This informal CPD article, ‘Safeguarding in Payments and E-Money: What the Law Requires Today, and the Reset Coming Under PSD3 and the Payment Services Regulation’, was provided by CPDs.Academy, a CPD training platform delivering compliance education for professionals in EU-regulated financial services.
When a bank fails, an elaborate machinery protects its depositors, from prudential capital rules to a deposit guarantee scheme. A payment institution or an electronic money institution is a different kind of firm. It is not a bank, it cannot take deposits, and the customer money it holds is not a deposit guaranteed against the firm’s own failure. What protects that money instead is safeguarding, the legal duty to keep client funds separate and recoverable if the firm goes under. Safeguarding is the foundation of trust in the whole non-bank payments sector, and the European Union is in the middle of reworking the rules that govern it. The framework has held broadly steady for years, but the changes now in train will alter how safeguarding is framed, supervised and detailed. For firms in the sector, the rules as they stand repay a close reading, not least because what is coming builds directly on them.
What safeguarding requires today
The obligation sits in two places that say almost the same thing. For payment institutions, Article 10 of the second Payment Services Directive requires a firm to safeguard all the funds it receives from, or for, its payment service users (1). For electronic money institutions, Article 7 of the second Electronic Money Directive carries the same requirement across to the funds a firm receives in exchange for the electronic money it issues (2). The two regimes were built separately and differ in much else, but on the protection of client money they line up.
The law offers two routes. The first is segregation: the firm keeps the relevant funds apart from its own money and, where it still holds them at the close of the business day after they arrive, either places them in a separate account or invests them in secure, liquid, low-risk assets. That separate account can sit with an authorised credit institution or, since the 2024 Instant Payments Regulation amended Article 10, with a central bank where that central bank allows it (1). The second route is insurance, a policy or comparable guarantee from an insurer or credit institution that pays out if the firm cannot meet what it owes its users (1). In practice, many firms use designated safeguarding accounts at banks.
What counts as safeguarded matters as much as how it is held. The cover reaches the relevant funds, the client money a firm takes in to execute payments or in exchange for electronic money, and not the firm’s own resources or the fees it has properly earned. The Electronic Money Directive deals expressly with timing. Where the funds come in through a payment instrument, they need not be safeguarded until they have been credited to the institution’s payment account or otherwise made available to it, and in any event no later than five business days after the electronic money is issued (2). The discipline, then, is not only to hold client money apart but to know precisely which money is client money, and from when.
Safeguarding is an operational matter as much as a legal one. In practice it turns on a firm keeping its own record of what it owes customers in step with what actually sits in the safeguarding account, and resolving any difference without delay. The present directives say comparatively little about how that is to be done, leaving much of the detail to national supervisors, and it is one of the areas the new rules set out to standardise.
Why the choice of method matters becomes clear at the worst moment, and it helps to separate two different failures. If the payment or electronic money firm itself fails, there is no deposit guarantee on the firm to fall back on, since it is not a deposit-taker. Safeguarding is what answers that risk. Done properly, the safeguarded funds are held apart from the firm’s own assets and ring-fenced from its creditors, so that the money can be identified and returned to the customers it belongs to rather than absorbed into the general estate. The failure of the bank holding those funds is a different matter, and there a deposit guarantee scheme may be relevant. Directive (EU) 2026/804 is set to put that beyond doubt once transposed, requiring Member States to ensure deposit guarantee cover for client funds deposits, but only where the conditions in the new Article 8b are met: the clients are themselves eligible for protection, the funds sit in segregated accounts that comply with the safeguarding rules, and the clients are identified or identifiable before the deposits become unavailable. Where those conditions hold, the protected limit applies to each eligible, identified or identifiable client (3). The two regimes answer different questions, and safeguarding is the one built for the failure of the payment firm itself.
Where the present regime has strained
On paper this is straightforward. In practice it has proved uneven. Because the requirements arrived as directives, each Member State transposed them in its own way, and supervisors found the detail applied inconsistently across the Union. In its 2022 Opinion on the review of the payment services framework, the European Banking Authority set the problem out and recommended, among much else, that payment institutions and electronic money institutions be brought under the same requirements, safeguarding included (4).
The weak points are the kind supervisors tend to focus on because they determine whether safeguarding works in practice. Safeguarded funds can end up concentrated in a single bank, so that the failure of that bank, rather than the payment firm, becomes the real threat to client money. Reconciliation, evidence and timing can also become pressure points: which funds are caught, when they become subject to safeguarding, and whether the firm can prove that the protected amount is actually there. These are practical control issues rather than abstract legal ones, and the proposed EBA technical standards are meant to make expectations in these areas more consistent.
The inconsistency bites hardest across borders. A firm that passports its services into several Member States can find the same safeguarding obligation read differently in each, which complicates supervision and can leave customers in different countries unevenly protected for what is, in substance, the same client money. A requirement meant to be uniform had become, in practice, a set of local variations.
The reset under PSD3 and the Payment Services Regulation
On 28 June 2023 the European Commission proposed to rebuild the framework through two linked instruments. The third Payment Services Directive would repeal both the current Payment Services Directive and the Electronic Money Directive, fold electronic money institutions into a single payment-institution regime, and carry the rules on authorisation, supervision and safeguarding, the last of these now in Article 9 (5). Beside it sits the Payment Services Regulation, a directly applicable instrument that takes the conduct of business rules, on matters such as fraud, transparency and access to payment systems, out of national hands and applies them in the same words across the Union (6). Safeguarding, it is worth being clear, stays in the directive. The shift is not that it becomes a regulation, but that the directive tightens the standard and hands the European Banking Authority the task of filling in the detail.
The merger of the two regimes is more than housekeeping. Today an electronic money institution and a payment institution can face subtly different safeguarding expectations for what is, in economic terms, the same client money. Bringing them under one regime narrows that gap, and the arbitrage it can invite (5).
Within Article 9, the safeguarding rules are firmed up and made more uniform. The concentration point is the clearest example. A firm that segregates is expected to avoid concentration risk where appropriate, and to endeavour not to safeguard all of its users’ funds with a single credit institution, leaving the European Banking Authority’s technical standards to set out the circumstances and the detail (7). The central-bank account is carried forward from the current text and clarified rather than invented. The compromise text then goes further, treating users’ funds held in a settlement account with a designated payment system as safeguarded, provided they are not commingled with other funds and are insulated under national law, which matters as non-bank providers gain more direct access to payment systems (7). The same technical standards are expected to reach the segregation and designation of accounts, reconciliation and the calculation of the funds that must be safeguarded, the areas national supervisors have until now read in their own ways (7).
The package also looks past the live business to its end. Applicants seeking to provide the core payment services, those in points (1) to (5) and point (8) of Annex I to the directive, would be expected to submit a winding-up plan for the event of failure, the term the text uses, setting out how an orderly exit and the return of safeguarded funds would be handled rather than improvised in a crisis (7).
The legislation is well advanced but not yet in force. The European Parliament and the Council reached a provisional political agreement on 27 November 2025, and the compromise texts were taken forward through 2026, but formal adoption and publication in the Official Journal still set the final timetable (7). Once the texts are in force, Member States are due to transpose PSD3 within around twenty-one months, with the Regulation applying on a broadly similar schedule and certain provisions later still. The sensible course for firms is to prepare now, while accepting that the exact application date will depend on final adoption and publication.
What it means for firms
For a payment or electronic money firm the message runs two ways. The core obligation does not change. Safeguarding still means keeping client funds separate and recoverable, and the segregation and insurance routes remain recognisable (1). The change is one of rigour and detail. The two regimes converge, the standard in PSD3 is firmer on concentration, the central-bank route carries over and a designated-payment-system route is added, and binding technical standards from the European Banking Authority will pin down points that national supervisors once read differently (7). The firms best placed for the new regime will be those that already treat safeguarding as a daily control discipline, with records and evidence to match, rather than as a policy document that is written once and left on file.
Closing thoughts
Safeguarding draws little attention until it fails, and then it draws nothing else. For the customers of non-bank payment firms it is the one thing standing between them and the firm’s creditors, which is why the European Union has chosen to make it firmer and more consistent rather than leave it to twenty-seven national readings. The obligation that began in Article 10 of the Payment Services Directive (1) and Article 7 of the Electronic Money Directive (2) is being recast in PSD3, the directive that will replace them (5), with binding technical standards meant to make the detail more consistent across the Union (7). For firms, the work between now and then is unglamorous and exact. Know where the safeguarded money is, be able to prove it is there, and be ready to show that it would survive the day the firm did not.
We hope this article was helpful. For more information from CPDs.Academy, please visit their CPD Member Directory page. Alternatively, you can go to the CPD Industry Hubs for more articles, courses and events relevant to your Continuing Professional Development requirements.
References
(1) Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market (the second Payment Services Directive, PSD2), in particular Article 10 on safeguarding requirements, as amended by Regulation (EU) 2024/886 (the Instant Payments Regulation), which added the option of safeguarding in a separate account at a central bank, at that central bank’s discretion.
(2) Directive 2009/110/EC of the European Parliament and of the Council of 16 September 2009 on the taking up, pursuit and prudential supervision of the business of electronic money institutions (the second Electronic Money Directive, EMD2), in particular Article 7 on safeguarding requirements.
(3) Directive 2014/49/EU of the European Parliament and of the Council of 16 April 2014 on deposit guarantee schemes (DGSD), under which deposits of payment and electronic money institutions are not themselves covered, while client funds held in a safeguarding account at a credit institution may, through the look-through in Article 7(3), reach the underlying clients. Directive (EU) 2026/804, amending the DGSD as part of the crisis management and deposit insurance reform, inserts a new Article 8b requiring Member States to ensure coverage for client funds deposits where its conditions are met: the clients are eligible for protection, the funds are on segregated accounts compliant with safeguarding requirements, and the clients are identified or identifiable before the deposits become unavailable. The cover applies up to the protected limit, EUR 100,000, per eligible client. It was published in the Official Journal on 20 April 2026 and entered into force on 10 May 2026, and Member States are required to transpose most provisions within 24 months of entry into force, by 11 May 2028.
(4) European Banking Authority, Opinion on its technical advice on the review of Directive (EU) 2015/2366 (PSD2), EBA-Op-2022-06, 23 June 2022.
(5) European Commission, Proposal for a Directive of the European Parliament and of the Council on payment services and electronic money services in the internal market (the third Payment Services Directive, PSD3), COM(2023) 366, 28 June 2023, which would repeal Directive (EU) 2015/2366 and Directive 2009/110/EC and locates the safeguarding framework in Article 9.
(6) European Commission, Proposal for a Regulation of the European Parliament and of the Council on payment services in the internal market (the Payment Services Regulation, PSR), COM(2023) 367, 28 June 2023, a directly applicable instrument containing the conduct of business rules that sit alongside PSD3, including transparency, fraud-related provisions and access to payment systems.
(7) Council of the European Union, compromise texts on the PSD3 proposal (document ST 8222/26) and the Payment Services Regulation proposal (document ST 8221/26), both dated 17 April 2026, together with the Council and European Parliament announcements following the provisional political agreement of 27 November 2025. These texts are the source for the current detail of the Article 9 safeguarding requirements, including the concentration-risk wording, the central-bank and designated-payment-system account treatment, and the mandate for European Banking Authority regulatory technical standards on the segregation and designation of accounts, reconciliation, calculation of safeguarded funds and concentration risk, as well as for the transposition and application timetable. Formal adoption and publication in the Official Journal determine the final timetable, with PSD3 transposition generally around twenty-one months from entry into force and certain provisions later.