Schedule 8, Part 2, paragraph 5(29)
In Schedule 1 (information to be included in or with an application for authorisation)— after paragraph 5 insert— A description of the applicant's procedure for monitoring, handling and following up security incidents and security-related customer complaints, including where appropriate an incidents reporting mechanism which takes account of the notification obligations under regulation 99 of the Payment Services Regulations 2017. A description of the applicant's process for filing, monitoring, tracking and restricting access to sensitive payment data. A description of the applicant's business continuity arrangements, including a clear identification of the critical operations, effective contingency plans, and a procedure for regular testing and reviewing of the adequacy and efficiency of such plans. A description of the principles and definitions used by the applicant in collecting statistical data on performance, transactions and fraud. A statement of the applicant's security policy, including— a detailed risk assessment in relation to the payment services to be provided, including risks of fraud and illegal use of sensitive and personal data, and a description of— the applicant's security control and mitigation measures to provide adequate protection to users against the risks identified, how such measures ensure a high level of technical security and data protection, including such security and protection for the software and IT systems used by the applicant and any undertakings to which the applicant outsources any part of its operations, and where appropriate, the applicant's measures to comply with regulation 98(1) of the Payment Services Regulations 2017, taking into account any guidelines issued by the European Banking Authority under Article 95(3) of the payment services directive. in paragraph 7, after “branches and” insert “ the off-site and on-site checks that the applicant undertakes to perform on them at least annually, ”; in paragraph 13, after “5” insert “ , 5A ”; and after paragraph 13, insert— In the case of an applicant which proposes to provide payment initiation services or account information services, the professional indemnity insurance or comparable guarantee which it holds in relation to such services.
← 28 · All articles · 30 →
Source: legislation.gov.uk · retrieved 2026-09-04