# PSD3 Article 3 — Applications for authorisation

Textual state: amended_substantial. 1141 words changed; 1 paragraph added

- Current text: Council final compromise text (Council document 8222/26) — not yet law.
- Compared against: COM(2023) 366 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. Member States shall require undertakings other than the undertakings referred to in Article 2(1), points (a), (b), (d), and (e), of Regulation XXX [PSR], and other than natural or legal persons benefiting from an exemption pursuant to Articles 34, 36, 37 and 38 of this Directive, that intend to provide any of the payment services referred to in Annex I, [-or electronic money services, -]to obtain authorisation from the competent authorities of the home Member Sate for the provision of those services.

## Paragraph 2

2. The authorisation referred to in [-the first subparagraph -]{+paragraph 1 +}shall only be required for those payment services that the applicant payment institutions actually intend to provide.

## Paragraph 3

3. Member States shall ensure that undertakings that apply for an authorisation as referred to in paragraph 1 provide the competent authorities of the home Member State with an application for authorisation, together with the following: (a) a programme of operations setting out in particular the type of payment services envisaged; (b) a business plan including a forecast budget calculation for the first 3 financial years which demonstrates that the applicant is able to employ the appropriate and proportionate systems, resources and procedures to operate soundly; (c) evidence that the applicant holds initial capital as provided for in Article 5; (d) for the undertakings applying to provide services as referred to in Annex I, points (1) to (5), and [-electronic money services, -]{+(8) +}a description of the measures taken for safeguarding payment service users’ funds in accordance with Article 9; (e) a description of the applicant’s governance arrangements and internal control mechanisms, including administrative, risk management and accounting procedures, and a description of the applicant’s arrangements for the use of ICT services as referred to in Articles 6 and 7 of Regulation (EU) 2022/2554, which demonstrates that those governance arrangements, internal control mechanisms and arrangements for the use of ICT services are proportionate, appropriate, sound and adequate; (f) a description of the procedure in place to monitor, handle and follow up a security incident and security related customer complaints, including [-an -]{+a description of the +}incident reporting mechanism which takes account of the notification obligations of the payment institution laid down in Chapter III of Regulation (EU) 2022/ 2554; (g) a description of the process in place to file, monitor, track and restrict access to sensitive payment data; (h) a description of business continuity arrangements including a clear identification of the critical operations, a description of the ICT business continuity plans and ICT response and recovery plans, and a description of the procedure to regularly test and review the adequacy and efficiency of such ICT business continuity and ICT response and recovery plans, as required by Article 11(6) of Regulation (EU) 2022/2554; [-(i) a description of the principles and definitions applied for the collection of statistical data on performance, transactions and fraud; -](j) a security policy document, including: (i) a detailed risk assessment in relation to the applicant’s payment [-and electronic money -]services; (ii) a description of security control and mitigation measures to adequately protect payment service users against the risks identified, including fraud and the illegal use of sensitive and personal data; [-(iii) for applicant institutions wishing to enter information sharing arrangements with other payment service providers for the exchange of payment fraud related data as referred to in Article 83(5) of Regulation XXX [PSR], the conclusions of the data protection impact assessment referred to in Article 83(5) of Regulation XXX [PSR] and pursuant to Article 35 of Regulation (EU) 2016/679 and, where applicable, the outcome of the prior consultation of the competent supervisory authority pursuant to Article 36 of that Regulation; -](k) for applicant {+payment +}institutions [-that are -]subject to the obligations in relation to money laundering and terrorist financing under [-Directive -]{+[Regulation +}(EU) [-2015/849 -]{+2024/1624 +}of the European Parliament and of the [-Council[53] -]{+Council] +}and [-Regulation -]{+[Regulation +}(EU) [-2015/847 -]{+2023/1113 +}of the European Parliament and of the [-Council[54], -]{+Council], +}a description of the internal control mechanisms which the applicant {+payment institution +}has established to comply with [-that Directive and Regulation; -]{+those Regulations; +}(l) a description of the [-applicant’s -]{+applicant payment institution’s +}structural organisation, including, where applicable, a description of: (i) the intended use of [-agents, distributors -]{+agents +}or branches; (ii) the off-site and on-site checks that the applicant undertakes to perform on those [-agents, distributors -]{+agents +}or branches at least annually; (iii) a description of outsourcing arrangements; (iv) the applicant’s participation in a national or international payment system; (m) the identity of the persons that hold in the applicant, directly or indirectly, qualifying holdings within the meaning of Article 4(1), point (36), of Regulation (EU) No 575/2013, the size of their holdings and evidence of their suitability to ensure the sound and prudent management of the applicant; (n) the identity of directors and other persons responsible for the management of the applicant payment institution and, where relevant: (i) the identity of the persons responsible for the management of the payment services activities of the payment institution; (ii) evidence that the persons responsible for the management of the payment services activities of the payment institution are of good repute and possess appropriate knowledge and experience to perform payment services as determined by the home Member State of the applicant; (o) where applicable, the identity of the statutory auditors and audit firms as defined in Article 2, points 2 and 3, of Directive 2006/43/EC of the European Parliament and of the [-Council[55]; -]{+Council21; 21 Directive 2006/43/EC of the European Parliament and of the Council of 17 May 2006 on statutory audits of annual accounts and consolidated accounts, amending Council Directives 78/660/EEC and 83/349/EEC and repealing Council Directive 84/253/EEC (OJ L 157, 9.6.2006, p. 87). +}(p) the applicant’s legal status and articles of association; (q) the address of the applicant’s registered office; (r) an overview of EU jurisdictions where the applicant {+payment institution +}is submitting or is planning to submit an application for authorisation to operate as a payment [-institution. -]{+institution, or where other entities belonging to the same group as the applicant payment institution have submitted such an application in the past three years. Where the applicant payment institution or any other entity belonging to the same group has submitted an application within the last three years, the decision of the relevant competent authority granting or refusing such authorisation, and, if applicable, the main reasons for refusal. +}(s) {+for applicants that intend to provide payment services as referred to in Annex I, points (1) to (5), or point (8), +}a winding-up plan in case of failure, which is adapted to the envisaged size and business model of the [-applicant. -]{+applicant, including the return of safeguarded funds in the event of a disorderly wind-up. +}For the purposes of the first subparagraph, points (d), (e), (f) and (l), Member States shall ensure that the applicant provides a description of its audit arrangements and of the organisational arrangements it has set up to protect the interests of its users and to ensure continuity and reliability in the performance of payment [-or electronic money -]services. The security control and mitigation measures referred to in the first subparagraph, point (j), shall indicate how the applicant will ensure a high level of digital operational resilience as required by Chapter II of Regulation (EU) 2022/2554, in particular in relation to technical security and data protection, including for the software and ICT systems used by the applicant or the undertakings to which it outsources its operations.

## New paragraph 3a

{+3a. Notwithstanding paragraph 3, Member States shall ensure that undertakings that have been authorised as crypto-asset service provider in accordance with Article 63 of Regulation (EU) 2023/1114 [MiCA] and that apply for an authorisation as referred to in paragraph 1 provide the competent authorities of the home Member State with an application for authorisation, together with the following: (a) the information and documentation required under Article 3(3), points (e), (k), (o), (p), (q) and (r), in the form in which it has been previously submitted in the licensing process pursuant to Article 62 of Regulation (EU) 2023/1114; in the event that parts of this information and documentation are no longer up-to-date, the undertaking shall provide the information and documentation in updated form indicating the documents in which changes have been made; (b) a programme of operations pursuant to Article 3(3), point (a), and a business plan and forecast budget calculation pursuant to Article 3(3), point (b), that builds on the information handed in pursuant to Article 62(2), point (d), of Regulation (EU) 2023/1114, amended by the information according to the additional provision of payment services envisaged; (c) evidence that the undertaking holds initial capital as provided for in Article 5 pursuant to Article 3(3), point (c); (d) a description of the procedure in place to monitor, handle and follow up a security incident and security related customer complaints, including a description of the incident reporting mechanism which takes account of the notification obligations of the payment institution laid down in Chapter III of Regulation (EU) 2022/2554 pursuant to Article 3(3), point (f); that description shall build on the information handed in pursuant to Article 62(2), point (i), of Regulation (EU) 2023/1114, amended by the information according to the additional provision of payment services envisaged; (e) a description of the process in place to file, monitor, track and restrict access to sensitive payment data according to Article 3(3), point (g); (f) a description of business continuity arrangements including a clear identification of the critical operations, a description of the ICT business continuity plans and ICT response and recovery plans, and a description of the procedure to regularly test and review the adequacy and efficiency of such ICT business continuity and ICT response and recovery plans, as required by Article 11(6) of Regulation (EU) 2022/2554 pursuant to Article 3(3), point (h); those descriptions shall build on the information submitted pursuant to Article 62(2), point (j), of Regulation (EU) 2023/1114, amended by the information according to the additional provision of payment services envisaged; (h) the security policy document pursuant to Article 3(3), point (j), concerning the payment services envisaged; (i) a description of the undertaking’s structural organisation according to Article 3(3), point (l), that builds on the information submitted pursuant to Article 62(2), points (d) and (f), of Regulation (EU) 2023/1114, amended by the information according to the additional provision of payment services envisaged; (j) information according to Article 3(3), points (m) and (n), that builds on the information handed in according to Article 62(2), points (g) and (h), of Regulation (EU) 2023/1114, amended by the information according to the additional provision of payment services envisaged, containing a clear statement that the information provided under Regulation (EU) 2023/1114 is still up-to-date; (k) a winding-up plan in case of failure, which is adapted to the envisaged size and business model of the undertaking, pursuant to Article 3(3), point (s); (l) if applicable to the intended payment service the information pursuant to Article 3(3), point (d), and Article 3(4).+}

## Paragraph 4

4. Member States shall require undertakings that apply for authorisation to provide payment services as referred to in Annex I, point (6), as a condition of their authorisation, to hold a professional indemnity insurance, covering the territories in which they offer services, or some other comparable [-guarantee against liability to -]{+guarantee, and that they +}ensure that: (a) they can cover their liabilities as specified in Articles 56, 57, 59, 76, and 78 of Regulation XXX [PSR]; (b) they cover the value of any excess, threshold or deductible from the insurance cover or comparable guarantee; (c) they monitor the coverage of the insurance or comparable guarantee on an ongoing basis. {+For the purpose of the first subparagraph, the professional indemnity insurance or the other comparable guarantee shall be in place at the moment when the applicant starts providing payment services.+}

## Paragraph 5

5. The EBA shall develop draft regulatory technical standards specifying: (a) the information to be provided to the competent authorities in the application for the authorisation of payment [-institutions, -]{+institutions and for the registration of account information service providers, +}including the requirements laid down in paragraph 3, points (a), (b), (c), [-(e) -]{+(e), (f) +}and (g) to [-(k) -]{+(k), (r) +}and [-(r); -]{+(s), and in paragraph 3a; (aa) the information to be provided to the competent authorities in the registration of ATM deployers, including the requirements laid down in paragraph 3, points (a), (b), (e) to (h), (j) to (l), (n), (p) and (q); +}(b) a common assessment methodology for granting authorisation [-as a -]{+of +}payment [-institution, or -]{+institutions, and for +}registration [-as an -]{+of +}account information service [-provider -]{+providers +}or ATM [-deployer, -]{+deployers, +}under this Directive; (c) what is a comparable guarantee, as referred in paragraph [-4, -]{+4 of this Article and in Article 36(4), +}first subparagraph, [-which should -]{+that could +}be [-interchangeable -]{+considered inter-changeable +}with a professional indemnity insurance; (d) the criteria on how to stipulate the minimum monetary amount of the professional indemnity insurance [-or -]{+and +}other comparable guarantee as referred in paragraph [-4. -]{+4 of this Article and Article 36(4). For the purposes of point (c), the own funds or initial capital of an undertaking referred to in paragraph 4 that are beyond the level required pursuant to this Directive or of an account information service provider referred to in Article 36(1) shall not be excluded from what a comparable guarantee is, provided that theundertaking or the account information service provider provides evidence, to the satisfaction of the relevant competent authority, that it has appropriate safeguards in place to ensure that the respective own funds or initial capital will be available at all times, including in the event of insolvency, in order to meet the liabilities referred to in paragraph 4 of this Article or Article 36(4), respectively.+}

## Paragraph 6

6. When developing those draft regulatory technical standards referred to in paragraph 5, the EBA shall take account of the following: (a) the risk profile of the undertaking; (b) whether the undertaking provides other payment services as referred to in Annex I or is engaged in other businesses; (c) the size of the activity of the undertaking; (d) the specific characteristics of comparable guarantees, as referred in paragraph 4, and the criteria for their implementation. The EBA shall submit those draft regulatory technical standards referred to in paragraph 5 to the Commission by [ OP please insert the date= 1 year after the date of entry into force of this Directive]. Power is delegated to the Commission to adopt the regulatory technical standards in accordance with Article 10 to 14 of Regulation (EU) No 1093/2010.
