EBA欧洲银行-EBA-Opinion-on-the-amended-text-of-the-RTS-on-SCA-and-CSC-28EBA-Op-2017-0929_12页_470kb
报告摘要
EBA Opinion on the European Commission's Intention to Amend RTS on Strong Customer Authentication and Common and Secure Communication under PSD2
Introduction and Legal Basis
The European Banking Authority (EBA) submitted final draft Regulatory Technical Standards (RTS) under Article 98 of Directive (EU) 2015/2366 (PSD2) on 22 February 2017. These RTS outline requirements for strong customer authentication (SCA), exemptions, security measures, and common and secure communication standards (CSC) between payment service providers (PSPs). On 24 May 2017, the European Commission expressed its intention to partially endorse and amend these RTS.
The EBA's role in commenting on the amendments is based on Article 10(1) of Regulation (EU) No 1093/2010. The opinion was adopted by the Board of Supervisors in accordance with its Rules of Procedure.
Core Content and Main Objectives
The EBA's opinion focuses on the Commission's proposed amendments to Chapters 1, 3, and 5 of the draft RTS, as well as general legal drafting improvements. The main objectives of the RTS, as outlined in the EBA's original submission, include:
- Enhancing security
- Promoting competition
- Ensuring technological and business-model neutrality
- Contributing to the integration of payments in the EU
- Protecting consumers
- Facilitating innovation
- Enhancing customer convenience
The EBA acknowledges the importance of these objectives and agrees with the Commission's intent to improve the RTS, but raises concerns about the specific amendments.
Specific Comments on Amendments
a. Audit Requirement for Transaction Risk Analysis Exemption
Commission's Proposal: The audit for the transaction risk analysis exemption should be performed by statutory auditors.
EBA's Concerns:
- Statutory auditors are typically responsible for certifying financial statements, not for assessing security.
- The requirement may impose new, disproportionate obligations on small PSPs that are not currently required to perform statutory audits.
- It may not ensure the independence or expertise of auditors in the context of SCA.
EBA's Recommendation:
- Replace 'statutory audit' with 'audit performed by an auditor with expertise in IT security and payments and operationally independent'.
- Require external audits only during the first year and every three years thereafter, or upon request.
b. Exemption for Certain Corporate Payments
Commission's Proposal: Add an exemption for corporate payments using dedicated payment processes or protocols.
EBA's Concerns:
- The proposed exemption lacks a clear definition of 'corporate payments'.
- There is no reliable evidence that all such transactions are low risk.
- The exemption may contradict the principle of technological neutrality and risk becoming outdated or misused.
EBA's Recommendation:
- Introduce a new category under the transaction risk analysis exemption for non-consumer payers, without a monetary threshold, based on a reference fraud rate of 0.005%.
c. Reporting Requirements for Exemptions
Commission's Proposal: PSPs should report monitoring outcomes and fraud rate methodology to the EBA and national competent authorities (NCAs).
EBA's Concerns:
- The current draft may create overlapping reporting obligations with Article 96(6) of PSD2.
- It could lead to confusion and duplication of efforts.
EBA's Recommendation:
- Restrict reporting to 'upon request' with prior notification to the relevant competent authorities.
d. Fallback Access via Customer Interface
Commission's Proposal: Allow AISPs and PISPs to access data via the ASPSP's customer interface if the dedicated interface is unavailable or non-compliant.
EBA's Concerns:
- This approach may compromise security, especially in the case of short intervals (e.g., 30 seconds).
- It could lead to increased fragmentation, higher costs, and unclear consumer consent.
- It may not ensure compliance with PSD2's security requirements.
EBA's Alternative Approach:
- Reinforce the requirements for ASPSPs to ensure reliable and continuous access to data.
- Increase transparency between PSPs and TPPs.
- Facilitate early testing of interfaces by requiring ASPSPs to make them available at least three months before the RTS apply.
- Monitor interface performance as part of the EBA's review process under Article 36.
Legal Drafting Changes
The EBA also raises concerns about certain legal drafting changes, including:
- Requiring three conditions (single transaction limit, cumulative limit, and number of transactions) in Articles 11 and 16 of the draft RTS.
- The EBA suggests using 'or' to clarify that these conditions are optional, not cumulative.
- Reintroducing 'or confirmed' in Article 13 for trusted beneficiaries.
- Replacing 'account servicing payment service providers' with 'payment service providers' in the context of SCA exemptions.
Conclusion
The EBA supports the Commission's intention to enhance the RTS but believes that the proposed amendments may introduce unnecessary burdens, reduce technological neutrality, and compromise security. The EBA proposes alternative measures that align with the objectives of PSD2 while ensuring consistency, reliability, and consumer protection.
试读结束,高清完整版pdf/doc/ppt,请点下载