2023-03-23 | 14/2023Added · Updated
The Bank of Albania’s Supervisory Council issued Regulation 14/2023 to establish comprehensive rules for the licensing, operational activities, and supervisory oversight of payment institutions. The regulation mandates robust risk management and internal control frameworks, including dedicated compliance and internal audit functions, while enforcing strict capital adequacy and client fund safeguarding requirements. It defines precise capital calculation methods based on payment volumes, outlines permissible non-payment activities, and sets clear prudential standards to ensure financial stability and regulatory compliance across the sector.
Get BOA alerts — same-day email on every new publication.
R E P U B L I C O F A L B A N I A
BANK OF ALBANIA
SUPERVISORY COUNCIL
DECISION
No. 14, dated 23.3.2023
ON THE
APPROVAL OF REGULATION
“ON CARRYING OUT OF ACTIVITY AND SUPERVISION OF PAYMENT INSTITUTIONS” In accordance with article 1, paragraph 4, letter “b”, article 12, letter “a” and article 43, letter “c” of the law no. 8269, dated 23.12.1997 “On the Bank of Albania”, as amended, and articles 10, 11, 12, 18, 19, 24 and 25 of the law no. 55/2020, dated 30.04.2020 “On payment services”; having regard to the proposal from the Supervision Department, the Supervisory Council of the Bank of Albania, D E C I D E D:
ELVIS ÇIBUKU GENT SEJKO
CHAPTER I
GENERAL PROVISIONS
Article 1
Object
The purpose of this regulation is to set out the rules for the carrying out of the activity of payment institutions and for the management of risks related to this activity, as well as their supervision.
Article 2
Subjects
Subjects of this regulation are payment institutions, as defined in point 13 of the article 5 of the law “On payment services”.
Article 3
Legal ground
This regulation is issued in accordance with article 1, paragraph 4, letter “b”, article 12, letter “a” and article 43, letter “c” of the law no. 8269, dated 23.12.1997 “On the Bank of Albania”, as amended and articles 10, 11, 12, 18, 19, 24 and 25 of the law no. 55/2020, dated 30.04.2020 “On payment services” (which hereinafter in this regulation shall be referred as the law “On payment services”).
Article 4
Definitions
CHAPTER II
GENERAL REQUIREMENTS FOR RISK MANAGEMENT AND SUPERVISION OF THE ACTIVITY OF PAYMENT INSTITUTIONS
Article 5
General prudential rules
approach and risk tolerance, and ongoing monitoring for compliance with the latter, and shall ensure that capital levels are adequate to cover this risk.
2. Steering bodies of payment institution, through their way of management, shall encourage
(stimulate) an adequate management culture, based on high professional standards and ethical values.
3. Steering bodies of payment institution shall take all measures to accomplish high ethical and
professional standards for the payment institution’s management.
Article 9
Risk management system
iv. the monitoring and evaluation of the decisions to accept certain risks, the measures
for risk mitigation and the compliance of decisions of steering bodies on risk policies;
v. reporting directly and independently to the steering bodies on all the abovementioned issues.
Article 10
Internal audit function/unit
Payment institutions shall establish the internal audit function/unit, as part of the internal
control system.
The internal audit function/unit is a separate organizational unit of the entity, independent from
the activities, structures and individuals that it reviews or controls, that reports to the management/supervisory board and/or the audit committee of the entity.
The internal audit function/unit shall ensure, independently, the steering bodies on the quality
and effectiveness of the internal audit of the entity, as well as the management/governance and risk management system and processes.
The internal audit function/unit shall implement international standards of internal control.
Payment institutions shall establish and approve internal acts for the functioning and carrying
out the activity of this function/unit that shall be drafted and reviewed as frequently as deemed necessary.
The internal acts which define the manner of functioning and carrying out the activity of the
internal audit function/unit, shall include at least the following elements:
a) the scope and field of activity of the internal audit function/unit; b) the role, authority and responsibilities of the internal audit function/unit; c) the relations of the internal audit function/unit with other functions of the control system within the entity; d) the ways and lines of communication of the results of the auditing activities; e) the procedures for the coordination with the statutory auditor or the auditing company and the supervisory authority; f) the right for unlimited and unconditional use of any registration, file, database, physical assets of the payment institution, as well as every document of the steering bodies or organizational units, necessary for the carrying out of this function’s/unit’s functions; g) the right of the head of the internal audit function/unit to have direct communication with the steering bodies; h) the right of planning and determining controls independently; i) the assurance of avoidance of any conflict of interests in carrying out the duties of internal audit; j) the requirements for compliance with the internationally accepted standards of internal audit.
The frequency of the audit shall be based on the risk based evaluation of every field of activity
and services and/or organizational unit of the payment institution. All the areas of activity and services and/or organizational units of the payment institution shall be subject to auditing by the internal audit function/unit, at least every three years, including also those activity and services and/or organizational unit with low risk, and also branches, agents and outsourcing contracts.
The internal audit function/unit shall prepare a report on any audit carried out, which shall
include at a minimum:
a) the audit object; b) description of the audit work (description of the methodology, steps and procedures followed so as to attain the audit targets, etc.); c) audit findings; d) comments by the managers of the audited organizational units on the audit findings; e) assessments on the qualifications of employees, adequacy of internal acts and risk assessment system, on a case by case basis; f) recommendations on correcting and improving findings that were observed during the audit session; and g) extent of implementation of recommendations proposed by previous audits.
The employees of the internal audit function/unit should have:
a) high ethical and professional reputation; b) professional capability to implement international internal audit standards and auditing procedures and techniques in all of the operating areas of the payment institution; c) knowledge of and/or experience in implementing accounting standards; d) knowledge of risk management principles.
The internal audit function/unit shall be responsible to draft at every year’s end, the work plan
for the following year, which shall be subject to approval by the steering bodies of the payment institution.
The internal audit function/unit presents an annual report on the work conducted by the unit to
the steering bodies of the payment institution, which shall contain the following elements:
a) a report on the level of implementation of the annual work plan of the internal audit function/unit; b) a list of all the activities planned and carried out by the internal audit function/unit; c) a list of all the activities conducted, but not planned in the annual work plan of the internal audit function/unit; d) a list of all the activities planned, but unrealized by the internal audit function/unit, along with the reasons for non-realization; e) a summary of the most important findings identified during audits; f) a general assessment of the adequacy and efficiency of the internal control system in the areas covered by the internal audit function/unit;
g) a general assessment of the adequacy and efficiency of the risk management system; h) a report on the extent of implementation of recommendations and corrective measures defined based on the recommendations, as well as the reasons for the lack of their implementation.
Article 11
Compliance function
Payment institutions shall have an executive director, responsible for the identification,
coordination and management of the compliance risk.
The compliance structure/unit is independent from the business lines and the internal units that
controls and has the authority, reputation and sufficient resources.
The main responsibility of the structure/unit that fulfills the entity’s compliance function, is to
assist the steering bodies of the payment institution for effectively managing compliance risk.
The compliance structure/unit shall advise the steering bodies of the payment institution, on
compliance with laws, rules and standards, informing regularly on developments in the field and more specifically it performs the following tasks:
a) educate and train the staff on compliance issues and act as a contact point within the entity for compliance-related queries or questions from staff members; b) establish written internal guidelines for the staff on the appropriate implementation of laws, regulations and standards through policies and procedures and other documents such as compliance manuals, internal codes of conduct and practical guidelines; c) identify, record and assess compliance risks associated with the operations of the payment institution, including new products and practices, proposed establishment of new types of business or customer relations, and material changes in the nature of such relations; d) assess the possible impact of any legal and regulatory change on the activity of payment institution and on the compliance framework; e) measure the compliance risk by using performance indicators (e.g. increased number of customer complaints, irregularities in payments, etc.) to enhance compliance risk assessment; f) assess the appropriateness of compliance procedures and regulations and the identified deficiencies, by formulating proposals for amendments; g) monitor, test and report results of the compliance adequacy testing in accordance with internal risk management system, identifying any changes in the compliance risk profile based on relevant performance indicators, identified breaches and/or deficiencies and corrective measures that have been taken; h) create an encouraging and suitable climate for the employees of the payment institution to communicate/signal non-compliance with the rules, procedures, operations, etc., ensuring at the same time, the confidentiality and protection for the employees.
The compliance structure/unit may accomplish other specific statutory functions in the
framework of fulfilling legal obligations of the entity (such as anti-money laundering etc.), as well as liaise with the Bank of Albania and/or other financial supervisory authorities, external statutory auditors or the auditing company, etc.
The compliance structure/unit performs the duties specified in this regulation and in the
payment institution’s regulatory acts under a compliance programme that sets out its planned activities, such as implementation and review of specific policies and procedures on compliance risk, compliance testing and assessment, as well as staff training and education on compliance matters.
The programme of the compliance structure/unit shall be risk-focused and subject to ongoing
review to ensure appropriate coverage across all entity business/activity lines of payment institution and coordination among risk management functions.
CHAPTER IV
CAPITAL AND SAFEGUARDING REQUIREMENTS AND RISK MANAGEMENT SUBCHAPTER I CAPITAL ADEQUACY
Article 12
General requirements for the capital of payment institution
The payment institution shall insure sufficient levels of capital, so as to exercise a stable and
safe activity, as well as to fulfill its obligations during its business.
The regulatory capital of payment institution, at any time, shall not fall below the amount of
minimum initial capital laid down in regulation “On the licencing of payment institutions and electronic money institutions and the registration of payment service providers”, or below the amount of regulatory capital requirements, calculated according to article 14 of this regulation, whichever amount is the higher.
In case the payment institution’s regulatory capital falls below the limits established in
paragraph 2 of this article, the institution reports immediately to the Bank of Albania, which defines the necessary measures and time to comply with the limits.
In the case when the payment institution grants credit relating to payment services, the total
amount of credit granted does not in any case negatively affect the regulatory capital and the fulfillment of the supervisory requirements of the Bank of Albania.
On the basis of an evaluation of the risk-management processes, of the risk loss databases and
internal control mechanisms of the payment institution, Bank of Albania may require at any time an additional amount of capital, up to 20 % (twenty percent) higher than the amount of regulatory capital requirements calculated according to article 14 of this regulation.
Article 13
Elements of payment institution’s regulatory capital
SUBCHAPTER II
CALCULATION OF REGULATORY CAPITAL REQUIREMENTS
Article 14
Calculation method of regulatory capital requirements of payment institution
a regulatory capital requirement for credit risk, at least 6% (six percent) of the outstanding amount of disbursed loans, excluding payment transactions with credit cards.
6. Payment institutions shall hold at any time a capital amount, of at least equal to the amount of
the capital requirement for payment services and the capital requirement for credit risk (where applicable). SUBCHAPTER III FUNDS’ SAFEGUARDING
Article 15
Safeguarding the funds of payment institutions’ clients
The payment institution ensures that the funds of the payment services users are kept in
separate accounting accounts, separated from other accounts of the institution that are not related to the payment services.
The payment institution that provides payment services according to items 1 to 6 of annex 1
of the law “On payment services”, safeguards all the funds received from payment services users or through other providers of payment services, for carrying out of payment transactions, in accordance with the requirements of article 12 of the law “On payment services” and in one of the forms provided for in letter “a” or in letter “b” of paragraph 1 of article 12 of the law “On payment services”.
For the purpose of implementing paragraph 1, letter “a” of article 12 of the law “On payment
services”, “secure low-risk and liquid assets” of a payment institution shall be considered:
a) debt securities issued or guaranteed by Albanian government, by central governments and central banks, by international organisations, by multilateral development banks or regional governments or local authorities, which are assigned a credit quality step “1” or which would receive a 0% risk weight under the regulation “On capital adequacy ratio”; b) debt securities issued or guaranteed by Albanian government, by central governments and central banks, by international organisations, multilateral development banks or regional governments or local authorities, which are assigned a credit quality step “2” or “3”, under the regulation “On capital adequacy ratio”; c) debt securities issued by the supervised institutions, which are assigned a credit quality step “1” or “2”, or debt securities issued by supervised institutions, which are assigned a credit quality step “3”, but which are treated according to the requirements of article 17/2, paragraph 3 of the regulation “On the capital adequacy ratio”; d) debt securities issued by corporates, which are assigned a credit quality step “1” or “2” under the regulation “On capital adequacy ratio”; e) units in collective investment undertakings in transferable securities (UCITS), which invest solely in assets as specified in the letters “a” to “d” of this paragraph.
The insurance policy or the guarantee provided for in letter “b” of paragraph 1 of article 12 of
the law “On payment services”, must be payable, in case the payment institution is unable to fulfill its financial obligations to the payment services users, according to the causes/events (triggers) that activate their implementation and which are defined, respectively, in the insurance contract or in the guarantee contract. The insurance policy or guarantee does not have any clause on the franchise, deductible or threshold that may affect the disbursement of payments to the beneficiaries or any other payment service provider.
Payment institutions shall notify the Bank of Albania, in advance of any significant changes in
the measures taken by them, for the safeguarding of the funds of payment services users.
Article 16
Diversification of funds’ safeguarding
Payment institutions that safeguard funds of payment services users, as referred to in article
12, paragraph 1, letter “a” of the law “On payment services”, shall invest clients’ funds in diversified ways, in different counterparties.
The payment institution, in its decision-making for the ways of safeguarding funds according
to the provisions of article 15 of this regulation, may also consider the following elements:
a) the level of capital of the bank and/or insurance company, which should be proportionate to the amount of relevant funds deposited in accounts, or guaranteed or insured; b) the level of risk accompanying the lending activity or investments undertaken by the bank and/or insurance company.
The payment institution shall document its decision-making, according to the provision of
paragraph 2 of this article.
Article 17
Professional indemnity insurance and other comparable guarantees Payment institutions that provide payment services according to points 7, 8 or both (7 and 8) of
annex 1 of the law “On payment services”, shall hold a professional indemnity insurance or other
comparable guarantees, in accordance with the requirements of the guideline “On the criteria on how to stipulate the minimum monetary amount of the professional indemnity insurance or other comparable guarantees”.
SUBCHAPTER IV
EXPOSURES TO RISK AND LIMITS
Article 18
Allowable open foreign exchange position
Article 20
Credit granting related to payment services
Article 22
Statutory audit
Read the rest free
Source: Bank of Albania — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works