Opinion of the European Central Bank of 1 June 2023 on the system security oversight of payment systems (CON/2023/14)
OPINION OF THE EUROPEAN CENTRAL BANK of 1 June 2023 on the system security oversight of payment systems (CON/2023/14) Introduction and legal basis
On 26 April 2023 the European Central Bank (ECB) received a request from the Oesterreichische Nationalbank (OeNB) for an opinion on a draft ordinance on the system security of payment systems (hereinafter the ‘draft ordinance’). The ECB’s competence to deliver an opinion is based on Articles 127(4) and 282(5) of the Treaty on the Functioning of the European Union and the third, fifth and sixth indents of Article 2(1) of Council Decision 98/415/EC , as the draft ordinance relates to the OeNB, payment and settlement systems, and rules applicable to financial institutions that materially influence the stability of financial institutions and markets. In accordance with the first sentence of Article 17.5 of the Rules of Procedure of the European Central Bank, the Governing Council has adopted this opinion.
1. Purpose of the draft ordinance
1.1 According to the Law on the Oesterreichische Nationalbank (hereinafter the ‘Law on the OeNB’), one of the basic tasks of the OeNB is to exercise oversight of payment systems. This oversight includes the examination of the systemic security of payment systems and extends to (1) operators of payment systems governed by Austrian law and (2) payment system participants established in Austria (hereinafter the ‘obliged parties’) . 1.2 The OeNB has broad oversight powers under the Law on the OeNB and can request the obliged parties to provide information and documents on the measures they have taken to ensure the system security of, and security of participation in, a payment system. The OeNB is also entitled to have onsite inspections carried out at the premises of obliged parties and may request them to remedy identified deficiencies within a reasonable period. Further, the OeNB can prohibit the operation of, or participation in, a payment system if the obliged parties do not (fully) comply with their duties under the Law on the OeNB and the draft ordinance. Lastly, the OeNB is entitled to publish, in the Official Gazette of the Wiener Zeitung or in any other official gazette with nationwide circulation, the supervisory measures it has imposed.
1.3 Pursuant to the Law on the OeNB, the OeNB is entitled to determine by ordinance the content of recommendations of the ECB and of the Basel Committee on Payment and Settlement Systems (now the Committee on Payment and Market Infrastructures), which constitute international principles for the systemic security of payment systems, as binding in the area of payment system oversight . The draft ordinance is the first regulation issued by the OeNB based on this competence and aims to implement the Committee on Payment and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) principles for financial market infrastructures (hereinafter the ‘CPMI-IOSCO principles’) in a legally binding ordinance. 1.4 The OeNB found during its oversight activities that the operators of and participants in payment systems are sometimes not fully aware of the requirements for ensuring the system security of payment systems. Thus, the draft ordinance seeks to increase the transparency of these requirements, primarily for the obliged parties. 1.5 Against this backdrop, the draft ordinance sets out the requirements for obliged parties that are used by the OeNB to verify payment system security. The OeNB can explicitly stipulate further requirements by exercising its oversight powers under the Law on the OeNB. However, the draft ordinance also proposes that the checks to be carried out by the OeNB should depend on the size and systemic relevance of the obliged parties, as well as on the type, scope and complexity of their transactions . Thus, depending on the structure of the payment system, not all the sections of the draft ordinance need apply. 1.6 Under the draft ordinance, payment system operators are required to notify the OeNB within two weeks of the taking-up and termination of their operation, the participants in their payment systems and any changes in this regard . Payment system operators must also notify the OeNB of severe security and operational incidents using a standardised template . 1.7 Legal framework and organisational requirements The draft ordinance proposes that payment systems should have a solid, clear, transparent and enforceable legal basis for all of their essential activities . Further, the management structures of a payment system should be regulated in a clear and transparent manner in order to promote the security and effectiveness of the payment system . 1.8 Risk management The draft ordinance proposes that a payment system should have a robust risk management to manage legal, credit, liquidity, operational and other risks . The risk management is described in more detail for the risk categories mentioned. In particular, a payment system should ensure the effective monitoring and management of its credit risk exposures to participants or those credit risk
exposures arising from payment, clearing and settlement processes of the payment system . A payment system should therefore also request collateral with low credit, liquidity and market risks to secure its own and participants’ credit risk exposures . For the effective management of liquidity risks, a payment system must have sufficient liquid funds available in all currencies that are relevant to the payment system in order to fulfil any payment obligations on the same day or at the latest on one of the following days . It must also ensure that general commercial risks are identified and that sufficient liquid net assets are available to allow transactions and services to continue in the event of a loss . A payment system must furthermore, through the use of appropriate systems, processes and controls, identify internal and external factors that could give rise to operational risks and limit their effects . Lastly, for a payment system linked to one or other payment systems, the associated risks must be identified, monitored and controlled . 1.9 Settlement The draft ordinance proposes that a payment system should ensure clear and irrevocable settlement by the end of the value date at the latest and, where necessary, offer irrevocable settlement on the same day or in real time . Further, cash settlement on behalf of a payment system should take place via central bank accounts depending on availability and practicability . Lastly, if a payment system settles transactions from which multiple obligations arise, such as securities or foreign exchange transactions, it should eliminate settlement risk by making the final settlement of one obligation conditional on the final settlement of the other obligation . 1.10 Rules for participant default The draft ordinance proposes that a payment system should establish effective and clearly defined rules for participant default. This would enable that payment system to limit losses and liquidity shortfalls in good time while meeting its obligations . 1.11 Investment policy Currently, there is no express binding requirement for a payment system to have an investment policy. Therefore, the draft ordinance proposes that a payment system should protect its own assets and its participants’ assets and minimise the risk of loss and/or delayed access to these assets. The draft ordinance also proposes that a payment system should invest its funds in instruments with minimal credit, market and liquidity risks .
1.12 Participant conditions The draft ordinance proposes that a payment system should have objective, risk based and publicly accessible participant criteria that allow fair and open access . Further, a payment system should identify, monitor and control significant risks linked to an indirect or tiered participant structure . Regarding the participants of a payment system, the draft ordinance also proposes that a payment system should meet its requirements, and the markets that it serves, efficiently and effectively . 1.13 Communication processes and publications Lastly, the draft ordinance proposes that a payment system should use the relevant internationally recognised communication processes and standards that enable their use to improve the efficiency of payments, clearing, settlement and recording . A payment system should also have clear and comprehensive rules and processes. These serve to make sufficient information available to give participants a precise understanding of the risks, fees and other major costs that arise through participation in a payment system. All relevant rules and processes should be disclosed in this regard .
2. General observations
2.1 The ECB welcomes the draft ordinance, which aims to achieve alignment with the CPMI-IOSCO principles. The ECB also welcomes the OeNB’s intention of supporting its role as overseer of payment system security by increasing transparency regarding the binding requirements for obliged parties. The draft ordinance will thus facilitate the consistent and harmonised application by OeNB of Eurosystem standards when conducting its oversight of payment systems in Austria. 2.2 The ECB understands that the draft ordinance, due to its broad definition of ‘payment systems’, also applies to Austrian prominently important retail payment systems and other retail payment systems. The ECB understands that the OeNB continues to apply the Eurosystem’s revised oversight framework for retail payment systems and oversight expectations for links between retail payment systems that have been implemented by the Eurosystem for non-systemically important retail payment systems operating in the euro area. 2.3 The ECB notes that the CPMI-IOSCO principles have been supplemented by the CPMI-IOSCO’s guidance on cyber resilience for financial market infrastructures , which the ECB has operationalised in its cyber resilience oversight expectations for financial market infrastructures .
The ECB understands that the OeNB already applies this guidance for its oversight activities in the area of cyber resilience as it forms part of the CPMI-IOSCO principles. This understanding is supported by section 1(3) of the draft ordinance, according to which the OeNB may stipulate further requirements by exercising its oversight powers under section 44a of the Law on the OeNB. 2.4 The ECB understands that the draft ordinance is exclusively concerned with payment systems governed by Austrian law or registered in Austria and that it does not interfere with the implementation of ECB and Eurosystem oversight policy for payment systems and payment instruments, as set out in Regulation (EU) No 795/2014 of the European Central Bank (hereinafter the ‘SIPS Regulation’) . The only systematically important payment system (SIPS) in Austria is the Austrian component in TARGET. However, the ECB understands that this component is not regulated by the draft ordinance because under the SIPS Regulation, which is directly applicable, the ECB is responsible for overseeing TARGET, which also encompasses the Austrian component in TARGET. The ECB further understands that if a SIPS were to emerge in Austria in the future, it would be regulated by the SIPS Regulation, given the supremacy of Union law, and especially the principle of priority of application.
This opinion will be published on EUR-Lex.
Done at Frankfurt am Main, 1 June 2023.
[signed]
The President of the ECB
Christine LAGARDE
Fotnoter
- Council Decision 98/415/EC of 29 June 1998 on the consultation of the European Central Bank by national authorities regarding draft legislative provisions (OJ L 189, 3.7.1998, p. 42). 2 See section 44a(1) of the Law on the OeNB.
- 3 See section 44a(3) of the Law on the OeNB. 4 Available on the Bank for International Settlements’ website at www.bis.org. 6 See section 4(1) of the draft ordinance. 7 See Annex 1 of the draft ordinance.
- 11 See section 8 of the draft ordinance. 12 See section 9 of the draft ordinance. 13 See section 10 of the draft ordinance. 14 See section 15 of the draft ordinance. 15 See section 17 of the draft ordinance. 16
- 22 See section 18 of the draft ordinance. 23 See section 19 of the draft ordinance. 24 See section 21 of the draft ordinance. 25 See section 22 of the draft ordinance. 26 See section 23 of the draft ordinance. 27 Eurosystem, ‘Revised oversight framework for retail payment systems’, February 2016, available on the ECB’s website at www.ecb.europa.eu. 28 Eurosystem, ‘Oversight expectations for links between retail payment systems’, 29 November 2012, available on the ECB’s website. 29 Committee on Payments and Market Infrastructures of the Bank for International Settlements and the International Organization of Securities Commissions, ‘Guidance on cyber resilience for financial market infrastructures’, CPMI Papers No 146, 29 June 2016, available on the Bank for International Settlements’ website. 30 ‘Cyber resilience oversight expectations for financial market infrastructures’, December 2018, available on the ECB’s website.
- 31 Regulation (EU) No 795/2014 of the European Central Bank of 3 July 2014 on oversight requirements for systematically important payment systems (ECB/2014/28) (OJ L 217, 23.7.2014, p. 16).