Payments  ·  PSD2  ·  PSD3  ·  PSR  ·  Open Banking
Regulatory status reviewed · 8 August 2026

PSD2 Compliance & PSD3 / PSR Transition Readiness

PSD2 compliance and PSD3 / Payment Services Regulation transition support for payment institutions, EMIs, banks, AISPs, PISPs and fintechs — covering safeguarding, strong customer authentication, fraud, conduct, open banking and regulatory remediation.

The scope is compliance, regulatory change and remediation after or alongside authorisation. A business seeking a new Payment Institution or Electronic Money Institution licence should use the separate PSP / EMI Licensing service →.

PSD2
Current framework
still applicable
PSD3
Authorisation, governance
& supervision
PSR
Directly applicable
conduct rules
Transition
Impact mapping,
remediation & readiness
Payments and financial analysis
Pexels · free-use editorial visual
Official regulatory referencesPSD2 — Directive (EU) 2015/2366PSD3 / PSR legislative status
Current and incoming framework

Three Names, Two Regulatory Stages.

PSD2 is the framework that applies today. PSD3 and the Payment Services Regulation form the incoming replacement package. They are related, but they perform different legal functions and should be mapped separately in a transition programme.

Currently applicable
PSD2
Directive (EU) 2015/2366 remains the current EU payment-services framework. It covers payment-service authorisation, conduct, open banking, Strong Customer Authentication, customer rights and supervision, together with related national implementation rules.
Incoming directive
PSD3
The incoming directive is designed to update authorisation, governance, supervision and institutional requirements for payment and electronic-money services. As a directive, it will require national implementation.
Incoming regulation
Payment Services Regulation
The PSR is intended to establish directly applicable rules on payment-service conduct, transparency, user rights, fraud prevention, open banking and related operational obligations, reducing divergence across Member States.
Legislative status checked 7 August 2026. The European Parliament and Council reached provisional political agreement on 27 November 2025. ECON approved the negotiated early-second-reading text on 5 May 2026. The European Parliament Legislative Train, updated 20 June 2026, still classified both files as “close to adoption”; PSD2 therefore remains the current framework pending formal adoption, publication and the applicable transition timetable.
Regulatory workstreams

Current Compliance, Transition Planning and Remediation.

The work is organised around the regulatory outcome the business needs, rather than around isolated provisions of the payments framework.

01 · Current-state review

PSD2 Compliance Review

Structured assessment of an existing payment or e-money business against the PSD2 obligations and authorisation conditions that apply today.

  • Permission scope and actual payment flows
  • Governance and compliance monitoring
  • Safeguarding, segregation and reconciliation
  • SCA implementation and exemption governance
  • Open-banking and TPP obligations
  • Customer information, complaints and conduct
  • Outsourcing and operational-control governance
  • AML/CFT and DORA interfaces at framework level
Typical outcome: findings report, gap register and prioritised remediation roadmap.
Discuss a PSD2 Compliance Review →
02 · Regulatory change

PSD3 / PSR Impact & Readiness Assessment

Forward-looking analysis of how the negotiated PSD3 / PSR package affects the operating model, controls, customer journey, contracts and implementation programme.

  • Applicability and legal-impact mapping
  • Authorisation and supervisory implications
  • Safeguarding and prudential changes
  • Fraud, liability and reimbursement impacts
  • Open-banking, consent and interface changes
  • SCA, information and transparency changes
  • Policy, contract, technology and data dependencies
  • Implementation ownership and sequencing
Typical outcome: impact matrix, transition roadmap, responsibility plan and change tracker.
Plan PSD3 / PSR Readiness →
03 · Corrective action

Payments Compliance Framework & Remediation

Development or remediation of governance, controls, policies, methodologies, registers and evidence required to close findings or prepare for regulatory change.

  • Payments governance and compliance monitoring
  • Safeguarding and reconciliation methodology
  • SCA and exemptions governance
  • Payment-fraud and incident procedures
  • Open-banking and TPP procedures
  • Outsourcing and third-party governance
  • Customer disclosures, complaints and registers
  • Implementation and evidence plan
Typical outcome: agreed framework documents, control inventory, remediation actions and evidence requirements.
Discuss Remediation Support →
04 · Ongoing support

Ongoing Payments Regulatory Support

Senior regulatory support for payment businesses that need continued help interpreting change, reviewing controls and managing compliance work without adding a full-time specialist role.

  • Regulatory-change interpretation
  • Policy and procedure review
  • Compliance questions and implementation decisions
  • Supervisory-readiness support
  • Material change and new-product review
  • Board and management compliance inputs
  • Coordination with specialist legal or technical partners where required
Engagement: retainer or defined ad hoc scope.
Discuss Ongoing Support →
Payments compliance scope

Key Areas We Can Review.

Scope is selected according to the payment services performed, the existing permission set, the customer journey and the regulatory decision the client needs to make.

01
Payment Services & Flow Mapping
How funds move, which entity performs each payment function, whether the operating model remains within existing permissions and where another regulated activity or partner dependency may arise.
02
Safeguarding & Reconciliation
Safeguarding approach, account structures, segregation, reconciliation methodology, escalation, governance and the evidence supporting the control framework.
03
SCA & Authentication Governance
Strong Customer Authentication, exemptions, customer journeys, control ownership and evidence. Technical implementation can be separately coordinated with specialist providers where required.
04
Fraud Prevention & Liability
Payment-fraud controls, escalation, customer handling, reimbursement and liability implications, including relevant PSD3 / PSR transition impacts.
05
Open Banking & TPPs
AISP/PISP interfaces, access rights, consent and permission governance, API-related regulatory requirements, prohibited obstacles and customer-facing transparency.
06
Customer Rights & Conduct
Information requirements, payment execution, charges, complaints, error handling, transparency and other conduct obligations applicable to the service model.
07
Outsourcing & DORA Interfaces
Material outsourcing, ICT and third-party dependencies where they affect the payments compliance question. A full DORA review remains a separate scope.
08
EMI, EMT & Crypto Intersections
Separation of payment-service and e-money functions from MiCA/CASP activity where the model combines fiat, e-money tokens or other crypto-assets.
Who we support

Payments Businesses Managing Current Obligations and Regulatory Change.

Payment Institutions
Existing PIs reviewing PSD2 controls, safeguarding, SCA, open banking, governance or the future impact of PSD3 / PSR.
Electronic Money Institutions
EMIs managing e-money and payment-service compliance, safeguarding, distribution models and transition implications.
Banks & ASPSPs
Institutions assessing payment-service conduct, open-banking access, TPP interaction, fraud controls and customer obligations.
AISPs & PISPs
Open-banking providers reviewing permissions, access, consent, SCA interfaces and changes to the future framework.
FinTech & Embedded Finance
Businesses using licensed payment partners or building payment functionality that need clarity on roles, flows, contracts and regulatory dependencies.
Crypto & Digital-Asset Businesses
CASPs or digital-asset businesses whose fiat or EMT flows may intersect with payment-services or e-money regulation.
How we work

A Defined Regulatory Question and Written Outcome.

The engagement is scoped around the business model, permissions, payment flows and the decision that management needs to make.

01 · Scope
Define services, markets, permissions, payment flows and the regulatory question.
02 · Review
Review policies, procedures, customer journeys, system descriptions, registers and available evidence.
03 · Analysis
Assess the current PSD2 position or map expected PSD3 / PSR impacts against the operating model.
04 · Outcome
Deliver the agreed report, matrix, roadmap or framework documents with clear priorities and ownership.
Why LEX ARTA

Payments Regulation Interpreted Through the Operating Model.

Payments questions are assessed against the actual flow of funds, regulated roles, safeguarding model, customer journey and outsourcing structure — while keeping current PSD2 obligations distinct from the PSD3/PSR transition.

Current + future framework
PSD2 compliance is kept legally distinct from PSD3/PSR readiness so present obligations and future changes are not mixed.
Operating-model analysis
Regulatory conclusions are tied to payment flows, account roles, customer interfaces, agents, outsourcing and safeguarding arrangements.
Senior-led work
Material perimeter, compliance and remediation decisions remain under senior legal and compliance oversight.
Connected regulation
Where the model intersects with e-money, MiCA, AML/CFT, DORA or data protection, those dependencies are identified rather than analysed in isolation.
Selected credentials and practitioner background. ACAMS Certified · CySEC AML Certified · ACFE Member · PhD in Law · practitioner experience across AML/CFT, compliance, investigations and regulatory work. Artlex Consult s.r.o. is a regulatory and compliance advisory company; reserved local-law or other licensed professional work is handled by appropriately qualified practitioners where required.
Common questions

PSD2 / PSD3 / PSR — Frequently Asked Questions.

Does PSD2 still apply?
+
Yes. PSD2 remains the current framework until PSD3 and the PSR are formally adopted, enter into force and become applicable through the relevant transition arrangements.
Why are both PSD3 and the PSR needed?
+
PSD3 deals primarily with matters operating through a directive, including authorisation, governance and supervision. The PSR is intended to contain directly applicable conduct, transparency, user-rights, fraud-prevention and open-banking rules.
Should businesses wait for the final application date?
+
A readiness assessment can identify policy, contract, technology, data and governance dependencies that may require implementation time, while current PSD2 compliance remains mandatory.
Does PSD3 / PSR readiness include a full DORA review?
+
No. The payments assessment can identify material DORA and outsourcing interfaces. A full DORA review is provided under a separately agreed DORA Compliance scope.
Is PI / EMI licence preparation included?
+
No. New authorisation and application preparation are handled through the separate PSP / EMI Licensing service. This page addresses current compliance, transition readiness and remediation.
Legal & Regulatory Services

Explore Legal & Regulatory Services.

01
Financial Services Regulatory Advisory →
02 · Current
PSD2 / PSD3 / PSR Compliance
03
DORA Compliance →
04
AI Act Compliance →
Related: PSP & EMI Licensing  ·  Regulatory Gap Analysis  ·  Financial Services Regulatory Advisory
Need a PSD2 review or PSD3 / PSR transition plan?
We define the regulatory question, information required and written outcome before the engagement begins — from current-state compliance and remediation to transition impact mapping. We respond within 1 business day.