2021-03-15

Added · Updated

Instruction No. 4/2021 on ICT and Security Risk Management for Payment Service Providers

This Instruction mandates Payment Service Providers (PSPs) with headquarters in Portugal to comply with the European Banking Authority's Guidelines on ICT and security risk management, specifically requiring the annual submission of an operational and security risk assessment report. PSPs must prepare this report based on data as of June 30 each year and submit it to the Bank of Portugal by July 31 of the same year via the BPnet portal. The first report, covering the period ending June 30, 2021, was due by July 31, 2021. This measure aims to ensure that PSPs effectively control operational and security risks, including cybersecurity incidents, related to their payment services.

Banco de Portugal logo

Portugal

Banco de Portugal

Click to view thumbnail

Instruction No. 4/2021 BO No. 3/2021 • 2021/03/15 .................................................................................................................................................................................................. Topics Supervision :: Prudential Standards Mod. 99999940/T – 01/14 Index Text of the Instruction Article 1.º Recipients Article 2.º Operational and security requirements Article 3.º Annual report on the assessment of operational and security risks Article 4.º Entry into force and final provision Text of the Instruction Subject: Instruction on the management and reporting, by payment service providers, of operational and security risks

In 2017, the European Banking Authority (EBA) published the “Guidelines on security measures to manage operational and security risks under Directive (EU) 2015/2366” (EBA/GL/2017/17), establishing a set of security requirements in Information and Communication Technologies (ICT) for payment service providers (PSPs).

Additionally, also in 2017, the EBA published the “Guidelines on ICT risk assessment within the supervisory review and evaluation process (SREP)” (EBA/GL/2017/05) with the aim of ensuring convergence of supervisory practices in the assessment of ICT risk, as specified in detail in the “EBA Guidelines on common procedures and methodologies for the SREP” (EBA/GL/2014/13).

In February 2019, the EBA published the “Guidelines on Outsourcing” (EBA/GL/2019/02) which establish procedures and requirements for effective management of ICT outsourcing, for which purpose the Bank of Portugal issued Circular Letter No. CC/2019/000000651.

More recently, on November 28, 2019, the EBA published the “Guidelines on ICT and security risk management” (EBA/GL/2019/04, hereinafter “Guidelines”), addressed to credit institutions, investment firms, and PSPs. These Guidelines incorporate and revoke the previous “Guidelines on security measures to manage operational and security risks under Directive (EU) 2015/2366” (EBA/GL/2017/17). In particular, the Guidelines specify the measures and procedures that financial institutions must adopt, within the scope of operational risk and internal governance, to manage their risks associated with ICT and security (which include, among others, on the one hand cybersecurity risk, and on the other hand operational and security risks related to payment services).

In this context, the Guidelines provide, by reference to the provisions of Article 95(2) of Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market (PSD2), that PSPs must communicate to the Bank of Portugal a comprehensive and updated assessment of the operational and security risks related to the payment services they provide, as well as the adequacy of the mitigation and control measures implemented in response to these risks. This annual communication aims to collect relevant information on the operational and security risks of payment services, ensuring that the entities concerned control these risks, as well as their exposure to severe operational and security incidents.

The Bank of Portugal communicated to the EBA its intention to comply with the aforementioned Guidelines from June 30, 2020, and in this context published Circular Letter No. CC/2020/00000029, of May 6, disclosing to the institutions concerned its intention and the respective compliance date with the Guidelines.

The present Instruction aims to implement the requirements contained in the Guidelines, including the duty to report the annual assessment of operational and security risks of the payment services provided.

It should be noted that the Instruction is addressed exclusively to PSPs, and therefore does not apply to Investment Firms, branches in Portugal of credit institutions authorized in other European Union (EU) Member States, branches of electronic money institutions with headquarters in the EU, and branches of payment institutions with headquarters in the EU.

The Bank of Portugal emphasizes the importance of these Guidelines for strengthening the operational resilience of the financial sector.

Firstly, the Guidelines introduce greater specification of supervisory expectations regarding ICT and security risks and thereby strengthen current prudential requirements, particularly in the ICT risk self-assessment questionnaire of credit institutions, the results of which are taken into account in the SREP, namely in the risk analysis for capital, in the category of information systems, and in the context of operational risk.

Secondly, the Guidelines describe more clearly the responsibilities of top management and the second and third lines of defense in the management of the ICT strategy and governance model.

Thirdly, the Guidelines strengthen the Bank of Portugal's recent strategy for strengthening operational resilience in cybersecurity, complementing Instruction No. 1/2019 and Instruction No. 21/2019, which establish duties to report operational and security incidents, and cybersecurity incidents, in Portugal.

Finally, the Guidelines introduce the possibility for institutions to conduct intrusion tests, with greater or lesser scope, intensity, and periodicity, as a way to test potential vulnerabilities in systems and to assess the effectiveness and response capacity of defense mechanisms.

The present Instruction was subject to public consultation in accordance with the terms and for the purposes provided for in Articles 100(3)(c) and 101, both of the Administrative Procedure Code.

In this context, the Bank of Portugal, using the competence attributed to it by Articles 14 and 17 of its Organic Law, approved by Law No. 5/98, of January 31, as well as by Articles 115-T and 116(f) of the General Regime of Credit Institutions and Financial Companies and by Articles 70(3), 60(3), and 157(1) of the RJSPME, approves the following Instruction:

Article 1. Recipients The recipients of this Instruction are payment service providers (hereinafter “PSPs”), within the meaning of Article 11(1) of the RJSPME, with headquarters in Portugal, even if operating in other countries through the exercise of the right of establishment or the free provision of services.

Article 2. Operational and security requirements PSPs observe the requirements provided for in the Guidelines on ICT and security risk management of the European Banking Authority (EBA/GL/2019/04), in the management of operational and security risks related to the payment services they provide.

Article 3. Annual report on the assessment of operational and security risks 1 – PSPs prepare, with reference to June 30 of each year, an annual report on the assessment of operational and security risks of the payment services provided, in accordance with the model annexed to this Instruction. 2 – The report referred to in the preceding number is reported to the Bank of Portugal by July 31 of the same year. 3 – The annual assessment report aims to collect relevant information on the operational and security risks of payment services, ensuring that PSPs control these risks and are not exposed to a high number of severe operational and security incidents, as well as significant or severe cybersecurity incidents. 4 – With prior authorization requested from the Bank of Portugal, the recipients of this Instruction may delegate the reporting of information to another entity within the same group, without prejudice to remaining responsible for the correction and updating of the reported information. 5 – PSPs must fill out the report model contained in “Ad-hoc Reports via correspondence” in the Thematic Area of “Prudential Supervision” on the BPnet Portal (www.bportugal.net), complying with the instructions provided there and submitting it through that portal.

Article 4. Entry into force and final provision 1 – This Instruction enters into force on the day following its publication. 2 – The first annual report on the assessment of operational and security risks, referring to June 30, 2021, shall be sent to the Bank of Portugal by July 31, 2021.