2018年-ECB欧洲央行_Eurosystem_report_on_the_gap_assessment_of_card_payment_schemes_against_the_“Oversight_framework_for_card_payment_schemes_–_standards”_16页_354kb
报告摘要
Eurosystem Gap Assessment Report Summary
Executive Summary
The Eurosystem conducted a gap assessment of 16 card payment schemes (CPSs) in the euro area against the "Oversight framework for card payment schemes – standards" approved by the ECB Governing Council on 4 January 2008. The aim of the standards is to ensure the reliability of CPSs, public confidence in card payments, and a level playing field across the euro area.
The assessment was based on an updated guide from February 2015, which incorporated the "SecuRe Pay Recommendations on the security of internet payments" and was used to identify differences between the original and updated standards. The gap assessment was carried out sequentially from the second quarter of 2015 to the third quarter of 2018.
Out of the 16 CPSs assessed, 11 fully observed all oversight standards, while the remaining 5 broadly observed them. The overall compliance level has improved compared to the previous comprehensive assessment in 2014, indicating enhanced risk management and compliance practices among CPSs.
Background Information
- The oversight framework applies to all CPSs, including three-party and four-party schemes, and defines the standards for legal basis, information availability, security, governance, and clearing/settlement processes.
- A waiver policy excludes CPSs with less than 1 million cards issued annually or less than €1 billion in average transactional value over three years from oversight.
- The framework is based on a risk-based approach, focusing on five main standards with detailed sub-domains and key issues.
- The updated assessment guide aims to ensure consistency and foster a common understanding of the standards among overseers and CPSs.
Observance Status
Observance at the Level of the Standards
| Standard | Observed | Broadly Observed |
|---|---|---|
| 1. Legal basis | 15 | 1 |
| 2. Comprehensive information | 16 | 0 |
| 3. Security, operational reliability & business continuity | 12 | 4 |
| 4. Governance arrangements | 15 | 1 |
| 5. Clearing & settlement process | 14 | 1 |
Standard 1 - Sound Legal Basis
- Key Issues: 1.1 Legal framework, 1.2 Conflicting jurisdictions
- Compliance: All but one CPS fully observed the standard.
- Focus: Compliance with recent EU legislation such as the revised Payment Services Directive (PSD2), Anti-Money Laundering Directive, and Interchange Fees Regulation.
- Not Applicable: 7 national CPSs did not need to address key issue 1.2 due to lack of cross-border facilities.
Standard 2 - Comprehensive Information
- Key Issues: 2.1 Governance adequately documented, 2.2 Access to information
- Compliance: All CPSs fully observed key issue 2.1; most observed key issue 2.2.
- Recommendations: Some CPSs were recommended to improve communication with card holders and merchants regarding security and financial risks.
Standard 3 - Security, Operational Reliability & Business Continuity
- Key Issues: 3.1 Security management, 3.2 Card and device manufacturing, 3.3 Transactions, 3.4 Clearing & settlement, 3.5 Business continuity, 3.6 Outsourcing
- Compliance: 12 schemes observed key issue 3.1, 14 observed 3.2, 12 observed 3.3, 16 observed 3.4, 15 observed 3.5, and 15 observed 3.6.
- Findings: Issues were mainly related to the definition of sensitive payment data, customer authentication procedures, and the management of secrets. Some CPSs did not mandate strong customer authentication (SCA) for all transactions.
- Positive Note: Many CPSs have implemented efficient fraud monitoring and transaction blocking measures.
Standard 4 - Governance Arrangements
- Key Issues: 4.1 Decision processes, 4.2 Internal control framework
- Compliance: 15 CPSs observed key issue 4.1; 15 observed key issue 4.2.
- Improvement Areas: One CPS was broadly compliant with key issue 4.1, and one was partly compliant with key issue 4.2.
- Positive Developments: All CPSs have established efficient processes for evaluating customer satisfaction and performance.
Standard 5 - Clearing and Settlement Process
- Key Issues: 5.1 Risks, 5.2 Providers, 5.3 Actor solidity
- Compliance: 14 CPSs observed key issue 5.1; 16 observed 5.2; 8 observed 5.3.
- Not Applicable: 1 CPS for key issue 5.1 and 8 CPSs for key issue 5.3.
- Findings: The assessment guide changes were mostly editorial, introducing a distinction between clearing and settlement arrangements.
General Conclusions and Follow-Up
- The main conclusion is that all 16 CPSs broadly observe the five standards, with 11 achieving full compliance.
- The Eurosystem continues to monitor the implementation of recommendations and follow-up actions by the governance authorities (GAs) of CPSs.
- There is still room for improvement in risk management, particularly in security and fraud risk areas.
- The implementation of SCA for remote electronic transactions is expected to become mandatory from 14 September 2019, following the application of the RTS on SCA and CSC, and national provisions of PSD2.
Annex
- The report includes an overview of the five standards and their associated key issues, providing a detailed breakdown of the compliance levels for each CPS.
试读结束,高清完整版pdf/doc/ppt,请点下载