2018-08-08 | 12/POJK.03/2018Added
The Financial Services Authority mandates that commercial banks obtain prior approval before implementing electronic or digital banking services, requiring submission of risk analyses, IT infrastructure readiness, and independent audit reports at least two months before implementation. Banks must enforce two-factor authentication for customer verification, establish dedicated digital banking units, and strictly prohibit assuming risks for products offered by third-party partners in digital partnerships. The regulation also imposes reporting obligations for service realization and IT conditions within three months of implementation and allows the Authority to order the cessation of services that deviate from approved plans or negatively impact bank performance.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
BY THE GRACE OF GOD THE ALMIGHTY,
THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering:
a. that the increasingly high competition in the financial services industry encourages banks to improve the quality of service to customers more effectively and efficiently and continuously; b. that to drive the effectiveness, efficiency, and create continuity of service to customers, banks need to further increase their capabilities followed by aligning business strategies more accurately;
c. that as one of the efforts to increase bank capabilities, the optimal utilization of information technology developments is a prerequisite in supporting bank service innovation;
d. that to achieve business strategy alignment to be more accurate, banks need to provide easy access to information technology-based banking services without time and place limitations to encourage better customer financial management; e. that service innovation and strategy alignment in the use of information technology drive the banking industry to enter the era of digital banking services; f. that the provision of digital banking services can impact increased risks, particularly operational risk, strategic risk, and reputational risk, so there is a need to increase the application of risk management in the use of information technology effectively by banks; g. that based on the considerations as referred to in letters a through f, it is necessary to establish a Financial Services Authority Regulation concerning the Provision of Digital Banking Services by Commercial Banks.
Recalling:
DECIDING:
Establishing: FINANCIAL SERVICES AUTHORITY REGULATION CONCERNING THE PROVISION OF DIGITAL BANKING SERVICES BY COMMERCIAL BANKS.
In this Financial Services Authority Regulation, the following terms are defined as:
(1) Banks may provide Electronic Banking Services or Digital Banking Services.
(2) Banks providing Electronic Banking Services or Digital Banking Services must apply risk management, prudential principles, and meet the provisions in this Financial Services Authority Regulation.
Banks provide Electronic Banking Services by utilizing distribution channels.
Banks providing Electronic Banking Services as referred to in Article 3 must be included in the Commercial Bank group based on business activities as regulated in the Financial Services Authority regulations.
(1) Banks must include the plan for issuing Electronic Banking Service products in the Bank's business plan.
(2) Banks issuing Electronic Banking Service products that are transactional must obtain approval from the Financial Services Authority.
(3) To obtain approval as referred to in paragraph (2), Banks must submit an application for approval of Electronic Banking Service products to the Financial Services Authority. (4) The application for approval of Electronic Banking Service products as referred to in paragraph (3) must be accompanied by documents consisting of:
a. evidence of readiness to provide Electronic Banking Services which at least contains:
Banks must apply data and transaction security control principles for customer Electronic Banking Services on every electronic system used by the Bank.
Banks provide Digital Banking Services which may be advanced products of Electronic Banking Services.
(1) Digital Banking Services may be provided by:
a. Banks; and/or b. Banks based on partnership agreements between Banks and Bank Partners.
(2) Bank Partners as referred to in paragraph (1) letter b may be FSIs or non-FSI institutions.
(1) Banks providing Digital Banking Services must form a unit or function tasked with handling the provision of Digital Banking Services.
(2) The unit or function handling the provision of Digital Banking Services as referred to in paragraph (1) has duties at least to:
a. formulate policies, standards, and procedures for the provision of Digital Banking Services; b. ensure the alignment of Digital Banking Service provision with the Bank's business activity strategic plan;
c. monitor the implementation of cooperation with Bank Partners in the provision of Digital Banking Services;
d. monitor Digital Banking Service financial transaction data; e. ensure the effectiveness of steps used in providing Digital Banking Services; f. monitor obstacles and problems arising from the provision of Digital Banking Services; and g. ensure the adequacy and allocation of resources related to Digital Banking Services owned by the Bank.
(1) Digital Banking Services provided by Banks as referred to in Article 8 paragraph (1) letter a consist of:
a. account administration; b. transaction authorization; and/or
c. financial management; and/or
d. provision of other financial products based on Financial Services Authority approval.
(2) Banks in providing Digital Banking Services consisting of transaction authorization as referred to in paragraph (1) letter b must utilize data and/or information whose truthfulness can be accounted for.
(1) In conducting business relationships with customers or prospective customers through Digital Banking Services, Banks must conduct:
a. identification of customers or prospective customers; and b. verification of information and supporting documents of customers or prospective customers as referred to in letter a. (2) Banks conduct verification of information and supporting documents of customers or prospective customers as referred to in paragraph (1) letter b by:
a. through face-to-face interaction:
(1) In fulfilling obligations as referred to in Article 11 paragraph (1), Banks may utilize data and/or information owned by authorized institutions or other sources that already have a cooperative relationship with the Bank. (2) Banks must ensure the readiness of supporting infrastructure in the utilization of data and/or information as referred to in paragraph (1).
(1) Digital Banking Services by Banks based on partnership agreements between Banks and Bank Partners as referred to in Article 8 paragraph (1) letter b consist of:
a. informative services; b. transactional services; and/or
c. other services based on Financial Services Authority approval.
(2) In conducting cooperation with Bank Partners as referred to in paragraph (1), Banks must still pay attention to statutory regulations.
Bank Partners in providing informative services as referred to in Article 13 paragraph (1) letter a must be FSIs.
(1) Bank Partners in providing transactional services as referred to in Article 13 paragraph (1) letter b consist of:
a. FSIs; and/or b. non-FSI institutions.
(2) Bank Partners as referred to in paragraph (1) that are Information Technology-based financial service providers must have obtained approval from the Financial Services Authority or other authorized authorities. (3) The provision of transactional services as referred to in paragraph (1) may utilize connectivity between the Bank's electronic systems and the Bank Partner's electronic systems. (4) Banks are prohibited from becoming marketplaces in providing transactional services to Bank Partners through applications and/or websites owned by the Bank. (5) Banks must apply at least 2 (two) authenticity factors (two-factor authentication) for financial transaction verification on transactional services.
(1) In providing Digital Banking Services by Banks based on partnership agreements between Banks and Bank Partners, Banks must have:
a. policies and procedures in determining Bank Partners; and b. written cooperation agreements with Bank Partners drafted in the Indonesian language.
(2) Banks may only provide information on products and/or services offered by Bank Partners as stated in the cooperation agreement as referred to in paragraph (1) letter b.
(1) Banks are prohibited from bearing or jointly bearing risks arising from products and/or services offered by Bank Partners in providing Digital Banking Services by Banks based on partnership agreements between Banks and Bank Partners. (2) The use of Bank logos and/or attributes in marketing documents used is only intended to indicate cooperation between Banks and Bank Partners. (3) Products offered by Bank Partners other than FSIs consisting of Banks are not included in the scope of the guarantee program as referred to in statutory regulations concerning deposit guarantee institutions.
Banks providing Digital Banking Services as referred to in Article 7 must meet the following requirements:
a. have a risk profile rating of Rating 1 (one) or Rating 2 (two) based on the assessment of the Bank's health level in the last assessment period; b. have adequate Information Technology infrastructure and Information Technology infrastructure management; and
c. be included in the Commercial Bank group based on business activities that at least can conduct Electronic Banking Service activities as regulated in Financial Services Authority regulations.
(1) Banks must include the plan for the provision of Digital Banking Services by Banks and/or by Banks based on partnership agreements between Banks and Bank Partners in the Bank's business plan. (2) Banks having plans for the provision of Digital Banking Services as referred to in paragraph (1) must obtain approval from the Financial Services Authority. (3) The provision of Digital Banking Services required to obtain approval from the Financial Services Authority as referred to in paragraph (2) is:
a. Digital Banking Services issued for the first time; and/or b. development of Digital Banking Services that have different characteristics and/or add or increase specific risk exposures to the Bank. (4) To obtain approval as referred to in paragraph (2), Banks having plans for the provision of Digital Banking Services must submit an application for approval of Digital Banking Services to the Financial Services Authority. (5) The application for approval of Digital Banking Service products as referred to in paragraph (4) must be accompanied by documents containing the following:
a. evidence of readiness to provide Digital Banking Services which at least contains:
(1) Banks must implement the Electronic Banking Service plan as referred to in Article 5 or the Digital Banking Service plan as referred to in Article 19 at the latest 6 (six) months from the date of approval given by the Financial Services Authority. (2) In the event that Banks do not implement the Electronic Banking Service or Digital Banking Service plan within the 6 (six) month period from the date of approval given by the Financial Services Authority as referred to in paragraph (1), the Financial Services Authority approval becomes invalid. (3) In the event that the Financial Services Authority approval has become invalid as referred to in paragraph (2), and Banks still intend to implement the Electronic Banking Service or Digital Banking Service plan, Banks must submit the approval application again to the Financial Services Authority.
(1) Banks providing Electronic Banking Services or Digital Banking Services must apply consumer protection principles as referred to in statutory regulations concerning consumer protection in the financial services sector. (2) Banks providing Digital Banking Services must have functions and mechanisms for handling every inquiry and/or complaint from customers that operate 24 (twenty-four) hours a day. (3) The mechanism and procedures for applying consumer protection principles as referred to in paragraph (1) refer to statutory regulations concerning consumer protection in the financial services sector.
(1) Banks must submit reports on the realization of Electronic Banking Services or Digital Banking Services to the Financial Services Authority at the latest 3 (three) months after implementation. (2) Banks must submit reports on the current condition of Information Technology usage, reports on Information Technology development plans, reports on Information Technology audit results, and incidental reports in the provision of Information Technology related to Electronic Banking Services or Digital Banking Services.
(1) The format for applications for approval of Electronic Banking Services as referred to in Article 5 and the format for applications for approval of Digital Banking Services as referred to in Article 19, as well as reports on the realization of Electronic Banking Services or Digital Banking Services as referred to in Article 22 paragraph (1) refer to the Appendix which is an integral part of this Financial Services Authority Regulation. (2) The time limit and format for submitting reports as referred to in Article 22 paragraph (2) refer to Financial Services Authority regulations concerning the application of risk management in the use of information technology by Commercial Banks.
(1) Applications for approval of the provision of Electronic Banking Services as referred to in Article 5 or Digital Banking Services as referred to in Article 19, as well as the submission of reports as referred to in Article 22 and Article 23 are submitted to the Financial Services Authority online. (2) In the event that the online submission facility for approval applications and/or reporting as referred to in paragraph (1) is not yet available or is available but there are technical disturbances, approval applications and/or reporting are submitted to the Financial Services Authority at the address:
a. the Department of Supervision of the Relevant Bank, the Department of Sharia Banking, or the Regional Office of the Financial Services Authority in Jakarta, for Banks headquartered in the Special Capital Region of Jakarta province; or b. the Regional Office of the Financial Services Authority or the Local Financial Services Authority Office, according to the area where the Bank's headquarters is located.
The Financial Services Authority may order Banks to stop the provision of Electronic Banking Services or Digital Banking Services, in the event that based on the Financial Services Authority's evaluation, the services provided:
a. do not match the new activity implementation plan reported to the Financial Services Authority or the approval and/or recording of products from the Financial Services Authority; and/or b. have the potential to have a negative impact on the performance and reputation of the Bank.
CHAPTER VIII
SANCTIONS
Article 26
(1) Banks that do not implement the provisions as referred to in Article 2 paragraph (2), Article 4, Article 5 paragraph (1), Article 5 paragraph (2), Article 5 paragraph (3), Article 5 paragraph (8), Article 6, Article 9 paragraph (1), Article 10 paragraph (2), Article 11 paragraph (1), Article 11 paragraph (4), Article 11 paragraph (5), Article 14, Article 15 paragraph (2), Article 15 paragraph (4), Article 15 paragraph (5), Article 16 paragraph (1), Article 17 paragraph (1), Article 19 paragraph (1), Article 19 paragraph (2), Article 19 paragraph (4), Article 19 paragraph (9), Article 20 paragraph (3), Article 21 paragraph (1), and/or Article 21 paragraph (2), shall be subject to administrative sanctions in the form of:
a. written reprimand; b. downgrade of health level in the form of a downgrade of the governance factor rating in the Bank's health level assessment;
c. prohibition on issuing products or carrying out new activities;
d. suspension of certain business activities; and/or e. inclusion of members of the Board of Directors, Board of Commissioners, and executive officials in the list of failed candidates through the mechanism of competence and propriety tests. (2) Sanctions as referred to in paragraph (1) letters b, c, d, and/or e may be imposed with or without prior imposition of the written reprimand sanction as referred to in paragraph (1) letter a.
Article 27
(1) Banks that do not meet the reporting provisions as referred to in Article 22 shall be subject to administrative sanctions in the form of:
a. a fine of Rp1,000,000.00 (one million rupiah) per day of delay per report; or b. a fine of Rp50,000,000.00 (fifty million rupiah) per report, for Banks that have not submitted the report after 1 (one) month from the final deadline for report submission. (2) The imposition of fine sanctions as referred to in paragraph (1) does not eliminate the obligation to submit reports.
CHAPTER IX
TRANSITIONAL PROVISIONS
Article 28
(1) The process of submitting applications for approval of Electronic Banking Services that were submitted before this Financial Services Authority Regulation takes effect shall refer to the Financial Services Authority's provisions regarding the implementation of risk management in the use of information technology by Commercial Banks. (2) At the time this Financial Services Authority Regulation takes effect, applications for approval of Electronic Banking Services shall be subject to this Financial Services Authority Regulation and the Financial Services Authority Circular Letter regarding the Implementation of Risk Management in the Use of Information Technology by Commercial Banks.
This copy is in accordance with the original
Director of Law 1
Legal Department signed
Yuliana
CHAPTER X
FINAL PROVISIONS
Article 29
This Financial Services Authority Regulation shall take effect on the date of its promulgation.
In order that everyone knows it, it is ordered to promulgate this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia. Determined in Jakarta on 6 August 2018
CHAIRMAN OF THE COMMISSIONERS
FINANCIAL SERVICES AUTHORITY, signed
WIMBOH SANTOSO promulgated in Jakarta on 8 August 2018 MINISTER OF LAW AND HUMAN RIGHTS REPUBLIC OF INDONESIA, signed YASONNA H. LAOLY STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2018 NUMBER 127
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
NUMBER 12 /POJK.03/2018
CONCERNING
THE PROVISION OF DIGITAL BANKING SERVICES BY COMMERCIAL BANKS
I. GENERAL
The financial services industry in Indonesia is one of the industries that plays an important role in economic activities. The large number of players in the financial services industry causes a high level of competition, especially in acquiring customers. On the other hand, the development of times also shows changes both in the development of Information Technology and changes in people's behavior patterns in using services provided by Financial Service Institutions. This phenomenon currently encourages the emergence of new financial service players known as information technology-based financial service providers (financial technology) that offer new innovations in financial services. This has an impact on increasing competition in the financial services industry and encourages players to provide higher quality services and add value to customers to maintain their existence. Banks, as one of the main players in the financial services industry that provide banking services directly to the public, also need to make breakthroughs in providing services. The interaction that occurs between customers and Banks currently is mostly physical interaction carried out either through the Bank's office network or the Bank's devices manually, which requires relatively more time and is less practical.
On the other hand, banking services for customers in Indonesia are still product-centric. In answering the increasingly tight competitive challenges, Banks need to align their strategy for providing financial services that are customer-centric (personalized). The role of Information Technology becomes a very important aspect considering the increasingly high use of mobile devices and computers as media for financial transactions. This is also supported by the increasing use of the internet network in Indonesia followed by the expansion of internet network infrastructure construction. The use of Information Technology becomes one of the prerequisites in the provision of financial services by Banks. The use of Information Technology can be carried out by Banks either through independent development of supporting infrastructure or through cooperation with Bank partners. By utilizing Information Technology, Banks are expected to be able to provide services to customers without place and time limitations, and with minimal costs that provide maximum comfort to customers according to customer preferences. The increased use of Information Technology in improving personalized services to customers directs Banks into a new era, namely the digital banking era. Personalized services to customers in the digital banking era can be realized from the beginning of the business relationship between customers and Banks until it ends. The process of opening savings accounts, executing financial transactions, to closing savings accounts can be done by utilizing Information Technology. Service innovation, cooperation with Bank partners, and process automation are several things that must be considered by Banks, especially in facing risks that may arise from every strategy that will be formulated in the future. Digital Banking is expected to provide ease at a higher level compared to existing services. On the other hand, Digital Banking increases the risks that Banks will face, especially related to operational risk, strategic risk, and reputational risk.
With the issuance of this Financial Services Authority Regulation, Banks are expected to be able to provide Digital Banking Services while still prioritizing risk management in the use of Information Technology.
II. ARTICLE BY ARTICLE
Article 1
It is clear enough.
Article 2
Paragraph (1)
The provision of Electronic Banking Services or Digital Banking Services is one of the efforts by Banks to play an active role in expanding public financial access.
The expansion of public financial access includes, among others, opening savings accounts at Banks that can be done independently and increasing financial services to facilitate customer financial management. Paragraph (2) The implementation of risk management refers to the Financial Services Authority's provisions regarding the implementation of risk management by Banks.
Article 3
Examples of delivery channels for Electronic Banking Services include Automated Teller Machine (ATM), Cash Deposit Machine (CDM), phone banking, Short Message Services (SMS) banking, Electronic Data Capture (EDC), Point of Sales (POS), internet banking, and mobile banking.
Article 4
The term "Financial Services Authority provisions" includes, among others, provisions regarding business activities and office networks based on core capital, business activities of Commercial Banks based on core capital, and/or products and activities of Sharia Commercial Banks and Sharia Business Units.
Article 5
Paragraph (1)
It is clear enough.
Paragraph (2)
Electronic Banking Services products that are transactional and require approval from the Financial Services Authority are new products that have characteristics different from existing products in the Bank and/or add to or increase certain risk exposures in the Bank. Examples of transactional Electronic Banking Services include book transfers, fund transfers, payments, and purchases. Paragraph (3) It is clear enough. Paragraph (4) Letter a Number 1 The term "management" includes, among others, the Board of Directors, Board of Commissioners, and Information Technology Steering Committee. Number 2 It is clear enough. Number 3 It is clear enough. Number 4 It is clear enough. Number 5 It is clear enough. Number 6 It is clear enough. Number 7 It is clear enough. Number 8 It is clear enough. Letter b It is clear enough. Letter c Supporting documents include, among others, documents required by relevant authorities, such as:
Article 6
The principle of controlling the security of customer data and transactions from Electronic Banking Services on each electronic system includes, among others:
a. confidentiality; b. integrity;
c. availability;
d. authentication; e. non-repudiation; f. authorization control in systems, databases, and applications; g. segregation of duties; and h. maintenance of audit trails.
The term "electronic system" is as referred to in the Financial Services Authority Regulation regarding the Implementation of Risk Management in the Use of Information Technology for Commercial Banks.
Article 7
Examples of Digital Banking Services:
a. self-service account opening services by customers through ATMs that have been developed or Bank applications found on smartphones, supported by facilities such as fingerprint scanners, identity card scanners, and/or video banking; b. housing credit application services to customers. In granting credit approval, the Bank analyzes customer financial data in the form of financial position, transaction patterns, and financial portfolio. In addition, the Bank also provides advice to customers in helping make home purchase decisions by providing data such as house prices and locations from third parties that match customer needs and characteristics. Credit applications are made directly through the Bank application found on the customer's smartphone with transaction authorization using, among others, fingerprints.
Article 8
Paragraph (1)
Letter a
The term "provided by the Bank" refers to Digital Banking Services provided by the Bank. The provision of Information Technology related to Digital Banking Services by the Bank can be carried out by the Bank independently and/or by Information Technology service providers. Letter b The term "provided by the Bank based on a partnership agreement between the Bank and Bank partners" refers to Digital Banking Services provided by the Bank in cooperation with Bank partners. Paragraph (2) It is clear enough.
Article 9
Paragraph (1)
The function responsible for handling the provision of Digital Banking Services can be carried out by existing work units or operational units within the Bank, according to the complexity of the Bank's business. Paragraph (2) Letter a It is clear enough. Letter b It is clear enough. Letter c It is clear enough. Letter d Monitoring of Digital Banking Services financial transaction data includes, among others, monitoring of transaction amounts, types of transactions, transaction frequency, and obstacles occurring in transactions according to monitoring period groups. Letter e This task is carried out so that the Bank's investment in the provision and development of Digital Banking Services contributes significantly to achieving the Bank's business objectives. Letter f It is clear enough. Letter g It is clear enough.
Article 10
Paragraph (1)
Letter a
Account administration includes, among others, account opening, updating customer data, to account closure, utilizing electronic media. Accounts can include, among others:
Article 11
Paragraph (1)
Letter a
Customer or prospective customer identification is carried out through requests for data and information as regulated in the Financial Services Authority's provisions regarding the implementation of anti-money laundering and counter-terrorism financing programs in the financial services sector. Letter b It is clear enough. Paragraph (2) Letter a Number 1) It is clear enough. Number 2) Examples of Bank-owned software and Bank-owned hardware used for face-to-face verification include devices such as ATMs located in the Bank's office network equipped with video banking applications connected directly in real-time online with Bank employees. Banks can utilize other Bank-owned software and hardware that can facilitate face-to-face interactions between customers or prospective customers and Bank employees in real-time online. Examples of Bank-owned software and customer or prospective customer-owned hardware used for face-to-face verification include Bank applications accessible via smartphones and/or tablet computers owned by customers or prospective customers, equipped with video banking facilities. Hardware owned by customers or prospective customers of the Bank is equipped with supporting verification features such as cameras and identity card scanners. Letter b Examples of Bank-owned software and hardware used for non-face-to-face verification include ATMs located in the Bank's office network equipped with applications having functions such as fingerprint scanners and identity card scanners. Examples of Bank-owned software and customer or prospective customer-owned hardware used for non-face-to-face verification include:
Article 12
Paragraph (1)
Competent institutions or agencies include, among others, the Ministry of Home Affairs, Ministry of Law and Human Rights, Ministry of Finance, Ministry of Communication and Informatics, Ministry of Education and Culture, Ministry of Social Affairs, and/or the Indonesian National Police. Examples of other sources are telecommunications companies and/or other data providers, whose data truthfulness can be accounted for. Paragraph (2) Supporting infrastructure in the utilization of data or information includes, among others, cooperation agreements and the availability of necessary hardware and software.
Article 13
Paragraph (1)
Letter a
The term "informational services" refers to services limited only to providing information to Bank customers without further interaction and not followed by the execution of financial transactions. Providing information to Bank customers includes, among others:
with customer needs and capabilities, before the customer executes the transaction.
The provision of information to Bank customers includes:
Letter c
The term "other services" refers to new service forms other than informative services and transactional services.
Paragraph (2)
The term "regulatory provisions" includes, among others, Laws regarding banking, Laws regarding Sharia banking, Laws regarding the capital market, and/or Laws regarding insurance.
Article 14
Examples of informative services that can be provided by Banks based on partnership agreements between the Bank and its partners, such as Financial Service Institutions (LJK), include:
Article 15
Paragraph (1)
Letter a
Example of providing transactional services with LJK:
Bank "P", which has obtained approval from the Financial Services Authority (OJK) to conduct bancassurance activities under a distribution cooperation business model.
Bank "P" offers life insurance products from insurance company PT "QRS" that match the customer's profile. If the customer is interested, Bank "P"'s customer can submit an application for the closure of a life insurance policy from PT "QRS" through Bank "P"'s application and/or website.
Letter b
Example of providing transactional services with non-LJK institutions:
Bank "C" conducts a credit analysis of the customer's application before granting approval for the credit application. Credits approved by Bank "C" are followed up with disbursement.
2. Bank "D" cooperates with PT "JKL" which provides a marketplace website.
Bank "D"'s application and/or website is connected to PT "JKL"'s website to present information on commercial products sold or consigned on PT "JKL"'s website to customers. The commercial product information presented to customers is personal information based on the Bank's analysis of the customer's shopping and payment behavior as well as the customer's financial position. If the customer is interested in making a purchase, Bank "D"'s application and/or website provides a payment facility.
Paragraph (2)
Clearly stated.
Paragraph (3)
The connection between the Bank's electronic systems and its partner Bank's electronic systems includes, among others, through Open Application Programming Interface (Open API).
Example of Open API usage:
The application and/or website of airline company PT "MNO" is connected to Bank "E"'s payment facility.
If Bank "E"'s customer wishes to make a plane ticket payment transaction, the customer can directly access the payment feature on PT "MNO"'s application and/or website, which is connected to the open API of Bank "E"'s application and/or website.
Paragraph (4)
Clearly stated.
Paragraph (5)
Clearly stated.
Article 16
Paragraph (1)
Letter a
Policies and procedures in determining Bank partners include, among others:
Letter b
Written cooperation agreements include, among others:
Paragraph (2)
Clearly stated.
Article 17
Paragraph (1)
Examples of risks arising from products and/or services offered by Bank partners related to Digital Banking Services, such as transactional services, include:
Paragraph (2)
Clearly stated.
Paragraph (3)
Clearly stated.
Article 18
Letter a
Risk profile rating assessments refer, among others, to Financial Services Authority (OJK) provisions regarding the assessment of the health level of General Banks or the assessment of the health level of General Sharia Banks and Sharia Business Units. The risk profile rating assessment used is the result of the assessment by the Financial Services Authority (OJK).
Letter b
Clearly stated.
Letter c
Financial Services Authority (OJK) provisions include, among others, provisions regarding business activities and office networks based on core bank capital, business activities of General Banks based on core capital, and/or products and activities of General Sharia Banks and Sharia Business Units.
Article 19
Paragraph (1)
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
Clearly stated.
Paragraph (4)
Clearly stated.
Paragraph (5)
Clearly stated.
Paragraph (6)
Clearly stated.
Paragraph (7)
Clearly stated.
Paragraph (8)
Clearly stated.
Paragraph (9)
Financial Services Authority (OJK) provisions include, among others:
a. implementation of risk management for General Banks; b. implementation of risk management for General Sharia Banks and Sharia Business Units;
c. implementation of risk management in the use of information technology by General Banks;
d. business activities and office networks based on core bank capital; e. implementation of anti-money laundering and counter-terrorism financing programs in the financial services sector; f. consumer protection in the financial services sector; g. implementation of risk management on banks conducting marketing cooperation activities with insurance companies (bancassurance); and/or h. digital lending services based on information technology.
Provisions for the implementation of Information Technology for Digital Banking Services conducted by the service provider of Information Technology (Bank and/or Information Technology service provider) refer to Financial Services Authority (OJK) provisions regarding the implementation of risk management in the use of information technology by General Banks.
Relevant authority provisions include, among others, regulatory provisions regarding the implementation of payment activities using cards.
Article 20
Clearly stated.
Article 21
Paragraph (1)
Consumer protection principles include:
a. transparency; b. fair treatment;
c. reliability;
d. confidentiality and security of consumer data/information; and e. handling of complaints and resolution of consumer disputes simply, quickly, and at an affordable cost.
Paragraph (2)
The function and mechanism for handling each customer inquiry and/or complaint can be facilitated through media such as telephone, email, and written documents.
Paragraph (3)
Clearly stated.
Article 22
Paragraph (1)
Clearly stated.
Paragraph (2)
Audit of Electronic Banking Services or Digital Banking Services includes, among others, audits of the Bank's applications and/or websites used in providing Electronic Banking Services or Digital Banking Services.
Article 23
Paragraph (1)
Clearly stated.
Paragraph (2)
The report in this paragraph related to the implementation of Electronic Banking Services is the same report as referred to in the Financial Services Authority (OJK) provisions regarding the implementation of risk management in the use of information technology by General Banks.
Article 24
Clearly stated.
Article 25
Clearly stated.
Article 26
Clearly stated.
Article 27
Clearly stated.
Article 28
Clearly stated.
Article 29
Clearly stated.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 6235
APPENDIX
FINANCIAL SERVICES AUTHORITY REGULATION
NUMBER 12 /POJK.03/2018
REGARDING
THE PROVISION OF DIGITAL BANKING SERVICES BY GENERAL BANKS
FORMAT OF REPORT ON THE PROVISION OF DIGITAL BANKING SERVICES BY GENERAL BANKS
TABLE OF CONTENTS
Appendix A APPLICATION FOR APPROVAL OF THE PROVISION OF ELECTRONIC BANKING SERVICES BY GENERAL BANKS
Appendix B REPORT ON THE IMPLEMENTATION OF ELECTRONIC BANKING SERVICES BY GENERAL BANKS
Appendix C APPLICATION FOR APPROVAL OF THE PROVISION OF DIGITAL BANKING SERVICES BY GENERAL BANKS
Appendix D REPORT ON THE IMPLEMENTATION OF DIGITAL BANKING SERVICES BY GENERAL BANKS
Appendix A
APPLICATION FOR APPROVAL
PROVISION OF ELECTRONIC BANKING SERVICES
BY GENERAL BANKS
Bank Name: ......................................
Bank Headquarters Address: ...............
Telephone Number: .................................
Reporter Name: ...................................
Reporter Office/Division/Department: ...........
Reporter Address: .................................
Telephone Number: .................................
Report Date: ...............................
Appendix A
APPLICATION FOR APPROVAL
PLAN FOR THE PROVISION OF ELECTRONIC BANKING SERVICES BY GENERAL BANKS *)
Appendix B
IMPLEMENTATION REPORT
PROVISION OF ELECTRONIC BANKING SERVICES
BY GENERAL BANKS
Bank Name: ......................................
Bank Headquarters Address: ...............
Telephone Number: .................................
Reporter Name: ...................................
Reporter Office/Division/Department: ..........
Reporter Address: .................................
Telephone Number: .................................
Report Date: ..............................
Appendix B
IMPLEMENTATION OF ELECTRONIC BANKING SERVICES
BY GENERAL BANKS
Appendix C
APPLICATION FOR APPROVAL
PROVISION OF DIGITAL BANKING SERVICES
BY GENERAL BANKS
Bank Name: ......................................
Bank Headquarters Address: ...............
Telephone Number: .................................
Reporter Name: ...................................
Reporter Office/Division/Department: ...........
Reporter Address: .................................
Telephone Number: .................................
Report Date: ...............................
Appendix C
APPLICATION FOR APPROVAL
PLAN FOR THE PROVISION OF DIGITAL BANKING SERVICES BY GENERAL BANKS *)
Appendix D
IMPLEMENTATION REPORT OF THE PROVISION OF DIGITAL BANKING SERVICES BY GENERAL BANKS
Bank Name: ......................................
Bank Headquarters Address: ...............
Telephone Number: .................................
Reporter Name: ...................................
Reporter Office/Division/Department: ..........
Reporter Address: .................................
Telephone Number: .................................
Report Date: ..............................
This copy is in accordance with the original
Legal Director 1
Legal Department signed
Yuliana
Appendix D
IMPLEMENTATION OF THE PROVISION OF DIGITAL BANKING SERVICES BY GENERAL BANKS
CHAIRMAN OF THE BOARD OF COMMISSIONERS
FINANCIAL SERVICES AUTHORITY, signed
WIMBOH SANTOSO
Read the rest free
Amended 1 time · last 2023-12-22
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works