Search This Blog

Friday, 27 January 2023

FCA Consumer Duty Implementation: Are Firms Trying To Wing It?

The UK's Financial Conduct Authority has conducted a review of firms' progress in implementing the new Consumer Duty for new or existing products by 31 July 2023 (and for closed products with existing customers by 31 July 2024). Firms had until 31 October 2022 for their board to approve their implementation plan and show that it has scrutinised and challenged the plans to ensure they are deliverable and robust. Since then, the FCA has checked on larger firms with dedicated FCA supervision teams and found that: 

"some firms may be further behind in their thinking and planning for the Duty. This brings a risk that they may not be ready in time, or they may struggle to embed the Duty effectively throughout their business."

Aside from my February blog post here, I summarised the Consumer Duty requirements and key steps for implementation in a Keynote last September. That explains there is another recommended milestone at the end of April and the board must also oversee progress to ensure deadlines are met...
 
However, the FCA has published detailed findings across six aspects of the implementation process which shows where firms may be falling short. Generally, in the remaining six months to the end of July, the FCA wants firms to: 

  • ensure they are prioritising efforts where they are likely to be furthest away from the requirements; 
  • carefully consider the substantive requirements in reviewing products, services, communications, customer journeys and identify/make the changes needed; and 
  • work on all this with other firms in their distribution chain. 
Please let me know if you need assistance.

Monday, 16 January 2023

UK Review of the Payment Services (and E-money) Regulations

The Treasury is calling for evidence to assist in its review of the Payment Services Regulations 2017. This also necessarily involves consideration of the Electronic Money Regulations 2011, since e-money institutions are subject to both. Those regulations implemented corresponding EU directives that are also being reviewed (which the Treasury ignores). You have until 7 April 2023 to submit responses to the UK process. Please let me know if you would like assistance.

Of course, 'elephant in the room' is whether the UK regulations should remain harmonised with the EU directives that they implemented, particularly as most UK payment service providers will have EEA aspirations, at least, if not their own regulated firms within the trade bloc. Indeed, the UK review will seem eerily familiar to many, because the European Commission embarked on its own review of the second Payment Services Directive (PSD2) in May 2022; and in July the European Banking Authority proposed numerous changes that I summarised for Ogier Leman in Ireland, including the merger of PSD2 and the second E-money Directive (EMD2). I suspect the UK review is timed to coincide with likely changes arising from the EU's review process. The timing might not work perfectly, so the UK might make any changes that seem settled or non-controversial in the EU process, then mop up the rest in due course.

The UK government believes that its e-money and payment services regulation should address: 

  • 'authorised push payment' (APP) fraud; 
  • whether 'strong customer authentication' requirements are too prescriptive and should be 'outcome-based' including delaying payments where APP fraud is suspected to allow for communication with a potentially affected customer;
  • the use of cryptoassets or cryptocurrencies as payment methods.

There is no mention of the European Commission or EBA proposals relating to the review of PSD2 and EMD2, let alone consideration of whether those proposals should be addressed in the UK. I guess that is left to the rest of us to consider and submit.

The UK has already made changes to its insolvency regime to cater for the more orderly and efficient wind-down of payment and e-money institutions, as this was something that the EU directives did not really address (aside from the 'pooling' provisions relating to safeguarded funds). The UK government is also inviting evidence on whether these additional arrangements are adequate (and the EBA has urged greater clarity on wind-down arrangements under the EU directive(s).

The government persists in its tediously jingoistic claims that the UK somehow pioneered 'Open Banking' through the API requirements proposed by the Competition and Markets Authority in 2016 (among other remedies to improve competition for retail banking). However, that happened three years after the specific open banking requirements were proposed in the first version of PSD2. In fact, such 'open data' and 'midata' initiatives were fully developed by 2012 common across Europe and, indeed, globally within the context of the World Economic Forum, as I posted at the time. It cites unspecified plans to ‘develop’ and ‘progress’ such services through a Joint Regulatory Oversight Committee after the CMA found that its mandated Open Banking Implementation Entity was improperly managed and lacked corporate governance.

While omitting a focus on whether banks unfairly withhold payment accounts from innovative financial services businesses, the consultation also includes highly irregular claims that the government is concerned about whether payment service providers might be terminating customer relationships in reaction to the customers' right wing, 'libertarian' political views. The paper concedes that there is no evidence at all that this is a genuine issue, merely citing assertions from a Conservative MP based on speculation by a conservative pundit about why PayPal might have regarded his accounts as suspicious. That such nonsense has found its way into a Treasury consultation paper is deeply worrying. It smacks of the false claims about Channel 4's activities by the then Culture Secretary, ironic given the government's decision to boycott and later sell Channel 4 in reaction to what it believed was unwarranted scrutiny of its activities by journalists. Just as the government has been forced to row back on the sale of Channel 4, it would seem unwise to politicise payment services regulation...

Though maybe the drafts-person was fully aware of the irony in referring to the 'Daily Sceptic' and the 'Free Speech Union' in the context of better ways to combat APP fraud.  


Tuesday, 13 December 2022

Overdue Reform of the UK Consumer Credit Act

The Treasury is consulting on a long overdue overhaul of the Consumer Credit Act 1974 (CCA) which covers the UK’s £200bn non-mortgage consumer credit industry, including personal loans, credit cards, hire purchase and pawn-broking. I'm waiting on publication of a longer note summarising the detail, and will post a link to that here. You have until 17 March 2023 to respond. Let me know if I can help you in understanding the proposals and likely impact. 

Brexit

As previously mentioned, the current consultation was actually proposed in June, just prior to the European Commission proposal for a new Consumer Credit Directive (CCD2).  Extensive changes were made to the CCA in 2010 to implement CCD1, which had considerable input from the UK. 

Supervision of the CCA transferred from the Office of Fair Trading to the Financial Conduct Authority  in 2014 under the Financial Services and Markets Act 2000 (FSMA). This meant adding consumer credit and hire agreements, and related activities, to the FSMA (Regulated Activities) Order 20012 (RAO); and transferring some CCA regulations to the FCA’s rules. The Treasury now wishes to transfer “the majority” of the CCA to FCA rules, which seem likely to align with CCD2. 

Some aspects that are specific to Scotland and Northern Ireland will be addressed later in the review process.

Scope and Impact

The CCA regulates consumer credit and consumer hire, although the latter has less protection. The government has already announced plans to regulate many Buy-Now Pay-Later (BNPL) products that are currently unregulated. 

Broadly, the activities of entering into regulated credit and hire agreements require FCA authorisation and specific permission when carried on by way of business, as do the activities of exercising the rights of a lender (or owner, for hire purposes) and various ‘ancillary services’ such as credit broking, debt collection, debt counselling, debt adjusting, debt administration, operating an electronic system in relation to lending (peer to peer lending), credit information services. 

Advertising credit and hire products is also regulated, even for unauthorised firms. 

The FCA’s new Consumer Duty does not apply to unregulated or exempt individuals or products in the same way as the CCA regime, but that new duty changes the context in which the CCA protections operate; and makes authorised firms liable for certain activities of unauthorised firms in the product 'distribution chain'.

About 6,000 authorised firms have permission to enter into consumer credit or consumer hire agreements; and 36,000 FCA firms have credit permissions (mainly credit broking). 

I will update this post with a link to the more detailed note shortly.


Friday, 9 December 2022

Treasury Tinkers With Payment Account Transparency

When the UK government finally acted to improve transparency in retail banking fees and charges, it sparked a similar effort in Brussels that the UK negotiated to align with its own initiatives. This resulted in the Payment Accounts Directive which the UK implemented via the Payment Accounts Regulations 2015 (PARs). Unfortunately (as the FCA later pointed out) the Treasury 'gold-plated' the implementation, by simply cutting and pasting the Directive. The EU was due to review the Directive in 2019, though that is yet to complete. Meanwhile, the Treasury completed its own review in 2021. Struggling to find any 'Brexit benefits', the Treasury has come up with the wheeze of timing its consultation on how payment account fees are presented to consumers with the political gestures announced by the Chancellor today as some kind of post-Brexit renaissance for Britain's financial services industry, now starved of access to its biggest market. You have until 23 February to have your say on these particular changes [yawns].

Among other things required by the PARs, payment service providers must: 

  • provide customers with a fee information document that sets out the fees associated with the payment account in a specific form (FID);
  • provide each customer with a statements of fees incurred on the payment account in a given period (SoFs) in a specific form; 
  • inform customers of whether it is possible to purchase a payment account separately, where it's offered as part of a package, and provide the consumer with separate information regarding the costs and fees associated with each of the other products in the package.

The Money and Pensions Service (MaPS) is also required to provide consumers with access to a website comparing fees charged by payment service providers (I challenge you to find this!).

The Treasury now wants to know your thoughts on the following questions:

Question 1 Do you consider the requirement for payment service providers to provide consumers with FIDs to have any positive impacts (e.g. supporting transparency and comparability of fee information related to payment accounts)?  

Question 2 Do you consider the requirement for payment service providers to provide consumers with FIDs to have any negative impacts (e.g. admin costs or duplication of information already provided)?  

Question 3 Do you consider the requirement for payment service providers to provide consumers with SoFs to have any positive impacts (e.g. supporting transparency and comparability of fee information)? 

Question 4 Do you consider the requirement for payment service providers to provide consumers with SOFs to have any negative impacts (e.g. administration costs or duplication of information already provided)?  

Question 5 Do you consider the presentational requirements (under Schedules 1 and 2 of the PARs) to be necessary? Could consumers be provided with the same or equivalent information by simpler or alternative means?  

Question 6 Do you consider the requirements for the FCA to maintain a linked services list, and for payment service providers to provide customers with a glossary of related definitions, to have any positive impacts (towards supporting transparency and comparability of fee information)? 

Question 7 Do you consider the requirement for the FCA to maintain a linked services list, and for payment service providers to provide customers with a glossary of related definitions, to have any negative impacts?  

Question 8 Do you consider the requirements for the Money and Pensions Service (MaPS) to provide consumers with access to a website comparing fees charges by payment service providers to have any positive impacts towards supporting transparency and comparability of fee information beyond private sector providers? Or could the same objectives be fulfilled without these specific requirements? 

Question 9 Where relevant, what are the costs to your organisation of adhering to Part 2 and Schedules 1 and 2 of the PARs?  

Question 10 Can you foresee any potential unintended consequences or negative impacts of removing any requirements under Part 2 and Schedules 1 and 2 of the PARs? 

Question 11 Do you have any other views on Part 2 and Schedules 1 and 2 of the PARs that you wish to share?

Monday, 5 December 2022

FCA To Allow Simpler Advice On 'Mainstream' Investments

The UK's Financial Conduct Authority is consulting on a new investment advice regime to allow consumers to access simplified advice on investments that qualify for stocks and shares ISAs from April 2024, and reflecting the fact that the new Consumer Duty will apply. 

The FCA's research revealed that "less wealthy" consumers do not access professional support where they want it to make financial decisions like investing in stocks and shares ISAs. Those who receive advice are those who already hold investment products. Investors are more confident in a personal recommendation and value human interaction in the advice process. If offered a free consultation, only 6% of adults would choose a robo-adviser, whereas 51% would choose to meet face-to-face with an adviser (Mintel, 2021).

The FCA plans to:

  • Cut the existing qualification requirements to reflect the lower risk of the narrower scope of advice (the necessary technical and regulatory understanding to advise on mainstream investments and where clients have straightforward needs). 
  • Reframe the suitability requirements to reflect the narrower scope and less complexity of the advice relevant to the more limited decision consumers will be making, with new guidance on minimum information expected for the 'fact find' to reduce time and liability consequences for firms not doing a more fulsome inquiry.
  • Limit the range of investments advisers can recommend to a set of mainstream investments and excluding any recommendations to invest in high‑risk investments. 
  • Allowing consumers to pay for transactional advice in instalments.

You have until 28 February 2023 to respond to the FCA's consultation.


Thursday, 1 December 2022

ICO Explains How To Do A Transfer Risk Assessment Under UK GDPR

The UK Information Commissioner's Office (ICO) has updated its guidance on international transfers of personal data from the UK to any country that does not benefit from an adequacy decision that its data protection regime is the same or better than the UK's ('restricted transfer'). If you need assistance, please let me know.

A ‘transfer risk assessment’ (TRAs) determines whether the effective and legally enforceable protection for data subjects and their personal data under the UK data protection regime will be undermined in the proposed receiving country, even if the transferring firm uses one of the ‘transfer tools’ for providing appropriate safeguards under Article 46 of the UK GDPR.

Those transfer tools include are the ICO’s International Data Transfer Agreement (IDTA), the Addendum to the EU SCCs (the Addendum) and ICO-approved Binding Corporate Rules (BCRs).

As explained previously, in backing the second successful challenge to the EU-US Privacy Shield, the ECJ decided that before a firm may rely on an Article 46 transfer tool to make a restricted transfer, it had to carry out a TRA to figure out if it also needs to take some other steps to fill in the gap. If there are gaps that cannot be filled, the transfer must not be made.

It's worth noting that the ICO states in its guidance:

You do not need to carry out a TRA if you are making a transfer to any country covered by UK adequacy regulations or if the transfer is covered by one of the exceptions [in Article 49].

This is supported by guidance from the European Data Protection Board (made up of all EU member state data protection regulators): 

27. If your transfer can neither be legally based on an adequacy decision, nor on an Article 49 derogation, you need to continue with Step 3.

But, again, as explained previously (and in the EDPB's own guidance on Article 49), the way GDPR works is that (unless the country in question benefits from an adequacy finding), you would need to have decided on to rely on a transfer tool under article 46 before you can try to rely on an exception under article 49, so you need a risk assessment either way.  

The ICO's template TRA tool is a Word document that may be opened by clicking the link at the foot of the guidance page. It asks 6 questions (with guidance) to help firms get to an initial assessment. It will likely be quite efficient to use the tool, but it's not mandatory and you could work through the questions yourself:

Question 1: What are the specific circumstances of the restricted transfer? 

Question 2: What is the level of risk to people in the personal information you are transferring? 

Question 3: What is a reasonable and proportionate level of investigation, given the overall risk level in the personal information and the nature of your organisation? 

Question 4: Is the transfer significantly increasing the risk for people of a human rights breach in the destination country? 

Question 5: 

(a) Are you satisfied that both you and the people the information is about will be able to enforce the Article 46 transfer mechanism against the importer in the UK? 

(b) If enforcement action outside the UK may be needed: Are you satisfied that you and the people the information is about will be able to enforce the Article 46 transfer mechanism in the destination country (or elsewhere)? 

Question 6: Do any of the exceptions to the restricted transfer rules [in Article 49 of UK GDPR] apply to the “significant risk data” [which you identified in Questions 4 and 5 as data for which your Article 46 transfer tool does not provide all the appropriate safeguards]. 

If by using the TRA tool, you decide that your Article 46 transfer mechanism will not provide appropriate safeguards and effective and enforceable data subject rights for all the personal data, then you must not make the restricted transfer.

The ICO will soon issue guidance on how to use the International Data Transfer Agreement (IDTA) and the Addendum to the Standard Contractual Clauses.

If you need assistance with any aspect of international personal data transfers, please let me know.


Tuesday, 29 November 2022

Steiner Case No Save Haven For Card Issuers, Acquirers, Processors or Merchants

I have a real problem with the facts and ultimate outcome for the cardholder in the recent case of Steiner v National Westminster Bank plc [2022] EWHC 2519 (KB) decided in October. I make no criticism of the lawyers or judge involved, but those in the payment card business should not see it as setting up any kind of safe haven. 

In essence, the court absolved a credit card issuer from liability for the price of a timeshare deal under section 75 of the Consumer Credit Act because the supplier of the timeshare ('CLC') was found not to be a party to the credit card 'arrangements'. Instead, those arrangements were found only to involve a separate company ('FNTC') that was not part of the same corporate group as CLC and was acting as a trustee and not as agent for CLC. 

Unfortunately, it seems the Mastercard rules were not fully explored, as the judge held:

13. Equally, there was no evidence before me as to the rules of the Mastercard network, but it was not suggested that they prohibited a merchant who was a member of the scheme from receiving payment under the scheme as trustee or agent for another.

However, the Mastercard rules effectively require that acquirers, merchants and sub-merchants (and the intermediate 'Payment Facilitator') must be party to the overall scheme arrangements, and it would be a breach of those rules if that were not the case (see Chapters 5 and 7). 

In addition, it appears that as a separate company and a trustee, FNTC was not lawfully able to handle funds due to CLC under the Payment Services Regulations 2017. There is no evidence that FNTC was a payment institution (or small payment institution) or the agent of one; and as a separate company and trustee it could not benefit from any of the exclusions from the need for authorisation/registration as a payment institution, the most common in such scenarios being the exclusion for a commercial agent or a group company collecting or making payments on behalf of other companies in the same group. 

In this specific case, there may have been good reasons why the Mastercard rules were not explored and/or the card acquirer, FNTC and CLC were not joined as defendants and subject to a barrage of claims and remedies to recover the funds (assuming that the card issuer could not have known of the apparent breach of scheme rules and FNTC's apparently unlawful conduct). There may have been shortcomings in the evidence or other issues involved in mounting the potential legal claims and remedies - not the least of which would be the necessary financial resources.

But I do not see this case as a reliable basis for anyone to start setting up trustees as payment processors in an attempt to avoid liability under supply contracts, card scheme rules, Payment Services Regulations and/or section 75 of the Consumer Credit Act!