[pic]
BOARD OF THE BANK OF LITHUANIA
RESOLUTION
ON THE AMENDMENT OF RESOLUTION NO 03-10 OF THE BOARD OF THE BANK OF LITHUANIA OF 21 JANUARY 2019 ON THE APPROVAL OF THE RULES REGARDING OPERATIONAL OR SECURITY INCIDENT REPORTING TO THE BANK OF LITHUANIA AND OF NOTIFICATION TEMPLATES
21 December 2021 No 03-215
Vilnius
The Board of the Bank of Lithuania has r e s o l v e d:
- To amend Resolution No 03-10 of the Board of the Bank of Lithuania of 21 January 2019 on the Approval of the Rules Regarding Operational or Security Incident Reporting to the Bank of Lithuania and of Notification Templates to read as follows:
“BOARD OF THE BANK OF LITHUANIA
RESOLUTION
ON HE APPROVAL OF THE RULES REGARDING OPERATIONAL OR SECURITY INCIDENT REPORTING TO THE BANK OF LITHUANIA AND OF NOTIFICATION TEMPLATES
Acting pursuant to Article 42(4)(1) of the Republic of Lithuania Law on the Bank of Lithuania, Article 10(4), Article 33(8), Article 38(4) and Article 57(5) of the Republic of Lithuania Law on Payments the Board of the Bank of Lithuania has r e s o l v e d:
To approve the following (attached):
1. Rules Regarding Operational or Security Incident Reporting to the Bank of Lithuania;
2. Notification template on major payment service provision-related operational or security incidents (OPRISK-MOSRI);
3. Notification template on major payment service provision-unrelated operational or security incidents (OPRISK-OSRI);
4. Notification template on the decision to decline to open a payment account, limit access to the account or close it (REJECT);
5. Notification template on the suspected fraudulent activities of the payer (FRAUD);
6. Notification template on limiting access for an account information service provider or a payment initiation service provider to a payment account (BLOCK).”
2. To establish that this Resolution shall enter into force on 1 April 2022.
Deputy Chairman of the Board
deputising for the Chairman of the Board Raimondas Kuodis
APPROVED
by Resolution No 03-10
of the Board of the Bank of Lithuania of 21 January 2019
(version of Resolution No 03-215
of the Board of the Bank of Lithuania
of 21 December 2021)
RULES REGARDING OPERATIONAL OR SECURITY INCIDENT REPORTING TO THE BANK OF LITHUANIA
CHAPTER I
GENERAL PROVISIONS
- The Rules Regarding Operational or Security Incident Reporting to the Bank of Lithuania (hereinafter – the Rules) specify the main criteria for the classification of major payment service provision-related and payment service provision-unrelated operational or security incidents, the procedure for reporting such incidents to the Bank of Lithuania as well as requirements for the content of such reports. The Rules also lay down the procedure for submitting notifications to the Bank of Lithuania on the decision to decline to open a payment account to an electronic money or payment institution, to limit access to such an account or to close it, notifications on the suspected fraudulent activities of the payer and on limiting access for an account information service provider or a payment initiation service provider to a payment account.
2. The Rules shall apply (excluding paragraph 6 and Chapter IV) to payment service providers (PSPs) that provide payment services under the Republic of Lithuania Law on Payments (hereinafter – the Law on Payments). Paragraph 6 and Chapter IV shall additionally apply to banks established in the Republic of Lithuania, foreign bank branches, including those of EU Member States, and central credit unions (hereinafter – the credit institution).
3. The Rules are drawn up with regard to Guidelines EBA/GL/2021/03 of the European Banking Authority of 10 June 2021 on major incident reporting under PSD2 and the Law on Payments.
4. Definitions:
4.1. payment service provision-unrelated operational or security incident (payment service provision-unrelated incident) means a singular event or a series of linked events unrelated to the provision of payment services and unplanned by the credit institution which have or are likely to have an adverse impact on its operating results resulting from inadequate or failed internal processes, people and systems or from external events;
4.2. payment service provision-related operational or security incident (payment service provision-related incident) means a singular event or a series of linked events unplanned by the PSP which has or are likely to have an adverse impact on the integrity, availability, confidentiality and/or authenticity of payment-related services;
4.3. payment-related services means payment services indicated in Article 5 of the Law on Payments and all the necessary technical supporting tasks for the correct provision of payment services;
4.4. other terms used in the Rules shall be understood as defined in the Law on Payments.
CHAPTER II
CONTENT OF INFORMATION PROVIDED
- PSPs shall submit to the Bank of Lithuania the following:
5.1. information on major payment service provision-related incidents. Information on such payment service provision-related incidents shall be provided when the incident fulfils 1 (one) or more criteria at the higher impact level, or 3 (three) or more criteria at the lower impact level, as specified in Annex to the Rules. Payment service provision-related incidents of a central credit union shall be assessed and reported to the Bank of Lithuania at the level of the entire consolidated group, irrespective of whether the payment service provision-related incident occurred in the central credit union or in an individual credit union belonging to the central credit union;
5.2. information on the suspected fraudulent activities of a payment service user;
5.3. information on limiting access for an account information service (AIS) provider or payment initiation service (PIS) provider to a payment account.
6. Credit institutions shall additionally provide to the Bank of Lithuania the following:
6.1. information on major payment service provision-unrelated incidents that are unrelated to payment service provision failures. Information on such payment service provision-unrelated incidents when a crisis business continuity plan is triggered or a high level of internal escalation is identified with regard to the payment service provision-unrelated incident;
6.2. notifications on the decision to decline to open payment accounts indicated in Article 17(1)(1) of the Republic of Lithuania Law on Payment Institutions and Article 25(1)(1) of the Republic of Lithuania Law on Electronic Money and Electronic Money Institutions, as well as other payment accounts of electronic money or payment institutions intended for payment operations of electronic money holders or payment service users; also notifications on the decision to limit access to such accounts or close them. Such information shall be provided to the Bank of Lithuania within 5 business days of taking such a decision by completing the template REJECT and also attaching additional information, should it be relevant or important.
CHAPTER III
PROCEDURE FOR DETECTING AND REPORTING MAJOR PAYMENT SERVICE PROVISION-RELATED INCIDENTS
- When assessing how the payment service provision-related incident affected the integrity, availability, confidentiality and/or authenticity of payment-related services, and whether the incident should be reported to the Bank of Lithuania, PSPs shall assess the following criteria:
7.1. Transactions affected. PSPs shall consider as affected transactions all transactions that have been or are likely to be directly or indirectly affected by a payment service provision-related incident (transactions that could not be initiated, processed, the content of which has been altered, that have been fraudulently instructed to be processed, or where the payment service provision-related incident prevents or otherwise interferes with the correct execution of the transaction). PSPs shall determine the total value of the transactions affected, as well as the number of payments compromised as a percentage of the regular level of payment transactions carried out with the affected payment services. The regular level of payment transactions shall be the daily annual average of PSPs’ domestic and cross-border payment transactions that have been affected by the incident, taking the previous year as the reference period for calculations. If this figure is not considered to be representative (e.g. because of seasonality), another, more representative, metric shall be used instead and the underlying rationale for this approach shall be conveyed to the Bank of Lithuania when submitting reports;
7.2. Payment service users affected. PSPs shall determine the number of payment service users affected, i.e. users that suffered or are likely to suffer the implications of a payment service provision-related incident, both in absolute terms and as a percentage of the total number of payment service users. PSPs shall take as the total number of payment service users the aggregated figure of domestic and cross-border payment service users contractually bound to them at the time of the payment service provision-related incident (or, alternatively, the most recent figure available) and with access to the affected payment service, regardless if they are considered active or passive payment service users. Each PSP shall consider only its own payment service users. In the case of the provision of operational services to other PSPs, a PSP must consider only its own payment service users (if any), and the PSPs receiving those operational services should assess the payment service provision-related incident in relation to their own payment service users;
7.3. Service downtime. PSPs shall consider the period of time that any task, process or channel related to the provision of payment services is down or is likely to be down and, thus, prevents the initiation and/or execution of a payment service and/or access to a payment account. PSPs shall count the service downtime from the moment the downtime starts, and they shall consider both the time intervals when they are open for business as required for the execution of payment services as well as the closing hours and maintenance periods, where relevant and applicable. If PSPs are unable to determine when the service downtime started, they shall exceptionally count the service downtime from the moment the downtime is detected;
7.4. Other PSPs or relevant infrastructures potentially affected. PSPs shall determine the systemic implications a payment service provision-related incident, i.e. its potential to spill over beyond the initially affected PSP to other PSPs, financial market infrastructures and/or card payment schemes. PSPs shall assess whether or not the payment service provision-related incident has been or is likely to be replicated at other PSPs, whether or not it has affected or is likely to affect the smooth functioning of financial market infrastructures and whether or not it has compromised or is likely to compromise the sound operation of the financial system as a whole;
7.5. Reputational impact. PSPs shall determine how the payment service provision-related incident can undermine users’ trust in the PSP itself and the underlying service or the market as a whole. PSPs shall consider the level of visibility that the payment service provision-related incident has gained or is likely to gain in the marketplace or its impact on society and the likelihood that it will receive or has already received media coverage. PSPs shall also consider whether there has been or is likely to be non-compliance with laws and regulations, contractual obligations that may give rise to legal action, and whether similar payment service provision-related incidents have occurred in the past;
7.6. Economic impact. PSPs shall consider both the costs and losses that can be connected to the payment service provision-related incident directly and those which are indirectly related to it. Among other things, PSPs shall take into account expropriated funds or assets, replacement costs of hardware or software, other court fees or remediation costs, fees due to non-compliance with contractual obligations, sanctions, external liabilities and loss of income. As regards the indirect costs, PSPs shall consider only those that are already known or likely to materialise;
7.7. High level of internal escalation. PSPs shall consider whether or not their manager or other member of the management body responsible for operational or security incidents has been or is likely to be informed about the payment service provision-related incident and whether or not, as a result of the impact of the incident, a crisis mode has been or is likely to be triggered according to a business continuity plan;
7.8. breach of the security of networks or information systems. PSPs shall assess whether any malicious activity has compromised the availability, authenticity, integrity or confidentiality of the network or information systems (including data) related to the provision of payment services.
8. The PSP shall assess the payment service provision-related incident within 24 hours of the detection of the incident and determine the level of exposure to the incident in accordance with the criteria assessment thresholds given in the table in the Annex to the Rules.
9. PSPs shall resort to estimations if they do not have actual data to support their judgements of whether or not a given threshold is or is likely to be reached before the major payment service provision-related incident is resolved.
10. PSPs shall carry out the assessment set out in paragraph 7 of the Rules on a continuous basis during the lifetime of the payment service provision-related incident, to identify any possible status change, either upwards (from non-major to major) or downwards (from major to non-major).
11. Having identified a major payment service provision-related incident, PSPs shall provide to the Bank of Lithuania information indicated in the template OPRISK-MOSRI.
12. PSPs shall provide information to the Bank of Lithuania on a continuous basis during the lifetime of a major payment service provision-related incident by providing the OPRISK-MOSRI general part, initial (A), intermediate (B) and final (C) reports.
13. PSPs shall provide all additional information to the Bank of Lithuania if it is relevant and important, attaching one or several annexes with additional documents to the template OPRISK-MOSRI.
14. Submission of initial reports on a major payment service provision-related incident:
14.1. PSPs must send the initial report to the Bank of Lithuania during its working hours and within 4 hours from the moment the major payment service provision-related incident was first detected or when the deadline for initial report on a major payment service provision-related incident expires outside of working hours of the Bank of Lithuania – on the next day within the first working hour of the Bank of Lithuania;
14.2. The Bank of Lithuania will assign a unique code to the initial report to identify the payment service provision-related incident, which will have to be used by the PSP in all subsequent notifications related to the same incident;
14.3. the initial report must also be submitted when a previously non-major payment service provision-related incident becomes a major one. In this case, immediately after the change of status of the incident is identified, PSPs shall send the initial report to the Bank of Lithuania during its working hours and within 4 hours or when the deadline for submitting initial report on a major payment service provision-related incident expires outside of working hours of the Bank of Lithuania – on the next day within the first working hour of the Bank of Lithuania;
14.4. PSPs shall include headline-level information in their initial reports, thus featuring some basic characteristics of the payment service provision-related incident and its expected implications based on the information available immediately after it was detected or reclassified. PSPs shall resort to estimations when actual data are not available. Also, in the initial report, the PSP shall explain the reasons if it took more than 24 hours to determine the level of exposure to the payment service provision-related incident.
15. Submission of intermediate reports:
15.1. the first intermediate report with a more detailed description of the payment service provision-related incident and its implications shall be submitted after the resumption of normal operations and return to business as usual. The PSP shall consider a return to business as usual to be the point at which activities and/or operations are restored to the same level of service and/or conditions as defined by the PSP or set out in contractual obligations, i.e. to the appropriate processing time, capacity, security requirements, etc., and contingency measures are no longer in place;
15.2. if normal operations cannot be resumed, the PSP shall submit an intermediate report within three working days from the date of submission of the initial report to the Bank of Lithuania, and shall continue to submit intermediate reports at a frequency of three working days until the business is back to normal;
15.3. an additional intermediate report shall be delivered at the request of the Bank of Lithuania;
15.4. as in the case of initial reports, when actual data are not available PSPs shall make use of estimations;
15.5. should business be back to normal before 4 hours have passed since the payment service provision-related incident was detected, PSPs shall submit both the initial and the intermediate report simultaneously by the 4-hour deadline.
16. Submission of final reports:
16.1. the final report shall be sent when the root cause analysis of the payment service provision-related incident has taken place (regardless of whether or not mitigation measures have already been implemented or the final root cause has been identified) and there are actual figures available to replace any estimates;
16.2. the final report shall be delivered within a maximum of 20 days after business is deemed back to normal. PSPs needing an extension of this deadline (e.g. if there are no actual figures on the impact available yet) shall contact the Bank of Lithuania before it has lapsed and provide an adequate justification for the delay, as well as a new estimated date for the final report;
16.3. Should PSP be able to provide all the information required in the final report within the 4-hour window since the recognition of the payment service provision-related incident as major, it should aim to submit in its initial report the information related to initial, last intermediate and final reports;
16.4. the final report shall include full information, i.e. actual figures on the impact instead of estimations, updated initial and intermediate reports and the final report, which includes the root cause of the payment service provision-related incident, if already known, and a summary of measures adopted or planned to be adopted to remove the problem and prevent its recurrence in the future;
16.5. the final report shall also be sent when it is identified that an already reported payment service provision-related incident no longer fulfils the criteria to be considered major and is not expected to fulfil them before it is resolved. In this case, PSPs shall send the general part of the template OPRISK-MOSRI indicating the change in the status of the incident and section C explaining the reasons for downgrading as soon as this circumstance is detected.
CHAPTER IV
PROCEDURE FOR DETECTING AND REPORTING MAJOR PAYMENT SERVICE PROVISION-UNRELATED INCIDENTS
- A credit institution shall consider a given payment service provision-unrelated incident as major in the following cases:
17.1. where the impact of the payment service provision-unrelated incident has or will trigger the crisis business continuity plan;
17.2. having identified a high level of internal escalation of the payment service provision-unrelated incident, i.e. where the incident has been or is likely to be communicated to the head of the credit institution.
18. Having identified a major payment service provision-unrelated incident, the credit institution shall provide to the Bank of Lithuania information indicated in the template OPRISK-OSRI.
19. The credit institution shall provide information to the Bank of Lithuania on a continuous basis during the lifetime of a major payment service provision-unrelated incident by providing the OPRISK-MOSRI general part, initial (A), intermediate (B) and final (C) reports.
20. The credit institution shall provide all additional information to the Bank of Lithuania, where relevant and important, by attaching one or several annexes with additional documents to the template OPRISK-OSRI.
21. The credit institution shall submit information specified in paragraph 19 in accordance with the procedure laid down in paragraphs 14-16 of the Rules.
CHAPTER V
DELEGATED AND CONSOLIDATED REPORTING
- PSPs wishing to delegate reporting on the payment service provision-related incident to a third party shall ensure that the following conditions are met:
22.1. the formal contract between a PSP and a third party or existing internal agreements within a group (between a PSP and a company which belong to the same group as the PSP) shall unambiguously define the allocation of responsibilities of all parties, clearly stating that, irrespective of the possible delegation of reporting obligations, the affected PSP remains fully responsible and accountable for the content of the incident reports;
22.2. delegation of reporting obligations is considered outsourcing of important operational functions to a third party, thus, delegation must comply with the requirements of the legal acts regulating such functions;
22.3. the confidentiality of sensitive data and the quality, consistency, integrity and reliability of the information to be provided to the Bank of Lithuania is properly ensured.
23. PSPs wishing to allow the designated third party to fulfil the reporting obligations in a consolidated way (i.e. by presenting one single report referred to several PSPs affected by the same major incident) shall inform the Bank of Lithuania, complete section ‘Affected PSPs’ of the template OPRISK-MOSRI and ensure that the following conditions are met:
23.1. include the provision regarding consolidated reporting in the contract underpinning the delegated reporting;
23.2. make the consolidated reporting conditional on the incident’s being caused by a disruption in the services provided by the third party;
23.3. confine the consolidated reporting to PSPs established in the Republic of Lithuania;
23.4. ensure that the third party assesses the materiality of the incident for each affected PSP and includes in the consolidated report only those PSPs for which the payment service provision-related incident is classified as major, and that, in case of doubt, a PSP is included in the consolidated report as long as there is no evidence that it should not;
23.5. ensure that, when there are fields of the template OPRISK-MOSRI where a common answer is not possible, the third party either fills them out individually for each affected PSP, or uses ranges, in those fields where this is an option, representing the lowest and highest values as observed or estimated for the different PSPs;
23.6. PSPs shall ensure that the third party keeps them informed at all times of all the relevant information regarding the incident and all the interactions that the third party may have with the Bank of Lithuania and of the contents thereof, but only as far as is compatible with avoiding any breach of confidentiality as regards the information that relates to other PSPs;
23.7. ensure that the Bank of Lithuania is provided with a list of all PSPs affected by the payment service provision-related incident.
24. PSPs wishing to withdraw the delegation of their reporting obligations shall communicate this decision to the Bank of Lithuania at least 5 business days in advance. PSPs shall also inform the Bank of Lithuania of any material development affecting the designated third party and its ability to fulfil the reporting obligations.
25. PSPs shall materially complete their reporting obligations without any recourse to external assistance whenever the designated third party fails to inform the Bank of Lithuania of an incident in accordance with the Rules. PSPs shall ensure that an incident is not reported twice, individually by the said PSP and once again by the third party.
26. PSPs shall ensure that, in the case of an incident caused by a failure of the services (or infrastructure) provided by a technical service provider affecting a large number of PSPs, the delegated reporting relates to the individual PSP’s data (with the exception of consolidation reporting).
CHAPTER VI
OTHER INFORMATION PROVIDED BY PSPs
- Having justified reasons to suspect that the payer carries out fraudulent activities, the PSP shall immediately, but no later than within the term indicated in Article 38(1) of the Law on Payments, during which they must return to the payer the unauthorised transaction amount(s) and, when applicable, restore the balance of the payment account from which the amount was transferred, inform the payer on refusal to return the transaction amount in an agreed manner; it shall also inform the Bank of Lithuania by completing the template FRAUD.
28. According to paragraph 27 of the Rules, the PSP can submit to the Bank of Lithuania one consolidated report on several unauthorised transaction amounts that were not returned if the following conditions are met:
28.1. the payer and payee of these transaction amounts is the same;
28.2. the PSP finds out or is notified of the unauthorised transactions on the same day or subsequent days;
28.3. if one consolidated report for all of these transactions is submitted within the time limit indicated in paragraph 27 of the Rules (each reported transaction must be assessed separately).
29. Having declined to grant access to the payment account(s) for a PIS provider or a AIS provider, the PSP shall inform the payer in an agreed manner, and the Bank of Lithuania – by completing the template BLOCK, in accordance with the procedures laid down Articles 33(5) and (7) of the Law on Payments.
30. The PSP shall remove the limitation for a PIS provider or a AIS provider to access the payment account when there are no more reasons to restrict such access and shall immediately inform the Bank of Lithuania. If payment account access limitations for a PIS provider or a AIS provider are not lifted in 10 business days, the PSP shall no later than the next business day additionally inform the Bank of Lithuania on additional details regarding limited access (e.g. if new facts have come to light, reasons for continued limiting of access, actions that have to be carried out by the PIS provider, AIS provider or the payer so as to restore full access, initiated pre-trial investigations, etc.).
31. Submission of reports indicated in paragraphs 27 and 29 of the Rules to the Bank of Lithuania shall not exclude the PSP from the obligation to report any reasonable suspicions regarding any criminal and/or other illegal actions of a payment service user, PIS provider or AIS provider, should any arise, to competent law enforcement authorities.
32. The PSP shall carry out an in-depth internal investigation to ascertain all circumstances indicated in paragraph 27 of the Rules under which the PSP declined to return to the payer the unauthorised transaction amount(s), and other related information. The internal investigation must not last longer than 15 business days after the day the circumstances indicated in paragraph 27 of the Rules became known. The PSP shall immediately inform the payer and the Bank of Lithuania of the results of the internal investigation and the PSP’s further actions.
33. Where, by reason of force majeure, a PSP cannot conclude the internal investigation within the time period indicated in paragraph 32 of the Rules, it shall inform the payer of a period within which the investigation will be concluded and the reasons for extending the investigation, except in cases, when revealing such reasons would undermine security measures or when it is prohibited under legal acts. The PSP shall also inform the Bank of Lithuania about extending the internal investigation. The internal investigation must never exceed 35 business days, when investigation was conducted with regard to card transactions – 120 days from the day the circumstances indicated in paragraph 27 of the Rules became known, but only when involvement of the international payment card association is necessary to conduct the internal investigation and the internal investigation cannot be concluded earlier due to circumstances surrounding such involvement.
34. If the PSP, under paragraph 31 of the Rules, applies to law enforcement authorities which, in accordance with the procedure set out by legal acts, initiate a pre-trial investigation, the internal investigation terms indicated in paragraphs 32 and 33 of the Rules shall no longer apply.
35. If during an internal investigation it becomes known that the PSP’s suspicions about the payer’s fraudulent activities were unfounded, or when the grounds for halting the return to the payer of the unauthorised transaction amount(s) become no longer applicable due to other reasons (e.g. law enforcement authorities establish that the actions of the payer cannot be deemed as fraudulent), the PSP shall immediately return to the payer the unauthorised transaction amount(s), the return of which was halted based on the grounds indicated in Article 38(1) of the Law on Payments.
CHAPTER VII
FINAL PROVISIONS
- The head of administration of a PSP or a credit institution shall be responsible for submitting information to the Bank of Lithuania in accordance with the time limits and procedures laid down in the Rules.
37. The head of administration of a PSP or a credit institution shall ensure that the PSP’s or credit institution’s internal rules clearly outline the obligation to report payment service provision-related incidents or payment service provision-unrelated incidents and that all processes regarding reporting requirements set out in the Rules are implemented.
38. The PSP or the credit institution shall submit the documents referred to in the Rules to the Bank of Lithuania via the Bank of Lithuania’s online system (the Reporting Module).
Annex
to the Rules Regarding Operational or Security Incident
Reporting to the Bank of Lithuania
| |Major payment service provision-related operational or security incident |
|Impact level |Lower impact level |Higher impact level |
|Number of criteria |3 and > |1 and > |
|Criteria | | |
|1. Transactions affected |> 10% of the payment service provider’s|> 25% of the payment service provider’s|
| |regular level of transactions (in terms|regular level of transactions (in terms|
| |of number of transactions) |of number of transactions) |
| |and | |
| |duration of a payment service | |
| |provision-related incident > 1 hour[1] | |
| |or |or |
| |> €500,000 |> €15 million |
| |and | |
| |duration of a payment service | |
| |provision-related incident > 1 hour | |
|2. Payment service users affected |> 5,000 |> 50,000 |
| |and | |
| |duration of a payment service | |
| |provision-related incident > 1 hour | |
| |or |or |
| |> 10% of the payment service provider’s|> 25% of the payment service provider’s|
| |payment service users |payment service users |
| |and | |
| |duration of a payment service | |
| |provision-related incident > 1 hour | |
|3. Service downtime |> 2 hours |N/A |
|4. Other payment service providers or relevant |Yes |N/A |
|infrastructures potentially affected | | |
|5. Reputational impact |Yes |N/A |
|6. Economic impact |N/A |> Max (0.1% Tier 1 capital[2], |
| | |€200,000) |
| | |or |
| | |> €5 million |
|7. High level of internal escalation |Yes |Yes, and a crisis mode (or equivalent) |
| | |is likely to be called upon |
|8. Breach of the security of networks and information |Yes |N/A |
|systems | | |
Template REJECT approved
by Resolution No 03-10
of the Board of the Bank of Lithuania
of 21 January 2019
(version of Resolution No 03-215
of the Board of the Bank of Lithuania
of 21 December 2021)
(name of the credit institution)
(code, address, phone, email)
NOTIFICATION ON THE DECISION TO DECLINE TO OPEN A PAYMENT ACCOUNT, LIMIT ACCESS TO THE ACCOUNT OR CLOSE IT
(date)
|1. |Name of the payment or electronic money institution (PSP) | |
|2. |Country code | |
|3. |Date of decision adoption | |
|4. |Account type |
|4.1. |Separate (client funds) account |YES/NO |
|4.2. |Payment account for making payment transactions on behalf of electronic |YES/NO |
| |money and/or payment service users | |
|5. |In case of closing an account or limiting access to it |
|5.1. |Date of the notification to the PSP of the decision taken |DD/MM/YYYY |
|5.2. |Time period granted to submit the notification before taking the | |
| |decision | |
|6. |In case of taking a decision to decline to open a payment account or grant access to it |
|6.1. |PSP was notified on decision taken to decline to open an account or |YES/NO |
| |grant access to it | |
|6.2. |If yes, please indicate date of notification |DD/MM/YYYY |
|6.3. |If no, please provide a reason for not notifying | |
|7. |Brief description of reasons for taking the decision to close an | |
| |account/limit access to it or refusal to open an account/grant access | |
|8. |Brief process description (e.g. the person(s) responsible for decision | |
| |making, all terms and procedures applied during the decision-making | |
| |process) | |
|9. |PSP was notified about the motivation behind the decision |YES/NO |
|10. |The PSP was given an opportunity to acknowledge the decision made by the|YES/NO |
| |credit institution, or to remove operational shortcomings before the | |
| |credit institution took the decision | |
|11. |If no, please indicate why such opportunity was not provided | |
Template FRAUD approved
by Resolution No 03-10
of the Board of the Bank of Lithuania
of 21 January 2019
(version of Resolution No 03-215
of the Board of the Bank of Lithuania
of 21 December 2021)
NOTIFICATION ON THE SUSPECTED FRAUDULENT ACTIVITIES OF THE PAYER
Payment service provider suspecting fraudulent activities
|1. Name | |4. E-mail of the contact person | |
|2. Address | |5. Phone of the contact person | |
|3. Contact person | |
Description of suspected fraudulent activities
|6. Information on the payer |Natural person |Legal person |
| |First name | |Name | |
| |Surname | |Legal entity number | |
|7. Information on the payment transaction |Payment account number | |
| |Date of the payment transaction | |
| |Amount of the payment transaction | |
| |Currency of the payment transaction | |
| |Date of receipt of the notification on the | |
| |unauthorised payment transaction | |
| |Date of notifying the payer of the refusal to | |
| |return the unauthorised transaction amount | |
| |Account number of the payee | |
|8. Short description of suspected fraud and |(please provide a brief description of suspected payer fraud, and circumstances leading to |
|circumstances leading to suspicion about the |suspicion that the payment service user carries out fraudulent activities) |
|payer’s fraudulent activities | |
|9. Additional information |(please provide other information deemed relevant) |
Template BLOCK approved
by Resolution No 03-10
of the Board of the Bank of Lithuania
of 21 January 2019
(version of Resolution No 03-215
of the Board of the Bank of Lithuania
of 21 December 2021)
NOTIFICATION ON LIMITING ACCESS FOR AN ACCOUNT INFORMATION SERVICE PROVIDER OR A PAYMENT INITIATION SERVICE PROVIDER TO A PAYMENT ACCOUNT
Information on the account servicing payment service provider (ASPSP)
|1. Name | |4. E-mail of the contact person | |
|2. Address | |5. Phone of the contact person | |
|3. Contact person | |
Description of the payment service provider’s limited access to a payment account
|6. Information on the payment service |Account information service provider |Payment initiation service provider |
|provider with limited access to an | | |
|account(s) | | |
| |Name of the payment service provider | |
| |Legal entity number | |
|7. Information on the payment service |Natural person |Legal person |
|user | | |
| |First name | |Name | |
| |Surname | |Legal entity number | |
|8. Information on limited access to the |Account number(s) of the payment service user | |
|payment account(s) | | |
| |Date from which the access was limited | |
| |Amount and currency of the payment transaction(s) not executed due to limited access| |
| |(not to be completed if the account information service was initiated) | |
|9. Reason for limiting the payment |Unauthorised access by the payment service provider |Illegal access by the payment service |
|service provider’s access to the payment | |provider |
|account(s) | | |
| |Unauthorised initiation of a payment transaction |Illegal initiation of a payment transaction |
| |Other (please provide a brief description) |
| | |
|10. Description of circumstances leading to suspicion about the PSP’s unauthorised| |
|or illegal access to the payment account(s), including unauthorised or illegal | |
|initiation of a payment transaction, fraud. | |
[1] In the Annex to the Rules, the threshold related to the duration of an incident exceeding one hour applies only to operational incidents affecting the ability of the PSP to initiate and/or process transactions.
[2] Tier 1 capital as defined in Article 25 of Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requ[pic][3]!"#-.OPRSV‚Š? % * - / 0 3 4 ; irements for credit institutions and investment firms and amending Regulation (EU) No 648/2012.