EBA欧洲银行-BSG-Response-to-EBA-CP-2014-31-CP-on-Internet-transactions_5页_201kb
报告摘要
EBA Banking Stakeholder Group Summary on EBA/CP/2014/31 Consultation Paper
Core Content
The EBA Banking Stakeholder Group (BSG) has provided detailed feedback on the Consultation Paper EBA/CP/2014/31, which outlines guidelines on the security of internet payments. The BSG supports the initiative to harmonize supervisory rules across Europe, aiming to ensure fair competition and more efficient cross-border operations. They also emphasize the importance of data sharing between European supervisors to avoid duplication of reporting efforts for banks.
Main Views and Key Points
1. Need for Legal Basis in Consumer Protection
- The BSG endorses the idea of establishing a solid legal framework for consumer protection in internet payments rather than relying on voluntary arrangements.
- They stress the importance of building consumer trust and confidence in using internet payment services.
2. Effectiveness of Guidelines
- Some BSG members question the effectiveness of the guidelines for EU-wide implementation, as financial institutions in certain member states may not follow them.
- The BSG highlights the need for more clarity on the role of 'competent authorities where they exist'.
3. Monitoring Mechanisms
- An effective monitoring mechanism is crucial for the successful implementation of the guidelines.
- National supervisory authorities require more guidance on how to ensure compliance with consumer protection standards, as many lack defined procedures or mandates in this area.
4. Exclusions from Guidelines
- The BSG requests clarification on why certain payment services are excluded from the guidelines, particularly points 1, 4, and 7.
- They argue that mobile phone payments and third-party services are emerging and may pose new risks, thus requiring high security standards.
5. Transparency and Reporting
- The BSG advocates for regular joint reporting of security incidents and fraud by Payment Service Providers (PSPs) to both authorities and the public.
- They believe that data on consumer harm, payment operations, and relevant risks can be very beneficial for consumers but is currently lacking in most member states.
6. Consumer-Friendly Security Instructions
- The BSG emphasizes the need for clear and accessible security instructions for all relevant payment operations.
- They stress that such instructions should be tailored for the 'average' consumer, avoiding overly technical or complex measures that may not be feasible for the general public.
7. Internal Security Evaluation
- The BSG supports the requirement for PSPs to evaluate their internal security controls against internal and external risk scenarios.
- However, they call for more information on how this evaluation will be monitored externally, including by supervisory authorities.
8. Clarification of Review Terms
- The BSG requests clarification on the terms "regular review" and "general review" mentioned in the Consultation Paper.
- They suggest that paragraph 2.4 should be revised to specify that the general review should occur at least once a year, and that additional reviews should follow major incidents.
9. Audit Frequency
- The BSG recommends that the term "periodically audited" in paragraph 4.6 be replaced with a specific time period to ensure clarity and consistency.
10. Security Arrangements by Insourcers
- The BSG questions whether there should be a requirement for PSPs to monitor and evaluate the security arrangements of insourcers (third-party service providers).
11. Maximum Period for Security Measures
- The BSG suggests that the guidelines should specify a maximum period for certain security measures to ensure consistency and enforceability.
12. Preference on Implementation
- The BSG members hold differing views on the implementation of the EBA guidelines and therefore do not express a unified preference in their response.
Conclusion
The BSG's comments reflect a strong support for the initiative to improve internet payment security across the EU, but also highlight the need for more clarity, enforceability, and consumer-centric approaches in the guidelines. They advocate for stronger monitoring, transparency, and accessibility in security practices, ensuring that all consumers, regardless of their technical knowledge, can benefit from secure payment services.
试读结束,高清完整版pdf/doc/ppt,请点下载