{"id":"circulars/cssf-19-713","title":"Circular CSSF 19/713","type":"circular","date":"2019-03-14","kind":"circular","html":"<p>Circular CSSF 19/713 is a CSSF circular, published 14 March 2019 and updated 25 August 2020. Subject: Guidelines of the European Banking Authority on the security measures for operational and security risks of payment services under Directive (EU) 2015/2366 (PSD2) – (EBA/GL/2017/17). It was repealed by <a href=\"/lhoft?page=circulars%2Fcssf-20-750\" class=\"wikiLink\" data-target=\"circulars/cssf-20-750\">Circular CSSF 20/750</a>.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>.</p>\n<p>Relevant for: Credit institutions, Payment institutions/electronic money institutions/AISPs.</p>\n<p>Keywords: Internal governance, Payment Service Provider (PSP).</p>\n<h2>Text</h2>\n<p>Luxembourg, 14 March 2019</p>\n<p>To all payment service providers</p>\n<p>Re : Guidelines of the European Banking Authority on the security measures for operational and security risks of payment services under Directive (EU) 2015/2366 (PSD2) (EBA/GL/2017/17)</p>\n<p>Ladies and Gentlemen, The purpose of this circular is to draw your attention to the Guidelines of the European Banking Authority (“EBA”) on the security measures for operational and security risks of payment services under Directive (EU) 2015/2366 1 (“PSD2”) (EBA/GL/2017/17 - the “Guidelines”), and with which the CSSF commits to comply, in its capacity as competent authority. The Guidelines provide details with regard to: (i) the annual auditing requirements as regards the security measures taken; and (ii) the annual reporting requirements regarding the assessment of major operational and security risks. 1. The Guidelines The Guidelines provide details for the security measures that should be taken in accordance with Article 105-1 (2) of the law of 10 November 2009 on payment services 2 (the “Law”) in order to manage the operational and security risks in relation to the payment services provided. 2. Scope The present circular is addressed to payment service providers as defined in Article 1 (37) of the Law, for which the CSSF is the designated competent authority for supervisory purposes (“PSPs”). 3. Auditing of the security measures According to point 2.6 of the Guidelines, the security measures established in accordance with the Guidelines should be audited. This audit should be carried out on an annual basis by the PSP’s internal auditor. 1</p>\n<p>Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC. 2 The law of 10 November 2009 on payment services, on the activity of electronic money institution and settlement finality in payment and securities settlement systems.</p>\n<ol start=\"4\">\n<li>Reporting period and deadlines According to point 3.4. of the Guidelines, the updated and comprehensive assessment of the operational and security risks relating to the payment services that the PSPs provide and of the adequacy of the mitigation measures and control mechanisms implemented in response to those risks, should be provided to the CSSF, in the form and timeframe described below: 1) for credit institutions, this assessment, signed by the management body, has to be submitted as soon as possible after the closure of the financial year and no later than 30 April of each year; 2) for payment institutions and e-money institutions, this assessment should be a dedicated section within the management report on internal control, to be issued as per the requirements of Circular CSSF 15/614, at the latest on the last day of the third month after the closing date of the financial year; and 3) for POST Luxembourg, this assessment should be a dedicated section within the management report on internal control, to be issued as per the requirements of Circular CSSF 98/143, at the latest one month after the annual general meeting approving the annual accounts of the PSP. 5. Date of application The present circular shall apply with immediate effect.</li>\n</ol>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-19-713/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf19_713eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}