E-Money Safeguarding Reconciliation
An EMI or PI CTO has to prove on any business day that customer balances in the ledger equal the safeguarding accounts. No EU instrument in force names how often that comparison runs. This walks the invariants that do exist, the way each one breaks and the control that catches the break, ordered by how fast the control fires.
Key takeaways: e-money safeguarding reconciliation 5
What EU law actually sets a deadline for on safeguarded funds, where the reconciliation cadence is fixed today in practice and the two clocks that sit on the same inbound leg.
- No EU instrument in force names a reconciliation frequency for safeguarded funds, so the cadence is an engineering decision today and a dossier commitment a supervisor reads The nearest fixed points in the text are a placement deadline, a five year retention duty and an annual audit cycle, and none of them state how often the ledger and the safeguarding accounts must be compared. A cadence is instead fixed today through the authorisation dossier that describes an applicant's own safeguarding measures.
- Two different clocks sit on the inbound leg: five business days after issuance under EMD2 Article 7(1), and the end of the business day following receipt in the destination article Issuance of electronic money and receipt of funds are two different events, so these are two separate intervals rather than one interval shortened into another, and neither is stated as tighter than the other. Typing receipts by their legal basis and giving each population its own clock keeps a blended report from hiding the day one population needs the longer window.
- PSD2 Article 10(1) has named electronic money institutions and carried a central bank deposit option since 8 April 2024, while Article 10(2) is unamended and names only a payment institution The central bank deposit option is current law rather than a new proposal, even though a great deal of commentary presents it as one. The two paragraphs of the same article should not be treated as covering both institution types the same way, since only paragraph 1 was amended to name electronic money institutions expressly.
- EMD2's end-of-calendar-day "average outstanding electronic money" is an own-funds measure recomputed monthly over six months, and wiring the safeguarding control to it hides single-day breaks The figure is computed daily and looks like a natural fit for a reconciliation check, but it is a six month average recalculated once a month and it serves the own funds and threshold exemption regime rather than any safeguarding duty. Pointing a safeguarding control at it silently inherits an averaging window that a genuine single day break would not survive.
- The word "reconciliation" enters EU payments law only in the PSD3 compromise text, as a mandate to write standards that do not exist, so build the cadence as a parameter That text is agreed but not yet law, and its mandate asks a regulator to develop standards covering reconciliation rather than stating one itself, with its own submission deadline still an unfilled placeholder. Building the cadence as a configurable parameter with a written rationale is what survives contact with a supervisor now and with a technical standard later.
Ask an engineering team what e-money safeguarding reconciliation runs on and the answer that comes back is usually a frequency somebody read somewhere. The job underneath the question is concrete and it does not move: on any business day you have to be able to prove that the sum of customer balances in the internal ledger equals what sits in the safeguarding accounts. What no EU instrument in force tells you is how often that proof must be produced. Sections below take the equation apart into the invariants that do hold, the way each one breaks in a real ledger and the control that catches the break, ordered by how fast the control fires.
In short: No EU instrument in force names a reconciliation frequency for safeguarded funds. What the instruments do set is a placement deadline of the end of the business day following receipt, a five year record retention period and separate accounting information subject to an auditor's report on the annual cycle. Two different clocks sit on the inbound leg, because EMD2 Article 7(1) measures five business days from the issuance of electronic money while the destination article measures to the end of the business day following the receipt of funds. PSD2 Article 10(1) has named electronic money institutions expressly and carried a central bank deposit option since 8 April 2024, when Regulation (EU) 2024/886 amended it, while Article 10(2) is unamended and still addresses only a payment institution. The word "reconciliation" enters EU payments law for the first time in the PSD3 compromise text, as a mandate to the European Banking Authority to write standards that do not yet exist, which makes the cadence an engineering decision today and a supervised one tomorrow.
No account holding customer money also holds ours
Detection here happens at posting time, which is why it comes first. The current text of PSD2 Article 10(1), as amended, requires "payment institutions which provide payment services as referred to in points (1) to (6) of Annex I to this Directive and electronic money institutions as defined in Article 2, point (1), of Directive 2009/110/EC" to safeguard all funds received from payment service users or through another payment service provider for the execution of payment transactions. Method (a) opens with the invariant itself: "funds shall not be commingled at any time with the funds of any natural or legal person other than payment service users on whose behalf the funds are held".
How the invariant actually breaks
Rarely by a deliberate transfer. It breaks through refunds and chargebacks routed back along the operating account path, through a fee sweep that debits the safeguarding account for the institution's own revenue because the fee was accrued against a customer balance, and through a settlement remainder parked in a house account while somebody works out whose it is. Each of those is a correctly functioning piece of software doing what it was told.
Assert on the flow, not on the balance
A balance check finds commingling after it has happened. A flow check refuses it. Every credit and debit against a safeguarding account carries a counterparty class, and any class outside the payment service user population fails at posting rather than at month end. The evidence that control emits is a rejected posting log.
Effective 8 April 2024, the amended text above is established from the consolidation of that date, which lists Regulation (EU) 2024/886 as its only amending act and already carries the new paragraph. The PSD3 compromise text redrafts the same standard as funds that "as soon as possible are no longer commingled", with a struck text marker sitting at exactly that point. Which formulation is stricter is not a conclusion this article draws.
Every receipt is out of the collection account by the end of the next business day
Detection moves to T plus one. Current PSD2 Article 10(1)(a) sets the placement trigger where funds are "still held by the payment institution or electronic money institution and not yet delivered to the payee or transferred to another payment service provider by the end of the business day following the day when the funds have been received". At that point the funds "shall be deposited in a separate account in a credit institution or in a central bank at the discretion of that central bank, or invested in secure, liquid low-risk assets as defined by the competent authorities of the home Member State".
Note the central bank option, which a great deal of commentary presents as a PSD3 innovation. It has been current law since 8 April 2024. The draft continues it rather than introducing it, and the same holds for the express naming of electronic money institutions in the chapeau.
Breaks cluster around receipts that never reach a destination. An onward payment fails and the receipt sits unrouted. A batch misses a cutoff and rolls. An inbound credit cannot be matched to a customer, so nobody owns it and it is never placed. The control is an age query over unplaced receipts, measured in business days and run before each cutoff rather than after it, and the evidence is the age distribution itself, retained.
One honest limit belongs here. EMD2 Article 7(1) defines business days by cross reference to point 27 of Article 4 of the repealed PSD1, and the correlation table rows retrieved for this article cover Article 9 and Articles 5 to 25, not Article 4 point 27. This article therefore names no destination for that definition.
The sum of customer balances equals the safeguarded balance, on a cadence no instrument names
This is the center of the article and the one section whose position in the ordering is a choice rather than a deadline. Every other invariant here has a latency set by something outside the institution. This one does not, and that is precisely the subject.
What was searched, and what came back
Targeted searches across PSD2 and EMD2 for reconciliation, record keeping and recomputation frequency returned six things. A placement deadline at the end of the business day following receipt. A representative portion "reasonably estimated on the basis of historical data to the satisfaction of the competent authorities". A five year record retention duty. Separate accounting information subject to an auditor's report. The annual statutory audit. And two application stage descriptions, of safeguarding measures and of accounting procedures. None of them states how often the safeguarded amount must be recomputed or reconciled against the internal ledger.
That retrieval was chunk based, so an absent passage means it was not surfaced rather than that it does not exist. This article states what was searched and what was found, and no more than that. It also makes no claim about national regimes, none of which were tested, even though EMD2 Article 7(4) lets Member States or their competent authorities "determine, in accordance with national legislation, which method shall be used by the electronic money institutions to safeguard funds".
Where the cadence is actually fixed today
Through the authorisation dossier and the supervision that follows it. PSD2 Article 5(1)(d) requires the application to contain "a description of the measures taken for safeguarding payment service users' funds in accordance with Article 10", and Article 5(1)(e) requires "a description of the applicant's governance arrangements and internal control mechanisms, including administrative, risk management and accounting procedures". Both reach electronic money institutions, because amended EMD2 Article 3(1) applies "Article 5, Articles 11 to 17, Article 19(5) and (6) and Articles 20 to 31 of Directive (EU) 2015/2366" to them mutatis mutandis. The applicant describes its own measures, and the cadence it writes down is the cadence it will be held to.
Licensing lead time in our own delivery record is 7 months, observed across 4 banking platform builds between 2012 and 2026. That figure is ours, not a regulatory one, and it carries a single consequence for this section: the cadence is declared in a long lead artefact, so the decision lands months before the first customer balance exists. Teams building toward a license should read that alongside how to build a neobank.
The break register is the deliverable
Breaks in this equation are boring and recurring. A reversal posted to the ledger but not yet settled at the bank. A fee accrual booked against a customer balance. An FX rounding remainder. An unallocated inbound credit sitting outside both sides of the comparison at once. The control is a signed comparison with a named break register, an ageing rule per break class and a resolution owner per class. Because no instrument names the cadence, the cadence and its written rationale are themselves the artefact a supervisor reads, and a recommendation you find in general circulation is not sourced to any of these instruments. Ours, offered as engineering and not as compliance: pick the cadence from the ageing profile of your own break classes, then defend it in writing.
The recital rationale under current law is older and thinner than the control it now supports: "Provision should be made for payment service user funds to be kept separate from the payment institution's funds." The PSD3 compromise text gets closer, requiring institutions to "safeguard the amount that corresponds to the claim against the payment institution of the payment service user arising from the provision of payment services", which is the equation stated almost in full and still with no frequency attached. That text is not law.
The e-money leg runs on five business days, not on the next business day
Detection slides to T plus five, and only for one population of receipts.
Two clocks measuring two different intervals
EMD2 Article 7(1) is unamended 2009 text. It requires an electronic money institution "to safeguard funds that have been received in exchange for electronic money that has been issued, in accordance with Article 9(1) and (2) of Directive 2007/64/EC", and then sets its own backstop:
In any event, such funds shall be safeguarded by no later than five business days, as defined in point 27 of Article 4 of that Directive, after the issuance of electronic money.
That clock starts at issuance. The destination article's clock starts somewhere else. PSD1 Article 9(1)(a), the reference as printed in the chain, ran to "the end of the business day following the day when the funds have been received", and current PSD2 Article 10(1)(a) carries the same trigger. Receipt of funds and issuance of electronic money are two different events, so these are two intervals rather than one interval shortened into another. Neither is tighter than the other on its own terms.
The chain the e-money clock travels
PSD2 Article 114 does the work: "Directive 2007/64/EC is repealed with effect from 13 January 2018", and "Any reference to the repealed Directive shall be construed as a reference to this Directive and shall be read in accordance with the correlation table in Annex II to this Directive." That table maps PSD1 Article 9(1) to PSD2 Article 10(1) and PSD1 Article 9(2) to PSD2 Article 10(2). For PSD1 Article 9(3) and (4) it prints no corresponding provision, which matters because EMD2 Article 7(3) applies the whole of PSD1 Article 9 to institutions for activities "not linked to the activity of issuing electronic money".
EMD2 still reads this way because Regulation (EU) 2024/886 reached electronic money institutions by amending PSD2, not EMD2. EMD2 has exactly one consolidation, dated 13 January 2018, and Article 7 sits in unamended base text inside it. Further live PSD1 cross references survive elsewhere in EMD2, including at Article 5(2) and Article 6(4).
What "in accordance with" does not settle
Here is a genuinely open question, and the reasoning below is ours. Amended Article 10(1) reaches electronic money institutions directly, but its scope clause covers funds received for the execution of payment transactions. Funds received in exchange for issued electronic money are a different basis and they route through EMD2 Article 7(1), which requires safeguarding "in accordance with" the same destination. One reading is that those words import the destination article's methods. The other is that they import its scope as well. Nothing retrieved answers it, and the destination is the same article under either reading, which is the reassuring part.
What follows for a build is unaffected by the ambiguity. Type receipts at ingestion by legal basis, give each type its own clock, its own alarm and its own evidence, and emit a per type ageing report rather than a blended one. A blended report hides the day a product genuinely needs the five days. One neighbouring clock is worth fencing off explicitly: where a significant e-money token issuer moves onto MiCA custody timing, that five working day rule is a different instrument with a different term and a different addressee. Separately, the PSD3 compromise text would cut the e-money issuance clock to the end of the business day following receipt, which is covered further down.
Every safeguarded euro sits in a place the instrument names
Detection on change, which in practice means weekly to monthly. Current PSD2 Article 10(1)(a) names the deposit and investment venues quoted above and then adds the insolvency limb: safeguarded funds "shall be insulated in accordance with national law in the interest of the payment service users against the claims of other creditors of the payment institution or electronic money institution, in particular in the event of insolvency". Method (b) is the alternative route, an insurance policy or comparable guarantee "from an insurance company or a credit institution, which does not belong to the same group as the payment institution or electronic money institution itself, for an amount equivalent to that which would have been segregated in the absence of the insurance policy or other comparable guarantee".
Read that measure twice if you use method (b), because the covered amount tracks the amount that would otherwise have been segregated, so a policy written once against a launch year balance drifts as the book grows.
The asset side, and where its chain stops
EMD2 Article 7(2) defines secure, low risk assets as "asset items falling into one of the categories set out in Table 1 of point 14 of Annex I to Directive 2006/49/EC" and "for which the specific risk capital charge is no higher than 1,6%, but excluding other qualifying items as defined in point 15 of that Annex", plus UCITS units investing solely in those assets. Directive 2006/49/EC has been superseded, and the repeal chain for it was not retrieved for this article, so no destination instrument is named here. The safe statement is that current EMD2 text references 2006/49/EC and the PSD3 draft replaces it with the CRR. Competent authorities may also carve assets out of the category "in exceptional circumstances and with adequate justification", on an evaluation of security, maturity, value or other risk element.
Breaks here are organisational. An account opened by treasury outside the register. An asset that drifts out of the permitted class after a rating change. A counterparty that turns out not to be a credit institution. The control is a venue register that is the authoritative list, reconciled against the bank's own account list and the custody statement rather than against a spreadsheet, and the evidence is the register diff, dated. One tier labeled note: the PSD3 draft narrows the deposit venue to a credit institution authorised in a Member State, where current law says a credit institution unqualified.
The end of day figure you already compute is not this one
Monthly detection, and the trap in the cluster. EMD2 Article 2(4) defines "‘average outstanding electronic money’" as "the average total amount of financial liabilities related to electronic money in issue at the end of each calendar day over the preceding six calendar months, calculated on the first calendar day of each calendar month and applied for that calendar month".
Three features make it look like a daily reconciliation duty. The figure is computed daily. It is an aggregate electronic money liability. It is the same order of quantity a reconciliation compares the safeguarded balance against. Three further features make it something else entirely. It is a six month average. It is recomputed on the first calendar day of each month and applied for that month. And it serves the own funds regime and the threshold exemption rather than any safeguarding obligation. It is legitimate here only as background that EU e-money law already reasons about an end of day aggregate liability figure, and it may not be read as evidence that EU law requires daily safeguarding reconciliation.
The break is a wiring decision that looks like reuse. A team points the safeguarding control at the own funds feed because both are end of day balances off the same event stream, and the safeguarding evidence silently inherits a six month averaging window that hides a single day break completely. Two computations, one point in time and one averaged, never the same job. The evidence is both figures, both dated, presented as visibly different quantities so nobody downstream confuses them again.
The representative portion still represents
Detection on recalibration, quarterly at best. PSD2 Article 10(2) allows a representative portion where the mixed use split "is variable or not known in advance", provided it "can be reasonably estimated on the basis of historical data to the satisfaction of the competent authorities". The statutory standard is about evidence rather than about a number, so the control is to recompute the portion from actual historical usage on a fixed cadence and keep the series. The evidence is the series, not the current value. Estimated once for the dossier and never revisited, the portion describes a product mix that stopped existing years ago.
An addressee asymmetry sits inside this one article and no conclusion is drawn from it here. Amended Article 10(1) names payment institutions and electronic money institutions. Unamended Article 10(2) still addresses only a payment institution, and the retrieved text does not state whether or how paragraph (2) reaches an electronic money institution. Worth noting alongside it: Article 10 is not inside the ranges that amended EMD2 Article 3(1) applies to electronic money institutions, so an institution reaches Article 10 through the 2024 amendment and through EMD2 Article 7(1), not through Article 3(1).
The control leaves a record that outlives it
Annual detection, through the one recurring verification hook current law does provide. PSD2 Article 17(3) requires institutions to "provide separate accounting information for payment services and activities referred to in Article 18(1), which shall be subject to an auditor's report", prepared where applicable by statutory auditors or an audit firm. Around it sits the accounting acquis, with annual and consolidated accounts audited under Directive 2006/43/EC unless exempted. PSD2 Article 21 then requires records to be kept "for the purpose of this Title for at least 5 years", and that duty reaches electronic money institutions both through amended EMD2 Article 3(1)'s "Articles 20 to 31" and independently through the correlation table row mapping PSD1 Article 19 to PSD2 Article 21.
The failure mode is familiar to anybody who has sat an audit. The comparison runs, it fires, somebody resolves it in a chat thread, and nothing survives in a form a statutory auditor can test. So the reconciliation output has to be a record in its own right: the comparison, the break register, the resolution and the sign off, retained on the five year clock and structured so the separate accounting information can be tied back to it.
Our own analogue, offered as delivery experience rather than as a regulatory claim. The most frequent catch in our Production Readiness Reviews, applied before roughly 19 launches and migrations, is an operational gap rather than a code defect, and the canonical example is a backup with no proven restore. A reconciliation with no retained evidence and no proven resolution path is the same defect class.
The equation has to survive a standard nobody has written
Everything in this section is agreed text and not law. It comes from Council of the European Union documents 8222/26 and 8221/26, dated 17 April 2026 and made public on 23 April 2026, both marked LIMITE and headed "Confirmation of the final compromise text with a view to agreement". Draft article numbers will move in legal linguistic revision, so citations here are by document number and page.
The mandate that names the word
Council doc 8222/26, page 92, mandates the EBA to develop "regulatory technical standards on safeguarding requirements, laying down in particular safeguarding risk management frameworks for payment institutions to ensure protection of users' funds, and including requirements on segregation, designation, reconciliation and calculation of safeguarded funds", and to specify "the circumstances in which it is appropriate to avoid concentration risks". Its submission deadline is printed as "[ OP please insert the date= 1 year after the date of entry into force of this Directive]". That is the only place across the whole harvest where reconciliation appears as a safeguarding obligation, it is a mandate to write standards rather than a standard, and its deadline is an unfilled placeholder counted from an entry into force that has not happened. What the standards will require is undetermined and is not predicted here.
What else the compromise text would change
One merged article would cover both fund types, in "one or more of the following ways". Funds held in settlement accounts with systems designated under Directive 98/26/EC would count as compliant where not commingled, and only where "the funds used for settlement are ultimately held in credit institutions or central banks". Concentration risk is soft drafted: institutions "shall avoid, where appropriate, concentration risk" and "shall endeavour not to safeguard all payment service users' funds with one credit institution", which is not a requirement to spread funds across two or more credit institutions. The e-money clock would tighten to the end of the business day following receipt. Secure, liquid, low risk assets would be repointed at "Table 1 of Article 336(1) of Regulation (EU) No 575/2013". Material changes in safeguarding measures would require advance notification. The authorisation dossier would gain "a winding-up plan in case of failure", including "the return of safeguarded funds in the event of a disorderly wind-up", which is only executable against a per user claim breakdown. Recital (26) states the merger in the drafters' own words: electronic money services "should be limited to the issuance of electronic money and classified as a distinct payment service". Where a payment institution issues electronic money tokens, the draft routes safeguarding to the methods in Article 54 of Regulation (EU) 2023/1114, whose text was not harvested for this article, so no reserve figure appears here.
Three dates, none of them filled in
Council doc 8221/26, page 428, sets the PSR to apply 21 months after entry into force, defers two named draft articles to 27 months and applies two others from entry into force itself. All three are unfilled "[ OP please insert the date= ...]" placeholders, and there is no single PSR application date to plan against. Which leaves one design instruction that is safe today: parameterise the cadence, keep the venue set data driven and keep the calculation auditable line by line, because the list of things the future standard will cover is the one thing about it that is known.
Building the control before the standard arrives
Our engineering view from here on, with every regulatory statement behind it cited in the sections above. Detection latency is the variable worth designing around, and that judgement comes from our own delivery record rather than from any instrument. Across 41 tracked Sev-1 and Sev-2 incidents on 9 products between 2023 and 2026, median time from onset to detection is about 8 minutes and from detection to service restoration about 47 minutes. Data, migrations, state or reprocessing account for 17 percent of primary causes in that same set. A break in a money ledger is a data class fault, and the damage it does scales with how long it goes unseen.
Five artefacts are worth being able to produce without opening a ticket. The cadence decision with its written rationale, since the dossier route through PSD2 Article 5(1)(d) and 5(1)(e) is what a supervisor reads and it reaches electronic money institutions through amended EMD2 Article 3(1). A break taxonomy with an owner per class. An ageing rule per class, with the alarm on the age rather than on the amount. A venue register held as data and diffed on change. And a retention path that puts the comparison, the register and the sign off on the five year clock alongside the separate accounting information. None of that is sized by any instrument, which makes it an engineering cost a budget has to carry on its own, of the kind we walk through in FinTech MVP compliance cost. Building it is FinTech development services work rather than a policy exercise.
How Pharos Production helps
Pharos Production builds the ledger side of this control: counterparty class assertions that fail a bad posting rather than reporting it, receipt typing by legal basis so each inbound population carries its own clock, a break register with ageing and ownership per class, a venue register held as data, and a retention path that makes the reconciliation itself an auditable record. We treat the cadence as a parameter and its rationale as a deliverable, because that is what survives contact with a supervisor today and with a technical standard later. Where this becomes a platform rather than a control, it is banking software development.
Sources: Directive (EU) 2015/2366 (PSD2) in its consolidated versions of 8 April 2024 (CELEX 02015L2366-20240408) and 17 January 2025 (CELEX 02015L2366-20250117), for Article 10(1) as amended by Regulation (EU) 2024/886 and Article 10(2) as unamended base text. Directive (EU) 2015/2366 as published in the Official Journal, OJ L 337, for Article 5(1), Article 17, Article 21, recital (37), Article 111 at OJ L 337/112 and L 337/113, Article 114 at OJ L 337/115 and the Annex II correlation table at OJ L 337/117 to L 337/120. For Article 2(4), Article 3(1) as replaced, Article 5(2), Article 6(4) and Article 7, the source is Directive 2009/110/EC (EMD2) in its single consolidated version of 13 January 2018 (CELEX 02009L0110-20180113). Directive 2007/64/EC, Article 9(1), quoted as the reference printed in the operative chain. Council of the European Union documents 8222/26 (pages 16, 64, 85 to 92) and 8221/26 (page 428), both marked LIMITE and headed as confirmation of a final compromise text with a view to agreement, not law and not in the Official Journal as of the date this was written. The second limb of Directive 2007/64/EC Article 9(1) is truncated in our source at a trailing "or" and is not completed here. No destination is named for PSD1 Article 9(3) and (4), for the definition of business days at point 27 of Article 4 of PSD1, or for the repeal chain of Directive 2006/49/EC. The invariant framing, the break taxonomy, the ageing rule, the ordering by detection latency and the reading of "in accordance with" are ours. Our licensing lead time, incident and Production Readiness Review figures are our own delivery record, not market data. This is engineering guidance, not legal advice.
FAQ
Quick answers to common questions about custom software development, pricing, process and technology.
Type to filter questions and answers. Use Topic to narrow the list.
Showing all 7
No matches
Try a different keyword, change the topic or clear filters
-
No EU instrument in force names a frequency. The nearest provisions set a placement deadline of the end of the business day following receipt, a five-year record retention period and separate accounting information subject to an auditor's report on the annual cycle.
A cadence is fixed in practice through the authorisation dossier and supervisory assessment, under PSD2 Article 5(1)(d) and 5(1)(e), which amended EMD2 Article 3(1) applies to electronic money institutions as well.
-
For the first time in the PSD3 compromise text, as a mandate to the EBA to develop regulatory technical standards covering segregation, designation, reconciliation and calculation of safeguarded funds. That text is not law, and the submission deadline is an unfilled placeholder set one year after an entry into force that has not happened.
-
Paragraph (1) names them expressly and has done since 8 April 2024, when Regulation (EU) 2024/886 amended it. Paragraph (2), the mixed-use and representative-portion paragraph, is unamended and still addresses only a payment institution.
The two paragraphs should not be described as covering both institution types uniformly.
-
Yes, under current law, at the discretion of that central bank. The option was added to PSD2 Article 10(1)(a) with effect from 8 April 2024.
It is not a PSD3 innovation, and material describing it as one is out of date.
-
EMD2 Article 7(1) is unamended 2009 text and gives no later than five business days after the issuance of electronic money, with the safeguarding itself to be done in accordance with the destination article, whose own placement rule is the end of the business day following receipt. Those are two different clocks on one inbound leg.
-
No. EMD2 Article 2(4) measures financial liabilities related to e-money in issue at the end of each calendar day over the preceding six calendar months, calculated on the first calendar day of each month and applied for that month. It serves the own-funds regime and the threshold exemption, and no safeguarding obligation attaches to it.
-
No. The compromise text says institutions shall avoid concentration risk where appropriate and shall endeavour not to safeguard all user funds with one credit institution. That is deliberately soft drafting, it is not law yet, and the EBA is mandated to specify when avoiding concentration risk is appropriate.
I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.
My focus is on complex products where mistakes are costly:
- Web3 and blockchain platforms
- FinTech and regulated products
- High-load startup systems
- MVP → scale transitions
We don’t do body-shopping.
We don’t sell generic outsourcing.Instead, we help founders:
- build the right team structure from day one
- keep technical ownership and transparency
- scale delivery without losing control
- avoid vendor lock-in and hidden risks
Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.