requirements within their own infrastructure, the participant must identify the elements that are part of the Payment Transaction Chain (PTC). More precisely, the payment transaction chain starts at a Point of Entry (PoE), i.e., a system that participates in the creation of operations (for example, a workstation, a counter or backoffice application, or a middleware application), and ends at the system responsible for sending the message to SWIFT (for example the SWIFT VPN box) or to the Internet (this latter applies in the case of Internet access). Requirement 1.1: Information Security Policy Management must define a clear policy direction, in line with business objectives, and demonstrate support and commitment to information security through the issuance, approval and maintenance of an information security policy intended to manage information security and cyber-resilience across the organization in terms of identification, assessment and treatment of information security and cyber-resilience risks. The policy must contain, at a minimum,
Instruction No. 13/2021 BO No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14
the following sections: objectives, scope (including domains such as organization, human resources, asset management, etc.), principles and assignment of responsibilities. Requirement 1.2: Internal Organization An information security regime is established to implement the information security policy within the organization. Management must coordinate and review the creation of the information security framework to ensure the implementation of the information security policy (in accordance with Requirement 1.1) across the organization, including the allocation of sufficient resources and the assignment of security responsibilities for this purpose. Requirement 1.3: External Parties The information security of the organization and its information processing facilities must not be compromised by the use of one or more external parties or products/services provided by them or by dependence on them or their products/services. Any access to the organization's information processing facilities by external parties must be controlled. Whenever external parties or external party products/services must have access to the organization's information processing facilities, a risk assessment must be carried out to determine the implications for security and control requirements. Controls must be agreed and defined in an agreement with each external party concerned. Requirement 1.4: Asset Management All information assets, operational processes and underlying information systems, such as operating systems, infrastructures, operational applications, standard products, services and user-developed applications, covered by the payment transaction chain must be accounted for and have a designated owner. Responsibility must be assigned for the maintenance and operation of appropriate controls over operational processes and their IT components with a view to protecting information assets. Note: the owner may, if necessary, delegate the implementation of specific controls, but remains responsible for the proper protection of assets. Requirement 1.5: Information Asset Classification Information assets must be classified according to their critical importance for the proper provision of service by the participant. The classification must indicate the need, priorities and degree of protection required in the processing of the information asset in the relevant operational processes and must also take into account the underlying IT components. A management-approved information asset classification system must be used to define a suitable set of protection controls throughout the entire lifecycle of information assets (including the removal and destruction of information assets) and to communicate the need for specific treatment measures. Requirement 1.6: Human Resources Security Security responsibilities must be defined before recruitment, through adequate job descriptions and employment conditions. All job candidates, contractors and third-party users must be subject to adequate control, especially with regard to sensitive positions. Employees, contractors and third-party users of information processing facilities must sign an agreement regarding their functions and security responsibilities. An adequate level of awareness must be ensured for all workers, contractors and third-party users, and teaching and training in security procedures and the correct use of information processing facilities must be provided to minimize possible security risks. A formal disciplinary process must be instituted for the handling of security violations by workers. Responsibilities must be defined to ensure the management of the exit from the organization or the transfer within the same of an employee, contractor or third-party user, as well as the return of all equipment and the revocation of all access rights. Requirement 1.7: Physical and Environmental Security Critical or sensitive information processing facilities must be located in secure zones, protected by defined security perimeters, with adequate barriers and entry controls. They must be physically protected against unauthorized access and damage and interference. Access is exclusively granted to persons covered by Requirement 1.6. Procedures and standards are established to protect physical media containing information assets during their transport. Equipment is protected against physical and environmental threats. Equipment protection (including equipment used off-site) and protection against removal of goods is necessary to reduce the risk of unauthorized access to information and to protect against loss or damage to equipment or information. Special safeguard and protection measures against physical threats to support facilities, such as power supply and cabling infrastructure, may be necessary. Requirement 1.8: Operations Management Responsibilities and procedures must be established for the management and operation of information processing facilities covering all underlying systems of the payment transaction chain, from end to end. Regarding operational procedures, including the technical administration of IT systems, separation of duties must be implemented whenever necessary, in order to reduce the risk of intentional or negligent misuse of the system. In case separation of duties is not
Instruction No. 13/2021 BO No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 can be implemented for documented objective reasons, compensatory controls must be introduced following a formal risk analysis. Controls must be established to prevent and detect the introduction of malicious code into payment transaction chain systems. Controls (including user awareness) must also be established to prevent, detect, and remove malicious code. Only mobile code from trusted sources (e.g., signed Microsoft COM components and Java Applets) should be used. Browser configuration (e.g., the use of extensions and plug-ins) must be strictly controlled. Management must implement data backup and recovery policies; such data recovery policies must include a restoration process plan that must be tested at least annually. Systems critical to payment security must be monitored, and relevant information security events must be logged. Operator logs must be used to ensure the identification of IT system problems. Operator logs must be regularly examined by sampling, taking into account the critical importance of operations. System monitoring must be used to verify the effectiveness of controls identified as critical to payment security and to verify compliance with an access policy model. Information exchanges between organizations must be based on a formal exchange policy, executed in accordance with exchange agreements entered into between the parties involved, and comply with all relevant legislation. Third-party software components used in information exchange with TARGET2 (such as software received from a service bureau in scenario 2 of the section on the scope of the TARGET2 self-certification agreement document) must be used under a formal agreement with the third party. Requirement 1.9: Access control Access to information assets must be justified based on operational needs (need-to-know 1) and in accordance with the established corporate policy framework (including the information security policy). Clear access control rules must be defined based on the principle of least privilege 2, in order to faithfully reflect the needs of the corresponding operational and IT processes. Where applicable (e.g., in relation to backup management), logical access control must be consistent with physical access control, unless adequate compensatory controls exist (e.g., encryption and anonymization of personal data). Formal and documented procedures must exist to control the assignment of access rights to IT systems and services covered by the scope of the payment transaction chain.
1 The 'need-to-know' principle refers to the identification of the set of information a person needs to access to perform their duties. 2 The principle of least privilege refers to adapting the subject's access profile to the IT system to match the corresponding professional function.
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 procedures must cover all phases of the user access lifecycle, from initial registration of new users to final deregistration of users who no longer need access. Special attention must be given, where applicable, to the assignment of access rights of such critical importance that their abuse could have serious negative repercussions on the participant's operations (e.g., access rights that allow system administration, neutralization of system controls, or direct access to operational data). Adequate controls must be adopted to identify, authenticate, and authorize users at specific points in the organization's network, for example, in relation to local and remote access to payment transaction chain systems. Personal accounts are not shared to ensure accountability. Regarding passwords, rules must be established and applied through specific controls to ensure that they cannot be easily deduced, for example, rules regarding their complexity and limited temporal validity. A secure password recovery and/or reset protocol must be established. A policy on the use of cryptographic controls to protect the confidentiality, authenticity, and integrity of information must be developed and implemented. A key management policy must be established to support the use of cryptographic controls. There must be a policy on the display of confidential information on screen or on paper, for example, a clear screen or clear desk policy, to reduce the risk of unauthorized access. Regarding remote work, the risks of working in an unprotected environment must be taken into account, and adequate technical and organizational controls must be applied. Requirement 1.10: Acquisition, development, and maintenance of IT systems Security requirements must be identified and agreed upon before the development and/or implementation of IT systems. Adequate controls must be incorporated into applications, including user-developed applications, to ensure correct processing. These controls must include validation of input data, internal processing, and output data. Additional controls may be necessary for systems that process or impact sensitive, valuable, or critical information. Such controls will be determined based on security requirements and risk assessment in accordance with established policies (e.g., information security policy, cryptographic control policy). Operational requirements for new systems must be established, documented, and tested before their acceptance and use. Regarding network security, adequate controls must be implemented, including segmentation and secure management, based on the criticality of
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 data flows and the risk level of the organization's network areas. Specific controls must exist to protect confidential information circulating on public networks. Access to system files and program source code must be controlled, and IT projects and support activities must be carried out securely. Exposure of sensitive data in test environments must be avoided. Project and support environments must be strictly controlled. The introduction of changes into production must be strictly controlled. A risk assessment of significant changes to be introduced into production must be carried out. Regular security testing activities for production systems must also be carried out according to a predefined plan based on the results of a risk assessment, and security tests must include, at least, vulnerability assessments. All deficiencies evidenced during security testing activities must be evaluated, and action plans must be developed to address any identified gaps, which must be followed up in a timely manner. Requirement 1.11: Information security in supplier relationships 3 To ensure the protection of the participant's internal IT systems accessible to suppliers, information security requirements to mitigate risks associated with supplier access must be documented and formally agreed with the supplier. Requirement 1.12: Management of information security incidents and related improvements To ensure a consistent and effective approach to managing information security incidents, including the communication of security occurrences and vulnerabilities, functions, responsibilities, and procedures must be established and tested, at operational and technical levels, to ensure rapid, effective, orderly, and secure recovery following information security incidents, including scenarios related to a cyber cause (e.g., fraud committed by an external attacker or an insider). Personnel involved in these procedures must receive adequate training. Requirement 1.13: Verification of technical compliance A participant's internal IT systems (e.g., back-office systems, internal networks, and external network connectivity) must be regularly assessed for compliance
3 In the context of this exercise, 'supplier' means any third party (and its personnel) who has entered into a contract (agreement) with the institution to provide a service and who has access, under the service agreement, remotely or on-site, to information and/or IT systems and/or information processing facilities of the institution covered by or associated with the scope of the TARGET2 self-certification exercise.
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 with the policy framework adopted by the organization (e.g., information security policy, cryptographic control policy). Requirement 1.14: Virtualization Guest virtual machines must comply with all security controls established for physical hardware and physical systems (e.g., hardening and logging). Controls related to hypervisors must include: hardening of the hypervisor and the host operating system, regular patching, strict separation of different environments (e.g., production and development). Centralized management, logging and monitoring, as well as access rights management, especially for privileged accounts, must be implemented based on a risk assessment. Guest virtual machines managed by the same hypervisor must have a similar risk profile. Requirement 1.15: Cloud computing The use of public and/or hybrid cloud computing solutions in the payment transaction chain must be based on a formal risk assessment, taking into account technical controls and contractual clauses relating to the cloud computing solution. If hybrid cloud computing solutions are used, it is understood that the overall system's criticality level is the highest of the connected systems. All on-premise components of hybrid solutions must be separated from other existing on-premise systems. Business continuity management (applicable only to critical participants) The following requirements (2.1 to 2.6) concern business continuity management. Each TARGET2 participant classified by the Eurosystem as critical for the proper functioning of the TARGET2 system must have a business continuity strategy that includes the following elements. Requirement 2.1: Business continuity plans have been developed and procedures for their maintenance are in place. Requirement 2.2: An alternative operational site must be available. Requirement 2.3: The risk profile of the alternative site must be different from the risk profile of the main site, to prevent both sites from being affected by the same event at the same time. For example, the alternative site must be on a different power grid and central telecommunications circuit from the company's main location. Requirement 2.4: In the event of a major operational disruption that renders the main site and/or critical personnel inaccessible, the critical participant must be able to resume normal operations from the alternative site, where it must be possible to properly close the business day and open the following business day or days.
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 Requirement 2.5: Procedures must be in place to ensure that transaction processing is resumed at the alternative site within a reasonable period after the initial service interruption and proportionate to the criticality of the disrupted activity. Requirement 2.6: The ability to cope with operational disruptions must be tested at least once a year and critical personnel must receive adequate training. The maximum interval between tests must not exceed one year." 16. In Annex II-A, Article 1 is amended as follows: i. The definition of "Instant payment order" is amended as follows: "- "Instant payment order", in the context of the European Payments Council's SEPA instant credit transfer scheme, means a payment instruction that can be executed at any time of the day, on any day of the year, with instant or near-instant processing and notification to the payer and which includes i) TIPS DCA to TIPS DCA instant payment orders, ii) TIPS DCA to TIPS AS technical account instant payment orders, iii) TIPS AS technical account to TIPS DCA instant payment orders and iv) TIPS AS technical account to TIPS AS technical account instant payment orders," ii. The following definitions are added: "- "TIPS ancillary system technical account/TIPS AS technical account", means the account held by an ancillary system or by a CB on behalf of an ancillary system in the CB's TARGET2 component system for use by the ancillary system for the purpose of settling instant payments in its own accounting records;" "- "TIPS DCA to TIPS AS technical account liquidity transfer order", means the instruction to transfer a specified amount of funds from a TIPS DCA to a TIPS AS technical account, for financing the position of the TIPS DCA holder (or the position of another ancillary system participant) in the ancillary system's accounting records;" "- "TIPS AS technical account to TIPS DCA liquidity transfer order", means the instruction to transfer a specified amount of funds from a TIPS AS technical account to a TIPS DCA, for reducing the
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 financing of the position of the TIPS DCA holder (or the position of another ancillary system participant) in the ancillary system's accounting records;" "- "Network Service Provider/NSP", means a company that has obtained a concession from the Eurosystem to provide connectivity services through the Eurosystem Single Market Infrastructure Gateway," iii. The definition of 'T2S network service provider' is deleted. 17. In Annex II-A, Article 4 is amended as follows: i. Subparagraph f-D) is added to paragraph 2: " f-D) TIPS DCA to TIPS AS technical account liquidity transfer orders and TIPS AS technical account to TIPS DCA liquidity transfer orders; and" ii. Paragraph 3 is amended as follows: "3. TARGET2 allows for real-time gross settlement of payments in euros, effected in central bank money between PM accounts, T2S DCAs and TIPS DCAs. TARGET2 is established and operates based on the ESMIG, through which the transmission and processing of payment orders and the final receipt of payments are carried out in a technically identical manner. With regard to the technical operation of T2S DCAs, TARGET2 is technically established and operates based on the T2S platform. With regard to the technical operation of TIPS DCAs and TIPS AS technical accounts, TARGET2 is technically established and operates based on the TIPS platform. Banco de Portugal is the service provider under these Conditions. The acts and omissions of the CBs providing the ESMIG and/or the 4 CBs will be considered acts and omissions of Banco de Portugal for which it assumes responsibility under Article 21 of this annex. Participation under these Conditions does not create any contractual relationship between T2S DCA holders and the CBs providing the ESMIG or the 4 CBs when any of the latter acts in that capacity. Instructions, messages or information that a T2S DCA holder receives from or sends to the ESMIG or the T2S platform, relating to services provided under these Conditions, are considered received from or sent to Banco de Portugal." 18. In Annex II-A, references to "T2S network service provider" (singular or plural) in Article 6, paragraph 1, subparagraph a), sub-subparagraph i), Article 9, paragraph 5, Article 10, paragraph 6, Article 14, paragraph 1, subparagraph a), Article 22, paragraph 1, Article 22, paragraphs 2 and 3, Article 27, paragraph 5, Article 28, paragraph 1, Article 29, paragraph 1, and paragraph 1 of Appendix I are replaced by references to "NSP".
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 19. In Annex II-A, Article 8, paragraph 3 is amended as follows: "3. If Banco de Portugal grants a request from a T2S DCA holder under paragraph 1, the T2S DCA holder is deemed to have granted the participating CSD(s) a mandate to debit the T2S DCA for amounts relating to securities transactions executed in those securities accounts." 20. In Annex II-A, Article 28, paragraph 1 is amended as follows: "1. T2S DCA holders are presumed to know, comply with, and be able to demonstrate to the relevant competent authorities compliance with all obligations imposed on them by data protection legislation. They are presumed to know and comply with all obligations incumbent on them by legislation on the prevention of money laundering and terrorist financing, nuclear proliferation activities, and the development of nuclear weapon vectors, especially with regard to the adoption of appropriate measures relating to any payments debited or credited to their respective T2S DCAs. T2S DCA holders must ensure that they are informed about their respective NSP's data recovery policy before establishing a contractual relationship with it." 21. In Annex II-A, Article 30 is amended as follows: "Article 30. Contractual relationship with an NSP
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 22. Article 34-A is added to Annex II-A: «Article 34-A Transitional provisions As soon as the TARGET system is operational and TARGET2 has ceased its activity, T2S CND holders will become T2S CND holders in the TARGET system.» 23. In Annex II-A, Appendix I, number 7, point 1, subparagraph b) is amended as follows: «b) User-to-application (U2A) mode The U2A mode allows direct communication between a T2S CND holder and the T2S GUI module. Information is displayed in a browser program installed on a PC system. For U2A access, the IT infrastructure must be capable of supporting cookies. The T2S user manual contains more detailed information.» 24. In Annex II-B, the references to «TIPS network service provider» (in the singular or plural) in Article 17, number 1, subparagraph a), in Article 24, numbers 1 and 2, in Article 26, number 2, subparagraph d), in Article 29, number 6 are replaced by references to «NSP». 25. In Annex II-B, Article 1 is amended as follows: i. The definitions of “Reachable party”, “Payment order”, and "Instant payment order" are amended as follows: «- "Reachable party": an entity: a) holding a BIC; b) designated as a reachable party by a TIPS CND holder or an ancillary system; c) correspondent, client or branch of a TIPS CND holder or participant of an ancillary system, or correspondent, client or branch of the participant of an ancillary system; and d) that can be contacted via the TIPS platform and is able to submit or receive instant payment orders, either through the TIPS CND holder or the ancillary system, or directly if authorized by the TIPS CND holder or the ancillary system.» «- "Payment order": except when the term is used in Articles 16 to 18 of this annex, an instant payment order, a positive revocation response, a liquidity transfer order from an MP account to a TIPS CND, a liquidity transfer order from a TIPS CND to an MP account, a TIPS AS technical account to a TIPS CND liquidity transfer order or a TIPS CND to TIPS AS liquidity transfer order.» «- "Instant payment order": in the context of the European Payments Council's SEPA Instant Credit Transfer scheme, the payment instruction that can be executed at any time of the day, on any day of the year, with instant or near-instant processing and notification to the payer and which includes i) instant payment orders from TIPS CND to TIPS CND, ii) instant payment orders from TIPS CND to TIPS AS technical account, iii) instant payment orders from TIPS AS technical account to TIPS CND and iv) instant payment orders from TIPS AS technical account to TIPS AS technical account.» ii. The following definitions are added: «- “TIPS ancillary system technical account (TIPS AS technical account)”: the account held by an ancillary system or by the CB on behalf of an ancillary system in the CB's TARGET2 component system for use by that ancillary system for the purpose of settling instant payments in its own accounting records;
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 29. In Annex II-B, Article 9 is amended as follows: «Article 9 Contractual relationship with an NSP
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 37. In Annex II-B, Article 26, number 9 is amended as follows: «9. The obligations of Banco de Portugal established in paragraphs 1 to 7 of Article 34 of Annex II are also applicable in case of suspension or cessation of use of the TIPS platform by ancillary systems.» 38. In Annex II-B, Article 30, number 1 is amended as follows: «1. TIPS CND holders are presumed to know, comply with, and be able to demonstrate to the relevant competent authorities compliance with all obligations imposed on them by data protection legislation. They are presumed to know and comply with all obligations incumbent upon them by legislation on the prevention of money laundering and terrorist financing, nuclear proliferation activities and the development of nuclear weapon vectors, especially with regard to the adoption of appropriate measures concerning any payments debited or credited to their respective TIPS CNDs. TIPS CND holders must ensure they are informed about the NSP's data recovery policy before establishing a contractual relationship with it.» 39. Article 35-A is added to Annex II-B: «Article 35-A Transitional provision As soon as the TARGET system is operational and TARGET2 has ceased its activity, TIPS CND holders will become TIPS CND holders in the TARGET system.» 40. In Annex II-B, Appendix I, the table in paragraph 2 is replaced by the following: Message Type Message Name Pacs.002 FIToFIPayment Status Report Pacs.004 PaymentReturn Pacs.008 FIToFICustomerCreditTransfer Pacs.028 FIToFIPaymentStatusRequest camt.003 GetAccount camt.004 ReturnAccount camt.005 GetTransaction camt.006 ReturnTransaction camt.011 ModifyLimit camt.019 ReturnBusinessDayInformation
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 camt.025 Receipt camt.029 ResolutionOfInvestigation camt.050 LiquidityCreditTransfer camt.052 BankToCustomerAccountReport camt.053 BankToCustomerStatement camt.054 BankToCustomerDebitCreditNotification camt.056 FIToFIPaymentCancellationRequest acmt.010 AccountRequestAcknowledgement acmt.011 AccountRequestRejection acmt.015 AccountExcludedMandateMaintenanceRequest reda.016 PartyStatusAdviceV01 reda.022 PartyModificationRequestV01 41. In Annex II-B, Appendix I, paragraph 6, subparagraph 1), sub-subparagraph b) is amended as follows: «b) User-to-application (U2A) mode The U2A mode allows direct communication between a TIPS CND holder and the TIPS GUI module. Information is displayed in a browser program installed on a PC system. For U2A access, the IT infrastructure must be capable of supporting cookies. The TIPS user manual contains more detailed information.» 42. In Annex II-B, Appendix I, the references to «TIPS network service provider» are replaced by references to «NSP». 43. In Annex II-B, Appendix II, the reference to «network service provider» is replaced by reference to «NSP». 44. In Annex II-B, Appendix IV, paragraph 2 is eliminated. 45. In Annex II-B, Appendix V is eliminated. 46. In Annex IV, paragraph 14, subparagraph 14, sub-subparagraph d) is amended as follows: «d) SWIFT orders cannot be submitted via MT 103 messages.» 47. In Annex IV, paragraph 18 is amended as follows: i. In subparagraph 1), sub-subparagraph b), the first line of the table is amended as follows: Range From (in millions of EUR/day) To (in millions of EUR/day) Annual fee (EUR) Monthly fee (EUR) ii. In subparagraph 1), sub-subparagraph d), number iv), the last paragraph is eliminated. 48. Annex IV-A is added: «ANNEX IV-A – TIPS SERVICE FOR ANCILLARY SYSTEMS SETTLING INSTANT PAYMENTS
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 2) TIPS AS technical accounts are identified by a unique account number consisting of a maximum of 34 characters, and are structured as defined in the table: Name Format Content Part A Account type Exactly 1 digit 'A' for the AS technical account Central bank country code Exactly 2 digits ISO 3166-1 country code Currency code Exactly 3 digits EUR Part B Account holder Exactly 11 digits BIC Part C Account sub-classification Up to 17 digits Free text (alphanumeric) to be provided by the account holder. 3) TIPS AS technical accounts can only have a zero or positive balance during the day and can maintain a positive balance overnight. The overnight balance of the account is subject to the same remuneration rules applicable to guarantee funds under Article 11 of this guideline. 4. Settlement procedure
Instruction No. 13/2021 Official Gazette No. 10/2021 • 2021/10/15 Topics Payment Systems :: Large-Value Payment System .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 b) A fee based on the underlying gross volume of instant payments settled on the peripheral system's own platform and activated by pre-funded positions in the SP TIPS technical account. The fee is EUR 0.0005 per instant payment. 2) The underlying gross volume of instant payments of the peripheral system must be calculated monthly by the BCSP based on the underlying gross volume of the previous month, rounded down to the nearest ten thousand, and reported by the peripheral system no later than the third business day of the following month. The calculated gross volume is applied in the fee calculation in the following month. 3) Each peripheral system receives from its respective BCSP, no later than the ninth business day of the following month, an invoice for the previous month based on the fees referred to in point 1) of this number. Payment must be made no later than the fourteenth business day of the month in which the invoice is issued, to the credit of the account indicated by the BCSP or to the debit of the account indicated by the peripheral system. 4) For the purposes of the fee schedule and invoicing under this annex: a) A peripheral system that has been designated as a system under Directive 98/26/EC must be treated as a separate peripheral system, even if it is operated by a legal entity that operates another peripheral system; b) A peripheral system that has not been designated as a system under Directive 98/26/EC must be treated as a separate peripheral system if it meets the following criteria: i. it is a formal agreement, in the form of a contract or legislative instrument; ii. it has more than one participant, excluding the operator of that system; iii. it has been established for the purposes of clearing, netting and/or settlement of payments and/or securities between participants; and iv. it applies common rules and standardized mechanisms for clearing, netting and/or settlement of payments and securities between participants. 5) For the purposes of invoicing under this article, for the period between December 1, 2021, and February 28, 2022, the fees correspond to the average of the total fees invoiced for the months of September, October, and November 2021.» 49. The provisions of this Instruction shall apply from November 21, 2021, except for numbers 16. iii), 18., and 21. of this Instruction, which shall apply from June 13, 2022.
More like this from BDP
BDP published 5 documents in the last 30 days. We email you each new one the day it's published.