AML / CTF

CBI Financial Crime Bulletin, Issue 2: the NRA, the REQ cycle, sanctions and trusts, and the APP fraud thematic

The Central Bank's July 2026 Financial Crime Bulletin knits together Ireland's third National Risk Assessment, the REQ data programme, AMLA's build-out and three live thematic reviews. Payment firms, EMIs and CASPs are rated Very Significant for ML/TF risk. Refresh the BWRA before the CBI asks whether you have.

Finvisor briefing on the Central Bank of Ireland Financial Crime Bulletin, Issue 2

Finvisor Regulatory Briefing, issued 25 July 2026. Board, MLRO and Head of Compliance reading for payment and e-money institutions, CASPs, credit institutions and funds.

A regulator joining the dots on financial crime

The Central Bank of Ireland published Issue 2 of its biannual Financial Crime Bulletin in July 2026, now covering market abuse alongside AML, CFT, financial sanctions and fraud. It is anchored by Ireland's third National Risk Assessment, published in June 2026 with a new Priority Action Plan and, for the first time, a formal assessment of proliferation financing risk.

The NRA rates Ireland's overall money laundering threat as Moderate, driven principally by drug offences and fraud, with criminal networks combining cash-based methods, crypto-assets and money mule networks. Terrorist financing and proliferation financing threats are assessed as Low. Retail and digital banks, e-money institutions, payment institutions and CASPs are all rated Very Significant for ML/TF risk. For payments and e-money the message is blunt: much deeper work is required on risk management and control frameworks.

Our view: the bulletin ties together the NRA, the REQ data programme, AMLA's build-out and three live thematic reviews, on APP fraud in banking and payments, STR reporting in funds, and market abuse frameworks. Each will produce findings-based supervisory expectations. Firms should assume their frameworks will be measured against these outputs and refresh their business-wide risk assessment against the NRA before the Central Bank asks whether they have.

What the Central Bank is telling the sector

Payments and e-money: much deeper work required. Some firms have strengthened AML/CFT frameworks, but the Central Bank wants governance, systems, controls and reporting proportionate to the nature, scale and complexity of each business. AI-driven social engineering is now described as a primary threat.

The NRA is required reading. All regulated entities and designated persons are encouraged to read the June 2026 NRA and use it to inform their risk-based approach. Sector ratings of Very Significant should flow directly into business-wide risk assessments.

Five expectations for managing financial crime risk. Understand your firm-specific risks; invest in controls built on good-quality data and calibration; handle and report systems failures promptly, internally and to the regulator; report suspicious activity effectively; embrace technology with care.

The APP fraud thematic will reset expectations. A thematic review of authorised push payment fraud controls in banking and payments is under way. Firms must prevent, detect and report fraud and support victims in a consumer-centric way. Payment fraud reported by Irish PSPs reached €160m in 2024, up from €102m in 2022, with 815,000 fraudulent transactions, more than double 2022 levels.

Sanctions and trusts: substance over form. Three Court of Justice judgments of 21 May 2026 (Cases C-483/23, C-428/24 and C-476/24) confirm that EU asset freezes reach trust assets where a sanctioned person exercises substantive control or influence, regardless of formal legal title. Firms must run a reality-based control analysis, a granular trust deed review and an assessment of de facto influence and benefit. Where due diligence gives reasonable grounds for suspicion, freeze the assets and report immediately to An Garda Síochána and the Central Bank Financial Sanctions Team.

STORs drive enforcement, and the Central Bank wants more. The majority of live enforcement investigations began with a suspicious transaction and order report. The Central Bank expects proactive reporting backed by effective surveillance and is running a thematic assessment of market abuse frameworks.

Key dates

  • June 2026: third NRA and Priority Action Plan published. Map findings and sector ratings into the BWRA.
  • 9 September 2026: payments and e-money REQ submission relating to 2024 and 2025 data. Confirm data owners now.
  • H2 2026: enhanced REQ rollout continues; APP fraud, funds STR and market abuse thematics in progress. Self-assess now rather than waiting for publication.
  • March 2027: REQs relating to 2026 data, standardised across all sectors to align with AMLA's reporting framework. Plan for the shortened cycle.
  • 2028 onwards: annual REQ submission each March. Embed REQ production as a business-as-usual process.

Cross-cutting developments

AMLA's Single Programming Document 2026 to 2028 sets priorities across completing the Single Rulebook, supervisory convergence and FIU cooperation; the Central Bank sits on its internal committees and is inviting private-sector feedback. Central Bank research from April 2026 found that over a third of Irish adults have experienced fraud or scams, nearly two thirds of victims lost money and 38% never reported it; 57% of those who reported recovered funds against 13% who did not. The Central Bank also flags a rise in fraud loss recovery scams targeting prior victims for upfront fees, and suggests firms warn previously affected customers directly.

Questions your firm should be asking now

Board. Can we demonstrate an understanding of our key ML/TF risks and the adequacy of our control framework? Has the June 2026 NRA been briefed to us and reflected in our risk appetite and BWRA? Are we resourced for the REQ cycle and AMLA-driven data demands through to March 2027 and beyond? Does our MI on fraud losses, victim outcomes and systems failures give a picture that would withstand supervisory scrutiny?

MLRO. Has the BWRA been refreshed against the NRA's findings and the Very Significant sector rating? Are transaction monitoring and screening models calibrated on good-quality data with documented governance? When systems fail, is there a tested route to prompt escalation and reporting? Would our STR processes withstand the scrutiny being applied to the funds sector?

Head of Compliance. Does our sanctions due diligence apply the substance-over-form test to trusts and complex structures, with freeze-and-report procedures? Are we self-assessing against the APP fraud thematic now? Are we tracking AMLA consultations and responding where draft standards are material? If we execute orders, is STOR reporting backed by effective surveillance?

How Finvisor can help

We refresh business-wide risk assessments against the NRA's threat findings, sector ratings and the Central Bank's five expectations; build substance-over-form sanctions and trust due-diligence frameworks; prepare REQ data for your sector's submission date with gap analysis against AMLA's emerging technical standards; and review fraud prevention, detection, reporting and victim support ahead of the updated APP fraud expectations. See our AML/CTF services or email info@finvisor.global.

This briefing reflects Finvisor's interpretation of the Central Bank of Ireland Financial Crime Bulletin, Issue 2 (July 2026) and does not constitute legal or regulatory advice.

Share this post