Skip to content
Central Bank of Ireland · Ireland

ISBAR — Ireland’s bank and payment account register

Fintech Passport
October 1, 2026 · 10-min read
ISBAR — Ireland’s bank and payment account register

ISBAR is Ireland’s account register, and today it binds only credit institutions — a scope the 2024 AML package will widen. The Ireland Safe Deposit Box, Bank and Payment Accounts Register is operated by the Central Bank of Ireland under S.I. No. 46 of 2022. In-scope institutions upload a baseline file, then weekly delta files through the CBI Portal: who holds each Irish IBAN, who acts for them, and who owns them. No balances, no transactions. This guide covers who files now, what goes in the XML, how files are validated and rejected, and what payment and e-money institutions issuing Irish IBANs should build before Directive (EU) 2024/1640 brings them in.

1. What ISBAR is, and its legal basis

Article 32a of Directive (EU) 2015/849, inserted by Directive (EU) 2018/843, required every Member State to set up a centralised automated mechanism to identify, in a timely manner, the holders and controllers of IBAN-identified bank and payment accounts and of safe-deposit boxes. Ireland chose a central register rather than a data-retrieval system, and the Department of Finance gave the job of building and running it to the Central Bank.

The legal stack is four statutory instruments:

InstrumentWhat it does
S.I. No. 46 of 2022European Union (Anti-Money Laundering: Central Mechanism for Information on Safe-Deposit Boxes and Bank and Payment Accounts) Regulations 2022 — establishes the register; in force from 3 February 2022
S.I. No. 445 of 2022Amendment Regulations — among other things, limits closed-account reporting to accounts closed on or after 3 February 2022
S.I. No. 704 of 2022Gives the Revenue Commissioners access, transposing the tax-cooperation access route
S.I. No. 22 of 2023Transposes Directive (EU) 2019/1153 and extends access to the Criminal Assets Bureau and other branches of An Garda Síochána

The primary user is the Financial Intelligence Unit within An Garda Síochána. There is no public access, and the register holds no balances or other monetary information. The Central Bank notified in-scope credit institutions of their obligations in February 2023, began a phased collection from 27 February 2023, and began onboarding competent authorities from May 2023.

2. Who must report — and who does not, yet

The reporting obligation falls on credit institutions established in Ireland — using the Capital Requirements Regulation definition, including branches located in the Union — that either issue Irish IBANs or hold safe-deposit boxes. An Post is covered for activity that would make it a credit institution. A credit institution that does neither must notify the Central Bank using the IBAN Attestation Form or the Safe Deposit Box Attestation Form.

The Central Bank’s own guidance is explicit that other financial institutions issuing Irish IBANs are not yet in scope: further primary legislation is needed to extend the obligation to them, and they will be onboarded later. For an Irish-authorised payment institution or e-money institution, ISBAR is therefore a planned obligation rather than a current one.

The direction is set by Article 16 of Directive (EU) 2024/1640. It requires the national mechanisms to cover accounts held by a credit institution or financial institution, and to add virtual IBANs, securities accounts and crypto-asset accounts, with transposition due by 10 July 2027. The national mechanisms are to be interconnected through BARIS, which the Commission must deliver by 10 July 2029, and holder information must stay available for five years after closure.

3. What is reported: three parties per account

The Bank Account Register Data File carries, for each account: the IBAN, the account name, the opening date and, where applicable, the closing date. Each record then lists parties to the account in three roles:

Role codePartyNatural personNot a natural person
CAHCustomer-Account HolderForename, surname, date of birth, addressName and registered address
PPAPerson purporting to act on behalf of the CAHForename, surname, date of birth, addressName and registered address
BOCBeneficial owner of the CAHForename, surname, date of birth, addressNot permitted — a BOC is always a natural person

The Safe Deposit Box Register Data File carries the lessee’s identification and the lease period. The guidance also settles recurring edge cases. If the CAH is a natural person who is their own beneficial owner, they need not be repeated as BOC. If a CAH is an entity, its beneficial owners must be reported as BOC; where none can be identified, the senior managing officials are reported instead. Beneficial owners of a corporate PPA are not required. PPAs include powers of attorney, executors and administrators, wards of court, formally authorised third parties for vulnerable customers, and an agent, employee, partner, director or officer acting for a firm. Personal public service numbers are not collected.

4. Files, naming, size and frequency

Files are XML, one XML file per ZIP, generated against the technical schema the Central Bank publishes; the current schema dates from September 2023. Submission is through the CBI Portal, under the Anti-Money Laundering section of the return types, as either the Bank Account Register Data File or the Safe Deposit Box Register Data File. The C-Code in the filename must match the institution logged in.

  • Naming: C-Code_YYYYMMDD_BAR.zip and C-Code_YYYYMMDD_SDB.zip, with the same pattern for the XML inside.
  • Size: maximum 80 MB compressed, which the Central Bank estimates at roughly 200,000 to 300,000 records. Larger datasets go in several files.
  • Several files at once: the recommended approach is to date one file with the upload date and each further file with a different past date, so all are processed in sequence. The alternative is identical filenames uploaded one at a time, each fully processed first — indicatively 30 to 60 minutes per 80 MB file.
  • Frequency: one Initial Upload as a baseline, then a weekly delta with new records, changes (names, parties added or removed, addresses) and accounts closed since the baseline. No nil delta is required in a week without changes, and reporting on public holidays is not mandatory. The Central Bank may alter the frequency.

5. Validation, rejection and resubmission

Validation runs at three levels. A file that breaks a schema rule, or has the wrong filename, size or type, is rejected in full. At record level, records that pass are stored and records that fail are rejected individually; the failures appear in a feedback file on the CBI Portal, and the notification e-mail does not contain the detail. Only failed records are corrected at source and resubmitted.

Among the record-level rules the guidance lists: every record needs at least one person name or one entity name; every record needs at least one CAH; and every record whose CAH is an entity needs at least one BOC. That last rule is where business-account data most often breaks, because many core systems hold beneficial owners in the onboarding tool rather than against the account.

Where data cannot be supplied, the guidance prescribes substitute values so the file still loads and authorities can tell why:

SituationSubstitute values
Exemption — BO of a company listed on a regulated market with adequate disclosureFirst and last name “Exempt”, date of birth 01/01/1900, address “Exempt”, country IRL
Missing data, or characters the schema cannot carryNames “Unknown”, date of birth 31/12/1901, address “Unknown”, country TUV (plus lease dates 31/12/1901 and 02/01/1902 for safe-deposit boxes)

Substitute data is temporary. An institution using it must confirm the exact record count on the Substitute Data Confirmation Form, signed by the Head of Compliance or equivalent and sent to the ISBAR mailbox, and the Central Bank then follows up bilaterally to reduce the volume. Single-name customers are reported with the last name “No Last Name”.

6. Which accounts — and the edge cases

Every account identified by an IBAN under Regulation (EU) No 260/2012 is in scope: current, savings, demand deposit, fixed-term and notice, currency, share, loan, mortgage and corporate term deposit accounts. Accounts without an IBAN — credit cards, leasing, some corporate loans, life and pension policies — are not. The Central Bank has so far proceeded on the basis that virtual accounts are not reported, while noting they may be added; Article 16 of Directive (EU) 2024/1640 removes that discretion for virtual IBANs.

  • Closed accounts: report those closed on or after 3 February 2022; earlier closures are rejected. Closed records are deleted automatically five years after the closure date.
  • Dormant accounts: treated as open unless deemed closed; those moved to the National Treasury Management Agency and deemed closed before 3 February 2022 are not reportable.
  • Deceased customers: report the account until it is closed.
  • Accounts reopened after an erroneous closure: report as open again in the next delta with the original opening date.
  • Child accounts held in a parent’s name: the parent or guardian is the beneficial owner.

7. Three scenarios

Scenario one — an EEA bank branch issuing Irish IBANs. Facts: a bank headquartered elsewhere in the EU opens a Dublin branch and issues IE IBANs to retail customers. Rule: the branch is a credit institution established in Ireland for ISBAR purposes. What the reporting team does: obtains CBI Portal access, builds the BAR XML from the core banking system, files the Safe Deposit Box Attestation Form if it offers no boxes, and plans an Initial Upload followed by weekly deltas. Outcome: in scope from the start of IBAN issuance.

Scenario two — an Irish e-money institution issuing Irish IBANs. Facts: an EMI authorised by the Central Bank issues IE IBANs to consumers and SMEs. Rule: under the current instruments only credit institutions report; further primary legislation, and Article 16 of Directive (EU) 2024/1640 by 10 July 2027, will extend the perimeter. What the compliance officer does: records the out-of-scope position with the date and source, and starts building a CAH/PPA/BOC data model with a weekly change feed, including virtual IBANs and the account each one redirects to. Outcome: no filing today, no rebuild later.

Scenario three — a delta rejected at record level. Facts: a weekly delta returns “partially processed”; 1,200 business-account records failed. Rule: records with an entity CAH must carry at least one BOC; failed records are not stored. What the team does: downloads the feedback file, finds the beneficial owners missing from the account extract, fixes the join to the onboarding data, and resubmits only those 1,200 records. Where an owner genuinely cannot be identified, it reports senior managing officials as the guidance requires. Outcome: the register catches up in the next cycle; using “Unknown” substitutes for missing BOCs would have triggered the confirmation form and follow-up.

8. Operational guidance

ISBAR looks like a reporting task but behaves like a data-quality obligation. The Central Bank acts as data controller and states that it monitors adequacy, accuracy and currency, and raises queries with reporting institutions; it deals with the institution, not with any service provider it uses. Three controls do most of the work:

  • Event capture: every change to an account party — new signatory, change of address, ownership change found at periodic review — must reach the delta feed in the same week.
  • Reconciliation: count open IBANs in the core system against open records on ISBAR after each delta; investigate any gap.
  • Substitute-data burn-down: track the “Unknown” population by age and close it through customer remediation.

FAQ

What does ISBAR stand for?

Ireland Safe Deposit Box, Bank and Payment Accounts Register — the central account register the Central Bank of Ireland operates under S.I. No. 46 of 2022.

Do payment and e-money institutions report to ISBAR?

Not under the current instruments, which cover credit institutions. The Central Bank has said further primary legislation will extend the obligation to other financial institutions issuing Irish IBANs, and Directive (EU) 2024/1640 requires that wider scope by 10 July 2027.

How often must data be submitted?

An Initial Upload, then weekly delta files with new records, changes and closures. No nil delta is needed in a week without changes.

Which channel and format?

XML files, one per ZIP, named C-Code_YYYYMMDD_BAR.zip or _SDB.zip, uploaded through the CBI Portal under the Anti-Money Laundering return types, with an 80 MB compressed limit per file.

Does ISBAR include balances or transactions?

No. It holds identity data on holders, representatives and beneficial owners, plus IBAN, account name and dates.

Who can search ISBAR?

The FIU within An Garda Síochána, and under later instruments the Criminal Assets Bureau, other Garda branches and the Revenue Commissioners. There is no public access.

How long are closed accounts kept?

Records reported as closed are deleted automatically five years after the closure date recorded on the register.

What to do, today

  • If you are a credit institution issuing IE IBANs: reconcile open IBANs with open ISBAR records and clear any substitute-data backlog.
  • If you are a PI or EMI issuing IE IBANs: document the current out-of-scope position and start the CAH/PPA/BOC data model, including virtual IBANs.
  • Make sure beneficial owners sit against the account, not only in the onboarding tool.
  • Wire party changes into a weekly change feed now; it is the hardest part to retrofit.

Related: Account registers compared across the EU · Central Bank of Ireland Portal returns · RBO Ireland

Related reads.