RegRally Insights: Payment Services Regulation, August 2026

Payments RegRally, Aug 2026

Payment services regulation is increasingly focused on whether regulated institutions can demonstrate effective controls, financial resilience and operational readiness in practice.

Recent supervisory activity in Lithuania and Latvia, together with developments at the EU and UK levels, highlights several areas receiving particular attention: client funds safeguarding, regulatory remediation, wind-down planning, qualifying holdings, ICT resilience and the risks arising from increasingly complex technology dependencies.

This month’s RegRally highlights the developments most relevant to payment institutions (PIs), electronic money institutions (EMIs), fintech businesses and groups operating across the Baltic and wider European markets.

Lietuvos bankas imposes EUR 90,000 measure on Nayax Europe over client funds safeguarding

Date: 24 July 2026 | Source: Lietuvos bankas – Financial Market Supervision Committee decisions
Link

Lietuvos bankas concluded an administrative settlement with the electronic money institution Nayax Europe UAB, imposing a EUR 90,000 measure for breaches related to client funds safeguarding and associated internal control requirements, identified during a targeted, scheduled inspection.

Nayax Europe had already begun remediation before submitting its settlement proposal and committed to providing an audit firm’s opinion confirming remediation by 30 April 2027.

In the same set of decisions, Lietuvos bankas reported that an inspection of Perlas Finance UAB identified only minor breaches, most of which were promptly remedied. No enforcement measure was imposed.

The decisions also included several qualifying holding assessments involving financial market participants.

What this means for businesses

The different outcomes demonstrate that supervisory authorities consider not only the existence of deficiencies but also the institution’s response, the speed of remediation, and the ability to demonstrate that corrective measures have been implemented.

For EMIs and PIs, client funds safeguarding remains a key supervisory priority. Safeguarding arrangements and the internal controls supporting them should therefore be tested for effective operation, rather than assessed only on the basis of policies and procedures.

Recommended actions

EMIs and PIs should:

  • review client funds safeguarding arrangements and related internal controls;
  • test whether safeguarding controls operate effectively in practice;
  • ensure supervisory findings are assigned to responsible persons and remediated within defined deadlines;
  • maintain evidence of remediation and, where appropriate, obtain independent assurance;
  • review escalation procedures for material safeguarding deficiencies.

For qualifying holding transactions, businesses should also ensure that acquisition documentation covers the complete direct and indirect ownership chain, including non-EU entities and entities undergoing corporate reorganisation.


AlphaPay licence revoked following multiple regulatory breaches

Date: 22 July 2026 | Source: Lietuvos bankas – Board resolutions
Link

Lietuvos bankas revoked the payment institution licence of AlphaPay, UAB (formerly NovaPay, UAB), following multiple breaches of regulatory requirements.

The institution no longer met licensing requirements concerning its internal control system and ICT infrastructure, failed to ensure adequate protection of payment service users’ funds and no longer complied with its own funds requirements.

AlphaPay also failed to submit its audited 2025 annual financial statements, audit opinion and shareholder resolution on profit or loss allocation within the prescribed deadlines.

The licence had been suspended in April 2026, with access to client fund accounts restricted. According to Lietuvos bankas, AlphaPay subsequently failed to comply with remediation orders. The institution was found to be insolvent, with negative equity, and Lietuvos bankas announced that it would apply to the court for bankruptcy proceedings.

What this means for businesses

The case illustrates how supervisory intervention can escalate from remediation and suspension to licence revocation and insolvency where material deficiencies remain unresolved.

It also demonstrates that regulatory compliance extends beyond customer-facing requirements. Internal controls, ICT infrastructure, safeguarding, own funds and timely financial reporting are all integral to maintaining a payment institution licence.

Recommended actions

PIs and EMIs should:

  • maintain a central register of supervisory findings and remediation obligations;
  • assign clear responsibility and deadlines for corrective actions;
  • provide timely evidence of remediation to the supervisory authority;
  • monitor own funds and solvency requirements continuously;
  • ensure audited financial statements and other regulatory reports are submitted on time;
  • regularly reassess whether internal control and ICT arrangements continue to satisfy licensing requirements.

Lietuvos bankas finds significant weaknesses in EMI and PI wind-down plans

Date: 17 July 2026 | Source: Lietuvos bankas – Financial Market Supervision Committee decisions
Link

Lietuvos bankas assessed the wind-down plans of 12 electronic money and payment institutions, focusing on their content, practical applicability and legal compliance.

Four plans were assessed as comprehensive and implementable, while five were considered insufficiently detailed and three overly formal and theoretical. Each institution received an individual assessment and recommendations, with aggregated findings also published by Lietuvos bankas.

The same supervisory decisions included several qualifying holding assessments, including the proposed acquisition of a qualifying holding exceeding 50% in payment institution SOLLO, UAB.

What this means for businesses

The findings indicate that a wind-down plan is expected to be operationally usable, rather than simply a formal document prepared for licensing purposes.

A credible plan should explain how the institution would actually cease its activities, including how client funds would be returned, how outstanding transactions would be handled, which persons would be responsible and which operational and ICT dependencies would need to remain available during the wind-down.

Recommended actions

EMIs and PIs should:

  • reassess existing wind-down plans against the latest supervisory findings;
  • ensure the plan reflects the institution’s actual business model and operational dependencies;
  • document the mechanics and timing of client fund returns;
  • identify responsible persons and decision-making arrangements;
  • address critical banking, outsourcing and ICT dependencies;
  • test the plan against realistic wind-down scenarios rather than relying solely on a theoretical document.

The decisions also reinforce the need for complete qualifying holding notifications covering all relevant direct and indirect acquirers.


Latvijas Banka grants new EMI licence as Latvian payments sector continues to grow

Date: 9 July 2026 | Source: Latvijas Banka – MOIN Payments licence announcement
Link

Latvijas Banka granted an electronic money institution licence to SIA MOIN Payments, including authorisation to provide money remittance services.

At the time of the announcement, Latvia had 12 licensed and one registered electronic money institution and 10 licensed payment institutions. Latvijas Banka had already issued four EMI licences and five PI licences during 2026.

The Latvian regulator continues to promote pre-licensing consultations for businesses preparing to enter the market.

What this means for businesses

The continued licensing activity confirms that Latvia remains an active jurisdiction for payment and e-money businesses.

For prospective applicants, early regulatory engagement and the quality of the licensing package remain important. The business model, governance arrangements, safeguarding framework, AML/CTF controls, financial resources and ICT architecture should be presented as a coherent regulatory framework rather than as separate documentation streams.

Recommended actions

Businesses considering a Latvian PI or EMI licence should:

  • use Latvijas Banka’s pre-licensing consultation process at an early stage;
  • clearly define the proposed business model and regulated services;
  • align governance, safeguarding, AML/CTF, risk management and ICT documentation with the actual business;
  • identify regulatory gaps before submitting the formal application;
  • ensure the licensing package demonstrates how the proposed controls will operate in practice.

UK regulators begin oversight of critical cloud and technology providers

Date: 10 July 2026 | Source: FCA
Link

UK financial regulators began overseeing the first Critical Third Parties (CTPs) from 13 July 2026, following HM Treasury’s designation of four global cloud and technology providers:

  • Amazon Web Services EMEA SARL;
  • Google Cloud EMEA Limited;
  • Microsoft Ireland Operations Ltd;
  • Oracle Corporation UK Limited.

The Bank of England, PRA and FCA will jointly oversee the resilience of critical services provided by these organisations to the UK financial sector, focusing on systemic risks, coordination and information sharing.

The regime complements, rather than replaces, existing outsourcing and operational resilience requirements. Regulated firms remain responsible for their own third-party risk management, due diligence and contingency planning.

The UK regulators have also established arrangements for cooperation with comparable regimes, including the EU’s DORA framework.

What this means for businesses

For financial institutions operating across the EU and UK, ICT third-party oversight is becoming increasingly cross-border and systemic.

The designation of a cloud provider as a critical third party does not transfer the regulated firm’s responsibility for managing outsourcing and ICT risks. PIs and EMIs must still understand their dependencies, assess concentration and exit risks, and maintain appropriate contingency arrangements under DORA.

Recommended actions

Financial groups with UK operations should:

  • identify whether critical ICT providers are used across their UK and EU operations;
  • map material ICT dependencies and concentration risks;
  • maintain accurate outsourcing and ICT third-party registers;
  • assess contractual arrangements and contingency measures for critical providers;
  • distinguish provider-level regulatory oversight from the firm’s own DORA and operational resilience obligations.

EU regulators call for stronger ICT risk management against frontier AI threats

Date: 31 July 2026 | Source: ESMA
Link

The European Supervisory Authorities — EBA, EIOPA and ESMA — published a joint statement calling for a consistent, risk-based approach to ICT risks arising from frontier AI models.

The authorities highlighted the ability of AI-enabled cyber tools to rapidly identify and exploit vulnerabilities, target shared infrastructure and exploit single points of failure across financial entities.

The ESAs recommend strengthening ICT risk management across three areas:

  • Prevention: asset inventories, secure-by-design practices, proactive patching and supply-chain standards.
  • Detection: continuous vulnerability scanning, behavioural monitoring and more frequent testing.
  • Management: resilience testing against AI-enhanced scenarios, dependency mapping and management-body accountability.

The authorities emphasise that measures should be proportionate to the institution’s size, risk profile and the nature, scale and complexity of its services, consistent with DORA’s proportionality principle.

What this means for businesses

AI-related cyber risk is increasingly becoming part of the core DORA ICT risk management framework.

For PIs and EMIs, periodic cybersecurity reviews may no longer be sufficient where vulnerabilities can be identified and exploited at significantly greater speed. ICT risk management should account for AI-assisted attacks that affect multiple systems, shared infrastructure, and critical third-party providers.

Recommended actions

PIs and EMIs should:

  • review ICT risk assessments against AI-enhanced attack scenarios;
  • assess whether vulnerability scanning and patching cycles remain sufficiently frequent;
  • map critical ICT dependencies and potential single points of failure;
  • test business continuity and incident-response arrangements against AI-assisted attacks;
  • ensure management bodies receive timely information on material ICT risks;
  • consider AI-driven threats when reviewing risk appetite and DORA compliance frameworks.

Key takeaways for payment institutions and EMIs

The latest regulatory developments point to several priorities for the payments sector:

  • Safeguarding must be effective in practice.
    Client funds arrangements and the controls supporting them remain a significant supervisory focus.
  • Remediation needs to be demonstrable.
    Institutions should be able to show that supervisory findings have been addressed promptly and effectively.
  • Wind-down plans must be operationally credible.
    A plan should explain how the business could actually be wound down, including client fund returns, responsibilities and critical dependencies.
  • Regulatory reporting is part of licensing compliance.
    Late or incomplete financial reporting can contribute to serious supervisory consequences.
  • ICT third-party risk is becoming increasingly systemic.
    DORA compliance requires institutions to understand and manage their dependencies on critical technology providers.
  • AI is changing the ICT threat environment.
    PIs and EMIs should consider whether their current vulnerability management, monitoring, resilience testing, and incident response arrangements are adequate for AI-enhanced attacks.
  • The Baltic payments market remains active.
    Both Lithuania and Latvia continue to licence and supervise payment and e-money institutions, while cross-border acquisitions and changes of control remain subject to detailed regulatory scrutiny.

Need assistance?

Our payment services and fintech specialists advise PIs, EMIs and other regulated businesses on:

  • PI and EMI licensing and regulatory authorisations
  • Payment services and e-money regulatory compliance
  • Client funds safeguarding
  • DORA and ICT risk management
  • AML/CTF and risk management frameworks
  • Wind-down and exit planning
  • Regulatory inspections and remediation
  • Qualifying holdings and changes of control
  • Regulatory reporting and supervisory communications
  • Baltic market entry and cross-border regulatory matters

If you have questions regarding the developments covered in this edition or would like to assess your payment institution’s regulatory readiness, our team will be happy to assist.

Related news

Knowledge without experience is of little use. Therefore we are proud of having our own valuable experience to share with you.

Newsletter SubscriptionGet in touch