2019-04-04

Added · Updated

Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators in the Arab Republic of Egypt

The Central Bank of Egypt establishes minimum rules for banks interacting with Payment Aggregators and Electronic Payment Facilitators, requiring board approval of risk strategies, due diligence, and specific contractual clauses including non-disclosure and audit rights. Banks must implement internal controls, daily transaction monitoring, and emergency plans, while prohibiting engagement with specific high-risk activities such as virtual currencies, pyramid schemes, and gambling. The regulations mandate adherence to anti-money laundering laws, information security policies, and the maintenance of bank guarantees equivalent to three days of collected funds.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators Inside the Arab Republic of Egypt Aggregator Payment Technical Facilitators Payment &

Contents Introduction Definitions 1 - Scope of the Rules 2 - Responsibilities and Obligations of the Board of Directors and Senior Management 3 - Risks Associated with Provided Services 4 - Anti-Money Laundering and Counter-Terrorism Financing Rules and Information Security 5 - Preparation of Information Security Policy 6 - General Rules for Banks to Use Technology Service Providers and Payment Facilitators 7 - Confidentiality and Integrity of Information 8 - Monitoring Abnormal Activities 9 - Awareness of Subsidiary Companies 10 - Procedures for Obtaining a License to Provide the Service

4 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators

Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 5 Introduction These rules were prepared due to the rapid development in the collection and payment of bills and services, and the need for the existence of Payment Technology Service Providers (Aggregator Payment) as well as Electronic Payment Process Facilitators (Facilitator Payment). The ability of these companies to provide financial and technological services to many merchants and companies, and to provide appropriate contractual methods, helps in providing and spreading electronic collection services through various distribution channels. This has a significant impact on increasing the acceptance of electronic payment methods among these categories of companies and merchants, ensuring tangible steps in the field of electronic payments in a secure manner for all parties participating in the electronic collection process.

6 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators

Payment Aggregator Technical It is a company with financial solvency that provides technological services to its subsidiary companies on behalf of the bank through the electronic distribution channels of the service providers, including providing electronic collection services for the value of bills/services provided. Its roles include, but are not limited to:

  • Creating a technological platform to collect bill/service values for subsidiary companies and linking them to electronic collection services.
  • Providing the bank with data of the subsidiary companies to be registered with it.
  • Providing the contractual method with the subsidiary company according to the bank's requirements.
  • Providing the necessary technical support for the subsidiary companies on behalf of the bank.
  • Providing the necessary awareness to the subsidiary companies regarding the financial services it will provide on behalf of the bank.
  • Providing all necessary reports for the subsidiary companies regarding all operations executed through it.

Payment Facilitator It is a company with financial solvency that provides financial and technological services through the electronic distribution channels of the subsidiary companies contracted with it on behalf of the bank for electronic collection. Its roles include, but are not limited to:

  • Creating technological platforms for subsidiary companies and linking them to electronic collection services.
  • Creating intermediary systems that provide value-added services for subsidiary companies and linking them to electronic collection services.
  • Providing the bank with data of the subsidiary companies to be collected from.
  • Contracting with companies on behalf of the bank to provide electronic collection services.
  • Receiving financial settlements from the contracted bank on behalf of the registered companies.
  • Executing financial settlements for the registered companies on behalf of the bank.
  • Providing the necessary technical support for the registered companies on behalf of the bank.
  • Providing the necessary awareness to the registered companies regarding the financial services it will provide on behalf of the bank.
  • Providing all necessary reports for the registered companies regarding all financial operations executed through it.

Definitions

Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 7

Subsidiary Company for Payment Technology Service Providers These are companies that have a valid legal entity and contract with Payment Technology Service Providers and the bank (according to the mentioned contracting methods) to provide bill/service payment services for their customers through the electronic distribution channels of Payment Technology Service Providers. The subsidiary company must have:

  • A specific bank account for the subsidiary company to which collection is made and the value of paid bills/services is transferred.
  • A real headquarters inside the Arab Republic of Egypt.
  • Clear contact details (phone number inside the Arab Republic of Egypt / email).

Subsidiary Company for Electronic Payment Process Facilitators It is a company that has a valid legal entity and contracts with the Electronic Payment Process Facilitator to provide electronic payment services for its customers through its own channels, for example, but not limited to: the company's website, the company's mobile application, the company's specific branch, etc.

Electronic Distribution Channels These are the electronic channels that allow electronic collection from customers, including, but not limited to:

  • Electronic Point of Sale (POS).
  • Electronic collection through internet websites (E-Commerce).
  • Mobile Wallet.

8 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators

1 - Scope of the Rules

  • These rules and regulations are the minimum required for banks to deal with Payment Technology Service Providers and Electronic Payment Process Facilitators. All banks must not rely solely on this and must ensure taking all necessary measures regarding the management of risks associated with providing this type of banking service.
  • These rules regulate the use of Payment Technology Service Providers and Electronic Payment Process Facilitators only, without prejudice to the supervisory regulations for electronic banking operations previously issued by the Central Bank of Egypt, as well as the instructions and rules for implementing banking operations and anti-money laundering and counter-terrorism financing regulations issued by the Central Bank of Egypt, and the due diligence procedures issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.

Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 9

2 - Responsibilities and Obligations of the Board of Directors and Senior Management The Board of Directors assumes the responsibility of adopting the business strategy prepared by the Senior Management of the bank, as well as making a clear strategic decision regarding the bank's desire to deal with Payment Technology Service Providers or Electronic Payment Process Facilitators or not. Specifically, the Board of Directors must ensure the following:

  • The plans for relying on Payment Technology Service Providers and Electronic Payment Process Facilitators align with the bank's strategic objectives.
  • Analysis of the risks specific to those services.
  • Preparation of appropriate procedures to monitor and mitigate risks regarding identified risks.
  • Continuous review of the evaluation results of relying on Payment Technology Service Providers and Electronic Payment Process Facilitators according to defined plans and objectives.
  • Conducting periodic inspection operations on Payment Technology Service Providers and Electronic Payment Process Facilitators.
  • The bank must conduct necessary due diligence regarding the competence, infrastructure, and financial capacity of Payment Technology Service Providers and Electronic Payment Process Facilitators before entering into any agreements, and prepare a comprehensive and continuous mechanism for due diligence and supervision of Payment Technology Service Providers and Electronic Payment Process Facilitators, including, but not limited to:
    • Technical inspection.
    • Financial inspection.
    • Reputation inspection.
  • The bank must establish a risk policy specific to Payment Technology Service Providers and Electronic Payment Process Facilitators and study the risks associated with the following:
    • Refunds.
    • Fraud.
    • Disputes.
    • Bankruptcy.

10 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators

3 - Risks Associated with Provided Services Providing collection services through Payment Technology Service Providers and Electronic Payment Process Facilitators is accompanied by many risks and advantages at the same time. While these risks are not new to banks, providing collection services through them may increase risk levels in addition to creating new challenges for managing these risks. These risks include, but are not limited to:

3-1 Strategic Risks:

  • Consist of the decision to provide collection services through Payment Technology Service Providers and Electronic Payment Process Facilitators, the type of services provided, and choosing the appropriate time for providing them. This specifically refers to the economic viability of providing these services.

3-2 Operational Risks / Transaction Risks:

  • Consist of risks resulting from fraud, refunds, disputes, errors in executing transactions, or failure in the operation of the Payment Technology Service Provider or Electronic Payment Process Facilitator system or the bank's system, or other unexpected events that may lead to the bank's inability to provide services or expose the bank or its customers to financial losses. While risks exist in all products and services provided, the level of transaction risk is affected by the structure of banking procedures and transactions, including the types of services provided, the degree of process complexity, and the technological aids used.

3-3 Compliance Risks / Legal Risks:

  • These risks arise from the spread of collection services through Payment Technology Service Providers or Electronic Payment Process Facilitators and may include regulatory/legal challenges such as:
    • In light of banks' commitment to the Central Bank and Banking Authority Law and supervisory regulations and instructions, banks must put procedures and regulations to preserve data privacy and customer account confidentiality to manage increasing risks related to providing collection services through Payment Technology Service Providers and Electronic Payment Process Facilitators, as well as the legal responsibility of banks towards customers due to the possibility of data privacy breaches or other problems caused by hacking, fraud, or other technological failures, and working to protect these data from misuse.

Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 11

  • Banks providing collection services through Payment Technology Service Providers and Electronic Payment Process Facilitators bear a higher degree of compliance risks due to the changing nature of technology and supervisory amendments aimed at dealing with problems related to providing this type of service.
  • Retention of required compliance documents related to records, applications, account statements, disclosures, and notifications.
  • Identifying and assessing money laundering and terrorism financing risks that may arise from collection services through Payment Technology Service Providers or Electronic Payment Process Facilitators. This assessment must be completed before launching collection services through them. If the service is already active at the bank, this assessment must be re-executed immediately upon the issuance of these rules in light of the supervisory requirements contained therein and the due diligence procedures issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.

3-4 Reputation Risks:

  • The level of reputation risks increases due to the bank's decision to provide collection services through Payment Technology Service Providers or Electronic Payment Process Facilitators, especially regarding more complex transactions. Some risks that may affect the bank's reputation through providing collection services through Payment Technology Service Providers or Electronic Payment Process Facilitators include:
    • Disclosure of confidential information to unauthorized parties or its theft.
    • Failure to provide reliable services due to repeated service outages or long downtime.
    • Complaints about the difficulty of using collection services through Payment Technology Service Providers or Electronic Payment Process Facilitators, or the inability of technical support staff to solve these problems.

12 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators

4 - Anti-Money Laundering and Counter-Terrorism Financing Rules and Information Security

4-1 Commitment to the Anti-Money Laundering Law issued by Law No. 80 of 2002 and its executive regulations, and the supervisory regulations for banks regarding anti-money laundering and counter-terrorism financing, and customer identification rules issued in 2011, as well as due diligence procedures for mobile payment service customers issued in 2016 and all subsequent amendments to them.

4-2 Paying sufficient attention to identify operations suspected of involving money laundering or terrorism financing according to the nature of the service and the supervisory regulations for banks regarding anti-money laundering and counter-terrorism financing issued by the Central Bank of Egypt in 2008.

4-3 In case of suspicion of any operations conducted through Payment Technology Service Providers or Electronic Payment Process Facilitators, notify the Anti-Money Laundering and Counter-Terrorism Financing Unit regarding them, in accordance with the provisions of the Anti-Money Laundering Law issued by Law No. 80 of 2002.

4-4 Commitment to any instructions subsequently issued by the Central Bank of Egypt regarding Payment Technology Service Providers or Electronic Payment Process Facilitators.

4-5 Necessity of notifying the Information Security Department at the Central Bank of Egypt via email eg.org.cbe@infosec.cbe and the Cybersecurity Department via email eg.org.cbe@team-csirc and the Supervision and Inspection Sector immediately regarding any data breach cases concerning Payment Technology Service Providers or Electronic Payment Process Facilitators.

Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 13

5 - Preparation of Information Security Policy

5-1 Senior management must ensure that the information security policy applied by the bank - approved by the Board of Directors and updated periodically - covers collection services through Payment Technology Service Providers and Electronic Payment Process Facilitators. This helps identify the necessary policies, procedures, and supervisory controls to protect banking operations from breaches and security violations, as well as defining individual responsibilities and explaining the mechanisms for implementation and procedures to be taken in case of violation of these policies and procedures.

5-2 Senior management is responsible for enhancing and spreading the security culture at all levels of the bank by emphasizing their commitment to high information security standards and spreading this culture among all bank employees.

14 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators

6 - General Rules for Banks to Use Technology Service Providers and Payment Facilitators

6-1 The contract with Payment Technology Service Providers and Electronic Payment Process Facilitators must include at least the following:

1-6-1 Clearly defining the contractual responsibilities of all parties to outsourcing, partnership, or agency agreements. For example, the responsibilities of providing information to Payment Technology Service Providers and Electronic Payment Process Facilitators and receiving it from them must be clearly defined.

2-6-1 A non-disclosure agreement for confidential information to external parties and a service level agreement, which includes, but is not limited to: defining roles and responsibilities, the time required to execute the service, escalation procedures and details, and penalties in case of non-compliance. This is in addition to clauses preserving the bank's right to audit services or rely on approved audit reports (issued by approved audit entities).

3-6-1 The contract between the bank and Payment Technology Service Providers or Electronic Payment Process Facilitators must stipulate the possibility of suspending/cancelling any of the subsidiary companies, and the bank must put mechanisms that enable it to suspend any subsidiary company immediately.

4-6-1 All systems and operations related to collection services through Payment Technology Service Providers and Electronic Payment Process Facilitators conducted through outsourcing or agency must be subject to the bank's risk management system and privacy and information security policies that comply with the bank's standards.

5-6-1 Providing all audit and evaluation reports to the inspectors of the Supervision and Inspection Sector at the Central Bank of Egypt.

6-6-1 Termination/cancellation procedures must be effective, ensuring the preservation of business continuity, data integrity, as well as its transfer and disposal.

7-6-1 Payment Technology Service Providers or Electronic Payment Process Facilitators are not allowed to contract with other companies (external parties) for subcontracting to perform tasks assigned to them by the bank through this contract, except with the written approval of the bank, with a list of tasks subcontracted by Payment Technology Service Providers or Electronic Payment Process Facilitators to external parties.

Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 15

6-2 General Controls

1-6-2 The bank must conduct periodic internal and/or external audits on operations, and the scope of audit coverage should not be less than similar operations applied at the internal level in the bank.

2-6-2 The bank must put appropriate emergency plans for collection services through Payment Technology Service Providers or Electronic Payment Process Facilitators.

3-6-2 Payment Technology Service Providers and Electronic Payment Process Facilitators must carefully examine the documents of the subsidiary companies they will register with them, according to the requirements listed in that approval in addition to the bank's requirements.

4-6-2 The bank must obtain data and documents of each subsidiary company it contracts with according to the bank's requirements, and Payment Technology Service Providers and Electronic Payment Process Facilitators must obtain the bank's approval before registering the subsidiary company in the system of Payment Technology Service Providers or Electronic Payment Process Facilitators.

5-6-2 The bank must have mechanisms that allow it full control over accepting or suspending the settlement of the total daily collections of subsidiary companies with Payment Technology Service Providers or Electronic Payment Process Facilitators, based on the "Bank Guarantee Value provided by Payment Technology Service Providers or Electronic Payment Process Facilitators to the bank."

6-6-2 The bank must, as a minimum, put an internal system that allows it continuous monitoring of operations conducted through Payment Technology Service Providers or Electronic Payment Process Facilitators, including the following:

  • The bank must ensure before activating the service that the subsidiary company is not on any negative lists.
  • Ensure the absence of any suspicion related to money laundering, terrorism financing, or any crime, in accordance with the provisions of the Anti-Money Laundering Law issued by Law No. 80 of 2002.

7-6-2 The bank must apply a mechanism through which it can separate the electronic collection operations of subsidiary companies belonging to Payment Technology Service Providers or Electronic Payment Process Facilitators upon completion of the payment process (Online).

8-6-2 The bank must examine movements conducted by subsidiary companies on a daily basis without relying on Payment Technology Service Providers or Electronic Payment Process Facilitators to do so.

16 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators

9-6-2 The bank must provide a transaction review system for Payment Technology Service Providers and Electronic Payment Process Facilitators, which enables them to match and review all transactions executed through it for all subsidiary companies with it on a real-time/daily basis.

10-6-2 The bank must ensure that Payment Technology Service Providers and Electronic Payment Process Facilitators have a specific system for examining and monitoring movements of their subsidiary companies to monitor and carefully examine their specific movements.

11-6-2 The bank must conduct periodic inspection campaigns at the headquarters and systems of Payment Technology Service Providers or Electronic Payment Process Facilitators to ensure that the rules of operation followed comply with the regulations issued by the Central Bank of Egypt and the rules issued by the bank, and this must be included in the contract concluded between the bank and Payment Technology Service Providers or Electronic Payment Process Facilitators.

12-6-2 The bank must define clear rules for resolving disputes that may arise between the parties of the system according to the distribution channel used.

13-6-2 The bank must ensure that Payment Technology Service Providers and Electronic Payment Process Facilitators commit to providing a customer service center to respond to any inquiries, and that they spread the necessary awareness to subsidiary companies regarding:

  • How to use the system, extract required reports, and access data of specific movements.
  • Fraud operations and how to study movements.
  • Dispute operations and what mechanisms will be used and what documents are required for these movements.

14-6-2 Dealing in the following activities by subsidiary companies registered with Payment Technology Service Providers or Electronic Payment Process Facilitators is prohibited:

  • Virtual currencies.
  • Network marketing / Pyramid schemes.
  • Buying / selling securities.
  • File custody or sharing services (Sharing File).
  • Dating websites / Mobile Apps.
  • Buying and selling gold, jewelry, and precious stones.
  • Gambling and lottery services, including casino games, races, etc.
  • Crowdfunding services (Funding Crowd).

15-6-2 No company or activity requiring prior approval from the Central Bank of Egypt can be registered with Payment Technology Service Providers or Electronic Payment Process Facilitators except after obtaining approval from the Central Bank of Egypt.

16-6-2 Regarding Electronic Payment Process Facilitators, the bank must commit to the following:

  • A valid legal entity for subsidiary companies (merchants-Sub) according to customer identification rules issued in 2011 and due diligence procedures for mobile payment service customers issued in 2016 and all subsequent amendments to them, with ensuring the existence of the following:
    • A real headquarters inside the Arab Republic of Egypt.
    • Clear contact details (phone number inside the Arab Republic of Egypt / email).
    • A website / mobile application (if available according to the service provided).
  • The Electronic Payment Process Facilitator must transfer the collections of subsidiary companies (merchants-Sub) according to a service level agreed upon with the registered subsidiary companies, with the transfer of collections occurring on the second working day and within a maximum deadline of 3 working days from the date of the financial transaction, with the bank putting mechanisms to ensure this.
  • The bank must keep a bank guarantee from the Electronic Payment Process Facilitator to secure transactions executed through it, and this guarantee must be equal to or greater than the value of what is collected by the Electronic Payment Process Facilitator during three working days. This guarantee must be re-evaluated periodically, and under no circumstances should the value of operations collected by the Electronic Payment Process Facilitator exceed the guarantee held by the bank.
  • The bank must ensure that the settlement account for the Electronic Payment Process Facilitator is specific only to settling the collections of its subsidiary companies, without using these collections for any other work belonging to the Electronic Payment Process Facilitator.
  • Regularly monitoring financial transfers related to the service from the Electronic Payment Process Facilitator to the subsidiary companies (merchants-Sub) and completing them according to the agreed service level.
  • The bank must commit to the appearance of movements conducted through subsidiary companies according to the following description: ** Electronic Payment Process Facilitator Name ** Subsidiary Company Name **.
  • The bank must conduct inspection operations on a...

[RegAlert note: the English text above is a translation of the first 24,000 characters of a 39,349-character original (61% of the document). The remainder was not translated. The complete original-language text is stored with this document.]