Payments

Five regulations, one roadmap: what I would prioritise as a Compliance Officer in an Irish PI or EMI

After a Financial InnovateHER panel on PSD3 and the Payment Services Regulation, Simon McFeely sets out how he would prioritise DORA, AMLR, Instant Payments, the PSR and PSD3 over the next six months, and why they belong on one roadmap.

Five regulations, one roadmap: DORA applies now, AMLR from 10 July 2027, Instant Payments by 9 April 2027, PSR and PSD3 start now.

By Simon McFeely, Managing Director, Finvisor.

Last week I had the pleasure of joining a Financial InnovateHER panel at Rippling’s Dublin office to discuss PSD3 and the new Payment Services Regulation.

Valerie Masterson did a great job moderating the discussion, and I was joined by Hannah Vero from A&L Goodbody, Elaine Deehan from Monzo and Fiona Jelly from Complyfirst.

We spent much of the evening talking about PSD3 and PSR. But, for me, one of the most useful questions came right at the end: what is the most important thing a Compliance Officer should take away from all of this?

I was asked for one thing. Naturally, I gave three. My answer was broadly:

  1. Map the regulation against the customer journey.
  2. Map the resulting changes into your systems, controls and technology.
  3. Then prioritise what actually needs to be done over the next six months.

I’ve been thinking about that answer since. Because PSD3 and PSR don’t exist in isolation.

The real risk is doing everything at once

For an Irish payment or e-money firm, the volume of regulatory change coming through at the same time is significant: DORA, the Instant Payments Regulation, AMLR and its supporting technical standards, PSR, PSD3 and a wider supervisory focus on operational resilience, financial crime, fraud and consumer outcomes.

For some crypto firms, several of those developments will also overlap with MiCA and the new AML framework.

The biggest risk for a Compliance Officer right now may not be missing a new piece of legislation. It may be trying to do everything at once.

So, if I were running Compliance in an Irish PI or EMI today, what would my next six months look like? I’d prioritise the work roughly as follows.

1. DORA: prove that it works, not that you have the documents

Timing: applies now.

DORA would be at the top of my list. Not because it is new. It isn’t.

DORA has applied since January 2025 and there was no transitional period. The Central Bank has been clear that firms should already have identified their gaps and have a structured approach for addressing them. Its 2026 supervisory outlook continues to place operational resilience and technology risk firmly on the supervisory agenda.

So I would move the conversation away from “Do we have a DORA framework?” and towards “Can we demonstrate that the framework actually operates?”

That means testing the ICT risk framework, incident processes, third-party arrangements, registers, business continuity arrangements and resilience testing. It means understanding where your critical services depend on third parties. And, importantly, it means conducting a genuine gap analysis rather than producing another policy document.

If the regulator walked in tomorrow, could you evidence the operation of the controls? That is the question.

2. AMLR: start with the customer journey

Timing: applies from 10 July 2027.

Next, I would turn to AMLR. The temptation with a new AML regime is to start rewriting the AML policy. I wouldn’t. I would start with the customer journey.

AMLA has now published its final draft RTS on Customer Due Diligence under Article 28(1) AMLR, alongside other important standards supporting the new Single Rulebook. Those standards provide considerably more detail around what information and documentation firms will need to collect and how CDD is expected to operate.

For a payment firm, I would map:

Regulatory requirement → customer journey → data requirement → verification → system → control → evidence.

Ask practical questions:

  • What additional information will we need from an individual customer?
  • What changes for corporate customers?
  • Where does that information enter our onboarding journey?
  • Can our existing KYC provider capture and verify it?
  • What happens to conversion? What happens to abandonment?
  • Does the information feed properly into the customer risk assessment?
  • Does the risk rating then drive the appropriate due diligence and monitoring?

That is where AMLR implementation becomes real. It is not primarily a policy rewrite exercise. It is an operating-model exercise.

3. Instant Payments: April 2027 is much closer than it sounds

Timing: 9 April 2027.

For Irish payment institutions and EMIs, the Instant Payments Regulation should now be a live implementation programme.

Non-bank PSPs in euro-area Member States are due to be able to send and receive euro instant credit transfers by 9 April 2027. That leaves very little time.

And this isn’t simply a payments-operations project. There are significant financial-crime implications.

The sanctions-screening model is different: for targeted financial restrictive measures, PSPs offering instant payments must verify their customers immediately following new or amended measures and at least daily, rather than simply transaction-screening the payer and payee again during each instant payment.

At the same time, fraud and AML monitoring need to operate in a world where the payment is completed in seconds. So I would already be asking:

  • Can our transaction-monitoring architecture operate at the speed required?
  • Which controls need to operate pre-transaction?
  • Which can operate post-transaction?
  • How quickly can an alert be decisioned?
  • What happens outside business hours?
  • How do sanctions, AML and fraud controls interact?
  • What data do we have before execution?

Instant payments are not just about making an existing payment faster. They force firms to rethink the control environment around the payment.

Further reading: Instant Payments Regulation: are Irish payment and e-money firms fit for April 2027?

4. PSR: start building the fraud-control architecture now

Timing: start now.

Next would be the Payment Services Regulation. The current compromise text contains detailed provisions around transaction monitoring and fraud prevention.

One particularly important development is the relationship between transaction monitoring and a PSP’s obligation to suspend a transaction where there are objectively justified reasons to suspect fraud. Under the agreed text, failure to suspend in those circumstances can have direct consequences for who bears the financial loss.

That starts moving transaction monitoring beyond being simply a financial-crime control. It becomes central to customer protection, liability and the economics of fraud.

So I would not leave PSR implementation with Legal to interpret and return with a requirements paper in 12 months. I’d bring together Compliance, Fraud, Operations, Product, Technology and Legal now.

  1. Map the requirements.
  2. Map your current fraud decisioning.
  3. Identify the gaps.
  4. Work out which changes require technology development.

Those technology changes will almost certainly have the longest lead time.

5. PSD3: dust off the original authorisation file

Timing: start now.

Finally, I would start preparing for PSD3. And this is where I half-corrected Hannah during the panel, so Hannah, my apologies!

We were discussing the implementation period and I jumped in with 21 months rather than 27. The more complete answer is that the current compromise texts use 21 months as the principal PSR application and PSD3 transposition period, while the transitional provisions can allow existing authorised firms to continue operating for up to 27 months, subject to the relevant requirements.

But the more important point isn’t whether the number is 21 or 27. It is this: don’t assume your existing authorisation simply rolls forward untouched.

Some Irish PIs and EMIs obtained their authorisations many years ago. Since then the firm may have changed significantly. Products have changed. Customers have changed. Distribution models have changed. Technology stacks have changed. Outsourcing arrangements have changed. Geographical footprints have changed.

And in some cases, the original Programme of Operations bears only a passing resemblance to the business operating today.

So I’d retrieve the original authorisation pack now, compare it with the firm that exists today and update the Programme of Operations. Then check:

  • Governance
  • Safeguarding
  • Outsourcing
  • Financial projections
  • The control functions and resourcing model

And start building the evidence that will ultimately support the transition into the new regime.

The common theme: stop managing regulation regulation-by-regulation

The conclusion I’ve come to since the panel is that Compliance Officers need to resist managing each regulatory change as an independent project.

  • DORA affects technology and outsourcing.
  • AMLR affects onboarding, KYC, customer risk assessment and monitoring.
  • Instant payments affect payment processing, sanctions, fraud and transaction monitoring.
  • PSR affects fraud controls, liability, customer journeys and technology.
  • PSD3 ultimately brings much of the organisation back into the regulatory authorisation process.

They overlap. So the right approach is not a DORA project, an AMLR project, an IPR project, a PSR project and a PSD3 project.

It is to build one regulatory change map across the business. For every material requirement, ask:

  1. What regulation is changing?
  2. Where does it touch the customer or payment journey?
  3. Which process or control changes?
  4. Which system supports that control?
  5. What needs to be built or changed?
  6. Who owns it?
  7. When must it be completed?

That gives the Compliance Officer something much more useful than five separate gap analyses. It gives them a regulatory implementation roadmap.

And, more importantly, it lets the Board see where regulatory change is competing for the same technology, operational and compliance resources.

If I were a Compliance Officer in an Irish payment or e-money firm today, that is what I would want in front of me for the next six months. Because there is a lot coming.

The firms that deal with it best will not necessarily be the firms with the biggest Compliance teams. They will be the ones that prioritise early, understand how the requirements connect, and turn regulation into actual changes in the business.

At Finvisor Fintech Partners, this is increasingly the conversation we’re having with payment, e-money and crypto firms: moving beyond “what does the regulation say?” to “what actually needs to change in the firm?”

And that, for me, was the biggest takeaway from last week’s discussion.

To talk about your regulatory change roadmap, see how Finvisor supports payment and e-money firms or contact info@finvisor.global.

Share this post