top of page

Search Results

70 results found with an empty search

  • MiFID II Best Execution: New Requirements for Order Execution Policies - Get prepared ahead

    Introduction Commission Delegated Regulation (EU) 2026/825 introduces new Regulatory Technical Standards concerning the establishment, implementation and assessment of investment firms’ Order Execution Policies under MiFID II. The Regulation was published in the Official Journal of the European Union on 23 July 2026, enters into force on 12 August 2026 and will apply from 12 February 2028. It represents an important development in the EU best execution framework, introducing significantly more detailed requirements regarding execution-venue selection, order-routing arrangements, execution-quality monitoring, governance and the assessment of whether firms consistently achieve the best possible result for their clients. The best execution obligation remains unchanged Investment firms remain subject to the obligation under Article 27 of MiFID II to take all sufficient steps to obtain the best possible result for their clients. In doing so, firms must consider relevant execution factors, including: price; costs; speed; likelihood of execution and settlement; size; nature of the order; and any other consideration relevant to its execution. Commission Delegated Regulation (EU) 2026/825 does not change this fundamental obligation. Instead, it establishes a more structured framework for demonstrating how the obligation is embedded within a firm’s policies, governance arrangements, execution processes and monitoring systems. Key requirements under the new Regulation Governance over the selection of execution venues Investment firms will be required to describe within their Order Execution Policy the internal governance procedures applied when selecting execution venues. Firms must also maintain an internal and up-to-date list of approved execution venues. The list should include relevant information concerning: the identity of the venue; the date on which it was approved; the person or governance body responsible for its approval; the classes of financial instruments for which it may be used; the types of transactions permitted; the relevant client categories; and any applicable restrictions or limitations. This introduces clearer expectations regarding ownership, accountability, approval and periodic review of execution-venue arrangements. More structured venue-selection criteria The selection of execution venues must be based on an assessment of the characteristics and needs of the firm’s clients, as well as the characteristics of the relevant financial instruments and orders. Relevant considerations may include: the order types supported by the venue; typical client order sizes and frequency; available execution prices; trading and membership costs; connectivity costs; clearing, settlement and custody costs; and other administrative or operational costs associated with using the venue. Where costs incurred by the investment firm are passed on to clients, whether directly or indirectly, those costs must also be considered in the venue-selection process. Use of reliable reference and market data The Regulation places increased emphasis on the quality of data used to select venues and assess execution outcomes. Investment firms must use reliable and accurate reference data that provides a sufficiently complete representation of available market prices and execution conditions. The data used should include information from the most liquid venues relevant to the applicable class of financial instruments. Where available and appropriate, firms may also use consolidated market data. For instruments executed outside a trading venue, including bespoke or less liquid products, firms must use appropriate data to assess whether the proposed price is fair and supports the best possible result for the client. Single-venue execution arrangements Where an investment firm uses only one execution venue for a particular class of financial instruments, the Order Execution Policy must explain how that venue enables the firm to obtain the best possible result for clients on a consistent basis. Firms must be able to substantiate this conclusion and periodically compare the execution outcomes achieved through the selected venue against those potentially available through alternative venues. This requirement is particularly relevant to firms that rely on: a single broker; a single liquidity provider; a group company; a single market maker; or another exclusive execution counterparty. A single-venue model is not prohibited, but it must be supported by an objective, documented and periodically reviewed assessment. Clear order-routing methodology Where more than one execution venue is available, the firm must establish the criteria used to determine where individual client orders will be executed. The Order Execution Policy must explain the relative importance assigned to the relevant execution factors and how those factors are applied in practice. The assessment should take into account matters such as: the class of financial instrument; whether the client is retail or professional; the costs directly associated with execution; the size and nature of the order; prevailing market conditions; and current and historical execution data. Where automatic order-routing systems are used, the policy should explain the principal characteristics of the system and the controls ensuring that the routing methodology properly reflects the firm’s best execution obligations. Specific client instructions The Order Execution Policy must clearly explain what constitutes a specific instruction from a client and how such an instruction may affect the firm’s ability to apply its standard execution arrangements. Where the instruction relates only to a particular element of the order, only that element should be treated as subject to the client’s instruction. The firm must continue to apply its Order Execution Policy to all remaining elements of the order. Firms should therefore avoid treating a limited client instruction as removing the best execution obligation in respect of the entire transaction. Dealing on own account and OTC execution Investment firms executing client orders by dealing on own account must explain how they ensure that clients continue to receive the best possible result. The Order Execution Policy should address: how the execution outcome is assessed; how conflicts of interest are identified and managed; how potential risks or disadvantages to the client are evaluated; and how the fairness of the proposed price is verified. For financial instruments executed outside a trading venue, firms must compare the proposed price against relevant market information, comparable transactions or similar financial instruments. Where reliable external pricing information is unavailable, the firm should use an appropriate internal valuation or pricing model based on accurate and reliable market data. Quantitative monitoring of execution quality The Regulation introduces more structured expectations for the ongoing monitoring of execution outcomes. For representative samples within each class of financial instruments, firms will need to establish predetermined indicators and thresholds against which execution quality can be assessed. These may include: acceptable deviations between execution prices and relevant reference prices; the proportion of executed volume meeting predetermined execution standards; the number or percentage of client orders meeting the applicable thresholds; execution speed; likelihood of execution; settlement performance; and total execution costs. The monitoring framework should be capable of identifying material exceptions, deteriorating execution quality and situations in which the firm may no longer be obtaining the best possible result consistently. This will require firms to move beyond high-level or primarily narrative policy reviews and establish measurable, data-supported monitoring arrangements. Annual and event-driven effectiveness assessments Investment firms must assess the effectiveness of their Order Execution Policy and execution arrangements at least annually. An additional assessment must be carried out where: monitoring identifies a material deficiency; a material change affects the firm’s ability to achieve best execution; market or liquidity conditions change significantly; a new execution venue or execution functionality becomes available; relevant fee structures change; liquidity shifts between venues; an existing venue ceases operating, merges or becomes unavailable; or another development materially affects the firm’s execution arrangements. The assessment should examine whether the venues included in the policy continue to support the best possible result and whether the firm’s routing methodology, monitoring indicators and governance controls remain effective. Any identified deficiencies must be addressed as soon as reasonably possible, taking into account their seriousness and potential impact on clients. Practical implications for investment firms Although the Regulation will apply from 12 February 2028, firms should not underestimate the implementation work that may be required. The new requirements may affect not only the wording of the Order Execution Policy, but also the underlying operational, technological and governance arrangements through which orders are routed, executed, monitored and reviewed. Investment firms should consider: performing a detailed gap assessment against Commission Delegated Regulation (EU) 2026/825; reviewing the governance and approval process for execution venues; establishing or updating the internal inventory of approved venues; documenting the methodology used to select and periodically reassess venues; reviewing arrangements involving a single broker, venue or liquidity provider; evaluating the availability, quality and completeness of execution and reference data; developing quantitative execution-quality indicators and thresholds; reviewing automatic order-routing logic and related controls; strengthening OTC price-fairness and valuation procedures; updating the methodology for annual and event-driven effectiveness assessments; establishing clear escalation and remediation procedures for identified deficiencies; and assessing whether related client disclosures, procedures and governance documents require amendment. A shift towards demonstrable best execution The new framework reinforces the expectation that best execution must be demonstrable in practice and not merely described at a policy level. Investment firms will be expected to show, through appropriate governance, data, quantitative analysis, documented decisions and effective monitoring, that their execution arrangements are designed and operated to achieve the best possible result for clients on a consistent basis. The implementation period therefore provides an opportunity for firms to review not only their formal Order Execution Policy, but the complete control framework supporting venue selection, order routing, pricing, monitoring, escalation and governance. Early preparation will be particularly important for firms with limited execution data, single-venue arrangements, manual monitoring processes or significant reliance on third-party brokers and liquidity providers. This publication is provided for general information purposes only and does not constitute legal, regulatory or other professional advice.

  • EU Regulators Propose Margin Relief for Firms Falling Below the €8 Billion OTC Derivatives Threshold

    What's changing, why it matters, and what CIFs, PIs and insurers active in uncleared OTC derivatives should do now On 31 July 2026, the European Supervisory Authorities (EBA, EIOPA and ESMA) published their Final Report (ESA 2026 07) proposing amendments to the RTS on risk-mitigation techniques for uncleared OTC derivatives under Commission Delegated Regulation (EU) 2016/2251. The changes are limited in scope but operationally significant for any counterparty whose derivatives activity sits near the EUR 8 billion AANA threshold. The problem the ESAs are fixing Under the current rules, a counterparty whose aggregate month-end average notional amount (AANA) of non-centrally cleared OTC derivatives, measured over March, April and May of the preceding year, falls below EUR 8 billion is exempt from posting initial margin, but only on new trades. Existing contracts remain subject to initial margin obligations for as long as they run. That means firms still have to maintain margin calculation processes, exchange collateral, and keep custodial and segregation arrangements in place for legacy trades, even after they've genuinely dropped below the threshold. It also puts EU counterparties at a disadvantage relative to other jurisdictions, which already exempt existing contracts once a firm falls below the equivalent threshold, creating an incentive to trade with non-EU counterparties instead. What the draft RTS actually change 1. Existing contracts get relief too, across the whole bilateral portfolio. Where the March to May AANA of either counterparty falls below EUR 8 billion, no initial margin needs to be collected on new or existing uncleared OTC derivative contracts between them, not just new trades as today. 2. Already-posted margin may be released. Where the exemption applies, initial margin already collected on outstanding contracts can be released, freeing up liquidity previously locked up in legacy trades. Importantly, this is elective, not automatic: counterparties don't have to release collateral precisely on the trigger date. They can time the release to suit their operational readiness, agree the release process between themselves, or simply choose to keep collecting margin voluntarily if that's more convenient. 3. Faster exit, slower entry, an intentional asymmetry. Falling below the threshold: firms may implement the exemption as early as 1 June of the relevant year (rather than waiting until year-end), based on the March to May AANA calculation. Rising above the threshold: firms only become subject to margin requirements on new trades from 1 January of the following year, preserving the existing preparation runway for firms moving into scope. Existing contracts aren't retrospectively pulled back into scope just because the threshold is exceeded again. 4. AANA calculation methodology is unchanged. The threshold test still runs off the March, April and May month-end average notional amount, and is still calculated at counterparty level, or at group level where the counterparty belongs to a group. This EUR 8 billion test is separate from the EMIR clearing thresholds, which are set by asset class, and the two shouldn't be confused. 5. A related tidy-up for equity options. Following EMIR 3 (Regulation (EU) 2024/2987), which already exempts single stock options and equity index options from collateral-exchange requirements, Article 38(1) of the RTS, which contained now-obsolete transitional wording for these instruments, is deleted. The underlying exemption for these instruments is unaffected; this is purely a technical clean-up. What this doesn't change It's worth being precise here: the amendment is about initial margin specifically. It doesn't touch the other EMIR risk-mitigation obligations that continue to apply regardless of where a counterparty sits against the AANA threshold, including variation margin, timely confirmation, portfolio reconciliation, dispute resolution, and portfolio compression requirements. Why it matters in practice For treasury and collateral management functions, this removes a real operational drag: no more running parallel margin, custody and reconciliation processes for counterparty relationships that have genuinely fallen below the relevant activity threshold. For insurers in particular, who per feedback from EIOPA's Stakeholder Groups tend to sit closer to this threshold than banks given the more targeted, hedging-driven use of derivatives, the relief may be proportionally more relevant than for larger banking counterparties with consistently high derivatives volumes. The ESAs opted for a light-touch consultation (Stakeholder Groups only, no open public consultation or impact assessment) given the narrow scope of the amendment, a route several stakeholders accepted as appropriate here, while flagging it shouldn't become the default approach for future RTS changes. What's next The Final Report has been submitted to the European Commission for endorsement as a Commission Delegated Regulation. It will then go through non-objection by the European Parliament and Council before publication in the Official Journal, entering into force 20 days after publication. No firm date has been set yet, so this is one to watch rather than act on immediately, but firms with derivatives activity near the threshold should start reviewing their margining, custodial and collateral-release processes now so they're ready to apply the exemption as soon as it takes effect.

  • EU AI Act Transparency Rules: New Labelling Tools and Key Compliance Steps for AI-Generated Content

    Introduction The European Union is moving from the legislative design of the AI Act to its practical implementation. Recent developments concerning the identification, marking and labelling of AI-generated content provide businesses with greater clarity on how the EU’s transparency requirements are expected to operate in practice. In June 2026, the European Commission published the final Code of Practice on Transparency of AI-Generated Content, together with EU labelling icons and supporting frequently asked questions. These tools are intended to assist providers and deployers of generative AI systems in preparing for the transparency obligations under Article 50 of the EU AI Act. The developments are particularly relevant to organisations using generative AI to produce or modify text, images, audio and video, including financial institutions, professional-services firms, media organisations, marketing agencies, online platforms and other businesses publishing content directed at the public. What does Article 50 of the AI Act require? Article 50 establishes transparency requirements for certain AI systems and AI-generated or manipulated content. The obligations differ depending on whether an organisation acts as a provider of the relevant AI system or as a deployer using the system in its activities. Obligations for providers Providers of AI systems that generate synthetic audio, image, video or text content must ensure that their outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. The marking solution must be effective, interoperable, robust and reliable, taking account of the type of content, technical limitations and generally recognised standards. This requirement is primarily directed at the developers and providers of generative AI systems rather than ordinary business users. Obligations for deployers Organisations using AI systems must disclose that content has been artificially generated or manipulated where they: generate or manipulate image, audio or video content constituting a deep fake; or generate or manipulate text published for the purpose of informing the public about matters of public interest. The disclosure must be clear and distinguishable and must be made no later than the first exposure of the content to the public. Certain exceptions apply, including circumstances involving authorised law-enforcement uses and, subject to specific conditions, artistic, creative, satirical or fictional works. For public-interest text, the disclosure requirement may also not apply where the AI-generated content has undergone human review or editorial control and a person or organisation holds editorial responsibility for its publication. The new EU icons for AI-generated content The Commission has introduced a set of standardised icons that deployers may use when labelling AI-generated or manipulated content. The purpose of the icons is to provide a recognisable and consistent visual indication that content was created or modified using AI. Their use may help individuals distinguish authentic content from synthetic or manipulated material and may contribute to reducing deception, impersonation and misinformation risks. The icons are freely available and form part of the practical framework accompanying the Transparency Code of Practice. However, an important distinction must be maintained: Use of the EU icons is voluntary, but compliance with the applicable transparency obligations is mandatory. Simply displaying an icon will not automatically establish compliance. An organisation must still assess whether the disclosure is sufficiently clear, appropriately placed and provided at the correct point in time. It must also consider whether additional wording or technical marking is required, depending on the content and the organisation’s role. The Transparency Code of Practice The Code of Practice is divided into two principal sections: Measures for providers, addressing the marking and detection of AI-generated or manipulated content. Measures for deployers, addressing the visible labelling of deep fakes and certain AI-generated or manipulated text. Adherence to the Code is voluntary. Nevertheless, the European Commission and the European AI Board have assessed it as an appropriate tool through which signatories may demonstrate compliance with the relevant AI Act transparency obligations. Signing the Code may therefore provide participating organisations with a more predictable and harmonised compliance framework across the EU. It may also reduce uncertainty regarding the technical and organisational measures expected by supervisory authorities. The Code does not replace the AI Act and does not provide an unconditional safe harbour. A signatory remains responsible for assessing its own systems, use cases and disclosures and for ensuring that the measures it implements satisfy the legal requirements in practice. Revised AI Act implementation timetable The wider AI Act implementation timetable has also been amended through the EU’s Digital Omnibus on AI. The European Parliament approved the amendments on 16 June 2026 by 423 votes to 57, with 174 abstentions. The Council gave its final approval on 29 June 2026. Under the revised timetable, the requirements for high-risk AI systems will generally apply: from 2 December 2027 for stand-alone high-risk AI systems; and from 2 August 2028 for high-risk AI systems embedded as safety components in products governed by specified EU sectoral legislation. The amendments also introduce a prohibition relating to AI systems designed to generate child sexual abuse material or non-consensual intimate content involving identifiable persons. These postponements concern the high-risk AI framework and should not be interpreted as a general suspension of all AI Act obligations. In particular, the Article 50 transparency obligations concerning AI-generated and manipulated content are scheduled to become applicable from 2 August 2026, subject to any specific transitional provisions introduced for systems already placed on the market. What businesses should do now Organisations should not limit their preparations to identifying whether they develop AI systems. Businesses that use publicly available generative AI applications may themselves qualify as deployers and become responsible for the way AI-generated content is reviewed, approved, labelled and published. A practical compliance exercise should include the following steps. 1. Identify AI-generated content 2. Determine the organisation’s role 3. Distinguish assistance from generation 4. Establish an approval and labelling procedure 5. Introduce human editorial controls 6. Review contracts with technology and content providers 7. Train employees AI transparency is broader than the AI Act Compliance must also be considered alongside other areas of EU and national law. Where AI-generated content involves identifiable individuals, personal data or automated decisions, the GDPR may apply. Relevant issues may include transparency, lawful processing, data accuracy, the use of biometric data, automated decision-making and the rights of affected individuals. Intellectual-property rights, personality rights, consumer-protection rules, advertising standards, defamation law and sector-specific regulatory obligations may also apply. Accordingly, an AI label does not make otherwise unlawful content permissible. A properly labelled deep fake, for example, may still infringe privacy, data-protection, copyright or personality rights. Conclusion The publication of the Transparency Code of Practice, the supporting FAQs and the EU labelling icons represents an important step towards the operational application of the AI Act. For businesses, the central message is that AI transparency is no longer merely a matter of voluntary ethics or good practice. In the circumstances covered by Article 50, it is becoming a formal compliance obligation. Organisations should therefore establish a structured approach for identifying AI-generated content, determining their regulatory role, applying appropriate labels, documenting human review and retaining evidence of compliance. The postponement of certain high-risk AI requirements should not delay this work. The transparency rules for AI-generated and manipulated content follow a separate timetable and require immediate operational preparation.

  • Pay Transparency in Cyprus: What Employers Should Know About the New Draft Law

    Cyprus is moving forward with the implementation of Directive (EU) 2023/970 on pay transparency and equal pay between men and women for equal work or work of equal value. A draft Cyprus law has been prepared under the title “The Law on Strengthening the Application of the Principle of Equal Pay between Men and Women for Equal Work or Work of Equal Value through Pay Transparency and Enforcement Mechanisms, Law of 2026.” Although the law is still in draft form, it gives a clear indication of the obligations employers should start preparing for. Who Is Impacted? The draft law is relevant to both public and private sector employers in Cyprus. Its practical impact will differ depending on the size and structure of the employer: All employers will need to consider how they determine pay, communicate salary information and justify pay differences. Employers recruiting staff will need to review job advertisements, salary ranges and interview practices. Employers with structured teams or multiple roles will need to assess whether employees performing equal work or work of equal value are treated consistently. Employers with 100 or more employees will be directly impacted by gender pay gap reporting obligations. Employers with fewer than 100 employees may not be subject to mandatory reporting, but should still be prepared to respond to employee pay information requests and comply with the equal pay principles. In practice, this is not only an issue for large organisations. Even smaller employers may need to review employment contracts, confidentiality clauses, recruitment practices and internal pay criteria. What Is Changing? The draft law introduces a more transparent framework around how pay is determined, communicated and justified. Employers will need to ensure that their pay structures are based on objective and gender-neutral criteria, such as skills, effort, responsibility, working conditions and other relevant role-specific factors. This means that salary decisions, bonuses, promotions and pay progression should be capable of being explained and supported by evidence. Recruitment and Salary Ranges One of the most practical changes concerns recruitment. Job applicants will have the right to receive information on the initial salary or salary range for the position before the interview stage. Importantly, where a salary range is provided, the draft Cyprus law provides that the difference between the lower and upper end of the range should not exceed 20%. Employers will also be prohibited from asking candidates about their previous salary history. This means that job advertisements, interview practices and offer approval processes should be reviewed. Employee Right to Pay Information Employees will have the right to request written information about: their individual pay level; and average pay levels, broken down by gender, for employees performing equal work or work of equal value. Employers must provide this information within a reasonable period and, in any case, within two months from the request. Employers must also inform employees annually about this right and how it can be exercised. Gender Pay Gap Reporting The draft law introduces gender pay gap reporting obligations based on employer size: employers with 250+ employees: first report by 7 June 2027 and annually thereafter; employers with 150–249 employees: first report by 7 June 2027 and every three years thereafter; employers with 100–149 employees: first report by 7 June 2031 and every three years thereafter; employers with fewer than 100 employees: voluntary reporting. The reported information will include gender pay gaps, variable pay gaps, median pay gaps and the distribution of men and women across pay quartiles. Joint Pay Assessment Where reporting shows a pay gap of at least 5% in any category of employees, and the employer cannot justify it objectively or correct it within six months, a joint pay assessment may be required. This is a key compliance risk. Employers should therefore be ready not only to calculate pay gaps, but also to explain and, where needed, correct them. What Employers Should Do Now Employers should start preparing by: reviewing salary structures and job categories; documenting objective pay and promotion criteria; reviewing job advertisements and salary range practices; removing salary history questions from recruitment; checking whether HR/payroll systems can produce the required data; reviewing confidentiality clauses and pay secrecy provisions; preparing an internal process for employee pay information requests; and ensuring GDPR-compliant handling of pay data. Final Comment Pay transparency is becoming a practical employment compliance obligation in Cyprus. The key issue for employers will not only be whether pay differences exist, but whether they can be objectively justified, properly documented and explained. Early preparation will help employers manage legal, operational and reputational risk under the forthcoming Cyprus framework.

  • New CBC Governance Directives for Payment and Electronic Money Institutions: What Firms Should Do Now

    The Central Bank of Cyprus has issued new 2026 Directives (Κ.Δ.Π 245/2026 and Κ.Δ.Π 246/2026),on the internal organisation and governance of Payment Institutions and Electronic Money Institutions, introducing a more detailed and structured governance framework for the payments and e-money sector in Cyprus. The new framework marks an important supervisory development. It moves beyond general governance expectations and sets out more concrete requirements on board composition, internal organisation, committees, internal controls, risk management, compliance, internal audit, outsourcing, ICT risk, reporting and transparency. For Payment Institutions and Electronic Money Institutions, this should not be treated as a simple policy update. It requires a practical review of how the institution is organised, how responsibilities are allocated, how risks are monitored, and how the Board exercises effective oversight. The Big Picture: Governance Becomes More Structured The new Directives are based on the principle that institutions must maintain an effective governance framework that is proportionate to their size, risk profile, nature, scale and complexity of activities. This means that firms are not expected to apply a one-size-fits-all model. However, they must be able to demonstrate that their governance arrangements are appropriate, documented, operationally effective and aligned with their business model and risk profile. The Central Bank’s expectations are clearly focused on substance. Institutions must not only have policies and procedures in place; they must also be able to evidence that these arrangements are understood, implemented, monitored and regularly reviewed. Enforcement and Supervisory Expectations The deadlines create a clear supervisory expectation. Institutions should be ready to demonstrate to the Central Bank that they have: assessed their current governance framework; identified gaps against the new requirements; prepared and submitted a clear action plan within the required timeframe; assigned responsibility for implementation; updated relevant policies, procedures and terms of reference; strengthened reporting lines and Board oversight; and achieved full implementation within the nine-month compliance period. Failure to take timely and structured action may expose institutions to supervisory scrutiny, particularly where governance weaknesses affect internal controls, risk management, outsourcing oversight, ICT risk, compliance or Board effectiveness. Key Areas Covered by the New Framework The Directives cover a wide range of governance and internal organisation requirements. The most important areas for firms to assess include the following. 1. Board Responsibility and Oversight The administrative body has ultimate responsibility for the internal governance of the institution. This includes approving and overseeing the governance framework, business strategy, risk management arrangements, internal control system and compliance framework. The Board must be able to demonstrate active and informed oversight. This includes regular review of policies, risks, internal controls, outsourcing arrangements, ICT risk and the effectiveness of the institution’s governance structure. 2. Board Composition and Independence Institutions should review whether the Board has the appropriate size, composition, knowledge, experience and independence to exercise effective oversight and challenge. This is particularly important for institutions with founder-led, operationally driven or informal governance structures, where Board responsibilities may not have been sufficiently documented or separated from day-to-day management. 3. Committees and Governance Structure The Directives refer to the establishment and operation of Board committees, including risk and audit-related governance arrangements, subject to proportionality. Institutions should assess whether their committees are properly documented, whether their terms of reference are clear, whether their reporting lines are effective and whether they have access to the information and resources needed to discharge their responsibilities. Where committees are not established due to proportionality considerations, the institution should still be able to evidence how the relevant oversight responsibilities are carried out. 4. Internal Control Framework A central part of the new framework is the requirement for a sound internal control framework. This includes a clear organisational structure, transparent reporting lines, proper segregation of duties, documented responsibilities and effective control mechanisms. The internal control framework should cover the whole institution, including the Board, senior management, operational departments, internal control functions and outsourced activities. Institutions should therefore review whether their internal governance documents reflect how the business actually operates in practice. 5. Risk Management, Compliance and Internal Audit The Directives place significant emphasis on the key internal control functions. The risk management function should identify, assess, monitor and report the risks to which the institution is exposed. The compliance function should support and monitor compliance with applicable laws, regulatory requirements and internal policies. The internal audit function should provide independent assurance on the adequacy and effectiveness of the internal control framework. Institutions should assess whether these functions are clearly assigned, sufficiently independent, properly resourced and supported by appropriate reporting to the Board. 6. ICT Risk and Operational Resilience ICT risk is expressly integrated into the governance framework. Institutions are expected to have appropriate arrangements for managing ICT-related risks, including alignment with the broader EU operational resilience framework. This requires more than maintaining IT policies. Institutions should be able to demonstrate that ICT risk is identified, monitored, reported and incorporated into the wider risk management and internal control framework. 7. Outsourcing and Third-Party Arrangements The Directives place strong emphasis on outsourcing governance. Institutions remain fully responsible for outsourced activities and must ensure that outsourcing arrangements do not weaken their governance, internal controls, regulatory compliance or ability to serve customers. Institutions should review their outsourcing policy, outsourcing register, oversight arrangements, reporting lines, contractual protections and escalation mechanisms. Particular attention should be given to critical or important outsourced functions, ICT service providers and arrangements supporting core operational processes. 8. Complaints, Whistleblowing and Conduct The new framework also addresses complaints handling, internal reporting and whistleblowing arrangements, corporate values and codes of conduct. This reflects the expectation that governance is not only a matter of structure, but also of culture. Institutions should ensure that staff understand expected standards of conduct, escalation channels, internal reporting procedures and the consequences of non-compliance. What PIs and EMIs Should Do Now Payment Institutions and Electronic Money Institutions should move quickly and carry out a practical gap analysis against the new requirements. Key areas to review include: Board composition, independence, responsibilities and reporting arrangements; terms of reference and operation of Board committees; governance framework, organisational structure and allocation of responsibilities; internal control framework and segregation of duties; risk management, compliance and internal audit arrangements; ICT risk governance and operational resilience arrangements; outsourcing policy, outsourcing register and third-party oversight; complaints handling, whistleblowing and conduct standards; reporting to the Central Bank of Cyprus; and evidence demonstrating that governance arrangements operate effectively in practice. The immediate priority should be to prepare a structured gap analysis and action plan within the three-month deadline, followed by full implementation within the nine-month compliance period. Why This Matters For many institutions, the main challenge will not be the complete absence of policies, but whether existing policies, governance arrangements and reporting lines are sufficiently specific, operational and aligned with the actual business model. The Central Bank’s expectations are increasingly focused on effective implementation. Institutions should be ready to demonstrate that their governance framework is not only documented, but also embedded, monitored and capable of withstanding supervisory review. This creates a clear need for Payment Institutions and Electronic Money Institutions to move from general governance documentation to a more structured, risk-based and supervisory-ready framework. Deadlines for Compliance The Directives introduce specific implementation deadlines which institutions should treat as immediate regulatory priorities. Within 3 months Institutions must submit to the Central Bank of Cyprus an action plan for achieving full compliance with the provisions of the relevant Directive. This action plan should be based on a proper gap analysis and should identify the actions required, responsible persons, timelines and areas where existing arrangements need to be updated or strengthened. Within 9 months Institutions must achieve full compliance with the relevant Directive within nine months from the date the Directive enters into force. This means that the implementation period should not be used only for drafting documents. Institutions should ensure that the revised governance framework is properly approved, embedded and capable of being evidenced in practice. How ENAH Services Ltd Can Support ENAH Services Ltd can support Payment Institutions and Electronic Money Institutions in assessing and implementing the requirements of the new CBC Governance Directives. Our support can include a regulatory gap analysis, preparation of the required action plan, review of governance and internal control arrangements, assessment of Board and committee documentation, review of risk management, compliance and internal audit frameworks, outsourcing governance review, ICT risk governance alignment and preparation of practical remediation actions. We combine legal, regulatory and practical implementation experience, helping institutions translate supervisory requirements into workable governance arrangements that reflect their actual operating model. The new Directives should be seen as an opportunity for institutions to strengthen their governance framework, enhance supervisory readiness and build a more resilient and well-controlled organisation.

  • EMIR 3: The New Clearing Threshold Regime — What Market Participants Need to Know

    On 25 February 2026, the European Securities and Markets Authority (ESMA) published its Final Report setting out revised clearing thresholds under EMIR 3. This article explains what is changing, what the new numbers mean in practice, and what action you should be taking now.   The Big Picture: Why This Matters The European Market Infrastructure Regulation, commonly known as EMIR, sets the framework governing over-the-counter (OTC) derivative markets in the EU. At its core is the clearing obligation : the requirement for certain counterparties to clear eligible OTC derivative contracts through authorised Central Counterparties (CCPs) rather than settling bilaterally. Whether a counterparty is subject to this obligation depends on whether their OTC derivatives positions exceed defined clearing thresholds . Exceed the threshold in any asset class and mandatory clearing kicks in for all OTC derivatives in that class. EMIR 3 (Regulation (EU) 2024/2987), which entered into force on 24 December 2024, significantly overhauled how these thresholds are calculated. ESMA has now published the draft Regulatory Technical Standards (RTS) that set out the specific new threshold values, amending Commission Delegated Regulation (EU) No 149/2013. These RTS are now with the European Commission for endorsement, expected within three months. Until formally adopted, the current rules remain in force .   The Fundamental Change: From All OTC to Uncleared Only This is the most important conceptual shift and it is worth understanding clearly before looking at the numbers.     The regime also introduces different rules depending on whether you are a Financial Counterparty (FC) or Non-Financial Counterparty (NFC). For Financial Counterparties (FCs) FCs face a dual assessment. They must test their positions against: An uncleared positions threshold : measuring only uncleared OTC derivatives (shared with NFCs); and An aggregate backstop threshold : measuring both cleared and uncleared OTC derivatives, but applicable only for interest rate and credit derivatives (the asset classes currently subject to the clearing obligation). The backstop threshold exists to ensure that FCs with very large cleared portfolios, who may fall below the uncleared threshold, are still captured by the clearing obligation. For Non-Financial Counterparties (NFCs) Two important changes apply to NFCs: NFCs now test only against the uncleared threshold . There is no aggregate backstop for NFCs. Position calculation moves from group level to entity level . Previously, an NFC included the OTC derivatives of other NFCs in its group. Under EMIR 3, each NFC calculates based only on its own uncleared speculative transactions. Cleared positions and other group entities are excluded. For many NFCs, particularly those active in energy and commodity markets, this shift to entity-level calculation on an uncleared-only basis is likely to be a favourable change, potentially bringing them below the threshold.   3. The New Threshold Values ESMA consulted on proposed threshold levels in April 2025 and received 35 responses from a broad range of financial counterparties, non-financial counterparties and trade associations. The final values reflect upward revisions in certain asset classes to account for inflation, price developments and market growth since the original thresholds were set.   Uncleared OTC Positions Threshold — Applies to Both FCs and NFCs     Aggregate OTC Positions Threshold — FCs Only (Backstop) In addition to the uncleared threshold, FCs must also test against an aggregate threshold covering both cleared and uncleared OTC derivatives. This backstop applies only to the two asset classes subject to the clearing obligation:   What This Means The impact of these changes will vary significantly depending on your counterparty classification, your derivative activity, and the proportion of your positions that are currently cleared. If you are a Non-Financial Counterparty The shift to entity-level, uncleared-only calculation is likely to be favourable for many NFCs. Cleared positions and those of other group entities are now excluded. Energy companies and commodity market participants should re-assess their threshold position under the new methodology, the measured exposure may fall significantly even before the benefit of the higher commodity threshold is considered. NFCs relying on VPPAs or other structured hedging should note that these are not eligible for the hedging exemption under the current framework and this has not changed. If you are a Financial Counterparty Review both the uncleared threshold and  the aggregate backstop for interest rate and credit derivatives. You must satisfy both tests. FCs with large cleared portfolios in interest rate or credit derivatives should pay particular attention to the aggregate backstop, which remains at €3bn and €1bn, respectively. The reduced uncleared thresholds for interest rate (€2.2bn), credit (€0.8bn), and equity (€0.7bn) derivatives reflect the narrower scope of what is being measured, not a straightforward tightening of the regime.   Next Steps and Timeline     We recommend that regulated entities begin preparing now by: Modelling their positions under the new uncleared-only methodology to understand the change in their measured exposure; Reviewing group structure and the impact of the move from group-level to entity-level calculation (for NFCs); Assessing whether any current clearing obligation would continue under the new regime, or whether they may fall below a threshold; and Updating internal threshold monitoring and compliance processes ahead of the RTS coming into force.

  • PSD3 & PSR: What Every Board and Senior Manager Needs to Know

    1. The Big Picture: Why This Matters to You The European Union's payments landscape is undergoing its most significant transformation in over a decade. The Third Payment Services Directive (PSD3) and the new Payment Services Regulation (PSR) together replace the existing PSD2 framework, and the implications reach every institution that touches payments in the EU, from banks and FinTechs to insurance groups and investment firms. On 27 November 2025, the European Parliament and the Council of the EU reached a provisional political agreement on both texts. Formal adoption and publication in the Official Journal are expected in mid-2026, followed by an 18-to-21-month transition period. That puts the compliance deadline squarely in late 2027, but for organisations with complex operating models, that window will pass quickly. This is not a regulation to approach reactively. The institutions that start now will be better positioned, better protected, and better able to capture the competitive opportunities the new framework creates. 2. PSD3 vs PSR: Understanding the Two Forces One of the most important structural changes in this reform is the deliberate split between a Directive and a Regulation: PSD3: The Directive PSD3 primarily governs authorisation and supervision of payment service providers. As a directive, it must be transposed into national law by each EU Member State. It will address licensing frameworks, governance requirements, capital thresholds, and the regulatory relationship between payment institutions and national competent authorities. Critically, existing authorisations granted under PSD2 will remain valid for 24 months from PSD3's entry into force, but institutions will need to submit a new application demonstrating compliance with updated requirements. Plan for this re-authorisation process early. PSR: The Regulation The Payment Services Regulation is directly applicable across all EU Member States without national transposition. It covers the rules governing how payment services are delivered, security, strong customer authentication (SCA), open banking obligations, fraud prevention, and consumer rights. PSR obligations may become binding before PSD3 is transposed in certain jurisdictions. Compliance timelines for the two instruments may differ, and firms must plan accordingly. 3. Five Key Changes Boards Must Understand 1. Fraud Liability Has Shifted — Significantly Under the new framework, if a Payment Service Provider fails to implement appropriate fraud prevention mechanisms, it will be held liable for covering customer losses. PSPs are now required to verify that a payee's name and unique identifier match before processing a credit transfer. Where discrepancies exist, the payment must be refused and the payer informed. For impersonation fraud, where a criminal poses as a PSP employee to manipulate a customer into approving a transaction, PSPs must refund the full amount, provided the customer reports the fraud to the police. This is a substantial extension of liability and requires robust fraud detection infrastructure. Action Point:  Review your fraud prevention architecture, SCA implementation, and customer refund policies against the new liability standard now, do not wait for final texts. 2. Open Banking Gets a Meaningful Upgrade PSD2 introduced open banking, but its implementation was inconsistent across the EU. PSD3 and PSR aim to resolve this by standardising API access requirements, setting clear reliability and availability expectations, and introducing consent dashboards that give consumers visibility and control over who accesses their financial data. Firms that invest in high-quality, standards-compliant APIs will be better positioned in the competitive landscape for financial data services, especially as the proposed Financial Data Access (FIDA) framework develops in parallel. 3. A Level Playing Field Between Banks and Non-Banks PSD3 and PSR provide clearer and more consistent conditions for non-bank payment service providers to access payment systems and hold accounts at credit institutions. Banks face greater competitive pressure from fintechs and payment institutions. Non-bank PSPs face higher compliance obligations as their regulatory footing becomes equivalent. 4. Stronger Consumer Rights and Transparency The new framework significantly strengthens consumer-facing obligations: unexpected account blocks, unclear fee structures, and insufficient transparency on ATM charges and cross-border payment costs are all addressed. PSPs must offer customers clear spending limits and account-blocking tools, and consumers will have enhanced dispute resolution rights. 5. Crypto and MiCA Alignment PSD3 introduces a simplified authorisation pathway for providers already licensed under the EU Markets in Crypto-Assets Regulation (MiCA). For firms operating at the intersection of traditional payments and digital assets, this alignment reduces regulatory duplication, but requires careful analysis of which activities fall under which regime. 4. The Compliance Timeline: What to Do and When Now - Mid 2026: Monitor and Diagnose –      Conduct a preliminary gap analysis against the agreed political text, sufficient detail is available now to begin. –      Identify which parts of your business are in scope for PSR (directly applicable) versus PSD3 (transposition dependent). –      Map your fraud prevention and SCA architecture against the new liability standard. –      Engage with your national competent authority on the re-authorisation process timeline. Mid 2026 - End 2026: Detailed Impact Assessment –      Obtain and review the final published texts once available in the Official Journal. –      Commission a full regulatory impact assessment covering systems, processes, governance, and contracts. –      Begin API remediation projects if open banking access is material to your business. –      Update compliance monitoring programmes and internal audit plans to reflect new requirements. 2027: Implementation and Readiness –      Complete re-authorisation submissions ahead of national deadlines. –      Staff training and awareness programmes, regulators will expect documented evidence. –      Final testing of fraud detection, SCA, and customer-facing transparency tools. –      Pre-deadline internal audit to verify compliance readiness. 5. How ENAH Services Ltd Can Help ENAH Services Ltd has deep expertise in EU financial services regulation, internal audit, and compliance across payments, banking, and investment services. Our team has supported clients through PSD2 implementation and is already advising on PSD3 and PSR readiness. We offer a structured PSD3/PSR readiness programme tailored to your institution's size, business model, and regulatory footprint, including: –      Regulatory gap analysis and impact assessment –      Compliance programme design and policy drafting –      Internal audit readiness and independent review –      Tailored training for boards, senior management, and compliance teams –      Ongoing regulatory monitoring and horizon scanning Get in touch with ENAH Services Ltd to discuss your PSD3/PSR readiness. www.enaservicesltd.com   |  consulting@enaservicesltd.com

  • Digital Omnibus : What is Changing and Why It Matters for EU Businesses

    In November 2025, the European Commission presented the Digital Omnibus Regulation proposal (COM(2025) 837) as part of a broader drive to “simplify” EU digital compliance and reduce fragmentation. The proposal is presented as a pragmatic, technical package—yet it touches multiple sensitive areas: cookie rules, GDPR enforcement practicality, AI-related processing, and cybersecurity incident reporting. This article explains what is changing, what is being debated, and what organizations should do now. What is the Digital Omnibus? An “omnibus” legislative instrument is a package that amends multiple legal areas through a single proposal. The Digital Omnibus is designed to streamline the EU digital compliance environment and align certain elements across: GDPR (data protection) AI Act implementation Cybersecurity reporting / incident notification frameworks certain overlaps with the wider EU digital rulebook The central claim is “simplification.” The central question is whether simplification is achieved by reducing unnecessary burden while maintaining safeguards—or whether some changes risk weakening rights or enforcement effectiveness. What is changing (as proposed) A) Cookies and terminal equipment: closer to GDPR logic A major shift described in the proposal is moving rules around terminal equipment data (including cookies and similar identifiers) more clearly into a GDPR-style compliance and enforcement approach. Practical meaning : cookie compliance is likely to become more explicitly tied to GDPR concepts and enforcement consequences, potentially changing how organizations design consent, records, and user controls. B) Cookie consent redesign: fewer repeated prompts The proposal describes a consent model intended to reduce “banner fatigue,” including: clearer Accept / Reject choices if a user rejects, the website should not ask again for at least six months stronger emphasis on respecting central privacy preferences (e.g., browser/device-level settings) where applicable a limited “whitelist” logic for certain low-impact cookies (e.g., basic aggregated measurement) under strict conditions Practical meaning:  banner UX and consent management platforms may need redesign. Organizations should also re-check which cookies truly need consent vs. which may fall within narrowly defined low-impact categories. C) Pseudonymised data: clearer boundaries for recipients The proposal introduces clarification that pseudonymised data shared with third parties who cannot realistically or lawfully re-identify individuals may not be treated as personal data for those recipients. Practical meaning:  this could enable safer data sharing for analytics, research, and AI development—but it raises governance questions: who can re-identify, under what conditions, and how that is evidenced contractually and technically. D) AI development under GDPR: more explicit use of “legitimate interests” The proposal describes a more explicit route for processing personal data in the context of developing and operating AI systems/models using legitimate interests, with safeguards (e.g., minimisation, transparency, right to object, and impact assessments where needed). It also references limited processing of special category data in specific contexts such as bias detection and correction, subject to strict safeguards. Practical meaning: organizations building or deploying AI should expect intensified scrutiny of: legitimate interest assessments, transparency practices, objection handling, data minimisation and purpose limitation, and DPIA triggers. E) Right of access: addressing “manifestly abusive” requests The proposal introduces provisions allowing controllers to limit handling of access requests where there is manifest abuse (e.g., repeated, excessive, or clearly bad-faith requests). Practical meaning:  companies may gain more operational flexibility, but must apply the concept cautiously—because misuse could become a major enforcement and reputational risk. F) Automated decision-making (GDPR Article 22): clearer conditions The proposal clarifies/reframes the conditions under which decisions with legal or similarly significant effects may be solely automated (e.g., necessity for contract, authorization by law with safeguards, or explicit consent). Practical meaning : organizations using scoring, profiling, or automated eligibility decisions should re-check: whether Article 22 applies, whether there is meaningful human involvement, and whether safeguards and transparency are adequately documented. G) “Unified policies” across regimes The proposal describes a direction toward integrated policies and documentation across multiple regimes (e.g., GDPR + AI Act + cybersecurity reporting), reducing parallel paperwork. Practical meaning:  good governance programs (single control frameworks, shared risk registers, unified policies) become more valuable—especially for multi-country operations. Cybersecurity: one reporting “entry point” for incidents Another key element is the concept of a single entry point for incident reporting to reduce duplicate notifications across frameworks. A 96-hour window is referenced for the unified submission concept, while recognizing that existing obligations under specific laws (including earlier notifications where required) remain relevant. Practical meaning:  security and privacy teams should align incident response so that: one internal workflow supports multiple legal notifications, evidence and timelines are controlled, and decision-making is documented. Why this is controversial Although the package is described as simplification, stakeholders debate whether certain changes may: make enforcement harder or slower through procedural shifts narrow practical access to remedies or complaint pathways create uncertainty around rights (especially in AI-related processing) rebalance the system more toward administrative efficiency than fundamental rights EU-level privacy regulators have emphasized that simplification must not weaken effective protection and must preserve enforceability and rights in practice. What businesses should do now Even before the final text is adopted, the proposal is a strong signal: EU compliance will increasingly reward organizations that have clear governance, good records, and fast operational response. Recommended actions: Audit cookies and consent architectureMap cookies/SDKs, re-validate legal bases, and prepare for “reject = no re-ask for months” logic. Re-check pseudonymisation and sharingDocument re-identification risk, control access to keys, and ensure contracts reflect technical reality. Strengthen AI compliance documentationLegitimate interest assessments, DPIAs where appropriate, transparency and objection handling, model training data governance. Prepare for Article 22 questionsIdentify where automated decisions have significant effects; document safeguards and human oversight. Unify incident responseBuild a single internal workflow that can serve multiple notifications, with clearly assigned roles and timelines. Conclusion The Digital Omnibus is framed as a simplification initiative, but it introduces meaningful changes across cookies, pseudonymised data, AI-related processing, data subject rights operations, automated decision-making, and cybersecurity reporting. For organizations, the right strategy is structured readiness: strengthen governance now so you can adapt quickly once the final text is agreed.

  • What’s Changing in the EU Suitability Assessment Rules - Joint EBA & ESMA Guidelines (Consultation Paper)

    On 25 February 2026, ESMA and the EBA published a consultation on revised joint guidelines for assessing the suitability of members of the management body and key function holders in banks and investment firms. The suitability guidelines themselves already exist: what’s new here is a set of targeted updates designed to reflect recent EU legal developments, expand and clarify supervisory expectations, and improve consistency across Member States. Below is a practical breakdown of the key changes. Alignment with updated EU prudential requirements (CRD) A major driver of the revision is alignment with the updated Capital Requirements Directive (CRD). The revised framework clarifies how institutions and supervisors should apply suitability requirements under the latest prudential rules, especially where the updated CRD introduces new expectations around governance and appointments. What this means in practice: more explicit links between legal requirements and the suitability process, clearer expectations on how assessments should be performed and evidenced. Wider focus on key roles beyond board membership The revised approach strengthens the focus on key function holders, including roles that may not sit on the board but have a critical impact on governance and control. In particular, the revisions emphasise suitability assessment expectations for senior control and financial roles (for example, internal control functions and senior finance leadership), reinforcing that governance risk isn’t limited to board appointments alone. Clearer approach for third-country branches The consultation also addresses how the suitability framework should apply in the context of third-country branches operating in the EU. This is important for groups with non-EU headquarters and EU branch structures, as it clarifies supervisory expectations around governance and key individuals in those branch setups. Stronger link to financial crime and AML/CFT considerations Another notable development is the clearer connection between suitability assessments and AML/CFT risk considerations. This doesn’t replace existing fit-and-proper principles, but it strengthens how institutions and supervisors should factor in integrity, reputation, and relevant risk signals when assessing individuals in senior positions. More harmonised documentation expectations Alongside the revised guidelines, the consultation package supports greater standardisation of what information is expected for suitability reviews (such as the structure/content of questionnaires, CV information, and supporting documentation). The practical outcome is likely to be: more consistent submissions to regulators, fewer jurisdiction-by-jurisdiction differences in what is considered “enough” evidence, clearer internal file standards for firms. Clarifications aimed at consistency and reduced friction The revised guidelines also include clarifications intended to improve: supervisory convergence (more consistent outcomes across the EU), operational clarity (who assesses what, when, and how), and overall efficiency, reducing avoidable administrative complexity where possible. Conclusion This consultation is a signal that EU supervisors want more consistent, better-documented, and more risk-aware suitability assessments, not only for boards, but also for senior roles that drive control, finance, and governance outcomes.

  • CySEC Circular C754: What CIFs Need to Know About the 2025 Cross-Border Reporting Requirement

    The Cyprus Securities and Exchange Commission (CySEC)  issued today its Circular C754 , introducing a targeted electronic cross-border reporting obligation for Cyprus Investment Firms (CIFs). The circular focuses on CIFs that provided cross-border investment services to retail clients  in other EEA Member States during 2025 . This development aligns with broader EU supervisory efforts to strengthen oversight of cross-border activities and enhance data consistency across Member States. Who Is in Scope? The requirement applies to CIFs that, between 1 January and 31 December 2025 , provided investment services on a freedom to provide services (FPS) basis to more than 50 active retail clients in at least one EEA Member State. Important clarification: “Retail clients” also include clients treated as professionals on request under MiFID II (opt-up clients). This means some firms may fall within scope even if their client base is not traditionally retail-focused. What Is Required? In-scope CIFs must participate in an electronic questionnaire  hosted on a dedicated EU reporting platform. The questionnaire will collect structured information on cross-border activities, enabling competent authorities to better assess scale, impact, and potential risks arising from such services. Immediate Action Required & Deadlines By Wednesday, 18 February 2026 , all CIFs must take one of the following actions : If in scope: Email riskstatistics.cifs@cysec.gov.cy  with a generic company email address  (e.g., compliance@ , info@ ). CySEC will then send the link to the electronic questionnaire. If not in scope: Formally notify CySEC at the same email address that the firm does not meet the threshold  (i.e., fewer than 50 active retail clients in any EEA Member State). Failure to respond whether in scope or not may be treated as non-compliance.

  • Regulatory Alert: CySEC Circular C751 – DORA Reporting, Governance Portal and Related Obligations

    CySEC has issued Circular C751 , providing targeted operational guidance on specific obligations arising under Regulation (EU) 2022/2554 (DORA) . The Circular focuses on four practical areas: ICT-related incident reporting, the Register of Information submission format, governance of the ICT risk management framework, and mandatory entries in the CySEC Portal. ICT-related incident reporting CySEC states that it has identified deficiencies in how regulated entities classify and report ICT-related incidents. In particular: incidents that should have been classified and reported as “major” were not reported; incidents were reported but incorrectly classified as major. Regulated entities are required to apply the classification criteria and materiality thresholds in Commission Delegated Regulation (EU) 2024/1772 and to ensure timely reporting upon detection of a major ICT-related incident. Register of Information – XBRL-CSV only CySEC reiterates that the “Build in Excel” file is no longer accepted. The Register of Information must be submitted exclusively in XBRL-CSV format, which is the only format accepted by the EBA. Key operational points: use XBRL-compatible software supporting mapping and validation against EBA rules; generate fully compliant XBRL files; zip the files and submit them via the CySEC XBRL Portal; submit annually by 28 February , with reference date 31 December of the preceding year. ICT risk management framework – governance, review and audit CySEC reminds regulated entities of their obligations under Article 6 DORA to establish, implement and maintain a documented ICT risk management framework. In particular: for non-microenterprises, ICT risk management and oversight must be assigned to a control function with appropriate independence and segregation from internal audit; the framework must be reviewed at least annually and following major ICT incidents, supervisory instructions or resilience testing and audit findings; a report on the review must be submitted to CySEC upon request and should be based on Chapter V of Commission Delegated Regulation (EU) 2024/1774 ; for non-microenterprises, the framework must be subject to regular internal audit, with a formal follow-up process for critical ICT audit findings; small and non-interconnected (Class 3) investment firms remain subject to a simplified ICT framework. CySEC Portal – mandatory designations Circular C751 introduces two specific operational obligations in the CySEC Portal: designation of the ICT auditor (for non-microenterprises) under the Auditors section, selecting “Is ICT”; designation of the person responsible for the ICT risk control function under the Personnel section. How ENAH Services Can Support ENAH Services supports regulated entities across the banking, payments, investment and fintech sectors with: DORA implementation and gap assessments ICT risk governance frameworks Incident reporting workflows and simulations ICT third-party risk management and contract reviews Board-level DORA readiness reporting Regulatory engagement and remediation programmes For further information or tailored DORA support, please contact us at consulting@enaservicesltd.com .

  • EU Pay Transparency Directive: What It Means for Employers and Employees in 2026

    In May 2023, the European Union adopted Directive (EU) 2023/970, a landmark piece of labour law aimed at tackling persistent gender-based pay disparities. Often referred to as the EU Pay Transparency Directive, its primary objective is to transform the principle of “equal pay for equal work or work of equal value” into enforceable practice through transparency, reporting, and accountability. Why This Directive Matters Despite decades of law promoting equal pay, wage inequalities across the EU persist. According to recent Eurostat figures, the average gender pay gap remains around 12 – 13 %, with notable differences across Member States. The Directive is designed to: Make pay practices transparent Equip workers with the right to information Expose unjustified pay gaps Encourage early correction and remedies In this way, transparency becomes a tool not just for disclosure, but for action. Key Deadlines Every Employer Should Know EU Member States must transpose the Directive into national law by 7 June 2026 . Only after this transposition will the specific obligations become enforceable at the national level. Once national laws are in place, employers need to prepare for phased pay gap reporting: 250+ employees: first reports due by 7 June 2027 (then annually) 150 – 249 employees: first report by 7 June 2027 (then every 3 years) 100 – 149 employees: reporting begins by 2031 (every 3 years) Member States may impose even stricter requirements or include smaller companies in reporting obligations. What Employers Will Be Required to Do Once implemented nationally, the Directive introduces several important duties: 1. Reporting on Gender Pay Gaps Employers with 100+ employees will need to publish detailed pay gap reports, covering: Average gender pay gap Gap in variable or supplementary pay Median and mean pay comparisons Distribution of men and women across pay quartiles   If a pay gap of 5 % or more  is identified and cannot be justified on objective, gender-neutral grounds, companies must take action to correct it within six months of reporting. 2. Salary Transparency in Recruitment Employers will be required to include salary ranges  in job postings and disclose the criteria used to determine pay. Potential and current employees should have the right to request information on pay comparisons for roles of equal value. This is intended to prevent discriminatory negotiation practices and reduce information asymmetry in hiring. 3. Objective Pay Setting The Directive strengthens the legal principle that equal work or work of equal value must be remunerated equally. Employers must rely on objective, gender-neutral criteria  when determining remuneration. How Employers Can Prepare Now With the June 2026 deadline approaching fast, preparation should begin immediately: Audit Current Pay Structures: Start collecting and analysing internal pay data by gender across all job categories. Establish Transparent Pay Policies : Create documented, objective criteria for salary decisions and ranges for roles. Engage HR, Legal & Compliance: Integrate reporting and compliance tasks into your HR and governance frameworks. Educate Leaders and Employees: Build internal understanding of the Directive’s requirements and expectations. Conclusion The EU Pay Transparency Directive marks a significant shift from “equal pay as a principle” toward equal pay as proof. It places employers and policymakers on a shared journey toward measurable gender pay equity, backed by enforceable transparency measures and accountability. For employers operating across the EU and HR professionals supporting them early action is not only wise, it’s essential. Compliance will require strategic planning, cultural change, and robust data management, but it also presents a unique opportunity to lead on fairness and equity in the workplace.

bottom of page