When the obligation arises, and which funds it covers
Safeguarding is the obligation on a payment institution to keep the funds it receives from its users separate from its own assets. Article 10 of Directive (EU) 2015/2366, known as PSD2, imposes it across the European Economic Area. Article 7 of Directive 2009/110/EC extends it to e-money issuers. Article 18 of PSD2 defines the status of these funds: they are neither a deposit nor e-money. The institution therefore cannot use them for its own account, and any credit it grants can never be funded with money received to execute a payment transaction. It holds the funds in custody for its users. It cannot dispose of them. Safeguarding is the counterpart of that ban on using them.
The scope of the obligation follows from Annex I of PSD2, which lists the payment services. Safeguarding applies to providers of any of services 1 through 6 in that annex. Those providers actually receive funds. Payment initiation and account information, items 7 and 8 of the same annex, are excluded, because neither service ever puts user funds in the provider’s hands. The distinction shapes how payment flows are designed. A payment pushed from the payer’s account to the merchant’s account triggers no safeguarding, because no intermediary holds the funds. That explains part of the success of bank transfer checkouts in European e-commerce.
Article 10 sets two separate timing requirements. The first allows no delay at all: the funds must never be commingled with the funds of anyone other than the users on whose behalf they are held. The second sets a deadline. Funds still held at the end of the business day after the day they were received must be deposited in a separate account at a credit institution. Regulation (EU) 2024/886 added an option: since April 9, 2025, that account can be held at a central bank willing to provide it. The funds can also be invested in secure, liquid, low-risk assets, as defined by the authority of the home member state. Separation therefore applies from the moment of receipt, while the deposit into the protected account comes with a grace period.
| Case | What the law says | Reference |
|---|---|---|
| Funds received from a user to execute a payment transaction | Never commingled with anyone else’s funds; if still held at the end of the business day after receipt, deposited in a separate account at a credit institution or at a central bank willing to hold it, or invested in secure, liquid assets | PSD2, Art. 10(1)(a), as amended by Regulation (EU) 2024/886 |
| Funds received through another payment service provider | Same regime: the text expressly covers funds received “through another payment service provider” | PSD2, Art. 10(1) |
| Hybrid institution, with funds partly intended for services other than payment services | Only the share intended for future payment transactions is safeguarded. If that share is variable or unknown in advance, a representative portion estimated from historical data and accepted by the competent authority | PSD2, Art. 10(2) |
| Funds received in exchange for e-money issued | Safeguarded under the PSD2 regime; the obligation attaches to issuing the e-money, not to the customer’s order | Directive 2009/110/EC, Art. 7(1) |
| E-money paid for by payment instrument, especially by card | No safeguarding required until the funds are credited to the issuer’s payment account, and in any case due no later than five business days after issuance | Directive 2009/110/EC, Art. 7(1) |
| Payment initiation and account information | Out of scope for safeguarding, since these providers never hold user funds | PSD2, Annex I, items 7 and 8 |
Mixed funds are amounts received of which only part is intended for future payment transactions. Article 10(2) gives them their own treatment. Only the share intended for payment transactions is subject to safeguarding. The rest stays outside the protected scope. The text allows for that share to be variable or unknown when the funds arrive. The institution then applies a representative portion, estimated from historical data and accepted by the competent authority. The regime covers hybrid institutions, from a software vendor that collects payments for its customers to an operator that bills a subscription and a money transfer service on the same invoice.
E-money has a different starting point: issuance rather than receipt of the funds. Article 7 of Directive 2009/110/EC applies the PSD2 regime to funds received in exchange for e-money issued. It adds a specific rule for funds paid by payment instrument. Those funds need not be safeguarded until they are credited to the issuer’s payment account or otherwise made available to it. The same article then sets an absolute limit of five business days after the e-money is issued.
The two methods, and why only one is used in practice
Article 10(1) of PSD2 requires one of two protection methods and favors neither. The first, under point (a), segregates the funds in a separate account or invests them in secure, liquid assets. The second, under point (b), leaves the funds in the institution’s own accounts and covers them with a third party’s promise to pay. Both aim at the same result: putting the funds beyond the reach of the institution’s creditors. But they do not have the same effect on the day the institution fails. The difference lies in what a liquidator finds: an identifiable asset in one case, a claim to pursue in the other.
Segregation places the funds in a separate account held at a credit institution or at a central bank willing to provide one. It also allows them to be invested in secure, liquid, low-risk assets. PSD2 does not define those assets; the authority of the home member state does. The e-money regime is more specific. Article 7 of Directive 2009/110/EC excludes any asset whose own funds requirement for specific risk exceeds 1.6%. It allows units in undertakings for collective investment in transferable securities (UCITS) that invest solely in such assets. The same provision lets the competent authority exclude some of those assets case by case, based on their security, maturity, or value.
The second method replaces segregation with a guarantee. An insurance policy or comparable guarantee from an insurer or credit institution outside the group covers an amount equal to what would have been segregated. It pays out when the institution becomes unable to meet its financial obligations. Two constraints limit its use. The amount covered must track an outstanding balance that changes every day, or part of customer balances goes unprotected. And the guarantor cannot belong to the same group as the protected institution, which rules out the parent company and any in-group insurance subsidiary. A single contract has to meet both requirements, and the method remains rare. European authorities do not publish how institutions split between the two methods, and no reliable count exists for the European Economic Area as a whole.
| Criterion | Segregation or secure assets (point a) | Insurance or comparable guarantee (point b) |
|---|---|---|
| Where the money sits | In a separate account at a credit institution, or, since Regulation (EU) 2024/886, at a central bank willing to hold it; or invested in secure, liquid, low-risk assets defined by the home authority | In the institution’s own accounts; the protection is a third party’s promise to pay |
| Who provides the protection | The credit institution holding the account, or the issuer of the securities held | An insurer or credit institution not in the same group as the protected institution |
| Amount protected | The balance actually deposited or invested, reconciled daily against the amounts owed | An amount equal to what would have been segregated without a guarantee |
| What triggers the protection | Nothing: national law puts the funds beyond creditors’ reach, with no action required | The institution’s inability to meet its financial obligations, as defined in the contract |
| Main residual risk | Failure of the account-holding bank, whose treatment under the deposit guarantee depends on national transposition | The guarantor’s solvency, the time needed to call the guarantee, and the contract’s exclusions and caps |
| What a liquidator finds | An identifiable asset that can be isolated from the rest of the estate | A claim to file and collect from the guarantor, with the delay that entails |
Segregation transforms the risk but does not remove it. Safeguarded funds become a claim on the bank that holds the account, so that bank’s failure hits the protected pool itself. PSD2 requires neither diversification across several banks nor a cap per bank. An issuer that places its entire outstanding balance with a single bank complies with the text, and the resulting concentration is a matter for its own continuity plan. The European Banking Authority called for the safeguarding regime to be clarified in its technical advice of June 23, 2022, on the PSD2 review. The legislative package the European Commission published on June 28, 2023, reopens the issue. A political agreement was reached on November 27, 2025, and the Council published the final texts on April 23, 2026. None of it applies yet, because the texts have not been published in the Official Journal.
Running safeguarding day to day
The daily safeguarding check reconciles two positions taken on the same date. The obligation is strict, and compliance is assessed day by day. The first position is the internal ledger, which gives the total of balances owed to users. The second is the protected account statement, plus the value of any assets held as cover. The two amounts must match. A break usually comes from money that has left one side without yet reaching the other. A good setup is one that can tie each of those amounts to an originating date and an expected counterparty.
The adequacy check tests an inequality between two amounts: the protected amount must be greater than or equal to the total owed to users, at every moment. A shortfall is topped up from own funds the same day, before its cause is known, because the inequality must hold at all times. A surplus also needs an explanation. It means either that the internal ledger understates what is held, or that fees earned by the institution are still sitting in the protected scope. Leaving them there is exactly the commingling that Article 10 prohibits.
- Settlement timing differences: acquirer settlements announced but not yet credited, transfers sent late in the day, direct debits presented but not yet settled. Each one has a date that explains it, and they clear on their own.
- Returns and disputes: a direct debit return or a card dispute debits the safeguarding account after the fact, when the customer balance has already been updated. The shortfall shows on the account side, not the ledger side.
- Fees not extracted: amounts earned by the institution stay in the protected scope because no outgoing entry was booked. The break is positive, and it is a breach.
- Multicurrency balances: one safeguarding account per currency, with customer balances converted at different rates, produces a revaluation difference. That is not an incident, as long as it is calculated and documented.
- Returned payouts: an outgoing transfer rejected for a wrong IBAN comes back to the account, but the customer balance has not been re-credited. The break persists until the funds are reallocated.
- Orphaned funds: balances of customers who have disappeared or were never verified. They are still owed and therefore still protected, however old the relationship.
Reconciliation for March 14
A Total customer balances, internal ledger .............. 12,480,316.42
B Safeguarding account balance (holding bank) ........... 12,402,118.07
C Acquirer settlements of March 13, in transit .......... 91,204.55
D Card top-ups issued March 14, not yet settled ......... 33,870.00
E Fees earned by the institution, to be extracted ....... 8,412.20
Protected amount used = B + C + D - E .................... 12,518,780.42
Break = protected amount - A ............................. +38,464.00
Internal alert threshold = 0.05% of A .................... 6,240.16
=> threshold exceeded: incident opened, cause to be found before close
=> POSITIVE break: check fee extraction first (item E)
then credits received but not posted to the ledgerThe annual safeguarding audit is a national requirement. EU law does not impose it; national authorities added it where they found failings. The Central Bank of Ireland wrote to the industry on January 20, 2023, requiring every institution to commission an external audit of its safeguarding. The auditor’s opinion and the board’s response were due before July 31, 2023. The UK regulator, in a neighboring market that has been outside the EU since 2020, also expects an annual audit. In September 2024, it consulted on tightening the regime as a whole.
An orderly wind-down plan is the document that sets out how funds would be returned if the institution ceased operating. It details the reports to be produced, who is authorized to act, and how long it would take to liquidate each class of assets. On April 9, 2024, the Central Bank of Ireland published a statement of expectations for the authorization of payment and e-money institutions. That document lists the wind-down plan among the items it reviews. A workable plan names the specific files, systems, and people involved, whereas a plan of intent merely states the expected outcome.
What safeguarding actually protects
Article 10 requires the funds to be insulated, under national law, from claims by the institution’s other creditors, especially in insolvency. The directive sets the result to achieve without prescribing the legal technique that must deliver it. Each member state has therefore built its own, with the tools of its civil law or common law. There is no single European rule on what happens to the funds in a liquidation. The protection exists throughout the European Economic Area, but the route by which it takes effect varies from one member state to another. That variation makes no difference while the institution is operating, and it shapes what happens to the funds the day it fails.
French law makes the funds immune from seizure. Articles L. 522-17 and L. 526-32 of the French Monetary and Financial Code provide for the funds to be deposited in a safeguarding account at a credit institution, separate from the operating accounts. Funds protected this way are beyond the reach of the institution’s other creditors, even when insolvency proceedings under Book VI of the French Commercial Code are opened against it. The protection applies without a court first having to rule on the nature of the users’ rights. It does, however, require the funds to have actually reached the protected account, which brings the issue back to meeting the deposit deadline.
UK law took more than two and a half years to settle the same question. Ipagoo LLP, an e-money institution, went into administration in August 2019 with imperfectly segregated funds. The Court of Appeal of England and Wales ruled in 2022 on the nature of e-money holders’ rights. It rejected the existence of a trust over the funds and held that they form a pool of assets applied first to e-money holders. Amounts that should have been safeguarded but were not fall into that pool. The holders therefore won on the merits, after two levels of court.
| What fails | Effect on safeguarded funds | What the user is left with |
|---|---|---|
| The payment institution or e-money institution | The protected funds are insulated from the institution’s creditors by whatever technique the applicable national law uses | Funds are returned from the protected pool, less the costs of the proceedings; any shortfall becomes an unsecured claim |
| The bank holding the safeguarding account | The protected pool turns into a claim on a failed bank | Depends on how the exclusion of financial institutions interacts with the look-through to the person entitled under Article 7(3) of Directive 2014/49/EU |
| The guarantor, under the insurance method | No assets had been segregated: the protection rested entirely on the guarantor’s promise | A claim on the insurer or guarantor bank, subject to that entity’s own insolvency regime |
| An agent or distributor collecting funds on the institution’s behalf | The funds have not yet reached the protected account; their status depends on where and when they were received | A question of fact before it is a question of law, decided on the records of the collection chain |
| The safeguarding arrangement itself, through internal misappropriation | The protected pool is already short before any proceedings are opened | Pro rata distribution of what remains, and an unsecured claim for the rest |
No European winding-up regime applies to payment institutions. Directive 2001/24/EC on reorganization and winding up covers only credit institutions, and a payment institution is not one. Its failure is therefore handled under the ordinary insolvency law of its home member state, by a court and an insolvency practitioner applying rules designed for an ordinary company. EU harmonization covers the authorization of the institution, not how its failure is handled. Users of an institution passported into 25 member states all fall under the proceedings opened in its home country, wherever they live. Those proceedings follow that country’s rules and run in its language.
What the user ends up receiving depends on what is in the protected pool and on the costs charged to it. Distribution is pro rata, meaning in proportion to the amount owed to each person. A customer with a balance of €1,000, in a pool that is 80% funded, receives €800. That customer becomes an unsecured creditor for the rest, a claim that ranks behind preferential creditors and only rarely leads to any recovery. No deposit guarantee scheme steps in, because a balance at a payment institution is not a deposit. User protection therefore rests on safeguarding and on supervision of the institution.
The failure, from withdrawal of authorization to repayment
Withdrawal of authorization is governed by Article 13 of PSD2, which lists the grounds, from failing to meet the conditions of authorization to posing a threat to the stability of the payment system. In practice, the sequence rarely starts with the withdrawal itself. An authority first imposes requirements or restrictions on the business, a faster and reversible measure. Payment flows stop at that very moment, before anyone knows whether there is a safeguarding shortfall. The merchant learns of the incident when its payments start failing, often the same day the press does.
The Wirecard collapse in June 2020 is a well-documented example of this sequence. On June 22, 2020, Wirecard AG acknowledged that €1.9 billion booked in trustee accounts probably did not exist, and it filed for insolvency in Munich on June 25. The next day, the UK regulator barred its subsidiary Wirecard Card Solutions, an e-money issuer, from carrying on any regulated activity. Cards issued for several programs stopped working overnight. The authority gave its written consent on June 29, and the ban was lifted at 12:01 a.m. on June 30. Other requirements remained in force.
The administrator’s or liquidator’s work then follows a sequence of steps that cannot be compressed. They freeze the accounts, identify the protected assets, and then work out who is owed what. That reconstruction relies on the failed institution’s ledger, the very document whose reliability broke down in the most serious cases. Next comes a call for claims with a deadline, then distribution of the available funds. Every step requires identity checks and anti-money laundering controls that the proceedings do not waive.
No harmonized European model governs how customers are kept informed during the proceedings. Information comes through press releases from the authority, notices from the insolvency practitioner, and information pages updated as often as the case requires. A merchant is not necessarily a direct recipient of those notices when its contract runs through a technical intermediary. Silence then says nothing about how far the proceedings have progressed. No consolidated European statistics on repayment times are published. Documented cases take years rather than weeks, and the UK created a special procedure in 2021 precisely because ordinary insolvency law returned funds too slowly.
A merchant’s failover plan
A merchant’s failover plan is the set of arrangements that keep it taking payments when its payment provider stops operating. Its scope goes beyond the funds stuck at that provider. It covers four separate exposures: payment acceptance that stops, refunds owed to customers, disputes that keep coming in, and transaction history that can no longer be accessed. Each exposure is handled separately, and only the first can be fixed quickly. Every step of the plan assumes a contract already signed, an integration already tested, and data already in the merchant’s hands. The plan must therefore be prepared before the failure.
Rerouting payment acceptance is the fastest step in the plan, provided a second contract already exists. A second acquiring or processing contract, integrated and kept live on a small share of traffic, can take over within hours. The hard part is stored cards. Tokens issued by one provider do not move to another on their own. Migrating stored cards has to be prepared with the card networks and the receiving provider, it takes weeks, and it becomes impossible once the original provider has shut off access. A merchant whose recurring payments rely on non-transferable tokens therefore loses the ability to charge its subscribers, even after restoring one-off payments.
SEPA direct debit is more portable. The reason is who owns the instruments. The creditor identifier is assigned to the creditor itself, not to its bank or provider, and mandates are signed in the creditor’s favor. Switching providers therefore keeps existing mandates in place, provided debtors are notified of the change in collection details under the scheme rules. A merchant that collects by both card and direct debit spreads its exposure across two instruments with different portability. It then diversifies its payment rail risk as much as its provider risk.
- Open a second payment acceptance contract and keep it live. Even a small share of traffic proves every day that the integration works and that the settlement account actually receives the funds.
- Export settlement data daily, outside the provider’s systems. Settlement files and details of transactions, refunds, disputes, and fees. Rebuilding a history after access is cut off depends on the cooperation of an insolvency practitioner who has other priorities.
- Document the consent chain. Direct debit mandates, mandate references, recurring payment chaining, and authentication evidence determine whether collection can resume elsewhere.
- Know the nature of any reserve being held. A security reserve withheld by the provider is money owed to the merchant, and whether it counts as safeguarded determines what happens to it. The question belongs in the contract, not in the liquidation.
- Check the provider’s country of authorization and supervisor in the public register. The EU passport moves insolvency proceedings to the home country, whose law will govern the funds.
- Quantify the balance at risk. The amount not yet paid out at any given moment depends on the negotiated payout frequency: a weekly payout exposes seven times more than a daily one.
Disputes keep coming in after the provider fails, and handling them immediately gets harder. A card dispute reaches the merchant several weeks after the purchase, when the acquiring contract is already suspended and the reserve funds are frozen with everything else. The merchant’s obligation to its customer remains intact, since it stems from sales law, not from its provider’s situation. The merchant then refunds, out of its own cash, transactions whose proceeds it never received. Those refunds come on top of the balance already tied up at the provider, and both losses hit the same cash position.
Rebuilding transaction history is the only task in the plan that can be fully prepared in advance. Bookkeeping, a value-added tax (VAT) return, a refund calculation, and a proof of claim all require transaction-level detail. That detail often exists only in the provider’s admin dashboard, and access is cut off the moment the freeze hits. A daily export of the raw files to storage the merchant controls puts that detail out of the incident’s reach. Without that copy, the merchant depends entirely on what the insolvency practitioner agrees to send, on whatever timetable the practitioner sets.
Elsewhere in the world. The same mechanism, elsewhere.
What a country provides for when an institution holding its customers’ funds stops operating
In July 2021, the UK created a special administration regime reserved for payment institutions and e-money institutions. Returning customer funds as soon as reasonably practicable becomes Objective 1, alongside engagement with the authorities and rescue or wind-down. The regulations state that the order in which the three objectives are listed carries no weight, and the administrator sequences the work as it sees fit. What the regime adds is therefore tooling rather than a hierarchy, including transfer arrangements that move funds and customers to another authorized institution. The European Economic Area has no equivalent: a failed payment institution there goes through the ordinary insolvency law of its home member state.
The Payment and Electronic Money Institution Insolvency Regulations 2021 (SI 2021/716), regulations 12 and 24, in force since July 8, 2021
In India, the Reserve Bank of India issued a direction on January 31, 2024, barring Paytm Payments Bank from accepting, after February 29, 2024, any new deposits, credit transactions, or top-ups to accounts, wallets, or FASTag toll tags. The deadline was later extended to March 15, 2024. Existing balances could still be withdrawn with no time limit. The measure targeted the business, not the funds, and that alone was enough to cut off payment acceptance for the merchants that relied on it.
Reserve Bank of India, press releases of January 31, 2024, and February 16, 2024