[eu]cite

Home› Payment Services› ZAG-EN

Part 10 · Common Provisions for All Payment Service Providers  ›  Chapter 3 · Risks and Reporting of Incidents › Section 53

Management of Operational and Security Risks

(1) A payment service provider must establish, maintain and apply appropriate risk mitigation measures and control mechanisms to manage the operational and security risks connected with the payment services it provides. This includes effective procedures for handling operational disruptions, including for detecting and classifying major operational and security incidents. For payment service providers within the meaning of section 1(1), first sentence, no. 1, 2 or 3, the first and second sentences apply without prejudice to the provisions of Chapter II of Regulation (EU) 2022/2554.
(2) A payment service provider must provide BaFin, once a year, with an up-to-date and comprehensive assessment of the operational and security risks connected with the payment services it provides, and of the adequacy of the risk mitigation measures and control mechanisms it has put in place to manage those risks. BaFin may require a payment service provider to provide the assessment under the first sentence at shorter intervals.

←→ also move between sections