Payments

What the BlueSnap enforcement teaches payment firms about safeguarding

In November 2024 the Central Bank fined BlueSnap Payment Services Ireland €324,240 for safeguarding, notification and reconciliation failures. With a PCF Head of Safeguarding now in place and safeguarding a 2026 supervisory priority, the lessons are more relevant than ever.

Safeguarding of customer funds, illustrating lessons from the BlueSnap enforcement

Finvisor Fintech Partners. First circulated to clients in November 2024; republished in September 2026 with the 2026 context added.

What happened

On 26 November 2024 the Central Bank of Ireland imposed a monetary penalty of €324,240 on BlueSnap Payment Services Ireland Limited and reprimanded the firm for breaches of the European Union (Payment Services) Regulations 2018 between January 2021 and December 2022. The case turned on three failures. The firm did not deposit users' funds into designated safeguarding accounts and allowed them to be mixed with funds that were not users' funds. It delayed informing the Central Bank of its control failures and did not disclose that it had deviated from the safeguarding arrangements described at authorisation. And the investigation found a breakdown in governance, inadequate or missing daily reconciliations of safeguarding accounts, and insufficient measures to segregate funds at a user-specific level.

The rule at the centre of the case

Regulation 17 of the PSR 2018 defines users' funds as funds received by a payment institution from a payment service user, or through another payment service provider, for the execution of a payment transaction. Those funds shall not be mixed at any time with the funds of any person other than the user on whose behalf they are held, and where they are still held by the institution at the end of the business day after receipt they must be deposited in a separate account with a credit institution or invested in assets the Central Bank has approved as secure, liquid and low-risk. The Central Bank had already set out its expectations in a Dear CEO letter in September 2021; BlueSnap's breaches ran through the following year.

Five lessons for payment and e-money firms

Heart and mind. The Central Bank consistently raises this. The local team in Ireland must be fully empowered to oversee its regulatory obligations. A safeguarding framework run from a group function elsewhere, with the Irish entity as a bystander, is exactly what this case describes.

Report to the Central Bank early. Firms take different approaches, but the Central Bank has repeatedly asked for transparency at all times. When issues or potential issues arise in the course of normal business, over-reporting is the safe path. Delayed notification was a breach in its own right here.

Board governance. Key threats, vulnerabilities and exposures need to be discussed and documented at Board level, with the risk register updated as often as the position changes. Safeguarding is not a back-office reconciliation topic; it is a Board matter.

Account usage by the group. The Central Bank noted that co-mingling occurred when safeguarding accounts were used for payouts relating to other group entities. Firms with similar structures should define clearly in the safeguarding policy what constitutes relevant funds, and make sure intra-group outsourcing contracts reflect it.

Check your authorisation papers. Business models change. Robust change management controls should include a check that nothing has deviated from what was described to the Central Bank at authorisation, and a notification where it has.

Why this matters more in 2026

Since this decision the Central Bank has introduced a Pre-Approval Controlled Function for the Head of Safeguarding, effective February 2026, and has made safeguarding one of five supervisory focus areas in its 2026 Outlook, with assessment of the operational effectiveness of safeguarding processes and follow-up on previously identified gaps planned through the year. The FCA has moved in parallel, with its interim-state safeguarding rules applying in the UK since May 2026. The BlueSnap case is the template for what a safeguarding enforcement looks like: co-mingling, weak reconciliation, group entanglement and late notification. Every one of those is testable today.

What we recommend

The Head of Compliance should brief the Board on the current state of safeguarding controls and on any enhancements still outstanding from earlier attestations. The Safeguarding Description Document should be current and match how funds actually flow. The control framework should be mapped to the legislative requirements and to supervisory expectations, drawing on the FCA's Approach Document where helpful. And the Board should ask internal audit, or an independent reviewer, to test the enhanced controls rather than rely on management's assurance that they were implemented.

Finvisor conducts independent safeguarding reviews and audits for payment and e-money institutions and supports firms preparing for the Head of Safeguarding PCF. See how we support payment and e-money firms or email info@finvisor.global.

Share this post