2021-11-23 | NBB_2021_26Added · Updated
Payment institutions and electronic money institutions governed by Belgian law must submit an annual comprehensive assessment of operational and security risks related to their payment services, including inherent risk levels, mitigation measures, and residual risk. The report must also evaluate compliance with EBA Guidelines on ICT and security risk management and detail any developments since the previous submission or authorization. Institutions may satisfy this statutory obligation by completing standardized IT risk questionnaires and practical instructions made available annually by the National Bank of Belgium. This circular applies from 1 January 2022 and replaces circular NBB_2020_24.
ÊZËÎÆË'ÊÊÊÂËÊÆËË‘“‘“BE"°°°B'"“°'S n lBanqueNationaleBank Company number: 0203201340 DE BELGIQUE VAN BELGIË RPM (Trade Register) Brussels E u rosystem www.nbb.be C | rcu lar Brussels, 23 November 2021 Reference: NBB_2021_26 Contact person: Thomas Plomteux Phone +32 2 221 21 97 thomas.plomteux@nbb‚be Reporting on operational and security risks of payment services to be submitted by payment institutions and electronic money institutions Scope Payment institutions governed by Belgian law, registered payment institutions governed by Belgian law providing account aggregation services, limited payment institutions governed by Belgian law, electronic money institutions governed by Belgian law, limited electronic money institutions governed by Belgian law Summar IOb'ectives This circular establishes how payment institutions and electronic money institutions should comply with the reporting obligation imposed by Article 50, § 2 of the Law of 11 March 2018’. This circular applies from 1 January 2022 and replaces circular NBB_2020_24, which ceases to apply from that date. 1 The Law of 11 March 2018 on the legal status and supervision of payment institutions and electronic money institutions, access to the activity of payment service provider and the activity of issuing electronic money, and access to payment systems, Belgian Official Gazette of 26 March 2018 (hereinafter referred to as “the Law of 11 March 2018"). NBB_2021_26 — 2311 2021 Circular— Page 1/3
m Dear Sir, Dear Madam, Through this circular, the National Bank of Belgium (hereinafter referred to as “the Bank”) aims to clarify the reporting obligation imposed by Article 50, § 2 of the Law of 11 March 2018. Article 50, § 2 of the Law of 11 March 2018 requires institutions to submit a reporting to the supervisory authority consisting of an updated and comprehensive assessment of the operational and security risks relating to the payment services provided by the institution and of the adequacy of the mitigation measures and control mechanisms implemented in response to those risks. With this circular, the Bank wishes to clarify its expectations regarding the report to be submitted annually by the payment institutions governed by Belgian law, the registered payment institutions governed by Belgian law providing account information services, the limited payment institutions governed by Belgian law, the electronic money institutions governed by Belgian law and the limited electronic money institutions governed by Belgian law. These institutions should submit a detailed and reasoned assessment of the operational and security risks of both the payment services already offered and the payment services expected to be offered within the next year. This means that:
rfl In order to ensure a sufficiently high quality of this reporting and to help institutions as much as possible to fulfil their reporting obligation, the Bank will annually make standardised IT risk questionnaires and practical instructions available to the institutions falling under the scope of application of this circular. These questionnaires will more specifically focus on the inherent exposure of these institutions to a number of lCT risk categories3 and on the corresponding mitigation measures and controls in a number of ICT risk control areas4. Moreover, in the light of the principle of proportionality, these questionnaires may differ from institution to institution, for example depending on the size and internal organisation of the institution concerned or on the nature, scale, complexity and riskiness of the services and products that it provides or intends to provide. Institutions are expected to complete these questionnaires annually in a sufficiently comprehensive and critical manner. In that case, and if the institution responds adequately to any requests for additional information and/or documentation, the Bank will consider the completion of this questionnaire sufficient to comply with the statutory reporting requirement. This circular applies from 1 January 2022. A copy of this circular will be sent to your institution's accredited statutory auditor(s). Yours faithfully, gfvzryolrlnSCh n Vanackere Vice-governor 3 The following are some of the categories that may be concerned: ICT availability and continuity risk. ICT security risk, ICT change risk, lCT data integrity risk and lCT outsourcing risk. 4 The following are some of the areas that may be concerned: ICT governance, ICT organisation and ICT outsourcing, ICT risk management, ICT security management, management of ICT operations, software acquisition and development and project management, data quality management, ICT continuity management, ICT reporting and internal ICT audit. NBB_2021_26 — 2311 2021 Circular - Page 3I3