The Joint Committee of the three European Supervisory Authorities (EBA, EIOPA e ESMA) published two amended Implementing Technical Standards (ITS) on the mapping of credit assessments of External Credit Assessment Institutions (ECAIs).

The ITS are part of the EU Single Rulebook for banking and insurance. The amendments reflect:

  • the recognition of two new credit rating agencies (CRAs);
  • the outcome of a monitoring exercise on the adequacy of existing mappings; and
  • the deregistration of a number of CRAs.

The ESAs also published individual draft mapping reports illustrating how the methodology was applied to produce the amended mappings, in line with the mandate from the Capital Requirements Regulation (CRR).

EBA has published a Report on the data provided by Payment service providers (PSPs) on their readiness to apply strong customer authentication (SCA) for the subset of payment transactions that are e-commerce card-based payment transactions.

The Report considers the status of issuing and acquiring PSPs in enrolling online merchants, payment cards and payment service users (PSUs) into SCA-compliant solutions, and in requesting SCA for online payment transactions after 31 December 2020, when the SCA migration period ended.

The Report highlights:

  • The industry reported significant progress over the past 9 months in complying with the requirements for SCA for e-commerce card-based payment transactions.
  • This progress coincided with a significant reduction of the volume and value of fraud, for the same type of transactions and the same time period.
  • PSPs in some jurisdictions are still lagging behind on some indicators.

EBA has issued a revised list of validation rules in its Implementing Technical Standards (ITS) on supervisory reporting.

The report highlighting those, which have been deactivated either for incorrectness or for triggering IT problems.

EBA has published its final revised Guidelines on major incident reporting under the Payment Service Directive (PSD2).

The revised Guidelines optimise and simplify the reporting process and templates, focus on incidents with significant impact on payment service providers (PSPs), and improve the meaningfulness of the information to be reported. The revised Guidelines are also estimated to reduce the reporting burden for PSPs by removing unnecessary steps from the reporting process, allowing more time for the submission of the final report and simplifying the standardised reporting template..

The Guidelines will apply as of 1 January 2022.

The Basel Committee on Banking Supervision today issued a public consultation (that runs until 10 September 2021) on preliminary proposals for the prudential treatment of banks’ cryptoasset exposures.

The proposed prudential treatment outlined in the consultation divides cryptoassets into two broad groups:

  • Group 1 cryptoassets – these fulfil a set of classification conditions and as such are eligible for treatment under the existing Basel Framework (with some modifications and additional guidance). These include certain tokenised traditional assets and stablecoins.
  • Group 2 cryptoassets – are those, such as bitcoin, that do not fulfil the classification conditions. Since these pose additional and higher risks, they would be subject to a new conservative prudential treatment.

Central bank digital currencies are not within the scope of the consultation.

Published on the Official Journal of the European Union the Commission Delegated Regulation (EU) 2021/923 supplementing Directive 2013/36/EU of the European Parliament and of the Council with regard to regulatory technical standards setting out the criteria to define managerial responsibility, control functions, material business units and a significant impact on a material business unit’s risk profile, and setting out criteria for identifying staff members or categories of staff whose professional activities have an impact on the institution’s risk profile that is comparably as material as that of staff members or categories of staff referred to in Article 92(3) of that Directive.

 Published on the Official Journal of the European Union the Commission Delegated Regulation (EU) 2021/930 supplementing Regulation (EU) No 575/2013 of the European Parliament and of the Council with regard to regulatory technical standards specifying the nature, severity and duration of an economic downturn referred to in Article 181(1), point (b), and Article 182(1), point (b), of that Regulation.

Published on the Official Journal of the European Union the Commission Delegated Regulation (EU) 2021/931 supplementing Regulation (EU) No 575/2013 of the European Parliament and of the Council with regard to regulatory technical standards specifying the method for identifying derivative transactions with one or more than one material risk driver for the purposes of Article 277(5), the formula for calculating the supervisory delta of call and put options mapped to the interest rate risk category and the method for determining whether a transaction is a long or short position in the primary risk driver or in the most material risk driver in the given risk category for the purposes of Article 279a(3)(a) and (b) in the standardised approach for counterparty credit risk.

(Only in Italian)

CONSOB ha pubblicato il III Rapporto sulla rendicontazione non finanziaria delle società quotate italiane.

Il Rapporto presenta un’analisi della rendicontazione non finanziaria delle società quotate italiane, a seguito dell’applicazione del d.lgs. 254/2016 di recepimento della Direttiva 2014/95/Ue.

(Only in Italian)

Il Consiglio dei Ministri, riunitosi il 10 giugno 2021, ha approvato un decreto-legge che introduce disposizioni urgenti in materia di cybersicurezza, definizione dell’architettura nazionale di cybersicurezza e istituzione dell’Agenzia per la cybersicurezza nazionale (ACN).

Come si legge nel comunicato stampa del Governo il provvedimento completa la strategia di cyber-resilienza nazionale, avviata con la disciplina sul perimetro cibernetico, e accresce, attraverso la promozione della cultura della sicurezza cibernetica, la consapevolezza del settore pubblico, privato e della società civile sui rischi e le minacce cyber.

L’Agenzia opererà sotto la responsabilità del Presidente del Consiglio dei ministri e dell’Autorità delegata per la sicurezza della Repubblica e in stretto raccordo con il Sistema di informazione per la sicurezza della Repubblica e sarà tra l’altro incaricata di:

  • esercitare le funzioni di Autorità nazionale in materia di cybersecurity, a tutela degli interessi nazionali e della resilienza dei servizi e delle funzioni essenziali dello Stato da minacce cibernetiche;
  • sviluppare capacità nazionali di prevenzione, monitoraggio, rilevamento e mitigazione, per far fronte agli incidenti di sicurezza informatica e agli attacchi informatici, anche attraverso il Computer Security Incident Response Team (CSIRT) italiano e l’avvio operativo del Centro di valutazione e certificazione nazionale;
  • contribuire all’innalzamento della sicurezza dei sistemi di Information and communications technology (ICT) dei soggetti inclusi nel perimetro di sicurezza nazionale cibernetica, delle pubbliche amministrazioni, degli operatori di servizi essenziali (OSE) e dei fornitori di servizi digitali (FSD);
  • supportare lo sviluppo di competenze industriali, tecnologiche e scientifiche, promuovendo progetti per l’innovazione e lo sviluppo e mirando a stimolare nel contempo la crescita di una solida forza di lavoro nazionale nel campo della cybersecurity in un’ottica di autonomia strategica nazionale nel settore;
  • assumere le funzioni di interlocutore unico nazionale per i soggetti pubblici e privati in materia di misure di sicurezza e attività ispettive negli ambiti del perimetro di sicurezza nazionale cibernetica, della sicurezza delle reti e dei sistemi informativi (direttiva NIS), e della sicurezza delle reti di comunicazione elettronica.

Inoltre, il decreto istituisce il Comitato interministeriale per la cybersicurezza (CIC) e prevede specifici poteri di controllo da parte del Comitato parlamentare per la sicurezza della Repubblica (COPASIR).

Infine il Governo ha individuato l’Agenzia quale Centro nazionale di coordinamento italiano, che si interfaccerà con il “Centro europeo di competenza per la cybersicurezza nell’ambito industriale, tecnologico e della ricerca” di recente istituzione, concorrendo ad aumentare l’autonomia strategica europea nel settore.

(Only in Italian)

Il Ministero dell’Economia e delle Finanze, ha posto in pubblica consultazione lo schema di decreto diretto ad individuare il contenuto induttivo degli elementi indicativi di capacità contributiva, finalizzato alla determinazione sintetica dei redditi delle persone fisiche relativi agli anni d’imposta a decorrere dal 2016 (c.d. redditometro).

La norma prevede che con decreto del Ministro dell’economia e delle finanze, da pubblicare nella Gazzetta Ufficiale con periodicità biennale, sentiti l’ISTAT e le associazioni che maggiormente rappresentano i consumatori, sono individuati elementi indicativi di capacità contributiva, mediante l’analisi di campioni significativi di contribuenti, differenziati anche in funzione del nucleo familiare e dell’area geografica di appartenenza.

La consultazione terminerà il 15 luglio 2021.