# PSR Article 81 — Management of operational and security risks

Textual state: amended_substantial. 114 words changed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. Payment service providers shall establish a framework with appropriate mitigation measures and control mechanisms to manage operational and security risks relating to the payment services they provide. As part of that framework, payment service providers shall establish and maintain effective incident management procedures, including for the detection and classification of major operational and security incidents. The first subparagraph shall be without prejudice to the application of Chapter II of Regulation (EU) 2022/2554 of the European Parliament and of the [-Council[65] -]{+Council28 +}to: (a) payment service providers referred to in Article 2(1), points (a), (b) and (d) of this Regulation; {+28 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1). +}(b) account information service providers referred to in Article 36(1) of Directive (EU) (PSD3); and (c) payment institutions exempted pursuant to Article 34(1) of Directive (EU) (PSD3). [-Payment service providers shall provide to the competent authority designated under Directive (EU) XXX (PSD3) on an annual basis, or at shorter intervals as determined by the competent authority, an updated and comprehensive assessment of the operational and security risks relating to the payment services they provide and on the adequacy of the mitigation measures and control mechanisms implemented in response to those risks.-]

## Paragraph 2

2. The EBA shall promote cooperation, including the sharing of information, in the area of operational and security risks associated with payment services among the competent authorities, between the competent authorities and the ECB and, where relevant, the European Union Agency for Network and Information Security.
