News · 2022-08-28
MaSI
Specific problems for payment providers when applying internal corporate policies to external partner companies
Specific problems for payment providers when applying internal corporate policies to external partner companies
Due to the increasing complexity of financial solutions offered, new regulations for financial markets cover more and more areas, such as payment transactions. Developments in digital banking and e-commerce forced the European Parliament to vote on the PSD (Payment Services Directive) and PSD 2 directives. The so-called PSD 21 deals with increased security in payment transactions. This is a major step towards deeper integration in the internal payment market. As PSD 2 is set to enter into force in 2018, some authorities have already issued documents specifying minimum requirements for internet payments based on PSD 1. Examples are EBA (European Banking Authority) guidelines (based on SecurePay Forum recommendations) and MaSI (Minimum Requirements for the Security of Internet Payments) 2 issued by BaFin, which enable the implementation of the EBA guidelines in Germany.
MaSI consists of 14 parts specifying key requirements for payment service providers (PSPs). These include governance, risk assessment and management, customer identification, and protection of sensitive payment data. Even a brief look at the MaSI document leads to the conclusion that the new requirements enforce a broader framework extending far beyond the PSP corporate landscape. Such topics include, for example, cooperation with e-merchants (Part 3 of MaSI). According to these regulations, PSPs should monitor the activities of the e-merchant (who stores and processes sensitive payment data) and check whether they have the necessary precautions in place to protect this data. If the e-merchant has no or insufficient security precautions, the PSP should enforce contractual provisions or terminate the contract. Other important recommendations are in Part 12 of MaSI, which defines the requirements for communication with customers and obliges PSPs to provide at least one secure channel to communicate with customers. Additionally, the PSP should oblige the e-merchant to clearly separate payment processes from the e-shop to make it easier for customers to clearly determine whether they are communicating with the payment provider or the e-shop.
Under MaSI, PSPs are also obliged to carry out payment transactions using dedicated software (Part 10). This is also a major challenge for the IT landscape of PSPs.
The topics mentioned above are only selected challenges for PSPs arising from the implementation of PSD 2. If you would like to learn more about how MaSI/PSD affects your payment business, call us or send us an email.
1 DIRECTIVE (EU) 2015/2366 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 November 2015
2www.bafin.de/SharedDocs/Veroeffentlichungen/DE/Rundschreiben/2015/rs_1504_ba_MA_Internetzahlungen.html
See how MeJuvante products can help your team.
Explore the store