Safeguarding Accounts for Payment Institutions and EMIs in the EU
At a glance
1. EU payment institutions providing services in PSD2 Annex I points 1–6 must safeguard funds received from users or another payment service provider for executing payment transactions. Electronic money institutions must also safeguard funds received in exchange for issued e-money. [1, 2]
2. The main statutory routes are segregation of funds or an insurance policy or comparable guarantee. A policy saying “client funds are protected” is insufficient without an account structure, calculation method, reconciliation process and insolvency analysis. [1, 3]
3. Under the segregation route, relevant PI funds still held at the end of the business day following receipt must be placed in a separate account at a credit institution or central bank, subject to the central bank's discretion, or invested in secure, liquid, low-risk assets. E-money has a separate timing rule for funds received through a payment instrument. [1, 2]
4. A safeguarding account should be clearly designated and kept separate from the institution's own money. Its operating mandate, ledger logic and access controls should match the fund-flow diagrams submitted to the bank and regulator. [1, 3, 4]
5. PSD2 gives payment institutions a right to request access to credit-institution account services on an objective, non-discriminatory and proportionate basis. It does not guarantee that every bank will accept every model. The bank still assesses the institution, flows, customers, countries and controls. [1]
A safeguarding account sits at the centre of many payment institution and electronic money institution applications. It is also one of the arrangements most likely to expose a weak operating model. A regulator may read a polished safeguarding policy, while the proposed bank, processor and internal ledger each describe a different path for customer money.
This guide explains how to turn the legal requirement into an account structure and evidence package. It covers the EU framework under PSD2 and EMD2. National insolvency law, account documentation and supervisory expectations still need to be checked in the chosen home member state. [1, 2, 3]
1. Identify which funds must be safeguarded
The first task is to classify every balance in the product. For a payment institution providing services in Annex I points 1–6, Article 10 applies to funds received from payment service users or through another payment service provider for executing payment transactions. An EMI must safeguard funds received in exchange for e-money that it has issued. [1, 2]
This classification should follow the legal role and actual money flow. Product labels such as “wallet”, “settlement balance” and “merchant reserve” do not determine the answer by themselves.
| Balance or flow | Starting treatment | Question to document |
|---|---|---|
| Funds received to execute a payment service in Annex I points 1–6 | Within the PI safeguarding perimeter. | When does the institution receive or control the funds, and when are they paid to the payee or another provider? |
| Funds received in exchange for issued e-money | Within the EMI safeguarding perimeter. | When is e-money issued, what amount is outstanding, and how is redemption funded? |
| Application, subscription or transaction fee already earned by the institution | Potentially outside the safeguarded amount once validly due to the institution. | Does the customer contract and ledger clearly separate the fee from money held for payment or redemption? |
| Regulatory capital and operating cash | Own funds, held outside the client-funds pool. | Can the institution show that expenses are paid without drawing on safeguarded balances? |
| Funds in transit through a processor, acquirer or settlement partner | Requires a flow-specific analysis. | Which entity holds the funds at each stage, and does the institution's safeguarding obligation continue? |
| Payment initiation or account information service with no receipt of user funds | Article 10 safeguarding may not arise for that service. | Can the technical and contractual model demonstrate that the provider never possesses the funds? |
The last row matters for firms that provide only payment initiation or account information services. Irish supervisory guidance gives these as examples of models where the applicant does not receive user funds. A mixed business may still have safeguarded funds from its other services. [4]
Create a balance taxonomy before drafting the policy. Each ledger account should map to a legal category, a bank or partner account, an owner and a reconciliation rule. Unclassified suspense balances are a warning sign because their safeguarding status cannot be tested reliably.
2. Choose between segregation and insurance or a guarantee
PSD2 Article 10 provides two safeguarding methods. Under the segregation route, relevant funds must not be commingled with the institution's own money. If they remain held at the end of the business day following receipt, the funds must be placed in a separate account at a credit institution or central bank, at the central bank's discretion, or invested in secure, liquid, low-risk assets as determined by the competent authority. National law must protect them from claims by other creditors, particularly in insolvency. [1]
The alternative is an insurance policy or comparable guarantee from an insurance company or credit institution outside the same group. The cover must be for an amount equivalent to what would otherwise have been segregated and payable if the institution cannot meet its financial obligations. [1]
| Method | Core legal features | Practical evidence |
|---|---|---|
| Separate-account segregation | No commingling with own funds; timely transfer to a separate account; protection from other creditors under applicable law. | Bank term sheet or draft agreement, account designation, mandate, flow diagram, daily calculation, reconciliation and insolvency opinion where required. |
| Permitted low-risk assets | Secure, liquid, low-risk assets identified under the applicable supervisory framework. | Investment policy, eligibility criteria, valuation, liquidity limits, custody arrangement and process for covering shortfalls. |
| Insurance or comparable guarantee | Provider outside the group; cover equivalent to the amount otherwise safeguarded; proceeds payable when the institution cannot meet its obligations. | Policy or guarantee wording, calculation of cover, exclusions, renewal controls, claims process and destination account for proceeds. |
The insurance route can reduce reliance on a dedicated account, but it does not remove operational work. The institution still needs to calculate the protected amount, monitor whether cover remains sufficient, manage renewal risk and show that exclusions do not defeat the protection. Irish guidance also expects policy proceeds to be paid into a separate account if the institution cannot meet its obligations. [4]
Many applicants use segregation because it is easier to explain to customers, auditors and supervisors. Availability depends on the proposed business and banking market. Choose the route after testing real provider terms.
3. Design the safeguarding account around the money flow
A safeguarding account is not a general operating account. The bank documentation and internal controls should identify its protected purpose. The institution should avoid paying payroll, vendors, taxes or shareholder distributions from the same account. Own money used for fees, capital and expenses needs a separate path.
A typical architecture may include:
- an operating account for the institution's own funds and expenses;
- one or more safeguarding accounts for protected customer money;
- settlement accounts used with payment systems, correspondents, acquirers or processors;
- scheme collateral or reserve accounts where the business model requires them; and
- ledger accounts that identify the safeguarded liability for every customer and currency.
The names and number of accounts depend on the model. The important control is traceability. A transaction diagram should show the legal entity, account holder, bank, currency, expected timing and balance ownership at each stage. It should also cover refunds, reversals, chargebacks, failed transfers, weekends and partner outages.
The account mandate needs the same level of care. Specify who may view balances, initiate transfers, approve payments and change beneficiaries. Apply dual approval and role separation where appropriate. Bank portal access should be included in joiner, mover and leaver controls, with periodic access reviews.
Clear designation also supports insolvency protection. The Central Bank of Ireland states that the designation should sufficiently distinguish safeguarded funds from the applicant's own funds. Exact wording and legal effect depend on the account agreement and national law. [4]
4. Calculate the safeguarded amount and reconcile it every day
The safeguarding calculation compares the amount that should be protected with the assets actually available for that purpose. The method should be repeatable from source systems and produce evidence that finance, compliance, internal audit and the supervisor can review.
A daily process normally needs to address:
- the opening safeguarded liability by customer and currency;
- money received, issued, redeemed, executed, refunded or returned during the day;
- funds held by processors or settlement partners and their legal treatment;
- cut-off times, weekends and the statutory transfer deadline;
- fees that have become due to the institution;
- foreign-exchange conversion and valuation rules;
- chargebacks, reserves, suspense items and negative customer balances; and
- the safeguarded account balance and any eligible protected assets or cover.
Assign a named owner, reviewer and escalation route. A shortfall should trigger immediate investigation, correction and management reporting. An excess may provide a prudent operational buffer, but the policy should explain whose money it is and how it is treated. Long-running differences should never be hidden inside a general suspense account.
The legal timing rules also need to be coded into the process. PSD2 applies the end-of-following-business-day test to relevant PI funds that are still held. Under EMD2, money received by an EMI through a payment instrument need not be safeguarded until credited to the EMI's payment account or otherwise made available, and in any event no later than five business days after e-money is issued. The two rules address different flows and should not be combined into one generic deadline. [1, 2]
5. Prepare the bank's safeguarding-account file
The bank needs enough information to decide whether it can understand, monitor and support the account. A licence application may describe the regulatory theory, while bank due diligence focuses on actual customers, corridors, products, transaction sizes, currencies, counterparties and controls.
| Banking workstream | Evidence to prepare |
|---|---|
| Legal and regulatory status | Corporate structure, owners, management, application status, requested permissions and expected authorisation sequence. |
| Product and customers | Customer journeys, target segments, prohibited activity, countries, currencies, average and maximum transaction values. |
| Money flow | Account-level diagrams covering funding, execution, settlement, refunds, chargebacks, redemption and failed payments. |
| Financial-crime controls | Customer risk assessment, onboarding, sanctions screening, transaction monitoring, escalation and suspicious-activity reporting. |
| Safeguarding controls | Scope methodology, transfer timetable, reconciliation, shortfall response, account access and management reporting. |
| Partner network | Processors, schemes, correspondents, acquirers, custodians and outsourced technology providers, with contract status. |
| Forecasts | Monthly payment volumes, peak safeguarded balance, currency mix and plausible growth cases. |
PSD2 Article 36 requires member states to ensure that payment institutions have access to credit institutions' payment-account services on an objective, non-discriminatory and proportionate basis. A rejecting bank must provide duly motivated reasons to its competent authority. The rule supports fair access; it does not remove the bank's financial-crime, risk and commercial assessment. [1]
Start bank discussions while the product and application are still adjustable. A bank may identify unsupported geographies, nested payment activity, processor dependencies or reconciliation limits that require changes to the operating model. Our guide on why crypto and payment businesses get rejected by banks covers the broader onboarding file.
6. Put concrete safeguarding evidence into the licence application
PSD2 Article 5 requires the application to describe safeguarding measures. The EBA authorisation guidelines then turn that requirement into operational information. Depending on the method and national process, the authority may expect the account arrangement, access responsibilities, reconciliation process, draft bank agreement and confirmation that the setup complies with Article 10. [1, 3]
| Application item | What it should prove |
|---|---|
| Safeguarding policy | The legal scope, chosen method, timing rules, responsible functions, monitoring and escalation. |
| Fund-flow diagrams | Where money enters, who controls it, when the safeguarding obligation arises and how funds leave. |
| Account evidence | The proposed provider, account purpose, designation, currencies, mandate and contractual status. |
| Safeguarding calculation | The data sources, formula, cut-off, treatment of exceptions and comparison with protected assets. |
| Reconciliation procedure | Frequency, preparer, reviewer, evidence retention, investigation and shortfall correction. |
| Insolvency protection | How applicable law and the account arrangement protect customer funds from other creditors. |
| Insurance or guarantee evidence | Provider independence, covered amount, exclusions, claims trigger, renewal and payment destination. |
| Wind-down plan | How protected funds are identified, returned or transferred if the institution stops operating. |
Every document should describe the same live arrangement. If the policy says reconciliation is daily, the systems and staffing plan must support daily reconciliation. If the flow diagram uses a direct bank connection, the outsourcing register should not describe the processor as the holder of all customer money.
Applicants planning a PI licence can use our EU payment institution licence guide for the wider capital, governance and application sequence. The EU EMI licence guide covers issuance, redemption and the EUR 350,000 initial-capital floor.
7. Avoid the safeguarding gaps that delay applications
Most weaknesses come from a mismatch between documents and the proposed product. Common examples include:
- treating the entire bank balance as safeguarded without calculating the underlying liability;
- using one account for customer funds and the institution's ordinary expenses;
- leaving processor, acquirer or scheme balances outside the fund-flow analysis;
- describing daily reconciliation without defined source data, cut-off time, reviewer or exception process;
- assuming the bank will agree to safeguarding wording after authorisation;
- using an account title that does not identify the protected purpose;
- depending on one provider without a response plan for restriction, closure or outage;
- setting insurance cover once and failing to monitor growth in the protected amount; and
- letting the safeguarding policy, customer terms and bank contract assign different responsibilities.
A useful review follows one customer transaction through onboarding, receipt, safeguarding, execution, settlement, reconciliation, refund and wind-down. Each step should identify the accountable entity, system record, bank account and control owner.
Safeguarding-account readiness checklist
- Classify every customer, settlement, fee, reserve and suspense balance.
- Select segregation, eligible assets, insurance or a permitted combination based on real provider terms.
- Draw account-level flows for normal transactions and exceptions.
- Confirm the transfer deadline and reconciliation cut-off for each service and currency.
- Document account designation, access rights, approvals and change controls.
- Test the calculation with peak volumes, weekends, reversals and partner delays.
- Align the policy, bank contract, customer terms, ledger and licence application.
- Prepare a wind-down process that can identify and return protected funds.
Frequently asked questions
What is a safeguarding account?
It is an account used to hold funds protected under the payment-services or e-money safeguarding rules. Under the segregation route, the account is separate from the institution's own money and structured so that protected funds are insulated from claims by other creditors under applicable law. [1, 2]
Can an EMI or payment institution use its operating account for customer funds?
The segregation method requires relevant customer funds to remain separate from the institution's own funds. Using one account for protected money and ordinary company expenses creates commingling and reconciliation problems. The precise account architecture should be agreed with the bank and competent authority. [1]
When must funds be moved to the safeguarding account?
For relevant PI funds still held, PSD2 uses the end of the business day following receipt. EMD2 includes a specific rule for funds received through a payment instrument: safeguarding starts when the money is credited or otherwise made available to the EMI, and no later than five business days after e-money issuance. Apply the rule to the actual flow. [1, 2]
Can insurance replace a safeguarding account?
PSD2 allows an insurance policy or comparable guarantee from an eligible provider outside the same group. It must cover an equivalent amount and be payable if the institution cannot meet its obligations. Provider terms, exclusions and supervisory acceptance need to be settled before relying on this route. [1, 4]
Does Article 36 force a bank to open the account?
Article 36 requires access to credit-institution payment-account services on an objective, non-discriminatory and proportionate basis. It also requires reasons for rejection to be provided to the competent authority. It does not guarantee acceptance of every applicant or business model. [1]
Can safeguarded funds be held at a central bank?
PSD2 now refers to a separate account at a credit institution or a central bank, at the central bank's discretion. Availability should be checked directly. The Eurosystem has stated that its central banks do not offer standalone safeguarding accounts, so the provision should not be treated as a generally available substitute for a commercial banking arrangement. [1, 5]
Can the safeguarding account be outside the EU?
Do not assume that a foreign account will be accepted. The legal wording, national implementation, insolvency protection and the home authority's expectations must all be checked for the proposed provider and jurisdiction.
Related DM Strategy guides
- How to Get a Payment Institution Licence in the EU, covering capital, safeguarding, application evidence and timeline.
- How to Get an EMI Licence in the EU, covering e-money issuance, own funds, redemption and passporting.
- Why Crypto and Payment Businesses Get Rejected by Banks, covering bank due diligence and operating-model gaps.
- EMI vs CASP, distinguishing payment and crypto-service permissions.
Key primary sources
| Ref | Primary source |
|---|---|
| 1 | PSD2, consolidated Directive (EU) 2015/2366, especially Articles 5, 10, 36 and Annex I. |
| 2 | Electronic Money Directive 2009/110/EC, especially Article 7. |
| 3 | EBA Guidelines on authorisation and registration under PSD2. |
| 4 | Central Bank of Ireland PSD2 and E-Money authorisation guidance note, safeguarding section. |
| 5 | ECB Decision (EU) 2025/222, including the treatment of standalone safeguarding accounts in the Eurosystem. |
Disclaimer
This article is for information only and is not legal or regulatory advice. Safeguarding scope, insolvency protection, account documentation and supervisory expectations depend on the services, money flow and home member state. Check current EU and national requirements before implementing the arrangement.
DM Strategy helps founders map payment flows, safeguarding, banking and application evidence for regulated payment businesses. If you are preparing a PI or EMI application, contact DM Strategy before committing to the account structure or provider contracts.

.jpg)