Payments

The CBI's 2026 supervisory programme for PIs and EMIs: what authorised firms need to do now

The Central Bank's 2026 Regulatory and Supervisory Outlook sets out five focus areas for payment and e-money institutions with more directness than prior editions. Safeguarding, financial crime, wind-down credibility, DORA and governance all carry planned supervisory activity in 2026. The CBI is moving from observation to intervention.

Finvisor analysis of the Central Bank of Ireland 2026 supervisory programme for payment and e-money institutions

Finvisor Fintech Partners, April 2026. This article accompanies our four-page briefing, CBI RSO 2026: Payment Institutions and E-Money Institutions.

The Central Bank of Ireland's Regulatory and Supervisory Outlook 2026, published on 26 February, sets out the supervisory priorities for payment institutions and electronic money institutions with more directness than prior editions. The numbers provide the backdrop: 58 CBI-authorised payment and e-money firms, €11.8bn in safeguarded customer funds, €702bn in payment transactions processed in 2025, and €57m in fraudulent payments recorded, three times the prior year. The 2026 programme is structured around five focus areas, all of which carry planned supervisory activities across H1 and H2.

The message running through the RSO is consistent: the Central Bank is moving from observation to active intervention. Firms that have not already aligned their compliance monitoring programmes to these priorities should treat that as urgent.

Safeguarding: the new PCF role is not optional

Safeguarding remains the area of most immediate concern. The Central Bank has been explicit that significant deficiencies persist despite repeated supervisory engagement. The new PCF Head of Safeguarding role became effective in February 2026. Firms that have not yet appointed an approved holder or embedded the role in their governance structure are already behind. The 2026 programme includes assessment of the operational effectiveness of safeguarding processes, review of actions taken to address previously identified gaps, and follow-up on the PCF implementation. Expect this to be a live topic throughout the year.

Financial crime: the REQ submission raises the bar

Firms are continuing to show insufficient understanding of their own ML/TF risk exposure. The enhanced REQ submission will require quantitative and qualitative ML/TF risk data that many firms' current data infrastructure cannot readily produce. A cross-sectoral review of fraud controls and the fair treatment of fraud victims is also in scope. Firms whose fraud controls have not kept pace with their transaction volumes are exposed.

Wind-down plans: credible and actionable, not filed and forgotten

The Central Bank has flagged business model resilience as a focus area, driven by competition, high operating costs and market saturation. A thematic review of financial resilience, strategic planning and wind-down plans is planned for H2 2026. The standard is clear: wind-down plans must be credible and actionable and must prioritise the timely return of customer funds. A plan that has not been stress-tested, does not address realistic run-off scenarios and has not been presented to the Board is not a wind-down plan. It is a document. The Central Bank knows the difference.

Active surveillance: the Central Bank does not only review what you send

Supervisors review publicly accessible information as a matter of course. Your website, your app store presence, your marketing materials and your social media channels are visible to your supervisor at any time. The Consumer Protection Code 2025 sets the standard for how firms communicate with retail customers, and the PSD2 framework imposes specific disclosure requirements. If there is a gap between what your authorisation conditions require and what a customer sees when they visit your website, that is a supervisory risk that exists today.

PCF changes: your supervisor should not learn from LinkedIn

Staff turnover at senior and regulated levels is normal. What is not acceptable is a failure to notify the Central Bank promptly when a PCF holder departs or changes role. The governance and culture thematic review will cover board composition and oversight structures, and undisclosed PCF changes create exactly the kind of gap that produces supervisory escalation. Notify the Central Bank when a PCF leaves. Do not assume it can wait for the next scheduled return.

DORA and the IT outsourcing thematic

IT outsourcing thematic findings are due in H1 2026, and DORA Registers of Information and major incident reporting assessments are live supervisory activities. Firms that treated DORA as a one-time implementation exercise rather than an ongoing operational obligation will find themselves behind when these reviews land. The Central Bank's August 2026 Dear CEO letter on ICT risk has since confirmed that direction.

What your compliance programme should look like now

The five focus areas, safeguarding, financial crime, business model resilience, operational and cyber resilience, and culture and governance, should each have an explicit mapping in your Annual Compliance Monitoring Plan for 2026. If your plan was drafted before the RSO was published and has not been reviewed against it, that review should happen now. Supervisory contact that arises because a firm was not prepared is a harder conversation than one where the firm can show it identified the gap and addressed it.

Request the full briefing from the Regulatory Briefings page, or see how Finvisor supports payment and e-money firms.

Share this post