2017-08-24

Added · Updated

PSD Circular No. 04/2017: Ensuring Security, Minimizing Transaction Risks and Enhancing Public Awareness in Card-Based Payments Through Different Payment Channels to Discourage or Reduce Cash Transactions

Bangladesh Bank mandates that all domestic interbank card transactions be processed through the Bangladesh Switch (BAS) by December 31, 2017, and requires all card transactions to be PIN-based by the same date. Banks must ensure ATM and POS terminals are equipped with chip card technology, anti-skimming devices, and PIN pads by June 30, 2018, and upgrade existing magnetic stripe cards to chip technology by that date. The circular further requires the implementation of Two-Factor Authentication (2FA) for internet/mobile banking by December 31, 2017, and obligates banks to conduct cybersecurity risk assessments, establish 24/7 Security Operations Centers, and enhance customer awareness regarding secure card usage.

Bangladesh Bank logo

Bangladesh

Bangladesh Bank

Click to view thumbnail

Department of Payment Systems Bangladesh Bank Head Office Dhaka PSD Circular No: 04 /2017 Date: ------------------- 09 Bhadro 1424 Managing Director / Chief Executive Officer All Scheduled Banks operating in Bangladesh

Dear Sir,

In the context of ensuring the security of card-based transactions conducted through various payment channels, minimizing risks, and enhancing customer awareness, with the aim of discouraging or reducing cash transactions.

With the increasing reliance on IT-dependent banking services, banks are providing facilities to their customers to conduct transactions in local currency using ATMs, POS, and Internet/Mobile/Online Banking. In order to ensure the security of such transactions, minimize risks, and enhance customer awareness, this circular is issued consolidating previously issued circulars and other instructions regarding the supervision and monitoring of various platforms, in light of Section 7(b) of the Bangladesh Bank Order, 1972 (amended 2003), Section 49(1)(c) of the Banking Company Act, 1991 (amended 2013), and the Bangladesh Bank Act, 1991.

  1. Regarding Cards:

  2. All domestic (interbank) interbank card transactions issued by all banks and financial institutions conducting card-based transactions must be processed/completed through the Bangladesh Automated Clearing House (BACH) operated by Bangladesh Bank.

  3. All types of card-based transactions must be made PIN-based by December 31, 2017.

  4. Information regarding all card-based transactions via ATM services must be instantly informed to the customer.

  5. To ensure the security of card transactions and to make the transaction infrastructure meet national standards, banks must be PCI-DSS (Payment Card Industry Data Security Standard) Certified by December 31, 2018.

  6. All branded cards issued by banks and financial institutions must be equipped with Chip and PIN (Chip and PIN); previously issued magnetic stripe cards of this type must be upgraded to this technology, and this process must be completed entirely by June 30, 2018.

  7. In case a card is stuck during a transaction, the ATM shall provide the Card Information Error Message in the case of cash withdrawal transactions; however, in the case of non-cash transactions, if the card is stuck, the bank shall resolve it according to its own adopted rules. In both cases, the Card Information Error shall be resolved within 7 working days of receiving the customer's application.

  8. If it is suspected/confirmed that a customer's card information and PIN number have been compromised, the respective error device (POS machine/ATM booth) used must be identified instantly, and the customer must be informed regarding the bank's cards, and the card must be cancelled, and a new card must be provided to the customer as soon as possible. If the customer belongs to another bank, the respective card-issuing bank must be informed instantly to take appropriate action.

  9. In the case of issuing proprietary cards, collection of PAN (Primary Account Number) must be obtained from the Payment Systems Department of Bangladesh Bank.

  10. Facilities for the use of cards must be informed to encourage customers in card-based transactions.

  11. To reduce risks in card-based transactions, posters containing images of correct card usage rules, along with appropriate caution/confidentiality measures in all transactions, must be displayed in bank branches, and print and electronic media campaigns must be started to enhance customer awareness.

  12. Regarding Various Channels: 2.1 Regarding ATM Transactions:

  13. All ATMs established by member banks-institutions of BACH operating in Bangladesh must be connected to BACH, and interbank card transactions conducted via ATMs must be processed/completed through BACH.

  14. All newly established ATMs must mandatorily be equipped with Chip Card processing technology, Anti-Skimming technology, PIN pads, and Encrypted PIN pads, and existing ATMs must also be equipped with the aforementioned technologies by December 31, 2017.

  15. Video footage of daily transactions occurring in ATM booths must be monitored appropriately and stored for a minimum of 01 (one) year, of which 03 (three) months must be online and the rest in archive status, and if any suspicious matter is observed, action must be taken by the bank.

  16. ATM service-providing banks must inspect/visit a minimum of 20 ATMs per month. If the number of their ATMs is less than 20, they must inspect/visit all of them. Inspection reports must be prepared in the format provided from this section and stored in their own management for a minimum of one year.

  17. Cash supply must be ensured in ATM booths to keep the ATM service sub-system running.

  18. Arrangements must be made to display a notice in front of closed or inactive ATM booths, and they must be made operational within a maximum of 72 hours.

  19. During the installation/repair of any new machine in the booth, the security guard working in the ATM booth must contact the authorized officer of the bank regarding this matter to verify the identity of visitors/persons. If necessary, the respective bank officer must personally visit the ATM booth to verify the identity of such persons.

  20. To ensure instant resolution of customer problems, the contact phone number for the 24/7 Service Center must be displayed as a notice in the ATM booth.

  21. Guards employed in ATM booths must be provided with necessary training to prevent fraud/deception. Additionally, special caution must be exercised regarding customers wearing sunglasses, carrying bags, and other suspicious customers.

  22. All types of fees/charges related to ATM transactions must be displayed in visible places.

  23. Posters containing images of correct rules for ATM use in simple language must be displayed in visible places in the booth.

2.2 Regarding POS Transactions:

  1. All POS established by all banks and financial institutions that are members of BACH operating in Bangladesh must be connected to BACH by December 31, 2017, and interbank card transactions conducted via POS must be processed/completed through BACH.
  2. All transactions conducted via POS machines must be PIN-based. In POS transactions, the cardholder must provide the PIN manually, which must be completed through the Encrypted PIN Pad.
  3. Except for online hotel booking and online domestic flight ticket purchases, the use of Signature-based transactions in POS has been banned in all other cases.
  4. In the case of card-based POS transactions, the responsibility for ensuring the security of the customer's card-related information lies with the merchants on the banks.
  5. In the case of card-based POS transactions, the network of all terminals under the network must be PCI-PTS (Payment Card Industry Point-to-Point Encryption) certified by December 31, 2017.
  6. All newly installed POS machines must mandatorily be equipped with Chip Card processing technology, CVMs, Encrypted PIN pads, and PIN pads, and existing POS machines must also be equipped with the aforementioned technologies by June 30, 2018.
  7. To prevent fraud/deception and conduct safer POS transactions, merchants must be trained.
  8. In the case of POS transactions at various merchant points, banks must ensure that merchants do not charge customers extra money beyond the agreed price of the goods or services, and must enhance customer awareness along with cautioning merchants.
  9. Initiatives must be taken to expand the merchant payment network. Contracts must be signed with new merchants after analyzing their capacity, business scope, and risk.
  10. In the case of placing POS machines of different banks at the same merchant's same point, emphasis must be placed on keeping a maximum of three POS machines capable of interbank card transactions.

2.3 Regarding Internet/Mobile/Online Banking:

  1. For all transactions related to bank accounts/cards in Internet/Mobile/Online Banking, a One-Time Password (OTP)/Dynamic Authentication/Static Authentication (2FA) system must be implemented by December 31, 2017.

  2. In all these transactions, the IT Act must be properly complied with, and if any discrepancy is observed, it must be immediately informed to the Bangladesh Financial Intelligence Unit.

  3. All transactions must be settled in local currency.

  4. Banks providing Mobile Banking services must ensure that this service remains operational. If this service is disrupted for any reason, the customer must be informed, and it must be made operational within a maximum of 72 hours.

  5. Others:

  6. Each bank and financial institution must formulate a Cyber Security Risk Assessment and Operational Continuity Plan policy to monitor operations and develop a plan to deal with any cyber risk/attack.

  7. Before implementing any IT infrastructure (especially transaction systems) and starting its operation, a Security and Privacy Impact Assessment (SPIA) must be conducted. Additionally, SPIA must be conducted for existing transaction systems at specified intervals (at least once every two years).

  8. Banks must appropriately inform customers about self-service/digital (online/offline) systems already in operation - such as Cards, EFT, RTGS, FPS, Mobile Banking, etc. - to discourage cash transactions. Arrangements must be made to hang notices regarding self-service systems in visible places in each branch of the bank.

  9. A 24/7 Security Operations Center (SOC) must be established for continuous monitoring of the entire system, including conducting technical vulnerability assessments and developing emergency management plans.

  10. Banks must build a workforce of their own officers and employees who are aware and trained regarding alternative payment systems to discourage cash transactions and related cyber security and transaction risks. This matter will be a continuous process.

This instruction shall come into force immediately.

Yours faithfully, (Lila Rashid) General Manager Phone: 9530174

More like this from BB

BB published 33 documents in the last 30 days. We email you each new one the day it's published.

Share