Skip to content

Site navigation

Payments & E-money

A weak or stalled application: repair it, reset the scope, or stop

A stalled application is usually a scope problem in documentation clothing. Which of the two you have decides whether repairing it is worth anything at all.

The decision

Your application is weak, delayed or being challenged. Do you repair it, reset the scope, or stop and rebuild?

In short

An application is usually repairable when the activity list is settled and the gaps are in evidence, and usually not when the gaps are in the perimeter itself. The test is concrete: can every activity the firm performs be named in the terms the framework uses. Not every activity that moves money is a payment service, and the exclusions are checked before the authorisation question, not after it.1213 Where that answer is no, more documents make the file longer rather than stronger, and the decision in front of you is a scope decision.

What the law requires

Who this is for, and who it is not for

This guide is for a firm whose application has stalled, is drawing repeated questions, or is being run against a plan nobody in the room now believes.

It is not a prediction of what any authority will do. Nothing here says an application would be granted, refused or decided by a date, and this site holds no evidence that would support such a statement.

It is not for a firm that has not yet applied. Choosing a route and building the evidence in the right order is a different problem, and it starts with the perimeter: an activity excluded from the framework entirely is not made into a payment service by an application.1213

What the law requires

The facts that decide whether repair is worth anything

Whether the perimeter is settled. PSD2 excludes a list of activities from its scope entirely and the E-Money Directive excludes certain monetary value from the definition of electronic money, so a file can be complete and still be for the wrong thing.1213

Whether the entity can hold the permission at all. A payment institution authorisation is granted only to a legal person established in a Member State, and the Union frameworks generally require the authorised entity to be established in a Member State and to have its head office or effective management there.131015

Whether the capital position still matches the model. Several frameworks measure own funds against a proportion of fixed overheads, so a requirement met at the start of a programme rises with the cost base rather than staying at the headline figure.24

Whether funds received from users are safeguarded as the framework requires, since those arrangements are supervised on an ongoing basis rather than evidenced once.914

Whether the operational and security evidence exists in the form the application asks for. A payment institution application must include a security policy document containing a risk assessment and a description of the security control and mitigation measures.8

Whether obligations the firm treated as future have already attached. An applicant that already holds another authorisation may already be a listed financial entity in that other capacity, in which case DORA already binds it.5

What the law requires

Repair, reset the scope, or stop

Repair is the right answer when the activity list is stable, the entity can hold the permission, and what is missing is evidence that can actually be produced: governance records, control descriptions, the security policy document and the reconciliation behind safeguarding.8914

Reset the scope when the activity list itself is the problem, because the exclusions are checked before the authorisation question rather than after it, and a file that names the wrong activity cannot be corrected by adding pages to it.1213

Reset the entity when the applicant cannot satisfy the establishment condition, since the authorisation is granted only to a legal person established in a Member State and no quantity of evidence changes that.10

Where an applicant is not otherwise a listed financial entity, what an authority examines on operational resilience at this stage is the evidence the sectoral framework requires in the application itself, so a resilience gap and an application gap are not always the same gap.58

Consider stopping when repair and reset both require the business model to change so far that what is left is a different firm. That is a commercial decision rather than a regulatory one, and it costs less taken deliberately than discovered.

What the law requires

Outsourcing and third parties, where scope quietly widens

A payment institution may provide payment services through agents that it registers with its home competent authority, and it remains responsible for their acts. An agency arrangement gives the agent no permission of its own.11

Whether DORA binds a given firm is a conclusion rather than an assumption. It applies to the financial entities listed in Article 2(1), which is a closed list, excludes certain entities entirely and applies a simplified ICT risk management framework to others.56

Where it does bind, it requires ICT third-party risk to be managed and a register of information on contractual arrangements to be maintained, and it establishes an oversight framework for critical ICT third-party service providers.7

RenIQ practitioner observation

The failure modes that produce a stalled file

Answering questions one at a time. A file that answers twelve questions in twelve voices reads as twelve positions, and the next round is then about the inconsistencies rather than about the business.

Nobody owning the answer. When each question goes to whoever is free, the file loses the one thing an assessor is looking for, which is a firm that knows what it is.

Treating an evidence gap as a drafting task. If the control does not exist, describing it produces a document that the first operational question will contradict.

Leaving the scope question open because it is uncomfortable. It does not get cheaper later; it becomes the reason the rest of the work has to be done again.

Moving the file to another Member State to escape the questions. The framework travels with the activity, so the same questions arrive again against a new file and a later start.

RenIQ practitioner observation

The decision to make next

Before writing another response, write the activity list: one line per activity the firm performs, in the words the framework uses, with the entity that performs it and the customer funds it touches. If that page is clean you have a repair. If it is not, you have a scope decision, and it is the only one worth taking this week.

Related regime guide: Payments & E-money

Primary sources for this page

15 citations, each to the article or section the statement rests on. The numbers beside a statement point to the citation behind it. Always confirm against the current official text.

  1. 1Article 59, authorisation of crypto-asset service providersRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  2. 2Article 67 and Annex IV, prudential requirements and permanent minimum capital requirements by class of crypto-asset servicesRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  3. 3Article 8 and Article 13, authorisation of credit institutions and the location of the head officeDirective 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutionsEuropean Parliament and Council of the European Union
  4. 4Article 11, prudential safeguards and the forms they may takeRegulation (EU) 2020/1503 of the European Parliament and of the Council of 7 October 2020 on European crowdfunding service providers for businessEuropean Parliament and Council of the European Union
  5. 5Article 2(1), the list of financial entities to which DORA applies, and Article 2(3), the entities excluded from itRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
  6. 6Article 16, simplified ICT risk management framework for the entities it listsRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
  7. 7Chapter V, management of ICT third-party risk, including the register of information and the oversight framework for critical ICT third-party service providersRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
  8. 8Article 5(1), the contents of an application for authorisation as a payment institution, including point (j), the security policy documentDirective (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal marketEuropean Parliament and Council of the European Union
  9. 9Article 10, safeguarding requirements for funds received from payment service usersDirective (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal marketEuropean Parliament and Council of the European Union
  10. 10Article 11, granting of authorisation, including the requirement that authorisation be granted only to a legal person established in a Member StateDirective (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal marketEuropean Parliament and Council of the European Union
  11. 11Article 19, use of agents, branches or entities to which activities are outsourcedDirective (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal marketEuropean Parliament and Council of the European Union
  12. 12Article 3, activities excluded from the scope of the DirectiveDirective (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal marketEuropean Parliament and Council of the European Union
  13. 13Article 1(4) and (5), monetary value excluded from the definition of electronic money, and Article 9, optional exemptions for small electronic money issuersDirective 2009/110/EC of the European Parliament and of the Council of 16 September 2009 on the taking up, pursuit and prudential supervision of the business of electronic money institutionsEuropean Parliament and Council of the European Union
  14. 14Article 2(2), definition of electronic money, and Article 7, safeguarding requirementsDirective 2009/110/EC of the European Parliament and of the Council of 16 September 2009 on the taking up, pursuit and prudential supervision of the business of electronic money institutionsEuropean Parliament and Council of the European Union
  15. 15Article 5, requirement for authorisation, and Article 5(4), location of the head officeDirective 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instrumentsEuropean Parliament and Council of the European Union

Last updated 2026-08-26. 5 min read, calculated from 1026 words.

Talk through Application Remediation & Programme Rescue

Your enquiry will record Application Remediation & Programme Rescue as the engagement you are asking about. Tell RenIQ what you are building, where you want to operate and how far you have got, and a senior practitioner will come back on scope and on whether this is the right engagement for you.

Read what the engagement covers first: Application Remediation & Programme Rescue.