error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

      Why payment and electronic money institutions should treat PSD3 as more than a regulatory filing exercise

      The European payments regulatory landscape is entering another significant period of change.

      PSD3 and the accompanying Payment Services Regulation (PSR) will reshape the existing framework for payments across Europe. The new framework also brings payment institutions and electronic money institutions within a more integrated regulatory regime, incorporating the existing e-money framework into PSD3.

      For existing payment and electronic money institutions, however, one aspect deserves particular attention: the transition of existing authorisations into the new regime.

      It would be easy to treat that predominantly as a licensing exercise.

      We think that understates the challenge.

      Reauthorisation is the trigger. The real question is: Is business behind the licence ready?

      Shane Garahy

      Partner, Risk Consulting

      KPMG in Ireland


      From authorisation to readiness

      An existing authorisation demonstrates that a firm meets the requirements of today's regulatory framework. PSD3 requires firms to consider how their existing arrangements align with the requirements of the new one.

      That distinction matters.

      The authorisation ultimately rests on the regulated organisation underneath it: its governance, financial resources, safeguarding arrangements, fraud controls, customer protections and wider policies, processes and controls.

      KPMG's existing analysis has identified potential PSD3 implications across areas including capital and own funds, safeguarding, fraud management, identification and verification and data sharing.

      For firms, the relevant question is therefore not simply:

      What do we need to submit?

      It is:

      Can we demonstrate that our operating model, governance and controls meet the requirements of the new regime?

      A firm may have comprehensive regulatory documentation and still identify gaps in the underlying business. Addressing those gaps may require considerably more than updating an application or policy.


      Three questions firms should be asking now

      The impact of PSD3 will inevitably vary depending on a firm's activities and existing regulatory arrangements.

      Organisations should understand how the new requirements apply across their permissions, products, services, entities and operating model.

      This is particularly relevant for electronic money institutions given the integration of the existing e-money regime into the future PSD3 framework.

      The objective should be a business-specific view of impact, rather than simply an inventory of regulatory change.

      Having a framework on paper and demonstrating that it operates effectively are different things.

      For each material requirement, firms should understand who owns it, how it is addressed, what controls support it and, importantly, what evidence demonstrates that those arrangements work in practice.

      That shifts the question from:

      "Do we have a policy for that?"

      to:

      "Can we demonstrate how this works?"

      That is a much stronger test of PSD3 readiness.

      Some gaps may require targeted changes to policies, documentation or governance.

      Others could reach further into the organisation.

      Safeguarding, fraud management, authentication, data and other requirements may have implications for processes, controls, technology and the wider operating model. KPMG's existing PSD3 work already identifies a number of these as areas for firms to consider as part of the transition.

      The important distinction is between regulatory documentation that needs to change and the business itself that needs to change.

      Identifying that early gives firms more scope to manage remediation in a structured way and address changes with longer implementation lead times.


      Reauthorisation can also be an opportunity

      There is a wider strategic question.

      The payments market itself is evolving alongside the regulatory framework.

      Instant payments, strengthened open banking and emerging account-to-account propositions are changing the European payments landscape. KPMG's existing research on European payments sovereignty identifies mandatory instant payments and PSD3/PSR as important developments supporting the growth of account-to-account payments alongside established card models. 

      Firms should therefore ask:

      If we need to revisit our regulated payments business anyway, are we simply going to make today's model compliant, or use the opportunity to make tomorrow's model better?

      Where change is required, PSD3 provides an opportunity to look beyond minimum compliance and consider whether the resulting operating model can also be simpler, more resilient, better controlled and better positioned for the future direction of payments.

      Reauthorisation may be the regulatory catalyst. The real opportunity is to build a payments business that is both regulator-ready and fit for what comes next.


      How KPMG can help

      KPMG brings together payments, regulatory, risk, technology and transformation expertise to help firms understand the impact of PSD3/PSR, assess their readiness, identify and remediate gaps, and prepare for transition to the new regulatory framework.

      Shane Garahy

      Partner, Risk Consulting

      KPMG in Ireland

      Solving challenges from scaling AI and modernising digital platforms to securing your infrastructure and unlocking new revenue models

      Read more in Tech

      Something went wrong

      Oops!! Something went wrong, please try again