No spam - just the latest insights!
Join over 30,000 industry professionals who subscribe for free
Subscribe for free!
We'll never share your information or send you spam
Niall Esler is partner and head of the regulatory group in Walkers’ Ireland office and a member of the Walkers fintech group. He specialises in Irish and EU financial services regulation with a particular focus on the regulation of fintech, investment services and banking services. Niall advises domestic and international financial institutions including fintechs, payment/e-money institutions, credit institutions, investment firms, asset managers, funds and crypto-asset service providers. He is a member of the Incorporated Law Society of Ireland, the Compliance Institute, the Irish Funds Investment Firms Working Group and the Blockchain Ireland Legal Working Group on Digital Assets.
Shane Martin is partner in the regulatory group in Walkers’ Ireland office. He has significant experience in regulatory risk and compliance advising domestic and international financial services firms, including fintechs, across the banking, funds, asset management, payment services, crypto-assets and credit union sectors. Prior to joining Walkers, Shane worked for a number of years for the Central Bank of Ireland, where he managed a specialist anti-money laundering supervision team. He is a member of the Incorporated Law Society of Ireland, the Compliance Institute and the FATF Private Sector Consultative Forum.
Laura Whitson is based in Walkers’ Ireland office, where she is an associate in the regulatory group. She advises on Irish and EU financial regulation and compliance, acting for domestic and international credit institutions, investment firms, international payment/e-money institutions, crypto-asset service providers, asset managers and other institutions.
Ireland is considered a fintech hub and is home to globally recognised technology and financial services firms. Recent years have seen continued growth in fintech activity in Ireland and in the number of entities operating in the country, reflecting the positive ecosystem that has developed.
In addition to the growing number of Irish fintechs, Ireland is a popular location for non-European Union (“EU”) firms (particularly from the United States (“US”)) seeking to establish an EU base which has increased further following the United Kingdom’s withdrawal from the EU. These international fintechs will seek to become authorised in Ireland and then “passport” that authorisation so as to provide services into other EU Member States, as well as in Ireland.
International financial services companies have set up research and development operations in Ireland focusing on themes such as the utilisation of blockchain, crypto, and artificial intelligence (“AI”). BNY Mellon announced the establishment of a new Digital Research and Development Hub in Dublin that will drive innovation in the areas of AI, machine learning, and data analytics. Mastercard’s European Technology Hub and Citi’s Global Innovation Labs are based in Dublin and are investing in emerging areas such as AI, cybersecurity, blockchain and virtual reality. Furthermore, Fidelity Investments’ Center for Applied Technology lab has a base in Ireland and provides technology and operational business services to the US in areas such as cloud, cybersecurity, digital assets, AI and the metaverse.
The Irish government has actively supported the growth of the financial services sector in Ireland, which includes a focus on fintech. The strategy titled “Ireland for Finance,” aimed at developing the international financial services sector through 2026, incorporates initiatives to promote fintech and blockchain technologies. In March 2024, an updated version of the Ireland for Finance Action Plan was published, outlining 13 action measures across five interconnected themes: Sustainable Finance, Fintech and Digital Finance, Diversity and Talent, Regionalisation and Promotion, and Operating Environment. Previous updates to this plan also included provisions for fintech development.
Further developments from the government include the appointment of Neale Richmond as the Minister of State at the Department of Finance, with specific responsibilities for financial services, credit unions, and insurance as of 10 April 2024. This appointment marks a strategic move towards Ireland’s ongoing efforts to enhance its presence in the global fintech sector.
On 15 October 2024, the Minister for Finance introduced the National Payments Strategy for Ireland, addressing topics such as the ongoing role of cash in society, payment fraud, and future payment methods. The key objectives of the strategy include enhancing access and choice to payment options, focusing on security and resilience of the payment systems, encouraging the adoption of innovative payment technologies and ensuring they are inclusive and accessible to all users, as well as development payment solution that are sustainable and efficient. The strategy outlines a vision for a resilient payments ecosystem by 2030 and includes a roadmap for implementation.
The Central Bank of Ireland (the “Central Bank”), as the national regulatory authority of financial services firms, established its Innovation Hub in 2018 to provide firms, engaged in the Fintech and innovation space, with a point of contact outside of the existing formal engagement processes. The Innovation Hub 2023 Update notes that by the end of 2023, the Central Bank Innovation Hub held 389 engagements across a number of sectors, including Payments, RegTech, Blockchain, Crypto and InsurTech.
The Central Bank has recently established an Innovation Sandbox Programme to inform the early-stage development of selected innovative initiatives and provide regulatory advice and support to firms on their innovative projects. The Innovation Sandbox Programme will take a thematic approach. The theme of the first programme is “Combatting Financial Crime” and applications have opened on the Central Bank website. The Sandbox Programme framework comprises workshops, ongoing bespoke engagement with dedicated Sandbox Relationship Managers, and access to data platforms.
On 29 February 2024, the Central Bank published its Regulatory Supervisory Outlook Report for 2024 which provides a sector-by-sector analysis, including specific sections on payments and e-money institutions. A number of the key supervisory activities for 2024/2025 specific to payments and e-money institutions include:
The Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, as amended (“CJA 2010”) implements European anti-money laundering and countering the financing of terrorism (“AML/CFT”) rules into Irish law. The CJA 2010 was amended in 2021 to implement the EU’s Fifth AML Directive (“5AMLD”) to include a registration requirement for Virtual Asset Service Providers (“VASPs”), which include persons engaging in exchange services between virtual assets and/or virtual assets and fiat currencies, transfers of virtual assets, the provision of custodian wallet services and/or participation in, and provision of, financial services related to an issuer’s offer or sale of virtual assets. It should be noted that the VASP registration requirement is not an authorisation by the Central Bank but merely a registration for AML/CFT purposes.
The Markets in Crypto-Asset Regulation (“MiCA”) introduces an EU harmonised legislative framework for crypto-assets and related activities and services. MiCA creates a regulatory framework for the following activities and services:
MiCA creates a harmonised definition of “crypto-asset” (i.e. “a digital representations of value or rights which may be transferred and stored electronically, using distributed ledger technology (“DLT”) or similar technology”) and divides in-scope tokens into three categories: Electronic Money Tokens; Asset-Referenced Tokens; and all other crypto-assets which includes utility tokens. Crypto-assets which fall within existing financial services legislation are not regulated under MiCA.
The provisions regarding the regulation of stablecoin issuers apply since 30 June 2024 and the remainder of the provisions under MiCA will apply from 30 December 2024.
Entities which are registered and operating as a VASP in Ireland will be permitted, post 30 December 2024, to avail of a transitional period enabling them to continue to operate until 30 December 2025 or until their CASP authorisation is granted or refused, whichever is sooner. Following the transitional period the VASP regime under the CJA 2010 will be made redundant, as VASP entities will be required to obtain a CASP authorisation.
Tokenisation
Tokenisation of assets is a hot topic. Prominent use cases include tokenised real-world assets, stablecoins, central bank digital currencies, tokenised deposits and tokenised debt instruments.
The Central Bank has acknowledged that tokenisation has the potential to speed up settlement cycles and increase efficiency and liquidity of trading in assets, as well as bringing potential benefits to investors in terms of ease of access to financial products and lower costs. The Central
Bank is supportive of understanding how tokenisation and related technology can bring benefits to both firms and investors and has engaged with the funds industry to explore pathways and the potential of tokenisation for investment funds, in particular to understand how tokenisation will sit within the existing regulatory framework.
The Central Bank confirmed in its Regulatory Supervisory Outlook Report 2024, that while there is clear potential for DLT and tokenisation to benefit the functioning of the financial system, given the volatility of crypto there are also risks to consumers and retail investors, and therefore this will be a focus for the Central Bank’s key supervisory activities in 2024/2025.
Financial instruments issued by means of DLT will fall within the existing investment services regime set out in the European Union (Markets in Financial Instruments) Regulations 2017, which implements Directive 2014/65/EU (“MiFID II”) into Irish law.
As part of the Digital Finance Package, the EU DLT pilot regime commenced in March 2023 which provides the legal framework for trading and settlement of transactions in crypto-assets that qualify as financial instruments under MiFID II. This sandbox regime further facilitates the set-up of new types of market infrastructures. These market infrastructures include DLT multilateral trading facilities, DLT settlement systems, and DLT trading and settlement systems. In addition to already authorised investment firms, market operators and central securities depositories (“CSDs”), new entrants may apply for temporary authorisations as investment firms/market operators or CSDs, alongside an application under the DLT Pilot Regime.
ESMA published a letter to the European Commission, providing an update on the uptake of the DLT pilot regime and notes that as of April 2024, four official applications have been submitted, with eight further applications to be expected to be submitted during 2024. ESMA notes that the novelty of the regime in combination with certain
challenges may explain the slow uptake.
In the securities lending and repo space, the concept of utilising tokenised instruments for settlement purposes has developed into an interesting use case for tokenised assets. To this end the International Capital Market Association has published the Digital Asset Annex which aims to bring consistency to the legal terms used by market participants when trading certain digital assets under the Global Master Repurchase Agreement 2011 and Global Master Securities Lending Agreement 2010. The Digital Assets Annex provides a standardised framework for the use of digital cash or asset-backed digital assets, including tokenised traditional securities, for securities lending and repo transactions.
Digital Operational Resilience
There has been an increasing focus by supervisory authorities on digital operational resilience and cybersecurity in the financial sector. Regulators are recognising that the financial sector is increasingly dependent on information and communication technology (“ICT”) tools and systems to deliver their services. In order to address the increasing ICT risk to financial institutions and the sector at large, the EU Digital Operational Resilience Act (“DORA”) entered into force in January 2023 and will apply from 17 January 2025.
DORA applies directly to certain “financial entities” with the objective of ensuring that those entities operating in the EU financial services industry can withstand, respond to and recover from all types of ICT-related disruptions and threats. DORA also applies requirements to service providers to the financial services industry which are designated as critical ICT third-party service providers. These critical service provides will be subject to an oversight framework by the European Supervisory Authorities. This is a noteworthy development for the technology industry as the providers will face a form of supervision under this financial services regime, even though they do not themselves provide financial services.
DORA aims to address ICT risk by targeting five pillars,
including:
Furthermore, the technical, operational and organisational cybersecurity measures contained in the Directive (EU) 2022/2555, referred to as NIS 2, replaces the Network and Information Security Directive, and sets out requirements in relation to cybersecurity and incident reporting of operators of essential services and digital services providers, which includes cloud computing service providers.
Instant payments / PSD3
The Instant Payments Regulation entered into force on 8 April 2024, with a phased implementation schedule extending from January 2025 to July 2027. It aims to ensure that instant euro payments are accessible to both consumers and businesses throughout the EU by amending existing EU payments regulations.
In alignment with the Digital Finance Strategy and the Retail Payments Strategy, the European Commission is actively reviewing the EU Payment Services Directive 2 (“PSD2”). On 28 June 2023, the European Commission proposed a revised payment services package, which includes a Payment Services Directive 3 (“PSD3”), a Regulation on payment services, and a Regulation on a framework for financial data access. The proposed legislative texts will impact a range of areas, including fraud prevention requirements and the merging of legal frameworks that apply to e-money institutions and payment institutions. Under PSD3, it is proposed that e-money institutions will be licensed as payment institutions, and that the E-Money
Directive 2 will be repealed.
The PSD3 legislative package is progressing through the legislative process for final approval by the EU institutions. Contributing to progressing the review of PSD2 is also part of the Central Bank’s key supervisory priorities for 2024.
Crowdfunding and Lending
The Regulation (EU) 2020/1503 (the “Crowdfunding Regulation”) creates a designated EU regulatory framework for equity and peer-to-peer lending-based crowdfunding within the EU and allows operators of crowdfunding platforms to obtain authorisation as a crowdfunding service provider (“CSP”), which can be passported across the EU. The Crowdfunding Regulation came into force on 10 November 2021 and the transitional period ended on 10 November 2023 for existing providers who have sought authorisation. As of November 2024, the Central Bank has authorised six CSPs pursuant to the Crowdfunding Regulation.
In order to address the growing Buy Now Pay Later market in Ireland, the Consumer Protection (Regulation of Retail Credit and Credit Servicing Firms) Act 2022 commenced on 16 May 2022 and widened the scope of the retail credit firm regime to include firms offering “indirect credit” (e.g. the provision of credit to a borrower by paying a retailer on behalf of a consumer for the purchase of a good or service as part of a “buy now, pay later” offering).
Artificial Intelligence
On 9 December 2023, the European Parliament and the Council of the EU reached a provisional agreement on the Artificial Intelligence Act (“AI Act”), which was subsequently approved in its final form on 21 May 2024. The AI Act entered into force on 1 August 2024, with most of its provisions set to apply two years after this date, although certain exceptions apply. The AI Act establishes a regulatory framework aimed at harmonising rules for AI across the EU. It seeks to regulate both providers who market or deploy AI systems within the EU and users of these systems, ensuring that fundamental rights, democracy, the rule of law, and environmental sustainability are safeguarded against high-risk AI applications while fostering innovation in the sector.
In its Regulatory and Supervisory Outlook Report 2024, the Central Bank highlighted plans to enhance its policy framework and supervisory expectations regarding the use of AI in financial services, particularly in preparation for the implementation of the AI Act. The Central Bank aims to gain insights into how firms are utilising AI to deliver and support existing financial services, and explore potential applications for new products, services, and business models. Adjustments to its supervisory framework will be made as necessary based on practical experiences with AI deployment to maintain effective regulatory oversight.
In 2021, the Irish government launched the ‘National AI Strategy’ which aims to drive AI adoption in enterprise and public services, including creating a supportive innovation ecosystem and a secure data and connectivity infrastructure. On 6 November 2024, the Irish government revised its National AI Strategy. Updates include seeking to ensure that Ireland is a leader in the effective implementation of the EU AI Act, including through constructive participation in the EU AI Board and its working groups, rolling out AI standards and certification and establishing an AI regulatory sandbox to foster innovation in AI.