Skip to content
NBB · Belgium

OneGate — the NBB’s PI and ELMI reports (domain MBS)

Fintech Passport
September 11, 2026 · 11-min read
OneGate — the NBB’s PI and ELMI reports (domain MBS)

OneGate is the National Bank of Belgium’s collection portal, and for a payment or e-money institution it is not optional in any sense. Prudential and financial reporting goes in through domain MBS as three named reports — PI, ELMI and PI-ELMI-QUAL — and only over an electronic certificate. The filing rhythm is quarterly, due on the first business day of the second calendar month after the reporting date, and the current table versions started on 1 March 2026. Here is the channel, the XML grammar, the traps that silently change what you filed, and the tables themselves.

1. What OneGate is, and how you get in

OneGate is a secure internet collection application through which declarers complete statistical, financial and prudential declaration forms, either by typing data in or by uploading files. The Bank offers two access modes: standard secured, by user code and password, and strong secured, by electronic certificate.

For payment institutions and electronic money institutions the choice is made for you. The financial reporting of these institutions is to be done only via OneGate and only in strong-secured mode, that is by certificate. Certificate and registration questions go to the Bank’s OneGate access desk, which operates separate Dutch and French lines and a shared access.onegate mailbox.

2. The three reports in domain MBS

Domain MBS carries a wide set of reports, most of them for banks. Three are yours:

ReportWho filesWhat it is
PIPayment institutionsQuantitative reporting — balance sheet, profit and loss, payment-services figures, safeguarding, own funds, exchange transactions
ELMIElectronic money institutionsQuantitative reporting — the same spine plus statistical tables, without the exchange-transaction section
PI-ELMI-QUALBothQualitative reporting — documents uploaded directly through the interface

The quantitative reports share most of their structure. Both run 1.1.A and 1.1.B (balance sheet after appropriation, assets and liabilities), 1.2 (profit and loss), 1.3 (appropriation account), 1.4 (identification of third-party funds held and carried on the balance sheet), the 1.5 family of payment-services figures, 1.6 (cross-border detail), 1.7 (safeguarding of funds received), 2.1 (capital adequacy, with a COREP reference column) and 2.2.A, 2.2.B and 2.2.C (own-funds requirement under methods A, B and C).

Two differences matter. PI alone has section 3 — 3.1 and 3.2, the detail of exchange transactions bought and sold, split below and above €10,000 and against professional counterparties, and 3.3, the global statement of exchange transactions. ELMI alone has 1.5.A and 1.5.B, supplementary statistical tables broken down over Belgium, other euro-area countries and the rest of the world — 1.5.A for all currencies in euro equivalent and 1.5.B for euro only.

3. Periodicity and the deadline that is not month-end

The reporting scheme for payment institutions rests on Article 77 of the Law of 11 March 2018, which requires institutions to send the Bank a detailed financial position periodically, on rules and at a frequency the Bank sets, and lets it require other figures or descriptive information needed to verify compliance. The own-funds side additionally rests on the Bank’s regulation of 10 April 2018 on the own funds of payment institutions, approved by Royal Decree of 27 April 2018.

The cadence is quarterly, with two exceptions — states 1.3 (appropriation account) and 1.6 (cross-border figures) are filed annually. The deadline is the point firms get wrong: not a fixed number of days, but the first business day of the second calendar month following the reporting date. For a 31 March reference date that is the first business day of May. Statutory annual-account annexes, and consolidated accounts where they exist, go to the Bank fifteen days before the general meeting.

Two further points sit in the same section. Institutions must be organisationally capable of producing the states at a higher frequency if the Bank asks in exceptional circumstances. And where the reporting date coincides with the accounting close, the figures must reflect the position after management’s appropriation proposals to the board have been processed.

4. The XML grammar

Data can be typed in, imported table by table as XML or CSV, or uploaded as one XML report covering some or all tables. A OneGate XML report has two parts — an Administration block and a Report block — inside a DeclarationReport element on the onegate.eu/2010-01-01 namespace.

In Administration, From carries the institution’s identifier with a declarerType attribute whose value depends on the institution and report — possible values include KBO, LEI, CODE and BIC, but in general KBO is used, the Belgian enterprise number. To is NBB, Domain is MBS. An optional Response block sets a feedback e-mail address and a feedback language of NL, FR or EN; feedback defaults to true if the attribute is absent.

The Report element carries four attributes that decide what actually happens to your data:

  • code — which report the data belong to: PI, ELMI or PI-ELMI-QUAL.
  • date — the reporting period, in YYYY-MM format.
  • actionreplace clears the entire report before processing the submission; update replaces only the values present in this submission and leaves everything else from earlier uploads intact. If the attribute is absent the default is update, which is the quiet source of a whole class of reconciliation failures.
  • close — true or false, whether to close the report.

Inside, each Data form="..." block holds items made of Dim prop="..." dimension properties. The property codes are prefixed per report — PI_ or ELMI_ — and cover COL (column codes), RUB (row codes), VALNUM (decimal values), INT (integers), KEY, DATE in YYYY-MM-DD, SEQ (row ID), CNTRY (ISO 3166 two-letter), CUR (ISO 4217 three-letter), SECTION (section ID in form 1.7) and STRING. Form codes are “1.1.A”, “1.1.B” and so on, and are listed in the OneGate control panel.

The ELMI report adds a requirement PI does not have: its forms must be characterised by form dimensions, and these must be reported even for a nihil declaration. ELMI_BAS takes 10 (territorial basis), 20 (statutory basis) or 30 (consolidated basis); ELMI_CBRK takes 2 (all currencies aggregated in euro equivalent) or 5 (separate statement per relevant currency); ELMI_CUR accepts only EUR unless stated otherwise.

An empty form is declared nihil, either in the tool or with <Data form="..." action="nihil"/>. And rather than building an envelope by hand, export an empty report from the OneGate control panel — that gives you a valid, representative XML document to work from.

5. Validation, tolerance and closing

Two conventions decide whether a report is valid. First, every report must be formally closed, and closing is only possible when no initial or erroneous forms remain. Closing can be done in the control panel or by close="true" in the XML. An institution that closes the report is taken to have approved the figures and their completeness; the close is timestamped, and every form then becomes read-only. If a correction is needed afterwards, the institution must ask its prudential supervisor to reopen the report — it is not a self-service action.

Second, reporting is in euros or euro cents, with an absolute tolerance of €1,000 when validation rules are applied, to absorb rounding — except for checks on percentages or where stated otherwise. Zero-value facts may optionally be reported; until a fact is reported it is treated as zero both by the validation engine and in the Bank’s analysis environments.

The qualitative report works differently: PI-ELMI-QUAL data are provided by uploading documents directly through the OneGate interface, where they are then saved. All document types are allowed unless stated otherwise.

6. What the tables actually ask for

Three of the states carry most of the interpretation risk for a payments firm.

State 1.4, third-party funds. Article 42 of the Law of 11 March 2018 requires funds received from third parties for the execution of payment transactions to be distinctly identified in the accounts and never mixed with other funds. The table exists to check that segregation where those funds appear on the balance sheet. It captures only funds still held at the balance-sheet date, not flows that netted out during the year, and it breaks them down by the counterparty with which the funds were placed — and where that counterparty re-places the funds with a third party in the institution’s name and on its behalf, it is that third party which must be named.

State 1.5, payment-services figures. Amounts, volumes and turnover, reported year to date from the start of the statutory accounting year. The breakdown is two-dimensional: by payment service, using the numbering of Annex I to the Law of 11 March 2018, and by the geographic location of the counterparty — Belgium, the EEA excluding Belgium, and the rest of the world. No transaction may be attributed to more than one payment service. Where in and out flows differ in volume or turnover the split is required; where the distinction is not relevant, everything is reported in the out column only. The Bank may ask for an explanation where in and out amounts are not identical.

State 2.2, own-funds requirement. An institution reports only the data for the calculation method assigned to it, A, B or C. Under method A the requirement is 10% of the preceding year’s fixed overheads; where the institution has not completed a full year of activity at the calculation date, it is 10% of the overheads in its business plan, unless the Bank requires that plan to be adjusted. Overheads directly linked to activity volume — remuneration tied to transaction levels, which would not be incurred without the activity — are excluded from the base.

7. Three worked examples

One: the correction that erased three tables. Facts: a firm re-files one corrected figure in form 1.2 and submits an XML containing only that form, with no action attribute. Rule: the default is update, which replaces only submitted values — but a team that assumed replace semantics would have wiped the rest. Action: set action explicitly on every submission, use update for targeted corrections and replace only for a full refile, and reconcile the control panel after upload. Outcome: the correction lands without a silent, and in the opposite case irreversible, side effect on the other tables.

Two: the quarter closed too early. Facts: an institution closes its Q1 report on the last day of April, then finds the safeguarding figure in 1.7 was struck before an end-of-quarter reconciliation. Rule: closing is timestamped and freezes every form as read-only; reopening requires the prudential supervisor. Action: file the tables as they firm up but hold the close until the reconciliation is signed off — the deadline is the first business day of the second month after the reporting date, so a 31 March report still has the first days of May. Outcome: a supervisor conversation avoided, and the approval that closing represents made deliberately.

Three: the ELMI nihil that was rejected. Facts: an EMI with no activity in a statistical table declares the form nihil and the upload fails validation. Rule: ELMI forms must carry their form dimensions — ELMI_BAS, ELMI_CBRK and ELMI_CUR — and these must be reported even in a nihil declaration. Action: pull the accepted values from the control-panel information and attach them to the nihil declaration too. Outcome: the nihil is accepted and the report becomes closeable, since a form left in error state blocks the close.

Can a payment institution file to OneGate with a user code and password?

No. OneGate offers standard-secured access by user code and password, but the financial reporting of payment institutions and electronic money institutions must be done in strong-secured mode, by electronic certificate.

When exactly is the quarterly report due?

On the first business day of the second calendar month following the reporting date — so for a 31 March reference date, the first business day of May. States 1.3 and 1.6 are annual rather than quarterly, and annual-account annexes go in fifteen days before the general meeting.

What is the difference between action=”replace” and action=”update”?

replace initialises and clears the entire report before processing the submission; update replaces only the values present in the submission and leaves earlier values in place. If the attribute is omitted, OneGate defaults to update.

Can we reopen a report we have closed?

Not on your own. Closing is timestamped and makes every form read-only; an exceptional correction requires the institution to contact its prudential supervisor to reopen the closed report.

8. What to do, today

  • Put the OneGate certificate expiry on the same calendar as the reporting dates, and name a second holder — there is no password fallback for PI or ELMI filing.
  • Set action explicitly on every XML submission rather than relying on the update default, and record which mode each refile used.
  • Diarise the deadline as the first business day of the second month after each reference date, not as a day count, and keep 1.3 and 1.6 on the annual track.
  • Separate “filed” from “closed” in your internal control: close only once the figures are approved, because reopening runs through the supervisor.
  • Build 1.5 as a year-to-date extract keyed on the Annex I service numbering and on counterparty location, with a rule preventing a transaction being counted under two services.
  • Check that the 1.4 counterparty is the entity the funds actually sit with, following any onward placement made in your name and on your behalf.
  • Export an empty report from the control panel as the envelope template rather than hand-building one, and re-export whenever the table version changes.

Related: PCC/CAP, Belgium’s account register · ONEGATE at the Banque de France · CSSF eDesk and the S3 API · Reporting channels compared

Related reads.