SIGNATORY RECORD

STET

Date of signature : 01/30/2023

  • Signatory of the Sustainable IT Charter

Small/Medium-sized Enterprises (10 to 250 employees)

IT, telecoms

200 contributors

Courbevoie, France

stet@stet.eu

https://www.stet.eu

Presentation

A propos de STET : activités de STET et modèle d’affaires
▪ En 2004, un groupe de grandes banques françaises a fondé STET avec comme
vision la construction d’une nouvelle plateforme qui répondrait aux défis soulevés par
l’industrie des paiements avec l’émergence du SEPA.
STET est ainsi devenu l’un des principaux processeurs de paiements en Europe,
opérant à la fois un système de compensation et de règlement (CSM) très performant
ainsi qu’un réseau d’autorisation cartes.
▪ Depuis son lancement réussi en janvier 2008, la plateforme CORE propose un
système de compensation industriel de traitement de masse efficace et sécurisé,
hébergeant la gamme complète des instruments de paiement sur le marché français.
▪ En 2012, la communauté bancaire belge a confié à STET le traitement, la
compensation et le règlement des instruments de paiement SEPA et non SEPA, ce qui
a permis à l’entreprise de consolider sa position sur le marché européen.
▪ A la suite de la fusion avec SER2S en janvier 2016, STET est devenu l’opérateur
du réseau d’autorisation de paiements par cartes. Dans un environnement
technologique en pleine mutation, STET suit en permanence les évolutions et les
tendances du marché.
▪ Alors que l'Europe entre dans l’ère du temps réel, STET a lancé le développement en
2017 d’un nouveau système paneuropéen de paiement afin de traiter les transactions
SEPA de paiements instantanés.
▪ En 2019, dans ce cadre, STET a développé le service SWIP (Single Window for
Instant Payments) d'interopérabilité technique avec les systèmes TIPS et RT1, offrant
©STET – INTERNAL – Any use or copy without STET authorization is prohibited| Page 6 sur 41
Dernière mise à jour: 02/09/2022
de nombreux avantages pour les PSP, notamment des gains d'efficacité, une
mutualisation des coûts et une « reachabilité » paneuropéenne.
En tant que partenaire de confiance dans l'espace interbancaire, STET joue un rôle clé
dans la fourniture de services de sécurisation des transactions de paiement.
Pour réduire le risque de fraude et renforcer la sécurité autour des paiements SEPA
(SCT, SDD et SCTinst), STET propose à ses clients un service de scoring innovant en
s'appuyant sur son expérience en matière de scoring des transactions par carte.
Dans un monde de plus en plus digital, l’utilisation des mécanismes de tokenisation
est un moyen très efficace d'accroître la sécurité des moyens de paiements cartes et
SEPA.
STET a lancé le service SDS (STET Digital Solution) qui inclus un fournisseur de
services de token (TSP) en marque blanche ainsi que l’accès à différents fournisseurs,
par le biais d’un HUB digital. Cette solution permet de lier les différentes solutions xPay
et les portefeuilles des émetteurs de cartes cobadgées.
L'association des paiements instantanés et de la mise en œuvre de la DSP2 facilite
l'émergence de nouvelles solutions de paiement. STET va offrir un nouveau service de
demande de paiement. La solution RTP (Request To Pay) proposée par STET, alignée
sur les travaux menés par l'EPC, garantira la fourniture de services paneuropéens
normalisés.
▪ En 2021, STET a renforcé son offre de sécurisation des moyens de paiement en
proposant un scoring du parcours d’authentification.
STET est aussi l’acteur de normalisation des API DSP2 pour le compte de la
communauté française.
STET a traité 28,64 milliards de transactions et 192,12 millions de paiements
instantanés

Planned commitments and actions

  • Raise awareness on Sustainable IT (e.g. information workshop, MOOC, dissemination of good practice guides)
  • Establish a Sustainable IT Working Group within the organisation
  • Communicate to its stakeholders on the actions taken
  • Implementing data governance of your organisation and GDPR compliance or by following the principles of the GDPR in compliance with locally applicable data protection rules locally applicable data protection rules for other countries
  • Deployment of a security plan for its digital environments (antivirus, VPN, supplier audits, permanent monitoring)
  • Evaluate the robustness of its infrastructures (regular tests) and prioritise European infrastructures
  • Manage my fleet with an inventory by category
  • Measure the lifespan of my equipment by type
  • Favour the purchase of sustainable equipment (reparability and durability criteria)
  • Engage with actors in the reuse sector and/or the social and solidarity economy in the management of the end-of-life of my equipment
  • Integrate environmental requirements in my calls for tender and establish a dialogue and measurement elements over the duration of the service with my suppliers
  • Ensuring that its suppliers and service providers comply with their GDPR requirements or follow the principles of the GDPR in compliance with locally applicable data protection rules for other countries, environmental, social and diversity
  • Encourage diversity among my service providers, particularly in relation to disability issues
  • Measure the energy consumption and impact of my Information System (multi-criteria analysis)
  • Avoid unnecessary energy consumption e.g. by switching off at night, weekends and holidays
  • Plan the archiving and cleaning of data with its teams to reduce their environmental footprint
  • Measure the impact of its digital services (e.g. frequency of use or energy consumption) using a multi-criteria and global approach to the entire service (equipment, servers, networks, etc.)
  • Ensure diversity in the recruitment of IS teams (initial and continuing training, diversity of training, origins, disability status)
  • Encourage gender diversity in the digital field at all levels
  • Promote work-life balance by, for example, respecting the right to disconnect and arranging for teleworking measures
  • Favour the use of local and European tools in order to encourage the consolidation of players who respect the sovereignty of European data

Actions started

  • Raise awareness on Sustainable IT (e.g. information workshop, MOOC, dissemination of good practice guides)
  • Implementing data governance of your organisation and GDPR compliance or by following the principles of the GDPR in compliance with locally applicable data protection rules locally applicable data protection rules for other countries
  • Deployment of a security plan for its digital environments (antivirus, VPN, supplier audits, permanent monitoring)
  • Evaluate the robustness of its infrastructures (regular tests) and prioritise European infrastructures
  • Manage my fleet with an inventory by category
  • Measure the lifespan of my equipment by type
  • Favour the purchase of sustainable equipment (reparability and durability criteria)
  • Engage with actors in the reuse sector and/or the social and solidarity economy in the management of the end-of-life of my equipment
  • Integrate environmental requirements in my calls for tender and establish a dialogue and measurement elements over the duration of the service with my suppliers
  • Ensuring that its suppliers and service providers comply with their GDPR requirements or follow the principles of the GDPR in compliance with locally applicable data protection rules for other countries, environmental, social and diversity
  • Encourage diversity among my service providers, particularly in relation to disability issues
  • Measure the energy consumption and impact of my Information System (multi-criteria analysis)
  • Avoid unnecessary energy consumption e.g. by switching off at night, weekends and holidays
  • Plan the archiving and cleaning of data with its teams to reduce their environmental footprint
  • Measure the impact of its digital services (e.g. frequency of use or energy consumption) using a multi-criteria and global approach to the entire service (equipment, servers, networks, etc.)
  • Ensure diversity in the recruitment of IS teams (initial and continuing training, diversity of training, origins, disability status)
  • Encourage gender diversity in the digital field at all levels
  • Promote work-life balance by, for example, respecting the right to disconnect and arranging for teleworking measures
  • Favour the use of local and European tools in order to encourage the consolidation of players who respect the sovereignty of European data