After a Financial InnovateHER panel on PSD3 and the Payment Services Regulation, Simon McFeely sets out how he would prioritise DORA, AMLR, Instant Payments, the PSR and PSD3 over the next six months, and why they belong on one roadmap.

By Simon McFeely, Managing Director, Finvisor.
Last week I had the pleasure of joining a Financial InnovateHER panel at Rippling’s Dublin office to discuss PSD3 and the new Payment Services Regulation.
Valerie Masterson did a great job moderating the discussion, and I was joined by Hannah Vero from A&L Goodbody, Elaine Deehan from Monzo and Fiona Jelly from Complyfirst.
We spent much of the evening talking about PSD3 and PSR. But, for me, one of the most useful questions came right at the end: what is the most important thing a Compliance Officer should take away from all of this?
I was asked for one thing. Naturally, I gave three. My answer was broadly:
I’ve been thinking about that answer since. Because PSD3 and PSR don’t exist in isolation.
For an Irish payment or e-money firm, the volume of regulatory change coming through at the same time is significant: DORA, the Instant Payments Regulation, AMLR and its supporting technical standards, PSR, PSD3 and a wider supervisory focus on operational resilience, financial crime, fraud and consumer outcomes.
For some crypto firms, several of those developments will also overlap with MiCA and the new AML framework.
The biggest risk for a Compliance Officer right now may not be missing a new piece of legislation. It may be trying to do everything at once.
So, if I were running Compliance in an Irish PI or EMI today, what would my next six months look like? I’d prioritise the work roughly as follows.
Timing: applies now.
DORA would be at the top of my list. Not because it is new. It isn’t.
DORA has applied since January 2025 and there was no transitional period. The Central Bank has been clear that firms should already have identified their gaps and have a structured approach for addressing them. Its 2026 supervisory outlook continues to place operational resilience and technology risk firmly on the supervisory agenda.
So I would move the conversation away from “Do we have a DORA framework?” and towards “Can we demonstrate that the framework actually operates?”
That means testing the ICT risk framework, incident processes, third-party arrangements, registers, business continuity arrangements and resilience testing. It means understanding where your critical services depend on third parties. And, importantly, it means conducting a genuine gap analysis rather than producing another policy document.
If the regulator walked in tomorrow, could you evidence the operation of the controls? That is the question.
Timing: applies from 10 July 2027.
Next, I would turn to AMLR. The temptation with a new AML regime is to start rewriting the AML policy. I wouldn’t. I would start with the customer journey.
AMLA has now published its final draft RTS on Customer Due Diligence under Article 28(1) AMLR, alongside other important standards supporting the new Single Rulebook. Those standards provide considerably more detail around what information and documentation firms will need to collect and how CDD is expected to operate.
For a payment firm, I would map:
Regulatory requirement → customer journey → data requirement → verification → system → control → evidence.
Ask practical questions:
That is where AMLR implementation becomes real. It is not primarily a policy rewrite exercise. It is an operating-model exercise.
Timing: 9 April 2027.
For Irish payment institutions and EMIs, the Instant Payments Regulation should now be a live implementation programme.
Non-bank PSPs in euro-area Member States are due to be able to send and receive euro instant credit transfers by 9 April 2027. That leaves very little time.
And this isn’t simply a payments-operations project. There are significant financial-crime implications.
The sanctions-screening model is different: for targeted financial restrictive measures, PSPs offering instant payments must verify their customers immediately following new or amended measures and at least daily, rather than simply transaction-screening the payer and payee again during each instant payment.
At the same time, fraud and AML monitoring need to operate in a world where the payment is completed in seconds. So I would already be asking:
Instant payments are not just about making an existing payment faster. They force firms to rethink the control environment around the payment.
Further reading: Instant Payments Regulation: are Irish payment and e-money firms fit for April 2027?
Timing: start now.
Next would be the Payment Services Regulation. The current compromise text contains detailed provisions around transaction monitoring and fraud prevention.
One particularly important development is the relationship between transaction monitoring and a PSP’s obligation to suspend a transaction where there are objectively justified reasons to suspect fraud. Under the agreed text, failure to suspend in those circumstances can have direct consequences for who bears the financial loss.
That starts moving transaction monitoring beyond being simply a financial-crime control. It becomes central to customer protection, liability and the economics of fraud.
So I would not leave PSR implementation with Legal to interpret and return with a requirements paper in 12 months. I’d bring together Compliance, Fraud, Operations, Product, Technology and Legal now.
Those technology changes will almost certainly have the longest lead time.
Timing: start now.
Finally, I would start preparing for PSD3. And this is where I half-corrected Hannah during the panel, so Hannah, my apologies!
We were discussing the implementation period and I jumped in with 21 months rather than 27. The more complete answer is that the current compromise texts use 21 months as the principal PSR application and PSD3 transposition period, while the transitional provisions can allow existing authorised firms to continue operating for up to 27 months, subject to the relevant requirements.
But the more important point isn’t whether the number is 21 or 27. It is this: don’t assume your existing authorisation simply rolls forward untouched.
Some Irish PIs and EMIs obtained their authorisations many years ago. Since then the firm may have changed significantly. Products have changed. Customers have changed. Distribution models have changed. Technology stacks have changed. Outsourcing arrangements have changed. Geographical footprints have changed.
And in some cases, the original Programme of Operations bears only a passing resemblance to the business operating today.
So I’d retrieve the original authorisation pack now, compare it with the firm that exists today and update the Programme of Operations. Then check:
And start building the evidence that will ultimately support the transition into the new regime.
The conclusion I’ve come to since the panel is that Compliance Officers need to resist managing each regulatory change as an independent project.
They overlap. So the right approach is not a DORA project, an AMLR project, an IPR project, a PSR project and a PSD3 project.
It is to build one regulatory change map across the business. For every material requirement, ask:
That gives the Compliance Officer something much more useful than five separate gap analyses. It gives them a regulatory implementation roadmap.
And, more importantly, it lets the Board see where regulatory change is competing for the same technology, operational and compliance resources.
If I were a Compliance Officer in an Irish payment or e-money firm today, that is what I would want in front of me for the next six months. Because there is a lot coming.
The firms that deal with it best will not necessarily be the firms with the biggest Compliance teams. They will be the ones that prioritise early, understand how the requirements connect, and turn regulation into actual changes in the business.
At Finvisor Fintech Partners, this is increasingly the conversation we’re having with payment, e-money and crypto firms: moving beyond “what does the regulation say?” to “what actually needs to change in the firm?”
And that, for me, was the biggest takeaway from last week’s discussion.
To talk about your regulatory change roadmap, see how Finvisor supports payment and e-money firms or contact info@finvisor.global.
We use strictly necessary cookies to run this site, and optional analytics cookies (Google Analytics) to understand how it is used. Analytics cookies are only set if you accept them. See our Cookie Policy and Privacy Policy.