Article 3 Review of the security measures

  1. (1)

    The implementation of the security measures referred to in Article 1 shall be documented, periodically tested, evaluated and audited in accordance with the applicable legal framework of the payment service provider by auditors with expertise in IT security and payments and operationally independent within or from the payment service provider.

  2. (2)

    The period between the audits referred to in paragraph 1 shall be determined taking into account the relevant accounting and statutory audit framework applicable to the payment service provider.

    However, payment service providers that make use of the exemption referred to in Article 18 shall be subject to an audit of the methodology, the model and the reported fraud rates at a minimum on a yearly basis. The auditor performing this audit shall have expertise in IT security and payments and be operationally independent within or from the payment service provider. During the first year of making use of the exemption under Article 18 and at least every three years thereafter, or more frequently at the FCA’s request, this audit shall be carried out by an independent and qualified external auditor.

  3. (3)

    This audit shall present an evaluation and report on the compliance of the payment service provider’s security measures with the requirements set out in these Standards.

    The entire report shall be made available to the FCA upon its request.