1. Vellykket implementering av
PSD 2 i Norge
Oslo Startup Day: PSD 2
Oslo Fintech Hub
Olav Johannessen
Seksjonsleder tilsyn IT og betalingstjenester
Finanstilsynet
2. Speaking notes
• Thank you for the opportunity to say some few words about PSD 2 in this early mark of EU's tomorrow
introduction of PSD 2
Oslo Startup Day: PSD 2 12. jan 20182
3. PSD 2 pilarer / hovedhensikter
Intensjonen med PSD 2 - Hvordan ses dette på i Norge
Oslo Startup Day: PSD 2 12. jan 2018
3
Anvendelsesområde
Innovasjon
Sikkerhet
Tilsyn
Forbrukerbeskyttelse
Bedreklageprosedyrer
PSD 2 skal
Fremme innovasjon gjennom økt konkurranse
mellom eksisterende og nye aktører
Åpne opp for flere aktører som betalingstjeneste
tilbydere
Gi bredere anvendelsesområde
Bidra til forsterket tilsyn og tilsynssamarbeid ved
grensekryssende virksomhet
Forsterke forbruker beskyttelsen
Bidra til høyere sikkerhetskrav for alle
elektroniske betalinger og alle betalingstjeneste
tilbydere
Nivå 2 lovverk (RTS)
PSD 2’s pilarer
PSD2
4. Speaking notes
• When marking the introduction of PSD 2, one have to mention the main purpose of the directive
• PSD 2 should
• Foster innovation through increased competition between existing and new players
• Open up for more actors as payment service providers
• Provide a wider scope
• Contribute to enhanced supervision and supervisory cooperation in cross-border activities
• Enhance consumer protection
• Contribute to higher security requirements for all electronic payments and all payment service providers
• When it comes to higher security requirements I would like to mention a few points
• PSD 2 is assumed to contribute to reduce Card-Not-Present losses since there is assumed to be a shift from use of paymentcards
to account transfers,. And a reduced use of paymentcards is then expected to reduce losses on fraud.
• Strong authentication, is already practiced over many years in Norway, and is also set out in the regulations for payment services
since 1. of January 2016. So it is nothing new for the Norwegian market.
• With regard to new players, a number of different business models, technological methods of interaction and interaction structures
already exist. The Italian central bank has made an assessment where they found at least 256 different models.
•
Oslo Startup Day: PSD 2 12. jan 20184
5. Mulig tidslinje for PSD 2 og RTS autentisering
og kommunikasjon inn i norsk rett
Oslo Startup Day: PSD 2 12. jan 20185
Nov
2015
Jan
2016
Adopsjon Ikraft-
treden
Jan
2018
AnvendelsePSD 2
EØS-
behandling ?
Fastsatt AnvendelseHøring 1
Jan
2017
Anvendelse
Sep ?
2019
EU-
behandlet
Nov
2017
AnvendelseFastsatt
?
RTS
SCA & CSC
PSD 2 inn i
norsk rett
RTS
SCA & CSC inn
i norsk rett
EØS-
behand
-ling ?
Øvrige RTS og
Guidelines PSD 2
inn i norsk rett
Fastsatt
kommisjonen
Høring 2
Feb
2018
?
?
6. Speaking notes
• I will now give you, as seen pr today, a view on a possible timeline for PSD 2 and the RTS for
authenication and communication to enter into force in Norway
• First, you will see the timeline for PSD 2 and the possible timeline for the RTS in EU
• And then a guess for a possible timeline for PSD 2, the RTS for SCA & CSC and all the other RTSes and
gudelines in Norway
• PSD 2 has yet not been processed through the EAA and there is still not taken any decision about early
implementation into Norwegian law
• And I have, ufortunately, no secret to reveal
• As everyone is probably more or less familiar with, it will be a transition period after PSD 2 will apply, where
existing institutions are given a certain amount of time to reauthorize themselves
• It will also in the period from PSD 2 takes effect to the RTS for SCA & CSC enters into force, be a transition period
where special rules apply and where EBA has, on these, published an opinion.
• As a consequence, with regard to the new payment services
• Norway / EEA is out of sync with the European regulations
• Norwegian entities will not be able to get authorization and can not perform cross-border business unless they establish
agreements with actors
• Foreign institutions can not perform cross-border business under PSD 2 unless they establish necessary agreements
• I would also like to mention that about 50% of EU / EEA countries are somewhat delayed in taking PSD 2 into
national legislation, including our neigbour Sweden, assuming this will happen in May 2018. But all EU-states
seems to be in place during this spring
• In most countries, except in the UK, so far, there have not been many request by actors for license.
• Sweden may well be said to be the country in the EU today with most significant players already providing the new
services that now are being regulated.
Oslo Startup Day: PSD 2 12. jan 20186
7. Tilbydere av betalingstjenester -
Konsesjonstyper
Bank/kreditt-
institusjon
E-
pengeforetak
Betalings-
foretak
(ordinært)
Betalings-
foretak
(begrenset)
Oslo Startup Day: PSD 2 12. jan 20187
Innskudd etc.
Utstede e-penger
Betalings-
tjenester
Pengeover-
føringer
Betalingsfullmektig
Opplysningsfullmektig
8. Speaking notes
I will now give you an overview of todays licencetypes and the licence landscape when PSD 2 enter into force
First we have payment institutions with limited licence. They can only perform money remittances
Then we have payment institutions with full licence. They can perform all types of payment services.
Then we have e-money institutions which both can perform payment services and issue e-money.
Finally we have credit institutions, which can perform both payment services, issue e-money and hold funds.
We use to say that the more extensive license "eat up" the smaller ones, so the institustions only need the
most comprehensive license to deliver all the services down the "triangle"
When PSD 2 enter into force, we will get two new types of payment institutions, namely payment initiation
institutions and account information institutions. As you will see, the are regarded to have a licence with rights
somewhere between payment institutions with limited licence and payment institutions with full licence. And as
the picture shows, institutions with a higher licence type are allowed to perform the two new payment types,
payment initiation and account information
Oslo Startup Day: PSD 2 12. jan 20188
9. PSD 2 mandater EBA
RTS on Strong Authentication & Secure Comms. under PSD2
RTS on Central Contact Points under PSD2
GL on Professional Indemnity Insurance under PSD2
RTS & ITS on EBA Register under PSD2
GL on Authorisation of payment institutions under PSD2
GL on Operational & Security Measures under PSD2
GL on Complaints Procedures by CAs under PSD2
RTS on Passporting Notifications under PSD2
GL on Incident Reporting under PSD2
RTS on home-host coordination under PSD2
GL on fraud reporting under PSD2
Leveranser
Milepæler Milestone 2:
EBA has published
CP with draft GL/TS
Milestone 3:
EBA has published
Final draft TS or Final GL
Milestone 4:
EBA has published GL
Compliance table
or Commission has published TS
in OJ
2018Q1
2018Q1
2017Q4
2018Q1
2017Q4
2018Q1
2017Q4
Oslo Startup Day: PSD 2 12. jan 2018
5
7
9
8
11
6
3
10
4
2
1
9
2018Q1
2018Q1
com dep
com dep
com dep
?
10. Speaking notes
• This slides give you a view on the status for all the mandates given EBA for developing either regulatory
standards or guidelines.
• As you will see, this task is more or less finished from EBA which already have published some of the in their
open journal and which applies from tomorrow. The other GLs will be published during the first quarter of this
year except the GL on fraud reporting which is still under progress.
• One regulatory standard is already published in EUs Open journal, the other regulatory standards are submitted
to the Commission which have the final decision when it comes to the provisions and when to enter into force.
• In addition EBA has published an opinion on the transition from PSD 1 to PSD 2
Oslo Startup Day: PSD 2 12. jan 201810
11. Nye aktører – endret risiko?
• Konsesjons- / Tillatelseskrav, strenge krav som skal oppfylles
• Tilsyn
• Forbedret grensekryssende samarbeid
– Et kontaktpunkt hos tilsynsmyndighetene
– Mulighet for sentralt kontaktpunkt for agenter – (10 / omsetning 3 mill EUR / 100 000 transaksjoner)
– Initiering av tilsyn og tilsynsdeltakelse
– Varsling mistanke om overtredelse
– Statistisk og aktivitetsrapportering
Oslo Startup Day: PSD 2 12. jan 201811
Omfattende krav til den operasjonelle virksomheten
Betalings-
foretak
Betalings-
fullmektig
Opplysnings-
fullmektig
Forretningsplan og tjenestene som skal tilbys V V V
Hvordan midler skal sikres V
Hvordan virksomheten skal styres og dens kontroll ordninger V V V
Hvordan sikkerhetshendelser skal overvåkes og håndteres V V V
Håndteringen av sensitive betalingsdata V V V
Beredskapsplaner V V V
Operative, mislighets og transaksjons statistikker V V
Sikkerhetspolicy for tjenestene og IT-virksomheten V V V
Hvitvaskingsrutiner V V
Kapitalkrav / Forsikrings-/garantiordninger V V V
12. Speaking notes
• Well, will the new players create changes in the risks in the payment landscape or create new risks?
• First I will pinpoint that they will need licence and they will not come in touch with or hold funds – which will still
be on hand of the banks
• There is both stricter and more extensive requirements for the operational business under PSD 2 than under
PSD 1 and they have to fulfill almost the same obligations as existing payment institutions,
• They will be supervised, and I have to emphasize that it is the FSAs duty to supervise them, no one else
• There will be improved cross-border supervisory cooperation
• New players can be said to have a higher risk since they are newcomers and the field for them may be new.
But on the other hand, with new technology they might represent a lower operational risk
• So, al in al, We assume that the risk in general not will increase much, but of course - more players and longer
value chains will totaly probably give more risks
Oslo Startup Day: PSD 2 12. jan 201812
13. Vellykket implementering av PSD 2
• Konsesjonsbehandling iht fastsatt regelverk (mer omfattende enn for PSD 1)
• God kommunikasjon med næringen, både eksisterende aktører og nye aktører når det gjelder
– Informasjon om regelverket, konsesjonskravene og konsesjonsprosessen
– Forståelse av regelverket
– Oppmuntre til å tilpasse seg fastsatt regelverk (jo før jo bedre), selv om det ennå ikke har trådt i
kraft (særlig RST SCA & CSC), ref EBA Opinion
– Forventet etterlevelse av regelverket
• Sikre at fastsatt regelverk etterleves både ifm
– Konsesjonsgivningen
– Løpende oppfølging av foretakene
– Tilsyn
– Mao – sikre at kontotilbydere ivaretar sine forpliktelser og at aktører som vil tilby de nye
betalingstjenestene basert på rett til tilgang til betalingskonto ivaretar sine forpliktelser
• Ivareta forpliktelsene som følger av regelverket
• Sikre best mulige rapporteringsløsninger for påkrevd rapportering
• Samhandle med medlemslandene i EU, særlig de nordiske og bidra til et forbedret
grensekryssende samarbeid
• Bidra til «regulatory convergence» innenfor EU/EØS
Oslo Startup Day: PSD 2 12. jan 201813
14. Speaking notes
So how will the FSA contribute to a successful implementations of PDS 2
We will ensure licensing in accordance with established regulations (as mentioned, it’s more extensive than for
PSD 1)
We will strive for good communication with the industry, both existing actors and new actors when it comes to
Information about the regulations, the license requirements and the licensing process
The understanding of the regulations
Encourage adaptation to established rules (even before the better), although they has not yet come into force (especially
RST SCA & CSC), ref EBA Opinion
Express FSAs expectation of compliance with the regulations
Ensure that regulations are complied with both with regards to
The licensing
Ongoing follow-up of the institutions
Supervision
With other words - Ensure that account providers fulfill their obligations and that actors who want to offer the new payment
services, based on the right to access payment accounts, fulfill their obligations
Take care of the supervisory obligations arising from the regulations
Ensure the best possible reporting solutions for required reporting
Collaborate with member countries in the EU, especially the Nordic countries, and contribute to improved cross-
border cooperation
Contribute to regulatory convergence within the EU / EEA
And last, but not least, ensure level playing filed based on the given regulation
Oslo Startup Day: PSD 2 12. jan 201814
16. Speaking notes
Finally I will mention that the FSA has, on our web sites, established a site to guide FinTechs, you will find
it under the menu
Oslo Startup Day: PSD 2 12. jan 201816