2021-03-15

Added · Updated

Instruction No. 4/2021 on the Management and Reporting of Operational and Security Risks by Payment Service Providers

Payment service providers (PSPs) with headquarters in Portugal must comply with the European Banking Authority's guidelines on ICT and security risk management and submit an annual operational and security risk assessment report to the Bank of Portugal by July 31 each year, referencing June 30 of that same year. The first such report, covering the period ending June 30, 2021, was due by July 31, 2021. PSPs may delegate reporting to another group entity with prior authorization from the Bank of Portugal but remain responsible for the accuracy and updates of the reported information.

Banco de Portugal logo

Portugal

Banco de Portugal

Click to view thumbnail

Instruction No. 4/2021 BO No. 3/2021 • 2021/03/15 .................................................................................................................................................................................................. Topics Supervision :: Prudential Standards Mod. 99999940/T – 01/14 Index Text of the Instruction Article 1.º Recipients Article 2.º Operational and security requirements Article 3.º Annual report on the assessment of operational and security risks Article 4.º Entry into force and final provision Text of the Instruction Subject: Instruction on the management and reporting, by payment service providers, of operational and security risks In 2017, the European Banking Authority (EBA) published the "Guidelines on security measures to manage operational and security risks under Directive (EU) 2015/2366" (EBA/GL/2017/17), establishing a set of security requirements in Information and Communication Technologies (ICT) for payment service providers (PSP). Additionally, also in 2017, the EBA published the "Guidelines on ICT risk assessment within the supervisor review and evaluation process (SREP)" (EBA/GL/2017/05) with the aim of ensuring convergence of supervisory practices in the assessment of ICT risk, as specified in detail in the "EBA Guidelines on common procedures and methodologies for the SREP" (EBA/GL/2014/13). In February 2019, the EBA published the "Guidelines on Outsourcing" (EBA/GL/2019/02) which establish procedures and requirements for effective management of external ICT outsourcing, for which purpose the Bank of Portugal issued Circular Letter No. CC/2019/000000651. More recently, on November 28, 2019, the EBA published the "Guidelines on ICT and security risk management" (EBA/GL/2019/04, hereinafter "Guidelines"), addressed to credit institutions, investment firms and PSPs. These Guidelines incorporate and revoke the previous "Guidelines on security measures to manage operational and security risks under Directive (EU) 2015/2366" (EBA/GL/2017/17). In particular, the Guidelines specify the measures and procedures that financial institutions must adopt, within the scope of operational risk and internal governance, to manage their risks associated with ICT and security (which include, among others, on the one hand cybersecurity risk and, on the other hand, operational and security risks related to payment services). In this context, the Guidelines provide, by reference to Article 95(2) of Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015, on payment services in the internal market (PSD2), that PSPs must communicate to the Bank of Portugal a comprehensive and updated assessment of the operational and security risks related to the payment services they provide, as well as the adequacy of the mitigation and control measures implemented in response to those risks. This annual communication aims to collect relevant information on the operational and security risks of payment services, ensuring that the entities concerned control these risks, as well as their exposure to severe operational and security incidents. The Bank of Portugal communicated to the EBA its intention to comply with the aforementioned Guidelines from June 30, 2020, and in this context published Circular Letter No. CC/2020/00000029, of May 6, informing the entities concerned of its intention and the respective compliance date with the Guidelines. The present Instruction has as its object to implement the requirements contained in the Guidelines, including the duty to report the annual assessment of operational and security risks of the payment services provided. It should be noted that the Instruction is directed exclusively to PSPs, so it does not apply to Investment Firms, to branches in Portugal of credit institutions authorized in other Member States of the European Union (EU), to branches of electronic money institutions with headquarters in the EU and to branches of payment institutions with headquarters in the EU. The Bank of Portugal emphasizes the importance of these Guidelines for strengthening the operational resilience of the financial sector. Firstly, the Guidelines introduce greater specification of supervisory expectations regarding ICT and security risk and thereby strengthen the current prudential requirements, particularly in the ICT risk self-assessment questionnaire of credit institutions whose results are taken into account in the SREP, namely in the capital risk analysis, in the category of information systems and in the context of operational risk. Secondly, the Guidelines describe more clearly the responsibilities of senior management and the second and third lines of defense in the management of the ICT strategy and governance model. Thirdly, the Guidelines strengthen the recent strategy of the Bank of Portugal for strengthening operational resilience in matters of cybersecurity, complementing Instruction No. 1/2019 and Instruction No. 21/2019, which institute duties to report operational and security incidents, and cybersecurity incidents, in Portugal. Finally, the Guidelines introduce the possibility for institutions to carry out intrusion tests, with greater or lesser scope, intensity and periodicity, as a way to test potential vulnerabilities in systems and to assess the effectiveness and response capacity of defense mechanisms. The present Instruction was subject to public consultation in accordance with the terms and for the purposes provided for in Articles 100(3)(c) and 101, both of the Administrative Procedure Code. In this context, the Bank of Portugal, using the competence attributed to it by Articles 14 and 17 of its Organic Law, approved by Law No. 5/98, of January 31, as well as by Articles 115-T and 116(f) of the General Regime of Credit Institutions and Financial Companies and by Articles 70(3), 60(3) and 157(1) of the RJSPME, approves the following Instruction: Article 1. Recipients The recipients of this Instruction are payment service providers (hereinafter "PSP"), within the meaning of Article 11(1) of the RJSPME, with headquarters in Portugal, even if operating in other countries through the exercise of the right of establishment or the free provision of services. Article 2. Operational and security requirements PSPs observe the requirements provided for in the Guidelines on ICT and security risk management of the European Banking Authority (EBA/GL/2019/04), in the management of operational and security risks related to the payment services they provide. Article 3. Annual report on the assessment of operational and security risks 1 – PSPs prepare, with reference to June 30 of each year, an annual report on the assessment of operational and security risks of the payment services provided, according to the model annexed to this Instruction. 2 – The report referred to in the preceding number is reported to the Bank of Portugal by July 31 of the same year. 3 – The annual assessment report aims to collect relevant information on the operational and security risks of payment services, ensuring that PSPs control these risks and are not exposed to a high number of severe operational and security incidents, as well as significant or severe cybersecurity incidents. 4 – With prior authorization requested from the Bank of Portugal, the recipients of this Instruction may delegate the reporting of information to another entity of the same group, without prejudice to remaining responsible for the correction and updating of the reported information. 5 – PSPs must fill in the report model contained in "Ad-hoc Reports via correspondence" in the Thematic Area of "Prudential Supervision" of the BPnet Portal (www.bportugal.net), complying with the instructions therein and submitting it through that portal. Article 4. Entry into force and final provision 1 – This Instruction enters into force on the day following its publication. 2 – The first annual report on the assessment of operational and security risks, referring to June 30, 2021, shall be sent to the Bank of Portugal by July 31, 2021.

More like this from BDP

BDP published 2 documents in the last 30 days. We email you each new one the day it's published.

Share