2019-04-04
Added · Updated
The Central Bank of Egypt establishes minimum rules for banks interacting with Payment Aggregators and Electronic Payment Facilitators, requiring board approval of risk strategies, due diligence, and specific contractual clauses including non-disclosure and audit rights. Banks must implement internal controls, daily transaction monitoring, and emergency plans, while prohibiting engagement with specific high-risk activities such as virtual currencies, pyramid schemes, and gambling. The regulations mandate adherence to anti-money laundering laws, information security policies, and the maintenance of bank guarantees equivalent to three days of collected funds.
Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators Inside the Arab Republic of Egypt Aggregator Payment Technical Facilitators Payment &
Contents Introduction Definitions 1 - Scope of the Rules 2 - Responsibilities and Obligations of the Board of Directors and Senior Management 3 - Risks Associated with Provided Services 4 - Anti-Money Laundering and Counter-Terrorism Financing Rules and Information Security 5 - Preparation of Information Security Policy 6 - General Rules for Banks to Use Technology Service Providers and Payment Facilitators 7 - Confidentiality and Integrity of Information 8 - Monitoring Abnormal Activities 9 - Awareness of Subsidiary Companies 10 - Procedures for Obtaining a License to Provide the Service
4 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators
Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 5 Introduction These rules were prepared due to the rapid development in the collection and payment of bills and services, and the need for the existence of Payment Technology Service Providers (Aggregator Payment) as well as Electronic Payment Process Facilitators (Facilitator Payment). The ability of these companies to provide financial and technological services to many merchants and companies, and to provide appropriate contractual methods, helps in providing and spreading electronic collection services through various distribution channels. This has a significant impact on increasing the acceptance of electronic payment methods among these categories of companies and merchants, ensuring tangible steps in the field of electronic payments in a secure manner for all parties participating in the electronic collection process.
6 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators
Payment Aggregator Technical It is a company with financial solvency that provides technological services to its subsidiary companies on behalf of the bank through the electronic distribution channels of the service providers, including providing electronic collection services for the value of bills/services provided. Its roles include, but are not limited to:
Payment Facilitator It is a company with financial solvency that provides financial and technological services through the electronic distribution channels of the subsidiary companies contracted with it on behalf of the bank for electronic collection. Its roles include, but are not limited to:
Definitions
Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 7
Subsidiary Company for Payment Technology Service Providers These are companies that have a valid legal entity and contract with Payment Technology Service Providers and the bank (according to the mentioned contracting methods) to provide bill/service payment services for their customers through the electronic distribution channels of Payment Technology Service Providers. The subsidiary company must have:
Subsidiary Company for Electronic Payment Process Facilitators It is a company that has a valid legal entity and contracts with the Electronic Payment Process Facilitator to provide electronic payment services for its customers through its own channels, for example, but not limited to: the company's website, the company's mobile application, the company's specific branch, etc.
Electronic Distribution Channels These are the electronic channels that allow electronic collection from customers, including, but not limited to:
8 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators
1 - Scope of the Rules
Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 9
2 - Responsibilities and Obligations of the Board of Directors and Senior Management The Board of Directors assumes the responsibility of adopting the business strategy prepared by the Senior Management of the bank, as well as making a clear strategic decision regarding the bank's desire to deal with Payment Technology Service Providers or Electronic Payment Process Facilitators or not. Specifically, the Board of Directors must ensure the following:
10 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators
3 - Risks Associated with Provided Services Providing collection services through Payment Technology Service Providers and Electronic Payment Process Facilitators is accompanied by many risks and advantages at the same time. While these risks are not new to banks, providing collection services through them may increase risk levels in addition to creating new challenges for managing these risks. These risks include, but are not limited to:
3-1 Strategic Risks:
3-2 Operational Risks / Transaction Risks:
3-3 Compliance Risks / Legal Risks:
Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 11
3-4 Reputation Risks:
12 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators
4 - Anti-Money Laundering and Counter-Terrorism Financing Rules and Information Security
4-1 Commitment to the Anti-Money Laundering Law issued by Law No. 80 of 2002 and its executive regulations, and the supervisory regulations for banks regarding anti-money laundering and counter-terrorism financing, and customer identification rules issued in 2011, as well as due diligence procedures for mobile payment service customers issued in 2016 and all subsequent amendments to them.
4-2 Paying sufficient attention to identify operations suspected of involving money laundering or terrorism financing according to the nature of the service and the supervisory regulations for banks regarding anti-money laundering and counter-terrorism financing issued by the Central Bank of Egypt in 2008.
4-3 In case of suspicion of any operations conducted through Payment Technology Service Providers or Electronic Payment Process Facilitators, notify the Anti-Money Laundering and Counter-Terrorism Financing Unit regarding them, in accordance with the provisions of the Anti-Money Laundering Law issued by Law No. 80 of 2002.
4-4 Commitment to any instructions subsequently issued by the Central Bank of Egypt regarding Payment Technology Service Providers or Electronic Payment Process Facilitators.
4-5 Necessity of notifying the Information Security Department at the Central Bank of Egypt via email eg.org.cbe@infosec.cbe and the Cybersecurity Department via email eg.org.cbe@team-csirc and the Supervision and Inspection Sector immediately regarding any data breach cases concerning Payment Technology Service Providers or Electronic Payment Process Facilitators.
Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 13
5 - Preparation of Information Security Policy
5-1 Senior management must ensure that the information security policy applied by the bank - approved by the Board of Directors and updated periodically - covers collection services through Payment Technology Service Providers and Electronic Payment Process Facilitators. This helps identify the necessary policies, procedures, and supervisory controls to protect banking operations from breaches and security violations, as well as defining individual responsibilities and explaining the mechanisms for implementation and procedures to be taken in case of violation of these policies and procedures.
5-2 Senior management is responsible for enhancing and spreading the security culture at all levels of the bank by emphasizing their commitment to high information security standards and spreading this culture among all bank employees.
14 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators
6 - General Rules for Banks to Use Technology Service Providers and Payment Facilitators
6-1 The contract with Payment Technology Service Providers and Electronic Payment Process Facilitators must include at least the following:
1-6-1 Clearly defining the contractual responsibilities of all parties to outsourcing, partnership, or agency agreements. For example, the responsibilities of providing information to Payment Technology Service Providers and Electronic Payment Process Facilitators and receiving it from them must be clearly defined.
2-6-1 A non-disclosure agreement for confidential information to external parties and a service level agreement, which includes, but is not limited to: defining roles and responsibilities, the time required to execute the service, escalation procedures and details, and penalties in case of non-compliance. This is in addition to clauses preserving the bank's right to audit services or rely on approved audit reports (issued by approved audit entities).
3-6-1 The contract between the bank and Payment Technology Service Providers or Electronic Payment Process Facilitators must stipulate the possibility of suspending/cancelling any of the subsidiary companies, and the bank must put mechanisms that enable it to suspend any subsidiary company immediately.
4-6-1 All systems and operations related to collection services through Payment Technology Service Providers and Electronic Payment Process Facilitators conducted through outsourcing or agency must be subject to the bank's risk management system and privacy and information security policies that comply with the bank's standards.
5-6-1 Providing all audit and evaluation reports to the inspectors of the Supervision and Inspection Sector at the Central Bank of Egypt.
6-6-1 Termination/cancellation procedures must be effective, ensuring the preservation of business continuity, data integrity, as well as its transfer and disposal.
7-6-1 Payment Technology Service Providers or Electronic Payment Process Facilitators are not allowed to contract with other companies (external parties) for subcontracting to perform tasks assigned to them by the bank through this contract, except with the written approval of the bank, with a list of tasks subcontracted by Payment Technology Service Providers or Electronic Payment Process Facilitators to external parties.
Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators 15
6-2 General Controls
1-6-2 The bank must conduct periodic internal and/or external audits on operations, and the scope of audit coverage should not be less than similar operations applied at the internal level in the bank.
2-6-2 The bank must put appropriate emergency plans for collection services through Payment Technology Service Providers or Electronic Payment Process Facilitators.
3-6-2 Payment Technology Service Providers and Electronic Payment Process Facilitators must carefully examine the documents of the subsidiary companies they will register with them, according to the requirements listed in that approval in addition to the bank's requirements.
4-6-2 The bank must obtain data and documents of each subsidiary company it contracts with according to the bank's requirements, and Payment Technology Service Providers and Electronic Payment Process Facilitators must obtain the bank's approval before registering the subsidiary company in the system of Payment Technology Service Providers or Electronic Payment Process Facilitators.
5-6-2 The bank must have mechanisms that allow it full control over accepting or suspending the settlement of the total daily collections of subsidiary companies with Payment Technology Service Providers or Electronic Payment Process Facilitators, based on the "Bank Guarantee Value provided by Payment Technology Service Providers or Electronic Payment Process Facilitators to the bank."
6-6-2 The bank must, as a minimum, put an internal system that allows it continuous monitoring of operations conducted through Payment Technology Service Providers or Electronic Payment Process Facilitators, including the following:
7-6-2 The bank must apply a mechanism through which it can separate the electronic collection operations of subsidiary companies belonging to Payment Technology Service Providers or Electronic Payment Process Facilitators upon completion of the payment process (Online).
8-6-2 The bank must examine movements conducted by subsidiary companies on a daily basis without relying on Payment Technology Service Providers or Electronic Payment Process Facilitators to do so.
16 Rules for Payment Technology Service Providers and Electronic Payment Process Facilitators
9-6-2 The bank must provide a transaction review system for Payment Technology Service Providers and Electronic Payment Process Facilitators, which enables them to match and review all transactions executed through it for all subsidiary companies with it on a real-time/daily basis.
10-6-2 The bank must ensure that Payment Technology Service Providers and Electronic Payment Process Facilitators have a specific system for examining and monitoring movements of their subsidiary companies to monitor and carefully examine their specific movements.
11-6-2 The bank must conduct periodic inspection campaigns at the headquarters and systems of Payment Technology Service Providers or Electronic Payment Process Facilitators to ensure that the rules of operation followed comply with the regulations issued by the Central Bank of Egypt and the rules issued by the bank, and this must be included in the contract concluded between the bank and Payment Technology Service Providers or Electronic Payment Process Facilitators.
12-6-2 The bank must define clear rules for resolving disputes that may arise between the parties of the system according to the distribution channel used.
13-6-2 The bank must ensure that Payment Technology Service Providers and Electronic Payment Process Facilitators commit to providing a customer service center to respond to any inquiries, and that they spread the necessary awareness to subsidiary companies regarding:
14-6-2 Dealing in the following activities by subsidiary companies registered with Payment Technology Service Providers or Electronic Payment Process Facilitators is prohibited:
15-6-2 No company or activity requiring prior approval from the Central Bank of Egypt can be registered with Payment Technology Service Providers or Electronic Payment Process Facilitators except after obtaining approval from the Central Bank of Egypt.
16-6-2 Regarding Electronic Payment Process Facilitators, the bank must commit to the following:
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 39,349-character original (61% of the document). The remainder was not translated. The complete original-language text is stored with this document.]