PSD3 Preparedness and Reauthorisation

Navigate the transition to PSD3 with a structured approach to gap assessment, implementation and regulatory readiness.

PSD3 preparedness support for payment institutions in Malta.

MFSA sets out minimum expectations for PSD3 preparedness: what should Payment Institutions and Electronic Money Institutions be doing now?

The road to PSD3 reauthorisation starts now

On 8 June 2026, the Malta Financial Services Authority (MFSA) issued a Dear CEO Letter setting out its minimum expectations for the preparedness of authorised Payment Institutions (PIs) and Electronic Money Institutions (EMIs) for the forthcoming implementation of the Third Payment Services Directive (PSD3).

The MFSA's message is clear: authorised institutions should not wait for the final regulatory framework before beginning their preparations.

PSD3, together with the new Payment Services Regulation (PSR), represents a significant development of the existing payment services framework within Europe. While the PSR will primarily address conduct of business requirements, PSD3 will focus on the authorisation and supervision of PIs. One of the key changes is the consolidation of the current PSD2 and Electronic Money Directive 2 (EMD2) frameworks into a single authorisation regime. Under the new framework, institutions currently authorised as EMIs will transition into the Payment Institution regime, with electronic money issuance becoming a regulated payment service.

The MFSA has also highlighted the importance of timing. Existing PIs and EMIs will be required to undergo a reauthorisation process, with the necessary reauthorisation to be obtained within 27 months following the publication of PSD3 in the Official Journal of the European Union. The European Banking Authority (EBA) is expected to develop Regulatory Technical Standards on authorisation and registration within 12 months of publication, meaning that institutions will have a relatively limited period in which to finalise their preparations.


What does the MFSA expect from authorised institutions?

The MFSA has identified five areas where institutions are expected to start preparing for the forthcoming requirements.

1. Safeguarding of customer funds

Safeguarding is an area where PSD3 introduces a number of important changes.

Among other matters, the proposed framework addresses the point up to which remain subject to safeguarding requirements, the amount that must be safeguarded and the information that must be provided to payment service users regarding the safeguarding arrangements.

The MFSA also highlights concentration risk. Where funds are safeguarded through deposits with credit institutions, institutions will need to consider whether excessive reliance on a single institution creates concentration risk and ensure that such risk is appropriately identified, monitored and managed.

Importantly, customers will also need to receive clear information regarding how their funds are safeguarded, the insolvency law applicable to those funds and where a claim would need to be raised in the event of the institution’s insolvency. This will have implications not only for internal safeguarding arrangements, but also for contractual documentation and customer disclosures.

For institutions with complex payment flows, card-acquiring arrangements or multiple intermediaries, this is likely to be an area requiring particularly careful review.


2. Governance and internal controls

PSD3 will place increased emphasis on the governance arrangements supporting payment services.

The MFSA highlights the need for clear organisational structures, defined responsibilities, effective risk management procedures and adequate internal controls, administration and accounting procedures.

A particularly important development is the explicit integration of ICT arrangements with the requirements of the Digital Operational Resilience Act (DORA). Institutions will therefore need to consider PSD3 and DORA together rather than treating them as separate regulatory workstreams.

For boards and senior management, this means that PSD3 preparedness should extend beyond reviewing policies. Institutions should be able to demonstrate that governance arrangements, responsibilities and controls operate effectively in practice.


3. Security incidents and incident reporting

PSD3 also updates the requirements relating to security incidents and incident reporting.

Institutions will need appropriate procedures for monitoring, handling and following up on security incidents and security-related customer complaints, while their incident reporting mechanisms will need to take account of the notification requirements under DORA.

This creates an important intersection between payment services compliance, operational resilience and ICT risk management. Existing incident management frameworks should therefore be reviewed to determine whether they remain appropriate under the combined PSD3 and DORA requirements.


4. Business continuity and ICT recovery

The MFSA expects institutions to have business continuity arrangements which clearly identify critical operations and include appropriate ICT business continuity, response and recovery plans.

These arrangements should also be regularly tested and reviewed.

For many institutions, this will require more than updating a business continuity policy. Institutions should consider whether their critical payment services, systems, third-party dependencies and recovery arrangements have been properly mapped and whether testing demonstrates that the arrangements would work effectively during an actual disruption.


5. Winding-up plans

Perhaps one of the more significant new requirements is the introduction of a proportionate winding-up plan.

The plan will need to reflect the size and business model of the institution and address, among other matters, the return of safeguarded funds in the event of a disorderly wind-down.

This represents a shift towards greater consideration of how an institution would exit the market in an orderly manner, rather than focusing predominantly on how it operates as a going concern.

For institutions with significant customer balances, complex operational structures or reliance on third-party providers, developing a practical winding-up plan may require input across regulatory, legal, operational, financial and technology functions.


The MFSA's expectations go beyond a policy review

The Dear CEO Letter is particularly notable because the MFSA has gone beyond simply identifying the forthcoming regulatory changes.

The Authority expects boards to be informed of the implications of PSD3 and the reauthorisation process. It expects institutions to take steps towards alignment, perform and document a comprehensive gap analysis, develop an implementation plan and have that plan approved by the board.

The MFSA also expects boards, senior management and key function holders to understand the requirements relevant to their areas of responsibility. Institutions are expected to monitor the development of the EBA's technical standards and guidelines and to be able to demonstrate compliance in a clear and comprehensive manner.

In other words, PSD3 preparedness should be treated as a structured regulatory change programme rather than a compliance exercise that begins once the reauthorisation application becomes available.


The time to prepare is now

The MFSA's latest communication provides an important indication of the Authority's supervisory expectations ahead of PSD3.

Although the final legislative and technical framework is still developing, the direction of travel is already sufficiently clear for authorised institutions to begin preparing. The MFSA itself has emphasised that institutions should commence their compliance assurance work without undue delay, particularly given the limited period expected to remain between the publication of the EBA's Regulatory Technical Standards and the reauthorisation deadline.

For Maltese Payment Institutions and Electronic Money Institutions, the immediate priority should therefore be to understand the impact of PSD3, identify the areas requiring change and establish a clear, board-supported roadmap towards reauthorisation.


How BDO Malta can assist

At BDO Malta, we can support Payment Institutions and Electronic Money Institutions in turning PSD3 preparedness into a structured and practical programme.

Our support can include:

  • PSD3 regulatory gap assessment – assessing the institution's existing framework against the forthcoming PSD3 requirements and identifying regulatory, operational and governance gaps.
  • Safeguarding review – reviewing safeguarding arrangements, policies, reconciliation processes, account structures, concentration risk and customer disclosures against the forthcoming requirements.
  • Governance and internal controls – assessing governance structures, roles and responsibilities, risk management arrangements, internal controls and related policies and procedures.
  • DORA and ICT alignment – helping institutions assess the interaction between PSD3 requirements and their existing DORA framework, including ICT risk, incident management, business continuity and recovery arrangements.
  • Business continuity and operational resilience – reviewing critical operations, business continuity arrangements, ICT recovery plans and testing frameworks.
  • Winding-up planning – assisting institutions in developing proportionate and practical winding-up plans, including arrangements for the orderly return of safeguarded customer funds.
  • Implementation planning and regulatory readiness – translating identified gaps into a prioritised remediation roadmap, with clear responsibilities, milestones and board-level reporting.
  • Board and senior management awareness – providing targeted briefings to boards, senior management and key function holders on the implications of PSD3 and the steps required to achieve readiness.


BDO Malta can assist institutions in navigating this transition from regulatory analysis through to implementation and readiness.

If your institution has not yet commenced its PSD3 preparedness exercise, now is the time to start. Get in touch with BDO Malta’s Legal team to discuss your organisation’s readiness.


Want to know more?