On 29 May 2026, the Central Bank of Cyprus applied the full Payment Institutions governance regime to Electronic Money Institutions. It took effect the day it was published. There is no transition period — and the accountability sits with your board.
Six articles. One that matters.
K.Δ.Π. 245/2026 is easy to file as routine. It runs to six articles and, on its face, introduces very little new text.
That is the trap.
Article 5 applies the Payment Institutions Internal Organisation & Governance Directive of 2026 to EMIs by analogy. In a single sentence, a far more demanding regime — one your institution was never scoped against — now defines what the regulator expects of you.
The obligations are not abstract. Board oversight with clearly allocated responsibilities. Three lines of defence. An enterprise risk framework. ICT and outsourcing risk management. An independent compliance function and MLRO. Internal audit. A defined policy suite. And documented internal controls — segregation of duties, four-eyes approvals, escalation, incident reporting.
For an institution built lean and fast, several of these are, at best, partially built.
Where do you actually stand?
Find out where you actually stand.
A structured diagnostic against every obligation under 245/2026.
The detail most boards will miss
Article 6 brings the directive into force from the date of publication.
No phase-in. No grace window. No staged timetable.
This changes the question in front of your board. It is no longer "when do we need to be ready?" It is "can we evidence, today, that we already are?"
Most EMIs cannot answer that with confidence. Not because they lack policies — but because they cannot produce the proof.
Five questions. If you can't answer all five, you have exposure.
Take these to your next board meeting:
Can we produce, within an hour, the complete decision trail behind any single high-risk onboarding — who decided, on what evidence, approved by whom, and when?
Can we demonstrate four-eyes approval as an enforced control, not a policy statement?
Can we show the board received, reviewed and acted on our material risks — with dates?
Can we evidence ICT and third-party risk management to the standard now expected of us?
If the supervisor asked tomorrow, would our answer come from a system — or from someone reconstructing it across spreadsheets and email threads?
A supervisor rarely disputes that a policy exists. They ask to see it operating. The institutions that struggle are not the ones without policies. They are the ones whose policies live in documents while the work happens across disconnected tools — leaving no coherent audit trail to point to.
Governance that cannot be evidenced is, functionally, governance you do not have.
What good looks like — and what it costs you not to have it
Closing the gap is half organisational, half operational.
The organisational half — committee structures, an independent MLRO, the policy suite, board reporting rhythms — is governance design. It requires judgement and regulatory experience, not software.
The operational half — turning controls into enforced, timestamped, auditable actions — is where technology earns its place. This is the half that removes weeks of manual effort and produces exactly the evidence a regulator asks for.
Get both right and the calculus inverts: the same infrastructure that satisfies your supervisor gives your compliance team its time back. Institutions running this properly have replaced four to six fragmented tools with a single auditable layer and cut manual compliance workload substantially.
Get it wrong and you carry an exposure your board cannot see, cannot quantify, and cannot defend on the day it is tested.
The next 30 days
Read 245/2026 against the directive it references — not in isolation.
The obligations are in the instrument it points to.
Map your framework to each Article 4 obligation.
Not a self-assessment over coffee — a structured gap analysis.
Prioritise what a supervisor tests first.
Audit trail, four-eyes, risk reporting, AML/CFT controls, ICT and outsourcing risk.
Close organisational gaps through design; operationalise control gaps through one platform.
Not another point tool on the pile.
Start with a clear read on where you stand
Infocredit Group supports EMIs across both halves: advisory to design the governance framework, and ComplianceSuite.ai to operationalise and evidence the compliance, risk-control and audit-trail obligations at its core.
Gold & Platinum — Compliance Awards 2025. ISO 27001 certified. Trusted across 100+ regulated deployments.
Request your Governance Gap Assessment
A structured, no-obligation diagnostic against every obligation under 245/2026 — with a written read of where you stand and what to fix first.
