EBA · 2019_5042 Final Q&A

Reporting of PISP transactions

Regulation
Directive 2015/2366/EU (PSD2)
Article
96, para. 6
Topic
Fraud reporting
Submitted by
Competent authority
Submitted
2019-12-12
Answered
2020-07-24
Answer provided by
ESAs (EBA, ESMA, EIOPA)

Question

Should payment initiation service provider (PISP) initiated payments be reported under both Table A (1.1) and Table H (8.x)? More specifically how should these transactions be reported where the customer initiates a payment via a PISP, from their bank account, to one of their payees flagged in the bank’s online channel as “trusted beneficiaries” (Article 13 of the RTS on SCA&CSC).

Background

We would very much appreciate your support on the recording of PISP initiated payments. In principle, PISP initiated payments should be reported by both the ASPSP, under Table A (1.1), and by the PISP that has initiated the transaction, under Table H (see GL 7.6).

Answer

In accordance with Guidelines 7.5 and 7.6 of the EBA Guidelines on fraud reporting under PSD2 (EBA/GL/2018/05) as amended by the EBA Guidelines EBA/GL/2020/01 , payment initiation services providers (PISPs) should report the executed payment transactions and fraudulent transactions they initiated in accordance with Data Breakdown H in Annex 2  of the Guidelines. In addition, credit transfers should also be reported by the account servicing payment service provider (ASPSP) that executed the respective credit transfer in accordance with Guidelines 2.12 and 7.9, under the Data Breakdown A in Annex 2 of these Guidelines. In the submitter’s example, a credit transfer initiated by a PISP, that is subject to the exemption from strong customer authentication under Article 13 of the Commission Delegated Regulation (EU) 2018/389 should be reported: by the ASPSP that executed the credit transfer in accordance with the Data Breakdown A in Annex 2 of the Guidelines (under the rows 1 (Credit transfers); 1.1 (Of which initiated by payment initiation service providers); 1.3 (Of which Initiated electronically); 1.3.1 (Of which initiated via remote payment channel) (assuming the payment is initiated via a remote payment channel); 1.3.1.2 (Of which authenticated via non-strong customer authentication); 1.3.1.2.6 (Trusted beneficiary (Art.13 of the Delegated Regulation)); and by the PISP that initiated the transaction in accordance with the Data Breakdown H in Annex 2 of the Guidelines.

Original source: European Banking Authority, Q&A ID 2019_5042

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.