Advanced Search Options : ❯
Regulation 22 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must maintain complete and up-to-date records of every Third-Party Service Relationship identified under the risk-management identification requirement in sub-regulation (1) of regulation 18. Record maintenance is linked to relationships identified through the prescribed third-party service relationship risk-management framework.
Regulation 21 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must ensure that Third-party Service Providers maintain clearly defined incident-management processes covering identification, investigation, remediation and timely notification. Notification must be given to the Payment Service Provider when an incident affects the Third-party Service Provider's ability to deliver agreed-upon services. Responsibility rests with the Payment Service Provider to secure these operational and reporting arrangements within third-party service relationships.
Regulation 20 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must identify, document and, where practically feasible, test exit strategies for Third-party Service Relationships involving critical services. Exit planning must address planned service migration and adverse events, including legal or contractual breaches, deteriorating service quality, provider governance, financial, resilience or risk-management weaknesses affecting critical services, and extended disruptions that cannot be managed through other business-continuity measures.
Regulation 19 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must conduct proportionate planning and due diligence before engaging Third-party Service Providers for critical services. The assessment covers operational capability, financial soundness, risk controls, ICT and cyber-security risks, supply-chain dependencies, conflicts, regulatory-compliance capability and substitutability. Critical services require legally binding arrangements, including information-sharing obligations with the Authority, and ongoing monitoring of the provider's contractual performance.
Regulation 18 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must use a risk-based framework to identify critical services received or planned to be received from Third-party Service Providers. Assessment is required at the commencement of operations and at regular intervals. Criticality must consider the service's financial, operational and strategic importance, acceptable disruption tolerance for dependent critical operations, the nature of shared data or information, and the ease or lack of substitutability of the service.
Regulation 17 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must maintain a Board-reviewed risk-management policy with policies, procedures and systems to identify, measure, monitor and manage risks arising from payment services. They must establish a robust operational risk-management framework with appropriate systems, policies, procedures and controls. Providers establishing links with Payment Systems must identify, monitor and manage link-related risks.
Regulation 16 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must document governance arrangements covering Board and senior management functions, reporting lines, ownership, internal governance, risk management, internal controls, appointment procedures, and performance accountability. Activities beyond Payment Services require prior permission and specified conditions. Providers must formulate clear service rules and procedures and provide users sufficient information to understand applicable risks, fees, and other material costs.
Regulation 15 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must begin operations within six months from issuance of the Certificate of Authorisation. An extension application requires board authorisation, timely submission, reasons for delay, the period sought, and remedial steps. Where satisfied that commencement cannot occur within the stipulated period, the Authority may grant one extension of up to three months.
Regulation 14 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Security deposits of Payment Service Providers may be appropriated following surrender or revocation of authorisation to discharge outstanding sums claimed by customer Payment Service Users. Release of the deposit or its balance requires that no such customer claims remain outstanding and that all surrender conditions have been fulfilled. Release is subject to a one-year period from approval of surrender or revocation, permitting legitimate outstanding claims or dues to be addressed.
Regulation 13 of the International Financial Services Centres Authority (Payment Services) Regulatio...
A Payment Service Provider may apply to the Authority for surrender of authorisation in accordance with the conditions and format prescribed in Schedule III. Permission depends on satisfaction that surrender is unlikely to materially adversely affect the IFSC financial ecosystem or Payment Service Users' interests. Surrender may be permitted subject to appropriate conditions, and a written order may specify the date from which authorisation ceases to have effect.
Regulation 12 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Authorisation may be revoked where a Payment Service Provider breaches authorisation conditions, applicable regulatory requirements, or Authority orders or directions, or carries on payment services prejudicially to Payment Service Users' interests. An order revoking authorisation may be issued only after the concerned provider receives a reasonable opportunity of hearing.
Regulation 11 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Where authorisation cannot be granted because of deficiencies, the Authority must communicate them to the applicant and allow thirty days for rectification. Failure to rectify leads to refusal, subject to a reasonable opportunity of hearing. An applicant may withdraw an application before authorisation is granted. Following refusal or withdrawal, a fresh application may be submitted only after six months from communication of refusal or the date of withdrawal, respectively.
Regulation 10 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Eligible Payment Service Providers may receive a Certificate of Authorisation subject to conditions determined by the Authority. The certificate remains valid unless revoked or surrendered. Providers may be required to maintain a specified security deposit, identify an IFSC Banking Unit or IFSC Banking Company as Nodal Bank with its concurrence, and disclose material changes in previously furnished information. Conditions for commencing or carrying on Payment Services may be modified.
Regulation 9 of the International Financial Services Centres Authority (Payment Services) Regulation...
In-principle approval for payment service provider authorisation may be issued where an application prima facie meets the conditions for authorisation, subject to conditions imposed before authorisation is granted. It does not create an automatic entitlement to authorisation. Changes in ownership or control must be notified and trigger review, with the outcome communicated to the applicant. Revocation following review requires a reasonable opportunity of hearing before a final decision.
Regulation 8 of the International Financial Services Centres Authority (Payment Services) Regulation...
Payment Service Provider authorisation assessment considers the experience of relevant persons, including existing authorisation for similar services in another jurisdiction; adequate infrastructure and manpower; and compliance with the prescribed net worth requirement. It also considers financial soundness, fit and proper requirements, past refusals of authorisation, pending breach-of-law proceedings, and adequate protection of Payment Services Users' interests through the governing terms and conditions.
Regulation 7 of the International Financial Services Centres Authority (Payment Services) Regulation...
Applicants and Payment Service Providers must ensure that their directors, key managerial personnel, and persons exercising control meet the fit and proper requirements. The Authority may assess any Relevant Person during authorisation processing or at any later time. Where the applicant's or provider's assessment differs from the Authority's assessment, the Authority's assessment prevails.
Regulation 6 of the International Financial Services Centres Authority (Payment Services) Regulation...
Payment Service Providers must continuously maintain the prescribed minimum net worth. The threshold may be reviewed and adjusted to address emerging risks and changes in the financial environment. Any additional net-worth requirement arising from such review must be met within 180 days of communication. Corrective action may apply where net worth falls below applicable requirements, and providers may be required to conduct stress tests of their ability to withstand adverse economic scenarios.
Regulation 5 of the International Financial Services Centres Authority (Payment Services) Regulation...
Every applicant seeking authorisation under regulation 4 must be incorporated as a company and maintain its registered office in an International Financial Services Centre. Company incorporation and an IFSC registered office are mandatory legal-form and location conditions for an authorisation application.
Regulation 4 of the International Financial Services Centres Authority (Payment Services) Regulation...
Persons seeking to provide Payment Services in or from an IFSC must obtain authorisation as a Payment Service Provider through an application in the specified format and manner, accompanied by a non-refundable fee. Schedule IV persons are exempt. Authorised providers may offer services listed in Part A of Schedule I, while those also meeting Part C conditions are designated Significant Payment Service Providers.
Regulation 3 of the International Financial Services Centres Authority (Payment Services) Regulation...
Authorisation for Payment Services is mandatory for any person seeking to provide Payment Services in or from an International Financial Services Centre. A certificate of authorisation under the International Financial Services Centres Authority (Payment Services) Regulations, 2024 is required before commencing or carrying on such activity.