EBA欧洲银行-Final-Report-on-Guidelines-on-the-exemption-to-the-fall-back-_DA_14页_251kb
报告摘要
Summary of EBA/GL/2018/07 Guidelines
Core Content
These guidelines, issued by the European Banking Authority (EBA), provide detailed instructions on the conditions for exemption from the readiness mechanism requirements outlined in Article 33, paragraph 6, of Commission Delegated Regulation (EU) 2018/389. They are directed at competent authorities and payment service providers (PSPs) and are based on Article 16 of Regulation (EU) No 1093/2010. The guidelines aim to ensure that PSPs who have chosen a dedicated interface can be exempted from the readiness mechanism obligations, provided they meet certain criteria.
Main Points
- Compliance Obligations: Competent authorities must strive to comply with these guidelines and report to the EBA if they fail to do so. Reports must be submitted using a specified form and sent to compliance@eba.europa.eu with the reference "EBA/GL/2018/07".
- Scope: The guidelines apply to the readiness mechanism for a specific interface, particularly the exemption from the mechanism as outlined in Article 33, paragraph 4, of the technical standards.
- Target Audience: Competent authorities as defined in Article 4, paragraph 2, letter i), of Regulation (EU) No 1093/2010, and payment service providers as defined in Article 4, paragraph 11, of Directive (EU) 2015/2366.
- Effective Date: The guidelines became effective from January 1, 2019.
Key Information
1. Compliance with Exemption Conditions
- Condition 1.1: Competent authorities should assess whether a payment service provider (PSP) has met the four conditions in Article 33, paragraph 6, of the technical standards, provided they meet the requirements in Guidelines 2–8.
- Condition 1.2: PSPs must provide necessary information to competent authorities to demonstrate compliance with the guidelines.
2. Service Level and Performance Indicators
- 2.1: PSPs must define key performance indicators (KPIs) and service level objectives (SLOs) for the dedicated interface, which should be at least as stringent as those for interfaces used by their own customers.
- 2.2: Minimum KPIs for availability include uptime and downtime per day.
- 2.3: Minimum KPIs for performance include average response times for various service requests and error rate percentages.
- 2.4: Downtime is calculated based on the time taken to respond to five consecutive requests exceeding 30 seconds.
3. Publication of Statistics
- 3.1: PSPs must provide quarterly reports to competent authorities on the availability and performance of the dedicated interface, including the date and location of publication.
- 3.2: These reports should include details on how the interface's performance compares with the availability and performance of the interfaces used by their own customers.
4. Stress Testing
- 4.1: PSPs must conduct stress tests to evaluate the performance of the dedicated interface under extreme conditions.
- 4.2: Stress testing should cover handling of multiple simultaneous requests, large volumes of requests, high session usage, and data-intensive operations.
- 4.3: PSPs must summarize the results of these tests, including any deviations from the standard and how they were resolved.
5. Obstacles
- 5.1: PSPs must provide a summary of the authentication methods used for customers accessing the dedicated interface and a justification that these methods do not hinder the authentication procedures used by third-party service providers.
- 5.2: PSPs must confirm that no additional consents or registrations are required beyond those specified in Directive (EU) 2015/2366.
6. Testing for Satisfaction
- 6.1: PSPs must provide documentation to competent authorities that the dedicated interface meets legal requirements and functional specifications.
- 6.2: The documentation should include details on market initiatives and conformance testing results.
- 6.3: PSPs must make technical specifications available for authorized third parties.
- 6.4: Test facilities should allow for secure testing with non-real user data.
- 6.5: The interface must support secure communication, error handling, and authentication procedures.
- 6.6: PSPs must provide a summary of test results, including feedback, identified problems, and actions taken to resolve them.
7. Broad Use of the Interface
- 7.1: PSPs must provide a description of the interface's usage, including the number of third-party providers and the volume of requests processed.
- 7.2: Competent authorities must consider information from previous guidelines when evaluating compliance with the broad use requirement.
- 7.3: The three-month period for broad use may overlap with the testing period.
8. Problem Resolution
- 8.1: PSPs must inform competent authorities about their systems and procedures for tracking, resolving, and closing issues.
- 8.2: They must also report on unresolved issues that do not meet the service level objectives.
9. EBA Consultation
- 9.1: Competent authorities must consult EBA before granting exemptions and consider EBA's feedback.
- 9.2: Authorities may submit evaluation forms to EBA until December 31, 2019, if they have consulted EBA.
- 9.3: Negative evaluations must be provided for all rejected exemption requests.
- 9.4: For PSPs in a group operating across multiple member states, each competent authority must inform the others if it denies an exemption and provide the rationale.
Appendix 1 – Evaluation Form
| Field | Description |
|---|---|
| 1) | Member State |
| 2) | Name of the competent authority |
| 3) | Confirmation that the competent authority has followed Guideline 9.4 (if applicable) |
| 4) | Contact person |
| 5) | Date of submission to EBA |
| 6) | Name(s) and identification number(s) of the payment service provider(s) |
| 7) | Type(s) of payment service provider(s) |
| 8) | Competent authority's decision |
| 9) | Reason for any rejection of the exemption request |
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载