# Complyfirst | About Us

> Complyfirst is the #1 reporting platform for PIs, EMIs, and banks, trusted by leading financial institutions in multiple jurisdictions.

# We make reporting _one less thing_ to worry about.



# 

Complyfirst is the reporting platform we always needed. Reporting in payments and e-money has always been messy with high-stakes of getting it right. We're on a mission to change that.

## Who we are, and _why we exist_



We’ve been in your shoes.



Between us we have over 10 years of experience in compliance across Goldman Sachs, Citi, and UK and EU fintechs. 



Fiona has secured regulatory licences, built compliance programs from the ground up, and worked with global regulators. She is a Barrister in England & Wales and a Certified Anti-Money Laundering Specialist.



Dan worked as an FX and Interest Rates Sales/Trader at Goldman Sachs and later built software and integrated with the Bank of Lithuania. He is a self-taught developer with an economics background.



With Complyfirst, we’re building the reporting platform we always wanted for ourselves.  
  
**Fiona & Dan Jelly**  
Founders of Complyfirst

```json
{
  "_key": "eabf1655a90f",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "OUR IMPACT"
    }
  ]
}
```

## Complyfirst's _impact_ at a glance

### average reduction in reporting efforts for our clients

### of hours saved in regulatory, tax, internal, and audit reports

### jurisdictions supported by our platform (and counting)

```json
{
  "_key": "6c23d6f31ed5",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "OUR BRAND VALUES"
    }
  ]
}
```

## What we _stand for_

### Your win is our win

We only succeed if you do. Your success is the metric that matters most. Everything we do, we do to make compliance teams’ lives easier.

### Trust & reliability

Trust is everything in this industry. We’re building a platform and providing support that you can rely on, always.

### Human in-the-loop, always

We believe the best systems combine automation with expertise. We automate the repetitive and leave judgement with the experts.

### Straight talking, no jargon

Compliance is complicated enough. We explain things clearly, skip buzzwords, and tell you what you need to know.

### Find a way

We’re doers. When something’s messy, unclear, or never been done before, we roll up our sleeves and take on the challenge.

### Serious without a suit

Compliance is serious business, but we keep things human, approachable, and real.

## Want to join us?



We’re growing fast and always looking for people who are exceptional at what they do. View our open roles and get in touch.



```json
{
  "_key": "7eac9c03e053",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "/careers",
      "label": "View open roles",
      "variant": "contained"
    }
  ]
}
```

## Submit your _first report_ with Complyfirst  
  

  
Regulatory, tax, audit, fraud, or custom reports. There’s no report we can’t handle.  
  



```json
{
  "_key": "f3e50e793ccf",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/demo",
      "label": "Get in touch",
      "variant": "contained"
    }
  ]
}
```

---
Source: https://complyfirst.co/about-us

---

# Complyfirst Careers

> Complyfirst is the go-to reporting platform for regulated financial firms. We're hiring. Come build with us.

**Join the team**

#  

# We're fixing compliance reporting. _For good._

## A word from our _founders_

We won't pretend compliance reporting is glamorous. But solving a problem that every regulated firm in the world has, and doing it better than anyone else... **is**. 



Compliance reporting is a problem every bank, payments firm, and regulated institution you can think of faces, yet nobody has solved it properly. We’re fixing that.



We’re growing fast, our clients are some of the biggest names in finance and we’re just getting started.



We’re a small team. Everyone owns their work from day one. We move fast and we care deeply about getting it right.



If that’s the kind of bet you want to be part of, let’s talk.

****

**Fiona & Dan Jelly**  
Founders of Complyfirst

```json
{
  "_key": "47ecb33137f4",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "OPEN ROLES"
    }
  ]
}
```

## Come build _something big_

# 

Compliance reporting touches every regulated institution on the planet. We’re the team building the infrastructure that powers it. Come help us build it.

#  

```json
{
  "_key": "acb82cb3057c",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "/careers/open-positions",
      "label": "See open positions",
      "variant": "contained"
    }
  ]
}
```

```json
{
  "_key": "dda26f59a564",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "OUR VALUES"
    }
  ]
}
```

## How we _work_

  
This is what we expect from each other.

### Obsess over customer wins

We’re hands-on with our customers in a way most software companies aren't. This closeness is what keeps us ahead of the market how we're building the best software.

### Ownership from day one

You don’t wait to be told what needs doing. You see the problem, you own the fix, and you see it through from start to finish.

### Fast, without compromise

Speed matters, and so does accuracy. At Complyfirst, we're building a team of experts that know how to balance the two.

### Thrive under pressure

Regulatory deadlines are fixed and the stakes are real. If pressure brings out the best in you, you'll fit right in.

### Never stop learning

We’re growing fast and the people who grow with us are the ones who treat every challenge as a chance to get sharper, not a reason to slow down.

### Run through walls

We don’t have perfect resources or perfect conditions, and we don’t use that as an excuse. When something needs to happen, we make it happen.

```json
{
  "_key": "361d01e27417",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "BENEFITS & PERKS"
    }
  ]
}
```

## What _you get_

- Salary that reflects your impact
- Private medical care
- Professional growth budget
- Flexible paid leave
- Hybrid working model
- Autonomy from day one

## No role that fits? Apply anyway.

   
We’re growing fast and always looking for people who are exceptional at what they do. Send us your CV and make the case for yourself.  
    
 

```json
{
  "_key": "040cb612f27f",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "mailto:jobs@complyfirst.co",
      "label": "Send us your CV",
      "variant": "contained"
    }
  ]
}
```

## FAQs

```json
{
  "_key": "4cfed4680336",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "72e9ef0638ce",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "4fb6314b2abf",
          "_type": "block",
          "children": [
            {
              "_key": "1ab5ddb5ea21",
              "_type": "span",
              "text": "We’ll start off with an intro call to get to know each other. If the role feels like a good fit, we’ll ask you to complete a short (and paid) assignment, introduce you to the team, and then move to a final discussion."
            }
          ],
          "style": "normal"
        }
      ],
      "title": "What's the hiring process like?"
    },
    {
      "_key": "1feb70d41381",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "de7727807437",
          "_type": "block",
          "children": [
            {
              "_key": "b448ef7bd420",
              "_type": "span",
              "text": "We’re hybrid. We come into the office 3 times a week and work remotely twice a week."
            }
          ],
          "style": "normal"
        }
      ],
      "title": "Are Complyfirst roles remote or in-office?"
    },
    {
      "_key": "4b0749c49282",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "54f8aeeac0f0",
          "_type": "block",
          "children": [
            {
              "_key": "9d4bf97f9c74",
              "_type": "span",
              "text": "That’s okay. If you’re excited about the role and confident you can grow into it, we still encourage you to apply."
            }
          ],
          "style": "normal"
        }
      ],
      "title": "What if I don’t meet every requirement?"
    },
    {
      "_key": "38fc52345b55",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "5f8a12950265",
          "_type": "block",
          "children": [
            {
              "_key": "f58529b4eb17",
              "_type": "span",
              "text": "Not necessarily, but you do need to be comfortable being scrappy, taking ownership, and figuring out challenges that are new to you."
            }
          ],
          "style": "normal"
        }
      ],
      "title": "Do I need startup experience?"
    }
  ]
}
```

#

---
Source: https://complyfirst.co/careers

---

# Account Executive Position

# Account Executive

#### About Complyfirst

Complyfirst is an AI-powered reporting automation platform for compliance teams in financial services. Use cases include regulatory reporting, suspicious activity reporting, fraud reporting and more. Our founders are a former Head of Compliance and CTO who lived the problem firsthand. Our clients include Bank of China, SumUp, TrueLayer, Corpay, Rippling and more. We grew almost 6x last year and are building the team to match.



#### Role Overview

We're hiring our first Account Executive. You'll report directly to the CEO and be responsible for the full sales cycle - generating pipeline, discovery and demo calls, and closing deals. You'll initially inherit a foundation of warm relationships, active prospects, and a product that sells itself to the right buyer.



This is a genuine ground-floor opportunity to get into a fast-growing AI and compliance start-up with a limited pool of credible competitors. If you know financial services compliance and you know how to sell, the conditions here are as good as they get.



One thing worth knowing: we sell in an anti-sales way. Compliance professionals are allergic to being pitched at, so we don’t pitch. We treat prospects like colleagues. We do our research before every call, come in with a point of view on their specific situation, and ask good questions. The conversation is informal and collegiate. You need to be comfortable with a more consultative motion and you need to understand the regulatory world well enough to have a genuine opinion on it.



#### What You'll Do

- **Own pipeline generation. **Research and prioritise target accounts (payment and e-money firms, banks, investment firms) and run outbound to get into conversations.
- **Run the full sales cycle. **From first outreach through discovery, demo, proposal, negotiation, and close. You will own every stage.
- **Run credible discovery conversations. **Understand a prospect's reporting obligations and operational setup well enough to map Complyfirst's product to their specific problems.
- **Manage pipeline and forecast accurately. **Keep CRM updated, prioritise ruthlessly, and give the business visibility on what's coming.
- **Feed back to product. **You're closest to the prospect. What objections keep coming up? What features would unlock deals? That intelligence needs to reach the team.
- **Work the market. **Industry events, LinkedIn, warm introductions. You're building a presence in the compliance and payments space, not just working a list.



#### What We're Looking For

- **Relevant domain knowledge. **You have worked in or sold into financial services - payment institutions, e-money institutions, banks or similar profile of firm. You understand what compliance reporting means in practice and can hold a credible conversation about without needing a briefing document.
- **A track record of closing. **You've run a sales cycle end to end and you have numbers to show for it. Pipeline generation and deal closure (not just relationship management).
- **3+ years in a quota-carrying sales role. **B2B SaaS or fintech/regtech preferred. You've sold to compliance, finance, or operations buyers at regulated firms.
- **Self-starter. **You don't need an SDR team, a large marketing budget, or a fully built playbook. You build the pipeline and you close it.
- **Clear communicator. **Written and verbal. Our buyers are sophisticated. Vague or generic sales communication does not work here.
- **The right sales instincts. **You know that compliance buyers cannot be pitched at. You do your research before every call, come in with a hypothesis on how you can help, and let the conversation develop from there. Strategic, informal, and consultative - not transactional.



#### This Role Is Not For You If…

- You have no background in financial services or compliance and are not prepared to invest in learning it quickly.
- You need an SDR to generate pipeline for you.
- You are looking for a large team, an established process, or a fully built sales playbook.
- Your track record is in relationship management or account management rather than new business generation.
- You need clear targets and defined territory before you can get started.
- Your idea of outreach is a generic sequence blasted to a list. Our buyers will ignore it and we will lose credibility in the market.



#### What We Offer

- Competitive base salary plus uncapped commission
- Private medical insurance
- Hybrid working (3 days / week in our Hillsborough, NI office)
- 35 days holiday (inclusive of bank holidays)
- Company laptop
- Equity options available
- Genuine ownership of the commercial function in a fast-scaling regtech



#### How to Apply

Send your CV to jobs@complyfirst.co. Tell us what you've sold, who you've sold to, and what the numbers looked like.

## Is this role not a perfect fit, but you still want to apply? 

  
We’re growing fast and always looking for people who are exceptional at what they do. Send us your CV and make the case for yourself.  
      
  

```json
{
  "_key": "79ca9dfb5829",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "mailto:jobs@complyfirst.co",
      "label": "Send us your CV",
      "variant": "contained"
    }
  ]
}
```

---
Source: https://complyfirst.co/careers/account-executive

---

# AI Data Scientist Position

# AI Data Scientist

#### About ComplyFirst

Complyfirst is a reporting automation platform for financial services compliance teams. We remove 80% of manual reporting work so teams can focus on reviewing, not doing. We grew almost 6x last year and are hiring across the business.



#### Role Overview

We’re hiring an AI Data Scientist to work directly with our CTO and engineering team. Your job is to design, build, and ship AI and ML models that make our compliance product meaningfully smarter - from automating document interpretation to improving how we detect and flag suspicious activity.



This is a hands-on role. You’re not here to research. You’re here to build things that work in production and make a measurable difference to what our clients can do.



#### What You’ll Do



- **Build and ship AI/ML models. **Design, train, and deploy models that power core product features - from document parsing and classification to anomaly detection and narrative generation.
- **Own the full model lifecycle. **From problem definition through to production. You’re responsible for what you build, including monitoring, iteration, and improvement after it ships.
- **Work directly with engineering. **Collaborate closely with the dev team to integrate models into the product cleanly. You understand how your work fits into a production system.
- **Push our AI roadmap forward. **Work with the CTO to identify where AI can have the biggest impact on the product and build the case for what we build next.
- **Stay ahead of the field. **The AI landscape moves fast. You track what matters, cut through the noise, and apply what’s genuinely useful.



#### What We’re Looking For



- **Real world experience **building and deploying AI/ML models in a production environment — not just research or experimentation.
- **Strong Python skills. **You’re comfortable with the modern ML stack: PyTorch or TensorFlow, LangChain or similar, and the tooling around it.
- **Experience with LLMs. **You’ve worked with large language models in a product context — fine-tuning, RAG, prompt engineering, or building pipelines around them.
- **High agency. **You define the problem, propose the approach, and execute. You don’t need the work handed to you.
- **Commercial instinct. **You care about whether your work actually moves the product forward, not just whether the model performs well in evaluation.
- **Clear communicator. **You can explain what you’re building and why to non-technical stakeholders without losing the detail that matters.



#### This Role Is Not For You If…

- You’ve worked primarily in research or academic settings and haven’t shipped models into production.
- You need a large data team around you to get things done.
- You’re looking for a clearly scoped role with well-defined problems. We’re still figuring out a lot of this.
- You’re not comfortable working in a fast-moving, early-stage environment.



#### What We Offer

- Competitive salary, based on experience
- Private medical cover
- Hybrid or fully remote roles available
- 35 days holiday (inclusive of bank holidays)
- Company laptop
- Outsized responsibility and growth, from day one



#### How to Apply

Send your CV to dan@complyfirst.co. Include links to work you’re proud of — models you’ve shipped, repos, papers, anything that shows how you think and build.

## Is this role not a perfect fit, but you still want to apply? 

  
We’re growing fast and always looking for people who are exceptional at what they do. Send us your CV and make the case for yourself.  
      
  

```json
{
  "_key": "9434719e09f0",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "mailto:jobs@complyfirst.co",
      "label": "Send us your CV",
      "variant": "contained"
    }
  ]
}
```

---
Source: https://complyfirst.co/careers/ai-data-scientist

---

# Chief of Staff Position

# Chief of Staff

#### About Us

Complyfirst is a reporting automation platform for financial services compliance teams. We remove 80% of manual reporting work so teams can focus on reviewing, not doing. We grew almost 6x last year and are hiring across the business.

####    
Role Overview

We're hiring a Chief of Staff to work directly with the CEO. Your job is to give the CEO leverage - by keeping focus on what matters, unblocking what's stuck, and making sure commitments get delivered. If you move fast, thrive in ambiguity, and take personal ownership of outcomes, this is for you.

####   
What You’ll Do **  
   
 **

- **Run the CEO's priorities.** Translate the CEO’s vision into structured plans and actions. Help prepare for meetings and protect the CEO's time. Booking travel one day, preparing a board update the next - nothing is beneath you.
- **Own execution.** Track key workstreams, hold owners to account, and make sure nothing falls through the cracks.
- **Support commercial activity.** This includes research, outreach, proposal drafting, preparing for demos, and helping move deals forward.
- **Lead special projects.** Own strategic projects end to end: market entry, product launches, hiring pushes. You own the outcome, not just the coordination.
- **Build and document systems.** Spot where things are ad hoc or stuck in someone's head. Systematise it. Document it in Confluence.
- **Support hiring and onboarding.** Help recruit, onboard, and get new hires productive fast.



####   
What We’re Looking For

- **5+ years of relevant experience.** You've done real work in a real business and have enough experience to have seen things break and know how to fix them.
- **You’re T-shaped:** you’re an expert in one discipline (marketing, sales, product, ops etc) and dangerous in the rest. You can run a board memo, manage a hiring process, and work through a financial model in the same week. You don't have a lane - you have range.
- **Extreme ownership:** if something fails on your watch, you fix it. You close loops without being asked.
- **Systems thinker:** You spot inefficiency and build structure. You don't just complain about problems.
- **Technically comfortable:** Not a technical hire, but you pick up new tools fast and use AI to move faster.
- **Discreet and trustworthy:** You'll be across investor relations, legal matters, and hiring decisions. Discretion is non-negotiable.

####   
This Role is Not For You if…

- You need a defined remit or stable scope.
- You need clarity before you start. Ambiguity is the default here.
- You’re used to reporting statuses instead of driving outcomes.
- You're looking for a strategy-only role. This role gets hands dirty.



#### What We Offer

- Competitive salary, based on experience
- Private medical insurance
- Hybrid work - 3 days per week in our Hillsborough, NI office
- 35 days holiday (inclusive of bank holidays)
- Company laptop
- Outsized responsibility and growth, from day one



#### How to Apply

Email us at **jobs@complyfirst.co** with the following information:  
  


1. Your name
2. The Position you’re applying to
3. An Attached CV
4. Your Linkedin Profile Link

## Is this role not a perfect fit, but you still want to apply? 

  
We’re growing fast and always looking for people who are exceptional at what they do. Send us your CV and make the case for yourself.  
      
  

```json
{
  "_key": "4eceb77ba12c",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "mailto:jobs@complyfirst.co",
      "label": "Send us your CV",
      "variant": "contained"
    }
  ]
}
```

---
Source: https://complyfirst.co/careers/chief-of-staff

---

# Pre-Sales Compliance Consultant Position

# Pre-Sales Compliance Consultant

#### About Complyfirst

Complyfirst automates regulatory reporting, suspicious activity reporting workflows, and fraud case management for multi-licensed financial services firms. We were built by a compliance head and a CTO who lived the problem firsthand. Our clients include Zen, SumUp, Rippling, and TrueLayer. We grew almost 6x last year and are building the team to match.



#### Role Overview

We are hiring a Pre-Sales Compliance Consultant to work alongside our Account Executive and CEO in the sales cycle. Your job is to own the credibility side of every deal. When a prospect asks a hard question about compliance reporting, you are the person in the room with the answer.



Our buyers are Heads of Compliance, MLROs, CFOs, and COOs at regulated financial services firms. They are domain experts, and they will test you. What wins deals at this level is not a polished demo or a sharp deck – it’s a conversation between people who understand the same regulatory reality. That is what you bring.



You will work as a unit with the Account Executive. They own pipeline, relationship, and commercial close. You own the demonstration that the product actually solves the problem. Together you cover the full buying committee.



#### What You'll Do

- **Own the compliance side of every deal. **Join discovery calls to understand a prospect's compliance reporting obligations, existing setup, and compliance function in depth. Ask the questions that reveal the real problem and map it to what we can do.
- **Run tailored product demonstrations. **Configure demos around the prospect's specific context, not a generic walkthrough. A regulatory reporting demo for a Dutch PSP looks different from an SAR reporting demo for a Lithuanian EMI. You know the difference.
- **Handle regulatory objections in the room. **When a prospect pushes back on product capability, you respond with authority, because you know the answer.
- **Own procurement responses. **Take the lead on due diligence questionnaires, and security assessments. Our buyers at larger regulated firms run structured procurement processes and expect thorough, accurate responses.
- **Feed intelligence back to product. **You hear more technical and regulatory detail from prospects than anyone else. What is coming up repeatedly? What would close more deals? That needs to reach the founders and the dev team.



#### What We're Looking For

- **Hands-on compliance or regulatory reporting experience. **You have worked in compliance, regulatory reporting, or financial crime or similar function at a payment institution, e-money institution, bank, or consultancy serving them. You understand regulatory reporting, SAR reporting, fraud reporting and basic things, like AML frameworks from having worked with them, not just read about them.
- **Credibility in the room. **You can sit across from a Head of Compliance and answer their hardest questions, and hold your own. They will probe. You need to be the most knowledgeable person in that conversation.
- **The right sales instincts. **We sell in an informal, consultative way. No pitch slapping. You do your research before every call, come in with a point of view on the prospect's specific situation, and let the conversation develop from there. Compliance buyers are allergic to being sold at.
- **Clear and confident communicator. **You can simplify regulatory complexity for a C-suite exec who does not live in the detail and you can also go deep with a Head of Compliance who does.
- **3+ years of relevant experience. **In compliance, regulatory reporting, financial crime, or a specialist consultancy serving regulated firms. Experience in a commercial or client-facing role is a strong advantage.



#### This Role Is Not For You If…

- You have not worked directly with compliance reporting obligations and are not prepared to invest hard in learning the domain quickly.
- You have limited regulatory knowledge. Our buyers will see through that immediately.
- You want a clearly defined advisory role with no commercial accountability. This role exists to help close deals.
- You are not comfortable operating in an early-stage environment where the playbook is still being written.
- You need a large team around you to get things done.



#### What We Offer

- Competitive salary, based on experience
- Private medical insurance
- Hybrid (3 days / week from our Hillsborough, NI office)
- 35 days holiday (inclusive of bank holidays)
- Company laptop
- Equity options available
- A front-row seat in a fast-scaling regtech where your domain knowledge directly drives commercial outcomes



#### How to Apply

Send your CV to jobs@complyfirst.co. Tell us where you have worked in compliance or regulatory reporting, what obligations you have dealt with, and why this kind of role interests you.

## Is this role not a perfect fit, but you still want to apply? 

  
We’re growing fast and always looking for people who are exceptional at what they do. Send us your CV and make the case for yourself.  
      
  

```json
{
  "_key": "ea93bb6371e9",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "mailto:jobs@complyfirst.co",
      "label": "Send us your CV",
      "variant": "contained"
    }
  ]
}
```

---
Source: https://complyfirst.co/careers/presales-compliance-consultant

---

# Senior Full Stack Developer Position

# Senior Full Stack Developer

#### About Us

Complyfirst is a reporting automation platform for financial services compliance teams. We remove 80% of manual reporting work so teams can focus on reviewing, not doing. We grew almost 6x last year and are hiring across the business.

####    
Role Overview

We’re hiring a Senior Full Stack Developer to work directly with our CTO. You’ll be one of the most important technical hires we make - helping architect and build the product as we scale. This role requires deep experience in PHP, Laravel, and Vue.js, and the ambition to build something genuinely world-class.

# 

#### What You’ll Do

# 

- **Architect and build. **Design, develop, and maintain high-performance, secure applications. You own the quality of what ships.
- **Drive AI integration. **Design and build AI-powered features that push our compliance automation further. This is a growing part of what we do.
- **Own the full stack. **Front to back. You’re comfortable across the stack and don’t need to hand off to get things done.
- **Set the technical bar. **Hold the standard on code quality, security, and performance. Shape the technical roadmap alongside the CTO.
- **Work across the business. **Work closely with founders, engineers, and the product team. We’re small — everyone has context and everyone has a voice.



#### What We’re Looking For



- **5+ years of experience. **In professional software development, with strong expertise in PHP, Laravel, and Vue.js. Experience with Python or AI/ML is a plus.
- **High agency. **You don’t wait to be told what to do. You see the problem, you own the fix, and you see it through.
- **Obsessed with quality. **You take genuine pride in your work. You don’t ship things you’re not proud of.
- **Low ego. **You’re confident in your ability but not territorial about it. You want the product to win, not to be right.
- **Technically curious. **You follow where the technology is going (especially AI) and push for adoption where it moves us forward.
- **Resilient under pressure. **Deadlines are real here. If you do your best work when the stakes are high, you’ll fit right in.



#### This Role Is Not For You If…



- You need detailed specs before you start. Ambiguity is the default here.
- You’re looking for a large team with established processes. We’re still building those.
- You want to stay in a narrow technical lane. We need range.
- You’re not interested in growing fast. We have a high bar, and we expect it to keep rising.



#### What We Offer

- Competitive salary plus performance-based share options
- Private medical and dental cover
- Pension: 5% employer contribution
- 35 days holiday (inclusive of bank holidays)
- Hybrid working — 3 days in our Hillsborough, NI office
- Company laptop
- Outsized responsibility and growth, from day one



#### How to Apply

Send your CV to dan@complyfirst.co. Include links to work you’re proud of — projects, repos, anything that shows how you build. Tell us what you’ve shipped and what you’d do differently.

## Is this role not a perfect fit, but you still want to apply? 

  
We’re growing fast and always looking for people who are exceptional at what they do. Send us your CV and make the case for yourself.  
      
  

```json
{
  "_key": "d886d6ec0c21",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "mailto:jobs@complyfirst.co",
      "label": "Send us your CV",
      "variant": "contained"
    }
  ]
}
```

---
Source: https://complyfirst.co/careers/senior-full-stack-developer

---

# Code of Business Ethics

## Code of Business Ethics

Version 1.0

Reviewed annually or more frequently if required.

At Complyfirst we care about doing the right thing. It is simple. Treat people fairly act with integrity and make choices we can stand behind. This Code sets out the standards we hold ourselves to and what you can expect from us.

**Our commitment to ethical conduct**

We believe good business starts with trust. Every decision we make should be honest responsible and respectful. If something feels off we expect our team to speak up and we make sure those concerns are listened to.

**Zero tolerance for bribery and corruption**

Bribery and corruption undermine trust so we have no place for them. We do not offer request or accept anything that could influence decisions or create a conflict of interest. We comply with the laws that set the bar across our markets including the UK Bribery Act 2010 the Irish Criminal Justice Corruption Offences Act 2018 and the EU Directive on combating corruption.

**Respect for human rights**

We respect and support internationally recognised human rights. We do not tolerate forced labour child labour discrimination harassment or unsafe working conditions. We work with partners who share this commitment and expect the same care for people throughout their operations.

**Speaking up and accountability**

If someone sees behaviour that does not align with our standards we want to hear about it. Concerns are taken seriously. Speaking up in good faith is supported and retaliation is not allowed. We review our policies regularly so our approach stays strong and up to date.

**Our promise**

Complyfirst exists to help organisations work with confidence and clarity. We hold ourselves to that same standard. This Code is our public commitment to fairness transparency and respect for the people we serve and the communities we are part of.

**Reporting a concern**

If you would like to raise a concern about behaviour that does not align with this Code please contact us at hello@complyfirst.co. Reports can be made confidentially and are reviewed promptly by our leadership team. Speaking up in good faith is always supported.

---
Source: https://complyfirst.co/code-of-business-ethics

---

# Complyfirst Poker Night

---
Source: https://complyfirst.co/complyfirst-poker-night

---

# Cookie Policy

*Cookie Policy*

#### 1. General

FDJ Ecommerce Ltd, trading as Complyfirst (“Complyfirst”), International House, 36-38 Cornhill, London, EC3V 3NG („Complyfirst” or „we” or „us”) uses cookies to give you a better online experience. In order to get the most out of our Complyfirst web application, your computer, tablet or mobile phone must accept cookies. We consider it important to know what types of cookies our web application uses and for what purposes. This will help protect your privacy while giving you the best online experience.



#### 2. What is a cookie?

Cookies are small text files that contain small amounts of information that are downloaded and can be stored on your user device - for example, your computer (or other Internet-enabled devices, such as a smartphone or tablet). At Complyfirst we can use similar techniques, such as pixels, web beacons and fingerprints. For the sake of consistency, all these combined techniques will be referred to as "cookies".

This Cookie Policy provides you with information about the cookies we use and the reasons for their use. Our [privacy policy](https://www.complyfirst.co/privacy) sets out the full details of the other information we may collect and how we may use your personal data.



#### 3. Cookies used on our web application

Complyfirst uses several types of cookies. Some of these are session cookies, which are temporary and allow us to connect your actions during a working session in the browser. Session cookies are deleted when you close your browser. Others are persistent cookies and remain in your device for the time specified in the cookie. The web application uses cookies for the following purposes:



#### 3.1. Functional cookies

MFunctional cookies are essential and help you navigate the website. They improve the user-friendliness of the website. These cookies also help to strengthen the security and ensure the basic functionality of the web application.



#### 3.2. Analytical cookies

Analytical cookies help us to understand the behavior of our visitors and the use of the website in an aggregate manner. For example, we may use these cookies to obtain information about how visitors use our website. This means that we can find out what works and what doesn't, it allows us to constantly improve our website and measure the effectiveness of advertising and communication.

We use Google Analytics cookies to gain an overview of your habits and the number of visitors and to help improve your overall experience on our site. You may refuse the use of cookies by selecting the appropriate settings on your browser, as described below. In addition, you can prevent the collection and use of data by Google (cookies and IP address) by downloading and installing the browser plug-in available at [https://tools.google.com/dlpage/gaoptout?hl=en-GB#](https://tools.google.com/dlpage/gaoptout?hl=en-GB#). You can disable the use of Google Analytics by accessing the disable Google Analytics link. This link creates an option to disable cookies, which prevents further processing of your data. For more information about Google Analytics cookies, please see the Google Help and Privacy Policy page:



[Google’s Privacy Policy](https://policies.google.com/privacy)

[Google Analytics Help pages](https://support.google.com/analytics/?hl=en#topic=3544906)



#### 3.3. Social networking cookies

Complyfirst allows cookies from third-party social networks (eg Facebook, YouTube, Twitter, LinkedIn). This allows you to share content from your website on social networks. These third parties may use cookies for their own purposes. Complyfirst has no influence on how social networks use your data. For more information on cookies set by social networks, please see their own privacy and cookie policies.



#### 4. Adjust your cookie settings

Once you agree to our use of cookies, we will store a cookie on your computer or device to remember this next time. If you wish to withdraw your consent to cookies at any time, you will need to delete our cookies using your internet browser settings. You should do this through the browser settings for each browser you use. Please note that some of our services will not work if your browser does not support cookies. However, you can allow cookies from certain websites by setting them as "trusted sites" in your internet browser. The following links may help you manage your cookie settings, or you can use the "Help" option in your web browser for further details.



Internet Explorer: [https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies](https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies)

Mozilla Firefox: [http://support.mozilla.com/en-US/kb/Cookies](http://support.mozilla.com/en-US/kb/Cookies)

Google Chrome: [http://www.google.com/support/chrome/bin/answer.py?hl=en&answer=95647](https://www.google.com/support/chrome/bin/answer.py?hl=en&answer=95647)

Safari: [http://support.apple.com/kb/PH5042](http://support.apple.com/kb/PH5042)

Opera: [http://www.opera.com/help/tutorials/security/privacy/](http://www.opera.com/help/tutorials/security/privacy/)

Adobe (flash cookies): [https://www.adobe.com/support/flash/downloads.html](https://www.adobe.com/support/flash/downloads.html)



#### 5. Cookies overview

Below is a complete list of cookies used on the Complyfirst web application:



#### 5.1 Functional cookies

**Cookie:** _GRECAPTCHA  
**Description:** This cookie is set by Google recaptcha to identify the robots and to protect the website against malicious spam attacks.

**Cookie:** __cookie_consent  
**Description:** The cookie is set to record the user's consent to the cookie policy.

**Cookie:** cookieyes-consent  
**Description:** The cookie is set to record the user's consent to the cookie policy.

**Cookie:** comply_first_session  
**Description:** This cookie is provided by the Complyfirst framework in order to handle sessions.

**Cookie:** _cfuvid  
**Description:** The _cfuvid cookie is only set when a site uses this option in a Rate Limiting Rule, and is only used to allow the Cloudflare WAF to distinguish individual users who share the same IP address.

**Cookie:** XSRF-TOKEN  
**Description:** This cookie is written to help with site security in preventing Cross-Site Request Forgery attacks.

**Cookie:** hubspotutk  
**Description:** This cookie name is associated with websites or forms built on the HubSpot platform. HubSpot report that its purpose is user authentication.

**Cookie:** __cf_bm  
**Description:** This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.

#### 5.2 Analytical cookies

**Cookie:** _ga  
**Description:** The _ga cookie, installed by Google Analytics, calculates data about visitors, sessions and campaigns and also keeps track of the use of the site for the site analysis report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.

**Cookie:** __hstc  
**Description:** This cookie name is associated with websites built on the HubSpot platform. It is reported by them as being used for website analytics.

**Cookie:** __hssrc  
**Description:** This cookie name is associated with websites built on the HubSpot platform. It is reported by them as being used for website analytics.

**Cookie:** __hssc  
**Description:** This cookie name is associated with websites built on the HubSpot platform. It is reported by them as being used for website analytics.

#### 6. Final conclusions

This Cookie Policy will be subject to ongoing review and regular updates. Any changes to this Cookie Policy will be posted on our website and will be communicated to you to the extent possible. You can check out this web page for the latest updated version.

If you have any further questions and / or comments, please contact us by email at hello@complyfirst.co

---
Source: https://complyfirst.co/cookie-policy

---

# Complyfirst Customers | #1 Reporting Platform for PIs, EMIs, Banks

> Regulatory, tax, internal, qualitative, quantitative. There’s no report Complyfirst can’t handle. XML/XBRL generation. Fast 1:1 support. Automated data collection, real-time validation, built for multi-jurisdiction reporting.

# Compliance and Finance teams _just win_ with us

### reduction in reporting effort for SumUp

### of hours saved in reporting for TrueLayer

### time to go live for Decta, reporting in < 1 day

## _Winning_ customer stories

- [Central Bank of Ireland's AML REQ for Crypto-Asset Service Providers (CASPs): What You Need to Know](https://complyfirst.co/resources/aml-req-for-casps-explained) — The new AML REQ for CASPs introduces XML-only submissions, strict validation rules and significantly more AML data reporting. Here’s what crypto firms need to know.
- [How to Submit Monthly REP027 Returns via FCA RegData](https://complyfirst.co/resources/how-to-submit-monthly-rep027-returns-via-fca-regdata) — REP027 has 17 sections and a 21 July deadline. We break down who's in scope, the three trickiest sections, and how to build a repeatable monthly process.
- [Inside REP027: Preparing for the FCA's New Monthly Safeguarding Return](https://complyfirst.co/resources/inside-rep027-preparing-for-the-fca-s-new-monthly-safeguarding-return) — Dan and Fiona covered all things REP027 - who's in scope, how to complete the return, and how you can automate it.
- [Investment Firms AML REQ Explained: Everything to Know Before the 30 June 2026 Deadline](https://complyfirst.co/resources/investment-firms-aml-req-explained) — The new AML REQ for Investment Firms introduces XML-only submissions, strict validation rules and significantly more AML data reporting. Here’s what firms need to know.
- [AML REQ for Credit Institutions](https://complyfirst.co/snapshot/aml-req-for-cis) — High-level overview of the Central Bank of Ireland AML REQ for Credit Institutions, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.
- [AML REQ for PIs and EMIs](https://complyfirst.co/snapshot/aml-req-for-pis-and-emis) — High-level overview of the CBI's AML REQ for PIs and EMIs, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.
- [AML REQ for Crypto-Asset Service Providers (CASPs)](https://complyfirst.co/snapshot/aml-req-for-crypto-asset-service-providers-casps) — Get a high-level overview of the Central Bank of Ireland AML REQ for CASPs, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.
- [AML REQ for Investment Firms](https://complyfirst.co/snapshot/aml-req-for-investment-firms) — Get a high-level overview of the CBI's AML REQ for Investment Firms, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.
- [AML REQ for Credit Unions](https://complyfirst.co/snapshot/aml-req-for-credit-unions) — High-level overview of the Central Bank of Ireland AML REQ for Credit Unions, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.
- [AML REQ for Life Insurance Institutions](https://complyfirst.co/snapshot/aml-req-for-life-insurance-institutions) — High-level overview of the Central Bank of Ireland AML REQ for Life Insurance, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.
- [How to Complete the FCA Safeguarding Return (REP027): A Step-by-Step Guide](https://complyfirst.co/resources/how-to-complete-the-fca-safeguarding-return-rep027-a-step-by-step-guide) — A complete guide to REP027, the FCA’s new monthly safeguarding return for UK payment and e-money institutions. Learn who it applies to, key deadlines, reporting requirements, and how to prepare before the July 2026 deadline.
- [FCA PS25/12 Explained: What the New Safeguarding Regime Means for PIs and EMIs](https://complyfirst.co/resources/fca-ps25-12-explained-what-the-new-safeguarding-regime-means-for-pis-and-emis) — Stay ahead of the FCA’s new safeguarding rules under PS25/12. Learn how annual audits and monthly RegData reporting will impact EMIs and payment institutions from May 2026, and how to prepare.
- [Instant Payments Regulation (IPR) Reporting: What EU PSPs Must Submit by 9 April 2026](https://complyfirst.co/resources/instant-payments-regulation-ipr-reporting-what-eu-psps-must-submit-by-9-april-2026) — EU Instant Payments Report (IPR) explained: reporting scope, 4-year backfill, entity-level obligations, and what PSPs need to prepare for the 9 April 2026 deadline.
- [New EBA Instant Payments Report: What firms need to know  before 9 April](https://complyfirst.co/resources/new-eba-instant-payments-report-what-firms-need-to-know-before-9-april) — Together with Financial InnovateHER, Fiona and Dan covered what to look out for and how to complete your IPR submission (each tab step-by-step).
- [DORA ROI](https://complyfirst.co/snapshot/dora-roi) — Get a snapshot guide on how to complete the DORA ROI: The 4 keys, supply chain mapping, and data quality.
- [CPC 2026: Are you ready? A practical session for PIs & EMIs](https://complyfirst.co/resources/cpc-2026-are-you-ready-a-practical-session-for-pis-and-emis) — Webinar on Ireland’s new Consumer Protection Code (CPC): CBI expectations, common myths, and a practical look at how firms can operationalise the requirements.
- [CARF](https://complyfirst.co/snapshot/carf) — Learn the UK CARF reporting requirements for crypto-asset service providers, including scope, data fields, reporting deadlines, and HMRC compliance steps.
- [The CBI’s RSO for 2026: A Snapshot Guide for PIs & EMIs](https://complyfirst.co/resources/files/the-cbis-rso-for-2026-focus-areas-for-pis-emis) — A practical snapshot guide to the CBI’s 2026 Regulatory & Supervisory Outlook for Irish PIs and EMIs. Understand the key supervisory priorities shaping Payments and E-money this year.
- [CRS2](https://complyfirst.co/snapshot/crs2) — Get a clear snapshot of CRS2 outlining scope, data requirements, reporting obligations, deadlines, and next steps for financial institutions preparing for enhanced tax transparency.
- [DAC8](https://complyfirst.co/snapshot/dac8) — Get an overview of the EU DAC8 crypto-asset reporting rules, including scope, data requirements, and annual XML reporting under the OECD CARF framework.
- [Instant Payments Report](https://complyfirst.co/snapshot/instant-payments-report) — Understand the EU Instant Payments Report (IPR): who it applies to, required templates, sanctions reporting, annual deadlines, and XBRL filing process.
- [FCA Safeguarding Return](https://complyfirst.co/snapshot/fca-safeguarding-return) — Learn how the FCA's monthly Safeguarding reporting works, who’s in scope, what data to report, and how to submit.
- [Spanish Models 196 & 170](https://complyfirst.co/snapshot/spanish-models-196-and-170) — Learn how Spanish Tax Agency Models 170 and 196 reporting works, who’s in scope, what data to report, and how to submit monthly filings.
- [How to Complete the FCA Safeguarding Monthly Return (Guide for APIs, EMIs, SPIs and SEMIs)](https://complyfirst.co/resources/how-to-complete-the-fca-safeguarding-monthly-return-guide) — Guide to the FCA’s new monthly safeguarding return for UK EMIs, APIs and SPIs, covering scope, required data fields, RegData submission deadlines and practical steps.
- [🇬🇧 UK Webinar: Major Regulatory & Tax Reporting Changes in 2026. Are You Ready?](https://complyfirst.co/resources/uk-webinar-major-regulatory-and-tax-reporting-changes-in-2026-are-you-ready) — Fiona presented a clear, practical overview of the FCA's monthly Safeguarding Return, CRS2, and CARF.
- [🇪🇺 EU Webinar: Major Regulatory & Tax Reporting Changes in 2026. Are You Ready?](https://complyfirst.co/resources/eu-webinar-major-regulatory-and-tax-reporting-changes-in-2026) — Fiona presented a clear, practical overview of Spanish tax reporting (Models 196 & 170), CRS2, DAC8, and IPR reporting.
- [CRS 2.0 Reporting Requirements for E-Money Firms and Financial Institutions Explained](https://complyfirst.co/resources/crs-2-reporting-requirements-explained) — CRS 2.0 amends the Common Reporting Standard and brings e-money firms into scope. The UK (HMRC) and EU (DAC8) deadlines, data rules and penalties, explained.
- [EU DAC8 Crypto-Asset Reporting Requirements Explained (2026 Guide)](https://complyfirst.co/resources/dac8-crypto-asset-reporting-guide) — This blog breaks down what DAC8 is, who it applies to, and how reporting works in practice.
- [New Spanish AEAT Tax Reporting Requirements Explained: Models 196 and 170 (2026 Guide)](https://complyfirst.co/resources/tax-reporting-models-196-and-170-2026-guide) — This guide breaks down Spanish tax models 196 and 170, and their reporting obligations.
- [SumUp’s Switch to Complyfirst Cuts Reporting Workload by 90% in 4 Jurisdictions](https://complyfirst.co/resources/sumup-regulatory-reporting) — SumUp manages regulatory reporting obligations across multiple jurisdictions with Complyfirst.
- [Decta Goes Live With Regulatory Reporting in <24hrs](https://complyfirst.co/resources/decta-regulatory-reporting) — Following their 2024 authorisation, Decta needed a fast, reliable way to meet immediate regulatory reporting requirements.
- [Zing Speeds Up SAR Investigation Time From 6 Hours to Under 1](https://complyfirst.co/resources/zing-regulatory-reporting-and-sars) — Zing, a UK EMI and HSBC subsidiary, used Complyfirst to automate regulatory reporting and SARs, cutting workload and freeing up compliance teams.
- [TrueLayer Spends 50% Less Time on Regulatory Reporting with Complyfirst](https://complyfirst.co/resources/truelayer-regulatory-reporting) — TrueLayer, Europe’s leading Pay by Bank provider, regulated by the FCA and CBI, needed to simplify regulatory reporting across the UK and Ireland.
- [DORA Register of Information Requirements Explained (Guide for EU Financial Entities)](https://complyfirst.co/resources/dora-roi-guide-for-eu-financial-entities) — Clear guide to the DORA ROI: what it includes, how to complete the 15 tables, use the 4 keys, and avoid the errors seen in the dry run.
- [DORA ROI Demystified](https://complyfirst.co/resources/complyfirst-fscom-dora-webinar) — Fiona joins fscom’s Stuart Smith and Benjamin Gray to discuss how firms have responded to DORA one year after implementation, sharing lessons learned, reporting insights, and best practices.
- [Briefing 1: AML REQ Overview](https://complyfirst.co/resources/aml-req-overview) — A practical walkthrough of the new AML REQ: who it applies to, what’s changing, key deadlines for PI/EMI and Credit Institutions, and how to prepare for XML-only submissions via the CBI portal.
- [Briefing 2: Practical steps to comply with the AML REQ](https://complyfirst.co/resources/briefing-2-aml-req-steps) — A practical walkthrough of the steps firms need to complete for the AML REQ:  from data extraction and gap analysis to XML decisions, and CBI testing and submission.
- [Central Bank of Ireland's New AML REQ Explained for Payment and E-Money Institutions](https://complyfirst.co/resources/cbi-new-aml-req-requirements-explained) — The Central Bank of Ireland has introduced a new XML-based AML REQ for Irish PIs and EMIs. Learn what’s changed, what data is required, and how to prepare for the 13 Feb 2026 deadline.

*Designed for <em>trust and control</em>*

### ISO 27001 compliant

We follow ISO 27001 standards to keep your data safe and in line with what regulators recognise and trust.

### AI that stays factual

Inputs are yours. Outputs are yours. The AI is trained only on your knowledge base and regulations.

### EU data residency

Your information remains in EU-based centres, aligned with EU privacy standards.

## Reporting slowing you down?

    
Tell us what reports you need. Regulatory, tax, audit, fraud, or custom reports. There’s no report we can’t handle.    
 

```json
{
  "_key": "f1a6ff97a49f",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "/demo",
      "label": "Get in touch",
      "variant": "contained"
    }
  ]
}
```

#

---
Source: https://complyfirst.co/customers

---

# #1 Reporting Platform for PIs, EMIs, Banks

> Regulatory, tax, audit, fraud, or custom reports. There’s no report Complyfirst can’t handle. XML/XBRL generation. Fast 1:1 support. Automated data collection, real-time validation, built for multi-jurisdiction reporting.

# Report on anything.

#  

# 

```json
{
  "_key": "ccae218f1006",
  "_type": "animated-text-block",
  "alignment": "center",
  "animationSpeed": "medium",
  "animationType": "typewriter",
  "headingLevel": "h1",
  "line1": null,
  "line2Items": [
    "regulatory returns",
    "suspicious activity reports",
    "audit reports",
    "fraud reports",
    "custom reports"
  ],
  "line3": null
}
```

#  

#  

```json
{
  "_key": "96a15fdebd55",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/demo",
      "label": "Get a Demo",
      "variant": "contained"
    }
  ]
}
```

#

```json
{
  "_key": "85801cb7d833",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "THE PROBLEM"
    }
  ]
}
```

## Every new report is another spreadsheet to manage.



Each report comes with its own rules and deadlines to manage, and most teams are still holding it all together across spreadsheets and Teams notifications.

####

## This is where Complyfirst comes in.



#### Complyfirst automates every report you need to file, for every regulator, in every jurisdiction.



```json
{
  "_key": "48d659533609",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "/demo",
      "label": "See how it works",
      "variant": "contained"
    }
  ]
}
```

```json
{
  "_key": "53d008dadc07",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "HOW IT WORKS"
    }
  ]
}
```

## Two products to cover _all_ your reports

#  

For structured regulatory returns, rules are already built in for you. For process-specific reports, we build a workflow around how your team already works.

### Regulatory Reporting

**For structured reports. **

You upload your data, the platform validates it, and generates a regulator-ready report to submit.

### AI Custom Reporting Workflows

**For SARs and custom reports.**

We build an AI workflow around how your team already works, from trigger to submission.

```json
{
  "_key": "7aa71220f414",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING USE CASES"
    }
  ]
}
```

## Teams file _every_ report with Complyfirst

#  

There's a workflow for every type of report teams need to submit.

### <strong>CFOs</strong> can

file regulatory returns

### <strong>MLROs</strong> can

create and submit SARs

### <strong>Auditors</strong> can

perform audit reviews

### <strong>Compliance teams</strong> can

create fraud reports

### <strong>We</strong> can

build a custom workflow

```json
{
  "_key": "3729b2724b21",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports",
      "label": "See all reports →",
      "variant": "outlined"
    }
  ]
}
```

## Teams that _switched_ aren't going back

```json
{
  "_key": "b1a8d7d7709d",
  "_type": "image",
  "alt": "Sumup Logo",
  "asset": {
    "_id": "image-aa4f4898a13092cd6622658a5c3f7d1d945f3e77-180x72-svg",
    "metadata": {
      "dimensions": {
        "height": 72,
        "width": 180
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAAsTAAALEwEAmpwYAAABrklEQVR4nKVSy24UMRA0j+UtZTNjt3f2MeNub0CbSEFiEXCBiBMIorBrT3uCRHhEaDlxgUsQh3wDQXAGwS0n+AfELcA3hBt8BPJMxAeApZKqW3bZ1WUB6JelDRc65C9GRK6Glc2y1VPiXxbY8E4TfwTiN0C809TVVhQVgo+I4c3jYjxr1VysHBXFgxM1Iq97s5ZY5GNNPWsJIN4H4j1A3tHEbzWFH0BhVxt/WebTbH7gl1LD59rGFZA7io7aZnp+Lmec794ZSJyc7eS8qIvKpIP1bhT8pYm/APIzoHJbU/UdLH/WNlyHIlyR6DcV8UOFXErjKmV4IzW8odD5tAiTyDXypia+HS8TYPm3pvANkF8Chuea+Ksm/iSNu5blPFZUPpJYPlamvC+pXE8Nr0n0qwqDj2IphSfKlE8luVvJcNqPL/zZ2OTXje2wB5Z3NfKlTodVUlSjZKEaJcVkpCwPkz730sFady531O755Tb6q8q4G5LcQj1LIH5fw4ZXMRhN4YPG8CIergcdN8VQ6sGPD8I5CKjPJ89kd2XSm/aFvne6Sfn/vs2hv0mL7cOx8wd6Q22l7qKvgAAAAABJRU5ErkJggg=="
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/aa4f4898a13092cd6622658a5c3f7d1d945f3e77-180x72.svg"
  }
}
```

```json
{
  "_key": "fc0cb15f269d",
  "_type": "resource-quote",
  "author": {
    "name": "Adrian Witkowski",
    "position": "Head of Regulatory Reporting"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "371467bc8130",
      "_type": "block",
      "children": [
        {
          "_key": "f9861b8d99e7",
          "_type": "span",
          "marks": [],
          "text": "\"What used to take weeks was fixed in hours with Complyfirst. "
        },
        {
          "_key": "acd8abe42afa",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "We were live, errors resolved, and submitted within 48 hours.\""
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "9d71bde61ff6",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "ef250fe4bcf9",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "c5efc0ce1884",
          "_type": "block",
          "children": [
            {
              "_key": "409d5fae4197",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "90%"
            },
            {
              "_key": "355908b5ec64",
              "_type": "span",
              "marks": [],
              "text": " less reporting effort"
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "d11f339c5eee",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "f0e50fc8502c",
          "_type": "block",
          "children": [
            {
              "_key": "da1bc1353c16",
              "_type": "span",
              "marks": [],
              "text": "SumUp was onboarded, validated, and live on Complyfirst within "
            },
            {
              "_key": "2f267e4862ee",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "48 hours."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ]
    }
  ]
}
```

```json
{
  "_key": "d395f8675a54",
  "_type": "image",
  "alt": "TrueLayer Logo",
  "asset": {
    "_id": "image-44014da9a57177091c902bed58a897126f321b97-180x72-svg",
    "metadata": {
      "dimensions": {
        "height": 72,
        "width": 180
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAAsTAAALEwEAmpwYAAABLklEQVR4nK1R22rCQBCdvgjGxJi9WFOCySYbk4bGilZrESu+CS02mziCl9I3H/r/H1A2pV9QBw4zzBzOzGEArh2co2ndFdQJ0YYMGwBw8y9BKvZT6u/XPNwveITS7r85dn50zMGB/S3SsP2PDs/QhDk2wcNm3ct/uT2J3B0cmAawCC88xC8qdice4caUmBm5Gnfiasn75YL1cULD6okInJlxcd8YFgMr2CYkLmZGqsZGhiN9EAtwdeuXa+Bi980D/OQCd0ziyo7L0MwwI1LNu76aU6GmJKietWArVQ/GSD3aKU6csFy0csytBBPtjolq2QvKV9DEboQvLFJjIpUH7rsBw3NLW6zt1/no6JrITVvbtNKCatBka2m+nrc9JJ6HBFz3YhB5atfDazzl2vEDKIE7YLedL4AAAAAASUVORK5CYII="
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/44014da9a57177091c902bed58a897126f321b97-180x72.svg"
  }
}
```

```json
{
  "_key": "36aa06149042",
  "_type": "resource-quote",
  "author": {
    "name": "Pamela Crilly",
    "position": "EU COO"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "f7bbf30b05ae",
      "_type": "block",
      "children": [
        {
          "_key": "edfc4d4d9767",
          "_type": "span",
          "marks": [],
          "text": "\"What sets Complyfirst apart is its ability to "
        },
        {
          "_key": "0a7e3c08479a",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "simulate a regulator’s review"
        },
        {
          "_key": "dda054dd6f1b",
          "_type": "span",
          "marks": [],
          "text": ", identifying discrepancies before the actual submission.\""
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "42e981d7c56c",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "fcfd5ca08d0b",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "4dad448c1d1c",
          "_type": "block",
          "children": [
            {
              "_key": "80e2a87f79d0",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "50%"
            },
            {
              "_key": "e95e69901dd6",
              "_type": "span",
              "marks": [],
              "text": " less reporting effort"
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "5063d066807c",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "0155f4f74ba0",
          "_type": "block",
          "children": [
            {
              "_key": "25ccc0a47a21",
              "_type": "span",
              "marks": [],
              "text": "DORA was submitted within "
            },
            {
              "_key": "c9583794da74",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "24 hours."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ]
    }
  ]
}
```

```json
{
  "_key": "12cad44ff8ae",
  "_type": "image",
  "alt": "Decta Logo",
  "asset": {
    "_id": "image-e3aaf09403b85d61f1b5f2476a929595bee2bf77-158x34-svg",
    "metadata": {
      "dimensions": {
        "height": 34,
        "width": 158
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAYAAACOXx+WAAAACXBIWXMAAAsTAAALEwEAmpwYAAABEUlEQVR4nDXNsUoDURCF4byBsPfO3GDh7sxESGGrIIoSNUiamOzemU0iiAoGG22CViqmMCgWKkQsFdT3lIgWp/y/U8EsHwaOn8hx6rPOZkK6gqIPWLMpiO36RdtALibA8Q4zbXvSY0/xA8ieE9auYx0A6ZMjG82lZVbBTIdAOka2K+R8kJDtANulY71wkjdQir3Aeh7EGpBqNfwe2ghYDx3rFoidodgLkI0D29I/eIus15DFA6C8QLJHz3rjFrpbyNr1f+B8veNAtIYU97GmTWBbm3Uo5StyOUHR1Qqmehq4/AKyt4R6TZ8WrcD6jaTvVS5aTqyBFO+RdQKs6y7t15302jOsSraMoifA/aPZkMvtH1mOSj/w4XWpAAAAAElFTkSuQmCC"
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/e3aaf09403b85d61f1b5f2476a929595bee2bf77-158x34.svg"
  }
}
```

```json
{
  "_key": "74b7c9cb6092",
  "_type": "resource-quote",
  "author": {
    "name": "Neil McDermott",
    "position": "Chief Financial Officer"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "3586be135e1f",
      "_type": "block",
      "children": [
        {
          "_key": "6a6d77e19f6e",
          "_type": "span",
          "marks": [],
          "text": "\"I’ve worked at large banks with entire teams managing returns. "
        },
        {
          "_key": "c7ee711af634",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "With Complyfirst, we had it done in days.\""
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "852ab463f668",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "7b6ca9efa46a",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "46be21ec2360",
          "_type": "block",
          "children": [
            {
              "_key": "cd0564ea4a14",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "<24hr"
            },
            {
              "_key": "2eba60f4157c",
              "_type": "span",
              "marks": [],
              "text": " time to go live"
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "e0ecad219d6c",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "cb3a716ed00a",
          "_type": "block",
          "children": [
            {
              "_key": "04b6fe14d712",
              "_type": "span",
              "marks": [],
              "text": "Decta submitted clean regulatory returns with "
            },
            {
              "_key": "c8441b9cbeb2",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "0 issues"
            },
            {
              "_key": "6fd3e3d2bd44",
              "_type": "span",
              "marks": [],
              "text": " or rework."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ]
    }
  ]
}
```

#

```json
{
  "_key": "f8b972652204",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary",
      "label": "WHY COMPLYFIRST"
    }
  ]
}
```

## Why teams _choose us_ over last-mile tools

#  

We're different to the traditional Excel to XML/XBRL template converters you’re used to.

## 1:1 support,   
_even on deadline day_

# 

Message us on Slack or MS Teams and hear back in under an hour, _especially_ on deadline day.

### No ”rip-and-replace”

We work with your existing tech stack, so there’s nothing to tear out and rebuild.

### 1:1 implementation

No cookie-cutter solutions here. We build a workflow around your processes.

### Bank-grade security

ISO 27001 certified, with EU data residency, and enterprise AI built on AWS Bedrock.

## Your first XML/XBRL return is on us.

  
Got a deadline coming? We've got you. Get _free_ file generation and support on your first filing.





```json
{
  "_key": "9e5df49dc3f6",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "/demo",
      "label": "Get in touch",
      "variant": "contained"
    }
  ]
}
```

---
Source: https://complyfirst.co

---

# Microsoft Integration

# Microsoft Integration Setup

# 

This guide walks you through setting up SAML 2.0 Single Sign-On (SSO) between Microsoft Entra ID (formerly Azure Active Directory) and ComplyFirst. Once completed, chosen users in your Microsoft directory will be able to log in to Complyfirst using their Microsoft SSO credentials.

```json
{
  "_key": "1e8ea33de047",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

**Create a new Enterprise Application in Microsoft**

1. Log in to Micosoft Entra ID as an admin
2. Navigate to **Entra ID → Enterprise apps**
3. Click **New Application**, then **Create your own application**
4. Enter a name for the application and select **"Integrate any other application you don't find in the gallery (Non-gallery)"**
5. Click **Create**

```json
{
  "_key": "b7ea853a9792",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

**Configure SAML Single Sign-On**

1. In your new enterprise application, go to **Single sign-on** in the left menu
2. Select **SAML** as the single sign-on method
3. In **Section 1 - Basic SAML Configuration**, click **Edit** and enter:
   1. **Identifier (Entity ID) - **https://app.complyfirst.co/auth/saml2
   2. **Reply URL (ACS URL) - **https://app.complyfirst.co/auth/saml2/callback
4. Leave the rest empty and click **Save**

```json
{
  "_key": "e371f47c58a8",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

**Verify Attributes & Claims**

1. In **Section 2 - Attributes & Claims**, click Edit and verify the following claims are configured:
   - **Claim:** http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress **Attribute:** user.mail or user.userprincipalname
   - **Claim:** http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname **Attribute:** user.givenname 
   - **Claim:** http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname **Attribute:** user.surname

**Note**: The email claim is required for ComplyFirst to identify users. If this claim is not configured, the system will fall back to using the NameID value.

```json
{
  "_key": "5bded90974f1",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP FOUR"
    }
  ]
}
```

**If the emailaddress claim is missing**

1. If the **emailaddress** claim is missing, click Add New Claim and enter the following:
   - **Name: **emailaddress
   - **Namespace: **http://schemas.xmlsoap.org/ws/2005/05/identity/claims
   - **Source attribute:** user.mail (or user.userprincipalname if user.mail is not populated)
2. Click **Save**

```json
{
  "_key": "eaa07b56094e",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP FIVE"
    }
  ]
}
```

**Copy the Federation Metadata URL**

1. In **Section 3 - SAML Certificates**, locate the **App Federation Metadata Url**
2. The URL will look like: https://login.microsoftonline.com/{tenant-id}/federationmetadata/2007-06/federationmetadata.xml?appid={app-id}
3. **Copy** this URL for later

```json
{
  "_key": "eaa07b56094e",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP SIX"
    }
  ]
}
```

**Assign Users to the Application**

1. In the enterprise application, go to **Users and groups**
2. Click **Add user/group**
3. Select the users or groups who should have access to ComplyFirst
4. Click **Assign**

**Important**: Users who are not assigned to the application will receive an error when attempting to sign in: _"AADSTS50105: Your administrator has not assigned you a role for this application."_

```json
{
  "_key": "eaa07b56094e",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP SEVEN"
    }
  ]
}
```

**Configure Complyfirst**

1. Log in to Complyfirst as an admin
2. Navigate to **Settings > Integrations**
3. Find **Microsoft SAML** and click **Configure**
4. Enter the **Federation Metadata URL **you copied from step 5
5. Click **Save**

```json
{
  "_key": "eaa07b56094e",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "OPTIONAL STEP"
    }
  ]
}
```

**Enforce Multi-Factor Authentication (optional)**

1. In the Enterprise apps section of the Microsoft Entra admin center, navigate to **Security > Conditional Access**
2. Click **Create new policy**
3. Configure:
   - **Name**: Require MFA for Complyfirst
   - **Users**: Select the users or groups who access Complyfirst
   - **Target resources > Cloud apps**: Select your Complyfirst enterprise application
   - **Grant**: Select **Require multifactor authentication**
4. Set the policy to **On** and click **Create**

#### Troubleshooting

```json
{
  "_key": "eb40b34009b7",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "a32e3aaac725",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "9da6581102b6",
          "_type": "block",
          "children": [
            {
              "_key": "adc65c34e6f9",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Cause: "
            },
            {
              "_key": "eeaa1502e392",
              "_type": "span",
              "marks": [],
              "text": "User not assigned to the application"
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "5332b82dc250",
          "_type": "block",
          "children": [
            {
              "_key": "b3fc0c0e930a",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Solution:"
            },
            {
              "_key": "b43471888221",
              "_type": "span",
              "marks": [],
              "text": " Assign the user to the enterprise application in "
            },
            {
              "_key": "f01d428d7233",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Users and groups"
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Error Code: AADSTS50105"
    },
    {
      "_key": "0f533d0e93237a47dde0475a3958d09c",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "9da6581102b6",
          "_type": "block",
          "children": [
            {
              "_key": "adc65c34e6f9",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Cause: "
            },
            {
              "_key": "dae32a5dd96d",
              "_type": "span",
              "marks": [],
              "text": "Entity ID mismatch"
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "5332b82dc250",
          "_type": "block",
          "children": [
            {
              "_key": "b3fc0c0e930a",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Solution:"
            },
            {
              "_key": "b43471888221",
              "_type": "span",
              "marks": [],
              "text": " Verify the Identifier in Basic SAML Configuration matches https://app.complyfirst.co/auth/saml2"
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Error Code: AADSTS700016"
    },
    {
      "_key": "06376b5af099458b483d7f9023fcb19b",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "9da6581102b6",
          "_type": "block",
          "children": [
            {
              "_key": "adc65c34e6f9",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Cause: "
            },
            {
              "_key": "c344ca0dec77",
              "_type": "span",
              "marks": [],
              "text": "Reply URL mismatch"
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "5332b82dc250",
          "_type": "block",
          "children": [
            {
              "_key": "b3fc0c0e930a",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Solution:"
            },
            {
              "_key": "b43471888221",
              "_type": "span",
              "marks": [],
              "text": " Verify the Reply URL matches https://app.complyfirst.co/auth/saml2/callback"
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Error Code: AADSTS50011"
    },
    {
      "_key": "ac77620efb9fc00358a99ccc14b9e22b",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "9da6581102b6",
          "_type": "block",
          "children": [
            {
              "_key": "adc65c34e6f9",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Cause: "
            },
            {
              "_key": "f319b222577b",
              "_type": "span",
              "marks": [],
              "text": "User's email not linked to SSO"
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "5332b82dc250",
          "_type": "block",
          "children": [
            {
              "_key": "b3fc0c0e930a",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Solution:"
            },
            {
              "_key": "b43471888221",
              "_type": "span",
              "marks": [],
              "text": " Ensure the user exists in Complyfirst and their company has SSO enabled"
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "\"No SSO configuration found\""
    }
  ]
}
```

**If you have followed these steps and are still unable to connect Complyfirst to Microsoft, please reach out to our team.**

---
Source: https://complyfirst.co/integrations/microsoft

---

# Okta Integration

# Okta Integration Setup

# 

This guide will help you connect your Complyfirst account with your company okta account. Once completed, users in your Okta directory will be able to log in to Complyfirst using their Okta SSO credentials.

```json
{
  "_key": "c37adfbe953a",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

**Find ComplyFirst in Okta**

1. Log into your **Okta Admin Console**.
2. Navigate to **Applications → Applications**.
3. Click on **Browse App Catalog**.

```json
{
  "_key": "c37adfbe953a",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

**Add ComplyFirst integration**

1. Search for **ComplyFirst** in the app catalog.
2. Click **Add Integration**.
3. During setup, you will be prompted to enter an **Organisation ID**. You can enter whatever you like, but you will need this later to connect Okta to Complyfirst.

```json
{
  "_key": "aabe8d4aa34f",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

**Find Client ID and Client Secret**

1. After the app is created, go to the **Sign On** tab of the ComplyFirst app in Okta.
2. Locate and copy your **Client ID** and **Client Secret**. These will be required when configuring the integration in ComplyFirst.

```json
{
  "_key": "472818160220",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP FOUR"
    }
  ]
}
```

**Go to Complyfirst Integrations Page**

1. Log into the **ComplyFirst platform** as the company admin.
2. Go to **Settings → Integrations**.

```json
{
  "_key": "123178bde267",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP FIVE"
    }
  ]
}
```

**Connect Complyfirst to Okta**

1. Toggle the **Okta integration switch** on.
2. In the connection settings:
   - Enter the same **Organisation ID** used during Okta setup.
   - Provide your **Okta domain URL**.**Format:** https://{organisation}.okta.com  
**Example:** https://acme.okta.com
   - Enter the **Client ID** and **Client Secret** you copied from the Okta.

**If you have followed these steps and are still unable to connect Complyfirst to Okta, please reach out to our team.**

---
Source: https://complyfirst.co/integrations/okta

---

# Slack Integration

# Slack Integration Setup

# 

This guide will help you connect your Complyfirst account with your company slack account.

```json
{
  "_key": "fcae131982a8",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

Log in to your [Complyfirst account](https://app.complyfirst.co) and click on the gear icon in the left menu bar to navigate to Settings>Integrations

```json
{
  "_key": "fcae131982a8",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

Turn on the Slack integration by selecting the toggle in the top right of the Slack integration box, then click "Connect Slack".

```json
{
  "_key": "fcae131982a8",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

Select your company from the dropdown and click "Allow".

```json
{
  "_key": "fcae131982a8",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP FOUR"
    }
  ]
}
```

Click the gear in the Slack integration box, toggle on "task notifications enabled", and select the slack channel you would like Complyfirst to send notifications into. Click "Test" to send a sample notification.

```json
{
  "_key": "fcae131982a8",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "STEP FIVE"
    }
  ]
}
```

Lastly, Check that your test notification posted to the correct channel in Slack. If it worked, congratulations! you've successfully integrated Complyfirst with Slack.

**If you have followed these steps and are still unable to connect Complyfirst to Slack, please reach out to our team.**

---
Source: https://complyfirst.co/integrations/slack

---

# Information Security Management System (“ISMS”) Policy

*Information Security Management System (“ISMS”) Policy*

**Company Name:** FDJ Ecommerce LTD  
**Policy Owner:** CEO  
**Effective Date:** 1 August 2024

## Purpose

This policy provides a framework to be applied when establishing, implementing, maintaining, and continually improving the information security management system (“ISMS”), as defined in 01-ISMS Scope of the ISMS, in accordance with the requirements of the ISO/IEC 27001 (“ISO 27001”) standard.

## Information Security Objectives

Information security objectives are set and monitored annually by FDJ Ecommerce LTD's ISMS Governance Council based upon a clear understanding of business requirements. The current information security objectives are as follows:

- Protect the confidentiality, availability, and integrity of company, customer, and employee data
- Comply with applicable laws, regulations, and customer contractual obligations
- Achieve and maintain ISO 27001 certification

Action plans to achieve these objectives are maintained and reviewed annually by the ISMS Governance Council. Refer to 10-ISMS Information Security Objectives Plan for further details.

## Leadership and Commitment

FDJ Ecommerce LTD is dedicated to establishing, implementing, maintaining, and continually improving the ISMS. Leadership commitment is demonstrated by the ISMS Governance Council when carrying out their responsibilities as defined in the 03-ISMS Roles, Responsibilities, and Authorities document.

## Roles, Responsibilities and Authorities

FDJ Ecommerce LTD has defined the roles, responsibilities, and authorities involved in establishing, implementing, maintaining, and continually improving the ISMS. FDJ Ecommerce LTD has also defined how performance and competence will be measured and how competency gaps will be addressed. For further details, please refer to the 03-ISMS Roles, Responsibilities, and Authorities document.

## Approach to Assessing and Treating Risk

FDJ Ecommerce LTD has defined a Risk Assessment and Risk Treatment Process for identifying, analyzing, treating, and monitoring risks over time. For further details, please refer to the 04-ISMS Risk Assessment and Risk Treatment Process document.

## Control of Documented Information

FDJ Ecommerce LTD has defined a procedure for the control and protection of documented information. For further details, please refer to the 05-ISMS Procedure for the Control of Documented Information document.

## Communication

This and other relevant information security policies will be communicated to all in-scope personnel at least annually after review and approval, or after any significant changes occur to the policy. The policy will be made available in Vanta and are accessible by all FDJ Ecommerce LTD personnel. For further details, please refer to the 06-ISMS Information Security Communication Plan document.

## Internal Audit

FDJ Ecommerce LTD performs internal audits of its ISMS annually and has defined an ISMS Internal Audit Procedure. For further details, please refer to the 07-ISMS Procedure for Internal Audits document.

## Management Review

FDJ Ecommerce LTD has defined an ISMS Management Review Procedure consisting of the necessary inputs and outputs to ensure that the company's ISMS is operating effectively, as intended, and is continually improving. For further details, please refer to the 08-ISMS Procedure for Management Review for further details.

## Corrective Action and Continual Improvement

FDJ Ecommerce LTD has defined an ISMS Corrective Action and Continual Improvement Procedure when non-conformities are identified. Non-conformities may be identified during internal audits, external audits, management reviews, or ongoing monitoring of the ISMS. For further details, please refer to the 09-ISMS Procedure for Corrective Action and Continual Improvement document.

## Policy Violation

All FDJ Ecommerce LTD personnel (including employees, contractors, and applicable third parties) must maintain the security, confidentiality, availability, integrity, and privacy of FDJ Ecommerce LTD assets. Violations of ISMS policies and procedures may be considered serious breaches of trust, which can result in disciplinary action up to and including termination of employment or contract and prosecution in accordance with applicable laws.

## ISO 27001 Coverage

ISO 27001 4.1; 4.2; 4.3; 5.1

## Version History

**Version: **1.0

**Date:** 1 August 2023

**Description: **Initial policy

**Author:** COO

**Approved by:** CEO



**Version: **2.0

**Date:** 1 August 2024

**Description: **Annual review

**Author:** Daniel Jelly

**Approved by:** Fiona Jelly

---
Source: https://complyfirst.co/isms-policy

---

# Privacy Policy

## Privacy Policy

Thank you for trusting Complyfirst Limited (we, us or Complyfirst) to be responsible for your personal data. We respect your privacy and are committed to protecting your personal data.

This privacy policy (policy) applies to all processing of personal data undertaken by Complyfirst (other than processing of personal information in the context of recruitment and employment, which is dealt with under separate internal policies) including when you interact with us as one of our suppliers or customers (or as an employee or representative of same), when you visit our premises, or visit or use our website (regardless of where you visit it from) [https://www.complyfirst.co/](https://www.complyfirst.co/) (our website) and the software services available through it and the Complyfirst application (the software services).

Any data that we collect through our website or generally when providing you with our other services shall be known as the Customer Data, and any data collected specifically through the software services known as the Complyfirst Data.

The software services prioritise your security and privacy by implementing privacy by design and data minimisation principles. We are conscious of the sensitivity of personal data, particularly within the financial sector. As such, we aim to collect as little personal data from our users as possible (and the only personal data we collect by default through the software services are names and email addresses of users, as well as date and place of birth of shareholders or other mandatory details required for regulatory reporting which you upload via the software services).

This policy also informs you about your privacy rights and how the law protects you. It does not cover any third party website you have used to access our websites or software services, any third party websites that you access from them, or any interactions between users which have not been conducted via our website or software services.

It is important that you read this policy so that you are fully aware of how and why we are using your data.

1. WHO WE ARE
   1. Contact Details
   2. Full name of legal entity:Complyfirst Limited, a company incorporated in the Republic of Ireland under registered company number 725307.
   3. Email address:[hello@complyfirst.co](mailto:hello@complyfirst.co)
   4. Postal address: 12 Lower Hatch Street, Dublin 2, Dublin, D02 R682, Ireland
   5. Under the UK General Data Protection Regulation or the EU General Data Protection Regulation (collectively GDPR) and other relevant data protection legislation, including the UK Data Protection Act 2018 and the Irish the Data Protection Acts 1988 to 2018, we act as both a controller (i.e., where we make decisions) in relation to your personal data that we collect, as well as a processor (i.e. process data broadly in accordance with your instructions).
      1. When we act as a Processor: When our users you use the software services to process other peoples' personal data, or make decisions regarding their own personal data, we act as a processor. Under these circumstances, you may, as a user, act as a controller or processor yourself, and we will act as either a processor or a sub-processor. Any Complyfirst Data is processed by us strictly as a processor.
      2. When we act as a Controller: By contrast, when we collect personal data and determine the purposes and means of processing that personal data – for example, when we store account information for account registration, administration, services access, or contact information as explained below – we act as a controller. This policy is intended to tell you more about the ways in which we process your personal data as a controller.
   6. Third-Party Links
      1. Our websites and software services may include links or connections to third-party websites, plug-ins or applications (including various social services as a user, you may be asked to provide information about yourself, including your full name and email address, alongside other non-personal details.
      2. You may also, on behalf of your organisation, provide details such as the date and place of birth of shareholders or other mandatory details required for regulatory reporting, uploaded via the software services
      3. There are parts of our software services that may offer users the opportunity to upload text into free form fields or provide the option to bulk upload redacted data if there is a need to provide further evidence in relation to, for example, a customer complaint.
      4. In such case, you would be the controller of such data and you would be responsible for redacting the uploaded documents adequately (as to remove any personal data). Where you do share personal data relating to third parties via the software services, you must ensure you have a lawful basis to do so.
2. PERSONAL DATA WE COLLECT
   1. Financial Details: We currently only accept payment by bank transfer, and so will only collect your organisation's bank account details where you are a supplier (to make payments), or where we need to refund any money to you (as a customer). All details will be held securely.
   2. Verbal Information: If you provide verbal personal information that you give us consent to use you will have such consent confirmed back to you in writing.
   3. Marketing Strategy: If in future you will be able to communicate your preferences in receiving marketing from us and our third parties and your communication preferences (including details you provide when you opt-in to receive marketing communications from us) will constitute information you supply to us.
   4. IF YOU FAIL TO PROVIDE PERSONAL DATA
      1. Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with our software services). In this case, we may not be able to provide those services.
   5. Telephone Recordings: We may in future record telephone conversations may be recorded for training or monitoring purposes, but you will be notified of that at the time.
   6. DATA WE RECEIVE FROM THIRD-PARTIES
      1. Device Data: analytics providers such as Google or Hubspot; and search information providers such as Google.
      2. Social Media:Complyfirst may use social media, which will provide us with publicly available information through social media sites, such as Facebook, Instagram, LinkedIn, Twitter, and Google, including where you engage with us through social media sites.
      3. Publicly Available Information: we may collect personal information about you from other publicly available sources. This can include your name, address and other publicly available information. As far as possible, we ensure that where any third-parties are involved in suppling such information, that they are compliant to do so. This may include credit reference agencies such as Experian, public registers such as the UK Companies House registry, the Financial Services Register, the Irish Companies Registration Office or the relevant electoral registers.
   7. KEEPING YOUR PERSONAL DATA UP TO DATE
      1. It is important that the data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
   8. WHAT INFORMATION IS NOT COLLECTED?
      1. We do not intentionally collect sensitive personal data or special category data (including details about your race or ethnicity, religious or philosophical beliefs, medical information, sex life, sexual orientation, political opinions, trade union membership, genetic and biometric data, social security numbers). Nor do we collect any information about criminal convictions and offences.
      2. We require all of our customers to agree to procure that those using the software services do not use them to process such data, but do not actively monitor content uploaded or processed using the software services and are not responsible for enforcing those terms.
      3. If you are reviewing this policy because you believe your data has been used in violation of those terms, please contact us.
      4. If you're a child under the age of 18 (or are otherwise younger than the legal age limit required in the country in which you reside), you may not have an account on Complyfirst. Complyfirst does not knowingly collect information from or direct any of our content specifically to children we rely upon to process third-party data our users upload when using the software services.
3. HOW WE USE YOUR PERSONAL DATA
   1. We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
      1. Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
      2. Where we need to comply with a legal or regulatory obligation.
   2. Generally, we do not rely on consent as a legal basis for processing your personal data other than as set out below in relation to marketing. We may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data.
   3. Our Standard Business Operations:
      1. To provide the software services that we contract to provide to you or others;
      2. To provide you with information that you request from us;
      3. To confirm your identity as a natural living person; and
      4. As part of our billing, payments and recovery processes.
      5. For example, we may use contact information to notify you of any issues which might impact the provision of the software services to you, confirm your bookings placed via the software services, respond to requests that you make, or notify you of changes to your account or the software services.
   4. Marketing
      1. We may in future maintain contact lists (with email addresses and other information) to allow us to communicate with individuals who do business with us or who have expressed an interest in our software services.
      2. We may use your identity, contact, technical, usage and profile data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing).
      3. If you subscribe for these features, we may contact you for marketing purposes, both to inform you of any updates or news in relation to us or the software services or to otherwise inform you of information related to our business or your account with us (direct marketing relating to Complyfirst), or, if you have opted in to this feature, we may also send third party direct marketing communications to you via email, or other mediums.
      4. You will be able to ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
   5. Legal Requirements
      1. We will keep and use your data in terms of any legal or regulatory requirements that we have and can use your data to protect our legal position, if legal action is required, including the recovery of any outstanding debts.
      2. By way of further example, we will share your personal data with the relevant agencies and without notice, where we are requested to or suspect fraudulent activities, money laundering, terrorist related activities or other illegal behaviours.
   6. Enhancing the software services
      1. We may use personal data (other than that comprised in private Customer Data) for the purposes of providing or enhancing our Services and products.
   7. Website Administration and Customisation
      1. We may use the information we collect about you for a variety of website administration and customisation purposes. For example, we use your information to process your registration request, provide you with services and communications that you have requested, send you email updates and other communications, customise features and advertising that appear on our websites, deliver our websites content to you, measure Website traffic, measure user interests and traffic patterns, and improve our websites and the software services and features offered via our websites.
   8. Aggregated or Non-Identifying Information
      1. Non-identifying information includes information collected from or about you that does not personally identify you. Aggregated information is similar, but includes bulk data about, for example aggregate volumes of complaints.
      2. Insofar as aggregated or non-identifying information forms part of the Complyfirst Data, Complyfirst will not use such information for any purpose, and it is treated as strictly confidential in accordance with our customer terms (i.e. your or your organisation's name or identity will never be associated with the data), but we do reserve a right to use aggregated or anonymised data (for example, in respect of aggregate or average complaint levels or reports of fraud, for the purposes of benchmarking customers).
4. WHAT INFORMATION IS SHARED?
   1. We do not disclose personal data outside Complyfirst, except in the situations listed in this section or in the section below on Compelled Disclosure, but may have to share your personal data with the categories of processors or controllers set out below for the purposes set out above or otherwise below:
   2. any member of our group, which means our subsidiaries, our ultimate holding company, FDJ Ecommerce Ltd t/a Complyfirst, a company incorporated in England under registered company number 725307 and its subsidiaries, as defined in section 1159 of the Companies Act 2006;
   3. with HM Revenue & Customs, the Irish Revenue Commissioners, the FCA, and other authorities and regulators acting as processors of this policy and our Customer Terms [https://complyfirst.co/terms-and-conditions](https://complyfirst.co/terms-and-conditions);
   4. with the FCA or other financial regulatory authorities, where you elect to permit such disclosures as part of your use of the software services, or where we are subject to a Compelled Disclosure;
   5. with professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services, where they have a strict need to know same for any of the purposes set out above;
   6. with specific selected third parties, determined by us, where they have a strict need to know same, if you breach any agreement with us, so as to enforce our rights against you, including credit-reference agencies, debt-collection firms or service providers, solicitors or barristers and law enforcement agencies (if applicable);
   7. with other service providers acting as processors based in the European Union or United Kingdom who provide IT and system administration services, including for the performance of our contract with you, as set out below: When we transfer your data to our service providers, we remain responsible for it:
      1. with email marketing services to send marketing emails where you have opted in to receiving them. You will be able to unsubscribe directly from any mailing list using the unsubscribe links provided within emails;
      2. with analytical service providers, such as Google Analytics or Hubspot Analytics, in order to analyse our website traffic or usage of our software services to improve products and services;
      3. with external software development agencies, based in the UK or EU, in order toassist us in the provision of our software services;
      4. with processors offering software tools, or EU or UK based external servers (including externally provided original and backup servers), that are used to store personal data provided by you on our behalf (our current servers are maintained by Amazon Web Services, whose privacy policies are available at [https://aws.amazon.com/privacy/](https://aws.amazon.com/privacy/). By default, and unless we have agreed otherwise in writing with the location of these servers will be within the EU; and
      5. with providers of cloud-based customer relationship management tools, who may data with your permission, so we can perform services you have requested.
5. HOW IS MY INFORMATION SECURED?
   1. Complyfirst takes all measures reasonably necessary to protect personal data from unauthorised access, alteration, or destruction, maintain data accuracy and help ensure the appropriate use of personal data. We follow reasonable industry standards to protect the personal data we hold, both during transmission and once we receive it.
   2. In addition, we limit access to any personal data to those employees, agents, contractors, service providers and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to duties of confidentiality.
   3. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
   4. No method of transmission, or method of electronic storage, is 100% secure. Although we will do our best to protect your personal data, we cannot guarantee its absolute security. Any transmission is at your own risk.
6. HOW IS INFORMATION COLLECTED AND STORED GLOBALLY?
   1. Information that we collect will be stored and processed in the United Kingdom and European Union in accordance with this policy. Where required by law to facilitate such processing, we will ensure that they sign data transfer agreements such as EU standard contractual clause agreements or the UK international data transfer agreement.
   2. In particular:
      1. we provide clear methods of unambiguous, informed consent at the time of data collection, when we do collect your personal data and if applicable. Where consent is not the applicable ground for processing, we will ensure that it has an appropriate ground for processing any personal data (including but not limited to contractual obligation or legitimate interest);
      2. we collect only the minimum amount of personal data necessary, unless you choose to provide more. We encourage you to only give us the amount of data you are comfortable sharing;
      3. we offer you simple methods of accessing, correcting, or deleting the data we have collected; and
      4. we provide our users notice, choice, accountability, security on issues ([www.ico.org.uk](http://www.ico.org.uk/)), the Irish Data Protection Commission, the ROI supervisory authority for data protection issues ([https://www.dataprotection.ie/](https://www.dataprotection.ie/)) or other competent supervisory authority of an EU member state if the software services are accessed outside the UK or Ireland.
   3. We would appreciate the chance to deal with your concerns before you approach such bodies so would ask that you please contact us in the first instance.
7. HOW DO YOU RESPOND TO COMPELLED DISCLOSURE REQUIREMENTS?
   1. Complyfirst may disclose personal data or other information we collect about you to law enforcement in response to a valid subpoena, court order, warrant, or similar governmental order.
   2. In complying with court orders and similar legal processes, Complyfirst strives for transparency. When permitted, we will make a reasonable effort to notify users of any disclosure of their information, unless we are prohibited by law or court order from doing so, or in rare, exigent circumstances.
8. HOW CAN I ACCESS MY OWN PERSONAL INFORMATION?
   1. If you're already a user, you may access, update, alter, or delete your basic user profile information by editing your user profile or contacting us.
   2. Under certain circumstances, where you are a citizen of the European Union or UK, you have rights under data protection laws in relation to your personal data under GDPR.
   3. You have the right to:
      1. Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a (transferable) copy of the personal data we hold about you and to check that we are lawfully processing it.
      2. Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
      3. Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law.
      4. Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
      5. Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
      6. In relation to profiling you have the right not to be subject to solely automated decisions and where we make such automated decisions, you have a right to have a person review the decision.
      7. Withdraw consent at any time (or object to processing) where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
   4. If you wish to exercise any of the rights set out above, please contact us.
   5. You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
   6. Where you exercise one of your rights, we may need to request specific information from you to help us confirm your identity and ensure your right to exercise such rights. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
   7. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
9. DATA RETENTION AND DELETION
   1. Personal Data Generally
      1. We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
      2. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data or the purposes of contract administration, we will also store all data as long as the contract you have placed through us endures and for the six year limitation period thereafter in case you raise any claims in relation to any products or services you or your employer or other person by whom you have been authorised to use the software services have purchased from us.
      3. If you have otherwise closed your account through the software services, save for the anonymised data mentioned below, or the basic information mentioned above, we will endeavour to delete all personal data we no longer have grounds to process within 6 months of the date of such deletion.
      4. In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
      5. If you would like to cancel your account and initiate deletion of your personal data, you may do so by contacting us at [hello@complyfirst.co](mailto:hello@complyfirst.co). As above, we will retain and use your information as necessary to comply with our legal obligations, resolve disputes, maintain security, and enforce our agreements, but barring legal requirements, the timeframe above will be observed for deletion.
10. HOW DO YOU COMMUNICATE WITH USERS?
   1. We will use your email address to communicate with you, if you've given us the OK, and only for the reasons you'vepermitted. Emails by default are not disclosed with other users, even if you belong to the same organisation. This will not change how we contact you, as we always utilise your primary email address.
   2. Depending on your email settings, Complyfirst may occasionally send notification emails about new features, requests for feedback, important policy changes, or offer customer support. We also send marketing emails, including ones featuring new services and products offered by our commercial partners (as noted above), but only with your consent. There's an unsubscribe link located at the bottom of each of the emails we send you.
   3. Our emails might contain a pixel tag, which is a small, clear image that can tell us whether or not you have opened an email and what your IP address is. We use this pixel tag to make our email instances and legal developments.
11. CHANGES TO THIS POLICY
   1. Although most changes are likely to be minor, it may change and if it does, these changes will be posted on this page and, where appropriate, may be notified to you when you next log on to use the software services. Otherwise, any changes shall be applicable without further notice.
   2. This version one of this policy was last updated on 1st of December 2023 and historic versions can be obtained by contacting us.
12. HOW CAN I CONTACT COMPLYFIRST?
   1. Questions regarding our Privacy Policy or information practices should be directed to us via one of the contact methods that we have provided in this policy.
13. LEGAL
   1. This policy shall be governed by and interpreted in accordance with the laws of England and you irrevocably agree that the courts of England and Wales shall have exclusive jurisdiction to settle any disputes which may arise out of or in connection with this policy.

---
Source: https://complyfirst.co/privacy-policy

---

# Complyfirst Reports

> Launch, scale and report in every jurisdiction with us. No need for your teams to interpret schemas and rules from scratch.

# Multi-jurisdiction reports are covered with us.



Launch, scale and report in every jurisdiction with us. No need for your teams to interpret schemas and rules from scratch.



```json
{
  "_key": "789fed8d4b74",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "/demo",
      "label": "Get a demo",
      "variant": "contained"
    }
  ]
}
```

#

## Reports _we cover_

- [AMLREQ_CASP](https://complyfirst.co/reports/cbi-aml-req) — Annual XML report
- [AMLREQ_CI](https://complyfirst.co/reports/cbi-aml-req) — Annual XML report
- [AMLREQ_CU](https://complyfirst.co/reports/cbi-aml-req) — Annual XML report
- [AMLREQ_IF](https://complyfirst.co/reports/cbi-aml-req) — Annual XML report
- [AMLREQ_LI](https://complyfirst.co/reports/cbi-aml-req) — Annual XML report
- [AMLREQ_PIEMI](https://complyfirst.co/reports/cbi-aml-req) — Annual XML report
- [CESOP](/demo) — Quarterly XML report 
- [DORA](/demo) — Annual XBRL report 
- [EFTR](/demo) — Event-driven JSON report 
- [EIA](/demo) — Annual XBRL report
- [EIAS](/demo) — Annual XBRL supplementary report
- [FIN060a](/demo) — Annual XML report
- [FIN073](/demo) — Semi-annual XML report 
- [FIN074](/demo) — Annual XML report
- [FSA057](/demo) — Monthly XML report 
- [IPR](/demo) — Annual xBRL-CSV report 
- [M170](/demo) — Monthly XML report
- [M196](/demo) — Monthly XML report
- [PIA](/demo) — Annual XBRL report
- [PIAS](/demo) — Annual XBRL supplementary report
- [PS-Complaints](/demo) — Annual XML report
- [PSQ](/demo) — Quarterly XML report
- [PSS](/demo) — Semi-annual XML report
- [REP-CRIM](/demo) — Annual XML report 
- [REP001](/demo) — Annual XML report 
- [REP002](/demo) — Annual XML report
- [REP014](/demo) — Annual XML report 
- [REP017](/demo) — Semi-annual XML report
- [REP018](/demo) — Quarterly XML report 
- [REP020](/demo) — Quarterly XML report 
- [REP027](https://complyfirst.co/reports/rep027-fca-safeguarding-return) — Monthly XML report
- [ITP](/demo) — Monthly XML report 
- [P0607](/demo) — Quarterly XML report

### Are we missing a report?



Tell us what reports you need. Regulatory, tax, audit, fraud, or custom reports. There’s no report we can’t handle.

#   

#  

```json
{
  "_key": "5cb69ed62601",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "/demo",
      "label": "Request a report",
      "variant": "contained"
    }
  ]
}
```

---
Source: https://complyfirst.co/reports

---

# Automate Your Annual AML REQ Submission

> Automate your CBI AML REQ submission. XML generation, real-time XSD validation, and CBI portal upload across all six regulated sectors. Used by Fexco, SumUp, TransferMate, and leading Irish-regulated firms.

# Submit the CBI's AML REQ _with ease._

#  

No matter what sector you're in, we've got you covered with AML REQ reporting. From structured data collection and CBI-compliant XML generation to 1:1 support with us, _even on deadline day._

#  

```json
{
  "_key": "a86eaa6be9ec",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/cbi-aml-req#:~:text=Get%20your%20first-,AML%20REQ,-submission%20done%20for%20free.",
      "label": "Get free support on your first AML REQ submission",
      "variant": "contained"
    }
  ]
}
```

```json
{
  "_key": "b8d2c4e8bb5f",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "SECTORS WE SUPPORT"
    }
  ]
}
```

## AML REQ reporting across _all _sectors



Whatever your sector, we've got your AML REQ reporting covered.

### Payment & E-Money Institutions

Submission date 13 February 2026

### Credit Institutions

Submission date 27 February 2026

### Investment Firms

Submission date 30 June 2026

### Crypto-Asset Service Providers

Submission date 31 July 2026

### Life Insurers

Submission date 11 September 2026

### Credit Unions

Submission date 18 September 2026

```json
{
  "_key": "8fc0e0e0d784",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "WHY COMPLYFIRST"
    }
  ]
}
```

## Why CBI-regulated firms _love_ us

#  

We've got the platform and expertise to make annual AML REQ submissions stress-free, whatever your sector.

#### CBI definitions at your fingertips



The CBI's AML REQ template is dense. CBI definitions are built into every data field in both our template and the platform. You work in plain language.

#### N/A codes are automatically applied



Every data field in the AML REQ is mandatory. No blanks allowed. One click in Complyfirst automatically applies the correct, validated N/A codes.

#### Real-time validation in plain English



We validate your data as you work. When something’s wrong, we translate the error message into plain English and tell you how to fix it. Validate your reports, review errors, and make edits — all in one place.

#### Approvals & audit trail baked in



See changes, approvals and submission history for your AML REQ on one page.

#### XML output, named & ready to upload



Complyfirst has the correct CBI date format and C code already in the file name. Submit to the CBI portal without renaming or reformatting.

## You get 1:1 support   
_even on deadline day_



Talk to us on Slack, Teams, or Zoom and get fast, practical help in <1hour. Yes, even on deadline day.



```json
{
  "_key": "d4004f33f1e6",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/cbi-aml-req#:~:text=Get%20your%20first-,AML%20REQ,-submission%20done%20for",
      "label": "Get in touch",
      "variant": "contained"
    }
  ]
}
```

## Hear from _real people_ we've helped with the AML REQ

```json
{
  "_key": "6422a2be9e23",
  "_type": "image",
  "alt": "fexco Logo",
  "asset": {
    "_id": "image-638cc6c50f0db5f31fa08ce5fc9346710e5dc3c5-224x85-svg",
    "metadata": {
      "dimensions": {
        "height": 85,
        "width": 224
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAAsTAAALEwEAmpwYAAAB7UlEQVR4nJVST2sTQRR/O7uzO22NYv2DaEvSmTczMdIe0pyMiWDBg1hzKNZY21or1JM3qwhFPXlSv4B4EP0e/RKevAi9lBIzuzub3Y1BiCyCeO07Pd6P9x6/PwDHrAOYmTBQKQ+hogdQvtAHMZsRtTogcjdm8iF8BwwsqLMW8NwB1KYjqE2PYWGqWBwDPxX9m+lSBPOne6AvDly8mZG5lxnBdeupaxnBF5kjPqQuLkMK8pJ1RSf0ccW4uNz35a1wUtQNVQuGyVYYqCXD8PqAirphst1nqpm6ojN08ePQEV9ygtsZ8G5GeDcHgZBQccV6/Ln15V5I1VvDqq96TK3HVG5aqh7bQO4kFNesrzoRxQcJVavW480Rkbu/AfdzB9+nIBYLlgVbiALJE8q7MVUbEdN7YaDfGKY2DJWbMdXblv49GPv6TkRwLXH13dgTV0dEPBsB7v9y+LsUeONwip//AWUGPwFP5oGaiwIUll1um8nq7WhCNwzV89ZTzSRQNyyT7ZCKuvVky3iylRBxb+TwzyNHfB0QvmVdXClkKOSDMQAZwyL9BjW/B7oUl6pnjqB2YgxlZv4zpcAK03q+1qknnw4d8Skn8knk8UZC5P0c8FEOKI4VmdcA5DDQlZjIrZTIHQtYK54ewawo+iJGfwCC2LkgfiXAFQAAAABJRU5ErkJggg=="
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/638cc6c50f0db5f31fa08ce5fc9346710e5dc3c5-224x85.svg"
  }
}
```

```json
{
  "_key": "985cd97908a6",
  "_type": "resource-quote",
  "author": {
    "name": "Fiona Lynch",
    "position": "Head of Risk & Compliance"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "ba0d6d129166",
      "_type": "block",
      "children": [
        {
          "_key": "ed83251cf6d7",
          "_type": "span",
          "marks": [],
          "text": "\"Complyfirst took the pain out of the AML REQ return. The platform generated the XML file for us, and Fiona and Dan were quick and helpful on Teams throughout. "
        },
        {
          "_key": "f4c2fc9fa887",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "We submitted our return to the CBI same day and saved hours of effort.\""
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "53bb7d8ee394",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "4141e2ae8fec",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "228906609140",
          "_type": "block",
          "children": [
            {
              "_key": "20206abf2251",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Same-day submission "
            },
            {
              "_key": "856ffcfa364b",
              "_type": "span",
              "marks": [],
              "text": "to the CBI\n"
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "ff1ab8c55143",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "83caa182c3e5",
          "_type": "block",
          "children": [
            {
              "_key": "4da97b25cb04",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Hours of manual effort saved"
            },
            {
              "_key": "cf7633a60bf6",
              "_type": "span",
              "marks": [],
              "text": "\n"
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ]
    }
  ]
}
```

```json
{
  "_key": "973fa909ed23",
  "_type": "image",
  "alt": "Sumup Logo",
  "asset": {
    "_id": "image-aa4f4898a13092cd6622658a5c3f7d1d945f3e77-180x72-svg",
    "metadata": {
      "dimensions": {
        "height": 72,
        "width": 180
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAAsTAAALEwEAmpwYAAABrklEQVR4nKVSy24UMRA0j+UtZTNjt3f2MeNub0CbSEFiEXCBiBMIorBrT3uCRHhEaDlxgUsQh3wDQXAGwS0n+AfELcA3hBt8BPJMxAeApZKqW3bZ1WUB6JelDRc65C9GRK6Glc2y1VPiXxbY8E4TfwTiN0C809TVVhQVgo+I4c3jYjxr1VysHBXFgxM1Iq97s5ZY5GNNPWsJIN4H4j1A3tHEbzWFH0BhVxt/WebTbH7gl1LD59rGFZA7io7aZnp+Lmec794ZSJyc7eS8qIvKpIP1bhT8pYm/APIzoHJbU/UdLH/WNlyHIlyR6DcV8UOFXErjKmV4IzW8odD5tAiTyDXypia+HS8TYPm3pvANkF8Chuea+Ksm/iSNu5blPFZUPpJYPlamvC+pXE8Nr0n0qwqDj2IphSfKlE8luVvJcNqPL/zZ2OTXje2wB5Z3NfKlTodVUlSjZKEaJcVkpCwPkz730sFady531O755Tb6q8q4G5LcQj1LIH5fw4ZXMRhN4YPG8CIergcdN8VQ6sGPD8I5CKjPJ89kd2XSm/aFvne6Sfn/vs2hv0mL7cOx8wd6Q22l7qKvgAAAAABJRU5ErkJggg=="
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/aa4f4898a13092cd6622658a5c3f7d1d945f3e77-180x72.svg"
  }
}
```

```json
{
  "_key": "614e1e989f6a",
  "_type": "resource-quote",
  "author": {
    "name": "Adrian Witkowski",
    "position": "Head of Regulatory Reporting"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "715b61aa6813",
      "_type": "block",
      "children": [
        {
          "_key": "50ad6800e364",
          "_type": "span",
          "text": "\"What used to take weeks was fixed in hours with Complyfirst. "
        },
        {
          "_key": "abb0f664abaf",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "We were live, errors resolved, and submitted within 48 hours.\""
        }
      ],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "645b84deaf2b",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "67fcddf80386",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "1e25f7bdb0f6",
          "_type": "block",
          "children": [
            {
              "_key": "afe6bd2f6af9",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "90%"
            },
            {
              "_key": "4d16a75c54a7",
              "_type": "span",
              "text": " less reporting effort"
            }
          ],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "a5981cc9588a",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "fa844f594213",
          "_type": "block",
          "children": [
            {
              "_key": "0651cd8943df",
              "_type": "span",
              "text": "SumUp was onboarded, validated, and live on Complyfirst within "
            },
            {
              "_key": "41c1c7ef0530",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "48 hours."
            }
          ],
          "style": "normal"
        }
      ]
    }
  ]
}
```

```json
{
  "_key": "973fa909ed23",
  "_type": "image",
  "alt": "transfermate Logo",
  "asset": {
    "_id": "image-dbf322a28bee208223de5005503e8e934620d058-235x53-svg",
    "metadata": {
      "dimensions": {
        "height": 53,
        "width": 235
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAFCAYAAABFA8wzAAAACXBIWXMAAAsTAAALEwEAmpwYAAABMElEQVR4nI1QyU4CQRCdg3p0Y5kBEZipahi5EjDAdPWAyEHFoHH36snEJZ5ED5XuHtRf8G9N8wVW8lJV71WlFq+meLPZ53I4WvgujsY/G847NBTnW4qD+OArt9R6XETFlVhmJccv82RRcDp2eV0pXvEEmT0kPUXKpqA4hQGnQHooEjuOSJ+hMhcoeSJIy4j4SCh7C6m9BjJXgsx5Q5mZkNkxkO412pz3QNpd1wxkTh1cESRmFiXmBpR5QGnvHe8GIpk7JP2IqXkBZZ9Q6lcg/SYoe0alL6vyM/RaLV6LO8uTAjHKdqIBV91ZNcV1HFpwuXsJ9i2EkrthwuOQ9CEMbFqXPMHEnDg0JffD0dz3/m3t39Vq8r1V3J/7fo+L5c57LkjmhVqHg1h+lCoT3nbL/QHnB2C2ohD/mQAAAABJRU5ErkJggg=="
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/dbf322a28bee208223de5005503e8e934620d058-235x53.svg"
  }
}
```

```json
{
  "_key": "614e1e989f6a",
  "_type": "resource-quote",
  "author": {
    "name": "Peter Hession",
    "position": "Chief Risk Officer (CRO)"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "e481c64def2f",
      "_type": "block",
      "children": [
        {
          "_key": "edc6568664a0",
          "_type": "span",
          "marks": [],
          "text": "\"Our AML REQ "
        },
        {
          "_key": "01560b449105",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "went through first time"
        },
        {
          "_key": "b9431d8b5dbe",
          "_type": "span",
          "marks": [],
          "text": " a couple of days ago thanks to your help!\""
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

## FAQs

```json
{
  "_key": "80c530aef9ee",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "95add75abaac",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "9fcdf8c88efe",
          "_type": "block",
          "children": [
            {
              "_key": "18f975fd4595",
              "_type": "span",
              "marks": [],
              "text": "The AML REQ is the Central Bank of Ireland's annual anti-money laundering data return. Regulated firms must report on their money laundering and terrorist financing risk across customers, products, services, and jurisdictions. It is submitted annually in XML format via the CBI portal, using the CBI's prescribed XSD schema."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the AML REQ?"
    },
    {
      "_key": "7e89a0cb7763",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "7ae2a6d1fbe4",
          "_type": "block",
          "children": [
            {
              "_key": "966c106a28bc",
              "_type": "span",
              "marks": [],
              "text": "AML REQs currently apply across six regulated sectors: credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers, life insurance firms, and credit unions. Each sector is subject to specific CBI sectoral guidance and has a separate annual submission deadline."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Which firms are required to submit an AML REQ?"
    },
    {
      "_key": "3d5905731ecc",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "fd0e67105f89",
          "_type": "block",
          "children": [
            {
              "_key": "9a88d8ed1ebf",
              "_type": "span",
              "marks": [],
              "text": "The AML REQ is an annual regulatory return. Each sector has a different submission date set by the Central Bank of Ireland. Payment and e-money institutions submit in February. Credit institutions submit in late February. Investment firms submit in June. Crypto-asset service providers submit in July. Life insurers in September. Credit unions in September."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "How often is the AML REQ submitted?"
    },
    {
      "_key": "f344b6b1195f",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "4be8a6b8d964",
          "_type": "block",
          "children": [
            {
              "_key": "c5dc98eb07ff",
              "_type": "span",
              "marks": [],
              "text": "The CBI requires AML REQ submissions in XML format using the prescribed XSD schema. Excel files may be provided for reference purposes but cannot be submitted. The XML file must also follow the CBI's file naming convention, including the correct date format and C code, or the portal will reject it."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What format must the AML REQ be submitted in?"
    }
  ]
}
```

---
Source: https://complyfirst.co/reports/cbi-aml-req

---

# Automate Monthly REP027 Submissions

> Automate your monthly FCA Safeguarding Return (REP027). XML generation,
XSD validation, and direct RegData API submission. Used by leading UK PIs and EMIs.

# Submit REP027 _accurately,_ every month.



Automate your monthly REP027 process, from XML generation and XSD validation through to direct submission via FCA RegData, with 1:1 support whenever you need it.

# 

#  

```json
{
  "_key": "9d7c0e39e318",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/rep027-fca-safeguarding-return#:~:text=a%20quarter%20of-,REP027,-returns%20done%20for",
      "label": "Get free support on your first quarter of REP027 submissions",
      "variant": "contained"
    }
  ]
}
```

```json
{
  "_key": "e39e6d2d06a7",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REGULATORY CONTEXT"
    }
  ]
}
```

## What is the FCA Safeguarding Return (REP027)?

  
REP027 is the FCA's monthly safeguarding return for UK payment institutions and e-money institutions. Introduced under PS25/12, it requires firms to report how client funds are held against their safeguarding obligations, covering balances, where funds are held, reconciliations, and any notifiable CASS breaches. It must be submitted in XML format via FCA RegData within 15 business days of month-end, every month.

```json
{
  "_key": "9d37bc3991be",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "WHY COMPLYFIRST"
    }
  ]
}
```

## How we make REP027 _repeatable_

#  

We've got the platform and expertise to make monthly REP027 returns accurate and repeatable.

#### No monthly manual data-entering



Drop your data in. The platform maps it to the REP027 schema and generates the XML. No reformatting, re-keying, or starting from scratch each month.

#### Validation before submission reaches RegData



Every return is checked against the FCA’s REP027 XSD schema before it reaches RegData. When something’s wrong, we translate the error message into clear "how-to-fix-it" steps.

#### Direct API with FCA RegData



We have a direct API integration with FCA RegData. No logging in and keying fields line by line. The submission goes from Complyfirst to RegData in one step.

#### Approvals & audit trail are built-in for good governance



Everything your safeguarding accountable individual needs to confidently sign off is in the platform. If the FCA queries how a return was prepared, you have the answer in seconds.

## You get 1:1 support   
_even on deadline day_



REP027 is due within 15 business days of month-end. If something doesn't look right on day 14, you need an answer fast. Talk to us on Slack or Teams and get a response <1hour. Yes, even on deadline day.



```json
{
  "_key": "16685fcb2945",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/rep027-fca-safeguarding-return#:~:text=a%20quarter%20of-,REP027,-returns%20done%20for",
      "label": "Get in touch",
      "variant": "contained"
    }
  ]
}
```

## Don't just take our word for it...

```json
{
  "_key": "0ed668a3e722",
  "_type": "image",
  "alt": "Decta Logo",
  "asset": {
    "_id": "image-e3aaf09403b85d61f1b5f2476a929595bee2bf77-158x34-svg",
    "metadata": {
      "dimensions": {
        "height": 34,
        "width": 158
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAYAAACOXx+WAAAACXBIWXMAAAsTAAALEwEAmpwYAAABEUlEQVR4nDXNsUoDURCF4byBsPfO3GDh7sxESGGrIIoSNUiamOzemU0iiAoGG22CViqmMCgWKkQsFdT3lIgWp/y/U8EsHwaOn8hx6rPOZkK6gqIPWLMpiO36RdtALibA8Q4zbXvSY0/xA8ieE9auYx0A6ZMjG82lZVbBTIdAOka2K+R8kJDtANulY71wkjdQir3Aeh7EGpBqNfwe2ghYDx3rFoidodgLkI0D29I/eIus15DFA6C8QLJHz3rjFrpbyNr1f+B8veNAtIYU97GmTWBbm3Uo5StyOUHR1Qqmehq4/AKyt4R6TZ8WrcD6jaTvVS5aTqyBFO+RdQKs6y7t15302jOsSraMoifA/aPZkMvtH1mOSj/w4XWpAAAAAElFTkSuQmCC"
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/e3aaf09403b85d61f1b5f2476a929595bee2bf77-158x34.svg"
  }
}
```

```json
{
  "_key": "1f8a27212c95",
  "_type": "resource-quote",
  "author": {
    "name": "Neil McDermott",
    "position": "Chief Financial Officer"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "bd8edf1d9c59",
      "_type": "block",
      "children": [
        {
          "_key": "b1d3a546e8ee",
          "_type": "span",
          "text": "\"I’ve worked at large banks with entire teams managing returns. "
        },
        {
          "_key": "ab381ca39a54",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "With Complyfirst, we had it done in days.\""
        }
      ],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "12e5a661c2fd",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "8dacdd8c5ef3",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "21ed06403d42",
          "_type": "block",
          "children": [
            {
              "_key": "76b9f6815953",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "<24hr"
            },
            {
              "_key": "a09cb0ca6d94",
              "_type": "span",
              "text": " time to go live"
            }
          ],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "fa0428750040",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "f075e5f6b24c",
          "_type": "block",
          "children": [
            {
              "_key": "d0d269e0b0bb",
              "_type": "span",
              "text": "Decta submitted clean regulatory returns with "
            },
            {
              "_key": "5995a2a33c28",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "0 issues"
            },
            {
              "_key": "be24c15e75af",
              "_type": "span",
              "text": " or rework."
            }
          ],
          "style": "normal"
        }
      ]
    }
  ]
}
```

#

```json
{
  "_key": "535c85d0ef10",
  "_type": "image",
  "alt": "Sumup Logo",
  "asset": {
    "_id": "image-aa4f4898a13092cd6622658a5c3f7d1d945f3e77-180x72-svg",
    "metadata": {
      "dimensions": {
        "height": 72,
        "width": 180
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAAsTAAALEwEAmpwYAAABrklEQVR4nKVSy24UMRA0j+UtZTNjt3f2MeNub0CbSEFiEXCBiBMIorBrT3uCRHhEaDlxgUsQh3wDQXAGwS0n+AfELcA3hBt8BPJMxAeApZKqW3bZ1WUB6JelDRc65C9GRK6Glc2y1VPiXxbY8E4TfwTiN0C809TVVhQVgo+I4c3jYjxr1VysHBXFgxM1Iq97s5ZY5GNNPWsJIN4H4j1A3tHEbzWFH0BhVxt/WebTbH7gl1LD59rGFZA7io7aZnp+Lmec794ZSJyc7eS8qIvKpIP1bhT8pYm/APIzoHJbU/UdLH/WNlyHIlyR6DcV8UOFXErjKmV4IzW8odD5tAiTyDXypia+HS8TYPm3pvANkF8Chuea+Ksm/iSNu5blPFZUPpJYPlamvC+pXE8Nr0n0qwqDj2IphSfKlE8luVvJcNqPL/zZ2OTXje2wB5Z3NfKlTodVUlSjZKEaJcVkpCwPkz730sFady531O755Tb6q8q4G5LcQj1LIH5fw4ZXMRhN4YPG8CIergcdN8VQ6sGPD8I5CKjPJ89kd2XSm/aFvne6Sfn/vs2hv0mL7cOx8wd6Q22l7qKvgAAAAABJRU5ErkJggg=="
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/aa4f4898a13092cd6622658a5c3f7d1d945f3e77-180x72.svg"
  }
}
```

```json
{
  "_key": "0b3043c7d8a4",
  "_type": "resource-quote",
  "author": {
    "name": "Adrian Witkowski",
    "position": "Head of Regulatory Reporting"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "07c68c469af1",
      "_type": "block",
      "children": [
        {
          "_key": "e6d8d2ec7f64",
          "_type": "span",
          "text": "\"What used to take weeks was fixed in hours with Complyfirst. "
        },
        {
          "_key": "a2683f80a2a4",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "We were live, errors resolved, and submitted within 48 hours.\""
        }
      ],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "7edf863d17bd",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "dda9b6e81274",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "f590909cd97b",
          "_type": "block",
          "children": [
            {
              "_key": "971e54412080",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "90%"
            },
            {
              "_key": "5f0ca5cce475",
              "_type": "span",
              "text": " less reporting effort"
            }
          ],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "57c1d00919a1",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "52b3d1800ca4",
          "_type": "block",
          "children": [
            {
              "_key": "d7045c656120",
              "_type": "span",
              "text": "SumUp was onboarded, validated, and live on Complyfirst within "
            },
            {
              "_key": "d8ee704b4426",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "48 hours."
            }
          ],
          "style": "normal"
        }
      ]
    }
  ]
}
```

```json
{
  "_key": "396094e8d0dc",
  "_type": "image",
  "alt": "TrueLayer Logo",
  "asset": {
    "_id": "image-44014da9a57177091c902bed58a897126f321b97-180x72-svg",
    "metadata": {
      "dimensions": {
        "height": 72,
        "width": 180
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAAsTAAALEwEAmpwYAAABLklEQVR4nK1R22rCQBCdvgjGxJi9WFOCySYbk4bGilZrESu+CS02mziCl9I3H/r/H1A2pV9QBw4zzBzOzGEArh2co2ndFdQJ0YYMGwBw8y9BKvZT6u/XPNwveITS7r85dn50zMGB/S3SsP2PDs/QhDk2wcNm3ct/uT2J3B0cmAawCC88xC8qdice4caUmBm5Gnfiasn75YL1cULD6okInJlxcd8YFgMr2CYkLmZGqsZGhiN9EAtwdeuXa+Bi980D/OQCd0ziyo7L0MwwI1LNu76aU6GmJKietWArVQ/GSD3aKU6csFy0csytBBPtjolq2QvKV9DEboQvLFJjIpUH7rsBw3NLW6zt1/no6JrITVvbtNKCatBka2m+nrc9JJ6HBFz3YhB5atfDazzl2vEDKIE7YLedL4AAAAAASUVORK5CYII="
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/44014da9a57177091c902bed58a897126f321b97-180x72.svg"
  }
}
```

```json
{
  "_key": "b768dbe0816d",
  "_type": "resource-quote",
  "author": {
    "name": "Pamela Crilly",
    "position": "EU COO"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "f8e50923054d",
      "_type": "block",
      "children": [
        {
          "_key": "2fa8382a2989",
          "_type": "span",
          "text": "\"What sets Complyfirst apart is its ability to "
        },
        {
          "_key": "303156228b6f",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "simulate a regulator’s review"
        },
        {
          "_key": "6c070f63daf6",
          "_type": "span",
          "text": ", identifying discrepancies before the actual submission.\""
        }
      ],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "aff99be54f88",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "4fe46ad8dfbb",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "3a2a07a4a5a1",
          "_type": "block",
          "children": [
            {
              "_key": "4733674ff069",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "50%"
            },
            {
              "_key": "24d52b471d45",
              "_type": "span",
              "text": " less reporting effort"
            }
          ],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "d9dffd5e9a44",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-9e007efb92d9e3eafe875434f596ce689af059e5-600x600-svg",
          "metadata": {
            "dimensions": {
              "height": 600,
              "width": 600
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADc0lEQVR4nM1UW0hTYRw/6tTlJW2pc17m2KWLpkVjOrczPzYvRVh0YQ/5khAWURQRgVDwPeTc2eVMhxcYhAbShWEEPZTQw16iJx/EjppHT2dnNjOzMujy+MVfuzgFK+ihD/4P53zf+f9/t+9Q1P+0CCFJmCLJUBRFJW16OOwkKb7GsUymQcjpQmIuVC96k4URkY2GSOoT5n1O+PSywo9e5LFNMQVrfraFUGRjU5jGmmNb4GC3VVAH7ZKORTE9VBcSNYFjUdVj/FUzcv3T3oGWhUo/End57C93dtgmVbicS9uAKljNb2WsgjpAS9qAbVLVT0vbfiDsOSIVDbUu7h++/MF+t+2dpf/Iq50++0SZp27WwCC+BKOI/JceFEkCSr7al2WApLN+cnvYCRNXaRBMkh+5SP79y0vm222LqO/o/O5uh6D022ZK3fS01k1L25zOcMrPhkE9n+6xTBVBM0CTsElRFOh2Hy+VDLXNm0JOoTJgi6qCaK4kUC9pMXqRB9quPZ901TKVDbBZc0wB1NdrO4iI/Obx+bK+Q+Ju1hErBmR+FN/FoLmS4EE+fY0JOBkccjnGlTdsM6XYzCkwiiRMg2cXzeeDQR6LVATVSQs7VrRrENS4OZ6RQBUcAqegvPbnOj+K54WMJPXHQIiOu17SAkUv4gq9dl4H8oCGXrukg/01VEQ5UPXUzRnAXSgWzejhw3A5lwb7gBy0ddWMK91oSgPOXqkaywQj2NU45SZEZQUBPa3tRDF9hy2qWh0wYWAd08UgPiCCCAXhfcOsgW3iFJA5kMGNRA2kIzHMKCLz1c4WeGmhirFLFYHvTX2OaDljlSpA+MCBqKr3sFQx0LpoeIhJRi/isgB1t2NBecY4uiJPYtPmeAaI7KuPmVw0X+5FYiE0AgSuGkHZc/TVjnvnlk0j+Kv+6VWSDZKANIxxRb+NVw5yB2H2odgexiZUw5VizZwC6PQ0SEUDrfOmh+2fTSPXvpSGDiyqvBZeB0Px+uuWSJ3IfI2vC5g6odKLpvcxVk4dpPn8vhNzVXcuvHWELy4b+49LWnAWooORKP/tXyaCiCx4kN/aA3mrmzUA0sGWN9bw+aXGWy1vjWAQ/DhWw0w2b7Z2QQ7bTZPbu5sF9fDZj4YHlz5oQifjeRhxWeuD/8fLSYVTBk+J8ggmULK/QvSv1jf+h7s+p7iTkwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/9e007efb92d9e3eafe875434f596ce689af059e5-600x600.svg"
        }
      },
      "text": [
        {
          "_key": "f040dc6a792b",
          "_type": "block",
          "children": [
            {
              "_key": "e5693ec7f795",
              "_type": "span",
              "marks": [],
              "text": "Regulatory return was submitted within "
            },
            {
              "_key": "96198e50c8c8",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "24 hours."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ]
    }
  ]
}
```

## FAQs

```json
{
  "_key": "f759a601775c",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "740c51849d0a",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "b04bc0fa3b28",
          "_type": "block",
          "children": [
            {
              "_key": "b4b8ca0d6dbd",
              "_type": "span",
              "marks": [],
              "text": "Any UK PI or EMI that safeguards customer funds must submit REP027. This includes authorised PIs, authorised EMIs, and small PIs or EMIs that have opted into the safeguarding regime. If your firm holds client funds and is regulated by the FCA under the Payment Services Regulations or E-Money Regulations, REP027 applies to you."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Which firms need to submit REP027?"
    },
    {
      "_key": "974ee51c7888",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "fc4dc7993275",
          "_type": "block",
          "children": [
            {
              "_key": "1f6a8d5293c7",
              "_type": "span",
              "marks": [],
              "text": "REP027 is a monthly return. The deadline is 15 business days after month-end."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "How often does REP027 need to be submitted?"
    },
    {
      "_key": "743e754a359c",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "9c82503ee718",
          "_type": "block",
          "children": [
            {
              "_key": "1f238d9c980b",
              "_type": "span",
              "marks": [],
              "text": "REP027 must be submitted as an XML file, validated against the FCA’s published REP027 XSD schema. It is submitted through FCA RegData. If the file does not validate against the XSD schema, RegData will reject the submission."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What format does REP027 need to be submitted in?"
    }
  ]
}
```

---
Source: https://complyfirst.co/reports/rep027-fca-safeguarding-return

---

# Resources

---
Source: https://complyfirst.co/resources

---

# Service Level Agreement

## Complyfirst - Service Level Agreement

## Definitions

```json
{
  "_key": "3bb9f38bcd87",
  "_type": "html-block",
  "html": "<table style=\"border:none;border-collapse:collapse;\">\n                                    <tbody>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Commercially Reasonable Efforts</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>the same degree of priority and diligence with which Complyfirst meets the support needs of its other similar customers, but no less than a reasonable and prudent standard.</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Contract</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>means the contract between Complyfirst and the Customer.&nbsp;</span><span>&nbsp;</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Customer Cause</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>any of the following causes:</span></p>\n                                            <ol type=\"a\">\n                                                <li>\n                                                    any improper use, misuse or unauthorised alteration of the Software by Customer (including any of its customers, in cases where Customer is a reseller) and any of their authorised users;\n                                                </li>\n                                                <li>\n                                                    any use of the Software by Customer in a manner inconsistent with any written instructions or specifications provided by Complyfirst;\n                                                </li>\n                                                <li>\n                                                    the use by Customer of any hardware or software, or third party integration, with the Software that are not provided or implemented by Complyfirst or approved by the Complyfirst for use in connection with the Software;\n                                                </li>\n                                                <li>\n                                                    the use of a non-current version or release of the Software;\n                                                </li>\n                                                <li>\n                                                    any other cause outside of Complyfirst’s reasonable control, including any other such circumstances specified in the Contract.\n                                                </li>\n                                            </ol>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Fault</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>any failure of Complyfirst to deliver Software (where provided on a Saas basis) with reasonable skill and care and providing the baseline functionality specified in the Proposal, including any failure or error referred to in the Service Level Table.&nbsp;</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Help Desk Support</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>any support provided by help desk technicians sufficiently qualified and experienced to identify and resolve most support issues relating to the Software.</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Complyfirst</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>As defined in the Contract.&nbsp;</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Out-of-scope Services</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>any services which are outside the scope of the Support and Services, including:</span></p>\n                                            <ol type=\"a\">\n                                                <li>\n                                                    any services provided by Complyfirst in connection with any apparent problem regarding the Software reasonably determined by Complyfirst not to have been caused by a Fault, but rather by a Customer Cause or a cause outside Complyfirst’s control (including any investigational work resulting in such a determination);\n                                                </li>\n                                                <li>\n                                                    any Support provided pursuant to paragraph 1.3; or\n                                                </li>\n                                                <li>\n                                                    any other services in respect of matters which are outside the scope of a Fault (as defined).\n                                                </li>\n                                            </ol>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Software</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>as defined in the Contract, and includes the Subscription Services through which the Software is made available.&nbsp;</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Services</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>as defined in the Contract.&nbsp;</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Service Level Table</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>the table set out in paragraph 4.2.</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Service Levels</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>the target response times referred to in the Service Level Table.</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Solution</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>either of the following outcomes:</span></p>\n                                            <ol type=\"a\">\n                                                <li>\n                                                    correction of a Fault; or\n                                                </li>\n                                                <li>\n                                                    a workaround in relation to a Fault (including a reversal of any changes to the Software if deemed appropriate by Complyfirst) that is reasonably acceptable to Customer.\n                                                </li>\n                                            </ol>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Support&nbsp;</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>as defined in the Contract. &nbsp;</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Support Hours&nbsp;</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>means 9am to 5pm GMT on Business Days in the UK and Ireland.&nbsp;</span></p>\n                                        </td>\n                                    </tr>\n                                    <tr>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><strong><span>Support Request</span></strong></p>\n                                        </td>\n                                        <td style=\"border: solid #000000 0.5pt;\">\n                                            <p><span>request made by Customer for Support through the Complyfirst proscribed mechanisms for raising Support tickets.</span></p>\n                                        </td>\n                                    </tr>\n                                    </tbody>\n                                </table>"
}
```

1. SUPPORT SERVICES
   1. During the Term, Complyfirst shall perform the Support during the Support Hours in accordance with the Service Levels. This SLA shall form part of the Customer’s Contract and shall be subject to the terms thereof. Any terms defined but not used herein have the meaning given to them in the Contract.
   2. As part of the Support Services, Complyfirst shall:
      1. provide Help Desk Support by means of in-Service functionality;
      2. use Commercially Reasonable Efforts to correct all Faults notified under paragraph 3.1; and
      3. provide technical support for the Software in accordance with the Service Levels.
   3. Any Support provided (at the Customer’s request for such Support) by an individual whose qualification or experience is greater than that reasonably necessary to resolve the relevant Support Request shall be deemed an Out-of-scope Service, provided that an appropriately qualified or experienced individual was available at the time when such Support was sought.
   4. Complyfirst may reasonably determine that any services are Out-of-scope Services. If Complyfirst makes any such determination, it shall promptly notify Customer of that determination. The caveats and exclusions around the warranty set out in the Contract shall generally apply.
   5. Customer acknowledges that Complyfirst is not obliged to provide Out-of-scope Services having adjudged any Support to require Out-Of-Scope Services.
2. FEES
   1. The provision of Support Services on a remote, off-site basis (such as over the telephone or by e-mail) shall be included in the Subscription Charges, subject to reasonable usage and the other terms of the Contract.
   2. The provision of Out-of-scope Services shall be charged for at the applicable time and materials rates set out in Complyfirst’s published tariff schedule provided in the relevant Proposal.
3. SUBMITTING SUPPORT REQUESTS AND ACCESS
   1. Customer may request Support by way of a Support Request. Each Support Request shall include a description of the problem and the start time of the incident. Customer shall provide Complyfirst with prompt notice of any Faults.
   2. All Support tickets must be raised, and will be dealt with, in accordance with the terms of the Contract and any published support services policy we may introduce from time to time.
   3. All Support shall be provided remotely from Complyfirst’s office and provided in English. Remote access must be provided by Customer to allow Complyfirst access to Customer Equipment for emergency fixes, if required and requested.
4. SERVICE LEVELS
   1. Complyfirst will use Commercially Reasonable Efforts to make the Software available 24 hours a day, 7 days a week with 99.5% uptime, except for:
      1. planned maintenance carried out outside of Complyfirst’s Business Hours; and
      2. unscheduled maintenance, provided that Complyfirst have used reasonable endeavours to give Customer at least 4 hours' notice in advance; and
      3. downtime outside Complyfirst’s reasonable control, as further outlined in the Contract (including, where or to the extent any downtime relates to issues with any downloadable application comprised in the Software, any downtime attributable to the Customer Equipment or third party integrations not under Complyfirst’s control).
   2. Complyfirst will:
      1. use all reasonable endeavours to respond to requests for Support made through the helpdesk; and
      2. determine, acting reasonably, into which severity category an issue raised through the Support falls.
      3. use all reasonable endeavours to respond to Faults raised by Customer in accordance with the following response time matrix and work to provide a Solution as soon as reasonably possible.

```json
{
  "_key": "6b343372a301",
  "_type": "html-block",
  "html": "<table style=\"border-collapse: collapse; width: 100%;\">\n  <thead>\n    <tr style=\"background-color: #3cafd1; color: white;\">\n      <td style=\"border: 1px solid #ddd; padding: 12px;\">LEVEL OF SEVERITY</td>\n      <td style=\"border: 1px solid #ddd; padding: 12px;\">DESCRIPTION OF SEVERITY</td>\n      <td style=\"border: 1px solid #ddd; padding: 12px;\">TARGET RESPONSE TIMES (WITHIN BUSINESS HOURS)</th>\n    </td>\n  </thead>\n  <tbody>\n    <tr>\n      <td style=\"background-color: #d85156; color: white; border: 1px solid #ddd; padding: 12px; text-align: center;\">Level Red</td>\n      <td style=\"background-color: white; color: black; border: 1px solid #ddd; padding: 12px; text-align: center;\">Production application down or major malfunction resulting in majority of users unable to perform their normal functions.</td>\n      <td style=\"background-color: white; color: black; border: 1px solid #ddd; padding: 12px; text-align: center;\">4 Hours</td>\n    </tr>\n    <tr>\n      <td style=\"background-color: #f6793f; color: white; border: 1px solid #ddd; padding: 12px; text-align: center;\">Level Orange</td>\n      <td style=\"background-color: white; color: black; border: 1px solid #ddd; padding: 12px; text-align: center;\">Critical loss of application functionality or performance resulting in high number of users unable to perform their normal functions.</td>\n      <td style=\"background-color: white; color: black; border: 1px solid #ddd; padding: 12px; text-align: center;\">8 Hours</td>\n    </tr>\n    <tr>\n      <td style=\"background-color: #deda01; color: black; border: 1px solid #ddd; padding: 12px; text-align: center;\">Level Yellow</td>\n      <td style=\"background-color: white; color: black; border: 1px solid #ddd; padding: 12px; text-align: center;\">Moderate loss of application functionality or performance resulting in multiple users impacted in their normal functions.</td>\n      <td style=\"background-color: white; color: black; border: 1px solid #ddd; padding: 12px; text-align: center;\">1 Business Day</td>\n    </tr>\n    <tr>\n      <td style=\"background-color: #5164df; color: white; border: 1px solid #ddd; padding: 12px; text-align: center;\">Level Blue</td>\n      <td style=\"background-color: white; color: black; border: 1px solid #ddd; padding: 12px; text-align: center;\">Minor loss of application functionality or Software feature question.</td>\n      <td style=\"background-color: white; color: black; border: 1px solid #ddd; padding: 12px; text-align: center;\">2 Business Days</td>\n    </tr>\n  </tbody>\n</table>"
}
```

---
Source: https://complyfirst.co/sla

---

# Slavery Policy

# **Modern Slavery Statement**

Complyfirst Limited is committed to conducting business responsibly and with respect for human rights. We have zero tolerance for modern slavery, forced labour, human trafficking, or exploitative labour practices in our operations or supply chain.

This statement outlines the steps we take to prevent modern slavery and human trafficking across our operations and supply chain, including in accordance with the UK Modern Slavery Act 2015.

### **Our business**

Complyfirst provides compliance workflow automation software to regulated financial institutions. We operate primarily in the United Kingdom, Ireland, and across the European Union.

Our business is professional and technology-driven, with a hybrid workforce and a limited supplier base consisting mainly of technology providers, cloud infrastructure services, and professional services firms. As a result, we consider the risk of modern slavery in our direct operations to be low.

### **Our approach**

Our commitment to ethical conduct is supported by policies covering human rights and labour standards, anti-bribery and corruption, whistleblowing, and supplier due diligence.

We take a risk-based approach to supplier oversight, including due diligence during onboarding and periodic review of supplier relationships.

### **Our people and governance**

We are committed to fair treatment, lawful employment practices, and a respectful working environment. Concerns about unethical conduct can be raised through our whistleblowing process and are reviewed confidentially by senior management.

This statement is reviewed periodically by senior management.

---
Source: https://complyfirst.co/slavery-policy

---

# AML REQ for CIs Snapshot

> High-level overview of the Central Bank of Ireland AML REQ for Credit Institutions, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.

```json
{
  "_key": "85df3aed112e",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## AML REQ for Credit Institutions



The AML REQ is the Central Bank of Ireland’s annual data return on your firm’s money laundering and terrorist financing risk. Customers, products, jurisdictions, controls.

****

**The return must be submitted through the Central Bank Portal using the prescribed XML schema. Only XML submissions are accepted.**



Why it matters:

- **Statutory:** Mandatory under your AML/CFT obligations.
- **Supervisory:** The data directly shapes whether the CBI lines you up for a deep-dive inspection.
- **Strategic:** Feeds into the incoming EU AMLA framework
- **Visible:** Quality and completeness signal the maturity of your AML programme.

*What’s the scope?*

### Entities in scope

**Credit Institutions regulated by the CBI **must each submit their own REQ, with group and branch reporting determined by the institution’s legal structure.

### Group & branch reporting

Irish branches should report Irish branch data only, EU parent undertakings must aggregate EEA branch information excluding non-EEA branches, and non-parent group firms should report for the Irish institution only.

### Activity covered

The Credit Institutions REQ captures data across customer risk, correspondent relationships, crypto-asset exposure, lending and investment activities, onboarding channels, and transaction monitoring and sanctions controls.

### Reporting dates

**Standard reference date: **31 December of the preceding calendar year



**First submission deadline: **27 February 2026

### Reporting frequency

**Annual **reporting

### File format

**XML format only**, aligned with the prescribed XSD schema and required XML wrapper. The XML file must be validated before upload to the Central Bank Portal.

## Need a hand submitting your AML REQ?

We'll do your first return _for free._

```json
{
  "_key": "780bd8ec4e57",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/cbi-aml-req",
      "label": "Learn more",
      "variant": "contained"
    }
  ]
}
```

## _Key_ data areas



 The Credit Institutions REQ requires information across:

- Legal structure and international presence
- Statement of compliance
- Customer segments and customer risk exposure
- High-risk customers and sectors
- Correspondent relationships, including nesting and payable-through account exposure
- Crypto-asset products, trading, custody and wallet exposure
- Cash deposits, withdrawals and high-value cash activity
- Currency cash exchange
- Safe deposit boxes
- Virtual IBAN accounts
- Prepaid cards
- Lending, factoring and trade finance
- Investment services and activities
- Money remittance
- Physical presence, residence and establishment
- Beneficial owners
- Payment transactions and pooled accounts
- Geography of funds flow
- BWRA, risk appetite and AML/CFT controls
- Policies, procedures, governance, audit and training
- Compliance with the Fund Transfers Regulation

## Reporting considerations _to keep in mind_

- All questions are mandatory, even where a data point is not applicable
- Non-applicable fields must use the prescribed default values, such as 0, N/A, 2000-01-01 or the required default enumeration
- All values should be reported in euro
- Customer risk ratings may be based on the rating as at the reference date, even if the rating changed during the year
- XML submissions must follow the required table structures and strict table ordering
- Incorrect XML structure or table order may result in rejection
- Firms must complete both the “Finalise” and “Sign-Off” steps in the Portal
- Material issues should still be raised through normal supervisory channels, not solely through the REQ

## Steps to submission

A high-level overview of the key stages involved in preparing, validating and submitting the Credit Institutions AML REQ return to the Central Bank of Ireland.

```json
{
  "_key": "121b87810d6e",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "33c14cea6b75",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Determine reporting scope and legal structure

Confirm whether the return should cover the Irish institution only, Irish branch activity or aggregated EEA branch information.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "19299a2c14bc",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "5b2008be13bc",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Gather required AML/CFT, customer and transaction data

Collect the required data across customers, transactions, products, geographies, credit institution activities and AML/CFT controls.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "b1d69716fd3b",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "9e999ab3a434",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Map data to the required XML schema and REF fields

Align each data point to the prescribed XML taxonomy, including REF identifiers, enumerations, table structures and field formats.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "055c7b286661",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "8f85b5546c41",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FOUR"
    }
  ]
}
```

#### Generate and validate the XML file

Create the XML return in line with the XSD schema and validate it against mandatory fields, formatting rules and table ordering requirements.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "2b6efc8172b4",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "4f2948a0726d",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FIVE"
    }
  ]
}
```

#### Upload the return via the Central Bank Portal

Submit the validated XML file through the Central Bank Portal and resolve any validation issues raised during upload.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "79919aca3c04",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "0fc1b269dfdf",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP SIX"
    }
  ]
}
```

#### Finalise and sign off the submission

Complete the Portal “Finalise” and “Sign-Off” steps to ensure the REQ is successfully completed and transmitted.

[Speak with an expert](https://complyfirst.co/demo)

---
Source: https://complyfirst.co/snapshot/aml-req-for-cis

---

# AML REQ for Credit Unions Snapshot

> High-level overview of the Central Bank of Ireland AML REQ for Credit Unions, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.

```json
{
  "_key": "5ba4c924dcb6",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## AML REQ for Credit Unions



The AML REQ is the Central Bank of Ireland’s annual data return on your firm’s money laundering and terrorist financing risk. Customers, products, jurisdictions, controls.

****

**The return must be submitted through the Central Bank Portal using the prescribed XML schema. Only XML submissions are accepted.**



Why it matters:

- **Statutory:** Mandatory under your AML/CFT obligations.
- **Supervisory:** The data directly shapes whether the CBI lines you up for a deep-dive inspection.
- **Strategic:** Feeds into the incoming EU AMLA framework
- **Visible:** Quality and completeness signal the maturity of your AML programme.

## What's the scope?

#### Entities in scope



**The AML REQ applies to credit unions regulated by the Central Bank of Ireland.** Each credit union must use the sector-specific XSD schema for Credit Unions.

#

#### Activities covered



The REQ captures information across customer segments, high-risk customer activity, cash transactions, currency cash exchange, lending, money remittance, payment transactions, remote onboarding and AML/CFT controls.

### Reporting dates

**Standard reference date:** 31 December of the preceding calendar year



**First submission deadline:** 18 September 2026

### Reporting frequency

**Annual** reporting

### File format

**XML format only**, aligned with the prescribed XSD schema and required XML wrapper. The XML file must be validated before upload to the Central Bank Portal.

## Need a hand submitting your AML REQ?

We'll do your first return _for free._

```json
{
  "_key": "a2afaa063af2",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/cbi-aml-req",
      "label": "Learn more",
      "variant": "contained"
    }
  ]
}
```

## _Key_ data areas



 The Credit Unions REQ requires information across:

- Physical presence and branch numbers
- Statement of compliance
- Customer segments and customer risk exposure
- High-risk customer activity
- Cash deposits, withdrawals and high-value cash activity
- Currency cash exchange
- Lending and loan repayments
- Money remittance activity where acting as agent of money remitters
- Payment accounts and payment transactions
- Remote onboarding
- BWRA, risk appetite and AML/CFT controls
- Policies, procedures, governance, audit and training
- Customer due diligence and periodic review backlogs
- Sanctions screening and transaction monitoring
- Residence and establishment
- Beneficial owners
- Politically exposed persons
- Geography of funds flow

## Reporting considerations _to keep in mind_

- All questions are mandatory, even where a data point is not applicable
- Non-applicable fields must use the prescribed default values, such as 0, N/A, 2000-01-01 or the required default enumeration
- All values should be reported in euro unit value
- Customer risk ratings may be based on the rating as at the reference date, even if the rating changed during the year
- For the first REQ return, firms are not expected to retrospectively source certain customer segment or cash differentiation data where it was not captured
- XML submissions must follow the required table structures and strict table ordering
- Incorrect XML structure or table order may result in rejection
- The file name must follow the required format: CXXXXX_YYYYMMDD_A07.xml
- Firms must complete both the “Finalise” and “Sign-Off” steps in the Portal
- Material issues should still be raised through normal supervisory channels, not solely through the REQ

## So, what do you need to do?

There are no shortcuts, here is what the CBI requires end-to-end.

```json
{
  "_key": "903e9f9e2655",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "421f6cb7221a",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Download and review the REQ guidance pack

Download and review the sector-specific REQ pack, including the guidance notes, XML schema and reference files, to understand the reporting requirements in full.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-credit-unions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "1ed13cf5702a",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "71a98a9b72f3",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Prepare and map your reporting data

Align internal AML/CFT, customer, product and transaction data to the required REQ fields. Every field is mandatory & has a strict format.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-credit-unions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "29cc24387678",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "c174a4170efe",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Validate against the XSD schema

Validate the XML file against the Central Bank’s schema and formatting rules to identify structural or mandatory field errors before submission. Excel won’t fly. XML schema only.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-credit-unions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "aaf6ac2155c7",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "7ab61edc2529",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FOUR"
    }
  ]
}
```

#### Obtain internal sign-off

Complete internal review and approval processes before submission (typically MLRO and board-level).

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-credit-unions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "9beb749c5ab1",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "be003a5188d0",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FIVE"
    }
  ]
}
```

#### Upload the return via the Central Bank Portal before 16 September 2026

Submit the validated XML return through the Central Bank Portal and complete the required finalisation and sign-off steps.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-credit-unions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "9beb749c5ab1",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "be003a5188d0",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP SIX"
    }
  ]
}
```

#### Maintain an audit trail

Retain supporting documentation, validation records and reporting evidence to support audit and regulatory review requirements. The CBI will ask.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-credit-unions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

---
Source: https://complyfirst.co/snapshot/aml-req-for-credit-unions

---

# AML REQ for CASPs Snapshot

> High-level overview of the Central Bank of Ireland AML REQ for CASPs, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.

```json
{
  "_key": "3f99ef838bc8",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## AML REQ for Crypto-Asset Service Providers (CASPs)



The AML REQ is the Central Bank of Ireland’s annual data return on your firm’s money laundering and terrorist financing risk. Customers, products, jurisdictions, controls.

****

**The return must be submitted through the Central Bank Portal using the prescribed XML schema. Only XML submissions are accepted.**



Why it matters:

- **Statutory:** Mandatory under your AML/CFT obligations.
- **Supervisory:** The data directly shapes whether the CBI lines you up for a deep-dive inspection.
- **Strategic:** Feeds into the incoming EU AMLA framework
- **Visible:** Quality and completeness signal the maturity of your AML programme.

*What’s the scope?*

### Entities in scope

**CASPs regulated by the CBI **must each submit their own REQ, with reporting scope determined by the institution’s legal structure and whether EEA-wide aggregation applies, while former VASPs must also include relevant data relating to both former VASP activity and CASP activity where crypto-asset services commenced in 2025.

### Activity covered

The REQ covers crypto-asset custody and administration, trading platforms, exchanges, order execution and transmission, placement, advisory and portfolio management, transfer services, correspondent relationships, and transaction monitoring and sanctions controls.

### Reporting dates

**Reference date:** 31 December of the preceding calendar year

**First submission deadline:** 31 July 2026

### Reporting frequency

**Annual **reporting

### File format

**XML format only**, aligned with the prescribed XSD schema, and submitted via the Central Bank Portal. Excel files are provided for reference purposes only and cannot be submitted.

### Customer / Geographic nexus

Reporting includes EEA customer exposure, high-risk jurisdictions, cross-border activity under FOE/FOS, customer residence and establishment, the geography of funds flows, and self-hosted addresses and certain crypto-asset transaction channels.

## Need a hand submitting your AML REQ?

We'll do your first return _for free._

```json
{
  "_key": "c9705aec7103",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/cbi-aml-req",
      "label": "Learn more",
      "variant": "contained"
    }
  ]
}
```

## _Key_ data areas

#  

 The REQ captures information relating to:

- Legal structure and business model
- CASP services and activity comments
- Customer segments and risk ratings
- Transaction volumes and values
- High-risk customers and sectors
- Crypto-assets traded and gross traded value
- Cash transactions and prepaid cards
- Funding methods and payment instruments
- Intermediaries and distribution channels
- Remote onboarding
- Correspondent relationships
- BWRA and risk appetite
- AML/CFT policies and procedures
- Transaction monitoring and STR controls
- Governance, audit and training arrangements
- Compliance with the Fund Transfers Regulation

## Reporting considerations _to keep in mind_

- All data points are mandatory, including non-applicable fields
- Non-applicable fields must use prescribed default values, such as 0, N/A or 2000-01-01
- All values should be reported in EUR
- XML submissions must follow the required schema, table structures and table ordering
- Files must be validated before submission
- Firms must complete both ‘Finalise’ and ‘Sign-Off’ steps within the portal
- The REQ is not the channel for sole communication of material issues; these should be raised through normal supervisory channels

## So, what do you need to do?

There are no shortcuts, here is what the CBI requires end-to-end.

```json
{
  "_key": "8bef3f9eb765",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "7d848ac0d9a2",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Download and review the REQ guidance pack

Download and review the sector-specific REQ pack, including the guidance notes, XML schema and reference files, to understand the reporting requirements in full.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-crypto-asset-service-providers-casps#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "14a155a01acc",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "f62232678d93",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Prepare and map your reporting data

Align internal AML/CFT, customer, product and transaction data to the required REQ fields. Every field is mandatory & has a strict format.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-crypto-asset-service-providers-casps#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "5b237577f917",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "4685db86c6fb",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Validate against the XSD schema

Validate the XML file against the Central Bank’s schema and formatting rules to identify structural or mandatory field errors before submission. Excel won’t fly. XML schema only.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-crypto-asset-service-providers-casps#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "c8f8b55bb93b",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "932d2149d9fc",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FOUR"
    }
  ]
}
```

#### Obtain internal sign-off

Complete internal review and approval processes before submission (typically MLRO and board-level).

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-crypto-asset-service-providers-casps#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "21dd5697b204",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "1b0ec3f92018",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FIVE"
    }
  ]
}
```

#### Upload the return via the Central Bank Portal before 31 July 2026

Submit the validated XML return through the Central Bank Portal and complete the required finalisation and sign-off steps.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-crypto-asset-service-providers-casps#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "0b0800a1781a",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "d4a3cbd279aa",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP SIX"
    }
  ]
}
```

#### Maintain an audit trail

Retain supporting documentation, validation records and reporting evidence to support audit and regulatory review requirements. The CBI will ask.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-crypto-asset-service-providers-casps#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

---
Source: https://complyfirst.co/snapshot/aml-req-for-crypto-asset-service-providers-casps

---

# AML REQ for Investment Firms Snapshot

> High-level overview of the CBI's AML REQ for Investment Firms, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.

```json
{
  "_key": "30bee49d4be7",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## AML REQ for Investment Firms



The AML REQ is the Central Bank of Ireland’s annual data return on your firm’s money laundering and terrorist financing risk. Customers, products, jurisdictions, controls.

****

**The return must be submitted through the Central Bank Portal using the prescribed XML schema. Only XML submissions are accepted.**



Why it matters:

- **Statutory:** Mandatory under your AML/CFT obligations.
- **Supervisory:** The data directly shapes whether the CBI lines you up for a deep-dive inspection.
- **Strategic:** Feeds into the incoming EU AMLA framework
- **Visible:** Quality and completeness signal the maturity of your AML programme.

*What’s the scope?*

### Reporting dates

**Reference date:** 31 December of the preceding calendar year

**First submission deadline:** 30 June 2026

### Reporting frequency

**Annual **reporting

### File format

**XML format only**, aligned with the prescribed XSD schema, and submitted via the Central Bank Portal. Excel files are provided for reference purposes only and cannot be submitted.

## What’s actually changing?

#  

The CBI is moving from a one-size-fits-all REQ which was in Excel format, to a sector-specific one in machine-readable XML format. Here’s the difference:

## Before

- One generic return for every firm
- Light on detail, broad on categories
- Excel-friendly
- Manageable in-house

## After

- Sector-specific returns
- Granular AML data, hundreds of new fields
- XML only, strict schema, every field mandatory
- First submission: 4-8 weeks of effort

## Need a hand submitting your AML REQ?

We'll do your first return _for free._

```json
{
  "_key": "33f79781a1e4",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/cbi-aml-req",
      "label": "Learn more",
      "variant": "contained"
    }
  ]
}
```

## _Key_ data areas

#  

The REQ captures information relating to:

- Legal structure and business model
- Customer segments and risk ratings
- Transaction volumes and values
- High-risk customers and sectors
- International presence
- Funding methods and intermediaries
- Remote onboarding
- Crypto-asset activity
- BWRA and risk appetite
- AML/CFT policies and procedures
- Transaction monitoring and STR controls
- Governance, audit and training arrangements

## Reporting considerations _to keep in mind_

- All data points are mandatory, including non-applicable fields
- Non-applicable fields must use prescribed default values (e.g. 0, N/A, 2000-01-01)
- XML submissions must follow strict schema, table structure and table ordering requirements 
- Files must be validated before submission
- Firms must complete both ‘Finalise’ and ‘Sign-Off’ steps within the portal
- All values should be reported in EUR

## So, what do you need to do?

There are no shortcuts, here is what the CBI requires end-to-end.

```json
{
  "_key": "715971160318",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "fa8df47fc478",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Download and review the REQ guidance pack

Download and review the sector-specific REQ pack, including the guidance notes, XML schema and reference files, to understand the reporting requirements in full.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-investment-firms#:~:text=Report%20to%20the-,CBI,-%2C%20hassle%2Dfree)

```json
{
  "_key": "8eedad3645d1",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "70702675124c",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Prepare and map your reporting data

Align internal AML/CFT, customer, product and transaction data to the required REQ fields. Every field is mandatory & has a strict format.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-investment-firms#:~:text=Report%20to%20the-,CBI,-%2C%20hassle%2Dfree)

```json
{
  "_key": "8eedad3645d1",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "70702675124c",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Validate against the XSD schema

Validate the XML file against the Central Bank’s schema and formatting rules to identify structural or mandatory field errors before submission. Excel won’t fly. XML schema only.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-investment-firms#:~:text=Report%20to%20the-,CBI,-%2C%20hassle%2Dfree)

```json
{
  "_key": "8eedad3645d1",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "70702675124c",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FOUR"
    }
  ]
}
```

#### Obtain internal sign-off

Complete internal review and approval processes before submission (typically MLRO and board-level).

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-investment-firms#:~:text=Report%20to%20the-,CBI,-%2C%20hassle%2Dfree)

```json
{
  "_key": "8eedad3645d1",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "70702675124c",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FIVE"
    }
  ]
}
```

#### Upload the return via the Central Bank Portal before 30 June 2026

Submit the validated XML return through the Central Bank Portal and complete the required finalisation and sign-off steps.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "fbc1baff87c8",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "ff4e9a74e4d0",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP SIX"
    }
  ]
}
```

#### Maintain an audit trail

Retain supporting documentation, validation records and reporting evidence to support audit and regulatory review requirements. The CBI will ask.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-investment-firms#:~:text=Report%20to%20the-,CBI,-%2C%20hassle%2Dfree)

---
Source: https://complyfirst.co/snapshot/aml-req-for-investment-firms

---

# AML REQ for Life Insurance Snapshot

> High-level overview of the Central Bank of Ireland AML REQ for Life Insurance, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.

```json
{
  "_key": "41214ac17803",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## AML REQ for Life Insurance Institutions



The AML REQ is the Central Bank of Ireland’s annual data return on your firm’s money laundering and terrorist financing risk. Customers, products, jurisdictions, controls.

****

**The return must be submitted through the Central Bank Portal using the prescribed XML schema. Only XML submissions are accepted.**



Why it matters:

- **Statutory:** Mandatory under your AML/CFT obligations.
- **Supervisory:** The data directly shapes whether the CBI lines you up for a deep-dive inspection.
- **Strategic:** Feeds into the incoming EU AMLA framework
- **Visible:** Quality and completeness signal the maturity of your AML programme.

*What’s the scope?*

### Entities in scope

**The AML REQ applies to Life Insurance institutions regulated by the CBI.** Each regulated institution must submit its own REQ using the sector-specific XSD schema.

### Group & branch reporting

Where the institution is a Parent_of_group within the EEA or a Stand_alone_entity, Sections 8.2.2 and 8.4.16 must be reported on an aggregated basis for EEA entities. The remaining sections are reported for the Irish institution only; other legal structures report Irish institution data only.

### Activity covered

The REQ captures information across life insurance products, customer segments, high-risk sectors, intermediaries, remote onboarding, cash transactions, PEP exposure, geography of funds flow, transaction monitoring and AML/CFT controls.

### Reporting dates

**Standard reference date: **31 December of the preceding calendar year



**First submission deadline: **11 September 2026

### Reporting frequency

**Annual **reporting

### File format

**XML format only**, aligned with the prescribed XSD schema and required XML wrapper. The XML file must be validated before upload to the Central Bank Portal.

## Need a hand submitting your AML REQ?

We'll do your first return _for free._

```json
{
  "_key": "c2ae29a8b1ec",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/cbi-aml-req",
      "label": "Learn more",
      "variant": "contained"
    }
  ]
}
```

## _Key_ data areas



 The Life Insurance REQ requires information across:

- Legal structure and EEA international presence
- Statement of compliance
- Customer segments and high-risk customer activity
- High-risk legal entity customer sectors
- Protection policies and investment policies
- Pension and non-pension investment contracts
- Highly Personalised Portfolio Bonds
- Policy surrender and reassignment activity
- Cash inwards and cash outwards transactions
- Intermediaries and distribution channels
- Remote onboarding
- BWRA, risk appetite and AML/CFT controls
- Policies, procedures, governance, audit and training
- Customer due diligence and periodic review backlogs
- Sanctions screening and transaction monitoring
- Physical presence, residence and establishment
- Politically exposed persons
- Geography of funds flow

## Reporting considerations _to keep in mind_

- All questions are mandatory, even where a data point is not applicable
- Non-applicable fields must use the prescribed default values, such as 0, N/A, 2000-01-01 or the required default enumeration
- For this REQ, “customer” refers to the policyholder
- All values should be reported in full euro unit value
- Customer risk ratings may be based on the rating as at the reference date, even if the rating changed during the year
- XML submissions must follow the required table structures and strict table ordering
- Incorrect XML structure or table order may result in rejection
- The file name must follow the required format: CCCCCC_YYYYMMDD_A05.xml
- Firms must complete both the “Finalise” and “Sign-Off” steps in the Portal
- Material issues should still be raised through normal supervisory channels, not solely through the REQ

## So, what do you need to do?

There are no shortcuts, here is what the CBI requires end-to-end.

```json
{
  "_key": "3541f35f3574",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "e3335512d579",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Download and review the REQ guidance pack

Download and review the sector-specific REQ pack, including the guidance notes, XML schema and reference files, to understand the reporting requirements in full.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-life-insurance-institutions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "816d2411f4a4",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "259137ea691c",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Prepare and map your reporting data

Align internal AML/CFT, customer, product and transaction data to the required REQ fields. Every field is mandatory & has a strict format.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-life-insurance-institutions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "f11ac3b41702",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "087f2c2e2dc2",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Validate against the XSD schema

Validate the XML file against the Central Bank’s schema and formatting rules to identify structural or mandatory field errors before submission. Excel won’t fly. XML schema only.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-life-insurance-institutions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "92442fa9a5d6",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "a5cd8459a6ba",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FOUR"
    }
  ]
}
```

#### Obtain internal sign-off

Complete internal review and approval processes before submission (typically MLRO and board-level).

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-life-insurance-institutions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "f968ec87961a",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "9ade0fff0d9f",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FIVE"
    }
  ]
}
```

#### Upload the return via the Central Bank Portal before 11 September 2026

Submit the validated XML return through the Central Bank Portal and complete the required finalisation and sign-off steps.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-life-insurance-institutions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "1c86547c0403",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "f7bf3b3793f8",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP SIX"
    }
  ]
}
```

#### Maintain an audit trail

Retain supporting documentation, validation records and reporting evidence to support audit and regulatory review requirements. The CBI will ask.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-life-insurance-institutions#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

---
Source: https://complyfirst.co/snapshot/aml-req-for-life-insurance-institutions

---

# AML REQ for PIs and EMIs Snapshot

> High-level overview of the CBI's AML REQ for PIs and EMIs, including scope, reporting requirements, key data fields, XML submission rules and AML/CFT reporting considerations.

```json
{
  "_key": "bb6f8c84b2ea",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## AML REQ for Payment & E-money Institutions



The AML REQ is the Central Bank of Ireland’s annual data return on your firm’s money laundering and terrorist financing risk. Customers, products, jurisdictions, controls.

****

**The return must be submitted through the Central Bank Portal using the prescribed XML schema. Only XML submissions are accepted.**



Why it matters:

- **Statutory:** Mandatory under your AML/CFT obligations.
- **Supervisory:** The data directly shapes whether the CBI lines you up for a deep-dive inspection.
- **Strategic:** Feeds into the incoming EU AMLA framework
- **Visible:** Quality and completeness signal the maturity of your AML programme.

*What’s the scope?*

### Entities in scope

**Payment and E-money Institutions regulated by the CBI **must each submit their own REQ, with group and branch reporting determined by the institution’s legal structure.

### Group & branch reporting

Irish branches should report Irish branch data only, EU parent undertakings must aggregate EEA branch information excluding non-EEA branches, and non-parent group firms should report for the Irish institution only.

### Activity covered

The PI/EMI REQ captures data across payment and e-money services, including PSD2 activities, merchant acquiring, remittance, payment accounts, onboarding channels, and transaction monitoring and sanctions controls.

### Reporting dates

**Standard reference date: **31 December of the preceding calendar year



**First submission deadline: **13 February 2026

### Reporting frequency

**Annual **reporting

### File format

**XML format only**, aligned with the prescribed XSD schema and required XML wrapper. The XML file must be validated before upload to the Central Bank Portal.

## Need a hand submitting your AML REQ?

We'll do your first return _for free._

```json
{
  "_key": "6e1ce24116a7",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports/cbi-aml-req",
      "label": "Learn more",
      "variant": "contained"
    }
  ]
}
```

## _Key_ data areas



 The PI/EMI REQ requires information across:

- Legal structure and business model
- PSD2 activity and activity comments
- Integrated or partnered crypto-asset services
- Customer segments and customer risk ratings
- High-risk customers and sectors
- Transaction volumes and values
- Merchant acquiring activity
- Money remittance activity
- E-money products and digital accounts
- Prepaid cards and vouchers
- Payment accounts and virtual IBANs
- Currency exchange
- Cash deposits and withdrawals
- Crypto-asset related services, where applicable
- Lending and crowdfunding
- Correspondent relationships
- Funding methods and payment instruments
- BWRA, risk appetite and AML/CFT controls
- Policies, procedures, governance, audit and training
- Compliance with the Fund Transfers Regulation

## Reporting considerations _to keep in mind_

- All questions are mandatory, even where a data point is not applicable
- Non-applicable fields must use the prescribed default values, such as 0, N/A, 2000-01-01 or the required default enumeration
- All values should be reported in euroCustomer risk ratings may be based on the rating as at the reference date, even if the rating changed during the year
- XML submissions must follow the required table structures and strict table ordering
- Incorrect XML structure or table order may result in rejection
- Firms must complete both the “Finalise” and “Sign-Off” steps in the Portal
- Material issues should still be raised through normal supervisory channels, not solely through the REQ

## So, what do you need to do?

There are no shortcuts, here is what the CBI requires end-to-end.

```json
{
  "_key": "47e40e25088e",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "0582857c1b50",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Download and review the REQ guidance pack

Download and review the sector-specific REQ pack, including the guidance notes, XML schema and reference files, to understand the reporting requirements in full.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-pis-and-emis#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "ccaa69704a85",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "7b4c26091894",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Prepare and map your reporting data

Align internal AML/CFT, customer, product and transaction data to the required REQ fields. Every field is mandatory & has a strict format.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-pis-and-emis#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "5783be1f6b07",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "1547b03fd41d",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Validate against the XSD schema

Validate the XML file against the Central Bank’s schema and formatting rules to identify structural or mandatory field errors before submission. Excel won’t fly. XML schema only.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-pis-and-emis#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "cf6899e979bc",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "01bf9fce717f",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FOUR"
    }
  ]
}
```

#### Obtain internal sign-off

Complete internal review and approval processes before submission (typically MLRO and board-level).

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-pis-and-emis#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "b35f2f0a85e9",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "40a532b29181",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP FIVE"
    }
  ]
}
```

#### Upload the return via the Central Bank Portal before 13 Feb 2026

Submit the validated XML file through the Central Bank Portal and resolve any validation issues raised during upload.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-pis-and-emis#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

```json
{
  "_key": "57efcc73bea3",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "155882851307",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP SIX"
    }
  ]
}
```

#### Maintain an audit trail

Retain supporting documentation, validation records and reporting evidence to support audit and regulatory review requirements. The CBI will ask.

[Speak with an expert](https://complyfirst.co/snapshot/aml-req-for-pis-and-emis#:~:text=with%20an%20expert-,Report,-to%20the%20CBI)

---
Source: https://complyfirst.co/snapshot/aml-req-for-pis-and-emis

---

# CARF Snapshot

> Learn the UK CARF reporting requirements for crypto-asset service providers, including scope, data fields, reporting deadlines, and HMRC compliance steps.

```json
{
  "_key": "72c6189f90ba",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## CARF Reporting



CARF is an OECD tax reporting framework requiring crypto-asset service providers to collect user tax information and report certain crypto transactions to tax authorities. Implemented in the UK through HMRC regulations, it enables standardised reporting and international data sharing to improve tax transparency and compliance.



```json
{
  "_key": "c99da5d261ce",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/resources/files/uk-carf-crypto-asset-reporting-snapshot",
      "label": "Download PDF",
      "variant": "contained"
    }
  ]
}
```

*What’s the scope?*

### Entities in scope

Any Reporting **Crypto Asset Service Provider (RCASP)** required to report to HMRC, including UK and non-UK firms providing cryptoasset services to reportable users

### Nexus

**UK tax-resident users** (reporting is triggered by the user’s tax residence, not where the platform is headquartered)

### Activity

**Facilitating in-scope cryptoasset transactions** (e.g. crypto-to-fiat, crypto-to-crypto, transfers and certain in-scope payment transactions when crypto is used to pay for goods and services)

### Deadline

**Collect data from 1 Jan 2026. **Submit by 31 May 2027.

### Reporting frequency

**Annual **reporting

### File format

Generate **XML**

## Data fields needed

- **Accounts/wallets:** User/ account ref + wallet address/ID for reportable crypto activity



- **Individuals:** Name, address, DOB, all tax residences, TIN per country (or valid reason code where not available)



- **Corporates:** Entity name, address, tax residence + TIN(s), plus controlling persons (same fields as for individuals)



- **Transactions: **Crypto-asset type + annual totals by category (crypto-to-fiat, crypto-to-crypto, transfers and retail payments)

## Reporting considerations _to keep in mind_

#### User notice required

If a user/person is reportable, you must notify them their data will be reported to HMRC and may be shared internationally (by 31 Jan after their first reportable year)

#### HMRC registration

RCASPs must register with HMRC (by 31 May 2027, or 31 Jan after their first in-scope year, whichever is later)

## Steps to submission

Here are the steps required to meet CARF reporting obligations.

```json
{
  "_key": "f46aff8ab12c",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "a4640b1c92be",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Register with HMRC

If you’re an RCASP, complete HMRC registration.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "e0b566bbe6be",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "547cd1b8fcdb",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Build customer communications

Notify reportable users of HMRC reporting + possible cross-border sharing.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "8921998d2799",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "6077c2b87e7e",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Capture data + tag

Update your onboarding flow to capture tax residence + TINs (and reason codes) and tag UK reportable users + transaction categories (above) so reporting can be generated

[Speak with an expert](https://complyfirst.co/demo)

---
Source: https://complyfirst.co/snapshot/carf

---

# CRS2 Snapshot

> Get a clear snapshot of CRS2 outlining scope, data requirements, reporting obligations, deadlines, and next steps for financial institutions preparing for enhanced tax transparency.

```json
{
  "_key": "8081e0e4f113",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## CRS2 Reporting



CRS2 is the **updated OECD Common Reporting Standard**, implemented in the EU through [DAC8](https://complyfirst.co/snapshot/dac8). It requires reporting financial institutions including **banks, PIs, and EMIs** to enhance tax transparency.   
  
Under CRS2, firms must capture and validate customer tax residency at onboarding, monitor changes in circumstances, and submit an annual return reporting relevant account data in **XML format**.   
  
The regime expands scope to cover newly in-scope e-money and digital products, strengthens due diligence requirements, and ensures more complete and accurate tax residency reporting.



```json
{
  "_key": "fec5bc42becd",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/resources/files/reporting-snapshot-crs2",
      "label": "Download PDF",
      "variant": "contained"
    }
  ]
}
```

*What’s the scope?*

### Entities in scope

Reporting financial institutions under CRS include **banks, PIs and EMIs** where product meets CRS “financial account” test.

### Activity

**Offering CRS financial accounts** (if customers can hold stored value like an account assume it’s reportable)

### Nexus

**Account holder tax residency (global)** – you may need to report non-EU tax residents too, because CRS is a global AEOI standard (e.g. an Irish EMI may report Canadian tax resident customer under CRS.)

### Deadline

**Collect data from 1 Jan 2026.** Submit in 2027 (exact deadline set by each member state)

### Reporting frequency

**Annual **reporting

### File format

Generate **XML** using the OECD schema and submit it to your local EU member state tax authority.

## Data fields needed

- **Accounts:** Account ID/ref, product type, open/close status, reportable balance/value (year-end) and reportable income (where applicable)



- **Individuals:** Name, address, DOB (and POB where required), tax self-cert, all tax residences + TIN per country (or reason if unavailable)



- **Corporates:** Entity name, address, tax self-cert + entity CRS classification, plus controlling persons (name, address, DOB, tax residences + TINs) where required

## Reporting considerations _to keep in mind_

####  2026 is the "data year"

Firms must collect customer and account data in line with CRS2. You may need to update onboarding forms and expand data capture.

#### 2027 is the “reporting year”

Firms must report using the new CRS2 standards, relying on the data collected in 2026.

## Steps to submission

A step-by-step overview of how to implement CRS2 requirements across classification, data capture, monitoring, and reporting.

```json
{
  "_key": "f700a3df0a73",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "39fb519b6807",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Confirm scope

Classify accounts/wallets to identify which are CRS-reportable accounts.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "dd71cd0c3d8b",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "d58d588235ad",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Fix onboarding

Capture all tax residences + self-cert + TIN per country (or reason if missing) from day one.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "4126f1ae59bc",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "93afc4107811",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Ongoing monitoring

Cross-check tax data vs KYC and track changes in circumstances that might prompt you to ask the customer to refresh their tax info.

[Speak with an expert](https://complyfirst.co/demo)

---
Source: https://complyfirst.co/snapshot/crs2

---

# DAC8 Snapshot

> Get an overview of the EU DAC8 crypto-asset reporting rules, including scope, data requirements, and annual XML reporting under the OECD CARF framework.

```json
{
  "_key": "c28769c8e90d",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## EU DAC8 Crypto Asset Reporting



DAC8 is the **EU’s implementation of the OECD Crypto-Asset Reporting Framework (CARF)**, requiring crypto-asset service providers to annually report information on EU tax residents’ crypto activity **via XML. **

The goal is to give EU tax authorities structured visibility into cross-border crypto activity and strengthen tax compliance across member states.



```json
{
  "_key": "4b9cac91caef",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/resources/files/reporting-snapshot-dac8",
      "label": "Download PDF",
      "variant": "contained"
    }
  ]
}
```

*What’s the scope?*

### Entities in scope

**Any** **Reporting Crypto Asset Service Provider (RCASP)** including MiCA authorised CASPs and non-MiCA / non-EU operators where they have EU tax resident users.

### Customer nexus

**EU tax-resident users **(reporting is triggered by the users EU tax residency, not where the platform is headquartered).

### Activity covered

**Facilitating reportable crypto transactions** (e.g. crypto-to-fiat, crypto-to-crypto, transfers and certain in-scope payment transactions under the framework)

### Deadline

**Collect data from 1 Jan 2026**. Submit in 2027 (exact deadline set by each member state)

### Reporting frequency

**Annual **reporting

### File format

**XML** aligned with the DAC8 schema to submit to the tax authority in the EU member state where you’re registered.

## Data fields needed

- **Accounts/wallets: **Account ID/ref + wallet address/ID for reportable crypto activity
- **Individuals: **Name, address, DOB, all EU tax residences, TIN per country (or valid reason code  
where not available)
- **Corporates: **Entity name, address, tax residence + TIN(s), plus controlling persons (same fields  
as for individuals)
- **Transactions: **Crypto-asset type, transaction category (buy/sell/exchange/transfer/payment)  
and annual totals.

#

## Reporting considerations _to keep in mind_

### PIs/EMIs in scope*

*If they are the customer-facing entity providing the crypto service, either under their own crypto licence or via a group crypto entity they contract with.

### Non-EU firms

Will need to register in an EU member state for DAC8 reporting.

## Steps to submission

A step-by-step overview of how to prepare for DAC8, from onboarding and data capture to tagging, aggregation, and XML submission.

```json
{
  "_key": "b8e40dee93fd",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "22deacf4fc19",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Fix onboarding

Capture EU tax residence, TINs (and any missing reason codes) from day one.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "373505f018cc",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "210aae0b36da",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Tag EU customers

Add an ”EU” tag for DAC8 ensuring it’s based on tax residency (not nationality).

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "4eaf9688c3af",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "d48a77bddf41",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Tag transactions

Add transaction type tags (mentioned above) to every crypto event so totals can be extracted reliably.

[Speak with an expert](https://complyfirst.co/demo)

---
Source: https://complyfirst.co/snapshot/dac8

---

# DORA Register of Information (ROI) Snapshot

> Get a snapshot guide on how to complete the DORA ROI: The 4 keys, supply chain mapping, and data quality.


```json
{
  "_key": "61202d597911",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## DORA Register of Information (ROI)



Under the **EU Digital Operational Resilience Act (DORA)**, financial entities must maintain and submit a **Register of Information (ROI), **which is a structured record of their ICT third-party providers and the services they support.



The register gives regulators **visibility into how financial institutions rely on external technology providers**, including the services delivered, contractual arrangements, and supply chain dependencies.



Firms must **keep the register accurate and up to date and submit it through their national competent authority**, enabling regulators to monitor ICT risk across the financial sector.

## Why the ROI exists

Ensures your firm has **clear oversight** of ICT third party risks

Gives **supervisors visibility** into your ICT dependencies

Enables **effective supervision**, esp. of critical ICT providers

## The ROI structure & what it contains

The ROI is composed of 15 tables linked by 4 keys – and mapped across your ICT supply chain. It contains:

- 1 set of templates for all firms
- 15 tables
- 100's of pages of EBA guidance
- XBRL-CSV format only

## How to complete the ROI

Where to start

### 1. List all ICT services & functions

- Capture all ICT services from third-party + in-group providers
- List all business + operational functions and talk to them
- This is your initial inventory

### 2. Internal assessment

- Identify critical/ important functions (Art 3(22) DORA)
- Additional info isneeded for these(risk assessment, supply chain, subcontractors, concentration, exit strategy)
- Identify material sub-contractors (Art 30 (2) DORA)
- Rank providers (Direct = 1, Sub-contractors = 2-3)

#  

### 3. ICT supply chain

#  

- Map each ICT service to its service type (S01 – S19) Annex III
- Capture your supply chain: direct providers + subcontractors
- Link everything together in the same supply chain

### 4. Capture the 4 keys

- Record contract ref numbers (internal + external)
- Capture LEI’s for signing entities + direct ICT providers
- Assign ICT service type codes (S01 – S19) from Annex III
- Create consistent function IDs for every function

```json
{
  "_key": "67283f30d4fc",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "/demo",
      "label": "Get help preparing your ROI",
      "variant": "contained"
    }
  ]
}
```

#

## Scope + document your ICT supply chain

#  

### Scope



1. **All ICT providers are in-scope** (not just those who support critical or important functions)



2**. And extra details are required** when an ICT provider supports one a critical or important function, including:

- Risk assessments
- Subcontractors
- Concentration risk
- And your exit strategy

### What to record:

To clearly document the supply chain, you must:

- Contract ref number: between your firm and the direct ICT TPP.
- Assign ICT service type (Annex III, S01 – S19)
- Rank providers:
   - Rank 1 = Direct provider
   - Rank 2,3 = Material subcontractors (Upto the last material subcontractor in the chain)
- Links: Show how each provider fits within the same supply chain

#### Here’s Fiona walking through what an ICT service supply chain looks like in practice.

## The 4 keys that link everything together

#### Contract reference number

- Unique internal ID assigned to each ICT contract
- Must remain consistent across all ROI tables

#### Legal entity identifier (LEI)

- 20 character code, unique to each entity
- Required for your contracting entity + each direct ICT provider

#### Function identifier

- Unique function ID created from: LEI + licensed activity + function
- Must remain consistent across all tables.

#### ICT service type

- One of 19 ICT service types (S01 – S19) from Annex III
- Drives which fields + validations rules apply

## How the keys link across templates

This illustration shows how the four keys link across the different ROI templates.

  
Take the contract ref no. in green for example. It appears in 10 out of 15 tables. So, if a slightly different contract ID is used, the tables stop linking and the whole return breaks.

  
That’s why these keys need to be absolutely consistent everywhere.



**Small technical errors = immediate file rejection.  
**

```json
{
  "_key": "b84cb0defb9b",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "/demo",
      "label": "Get help preparing your ROI",
      "variant": "contained"
    }
  ]
}
```

#

## Don't forget that data quality is _everything_

### Data principles

Accuracy, completeness, consistency, integrity, uniformity, validity

### Clear taxonomies

Create clear taxonomies of functions so each ID clearly distinguishes between internal functions

### Consistency across the 4 keys

Check for consistency across the 4 keys at entity and group level

---
Source: https://complyfirst.co/snapshot/dora-roi

---

# FCA Safeguarding Return Snapshot

> Learn how the FCA's monthly Safeguarding reporting works, who’s in scope, what data to report, and how to submit.

```json
{
  "_key": "faa132eb8c1c",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## FCA Safeguarding Return (REP027)

The FCA’s safeguarding return is a mandatory monthly regulatory return requiring safeguarding firms to report how customer funds are protected, reconciled, and resourced.

- **Applies to EMIs, APIs, SPIs (opt-in), and SEMIs (opt-in)**
- Covers **relevant funds safeguarded** under the PSRs/EMRs
- Needs to be **submitted within 15 business days** after month-end
- Submission via the **FCA RegData platform**
- **Legal Basis:** SUP 16.14A / SUP 16 Annex 29BR — Safeguarding return (FCA 2025/38)



```json
{
  "_key": "e726fcc96703",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/resources/files/reporting-snapshot-fca-safeguarding-return-snapshot",
      "label": "Download PDF",
      "variant": "contained"
    }
  ]
}
```

## What’s the scope?

All safeguarding institutions are in scope, including API, EMI, SPI (opt-in) and SEMI (opt-in).

### Deadline

Go-live: 7 May 2026 (first return due 15 business days after month-end)

### Reporting frequency

**Monthly **reporting

### File format

Key in via RegData platform, or automate via **XML / API submission**

## Data fields needed for submission (Sections 1–9)



Core sections 1 – 9, covering:

1. **Firm + category** (and audit details if applicable)
2. **Safeguarding method** + client count
3. **Highest / lowest safeguarding requirement**
4. **Where funds are held:** accounts / assets / insurance / guarantees
5. **Resource vs requirement** (incl. excess/shortfall + adjustments)
6. **D+1 resource vs requirement**
7. **Reconciliation cadence **(internal + external)
8. **Accounts + acknowledgement letters**
9. **Notifiable CASS breaches **(Y/N + compliance Y/N)

Sections 10-17 cover unrelated payment services (UPS)

- Repeat the same checks as above for payment services unrelated to e-money issuance.

## Considerations   
(what applies to your firm)

- **Sections 1 – 2 + 9: **all firms
- **Sections 3 – 8: **only if you were required to safeguard in the period
- **Sections 10 – 17: **only for unrelated payment services i.e. EMI + UPS, SEMI (opt in), Credit union (opt in)

## Steps to submission

A practical step-by-step overview of how to prepare, validate, and submit the FCA Safeguarding Return.

```json
{
  "_key": "6dff3a43ada7",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "a0e6ff2d39bd",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

## Confirm scope

Are you required to safeguard (or opted in), and do UPS sections 10-17 apply?

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "6dff3a43ada7",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "a0e6ff2d39bd",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

## Automate reconciliations

You’ll be doing this monthly, so setting up a monthly pack will be essential.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "6dff3a43ada7",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "a0e6ff2d39bd",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

## Diarise submissions

Ensure you can submit the returns within 15 business days of month-end.

[Speak with an expert](https://complyfirst.co/demo)

---
Source: https://complyfirst.co/snapshot/fca-safeguarding-return

---

# Instant Payments Report (IPR) Snapshot

> Understand the EU Instant Payments Report (IPR): who it applies to, required templates, sanctions reporting, annual deadlines, and XBRL filing process.

```json
{
  "_key": "4b951940a30f",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## Instant Payments Report



The Instant Payments Report (IPR) is an annual EU reporting requirement for **Payment Service Providers (PSPs)** offering SEPA credit transfers. Firms must report:

- SCT and SCT Inst volumes and values (sent and received)
- Fees charged for credit transfers and payment accounts
- Total number of payment accounts and associated charges
- Sanctions-related rejects and freezes (national vs cross-border split)

Submissions are made **annually in XBRL** using EBA templates.



**Legal basis:** Article 15(3) of SEPA Regulation (EU) No 260/2012, with ITS under Article 15(5), as amended by the EU Instant Payments Regulation (EU) 2024/886.



```json
{
  "_key": "a57a94c865f9",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/resources/files/reporting-snapshot-ipr",
      "label": "Download PDF",
      "variant": "contained"
    }
  ]
}
```

## What's the scope?

#### Entities in scope



**PSPs** in euro member states and PSPs in non-euro member states offering euro credit transfers.

#### Activity / Nexus



Provision of **SEPA credit transfers** (SCT) and/or **SEPA Instant Credit Transfers** (SCT Inst).

### Deadline

First submission: **9 April 2026**

### Reporting frequency

**Annual** (with retrospective backfill requirement of 4 years)

### File format

**XBRL** using EBA templates, taxonomy, and validation rules, then submitted to the relevant NCA

## Data fields needed (core templates)

There are 4 core templates (6 if you include non-euro member state firms):



- **Template 1.1 (Volumes):** SCT + SCT Inst transfers sent/received, transaction counts and total values, split by national vs cross-border
- **Template 2.1 (Charges): **fees charged for SCT + SCT Inst sent/received, split by national vs cross-border
- **Template 3 (Accounts):** total number of payment accounts and total account charges (incl. maintenance fees)
- **Template 4 (Sanctions): **Number and % of SCT Inst rejected/frozen due to sanctions screening, split national vs cross-border



**Note:** Templates are linked — totals and splits should reconcile across them.

#

## Reporting considerations _to keep in mind_

### Backfill year 1

The first submission = four reports ‼️ (2022 partial: 26 Oct–31 Dec, then full years 2023–2025)

### Cross-check

Totals for transfers and accounts should align with other returns (e.g. Payment Statistics)

## Steps to submission

A practical, step-by-step overview of how to prepare, reconcile, and submit your IPR.

```json
{
  "_key": "d8b9d23b32c1",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "af22ea61148c",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Map ownership

Map which licensed entities/branches report to which CA (home vs host).

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "73764ae522f0",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "ae96a36f0d60",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Separate sanctions

Tag/extract “rejected/frozen” due to sanctions vs other fail reasons.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "8c2c02925d6c",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "5c2ce6e88eb1",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Dry-run backfill

Produce 2022 (partial), 2023, 2024 and 2025 early.

[Speak with an expert](https://complyfirst.co/demo)

---
Source: https://complyfirst.co/snapshot/instant-payments-report

---

# Spanish Models 196 & 170 Snapshot

> Learn how Spanish Tax Agency Models 170 and 196 reporting works, who’s in scope, what data to report, and how to submit monthly filings.

```json
{
  "_key": "38cca03f45f8",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REPORTING SNAPSHOT"
    }
  ]
}
```

## Spanish Models 196 & 170 

Spanish Tax Agency Models 170 and 196 are monthly reporting requirements for payment activity connected to Spain, giving tax authorities greater visibility into payment flows.

- **Applies to banks, PSPs, and EMIs** with Spanish-linked activity
- **Covers payments, accounts,** and **digital wallets**
- Requires **monthly XML submissions** to the Spanish Tax Agency
- Aims to **improve tax transparency** and detect undeclared income
- **Legal Basis:** Royal Decree 253/2025 (1 Apr 2025) amending the RGAT

```json
{
  "_key": "d4f07ed4517a",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/resources/files/reporting-snapshot-spanish-tax-models-196-170",
      "label": "Download PDF",
      "variant": "contained"
    }
  ]
}
```

*What’s the scope?*

### Entities in scope

**Banks**, Payment Institutions **(PIs)**, and Electronic Money Institutions **(EMIs)** connected to Spain, including branches and passported firms operating in Spain.

### Customer nexus

**Model 196: **Customers with Spanish tax residency or a Spanish permanent establishment

  
**Model 170: **Merchants or professional activities connected to Spain

### Activity covered

**Model 196: **Managing accounts and wallets (the “containers” of money)

  
**Model 170: **Collecting merchant payments via card, mobile, or POS (the movement of money)

### Deadline

First submission due **end of February 2026**, covering January 2026 data.

### Reporting frequency

**Monthly reporting** for both Model 170 and Model 196.

### File format

**XML files** aligned with the official XSD schema, validated prior to submission.

## Data fields needed for submission

## Model 196:  
Accounts & wallets

Covers where money is held in accounts and digital wallets connected to Spain. This includes customer identification details and reportable balances for individuals and businesses.

- **Accounts: **Account ID or reference, account type, open/close dates, and reportable balances
- **Individuals:** Full name, TIN (or passport/ID and issuing country if no TIN), residence, date of birth
- **Corporates: **Entity name, TIN (or registration/ID and issuing country), and UBO details (same fields as individuals)

## Model 170:  
Card & mobile payments

Covers how money moves through merchant payment activity connected to Spain. This includes card and mobile payments, transaction counts, and total amounts processed.

- **Payments: **Payment type (card/mobile), reporting period, transaction count, total amounts
- **Merchants:** Merchant name, TIN (or registration/ID and issuing country), settlement account / IBAN
- **Channel: **POS or terminal ID (if applicable) and payment instrument reference (card or payment ID)

## Reporting considerations _to keep in mind_

## Model 196

#### December Reporting Complexity

December submissions are more extensive, requiring year-end balances, average Q4 balances, and annual totals in addition to standard monthly data.

## Model 170

#### Expanded Scope

The €3,000 reporting threshold has been removed. All in-scope merchant payment activity connected to Spain must now be reported.

## Steps to submission

A practical step-by-step overview of how to prepare, validate, and submit Model 170 and 196 reports to the Spanish Tax Agency.

```json
{
  "_key": "44e47b5e9af2",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "aaa2be5fb9a6",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP ONE"
    }
  ]
}
```

#### Identify in-scope customers

Tag customers as “Spain reportable” based on tax residency, merchant activity, and account usage to drive monthly extracts.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "2523e993438f",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "aaa2be5fb9a6",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP TWO"
    }
  ]
}
```

#### Validate tax residency vs KYC

Cross-check TIN/VAT, addresses, and declared residency against KYC data and remediate gaps early.

[Speak with an expert](https://complyfirst.co/demo)

```json
{
  "_key": "796aa25dd007",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "_key": "aaa2be5fb9a6",
      "_type": "chipItem",
      "chipColor": "chip primary light",
      "label": "STEP THREE"
    }
  ]
}
```

#### Prepare and submit XML

Generate, validate, batch (max 10,000 records per file), and submit compliant XML files to the Spanish Tax Agency (AEAT).

[Learn how](https://complyfirst.co/demo)

---
Source: https://complyfirst.co/snapshot/spanish-models-196-and-170

---

# Terms and Conditions

## Terms and Conditions

1. **INTRODUCTION**
   1. This page sets out the general customer terms (**General Terms**) which apply to any Service (as defined below) which Complyfirst (as defined below) licences or provides to any Customer (as defined below), unless Customer has entered into a separate written contract with Complyfirst signed by both parties in respect of the Services.
   2. The parties’ agreement for the licensing, use and/or provision of the Services is made up of (i) these General Terms; (ii) the Proposal; and (iii) any other written document either issued by Complyfirst (and expressly referring to and incorporating itself into the agreement) or any amendments or supplements to the agreement signed and agreed in writing between the parties. Together the above documents shall constitute and be known as the **Agreement** and apply to the contract between the parties to the exclusion of any other terms that Customer may seek to impose or incorporate, or which are implied by trade, custom, practice or course of dealing. 
   3. When construing the meaning of the Agreement, the documents listed in clause 1.2 shall be interpreted in a reverse order of priority in the event of any inconsistency or conflict, with documents appearing later in the list taking priority over documents appearing earlier in the list.
   4. Any order placed by Customer shall only be deemed to be accepted upon Complyfirst’s signature of, or email agreement to, the Proposal, at which point and on which date the Agreement shall come into existence.
   5. These General Terms are published on Complyfirst’s website. Customer should print or save a copy of these General Terms for its records. **Complyfirst** may amend these General Terms from time to time during the Term and will endeavour to provide Customer with thirty (30) days’ notice before making the change effective when it does so. Every time Customer agrees a new Proposal with Complyfirst it should check these General Terms to ensure that it understands the terms which will apply to the Agreement at that time. This version three of these General Terms was most recently updated on 21 January 2025. Historic versions may be obtained by contacting Complyfirst. 
   6. Any Proposal issued by Complyfirst shall be valid for a period of 30 days (or such longer period specified on the Proposal) from the date of issue, if not agreed by Customer, at which point the offer outlined in the Proposal shall lapse.
2. **INTERPRETATION**
   1. In the Agreement the following definitions and rules of interpretation shall apply: 
      1. **Affiliate** means in relation to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with that party from time to time; 
      2. **Agreement** has the meaning given to it in clause 1.2; 
      3. **Authorised Users** means those employees and agents of, and independent contractors providing services to, the Customer only (excluding its Affiliates), who are authorised by the Customer to use the Subscription Services and their ancillary documentation, who are accessing the Subscription Services for the lawful business purposes of the Customer only (excluding its Affiliates); 
      4. **Beta Services** means any Subscription Service identified as a beta, preview or similar. These may be offered as Free Services; 
      5. **Business Day** means any day which is not a Saturday, Sunday, bank or public holiday in Ireland, England or the jurisdiction in which Customer is incorporated; 
      6. **Commencement Date** means the date specified in the Proposal; 
      7. **Complyfirst** means the Complyfirst contracting entity specified in the Proposal or Sales Order Form (as applicable), and references in these General Terms to “Complyfirst” shall be construed accordingly; 
      8. **Confidential Information** means in relation to either party, any or all information of a confidential nature (whether in oral, written or electronic form) including trade secrets and information (whether or not of commercial value) known and belonging to that party and concerning its business, suppliers, customers, products or services (including without limitation, in Complyfirst’s case, the Subscription Services and their ancillary documentation, any product or feature plans, and the pricing offered by Complyfirst), and in Customer’s case, all Customer Data, and any other information which the recipient knows or is notified or has reason to believe is confidential to the disclosing party; 
      9. **Controller, Processor, Data Subject, Personal Data, Personal Data Breach, processing and appropriate technical and organisational measures** each have the meaning given to them in relevant UK Data Protection Law, and where applicable, the EU General Data Protection Regulation (EU GDPR); 
      10. **Consumer Prices Index** means the (all-items) index of that name published by the UK Office of National Statistics, or such successor body or successor index as shall apply from time to time in future (so as to most closely mirror that index); 
      11. **Charges** means the applicable charges for the Services from time to time, including the Professional Services Charges and the Subscription Charges; 
      12. **Credits** means credits payable for Professional Services, or additional usage rights, as set out in the relevant Proposal, which may be purchased in advance by Customer (and shall be specified in the Proposal), and can be redeemed against the purchase of outside-scope Professional Services or usage rights during the Term as contemplated and subject to the provisions outlined in clause 9.11 (and where applicable in the relevant Proposal);  
      13. **Customer** means the organisation which has purchased access to the Subscription Services from Complyfirst, as specified in the Proposal; 
      14. **Customer Data **means the data, content and images inputted by the Authorised Users or (if applicable) Complyfirst on Customer’s behalf for the purpose of facilitating Customer’s or its Authorised Users’ use of the Software. All Customer Data shall be deemed to be the Confidential Information of the Customer by default; 
      15. **Customer Equipment** means a functioning hardware system and software facilitating access to the following modern and high usage web browsers, namely: Chrome, Safari or MS Edge, for the current and previous version of each such browser, and internet access, or such other relevant software and/or hardware reasonably notified to Customer by Complyfirst from time to time, although the Subscription Services are optimised on Chrome; 
      16. **Data Protection Law** means all applicable data protection and privacy legislation in force from time to time in the UK or Ireland, including, to the extent applicable, the UK or EU General Data Protection Regulation (**GDPR**); 
      17. **Free Service** means any Service that is provided without a charge; 
      18. **Feedback** means any ideas, know-how, algorithms, code contributions, suggestions, enhancement requests, recommendations or any other feedback on Complyfirst products or services; 
      19. **General Terms** has the meaning given to it in clause 1.1; 
      20. **Generative AI** has the meaning given to it in clause 
      21. **Implementation Services** means the implementation services and/or deliverables to be provided in respect of the Subscription Services, as described in the applicable Proposal; 
      22. **Information Security Policy** or **ISP** means **Complyfirst’s** information security policy setting out how it will safeguard the Customer Data stored via the Subscription Services from time to time available at [https://www.complyfirst.co/isms-policy](https://www.complyfirst.co/isms-policy); 
      23. **Initial Subscription Term** means the initial subscription term specified in the Proposal, which shall be 12 months unless otherwise specified; 
      24. **Licence Restrictions** means the licence restrictions specified or referred to in the Proposal or elsewhere in the Agreement; 
      25. **Payment Terms** means the payment terms set out in the Proposal. If none are specified the default payment terms shall require payment of any Subscription Charges in full in advance of the Initial Subscription Term or any subsequent Renewal Term, on demand, and payment for any Professional Services (other than Implementation Services, which are invoiced and payable in full in advance) monthly in arrears, on 30-day payment terms; 
      26. **Purpose** means accessing and using the Subscription Services as a tool to assist with the streamlining and automation of regulatory reporting to Regulators (or other regulatory authority to whom the Subscription Services may assist in reporting from time to time), including to (a) prepare reports (b) submit reports, and (c) view any stored reports, and otherwise making use of any of the functionality offered by the Software (including that contemplated within the Proposal) for its functionally contemplated purposes only; 
      27. **Premium Features** means any substantially new or enhanced features of the Software which Complyfirst may offer from time to time, other than the core Software functionality for the Software modules for which the Customer has subscribed, as described in the Proposal, which may be marketed to customers generally as premium features and locked behind a paywall, or be made available as separate modules; 
      28. **Privacy Policy** means Complyfirst’s privacy and cookies notice and policy, available at: [https://www.complyfirst.co/privacy-policy](https://www.complyfirst.co/privacy-policy); 
      29. **Professional Services** means any bespoke professional services to be provided by Complyfirst to Customer (as agreed from time to time or set out in the Proposal), other than the Subscription Services or basic Support, including for example, installation and technical assistance services on Customer site, on-request upgrades etc; 
      30. **Professional Services Charges** means the service charges detailed in the Proposal for any Professional Services, or which Complyfirst confirms to the Customer from time to time in respect of any further agreed Professional Services; 
      31. **Proposal** means the written quotation for, among other things, licensing and provision of the Services, provided by Complyfirst to Customer. There may be multiple live Proposals for additional Services, Premium Features or otherwise, and where this is the case, the Proposals shall collectively form part of the Agreement; 
      32. **Regulator** means any applicable regulatory, supervisory, governmental or enforcement authority with jurisdiction over the Customer’s activities or regulatory requirements;
      33. **Renewal Period** means rolling terms of the same duration as the Initial Subscription Term (or such other period as Complyfirst may agree in writing with Customer in the Proposal); 
      34. **Retail Prices Index** means the (all-items) index of that name published by the UK Office of National Statistics, or such successor body or successor index as shall apply from time to time in future (so as to most closely mirror that index); 
      35. **Sensitive Information** means (a) credit or debit card numbers; personal financial account information; national insurance or social security numbers or equivalents; passport numbers; driver’s licence numbers or similar identifiers; passwords; details of racial or ethnic origin; physical or mental health condition or information; or other employment, financial or health information, including any information defined under the UK Data Protection Legislation as ‘Sensitive Personal Data’ (or any analogous term which may apply from time to time), or any information subject to the US Health Insurance Portability and Accountability Act, the Payment Card Industry Data Security Standards, and other regulations, laws or industry standards designed to protect similar information as amended or applicable worldwide from time to time; 
      36. **Services** means both the Subscription Services and the Professional Services; **Site(s)** means the physical sites specified within the Proposal;  
      37. **Software** means those modules of Complyfirst’s end-to-end regulatory reporting software application, Complyfirst®, which provides Authorised Users access to the Complyfirst® portal for which the Customer has subscribed, as articulated in the relevant Proposal, and which includes any general upgrades to such modules released to all customers to which Customer is otherwise entitled under the terms of the Agreement, and which is accessed via the Subscription Services (but excluding Premium Features unless expressly stated otherwise in the Proposal); 
      38. **SLA** means Complyfirst’s service level agreement (where the Proposal states that it is applicable to the Customer) available at [https://www.complyfirst.co/sla](https://www.complyfirst.co/sla); 
      39. **Subscription Charges** means the total amounts specified in the Proposal from time to time or otherwise payable in accordance with the terms of the Agreement, to be paid in accordance with the timeframes and other stipulations set out in the Agreement; 
      40. **Subscription Services** means hosting of the Software (including any Premium Features purchased by the Customer from time to time) and making it available for access on a software as a service basis to Authorised Users using Customer Equipment via [https://www.complyfirst.co/](https://www.complyfirst.co/) or such other URL as Complyfirst may make available from time to time; 
      41. **Subscription Term** means the term beginning on the Commencement Date, and continuing for the Initial Subscription Term, and any Renewal Periods (subject to clause 14.3), unless and until the Agreement is terminated in accordance with its terms; 
      42. **Support **means the support services to be provided by Complyfirst in relation to each Authorised User, for the relevant Subscription Term, and made available, unless otherwise specified, during Complyfirst’s standard business hours (9am to 5.00pm UK time on Business Days) via email or telephone; 
      43. **Tariff** means Complyfirst’s published tariff of outside scope Services, available within the Proposal and as amended from time to time; 
      44. **Term** means the term of the Agreement as defined in clause 17.1; and 
      45. **Unused Portion** means, in respect of any period of the Subscription Term for which Customer has made a payment in advance, the proportion which the number of days following termination of the Agreement until the end of such remaining Subscription Term bears to the total number of days in that period.
   2. Clause headings shall not affect the interpretation of the Agreement. References to clauses are to the clauses of these General Terms.
   3. Words in the singular shall include the plural and vice versa.
   4. A reference to a statute or statutory provision is a reference to it as it is in force for the time being, taking account of any amendment, extension, or re-enactment and includes any subordinate legislation for the time being in force made under it.
   5. Any words following the terms including, include, in particular, for example or any similar expression shall be construed as illustrative and shall not limit the sense of the words, description, definition, phrase or term preceding those terms.
3. **ACCESS TO THE SUBSCRIPTION SERVICES**
   1. Customer warrants and represents that any information provided to Complyfirst is complete, accurate and not misleading (including information providing as part of the Agreement setup process), that it will inform Complyfirst if at any time that information changes whilst Customer or its Authorised Users continue to use the Subscription Services and acknowledges that Complyfirst may rely on such information and not seek to establish its reliability.
   2. Customer acknowledges that subject to certain limitations, and any limitations set by any Customer accounts with specific privileges, Authorised Users have administrative control over their accounts and the Customer Data stored on the central Customer account, and also for populating relevant information within the Subscription Services and Customer shall have sole responsibility for supervision and observation of the actions of its Authorised Users.
   3. Subject to payment and the other restrictions set out in the Agreement, Complyfirst hereby grants to Customer, subject to the Licence Restrictions a non-exclusive, non-transferable right to permit the Authorised Users to use the Subscription Services during the Subscription Term for the Purpose.
   4. The rights provided under clause 3.3 are granted to Customer only and shall not be considered granted to any subsidiary or holding company of Customer.
   5. In relation to the Authorised Users, Customer undertakes that: (a) it shall be responsible for compliance by Authorised Users with the applicable terms of the Agreement, and that relevant restrictions on Customer set out within the Agreement shall, unless the context requires otherwise, equally apply to any such persons; (b) the Customer will not allow or suffer any one Authorised User’s account to be used by more than one individual unless it has been reassigned in its entirety to another individual, in which case the prior individual shall no longer have any right to access or use the Subscription Services and/or their documentation; (c) each Authorised User shall keep a secure password for their use of the Subscription Services and its documentation, and that each Authorised User shall keep his password confidential; (d) it shall permit Complyfirst to audit the Subscription Services in order to establish Customer’s compliance with the Agreement; (e) if any of the audits referred to in clause 3.5(d) reveal that Customer has underpaid Subscription Charges to Complyfirst, then without prejudice to any other right to which it may be entitled, Customer shall pay to Complyfirst an amount equal to such underpayment (as calculated by reference to the additional Subscription Charges that would ordinarily be payable for any out of scope use) within 10 Business Days of the date of the relevant audit; (f) if any of the audits referred to in clause 3.5(d) reveal that any password has been provided to any individual who is not an Authorised User, then without prejudice to Complyfirst’s other rights, Customer shall promptly disable such passwords and Complyfirst shall not issue any new passwords to any such individual; and (g) all Authorised Users shall meet the relevant definition of Authorised User under these General Terms at all times, including that they are accessing the Subscription Services only for the Customer’s lawful business purposes, including subject to any Licence Restrictions, and it shall promptly disable the login details for any Authorised User who has ceased to meet the relevant definition.
   6. The Customer may issue an unlimited number of Users Licences to Authorised Users via the Subscription Services as long as it acts reasonably. All Authorised Users must be using the Subscription Services for purposes associated with the Customer’s lawful business. Customer should note that it will be responsible for its Authorised Users’ data usage and any relevant overages as specified below.
   7. Customer must not permit any of its Authorised Users to (a) be under the legal age to use the Subscription Services in the country the Authorised User resides in (or whose laws apply to them); (b) share with or permit access to any Authorised User’s account by multiple people; or (c) operate a service or automated account, where there is not a single human individual responsible for that account. If Complyfirst determines that there has been a breach of this clause, in addition to its other rights, it reserves the right to suspend or terminate the affected Authorised User accounts, or the Agreement, as noted below.
   8. Customer shall not access, store, distribute or transmit any viruses, or any material during the course of its use of the Subscription Services that: (a) is unlawful, harmful, threatening, defamatory, obscene, infringing, harassing or racially or ethnically offensive; (b) facilitates illegal activity; (c) depicts sexually explicit images; (d) promotes unlawful violence; (e) is discriminatory based on race, gender, colour, religious belief, sexual orientation, disability, or any other illegal activity; or (f) causes damage or injury to any person or property; and Complyfirst reserves the right, without liability to Customer, to disable Customer’s access to any material that breaches the provisions of this clause.
   9. Customer shall not: (a) other than as permitted by law, attempt to copy, modify, duplicate, create derivative works from, frame, mirror, republish, download, display, transmit, or distribute all or any portion of the Software made available via the Subscription Services and/or its documentation (as applicable) in any form or media or by any means; nor attempt to reverse compile, disassemble, reverse engineer or otherwise reduce to human-perceivable form all or any part of the Software; or (b) access all or any part of the Subscription Services in order to build a product or service which competes with the Subscription Services; or (c) use the Subscription Services to provide services to third parties; or (d) license, sell, rent, lease, transfer, assign, distribute, display, disclose, or otherwise commercially exploit, or otherwise make the Services available to any third party except the Authorised Users; or (e) attempt to obtain, or assist third parties in obtaining, access to the Subscription Services, other than as provided under this clause; or (f) interfere with or disrupt the integrity or performance of the Subscription Services or third party data contained therein; or (g) attempt to gain unauthorised access to the Subscription Services or their related systems or networks, including with a view to making alterations to, or modifications of, the whole or any part of the Software, or permitting the Software or any part of it to be combined with, or become incorporated in, any other programs.
   10. The Subscription Services may be used to process Sensitive Information where necessary for the Customer’s lawful regulatory reporting obligations, including suspicious activity reports. Customer remains responsible for ensuring it has a lawful basis for processing such Sensitive Information and for providing such data to Complyfirst.
   11. Customer shall use best endeavours to prevent any unauthorised access to, or use of, the Subscription Services and/or their documentation and, in the event of any such unauthorised access or use, promptly notify Complyfirst.
4. **PROFESSIONAL SERVICES**
   1. Complyfirst shall supply, during the Subscription Term, the Support, the Subscription Services and any agreed Professional Services to Customer on and subject to the terms of the Agreement.
   2. Complyfirst shall provide the agreed Implementation Services set out in the Proposal to assist in configuring the Subscription Services for the Customer’s specific use. Customer acknowledges that third-party integrations, import files or data streams required to integrate with the Subscription Services via API must be configured through the Implementation Services, and identified in advance by Customer and documented in the Proposal, and by default the Subscription Services do not offer these integrations.
   3. Complyfirst’s approach to Implementation Services is based on shared project responsibility, resulting in a cooperative, hands-on project that is jointly managed by Complyfirst and Customer. In addition to the assumptions and requirements set forth elsewhere in the Agreement, Customer acknowledges and agrees that the above approach, Charges, commitment to delivery of agreed Implementation Services (and Subscription Services going forward) and agreed timelines set out in Proposal are based on the following assumptions (as applicable), or any other assumptions identified in the Proposal:
      1. Customer will accurately complete all applicable questionnaires, templates, and other documents and requests for data as reasonably required for Complyfirst to fulfil its implementation roles and responsibilities, to the best of Customer’s knowledge and with timely assistance from Complyfirst where any such requests are unclear, each in the manner reasonably prescribed by Complyfirst by the agreed upon timelines;
      2. Customer will, where applicable, provide reasonable access to Customer’s personnel with the appropriate knowledge of Customer’s systems and their configuration;
      3. Any configuration or test environment (including all data) will be decommissioned after a period of sixty (60) days from the completion of the Implementation Services;
      4. Customer will appoint both a named technical product expert and a regulatory compliance expert who Complyfirst can work with in the delivery Implementation Services, who will be available for the duration of the implementation phase (save for illness, absence, leave or departure from the Customer’s employment), so as to help ensure a consistent and efficient rollout of the Subscription Services;
      5. Customer will confirm acceptance for all Implementation Services in a reasonably timely fashion and per any project schedule;
      6. Customer will complete training activities as outlined in any training curriculum provided by Complyfirst from time to time and per the project schedule, following the instructions contained in the training materials; and
      7. Customer will identify any required third-party integrations, import files or data streams prior to project kick-off, and these shall be documented up-front (whether in the Proposal or otherwise) and any required configuration for the Subscription Services shall form part of the Implementation Services. Any additional file(s) or data streams identified thereafter may result in additional Charges and potential delay in completion of the Implementation Services;
      8. If, during the course of the delivery of the Implementation Services, it transpires that any third party integration or API cannot provide the Software solution with some or all of the required data, this is outside Complyfirst’s control and there will be no reimbursement of any Implementation Services Charges, or re-negotiation of the terms of the Agreement; and
      9. Any material changes to scope described in the Proposal will be addressed through a change request, if these have a material impact on costs.
   4. The provision of the Subscription Services shall be subject to ongoing provision by Complyfirst’s hosting services provider from time to time, but also to the commitments made by Complyfirst in the SLA. Complyfirst shall use reasonable endeavours to inform Customer in advance of any planned service interruption to the Subscription Services.
   5. Complyfirst will, as part of the Services and at no additional cost to Customer other than the Subscription Charges, provide Customer with Support in accordance with Complyfirst’s support services policy (if any) in effect at the time that the Services are provided, subject to fair usage of the Support by Customer. Complyfirst is a UK based company and typically deals with Support tickets between 9 am and 5 pm GMT on Business Days. Customer’s representatives must be available to interact with Complyfirst’s support team where they have any queries regarding a particular request. For clarity, subject to fair usage, there are no limitations on the number of Support tickets or requests that may be raised by the Customer. Customer shall procure that its Authorised Users provide access to Complyfirst to their accounts where required in order to provide remote support. Complyfirst may also provide online support resources for Authorised Users. All Support shall be delivered remotely. Any support Services outside the above, including any on-Site support required by the Customer, or any support with specific advice on regulatory reporting requirements shall be outside of scope and shall, if agreed between the parties, be chargeable at Complyfirst’s then prevailing standard daily or hourly rates as a Professional Service, as specified in Complyfirst’s then published Tariff, together with any applicable expenses which shall be agreed in advance and separately chargeable. If Customer requires such assistance, its Authorised User will be notified when raising a Support ticket that the requested Support is outside scope.
   6. If the Customer wishes to request that a particular feature of the Subscription Services be improved or added at any time, it may request this, and this may be agreed and undertaken as a Professional Service, subject to agreement between the parties as to the nature of the request, timing and the charges for facilitating this request.
   7. The Subscription Services are generally subject to fair data usage limits as set out in the applicable Proposal. Any excess usage will be chargeable at the rates agreed in the Proposal or otherwise agreed in writing between the parties.
   8. The Subscription Services are also only intended for the usage permitted by the Licence Restrictions set out in the Proposal, including any usage restrictions associated with the kind of licence held by the Customer and specified in those Licence Restrictions, for example, a payments or e-money licence, and may not be used for any other kind of regulatory reporting, or any audit restrictions. If Customer exceeds those Licence Restrictions it shall be liable to pay Complyfirst’s charges for such excessive usage, calculated at Complyfirst’s reasonable discretion (or as set out in the Proposal) and payable upon demand (or in advance based on Complyfirst’s Credit system, as applicable). Complyfirst reserves the right, acting in its reasonable discretion, to apply fair usage limits around excessive or unusual token utilisation of underlying Generative AI models utilised by the Software, or where any third party service Generative AI providers whose products or services Complyfirst resells as part of the Software materially change their pricing. Such rights may be further outlined in any relevant Proposal, and any overage costs will be re-charged to Customer on a purely cost pass-through basis.
   9. Where Customer wishes to purchase access to Premium Features as part of the Subscription Services and use of the Software, these must be specified and agreed in a Proposal, but are not included by default.
   10. To the extent Customer uses any Free Services, it acknowledges and agrees that its entitlement to access and use such Free Services constitutes reasonable and sufficient consideration in return for which it is willing to adhere to the terms of the Agreement.
5. **WARRANTIES AND COMPLYFIRST’S OBLIGATIONS**
   1. Each party represents and warrants to the other that it has the legal power and authority to enter into the Agreement (in the case of an individual representing a Customer, on that organisation or entity’s behalf), and that the Agreement and each Proposal is entered into by an employee or agent of such party with all necessary authority to bind such party to the terms and conditions of the Agreement, and that the Agreement or Proposal is accordingly binding upon each party and enforceable per its terms. Any person representing the Customer also warrants and represents that they are authorised to perform or permit the performance of all actions taken by Customer or its Authorised Users via the Subscription Services, including uploading any Customer Data to Customer’s account (including making it available to other Authorised Users, or publicly available to third parties).
   2. Complyfirst undertakes that the Services will be performed with reasonable skill and care expected of a suitably skilled person engaged in the same type of business as Complyfirst, and that it shall use reasonable endeavours to ensure that the Subscription Services will perform substantially in accordance with and subject to any limitations outlined in the Proposal and the SLA (where applicable). Otherwise, Complyfirst gives no warranties concerning the Subscription Services.
   3. The undertaking at clause 5.2 shall not apply to the extent of any non-conformance which is caused by (as applicable): (a) use of the Services contrary to Complyfirst’s instructions or otherwise than as permitted by the Agreement, (b) modification or alteration of the Software or Services (or the deliverables of the Services) by any party other than Complyfirst or Complyfirst’s duly authorised contractors or agents, (c) issues with Customer Equipment; (d) interaction of the Subscription Services (or their integration) with other software programmes or plugins (where those are not covered by the Proposal); (e) use of the Software in an application, or with any software, hardware or materials for which it was not intended; or (f) acts or omissions otherwise attributable to Customer and/or outside Complyfirst’s reasonable control. If the Services do not conform with the foregoing undertakings, Complyfirst will, at its expense, use all reasonable commercial endeavours to correct any such non-conformance within a reasonable timeframe, or provide Customer with an alternative means of accomplishing the desired performance. Such correction or substitution constitutes Customer’s sole and exclusive remedy for any breach of the undertakings set out in clause 5.2. Notwithstanding the foregoing, Complyfirst does not warrant that Customer’s use of the Subscription Services will be uninterrupted or error-free, nor that the Services and/or their documentation will meet Customer’s requirements.
   4. Customer acknowledges that it has assessed the suitability of the Services for its requirements. Complyfirst does not warrant that the Software, the Services and/or their documentation will be suitable for such requirements or that any use will be uninterrupted or error free.
   5. The Agreement shall not prevent Complyfirst from entering into similar agreements with third parties, or from independently developing, using, selling or licensing documentation, products and/or services which are similar to those provided under the Agreement.
   6. Timing for performance of Complyfirst’s obligations under the Agreement shall not be of the essence.
   7. Complyfirst warrants that it has and will maintain all necessary licences, consents, and permissions necessary for the performance of its obligations under the Agreement.
6. **CUSTOMER’S OBLIGATIONS** Customer shall: (a) at its cost, provide Complyfirst with all necessary co-operation in relation to the Agreement, and all necessary data and access to information as may be required by Complyfirst, its agents or contractors, in order to render the Services, including but not limited to applicable specifications, data management decisions, approvals, security access information and configuration services; (b) comply with all applicable laws and regulations with respect to its activities under the Agreement; (c) carry out all other Customer responsibilities set out in the Agreement in a timely and efficient manner. In the event of any delays, Complyfirst may adjust any agreed timetable or delivery schedule as reasonably necessary; (d) ensure that the Authorised Users use the Services in accordance with the terms and conditions of the Agreement and shall be responsible for any breach of the Agreement by either; (e) obtain and shall maintain all necessary licences, consents, and permissions necessary for Complyfirst, its contractors and agents to perform their obligations under the Agreement, including without limitation the Services; (f) ensure that its network and systems comply with the relevant specifications provided by Complyfirst from time to time; (g) be solely responsible for procuring and maintaining its network connections and telecommunications links, and maintaining appropriate Customer Equipment; (h) provide a single main point of contact who can address questions or issues relating to the Services, provide timely feedback and review any changes to the Services; (i) be solely responsible at its own cost for generating Customer Data, content and data required to utilise the services and uploading all such content and data to the site provided to Customer using the Services. In the event that Customer requires any assistance from Complyfirst in this regard, Complyfirst may provide such assistance as it deems appropriate at its then prevailing charges as a Professional Service, and ensure that it implements appropriate information security controls having regards to the sensitivity of any Customer Data it uploads; and (j) comply and procure the compliance of its Authorised Users with any reasonable directions given to it by Complyfirst from time to time. 
7. **USAGE RESTRICTION** This clause sets out the restrictions and requirements with which Authorised Users must comply when using the Subscription Services, for whose adherence to which Customer shall be liable and responsible. 
   1. Customer and the Authorised Users must not use the Subscription Services:
      1. In any way that breaches any applicable local, national or international law or regulation, including any copyright or trademark laws, export control or sanctions laws. Customer is responsible for making sure that Customer and Authorised Users’ use of the Subscription Services complies with laws and any applicable regulations, including that Customer and/or Authorised Users are not prohibited from using or receiving the Subscription Services by any relevant laws in the UK or Ireland or which apply in the country in which the Customer and/or Authorised Users are resident or from which it proposes to use or access same;
      2. In any way that is unlawful or fraudulent, or has any illegal or fraudulent purpose or effect;
      3. In any way which interferes with the use of Complyfirst’s Subscription Services by other users, or attempts to harm them or their business;
      4. In any way that relates to link building purposes or for the primary promotion of other goods or services;
      5. To harm or attempt to harm others in any way, including to bully, insult, intimidate or humiliate any person;
      6. If Customer and/or the Authorised User is not able to form legally binding contracts or is under the legal age in the country in which it resides (or to whose laws Customer and/or Authorised Users are subject at any time);
      7. To attempt to, or access data not intended for Customer and/or the Authorised User;
      8. To attempt to scan or test the security or configuration of the Subscription Services or to breach security or authentication measures without proper authorisation from Complyfirst;
      9. To send, knowingly receive, upload, download, use or reuse any material which does not comply with Complyfirst’s content standards; or
      10. To transmit or procure any unsolicited or unauthorised advertising or promotional material or any other form of similar solicitation (spam), or any other chain letters or promote any pyramid schemes.
   2. Customer and the Authorised Users must also:
      1. Not use any robot, spider, scraper or other automated means to harvest data from the Subscription Services in a way that might interfere with the operation of the Subscription Services without Complyfirst’s express written permission;
      2. Not act illegally or maliciously against Complyfirst’s business interests or reputation, or that of other users;
      3. Not, or attempt to, copy, modify, duplicate, create derivative works from, frame, mirror, republish, download, display, transmit, or distribute all or any portion of the Subscription Services in any form or media or by any means;
      4. Not, or attempt to, reverse compile, disassemble, reverse engineer or otherwise reduce to human-perceivable form all or any part of the Subscription Services (or their underlying software), access all or any part of the Subscription Services to build a product or service which competes with the Subscription Services;
      5. Not, save as expressly permitted in these Terms of Service, licence, sell, rent, lease, transfer, assign, distribute, display, disclose, or otherwise commercially exploit, or otherwise make the Subscription Services available to any third party;
      6. Not access without authority, interfere with, damage or disrupt any part of the Subscription Services, or any underlying equipment;
      7. Not knowingly to take any action that places excessive demand on the Subscription Services, or imposes, or may impose an unreasonable or disproportionately large load, or otherwise disable, overburden or impair (as determined in Complyfirst’s sole reasonable discretion), Complyfirst’s servers or other portion of Complyfirst’s infrastructure supporting the Subscription Services or any network on which the Subscription Services is stored, any software used in the provision of the Subscription Services or any equipment or network or software owned or operated by any third party;
      8. Use the Subscription Services in compliance with any legal requirements that may apply;
      9. Not misuse Complyfirst’s Site by knowingly introducing viruses, trojans, worms, logic bomb, or otherwise technologically harmful material;
      10. Not attempt to gain unauthorised access to the server on which Complyfirst’s Site resides or any server, computer or database connected to Complyfirst’s Site or attack Complyfirst’s Site via a denial-of-service attack or a distributed denial-of-service attack; and
      11. Only upload Customer Data that the Customer and/or Authorised Users have the right to upload and that fully comply with any third-party licences relating to Data the Customer and/or Authorised Users interact with or upload.
   3. By breaching these provisions, Authorised Users may commit a criminal offence in the UK or elsewhere. We will report any criminal offence to the relevant authorities where we are required to do so by law and co-operate with those authorities to the extent required by law, by disclosing Customer’s or its relevant Authorised User’s identity to them (again where required to do so by law).
   4. These standards (**Standards**) apply to any Customer Data that Authorised Users upload to the Subscription Services. The Standards must be complied with in spirit and to the letter and apply to each part of any Customer Data and its whole. Complyfirst will determine, at its sole reasonable discretion, whether any Customer Data breaches the Standards. Customer warrants that any Customer Data complies with the Standards set out in the Agreement.
   5. Any Customer Data must not:
      1. Breach the law applicable in the UK, Ireland or in any country from which it is posted;
      2. Promote sexually explicit material;
      3. Promote violence;
      4. Breach of any legal duty owed to a third party, such as a contractual duty or a duty of confidence;
      5. Promote any illegal activity;
      6. Be in contempt of court;
      7. Give the impression that it emanates from or relates to us or one of Complyfirst’s employees, unless genuine;
      8. Impersonate any person, or misrepresent the Customer or Authorised Users’ identity or affiliation with any person;
      9. Advocate, promote, incite any party to commit, or assist any unlawful or criminal act such as (by way of example only) copyright infringement or computer misuse;
      10. Contain a statement which the Customer and/or Authorised Users know or believe, or has reasonable grounds for believing, that members of the public to whom the statement is, or is to be, published are likely to understand as a direct or indirect encouragement or other inducements to the commission, preparation or instigation of acts of terrorism;
      11. Contain viruses, Trojan horses, worms, time-bombs, keystroke loggers, spyware, adware, or any other harmful programs or similar computer code designed to affect any computer software or hardware operation adversely; or
      12. Knowingly infringe any copyright, database right, trademark or other intellectual property rights of any other person.
8. **THIRD PARTY INTEGRATIONS**
   1. Additionally, Customer may use or Complyfirst may facilitate the integration of standalone third party applications when accessing or using the Subscription Services, for example applications that integrate with or export data feeds to the Subscription Services or use the Subscription Services to authenticate or access another service. While the Agreement represents Complyfirst’s agreement with Customer, other parties’ terms govern their relationships. Whilst Complyfirst takes no responsibility for any Authorised User’s or Customer’s adherence to such terms or the actions taken by such third-parties, Customer warrants and represents that it will honour and adhere to such terms when using the Subscription Services and that Customer will not hold Complyfirst responsible for any interactions with such third parties or their terms, including for wrongful or negligent acts or omissions, or breaches of contract.
   2. When importing third party data streams using the Subscription Services, the Customer warrants and represents that it shall ensure it use industry standard anti-virus technology and otherwise checks such data streams for any malicious code or content, including Customer Data which would breach the terms of the Agreement.
   3. Complyfirst does not control the content, messages or information found in or on or accessible through any third party services accessible through or integrated with the Subscription Services. Complyfirst disclaims and will have no liability regarding such sites or services and any actions resulting from Customer’s or its Authorised Users’ use of the same. Such sites or services’ availability does not mean Complyfirst endorses, supports or warrants such sites or services.
   4. Complyfirst shall not be responsible for any issues with performance of any third party applications, and their integration within and functioning through the Subscription Services at all times is outside Complyfirst’s control and is not guaranteed. Complyfirst shall use all reasonable endeavours (subject to the caveats and assumptions set out in the Agreement, including clause 4.3 above and the terms of the Proposal) to facilitate third party integrations, but the third party integrations supported by the Subscription Services may change from time to time and Complyfirst cannot be held responsible for such changes during the Term. If Customer becomes aware that any third party whose solutions integrate with the Subscription Services is likely to make changes to their API, API documentation or data structures during the Term, or this is likely to happen with respect to Customer’s own APIs, etc, Customer will notify Complyfirst in advance of such changes, and if Complyfirst is required to make changes as a result of such changes the parties that this will be outside the scope of Complyfirst’s Support or other obligations under the Agreement, and any Professional Services requested by Customer to facilitate ongoing integration will be chargeable on the basis specific in Complyfirst’s published Tariff.
   5. Customer must have a valid account for any third party applications utilised by it to link to the Subscription Services via API at all times.
9. **CHARGES AND PAYMENT**
   1. Customer shall pay the Subscription Charges (and any Professional Service Charges, or other charges specified or agreed) to Complyfirst in accordance with the Payment Terms.
   2. If Complyfirst has not received payment for any Subscription Charges in advance, and any Professional Services Charges within 10 days after the due date, or notice of a bona fide dispute, without prejudice to any other rights and remedies of Complyfirst: (a) Complyfirst may, without liability to Customer, disable Customer’s and any Authorised Users’ passwords, accounts and access to all or part of the Services and Complyfirst shall be under no obligation to provide any or all of the Services while the invoice(s) concerned remain unpaid; and (b) interest shall accrue on such due amounts at annual rate equal to 8% over the then current base lending rate of Bank of England at the date the relevant invoice was issued, compounded monthly, commencing on the due date and continuing until fully paid, whether before or after judgment, or the highest rate otherwise permitted by law. Customer shall reimburse Complyfirst for all costs incurred in collecting any overdue payments and related interest, including, without limitation, legal fees, legal costs, court costs and collection agency fees.
   3. If Complyfirst suspends Customer’s account for non-payment, Customer will be entitled to reopen or reinstate its account by: (i) paying all outstanding invoices; (ii) paying all late fees or charges associated with past due invoices; (iii) paying any fees Complyfirst may be charged for unsuccessful direct debit or credit card charge(s); and (iv) executing a direct debit authorisation form or credit card charge authorisation form expressly authorizing Complyfirst to debit its bank account or charge its credit card according to the payment terms set out in the relevant Proposal.
   4. If Customer is paying by credit card, direct debit or other online payment methods, it authorises Complyfirst to charge Customer’s credit card, bank account or other online payment methods for all fees payable during the Subscription Term. Customer further authorises Complyfirst to use a third party to process payments and consent to disclose Customer’s payment information to such a third party.
   5. All amounts and fees stated or referred to in the Agreement: (a) shall be payable in pounds sterling (unless another currency is denominated in the Proposal); (b) are, subject to clause 17.6, non-cancellable and non-refundable; (c) are exclusive of taxes or duties payable under the Agreement as specified below, which shall be added to Complyfirst’s invoice(s) at the appropriate rate; and (d) shall be paid by bank transfer in full and cleared funds to the account specified on Complyfirst’s invoice, or by such other payment method (which must be kept up to date and accurate) as Complyfirst may accept from time to time.
   6. Customer is solely responsible for all taxes, fees, duties and governmental assessments (except for taxes based on Complyfirst’s net income or gross revenue) imposed or become due in connection with the provision of Services to Customer under the Agreement. If Customer is located in the UK, or another EU member state other than Ireland, current VAT rules at the date at which these General Terms were last updated permit Complyfirst to zero rate any invoice for VAT purposes, but Customer must fully comply with its own VAT reporting and payment obligations in its own domicile. Complyfirst will not issue refunds or credits for any VAT charged.
   7. If Customer is required to deduct or withhold any tax it must pay the amount deducted or withheld as required by law and pay Complyfirst an additional amount so that Complyfirst receives payment in full as if there were no deduction or withholding.
   8. If, at any time whilst using the Services, Customer exceeds the Licence Restrictions, Complyfirst shall charge Customer, and Customer shall pay, Complyfirst’s then prevailing charges for such excessive use.
   9. Customer must keep its contact information, billing information and credit card information (where applicable) up to date through its account.
   10. Complyfirst shall at the start of each Renewal Period, having given at least thirty (30) days’ prior notice to Customer (including via email), be entitled to increase the Subscription Charges and the Subscription Charges set out in Proposal shall be deemed to have been amended accordingly for the duration of the Renewal Period (unless the Customer objects to such increase not less than 14 (fourteen) days prior to the commencement of that Renewal Period, in which case the Agreement may not renew into any Renewal Period unless the parties otherwise agree). If no notice is given, the Subscription Charges applicable for over each subsequent Renewal Period shall be increased (only) by a percentage increase in line with the annual increase in either (a) the Retail Prices Index, or (b) the Consumer Prices Index (whichever is higher) over such period
   11. Complyfirst may offer, via an agreed Proposal, a system allowing Customer to purchase pre-paid Credits which can be redeemed for the future purchase of either (a) outside-scope Professional Services; or (b) additional usage rights in respect of the Software. Any Professional Services or usage rights purchased will need to be agreed with Complyfirst via a separate Proposal. Save as otherwise specified in a Proposal, Credits expire at the end of the then current Initial Subscription Term or Renewal Period (a **billing cycle**) in which they are purchased, meaning that any Credits Customer doesn’t use during the applicable billing cycle will not roll over into future billing cycles, other than in exceptional circumstances where Complyfirst may choose to facilitate this. If the Agreement is terminated or expires unused Credits will expire immediately. There will be no refund or payment for any unused Credits on termination or expiry. All Credits are non-refundable, non-cancellable, non-transferable and non-exchangeable, have no cash value and are not redeemable for cash or anything else. The exact number and type of Professional Services or usage rights required will dictate the number of Credits required, and be further specified in any relevant Proposal.
10. **PROPRIETARY RIGHTS AND DATA**
   1. Customer acknowledges and agrees that Complyfirst and/or its licensors own all intellectual property rights in or arising from the Services, Software and their documentation. All content on the Complyfirst’s site and the Subscription Service is copyright © FDJ Ecommerce Ltd t/a Complyfirst (Complyfirst’s parent company). The Complyfirst® name and brand, and all associated logos, are each the registered or unregistered trademarks of Complyfirst or of FDJ Ecommerce Ltd.
   2. Except as expressly stated herein, the Agreement does not grant Customer any rights to, or in, patents, copyrights, database rights, trade secrets, trade names, trademarks (whether registered or unregistered), or any other rights or licences in respect of the Services, Software and its documentation. This shall be without prejudice to Customer’s ownership of any background intellectual property rights owned by it separately from the Agreement and/or pre-dating the Agreement.
   3. Customer may not duplicate, copy, or reuse any portion of Complyfirst’s Software or Services or trademarks, without Complyfirst’s express permission, save that Customer may link to the Complyfirst’s website, provided it does so fairly and legally and in a way that does not damage Complyfirst’s reputation or take advantage of it. Customer must not establish a link in such a way as to suggest any form of association, approval or endorsement on Complyfirst’s part where none exists. Customer must not establish a link to Complyfirst’s Site on any website that Customer does not own unless Customer has relevant authorisations. Complyfirst reserves the right to withdraw linking permission without notice. The website in which Customer is linking must comply in all respects with the content standards set out in the Agreement. Complyfirst’s Site must not be framed on any other site. Complyfirst may withdraw this licence at any time on notice. If Customer wishes to link to or make any use of data on Complyfirst’s website other than that set out above, it must obtain Complyfirst’s prior written consent.
   4. Customer shall own all rights, title and interest in and to all of Customer Data and shall have sole responsibility for the legality, reliability, integrity, accuracy and quality of Customer Data and the means by which it acquired such Customer Data, provided that Complyfirst shall have a lien over any Customer Data in the event of non-payment of any Charges by Customer hereunder, and reserves the right to disable all access to the Customer Data in the event of non-payment as contemplated herein.
   5. Complyfirst shall use reasonable endeavours to maintain appropriate administrative, physical and technical safeguards for protection of the security, confidentiality and integrity of Customer Data, including in accordance with the Complyfirst’s ISP. However, Customer understands and acknowledges that use of the Subscription Services necessarily involves transmission of Customer Data over networks that are not owned, operated or controlled by Complyfirst, and that Complyfirst cannot be held responsible for any Customer Data lost, altered, intercepted or stored across such networks. Complyfirst does not guarantee that its security procedures will be error-free, that transmissions of Customer Data will always be secure or that unauthorised third parties will never be able to defeat Complyfirst’s security measures or those of Complyfirst’s third party service providers.
   6. Complyfirst shall not modify Customer Data, disclose Customer Data or access Customer Data except: (a) as required by law; (b) as expressly permitted by Customer; (c) to provide the Services; (d) to address technical problems or issues with the Services; or (e) at Customer’s request when providing Support.
   7. Customer hereby grants to Complyfirst a license to use, reproduce, modify, create derivative works from, distribute, perform, transmit, anonymize, and display Customer Data as strictly necessary to provide the Services, including the right for Complyfirst to grant equivalent rights to its service providers that perform services that form part of or are otherwise used to perform the Services. Customer further grants to Complyfirst all necessary rights to perpetually and irrevocably use, on a sub-licensable, perpetual and royalty-free basis, reproduce, modify, create derivative works from, distribute, perform, transmit and display Customer Data in a strictly **both** anonymised **and** aggregated form that does not identify individual persons or organisations (such as, by way of example and not by way of limitation, numbers of verifications, complaints or instances of reported fraud) in order to compile statistics regarding use of the Services (or their underlying data) and/or to develop and improve the Services, including, for example, to offer Customer and other Complyfirst customers aggregated benchmarking data pertaining to numbers of complaints that might be typical in a particular industry and territory (or for a particular sub-category of licensee). 
   8. Neither Customer or any Authorised Users may access the Subscription Services where they are engaged as an employee or contractor with any business that competes with Complyfirst own or to attempt to gain access to Complyfirst’s Confidential Information with a view to building, creating or amending any software or service which competes with any element of the Subscription Service offered by Complyfirst. Further, during the Subscription Term, and for twelve (12) months thereafter, Customer shall not, or attempt to, build or develop any product or service that commercially competes with or is substantially similar to the Software, which it provides or intends to provide to third parties for payment (i.e., which is not solely intended for internal use). This obligation shall cease to apply only where there is no longer a commercial relationship between the parties, and Customer can demonstrate that (a) an independent third party has licensed or sold the Software (or something similar to it) to it on arms’ length terms, and (b) such competing solutions do not incorporate or contain, are not based upon, and do not rely in any way upon any Confidential Information made available by Complyfirst to the Customer, or to which the Customer otherwise gained access, under the Agreement or any previous contract between the parties.
   9. If Customer (including its Authorised Users) gives Complyfirst any Feedback, it acknowledges and agrees by accepting the Agreement that Complyfirst will have a royalty-free, fully paid-up, worldwide, transferable, sub-licensable, irrevocable and perpetual licence to implement, use, modify, commercially exploit or incorporate the Feedback into Complyfirst’s products, services, and documentation.
   10. Customer acknowledges that it has no right to access the Software in source code form or unlocked coding or comments.
   11. Complyfirst will store report information created using the Subscription Services unless Customer has instructed Complyfirst to deactivate storage of data. Complyfirst shall use its reasonable commercial endeavours to back-up all Customer Data on a daily basis but otherwise backup of all Customer Data shall be the sole responsibility of Customer. In the event of any loss of or damage to Customer Data, Customer’s sole and exclusive remedy shall be for Complyfirst to use its reasonable commercial endeavours to restore the lost or damaged Customer Data from the latest back-up of such Customer Data maintained by Complyfirst. Customer should note that Complyfirst’s typical retention periods for Customer Data are as set out in its Privacy Policy. Complyfirst is not responsible for Customer’s compliance with its regulatory data retention requirements, and will only use reasonable endeavours to back-up / store finalised report information for a period of six years (on the basis outlined in this clause above), following which point it is automatically deleted, unless the Agreement has terminated earlier and the Customer Data been deleted as noted in clause 17.5 below.
11. **DATA PROTECTION**
   1. Both parties will comply with all applicable requirements of the Data Protection Law. This clause is in addition to, and does not relieve, remove or replace, a party’s obligations under the Data Protection Law.
   2. The parties acknowledge that for the purposes of the Data Protection Law, in relation to any Personal Data comprised within Customer Data (**Customer Personal Data**), Customer is the data controller and Complyfirst is the data processor. Such Personal Data shall only be processed by Complyfirst in accordance with any lawful instructions reasonably given by Customer from time to time in writing, as reasonably necessary to fulfil the Agreement (including as required by the underlying operating procedures for the Software) and exercise Complyfirst’s rights and obligations hereunder and as applicable in accordance with the terms of Complyfirst’s Privacy Policy. Complyfirst’s Privacy Policy provide detailed notice of Complyfirst’s privacy and data use practices concerning any personal data comprised in Customer Data. Complyfirst requires all authorised users and customers to adhere to the relevant provisions of the Privacy Policy. Customer shall be responsible and liable for its Authorised Users’ adherence to these requirements.
   3. As between the parties, where each party processes any Personal Data provided by or relating to the other party or its employees otherwise than Customer Personal Data, including employee names and email addresses of employees of Customer with whom Complyfirst interacts (for example), each party acknowledges that they shall act as a data controller in relation to such Personal Data and only process it for specified purposes in accordance with each party’s respective privacy policy for the purposes of contract administration or otherwise in its own legitimate interests, as permitted under Data Protection Law.
   4. Without prejudice to the generality of clause 11.1, Customer must ensure that its use of the Subscription Services and all Customer Data is at all times compliant with the terms of the Agreement, all applicable laws and regulations including Data Protection Law (nationally and internationally) and Customer represents and warrants that: (a) it has obtained all necessary rights, releases and permissions to provide all Customer Data to Complyfirst for the purposes and duration of the Agreement and to grant the rights granted to Complyfirst in the Agreement; and (b) Customer Data and its transfer to and use by Complyfirst as authorised by Customer under the Agreement do not violate any laws (including without limitation those relating to export control, the principle of demonstrable “consent” under Data Protection Law, specifically Article 7 of the EU or UK GDPR) and electronic communications) or rights of any third party, or data subject, including without limitation any intellectual property rights, rights of privacy, or rights of publicity, and any use, collection and disclosure authorised herein is not inconsistent with the terms of any applicable privacy policies. Other than Complyfirst’s security obligations under clause 9.3, limited back-up obligations in clause 10.7, and legal obligations under Data Protection Law (as set out in this clause 11) and confidentiality obligations in clause 12, Complyfirst assumes no responsibility or liability for Customer Data, and Customer shall be solely responsible for Customer Data and the consequences of determining the purpose and manner in which Customer Data is to be processed, used, disclosed, stored, or transmitted.
   5. Without prejudice to the generality of clause 11.1, Complyfirst shall, in relation to any Customer Personal Data: (a) process that Customer Personal Data only on the written instructions of Customer unless Complyfirst is required by Data Protection Law to otherwise process that Customer Personal Data; (b) ensure that it has in place appropriate technical and organisational measures to protect against unauthorised or unlawful processing of Customer Personal Data and against accidental loss or destruction of, or damage to, Customer Personal Data, appropriate to the harm that might result from the unauthorised or unlawful processing or accidental loss, destruction or damage and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures; (c) ensure that all personnel who have access to and/or process Customer Personal Data are obliged to keep Customer Personal Data confidential; (d) not transfer any Customer Personal Data outside of the UK or the EEA unless the prior written consent of Customer has been obtained and the following conditions are fulfilled: (i) Customer or Complyfirst has provided appropriate safeguards in relation to the transfer; (ii) the data subject has enforceable rights and effective legal remedies; (iii) Complyfirst complies with its obligations under the Data Protection Law by providing an adequate level of protection to any Customer Personal Data that is transferred; and (iv) Complyfirst complies with reasonable instructions notified to it in advance by Customer with respect to the processing of Customer Personal Data; (e) assist Customer, at Customer’s cost, in responding to any request from a Data Subject and in ensuring compliance with its obligations under the Data Protection Law with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators; (f) notify Customer without undue delay on becoming aware of a Personal Data breach; (g) at the written direction of Customer, delete or return Customer Personal Data and copies thereof to Customer on termination of the agreement unless required by Applicable Law to store Customer Personal Data (subject always to Customer having paid Complyfirst any then outstanding charges owing under the Agreement); and (h) maintain complete and accurate records and information to demonstrate its compliance with this clause.
   6. Customer consents to Complyfirst appointing the categories of sub-processor listed in the Privacy Policy or otherwise notified to Customer from time to time by Complyfirst, as third-party processors of any Personal Data processed by Complyfirst under the Agreement. Complyfirst confirms that it has entered or (as the case may be) will enter with such third-party processors into a written agreement substantially on those third party’s standard terms of business (which shall at a minimum require such sub-processors to treat any Customer Data as confidential and process any Customer Personal Data in compliance with Data Protection Law). As between Customer and Complyfirst, Complyfirst shall remain fully liable for all acts or omissions of any third-party processor appointed by it pursuant to this clause.
   7. If Complyfirst is deemed to process any personal data on Customer’s behalf when performing its obligations under the Agreement, the parties record their intention that the Agreement would represent the data processing agreement envisaged by Article 28 of the EU GDPR (and the equivalent provision under UK GDPR), together with the relevant provisions of Complyfirst’s Privacy Policy, which sets out the categories of personal data and data subjects, where Customer is the data controller and Complyfirst is a data processor.
   8. Customer hereby consents to Complyfirst conducting credit investigations, from time to time, including such requests for and exchange of information to and from consumer reporting agencies or credit grantors as it may require to approve and maintain any funding arrangements to be granted by Complyfirst in relation to the Services, and to provide payment history information to such agencies.
12. **CONFIDENTIALITY**
   1. Neither party will use the other’s Confidential Information except as permitted under the Agreement. Each party agrees to maintain in confidence and protect the other party’s Confidential Information using at least the same degree of care as it uses for its information of a confidential and proprietary nature but in any event at least a reasonable degree of care. Each party agrees to take all reasonable precautions to prevent any unauthorised disclosure of the other party’s Confidential Information, including, without limitation, disclosing such Confidential Information strictly only to those of its employees, representatives, consultants, contractors or agents (together **Representatives**) who need to know such information, are subject to restrictions around the use of such Confidential Information substantially similar to those set out in this clause. Each party shall be liable and responsible for its Representatives adherence to such terms. The preceding obligations will not restrict either party from disclosing Confidential Information of the other party under the order or requirement of a court, administrative agency, or other governmental body, provided that the party required to make such a disclosure gives reasonable notice to the other party to enable such party to contest such order or requirement (to the extent permitted by law).
   2. For the avoidance of doubt, Complyfirst considers Customer Data not publicly disclosed by Customer to be Customer’s Confidential Information and will protect and keep confidential such Confidential Information per (this) clause 12. Complyfirst may access and use such Confidential Information under the following circumstances (a) with Customer’s consent and knowledge, for support reasons; (b) if it have reason to believe such Confidential Information violates the law or of the Agreement (including in respect of a specific Authorised User’s usage), in which case it reserves the right to access, review, and remove them; (c) where it is compelled by law to disclose Customer’s Confidential Information; or (d) when access is required for operational or security reasons, including when access is required to maintain ongoing confidentiality, integrity, availability and resilience of Complyfirst’s Subscription Services (in which case access will be limited to specifically authorised personnel and only exercised to the extent necessary to facilitate such purposes).
   3. Customer is responsible for managing access to its account and Customer Data stored thereon, including invitations, administrative control, and access. Complyfirst is not responsible for the actions of any of Customer’s Authorised Users in this regard. Nor is Complyfirst responsible for any third party’s or Authorised User’s adherence to any terms imposed by Customer as a pre-requisite for access to its Customer Data. During the Term Customer can, via the Subscription Services, access (either manually or via API) and control (including delete) Customer Data.
   4. In accessing the Subscription Services, Customer and its Authorised Users may also gain access to information relating to Beta Services which Complyfirst considers being Confidential Information, and Customer agrees on behalf of itself and its Authorised Users to protect and keep strictly confidential such Confidential Information per this clause 12.
13. **NON-SOLICITION**
   1. During the Term and for 12 months thereafter, neither party, directly or indirectly, will solicit for employment or for engagement as an independent contractor, or encourage leaving its employment or engagement, any employee or independent contractor of the other party known to the soliciting party solely through the Agreement. For the avoidance of doubt, general public advertisements for employment or engagement and any individual’s response thereto will not be deemed a violation of this clause.
14. **INDEMNITY – CUSTOMER’S ATTENTION IS PARTICULARLY DRAWN TO THIS CLAUSE**
   1. Customer shall defend, indemnify and hold harmless Complyfirst against claims, actions, proceedings, losses, damages, expenses and costs (including without limitation court costs and reasonable legal fees) arising out of or in connection with its and/or the Authorised Users’ use of the Subscription Services including, without limitation, for any liability, damages, costs or claims incurred by Complyfirst due to Customer’s use of the Subscription Services for any purpose outside of the Purpose or any claim relating to Customer Data, including, without limitation, any claim brought by a third party alleging that Customer Data, or Customer’s use of the Subscription Services in breach of the Agreement infringes or misappropriates the intellectual property rights of a third party or violates applicable law, save to the extent directly attributable to Complyfirst’s breach of the Agreement.
   2. Complyfirst shall, subject to the other provisions of this clause 14 and the limitations in clause 15, defend Customer against any claim that the Subscription Services infringe any copyright, trade mark, patent or right of confidentiality and shall indemnify Customer for any amounts awarded by a court of competent jurisdiction against Customer in judgment or settlement of such claims, or agreed to by Complyfirst, provided that: (a) Complyfirst is given prompt notice of any such claim, together with all relevant details of the claim; (b) Customer provides reasonable co-operation to Complyfirst in the defence and settlement of such claim, at Complyfirst’s expense; and (c) Complyfirst is given sole authority to defend or settle the claim, and Customer does not compromise, settle or admit liability with respect to any claim without Complyfirst’s prior written consent (not to be unreasonably withheld).
   3. In the defence or settlement of any claim, Complyfirst may procure the right for Customer to continue using the Subscription Services, replace or modify the Subscription Services so that they become non-infringing or, if such remedies are not reasonably available, terminate the Agreement without any additional liability or obligation to pay liquidated damages or other additional costs to the Customer.
   4. In no event shall Complyfirst, its employees, agents and sub-contractors be liable to Customer to the extent that the alleged infringement is based on: (a) a modification of the Software or Subscription Services by anyone other than Complyfirst or Complyfirst’s authorised contractors or agents or (b) Customer’s use of the Services in a manner contrary to the instructions given to Customer by Complyfirst or Complyfirst’s authorised contractors or agents; (c) Customer’s use of the Subscription Services after notice of the alleged or actual infringement from Complyfirst or any appropriate authority; or (d) any element of the Software (or the Customer Data’s integration with same) not attributable to the Complyfirst (for example, Customer databases, or bespoke upgrades to the Software undertaken at the Customer’s direction incorporating content provided by the Customer).
   5. The foregoing provisions of clause 14 state Customer’s sole and exclusive rights and remedies, and Complyfirst’s (including Complyfirst’s employees’, agents’ and sub-contractors’) entire obligations and liability, for infringement of any patent, copyright, trade mark, database right or right of confidentiality.
15. **LIMITATION OF LIABILITY – CUSTOMER’S ATTENTION IS PARTICULARLY DRAWN TO THIS CLAUSE**
   1. This clause 15 sets out the entire financial liability of Complyfirst (including any liability for the acts or omissions of its employees, agents and sub-contractors) to the other in respect of: (a) any breach of the Agreement (including without limitation, any claim under clause 14.1 or clause 14.3); (b) any use made by Customer of the Software, Support or any part of them; and (c) any representation, statement or tortious act or omission (including negligence) arising under or in connection with this Agreement.
   2. Except as expressly and specifically provided in the Agreement: (a) all warranties, representations, conditions and all other terms of any kind whatsoever implied by statute or common law are, to the fullest extent permitted by applicable law, excluded from the Agreement, including without limitation any warranty of merchantability, fitness for a particular purpose, title, security, accuracy and non-infringement; (b) the Services and all other services provided, procured and/or sub-contracted by Complyfirst under the Agreement, are provided to Customer on an “as is” and “as available” basis; and (c) Customer assumes sole responsibility for the use of the Services and their associated documentation by Customer and Authorised Users, and for conclusions drawn from such use, including any decisions made as a result of the Customer’s use of the Subscription Services or any reliance placed thereon. Complyfirst shall have no liability for any damage caused by errors or omissions in any information, instructions or data provided to Complyfirst by Customer in connection with the Services, or any actions taken by Complyfirst at Customer’s direction.
   3. Complyfirst does not warrant that the Subscription Services will meet Customer’s requirements; that the Subscription Services will be uninterrupted, timely, secure, or error-free; that the information provided through the Subscription Services is accurate, reliable or correct; that any defects or errors will be corrected; that the Subscription Services will be available at any particular time or location (and in particular, Customer should note that the Subscription Services will only permit regulatory reporting during timeframes approved by the FCA or other relevant regulatory authority from time to time); or that the Subscription Services is free of viruses or other harmful components. Complyfirst will not be responsible for any risk of loss resulting from Customer’s downloading or using files, information, Data or other material obtained from the Subscription Service.
   4. Complyfirst may, from time to time at its discretion, generally upgrade and improve the Subscription Services as it sees fit, and Customer acknowledges that such upgrades and improvements may affect its use of the Subscription Services.
   5. Nothing in the Agreement excludes the liability of either party: (a) for death or personal injury caused by such party’s negligence; or (b) for fraud or fraudulent misrepresentation or (c) any other liability which cannot strictly be excluded or limited by relevant law.
   6. Subject to the foregoing: a) Complyfirst shall not be liable whether in tort (including for negligence or breach of statutory duty), contract, misrepresentation, restitution or otherwise for any loss of profits, loss of business, depletion of goodwill and/or similar losses or loss or corruption of data or information, or pure economic loss, or for any special, indirect or consequential loss, costs, damages, charges or expenses however arising under the Agreement; and (b) Complyfirst’s total aggregate liability in contract, tort (including negligence or breach of statutory duty), misrepresentation, restitution or otherwise, arising in connection with the performance or contemplated performance of the Agreement shall be limited to an amount equal the annual Subscription Charges paid for the 12 month period in which the claim arose.
   7. Customer acknowledges and accepts that Complyfirst does not and cannot warrant or represent that the Services are compliant with all regulatory or legal requirements to which Customer may be subject, or which may be relevant to the purposes for the Services may be used, subject to any terms of the Proposal and that Complyfirst only provides a digital tool to assisting the Customer’s in fulfilling its own regulatory reporting obligations, but cannot assume responsibility for final compliance. Customer acknowledges that the preparation and submission of accurate and timely reports to the FCA or other applicable regulatory body is its responsibility. Customer acknowledges and agrees that Complyfirst shall not be responsible or liable to Customer in any way (including in relation to damages or regulatory fines or penalties arising from use of the Subscription Services) regarding Customer’s regulatory compliance obligations and that results and outcomes cannot be in any guaranteed. In particular, Complyfirst cannot be held responsible or liable for ensuring that all relevant measures or referenced through or via the Subscription Services to facilitate regulatory reporting are undertaken or followed and Comply first is not responsible for human error and negligent or fraudulent data entry or provision in relation to compliance with or adherence to such measures. It is the sole responsibility of the Customer to monitor and audit its Authorised Users’ use of the Subscription Services and to ensure that the relevant measures are adhered to, and its regulatory obligations satisfied. Additionally, Customer acknowledges that use and interpretation of the Subscription Services requires specialist skill and knowledge, and that the Customer has that skill and knowledge and undertake that it and its Authorised Users will exercise same, and appropriate judgment, when using the Subscription Services.
   8. Complyfirst incorporates artificial intelligence functionality into its Subscription Services, which utilise third party large-scale language models (LLM) or other generative or similar / related AI functionality (**Generative AI**) to deliver certain content from interrogating third party sources or perform certain functions, including, for example, analysing text information, performing calculations, summarising call transcripts, interrogating third party legislative sources, and so on. Such Generative AI is a tool to facilitate inform and support the Customer’s internal or external compliance team(s) exercise their own professional expertise, judgment and responsibilities to advise Customer, but selecting appropriate sources and interrogating any content output, or calculations generated, from or by Generative AI requires specialist skill and expertise. Insofar as Generative AI produces content, such content is necessarily general in nature, may not reflect all recent legal developments and may not apply to the specific facts and circumstances of Customer’s regulated activities. Complyfirst is not a law firm, does not represent or advise Customer, and is not bound by the professional responsibilities and duties of a legal practitioner or similar. Nothing in the content or in the Agreement, nor any receipt or use of same, shall be construed or relied on by Customer, or Authorised Users or any third parties to whom Customer may distribute such content as creating any attorney-client relationship or providing any legal service, representation, advice or opinion whatsoever on behalf of Complyfirst. Generative AI may utilise general “Open Models” trained on all text or other data sources available on the internet accessed by the relevant Generative AI, or, at Customer’s option, “Closed Models” which only interrogate data sets from particular sources (in addition to Open Model functionality), typically to generate responses to Customer’s or its Authorised User’s requests or queries (Open Model and Closed Model Generative AI are together defined as AI below). Whilst Complyfirst (and the AI providers whose functionality Complyfirst utilises) will treat any responses generated by the AI featured in the Subscription Services as proprietary to the Customer (and part of the Customer Data), given the nature of machine learning, and the fact that AI uses all sources available on the Internet as a training set, outputs may not be unique across users and the Subscription Services may generate the same or similar output for Customer or any other third party using AI, in particular given the publicly available nature of the information that is published from the sources that Customer is likely to select when using the Subscription Services. Responses that are requested by and generated are not considered unique or proprietary to the Customer (or their Authorised User). Complyfirst cannot guarantee the uniqueness of any responses or content generated by any AI tool or their accuracy, completeness, lawfulness or appropriateness.
16. **FREE SERVICES AND BETA SERVICES**
   1. Customer acknowledges that all Free Services (including in this section any Beta Services (i.e., preview or early access Services)) may be subject to change at any time without notice. Customer uses Free Services entirely at its own risk. Complyfirst gives no warranties whatsoever, and to the extent permitted by law, accept no liabilities whatsoever regarding the Free Services and their use by Customer or any Authorised Users.
   2. Access to the Free Services and Beta Services (which have not been paid for) is permitted temporarily, and Complyfirst may suspend, withdraw, discontinue or change all or any part of the Free Services, either generally or to Customer specifically, at any time, for any reason, with or without notice. Complyfirst will not be liable to Customer if, for any reason, the Free Services are unavailable at any time or for any period.
   3. Customer acknowledges and agrees that access and use of any applicable Free Services or Beta Services Complyfirst offers constitutes reasonable and sufficient consideration. In return for that access, Customer is willing to adhere to the terms of the Agreement.
   4. As a Beta Services user, Customer may get access to information that isn’t yet publicly available about new products and features that Complyfirst plans to offer. Given the nature of this information, it is important that Customer keeps it confidential. Customer agrees that any Beta Service information that isn’t yet in the public domain, for example, information about a preview for a new Beta Service, is Complyfirst’s Confidential Information, whether or not expressly labelled as such. Customer agrees only to use such Confidential Information to test and evaluate the Beta Service (the **Purpose**), not for any other purpose. Customer also agrees not to disclose, publish, or share any Confidential Information with or to any third party unless it has set up the Beta Service in such a way that expressly encourages this (for example, where Customer is part of a forum Complyfirst has organised to trial or discuss a new Beta Service).
   5. Complyfirst’s Confidential Information relating to Beta Services does not include information that is: (a) (or becomes) publicly available without breach of the Agreement through no act or inaction on Customer’s part (for example, where a previously private Beta Service is rolled out as a regular Service by us); (b) independently developed by Customer without breach of any confidentiality obligation to Complyfirst or any third party; or (c) disclosed with Customer’s express written permission from Complyfirst. If Customer is required to disclose Confidential Information according to any order by a court or regulatory authority with jurisdiction over Complyfirst, it may do so provided that Complyfirst has been given reasonable advance written notice to object (unless prohibited by law) and the disclosure is limited to the maximum extent possible to comply with such an order of law.
17. **TERM AND TERMINATION**
   1. This Agreement shall commence on the Commencement Date, or the date the Proposal is agreed or signed by both parties, whichever is earlier, and shall (unless terminated earlier in accordance with these terms) continue in full force and effect until the end of the Subscription Term.
   2. Without prejudice to any other rights or remedies to which the parties may be entitled, either party may terminate the Agreement without liability to the other if: (a) the other party commits a material breach of any of the terms of the Agreement and (if such a breach is remediable) fails to remedy that breach within 30 days of that party being notified in writing of the breach; or (b) an order is made or a resolution is passed for the winding up of the other party or if an order is made for the appointment of an administrator to manage the affairs, business and property of the other party, or if such an administrator is appointed or if documents are filed with the court for the appointment of an administrator or if notice of intention to appoint an administrator is given by the other party or its directors or by a qualifying charge holder, or if a receiver is appointed of any of the other party’s assets or undertaking or if circumstances arise which entitle the court or a creditor to appoint a receiver or manager or which entitle the court to make a winding-up order or if the other party takes or suffers any similar or analogous action in consequence of debt; (c) the other party ceases, or threatens to cease, to trade. Complyfirst may also terminate the Agreement for cause on thirty (30) days’ notice if Complyfirst determines that Customer is acting, or has acted, in a way that has or may negatively reflect on or affect Complyfirst, Complyfirst’s prospects, or Complyfirst’s customers, or the Customer undergoes a change in control (as defined in section 1124 of the Corporation Tax Act 2010) which means that it is acquired by a Complyfirst competitor. The Agreement may not otherwise be terminated prior to the end of the Subscription Term.
   3. Complyfirst may suspend any Authorised User’s access to any or all Subscription Services without notice for: (i) use of the Subscription Services in a way that violates applicable laws or regulations or the terms of the Agreement, (ii) posting or uploading material that infringes or is alleged to infringe on the intellectual property rights of any person or relevant law, or (iii) to protect the integrity, operability, and security of the Subscription Services. Complyfirst may, without notice, review, edit and delete any Customer Data that Complyfirst has reason to determine in good faith violates the Agreement, provided that the parties acknowledge and agree that Complyfirst has no duty to, and shall not, pre-screen, control, monitor or edit Customer Data. Complyfirst will, in its discretion and using good faith, tailor any suspension as needed to preserve the integrity, operability, and security of the Subscription Services, and endeavour to give notice as soon as reasonably possible either before or after such suspension.
   4. The Subscription Term shall automatically renew over each Renewal Period unless and until either party gives notice to the other in writing (including by email) that it does not wish the Agreement to continue beyond the Initial Subscription Term or the then current Renewal Period, such notice to expire no later than 30 days prior to the end of the Initial Subscription Term or then current Renewal Period.
   5. On expiry or termination of the Agreement for any reason: (a) all licences granted under the Agreement shall immediately terminate, even if no expiration date is specified in the Proposal provided by Complyfirst; (b) each party shall return and make no further use of any Confidential Information belonging to the other party; and (c) the accrued rights of the parties as at expiry or termination, or the continuation after expiry or termination of any provision expressly stated to survive (including, without limitation, clauses 1, 2, 9, 10, 11, 12, 13, 14.1, 15, 17.5, 17.6 and 18) or implicitly surviving termination, shall not be affected or prejudiced; (d) subject to payment of a fee where applicable, Complyfirst will make reasonable efforts to provide Customer with a copy of its lawful, non-infringing Customer Data held in its or its Authorised Users’ accounts upon request, provided that Customer makes this request within 90 days of termination. Otherwise, Complyfirst will retain and use Customer Data as necessary to comply with its legal obligations, resolve disputes, and enforce Complyfirst’s agreements (and as further set out in Complyfirst’s Privacy Policy), but barring legal requirements, Complyfirst will delete all Customer Data within its control within the periods specified and subject to any limitations set out within the Complyfirst’s Privacy Policy. Complyfirst does not guarantee that any Customer Data can be recovered once this Agreement is terminated and any Authorised User Accounts closed; and (e) save where Customer validly and lawfully terminates in accordance with clause 17.2(a), Complyfirst may invoice the Customer for any unbilled proportion of the Subscription Charges for the remainder of any then current Initial Subscription Term or Renewal Period, together, with, by way of liquidated damages, a reasonable fee in respect of any management time incurred by Complyfirst in pursuit of recovery of sums due on foot of any unpaid invoice(s). Customer agrees to indemnify and hold harmless Complyfirst, on a full indemnity basis, from and against any and all legal and other professional costs (including lawyers’ fees, debt recovery agent fees and other third party fees) associated with recovery of such outstanding sums. The liquidated damages payable under this clause shall accrue from the first event of non-payment and shall continue until payment in full of any outstanding debts by Customer. This clause is without prejudice to the right of Complyfirst to claim general damages, but subject to customary common law prohibitions on double-recovery of the same losses. The parties confirm that these liquidated damages are reasonable and proportionate to protect Complyfirst’s legitimate interest in performance.
   6. Where Customer validly and lawfully terminates in accordance with clause 17.2(a) Complyfirst shall within 20 Business Days reimburse to Customer the Unused Portion of any Subscription Charges paid by Customer that pertains to the cost of licensing the Subscription Services (but excluding any non-refundable deposit as set out in the Proposal, or amounts relating to any Implementation Services).
18. **GENERAL**
   1. Complyfirst shall have no liability to Customer under the Agreement if it is prevented from or delayed in performing its obligations under the Agreement, or from carrying on its business, by acts, events, omissions or accidents beyond its reasonable control, including, without limitation, strikes, lock-outs or other industrial disputes (whether involving the workforce of Complyfirst or any other party), failure of a utility service or transport or telecommunications network, act of God, war, riot, civil commotion, malicious damage, compliance with any law or governmental order, rule, regulation or direction, accident, breakdown of plant or machinery, fire, flood, storm or default of suppliers or sub-contractors, provided that Customer is notified of such an event and its expected duration. Complyfirst shall not be responsible for the failure of any third party systems or platforms with which the Subscription Services interact.
   2. A waiver of any right under the Agreement is only effective if it is in writing and it applies only to the party to whom the waiver is addressed and to the circumstances for which it is given.
   3. Unless specifically provided otherwise, rights arising under the Agreement are cumulative and do not exclude rights provided by law.
   4. If any provision (or part of a provision) of the Agreement is found by any court or administrative body of competent jurisdiction to be invalid, unenforceable or illegal, the other provisions shall remain in force. If any invalid, unenforceable or illegal provision would be valid, enforceable or legal if some part of it were deleted, the provision shall apply with whatever modification is necessary to give effect to the commercial intention of the parties.
   5. The Agreement, and any documents referred to in it, constitute the whole agreement between the parties and supersede any previous arrangement, understanding or agreement between them relating to their subject matter. Complyfirst’s obligations are not contingent on the delivery of any future functionality or features of the Subscription Services or dependent on any oral or written public comments made by Complyfirst regarding the Subscription Services’ future functionality or features.
   6. Customer hereby authorises Complyfirst to reference and/or include Customer’s name or logo as part of Complyfirst’s marketing and advertising efforts without further review or advance approval, including to: (i) list Customer as a Complyfirst customer on social media sites, including Twitter, LinkedIn, Facebook, Complyfirst’s website, blog, or any other social media site; (ii) list Customer in Complyfirst marketing materials including corporate marketing collateral, website, social media sites, and other advertising campaigns. Complyfirst shall comply with any brand guidelines shared by Customer in the use of Customer’s name and logo in accordance with this clause, and shall not use Customer’s name or logo in such a way as to imply that Customer endorses Complyfirst or its products or services (other than to the extent they are noted as a Complyfirst customer).
   7. Customer shall not, without the prior written consent of Complyfirst (such consent not to be unreasonably withheld), assign, transfer, charge, sub-contract or deal in any other manner with all or any of its rights or obligations under the Agreement. Complyfirst shall be free to assign, transfer, charge, sub-contract or deal in any other manner with all or any of its rights or obligations under the Agreement without the consent of Customer but providing notice of any assignment or transfer. Complyfirst may also appoint a suitably qualified sub-contractor to perform or provide certain Services on its behalf. Customer will continue to be liable to pay Complyfirst any fees due under the Agreement and shall not be liable directly for any of the subcontractor’s fees or expenses. Complyfirst shall remain responsible for the performance by its sub-contractor of any sub-contracted Services and shall not sub-contract the Subscription Services in their entirety.
   8. Nothing in the Agreement is intended to or shall operate to create a partnership between the parties, or authorise either party to act as agent for the other, and neither party shall have the authority to act in the name or on behalf of or otherwise to bind the other in any way (including, but not limited to, the making of any representation or warranty, the assumption of any obligation or liability and the exercise of any right or power).
   9. Notwithstanding any other provisions of the Agreement, nothing in the Agreement confers or purports to confer any right to enforce any of its terms on any person who is not a party to it.
   10. Any notice required or permitted to be given under the Agreement shall be in writing and shall be delivered or transmitted to the intended recipient’s address as specified in the Agreement or such other address as either party may notify in writing to the other from time to time for this purpose. It may also, in the case of notice by Complyfirst only, be generally notified to Customers via their account, or notified by way of email to the email address Complyfirst has on account for a given Customer. Any notice shall be treated as having been served on delivery if delivered by hand, 4 Business Days after posting if sent by pre-paid first class post. In the case of notice served by posting on the Customer’s account or by email, the notice shall be deemed given at the time such upload goes live onto the website or at the time of transmission of the email (respectively).
   11. The construction, validity and performance of the Agreement shall be governed by the laws of England, and the parties submit any dispute regarding the construction, validity performance of the Agreement, or its subject matter, or any non-contractual disputes, to the exclusive jurisdiction of the courts of England.
   12. The Proposal may be executed in any number of counterparts, each of which will be considered an original, but all of which together will constitute the same agreement. The exchange of a fully executed valid Proposal (in counterparts or otherwise) by facsimile or electronic transmission, or its signature via DocuSign or other EIDAS compliant signature platform, or the Customer’s confirmation by email of its agreement to the terms of a valid Proposal, shall be sufficient to bind the parties to the terms and conditions of the Agreement.
   13. All Professional Services and Support, the Agreement and any correspondence between the parties regarding the Agreement’s subject matter shall be exclusively in the English language.
   14. Complyfirst might make versions of the Agreement available in languages other than English. If Complyfirst does, the English version of the Agreement will govern Complyfirst’s relationship. The translated version is provided for convenience only and will not be interpreted to modify the English version of this Agreement.
   15. Unless otherwise stated in these General Terms, no amendment or variation of the Agreement shall be effective unless it is in writing and signed by the parties (or their authorised representatives). The above notwithstanding, Complyfirst may, acting in its sole discretion, amend these General Terms from time to time and will endeavour to provide Customer with thirty (30) days’ notice before making the change effective when it does so. If Customer objects to any change the change shall not take effect (in relation to that Customer only) until the expiry of the then current Initial Subscription Term or Renewal Period (prior to which the Customer will have had an option under clause 9.10 to elect not to renew the Agreement into such subsequent term), and the version of the General Terms applicable to Customer until that point shall be the version applicable immediately prior to the latest update. Every time Complyfirst enters into a new Proposal with any Customer, the terms applying to the Agreement between the Parties shall be as outlined in the relevant version of these General Terms in force at the time of the signing of the relevant Proposal.

---
Source: https://complyfirst.co/terms-and-conditions

---

# Terms of Use

## Terms of Use

Thank you for visiting the Complyfirst site. Your use of it is subject to this notice, and any other terms and conditions that may be presented to you. If you do not agree to be bound by this notice, you should stop using our site immediately. 

Additional terms and conditions will apply if you register as a user of our platform. Those terms will be made available to you before you create an account with us.

We endeavour to keep the content of this site up-to-date, but don't guarantee that it is. The content on this site (including these terms) may be removed, changed or updated without notice. 

All content on our site belongs to FDJ Ecommerce Ltd, trading as Complyfirst, or is reproduced with permission from other copyright owners. All rights are reserved. By continuing to use the site you acknowledge that all available content is protected by copyright, trade marks, database rights and other intellectual property rights. Nothing shall be construed as granting, by implication or otherwise, any license or right to use any content or trade mark displayed on the site without our prior written permission. 

Unless you register as a user of our platform, your permissions in relation to the site are limited to viewing the site and its content for your own personal non-commercial use only. 

You must not reproduce, modify, copy, distribute or use for commercial purposes any content from our site or our services without our prior written permission. You must not screen-scrape or attempt to reverse engineer any of the appearance or functionality of the site or any of our services. You must not use any information obtained from our site or any of our services to send unsolicited marketing or other correspondence to any person. 

We may restrict your access to our site and any of our services, or take any other action we deem appropriate, for any abuse of these terms or our site at our sole discretion. 

All information on our site is provided as is, with no warranty as to its accuracy or fitness for any particular purpose, and with no assurances that the site or the server that hosts it are free from viruses or other forms of harmful computer code. You are responsible for ensuring that your use of the site and the services that we make available from it are suitable for your purposes.

We make reasonable efforts to ensure the security of our site. We are not liable for any losses resulting from the use of the site. Liability for personal injury or death caused by negligence or for fraud is not excluded or limited. 

Links to other sites are provided in good faith. We are not responsible for the materials contained in any linked sites. 

Our privacy notice explains how we handle any personal data you provide to us. 

If you have any questions about this site, please contact us at hello@complyfirst.co

---
Source: https://complyfirst.co/terms-of-use

---

# Thank You

## You’re in! 🎉

Thanks for registering for our event. Check your inbox for confirmation details.



See you soon!

---
Source: https://complyfirst.co/thank-you-event

---

# Complyfirst Use Cases

> Get started with Complyfirst's pre-built compliance automation workflows, fully customisable to your processes and policies.

# Ready-to-implement reporting _workflows_



Deploy a pre-built workflow, customised to how your team already works.



```json
{
  "_key": "3c0f78e05797",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/demo",
      "label": "Get started",
      "variant": "contained"
    }
  ]
}
```

### <strong>CFOs</strong> can

File regulatory returns

### <strong>MLROs</strong> can

Create and submit SARs

### <strong>Auditors</strong> can

Perform audit reviews

### <strong>Compliance Teams</strong> can

Create fraud reports

### <strong>We</strong> can

Build your workflow

## Get started right away.  
No integration necessary.



Your data can live anywhere. Excel spreadsheets, PDFs, chat logs, Amazon feeds, APIs and we can work with it. You don’t need engineering resources to get started. Just upload a file and you’re off.



```json
{
  "_key": "ae91f51ea538",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "/demo",
      "label": "Get started",
      "variant": "contained"
    }
  ]
}
```

#

---
Source: https://complyfirst.co/use-cases

---

# Regulatory Reporting Software for Multi-Licensed Firms

> Submit regulatory returns faster with software built for multi-licensed firms. Automatic validation, approvals, and audit trails, built in for every return.

```json
{
  "_key": "763f4645df74",
  "_type": "chips-block",
  "alignment": "left",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "REGULATORY REPORTING"
    }
  ]
}
```

# Submit regulatory returns faster.



Collect, validate, and generate regulator-ready reports automatically, with approvals, audit trails, and regulator-ready exports built in.



```json
{
  "_key": "fdafa1951d28",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "https://complyfirst.co/demo",
      "label": "Get your demo",
      "variant": "contained"
    }
  ]
}
```

```json
{
  "_key": "6ac1c4c3245f",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "https://complyfirst.co/reports",
      "label": "See all reports",
      "variant": "contained"
    }
  ]
}
```

```json
{
  "_key": "e98913007700",
  "_type": "chips-block",
  "alignment": "center",
  "chips": [
    {
      "chipColor": "chip primary light",
      "label": "HOW IT WORKS"
    }
  ]
}
```

## From data mapping to submission, we're the _home_ of regulatory reporting

#### Upload your data.

Use your own files or a regulator’s template. No reformatting is required.

- Excel, CSV, PDF, and more
- Works with existing internal data
- No engineering setup needed

#### Get built-in regulator guidance.

Get built-in regulator guidance directly in the cell you’re working in, aligned to the relevant reporting requirements.

- Regulator-specific definitions and instructions
- Fewer interpretation errors
- Confidence in how each field should be completed

#### Validate your data as you work.

Catch errors early with automated validation and clear guidance on how to fix them.

- Real-time validation directly in the cell you’re working in
- Clear “what’s wrong” and “how to fix it” feedback

## Get 1:1 support   
_even on deadline day_



DM us on Slack or Teams and get a response in <1hour (yes, even on deadline day).



```json
{
  "_key": "84a35d2b40b5",
  "_type": "buttons-block",
  "alignment": "left",
  "buttons": [
    {
      "href": "/demo",
      "label": "Get in touch",
      "variant": "contained"
    }
  ]
}
```

## Don't just take our word for it...

```json
{
  "_key": "25e11ee779f2",
  "_type": "image",
  "alt": "Sumup Logo",
  "asset": {
    "_id": "image-aa4f4898a13092cd6622658a5c3f7d1d945f3e77-180x72-svg",
    "metadata": {
      "dimensions": {
        "height": 72,
        "width": 180
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAAsTAAALEwEAmpwYAAABrklEQVR4nKVSy24UMRA0j+UtZTNjt3f2MeNub0CbSEFiEXCBiBMIorBrT3uCRHhEaDlxgUsQh3wDQXAGwS0n+AfELcA3hBt8BPJMxAeApZKqW3bZ1WUB6JelDRc65C9GRK6Glc2y1VPiXxbY8E4TfwTiN0C809TVVhQVgo+I4c3jYjxr1VysHBXFgxM1Iq97s5ZY5GNNPWsJIN4H4j1A3tHEbzWFH0BhVxt/WebTbH7gl1LD59rGFZA7io7aZnp+Lmec794ZSJyc7eS8qIvKpIP1bhT8pYm/APIzoHJbU/UdLH/WNlyHIlyR6DcV8UOFXErjKmV4IzW8odD5tAiTyDXypia+HS8TYPm3pvANkF8Chuea+Ksm/iSNu5blPFZUPpJYPlamvC+pXE8Nr0n0qwqDj2IphSfKlE8luVvJcNqPL/zZ2OTXje2wB5Z3NfKlTodVUlSjZKEaJcVkpCwPkz730sFady531O755Tb6q8q4G5LcQj1LIH5fw4ZXMRhN4YPG8CIergcdN8VQ6sGPD8I5CKjPJ89kd2XSm/aFvne6Sfn/vs2hv0mL7cOx8wd6Q22l7qKvgAAAAABJRU5ErkJggg=="
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/aa4f4898a13092cd6622658a5c3f7d1d945f3e77-180x72.svg"
  }
}
```

```json
{
  "_key": "a16a8b0bdcd8",
  "_type": "resource-quote",
  "author": {
    "name": "Adrian Witkowski",
    "position": "Head of Regulatory Reporting"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "1c4c69eb62f0",
      "_type": "block",
      "children": [
        {
          "_key": "defe563c92c5",
          "_type": "span",
          "text": "\"What used to take weeks was fixed in hours with Complyfirst. "
        },
        {
          "_key": "7e4b2788d8ed",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "We were live, errors resolved, and submitted within 48 hours.\""
        }
      ],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "34bac28dbd87",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "445ae41843c1",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-a052788b17939403f7491943ac867c5ae092c5ad-150x150-svg",
          "metadata": {
            "dimensions": {
              "height": 150,
              "width": 150
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAACZUlEQVR4nL2Uy27aUBCGD9A0EU1owi2BkISkDlVZNGotKBCbI25tFtnyCn2NswCMjW0oSje8Ql4i2y5QK1U0JAZjcyuqWvUVXA2EVSsuQupIliV8/PHP/88Yof9ZBBnmLDIsCBmmlUA1ur5WDf+ySfTQWWC+uwj+sk2CjccIoeXABjJMhB5axUTnqMSoL/m49oKL9KhSQnmWZ289JPzJRvDNo6WU8WHFJyfVMM+qYSHePs2zuqeEtT2R1Y/hqjKKq3Y5tGaz15a5QHI5tBbfaH4A8efqYQWP/GL025GYGbkLjOISYk1vmemeQAdF5usOwcZstWJm9ARAJNp2E7puraV/P+Wx4oOW4S7hO2eB+ewq4qYffhNiza2Fge/p+hpBxEywtnGVGjgqWPNDy3KkZwe1AORCtw6YhPnAkLZHcGMTYODVddawCLGfWzzu+/jz4aEYbbvH5zJtN/g+F5hjWwfQFodb1IekulvB2nb1QrEBSMY9qszqHjhTSKq7D+P074L0JLZ1kIMgGCUoYZUR42pIimuvKonOc1AIgQmxrnchYPVCWYd/B3UV3PQLbOs19wCUcYu6Sne9SwEJMswk0rBzuEHJyft9UMtFWlSe1j1gB4SzFBCK4JsNGJEyc38i0XfOj/jH5uQlwwRejmcU9305Vj8GYG1WKNP1GwcwGZF9sGH6jEsNHHKicyYm9SCXUgMwl2TW2EwL9hUOQ6LgW5Hp7oA62BwpocfkRP8s/073wFihRWsaEKQrpQYBId0/lVJqAJSDUpKd2IAWr3Hr67Cz8tueHVSCFVM/lwD9DV75A7tK/QH9iUyLZy0qFwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/a052788b17939403f7491943ac867c5ae092c5ad-150x150.svg"
        }
      },
      "text": [
        {
          "_key": "42651f273227",
          "_type": "block",
          "children": [
            {
              "_key": "2c0a69f5e343",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "90%"
            },
            {
              "_key": "8bc058ad3c7a",
              "_type": "span",
              "text": " less reporting effort"
            }
          ],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "3769751e162c",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-a052788b17939403f7491943ac867c5ae092c5ad-150x150-svg",
          "metadata": {
            "dimensions": {
              "height": 150,
              "width": 150
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAACZUlEQVR4nL2Uy27aUBCGD9A0EU1owi2BkISkDlVZNGotKBCbI25tFtnyCn2NswCMjW0oSje8Ql4i2y5QK1U0JAZjcyuqWvUVXA2EVSsuQupIliV8/PHP/88Yof9ZBBnmLDIsCBmmlUA1ur5WDf+ySfTQWWC+uwj+sk2CjccIoeXABjJMhB5axUTnqMSoL/m49oKL9KhSQnmWZ289JPzJRvDNo6WU8WHFJyfVMM+qYSHePs2zuqeEtT2R1Y/hqjKKq3Y5tGaz15a5QHI5tBbfaH4A8efqYQWP/GL025GYGbkLjOISYk1vmemeQAdF5usOwcZstWJm9ARAJNp2E7puraV/P+Wx4oOW4S7hO2eB+ewq4qYffhNiza2Fge/p+hpBxEywtnGVGjgqWPNDy3KkZwe1AORCtw6YhPnAkLZHcGMTYODVddawCLGfWzzu+/jz4aEYbbvH5zJtN/g+F5hjWwfQFodb1IekulvB2nb1QrEBSMY9qszqHjhTSKq7D+P074L0JLZ1kIMgGCUoYZUR42pIimuvKonOc1AIgQmxrnchYPVCWYd/B3UV3PQLbOs19wCUcYu6Sne9SwEJMswk0rBzuEHJyft9UMtFWlSe1j1gB4SzFBCK4JsNGJEyc38i0XfOj/jH5uQlwwRejmcU9305Vj8GYG1WKNP1GwcwGZF9sGH6jEsNHHKicyYm9SCXUgMwl2TW2EwL9hUOQ6LgW5Hp7oA62BwpocfkRP8s/073wFihRWsaEKQrpQYBId0/lVJqAJSDUpKd2IAWr3Hr67Cz8tueHVSCFVM/lwD9DV75A7tK/QH9iUyLZy0qFwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/a052788b17939403f7491943ac867c5ae092c5ad-150x150.svg"
        }
      },
      "text": [
        {
          "_key": "aa8e0253cec5",
          "_type": "block",
          "children": [
            {
              "_key": "ef95084d6d1d",
              "_type": "span",
              "text": "SumUp was onboarded, validated, and live on Complyfirst within "
            },
            {
              "_key": "fae3954ecfdf",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "48 hours."
            }
          ],
          "style": "normal"
        }
      ]
    }
  ]
}
```

```json
{
  "_key": "d7bcf38d356e",
  "_type": "image",
  "alt": "TrueLayer Logo",
  "asset": {
    "_id": "image-44014da9a57177091c902bed58a897126f321b97-180x72-svg",
    "metadata": {
      "dimensions": {
        "height": 72,
        "width": 180
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAAsTAAALEwEAmpwYAAABLklEQVR4nK1R22rCQBCdvgjGxJi9WFOCySYbk4bGilZrESu+CS02mziCl9I3H/r/H1A2pV9QBw4zzBzOzGEArh2co2ndFdQJ0YYMGwBw8y9BKvZT6u/XPNwveITS7r85dn50zMGB/S3SsP2PDs/QhDk2wcNm3ct/uT2J3B0cmAawCC88xC8qdice4caUmBm5Gnfiasn75YL1cULD6okInJlxcd8YFgMr2CYkLmZGqsZGhiN9EAtwdeuXa+Bi980D/OQCd0ziyo7L0MwwI1LNu76aU6GmJKietWArVQ/GSD3aKU6csFy0csytBBPtjolq2QvKV9DEboQvLFJjIpUH7rsBw3NLW6zt1/no6JrITVvbtNKCatBka2m+nrc9JJ6HBFz3YhB5atfDazzl2vEDKIE7YLedL4AAAAAASUVORK5CYII="
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/44014da9a57177091c902bed58a897126f321b97-180x72.svg"
  }
}
```

```json
{
  "_key": "6d4de0115c5d",
  "_type": "resource-quote",
  "author": {
    "name": "Pamela Crilly",
    "position": "EU COO"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "5104eee493d3",
      "_type": "block",
      "children": [
        {
          "_key": "b498d7ee2f88",
          "_type": "span",
          "text": "\"What sets Complyfirst apart is its ability to "
        },
        {
          "_key": "3a62cd5d49f6",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "simulate a regulator’s review"
        },
        {
          "_key": "0ef26982949b",
          "_type": "span",
          "text": ", identifying discrepancies before the actual submission.\""
        }
      ],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "6f1f0a6b4959",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "72b2498d1a81",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-a052788b17939403f7491943ac867c5ae092c5ad-150x150-svg",
          "metadata": {
            "dimensions": {
              "height": 150,
              "width": 150
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAACZUlEQVR4nL2Uy27aUBCGD9A0EU1owi2BkISkDlVZNGotKBCbI25tFtnyCn2NswCMjW0oSje8Ql4i2y5QK1U0JAZjcyuqWvUVXA2EVSsuQupIliV8/PHP/88Yof9ZBBnmLDIsCBmmlUA1ur5WDf+ySfTQWWC+uwj+sk2CjccIoeXABjJMhB5axUTnqMSoL/m49oKL9KhSQnmWZ289JPzJRvDNo6WU8WHFJyfVMM+qYSHePs2zuqeEtT2R1Y/hqjKKq3Y5tGaz15a5QHI5tBbfaH4A8efqYQWP/GL025GYGbkLjOISYk1vmemeQAdF5usOwcZstWJm9ARAJNp2E7puraV/P+Wx4oOW4S7hO2eB+ewq4qYffhNiza2Fge/p+hpBxEywtnGVGjgqWPNDy3KkZwe1AORCtw6YhPnAkLZHcGMTYODVddawCLGfWzzu+/jz4aEYbbvH5zJtN/g+F5hjWwfQFodb1IekulvB2nb1QrEBSMY9qszqHjhTSKq7D+P074L0JLZ1kIMgGCUoYZUR42pIimuvKonOc1AIgQmxrnchYPVCWYd/B3UV3PQLbOs19wCUcYu6Sne9SwEJMswk0rBzuEHJyft9UMtFWlSe1j1gB4SzFBCK4JsNGJEyc38i0XfOj/jH5uQlwwRejmcU9305Vj8GYG1WKNP1GwcwGZF9sGH6jEsNHHKicyYm9SCXUgMwl2TW2EwL9hUOQ6LgW5Hp7oA62BwpocfkRP8s/073wFihRWsaEKQrpQYBId0/lVJqAJSDUpKd2IAWr3Hr67Cz8tueHVSCFVM/lwD9DV75A7tK/QH9iUyLZy0qFwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/a052788b17939403f7491943ac867c5ae092c5ad-150x150.svg"
        }
      },
      "text": [
        {
          "_key": "e188ad52172b",
          "_type": "block",
          "children": [
            {
              "_key": "2da4a9bcbbb1",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "50%"
            },
            {
              "_key": "ccd390bd4f2e",
              "_type": "span",
              "text": " less reporting effort"
            }
          ],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "78128964b47a",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-a052788b17939403f7491943ac867c5ae092c5ad-150x150-svg",
          "metadata": {
            "dimensions": {
              "height": 150,
              "width": 150
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAACZUlEQVR4nL2Uy27aUBCGD9A0EU1owi2BkISkDlVZNGotKBCbI25tFtnyCn2NswCMjW0oSje8Ql4i2y5QK1U0JAZjcyuqWvUVXA2EVSsuQupIliV8/PHP/88Yof9ZBBnmLDIsCBmmlUA1ur5WDf+ySfTQWWC+uwj+sk2CjccIoeXABjJMhB5axUTnqMSoL/m49oKL9KhSQnmWZ289JPzJRvDNo6WU8WHFJyfVMM+qYSHePs2zuqeEtT2R1Y/hqjKKq3Y5tGaz15a5QHI5tBbfaH4A8efqYQWP/GL025GYGbkLjOISYk1vmemeQAdF5usOwcZstWJm9ARAJNp2E7puraV/P+Wx4oOW4S7hO2eB+ewq4qYffhNiza2Fge/p+hpBxEywtnGVGjgqWPNDy3KkZwe1AORCtw6YhPnAkLZHcGMTYODVddawCLGfWzzu+/jz4aEYbbvH5zJtN/g+F5hjWwfQFodb1IekulvB2nb1QrEBSMY9qszqHjhTSKq7D+P074L0JLZ1kIMgGCUoYZUR42pIimuvKonOc1AIgQmxrnchYPVCWYd/B3UV3PQLbOs19wCUcYu6Sne9SwEJMswk0rBzuEHJyft9UMtFWlSe1j1gB4SzFBCK4JsNGJEyc38i0XfOj/jH5uQlwwRejmcU9305Vj8GYG1WKNP1GwcwGZF9sGH6jEsNHHKicyYm9SCXUgMwl2TW2EwL9hUOQ6LgW5Hp7oA62BwpocfkRP8s/073wFihRWsaEKQrpQYBId0/lVJqAJSDUpKd2IAWr3Hr67Cz8tueHVSCFVM/lwD9DV75A7tK/QH9iUyLZy0qFwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/a052788b17939403f7491943ac867c5ae092c5ad-150x150.svg"
        }
      },
      "text": [
        {
          "_key": "c16c347bb2d6",
          "_type": "block",
          "children": [
            {
              "_key": "6d2403de71e7",
              "_type": "span",
              "text": "DORA was submitted within "
            },
            {
              "_key": "17315ab13e96",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "24 hours."
            }
          ],
          "style": "normal"
        }
      ]
    }
  ]
}
```

```json
{
  "_key": "016598cf0278",
  "_type": "image",
  "alt": "Decta Logo",
  "asset": {
    "_id": "image-e3aaf09403b85d61f1b5f2476a929595bee2bf77-158x34-svg",
    "metadata": {
      "dimensions": {
        "height": 34,
        "width": 158
      },
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAYAAACOXx+WAAAACXBIWXMAAAsTAAALEwEAmpwYAAABEUlEQVR4nDXNsUoDURCF4byBsPfO3GDh7sxESGGrIIoSNUiamOzemU0iiAoGG22CViqmMCgWKkQsFdT3lIgWp/y/U8EsHwaOn8hx6rPOZkK6gqIPWLMpiO36RdtALibA8Q4zbXvSY0/xA8ieE9auYx0A6ZMjG82lZVbBTIdAOka2K+R8kJDtANulY71wkjdQir3Aeh7EGpBqNfwe2ghYDx3rFoidodgLkI0D29I/eIus15DFA6C8QLJHz3rjFrpbyNr1f+B8veNAtIYU97GmTWBbm3Uo5StyOUHR1Qqmehq4/AKyt4R6TZ8WrcD6jaTvVS5aTqyBFO+RdQKs6y7t15302jOsSraMoifA/aPZkMvtH1mOSj/w4XWpAAAAAElFTkSuQmCC"
    },
    "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/e3aaf09403b85d61f1b5f2476a929595bee2bf77-158x34.svg"
  }
}
```

```json
{
  "_key": "b0c66f4ad570",
  "_type": "resource-quote",
  "author": {
    "name": "Neil McDermott",
    "position": "Chief Financial Officer"
  },
  "enableIllustrations": false,
  "text": [
    {
      "_key": "86d1faf0d212",
      "_type": "block",
      "children": [
        {
          "_key": "6de652d015dc",
          "_type": "span",
          "text": "\"I’ve worked at large banks with entire teams managing returns. "
        },
        {
          "_key": "cfcd43b1f40f",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "With Complyfirst, we had it done in days.\""
        }
      ],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "633d36386474",
  "_type": "icon-list-block",
  "items": [
    {
      "_key": "8f83a8fee273",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-a052788b17939403f7491943ac867c5ae092c5ad-150x150-svg",
          "metadata": {
            "dimensions": {
              "height": 150,
              "width": 150
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAACZUlEQVR4nL2Uy27aUBCGD9A0EU1owi2BkISkDlVZNGotKBCbI25tFtnyCn2NswCMjW0oSje8Ql4i2y5QK1U0JAZjcyuqWvUVXA2EVSsuQupIliV8/PHP/88Yof9ZBBnmLDIsCBmmlUA1ur5WDf+ySfTQWWC+uwj+sk2CjccIoeXABjJMhB5axUTnqMSoL/m49oKL9KhSQnmWZ289JPzJRvDNo6WU8WHFJyfVMM+qYSHePs2zuqeEtT2R1Y/hqjKKq3Y5tGaz15a5QHI5tBbfaH4A8efqYQWP/GL025GYGbkLjOISYk1vmemeQAdF5usOwcZstWJm9ARAJNp2E7puraV/P+Wx4oOW4S7hO2eB+ewq4qYffhNiza2Fge/p+hpBxEywtnGVGjgqWPNDy3KkZwe1AORCtw6YhPnAkLZHcGMTYODVddawCLGfWzzu+/jz4aEYbbvH5zJtN/g+F5hjWwfQFodb1IekulvB2nb1QrEBSMY9qszqHjhTSKq7D+P074L0JLZ1kIMgGCUoYZUR42pIimuvKonOc1AIgQmxrnchYPVCWYd/B3UV3PQLbOs19wCUcYu6Sne9SwEJMswk0rBzuEHJyft9UMtFWlSe1j1gB4SzFBCK4JsNGJEyc38i0XfOj/jH5uQlwwRejmcU9305Vj8GYG1WKNP1GwcwGZF9sGH6jEsNHHKicyYm9SCXUgMwl2TW2EwL9hUOQ6LgW5Hp7oA62BwpocfkRP8s/073wFihRWsaEKQrpQYBId0/lVJqAJSDUpKd2IAWr3Hr67Cz8tueHVSCFVM/lwD9DV75A7tK/QH9iUyLZy0qFwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/a052788b17939403f7491943ac867c5ae092c5ad-150x150.svg"
        }
      },
      "text": [
        {
          "_key": "8d5704028bf0",
          "_type": "block",
          "children": [
            {
              "_key": "d7f281838d2b",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "<24hr"
            },
            {
              "_key": "4bcbc068769f",
              "_type": "span",
              "text": " time to go live"
            }
          ],
          "style": "normal"
        }
      ]
    },
    {
      "_key": "670af1e50382",
      "icon": {
        "_type": "image",
        "alt": "tick icon",
        "asset": {
          "_id": "image-a052788b17939403f7491943ac867c5ae092c5ad-150x150-svg",
          "metadata": {
            "dimensions": {
              "height": 150,
              "width": 150
            },
            "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAACZUlEQVR4nL2Uy27aUBCGD9A0EU1owi2BkISkDlVZNGotKBCbI25tFtnyCn2NswCMjW0oSje8Ql4i2y5QK1U0JAZjcyuqWvUVXA2EVSsuQupIliV8/PHP/88Yof9ZBBnmLDIsCBmmlUA1ur5WDf+ySfTQWWC+uwj+sk2CjccIoeXABjJMhB5axUTnqMSoL/m49oKL9KhSQnmWZ289JPzJRvDNo6WU8WHFJyfVMM+qYSHePs2zuqeEtT2R1Y/hqjKKq3Y5tGaz15a5QHI5tBbfaH4A8efqYQWP/GL025GYGbkLjOISYk1vmemeQAdF5usOwcZstWJm9ARAJNp2E7puraV/P+Wx4oOW4S7hO2eB+ewq4qYffhNiza2Fge/p+hpBxEywtnGVGjgqWPNDy3KkZwe1AORCtw6YhPnAkLZHcGMTYODVddawCLGfWzzu+/jz4aEYbbvH5zJtN/g+F5hjWwfQFodb1IekulvB2nb1QrEBSMY9qszqHjhTSKq7D+P074L0JLZ1kIMgGCUoYZUR42pIimuvKonOc1AIgQmxrnchYPVCWYd/B3UV3PQLbOs19wCUcYu6Sne9SwEJMswk0rBzuEHJyft9UMtFWlSe1j1gB4SzFBCK4JsNGJEyc38i0XfOj/jH5uQlwwRejmcU9305Vj8GYG1WKNP1GwcwGZF9sGH6jEsNHHKicyYm9SCXUgMwl2TW2EwL9hUOQ6LgW5Hp7oA62BwpocfkRP8s/073wFihRWsaEKQrpQYBId0/lVJqAJSDUpKd2IAWr3Hr67Cz8tueHVSCFVM/lwD9DV75A7tK/QH9iUyLZy0qFwAAAABJRU5ErkJggg=="
          },
          "url": "https://cdn.sanity.io/images/7fl7n4qm/main_production/a052788b17939403f7491943ac867c5ae092c5ad-150x150.svg"
        }
      },
      "text": [
        {
          "_key": "8944406bd9d5",
          "_type": "block",
          "children": [
            {
              "_key": "af98dafe5448",
              "_type": "span",
              "text": "Decta submitted clean regulatory returns with "
            },
            {
              "_key": "ed66534d5adc",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "0 issues"
            },
            {
              "_key": "d36f344e10f9",
              "_type": "span",
              "text": " or rework."
            }
          ],
          "style": "normal"
        }
      ]
    }
  ]
}
```

#

# Need a hand submitting a regulatory return?



Chat to our founders, Dan and Fiona, to help you get it over the line.



```json
{
  "_key": "de9dde102c03",
  "_type": "buttons-block",
  "alignment": "center",
  "buttons": [
    {
      "href": "/demo",
      "label": "Chat to us",
      "variant": "contained"
    }
  ]
}
```

---
Source: https://complyfirst.co/use-cases/regulatory-reporting

---

# Central Bank of Ireland's AML REQ for Crypto-Asset Service Providers (CASPs): What You Need to Know

> The new AML REQ for CASPs introduces XML-only submissions, strict validation rules and significantly more AML data reporting. Here’s what crypto firms need to know.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: Ireland  
Published: 2026-06-12

```json
{
  "_key": "65ed4e2c8740",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

The Central Bank of Ireland's new [AML REQ for Crypto-Asset Service Providers](https://complyfirst.co/snapshot/aml-req-for-crypto-asset-service-providers-casps) is a significant step up in AML reporting expectations for the crypto sector.

The return moves away from any form of high-level reporting toward granular, XML-only submissions with strict schema validation and substantially deeper AML/CFT data requirements across crypto-specific activities.

For most CASP compliance teams, the challenge is operational: pulling together customer data, transaction volumes, crypto-asset exposure, and TM rule-level statistics across multiple systems, and structuring them into a format the CBI will accept.

This blog breaks down what the CBI is asking for, where firms are likely to run into issues, and what good preparation looks like.s like.

```json
{
  "_key": "3169b8b2d32e",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "53cec1c6c434",
      "_type": "block",
      "children": [
        {
          "_key": "16ae26777881",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "c3497a1a09a9",
      "_type": "block",
      "children": [
        {
          "_key": "16ae26777881",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "What it is:"
        },
        {
          "_key": "c80433578a50",
          "_type": "span",
          "marks": [],
          "text": " A mandatory AML Risk Evaluation Questionnaire used by the Central Bank of Ireland to collect structured, data-driven evidence of CASPs' AML, TF, and sanctions risk and controls."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "783d865a1d41",
      "_type": "block",
      "children": [
        {
          "_key": "fb3a5f186e73",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "When it's due:"
        },
        {
          "_key": "941e08d4f2ce",
          "_type": "span",
          "marks": [],
          "text": " The first submission is due "
        },
        {
          "_key": "40b0aafa3e01",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "31 July 2026"
        },
        {
          "_key": "c55540b4ddce",
          "_type": "span",
          "marks": [],
          "text": ", based on data as at "
        },
        {
          "_key": "9a54f46325d5",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "31 December 2025"
        },
        {
          "_key": "d1f6d8768b55",
          "_type": "span",
          "marks": [],
          "text": "."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "c0ad7b366439",
      "_type": "block",
      "children": [
        {
          "_key": "966e0b13925d",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Who it affects:"
        },
        {
          "_key": "807e6de6814d",
          "_type": "span",
          "marks": [],
          "text": " All CBI-authorised Crypto-Asset Service Providers, including firms that were previously registered as Virtual Asset Service Providers (VASPs)."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "ea1d5edce7ca",
      "_type": "block",
      "children": [
        {
          "_key": "4c4f42ae2d5d",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Why it matters:"
        },
        {
          "_key": "2cc2a71fef25",
          "_type": "span",
          "marks": [],
          "text": " It is the first crypto-specific supervisory return the CBI has published. It covers 19 reporting sections including eight crypto-activity sections that do not appear in any other CBI return."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

#### What Is the CBI AML REQ for Crypto Firms?

The [AML REQ (Risk Evaluation Questionnaire)](https://complyfirst.co/reports/cbi-aml-req) is the Central Bank of Ireland's annual AML/CFT supervisory return for regulated financial institutions. The CBI has been rolling out sector-specific versions since mid-2025, beginning with credit institutions and PI/EMIs.

The CASP REQ, published in March 2026, is the version built for Crypto-Asset Service Providers.

It is required under Section 22 of the Central Bank (Supervision and Enforcement) Act 2013 and the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010. The return also feeds into AMLA's EU-level data collection requirements under the Regulatory Technical Standards at Article 40(2) of AMLD and Article 12(7) of AMLAR.

The return gives the CBI structured, quantitative visibility into a CASP's:

- Customer risk profile and segmentation
- Crypto-specific product and service activity
- Geographic exposure by customer and by funds flow
- AML controls, governance, and outcomes
- Transaction monitoring rules, alerts, and outcomes

```json
{
  "_key": "36947c4712e5",
  "_type": "quote-v2",
  "authorName": "Fiona Lynch",
  "authorTitle": "Head of Risk & Compliance",
  "buttonLink": "https://complyfirst.co/reports/cbi-aml-req",
  "buttonText": "Learn how",
  "colorVariant": "dark",
  "image": {
    "_type": "image",
    "alt": "fiona lynch",
    "asset": {
      "_ref": "image-1d5d800a6c6c8a3df003955d3da25fd37002ca13-317x317-svg",
      "_type": "reference"
    }
  },
  "paddingBottom": "medium",
  "paddingTop": "medium",
  "quote": [
    {
      "_key": "62bf695edb4c",
      "_type": "block",
      "children": [
        {
          "_key": "51082869e1c6",
          "_type": "span",
          "text": "Complyfirst took the pain out of the AML REQ return. The platform generated the XML file for us, and Fiona and Dan were quick and helpful on Teams throughout. "
        },
        {
          "_key": "009c59cfe597",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "We submitted our return to the CBI same day and saved hours of effort."
        }
      ],
      "style": "normal"
    }
  ]
}
```

#### Who Must Comply and Key Reporting Dates

All CBI-authorised Crypto-Asset Service Providers must submit the CASP AML REQ. This includes Irish-authorised entities and Irish branches operating under Freedom of Establishment or Freedom of Services.

Each regulated legal entity must submit its own return, even if part of a wider group.

###### Former VASPs: 

If your firm was previously registered as a Virtual Asset Service Provider before transitioning to CASP authorisation, your first submission must cover both periods. You report data under your former VASP registration and separately under your CASP authorisation for any crypto-asset services commenced in 2025. This cannot be split across two returns.

###### Group structures: 

If your institution is reported as Parent of Group or Stand-alone entity, Sections 8.2.3 and 8.4.17 must be reported in an aggregated manner for all EEA business. Only Irish institution data is required for the remaining sections.

```json
{
  "_key": "34949489a935",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p>Milestone</p></th>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p>Date</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Reference date for all data</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>31 December 2025</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>First submission deadline</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>31 July 2026</strong></p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Extensions</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>None. Hard deadline.</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```



#### Key Changes Introduced 

The CBI is moving from a generic, one-size-fits-all REQ in Excel format to a crypto-specific return in machine-readable XML format. Here is what that means in practice:

```json
{
  "_key": "97c677a30233",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p>Old AML REQ</p></th>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p>New AML REQ for CASPs</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Generic return across sectors</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Crypto-Asset Service Provider specific</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Broad AML indicators</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Granular crypto-activity data by country and risk tier</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Excel-friendly</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>XML-only</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Limited validation</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Strict XSD schema validation</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Lower data volume</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>19 sections, hundreds of mandatory data fields</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Primarily governance focused</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Data, controls, risk analytics, and crypto-specific activity</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Manual completion possible</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Cross-functional data exercise requiring system-level extraction</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

#### Section-by-Section Overview of the CASP AML REQ

Let’s zoom in.

The CASP REQ has 19 reporting sections. At a high level, the return is structured to give the CBI detailed visibility into both your firm's inherent AML risk exposure and the effectiveness of your AML/CFT control framework.

1. **General**: Legal structure, LEIs, group structure, business model summary, CASP services operated, international presence by EEA country, and statement of compliance.
2. **Inherent Risk: Customer Segments**: Total customer counts by segment type (natural persons, legal entities, PEPs, high risk, complex structures, cash-intensive), split by product or service. Includes transaction volumes and values by segment.
3. **Inherent Risk: Sector**: High-risk legal entity customers by sector, referenced against Annex III of the AML Regulation.
4. **Inherent Risk: Anonymity**: Whether your products allow identity concealment, including explicit yes/no flags for self-hosted wallet addresses, DeFi platforms, mixer and tumbler platforms, and crypto ATMs involving cash.
5. **Inherent Risk: Crypto-Assets**: Your top five crypto-assets or cryptocurrencies by EUR traded value over 2025, expressed as a percentage of gross traded volume. Also includes average daily transacting users.
6. **Inherent Risk: Other**: Correspondent relationships, cash transactions, prepaid cards, crowdfunding, funding methods and payment instruments, intermediaries, remote onboarding proportions.
7. **Mitigation and Control: BWRA**: Whether your business-wide risk assessment covers ML, TF, sanctions, cybercrime, market abuse, crypto risks, customer groups, geographies, and distribution channels. How outcomes are applied.
8. **Mitigation and Control: Policies and Procedures**: Approval dates for each AML/CFT policy area, from customer onboarding to record keeping, sanctions, and geographic risk.
9. **Mitigation and Control: Onboarding and CDD**: Onboarding channel coverage, identity verification methods, CDD review frequencies by risk tier, backlog proportions, and customers without ML/TF risk profiles.
10. **Mitigation and Control: Transaction Monitoring**: TM approach (manual, automated, or both), model validation methodology, rule inventory, alert counts, true and false positive rates, backlog, and average time to close. Includes a specific question on whether your firm has implemented a distributed ledger analysis tool.
11. **Mitigation and Control: STR Reporting and Sanctions**: STR counts by GoAML category, days to report, sanctions list coverage, screening frequency, and confirmed sanction hits.
12. **Mitigation and Control: Governance and Assurance**: Outsourcing arrangements, training coverage, compliance testing dates, audit dates, governance reporting frequency, and AML staffing numbers.
13. **Physical Presence**: Subsidiaries, branches, agents, distributors, and white-labelling partners by country.
14. **Residence and Establishment**: Customer base by country: total, new, high-risk, and PEP-linked customers, for both natural persons and legal entities.
15. **Beneficial Owner**: Beneficial owner counts by country of residence.
16. **Politically Exposed Persons**: PEP exposure by country of nationality or citizenship for natural persons, and by country of establishment for legal entities.
17. **Custody Administration**: Country-level transaction numbers and EUR values for custody and administration of crypto-assets, split between all customers and high-risk customers.
18. **Trading Platform, Exchange Funds, Exchange Cryptos, Order Execution, Reception and Transmission, Portfolio Management, Transfer Cryptos**: For each CASP service your firm offers, country-level incoming and outgoing transaction numbers and values, split between all customers and high-risk customers.
19. **Correspondent Relationships, Geography of Funds Flow, Transaction Monitoring Rules**: Correspondent activity by country, funds flow source and destination by country with high-risk splits, and a rule-by-rule TM disclosure covering rule name, description, alert count, true positives, and false positives.

```json
{
  "_key": "4da9739dbefd",
  "_type": "quote-v2",
  "authorName": "Pamela Crilly",
  "authorTitle": "EU COO, TrueLayer",
  "buttonLink": "https://complyfirst.co/resources/truelayer-regulatory-reporting",
  "buttonText": "Read case study",
  "colorVariant": "light",
  "image": {
    "_type": "image",
    "alt": "pamela crilly",
    "asset": {
      "_ref": "image-bc89952675e6b810210c95c2ed3982943ccabb17-415x415-jpg",
      "_type": "reference"
    }
  },
  "paddingBottom": "medium",
  "paddingTop": "medium",
  "quote": [
    {
      "_key": "cab2b2a07dd9",
      "_type": "block",
      "children": [
        {
          "_key": "f4818697d329",
          "_type": "span",
          "text": "What truly sets Complyfirst apart is its "
        },
        {
          "_key": "247157253312",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "ability to simulate a regulator’s review, "
        },
        {
          "_key": "49c40cce35c7",
          "_type": "span",
          "text": "identifying potential data discrepancies or inconsistencies across multiple reports before submission."
        }
      ],
      "style": "normal"
    }
  ]
}
```

#### Submission Format and Validation Requirements

Now, for the reporting mechanics. 👀

The CBI requires CASP firms to submit the AML REQ in **XML format only**, generated in line with the official XSD schema provided for the CASP sector. Excel versions are available solely to support understanding and will not be accepted for submission.

The XML must comply with strict requirements: correct table ordering, approved variable names, valid enumerations, mandatory field formatting, and explicit closing tags throughout. Even minor technical errors can result in rejection by the CBI Portal.

###### File Naming Convention

Files must follow this structure:

```json
{
  "_key": "c6cdffc5ed08",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p>Element</p></th>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p>Example</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Institution Code</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Your CBI login code</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Reporting Date</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>YYYYMMDD</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Return Code</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>A04</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Extension</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>.xml or .zip</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

**Example:** CXXXXX_20251231_A04.xml

###### XML Table Structures

The CASP REQ uses two different XML table structures:

- **Table Structure A**: Used for country-level and activity-level tables. REF codes are entered as attributes within a single element.
- **Table Structure B**: Used for general and control sections. Requires an Identifier (REF code) and a Variable Name for each field.

The reporting sections must be entered in the strict order defined by the XSD schema. A file submitted in a different order will be automatically rejected.

###### Post-Upload Steps

Once the file passes the Portal's initial validation, two further steps are required:

1. Click **Finalise**
2. Click **Sign-Off**

Both are mandatory. Missing either step means the return has not been transmitted to the CBI.

###### Mandatory Data Rules

Every field in the CASP REQ is mandatory. No blanks are permitted, including fields that are not applicable to your business model.

The CBI requires firms to use approved placeholder values by field type:

```json
{
  "_key": "7d342d45dc8c",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-hug\" data-tb-col-color=\"purple\" data-tb-col-width=\"hug\" />\n    <col class=\"tb-col-hug\" data-tb-col-color=\"purple\" data-tb-col-width=\"hug\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-purple tb-nowrap\" data-tb-align=\"left\"><p>Data Type</p></th>\n      <th class=\"tb-header-purple tb-nowrap\" data-tb-align=\"left\"><p>Required Value</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Integer</p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>0</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Decimal</p><p></p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>0</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Date</p><p></p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>2000-01-01</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>String</p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>N/A</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>LEI</p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>00000000000000000000</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Country</p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>00</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

All values must be reported in euros. Exchange rates can be based on the transaction date or the reference date.

Here’s a walkthrough from our [AML REQ breakfast session](https://complyfirst.co/resources/briefing-2-aml-req-steps) where our CTO, Dan, breaks down the non-negotiables for completing the AML REQ:

```json
{
  "_key": "b1577dc0cec7",
  "_type": "resource-media",
  "mediaType": "mp4",
  "mp4File": {
    "_type": "file",
    "asset": {
      "_ref": "file-954eecb6703a464be10c84871b14ac064c66f41c-mp4",
      "_type": "reference"
    }
  }
}
```

#### Step-by-Step Checklist to Submit Your AML REQ

There are no shortcuts, here is what the CBI requires end-to-end.

###### Step 1: Download the CASP REQ pack

Download the CASP-specific materials from the Central Bank of Ireland:

- Guidance Notes v1.1 (March 2026)
- CASP XSD schema (A04)
- Sample XML file

```json
{
  "_key": "8eefb337ce45",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "0ee85ebe8769",
      "_type": "block",
      "children": [
        {
          "_key": "bbcc37214910",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "👋🏼 To help firms submitting their AML REQ, we built an AML REQ Excel template with CBI guidance built-in. Get in touch with us "
        },
        {
          "_key": "3c6178464317",
          "_type": "span",
          "marks": [
            "67dc04e95248",
            "strong"
          ],
          "text": "here"
        },
        {
          "_key": "ffa166fbc1d0",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": " to access it."
        }
      ],
      "markDefs": [
        {
          "_key": "67dc04e95248",
          "_type": "link",
          "href": "https://complyfirst.co/demo"
        }
      ],
      "style": "normal"
    }
  ]
}
```

###### Step 2: Read the guidance notes

Review the full guidance PDF document (typically 80-120 pages):

###### Step 3: Map your firm’s data to the REQ schema

Map internal data sources across all 19 sections.

Every field:

- is mandatory
- has a strict format
- must align to the XML schema requirements

###### Step 4: Complete the REQ

Complete the return across all required sections.

This includes hundreds of fields covering:

- customers
- products and services
- jurisdictions
- transaction activity
- AML controls
- governance
- monitoring frameworks

###### Step 5: Validate against the XSD schema

The submission must validate against the official CBI XSD schema before upload. Excel won’t fly! XML only.

###### Step 6: Obtain sign-off

Complete internal governance and approvals. Typically this involves MLRO and board-level review.

###### Step 7: Upload to the Central Bank Portal

Submit the validated XML file through the Central Bank Portal **before 30th June 2026.**

###### Step 8: Keep an audit trail

The CBI will ask.

#### How Complyfirst Helps CASPs Submit Their AML REQ

[Complyfirst](https://complyfirst.co/) provides the [tools and support](https://complyfirst.co/reports/cbi-aml-req) for CASP firms to deliver a compliant AML REQ submission, aligned to the CBI’s schema and deadlines.

```json
{
  "_key": "42bf2736ce55",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "5706b2da84ed",
      "_type": "block",
      "children": [
        {
          "_key": "4c27d9ed7988",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Plus, your first AML REQ is on us. We’re confident enough in the platform — and in our team — that we’ll get you through your first AML REQ submission for free."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

We have supported firms across the CBI's AML REQ since the first sector-specific returns launched. Fiona Lynch at Fexco told us that Complyfirst took the pain out of the AML REQ return entirely. The platform generated the XML file, they submitted to the CBI the same day, and saved hours of effort in the process. Adrian Witkowski at [SumUp](https://complyfirst.co/resources/sumup-regulatory-reporting) put it this way: "What took weeks, Complyfirst fixed in hours: within 48 hours we were live and submitted."

Here’s how we'll help:

- CBI definitions are built in-platform
- N/A codes are auto-applied in one click
- Real-time validation in plain English as you work
- Approvals and audit trail are baked in
- You get 1:1 support, even on deadline day
- Generated XML output, named & ready to upload

Get in touch [here](https://complyfirst.co/demo) to get started.

```json
{
  "_key": "082f174863b5",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "a8426191e50c",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "b5061325ef92",
          "_type": "block",
          "children": [
            {
              "_key": "88ecbd8aa3bc",
              "_type": "span",
              "marks": [],
              "text": "The CASP AML REQ is the Central Bank of Ireland's annual AML/CFT supervisory return for Crypto-Asset Service Providers. It requires firms to submit structured XML data across 19 sections covering customer risk, crypto-specific activity, controls, governance, and transaction monitoring, forming part of the CBI's core supervisory dataset and feeding EU-level AMLA reporting."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the CBI AML REQ for CASPs?"
    },
    {
      "_key": "a95e58a25440",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "e689ce9cb7a6",
          "_type": "block",
          "children": [
            {
              "_key": "958bfe3b8a3b",
              "_type": "span",
              "marks": [],
              "text": "All CBI-authorised Crypto-Asset Service Providers must submit. Each regulated legal entity submits its own return, even if part of a wider group."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Who must submit the CASP AML REQ?"
    },
    {
      "_key": "abd299a362e9",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "63865bdd2170",
          "_type": "block",
          "children": [
            {
              "_key": "a3c680b8b828",
              "_type": "span",
              "marks": [],
              "text": "The first CASP AML REQ must be submitted by "
            },
            {
              "_key": "61cb399c604b",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "31 July 2026"
            },
            {
              "_key": "35f803c30c86",
              "_type": "span",
              "marks": [],
              "text": ", based on data as at "
            },
            {
              "_key": "46fdf0d37afd",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "31 December 2025"
            },
            {
              "_key": "d35e4120b73f",
              "_type": "span",
              "marks": [],
              "text": ". The CBI has confirmed this is a hard deadline and no extensions will be granted."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the submission deadline for the CASP AML REQ?"
    },
    {
      "_key": "085aa6dbadbe",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "1abad7738dc5",
          "_type": "block",
          "children": [
            {
              "_key": "53f816e46448",
              "_type": "span",
              "marks": [],
              "text": "No. The CBI accepts XML files only. Excel is published for preparation and reference. It will not be accepted for submission."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Can CASP firms submit the AML REQ in Excel?"
    },
    {
      "_key": "eccc88d8905e",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "fddba3e71262",
          "_type": "block",
          "children": [
            {
              "_key": "ec2b2a010439",
              "_type": "span",
              "marks": [],
              "text": "The CASP AML REQ file must be named in the format CXXXXX_YYYYMMDD_A04.xml, where CXXXXX is your institution code, YYYYMMDD is the reporting date, and A04 is the CASP return code."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What format does the CASP AML REQ XML file name need to follow?"
    }
  ],
  "title": "FAQs"
}
```

---
Source: https://complyfirst.co/resources/aml-req-for-casps-explained
Last updated: 2026-07-10

---

# How to Submit Monthly REP027 Returns via FCA RegData

> REP027 has 17 sections and a 21 July deadline. We break down who's in scope, the three trickiest sections, and how to build a repeatable monthly process.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: UK  
Published: 2026-06-03

```json
{
  "_key": "c2cad6c574c0",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

The FCA has watched £6 billion a day flow through payment institutions. They have also watched what happens when safeguarding fails. [REP027](https://complyfirst.co/snapshot/fca-safeguarding-return) is how they plan to make sure it doesn't happen again.



Between 2018 and 2023 we saw a string of UK insolvencies (Ipagoo, Premier FX and others) where customer funds couldn't be returned in full. The FCA noted the average shortfall in those cases was 65%. That experience sits behind every policy decision in this new regime.



REP027 is a brand new, dedicated [monthly safeguarding return](https://complyfirst.co/resources/fca-ps25-12-explained-what-the-new-safeguarding-regime-means-for-pis-and-emis). You used to submit a small portion of safeguarding data as part of your capital adequacy return. Now it has its own home, its own sections, its own conditional logic, and its own first deadline: **21 July 2026**.



This blog walks you through what the return covers, which sections are tricky, what the FCA will be watching closely, and how to set up a good, repeatable monthly process.



```json
{
  "_key": "57a63bbde9b3",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "cd6191ffd1f3",
      "_type": "block",
      "children": [
        {
          "_key": "e27ced6d5d25",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL:DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "350325f17e4b",
      "_type": "block",
      "children": [
        {
          "_key": "80f79d56b607",
          "_type": "span",
          "marks": [],
          "text": "First submission deadline: "
        },
        {
          "_key": "590ff7357d3c",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "21 July 2026"
        },
        {
          "_key": "8796d0c4a6b4",
          "_type": "span",
          "marks": [],
          "text": ", then monthly (15 business days after month-end)"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "b510889c435d",
      "_type": "block",
      "children": [
        {
          "_key": "68991b7333ee",
          "_type": "span",
          "marks": [],
          "text": "In scope: authorised PIs, authorised EMIs, small EMIs that have opted into safeguarding"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "d7dac05d8730",
      "_type": "block",
      "children": [
        {
          "_key": "966daac809de",
          "_type": "span",
          "marks": [],
          "text": "The return has up to "
        },
        {
          "_key": "5d0ba35fb726",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "17 sections. "
        },
        {
          "_key": "6d747e845f21",
          "_type": "span",
          "marks": [],
          "text": "Which ones apply depends on your firm type and activity."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "d02780145765",
      "_type": "block",
      "children": [
        {
          "_key": "8ed00164a327",
          "_type": "span",
          "marks": [],
          "text": "A single director or senior manager is now formally accountable for safeguarding operations."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "e1d77a144986",
      "_type": "block",
      "children": [
        {
          "_key": "0fd1c34cb247",
          "_type": "span",
          "marks": [],
          "text": "Complyfirst is offering "
        },
        {
          "_key": "dc898df04aac",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "your first quarter "
        },
        {
          "_key": "c1da1808e96e",
          "_type": "span",
          "marks": [
            "em",
            "strong"
          ],
          "text": "free"
        },
        {
          "_key": "cd637175fdb9",
          "_type": "span",
          "marks": [],
          "text": ": full platform access, 1:1 support, and submission all the way to the FCA."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



#### What is the FCA REP027 Safeguarding Return?

[REP027](https://complyfirst.co/resources/how-to-complete-the-fca-safeguarding-return-rep027-a-step-by-step-guide) is a monthly regulatory return submitted via the FCA's RegData platform. It sits under the new CASS 15 sourcebook, which replaced the FCA's high-level safeguarding guidance with prescriptive operational rules from 7 May 2026.



The purpose is straightforward. The FCA wants standardised, frequent data on how firms are protecting customer funds. Not once a year. Every month.



#### Why the FCA built a dedicated return

EMIs safeguarded approximately £26 billion in customer funds in 2024, up from £11 billion in 2021. Payment institutions safeguard an estimated £6 billion per day. That scale, combined with the insolvency failures of the previous decade, made a dedicated return inevitable.



The FCA has been clear that it has zero tolerance for safeguarding failures. REP027 is their early warning system. One month's data is a data point. Several months of the same issue is a pattern, a pattern that will trigger supervisory action.



#### When is REP027 due?

The first submission covers the period from 7 May 2026 to 30 June 2026 and is due by **21 July 2026**. After that, submissions are due within 15 business days of each month-end, every month.



That is twelve submissions a year.



#### Is Your Firm in Scope for REP027?

There are three layers to work through.



###### Which firm types have to submit

1. **Layer 1: Firm type:** Authorised payment institutions (APIs) and authorised e-money institutions (AEMIs) are in scope. Small e-money institutions (SEMIs) are in scope if they have opted into safeguarding. Small payment institutions (SPIs) are only in scope if they have opted in. If you are not authorised or did not opt in, you are out of scope.
2. **Layer 2: Activity:** If you are in scope, sections 1, 2, and 9 always apply. That is your firm details, your safeguarding method, and any notifiable CASS breaches. Sections 3 to 8 only apply if you actually held relevant funds during the monthly reporting period. For smaller firms, if there was a month where nothing was safeguarded, you skip sections 3 to 8.
3. **Layer 3: Unrelated payment services (UPS):** If your firm provides payment services that are genuinely separate from your e-money issuance (for example, an EMI that also runs a standalone money remittance product for SMEs), you are providing UPS. Sections 10 to 17 apply. The FCA wants to see the UPS bucket separately from e-money because the two are safeguarded under different regimes and can have different treatment for returning funds in an insolvency.



###### Which sections apply to you

In short: sections 1, 2, and 9 apply to everyone in scope. Sections 3 to 8 depend on activity. Sections 10 to 17 depend on whether you provide UPS. Run through all three layers before you assume which sections you need to complete.



```json
{
  "_key": "ac6bc9ce66e4",
  "_type": "resource-media",
  "image": {
    "_type": "image",
    "alt": "in scope rep027 firms",
    "asset": {
      "_ref": "image-577a7f19dd62f0b84189caf1d0893540bb178129-1934x1080-png",
      "_type": "reference"
    }
  },
  "mediaType": "image"
}
```



#### The REP027 Return at a Glance: All 17 Sections

###### Sections 1–9: the core return

```json
{
  "_key": "115e3fca78ad",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p><strong>Section</strong></p></th>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p><strong>The Details</strong></p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 1: Firm information</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Your firm name, category of safeguarding institution, and details of your last safeguarding audit.</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 2: Safeguarding method</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>What method did you use? Segregation, insurance or guarantee, or a combination? Include the number of clients you safeguarded for, and any use of non-standard internal reconciliation procedures during the period. (More on why this matters below.)</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 3: Balances</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Your highest and lowest safeguarding requirement during the reporting period.</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 4: Where funds are held</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>For segregation: institution, account type, number of accounts, total held, country, contract terms. For insurance or guarantee: insurer name, amount covered, expiry date, overdue premiums. For relevant assets: asset type, custodian, total value held at period end. We will spend more time on this section below.</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 5: Resource vs requirement</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>What you actually safeguarded across bank accounts, segregated funds not yet placed, relevant assets, and any insurance or guarantee cover. Any excess or shortfall at month end and what you did about it. Also coming back to this one.</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 6: D+1 segregation check</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Your requirement vs resource from your last internal reconciliation, plus any adjustments made.</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 7: Reconciliations</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Confirmation that you carried out internal and external reconciliations on every reconciliation day during the period.</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 8: Record-keeping</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Your inventory of safeguarding accounts and assets: how many you held at the start of the month, opened, closed, and held at month end, plus acknowledgement letter coverage. We are coming back to this one too.</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 9: Notifiable breaches</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Did anything happen this month that you were required to notify the FCA about under CASS? material record-keeping errors, failed reconciliations, unresolved discrepancies, material shortfalls, an insurance or guarantee approaching expiry without a replacement, or any other breach of duty under CASS 15?</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```



###### Sections 10–17: the UPS block

Sections 10 to 17 mirror the core return but apply only to unrelated payment services. If UPS applies to your business model, you’ll need to complete these sections.



```json
{
  "_key": "0a1de63db648",
  "_type": "resource-media",
  "image": {
    "_type": "image",
    "alt": "rep027 return at a glance",
    "asset": {
      "_ref": "image-001ebd72006b60d752ad4a856242383c8d13f940-1920x1066-png",
      "_type": "reference"
    }
  },
  "mediaType": "image"
}
```



#### The Three Trickiest Sections

###### Section 4: Where your funds sit

Section 4 asks you to report where relevant funds actually sit, so which institutions, accounts, assets, insurance or guarantees. The reason it catches people out is that what you tick at the top of the section determines how much data you have to produce underneath.



There are five sub-sections, 4a through 4e, each triggered by a yes/no question:



- **11AA:** yes triggers 4a — your full list of bank accounts
- **12AA:** yes triggers 4b and 4c — your assets and custodian detail
- **14AA:** yes triggers 4d — insurer names, amounts covered, expiry dates, overdue premiums
- **15AA:** yes triggers 4e — guarantor names, amounts covered, expiry dates, overdue fees



One yes can generate a significant volume of follow-on data. For larger firms with multiple safeguarding methods or many bank accounts, section 4 alone can take considerable time to prepare.



And if you have an overdue premium on an insurance policy in 4d, that data point carries forward. It surfaces again in section 5 and is likely to attract supervisory attention.



###### Section 5: Resource vs requirement

This is the section supervisors will read first. It is where your actual safeguarding position becomes visible, and where patterns emerge over time.



A few things to note in section 5:

- **Insurance cover with an overdue premium** (field 17D) is still technically in force, but the FCA will notice it. An overdue premium is an early signal that the policy may lapse, and you may hear from them.
- **Unallocated funds** (field 19B) i.e. money received but not yet matched to a client, must be reported here. It is also worth fixing upstream. If clients are not sending funds with a correct payment reference, they cannot be tagged and safeguarded promptly. That is a process problem, not just a reporting problem.
- **Shortfalls** (fields 20A and 21A). You report any shortfall and what you did about it. A single shortfall corrected by a top-up is a data point. The same shortfall appearing month after month is a pattern. The FCA will be asking whether this is a one-off or a sign of something structural in your safeguarding operations.



###### Section 8: Record-keeping and acknowledgement letters

Section 8 is your inventory: accounts at the start of the month, opened during the period, closed during the period, accounts at month end, and how many of those are covered by an acknowledgement letter.



Two things to pay close attention to here.



**First,** the account count at month end (field 28AE) must tie exactly to the count of accounts listed in section 4a. If those numbers do not match, you have a consistency problem that will stand out.



**Second,** the number of accounts covered by an acknowledgement letter (field 28AF) is scrutinised. If you have accounts without letters on file, field 28AG requires a narrative explanation of what happened, and what you are doing about it. This is a running commentary. If you write in May that you are chasing the bank, and you are still writing the same thing in October, the FCA will come looking.



Section 8 is also where de-banking becomes visible for the first time in a structured way. De-banking is a known pain point for PIs and EMIs, as you often have no control over the timing. But historically, firms that lost safeguarding accounts and quickly replaced them did not always flag it to the FCA.



From now on, section 8 captures every account opened and closed, with narrative. Getting that wrong, or being economical with the truth, puts you in false-statement territory under the EMRs and PSRs.



#### What Answers in REP027 Will Trigger FCA Supervisory Attention?

Most of REP027 is straightforward data. But there are specific answers that are likely to prompt the FCA to take a closer look.



Four to flag:

1. **Section 2, question 8A** asks whether you used a non-standard method of internal safeguarding reconciliation during the period. Ticking yes will attract attention. Only tick yes if you genuinely did, and be prepared to explain why.
2. **Section 7, questions 26A and 27A** ask whether you carried out internal and external reconciliations on every reconciliation day. If you tick yes but actually missed days, that is a potentially false statement to the FCA. Be accurate here, and address any missed days in your narrative.
3. **Section 9, questions 29A and 30A** ask whether any notifiable CASS breaches arose and whether you complied with the notification requirements. The answers here can create serious supervisory issues if you get them wrong. Make sure you know what triggers a notification obligation under CASS 15 before you complete this section.
4. **Sections 10 to 17** — if UPS applies to your business model and you leave these sections blank, that will stand out. Know your scope before you submit.



###### Will the FCA flag my return if I missed a reconciliation day?

Yes, potentially. Section 7 asks you to confirm reconciliations were carried out on every reconciliation day. A missed day reported accurately is far better than a missed day covered up. Transparency with a clear explanation of what went wrong and what you have done to fix it is the right approach. False or misleading information in a regulatory return is a criminal offence under the EMRs and PSRs.



```json
{
  "_key": "7ce657d09bd5",
  "_type": "quote-v2",
  "authorName": "Neil McDermott",
  "authorTitle": "CFO",
  "buttonLink": "https://complyfirst.co/resources/decta-regulatory-reporting",
  "buttonText": "Learn how",
  "colorVariant": "light",
  "image": {
    "_type": "image",
    "alt": "neil decta",
    "asset": {
      "_ref": "image-851b8366eab105f0c9eacdbdce69fb15a0a03820-800x800-jpg",
      "_type": "reference"
    }
  },
  "paddingBottom": "medium",
  "paddingTop": "medium",
  "quote": [
    {
      "_key": "05c3f2d912b1",
      "_type": "block",
      "children": [
        {
          "_key": "ffc271615112",
          "_type": "span",
          "marks": [],
          "text": "I’ve worked at large banks with entire teams managing returns. With Complyfirst, we had it done in days."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



#### Who is the New Safeguarding Accountable Individual?

The FCA now requires a single director or senior manager of sufficient skill and authority to formally own safeguarding. Their responsibilities are to have oversight of the firm's operational compliance with the relevant funds regime, and reporting to the governing body on that oversight.



This is a taste of the SMCR regime arriving in a bespoke way for payment and e-money firms. This type of named accountability does not exist anywhere else for PIs and EMIs. It is new, it is specific to safeguarding, and it carries real consequences.



###### What are the consequences if the safeguarding accountable individual gets it wrong?

_At firm level: _financial penalty, public censure, or in the most serious cases cancellation of authorisation under the EMRs or PSRs.



_At individual level: _personal financial penalties, loss of fit and proper status (which effectively means loss of the role), and in the most serious cases a criminal offence for providing false or misleading information to the FCA.



If you are that individual (and for many of you reading this, _you are_) the way REP027 is prepared, approved, and evidenced each month is now a professional liability question.



#### How to Build a Repeatable Monthly REP027 Process

This is a monthly return. You will submit it twelve times a year. The goal is to design it once and run it the same way every month, so you’re not having to reinvent the wheel each time.



Here’s a practical four-step approach:

```json
{
  "_key": "eaac8d3fc820",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"purple\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p><strong>Step</strong></p></th>\n      <th class=\"tb-header-purple\" data-tb-align=\"left\"><p><strong>The Process</strong></p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Step 1: Data pull</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Set up an extract from your core systems (your banking platform, your reconciliation tooling) that you can run every month. It will not capture everything, but getting the core fields automated removes the most time-consuming manual keying.</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Step 2: Validate the data</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>You can validate manually on the FCA RegData platform, or technically against the FCA's XSD schema. The schema has conditional logic baked in, so validation catches errors before submission.</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Step 3: Approvals</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Your safeguarding accountable individual needs an audit trail of who approved what, and when. Build this into your process from the start. A spreadsheet signed off over email the night before is not the audit trail that individual wants to be relying on.</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Step 4: Submit to RegData</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>You can key data in manually via the RegData web interface, or submit via API directly from your reporting system. Given REP027 can run to hundreds of data points for larger firms, the manual route is not a sustainable long-term approach.</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

###### Should we automate REP027 or do it manually?

The honest answer is that manual works for the first submission or two. It will not work sustainably twelve times a year. The risk is not just time, it is accuracy. Manual keying introduces errors. And a process that lives in one person's head generates key person risk.



[Automating via API submission](https://complyfirst.co/integrations/fca) requires technical resource to build, and someone who can maintain it when the FCA updates the XSD schema (which it will). If you do not have that in-house, you need it in your corner before the errors start.



At [Complyfirst](https://complyfirst.co/), we built a reporting platform specifically for this. You drop your data in, the platform fills out the return automatically, your safeguarding accountable individual reviews and approves with a full audit trail, and we submit direct to RegData via API. When the FCA updates the schema, that is on us, not you or your team.



**_And, _we are offering your first quarter completely free. Full platform access, 1:1 support from our team, and submission all the way to the FCA. The first deadline is 21 July.**



```json
{
  "_key": "d68d70b9b9f4",
  "_type": "resource-quick-links",
  "links": [
    {
      "_key": "0fffc68de731",
      "_type": "linkItem",
      "title": "REP027 snapshot one-pager",
      "url": "https://complyfirst.co/resources/files/reporting-snapshot-fca-safeguarding-return-snapshot"
    },
    {
      "_key": "61f87a1e32e7",
      "_type": "linkItem",
      "description": "Webinar recording & slides",
      "title": "Inside REP027: Preparing for the FCA's New Monthly Safeguarding Return",
      "url": "https://complyfirst.co/resources/inside-rep027-preparing-for-the-fca-s-new-monthly-safeguarding-return"
    },
    {
      "_key": "77f9c1d08cc8",
      "_type": "linkItem",
      "title": "1:1 call with us",
      "url": "https://complyfirst.co/demo"
    }
  ],
  "title": "Complyfirst Resources"
}
```



#### Getting REP027 Right From the Start

Three things to take away from this post: know your scope and which sections apply to you, understand what the FCA is actually looking at in sections 4, 5, and 8, and build a repeatable monthly process with a clear approval trail for your safeguarding accountable individual.



If you are navigating this and want to talk it through, get in touch with us [here](https://complyfirst.co/demo). The 21 July deadline is close, and we are happy to help.



```json
{
  "_key": "7a378cf6daad",
  "_type": "resource-accordion",
  "description": [
    {
      "_key": "462c2976a50b",
      "_type": "block",
      "children": [
        {
          "_key": "4cb60403898f",
          "_type": "span",
          "marks": [],
          "text": "Here are some questions that came up in our "
        },
        {
          "_key": "9fb8ed56f228",
          "_type": "span",
          "marks": [
            "93b04b64a475"
          ],
          "text": "REP027 webinar"
        },
        {
          "_key": "8762b2626d8c",
          "_type": "span",
          "marks": [],
          "text": "."
        }
      ],
      "markDefs": [
        {
          "_key": "93b04b64a475",
          "_type": "link",
          "href": "https://complyfirst.co/resources/inside-rep027-preparing-for-the-fca-s-new-monthly-safeguarding-return"
        }
      ],
      "style": "normal"
    }
  ],
  "items": [
    {
      "_key": "392349d3da92",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "63d43ecda7a5",
          "_type": "block",
          "children": [
            {
              "_key": "57ced689b302",
              "_type": "span",
              "marks": [],
              "text": "Yes, it's live. The schema is available on the FCA website now. What they haven't published is a user-friendly Excel template, which is why we built one. DM us if you'd like a copy."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Has the FCA published the XSD schema?"
    },
    {
      "_key": "288df6df9a22",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "57042e83179f",
          "_type": "block",
          "children": [
            {
              "_key": "c9c08268f2b0",
              "_type": "span",
              "marks": [],
              "text": "If you hold no relevant funds in that month, you only need to complete sections 1, 2 and 9. Sections 3 to 8 are activity-driven. Sections 10 to 17 only apply if you provide unrelated payment services."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "We're an API with zero client funds. Do we really need to complete the whole return?"
    },
    {
      "_key": "f05749e47446",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "b7dfa99d7589",
          "_type": "block",
          "children": [
            {
              "_key": "bf733042f332",
              "_type": "span",
              "marks": [],
              "text": "Probably not. Most firms run with segregation as their sole safeguarding method. Insurance only comes into play if there's a specific operational reason or you want an extra layer of protection. It’s very business model specific, so worth a conversation if you're unsure."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Do we still need an insurance policy if we have zero client funds?"
    },
    {
      "_key": "fc2425e14759",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "718acbd53167",
          "_type": "block",
          "children": [
            {
              "_key": "25cfe470e6a4",
              "_type": "span",
              "marks": [],
              "text": "The threshold is materiality. You're required to notify the FCA of material excesses or shortfalls. What's material will depend on your business model. Our advice: if you're genuinely unsure, err on the side of caution and notify."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Does materiality matter for Section 9 discrepancies? Do we notify the FCA even for small ones?"
    },
    {
      "_key": "4487bc4e1ab0",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "9d1aa9c53a7c",
          "_type": "block",
          "children": [
            {
              "_key": "4445b713cbdc",
              "_type": "span",
              "marks": [],
              "text": "Section 5 asks for your safeguarding resource versus requirement. The figures reported are based on your last reconciliation at month end, not a daily consolidated amount. Your highest and lowest balances during the period are captured separately in Section 3."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "For Section 5, is the balance the month-end figure or a consolidated daily amount?"
    }
  ],
  "title": "FAQ"
}
```

---
Source: https://complyfirst.co/resources/how-to-submit-monthly-rep027-returns-via-fca-regdata
Last updated: 2026-06-12

---

# Inside REP027: Preparing for the FCA's New Monthly Safeguarding Return

> Dan and Fiona covered all things REP027 - who's in scope, how to complete the return, and how you can automate it.

Jurisdiction: UK  
Published: 2026-05-28

```json
{
  "_key": "c604cec45720",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://www.youtube.com/watch?v=q4hh8ZacFVM"
}
```



If you're up against REP027, this webinar is for you. Dan and Fiona covered:



- Exactly who's in scope and which sections of the return apply to your firm
- What you'll actually be reporting each month - balances, reconciliations, acknowledgment letters, notifiable CASS breaches
- How you can use technology to build a repeatable monthly reporting process that takes minutes, not days



```json
{
  "_key": "e715d70a4f08",
  "_type": "resource-quick-links",
  "links": [
    {
      "_key": "ac5b1a0cad8b",
      "_type": "linkItem",
      "title": "Webinar Slides",
      "url": "https://complyfirst.co/resources/files/rep027-webinar-slides.pdf"
    },
    {
      "_key": "5745b5f51326",
      "_type": "linkItem",
      "title": "REP027 Snapshot",
      "url": "https://complyfirst.co/resources/files/reporting-snapshot-fca-safeguarding-return-snapshot"
    },
    {
      "_key": "4c4039501265",
      "_type": "linkItem",
      "title": "Primary legal source: FCA 2025/38 — Payments and Electronic Money (Safeguarding) Instrument 2025",
      "url": "https://api-handbook.fca.org.uk/files/instrument/Glossary-GEN-CASS-SUP/FCA%202025/38-2026-05-07.pdf"
    },
    {
      "_key": "4bc3fb508f0f",
      "_type": "linkItem",
      "title": "FCA Safeguarding Policy Statement and REP027 Form",
      "url": "https://www.fca.org.uk/publication/policy/ps25-12.pdf"
    },
    {
      "_key": "c99633e9596d",
      "_type": "linkItem",
      "title": "FCA guidance notes for the form",
      "url": "https://handbook.fca.org.uk/handbook/sup16/sup16s14a"
    }
  ],
  "title": "More Resources"
}
```

---
Source: https://complyfirst.co/resources/inside-rep027-preparing-for-the-fca-s-new-monthly-safeguarding-return
Last updated: 2026-05-28

---

# Investment Firms AML REQ Explained: Everything to Know Before the 30 June 2026 Deadline

> The new AML REQ for Investment Firms introduces XML-only submissions, strict validation rules and significantly more AML data reporting. Here’s what firms need to know.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: Ireland  
Published: 2026-05-20

```json
{
  "_key": "c8d9499a6866",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

The [Central Bank of Ireland’s new AML REQ for Investment Firms](https://complyfirst.co/snapshot/aml-req-for-investment-firms) is a big step up in AML reporting expectations.

The return moves away from broad Excel-based submissions toward much more granular XML reporting, with stricter validation rules and significantly deeper AML/CFT data requirements.

For most firms, the challenge will be operational: pulling together customer, transaction, governance and control data across multiple systems in a format the CBI will accept.

This blog breaks down what has changed, what the CBI is asking for, where firms are likely to run into issues, and what good preparation looks like.

```json
{
  "_key": "ce14d135569a",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "e96c1e0ca6af",
      "_type": "block",
      "children": [
        {
          "_key": "a0901523976d",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "ca242ff71fe6",
      "_type": "block",
      "children": [
        {
          "_key": "721ca6757f3a",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "What it is:"
        },
        {
          "_key": "542304bc25fe",
          "_type": "span",
          "marks": [],
          "text": " A mandatory AML Risk Evaluation Questionnaire used by the Central Bank of Ireland to collect structured, data-driven evidence of investment firms’ AML, TF, and sanctions risk and controls."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "5961f3fa8e2e",
      "_type": "block",
      "children": [
        {
          "_key": "a13280713fd6",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "When it’s due: "
        },
        {
          "_key": "30255f0a3265",
          "_type": "span",
          "marks": [],
          "text": "The first submission is due "
        },
        {
          "_key": "0d8df569ec0a",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "30 June 2026"
        },
        {
          "_key": "2bb93c9915b1",
          "_type": "span",
          "marks": [],
          "text": ", based on data as at "
        },
        {
          "_key": "9e6ebb2f2112",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "31 December 2025"
        },
        {
          "_key": "cf6568b26f41",
          "_type": "span",
          "marks": [],
          "text": "."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "982e63d0967e",
      "_type": "block",
      "children": [
        {
          "_key": "b14a32c07901",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Who it affects: "
        },
        {
          "_key": "8804a6331883",
          "_type": "span",
          "marks": [],
          "text": "All Central Bank of Ireland-regulated investment firms, including Irish entities and Irish branches operating cross-border."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "a99374c86eec",
      "_type": "block",
      "children": [
        {
          "_key": "6b8baeb7db85",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Why it matters: "
        },
        {
          "_key": "8e4e055d4e85",
          "_type": "span",
          "marks": [],
          "text": "It replaces high-level narrative AML reporting with structured, quantitative data covering risk exposure, controls, and outcomes."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

#### What is the AML REQ for Investment Firms?

The AML REQ (Risk Evaluation Questionnaire) is the Central Bank of Ireland’s annual AML/CFT supervisory return for regulated Investment Firms.

The new version moves from broad Excel-based reporting to much more granular XML submissions, giving the CBI deeper visibility into a firm’s:

- customer risk
- transaction activity
- products and services
- geographic exposure
- AML controls and governance

#### Who Must Comply and Key Reporting Dates

In short, if you are a **CBI-regulated investment firm**, you are required to submit the REQ. This includes Irish-authorised entities, Irish branches, and firms operating cross-border into Ireland under Freedom of Establishment or Freedom of Services.

**Each regulated legal entity must submit its own REQ.** Being part of a group does not remove that obligation, although some sections require aggregated EEA-level data depending on your legal structure.

###### Key Deadlines

- **Submission deadline:** 30 June 2026 _(hard deadline)_
- **Reference date:** 31 December 2025

No deadline extensions will be granted.

```json
{
  "_key": "e62d017af793",
  "_type": "quote-v2",
  "authorName": "Fiona Lynch",
  "authorTitle": "Head of Risk & Compliance",
  "buttonLink": "https://complyfirst.co/reports/cbi-aml-req",
  "buttonText": "Learn how",
  "colorVariant": "dark",
  "image": {
    "_type": "image",
    "alt": "fiona lynch",
    "asset": {
      "_ref": "image-1d5d800a6c6c8a3df003955d3da25fd37002ca13-317x317-svg",
      "_type": "reference"
    }
  },
  "paddingBottom": "medium",
  "paddingTop": "medium",
  "quote": [
    {
      "_key": "f80af7753afe",
      "_type": "block",
      "children": [
        {
          "_key": "ba0c5dadaaaf",
          "_type": "span",
          "marks": [],
          "text": "Complyfirst took the pain out of the AML REQ return. The platform generated the XML file for us, and Fiona and Dan were quick and helpful on Teams throughout. "
        },
        {
          "_key": "72c3fbf8567c",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "We submitted our return to the CBI same day and saved hours of effort."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

#### Key Changes Introduced (Before vs After)

The CBI is moving from a one-size-fits-all REQ which was in Excel format, to a sector-specific one in machine-readable XML format. Here’s the difference:

```json
{
  "_key": "112ea2775a64",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Old AML REQ</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>New AML REQ</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Generic return across sectors</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Sector-specific returns</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Broad AML indicators</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Granular risk metrics</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Excel-friendly</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>XML-only</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Limited validation</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Strict XSD schema validation</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Lower data volume</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Hundreds of mandatory data fields</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Primarily governance focused</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Data, controls and risk analytics focused</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Manual completion possible</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Cross-functional data exercise</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

#### Section-by-Section Overview of AMLREQ_IF

Let’s zoom in.

At a high level, the AMLREQ_IF return is structured to give the Central Bank a detailed view of both your firm’s inherent AML risk exposure and the effectiveness of your AML/CFT control framework.

The AML REQ for investment firms consists of 11 sections:

1. **General: **This section captures core firm information (legal structure, group structure, LEIs, MiFID activities, international presence, statement of compliance).
2. **Inherent Risk: **This section focuses on where AML/CTF exposure exists within the business.
3. **Mitigation & Control: **This is the largest operational section of the return. It captures how your firm manages AML/CFT risk in practice.
4. **Physical Presence: **This section captures information on the jurisdictions where the firm maintains physical operations or presence.
5. **Residence and Establishment: **Focuses on customer geographic exposure, including where customers reside or are established.
6. **Beneficial Owner: **Captures data relating to beneficial ownership identification and verification.
7. **Politically Exposed Persons (PEPs): **This section focuses on exposure to PEPs, family members, and close associates.
8. **Order Execution: **Applies to firms conducting order execution activities.
9. **Portfolio Management: **Focuses on portfolio management activity, including customer segmentation, transaction activity, geography of funds flows, and high-risk exposure.
10. **Geography of Funds Flow: **Captures where funds originate from and flow to geographically.
11. **Transaction Monitoring: **This section focuses specifically on transaction monitoring frameworks and alert generation.

```json
{
  "_key": "aac4d683004d",
  "_type": "quote-v2",
  "authorName": "Pamela Crilly",
  "authorTitle": "EU COO, TrueLayer",
  "buttonLink": "https://complyfirst.co/resources/truelayer-regulatory-reporting",
  "buttonText": "Read case study",
  "colorVariant": "light",
  "image": {
    "_type": "image",
    "alt": "pamela crilly",
    "asset": {
      "_ref": "image-bc89952675e6b810210c95c2ed3982943ccabb17-415x415-jpg",
      "_type": "reference"
    }
  },
  "paddingBottom": "medium",
  "paddingTop": "medium",
  "quote": [
    {
      "_key": "6c4d12325aaf",
      "_type": "block",
      "children": [
        {
          "_key": "07c47cd300ff",
          "_type": "span",
          "marks": [],
          "text": "What truly sets Complyfirst apart is its "
        },
        {
          "_key": "04192ba6805d",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "ability to simulate a regulator’s review, "
        },
        {
          "_key": "bb44919ab787",
          "_type": "span",
          "marks": [],
          "text": "identifying potential data discrepancies or inconsistencies across multiple reports before submission."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

#### Submission Format and Validation Requirements

Now, for the reporting mechanics. 👀

The CBI requires firms to submit the AML REQ in **XML format only**, generated in line with the official XSD schema provided. Excel versions are available solely to support understanding and will not be accepted for submission.

The XML itself must comply with strict validation requirements, including correct table ordering, approved variable names, valid enumerations, mandatory field formatting, and explicit closing XML tags throughout the file structure.

Even minor technical formatting issues can result in the submission being rejected by the CBI Portal.

###### Mandatory Data Rules

This is one of the most operationally painful parts of the submission. Every field is mandatory. No blanks are allowed.

That includes fields which are not applicable.

The CBI requires firms to use the below approved placeholder values depending on field type:

```json
{
  "_key": "7268e6167e21",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-hug\" data-tb-col-color=\"blue\" data-tb-col-width=\"hug\" />\n    <col class=\"tb-col-hug\" data-tb-col-color=\"blue\" data-tb-col-width=\"hug\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue tb-nowrap\" data-tb-align=\"left\"><p>Data Type</p></th>\n      <th class=\"tb-header-blue tb-nowrap\" data-tb-align=\"left\"><p>Required Value</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Integer</p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>0</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Decimal</p><p></p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>0</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Date</p><p></p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>2000-01-01</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>String</p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>N/A</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>LEI</p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>00000000000000000000</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Country</p></td>\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>00</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

And this is where firms relying heavily on manual spreadsheet workflows are likely to experience repeated validation failures.

###### Naming Convention

Files must follow this structure:

```json
{
  "_key": "527404fc3b5a",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Element</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Example</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Institution Code</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>CCCCCC</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Reporting Date</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>YYYYMMDD</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Return Code</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>A03</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Extension</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>.xml</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

**Example:** CCCCCC_20251231_A03.xml

Here’s a walkthrough from our [AML REQ breakfast session](https://complyfirst.co/resources/briefing-2-aml-req-steps) where our CTO, Dan, breaks down the non-negotiables for completing the AML REQ:

```json
{
  "_key": "b022466b77c3",
  "_type": "resource-media",
  "mediaType": "mp4",
  "mp4File": {
    "_type": "file",
    "asset": {
      "_ref": "file-954eecb6703a464be10c84871b14ac064c66f41c-mp4",
      "_type": "reference"
    }
  }
}
```

#### So, What Do You Need to Do?

There are no shortcuts, here is what the CBI requires end-to-end.

###### Step 1: Download the REQ pack

Download the relevant REQ pack from the Central Bank of Ireland, including:

- XML template
- XSD schema
- Guidance notes

```json
{
  "_key": "c7ec5224be34",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "a867e71e17d0",
      "_type": "block",
      "children": [
        {
          "_key": "52d0f61c20fd",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "👋🏼 To help firms submitting their AML REQ, we built an AML REQ Excel template with CBI guidance built-in. Get in touch with us "
        },
        {
          "_key": "b031e07118d3",
          "_type": "span",
          "marks": [
            "bb39616870a6",
            "strong"
          ],
          "text": "here"
        },
        {
          "_key": "cb69da447134",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": " to access it."
        }
      ],
      "markDefs": [
        {
          "_key": "bb39616870a6",
          "_type": "link",
          "href": "https://complyfirst.co/demo"
        }
      ],
      "style": "normal"
    }
  ]
}
```

###### Step 2: Read the guidance notes

Review the full guidance PDF document (typically 80-120 pages):

###### Step 3: Map your firm’s data to the REQ schema

Map internal data sources to the REQ structure.

Every field:

- is mandatory
- has a strict format
- must align to the XML schema requirements

###### Step 4: Complete the REQ

Complete the return across all required sections.

This includes hundreds of fields covering:

- customers
- products and services
- jurisdictions
- transaction activity
- AML controls
- governance
- monitoring frameworks

###### Step 5: Validate against the XSD schema

The submission must validate against the official CBI XSD schema before upload. Excel won’t fly! XML only.

###### Step 6: Obtain sign-off

Complete internal governance and approvals. Typically this involves MLRO and board-level review.

###### Step 7: Upload to the Central Bank Portal

Submit the validated XML file through the Central Bank Portal **before 30th June 2026.**

###### Step 8: Keep an audit trail

The CBI will ask.

#### How Complyfirst Helps Investment Firms Submit Their AML REQ

[Complyfirst](https://complyfirst.co/) provides the [tools and support](https://complyfirst.co/reports/cbi-aml-req) for investment firms to deliver a compliant AML REQ submission, aligned to the CBI’s schema and deadlines.

**Plus, your first AML REQ is on us. We’re confident enough in the platform — and in our team — that we’ll get you through your first AML REQ submission for free.**

Here’s how we'll help:

- CBI definitions are built in-platform
- N/A codes are auto-applied in one click
- Real-time validation in plain English as you work
- Approvals and audit trail are baked in
- You get 1:1 support, even on deadline day
- Generated XML output, named & ready to upload

```json
{
  "_key": "15cd35599f1c",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "2bc9d2f80597",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "332ba5fe5f05",
          "_type": "block",
          "children": [
            {
              "_key": "3e9e6aedf493",
              "_type": "span",
              "marks": [],
              "text": "The AML Risk Evaluation Questionnaire (REQ) is a mandatory regulatory return used by the Central Bank of Ireland to assess AML, terrorist financing, and sanctions risk across investment firms. It replaces high-level narrative reporting with structured data that supports supervisory analysis, peer benchmarking, and EU-wide AML oversight."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the AML REQ and why is the Central Bank introducing it?"
    },
    {
      "_key": "67c89a63b07e",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "32e82588eb0b",
          "_type": "block",
          "children": [
            {
              "_key": "ec280128d424",
              "_type": "span",
              "marks": [],
              "text": "All Central Bank of Ireland-regulated investment firms must submit an AML REQ. This includes Irish-authorised entities and Irish branches, including firms operating under Freedom of Establishment or Freedom of Services. Each regulated legal entity submits its own return, even if part of a wider group."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Who is required to submit an AML REQ?"
    },
    {
      "_key": "5b1b4e3d8a9a",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "bcf95b5b26db",
          "_type": "block",
          "children": [
            {
              "_key": "d88cea629ce1",
              "_type": "span",
              "marks": [],
              "text": "The first AML REQ must be submitted by "
            },
            {
              "_key": "8faa51f386c5",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "30 June 2026"
            },
            {
              "_key": "32acaa098788",
              "_type": "span",
              "marks": [],
              "text": ", based on data as at "
            },
            {
              "_key": "6568f2295f42",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "31 December 2025"
            },
            {
              "_key": "cd0e27548104",
              "_type": "span",
              "marks": [],
              "text": ". This is a hard deadline, and firms should plan internal preparation and sign-off well in advance to avoid last-minute validation issues."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the submission deadline for the first AML REQ for investment firms?"
    },
    {
      "_key": "b54431c45f0c",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "7010e7af0cfd",
          "_type": "block",
          "children": [
            {
              "_key": "91bc1c107e1d",
              "_type": "span",
              "marks": [],
              "text": "The Central Bank only accepts the AML REQ in "
            },
            {
              "_key": "45818a81997b",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "XML format"
            },
            {
              "_key": "c17a6a379826",
              "_type": "span",
              "marks": [],
              "text": ", generated in line with its published XSD schema. Excel templates are provided for guidance only and cannot be submitted. Files that do not meet schema or validation requirements will be rejected."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What format must the AML REQ be submitted in?"
    },
    {
      "_key": "e893cabe57ab",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "4fd2b0213630",
          "_type": "block",
          "children": [
            {
              "_key": "fc58662affe8",
              "_type": "span",
              "marks": [],
              "text": "Yes. Every field must be completed, including fields that are not applicable. Prescribed N/A values must be used depending on field type."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Are all fields mandatory?"
    }
  ],
  "title": "FAQs"
}
```

---
Source: https://complyfirst.co/resources/investment-firms-aml-req-explained
Last updated: 2026-05-21

---

# How to Complete the FCA Safeguarding Return (REP027): A Step-by-Step Guide

> A complete guide to REP027, the FCA’s new monthly safeguarding return for UK payment and e-money institutions. Learn who it applies to, key deadlines, reporting requirements, and how to prepare before the July 2026 deadline.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: UK  
Published: 2026-05-04

```json
{
  "_key": "672851cbc37f",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

From 7 May 2026, every UK payment institution and e-money institution that safeguards customer funds has a new monthly return to submit: REP027. It’s the [first monthly regulatory return](https://complyfirst.co/resources/how-to-complete-the-fca-safeguarding-monthly-return-guide) UK PIs and EMIs have ever had to file, and the first deadline is already 21 July 2026.

The FCA XML schema has finally been published.  It’s what unlocks API-based submission and makes a repeatable monthly process actually achievable.

This guide will everything your team needs to know. What REP027 is, why it exists, who’s in scope, what you need to report section by section, and how to build a process that doesn’t fall apart by month three.

Let’s get into it!

```json
{
  "_key": "2af623ead6e3",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "4c067b38061a",
      "_type": "block",
      "children": [
        {
          "_key": "1b165612540a",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "83ad63a01f95",
      "_type": "block",
      "children": [
        {
          "_key": "33149944c645",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "What it is: "
        },
        {
          "_key": "85b1fb177edf",
          "_type": "span",
          "marks": [],
          "text": "A new standalone monthly safeguarding return submitted to the FCA via RegData"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "b075105fb3ee",
      "_type": "block",
      "children": [
        {
          "_key": "bdd228272c3f",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Who it affects: "
        },
        {
          "_key": "42bbbfd7b894",
          "_type": "span",
          "marks": [],
          "text": "All UK authorised payment institutions, e-money institutions, and any SPIs or SEMIs that have opted in to safeguarding"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "1cbed8d95ba2",
      "_type": "block",
      "children": [
        {
          "_key": "5d85c15c46c6",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "When: "
        },
        {
          "_key": "2bcd39be4121",
          "_type": "span",
          "marks": [],
          "text": "Go-live 7 May 2026. First return due 21 July 2026"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "f57f12ad9dfe",
      "_type": "block",
      "children": [
        {
          "_key": "45cc0ecb9b4d",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Frequency:  "
        },
        {
          "_key": "47b8f8e7f5c7",
          "_type": "span",
          "marks": [],
          "text": "Monthly, within 15 business days of month-end"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "fe6819027963",
      "_type": "block",
      "children": [
        {
          "_key": "c2cee8b7919a",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Why it matters: "
        },
        {
          "_key": "1abaf800d67f",
          "_type": "span",
          "marks": [],
          "text": "The first ever monthly regulatory return for UK PIs and EMIs. The FCA wants month-by-month visibility on how firms safeguard customer funds, not just an annual snapshot"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "8037194e0fe5",
      "_type": "block",
      "children": [
        {
          "_key": "a1fd80bfc63b",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Submission: "
        },
        {
          "_key": "fcd11ac1e7f0",
          "_type": "span",
          "marks": [],
          "text": "FCA RegData. Manually or via XML and API using the now-published XSD schema"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

REP027 is a standalone [monthly safeguarding return ](https://complyfirst.co/snapshot/fca-safeguarding-return)submitted to the FCA via RegData. It’s the first ever monthly regulatory return for UK payment institutions and e-money institutions.

It sits in the FCA Handbook at SUP 16.14A and Annex 29BR, introduced by FCA 2025/38, and runs alongside the new safeguarding rules in CASS 15.

The whole point of the return is to give the FCA proper visibility on how firms safeguard customer funds every month, not just a once-a-year snapshot. Annual reporting hasn’t been catching the problems that build up between periods. Monthly reporting closes that gap.

REP027 covers:

- Safeguarding method
- Balances
- Where funds are held
- Resource vs requirement
- The D+1 segregation check
- Reconciliations performed during the period
- Account-level record-keeping
- Any notifiable CASS breaches



Before REP027 submissions, safeguarding data was tucked inside broader returns like FSA056 and FIN060a. This is a completely different beast. Far more granular, standalone, and closer to a CASS-style return than anything UK PIs and EMIs have had to submit before.

```json
{
  "_key": "f624d90e6515",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/HH325NWaaso"
}
```



#### Why is REP027 Being Introduced?

REP027 is part of PS25/12, the FCA’s overhaul of the safeguarding regime. Arguably the biggest reform since the PSRs and EMRs came in.

Here’s why it got to this point:

- Safeguarded e-money balances have more than doubled to £26bn, up from £11bn in 2021
- Around 1 in 10 UK e-money holders now use these accounts for everyday spending
- Bank customers have the FSCS. Customers of PIs and EMIs don’t. They have the FCA safeguarding regime

That regime hasn’t held up. Three of the most prominent failures:



```json
{
  "_key": "5b9a471d94c5",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Milestones</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Date</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Go-live</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>7 May 2026</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>First return due</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>21 July 2026</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Reporting frequency</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Monthly</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Submission deadline</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>15 business days after month-end</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```



Each case dragged on for years. Customers recovered only a fraction of what they were owed.

And these firms aren’t outliers. Across 12 payment firm insolvencies between 2018 and 2023:

- **Average shortfall** between funds owed and funds safeguarded: 65%
- **For EMIs alone**, that figure rises to 80%



The FCA is closing the gap. And REP027 is a huge part of that.



#### What is Changing Under PS25/12?

REP027 is one of six areas PS25/12 tightens. Here is the before and after:

```json
{
  "_key": "8c0e689de721",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Area</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Before</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>After (PS25/12)</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Reconciliations</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Required under the PSRs and EMRs but no prescriptive cadence</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>One per reconciliation day (excludes weekends, bank holidays, foreign market closures), comparing safeguarding requirement vs resource. Any shortfall fixed immediately</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Separate reconciliations for e-money vs payment services</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Single safeguarding view across activities</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>E-money funds and payment services funds reconciled and safeguarded separately, so each pool is transparent in an insolvency</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Resolution packs</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>No formal requirement to maintain a single, live resolution pack</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Live document covering safeguarding accounts, custodians, agents, distributors, return-of-funds procedures, and safeguarding contracts</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Annual safeguarding audits</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>In practice, only larger firms in scope</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Almost all firms in scope (firms with under £100k safeguarded over the past 53 weeks are exempt)</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Third-party oversight</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Third-party oversight</p><p>High-level exprectations</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Detailed due diligence on banks, custodians, and insurers; documented diversification decisions; liquidity stress tests confirming 24-hour redemption capability; insurance and guarantee renewal decisions taken three months before expiry</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>FCA reporting</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Safeguarding data buried inside broader returns (FSA056, FIN060a)</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><ul><li><p>Standalone monthly return (REP027) submitted via Regdata</p></li></ul><p></p></td>\n    </tr>\n  </tbody>\n</table>"
}
```



That last row is the REP027 submission. It’s what we’re going to be diving into in this blog.



#### Who Does REP027 Apply To?

REP027 applies to all safeguarding institutions holding relevant funds under the PSRs or EMRs:

- Authorised Payment Institutions (APIs)
- E-Money Institutions (EMIs)
- Small Payment Institutions (SPIs) that have opted in to safeguarding
- Small E-Money Institutions (SEMIs) that have opted in to safeguarding

If you are an SPI or SEMI that has not opted in, REP027 does not apply. If you have opted in, even voluntarily, you are in scope.

Firms providing unrelated payment services (UPS) must also complete Sections 10 to 17. That roughly doubles the length of the return.

#### What Are the Key REP027 Deadlines?

```json
{
  "_key": "9ca1441ea50b",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-hug\" data-tb-col-color=\"blue\" data-tb-col-width=\"hug\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue tb-nowrap\" data-tb-align=\"left\"><p>Milestones</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Date</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Go-live</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>7 May 2026</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>First return due</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>21 July 2026</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Reporting frequency</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Monthly</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell tb-nowrap\" data-tb-align=\"left\"><p>Submission deadline</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>15 business days after month-end</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

The 15 business day window is where compliance teams will feel the pressure. It overlaps directly with month-end close, and the data sits across finance, ops, and compliance in different systems.

#### How is REP027 Submitted?

REP027 goes via the FCA’s RegData platform, within 15 business days of month-end. You’ve got two ways to do it:



###### **Option 1: Manual entry**

- Pull data from your systems
- Key it into RegData directly
- Fine for the first return
- Gets painful fast by the third or fourth

###### **Option 2: API or XML submission**

- Use the FCA’s published REP027 XSD schema
- Build a canned extract that auto-populates the return
- Submit to RegData via the FCA’s API
- No manual re-keying

Now that the schema’s been published, option 2 is really the no-brainer. It’s the one worth building toward.

```json
{
  "_key": "ec622706e794",
  "_type": "quote-v2",
  "authorName": "Pamela Crilly",
  "authorTitle": "EU COO, TrueLayer",
  "buttonLink": "https://complyfirst.co/resources/truelayer-regulatory-reporting",
  "buttonText": "Read case study",
  "colorVariant": "light",
  "image": {
    "_type": "image",
    "alt": "pamela crilly",
    "asset": {
      "_ref": "image-bc89952675e6b810210c95c2ed3982943ccabb17-415x415-jpg",
      "_type": "reference"
    }
  },
  "paddingBottom": "medium",
  "paddingTop": "medium",
  "quote": [
    {
      "_key": "6c4d12325aaf",
      "_type": "block",
      "children": [
        {
          "_key": "07c47cd300ff",
          "_type": "span",
          "marks": [],
          "text": "What truly sets Complyfirst apart is its "
        },
        {
          "_key": "04192ba6805d",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "ability to simulate a regulator’s review, "
        },
        {
          "_key": "bb44919ab787",
          "_type": "span",
          "marks": [],
          "text": "identifying potential data discrepancies or inconsistencies across multiple reports before submission."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

#### Which Sections of REP027 Apply to My Firm?

Not every firm fills in every section. Getting this wrong means either over-reporting or missing sections you should have completed.  


```json
{
  "_key": "6b9adfd25170",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Sections</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Who completes them</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Sections 1, 2 and 9</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Every firm in scope</p><p></p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Sections 3 to 8</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Only if you were required to safeguard during the period</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Sections 10 to 17</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Only firms providing unrelated payment services (EMIs providing UPS, SEMIs that opted in, credit unions that opted in)</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```



If your business model includes unrelated payment services, the return roughly doubles in length.



#### What Does REP027 Require You to Report?

Sections 1 to 9 are the core return:

```json
{
  "_key": "7850dfe91f75",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Section</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>What you report</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 1: Firm and category</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Firm name, category of safeguarding institution, details of your most recent safeguarding audit</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 2: Safeguarding method</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Method(s) used during the period (segregation, insurance, guarantee, or a mix), method at the time of your last internal reconciliation, number of clients safeguarded, whether you used any non-standard internal reconciliation procedure</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 3: Balances</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Highest and lowest safeguarding requirement during the period, in sterling</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 4: Where funds are held*</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>See breakdown below</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 5: Resource vs requirement</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>What you actually safeguarded across bank accounts, segregated funds not yet placed, relevant assets, and insurance or guarantee cover, compared to what you were required to safeguard. Any excess or shortfall at month-end, and what you did to fix it</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 6: D+1 segregation check</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>D+1 resource vs D+1 requirement from your last internal reconciliation, plus any adjustments made</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 7: Reconciliations</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Yes/no: did you carry out internal and external reconciliations on every reconciliation day?</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 8: Record-keeping</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Accounts at start of month, opened, closed, accounts at month-end, plus acknowledgment letter status for each. If letters are missing, you explain why</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><strong>Section 9: Notifiable CASS breaches</strong></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Anything you were required to notify the FCA about: material errors in records, failed reconciliations, unresolved discrepancies, material shortfalls between requirement and resource, insurance or guarantee cover nearing expiry (the FCA expects three months’ notice), or any other CASS 15 breach</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

****

****

***Section 4 in detail: Where funds are held**

This one varies depending on how you safeguard:

- **Segregation: **institution, account type, number of accounts, total balances, country, fixed-term or notice
- **Insurance and guarantees: **provider, coverage amoun t, expiry date, overdue premiums
- **Secure liquid assets: **asset type, custodian, value at period end

For firms providing unrelated payment services, Sections 10 to 17 repeat the same checks for that activity.

#### What Does REP027 Mean for Compliance Teams?

This is the first ever monthly regulatory return for UK PIs and EMIs. Here is where this is going to bite:

- **The cadence. **Everything else in the FCA’s calendar is quarterly, semi-annual, or annual. Monthly is a different rhythm. Most teams haven’t had to report at this frequency before and it will show.
- **The data. **Safeguarding data doesn’t sit in one place. It lives across finance, ops, and compliance. Pulling it together manually every month, inside a 15 business day window, on top of month-end close, is going to hurt.
- **The upside nobody talks about. **Get it right from day one and the monthly reporting trail feeds straight into your annual safeguarding audit. That’s the prize.



The firms that find the first deadline straightforward will be the ones building a repeatable monthly process now, not the week before it’s due.

#### How Should Compliance Teams Prepare for REP027?



```json
{
  "_key": "8dcc8cb57ef1",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Step</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Action</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Work out your scope</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><ul><li><p>Are you required to safeguard? </p></li><li><p>Did you opt in? </p></li><li><p>Do sections 10 to 17 apply to your business model?</p></li></ul><p></p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Map your data sources</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Work out where each REP027 data point currently lives. Section 4 and Section 8 tend to be the most fragmented</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Build a repeatable extract</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p><br>You’ll be doing this every month. A canned extract is the baseline. XML or API submission removes the manual re-keying entirely</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Set up maker/checker</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Build an approval workflow so every return gets reviewed before submission and there’s a record of how each figure was derived</p></td>\n    </tr>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Get the dates in the diary</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>15 business days after month-end, every month. First deadline: 21 July 2026</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Think ahead to your annual audit</p><p></p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>The monthly trail you build from day one feeds directly into your annual safeguarding audit. Get it right early and it does double duty</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

#### What Tools Are Available for REP027 Reporting?

The firms that’ll find the first deadline manageable are the ones treating this as an automation problem now, not a reporting problem in June.

The FCA’s published XSD schema is what makes that possible. It defines exactly what a valid REP027 submission looks like. With it, you can build a canned extract from your existing systems that maps directly to the return and submits to RegData automatically. Set it up once. Run it every month.





```json
{
  "_key": "6e601c6968f6",
  "_type": "html-block",
  "html": "<table class=\"tb\" data-tb-version=\"1\" data-tb-has-header=\"true\">\n  <colgroup>\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n    <col class=\"tb-col-fill\" data-tb-col-color=\"blue\" data-tb-col-width=\"fill\" />\n  </colgroup>\n  <thead>\n    <tr>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Approach</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>What it involves</p></th>\n      <th class=\"tb-header-blue\" data-tb-align=\"left\"><p>Sustainable long-term?</p></th>\n    </tr>\n  </thead>\n  <tbody>\n    <tr class=\"tb-row-even\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Manual</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Pull data from systems, key into RegData</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Honestly? No. The data is fragmented, the window is tight, and this is monthly</p></td>\n    </tr>\n    <tr class=\"tb-row-odd\">\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>API/XML</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Build a canned extract using the FCA’s XSD schema, submit via RegData API</p></td>\n      <td class=\"tb-cell\" data-tb-align=\"left\"><p>Yes. The setup takes time upfront, but then it just runs</p></td>\n    </tr>\n  </tbody>\n</table>"
}
```

#### How Does Complyfirst Help UK PIs and EMIs with REP027 Reporting?

[Complyfirst ](https://complyfirst.co/)is built specifically for UK PIs and EMIs getting ready for REP027. We’re the home of safeguarding reporting.

We sit in the middle of the monthly process so you don’t have to piece it together manually every time:

- **Works with any extract. **Excel, CSV, or any format your systems produce. We map it into the platform and auto-generate the return. No copy-pasting into report cells.
- **Validates before submission. **Every return is checked against the FCA’s REP027 XSD schema before it reaches RegData. XSD errors are caught before they become a problem.
- **[Submits via API](https://complyfirst.co/integrations/fca). **We submit directly to RegData via the FCA’s API. No keying it in.
- **Maker/checker built in. **Approval controls on every report with a full audit trail behind it. If the FCA queries how a return was prepared, you have the answer in seconds.



Get in touch to talk through your setup. And DM us if you’d like our Excel template to start mapping your data today, even if you’re not working with us.



```json
{
  "_key": "14265e33d53d",
  "_type": "resource-media",
  "mediaType": "mp4",
  "mp4File": {
    "_type": "file",
    "asset": {
      "_ref": "file-0ae3c06ba6d6d5aaef0288e156bb4cea3d1ac0fc-mp4",
      "_type": "reference"
    }
  }
}
```

```json
{
  "_key": "73407d8ce8b0",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "e37292c6fadf",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "8818851afc8a",
          "_type": "block",
          "children": [
            {
              "_key": "35f1c0d23299",
              "_type": "span",
              "marks": [],
              "text": "We hear this one a lot. And it’s the right question to be asking."
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "cf4c38c6f36c",
          "_type": "block",
          "children": [
            {
              "_key": "796b9e0f919b",
              "_type": "span",
              "marks": [],
              "text": "A big chunk of REP027 stays the same month after month:"
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "f3a52af5dab7",
          "_type": "block",
          "children": [
            {
              "_key": "46e9d03c3ab6",
              "_type": "span",
              "marks": [],
              "text": ""
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "acfe085d2865",
          "_type": "block",
          "children": [
            {
              "_key": "842fc3abf603",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Static fields (set once):"
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "c9a51afc1d8c",
          "_type": "block",
          "children": [
            {
              "_key": "d5ef4075c5dc",
              "_type": "span",
              "marks": [],
              "text": "Firm details"
            }
          ],
          "level": 1,
          "listItem": "bullet",
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "e1957599ed13",
          "_type": "block",
          "children": [
            {
              "_key": "8f83b06696d7",
              "_type": "span",
              "marks": [],
              "text": "Safeguarding method"
            }
          ],
          "level": 1,
          "listItem": "bullet",
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "6725bf3755c8",
          "_type": "block",
          "children": [
            {
              "_key": "c32c72766fc3",
              "_type": "span",
              "marks": [],
              "text": "Account structures"
            }
          ],
          "level": 1,
          "listItem": "bullet",
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "581317a7bf04",
          "_type": "block",
          "children": [
            {
              "_key": "35f68c20cbdb",
              "_type": "span",
              "marks": [],
              "text": "Acknowledgment letter status"
            }
          ],
          "level": 1,
          "listItem": "bullet",
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "c261f5e2a862",
          "_type": "block",
          "children": [
            {
              "_key": "0026acb14889",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Variable fields (pulled each period):"
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "c3dbd9cf2c2c",
          "_type": "block",
          "children": [
            {
              "_key": "dedf1395e684",
              "_type": "span",
              "marks": [],
              "text": "Balances"
            }
          ],
          "level": 1,
          "listItem": "bullet",
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "0df53ff27ff6",
          "_type": "block",
          "children": [
            {
              "_key": "0859c7c0b9a1",
              "_type": "span",
              "marks": [],
              "text": "Reconciliation outputs"
            }
          ],
          "level": 1,
          "listItem": "bullet",
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "0e04e5e3f425",
          "_type": "block",
          "children": [
            {
              "_key": "61dae964f842",
              "_type": "span",
              "marks": [],
              "text": "Any shortfalls"
            }
          ],
          "level": 1,
          "listItem": "bullet",
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "b290720b556d",
          "_type": "block",
          "children": [
            {
              "_key": "58b514386ca0",
              "_type": "span",
              "marks": [],
              "text": ""
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "68f587540963",
          "_type": "block",
          "children": [
            {
              "_key": "9857de7b600c",
              "_type": "span",
              "marks": [],
              "text": "The answer is a pre-canned extract with data mapping built in. You set the static fields once. The extract carries them forward. You only pull in what changes each period. That’s exactly how ComplyFirst works. Map your data once, lock down the static fields, refresh the variables. This means the monthly process takes minutes, not days."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "REP027 contains a lot of static data that doesn’t change month to month. How do we automate it?"
    },
    {
      "_key": "c2437e708f71",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "5c6bbe0626bb",
          "_type": "block",
          "children": [
            {
              "_key": "064b7ab1a7fc",
              "_type": "span",
              "marks": [],
              "text": "You report it in Section 5 and fix it immediately under PS25/12. If it’s a material CASS 15 breach, it also goes in Section 9."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What happens if there’s a shortfall in safeguarded funds?"
    },
    {
      "_key": "73373fe2c2ba",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "2d95396e3064",
          "_type": "block",
          "children": [
            {
              "_key": "347254905d06",
              "_type": "span",
              "marks": [],
              "text": "No. Sections 1, 2 and 9 apply to everyone in scope. Sections 3 to 8 only if you safeguarded during the period. Sections 10 to 17 only if you provide unrelated payment services."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Do I need to complete all 17 sections of REP027?"
    },
    {
      "_key": "6a343d3026bf",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "a21939c6be4a",
          "_type": "block",
          "children": [
            {
              "_key": "6ba89fb33c0e",
              "_type": "span",
              "marks": [],
              "text": "Section 6 asks for your D+1 resource vs D+1 requirement from your last internal reconciliation. Basically, what you held in safeguarding accounts the day after your reconciliation versus what you were required to hold at that point."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the D+1 segregation check in REP027?"
    }
  ],
  "title": "FAQ"
}
```

---
Source: https://complyfirst.co/resources/how-to-complete-the-fca-safeguarding-return-rep027-a-step-by-step-guide
Last updated: 2026-06-12

---

# FCA PS25/12 Explained: What the New Safeguarding Regime Means for PIs and EMIs

> Stay ahead of the FCA’s new safeguarding rules under PS25/12. Learn how annual audits and monthly RegData reporting will impact EMIs and payment institutions from May 2026, and how to prepare.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: UK  
Published: 2026-04-10

```json
{
  "_key": "a2d0368165e7",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

The UK Financial Conduct Authority (FCA) has introduced new safeguarding rules for _all_ e-money institutions and payment institutions operating in the UK.

Previously, safeguarding audits applied only to larger EMIs, and safeguarding information formed a small part of a broader regulatory submission. As a result, the FCA had limited insight into how smaller firms safeguarded money day-to-day.

FCA PS25/12 changes this.

From **7 May 2026**, all UK EMIs and PIs that safeguard funds must complete an **annual safeguarding audit**, and all firms will begin submitting a **dedicated [monthly safeguarding return](https://complyfirst.co/snapshot/fca-safeguarding-return)** through RegData (report code REP027).

But verifying that these changes are being applied correctly in practice isn’t going to be an easy feat.

For compliance teams, this mainly means more frequent reporting and more structure around safeguarding data.

Let’s dive in to the main changes EMIs and PIs need to be aware of.

```json
{
  "_key": "ddaad34dc6a5",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "16a59b21242d",
      "_type": "block",
      "children": [
        {
          "_key": "80806e6ffd8a",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "ca593d20afb4",
      "_type": "block",
      "children": [
        {
          "_key": "8ba220cea22b",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "What it is:"
        },
        {
          "_key": "a4aa2e6d6e73",
          "_type": "span",
          "marks": [],
          "text": " New FCA safeguarding rules introducing annual audits and a monthly safeguarding return via RegData."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "578df0070913",
      "_type": "block",
      "children": [
        {
          "_key": "e04fc51130a5",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Who it affects: "
        },
        {
          "_key": "6be4cca9f105",
          "_type": "span",
          "marks": [],
          "text": "All UK-authorised e-money institutions and payment institutions."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "bc00def36202",
      "_type": "block",
      "children": [
        {
          "_key": "bef024073a73",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Why it matters: "
        },
        {
          "_key": "44ec654a1cc1",
          "_type": "span",
          "marks": [],
          "text": "Safeguarding is the main protection for customer funds, and firms must now report it accurately every month."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

#### What Exactly are the New FCA Safeguarding Rules?

Let’s start with recapping what safeguarding means in practice.

Safeguarding requires firms to hold customer funds in a separate, protected account so that the money remains isolated from the firm’s own assets. This way, if a firm collapses, safeguarded customer funds should be returned quickly to customers (as they are not used for business operations).

With the PS25/12 coming into effect from May 2026, the FCA has two major objectives: expanding who must undergo an **annual** **audit,** and who must submit a **monthly return, **to have more oversight into how firms safeguard funds day-to-day**.**

Here’s an overview of the FCA’s annual audit and monthly return:

```json
{
  "_key": "f33c1b44bbe0",
  "_type": "table",
  "rows": [
    {
      "_key": "9fda7c9a-91b8-4e1f-9abf-ebe21288dcbf",
      "_type": "tableRow",
      "cells": [
        "",
        "Safeguarding Audit",
        "Safeguarding Return"
      ]
    },
    {
      "_key": "9109080e-2b42-49fc-bb35-2dc0b8866ee1",
      "_type": "tableRow",
      "cells": [
        "What changed",
        "Audit requirement now applies to all EMIs and PIs, not just larger EMIs.",
        "Safeguarding data is no longer a small section of another return (e.g., FSA056). It becomes a standalone monthly report with expanded fields."
      ]
    },
    {
      "_key": "9a1c8e3c-f400-4b12-ad74-dbbd68c06851",
      "_type": "tableRow",
      "cells": [
        "Purpose",
        "To independently verify that firms segregate customer funds correctly, perform reconciliations accurately, and maintain complete safeguarding records.",
        "To give the FCA ongoing visibility of safeguarded balances, reconciliation outcomes, and where customer funds are held."
      ]
    },
    {
      "_key": "a722447e-15b0-4211-804a-aae7ebfa96e8",
      "_type": "tableRow",
      "cells": [
        "Frequency",
        "Annually, with the first audit due within 6 months of the firm’s first year-end after 7 May 2026 (4 months in following years).",
        "Monthly, submitted through RegData once the FCA finalises the schema."
      ]
    }
  ]
}
```

```json
{
  "_key": "5e043eae6730",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/HH325NWaaso"
}
```

#### Who is in Scope?

The return applies to all firms that are required to safeguard customer funds, including:

- E-money institutions (EMIs)
- Authorised payment institutions (APIs)
- Small payment institutions (SPIs) that have opted in
- Small e-money institutions (SEMIs) that have opted in

The return covers relevant funds safeguarded under the PSRs and EMRs.

All firms must complete sections 1–9. Sections 10–17 apply only where firms provide unrelated payment services, such as EMI + UPS models or opted-in credit unions.

#### Timing, Frequency, and Submission

The new rules go live on **7 May 2026**.

The return must be submitted **monthly**, within **15 business days after month-end**, via the FCA’s **RegData** platform. The first return is expected to be due on **21 July 2026**, based on the initial reporting period.

Returns can be keyed directly into RegData or submitted using XML or API-based automation (we can help! 😉).



```json
{
  "_key": "ec622706e794",
  "_type": "quote-v2",
  "authorName": "Pamela Crilly",
  "authorTitle": "EU COO, TrueLayer",
  "buttonLink": "https://complyfirst.co/resources/truelayer-regulatory-reporting",
  "buttonText": "Read case study",
  "colorVariant": "light",
  "image": {
    "_type": "image",
    "alt": "pamela crilly",
    "asset": {
      "_ref": "image-bc89952675e6b810210c95c2ed3982943ccabb17-415x415-jpg",
      "_type": "reference"
    }
  },
  "paddingBottom": "medium",
  "paddingTop": "medium",
  "quote": [
    {
      "_key": "6c4d12325aaf",
      "_type": "block",
      "children": [
        {
          "_key": "07c47cd300ff",
          "_type": "span",
          "marks": [],
          "text": "What truly sets Complyfirst apart is its "
        },
        {
          "_key": "04192ba6805d",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "ability to simulate a regulator’s review, "
        },
        {
          "_key": "bb44919ab787",
          "_type": "span",
          "marks": [],
          "text": "identifying potential data discrepancies or inconsistencies across multiple reports before submission."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



#### How FCA Safeguarding Reporting Works in Practice

In practice, safeguarding reporting is a [repeatable monthly process](https://complyfirst.co/resources/how-to-complete-the-fca-safeguarding-monthly-return-guide) that sits alongside month-end close.

Each month, firms will calculate how much customer money should be safeguarded, confirm where those funds are held, and reconcile customer liabilities against safeguarding accounts. The return then records whether safeguarding requirements were met at all times, including on a **D+1 basis **where required.

Any shortfalls, excesses, adjustments, or notifiable issues must be identified and explained. Over time, this creates a consistent audit trail that feeds directly into the annual safeguarding audit.

#### What Information Firms Need to Report

Now, on to the data fields you’ll need to collect. If you were required to safeguard during the period, sections 1-9 apply:

Now on to the data fields you’ll need to collect.

If you were required to safeguard during the period, **sections 1–9 apply**:

###### Basic set-up

Your firm name, category of safeguarding institution, and details on your last safeguarding audit.

###### Safeguarding method

If you were in scope for safeguarding, what method did you use (segregation, insurance/guarantee, or some combination), the number of clients you safeguarded for, and any use of non-standard internal reconciliation procedures during the period.

###### Balances

Simply your highest and lowest safeguarding requirement during the period.

###### Where funds are held

- **If segregation is used:**  
The institution where funds are held, the type of account, number of accounts, total amounts held, country, and whether the contract is fixed-term or has a notice period.
- **For insurances/guarantees:**  
Name of insurer or guarantor, amount covered, date of expiry, and total overdue premiums.
- **For investment in secure liquid assets:**  
The asset type, name of custodian, and total value of assets held at the end of the period.

###### Resource vs requirement

You report what you’ve actually safeguarded across bank accounts, segregated funds not yet placed, relevant assets, and any insurance/guarantee cover.

Then you compare that to what you should be safeguarding (including any amounts received but unallocated to an individual client).

Then you work out whether you had an excess or shortfall at month-end and disclose what you did to fix it.

###### The D+1 (Day plus 1) segregation check

You report your requirement vs resource from your last internal reconciliation, along with any adjustments made.

###### Reconciliations

Did you carry out:

- Internal reconciliations using your own records every reconciliation day?
- External reconciliations using external evidence (e.g. bank statements)?

###### Record-keeping

This is your inventory of all safeguarding accounts and assets, including:

- How many accounts you had at the start of the month
- How many you opened
- How many you closed
- How many you had at the end of the month

Then you confirm how many of those accounts are covered by an acknowledgment letter, and if letters are missing, explain why.

###### Notifiable breaches

This is where the FCA is basically asking: did anything happen this month that you were required to notify them about under CASS, for example:

- Material errors in records — materially out of date, inaccurate, or invalid
- Failed reconciliations — you can’t perform the required internal/external reconciliations
- Unresolved discrepancies — you’re unable to fix shortfalls or excess after reconciliation
- Material shortfalls — a material difference between safeguarding requirement vs resource
- Insurance/guarantee — about to expire without replacement lined up (you need to tell the FCA three months in advance)
- Any other breach of duty under CASS 15

For firms providing unrelated payment services i.e. payment services unrelated to the issuance of e-money, you repeat the same checks as above in sections 10-17.

EMIs who provide UPS, SEMI opt-in and credit union opt-ins may have to complete this section.

#### Complyfirst Supports Monthly FCA Safeguarding Reporting

In practice, the biggest impact is the shift to regular reporting. Safeguarding data often sits across finance, operations, and compliance teams, and monthly reporting requires tighter coordination between those groups.

Month-end is already a busy period. Adding a safeguarding return means processes need to be repeatable, reconciliations need to be reliable, and last-minute fixes need to be kept to a minimum. _This is where we can help._

Here’s how [Complyfirst](https://complyfirst.co/) can help pick up the monthly load:

###### Direct API Integration with FCA RegData

Complyfirst has a direct [**API integration with the FCA RegData platform**.](https://complyfirst.co/integrations/fca)

This means:

- No manual keying of fields line by line into RegData
- No re-entering data already reconciled internally
- No duplication between internal reports and FCA submission

Instead, safeguarding data flows directly into the FCA reporting format via system integration.

###### What This Enables in Practice

Because submission is integrated rather than manual, firms will benefit from:

- Automated safeguarding data collection
- Built-in **data validation and error checks **before submission
- Accurate **RegData-ready XML generation**
- Clear **review, sign-off, and version control** processes
- **Responsive support** during month-end madness



```json
{
  "_key": "2876bd96ccda",
  "_type": "resource-media",
  "mediaType": "mp4",
  "mp4File": {
    "_type": "file",
    "asset": {
      "_ref": "file-0ae3c06ba6d6d5aaef0288e156bb4cea3d1ac0fc-mp4",
      "_type": "reference"
    }
  }
}
```

```json
{
  "_key": "aa0b6a9f2bd9",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "8f5997e3f662",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "ea8ea2c8d836",
          "_type": "block",
          "children": [
            {
              "_key": "fec7614abda1",
              "_type": "span",
              "marks": [],
              "text": "Firms should start by confirming whether they are required to safeguard customer funds and which parts of the monthly return apply to their business model. From there, preparation mainly involves making safeguarding a repeatable month-end process. This includes standardising customer funds calculations, tightening reconciliations to safeguarding accounts, assigning clear data ownership across finance and operations, and planning for submission within 15 business days. Firms should also ensure records and evidence are retained, as monthly reporting feeds directly into the annual safeguarding audit."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "How should firms prepare for the FCA safeguarding rules coming into force in May 2026?"
    },
    {
      "_key": "b57b676d12a3",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "79728630877a",
          "_type": "block",
          "children": [
            {
              "_key": "2639a5d5d5fa",
              "_type": "span",
              "marks": [],
              "text": "The FCA PS25/12 safeguarding regime is the updated framework governing how e-money institutions and payment institutions protect and report on customer funds. It introduces a mandatory annual safeguarding audit for all firms and a new standalone monthly safeguarding return submitted via RegData. The regime is designed to give the FCA regular visibility of safeguarding arrangements, following failures in the sector, and applies to firms safeguarding relevant funds under the Payment Services Regulations and Electronic Money Regulations."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the FCA PS25/12 safeguarding regime?"
    },
    {
      "_key": "c8142706dc40",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "6a50e2f5794a",
          "_type": "block",
          "children": [
            {
              "_key": "3870d4c6fa5b",
              "_type": "span",
              "marks": [],
              "text": "The FCA is expanding safeguarding audits to ensure consistent assurance across all EMIs and PIs, not just larger firms. Past failures and limited visibility of smaller institutions highlighted gaps in oversight. By requiring all firms to undergo an annual audit, the FCA can independently verify segregation and safeguarding controls and reduce the risk of customer loss in firm failure."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Why is the FCA expanding safeguarding audits?"
    },
    {
      "_key": "94dc2902f57f",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "12fbaf012fad",
          "_type": "block",
          "children": [
            {
              "_key": "7ab454c0fb05",
              "_type": "span",
              "marks": [],
              "text": "The new FCA safeguarding rules apply from 7 May 2026. From this date, firms must follow the updated safeguarding framework, including preparing for the new monthly safeguarding return. The first monthly return is due 21 July 2026."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "When do the new FCA safeguarding rules apply?"
    }
  ],
  "title": "FAQ"
}
```

#### Conclusion

The FCA’s safeguarding changes are mainly about consistency. By moving to monthly reporting, the FCA gains regular visibility of how customer funds are protected. For EMIs and payment institutions, the focus now is on setting up clear, repeatable processes so safeguarding reporting becomes part of the normal month-end cycle, rather than a recurring disruption.

---
Source: https://complyfirst.co/resources/fca-ps25-12-explained-what-the-new-safeguarding-regime-means-for-pis-and-emis
Last updated: 2026-06-12

---

# Instant Payments Regulation (IPR) Reporting: What EU PSPs Must Submit by 9 April 2026

> EU Instant Payments Report (IPR) explained: reporting scope, 4-year backfill, entity-level obligations, and what PSPs need to prepare for the 9 April 2026 deadline.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: EU  
Published: 2026-04-02

```json
{
  "_key": "96456aecf398",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

## What is the Instant Payments Report (IPR)?

The Instant Payments Report (IPR) is a supervisory statistical return requiring aggregated data on SEPA Instant usage (i.e. volumes, values and operational metrics relating to instant transfers) that must then be submitted to a firm’s national competent authority.



The key point of the IPR is that regulators want transparency on how instant payments are priced and how often they are rejected, especially due to sanctions screening.



And the first submission, due **9 April 2026**, requires **four historical reports in one go (2022–2025)**, which is where the reporting workload really racks up.



Submission is:

- Via your relevant NCA reporting portal (e.g., Central Bank of Ireland Portal)
- In **XBRL format**
- Due annually by **9 April**



It’s also important to note that this is _entity-level_ reporting under **Article 15(3) of Regulation (EU) No 260/2012**. We’ll come back to this further down the blog on why this is an important consideration.

```json
{
  "_key": "8d800e02e08d",
  "_type": "resource-media",
  "image": {
    "_type": "image",
    "alt": "ipr submission",
    "asset": {
      "_ref": "image-72b07c352917996ae6c06554a80f7af2afbc01d1-1763x117-png",
      "_type": "reference"
    }
  },
  "mediaType": "image"
}
```

```json
{
  "_key": "b59a0fa8422b",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "08fecfe36b7a",
      "_type": "block",
      "children": [
        {
          "_key": "19aa29aa9282",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "5aa652fb7f0b",
      "_type": "block",
      "children": [
        {
          "_key": "ec1d637eae28",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "What changed:"
        },
        {
          "_key": "b103989bef10",
          "_type": "span",
          "marks": [],
          "text": " PSPs offering SEPA Instant Credit Transfers must submit a new "
        },
        {
          "_key": "cf71f8e8cc5d",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Instant Payments Report (IPR)"
        },
        {
          "_key": "e3547a4033e0",
          "_type": "span",
          "marks": [],
          "text": " under the EBA’s draft ITS on uniform reporting."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "c3769ec8bd04",
      "_type": "block",
      "children": [
        {
          "_key": "3128be868b42",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Who is affected:"
        },
        {
          "_key": "9aac9cb32f58",
          "_type": "span",
          "marks": [],
          "text": " Banks, Payment Institutions (PIs) and E-Money Institutions (EMIs) providing SEPA Instant services across the EU."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "0e61631dfe7b",
      "_type": "block",
      "children": [
        {
          "_key": "c0507d3c3bd4",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "When:"
        },
        {
          "_key": "0d4dd3a2539f",
          "_type": "span",
          "marks": [],
          "text": " First submission due "
        },
        {
          "_key": "af238d50ed75",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "9 April 2026"
        },
        {
          "_key": "72cf1213fcd9",
          "_type": "span",
          "marks": [],
          "text": ", including multi-year backfill data (26 October 2022 – 31 December 2025)."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "2f6b0a0009be",
      "_type": "block",
      "children": [
        {
          "_key": "812ff7cce57d",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Why it matters:"
        },
        {
          "_key": "c2179696df7f",
          "_type": "span",
          "marks": [],
          "text": " For the first time, regulators get a consistent, EU-wide view of how instant payments are being used, priced, and controlled. In practice, that means they can benchmark you against peers on things like instant payment fees and sanctions-related rejection rates."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



## Scope: Who Must Report?

  
Let’s first clarify applicability.

You are in scope if:

- You are a **PSP in a euro Member State**, or
- You are a **PSP in a non-euro Member State offering euro credit transfers**,
- And you provide **SEPA Credit Transfers (SCT) and/or SEPA Instant Credit Transfers (SCT Inst).**

This includes:

- Credit institutions
- Payment Institutions
- E-Money Institutions

The trigger is activity-based.

If you provide SCT Inst, you are in scope.



## What are the Backfill Requirements?

This is where the bulk of effort sits for your first IPR submission.

Your first submission requires you to reconstruct and report **historical SEPA Instant data back to October 2022** in a structured, regulator-ready format.

It must include aggregated data for:

```json
{
  "_key": "02474a73a698",
  "_type": "table",
  "rows": [
    {
      "_key": "e824625e-a4cc-4f3a-986a-4e93f8d7ee07",
      "_type": "tableRow",
      "cells": [
        "Period Covered",
        "Reporting Requirement"
      ]
    },
    {
      "_key": "e108860f-13a9-4cae-91ab-9720617145db",
      "_type": "tableRow",
      "cells": [
        "26 October 2022 – 31 December 2022",
        "Aggregated data"
      ]
    },
    {
      "_key": "19af5923-55d7-4618-9f84-bbb6513a8045",
      "_type": "tableRow",
      "cells": [
        "1 January 2023 – 31 December 2023",
        "Annual aggregates"
      ]
    },
    {
      "_key": "460e3c8d-65d1-4af9-9ab9-13fc8d4f19dc",
      "_type": "tableRow",
      "cells": [
        "1 January 2024 – 31 December 2024",
        "Annual aggregates"
      ]
    },
    {
      "_key": "f6a1e689-f475-469d-8924-d8a25a1b88c6",
      "_type": "tableRow",
      "cells": [
        "1 January 2025 – 31 December 2025",
        "Annual aggregates"
      ]
    }
  ]
}
```

In other words:

**Year one = four reporting periods.**

From 2027 onward, submissions will cover the **preceding calendar year only**.

So what does that mean in practice?

If you offer SEPA Instant today, you need to extract and structure historical data going back to October 2022. After this initial backfill cycle, reporting becomes annual.



## Home vs Host Reporting (Where Reporting Load Can Quickly Add Up)

Article 15(3) reporting is aligned with ECB statistical approaches, and the rule is clear:

- **Parent entities report to their home Member State authority.**
- **Branches report to the competent authority in their host Member State.**

In plain English, this means that if you operate cross-border, you may file multiple reports.

Example of how the impact of the IPR report stacks up quickly:

- Parent PI authorised in Malta → reports to the **MFSA (home)**.
- Branches in Germany, Spain, Italy, France → each branch reports to its **host NCA**.

Translation: potentially multiple submissions for the same group.

If you have:

- 5 regulated entities
- 4 years of backfill

You are not filing one report.

You may be filing **20 reports in year one**.

That is where the operational load sits and what firms need to be aware of.  


```json
{
  "_key": "192f51ad7ac0",
  "_type": "resource-media",
  "image": {
    "_type": "image",
    "alt": "example of ipr home vs host reporting",
    "asset": {
      "_ref": "image-e5674301eb55a0ee2c07fe7e1b33dab267c39dfb-2196x1224-png",
      "_type": "reference"
    }
  },
  "mediaType": "image"
}
```

## What Exactly Needs to be Reported? (Filling out the Core Templates)

There are **four core templates** (six if including non-euro member state firms): volumes, charges, accounts, and sanctions. 



```json
{
  "_key": "55b628fa8ff5",
  "_type": "table",
  "rows": [
    {
      "_key": "97bd5420-3157-40a9-a9e3-cfff87c1de97",
      "_type": "tableRow",
      "cells": [
        "Template",
        "Description"
      ]
    },
    {
      "_key": "4400e88e-a54c-4542-952e-8cc170f15d56",
      "_type": "tableRow",
      "cells": [
        "Template 1.1 – Volumes",
        "SCT + SCT Inst transfers sent/received, transaction counts and total values, split by national vs cross-border."
      ]
    },
    {
      "_key": "5ca82ac3-86cf-43ff-9cc4-85c6813a481d",
      "_type": "tableRow",
      "cells": [
        "Template 2.1 – Charges",
        "Fees charged for SCT + SCT Inst sent/received, split by national vs cross-border"
      ]
    },
    {
      "_key": "34469a80-2b73-4dae-a237-ac7dda6f8b9e",
      "_type": "tableRow",
      "cells": [
        "Template 3 – Accounts",
        "Total number of payment accounts and total account charges (incl. maintenance fees)"
      ]
    },
    {
      "_key": "88128c02-f9d1-458f-a675-e5d38ec63070",
      "_type": "tableRow",
      "cells": [
        "Template 4 – Sanctions",
        "Number and % of SCT Inst rejected/frozen due to sanctions screening, split national vs cross-border"
      ]
    }
  ]
}
```



Importantly, the templates are linked, so totals and splits must reconcile across them. Supervisors will cross-check.

## Steps to Submitting Your IPR

#### 1. Assign Ownership (Entity vs Branch Reporting)

Start with reporting accountability, as in who submits to which authority, i.e. **licensed entities report to their home regulator, branches report to their host regulator.**

In practice:

- Legal entities report to their **home state regulator** (e.g. CBI, FCA)
- Branches report to the **local host regulator** where they operate

**What you need to do:**

- Map each reporting entity and branch
- Confirm regulator ownership per entity
- Align data flows to reporting responsibility

#### 2. Separate Sanctions-Related Failures from Other Rejections

Next, focus on data classification. Firms must distinguish transaction outcomes, i.e.** sanctions-related rejections vs operational or technical failures.**

You need to clearly separate:

- Payments **rejected or frozen due to sanctions screening**
- Payments **failed for other reasons** (e.g. technical errors, insufficient funds)

**What you need to do:**

- Review how rejection reasons are captured today
- Standardise classification logic across systems
- Ensure sanctions-related outcomes are clearly identifiable
- Validate historical consistency (back to 2022)

The regulator will expect clean separation and clear logic.

#### 3. Run the Backfill

This is the step most firms underestimate.

You are not submitting one year of data. You are submitting **multiple years for your first submission**.

So you need to:

- Run full historical extraction
- Test aggregation logic across all periods
- Identify gaps or inconsistencies
- Reconcile outputs against known volumes

## Make IPR Submissions Easy with Complyfirst

[Complyfirst](https://complyfirst.co/) supports IPR submissions from entity-level reporting and data mapping to continuous validation, XBRL generation, and 1:1 support when you need us.

#### Here’s how we can help:

- Map **entity vs branch reporting** correctly, aligned to **NCA guidance** for backfill submissions
- Support multi-source data ingestion (payments, sanctions, core systems)
- Real-time data validation with clear “how-to-fix-it” steps
- Generate submission-ready XBRL files aligned to NCA taxonomies
- DM us for 1:1 support and get a response in <1hour (yes, even on deadline day).

For a full snapshot of the IPR, you can also watch a video snippet below from Fiona’s [EU webinar session](https://complyfirst.co/resources/eu-webinar-major-regulatory-and-tax-reporting-changes-in-2026), or download a full PDF snapshot right [here](https://complyfirst.co/snapshot/instant-payments-report).

```json
{
  "_key": "b2d3af75b78e",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/IFdYO7KLR8Y"
}
```

```json
{
  "_key": "b949f5acf054",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "29bcd3ef0853",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "4d1d21114131",
          "_type": "block",
          "children": [
            {
              "_key": "cab7b4796353",
              "_type": "span",
              "marks": [],
              "text": "The Instant Payments Regulation (EU) is an EU law that amends the SEPA Regulation to standardise and expand the use of instant euro payments across the EU. As part of this, it introduces new obligations for PSPs, including requirements on pricing parity, payment processing timelines, and annual reporting under Article 15(3) to give regulators visibility into instant payment usage, charges, and sanctions-related rejections."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the new Instant Payment Regulation?"
    },
    {
      "_key": "39913684a530",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "82ac7fc4f39d",
          "_type": "block",
          "children": [
            {
              "_key": "5e71fcbcfd66",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "Yes."
            },
            {
              "_key": "bc8d89397905",
              "_type": "span",
              "marks": [],
              "text": " If you offer SCT/SCT Inst to customers, you’re in scope and must report even if settlement is done via a partner bank."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "We’re a PI/EMI and our partner bank settles the credit transfers, are we in-scope?"
    },
    {
      "_key": "aaa62bb59605",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "8fb28f30e9a2",
          "_type": "block",
          "children": [
            {
              "_key": "a7222ac4baea",
              "_type": "span",
              "marks": [],
              "text": "Yes, the four templates are interlinked, but a bit lighter than DORA. Templates reconcile on totals (SCT vs SCT Inst) and splits (national vs cross-border), but it’s not a beast like DORA (15 interlinking tables!)."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Is this EBA report inter-linked like the DORA return?"
    },
    {
      "_key": "2c794e464d91",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "6f51a8420b58",
          "_type": "block",
          "children": [
            {
              "_key": "390a22a699d6",
              "_type": "span",
              "marks": [],
              "text": "Regulators will use it to spot hidden instant-payment charges and/or abnormally high sanctions rejects/freezes, then benchmark you against peers and challenge outliers."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What will regulators actually use this data for?"
    }
  ],
  "title": "FAQs"
}
```

## Conclusion

The instant Payment Report is a multi-year data reconstruction exercise combined with ongoing supervisory reporting. With four years of backfill, entity-level obligations, and potential duplication across home and host authorities, the reporting workload stacks up quickly. The real work lies in getting this data aligned. The key is getting your data structured correctly for the first submission so you’re not reinventing the process each year.

---
Source: https://complyfirst.co/resources/instant-payments-regulation-ipr-reporting-what-eu-psps-must-submit-by-9-april-2026
Last updated: 2026-04-02

---

# New EBA Instant Payments Report: What firms need to know  before 9 April

> Together with Financial InnovateHER, Fiona and Dan covered what to look out for and how to complete your IPR submission (each tab step-by-step).

Jurisdiction: EU  
Published: 2026-04-01

```json
{
  "_key": "a62fd03a3356",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/jtEPFQaR2x8"
}
```

In partnership with Sinead Halhed-Moran Walsh, founder of Financial InnovateHER, Fiona and Dan break down everything you need to know about the EBA's new Instant Payments Report. 



They covered some grenades to look out for 💣 and how to complete this report (each tab step-by-step).



```json
{
  "_key": "2c392d9e309c",
  "_type": "resource-quick-links",
  "links": [
    {
      "_key": "41536c197195",
      "_type": "linkItem",
      "title": "Webinar Slides",
      "url": "https://complyfirst.co/resources/files/ipr-webinar-slides"
    },
    {
      "_key": "c9b7facbc78a",
      "_type": "linkItem",
      "title": "EBA technical standards",
      "url": "https://www.eba.europa.eu/publications-and-media/press-releases/eba-publishes-its-draft-final-technical-standards-reporting-data-charges-credit-transfers-and"
    },
    {
      "_key": "6eb848756175",
      "_type": "linkItem",
      "title": "IPR Snapshot",
      "url": "https://complyfirst.co/resources/files/reporting-snapshot-ipr"
    }
  ],
  "title": "More Resources"
}
```

---
Source: https://complyfirst.co/resources/new-eba-instant-payments-report-what-firms-need-to-know-before-9-april
Last updated: 2026-04-01

---

# CPC 2026: Are you ready? A practical session for PIs & EMIs

> Webinar on Ireland’s new Consumer Protection Code (CPC): CBI expectations, common myths, and a practical look at how firms can operationalise the requirements.

Jurisdiction: Ireland  
Published: 2026-03-10

```json
{
  "_key": "abf24b48b9a3",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/f5P0rlA7IU4"
}
```

In this webinar, Fiona is joined by Nora Beausang (Senior Financial Services Regulatory Expert, Simmons & Simmons) to walk through the CBI's updated **Consumer Protection Code (CPC)**. Together, they covered:

****

- **What the Central Bank is saying about consumer protection** in its latest _Regulatory & Supervisory Outlook Report_, published on 26 February.
- **A quick overview of the new CPC** and a discussion of some of the most common myths.
- **A short product demo of the Simmons & Simmons CPC tool**, showing how firms can operationalise the requirements in practice.

```json
{
  "_key": "4bcd8ee4c49d",
  "_type": "resource-quick-links",
  "links": [
    {
      "_key": "6add67de1a33",
      "_type": "linkItem",
      "description": "CPC 2026: Are you ready?\u000bA practical session for PIs & EMIs",
      "title": "Webinar Slides",
      "url": "https://complyfirst.co/resources/files/cpc-2026-are-you-ready-a-practical-session-for-pis-emis"
    }
  ],
  "title": "More Resources"
}
```

---
Source: https://complyfirst.co/resources/cpc-2026-are-you-ready-a-practical-session-for-pis-and-emis
Last updated: 2026-03-12

---

# How to Complete the FCA Safeguarding Monthly Return (Guide for APIs, EMIs, SPIs and SEMIs)

> Guide to the FCA’s new monthly safeguarding return for UK EMIs, APIs and SPIs, covering scope, required data fields, RegData submission deadlines and practical steps.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: UK  
Published: 2026-02-20

```json
{
  "_key": "f87d55d6f21e",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

#### The Bigger Picture: FCA Safeguarding Reform

Before we zoom into the “how-to’s” of the monthly return, it’s worth stepping back on the bigger safeguarding changes happening around it.

The new safeguarding regime goes live on **7 May**, and it’s basically the biggest overhaul of safeguarding rules since the PSRs and EMRs came into force.

It’s been driven by some high-profile firm failures, including **Ipagoo in 2019**, which exposed issues like poor record-keeping, years of delays, and customers recovering less than half of their funds.

So the FCA is trying to close those gaps, and the direction of travel is tighter controls, more evidence, and more frequent reporting.

So what does that actually look like in practice? Let’s break it down.

```json
{
  "_key": "f1e22601abd3",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "a56e51f87bd9",
      "_type": "block",
      "children": [
        {
          "_key": "bffbdb39c2f9",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "6d8a14b0e507",
      "_type": "block",
      "children": [
        {
          "_key": "b8025fc4a9ec",
          "_type": "span",
          "marks": [],
          "text": "The FCA’s new monthly safeguarding return requires UK APIs, EMIs, SPIs and certain SEMIs to submit detailed information on how relevant funds are safeguarded under the PSRs and EMRs. The return covers safeguarding methods, balances, reconciliations, record-keeping, breaches and resource-vs-requirement comparisons, and must be submitted via RegData within 15 business days of month-end. Firms should now assess scope, confirm which sections apply, and implement repeatable monthly reporting processes ahead of the new regime effective 7 May 2026."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

#### Five Core Safeguarding Changes

At a high level, the FCA is tightening safeguarding across **five key areas**:

- **Daily reconciliations:** The FCA expects reconciliations at least once on each “reconciliation day” rather than every business day, comparing safeguarding requirements vs safeguarding resource, i.e. what you should be holding vs the amount actually sitting in accounts.
- **Resolution packs:** These must be maintained as a live document containing: all safeguarding accounts and custodians, a list of agents and distributors, step-by-step procedures for returning funds, and copies of safeguarding contracts.
- **Annual safeguarding audits:** These must be completed for most firms (unless safeguarded funds are under £100k over the past 53 weeks). The auditor must be qualified and have safeguarding experience. The first audit is due within six months of period end, then four months thereafter.
- **Stronger third-party oversight:** Firms are expected to manage who holds their safeguarded funds and/or how funds are invested, and what you’ll do if insurances or guarantees lapse, with documented decisions and the ability to act quickly.
- **A new monthly FCA safeguarding return:** All firms must submit a new monthly return to the FCA, and we’re going to zoom in on exactly what that return asks for now.

The objective for this return is to ensure the FCA receives regular and comprehensive information about a firm’s safeguarding of relevant funds.

#### What Does the FCA Monthly Safeguarding Return Require Firms to Report?

At a high level, this monthly return (REP027) covers:

- Your safeguarding method
- Balances
- Institutions where funds are held
- Resource vs requirement
- Reconciliations
- Record-keeping
- And notifiable breaches

#### Who Must Submit the FCA Safeguarding Return?

And the question every firm asks: **does this report apply to me?**

- It applies to all safeguarding institutions. That includes APIs, EMIs, and SPIs and SEMIs where they have opted into safeguarding.
- And the “what you need to report” is any relevant funds safeguarded under the PSRs or EMRs.

#### When and How to Submit the FCA Safeguarding Return

The return needs to be submitted within **15 business days after month-end** via the FCA RegData platform. The first submission is due **21st of July 2026**. Make sure to mark that in your diaries!

#### Which Sections of the FCA Safeguarding Return Apply to Your Firm? (Conditional Reporting Explained)

Now there is one key consideration with this return, namely that sections are conditional:

- **Sections 1, 2 and 9 apply to all firms**
- **Sections 3–8 apply only if you were required to safeguard during the period**
- **Sections 10–17 only apply for unrelated payment services**, so if you’re an EMI providing UPS unrelated to your e-money issuance, a SEMI who opted in, or a credit union who opted in

#### Data Fields Needed for Submission: Section-by-Section Breakdown

Now on to the data fields you’ll need to collect.

If you were required to safeguard during the period, **sections 1–9 apply**:

```json
{
  "_key": "12de53dd65da",
  "_type": "table",
  "rows": [
    {
      "_key": "0941e79a-df36-4020-be7f-0ead1aa085b7",
      "_type": "tableRow",
      "cells": [
        "Section ",
        "What you need to report on"
      ]
    },
    {
      "_key": "f4bfc058-690e-47d5-95c2-5efb56303fa7",
      "_type": "tableRow",
      "cells": [
        "1. Basic set-up",
        "Your firm name, category of safeguarding institution, and details on your last safeguarding audit."
      ]
    },
    {
      "_key": "0d8aba54-685d-47e6-8b57-d22d0bcc4595",
      "_type": "tableRow",
      "cells": [
        "2. Safeguarding method",
        "If you were in scope for safeguarding, what method did you use (segregation, insurance/guarantee, or some combination), the number of clients you safeguarded for, and any use of non-standard internal reconciliation procedures during the period."
      ]
    },
    {
      "_key": "e82e4cd9-9218-40d4-aad9-a264211fcb64",
      "_type": "tableRow",
      "cells": [
        "3. Balances",
        "Simply your highest and lowest safeguarding requirement during the period."
      ]
    },
    {
      "_key": "44c6bce8-82ab-45e5-929e-63d9eec435f1",
      "_type": "tableRow",
      "cells": [
        "4. Where funds are held",
        "If segregation is used: the institution where funds are held, the type of account, number of accounts, total amounts held, country, and whether the contract is fixed-term or has a notice period. For insurances/guarantees: name of insurer or guarantor, amount covered, date of expiry, and total overdue premiums. For investment in secure liquid assets: the asset type, name of custodian, and total value of assets held at the end of the period."
      ]
    },
    {
      "_key": "82304b8b-d7af-4990-a618-8b65030a1102",
      "_type": "tableRow",
      "cells": [
        "5. Resource vs requirement",
        "You report what you’ve actually safeguarded across bank accounts, segregated funds not yet placed, relevant assets, and any insurance/guarantee cover. Then you compare that to what you should be safeguarding (including any amounts received but unallocated to an individual client). Then you work out whether you had an excess or shortfall at month-end and disclose what you did to fix it."
      ]
    },
    {
      "_key": "32d73b47-8f3e-4170-8e6c-8e73cb27b2d9",
      "_type": "tableRow",
      "cells": [
        "6. The D+1 (Day plus 1) segregation check",
        "You report your requirement vs resource from your last internal reconciliation, along with any adjustments made."
      ]
    },
    {
      "_key": "f23b4e12-e21f-40f5-8886-562027393785",
      "_type": "tableRow",
      "cells": [
        "7. Reconciliations",
        "Did you carry out internal reconciliations using your own records every reconciliation day, and did you carry out external reconciliations using external evidence (e.g. bank statements)?"
      ]
    },
    {
      "_key": "59c035bc-37bd-4687-bf21-a3d9b3db4afd",
      "_type": "tableRow",
      "cells": [
        "8. Record-keeping",
        "This is your inventory of all safeguarding accounts and assets, including how many accounts you had at the start of the month, how many you opened, how many you closed, and how many you had at the end of the month. Then you confirm how many of those accounts are covered by an acknowledgment letter, and if letters are missing, explain why."
      ]
    },
    {
      "_key": "f87e8762-98b5-4833-8dde-9f99e3784f0b",
      "_type": "tableRow",
      "cells": [
        "9. Notifiable breaches",
        "This is where the FCA is basically asking: did anything happen this month that you were required to notify them about under CASS, for example material errors in records, failed reconciliations, unresolved discrepancies, material shortfalls, insurance/guarantee about to expire without replacement lined up, or any other breach of duty under CASS 15."
      ]
    }
  ]
}
```

For firms providing unrelated payment services, i.e. payment services unrelated to the issuance of e-money, you repeat the same checks as above in **sections 10–17**.

EMIs who provide UPS, SEMI opt-in firms, and credit union opt-ins may have to complete this section.

#### Practical Next Steps

- **Determine scope:** Are you required to safeguard (did you opt in), and do sections 10–17 apply based on your business model?
- **Can you automate this?** You’ll be doing this monthly, so a canned extract will be essential.
- **Diary submissions:** They’re due 15 business days at the end of each month.

#### Make Monthly FCA Safeguarding Reporting More Manageable with Complyfirst

The move to a mandatory monthly FCA safeguarding return changes the rhythm of reporting for UK APIs, EMIs and SPIs. The rules themselves are familiar, the challenge is pulling everything together consistently within a 15-business-day window each month.

Safeguarding data usually sits across finance, operations and compliance, so without the right structure it can turn into a manual consolidation exercise at month-end. [Complyfirst](https://complyfirst.co/) addresses this by connecting directly to underlying safeguarding data and integrating with the FCA’s RegData platform, removing repetitive data entry, spreadsheet-based aggregation and reconciliation mismatches.

With automated data collection, built-in validation, structured approvals and clear audit traceability, firms can move from reactive month-end reporting to a controlled and repeatable FCA submission process.

```json
{
  "_key": "d12a512ca112",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/HH325NWaaso"
}
```

```json
{
  "_key": "becfea480153",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "777e1fae9e94",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "77256bf159e4",
          "_type": "block",
          "children": [
            {
              "_key": "23c7f60b32ed",
              "_type": "span",
              "marks": [],
              "text": "UPS stands for "
            },
            {
              "_key": "d6982c24dad9",
              "_type": "span",
              "marks": [
                "em"
              ],
              "text": "Unrelated Payment Services"
            },
            {
              "_key": "27287a93eb42",
              "_type": "span",
              "marks": [],
              "text": ". These are payment services you provide that are not directly connected to issuing e-money. Because they sit outside your e-money perimeter, the FCA requires you to complete Sections 10–17 to report how you safeguard funds within that separate scope."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What are Unrelated Payment Services (UPS) under the FCA Safeguarding regime?"
    },
    {
      "_key": "c3e45acbe097",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "c572121457c1",
          "_type": "block",
          "children": [
            {
              "_key": "de6fd6a03810",
              "_type": "span",
              "marks": [],
              "text": "Any reportable safeguarding issue that occurs during the month, such as material record-keeping errors, failed reconciliations, unresolved shortfalls, or gaps in insurance/guarantee cover, and confirmation of whether the FCA was notified."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is a notifiable safeguarding breach under Section 9 of the FCA Monthly Return?"
    },
    {
      "_key": "e91172e9f75d",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "38b59accc5ae",
          "_type": "block",
          "children": [
            {
              "_key": "965207cfa558",
              "_type": "span",
              "marks": [],
              "text": "Automate the process by generating a monthly safeguarding pack directly from your back-office systems or data warehouse, automatically calculating resource versus requirement, routing it for review and approval, and submitting it to RegData via API."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "How can UK EMIs and APIs automate the FCA Monthly Safeguarding Return?"
    }
  ],
  "title": "FAQ"
}
```

---
Source: https://complyfirst.co/resources/how-to-complete-the-fca-safeguarding-monthly-return-guide
Last updated: 2026-07-31

---

# 🇬🇧 UK Webinar: Major Regulatory & Tax Reporting Changes in 2026. Are You Ready?

> Fiona presented a clear, practical overview of the FCA's monthly Safeguarding Return, CRS2, and CARF.

Jurisdiction: UK  
Published: 2026-01-29

```json
{
  "_key": "00ec2c3c146a",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/5SWYDi1ebuI"
}
```

If you’re responsible for reporting at a PI, EMI, or bank, this 30 minute webinar is for you. Fiona presented a clear, practical overview of what’s coming, what’s changing, and what you need to focus on next, across: 



- FCA Safeguarding Return 
- Common Reporting Standard Phase 2 (CRS2) 
- Crypto Asset Reporting Framework (CARF)



```json
{
  "_key": "e41b263ae7bc",
  "_type": "resource-quick-links",
  "links": [
    {
      "_key": "de8ac9477d23",
      "_type": "linkItem",
      "description": "Major Regulatory & Tax Reporting Changes in 2026. Are You Ready?",
      "title": "Webinar Slides",
      "url": "https://complyfirst.co/resources/files/webinar-slides-uk-tax-reporting-changes-in-2026"
    }
  ],
  "title": "More Resources"
}
```

---
Source: https://complyfirst.co/resources/uk-webinar-major-regulatory-and-tax-reporting-changes-in-2026-are-you-ready
Last updated: 2026-03-12

---

# 🇪🇺 EU Webinar: Major Regulatory & Tax Reporting Changes in 2026. Are You Ready?

> Fiona presented a clear, practical overview of Spanish tax reporting (Models 196 & 170), CRS2, DAC8, and IPR reporting.

Jurisdiction: EU  
Published: 2026-01-22

```json
{
  "_key": "67dad26b920b",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/lEZEVfdOZ08"
}
```

Fiona presented a clear, practical overview of what’s coming, what’s changing, and what you need to focus on next, across:   


- Spanish tax reporting (Models 196 & 170) 
- Common Reporting Standard Phase 2 (CRS2) 
- Crypto Asset Reporting Framework (DAC8) 
- Instant Payment Regulation (IPR) reporting



```json
{
  "_key": "d1d02d149a42",
  "_type": "resource-quick-links",
  "links": [
    {
      "_key": "547d20c7ae8e",
      "_type": "linkItem",
      "description": "Major Regulatory & Tax Reporting Changes in 2026. Are You Ready?",
      "title": "Webinar Slides",
      "url": "https://complyfirst.co/resources/files/webinar-slides-eu-tax-reporting-changes-2026"
    }
  ],
  "title": "More Resources"
}
```

---
Source: https://complyfirst.co/resources/eu-webinar-major-regulatory-and-tax-reporting-changes-in-2026
Last updated: 2026-03-12

---

# CRS 2.0 Reporting Requirements for E-Money Firms and Financial Institutions Explained

> CRS 2.0 amends the Common Reporting Standard and brings e-money firms into scope. The UK (HMRC) and EU (DAC8) deadlines, data rules and penalties, explained.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: EU & the UK  
Published: 2026-01-22

```json
{
  "_key": "d7b12c0c0dfd",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

#### What Is CRS 2.0 and What Changed in the Common Reporting Standard

The OECD Common Reporting Standard is the global framework for the automatic exchange of financial account information between tax authorities. Banks and investment firms have reported under it for years. 

CRS 2.0 is the OECD's first full review of that standard, and it pulls products that used to sit outside the net firmly inside it.

###### Why e-money and digital products are now in scope

Under the original CRS framework, many e-money products sat outside scope because CRS was written for traditional bank accounts, not digital wallets. It focused on deposits and custodial accounts used for saving or investment, whereas e-money products are typically prepaid wallets, safeguarded rather than deposited, and used for payments.

CRS 2.0 closes that gap. It explicitly brings certain e-money and account-like digital products in, treats the holding of value and payment functionality as a potential trigger, and expects bank-grade due diligence and evidence behind every reportable account. Many EMIs are now Reporting Financial Institutions for the first time.

###### CRS 2.0 versus the original CRS

The standard has not been rebuilt from scratch. The obligations are familiar to anyone who owned the reporting obligation at a bank. What has changed is the perimeter and the detail. More products in scope, more granular data per account, stronger checks linking tax self-certifications to KYC, and an updated XML schema for the reports themselves.

```json
{
  "_key": "2adebf9399f5",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "46bfbc30cd48",
      "_type": "block",
      "children": [
        {
          "_key": "59e00bb29dd7",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "47fa1935f467",
      "_type": "block",
      "children": [
        {
          "_key": "e17414b49c2e",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "What it is:"
        },
        {
          "_key": "bcc44de489f7",
          "_type": "span",
          "marks": [],
          "text": " the amended OECD Common Reporting Standard, widening scope to e-money products, digital accounts, CBDCs and crypto-asset derivatives."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "546e868a9a17",
      "_type": "block",
      "children": [
        {
          "_key": "608a52a64ece",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Two routes:"
        },
        {
          "_key": "4b9ed90cb064",
          "_type": "span",
          "marks": [],
          "text": " HMRC regulations in the UK, DAC8 (Council Directive (EU) 2023/2226) in the EU. Same OECD standard underneath."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "5a8d12bf109f",
      "_type": "block",
      "children": [
        {
          "_key": "0ab717c0c1d2",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Four dates:"
        },
        {
          "_key": "221e0850c6fe",
          "_type": "span",
          "marks": [],
          "text": " register with HMRC by 31 December 2025, collect data under the new rules from 1 January 2026, first UK report by 31 May 2027, EU exchanges due in 2027 (by 30 September in most member states)."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "4709266d6792",
      "_type": "block",
      "children": [
        {
          "_key": "8596b60862ad",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Who's newly caught:"
        },
        {
          "_key": "6981566bc0bc",
          "_type": "span",
          "marks": [],
          "text": " many e-money institutions and payment firms now classed as Reporting Financial Institutions."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "4ad6e76e5b16",
      "_type": "block",
      "children": [
        {
          "_key": "2b0c57bd8ef2",
          "_type": "span",
          "marks": [
            "bb13287cfd7a"
          ],
          "text": "Download the CRS 2.0 snapshot"
        },
        {
          "_key": "20556017fb4b",
          "_type": "span",
          "marks": [],
          "text": " for a one-page version."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [
        {
          "_key": "bb13287cfd7a",
          "_type": "link",
          "href": "https://complyfirst.co/resources/files/reporting-snapshot-crs2"
        }
      ],
      "style": "normal"
    }
  ]
}
```

#### Key CRS Reporting Definitions: CRS, CARF and DAC8

Here is how CRS, CARF, and DAC8 all relate.

```json
{
  "_key": "1f47371ff02f",
  "_type": "table",
  "rows": [
    {
      "_key": "caadca24-3ea2-4a56-8963-abb06d7000dd",
      "_type": "tableRow",
      "cells": [
        "Term",
        "What it means"
      ]
    },
    {
      "_key": "af6d4cf6-81f2-4ca2-bfc8-54c5dd3fb85b",
      "_type": "tableRow",
      "cells": [
        "CRS (Common Reporting Standard)",
        "The OECD’s global standard for the automatic exchange of information on financial accounts. CRS applies to banks, investment firms, and now certain e-money and digital products. It sets the due-diligence and reporting requirements firms must follow."
      ]
    },
    {
      "_key": "1ccb3076-1a8f-4de6-81de-f75502c1f832",
      "_type": "tableRow",
      "cells": [
        "CRS 2.0 (the CRS amendments)",
        "Updates issued by the OECD that expand CRS scope, increase data granularity, strengthen due-diligence expectations, and update reporting schemas. These amendments are what change obligations for e-money institutions from 1 January 2026."
      ]
    },
    {
      "_key": "facfe8a5-76eb-4763-87bf-9d13c51e8ada",
      "_type": "tableRow",
      "cells": [
        "CARF (Crypto-Asset Reporting Framework)",
        "A separate OECD reporting framework for crypto-asset transactions. CARF applies to crypto firms and does not apply to traditional financial accounts or e-money products."
      ]
    },
    {
      "_key": "10375795-ce7e-4d4b-b42a-80ddf046f4d5",
      "_type": "tableRow",
      "cells": [
        "DAC8",
        "EU legislation that implements two OECD standards into EU law: CARF for crypto-asset reporting, and the amended CRS rules for financial accounts and certain digital money products. DAC8 is the EU legal mechanism through which these standards apply."
      ]
    }
  ]
}
```

#### What Data Must Be Captured Under the Amended CRS

This is where the work lands. CRS 2.0 raises the bar across onboarding, data quality and reporting. For many e-money institutions it means running CRS controls in practice for the first time. These are the grenades, the specific things to watch for.

```json
{
  "_key": "55a4a51b2909",
  "_type": "table",
  "rows": [
    {
      "_key": "b2fc76a5-0d0d-4451-9773-d6942ab7a9cb",
      "_type": "tableRow",
      "cells": [
        "CRS 2.0 change",
        "What it means in practice"
      ]
    },
    {
      "_key": "b63bcac1-5a27-4d55-8fb6-51dc115a5a21",
      "_type": "tableRow",
      "cells": [
        "E-money and account-like digital products are now in scope",
        "Certain e-money wallets and digital value products must be treated as reportable financial accounts. Many EMIs are required to apply CRS controls for the first time."
      ]
    },
    {
      "_key": "91715daf-6859-42f3-abff-ebd8b9087eaf",
      "_type": "tableRow",
      "cells": [
        "All tax residences must be captured and reported",
        "Record every country where a customer is tax resident and report all declared tax residences, not just a single primary one. Ensure onboarding flows and systems support multiple tax residencies per customer."
      ]
    },
    {
      "_key": "27dc56c9-6c25-46b5-aab5-3471c72bf899",
      "_type": "tableRow",
      "cells": [
        "More detailed customer information is required",
        "Capture structured tax data at onboarding and obtain a valid tax self-certificate confirming tax residence. Collect a Tax Identification Number (TIN) for each declared tax residence, or record a valid reason where unavailable, and keep customer tax information current."
      ]
    },
    {
      "_key": "18c508bc-53a8-45cc-b3d2-3377560883b2",
      "_type": "tableRow",
      "cells": [
        "Stronger checks on customer information",
        "Assess whether tax self-certifications and declared tax residences are consistent with KYC data, then investigate and resolve any inconsistencies. Retain evidence showing checks and reviews were performed."
      ]
    },
    {
      "_key": "fc7ad5f8-b577-4e21-9bf9-a0a419f06963",
      "_type": "tableRow",
      "cells": [
        "Ongoing monitoring is required",
        "Monitor customers for changes in circumstances that may affect tax residence and refresh self-certifications and tax data when changes are identified. Treat CRS as a continuous obligation rather than a one-off exercise."
      ]
    },
    {
      "_key": "eca27229-9ca6-4e38-952c-19b88965a0d5",
      "_type": "tableRow",
      "cells": [
        "Updated CRS XML schema",
        "Prepare annual reports using the updated OECD CRS XML schema and map internal data accurately to reporting fields. Be ready to correct rejected or incomplete files."
      ]
    },
    {
      "_key": "c198c508-d044-41eb-a1fa-efba204cecda",
      "_type": "tableRow",
      "cells": [
        "Closer regulatory scrutiny",
        "Expect closer review of onboarding, data quality, and evidence, and anticipate follow-up questions from tax authorities. Address gaps early to reduce audit and penalty risk."
      ]
    }
  ]
}
```

#### Who Must Comply with CRS 2.0, and When? (UK and EU)

CRS 2.0 applies to **all Reporting Financial Institutions** in the UK and EU, including e-money institutions now brought in for the first time. The standard underneath is identical. The legal route differs by region, and so do the exact deadlines.

###### The UK timeline under HMRC

The UK applies CRS 2.0 through HMRC's International Tax Compliance regulations, updated for 2025. The dates a UK compliance lead needs on the wall:

- **By 31 December 2025:** reporting financial institutions had to be registered with HMRC. If your firm came into scope and has not registered, treat that as overdue.
- **From 1 January 2026:** collect and maintain customer and account data under the CRS 2.0 rules. Updated onboarding forms, enhanced due diligence, expanded data capture.
- **By 31 May 2027:** file your first report covering the 2026 calendar year.

So 2026 is the data year. 2027 is the reporting year. Everything you file in 2027 rests on the data you are capturing right now.

###### The EU timeline under DAC8

The EU applies CRS 2.0 and CARF through DAC8, Council Directive (EU) 2023/2226. Member states had to transpose it into national law by 31 December 2025, and the rules apply from 1 January 2026. First exchanges are due in 2027, within nine months of the first reporting year ending. Most member states land on 30 September 2027, though some sit earlier at 30 June. Check the date in each jurisdiction you hold a licence in. We cover the crypto side in our [DAC8 and crypto-asset reporting guide](https://complyfirst.co/resources/dac8-crypto-asset-reporting-guide).

#### What Are the Penalties for CRS 2.0 Non-Compliance?

CRS obligations bite from the moment they apply. There is no grace period and no soft launch.

In the UK, legislation provides for financial penalties where CRS obligations are not met, including:

- **Up to £300 per instance** for failures such as not obtaining a valid self-certification when required
- **Up to £100 per account holder or controlling person** for due-diligence failures
- **Daily default penalties** where non-compliance continues after HMRC notification

In the EU, penalties are set by individual Member States but must be **effective, proportionate, and dissuasive**. This often means penalties in the **hundreds or thousands of euros**, depending on the nature and scale of the issue.

For EMIs, the risk is scale. Where the same issue affects large customer populations or persists across reporting cycles, the consequences can extend well beyond an isolated fine. In more serious cases, firms may face:

- **Cumulative financial penalties** running into six figures where systemic issues affect large volumes of accounts
- **Regulatory investigations**, leading to increased supervisory scrutiny and management distraction
- **Reputational impact**, particularly where a firm is viewed as a weak link in tax transparency controls
- **Cross-border enforcement risk,** as poor information exchanged under automatic exchange frameworks and CARF can trigger enquiries in other jurisdictions

These risks are not theoretical. HMRC have been clear that data collected under CRS 2 and CARF will be used to identify non-compliance and pursue enforcement action where necessary. Firms that delay preparation risk underestimating both the scale and complexity of the new requirements.

#### How Complyfirst Supports CRS 2.0 Reporting

[Complyfirst](https://complyfirst.co/) supports firms in implementing CRS 2.0 as a compliant, repeatable process, aligned with regulatory expectations.

###### **What We Deliver**

- CRS data mapping aligned to onboarding and refresh workflows
- Structured validation and consistency checks
- XML ready reporting processes aligned with OECD schemas
- Clear review, sign off, and audit trails
- Practical support through first reporting cycles

For a full snapshot of CRS2, you can watch the video snippet below from Fiona’s [EU webinar session](https://complyfirst.co/resources/eu-webinar-major-regulatory-and-tax-reporting-changes-in-2026), or download a full PDF snapshot right [here](https://complyfirst.co/resources/files/reporting-snapshot-crs2).

```json
{
  "_key": "16717adb4098",
  "_type": "resource-media",
  "mediaType": "youtube",
  "mp4File": {
    "_type": "file",
    "asset": {
      "_ref": "file-63f52a57d1381559c1fd3e02f904a278465cebe4-mp4",
      "_type": "reference"
    }
  },
  "youtubeUrl": "https://youtu.be/rmMd5bi_QBY"
}
```

```json
{
  "_key": "84abf21c420c",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "c0823d52af71",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "c8cc91acfe9f",
          "_type": "block",
          "children": [
            {
              "_key": "dc9051aa2b4f",
              "_type": "span",
              "marks": [],
              "text": "CRS 2.0 applies from 1 January 2026 in both the UK and the EU. That is the date firms must start collecting and maintaining data under the amended rules. The first reports covering 2026 data are due in 2027, by 31 May 2027 in the UK and within nine months of the reporting year end in the EU."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "When does CRS 2.0 take effect?"
    },
    {
      "_key": "4dde30f6cce7",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "8cc4599150c9",
          "_type": "block",
          "children": [
            {
              "_key": "9c70d3a52efc",
              "_type": "span",
              "marks": [],
              "text": "Yes, for many of them for the first time. The amended standard explicitly brings certain e-money wallets and account-like digital products into scope as reportable financial accounts. If your firm holds customer value or offers payment functionality through products that were previously outside CRS, you should assume you are now in scope until you have confirmed otherwise."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Does CRS 2.0 apply to e-money institutions?"
    },
    {
      "_key": "a84fff3ab127",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "82176f26a545",
          "_type": "block",
          "children": [
            {
              "_key": "c42b65c59d81",
              "_type": "span",
              "marks": [],
              "text": "CRS 2.0 is the amended Common Reporting Standard for traditional financial accounts, including the e-money and digital products newly brought in. CARF is a separate OECD framework for crypto-asset transactions and applies to crypto firms. Both are written into EU law through DAC8, and into UK law through HMRC regulations, but they cover different firms and different products."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the difference between CRS 2.0 and CARF?"
    },
    {
      "_key": "8654db889b31",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "1da6fb13b1a3",
          "_type": "block",
          "children": [
            {
              "_key": "53879b0fe27f",
              "_type": "span",
              "marks": [],
              "text": "In the UK, the first report covering the 2026 calendar year is due by 31 May 2027. In the EU, first exchanges fall in 2027, with most member states setting a deadline of 30 September 2027 and some at 30 June. The exact date depends on the jurisdiction, so confirm it per licence rather than assuming one date covers all of them."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "When is the first CRS 2.0 report due?"
    }
  ],
  "title": "FAQ about CRS 2.0"
}
```

#### Conclusion

For many e-money institutions, the amended CRS rules mark a step change in how tax reporting obligations apply in practice.

From January 2026, CRS compliance must be embedded into onboarding, customer data management, and ongoing monitoring. Firms that integrate CRS controls into their day-to-day processes will be better prepared for reporting, regulatory review, and follow-up. Firms that delay risk identifying gaps only once reporting requirements are live, when remediation is more complex and costly.

---
Source: https://complyfirst.co/resources/crs-2-reporting-requirements-explained
Last updated: 2026-06-19

---

# EU DAC8 Crypto-Asset Reporting Requirements Explained (2026 Guide)

> This blog breaks down what DAC8 is, who it applies to, and how reporting works in practice.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: EU  
Published: 2026-01-07

```json
{
  "_key": "cae8c23c9c82",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

#### What is DAC8 in Simple Terms?

First, let’s breakdown what DAC8 in its simplest definition.

DAC8 is an EU law that requires crypto companies to report customer and transaction information to tax authorities.

That information is then **shared automatically between EU countries** so tax authorities can see how crypto is being used and taxed across borders.

In practice, this means:

- Crypto firms report data to their local tax authority
- Tax authorities share that data with other EU Member States
- Tax authorities gain visibility into cross-border crypto activity

The goal is straightforward: improve tax transparency and reduce underreporting involving crypto-assets.

```json
{
  "_key": "3f4da7d9900d",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "b343da00a794",
      "_type": "block",
      "children": [
        {
          "_key": "895106d1bc55",
          "_type": "span",
          "marks": [],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "55ddfd183edc",
      "_type": "block",
      "children": [
        {
          "_key": "58de08b05614",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "What it does:"
        },
        {
          "_key": "d492b734d8fb",
          "_type": "span",
          "marks": [],
          "text": " Introduces mandatory, annual tax reporting for crypto-asset activity involving EU tax residents."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "08c93e060b04",
      "_type": "block",
      "children": [
        {
          "_key": "4581675d9e48",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "When it starts:"
        },
        {
          "_key": "536f5ac67961",
          "_type": "span",
          "marks": [],
          "text": " Data collection from 1 January 2026. First reports for the 2026 calendar year are due by 30 September 2027, subject to domestic transposition"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "cf2ad73c7bc3",
      "_type": "block",
      "children": [
        {
          "_key": "28dfea3a8c98",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Who it affects:"
        },
        {
          "_key": "4c232843f53c",
          "_type": "span",
          "marks": [],
          "text": " Crypto platforms, including non EU firms, that serve EU users"
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "dcfc29ba8a64",
      "_type": "block",
      "children": [
        {
          "_key": "9aa7b49ee670",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Why it matters:"
        },
        {
          "_key": "9b051f8cdfcd",
          "_type": "span",
          "marks": [],
          "text": " EU tax authorities gain structured, automated visibility into crypto activity across borders."
        }
      ],
      "level": 1,
      "listItem": "bullet",
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

#### What DAC8 Means for EU Crypto Firms

The EU’s Directive on Administrative Cooperation 8 (DAC8) introduces a material change to how crypto asset activity is reported for tax purposes. From **1 January 2026**, DAC8 extends the EU’s automatic exchange of information framework to crypto assets, bringing crypto asset service providers into a reporting regime that previously applied primarily to traditional financial institutions.

DAC8 is aligned with the OECD’s Crypto Asset Reporting Framework (CARF) and amendments to the Common Reporting Standard (CRS). Unlike those frameworks, DAC8 is binding EU law, with defined reporting formats, exchange mechanisms, and enforcement at Member State level.



###### Who DAC8 Applies to Beyond Crypto Firms

DAC8 primarily applies to Crypto Asset Service Providers. However, payment institutions and electronic money institutions are often indirectly affected where they support crypto activity.

This includes PIs and EMIs that:

- Provide accounts, safeguarding, or payment rails to crypto firms
- Support onboarding or customer due diligence for crypto related customers
- Operate group structures that include crypto entities
- Rely on crypto firms for customer or transaction data



#### Key Definitions and How They Relate

```json
{
  "_key": "946bc633ac05",
  "_type": "table",
  "rows": [
    {
      "_key": "0efd20e2-e0a3-403b-8fe4-9559c69519bc",
      "_type": "tableRow",
      "cells": [
        "Term  ",
        "What it is and how it fits"
      ]
    },
    {
      "_key": "e01b19fb-765f-4abd-b0b0-2e263c63ecdc",
      "_type": "tableRow",
      "cells": [
        "OECD",
        "The international body that sets global tax transparency standards. The OECD develops frameworks such as CARF and the Common Reporting Standard, which individual jurisdictions then implement through domestic law."
      ]
    },
    {
      "_key": "6da16b54-5884-4a1a-8da1-8d9827bb6348",
      "_type": "tableRow",
      "cells": [
        "CARF",
        "The OECD’s crypto asset reporting framework. CARF sets the global standard for how tax authorities collect and automatically exchange information on crypto-asset transactions."
      ]
    },
    {
      "_key": "a94329ef-74b7-420b-ae73-44576f740ac4",
      "_type": "tableRow",
      "cells": [
        "DAC8",
        "The EU law that implements CARF in the European Union. DAC8 makes crypto asset reporting mandatory for EU linked firms and defines timelines, reporting formats, and exchange mechanisms."
      ]
    },
    {
      "_key": "5caad459-0648-47ce-87a6-7e37e7016245",
      "_type": "tableRow",
      "cells": [
        "CRS",
        "The OECD standard for tax reporting on traditional financial accounts. CRS continues to apply to banks and certain digital money products, while DAC8 covers crypto assets specifically. Some firms will be subject to both."
      ]
    },
    {
      "_key": "66298ab1-fa6b-48bc-a76e-6d90341ed6ee",
      "_type": "tableRow",
      "cells": [
        "Reporting Crypto Asset Service Provider (RCASP)",
        "A crypto firm that must report under DAC8. This includes MiCA regulated Crypto Asset Service Providers and Crypto Asset Operators that are not MiCA regulated but have EU users."
      ]
    },
    {
      "_key": "94510900-6575-4137-9337-5505b4d96014",
      "_type": "tableRow",
      "cells": [
        "Reportable Users",
        "Customers of an RCASP who are resident in an EU Member State. These users trigger DAC8 reporting obligations regardless of where the firm is based."
      ]
    },
    {
      "_key": "6a175da9-35b6-4d4a-b499-ab7dc7766ddc",
      "_type": "tableRow",
      "cells": [
        "Reportable Crypto Assets",
        "Crypto assets within scope of DAC8, including most cryptocurrencies, certain stablecoins, and specified non fungible tokens used for payment or investment."
      ]
    },
    {
      "_key": "473b2a93-ece3-4514-a76a-25f1b9b9a8cc",
      "_type": "tableRow",
      "cells": [
        "Reportable Transactions",
        "Transactions must be reported under DAC8, including crypto to fiat exchanges, crypto to crypto exchanges, transfers of crypto assets, and qualifying retail payment transactions."
      ]
    },
    {
      "_key": "a7988cc4-dd54-4c26-bf33-9c866c21bb89",
      "_type": "tableRow",
      "cells": [
        "Reportable Retail Payment Transactions",
        "Situations where crypto is used to pay for goods or services and the payment value exceeds US$50,000 or equivalent. Payments below this threshold are not reportable. This threshold applies only to payments for goods or services and does not apply to trading, exchanges, or transfers, which remain reportable regardless of amount."
      ]
    }
  ]
}
```

#### What Changes for Firms Under DAC8

DAC8 extends the EU’s automatic exchange of information regime to crypto assets. In practice, this moves crypto activity from fragmented national approaches into a harmonised EU wide reporting framework.

Responsibility moves from user self disclosure to firm led reporting, supported by formal due diligence, standardised XML submissions, and automatic information exchange between tax authorities.

```json
{
  "_key": "c9f4172b82ce",
  "_type": "table",
  "rows": [
    {
      "_key": "11205103-0efc-4c72-a5ea-1e570a865785",
      "_type": "tableRow",
      "cells": [
        "Before DAC8",
        "After DAC8"
      ]
    },
    {
      "_key": "f578db9d-a65d-4e0e-9f09-23a7d13b4eee",
      "_type": "tableRow",
      "cells": [
        "No EU wide tax reporting obligation for crypto assets",
        "Mandatory EU wide crypto asset tax reporting"
      ]
    },
    {
      "_key": "c1272691-8faf-4edb-bbcf-1dee02735b20",
      "_type": "tableRow",
      "cells": [
        "Fragmented national approaches",
        "Harmonised rules with automatic exchange between Member States"
      ]
    },
    {
      "_key": "348ff620-aeff-4dbc-883f-2a6a315ea117",
      "_type": "tableRow",
      "cells": [
        "Limited tax data collection at onboarding",
        "Formal due diligence including tax residence and TINs"
      ]
    },
    {
      "_key": "69ac04e2-c696-43da-9f56-18eca3b89860",
      "_type": "tableRow",
      "cells": [
        "Reporting driven largely by user self disclosure",
        "Reporting driven by data supplied by firms"
      ]
    },
    {
      "_key": "68406762-703e-47ac-98e1-2418769422c7",
      "_type": "tableRow",
      "cells": [
        "Inconsistent or manual reporting formats",
        "Annual reporting using a standardised EU XML schema"
      ]
    }
  ]
}
```

#### Who Must Comply with the EU’s DAC8

The EU’s DAC8 applies to firms that facilitate crypto asset transactions for users, including:

- Crypto exchanges (centralised or broker-based)
- Crypto brokers and dealers
- Custodial wallet providers
- Platforms facilitating transfers or exchanges of crypto-assets

DAC8 applies to both EU-based and non-EU firms.

A firm must comply if it:

- Is resident, authorised, or registered in an EU Member State, or
- Provides crypto services to EU tax residents users

In short, if a crypto firm has EU users, DAC8 is likely relevant.

###### Who is Not in Scope?

DAC8 generally does not apply to:

- Individuals transacting on their own behalf
- Businesses that do not facilitate crypto transactions for users
- Purely decentralised protocols with no service provider

#### What Information Must be Reported Under the DAC8 Directive?

Under DAC8 Directive, Reporting Crypto-Asset Service Providers must collect, report, and exchange the following information annually:

```json
{
  "_key": "b9b8d8ee00d3",
  "_type": "table",
  "rows": [
    {
      "_key": "ac9f234e-8a82-4dc5-9b78-e15f7c5dbda0",
      "_type": "tableRow",
      "cells": [
        "Required Information",
        "Details"
      ]
    },
    {
      "_key": "43eae0fc-5eee-486e-9681-47a814c3fb3d",
      "_type": "tableRow",
      "cells": [
        "Information about the firm",
        "Legal name; Country of residence, authorisation, or registration; Licence or registration details"
      ]
    },
    {
      "_key": "e9b49537-1a1d-4b63-8307-2b0de94eee64",
      "_type": "tableRow",
      "cells": [
        "Information about users",
        "Name and address; Date of birth; Tax Identification Number (TIN); Jurisdiction(s) of tax residence"
      ]
    },
    {
      "_key": "83bb10e2-3ae3-496e-bb03-8ce90aac8ae6",
      "_type": "tableRow",
      "cells": [
        "Transaction information",
        "Type of crypto-asset; Type of transaction (e.g. buy, sell, exchange, transfer); Transaction value"
      ]
    }
  ]
}
```

Reports are submitted to the tax authority of the Member State where the firm is resident, authorised, or registered. Non-EU firms with EU tax resident users must register in one EU Member State for DAC8 purposes and submit their reports there.



#### How DAC8 Reporting Works in Practice

DAC8 EU reporting is deliberately centralised. Firms submit a single annual report to one tax authority. The EU manages the exchange of information between Member States. Firms do not file separate reports in multiple jurisdictions.

At a high level, the process is straightforward: collect the data, prepare it in the required XML format, submit it once, and respond to any follow up.

###### Step 1: Data collection

- Identify reportable users and transactions
- Collect required customer, tax residence, and transaction data in line with DAC8 definitions as part of customer onboarding and ongoing refresh

###### Step 2: Data validation and preparation

- Validate data for completeness and consistency
- Resolve missing or conflicting tax residence information
- Map internal data fields to DAC8 requirements
- Confirm data can be structured for XML reporting

###### Step 3: XML report creation

- Generate the report using the EU defined DAC8 XML schema • Apply required formatting and validation rules

###### Step 4: Submission to the local tax authority

- Submit a single report to the competent authority
- File in the Member State where the firm is resident, authorised, or registered

###### Step 5: Automatic exchange

- Local tax authority validates the submission
- Information is exchanged with other EU tax authorities
- Each authority receives data relevant to its own tax residents

###### Step 6: Follow up and corrections

- Respond to rejected or incomplete files
- Address questions from tax authorities
- Submit corrections where required

#### Where Firms Typically Underestimate DAC8

Firms most often struggle where:

- DAC8 requirements are not embedded into onboarding and refresh processes
- Tax residence and TIN data is inconsistent across systems
- XML generation cycles are underestimated
- Non EU firms assume they are out of scope because they are not MiCA authorised

#### Complyfirst Supports DAC8 XML Reporting

[Complyfirst](https://complyfirst.co/) supports firms in turning DAC8 requirements into a automated, repeatable reporting process aligned with EU standards.

###### What We Deliver

- **Data mapping** from internal systems to DAC8 reporting fields
- **XML-ready reporting workflows**, aligned with EU schema requirements
- Built-in **data validation and consistency checks** to reduce reporting errors
- Clear **review, sign-off, and version control** processes
- **Practical, 1:1 support **to help teams prepare for DAC8 submissions



For a full snapshot of DAC8, you can watch the video snippet below from Fiona’s [EU webinar session](https://complyfirst.co/resources/eu-webinar-major-regulatory-and-tax-reporting-changes-in-2026), or download a full PDF version right [here](https://complyfirst.co/resources/files/reporting-snapshot-dac8).



```json
{
  "_key": "e71803ba80b6",
  "_type": "resource-media",
  "mediaType": "youtube",
  "mp4File": {
    "_type": "file",
    "asset": {
      "_ref": "file-89b3f71bdcede4538a815e08b1223e7b75b77ef9-mp4",
      "_type": "reference"
    }
  },
  "youtubeUrl": "https://youtu.be/IK9oK4bgCJA"
}
```

```json
{
  "_key": "e78484c1b1f6",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "55b9bda9a67f",
      "content": [
        {
          "_key": "e08cbfcea7a5",
          "_type": "block",
          "children": [
            {
              "_key": "f19740afa473",
              "_type": "span",
              "marks": [],
              "text": "DAC8 is an EU law that requires crypto service providers to report customer and transaction data to tax authorities for automatic exchange."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the DAC8 Directive in simple terms?"
    },
    {
      "_key": "34c2d41370bd",
      "content": [
        {
          "_key": "e3dd9db2cf1c",
          "_type": "block",
          "children": [
            {
              "_key": "a183e23970c3",
              "_type": "span",
              "marks": [],
              "text": "Yes. Non-EU firms must comply if they serve EU tax residents or facilitate EU-linked crypto transactions."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Does DAC8 apply to non-EU crypto firms?"
    },
    {
      "_key": "280cb0b80466",
      "content": [
        {
          "_key": "85d4fce75a10",
          "_type": "block",
          "children": [
            {
              "_key": "f39a64ee783c",
              "_type": "span",
              "marks": [],
              "text": "No. MiCA regulates crypto markets and conduct, while DAC8 focuses on tax reporting and information exchange."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Is DAC8 the same as MiCA?"
    },
    {
      "_key": "0cd8df9ecacf",
      "content": [
        {
          "_key": "01f6630ea89d",
          "_type": "block",
          "children": [
            {
              "_key": "3f77868a6594",
              "_type": "span",
              "marks": [],
              "text": "Reports are submitted to the tax authority of the Member State where the firm is resident, authorised, or registered. Non-EU firms with EU tax resident users must register in one EU Member State for DAC8 purposes and submit their reports there."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Who receives DAC8 reports?"
    },
    {
      "_key": "f9fff5fa683b",
      "content": [
        {
          "_key": "0fb7f8a924f0",
          "_type": "block",
          "children": [
            {
              "_key": "0c15339f405e",
              "_type": "span",
              "marks": [],
              "text": "Tax authorities exchange DAC8 data via the EU Common Communication Network using XML-formatted reports."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "How is DAC8 data exchanged between EU Member States?"
    }
  ],
  "title": "FAQ"
}
```

#### Conclusion

DAC8 brings crypto-assets fully into the EU tax reporting framework. While the rules themselves are relatively clear, compliance in practice depends on data quality, reporting processes, and technical readiness, particularly around XML reporting.

For Crypto-Asset Service Providers, the key takeaway is timing. Early preparation makes it easier to avoid gaps, errors, and last-minute system changes.

---
Source: https://complyfirst.co/resources/dac8-crypto-asset-reporting-guide
Last updated: 2026-06-19

---

# New Spanish AEAT Tax Reporting Requirements Explained: Models 196 and 170 (2026 Guide)

> This guide breaks down Spanish tax models 196 and 170, and their reporting obligations.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Published: 2026-01-07

```json
{
  "_key": "4336b4d0e470",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

Spain is continuing its move toward greater, more frequent visibility of payment activity, particularly across digital and cross-border business models.



These changes were introduced by Royal Decree 253/2025, published in April 2025, which amends the RGAT, and they apply to reporting periods starting from 1 January 2026.



In practical terms, this marks a shift for payment and e-money firms. What was previously annual, fragmented, or threshold-based becomes monthly, comprehensive, and operational. This is no longer a “periodic filing” obligation. It is an ongoing reporting process that must run reliably every month.



To understand the impact, it helps to look at what applied before, and what applies from 2026 onwards.



```json
{
  "_key": "40d6cb46aaf9",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "b343da00a794",
      "_type": "block",
      "children": [
        {
          "_key": "895106d1bc55",
          "_type": "span",
          "marks": [],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "c90256635420",
      "_type": "block",
      "children": [
        {
          "_key": "ce7c4c8f4a98",
          "_type": "span",
          "marks": [],
          "text": "From "
        },
        {
          "_key": "38a995b8b2ab",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "1 January 2026"
        },
        {
          "_key": "a127ac5b9d1c",
          "_type": "span",
          "marks": [],
          "text": ", the Spanish Tax Agency (AEAT) requires "
        },
        {
          "_key": "5dc732443f7a",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "monthly tax reporting under Models 196 and 170"
        },
        {
          "_key": "78a529682c53",
          "_type": "span",
          "marks": [],
          "text": ". These obligations apply to payment institutions, electronic money institutions, banks, and other entities facilitating accounts or payment collections for Spanish merchants. Firms operating in Spain, including under freedom to provide services (FOS), must assess their data, systems, and reporting processes now to ensure timely compliance for the first filing in February 2026."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



## At a glance: what’s changed

Before (pre-2026)

- Model 196 was primarily an annual obligation and largely associated with banks
- Model 170 was filed annually and only once a €3,000 transaction threshold was exceeded
- Non-Spanish payment firms were often outside scope in practice

From 2026 onwards

- Model 196 must be filed monthly by banks, payment institutions, and EMIs
- Model 170 must be filed monthly, with no transaction threshold
- Cross-border firms operating in Spain under freedom to provide services (passporting) are explicitly in scope

From 2026, compliance moves from periodic reporting to a continuous monthly process.



#### Models 196 and 170 (Explained Without the Tax Jargon)

The simplest way to understand the two models is to separate where money sits from how money moves.

- Model 196 looks at the **containers of money**, i.e. accounts and wallets.
- Model 170 looks at the **movement of money**, i.e. card and mobile payments.

Together, they give the [**Agencia Estatal de Administración Tributaria (AEAT)**](https://sede.agenciatributaria.gob.es/Sede/inicio.html) a detailed, ongoing picture of payment activity connected to Spain.



#### Model 196: Financial Accounts (Where Money Sits)

Model 196 is a monthly declaration covering all financial accounts managed by regulated entities. This includes both traditional bank accounts and non-bank payment accounts.

Firms are required to report:

- All accounts opened, held, or closed during the period
- The people connected to those accounts, including account holders, beneficial owners, and authorised persons
- Account balances and holdings
- Any withholdings or account-related income



One practical point is worth calling out. While filings from January to November focus mainly on account existence and parties, the December filing is more extensive. It also includes year-end balances, average balances for the final quarter, and annual totals. For most firms, December will be the heaviest reporting month.

Two clarifications that are often missed:

- Non-resident accounts are included, with or without a Spanish permanent establishment
- Model 196 replaces the former Model 291 for non-resident accounts

Crypto and securities accounts are not in scope.

#### Model 170: Card and Mobile Payments (How Money Moves)

Model 170 focuses on payment collection activity carried out for merchants and professionals established in Spain.

Each month, firms must report information such as:

- Card payment transactions (physical and virtual)
- POS terminal activity
- Payments linked to mobile phone numbers
- Monthly transaction amounts and frequency
- Merchant identifiers and settlement accounts



There are two points that matter operationally.

- First, there is no minimum threshold. All in-scope transactions must be reported, regardless of value.
- Second, this model applies only to merchant payments. Consumer-to-consumer payments, such as transfers between individuals, are outside scope.

#### Reporting Timeline

- **Effective date:** 1 January 2026
- **First filing:** due in February 2026 (for January 2026 data)
- **Frequency:** Monthly submissions. Each filing is due by the end of the following month. For example, January data must be filed by the end of February.



#### Who Has to File Model 196 and 170?



The reporting obligation applies broadly across the payments ecosystem. **Most payment **and** e-money firms** will need to file both models.



In scope are:

- Payment institutions
- Electronic money institutions
- Banks and credit institutions
- Firms providing POS, acquiring, or payment collection services
- Spanish branches of EU and non-EU firms
- Firms operating under freedom to provide services (FOS), where authorised and registered with the Bank of Spain or the EBA  


```json
{
  "_key": "54510fe37177",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "61026630188b",
      "_type": "block",
      "children": [
        {
          "_key": "444979dd65a9",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Freedom to provide services (FOS)"
        },
        {
          "_key": "74105f69bb1b",
          "_type": "span",
          "marks": [],
          "text": " is an "
        },
        {
          "_key": "5e81818047b0",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "EU principle"
        },
        {
          "_key": "0a746c33dfaf",
          "_type": "span",
          "marks": [],
          "text": " that allows a company authorised in one EU Member State to offer services in another Member State without setting up a local branch or subsidiary there."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



The determining factor is Spanish tax nexus.

Reporting applies where the merchant or account holder:

- Is resident in Spain, or
- Is a non-resident with a Spanish permanent establishment

It does not apply to tourists, temporary visitors, or foreign merchants with no Spanish establishment.

What matters is the status of the merchant or account holder, not where your firm is based or where the transaction technically takes place.



```json
{
  "_key": "7399d8ac18ea",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "8c04441870c6",
      "_type": "block",
      "children": [
        {
          "_key": "953bd9e85817",
          "_type": "span",
          "marks": [],
          "text": "Establishment outside Spain "
        },
        {
          "_key": "a77ef39e14aa",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "does not"
        },
        {
          "_key": "26b6c436709b",
          "_type": "span",
          "marks": [],
          "text": " remove the obligation if Spanish merchants or account holders are involved."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



#### What Firms Should Be Doing in 2025

Firms that struggle with these obligations usually do so because preparation started too late.

During 2025, payment and e-money firms should:

- Confirm which entities, merchants, and accounts are in scope
- Clearly separate account data (Model 196) from transaction data (Model 170)
- Review AEAT technical specifications and XML schemas early
- Test whether systems can reliably produce monthly extracts
- Plan specifically for the heavier December Model 196 filing
- Run a dry-run of January 2026 data ahead of the first deadline





#### How Complyfirst Helps Firms Comply with Models 196 and 170

Most teams don’t struggle with understanding Models 196 and 170. They struggle with turning them into a process that runs smoothly every month. That’s what [Complyfirst](https://complyfirst.co/) is for.

Complyfirst helps firms:

1. Extract the required account and transaction data from existing systems on a monthly basis
2. Transform that data into the format required for Models 196 and 170
3. Generate AEAT-compliant XML files for submission
4. Manage corrections, resubmissions, and ongoing changes once reporting is live

For firms operating cross-border or under freedom to provide services, Complyfirst helps apply the same reporting process consistently across entities.

The goal is simple: make monthly AEAT reporting predictable, repeatable, and low-drama.



For a full snapshot of Spanish tax models 196 and 170, you can watch the video snippet below from Fiona’s [EU webinar session](https://complyfirst.co/resources/eu-webinar-major-regulatory-and-tax-reporting-changes-in-2026), or download a full PDF version right [here](https://complyfirst.co/resources/files/reporting-snapshot-spanish-tax-models-196-170).

```json
{
  "_key": "b8ccb080375b",
  "_type": "resource-media",
  "mediaType": "youtube",
  "mp4File": {
    "_type": "file",
    "asset": {
      "_ref": "file-1dc9eea82c07d948dc5ff50a2b1866168185e04a-mp4",
      "_type": "reference"
    }
  },
  "youtubeUrl": "https://youtu.be/ndNGhBRYnuM"
}
```



```json
{
  "_key": "abadcdca57ee",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "2d249a9b2751",
      "content": [
        {
          "_key": "a0f52b67d77c",
          "_type": "block",
          "children": [
            {
              "_key": "443233c01975",
              "_type": "span",
              "marks": [],
              "text": "Yes, if you passport into Spain, and have Spanish-resident customers with accounts or wallets (Model 196), and/or card or mobile payment activity linked to Spain (Model 170)."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Do non-Spanish firms need to file Models 196 & 170?"
    },
    {
      "_key": "7728c61bba2d",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "82de5980134a",
          "_type": "block",
          "children": [
            {
              "_key": "b6adaa2137d7",
              "_type": "span",
              "marks": [],
              "text": "IDOtro can be used, but only in the correct context. If the customer is a non-Spanish tax resident (resident abroad) and does not have a Spanish NIF, the foreign TIN should be reported in the IDOtro field, and “ClaveNoResidente” should be set to 2 (non-resident without permanent establishment)."
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "614b4cc3c9c4",
          "_type": "block",
          "children": [
            {
              "_key": "f181b5027aac",
              "_type": "span",
              "marks": [],
              "text": ""
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "853db53561ff",
          "_type": "block",
          "children": [
            {
              "_key": "b6adaa2137d7",
              "_type": "span",
              "marks": [],
              "text": "If the customer is a Spanish tax resident, nationality is irrelevant and “ClaveNoResidente” must be set to 1. The expected identifier is a Spanish NIF. If the NIF is not yet available, select “declared without NIF temporarily” under “No Obligado,” as described as a transitory case under Art 28.3 RGAT."
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "9111ecd0539d",
          "_type": "block",
          "children": [
            {
              "_key": "c83a520aca86",
              "_type": "span",
              "marks": [],
              "text": ""
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "5a4a98758cc2",
          "_type": "block",
          "children": [
            {
              "_key": "b6adaa2137d7",
              "_type": "span",
              "marks": [],
              "text": "Although the XML schema allows ID types such as 03 (passport) or 06 (other evidentiary document), using these for Spanish residents as a substitute for a NIF is not clearly described in the guidance/FAQs and may carry audit / interpretation risk."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "For non-Spanish users are we allowed to use ID Other field? What caveats / pitfalls should we be aware of?"
    },
    {
      "_key": "cf388030f095",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "69624c123741",
          "_type": "block",
          "children": [
            {
              "_key": "7775ce35c75a",
              "_type": "span",
              "marks": [],
              "text": "For a Spanish tax resident, there is no clear regulatory flexibility to replace a required NIF with a driving licence. Where the NIF is missing, the appropriate mechanism is “declared without NIF temporarily” on a genuinely temporary basis while remediation is ongoing."
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "518b73bbe827",
          "_type": "block",
          "children": [
            {
              "_key": "5433c92d2da1",
              "_type": "span",
              "marks": [],
              "text": "If the customer is a non-Spanish tax resident (resident abroad) and classified as ClaveNoResidente = 2, identification follows the non-resident regime. In that case, IDOtro may be used and IDType = 06 (“another evidentiary document”) may be used, and a driving licence number can be reported as the identifier."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "For Spanish users with a driving license, is there any flexibility in Form 196 to report ID other than NIF?"
    },
    {
      "_key": "9f7cb09d642a",
      "_type": "accordionItem",
      "content": [
        {
          "_key": "f302e8431f55",
          "_type": "block",
          "children": [
            {
              "_key": "40f49f09da6e",
              "_type": "span",
              "marks": [],
              "text": "Model 196 provides two values for L13:"
            }
          ],
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "532f3ad3ff80",
          "_type": "block",
          "children": [
            {
              "_key": "7542d826ccb8",
              "_type": "span",
              "marks": [],
              "text": "L13 = 1: “Other situations (residents and non-residents with permanent establishment)”"
            }
          ],
          "level": 1,
          "listItem": "bullet",
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "2a87f65f38a0",
          "_type": "block",
          "children": [
            {
              "_key": "c4590d6dee8c",
              "_type": "span",
              "marks": [],
              "text": "L13 = 2: “Non-resident without permanent establishment”"
            }
          ],
          "level": 1,
          "listItem": "bullet",
          "markDefs": [],
          "style": "normal"
        },
        {
          "_key": "f71118304c00",
          "_type": "block",
          "children": [
            {
              "_key": "115eaefeac8c",
              "_type": "span",
              "marks": [],
              "text": "Although “other” may suggest a residual category, it does not mean “unknown.” These are two clearly defined and mutually exclusive tax-status categories. There is no option for “residence not determined,” so L13 requires classification based on your firm’s due diligence (AML or CRS procedures)."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Annex I includes L13 = “1” (Other situations). How is this defined? Can this be used where tax residence is unknown?"
    },
    {
      "_key": "5ede0657e5a4",
      "content": [
        {
          "_key": "13586b47e5a7",
          "_type": "block",
          "children": [
            {
              "_key": "78f9b544e04c",
              "_type": "span",
              "marks": [],
              "text": "Yes. Model 196 includes both resident and non-resident accounts."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Are non-resident accounts included in Model 196?"
    },
    {
      "_key": "ed7e8460c0e5",
      "content": [
        {
          "_key": "8cce0e260702",
          "_type": "block",
          "children": [
            {
              "_key": "d2076c09249e",
              "_type": "span",
              "marks": [],
              "text": "No. All in-scope transactions must be reported."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Is there a transaction threshold for Model 170?"
    },
    {
      "_key": "be086ce4e4fc",
      "content": [
        {
          "_key": "ba1f52fff6d3",
          "_type": "block",
          "children": [
            {
              "_key": "aae9914e44dd",
              "_type": "span",
              "marks": [],
              "text": "Reporting applies from 1 January 2026, with first submissions due in February 2026."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "When does reporting begin?"
    }
  ],
  "title": "FAQs"
}
```

## Conclusion

Models 196 and 170 represent a significant expansion of Spanish tax reporting for payments and e-money firms. From 2026, compliance becomes monthly, technical, and continuous, including for firms operating cross-border into Spain.

---
Source: https://complyfirst.co/resources/tax-reporting-models-196-and-170-2026-guide
Last updated: 2026-02-17

---

# SumUp’s Switch to Complyfirst Cuts Reporting Workload by 90% in 4 Jurisdictions

> SumUp manages regulatory reporting obligations across multiple jurisdictions with Complyfirst.

Published: 2025-12-29

SumUp, a global payments provider, was facing growing complexity in regulatory reporting. Their previous setup made it difficult to catch and resolve submission issues quickly, resulting in a delayed DORA return.

**With Complyfirst, they were onboarded in 48 hours, resolved all validation errors in-platform, and successfully submitted to the Central Bank of Ireland.**

```json
{
  "_key": "b9dc5f5e37d6",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### The Challenge

The SumUp regulatory reporting team manages a wide range of obligations across multiple jurisdictions. But with their previous tools, schema changes led to delays, there was no real-time validation, and key business rules couldn’t be enforced — meaning errors were often only discovered during submission attempts.

```json
{
  "_key": "2763aea45c40",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "1586e5c3893e",
      "_type": "block",
      "children": [
        {
          "_key": "fb0b1bcbf592",
          "_type": "span",
          "marks": [
            "em"
          ],
          "text": "“Our DORA return kept getting rejected - we hit a wall. We needed a more effective solution to move forward.” - "
        },
        {
          "_key": "325d9288be03",
          "_type": "span",
          "marks": [],
          "text": "Adrian Witkowski, Head of Regulatory Reporting, SumUp"
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "2c1846d39e16",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### Our Solution

SumUp chose Complyfirst for speed, support, and reliability:

**Key features included:**

- Onboarded and DORA Register submitted within 48 hours
- Real-time technical and business rule validations
- Error resolution within the platform - zero re-uploads
- Intuitive UX that “just works”

```json
{
  "_key": "1426039f7919",
  "_type": "resource-quote",
  "author": {
    "_type": "object",
    "name": "Adrian Witkowski",
    "position": "Head of Regulatory Reporting, SumUp"
  },
  "enableIllustrations": true,
  "text": [
    {
      "_key": "0b1d41a6b125",
      "_type": "block",
      "children": [
        {
          "_key": "d81b0b2c477d",
          "_type": "span",
          "marks": [],
          "text": "What took weeks, Complyfirst fixed in hours—"
        },
        {
          "_key": "883516d0fc75",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "within 48 hours we were live, and submitted."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "db3f2e5755ac",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### The Results

**Complyfirst delivered immediate impact:**

- 90% reduction in reporting effort
- Successful DORA submission within 48 hours
- Zero back-and-forth with the regulator

```json
{
  "_key": "8af211385bf2",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### What's Next

Following the successful DORA implementation, SumUp plans to extend Complyfirst to:

- Central Bank of Ireland quarterly returns
- UK, Lithuanian and Australian regulatory reporting
- Common Reporting Standard (CRS) and future mandates.

---
Source: https://complyfirst.co/resources/sumup-regulatory-reporting
Last updated: 2026-03-11

---

# Decta Goes Live With Regulatory Reporting in <24hrs

> Following their 2024 authorisation, Decta needed a fast, reliable way to meet immediate regulatory reporting requirements.

Published: 2025-12-29

Decta is an Irish EMI that delivers a suite of payment services to businesses operating across Europe. Their offering includes payment gateway solutions, merchant accounts, and card services.



When Decta received its authorisation in 2024, regulatory obligations kicked in immediately - but with a tight deadline, **they needed a fast, reliable solution that could support reporting and help them hit key compliance milestones from day one.**

```json
{
  "_key": "66b11d76bdf4",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### The Challenge

Decta needed to submit its first regulatory return shortly after authorisation. The team had to move quickly to get the right systems in place, deliver accurate reports, and meet technical XML/XBRL formatting requirements without missing deadlines.

They also needed to ensure finance and compliance could work together on the process, even as the business was ramping up operations.

```json
{
  "_key": "f5b88e348e14",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "8a9980939b10",
      "_type": "block",
      "children": [
        {
          "_key": "f9bdf17125ed",
          "_type": "span",
          "marks": [
            "em"
          ],
          "text": "“We were licensed but not yet operational, and already facing a regulatory return. It had to be accurate, and it had to go in on time.” - "
        },
        {
          "_key": "5584a5713052",
          "_type": "span",
          "marks": [],
          "text": "Neil McDermott, CFO, Decta"
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "297fc5b4405a",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### Our Solution

Decta had to move fast. Complyfirst onboarded the team within 24 hours, giving them everything they needed to prepare, validate, and submit their return on time — no errors, no delays.



**Key features included:**

- Guided onboarding for first return
- Built-in XBRL output and CBI-ready formatting
- Rapid turnaround with real-time validation
- Collaborative workflow between finance and compliance

```json
{
  "_key": "bfeb7185c798",
  "_type": "resource-quote",
  "author": {
    "_type": "object",
    "name": "Neil McDermott",
    "position": "CFO, Decta"
  },
  "enableIllustrations": true,
  "text": [
    {
      "_key": "ddb4fed0d72b",
      "_type": "block",
      "children": [
        {
          "_key": "a5eaa0da7b2e",
          "_type": "span",
          "marks": [],
          "text": "I’ve worked at large banks with entire teams managing returns."
        },
        {
          "_key": "4a19db638c4d",
          "_type": "span",
          "marks": [
            "em"
          ],
          "text": " "
        },
        {
          "_key": "94732deef0c4",
          "_type": "span",
          "marks": [
            "em",
            "strong"
          ],
          "text": "With Complyfirst, we had it done in days."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "1fdf418a0971",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### The Results

Partnering with Complyfirst enabled Decta to:

1. **Achieve day-one compliance: **Live and reporting within 24 hours — an outcome that would take much longer at legacy institutions
2. **Submit error-free returns: **Despite being early in their operational setup, Decta filed clean reports.
3. **Establish audit-ready governance from the start: **The platform aligned finance and compliance teams from day one, creating a reliable and repeatable reporting process.

```json
{
  "_key": "27dfab50fa01",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### What's Next

With day-one compliance, Decta can scale fast, confident their reporting is accurate and audit-ready. Partnering with Complyfirst lets them enter new markets and launch products without compliance getting in the way.

```json
{
  "_key": "571c4c1c5a63",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "11dea08d897f",
      "_type": "block",
      "children": [
        {
          "_key": "6bc3f625f5e4",
          "_type": "span",
          "marks": [
            "em"
          ],
          "text": "“Reporting has become predictable and less concerning, so we can focus on the business.” "
        },
        {
          "_key": "4b716378566e",
          "_type": "span",
          "marks": [],
          "text": "— Neil McDermott, CFO, Decta"
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

---
Source: https://complyfirst.co/resources/decta-regulatory-reporting
Last updated: 2026-03-11

---

# Zing Speeds Up SAR Investigation Time From 6 Hours to Under 1

> Zing, a UK EMI and HSBC subsidiary, used Complyfirst to automate regulatory reporting and SARs, cutting workload and freeing up compliance teams.

Published: 2025-12-29

Zing, a UK-based Electronic Money Institution regulated by the FCA and subsidiary of HSBC, had an ambitious global roadmap. But as it scaled, compliance bottlenecks and manual processes were draining resources and slowing progress.

**To keep up, Zing needed a smarter, automated way to handle complex regulatory reporting and suspicious activity reporting requirements.**

```json
{
  "_key": "ec1690843a76",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### The Challenge

As Zing expanded, managing compliance across jurisdictions became increasingly complex. 

Manual workflows drained time and limited agility.

Zing required a scalable, tech-forward solution that could:

- Meet HSBC’s strict procurement and security standards
- Automate time-intensive reporting tasks
- Support growth across multiple products and markets

```json
{
  "_key": "19bfa1698713",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### Our Solution

After rigorous due diligence, Zing selected Complyfirst for its:

- ISO-27001 certification and enterprise-grade security
- Automation of regulatory and suspicious activity reporting
- Scalable, flexible workflows across jurisdictions and use cases

Zing first implemented Complyfirst’s regulatory reporting tools, then piloted AI-powered automation for UARs and SARs.

```json
{
  "_key": "3b1593779745",
  "_type": "resource-quote",
  "author": {
    "_type": "object",
    "name": "Lydia Whitely",
    "position": "Head Risk Framework & Operations, Zing by HSBC"
  },
  "enableIllustrations": true,
  "text": [
    {
      "_key": "4d81f5a2da37",
      "_type": "block",
      "children": [
        {
          "_key": "3a42056dd67f",
          "_type": "span",
          "marks": [],
          "text": "Complyfirst helps us pull together the "
        },
        {
          "_key": "305c7758dc74",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "right data, spot issues, and easily submit reports."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "7692133c82a7",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### The Results

The impact was immediate and substantial:

- Regulatory reporting cut significantly –** saving hundreds of hours annually**
- UARs/SARs reduced from** 6 hours to under 1 **– redeploying team resources
- AI-powered workflows called a** “game changer” **for compliance ops.

```json
{
  "_key": "3a8e752c1bd1",
  "_type": "resource-quote",
  "author": {
    "name": "Lydia Whitely",
    "position": "Head of Risk Framework &  Operations, Zing by HSBC"
  },
  "enableIllustrations": true,
  "text": [
    {
      "_key": "894be3dead3f",
      "_type": "block",
      "children": [
        {
          "_key": "b1d2d9451ef4",
          "_type": "span",
          "marks": [],
          "text": "The Complyfirst team is "
        },
        {
          "_key": "0f39b98798bb",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "adaptable, proactive"
        },
        {
          "_key": "5a122b1c1057",
          "_type": "span",
          "marks": [],
          "text": " and has made our processes slick and easy."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "9e736edf2f2c",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### What's Next

Zing is now moving the UAR/SAR automation from pilot to production, and expanding regulatory reporting automation into new jurisdictions.

---
Source: https://complyfirst.co/resources/zing-regulatory-reporting-and-sars
Last updated: 2026-03-11

---

# TrueLayer Spends 50% Less Time on Regulatory Reporting with Complyfirst

> TrueLayer, Europe’s leading Pay by Bank provider, regulated by the FCA and CBI, needed to simplify regulatory reporting across the UK and Ireland.

Published: 2025-12-15

TrueLayer, Europe’s leading Pay by Bank provider, regulated by the FCA and CBI, needed to simplify regulatory reporting across the UK and Ireland. Rapid growth drove the requirement to migrate from manual, spreadsheet-based processes to more efficient solutions.

**TrueLayer needed a more advanced and centralised approach to managing complex regulatory reporting requirements.**

```json
{
  "_key": "eed93f20d9bc",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### The Challenge

TrueLayer’s compliance, risk, and finance teams needed to streamline and coordinate regulatory reporting across multiple regimes. Their previous XML/XBRL conversion tool offered only basic functionality, requiring extensive manual input and oversight. To meet scaling demands, they needed a solution to enhance data consistency, reduce manual effort, and improve governance and oversight.

```json
{
  "_key": "9d55da700e1e",
  "_type": "resource-quote",
  "author": {
    "name": "Pamela Crilly",
    "position": "EU COO, TrueLayer"
  },
  "enableIllustrations": true,
  "text": [
    {
      "_key": "13ce287ba540",
      "_type": "block",
      "children": [
        {
          "_key": "a778fd11eca1",
          "_type": "span",
          "marks": [],
          "text": "Reporting involved multiple teams, lots of spreadsheets, with "
        },
        {
          "_key": "cb41d0c361d6",
          "_type": "span",
          "marks": [
            "strong",
            "em"
          ],
          "text": "limited visibility"
        },
        {
          "_key": "401e8648adcc",
          "_type": "span",
          "marks": [],
          "text": " across."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "6c71d0bb205b",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### Our Solution

Complyfirst replaced TrueLayer’s manual, spreadsheet-heavy workflows with an **AI-powered platform built for scale and control**.

**Key features included:**

- Spreadsheets replaced with a single AI-powered platform
- Real-time validation checks and intelligent variance analysis
- Approval workflows & audit trails for visibility andcompliance.

```json
{
  "_key": "3e9df705e218",
  "_type": "resource-quote",
  "author": {
    "name": "Pamela Crilly",
    "position": "EU COO, TrueLayer"
  },
  "enableIllustrations": true,
  "text": [
    {
      "_key": "5f5cd8d50267",
      "_type": "block",
      "children": [
        {
          "_key": "bfe921321e6e",
          "_type": "span",
          "marks": [],
          "text": "What truly sets Complyfirst apart is its ability to "
        },
        {
          "_key": "47d7e6507c49",
          "_type": "span",
          "marks": [
            "em",
            "strong"
          ],
          "text": "simulate a regulator’s review"
        },
        {
          "_key": "ba41334f6377",
          "_type": "span",
          "marks": [],
          "text": "."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```

```json
{
  "_key": "b1078b514e98",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### The Results

The impact of switching to Complyfirst was immediate:

- Reporting effort **reduced by 50% **- saving TrueLayer hundreds of hours annually
- The DORA Register was successfully submitted, error-free, to the CBI with **24 hours **of opening
- TrueLayer gained **a single source of truth **for data reporting across **multiple jurisdictions**, enabling robust compliance and governance.

This success was underpinned by **Complyfirst’s hands-on support and flexibility **throughout implementation.

```json
{
  "_key": "46c921e2fdb2",
  "_type": "resource-divider",
  "placeholder": "Visual divider"
}
```

###### What's Next

TrueLayer is now exploring new use cases for Complyfirst, including the automation of **financial crime, fraud, and AML reporting.**

---
Source: https://complyfirst.co/resources/truelayer-regulatory-reporting
Last updated: 2026-05-05

---

# DORA Register of Information Requirements Explained (Guide for EU Financial Entities)

> Clear guide to the DORA ROI: what it includes, how to complete the 15 tables, use the 4 keys, and avoid the errors seen in the dry run.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Published: 2025-12-15

```json
{
  "_key": "62f398fddd8f",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

Under the Digital Operational Resilience Act (DORA), all in-scope EU financial entities must submit a detailed Register of Information. Regulators like the European Banking Authority (EBA) use this Register to monitor ICT dependencies, assess exposure to critical ICT providers, and identify concentration risk across the EU financial system.



Nearly [93.5% of firms](https://en.paperjam.lu/article/93-5-of-dora-dry-run-submissions-had-at-least-1-data-error-esas-report) failed the dry run at the end of 2024, largely due to data quality problems and incorrect mapping. With mandatory annual reporting beginning in 2025, firms across the EU must improve their approach for the next DORA submission.



Let’s get into it. 💪🏻



```json
{
  "_key": "476d08f28b8d",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "03772a5a55c9",
      "_type": "block",
      "children": [
        {
          "_key": "a09c60ffb4b7",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "021121e270d4",
      "_type": "block",
      "children": [
        {
          "_key": "abcce5c38732",
          "_type": "span",
          "marks": [],
          "text": "The DORA Register of Information is a mandatory EU-wide return that captures a firm’s full ICT service and supply chain. It consists of 15 interconnected tables linked by four keys: "
        },
        {
          "_key": "a0ec7551bb7d",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "contract references, LEIs, function IDs,"
        },
        {
          "_key": "27a782394ef0",
          "_type": "span",
          "marks": [],
          "text": " and "
        },
        {
          "_key": "4a5734f3211c",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "ICT service types."
        },
        {
          "_key": "d8b4acd61d97",
          "_type": "span",
          "marks": [],
          "text": " 93.5% of firms failed the dry run due to missing mandatory data, weak supply-chain mapping, and inconsistent keys. This guide explains what the Register of Information contains, how to complete it, and how to avoid the common errors identified in the first round of DORA reporting."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



#### **What the DORA Register of Information Contains**

The DORA Register of Information consists of 15 structured tables that map a firm’s entire ICT environment. These tables are designed to capture all ICT arrangements and the interdependencies across providers and functions.  
  
The Register of Information includes:  


1. Entity details
2. List of entities
3. List of branches
4. Contract overview
5. Contract details
6. Intra-group contracts
7. Signing entities
8. ICT providers
9. In-group providers
10. Service users
11. Subcontractors
12. Supply chain
13. Functions list
14. ICT assessment
15. Definitions used



```json
{
  "_key": "40e6ac4cc4ff",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "118818e0d1be",
      "_type": "block",
      "children": [
        {
          "_key": "0cd185b05a9f",
          "_type": "span",
          "marks": [],
          "text": "💡 To support standardisation, the Register must be submitted in "
        },
        {
          "_key": "942cc337d2bb",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "XBRL-CSV format."
        },
        {
          "_key": "3461b0360db9",
          "_type": "span",
          "marks": [],
          "text": " It relies on extensive EBA Implementing Technical Standards (ITS) and Data Point Model (DPM) rules that define each data point. These rules determine what must be reported and how the keys must be used consistently."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



```json
{
  "_key": "4ac3bbedd67a",
  "_type": "resource-media",
  "image": {
    "_type": "image",
    "alt": "dora roi",
    "asset": {
      "_ref": "image-c79fe56c87bb003b0d05d1c1e8c9a04db3eb1002-2216x1204-png",
      "_type": "reference"
    },
    "crop": {
      "_type": "sanity.imageCrop",
      "bottom": 0.018364676768045474,
      "left": 0,
      "right": 0.005226815906861242,
      "top": 0
    },
    "hotspot": {
      "_type": "sanity.imageHotspot",
      "height": 0.9816353232319546,
      "width": 0.9947731840931388,
      "x": 0.4973865920465694,
      "y": 0.4908176616159773
    }
  },
  "mediaType": "image"
}
```



#### **Who Must Comply and When**

**Almost all financial entities in the EU must submit the Register of Information**, regardless of size or number of ICT contracts. This includes:

- Banks and credit institutions
- e-Money and payments firms
- Investment firms
- Insurers
- Crypto-asset service providers (MiCA + DORA interaction)
- Trading venues
- FinTech and RegTech entities in scope

###### **Frequency of reporting:**

- Annual reporting
- Additional reporting when material ICT changes occur (per DORA Articles 28–30)



These timelines mean firms need ongoing governance of ICT data, not just point-in-time collection.



#### **How to Complete the Register of Information (Using the 4 Keys)**

Now, most importantly, let’s take a look at the four keys that connect all 15 tables. These keys determine how data links together and form the backbone of the Register.

###### **Key 1: Contract Reference Number**

- Unique internal ID for each ICT contract
- Must be consistent across all templates
- Applies to external and internal/intragroup providers

###### **Key 2: Legal Entity Identifier (LEI)**

- Required for the contracting entity and each direct ICT provider
- This is a 20-character code unique to each entity

###### **Key 3: Function ID**

- This is a unique function ID that you create from the LEI, the licensed activity + the function
- For example, if Salesforce supports your sales team for both your payment and e-money activities, you need two separate function IDs.

###### **Key 4: ICT Service Type (Annex III Codes S01–S19)**

- Classifies the service and determines applicable data fields
- Examples include S01 (ICT Project Management) and S02 (ICT Development)



Using these keys correctly is essential because all validation checks rely on them. Take a look at how these keys link across the 15 tables.



```json
{
  "_key": "6456af44b205",
  "_type": "resource-media",
  "image": {
    "_type": "image",
    "alt": "dora roi links",
    "asset": {
      "_ref": "image-285b31b8e9ab07ae1ff7bcda7268ca2a81e06d97-1902x1246-png",
      "_type": "reference"
    }
  },
  "mediaType": "image"
}
```



#### **Step-by-Step Compliance Checklist**

This checklist provides a practical step-by-step process to follow once the four keys are understood.  


###### **Step 1: Build the ICT Services Inventory**

Begin by capturing all ICT services used across the organisation, including external and intragroup arrangements. Engage operational teams to ensure the list reflects actual usage. This step forms the foundation for the steps to follow.

****

###### **Step 2: Assess Criticality**

Next, determine whether each service supports Critical or Important Functions (CIFs) under Article 3(22). Identify material subcontractors under Article 30(2). This assessment helps determine which additional data fields will apply in later steps.

****

###### **Step 3: Map the ICT Supply Chain**

Once criticality is established, map the supply chain for each service.

- Assign the correct Annex III ICT service type
- Identify direct providers and any material subcontractors
- Rank them appropriately (Rank 1 = direct provider)
- Link all providers using contract references and ICT service types



Below is an example of what an ICT service supply chain looks like in practice.



```json
{
  "_key": "e4f8571159da",
  "_type": "resource-media",
  "image": {
    "_type": "image",
    "alt": "dora ict supply chain",
    "asset": {
      "_ref": "image-459bb8502786f07ca05f5c7b10860f1c0b46e3dc-1612x932-png",
      "_type": "reference"
    }
  },
  "mediaType": "image"
}
```



Your direct ICT providers are always **Rank 1.**  
They may use **Rank 2** material subcontractors.  
And those may rely on **Rank 3** subcontractors.  
  
The key point is that everyone in that chain sits in the same supply chain if they map back to the same contract reference number and the same Annex III ICT service type.



###### **Step 4: Apply the Four Keys Consistently**

Then, apply the four keys across every relevant template.

- Use the same contract reference number throughout
- Ensure each provider’s LEI is correct
- Apply Function IDs consistently across business units
- Verify that ICT service types match the service they describe

###### **Step 5: Validate Data Quality**

Finally, validate all fields. Check that all fields are complete and accurate. Follow the EBA’s Data Point Model (DPM) dropdown lists and coding rules carefully to avoid misreporting.



```json
{
  "_key": "8214d47c11bd",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "39e59257868c",
      "_type": "block",
      "children": [
        {
          "_key": "6142af6b6281",
          "_type": "span",
          "marks": [],
          "text": "💡 "
        },
        {
          "_key": "6a1d52170540",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "Conduct early validation"
        },
        {
          "_key": "dfa386e5be8d",
          "_type": "span",
          "marks": [],
          "text": " using a test portal to confirm that the dataset meets the submission requirements ahead of the reporting deadline."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



#### **Lessons Learned from DORA 1.0**

The dry run results show why firms must improve their approach ahead of the next DORA submission.



**As mentioned above, 93.5% of firms failed the dry run 😰 **meaning only 6.5% passed all 116 validation checks, with most failures being due to missing mandatory data.



Here’s where firms tripped up:



```json
{
  "_key": "a43cdd0be1d9",
  "_type": "table",
  "rows": [
    {
      "_key": "5cce45db-5f44-4b24-abfb-3f37c5db5231",
      "_type": "tableRow",
      "cells": [
        "Missing mandatory data (86% of errors)",
        "Key identifiers were missing: LEI’s for parent entities and ICT providers, Function IDs, ICT service type, Country of provider, Supply chain details."
      ]
    },
    {
      "_key": "a6d8c224-b56d-4865-aef3-ab1a661ac93d",
      "_type": "tableRow",
      "cells": [
        "Not using the 4 keys correctly",
        "Firms re-used values that must be unique (contract ref no, function ID etc) which prevents tables from linking correctly."
      ]
    },
    {
      "_key": "7e7f4ea8-28d1-44e6-bec0-bce8487677da",
      "_type": "tableRow",
      "cells": [
        "Not following the DPM (Data point model)",
        "Didn’t use the required drop-down values, used free text instead of the allowed codes, or didn’t follow the official DPM structure."
      ]
    },
    {
      "_key": "acc396df-182d-412d-a954-2d3bd5b2290f",
      "_type": "tableRow",
      "cells": [
        "FAQs differing from EBA guidance",
        "Firms got stuck when newer FAQs superseded the EBA guidance and working with multiple files + packages."
      ]
    },
    {
      "_key": "abe836ca-21e3-478e-a7ba-6a4391539ea5",
      "_type": "tableRow",
      "cells": [
        "Missing supply chain details",
        "Left supply chain fields blank, didn’t identify subcontractors, didn’t assign ranks, or didn’t link providers correctly."
      ]
    },
    {
      "_key": "9fbcfc34-807a-4b6b-b634-fc730c8628cc",
      "_type": "tableRow",
      "cells": [
        "Gap in compliance AND technical knowledge",
        "Teams struggled to fix validation errors + existing vendors couldn’t support or generate the correct files."
      ]
    }
  ]
}
```



These lessons show where firms should focus in the next submission, particularly on supplier LEIs, service-type mapping, and consistent key usage.



#### **Submit Your DORA Return 90% Faster with Complyfirst**

Now, in case you’re wondering how we support firms with their DORA returns, here’s a quick overview. We focus on 4 key things:

###### **1. Easy Uploads and Updates**

Easily upload your own files or EBA templates, and reuse last year’s Register to avoid having to start from scratch.

###### **2. EBA Guidance Built into Every Cell**

Each cell you’re working in includes direct extracts from official EBA materials to remove having to search across different documents.

###### **3. Real-Time, Plain-English Error Messages**

Validate your data as you work, and fix issues with clear “how to fix it” steps.

###### **4. 1:1 Expert Support**

Most importantly, we’re here for you! We’re available via Slack, Teams, and Zoom for quick troubleshooting (even on deadline day 😬).



#### Watch Our DORA ROI Lessons-Learned Webinar with Fiona

After supporting firms through the first full year of DORA, Fiona hosted a live webinar with [fscom](https://fscom.co/) sharing how financial entities across Europe responded to DORA, and what to do differently for the next submission. **Have a watch below.**



```json
{
  "_key": "8a32b8bd61bd",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/n1PWMOOn6Bo"
}
```



```json
{
  "_key": "8ffa14b274f7",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "88bd49d31fef",
      "content": [
        {
          "_key": "fbf82ec3f50d",
          "_type": "block",
          "children": [
            {
              "_key": "db145bfd1194",
              "_type": "span",
              "marks": [],
              "text": "The DORA Register of Information is a required inventory of all ICT systems, services, and third-party providers used by a financial entity. It must list each item, its purpose, its criticality, and the related contracts or data flows. The Register helps the EBA understand a firm’s technology dependencies and operational risks."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "1. What is the DORA Register of Information?"
    },
    {
      "_key": "760dcf79c163",
      "content": [
        {
          "_key": "9599a6535e31",
          "_type": "block",
          "children": [
            {
              "_key": "1282dd980a82",
              "_type": "span",
              "marks": [],
              "text": "DORA applies to almost all financial entities in the EU. This includes banks, payments firms, insurers, investment firms, and crypto-asset service providers. Critical ICT third-party providers are also covered. Non-EU firms operating in the EU must comply as well."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "2. Which firms are required to comply with DORA?"
    },
    {
      "_key": "11e2b1c8a1f6",
      "content": [
        {
          "_key": "68fb833691bd",
          "_type": "block",
          "children": [
            {
              "_key": "d94ec8540719",
              "_type": "span",
              "marks": [],
              "text": "There is no official tool for the DORA Register of Information. Firms must create their own Register and keep it complete and up to date. Tools like Complyfirst can support by letting you reuse last year’s data to avoid starting from scratch, view EBA guidance directly in each field, validate entries as you work, and access support when needed."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "3. Is there a DORA Register of Information tool?"
    },
    {
      "_key": "57b0503978f1",
      "content": [
        {
          "_key": "4a89f8aff6d9",
          "_type": "block",
          "children": [
            {
              "_key": "f64dd040c39e",
              "_type": "span",
              "marks": [],
              "text": "Missing LEIs are among the top validation failures. You must obtain LEIs for all direct ICT providers and the contracting entity."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "4. What happens if LEIs for providers are missing?"
    },
    {
      "_key": "f6948c8acbc1",
      "content": [
        {
          "_key": "5e89f66ee550",
          "_type": "block",
          "children": [
            {
              "_key": "94d651617c11",
              "_type": "span",
              "marks": [],
              "text": "Firms must identify "
            },
            {
              "_key": "846eec55e357",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "material subcontractors"
            },
            {
              "_key": "1cf0a954de1c",
              "_type": "span",
              "marks": [],
              "text": ", rank them, and link them within the supply chain."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "5. How detailed must subcontractor mapping be?"
    },
    {
      "_key": "8a565a3d2ed8",
      "content": [
        {
          "_key": "96c8e07a4fc4",
          "_type": "block",
          "children": [
            {
              "_key": "eb7732ff6827",
              "_type": "span",
              "marks": [],
              "text": "No. Function IDs must be unique. If the same ICT service supports two regulated activities, create two separate Function IDs."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "6. Can a Function ID be reused across activities?"
    },
    {
      "_key": "fc94bb54db04",
      "content": [
        {
          "_key": "c44f7de12fc4",
          "_type": "block",
          "children": [
            {
              "_key": "7a1c2c9f1cba",
              "_type": "span",
              "marks": [],
              "text": "Common reasons include inconsistent keys, missing mandatory fields, incorrect service types, and unsupported vendor tooling."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "7. What causes XBRL submissions to fail?"
    },
    {
      "_key": "626ca348ebfd",
      "content": [
        {
          "_key": "115cb60679c5",
          "_type": "block",
          "children": [
            {
              "_key": "34edc19f8007",
              "_type": "span",
              "marks": [],
              "text": "Start early. Data gathering and supply-chain mapping take longer than firms expect, particularly in large or decentralised organisations."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "8. How early should firms start the Register of Information process?"
    }
  ],
  "title": "FAQ"
}
```

## Conclusion

The DORA Register of Information is complex, data-heavy, and strictly validated. Firms must understand the 15-table structure, apply the four keys consistently, and document the full ICT supply chain, including subcontractors. With improved data governance, early preparation, and the right support, firms can avoid the high failure rates seen in DORA 1.0 and ensure smooth 2026 reporting.

---
Source: https://complyfirst.co/resources/dora-roi-guide-for-eu-financial-entities
Last updated: 2026-02-16

---

# DORA ROI Demystified

> Fiona joins fscom’s Stuart Smith and Benjamin Gray to discuss how firms have responded to DORA one year after implementation, sharing lessons learned, reporting insights, and best practices.

Published: 2025-11-28

```json
{
  "_key": "4d94b9723780",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/n1PWMOOn6Bo"
}
```

Fiona joins fscom’s Stuart Smith and Benjamin Gray to discuss how firms have responded to DORA one year after implementation, sharing lessons learned, reporting insights, and best practices.

```json
{
  "_key": "5b21ea113f7f",
  "_type": "resource-quick-links",
  "links": [
    {
      "_key": "35d404619acd",
      "_type": "linkItem",
      "description": "DORA ROI Demystified",
      "title": "Webinar Slides",
      "url": "https://complyfirst.co/resources/files/dora-webinar-slides"
    }
  ],
  "title": "More Resources"
}
```

---
Source: https://complyfirst.co/resources/complyfirst-fscom-dora-webinar
Last updated: 2026-03-12

---

# Briefing 1: AML REQ Overview

> A practical walkthrough of the new AML REQ: who it applies to, what’s changing, key deadlines for PI/EMI and Credit Institutions, and how to prepare for XML-only submissions via the CBI portal.

Published: 2025-11-21

```json
{
  "_key": "9c34f2d74186",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/OvQYNr4etRI"
}
```

Fiona gives a practical walkthrough of the new AML REQ: who it applies to, what’s changing, key deadlines for PI/EMI and Credit Institutions, and how to prepare for XML-only submissions via the CBI portal.

```json
{
  "_key": "e756f285753b",
  "_type": "resource-quick-links",
  "links": [
    {
      "_key": "4df2cda4aaf0",
      "_type": "linkItem",
      "description": "The New AML REQ & Beyond",
      "title": "Webinar Slides",
      "url": "https://complyfirst.co/resources/files/aml-req-breakfast-briefing-slides"
    }
  ],
  "title": "More Resources"
}
```

---
Source: https://complyfirst.co/resources/aml-req-overview
Last updated: 2026-03-12

---

# Briefing 2: Practical steps to comply with the AML REQ

> A practical walkthrough of the steps firms need to complete for the AML REQ:  from data extraction and gap analysis to XML decisions, and CBI testing and submission.

Published: 2025-11-20

```json
{
  "_key": "088819ad3b03",
  "_type": "resource-media",
  "mediaType": "youtube",
  "youtubeUrl": "https://youtu.be/mIfyr3hW63Y"
}
```

Dan gives a practical walkthrough of the steps firms need to complete for the AML REQ: from data extraction and gap analysis to XML decisions, and CBI testing and submission.

```json
{
  "_key": "88081bb0ca70",
  "_type": "resource-quick-links",
  "links": [
    {
      "_key": "d3ad31f3dc5b",
      "_type": "linkItem",
      "description": "The New AML REQ & Beyond",
      "title": "Webinar Slides",
      "url": "https://complyfirst.co/resources/files/aml-req-breakfast-briefing-slides"
    }
  ],
  "title": "More Resources"
}
```

---
Source: https://complyfirst.co/resources/briefing-2-aml-req-steps
Last updated: 2026-03-12

---

# Central Bank of Ireland's New AML REQ Explained for Payment and E-Money Institutions

> The Central Bank of Ireland has introduced a new XML-based AML REQ for Irish PIs and EMIs. Learn what’s changed, what data is required, and how to prepare for the 13 Feb 2026 deadline.

Author: Fiona Jelly, Founder & CEO of Complyfirst  
Jurisdiction: Ireland  
Published: 2025-11-18

```json
{
  "_key": "b55bef16c8b0",
  "_type": "resource-table-of-contents",
  "placeholder": "Table of contents will be automatically generated from headings"
}
```

The [Central Bank of Ireland](https://www.centralbank.ie/) has redesigned its [AML Risk Evaluation Questionnaire](https://www.centralbank.ie/regulation/anti-money-laundering-and-countering-the-financing-of-terrorism/sector-specific-ml-tf-risk-evaluation-questionnaire) to introduce a more structured, data-driven, and prescriptive reporting framework for Irish Payment Institutions and Electronic Money Institutions.  
  
This new AML REQ is not a survey or a one-off data call. It is a **core annual supervisory data set** that the CBI will use to evaluate ML/TF risks, review firm-level governance, and feed EU-wide AML oversight via AMLA.  
  
Because the return is now **schema-driven, mandatory, and XML-only**, Irish firms must prepare well ahead of the 13 February 2026 deadline.



```json
{
  "_key": "57e9f3af1072",
  "_type": "resource-highlighted-box",
  "content": [
    {
      "_key": "1e8e20c6dcc2",
      "_type": "block",
      "children": [
        {
          "_key": "71904ca1bd2c",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "TL;DR"
        }
      ],
      "markDefs": [],
      "style": "normal"
    },
    {
      "_key": "3e112a03b3c7",
      "_type": "block",
      "children": [
        {
          "_key": "424c4bfe6817",
          "_type": "span",
          "marks": [],
          "text": "The Central Bank of Ireland (CBI) has launched a new AML Risk Evaluation Questionnaire (AML REQ) that replaces the previous REQ for Payment Institutions (PIs) and Electronic Money Institutions (EMIs). The return is now a mandatory, fully XML-based data submission aligned with EU-level AMLA reporting. The first return covers data as at "
        },
        {
          "_key": "8c2c498ba44f",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "31 December 2024"
        },
        {
          "_key": "f5a0044baaa7",
          "_type": "span",
          "marks": [],
          "text": " and must be submitted by "
        },
        {
          "_key": "c077705a0db9",
          "_type": "span",
          "marks": [
            "strong"
          ],
          "text": "13 February 2026"
        },
        {
          "_key": "911dfb92bf66",
          "_type": "span",
          "marks": [],
          "text": " via the CBI Portal."
        }
      ],
      "markDefs": [],
      "style": "normal"
    }
  ]
}
```



#### What is the New AML REQ?

The AML Risk Evaluation Questionnaire is the Central Bank of Ireland’s annual ML/TF risk and controls return for Payment Institutions and Electronic Money Institutions.



The redesigned AML REQ is a **13-section XML submission** with mandatory fields, strict enumerations, and schema-based validations. It replaces the previous Excel-based REQ and is now aligned with AMLA’s EU-level data reporting model.



#### Who Must Comply and Key Deadlines



###### Affected Entities

- Payment Institutions operating in Ireland
- Electronic Money Institutions operating in Ireland



###### Key Dates

- **Reference date:** 31 December 2024 (and annually thereafter)
- **Submission deadline:** 13 February 2026 (CBI confirms **no extensions**)
- **Portal availability:** At least two weeks before deadline
- **Dry-run testing:** Q4 2025



#### Key Changes Introduced



###### Old REQ:

- 8 mixed-format sections
- Broad qualitative and quantitative fields
- Excel upload
- Less structured and low validation burden



###### New AML REQ:

- 13 structured, schema-driven sections
- XML-only submission
- Mandatory fields and strict “not applicable” codes
- Embedded CBI Portal validations + post-submission checks
- Expanded coverage of customers, products, risks, and controls



#### High-Level Changes

1. Full XML/XSD schema enforcement
2. Mandatory fields; no blanks permitted
3. Country, product, and activity enumerations
4. Transaction-level volume/value data by risk tier
5. Detailed control activity statistics (TM rules, alerts, false/true positives)
6. More granular geographic breakdowns (customers + funds flow)



```json
{
  "_key": "d317ce5b5711",
  "_type": "resource-media",
  "image": {
    "_type": "image",
    "alt": "cbi aml req ",
    "asset": {
      "_ref": "image-88cef1296b4cb8e40b215348513970a10cd9f561-2264x1272-png",
      "_type": "reference"
    }
  },
  "mediaType": "image"
}
```



#### Section-by-Section Overview of the New AML REQ

The new AML REQ consists of 13 sections:

1. **General** – Legal form, LEIs, PSD2 permissions, business model, cross-border operations.
2. **Inherent Risk** – Customer types, products, transaction counts/values by risk tier.
3. **Mitigation & Control** – BWRA, CDD, sanctions screening, TM rules and performance, audits.
4. **Physical Presence** – Subsidiaries, branches, agents by country.
5. **Residence & Establishment** – Customers by country, including high-risk, PEPs, new customers.
6. **Beneficial Owners** – BO counts by country and PEP status.
7. **Digital Accounts** – Account balances, loads/payouts, high-risk splits.
8. **Prepaid Cards & Vouchers** – Balances, loads, payouts, high-risk splits.
9. **Merchant Acquiring** – Payment/refund statistics and high-risk splits.
10. **Correspondent Relationships** – Respondent institutions, flows, high-risk splits.
11. **Money Remittance** – Remittance flows by country and high-risk classification.
12. **Geography of Funds Flow** – Source/destination volumes and high-risk indicators.
13. **Transaction Monitoring** – Rule inventory, alert counts, true/false positive data.



#### Submission Format and Validation Requirements



###### Format Requirements

- XML only
- Must validate against CBI’s published XSD schema
- Excel version is for preparation only; **Excel uploads are not accepted**



###### Validation Flow

1. **Pre-submission:**  
Pass schema checks locally to avoid CBI Portal errors.
2. **Portal checks:**  
Mandatory hard validations upon upload.
3. **Post-submission:**  
CBI performs further checks and may request clarification.
4. **Completion:**  
Firms must “Finalise” and “Sign-Off” to complete the submission.



#### Mandatory Data Rules

- **Risk ratings:** Use ratings as at the reference date (31 December 2024).
- **Currency:** Report all values in euro.
- **FX rate:** Use either transaction-date or reference-date rate.
- **Mandatory field logic:** 
   - Use required placeholders: 0, N/A, 2000-01-01, all-zero LEI, Country 00.
   - No blank fields permitted.



#### Step-By-Step Checklist to Submit Your AML REQ

1. **Assign Ownership** 
   - Appoint Board-level and operational owners.
   - Define sign-off responsibilities.
   - Maintain a documented REQ run-book.
2. **Map Your Data to the Schema** 
   - Map every field to the CBI XSD.
   - Build enumerations for products, PSD2 permissions, country codes, and outsourcing statuses.
   - Hard-code “N/A” rules to prevent blanks.
3. **Automate Data Extraction**  
   - Customers
   - Transactions
   - Products
   - Risk assessments
   - Controls
4. **Prepare Evidence for Supervisory Review**  
   - BWRA approvals
   - Policies and procedures
   - Training completion
   - Compliance and audit testing logs
5. **Run Validations and Dry Runs** 
   - Generate XML early and validate locally.
   - Participate in Q4 2025 dry-run testing.
   - Confirm “Finalise” + “Sign-Off.”
6. **Maintain a Repeatable Run-Book** 
   - Document sources, transformations, and checks.
   - Align with internal controls and governance expectations.



#### Common Challenges for Irish PI/EMI Firms

- Mapping legacy systems to XML schema fields
- High granularity of customer and geographic data
- TM rule-level statistics not currently centralised
- Lack of standardised enumerations
- Missing data lineage and documentation
- Underestimating build time for XML generation and validation



#### How Complyfirst Helps

Complyfirst provides the tools and support to deliver a compliant AML REQ submission, aligned to the CBI’s schema and deadlines.



#### What We Deliver

- Full data-to-XSD mapping support
- Automated XML generation in CBI-compliant format
- Built-in schema checks to avoid rejections
- Workflow, sign-off, and version control
- 1:1 support via Slack and Zoom, including deadline-day assistance



```json
{
  "_key": "6c18fb6c7e83",
  "_type": "resource-accordion",
  "items": [
    {
      "_key": "0077fd421d09",
      "content": [
        {
          "_key": "55b08faf8a1e",
          "_type": "block",
          "children": [
            {
              "_key": "afecc55359c7",
              "_type": "span",
              "marks": [],
              "text": "The CBI AML Risk Evaluation Questionnaire (AML REQ) is the Central Bank of Ireland’s annual reporting return used to assess money laundering and terrorist financing risks in Payment Institutions and Electronic Money Institutions. It requires firms to submit structured XML data on customers, products, geographic exposure, controls, and governance, forming part of the CBI’s core supervisory dataset."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "What is the CBI AML REQ?"
    },
    {
      "_key": "94ada219a229",
      "content": [
        {
          "_key": "b1d20d26ee96",
          "_type": "block",
          "children": [
            {
              "_key": "3ebc8b6e80d4",
              "_type": "span",
              "marks": [],
              "text": "Yes. The updated AML REQ is required for all Payment Institutions and Electronic Money Institutions supervised by the Central Bank of Ireland. The return forms part of the CBI’s core supervisory data set and is not optional."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Is the new AML REQ mandatory for all PIs and EMIs in Ireland?"
    },
    {
      "_key": "ecefb69fc725",
      "content": [
        {
          "_key": "6cfd54a82d95",
          "_type": "block",
          "children": [
            {
              "_key": "dc4ad69c0a5a",
              "_type": "span",
              "marks": [],
              "text": "No. Excel is for preparation only. The CBI will accept "
            },
            {
              "_key": "ce3ad6c139bb",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "XML files only"
            },
            {
              "_key": "c8c803fdb22a",
              "_type": "span",
              "marks": [],
              "text": ", and they must validate against the published XSD schema."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Can firms submit the AML REQ using Excel?"
    },
    {
      "_key": "fab27d3df309",
      "content": [
        {
          "_key": "6b18d8365118",
          "_type": "block",
          "children": [
            {
              "_key": "c762f3d45b12",
              "_type": "span",
              "marks": [],
              "text": "No. The CBI has confirmed the "
            },
            {
              "_key": "3f41849a301e",
              "_type": "span",
              "marks": [
                "strong"
              ],
              "text": "13 February 2026"
            },
            {
              "_key": "b43674753af9",
              "_type": "span",
              "marks": [],
              "text": " deadline is fixed and that extensions will not be provided. Firms must prepare early."
            }
          ],
          "markDefs": [],
          "style": "normal"
        }
      ],
      "title": "Will the CBI grant deadline extensions?"
    }
  ],
  "title": "FAQ"
}
```

## Conclusion

The new AML REQ represents the most significant AML data collection requirement Irish Payment Institutions and Electronic Money Institutions have faced. It is technical, prescriptive, and designed to provide the CBI and AMLA with a consistent, data-rich view of ML/TF risks and controls. Firms that prepare now, building data models, XML processes, and governance, will avoid deadline pressure and reduce the risk of regulatory follow-up.



If you want support preparing for the 2026 deadline, get in touch with us touch with us at at [Complyfirst](https://complyfirst.co/) for guidance and tools aligned with the CBI’s schema.

---
Source: https://complyfirst.co/resources/cbi-new-aml-req-requirements-explained
Last updated: 2026-08-13
