Reference🇪🇺 Payments in EuropeAdvanced⏱ 21 min read

🔐 Protecting customer funds, and what happens when the institution fails

The two safeguarding methods, when the obligation arises, daily reconciliation and the annual audit, then the failure itself: loss of authorization, frozen payment flows, ranking of claims, observed repayment times, and the merchant’s failover plan

When the obligation arises, and which funds it covers

Safeguarding is the obligation on a payment institution to keep the funds it receives from its users separate from its own assets. Article 10 of Directive (EU) 2015/2366, known as PSD2, imposes it across the European Economic Area. Article 7 of Directive 2009/110/EC extends it to e-money issuers. Article 18 of PSD2 defines the status of these funds: they are neither a deposit nor e-money. The institution therefore cannot use them for its own account, and any credit it grants can never be funded with money received to execute a payment transaction. It holds the funds in custody for its users. It cannot dispose of them. Safeguarding is the counterpart of that ban on using them.

The scope of the obligation follows from Annex I of PSD2, which lists the payment services. Safeguarding applies to providers of any of services 1 through 6 in that annex. Those providers actually receive funds. Payment initiation and account information, items 7 and 8 of the same annex, are excluded, because neither service ever puts user funds in the provider’s hands. The distinction shapes how payment flows are designed. A payment pushed from the payer’s account to the merchant’s account triggers no safeguarding, because no intermediary holds the funds. That explains part of the success of bank transfer checkouts in European e-commerce.

1 to 6
payment services in Annex I subject to safeguarding; payment initiation and account information are out of scope
Directive (EU) 2015/2366, Article 10(1), and Annex I
end of the next business day (D+1)
maximum time to deposit funds still held after receipt in a separate account, or to invest them in secure assets
Directive (EU) 2015/2366, Article 10(1)(a), as amended by Regulation (EU) 2024/886
5 business days
maximum time to safeguard funds paid by payment instrument, counted from the issuance of the e-money
Directive 2009/110/EC, Article 7(1)
1,6 %
specific-risk own funds requirement above which an asset is no longer “secure and low-risk” for an e-money issuer
Directive 2009/110/EC, Article 7(2)

Article 10 sets two separate timing requirements. The first allows no delay at all: the funds must never be commingled with the funds of anyone other than the users on whose behalf they are held. The second sets a deadline. Funds still held at the end of the business day after the day they were received must be deposited in a separate account at a credit institution. Regulation (EU) 2024/886 added an option: since April 9, 2025, that account can be held at a central bank willing to provide it. The funds can also be invested in secure, liquid, low-risk assets, as defined by the authority of the home member state. Separation therefore applies from the moment of receipt, while the deposit into the protected account comes with a grace period.

CaseWhat the law saysReference
Funds received from a user to execute a payment transactionNever commingled with anyone else’s funds; if still held at the end of the business day after receipt, deposited in a separate account at a credit institution or at a central bank willing to hold it, or invested in secure, liquid assetsPSD2, Art. 10(1)(a), as amended by Regulation (EU) 2024/886
Funds received through another payment service providerSame regime: the text expressly covers funds received “through another payment service provider”PSD2, Art. 10(1)
Hybrid institution, with funds partly intended for services other than payment servicesOnly the share intended for future payment transactions is safeguarded. If that share is variable or unknown in advance, a representative portion estimated from historical data and accepted by the competent authorityPSD2, Art. 10(2)
Funds received in exchange for e-money issuedSafeguarded under the PSD2 regime; the obligation attaches to issuing the e-money, not to the customer’s orderDirective 2009/110/EC, Art. 7(1)
E-money paid for by payment instrument, especially by cardNo safeguarding required until the funds are credited to the issuer’s payment account, and in any case due no later than five business days after issuanceDirective 2009/110/EC, Art. 7(1)
Payment initiation and account informationOut of scope for safeguarding, since these providers never hold user fundsPSD2, Annex I, items 7 and 8
What triggers safeguarding, case by case. Sources: Directive (EU) 2015/2366, Articles 10 and 18 and Annex I; Directive 2009/110/EC, Article 7.

Mixed funds are amounts received of which only part is intended for future payment transactions. Article 10(2) gives them their own treatment. Only the share intended for payment transactions is subject to safeguarding. The rest stays outside the protected scope. The text allows for that share to be variable or unknown when the funds arrive. The institution then applies a representative portion, estimated from historical data and accepted by the competent authority. The regime covers hybrid institutions, from a software vendor that collects payments for its customers to an operator that bills a subscription and a money transfer service on the same invoice.

E-money has a different starting point: issuance rather than receipt of the funds. Article 7 of Directive 2009/110/EC applies the PSD2 regime to funds received in exchange for e-money issued. It adds a specific rule for funds paid by payment instrument. Those funds need not be safeguarded until they are credited to the issuer’s payment account or otherwise made available to it. The same article then sets an absolute limit of five business days after the e-money is issued.

⚠️
Issuance comes before the money arrives, and the clock starts at issuance
A card top-up creates e-money the moment the customer’s balance goes up, while the matching funds arrive from the acquirer only later. During that gap, the issuer owes money it has not yet received. Directive 2009/110/EC caps the gap at five business days from issuance, not from receipt of the funds. An issuer whose acquirer settlement cycle runs longer covers the difference from its own funds, having no other source, for as long as the lag lasts. Compliance is measured from the issuance date, so late arrival of the acquirer’s funds does not push back the deadline.
🔑
Three dates to timestamp, or nothing can be proved
Proving that the deadlines were met depends on three timestamped dates in the institution’s systems. The first is the date the funds were actually received, which starts the clock under Article 10 of PSD2. The second is the date the e-money was issued, which starts the five-business-day clock in Directive 2009/110/EC. The third is the date of deposit into the protected account. That deposit stops both clocks. A system that records only the booking date of the transaction captures none of these three dates, so it cannot show that the deadline was met.

The two methods, and why only one is used in practice

Article 10(1) of PSD2 requires one of two protection methods and favors neither. The first, under point (a), segregates the funds in a separate account or invests them in secure, liquid assets. The second, under point (b), leaves the funds in the institution’s own accounts and covers them with a third party’s promise to pay. Both aim at the same result: putting the funds beyond the reach of the institution’s creditors. But they do not have the same effect on the day the institution fails. The difference lies in what a liquidator finds: an identifiable asset in one case, a claim to pursue in the other.

Segregation places the funds in a separate account held at a credit institution or at a central bank willing to provide one. It also allows them to be invested in secure, liquid, low-risk assets. PSD2 does not define those assets; the authority of the home member state does. The e-money regime is more specific. Article 7 of Directive 2009/110/EC excludes any asset whose own funds requirement for specific risk exceeds 1.6%. It allows units in undertakings for collective investment in transferable securities (UCITS) that invest solely in such assets. The same provision lets the competent authority exclude some of those assets case by case, based on their security, maturity, or value.

The second method replaces segregation with a guarantee. An insurance policy or comparable guarantee from an insurer or credit institution outside the group covers an amount equal to what would have been segregated. It pays out when the institution becomes unable to meet its financial obligations. Two constraints limit its use. The amount covered must track an outstanding balance that changes every day, or part of customer balances goes unprotected. And the guarantor cannot belong to the same group as the protected institution, which rules out the parent company and any in-group insurance subsidiary. A single contract has to meet both requirements, and the method remains rare. European authorities do not publish how institutions split between the two methods, and no reliable count exists for the European Economic Area as a whole.

CriterionSegregation or secure assets (point a)Insurance or comparable guarantee (point b)
Where the money sitsIn a separate account at a credit institution, or, since Regulation (EU) 2024/886, at a central bank willing to hold it; or invested in secure, liquid, low-risk assets defined by the home authorityIn the institution’s own accounts; the protection is a third party’s promise to pay
Who provides the protectionThe credit institution holding the account, or the issuer of the securities heldAn insurer or credit institution not in the same group as the protected institution
Amount protectedThe balance actually deposited or invested, reconciled daily against the amounts owedAn amount equal to what would have been segregated without a guarantee
What triggers the protectionNothing: national law puts the funds beyond creditors’ reach, with no action requiredThe institution’s inability to meet its financial obligations, as defined in the contract
Main residual riskFailure of the account-holding bank, whose treatment under the deposit guarantee depends on national transpositionThe guarantor’s solvency, the time needed to call the guarantee, and the contract’s exclusions and caps
What a liquidator findsAn identifiable asset that can be isolated from the rest of the estateA claim to file and collect from the guarantor, with the delay that entails
How the two methods in Article 10(1) of Directive (EU) 2015/2366 differ

Segregation transforms the risk but does not remove it. Safeguarded funds become a claim on the bank that holds the account, so that bank’s failure hits the protected pool itself. PSD2 requires neither diversification across several banks nor a cap per bank. An issuer that places its entire outstanding balance with a single bank complies with the text, and the resulting concentration is a matter for its own continuity plan. The European Banking Authority called for the safeguarding regime to be clarified in its technical advice of June 23, 2022, on the PSD2 review. The legislative package the European Commission published on June 28, 2023, reopens the issue. A political agreement was reached on November 27, 2025, and the Council published the final texts on April 23, 2026. None of it applies yet, because the texts have not been published in the Official Journal.

⚠️
Deposit guarantees do not answer the question being asked
The safeguarding account is opened in the name of the payment institution, which is the account holder. The money in it is owed to the institution’s customers. Directive 2014/49/EU excludes deposits made by financial institutions from deposit guarantee coverage, and a payment institution falls into that category. Article 7(3) of the same directive, however, provides that coverage goes to the person actually entitled to the funds, if that person is identified or identifiable before the authority’s determination. What happens to a safeguarding account therefore depends on how the national law of the account-holding bank’s country combines these two rules. That combination is not uniform across the European Economic Area. It depends on the national transposition that applies to the holding bank, whose position should be confirmed in writing before the account is opened.

Running safeguarding day to day

The daily safeguarding check reconciles two positions taken on the same date. The obligation is strict, and compliance is assessed day by day. The first position is the internal ledger, which gives the total of balances owed to users. The second is the protected account statement, plus the value of any assets held as cover. The two amounts must match. A break usually comes from money that has left one side without yet reaching the other. A good setup is one that can tie each of those amounts to an originating date and an expected counterparty.

📒
Internal and external reconciliation
Reconcile total customer balances with the safeguarding account balance every day, explaining each amount in transit by its originating date and expected counterparty.
⚖️
Adequacy check
Verify that the protected amount is always at least equal to the total owed to users. Coverage that is adequate on a monthly average does not meet the rule, which applies day by day.
✂️
Fee extraction
Amounts earned by the institution leave the protected scope through a dated, identifiable entry tied to the transactions that generated them. A fee left in the safeguarding account commingles the institution’s money with its customers’ money.
🔑
Governance of account movements
Authority to approve movements on the safeguarding account sits within the authorized entity, not with another group company or a service provider. The Central Bank of Ireland examines this point at authorization.

The adequacy check tests an inequality between two amounts: the protected amount must be greater than or equal to the total owed to users, at every moment. A shortfall is topped up from own funds the same day, before its cause is known, because the inequality must hold at all times. A surplus also needs an explanation. It means either that the internal ledger understates what is held, or that fees earned by the institution are still sitting in the protected scope. Leaving them there is exactly the commingling that Article 10 prohibits.

  • Settlement timing differences: acquirer settlements announced but not yet credited, transfers sent late in the day, direct debits presented but not yet settled. Each one has a date that explains it, and they clear on their own.
  • Returns and disputes: a direct debit return or a card dispute debits the safeguarding account after the fact, when the customer balance has already been updated. The shortfall shows on the account side, not the ledger side.
  • Fees not extracted: amounts earned by the institution stay in the protected scope because no outgoing entry was booked. The break is positive, and it is a breach.
  • Multicurrency balances: one safeguarding account per currency, with customer balances converted at different rates, produces a revaluation difference. That is not an incident, as long as it is calculated and documented.
  • Returned payouts: an outgoing transfer rejected for a wrong IBAN comes back to the account, but the customer balance has not been re-credited. The break persists until the funds are reallocated.
  • Orphaned funds: balances of customers who have disappeared or were never verified. They are still owed and therefore still protected, however old the relationship.
Daily reconciliation at an e-money issuer (illustrative example, fictitious amounts)
Reconciliation for March 14

A  Total customer balances, internal ledger ..............  12,480,316.42
B  Safeguarding account balance (holding bank) ...........  12,402,118.07
C  Acquirer settlements of March 13, in transit ..........      91,204.55
D  Card top-ups issued March 14, not yet settled .........      33,870.00
E  Fees earned by the institution, to be extracted .......       8,412.20

Protected amount used = B + C + D - E ....................  12,518,780.42
Break = protected amount - A .............................     +38,464.00

Internal alert threshold = 0.05% of A ....................       6,240.16
=> threshold exceeded: incident opened, cause to be found before close
=> POSITIVE break: check fee extraction first (item E)
   then credits received but not posted to the ledger
⚠️
A break is not an accounting glitch
A reconciliation break is a safeguarding matter, not just an accounting question of open reconciling items. The coverage inequality must hold at all times, so the institution cannot wait for an investigation to finish before restoring it. A shortfall is therefore covered from own funds first, and its cause established afterward. Several national authorities expect to be notified when a break exceeds a threshold or recurs, and they set that threshold in their own rules. A setup that finds its breaks only at the month-end close is in breach on every day the break was open.

The annual safeguarding audit is a national requirement. EU law does not impose it; national authorities added it where they found failings. The Central Bank of Ireland wrote to the industry on January 20, 2023, requiring every institution to commission an external audit of its safeguarding. The auditor’s opinion and the board’s response were due before July 31, 2023. The UK regulator, in a neighboring market that has been outside the EU since 2020, also expects an annual audit. In September 2024, it consulted on tightening the regime as a whole.

An orderly wind-down plan is the document that sets out how funds would be returned if the institution ceased operating. It details the reports to be produced, who is authorized to act, and how long it would take to liquidate each class of assets. On April 9, 2024, the Central Bank of Ireland published a statement of expectations for the authorization of payment and e-money institutions. That document lists the wind-down plan among the items it reviews. A workable plan names the specific files, systems, and people involved, whereas a plan of intent merely states the expected outcome.

What safeguarding actually protects

Article 10 requires the funds to be insulated, under national law, from claims by the institution’s other creditors, especially in insolvency. The directive sets the result to achieve without prescribing the legal technique that must deliver it. Each member state has therefore built its own, with the tools of its civil law or common law. There is no single European rule on what happens to the funds in a liquidation. The protection exists throughout the European Economic Area, but the route by which it takes effect varies from one member state to another. That variation makes no difference while the institution is operating, and it shapes what happens to the funds the day it fails.

French law makes the funds immune from seizure. Articles L. 522-17 and L. 526-32 of the French Monetary and Financial Code provide for the funds to be deposited in a safeguarding account at a credit institution, separate from the operating accounts. Funds protected this way are beyond the reach of the institution’s other creditors, even when insolvency proceedings under Book VI of the French Commercial Code are opened against it. The protection applies without a court first having to rule on the nature of the users’ rights. It does, however, require the funds to have actually reached the protected account, which brings the issue back to meeting the deposit deadline.

UK law took more than two and a half years to settle the same question. Ipagoo LLP, an e-money institution, went into administration in August 2019 with imperfectly segregated funds. The Court of Appeal of England and Wales ruled in 2022 on the nature of e-money holders’ rights. It rejected the existence of a trust over the funds and held that they form a pool of assets applied first to e-money holders. Amounts that should have been safeguarded but were not fall into that pool. The holders therefore won on the merits, after two levels of court.

What failsEffect on safeguarded fundsWhat the user is left with
The payment institution or e-money institutionThe protected funds are insulated from the institution’s creditors by whatever technique the applicable national law usesFunds are returned from the protected pool, less the costs of the proceedings; any shortfall becomes an unsecured claim
The bank holding the safeguarding accountThe protected pool turns into a claim on a failed bankDepends on how the exclusion of financial institutions interacts with the look-through to the person entitled under Article 7(3) of Directive 2014/49/EU
The guarantor, under the insurance methodNo assets had been segregated: the protection rested entirely on the guarantor’s promiseA claim on the insurer or guarantor bank, subject to that entity’s own insolvency regime
An agent or distributor collecting funds on the institution’s behalfThe funds have not yet reached the protected account; their status depends on where and when they were receivedA question of fact before it is a question of law, decided on the records of the collection chain
The safeguarding arrangement itself, through internal misappropriationThe protected pool is already short before any proceedings are openedPro rata distribution of what remains, and an unsecured claim for the rest
Five failures, and what happens to users’ money in each

No European winding-up regime applies to payment institutions. Directive 2001/24/EC on reorganization and winding up covers only credit institutions, and a payment institution is not one. Its failure is therefore handled under the ordinary insolvency law of its home member state, by a court and an insolvency practitioner applying rules designed for an ordinary company. EU harmonization covers the authorization of the institution, not how its failure is handled. Users of an institution passported into 25 member states all fall under the proceedings opened in its home country, wherever they live. Those proceedings follow that country’s rules and run in its language.

⚠️
The costs of the proceedings have to come from somewhere
Returning the funds costs money, and that cost comes out of the failed institution’s estate. Identifying the people entitled, rebuilding balances, sending notices, reviewing claims, and making distributions is lengthy work, billed by the insolvency practitioner. When the institution’s other assets are not enough, several national regimes allow those costs to be charged to the protected pool itself, which reduces the amount returned accordingly. The applicable rule depends on the institution’s home-country law, which is known from the moment the provider is chosen. Flawless safeguarding therefore does not guarantee full repayment.

What the user ends up receiving depends on what is in the protected pool and on the costs charged to it. Distribution is pro rata, meaning in proportion to the amount owed to each person. A customer with a balance of €1,000, in a pool that is 80% funded, receives €800. That customer becomes an unsecured creditor for the rest, a claim that ranks behind preferential creditors and only rarely leads to any recovery. No deposit guarantee scheme steps in, because a balance at a payment institution is not a deposit. User protection therefore rests on safeguarding and on supervision of the institution.

🔑
The law that would insulate the funds, and where to find it
Due diligence covers the national law that would insulate the funds, the legal technique it uses, and when that point was last checked. The first follows from the institution’s country of authorization, which appears in its supervisor’s register, not on its marketing website. Three further pieces of information round out the picture. The first is the name of the bank holding the safeguarding account. The second is the protection method used, segregation or guarantee, and the third is the date of the last external audit of the arrangement. The first two determine what happens to the funds if the institution fails; the third shows when the arrangement was last verified. The institution has all three on hand before any contract is signed.

The failure, from withdrawal of authorization to repayment

Withdrawal of authorization is governed by Article 13 of PSD2, which lists the grounds, from failing to meet the conditions of authorization to posing a threat to the stability of the payment system. In practice, the sequence rarely starts with the withdrawal itself. An authority first imposes requirements or restrictions on the business, a faster and reversible measure. Payment flows stop at that very moment, before anyone knows whether there is a safeguarding shortfall. The merchant learns of the incident when its payments start failing, often the same day the press does.

The Wirecard collapse in June 2020 is a well-documented example of this sequence. On June 22, 2020, Wirecard AG acknowledged that €1.9 billion booked in trustee accounts probably did not exist, and it filed for insolvency in Munich on June 25. The next day, the UK regulator barred its subsidiary Wirecard Card Solutions, an e-money issuer, from carrying on any regulated activity. Cards issued for several programs stopped working overnight. The authority gave its written consent on June 29, and the ban was lifted at 12:01 a.m. on June 30. Other requirements remained in force.

€1.9B
amount booked in trustee accounts that Wirecard AG acknowledged probably did not exist, four days before filing for insolvency
Wirecard AG, press release of June 22, 2020; insolvency filing in Munich on June 25, 2020
4 days
length of the freeze on Wirecard Card Solutions’ regulated activities imposed by the Financial Conduct Authority, June 26 to 30, 2020
Financial Conduct Authority; requirements imposed on June 26, 2020, written consent of June 29, lifted at 12:01 a.m. on June 30, 2020
more than 2.5 years
time between Ipagoo LLP entering administration and the appeal ruling that settled the nature of e-money holders’ rights over the funds
Administration of Ipagoo LLP, August 1, 2019; Court of Appeal of England and Wales, Re Ipagoo LLP [2022] EWCA Civ 302, March 9, 2022
0
European directive governing the winding up of a payment institution; Directive 2001/24/EC covers only credit institutions
Directive 2001/24/EC, Article 1
⚠️
The freeze always comes before any shortfall is found
The UK authority announced no safeguarding shortfall at Wirecard Card Solutions, yet its cardholders lost access to their money for four days. A freeze targets the regulated business, regardless of the state of the safeguarded funds. An authority that suspects wrongdoing suspends the business first and checks afterward, because the reverse order would let funds drain away during the investigation. For a merchant, the availability of its payment service and the solvency of its provider are therefore two separate risks. A continuity plan that covers only the second leaves the business unable to take payments for as long as a precautionary measure lasts.
August 2019
Ipagoo LLP goes into administration
The e-money institution stops operating with imperfectly segregated funds, triggering litigation over the nature of e-money holders’ rights.
June 22, 2020
Wirecard AG admits €1.9 billion is missing
The money had been presented as held in trustee accounts.
June 25, 2020
Wirecard AG files for insolvency in Munich
June 26, 2020
FCA freezes Wirecard Card Solutions
The UK subsidiary is barred from all regulated activity, and cards in several programs stop working.
June 30, 2020
Ban on activity lifted
The authority’s written consent is dated June 29. Regulated activity resumes at 12:01 a.m., with other requirements still in force.
July 2021
UK special administration regime
The UK creates a procedure specific to payment and e-money institutions, in which returning customer funds becomes an objective in its own right.
March 9, 2022
Appeal ruling in the Ipagoo case
The court rejects the existence of a trust and holds that the funds form a pool of assets applied first to e-money holders.
June 23, 2022
European Banking Authority technical advice
The EBA calls for the safeguarding regime to be clarified as part of the PSD2 review.
June 28, 2023
European Commission legislative package
The proposed revisions reopen the safeguarding question.
September 2024
FCA consultation on safeguarding
The UK regulator consults on tightening the rules for payment and e-money institutions.
April 9, 2025
Amended Article 10 takes effect
Regulation (EU) 2024/886 explicitly covers e-money institutions and allows the separate account to be held at a central bank willing to provide it.
April 23, 2026
Final texts of the revision package
The Council publishes the final versions, following the political agreement of November 27, 2025. Nothing applies until publication in the Official Journal.

The administrator’s or liquidator’s work then follows a sequence of steps that cannot be compressed. They freeze the accounts, identify the protected assets, and then work out who is owed what. That reconstruction relies on the failed institution’s ledger, the very document whose reliability broke down in the most serious cases. Next comes a call for claims with a deadline, then distribution of the available funds. Every step requires identity checks and anti-money laundering controls that the proceedings do not waive.

No harmonized European model governs how customers are kept informed during the proceedings. Information comes through press releases from the authority, notices from the insolvency practitioner, and information pages updated as often as the case requires. A merchant is not necessarily a direct recipient of those notices when its contract runs through a technical intermediary. Silence then says nothing about how far the proceedings have progressed. No consolidated European statistics on repayment times are published. Documented cases take years rather than weeks, and the UK created a special procedure in 2021 precisely because ordinary insolvency law returned funds too slowly.

A merchant’s failover plan

A merchant’s failover plan is the set of arrangements that keep it taking payments when its payment provider stops operating. Its scope goes beyond the funds stuck at that provider. It covers four separate exposures: payment acceptance that stops, refunds owed to customers, disputes that keep coming in, and transaction history that can no longer be accessed. Each exposure is handled separately, and only the first can be fixed quickly. Every step of the plan assumes a contract already signed, an integration already tested, and data already in the merchant’s hands. The plan must therefore be prepared before the failure.

The first 72 hours for a merchant whose provider has been frozen
Merchant
Establishes what has stopped and what still works
Authorizations, settlement batches, refunds, payouts, and outgoing transfers do not always stop at the same time. The picture comes from the technical logs, not from announcements.
Merchant
Switches payment acceptance to the backup contract
A second acquirer or provider that is already integrated and tested can be reactivated within hours. A contract that is merely signed needs weeks of certification and MID setup.
Merchant
Freezes the promises it can no longer keep
Automatic refunds, installment payments, and shipments paid for but not yet settled are suspended until the available cash is known.
Merchant
Informs its customers and partners
Factual information that the payment method is unavailable reduces disputes, which cost more than customer service calls.
Merchant
Secures its transaction history and files its claim
Settlement files and transaction tables are exported while access lasts, then a claim is filed with the insolvency practitioner in the form and within the deadlines set by the proceedings.

Rerouting payment acceptance is the fastest step in the plan, provided a second contract already exists. A second acquiring or processing contract, integrated and kept live on a small share of traffic, can take over within hours. The hard part is stored cards. Tokens issued by one provider do not move to another on their own. Migrating stored cards has to be prepared with the card networks and the receiving provider, it takes weeks, and it becomes impossible once the original provider has shut off access. A merchant whose recurring payments rely on non-transferable tokens therefore loses the ability to charge its subscribers, even after restoring one-off payments.

SEPA direct debit is more portable. The reason is who owns the instruments. The creditor identifier is assigned to the creditor itself, not to its bank or provider, and mandates are signed in the creditor’s favor. Switching providers therefore keeps existing mandates in place, provided debtors are notified of the change in collection details under the scheme rules. A merchant that collects by both card and direct debit spreads its exposure across two instruments with different portability. It then diversifies its payment rail risk as much as its provider risk.

  • Open a second payment acceptance contract and keep it live. Even a small share of traffic proves every day that the integration works and that the settlement account actually receives the funds.
  • Export settlement data daily, outside the provider’s systems. Settlement files and details of transactions, refunds, disputes, and fees. Rebuilding a history after access is cut off depends on the cooperation of an insolvency practitioner who has other priorities.
  • Document the consent chain. Direct debit mandates, mandate references, recurring payment chaining, and authentication evidence determine whether collection can resume elsewhere.
  • Know the nature of any reserve being held. A security reserve withheld by the provider is money owed to the merchant, and whether it counts as safeguarded determines what happens to it. The question belongs in the contract, not in the liquidation.
  • Check the provider’s country of authorization and supervisor in the public register. The EU passport moves insolvency proceedings to the home country, whose law will govern the funds.
  • Quantify the balance at risk. The amount not yet paid out at any given moment depends on the negotiated payout frequency: a weekly payout exposes seven times more than a daily one.

Disputes keep coming in after the provider fails, and handling them immediately gets harder. A card dispute reaches the merchant several weeks after the purchase, when the acquiring contract is already suspended and the reserve funds are frozen with everything else. The merchant’s obligation to its customer remains intact, since it stems from sales law, not from its provider’s situation. The merchant then refunds, out of its own cash, transactions whose proceeds it never received. Those refunds come on top of the balance already tied up at the provider, and both losses hit the same cash position.

Rebuilding transaction history is the only task in the plan that can be fully prepared in advance. Bookkeeping, a value-added tax (VAT) return, a refund calculation, and a proof of claim all require transaction-level detail. That detail often exists only in the provider’s admin dashboard, and access is cut off the moment the freeze hits. A daily export of the raw files to storage the merchant controls puts that detail out of the incident’s reach. Without that copy, the merchant depends entirely on what the insolvency practitioner agrees to send, on whatever timetable the practitioner sets.

✅
What to check before signing, not after
Six points can be checked before the contract is signed. The first is the provider’s country of authorization, which determines the law that applies to the funds; the second is its exact status in its supervisor’s register. The third combines the safeguarding method used, the name of the bank holding the account, and the date of the last external audit. The fourth is the payout frequency, which mechanically sets the balance at risk at any given moment. The fifth is the portability of stored cards and direct debit mandates, as written into the contract. The sixth is the availability of a complete daily export that can be retrieved without going through an admin dashboard. None of these six points can be established once payment flows are frozen.

Elsewhere in the world. The same mechanism, elsewhere.

What a country provides for when an institution holding its customers’ funds stops operating

In July 2021, the UK created a special administration regime reserved for payment institutions and e-money institutions. Returning customer funds as soon as reasonably practicable becomes Objective 1, alongside engagement with the authorities and rescue or wind-down. The regulations state that the order in which the three objectives are listed carries no weight, and the administrator sequences the work as it sees fit. What the regime adds is therefore tooling rather than a hierarchy, including transfer arrangements that move funds and customers to another authorized institution. The European Economic Area has no equivalent: a failed payment institution there goes through the ordinary insolvency law of its home member state.

The Payment and Electronic Money Institution Insolvency Regulations 2021 (SI 2021/716), regulations 12 and 24, in force since July 8, 2021

India

In India, the Reserve Bank of India issued a direction on January 31, 2024, barring Paytm Payments Bank from accepting, after February 29, 2024, any new deposits, credit transactions, or top-ups to accounts, wallets, or FASTag toll tags. The deadline was later extended to March 15, 2024. Existing balances could still be withdrawn with no time limit. The measure targeted the business, not the funds, and that alone was enough to cut off payment acceptance for the merchants that relied on it.

Reserve Bank of India, press releases of January 31, 2024, and February 16, 2024