Payments

CBI Regulatory and Supervisory Outlook 2026: what it means for payment and e-money firms

The Central Bank has set its stall out for 2026: fraud governance, AML effectiveness, DORA in practice, the Consumer Protection Code, financial resilience and wind-down credibility. Our first read of the Outlook, including the harder conversation about funding, AI and whether your wind-down plan is fit for purpose.

Finvisor digest of the Central Bank of Ireland Regulatory and Supervisory Outlook 2026

Finvisor Fintech Partners, February 2026.

The Central Bank of Ireland has published its supervisory priorities for payment institutions and e-money firms for 2026, and the message is clear: the bar is rising. We have been analysing the document closely, and several themes are both expected and, in the current legislative environment, particularly telling.

Fraud and consumer protection: the headline theme

The most striking element of the 2026 priorities is the prominence given to fraud and its impact on customers. At European level PSD3 and the PSR are still working through the legislative process, but the direction is unambiguous: regulators want payment firms to take greater ownership of fraud outcomes, and the proposed liability framework around authorised push payment fraud represents a meaningful shift in how responsibility is allocated between firms and their customers. Ireland's National Payments Strategy has been explicit about fraud as a national priority. The Central Bank is not waiting for European legislation to land before asking hard questions; we have seen this before with outsourcing and operational resilience. The conversation is no longer about having a fraud policy. Supervisors will want evidence of how fraud risks are identified and managed in practice, how customer impact is measured, and what firms do when things go wrong.

AML remains a focus point

The Central Bank expects ongoing improvement in how firms identify, assess and manage financial crime risk, and the new AML REQ will generate follow-up questions. With AMLA taking shape and the new AML package on the horizon, reviews will look not just at policies but at the quality of transaction monitoring, the robustness of customer due diligence, and whether the framework is fit for the firm's actual risk profile.

Reading between the lines: DORA and the CPC

DORA entered into force in January 2025 and firms have had time to get their frameworks in order. We expect 2026 to be the year supervisors move from asking whether firms have DORA frameworks to testing whether they work: ICT risk assessments, third-party risk management and incident reporting will all be in focus. The revised Consumer Protection Code is the other area to watch, particularly the customer best interests framework, vulnerability and product suitability. For payment and e-money firms the Code's application may feel less intuitive than for traditional financial services, which is precisely why supervisors will stress-test it.

Financial resilience: the elephant in the room

This priority deserves more attention than it typically gets. There are genuine warning signals in the global economy, and for payment and e-money firms in Ireland, many of which are scaling businesses on tight margins reliant on continued investment, financial resilience is not abstract. The Central Bank is increasingly focused on whether firms hold adequate resources not just to meet capital requirements on paper but to absorb stress. Firms that have run lean on the assumption that the next round or group support will always be available need to revisit that assumption.

The harder conversation is about AI. If AI compresses the cost advantages many payment and e-money firms were built on, and if incumbents and big tech can deploy it at scale faster, the investment case for some firms changes materially. We are already seeing a capital recalibration in fintech, with investors refocusing on profitability and asking what AI-driven disruption means for a firm's position in three to five years. For firms that have not yet reached sustainable revenue, the Central Bank will want to understand whether projections have been stress-tested against scenarios where the next funding round takes longer, costs more or does not materialise.

Wind-down plans: is yours actually fit for purpose?

Many firms completed wind-down plans as an authorisation requirement and have not revisited them meaningfully since. That is a problem. A wind-down plan needs to be operationally credible, stress-tested, regularly reviewed and owned by senior management and the board. The questions supervisors are likely to ask: how long would it actually take to return client funds, and is that consistent with your safeguarding arrangements? What are the dependencies on third-party providers under stress? Is the plan realistic given your current size, complexity and footprint? Does the board understand what an orderly wind-down would require and its true cost? For firms that have grown, changed model or added product lines since authorisation, a gap analysis is overdue.

What this means for firms

Review fraud governance and stress-test it against the emerging PSD3 and PSR framework. Ensure AML risk assessments reflect business model evolution. Conduct an honest assessment of DORA implementation: does it work, or does it merely exist? Revisit CPC implementation in customer-facing processes, not just policies. Stress-test financial projections against adverse funding scenarios. Pressure-test the wind-down plan. Firms that take these priorities seriously will be far better placed to grow sustainably and retain their licences.

Read our follow-up analysis, The CBI's 2026 supervisory programme for PIs and EMIs, or see how Finvisor supports payment and e-money firms.

Share this post