Skip to content
Banca d'Italia · Italy

CAI — the Centrale di allarme interbancaria

Fintech Passport
September 4, 2026 · 10-min read
CAI — the Centrale di allarme interbancaria

The Centrale di allarme interbancaria is the Italian archive of irregular cheques and payment cards, and a card issuer operating in Italy is a reporting entity in it from the day it issues its first card. It is held at the Banca d’Italia under Article 10-bis of Law 386 of 15 December 1990, it is divided into segments with different retention periods and different legal consequences, and its deadlines are counted in same-day and next-day terms rather than in weeks. This is what the CAI holds, which segment a payments firm actually touches, what the clock looks like, and where the responsibility for an error sits.

1. What the CAI is, and who feeds it

The archive was created by Article 10-bis of Law 386/1990, as amended by Legislative Decree 507 of 30 December 1999 and Legislative Decree 218 of 15 December 2017. Its operating rules come from two further instruments that a compliance team should have on file: the Decree of the Minister of Justice no. 458 of 7 November 2001 and the Banca d’Italia Regulation of 29 January 2002, both as subsequently amended. The Banca d’Italia describes it as a service of general economic interest aimed at the orderly functioning of the payment system — not as a supervisory return.

The reporting entities are banks, the postal service, supervised financial intermediaries issuing payment cards, the Prefects through the Ministry of the Interior, and the Ministry of Justice. The third of those is the limb that catches a payment or e-money institution: the obligation follows the act of issuing cards, not the type of licence.

2. Six segments, six retention periods

The segments are the structure that matters, because the consequence of an entry depends entirely on which one it lands in.

SegmentWhat it recordsRetention
CAPRIDrawers of bank or postal cheques issued without authorisation or without fundsThe period the revocation is effective
PASSIdentifying details of cheques not returned after revocation, and of cheques and money orders reported stolen or lost10 years
CARTERPersons whose authorisation to use a payment card has been revoked, plus any later full payment of the debt2 years
PROCARIdentifying details of revoked, stolen or lost payment cards2 years
ASA / ASPAdministrative penalties for issuing cheques without authorisation or funds, and criminal-court penalties for breaching themAs indicated by the reporting authority

The difference between CAPRI and CARTER is the point most often missed by firms new to the market. A CAPRI entry revokes every authorisation to issue cheques for six months and, for the same period, bars any bank or post office from concluding a new cheque agreement with that person or from paying cheques drawn after the entry — even cheques with funds behind them. A CARTER entry does none of that. It is informational: each issuer decides for itself whether to give a card to someone recorded in the archive. One segment removes capacity by operation of law; the other supplies a fact.

3. The clock

The deadlines that bind a card issuer are unusually short, and all three sit in the Banca d’Italia Regulation.

  • Revocation of a card authorisation: the issuer reports the card details and the holder’s identity to the central section on the same day the revocation is decided (Art. 8(1), as amended by the measure of 25 March 2021 published in the Gazzetta Ufficiale of 8 April 2021).
  • Later payment in full: where the holder subsequently settles everything owed on the revoked card, the issuer reports that too — by the day after the payment (Art. 8(2) and (4)).
  • Lost or stolen cards and cheques: reported on the same day the customer’s notification is received (Art. 9(1)). The operating manual may extend the same treatment to instruments blocked for other reasons.

Registration itself is not instantaneous. The archive runs in three timed phases: reporting entities transmit, the operator returns the flow to the holders of remote sections for reconciliation, and only then are the data registered and simultaneously consultable centrally and remotely. In the operating timetable this resolves to entry at 00:00 on day T+2, with the return flow to reporting entities running between 11:00 on day T and 15:00 on day T+1. For a system revocation following a cheque issued without funds, day T is itself the sixty-first working day after the deadline for presenting the cheque for payment. A revocation is therefore a scheduled event with a date that can be told to the customer in advance — and the Regulation requires exactly that, by making the drawee state in the notice of revocation the date on which the entry would be made.

4. Worked example — revoking a card

Facts: an EU e-money institution operating in Italy issues cards to consumers. A holder accumulates unpaid amounts and, after the internal process runs, the issuer decides on 14 April to revoke the authorisation to use the card.

What the rule says: the report to CARTER, and to PROCAR for the card’s own identifying details, goes to the central section on 14 April — the day the revocation is decided, not the day the letter goes out and not the day the balance is written off. The holder’s data stays in CARTER for two years; the card details stay in PROCAR for two years.

What the practitioner does: makes the reporting trigger the collections decision itself, wired to the case-management step that records the revocation, rather than to a nightly batch over a status field. A same-day duty cannot be met by a process that starts when someone reads a report the next morning. The second design point is the pair: CARTER and PROCAR are separate segments carrying different data about the same event, and an implementation that populates only the person segment leaves the card itself absent from the archive that other issuers consult.

5. Worked example — the holder pays late

Facts: the same holder settles everything owed on the revoked card on 3 September, sixteen months into the two-year registration, and asks the issuer to have the entry removed.

What the rule says: the issuer must report the payment by 4 September, the day after. But the Regulation is explicit that this report has no effect on how long the personal identifying data stays registered. The late-payment flag itself remains recorded until the CARTER entry it attaches to expires. The two years run from the revocation and are not shortened by paying.

What the practitioner does: writes that into the customer-facing script before the first such call arrives. The 2021 amendment was introduced precisely so that a person who settles can demonstrate it — it creates a new piece of information for the holder and for other institutions, not a right to removal. A firm that promises deletion in exchange for payment creates a complaint it cannot resolve, because the deletion is not in its gift.

6. Worked example — a report that lands late or wrong

Facts: a report is transmitted with a tax code that does not reconcile, and the entry is delayed while it is corrected.

What the rule says: where registration is delayed because a report was late, incomplete or carried an inconsistent tax code — and where a fresh report replaces one that did not allow the person to be identified — the reporting entity bears responsibility for making the necessary communications to the people concerned. And where a replacement report is filed because the original could not identify the subject, the period of effectiveness of a system revocation runs from the registration of the new report, not the original.

What the practitioner does: treats identifier quality as a legal deadline rather than a data-quality metric, because a bad identifier does not merely produce a rejection — it moves the start date of a measure that restricts a person’s ability to transact, and hands the firm a notification duty it did not plan for. Validate the tax code at the point the revocation decision is recorded, not at the point the file is assembled.

7. Consultation, logging and access

Every consultation by a private reporting entity or by a Prefect must be logged so that the individual who made it, its object and its date are certain and cannot be altered. That is a records requirement with a control objective behind it: the archive contains data about people who are not the firm’s customers, and the log is the only evidence of why it was looked at. Judicial authorities consult the central section directly, and their accesses are logged at both ends.

Access by the person concerned runs through the private reporting entities or through the branches of the Banca d’Italia, and it is free at the Banca d’Italia — no charge for either named or unnamed information. Requests can be made at a counter, through the Banca d’Italia’s online services platform, or by post; where a request is made online with a national digital identity credential and concerns the requester’s own data, the outcome appears in their personal area. Non-named data can also be accessed where there is an interest connected with the use of cheques and cards, at reporting entities offering that service and at Banca d’Italia branches.

FAQ

What is the CAI?

The Centrale di allarme interbancaria, the computerised archive of irregular cheques and payment cards held at the Banca d’Italia under Article 10-bis of Law 386/1990, organised into segments for cheque drawers, unreturned and stolen instruments, revoked card holders, revoked cards, and penalties.

Is a payment or e-money institution a reporting entity?

Supervised financial intermediaries issuing payment cards are listed among the private reporting entities, so a firm issuing cards in Italy reports card revocations and lost or stolen cards on the same terms as a bank.

How long does a CARTER entry last?

Two years. Reporting a subsequent payment in full does not shorten that period; it adds an item of information alongside the existing entry.

What does a CAPRI entry actually do?

It revokes every authorisation to issue cheques for six months and, for the same period, bars any bank or post office from concluding a new cheque agreement with that person or paying cheques drawn after the entry, even if funded.

Who fixes an incorrect entry?

The reporting entity that made it. The Banca d’Italia manages the archive but does not assess individual reports, so requests for correction or deletion go to the reporting entity.

When must a revoked card be reported?

On the same day the revocation is decided, with the identifying details of the card reported to the card segment at the same time.

What to do, today

  • Compliance officer: confirm which segments your Italian operation writes to and reads from, and hold the three source instruments — Law 386/1990, Ministerial Decree 458/2001 and the 2002 Regulation — as named references in the procedure.
  • Operations lead: move the reporting trigger onto the revocation decision itself. A same-day duty cannot be discharged by an overnight batch.
  • Customer-facing lead: script the late-payment answer now — the flag is recorded, the two years are not shortened, and deletion is not available in exchange for payment.
  • Data owner: validate the tax code at the point of decision. A bad identifier moves the start date of the measure and creates a notification duty on the firm.
  • Risk and audit: check that consultations are logged with user, object and date in a form that cannot be altered, and that the remote section is maintained to the standard the Regulation expects.

Related: Centrale dei Rischi — the Italian credit register · Anagrafe dei rapporti finanziari · FCC and FNCI — the French equivalents · Card fraud typologies in PSD2 reporting

Related reads.