# REP018: Can you refresh my memory?
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2018-11-29
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: REP018: Understanding the FCA Deadline for Report
Meta Description: Discover the importance of REP018 for PSPs under PSD2 requirements. Learn how to submit the report and protect your business from security risks.
URL: https://financedigest.com/rep018-can-you-refresh-my-memoryhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/rep018-can-you-refresh-my-memory-1736840203560-compressed.jpg)

Stephen Watkins, IT and InfoSec expert at leading financial services compliance firm [fscom](https://www.fscom.co.uk/), explores the need for greater awareness of REP018 ahead of the FCA deadline for report submissions.

Discussing reporting obligations with our payments clients recently has revealed a lack of awareness of REP018, a report driven by the requirements of the second payment services directive (PSD2). PSD2 included Article 95(2), which requires payment services providers (PSPs) to report to the competent authority with an operational and security risk assessment. So, what is REP018 and why has it caught so many by surprise?

The rationale and the history

![Stephen Watkins](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/stephen-watkins-450x675-1736840203624-compressed.jpg)

Stephen Watkins

There has always been a requirement to assess the risks to your business and show the FCA that you are alive to the weaknesses in your business, having taken steps to manage, control and strengthen those weaknesses.

However, PSD2 ups the ante, and quite reasonably so. Globally, we have come to realise our vulnerability to attack. A recent example: the [data breach](https://www.financedigest.com/when-not-if-why-a-data-breach-response-plan-is-more-important-now-than-ever.html "When not if: why a data breach response plan is more important now than ever") hack into British Airways (BA) where details of thousands of customers who booked flights on the airline’s website had their information, worth potentially millions to criminals, stolen. BA has suffered damage to its reputation and has voluntarily paid out compensation but there may yet be further fallout if the Information Commissioner’s Office decides to impose a fine or even ban them from processing [personal data](https://www.financedigest.com/data-privacy-and-navigation-how-our-personal-data-is-used-in-navigation-apps.html "Data Privacy and Navigation: How our personal data is used in Navigation Apps.") (effectively halting their operations). At an event I attended recently, it was said that for every £10 spent [defending against attacks it only costs](https://www.financedigest.com/uks-sunak-under-fire-over-cost-of-living-defends-his-tax-cut-plans.html "UK’s Sunak, under fire over cost of living, defends his tax cut plans") 10p to attack. That’s a [major disadvantage in protecting your valued assets](https://www.financedigest.com/how-to-best-protect-assets-following-major-global-shifts.html "How to Best Protect Assets Following Major Global Shifts").

And so, in PSD2, the [European Banking](https://www.financedigest.com/european-banks-cash-in-on-rising-rates-as-clouds-gather.html "European banks cash in on rising rates as clouds gather") Authority (EBA) was commissioned to produce guidelines on security measures for operational and security risks. After consultation, they published their final guidelines last December.

Since the EBA guidelines were still outstanding when the approach document and [reporting returns were first published](https://www.financedigest.com/according-to-the-recently-published-report-by-persistence-market-research-the-global-market-for-gene-expression-analysis-will-reflect-a-steady-growth-during-the-forecast-period-2017-2022-by-the-end.html "According to the recently-published report by Persistence Market Research, the global market for gene expression analysis will reflect a steady growth during the forecast period, 2017-2022. By the end of 2022"), there was no further information provided until the FCA consulted in March. The finalised REP018 was published in July along with accompanying guidance in chapter 13 in the FCA’s approach document.

**What is REP018?**

REP018 is the operational and security risk report that all PSPs must complete, that means all credit institutions, payment institutions, e-money institutions (whether authorised or registered) and registered account information [service providers](https://www.financedigest.com/sleep-service-providers-market-report.html "Sleep Service Providers Market Report").  It must be completed at least annually however it can be submitted as frequently as every quarter. The report must be submitted on GABRIEL, unless you are an electronic money institution in which case you should email the excel sheet to the FCA. The report requires each PSP to provide the latest risk assessment, their analysis of the findings, details of the latest audit and the number of security related customer complaints. So, what is involved in producing and maintaining a risk assessment, that is suitable for use and reporting to the FCA?

**Undertaking the risk assessment**

Identifying your organisation’s weaknesses begins with establishing the risk assessment methodology; you have to decide whether you want a qualitative or quantitative risk assessment. In my view, a quantitative approach is ideal for [time- and budget-bound single-purpose project because the costs](https://www.financedigest.com/netflixs-gaming-foray-will-cost-time-and-money-wall-st.html "Netflix’s gaming foray will cost time and money – Wall St") of the risks materialising can be calculated. Conversely, the costs are very difficult to quantify for enterprise-wide assessments that are conducted on an ongoing basis and the qualitative approach is more suitable.

Once you have identified a risk assessment methodology you can start the first step of the risk assessment, which is identifying the risks. Arguably, this is the most [important part of this process since](https://www.financedigest.com/eu-u-s-step-up-russian-aluminium-nickel-imports-since-ukraine-war.html "EU, U.S. step up Russian aluminium, nickel imports since Ukraine war") an undiscovered risk is, by default, an accepted risk without mitigation. The operational aspect means everything – HR, finance, IT, [customer services](https://www.financedigest.com/financial-services-is-upping-its-customer-experience-game.html "Financial services is upping its customer experience game"), payments team, even catering (if you have such a department!).

After identifying the risks, you must assess the [impact the risk would have on your business](https://www.financedigest.com/how-technology-consultants-impact-business-growth.html "How Technology Consultants Impact Business Growth") if it crystallised, and the likelihood of it happening. A risk matrix will allow you to [map](https://www.financedigest.com/feature-as-u-s-flooding-worsens-south-carolina-redraws-risk-maps.html "FEATURE-As U.S. flooding worsens, South Carolina redraws risk maps") and accurately assess the identified risks by considering likelihood against impact. In my experience, companies are usually [aware of only around 30% of their risks](https://www.financedigest.com/selfie-awareness-the-cyber-risk-going-undetected-in-banks.html "Selfie-awareness: the cyber risk going undetected in banks"). You will likely find this exercise [reveals more about your business](https://www.financedigest.com/revealed-1-45-million-tonnes-of-e-waste-is-produced-by-households-businesses-per-annum.html "Revealed: 1.45 million tonnes of e-waste is produced by households & businesses per annum") than you were previously aware; after you’re finished, you’ll start to appreciate the effort made.

It’s finally time to take some action and decide what to do with these risks; you can [approach this either on a cyclical basis or a risk](https://www.financedigest.com/demystifying-us-feds-approach-on-systemic-climate-risk-stress-testing.html "Demystifying US Fed’s approach on Systemic Climate Risk Stress Testing") basis. We advise a risk basis as not all [risks are created equal and resources](https://www.financedigest.com/new-isla-standards-provide-the-foundation-for-resource-optimisation-efficiency-and-risk-mitigation.html "New ISLA Standards Provide the Foundation for Resource Optimisation, Efficiency and Risk Mitigation") are not infinite – therefore, focus on the most important ones. There are four options for [dealing with an identified risk:](https://www.financedigest.com/iran-deal-a-wild-card-for-oil-market-strained-by-supply-risks-reuters-poll.html "Iran deal a wild card for oil market strained by supply risks – Reuters poll")

- Tolerate (accept) – it is within your organisation’s level of risk acceptance.
- Terminate (reject) – cease the activity or change the process that is [causing the risk](https://www.financedigest.com/putin-sanctions-risk-causing-energy-price-catastrophe-for-west.html "Putin: sanctions risk causing energy price catastrophe for West").
- Transfer (usually through insurance) – think [cyber insurance](https://www.financedigest.com/automated-cyber-risk-quantification-saving-the-insurance-industry.html "Automated Cyber Risk Quantification: Saving the Insurance Industry").
- Treat (control) – apply a control or risk [mitigation](https://www.financedigest.com/ai-holds-the-key-for-both-competitive-advantage-and-risk-mitigation-in-2022.html "AI holds the key for both competitive advantage and risk mitigation in 2022") process to reduce the risk.

If you have decided to treat or transfer the risk, then you will **re-score** the risk in light of the treatment.

After re-assessing the risks, an action plan must be formulated. Your action plan is carrying out the mitigations you identified earlier to address each weakness. For instance, set a date by which the new policy is to be created and enforced, with follow-up dates for staff [training](https://www.financedigest.com/why-training-staff-on-new-technology-should-not-be-overlooked.html "Why training staff on new technology should not be overlooked") and confirmation that staff have read and agreed to abide by the policy.

**Job done?** We have identified our risks, prioritised them, identified a treatment for each risk, that’s it. One more process complete to be placed on a shelf and dusted down sometime later…

**Not quite!**

A [risk assessment is a live document and should be a continuous process, the key to successful enterprise risk management](https://www.financedigest.com/extended-reality-applications-in-risk-management.html "Extended Reality Applications in Risk Management") is the response to this plan. Risks that are acceptable now may [become unacceptable in the future](https://www.financedigest.com/are-banks-destined-to-merely-become-infrastructure-providers-in-the-banking-industry-of-the-future.html "Are banks destined to merely become infrastructure providers in the banking industry of the future?"). A method of determining whether the [risk assessment must](https://www.financedigest.com/ecb-must-be-prudent-with-rates-hikes-as-recession-risk-rises-panetta.html "ECB must be prudent with rates hikes as recession risk rises: Panetta") be changed is the testing. The testing of your controls can be conducted either by going through a hypothetical situation, walkthrough scenario or a live simulation and documenting any [lessons learned](https://www.financedigest.com/aml-and-identity-checks-lessons-learned-from-the-natwest-case.html "AML and identity checks: Lessons learned from the NatWest case  .") to improve upon your controls.

Clearly, risk assessments can be undertaken by an internal team, but many find that deploying our expertise to be invaluable because we bring:

independencein calibrating the risks [across](https://www.financedigest.com/eliminating-financial-leaks-across-your-business.html "Eliminating financial leaks across your business") the business;
a breadth of experience in **benchmarking** against others in the industry; and
a depth of knowledge that makes us **efficient** in undertaking the task.

If you require any advice, please do not hesitate to contact me, or any of the team at [fscom](https://www.fscom.co.uk/).

![REP018 Infographic](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/rep018-infographic-1736840203881-compressed.jpg)


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

