Advanced Search Options : ❯
Regulation 24 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must comply with AML, CTF and KYC requirements and applicable anti-money laundering law. Providers using authorised agents must maintain updated agent lists, incorporate agents into AML/CTF programmes, and monitor compliance. Providers remain responsible and accountable for agents' transactions and actions. Transaction logs must be retained for at least ten years and made available for regulatory scrutiny when required.
Regulation 23 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must safeguard Applicable Funds, including through compliance with directions specified in Schedule VI. Applicable Funds must be kept segregated at all times from every other type of fund held by the provider. The duty requires continuous separation of Applicable Funds from all other funds throughout payment-service operations.
Regulation 22 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must maintain complete and up-to-date records of each Third-Party Service Relationship identified under the risk-management process in sub-regulation (1) of regulation 18. The record-keeping duty applies to all identified relationships on an ongoing basis, requiring relationship records to remain complete and current after identification. This obligation covers Third-Party Service Relationships identified through the prescribed risk-management process under regulation 18.
Regulation 21 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must ensure that Third-party Service Providers maintain clearly defined incident-management processes covering identification, investigation, remediation and timely notification. Notification must be given to the Payment Service Provider when an incident affects the Third-party Service Provider's ability to deliver agreed-upon services. Responsibility rests with the Payment Service Provider to secure these operational and reporting arrangements within third-party service relationships.
Regulation 20 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must identify, document and, where practically feasible, test exit strategies for Third-party Service Relationships involving critical services. Exit planning must address planned service migration and adverse events, including legal or contractual breaches, deteriorating service quality, provider governance, financial, resilience or risk-management weaknesses affecting critical services, and extended disruptions that cannot be managed through other business-continuity measures.
Regulation 19 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must conduct proportionate planning and due diligence before engaging Third-party Service Providers for critical services. The assessment covers operational capability, financial soundness, risk controls, ICT and cyber-security risks, supply-chain dependencies, conflicts, regulatory-compliance capability and substitutability. Critical services require legally binding arrangements, including information-sharing obligations with the Authority, and ongoing monitoring of the provider's contractual performance.
Regulation 18 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must use a risk-based framework to identify critical services received or planned to be received from Third-party Service Providers. Assessment is required at the commencement of operations and at regular intervals. Criticality must consider the service's financial, operational and strategic importance, acceptable disruption tolerance for dependent critical operations, the nature of shared data or information, and the ease or lack of substitutability of the service.
Regulation 17 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must maintain a Board-reviewed risk-management policy with policies, procedures and systems to identify, measure, monitor and manage risks arising from payment services. They must establish a robust operational risk-management framework with appropriate systems, policies, procedures and controls. Providers establishing links with Payment Systems must identify, monitor and manage link-related risks.
Regulation 16 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must document governance arrangements covering Board and senior management functions, reporting lines, ownership, internal governance, risk management, internal controls, appointment procedures, and performance accountability. Activities beyond Payment Services require prior permission and specified conditions. Providers must formulate clear service rules and procedures and provide users sufficient information to understand applicable risks, fees, and other material costs.
Regulation 15 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must begin operations within six months from issuance of the Certificate of Authorisation. An extension application requires board authorisation, timely submission, reasons for delay, the period sought, and remedial steps. Where satisfied that commencement cannot occur within the stipulated period, the Authority may grant one extension of up to three months.
Regulation 14 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Security deposits furnished by Payment Service Providers may be appropriated following surrender or revocation of authorisation to satisfy outstanding sums claimed by Payment Service Users who are customers. Release of the deposit or any balance requires that no outstanding customer claim exists and that all surrender conditions have been met. Release for legitimate outstanding claims or dues is to occur only after one year from approval of surrender or revocation of authorisation.
Regulation 13 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Surrender of authorisation by a Payment Service Provider requires an application to the Authority in compliance with prescribed conditions and the Schedule III format. Permission depends on satisfaction that surrender is unlikely to materially adversely affect the IFSC financial ecosystem or Payment Service Users' interests. Permission may be subject to appropriate conditions, and a written order may specify the date from which authorisation ceases to have effect.
Regulation 12 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Authorisation may be revoked where a Payment Service Provider breaches authorisation conditions, applicable regulatory requirements, or Authority orders or directions, or carries on payment services prejudicially to Payment Service Users' interests. An order revoking authorisation may be issued only after the concerned provider receives a reasonable opportunity of hearing.
Regulation 11 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Refusal of authorisation follows communication of deficiencies and an opportunity to rectify them within thirty days. Failure to rectify requires refusal only after the applicant has been given a reasonable opportunity of being heard. An applicant may withdraw before authorisation is granted. Applications refused for unrectified deficiencies or withdrawn may be replaced by a fresh application after six months, calculated from communication of refusal or withdrawal respectively.
Regulation 10 of the International Financial Services Centres Authority (Payment Services) Regulatio...
The Authority may grant a Certificate of Authorisation to an eligible applicant complying with prescribed conditions, subject to further conditions considered appropriate. The certificate remains valid unless revoked or surrendered. A Payment Service Provider may be required to maintain a security deposit, must identify a consenting IFSC Banking Unit or IFSC Banking Company as its Nodal Bank, and must intimate material changes to previously furnished information. Conditions for commencing or continuing Payment Services may be modified.
Regulation 9 of the International Financial Services Centres Authority (Payment Services) Regulation...
In-principle approval may be issued where an application prima facie satisfies authorisation conditions, subject to further conditions specified by the Authority. It does not confer an automatic right to authorisation and remains subject to the Authority's discretion. Applicants must disclose ownership or control changes during its validity. Such changes require review of the approval decision, communication of the outcome, and a reasonable opportunity of hearing before revocation.
Regulation 8 of the International Financial Services Centres Authority (Payment Services) Regulation...
Payment Service Provider authorisation depends on relevant experience, adequate operational infrastructure, compliance with net-worth requirements and financial soundness. The applicant and relevant persons must meet fit and proper requirements, with prior refusals of authorisation and proceedings for breach of law also considered. Adequate protection of Payment Services Users, including through governing terms and conditions, is required.
Regulation 7 of the International Financial Services Centres Authority (Payment Services) Regulation...
Fit and proper requirements apply to applicants seeking authorisation as Payment Service Providers and to authorised Payment Service Providers. Directors, Key Managerial Personnel, and persons exercising control, collectively termed Relevant Persons, must meet the standards in Schedule II. The Authority may evaluate any Relevant Person during authorisation processing or later. Where its evaluation differs from that of an applicant or provider, the Authority's evaluation prevails.
Regulation 6 of the International Financial Services Centres Authority (Payment Services) Regulation...
Payment Service Providers must maintain the minimum net worth prescribed in Schedule V on an ongoing basis. Additional net worth requirements resulting from review must be met within 180 days from communication. The Authority may establish a framework for prompt corrective action where net worth falls below applicable requirements and may require net worth stress tests to assess capacity to withstand adverse economic scenarios.
Regulation 5 of the International Financial Services Centres Authority (Payment Services) Regulation...
Authorisation of payment service providers requires an applicant seeking authorisation to be incorporated as a company and to maintain its registered office in an International Financial Services Centre.