4 Regulatory Trends PSPs Should Be Watching In 2026
PSP
Regulatory updates

Regulatory compliance for EU payment service providers has rarely been simple, but it has usually been manageable one framework at a time. What makes the current period genuinely different is the simultaneity. Four major regulatory instruments are in active motion at once, each with its own compliance architecture, its own deadline, and its own consequences for how a PSP operates, governs its technology, and documents its decisions.
The challenge this creates is not primarily a knowledge problem. Most compliance teams at EU PSPs understand individually what PSD3 means, what AMLA is building toward, what the Instant Payments Regulation requires, and what DORA demands. What is harder to manage, and where the real compliance risk concentrates, is the interaction between all four running in parallel. The most visible deadline in any given quarter tends to absorb the team's attention. The frameworks with longer fuses and equally serious consequences get scheduled for later. Later has a way of arriving faster than planned.
This article is a practical breakdown of each of the four trends: what has been confirmed in published regulatory texts, what the actual deadlines are, and what compliance teams at PSPs should be doing now. Everything here is drawn from official EU legislative documents and verified regulatory authority publications. We broke it down for you so that you don't have to.
Trend 1: PSD3 and the Payment Services Regulation Are Arriving, and the Implementation Clock Has Started
The biggest structural change to EU payments regulation since PSD2 is no longer a proposal. The Third Payment Services Directive (PSD3) and the directly applicable Payment Services Regulation (PSR) reached provisional political agreement on 27 November 2025, and the final compromise texts were published on 23 April 2026. As of the date of this article, the texts have passed through COREPER, the ECON Committee, and are pending the Parliament plenary vote and formal Council adoption. Publication in the Official Journal is expected in the second half of 2026, with some legal commentary suggesting June or July but noting the possibility of a September publication.
That publication date matters because it starts the implementation clock. The PSR, as a directly applicable regulation, enters into force twenty days after publication and most of its rules apply twenty-one months later, placing the compliance deadline around Q2 or Q3 of 2028. PSD3, as a directive, requires national transposition within twenty-one months of entry into force, on roughly the same timeline.
What this means practically for PSPs is that 2026 is the preparation year and 2027 is the implementation year, regardless of the precise Official Journal date.
Here is what is actually changing and why it matters.
The most fundamental structural change is the merger of the payment institution and electronic money institution regimes. EMD2 is being repealed, and EMIs become a sub-category of payment institutions under PSD3. Existing EMI licence holders are grandfathered into the new framework and do not need to re-apply from scratch, but they do need to update their authorisation files, governance documentation, and regulatory reporting to reflect the new taxonomy. For compliance teams at EMIs, this is not an administrative formality. It is a substantive exercise that needs to be mapped against the updated requirements for capital, safeguarding, and governance under PSD3.
The second major change is fraud liability. The PSR extends fraud reimbursement obligations and IBAN-name matching requirements that were previously specific to instant payments under the EU Instant Payments Regulation to all credit transfers. Payment institutions must check that the payee name matches the unique identifier provided by the payer, and must provide an early warning where there is a discrepancy. Liability attaches for failure to flag a mismatch before a payment proceeds, which means the technical infrastructure for payee name verification needs to be in place and functioning before the PSR's rules apply, not built in response to the first enforcement action.
The third change is the shift from a directive to a regulation for conduct rules. Under PSD2, national transposition created divergence: the same rule meant different things in Germany, Spain, and France depending on how the national legislator implemented it. Under the PSR, conduct rules covering strong customer authentication, transparency, open banking, and fraud liability apply directly and uniformly across all EU member states. For PSPs operating cross-border, this is broadly positive. It means a single compliance programme for conduct rules across markets, rather than national adaptations for each. But it also means there is nowhere to hide behind a lighter-touch national transposition.
For open banking, the PSR tightens the obligations on account-servicing payment service providers to provide dedicated, high-performance interfaces, introduces permission dashboards that give customers visibility and control over who has access to their payment account data, and prohibits obstacles to third-party provider access in more specific terms than PSD2 managed. These changes will require technical investment from any PSP that currently provides open banking access or relies on it.
What should you be doing now? The practical answer is: read the final compromise texts that were published on 23 April 2026 and map them against your current compliance programme and technical infrastructure. Do not wait for the Official Journal publication to start your impact assessment, because the texts that will become law are already published and the preparation time you are losing now cannot be recovered later. EMIs in particular should be mapping their re-authorisation pathway under the merged PSD3 regime and ensuring that their governance documentation and DORA evidence are being maintained in a form that will support an updated authorisation file.
Trend 2: AMLA Is Operational and Publishing the Technical Standards That Define What 2027 Actually Requires
On 1 January 2026, responsibility for all EU-level anti-money laundering and counter-terrorist financing tasks transferred from the European Banking Authority to the newly established Anti-Money Laundering Authority (AMLA). This is not a minor administrative handover. It is a structural change in who sets the EU AML/CFT standard and how that standard is enforced.
AMLA is now the central authority for developing the Single AML/CFT Rulebook under Regulation (EU) 2024/1624 (the AMLR) and Directive (EU) 2024/1640 (AMLD6), which become fully applicable on 10 July 2027. All existing EBA AML/CFT guidelines and technical standards remain in force under Article 54 of the AMLA Regulation until AMLA replaces them, which means there is no compliance gap. But the direction of travel is AMLA's framework, not the EBA's, and the two authorities will not always take identical positions on contested questions.
What AMLA is doing in 2026 is building out the detailed technical standards that define what the AMLR's principles actually require in practice. In March 2026, AMLA opened a public consultation on its draft Regulatory Technical Standards on Customer Due Diligence, which are required under Article 28(1) of the AMLR and will specify in detail which information and documents obliged entities must collect as part of the CDD process. The EBA consulted on a version of these RTSs previously, but AMLA is now the authority and its final standards will supersede whatever the EBA had published on this topic.
These RTSs matter because they are what transforms the AMLR's principles into specific obligations. The AMLR says obliged entities must verify the identity of customers using reliable, independent sources. The CDD RTSs will say which sources count as reliable and independent, what information must be collected for different customer types, and how the verification must be documented. For PSPs that are currently designing their AMLR-compliant onboarding workflows, the honest answer is that some of those design decisions cannot be finalised until the RTSs are in their final form. The practical response is to build flexibility into the workflow architecture rather than locking in specific procedures that may need adjustment once the standards are published.
Beyond the CDD RTSs, AMLA is developing standards on customer risk assessments, the requirements for group-wide AML policies, the criteria for selecting the 40 high-risk financial institutions that AMLA will directly supervise from 2028, and the methodology that national supervisors will use to assess ML/TF risk across obliged entities. That last point is particularly significant: AMLA has announced that from 2028 it will directly supervise 40 of the most complex, high-risk cross-border financial institutions in the EU. The selection process uses a harmonised ML/TF risk assessment methodology that all national supervisors are testing during 2026. For any large cross-border PSP or payment group, the question of whether you might be among those 40 is not theoretical. It is worth assessing against the published criteria.
For PSPs of all sizes, the AMLR brings two specific changes beyond the broader CDD and governance framework that deserve particular attention.
The first is the beneficial ownership threshold shift. Under the existing AML Directives, a beneficial owner is a natural person who owns "more than 25 percent" of a legal entity's shares, voting rights, or other ownership interests. Under the AMLR, the threshold shifts to "25 percent or more." This is a small change in wording but a meaningful one in practice: a person holding exactly 25 percent is now captured. For PSPs onboarding business customers, this means the data fields collected at onboarding and the logic used to determine who must be verified as a UBO need to be updated. Any workflow that was built around the old threshold will produce incorrect results under the AMLR.
The second is the compliance officer's personal accountability for suspicious transaction reporting to the FIU, which the AMLR makes more explicit than the current framework. This is not new in principle, but the AMLR's governance requirements, including the mandatory designation of a member of the management body with specific AML/CFT responsibility, create a governance architecture that PSPs need to have in place before 10 July 2027, not as a response to it.
What should you be doing now? Watch AMLA's regulatory instruments page at amla.europa.eu actively, not as a periodic check but as a regular part of your regulatory monitoring programme. The CDD RTSs, the risk assessment methodology, and the group-wide policy standards that AMLA publishes in 2026 are the documents that will define your compliance obligations in 2027. Treat 2026 as the design year for your AMLR programme, not the year before you start designing it.
Trend 3: The Instant Payments Regulation Compliance Sprint for Non-Bank PSPs
Euro-area banks have been living with the EU Instant Payments Regulation since early 2024, and the IBAN-name Verification of Payee obligation for bank-originated payments applied from October 2025. For non-bank PSPs, including payment institutions and EMIs, the compliance deadlines are later but they are now close enough to be real planning constraints.
The EU Instant Payments Regulation (Regulation (EU) 2024/886) requires non-bank PSPs to be able to receive instant payments by April 2027 and to send them by July 2027. Every payment within scope must complete within ten seconds, 24 hours a day, on any calendar day. That is not a target. It is a hard operational requirement, and the compliance infrastructure to support it needs to be in place and tested well before the deadline.
The compliance dimension that most PSPs underestimate is the sanctions screening requirement that sits alongside the speed obligation. The regulation does not permit transaction-level sanctions screening of instant payments, because a check that adds seconds to a transaction is incompatible with a ten-second settlement window. Instead, the regulation requires PSPs to screen their customer base against the EU's consolidated targeted financial sanctions list at least daily. This customer-level screening model is a meaningful operational change for any PSP that has historically screened at the transaction level.
The practical implications are significant. First, the screening infrastructure needs to run against the customer base on a daily cycle, not triggered by individual payment initiation. Second, the data quality of the customer base needs to support reliable screening: if customer names are stored inconsistently, or if beneficial ownership data is incomplete, the screening will produce unreliable results. Third, the alert management workflow needs to be designed for the daily cadence, not for the ad hoc volume that transaction-level screening generates.
The EBA has confirmed that the fraud risk associated with instant credit transfers is up to ten times higher than with regular credit transfers. For PSPs building their instant payment operations for the first time, this means fraud prevention infrastructure is not optional context to the instant payments build: it is a core part of the compliance case for the operation.
Verification of Payee under the Instant Payments Regulation requires PSPs to check whether the payee IBAN corresponds to the name provided by the payer before an instant payment is executed and to return a match, close match, or no match result. The PSR then extends this IBAN-name matching obligation to all credit transfers, not just instant ones, once the PSR applies. For PSPs planning their technical build, building VoP once and extending it to cover both the instant payments and the PSR scope is more efficient than building it twice for two different regulatory instruments.
What should you be doing now? If you are a non-bank PSP that plans to offer instant payment services, April 2027 for receiving and July 2027 for sending are closer than they feel for a project of this technical complexity. The build, testing, and regulatory notification requirements for instant payment readiness need to be in active delivery now, not in planning. The daily customer sanctions screening model in particular needs dedicated attention from both the compliance team and the technology team, since it requires a different architecture from transaction-level screening and the integration with the sanctions list update cycle needs to be reliable and documented.
Trend 4: DORA Is Now Business as Usual, and the EU AI Act Is Adding a New Governance Layer
The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) has applied to payment institutions and EMIs since 17 January 2025. That means the compliance programme that was a preparation exercise in 2024 is now a live, examinable obligation. In June 2026, the European Supervisory Authorities published their first annual report on major ICT-related incidents under the framework, noting 3,383 major incidents reported across EU financial entities in the first year of application, with around a third having cross-border impact.
For PSPs, the DORA obligations that most commonly reveal gaps in examination are: the completeness of the ICT third-party service provider register, the degree to which the management body genuinely oversees the ICT risk management framework rather than simply receiving annual reports, and the institution's ability to classify an incident correctly and produce the required notification within DORA's timelines without having practised the process in advance.
The first year of DORA application has produced a clearer picture of where the framework generates the most supervisory attention. The incident reporting regime is the most immediate pressure point because major incidents require an initial notification to the national competent authority within four hours of classification, and a full report within three business days. For PSPs that have not rehearsed the classification and notification process, the first major incident is not the moment to discover that the governance workflow does not work under real pressure.
Running alongside DORA is the EU AI Act, which has a separate but closely related set of implications for any PSP using AI-powered compliance tools.
The EU AI Act (Regulation (EU) 2024/1689) became fully applicable on 2 August 2026, with transparency obligations for AI systems applying from that date. The AI Omnibus package, for which political agreement was reached on 7 May 2026, has modified the timeline for high-risk AI system rules: rules applying to systems in certain areas including biometrics, employment, migration, and critical infrastructure now apply from 2 December 2027, and rules for AI systems integrated into products apply from 2 August 2028. The European Commission's digital strategy pages confirm this updated timeline.
What does this mean for PSPs in practice? AI-powered AML risk profiling, fraud detection, and automated decisions affecting access to financial services are classified as high-risk AI use cases under the Act's Annex III framework. PSPs using AI systems in these contexts need to assess whether their tools qualify as high-risk AI systems and, if so, what their obligations as deployers of those systems include. At a minimum, high-risk AI systems must be designed for effective human oversight, must maintain technical documentation, and must be subject to ongoing monitoring for accuracy and performance. The deployer of a high-risk AI system, which in most cases is the PSP using a vendor's AI-powered compliance tool, carries specific obligations that supplement the existing DORA, AML, and GDPR requirements.
GDPR Article 22 remains the foundational constraint on automated decisions. Any PSP whose AI-powered tools make or substantially influence decisions that produce significant legal effects on individuals, including denying access to services, flagging individuals as potential sanctions matches, or blocking transactions on fraud grounds, needs to ensure that meaningful human review is embedded in the decision process and that the automated system is not the sole basis for the determination.
The practical interaction between DORA and the AI Act is one that many PSPs have not yet fully mapped. An AI-powered compliance tool is simultaneously an ICT system for DORA purposes, a high-risk AI system potentially subject to the AI Act's governance requirements, and an automated processing tool subject to GDPR Article 22 where its outputs affect individuals. Compliance teams need to be thinking about those three frameworks together, not as three separate boxes to tick.
What should you be doing now? On DORA: if you have not yet rehearsed the incident classification and notification workflow in a tabletop exercise with the management body present, do it before the next incident makes it necessary to perform under pressure. On the AI Act: identify which compliance tools in your current stack use AI or machine learning, assess whether they qualify as high-risk AI systems under Annex III, and if they do, confirm with the vendor what documentation is maintained and what the human oversight mechanism looks like. That conversation is significantly easier now than it will be in 2027 when supervisory attention to AI governance in financial services is more acute.
The 2026 Regulatory Landscape for PSPs: A Snapshot Comparison
Regulatory Framework | Current Status (as of July 2026) | Primary PSP Compliance Deadline | Key Compliance Actions Required Now |
|---|---|---|---|
PSD3 and PSR | Final compromise texts published 23 April 2026; awaiting Official Journal publication (expected H2 2026); rules apply approximately 21 months after publication | Approximately Q2 to Q3 2028 for most rules; VoP liability from approximately Q3 2028 | Impact assessment against published texts; EMI re-authorisation planning; fraud liability gap analysis; open banking infrastructure review |
AMLR and AMLA | AMLA operational from January 2026; CDD RTS consultation ongoing; AMLR applies from 10 July 2027 | 10 July 2027 | Monitor AMLA RTS publications; update UBO threshold to 25% or more; confirm compliance officer governance; design AMLR-compliant onboarding and monitoring workflows |
EU Instant Payments Regulation (non-bank PSPs) | Banks already compliant; VoP for non-bank PSPs required October 2025; sending and receiving deadlines for non-bank PSPs in 2027 | Receiving: April 2027; Sending: July 2027 | Build daily customer sanctions screening capability; implement VoP/IBAN-name check; complete 10-second SLA infrastructure; fraud monitoring for instant payments |
DORA (ongoing) and EU AI Act | DORA live since January 2025; first annual ICT incident report published June 2026 (3,383 incidents); AI Act transparency obligations apply from 2 August 2026; high-risk AI rules apply from December 2027 for most categories | Ongoing for DORA; 2 August 2026 for AI Act transparency; 2 December 2027 for high-risk AI systems | Rehearse DORA incident classification and notification; complete ICT third-party register; assess AI compliance tools against EU AI Act high-risk criteria; map GDPR Article 22 human oversight requirements |
The Thread That Connects All Four Trends
Reading these four trends together, there is a common theme that compliance teams at PSPs should take seriously: the EU regulatory framework is systematically closing the gap between what regulations say and what regulators can verify is actually happening.
The PSR's direct applicability removes national transposition as a source of divergence. AMLA's harmonised supervision methodology means that being assessed more leniently in your home member state than in a neighbouring one will become progressively less viable as AMLA's standards embed. DORA's incident reporting requirement creates a real-time supervisory visibility into operational failures that did not exist under the previous framework. And the EU AI Act's governance requirements for AI systems used in compliance contexts create an audit trail obligation for the tools PSPs use, not just for the decisions those tools inform.
For compliance teams, this means the answer to regulatory compliance is no longer primarily about having the right policies. It is about being able to demonstrate that the policies are applied in practice, that the tools are properly governed and documented, and that the compliance record holds up under examination at any point rather than only when it has been specifically prepared.
About SpeedyDD
SpeedyDD is a KYB and due diligence platform whose mission is to help complex, regulated businesses, PSPs, EMIs, CSPs, and iGaming operators, maintain audit readiness as a default state rather than as something assembled in response to a regulatory request.
For PSPs navigating the four trends described in this article, the KYB and beneficial ownership verification layer sits at the intersection of all of them. The AMLR's 25% or more UBO threshold, the CDD RTSs that AMLA is publishing throughout 2026, the onboarding documentation requirements that banking partners apply to PSPs as counterparties, and the audit trail that DORA requires for ICT-supported compliance processes all require that beneficial ownership verification is done to a standard that can be demonstrated, not just asserted.
SpeedyDD connects to more than 30,000 corporate registry data sources across more than 200 countries and territories, integrates directly with The KYB for registry data retrieval, and logs every verification, decision, and approval automatically. For PSPs whose client base includes business customers across multiple EU member states and beyond, that registry depth and automatic audit trail are the operational difference between a compliance record that holds up under scrutiny and one that does not. SpeedyDD's marketplace connects compliance teams to more than 230 vetted providers across over 195 jurisdictions for the enhanced due diligence workflows that higher-risk relationships require.
Frequently Asked Questions
What is the difference between PSD3 and the PSR, and do both apply to PSPs?
PSD3 is a directive that governs authorisation, licensing, governance, capital, safeguarding, and supervision of payment institutions. It requires national transposition by each EU member state. The PSR is a directly applicable regulation, meaning it applies uniformly across all EU member states without national transposition, and it governs conduct of business rules including strong customer authentication, transparency, open banking standards, and fraud liability. Both apply to PSPs, but in different ways: PSD3 governs what a PSP must be and how it is authorised; the PSR governs how a PSP must behave when providing services.
When exactly does the PSR apply for PSPs?
The PSR will enter into force twenty days after its publication in the Official Journal, and most of its rules will apply twenty-one months after that. Based on the expected publication timeline in the second half of 2026, most PSR obligations are expected to apply around Q2 or Q3 of 2028. The Verification of Payee and payee name matching liability provisions apply twenty-four months after entry into force, giving additional time for the technical changes those provisions require. These timelines are projections based on the expected publication date; the official deadline will be confirmed once the regulation is published in the Official Journal.
What does the transfer of AML/CFT authority from the EBA to AMLA mean for PSPs day to day?
From 1 January 2026, AMLA is the authority responsible for developing and updating the EU's AML/CFT technical standards and guidelines. For PSPs, this means that the EBA's existing AML/CFT guidelines remain in force under a continuity provision until AMLA replaces them, so there is no gap in applicable standards. What changes is that new standards, including the CDD RTSs under the AMLR, will be published by AMLA rather than the EBA. PSPs that have historically monitored the EBA for AML regulatory developments need to switch that monitoring to AMLA. The AMLA regulatory instruments page at amla.europa.eu is now the primary source for these publications.
Does the Instant Payments Regulation require PSPs to screen every payment transaction against the sanctions list?
No, and this is one of the most commonly misunderstood aspects of the regulation. The Instant Payments Regulation requires PSPs to screen their customer base against the EU consolidated targeted financial sanctions list at least daily. It does not require transaction-level screening for instant payments, because the ten-second settlement requirement makes transaction-level screening incompatible with the payment flow. The compliance model shifts from "screen each transaction as it occurs" to "screen all customers daily and maintain confidence that no sanctioned entity is in the customer base before payments are processed." This is a different operational model from what most PSPs currently use for sanctions compliance.
Which PSPs are subject to DORA and what does that mean operationally?
DORA applies to payment institutions and EMIs that are authorised under PSD2, account information service providers, credit institutions, and certain other regulated financial entities. If your PSP holds a payment institution or EMI authorisation, DORA has applied since 17 January 2025. Operationally, this requires maintaining a comprehensive ICT risk management framework overseen by the management body, keeping a complete register of contractual arrangements with all ICT third-party service providers, classifying and reporting major ICT-related incidents to the national competent authority within defined timelines and using defined templates, and conducting resilience testing. The first year's data from the ESAs shows 3,383 major incidents were reported across EU financial entities, confirming that incidents at the scale DORA defines as major are not rare events for institutions processing meaningful payment volumes.
What compliance obligations does the EU AI Act create for PSPs using AI-powered compliance tools?
From 2 August 2026, the EU AI Act's transparency obligations apply. For AI systems used in AML risk profiling, fraud detection, and decisions affecting access to financial services, a high-risk AI classification applies under Annex III of the Act. Following the AI Omnibus political agreement of 7 May 2026, the detailed high-risk AI system obligations for most categories apply from 2 December 2027. As a deployer of a high-risk AI system, a PSP is required to implement appropriate human oversight measures, ensure the system is used in accordance with its documentation, monitor performance, and report incidents where the system malfunctions in a way that could create a risk. For PSPs using third-party AI-powered tools, the practical first step is confirming with each vendor whether their system qualifies as high-risk under the Act and what documentation and human oversight mechanisms are built into the product.
How should a PSP prioritise its compliance efforts across these four trends simultaneously?
The prioritisation depends on which deadlines are nearest and which gaps in your current programme are largest. The most immediate operational pressure for most non-bank PSPs is the Instant Payments Regulation, because the April 2027 receiving deadline and July 2027 sending deadline require technical infrastructure that takes months to build and test. DORA is live now and needs to be in active compliance programme mode rather than implementation mode. The AMLR preparation should be running throughout 2026 in parallel with AMLA's RTS publications, because waiting for the RTSs to be finalised before starting the programme design means losing the design lead time. PSD3 and PSR preparation should be in impact assessment and early planning mode now, with implementation delivery beginning in 2027.
What happens to EMI licences under the PSD3/PSR regime?
Under PSD3, the EMI licence type ceases to exist as a separate category. EMIs become payment institutions authorised for e-money issuance. Existing EMIs are grandfathered into the new regime and do not need to re-apply from scratch, but they must update their authorisation files, governance documentation, and regulatory reporting to reflect the new taxonomy within the transition period. The twenty-one-month transition period from PSR entry into force applies, placing the practical deadline for most EMI re-authorisation updates around late 2027 to early 2028. EMI compliance teams should be mapping their current authorisation against the PSD3 requirements now, since the published compromise texts contain sufficient detail to complete that mapping without waiting for the Official Journal publication.
