Skip to main content
News

PSD3 Reauthorisation: What Payment and E-Money Institutions Need to Know

By October 9, 2026No Comments

On 8 June 2026, the Malta Financial Services Authority (“MFSA”) issued a Dear CEO letter setting out how payment and electronic money institutions should prepare for the third Payment Services Directive (“PSD3”). PSD3 will replace PSD2 and the second Electronic Money Directive (“EMD2”) with a single regime. Institutions licensed under the Financial Institutions Act (Cap. 376) to provide payment services or issue electronic money will need to be authorised as payment institutions, and issuing electronic money will become a payment service in its own right.

PSD3 is not yet law. The final text was published in April 2026, and the European Parliament’s vote is provisionally scheduled for 14 December 2026. All deadlines run from entry into force, 20 days after publication in the Official Journal.

Existing institutions may keep operating for up to 27 months after entry into force, though the working window is shorter. The European Banking Authority (“EBA”) has 12 months to submit draft Regulatory Technical Standards (“RTS”) on authorisation to the European Commission, which must then adopt them. Firms will therefore have less than 15 months to evidence compliance against the final standards, which is why the MFSA has asked them to begin now.

What will the MFSA assess?

Within the transitional period, the MFSA must assess each institution’s initial capital, safeguarding, governance and ICT arrangements, incident handling, business continuity, and winding-up plan, together with any authorisation applications made by the firm or its group in other Member States. Institutions that comply are deemed authorised as payment institutions, a process the MFSA calls reauthorisation.

The MFSA has stated that safeguarding is both an authorisation requirement and an ongoing obligation. Its 2025 enforcement work found inadequate segregation of client funds, irregular reconciliations, and weak internal controls at certain institutions, and one financial institution lost its licence partly because of safeguarding breaches. In our view, open supervisory findings and un-remediated audit points will weigh on reauthorisation. A record of late regulatory returns is also likely to count against a licence holder. Late or missing submissions accounted for around 69% of all MFSA enforcement actions in 2025, and the MFSA treats timely reporting as a core obligation that cannot be delegated.

Consequences of falling short

As things stand, an institution that does not meet PSD3’s requirements for payment institutions by the deadline, 27 months after PSD3 enters into force, will be suspended from providing payment services until it provides the information needed to show compliance and the MFSA has verified it. The MFSA may also withdraw its authorisation. In exceptional cases, the current process to be adopted is that MFSA may delay a suspension by up to three months, where the institution has provided its information, but the MFSA could not process it in time. A suspension would also halt services provided into other Member States under a passport.

How can Shoulder help?

The MFSA’s letter expects board awareness, a documented gap analysis and a board-approved implementation plan, and, where applicable, engagement with external auditors or consultants. Shoulder can assist with the following:

  • Board and senior management training: briefings for directors and key function holders on PSD3 requirements and timelines, including the forthcoming RTS.
  • Gap analysis and implementation plan: a documented review against the agreed text, covering safeguarding, governance and ICT, incident reporting, business continuity, winding-up planning, and capital, with a remediation plan for board approval that is updated as EBA standards are published.
  • Safeguarding audits: the annual safeguarding audit required under the Financial Institutions Rulebook, used to test segregation, reconciliations, concentration across credit institutions and board oversight before reauthorisation. For firms investing client funds in UCITS money market funds, this includes the conditions in the MFSA’s May 2026 circular. We also cover PSD3’s new safeguarding duties, including telling users how their funds are protected.
  • Winding-up plans: PSD3 requires institutions subject to safeguarding to submit a plan, proportionate to their size and business model, covering an orderly wind-up, critical activities carried out by outsourced providers, agents or distributors, and the return of safeguarded funds. These elements are already in the agreed text, so the plan can be drafted now.
  • Remediation: closing outstanding MFSA and FIAU findings, including AML/CFT and sanctionsdeficiencies before the reauthorisation information is submitted.

 Neither PSD3 nor the MFSA has said how far back the MFSA will look when assessing a firm’s compliance, and the EBA’s standards on the information required are not yet available. Safeguarding audits are annual, for example, so the MFSA could ask for several years of audit reports rather than only the latest one. Remediation carried out shortly before the deadline may therefore not be enough.

Contact us at info@shoulder.mt for support.