Opinion of the European Central Bank of 15 November 2021 on the oversight of payment and securities settlement systems (CON/2021/33)
OPINION OF THE EUROPEAN CENTRAL BANK of 15 November 2021 on the oversight of payment and securities settlement systems (CON/2021/33) Introduction and legal basis
On 8 October 2021 the European Central Bank (ECB) received a request from Lietuvos bankas for an opinion on a draft resolution on the Description of the Guidelines for the Oversight of Payment and Securities Settlement Systems (hereinafter the ‘draft resolution’). The ECB’s competence to deliver an opinion is based on Articles 127(4) and 282(5) of the Treaty on the Functioning of the European Union and the second, third, fifth and sixth indents of Article 2(1) of Council Decision 98/415/EC , as the draft resolution relates to means of payment, Lietuvos bankas, payment and settlement systems, and rules applicable to financial institutions insofar as they materially influence the stability of financial institutions and markets. In accordance with the first sentence of Article 17.5 of the Rules of Procedure of the European Central Bank, the Governing Council has adopted this opinion.
1. Purpose of the draft resolution
1.1 The draft resolution recasts the framework for the conduct of payment and securities settlement systems oversight by Lietuvos bankas, which was approved by the Board of Lietuvos bankas in 2014 and entered into force on 1 January 2015. 1.2 The draft resolution aims to align the existing framework for the conduct of payment and securities settlement systems oversight with the relevant regulatory developments introduced since 2015, in particular the Union legal acts concerning the oversight of the payment and securities settlement systems (Regulation of the European Central Bank (EU) No 795/2014 (ECB/2014/28) and Regulation (EU) No 909/2014 of the European Parliament and of the Council ), as well as other documents approved by the ECB on the same subject matter . In addition, the draft resolution aims to introduce other amendments which follow from the experience gained by Lietuvos bankas when implementing the provisions of the oversight framework.
1.3 The draft resolution sets out measures that Lietuvos bankas takes in performing payment and securities settlement systems oversight tasks, namely: the registration, assessment and monitoring of systems. The draft resolution also contains provisions as regards the collection and sharing of statistical data and information related to major security incidents impacting these systems with other authorities and the ECB. 1.4 Under the draft resolution, the assessment of payment systems has been aligned with the Revised Oversight Framework for Retail Payment Systems and the Revised Assessment Methodology for Payment Systems approved by the ECB, as well as with other ECB documents applicable to the oversight of payment systems. 1.5 For the assessment of securities settlement systems, the draft resolution now refers, among other things, to Regulation (EU) No 909/2014. For the purposes of this Regulation, Lietuvos bankas is the designated competent authority , responsible for performing the duties under this Regulation with regard to the authorisation and supervision of central securities depositories (CSDs) established in Lithuania. Furthermore, Lietuvos bankas and the Eurosystem qualify as relevant authorities for CSDs under this Regulation. 1.6 The draft resolution contains an obligation for systemically important payment system operators to inform Lietuvos bankas about major incidents occurring in the system. To this end, the draft resolution describes the procedure for the payment system operator to inform Lietuvos bankas of a major incident and sets out criteria identifying major incidents. Likewise, under the draft resolution securities settlement system operators must inform Lietuvos bankas of an incident occurring in their systems. 1.7 Furthermore, the draft resolution details the information to be provided by the payment system operator before the implementation of major changes. A major system change is defined as a change in the functionality of a system that significantly alters the settings of the system or adds new core business functions. 1.8 Finally, the draft resolution provides that as part of the monitoring of systems, Lietuvos bankas arranges bilateral regular and/or thematic meetings with system operators for the exchange of information on ongoing or planned system changes, system oversight plans, potential regulatory changes, and other information related to system operation and oversight.
2. General observations
2.1 The ECB welcomes the draft resolution, which aims to (1) achieve alignment with the existing Eurosystem oversight framework, Regulation (EU) No 795/2014 (ECB/2014/28) on oversight requirements for systemically important payment systems and policies for the conduct of oversight of payment and securities settlement systems, as well as to ensure consistency with Regulation (EU) No 909/2014; (2) strengthen the operational and cyber resilience of the payment and
securities settlement systems operating in Lithuania; and (3) support the role of Lietuvos bankas as an overseer of these systems. 2.2 Furthermore, the ECB welcomes the alignment and implementation in the oversight activities of Lietuvos bankas with the Eurosystem’s major incident reporting framework and with the criteria described in the framework and respective oversight guide for systemically important payment systems and retail payment systems. 2.3 The ECB also welcomes the alignment of the draft resolution with the CPMI-IOSCO’s Guidance on cyber resilience for financial market infrastructures , which the ECB has operationalised in its Cyber Resilience Oversight Expectations for financial market infrastructures (CROE) . The ECB suggests that any guidance on cybersecurity developed under the draft resolution should be aligned with the CROE. 2.4 In addition, the ECB recommends that the draft resolution follows the ECB policy regarding the identification and oversight of critical service providers of financial market infrastructures . 2.5 Finally, the ECB takes note that the draft resolution aims to ensure consistency with the requirements laid down in Regulation (EU) No 909/2014. To that end, the ECB understands that no requirements that the draft resolution sets out for CSDs and the securities settlement systems that they operate refer to those aspects that Regulation (EU) No 909/2014 has already harmonised at Union level, except for the specific cases provided for in this Regulation.
This opinion will be published on EUR-Lex.
Done at Frankfurt am Main, 15 November 2021.
[signed]
The President of the ECB
Christine LAGARDE
Fotnoter
- 1 Council Decision 98/415/EC of 29 June 1998 on the consultation of the European Central Bank by national authorities regarding draft legislative provisions (OJ L 189, 3.7.1998, p. 42).
- 3 Regulation (EU) No 909/2014 of the European Parliament and of the Council of 23 July 2014 on improving securities settlement in the European Union and on central securities depositories and amending Directives 98/26/EC and 2014/65/EU and Regulation (EU) No 236/2012 (OJ L 257, 28.8.2014, p. 1). 4 See ECB/Eurosystem Revised Oversight Framework for Retail Payment Systems, February 2016; ECB/Eurosystem Revised Assessment Methodology for Payment Systems, June 2018. Both these documents are available on the ECB’s website at www.ecb.europa.eu.
- 5 Article 11 of Regulation (EU) No 909/2014 in conjunction with Articles 8(2)(2) and 42(2)(4) of the Law on Lietuvos bankas. 6 Article 12 of Regulation (EU) No 909/2014.
- 8 Committee on Payments and Market Infrastructures of the Bank for International Settlements and the International Organization of Securities Commissions. Available on the Bank for International Settlements’ website at www.bis.org. 9 Cyber resilience oversight expectations for financial market infrastructures (December 2018). can be accessed using the following link: CROE. 10 Eurosystem oversight policy framework, Revised version (July 2016) available on the ECB’s website at www.ecb.europa.eu.