EBA欧洲银行-EBA-Public-Hearing-Draft-GL-on-fraud-reporting-requirements-under-PSD2_25页_2mb
报告摘要
EBA Summary: Guidelines on Fraud Reporting under Article 96(6) of PSD2
1. Introduction to the EBA
The European Banking Authority (EBA) was established by Regulation (EC) No. 1093/2010 and came into existence on 1 January 2011. It took over the responsibilities of the Committee of European Banking Supervisors (CEBS) and added new functions, including consumer protection, financial innovation monitoring, and payments. The EBA is an independent authority accountable to the European Parliament and Council, with its governing body being the EBA Board of Supervisors, consisting of the heads of the 28 national supervisory authorities.
The EBA's regulatory remit includes several EU Directives and Regulations, such as the Capital Requirements Directive (CRR/D IV), the Deposit Guarantee Scheme Directive (DGSD), the Payment Accounts Directive (PAD), the Payment Services Directive (PSD1 and PSD2), the Anti-Money Laundering Directive (AMLD), and the Markets in Financial Instruments Directive (MiFID/R).
The EBA conducts public hearings to gather stakeholder input on its technical standards and guidelines. These hearings occur during the consultation period, typically a month before the deadline for written responses. The purpose is to clarify the Consultation Paper (CP) and allow participants to request additional explanations, though the hearings do not replace written responses.
2. PSD2 Mandates and Related Work
The Payment Services Directive 2 (PSD2) has multiple objectives, including enhancing consumer protection, promoting financial innovation, and improving payment security. The EBA is responsible for developing guidelines and technical standards to implement these objectives.
Progress on Other Payments-Related Mandates
- GL on security of internet payments under PSD1
- RTS on scheme separation under IFR
- RTS on Passporting Notifications under PSD2
- RTS on Strong Authentication & Secure Communications under PSD2
- GL on Professional Indemnity Insurance under PSD2
- GL on Authorisation of payment institutions under PSD2
- GL on Incident Reporting under PSD2
- GL on Complaints Procedures by CAs under PSD2
- GL on Operational & Security Measures under PSD2
- RTS on Central Contact Points under PSD2
- RTS & ITS on EBA Register under PSD2
- EBA GL on fraud reporting under PSD2
- RTS on home-host coordination under PSD2
Other Topics Progressed
- Implications of the transitional period under Articles 109 and 115 of PSD2
- Status of agents and distributors of electronic money under the EU freedom to provide services
- Impact of potential delays in the delivery of PSD2 mandates
- Feasibility of extending the EBA's web-based Q&A tool to cover PSD2-related queries
- Application of existing JC Guidelines on complaints handling to new AI and PI services
3. Draft EBA GL on Fraud Reporting under Article 96(6) PSD2
Background
Article 96(6) of PSD2 requires payment service providers (PSPs) to provide statistical data on fraud relating to different payment methods to their competent authorities (CAs), which in turn must report this data to the EBA and the European Central Bank (ECB). The EBA and ECB have developed guidelines to standardize this reporting process across the EU.
Key Objectives of the Guidelines
-
For PSPs:
- Compare fraud prevention performance with country-level benchmarks
- Collect transaction and fraud data for risk monitoring and assessment
- Proactively identify fraud trends
- Monitor compliance with Strong Customer Authentication (SCA) and Customer Security Criteria (CSC) requirements, especially Articles 18 and 20 of the draft RTS
-
For PSUs and Supervisory Authorities:
- Access to regular, reliable, and aggregated fraud data at EU and country levels
- Contribution to assessing the effectiveness of regulation, identifying fraud trends, and informing future regulatory changes
Data Definitions and Breakdowns
-
Definition of Fraudulent Payment Transactions:
Includes unauthorized payments, payments where the payer was manipulated, and payments where the payer acted fraudulently. -
Data Breakdowns:
The draft guidelines include breakdowns by payment method (e.g., card, direct debit, credit transfer), authentication method (SCA/no SCA), and reason for authentication choice (as defined in the draft RTS on SCA and CSC). These breakdowns are detailed in Annexes 2 and 3.
Scope of Reporting
-
Exclusions:
The EBA proposes to exclude Account Information Service Providers (AISPs) from the reporting requirements to avoid double counting and reporting. -
Frequency of Reporting:
Detailed data must be reported annually, while less detailed data can be reported quarterly. Small payment institutions and e-money institutions may be exempt from quarterly reporting. -
Double Reporting:
For card transactions, both the payer's and payee's PSPs are required to report, but national authorities are instructed not to sum the data to avoid double counting. -
Consumer vs. Other PSUs:
The EBA currently does not require data breakdown between consumers and other payment service users, as it is not always possible for PSPs to distinguish between the two.
4. Expected Timelines and Next Steps
- 03 November 2017: Consultation period ends
- December 2017: EBA assesses responses and decides on any changes to the draft guidelines
- January 2018: PSD2 applies, including Article 96(6) fraud reporting provisions
- 2018: Final guidelines are published in English and all EU languages, with a 2-month notification period for CAs
- Q2 2018: All PSPs must start reporting relevant data to CAs, who then report to the EBA and ECB
5. Summary of Key Questions and Proposals
| Question | Summary |
|---|---|
| Q1 | Assess whether the EBA and ECB's objectives for the guidelines are appropriate and complete. |
| Q2 | Evaluate if the definition of fraudulent payment transactions and data breakdowns cover all relevant data. |
| Q3 | Confirm agreement with the exemption of AISPs from reporting. |
| Q4 | Assess the rationale for not including data on attempted fraud. |
| Q5 | Evaluate the proposal to report both gross and net fraudulent transactions. |
| Q6 | Confirm if the proposed reporting frequency and exemptions are proportionate. |
| Q7 | Assess the feasibility of reporting data as specified in Guideline 7 and the three Annexes. |
| Q8 | Evaluate the balance between comprehensive data and avoiding double reporting. |
| Q9 | Confirm if PSPs should distinguish between consumer and non-consumer transactions. |
6. Conclusion
The EBA is working closely with the ECB to develop standardized guidelines on fraud reporting under Article 96(6) of PSD2. These guidelines aim to ensure consistent and reliable data collection across the EU, with a focus on consumer protection and market integrity. The EBA has made efforts to balance the need for comprehensive data with proportionality and the avoidance of double counting. The final guidelines are expected to be published in early 2018, following a consultation period and stakeholder feedback.
试读结束,高清完整版pdf/doc/ppt,请点下载