2019-05-23
Added · Updated
The Central Bank of Egypt establishes minimum standards for banks operating in Egypt to safely issue and accept contactless electronic payments. The document mandates that bank boards of directors approve strategies, analyze risks, and implement monitoring procedures for these services. It requires compliance with Anti-Money Laundering (AML) laws, specifically Law No. 80 of 2002, and information security protocols. These rules apply to all local banks and foreign bank branches, serving as a baseline that institutions must exceed through comprehensive risk management.
Contactless Payments Standards for Issuing and Accepting Contactless Electronic Payments in the Arab Republic of Egypt
| Page | Section |
|---|---|
| 5 | Introduction |
| 6 | General Definitions |
| 7 | -1 NFC Technology |
| 8 | -2 Responsibilities and Obligations of the Board of Directors and Senior Management |
| 9 | -3 AML/CFT Rules and Information Security |
| 10 | -4 Rules for Issuing Contactless Payment Instruments |
| 12 | -5 Rules for Accepting Contactless Payments |
| 14 | -6 Reporting of Unusual Transactions |
| 15 | 7 - Technical Requirements for Contactless Payment Service Providers |
| 16 | -8 Procedures for Obtaining Licenses to Provide the Service |
In light of the interest that the Central Bank of Egypt places on supporting and encouraging the use of electronic payment means and channels, with the aim of transitioning to an economy with less reliance on cash notes and achieving financial inclusion, and given the current technological development in the field of electronic payments and the emergence of Contactless Payments, and the need to keep pace with this development to ensure tangible steps are taken in the field of electronic payments securely for all parties participating in the electronic payment process, the following rules have been issued.
| Field | Definition |
|---|---|
| Near Field Communication "NFC" | Contactless payments that are performed using radio waves (radio frequency) by credit cards, debit cards, mobile payment devices (smartphones or smart watches), wearable devices, and other devices that utilize RFID and/or NFC technologies, enabling short-range communication between embedded chips and antennas within a few centimeters to complete transactions securely. |
| Secure Code | The security code assigned to the customer, which can be either Static or Dynamic. Dynamic codes are generated by the device used for transactions to prevent fraud. |
| Dual Interface (NFC) | Terminals that support both contactless and traditional card reading data transmission methods. |
| EMV Contactless | Specifications developed jointly by EMVCo that enable interoperability between terminals and payment instruments not exceeding 4 cm. |
| Dual Interface Terminals | Terminals that support both contactless and traditional card reading data transmission methods. |
| POS Terminals | Point of Sale terminals that support contactless payment transactions in case more than one contactless payment instrument is present in the same transaction area. |
| Collision | The phenomenon where multiple contactless payment instruments are present in the same transaction area. |
These rules apply to all banks operating in the Arab Republic of Egypt and branches of foreign banks, representing the minimum required to provide contactless payment services securely. All banks must not limit themselves to this but must ensure taking all necessary measures regarding risk management associated with providing this type of banking service.
These rules regulate only the issuance and acceptance of contactless payments, without prejudice to previous supervisory regulations for electronic banking operations issued by the Central Bank of Egypt, as well as instructions and rules regarding the implementation of banking operations, anti-money laundering and counter-terrorism financing controls issued by the Central Bank of Egypt, and due diligence procedures issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit.
The Board of Directors assumes responsibility for approving the business strategy prepared by the bank's senior management, as well as making a clear strategic decision regarding the bank's desire to provide payment services using Contactless Payments or not. Specifically, the Board of Directors must ensure the following:
The bank must establish a risk policy concerning service partner companies and study risks related to the following:
Banks that issue or accept contactless payment instruments must implement the following:
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 36,654-character original (65% of the document). The remainder was not translated. The complete original-language text is stored with this document.]