Advanced Search Options : ❯
Regulation 31 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must maintain their place of business and registered office in an IFSC. Activities relating to payment services from a business location outside the IFSC require prior approval from the Authority. An IFSC-based business presence and registered office are mandatory, subject to approved externally located activities.
Regulation 30 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Regulation 30 establishes an enforcement mechanism for defaults by Payment Service Providers. Where a provider contravenes applicable regulatory provisions, or any direction or order issued under the payment services framework, the Authority may initiate appropriate enforcement action. The provision links non-compliance with regulatory requirements, directions, and orders to potential enforcement proceedings.
Regulation 29 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers in IFSC must maintain adequate staff to address Payment Service User queries, complaints and grievances within thirty days of receipt. Users must have one or more accessible channels for raising queries and lodging complaints. Disputes unresolved through internal grievance redressal must be addressed through online conciliation and/or online arbitration as specified by the Authority. Providers must retain records of queries, complaints, grievances and their redressal.
Regulation 28 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must secure information technology systems and other infrastructure used for payment services against unauthorised access and manipulation. They must prepare and maintain written security policies and procedures. The Authority may issue directions on security procedures and may require certificates from independent professionals confirming compliance with system-security obligations, documentation requirements, and applicable directions.
Regulation 27 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must protect Payment Service Users by communicating relevant information clearly and fairly so as to minimise the possibility of users being misled. They must also comply with the disclosure requirements prescribed in Schedule VII, alongside their obligation to safeguard user interests through clear, fair communication of relevant information.
Regulation 26 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must deal openly and co-operatively with the Authority, report significant events, and communicate proposed major changes to payment-service features, processes, structure or operations with complete details. Prior approval is required for specified mergers, reorganisations, arrangements, compromises, amalgamations and reconstructions. Payment Service Providers and Third-Party Service Providers must assist the Authority with audits and inspections.
Regulation 25 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must comply with all applicable Indian laws and with applicable laws of every foreign jurisdiction in which they provide services or where Payment Service Users are based. The obligation attaches to both the location of service provision and the jurisdictional location of users in relation to cross-border operations.
Regulation 24 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must comply with AML, CTF and KYC requirements and applicable anti-money laundering law. Providers using authorised agents must maintain updated agent lists, incorporate agents into AML/CTF programmes, and monitor compliance. Providers remain responsible and accountable for agents' transactions and actions. Transaction logs must be retained for at least ten years and made available for regulatory scrutiny when required.
Regulation 23 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must safeguard Applicable Funds, including through compliance with directions specified in Schedule VI. Applicable Funds must be kept segregated at all times from every other type of fund held by the provider. The duty requires continuous separation of Applicable Funds from all other funds throughout payment-service operations.
Regulation 22 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must maintain complete and up-to-date records of each Third-Party Service Relationship identified under the risk-management process in sub-regulation (1) of regulation 18. The record-keeping duty applies to all identified relationships on an ongoing basis, requiring relationship records to remain complete and current after identification. This obligation covers Third-Party Service Relationships identified through the prescribed risk-management process under regulation 18.
Regulation 21 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must ensure that Third-party Service Providers maintain clearly defined incident-management processes covering identification, investigation, remediation and timely notification. Notification must be given to the Payment Service Provider when an incident affects the Third-party Service Provider's ability to deliver agreed-upon services. Responsibility rests with the Payment Service Provider to secure these operational and reporting arrangements within third-party service relationships.
Regulation 20 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must identify, document and, where practically feasible, test exit strategies for Third-party Service Relationships involving critical services. Exit planning must address planned service migration and adverse events, including legal or contractual breaches, deteriorating service quality, provider governance, financial, resilience or risk-management weaknesses affecting critical services, and extended disruptions that cannot be managed through other business-continuity measures.
Regulation 19 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must conduct proportionate planning and due diligence before engaging Third-party Service Providers for critical services. The assessment covers operational capability, financial soundness, risk controls, ICT and cyber-security risks, supply-chain dependencies, conflicts, regulatory-compliance capability and substitutability. Critical services require legally binding arrangements, including information-sharing obligations with the Authority, and ongoing monitoring of the provider's contractual performance.
Regulation 18 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must use a risk-based framework to identify critical services received or planned to be received from Third-party Service Providers. Assessment is required at the commencement of operations and at regular intervals. Criticality must consider the service's financial, operational and strategic importance, acceptable disruption tolerance for dependent critical operations, the nature of shared data or information, and the ease or lack of substitutability of the service.
Regulation 17 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must maintain a Board-reviewed risk-management policy with policies, procedures and systems to identify, measure, monitor and manage risks arising from payment services. They must establish a robust operational risk-management framework with appropriate systems, policies, procedures and controls. Providers establishing links with Payment Systems must identify, monitor and manage link-related risks.
Regulation 16 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must document governance arrangements covering Board and senior management functions, reporting lines, ownership, internal governance, risk management, internal controls, appointment procedures, and performance accountability. Activities beyond Payment Services require prior permission and specified conditions. Providers must formulate clear service rules and procedures and provide users sufficient information to understand applicable risks, fees, and other material costs.
Regulation 15 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Payment Service Providers must begin operations within six months from issuance of the Certificate of Authorisation. An extension application requires board authorisation, timely submission, reasons for delay, the period sought, and remedial steps. Where satisfied that commencement cannot occur within the stipulated period, the Authority may grant one extension of up to three months.
Regulation 14 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Security deposits furnished by Payment Service Providers may be appropriated following surrender or revocation of authorisation to satisfy outstanding sums claimed by Payment Service Users who are customers. Release of the deposit or any balance requires that no outstanding customer claim exists and that all surrender conditions have been met. Release for legitimate outstanding claims or dues is to occur only after one year from approval of surrender or revocation of authorisation.
Regulation 13 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Surrender of authorisation by a Payment Service Provider requires an application to the Authority in compliance with prescribed conditions and the Schedule III format. Permission depends on satisfaction that surrender is unlikely to materially adversely affect the IFSC financial ecosystem or Payment Service Users' interests. Permission may be subject to appropriate conditions, and a written order may specify the date from which authorisation ceases to have effect.
Regulation 12 of the International Financial Services Centres Authority (Payment Services) Regulatio...
Authorisation may be revoked where a Payment Service Provider breaches authorisation conditions, applicable regulatory requirements, or Authority orders or directions, or carries on payment services prejudicially to Payment Service Users' interests. An order revoking authorisation may be issued only after the concerned provider receives a reasonable opportunity of hearing.