EU-wide
Articles tagged EU-wide — pan-European regimes: CESOP, CRS, FATCA, DAC7/8, AnaCredit, Instant Payments, MiCA, DORA, AMLA.

Payment Accounts Directive — the fee information document, the statement of fees and the switching clock
Payment Accounts Directive for payment and e-money institutions: why Chapters II and III bind every PSP under Article 1(3), what the fee…

CARF explained — the OECD crypto-asset reporting framework, and how it lines up with DAC8
CARF explained for crypto firms: the Reporting Crypto-Asset Service Provider definition, the four nexus criteria that decide where you file, the four…

The EU AML package — AMLR, AMLD6 and AMLA dates, and what changes for payment firms
The EU AML package for payment and e-money institutions: the AMLR applies 10 July 2027, AMLD6 transposition dates from 2025 to 2029,…

E-money tokens under MiCA — the Title IV rules for issuing an EMT as an EMI
E-money tokens under MiCA Title IV: who may issue, the 40- and 20-working-day notification clocks, no redemption fee and no interest, the…

PSD2 fraud reporting under Article 96(6) — what counts, who files, and the six-month cycle
PSD2 fraud reporting under EBA/GL/2018/05 as amended by EBA/GL/2020/01: the two fraud limbs including manipulation of the payer, why blocked attempts are…

Own funds for EU payment and e-money institutions — initial capital and Methods A, B, C and D
Own funds for payment institutions and EMIs: the EUR 20,000 / 50,000 / 125,000 and EUR 350,000 initial capital floors, Methods A,…

The EU Digital Identity Wallet — why a payment firm will have to accept it, and when
Regulation (EU) 2024/1183 and the European Digital Identity Wallet: the Article 5f(2) acceptance obligation for firms subject to strong authentication requirements, the…

Funds transfer information under Regulation (EU) 2023/1113 — the intra-EU shortcut and the three-day clock
The fiat limb of Regulation (EU) 2023/1113: the full Article 4 payer and payee dataset, the intra-Union account-number-only derogation, the three-working-day retrieval…

DORA threat-led penetration testing — who is identified, who validates the scope, and the attestation
TLPT under DORA Articles 26 and 27: the competent authority identifies the entities and validates the scope, tests run on live production…

The PSD2 limited network exclusion — the three limbs, the EUR 1 million notification and how it is lost
PSD2 Article 3(k) and 3(l) explained: the three limited-network limbs, the functionally-connected test, the EUR 50 and EUR 300 telecoms caps, the…