REP018 operational and security risk assessment
FCA · Annually · At least once every calendar year
Payment service providers, including payment and e-money institutions, submit an updated assessment of their operational and security risks, and of the controls that address them, at least once every calendar year (SUP 16.13.13D). There's no fixed date, so you pick one in each calendar year.
What it covers
A full, current assessment of the operational and security risks of the payment services you provide, and whether your mitigation measures and control mechanisms are adequate (regulation 98 of the Payment Services Regulations). It's submitted on the FCA's form with supporting documents, and follows the EBA's guidelines on security measures for payment services.
Choosing your date
Submit it as soon as you can after the assessment is finished (SUP 16.13.14G). You can submit more often than once a year, but not more than once a quarter. The FCA's guidance says to submit a nil return for each quarter with no assessment (SUP 16.13.16G).
Operational resilience
The assessment should take account of the operational resilience rules in SYSC 15A, which also apply to payment and e-money institutions.
Get reminded before it's due
Regmindr tracks this alongside the rest of your compliance calendar, and emails your team before each deadline.
Sources
This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.