Skip to content
EBA · EU-wide

Safeguarding reporting — the notification nobody files

Fintech Passport
August 21, 2026 · 5-min read
Safeguarding reporting — the notification nobody files

Safeguarding carries a reporting obligation that has no template, no deadline and no calendar entry — and is breached by silence. Article 3(2) of Directive 2009/110/EC requires electronic money institutions to inform the competent authorities in advance of any material change in measures taken for safeguarding of funds received in exchange for e-money issued. There is no form. There is no date. There is simply a duty to tell the supervisor before you change how customer funds are protected — and it is the single most commonly missed reporting obligation in the payments perimeter.

1. “In advance” is the operative phrase

The duty is prospective. A change implemented and then notified is a breach even if the new arrangement is better than the old one, because the supervisor’s opportunity to object has been removed.

What counts as material is a judgement, and the sensible test is whether the change alters anything the supervisor relied on when it assessed the arrangement: the method used, the institution holding the funds, the assets funds are invested in, the reconciliation frequency, or the entity performing the reconciliation. Any of those is worth a conversation; none of them is worth discovering after the fact.

2. What the supervisor is protecting

Article 10 of Directive (EU) 2015/2366 offers two methods, and the choice is itself information a supervisor holds:

SegregationInsurance or comparable guarantee
MechanismNo commingling; funds still held by the institution and not yet paid out by the end of the business day following receipt go to a separate account at a credit institution or into secure, liquid low-risk assetsCover from an insurance company or credit institution outside the group, for an amount equivalent to what would have been segregated
ProtectionInsulation under national law against other creditors, in particular on insolvencyPayable where the institution cannot meet its obligations
What a change looks likeA new holding institution, a different asset class, a changed sweep timingA new insurer, a changed limit, a group-affiliated provider

The eligible-asset definition sits with the home member state’s competent authority rather than in the Directive, so a change of investment policy is a change against a national definition — and a firm passporting across the EU answers to one definition set at home.

3. The representative portion is a supervised estimate

Where funds are partly for future payment transactions and partly for other services, and the split is variable or not known in advance, Article 10(2) allows the safeguarding requirement to be applied on the basis of a representative portion — provided it can be reasonably estimated from historical data to the satisfaction of the competent authorities.

Those last words make the methodology a reportable artefact. The percentage, the historical data behind it and its periodic re-validation are part of the safeguarding file, not an internal finance assumption — and a change to the methodology is a material change to the safeguarding measures.

4. Ongoing evidence: reconciliation and attestation

Beyond the notification duty, national frameworks increasingly require positive evidence rather than a policy on a shelf. The Luxembourg governance circular is the clearest current example, requiring daily safeguarding reconciliation and an annual attestation signed by the whole management body.

Those two together change what the control has to produce. A daily reconciliation generates 250-odd artefacts a year, and an attestation signed by the board is a statement about all of them. The practical consequence is that the reconciliation output must be retained and reviewable, not merely performed — because the attestation is only as defensible as the records standing behind it.

5. A worked case

Facts: an EMI moves part of its safeguarded funds from one holding institution to another to improve diversification, executed by treasury as a routine banking change.

What the rule says: the identity of the institution holding safeguarded funds is part of the safeguarding measures. A change to it is capable of being material, and Article 3(2) requires the competent authority to be informed in advance.

What the practitioner does: puts a gate in the treasury change process — any change touching a safeguarding account, an eligible-asset class, the insurance arrangement or the reconciliation model requires a compliance sign-off, and that sign-off asks one question: does the supervisor need to be told first. The notification itself is a short letter; the control is knowing to write it.

For firms operating in several markets, the notification goes to the home authority, but a host authority may have its own expectations on safeguarding evidence — so the change log should record which authorities were told and when, not merely that a notification was made.

FAQ

Is there a safeguarding return to file?

Not as a periodic template in the EU framework. The reporting duty is the advance notification of a material change, alongside whatever ongoing evidence national rules require — such as daily reconciliation and an annual attestation.

What counts as a material change?

A judgement, but anything altering what the supervisor assessed: the method, the holding institution, the eligible assets, the insurance provider or limit, or the reconciliation model.

Is the representative portion an internal assumption?

No. It must be reasonably estimable from historical data to the satisfaction of the competent authorities, which makes the methodology part of the safeguarding file.


Related: What is a safeguarding account · Safeguarding compared · CSSF internal governance

Related reads.