2021-04-21
Added · Updated
The Central Bank of Egypt establishes the regulatory framework for the provision of mobile payment services, defining the roles and responsibilities of service providers and senior management. The rules mandate specific supervisory controls, including the issuance of electronic money, the management of third-party service providers, identity verification procedures, and password administration. Additional requirements cover money transfer operations, inter-operability, data confidentiality, application security, and IT infrastructure. The document also outlines operational rules for service contracts, incident reporting, and the procedures for obtaining licenses to provide these services.
CENTRAL BANK OF EGYPT
| Page | |
|---|---|
| 1. Introduction | 4 |
| 2. Management of Payment Services Using Mobile Phones | 5 |
| 2-1. Related Parties | 5 |
| 2-2. Responsibilities and Obligations of Senior Management | 6 |
| 2-3. Insurance Policy for Information | 9 |
| 2-4. Production of Payment Services Using Mobile Phones | 9 |
| 2-5. Powers of Compensation | 10 |
| 3. Supervisory Rules for Payment Services Using Mobile Phones | 11 |
| 3-1. Issuance of Electronic Money and System Management | 14 |
| 3-2. Outsourcing of Service Providers | 16 |
| 3-3. Management of Payment Service Providers | 17 |
| 3-4. Identity Verification Means (Verification) | 19 |
| 3-5. Password Management | 21 |
| 3-6. Special Rules for Money Transfer Operations | 22 |
| 3-7. Special Rules for Inter-operability | 24 |
| 3-8. Confidentiality and Data Protection | 25 |
| 3-9. Application Security | 26 |
| 3-10. IT Infrastructure and Security Monitoring for Payment Services Using Mobile Phones | 27 |
| 3-11. Security System Assessment for Payment Services Using Mobile Phones | 29 |
| 3-12. Incident Response and Management | 29 |
| 3-13. Business Continuity Planning | 30 |
| 4. Operational Rules for Other Service Providers | 31 |
| 4-1. Service Provision Contract / Service Request Form | 33 |
| 4-2. Reporting of Unusual Transactions | 34 |
| 4-3. Suspension of System Services | 35 |
| 5. Procedures for Obtaining a License to Provide the Service | 41 |
| Appendix (A): Rules and Powers Related to Outsourcing of Service Providers for Identity Verification | |
| Appendix (B): Rules Organizing the Provision of Electronic Money and the Exclusion of Numbers |
These rules are issued by the Central Bank of Egypt (the "Bank") pursuant to the powers conferred upon it by Law No. 88 of 2003 regarding the Central Bank of Egypt and the Organization of the Financial Sector and its Amendments, and the Executive Regulations thereof, as well as other relevant laws and regulations. These rules aim to regulate the provision of payment services using mobile phones in Egypt, ensuring the stability, security, and efficiency of the payment system, and protecting the rights of users.
Service providers must identify and manage relationships with related parties to avoid conflicts of interest and ensure the integrity of their operations. Related parties include any entity or individual that has the ability to control, jointly control, or exercise significant influence over the service provider, or over which the service provider has such ability.
Senior management of payment service providers is responsible for:
Service providers must implement robust information security policies to protect customer data and transaction information. This includes encryption, access controls, and regular security audits.
Service providers must ensure that the technical infrastructure and operational processes for providing payment services are reliable, scalable, and secure. They must also ensure that the services are accessible to all eligible users.
Service providers must have clear procedures for handling disputes and compensating users in case of errors, fraud, or system failures. These procedures must be transparent and communicated to users.
The issuance of electronic money through mobile phones is subject to specific regulations regarding capital adequacy, reserve requirements, and the segregation of customer funds. The system managing electronic money must be secure and monitored by the Bank.
Service providers may outsource certain functions to third parties, provided that:
The Bank supervises payment service providers to ensure compliance with these rules. Supervision includes on-site inspections, off-site monitoring, and regular reporting requirements.
Service providers must implement robust Know Your Customer (KYC) procedures to verify the identity of users. This includes collecting and verifying identification documents, biometric data, or other reliable means of identification as specified by the Bank.
Service providers must enforce strong password policies, including complexity requirements, regular updates, and protection against unauthorized access. Multi-factor authentication should be used where appropriate.
Money transfer operations via mobile phones must comply with anti-money laundering (AML) and counter-terrorism financing (CFT) regulations. Service providers must report suspicious transactions and maintain records of transactions for a specified period.
Service providers must ensure that their systems are interoperable with other payment systems to facilitate seamless transactions. The Bank may set technical and operational standards for inter-operability.
Service providers must protect the confidentiality of customer information and transaction data. They must not disclose such information to third parties without the user's consent, except as required by law or regulatory authorities.
Mobile applications used for payment services must be secure against malware, hacking, and other cyber threats. Regular security testing and updates are required.
Service providers must maintain robust IT infrastructure with redundancy and disaster recovery capabilities. Continuous security monitoring is required to detect and respond to security incidents.
Service providers must undergo regular security assessments by independent auditors to ensure the effectiveness of their security controls.
Service providers must have an incident response plan to handle security breaches, system failures, and other operational disruptions. Incidents must be reported to the Bank promptly.
Service providers must develop and maintain a business continuity plan to ensure the availability of payment services in case of emergencies or disasters.
Service providers must have clear contracts with users outlining the terms and conditions of service, fees, and liabilities.
Service providers must report unusual or suspicious transactions to the relevant authorities as required by AML/CFT regulations.
Service providers may suspend services in case of technical issues, security threats, or non-compliance by users, subject to notification requirements.
Entities wishing to provide payment services using mobile phones must apply for a license from the Bank. The application must include:
The Bank will review the application and may conduct due diligence before granting the license.
This appendix details the specific requirements for outsourcing identity verification services, including due diligence on third-party providers, data handling protocols, and audit rights.
This appendix outlines the rules for the issuance and management of electronic money, including limits on balances, transaction values, and the exclusion of certain phone numbers from service provision for security reasons.
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 220,262-character original (11% of the document). The remainder was not translated. The complete original-language text is stored with this document.]