2021-04-21

Added · Updated

Rules Regulating the Provision of Payment Services Using Mobile Phones, Third Edition, April 2021

The Central Bank of Egypt establishes the regulatory framework for the provision of mobile payment services, defining the roles and responsibilities of service providers and senior management. The rules mandate specific supervisory controls, including the issuance of electronic money, the management of third-party service providers, identity verification procedures, and password administration. Additional requirements cover money transfer operations, inter-operability, data confidentiality, application security, and IT infrastructure. The document also outlines operational rules for service contracts, incident reporting, and the procedures for obtaining licenses to provide these services.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Rules Regulating the Provision of Payment Services Using Mobile Phones

Third Edition - April 2021

CENTRAL BANK OF EGYPT

Contents

Page
1. Introduction4
2. Management of Payment Services Using Mobile Phones5
2-1. Related Parties5
2-2. Responsibilities and Obligations of Senior Management6
2-3. Insurance Policy for Information9
2-4. Production of Payment Services Using Mobile Phones9
2-5. Powers of Compensation10
3. Supervisory Rules for Payment Services Using Mobile Phones11
3-1. Issuance of Electronic Money and System Management14
3-2. Outsourcing of Service Providers16
3-3. Management of Payment Service Providers17
3-4. Identity Verification Means (Verification)19
3-5. Password Management21
3-6. Special Rules for Money Transfer Operations22
3-7. Special Rules for Inter-operability24
3-8. Confidentiality and Data Protection25
3-9. Application Security26
3-10. IT Infrastructure and Security Monitoring for Payment Services Using Mobile Phones27
3-11. Security System Assessment for Payment Services Using Mobile Phones29
3-12. Incident Response and Management29
3-13. Business Continuity Planning30
4. Operational Rules for Other Service Providers31
4-1. Service Provision Contract / Service Request Form33
4-2. Reporting of Unusual Transactions34
4-3. Suspension of System Services35
5. Procedures for Obtaining a License to Provide the Service41
Appendix (A): Rules and Powers Related to Outsourcing of Service Providers for Identity Verification
Appendix (B): Rules Organizing the Provision of Electronic Money and the Exclusion of Numbers

1. Introduction

These rules are issued by the Central Bank of Egypt (the "Bank") pursuant to the powers conferred upon it by Law No. 88 of 2003 regarding the Central Bank of Egypt and the Organization of the Financial Sector and its Amendments, and the Executive Regulations thereof, as well as other relevant laws and regulations. These rules aim to regulate the provision of payment services using mobile phones in Egypt, ensuring the stability, security, and efficiency of the payment system, and protecting the rights of users.

2. Management of Payment Services Using Mobile Phones

2-1. Related Parties

Service providers must identify and manage relationships with related parties to avoid conflicts of interest and ensure the integrity of their operations. Related parties include any entity or individual that has the ability to control, jointly control, or exercise significant influence over the service provider, or over which the service provider has such ability.

2-2. Responsibilities and Obligations of Senior Management

Senior management of payment service providers is responsible for:

  1. Establishing and maintaining an effective internal control system.
  2. Ensuring compliance with all applicable laws, regulations, and these rules.
  3. Overseeing the risk management framework, including credit, liquidity, operational, and reputational risks.
  4. Approving and reviewing the strategic direction and business plans of the service provider.
  5. Ensuring the adequacy of human, financial, and technological resources.
  6. Reporting to the Board of Directors on the status of compliance and risk management.

2-3. Insurance Policy for Information

Service providers must implement robust information security policies to protect customer data and transaction information. This includes encryption, access controls, and regular security audits.

2-4. Production of Payment Services Using Mobile Phones

Service providers must ensure that the technical infrastructure and operational processes for providing payment services are reliable, scalable, and secure. They must also ensure that the services are accessible to all eligible users.

2-5. Powers of Compensation

Service providers must have clear procedures for handling disputes and compensating users in case of errors, fraud, or system failures. These procedures must be transparent and communicated to users.

3. Supervisory Rules for Payment Services Using Mobile Phones

3-1. Issuance of Electronic Money and System Management

The issuance of electronic money through mobile phones is subject to specific regulations regarding capital adequacy, reserve requirements, and the segregation of customer funds. The system managing electronic money must be secure and monitored by the Bank.

3-2. Outsourcing of Service Providers

Service providers may outsource certain functions to third parties, provided that:

  1. The outsourcing does not impair the service provider's ability to comply with these rules.
  2. The Bank retains the right to supervise the outsourced activities.
  3. The service provider remains fully responsible for the outsourced functions.
  4. Appropriate contracts are in place to ensure data protection and service continuity.

3-3. Management of Payment Service Providers

The Bank supervises payment service providers to ensure compliance with these rules. Supervision includes on-site inspections, off-site monitoring, and regular reporting requirements.

3-4. Identity Verification Means (Verification)

Service providers must implement robust Know Your Customer (KYC) procedures to verify the identity of users. This includes collecting and verifying identification documents, biometric data, or other reliable means of identification as specified by the Bank.

3-5. Password Management

Service providers must enforce strong password policies, including complexity requirements, regular updates, and protection against unauthorized access. Multi-factor authentication should be used where appropriate.

3-6. Special Rules for Money Transfer Operations

Money transfer operations via mobile phones must comply with anti-money laundering (AML) and counter-terrorism financing (CFT) regulations. Service providers must report suspicious transactions and maintain records of transactions for a specified period.

3-7. Special Rules for Inter-operability

Service providers must ensure that their systems are interoperable with other payment systems to facilitate seamless transactions. The Bank may set technical and operational standards for inter-operability.

3-8. Confidentiality and Data Protection

Service providers must protect the confidentiality of customer information and transaction data. They must not disclose such information to third parties without the user's consent, except as required by law or regulatory authorities.

3-9. Application Security

Mobile applications used for payment services must be secure against malware, hacking, and other cyber threats. Regular security testing and updates are required.

3-10. IT Infrastructure and Security Monitoring for Payment Services Using Mobile Phones

Service providers must maintain robust IT infrastructure with redundancy and disaster recovery capabilities. Continuous security monitoring is required to detect and respond to security incidents.

3-11. Security System Assessment for Payment Services Using Mobile Phones

Service providers must undergo regular security assessments by independent auditors to ensure the effectiveness of their security controls.

3-12. Incident Response and Management

Service providers must have an incident response plan to handle security breaches, system failures, and other operational disruptions. Incidents must be reported to the Bank promptly.

3-13. Business Continuity Planning

Service providers must develop and maintain a business continuity plan to ensure the availability of payment services in case of emergencies or disasters.

4. Operational Rules for Other Service Providers

4-1. Service Provision Contract / Service Request Form

Service providers must have clear contracts with users outlining the terms and conditions of service, fees, and liabilities.

4-2. Reporting of Unusual Transactions

Service providers must report unusual or suspicious transactions to the relevant authorities as required by AML/CFT regulations.

4-3. Suspension of System Services

Service providers may suspend services in case of technical issues, security threats, or non-compliance by users, subject to notification requirements.

5. Procedures for Obtaining a License to Provide the Service

Entities wishing to provide payment services using mobile phones must apply for a license from the Bank. The application must include:

  1. Detailed business plan.
  2. Proof of capital adequacy.
  3. Technical specifications of the system.
  4. Risk management and compliance policies.
  5. Information on senior management and key personnel.

The Bank will review the application and may conduct due diligence before granting the license.


Appendix (A): Rules and Powers Related to Outsourcing of Service Providers for Identity Verification

This appendix details the specific requirements for outsourcing identity verification services, including due diligence on third-party providers, data handling protocols, and audit rights.

Appendix (B): Rules Organizing the Provision of Electronic Money and the Exclusion of Numbers

This appendix outlines the rules for the issuance and management of electronic money, including limits on balances, transaction values, and the exclusion of certain phone numbers from service provision for security reasons.


[RegAlert note: the English text above is a translation of the first 24,000 characters of a 220,262-character original (11% of the document). The remainder was not translated. The complete original-language text is stored with this document.]