
The EBA PSD2 register: what it is, how to read it, and why authorisation status matters
The EBA register lists every payment institution and electronic money institution authorised under PSD2 across the EEA. This article explains what the register contains, what the eight entity types mean in practice, how passporting works, and what to verify before contracting with any payment service provider operating in the EU.
This article is for informational purposes only and does not constitute legal advice. Consult a qualified legal professional for advice specific to your situation.
- The EBA register is the authoritative source for verifying whether a payment institution or electronic money institution is legally permitted to operate in the EU. It lists every entity authorised or registered under PSD2 across all EEA member states, sourced from national competent authority data and updated daily. For current data on authorised providers and their distribution across member states and entity types, see the PSD2 register.
- Authorisation is a legal prerequisite, not a quality signal. An entity providing payment services in the EU without valid authorisation or registration under PSD2 is operating unlawfully, regardless of its size, reputation, or prior history. Contracting with an unauthorised provider does not transfer that liability away from the buyer.
- The register contains eight distinct entity types, and the differences between them are legally significant. A payment institution, an electronic money institution, an exempted payment institution, and an excluded entity each carry different regulatory obligations and permissions. Checking that a provider is in the register is necessary but not sufficient; checking what it is authorised to do is equally important.
- Passporting allows authorised institutions to operate across EEA member states from a single home state authorisation. An institution passported into your jurisdiction has notified its home regulator of its intention to provide services there. An institution that is not passported into your jurisdiction and is not authorised there has no legal basis for the services it is providing you.
- Authorisation status can change. Licences are withdrawn, surrendered, and lapsed. An institution that was authorised when you contracted with it may not be authorised now. The register is updated daily; periodic re-verification is not excessive caution, it is basic counterparty due diligence.
What PSD2 created and why the register exists
The Second Payment Services Directive (Directive (EU) 2015/2366), which replaced PSD1 and entered into application in January 2018, established the legal framework under which payment services may be provided across the EU. It introduced new categories of regulated service provider, extended the scope of regulated activities, and created the passporting mechanism that allows a single home state authorisation to cover the entire EEA.
The European Banking Authority maintains the public register of all institutions authorised or registered under PSD2 across every EEA member state. National competent authorities (the central banks, financial supervisors, and equivalent bodies in each member state) provide the underlying data. The EBA consolidates this into a single searchable register updated on a daily basis.
The register exists because the EU legislature recognised that a single market for payment services requires a single, publicly accessible source of truth about who is permitted to provide those services. Before this consolidation, verifying whether a payment provider held valid authorisation across multiple jurisdictions required checking each national register separately. The EBA register removes that friction, but only for those who use it.
See which firms are authorised to provide payment services in the EU: The EBA PSD2 register lists all 6,600+ payment institutions, electronic money institutions, and related entities across all EEA countries, including their entity type, home state, passporting countries, and current authorisation status.
The eight entity types and what they mean
The register categorises every listed entity into one of eight types. These are not cosmetic distinctions. Each type reflects a different regulatory basis, a different scope of permitted activities, and a different level of supervisory obligation.
Payment Institution. A payment institution (PI) is a non-bank legal entity that has obtained full authorisation from its home state national competent authority to provide one or more of the payment services listed in Annex I of PSD2. These include credit transfers, direct debits, card payments, money remittance, and payment initiation and account information services. A fully authorised payment institution is subject to the complete set of PSD2 obligations including capital requirements, safeguarding requirements, and conduct of business rules. This is the most substantive category of authorisation in the register.
Electronic Money Institution. An electronic money institution (EMI) is authorised to issue electronic money as well as to provide payment services. EMI authorisation carries additional requirements beyond those for payment institutions, reflecting the added risk that comes with holding client funds in the form of e-money. An EMI may issue prepaid cards, digital wallets, and other e-money products; a payment institution without EMI authorisation may not. Checking whether a provider is a PI or an EMI matters if the service you are using involves the issuance or holding of electronic money rather than just the execution of payment transactions.
Exempted Payment Institution. PSD2 allows member states to apply a lighter registration regime to payment institutions whose payment transaction volumes fall below defined thresholds. Exempted payment institutions are registered rather than fully authorised, are subject to reduced ongoing obligations, and cannot passport their registration across member states. An exempted payment institution is only permitted to operate in its home member state. If you are engaging with an exempted PI from another member state, it has no legal basis to serve you under PSD2 and cannot acquire one through passporting.
Exempted Electronic Money Institution. The equivalent lighter regime for small e-money issuers. The same passporting restriction applies: exempted EMIs cannot passport, and their permissions are limited to the home member state.
Account Information Service Provider. An account information service provider (AISP) is authorised specifically to access payment account data with the account holder's consent, for the purpose of providing consolidated account information services. AISPs do not execute payment transactions and do not hold client funds. Open banking data aggregators, personal finance management tools, and credit decisioning services that pull bank account data typically operate under AISP registration. The scope of an AISP's permitted activities is narrower than that of a full payment institution.
Branch. A branch entry in the register represents an establishment of a payment institution or EMI that is incorporated in another EEA member state and is providing services in the listed jurisdiction through a local branch rather than on a cross border passported basis. The branch itself is not a separately authorised entity; the authorisation belongs to the parent institution in its home member state. For due diligence purposes, the relevant authorisation to verify is the parent institution's home state registration.
Institution under National Law. Some member states have categories of payment service provider that exist under national legislation outside or alongside the PSD2 framework. Postal operators, certain government bodies, and historically established payment systems may fall into this category. The regulatory basis for these entities is the relevant national law rather than PSD2 directly, and the obligations and permissions that apply to them vary accordingly.
Excluded Entity. PSD2 contains a set of exclusions for entities whose activities fall outside its scope entirely. These include commercial agents acting on behalf of a single payer or payee, certain intragroup payment transactions, and technical service providers that do not enter into possession of funds. An entity listed as excluded is not authorised to provide payment services to third parties under PSD2; it is recorded in the register because it has sought a determination from its national competent authority that it falls within an exclusion, not because it holds a payment services licence.
How passporting works under PSD2
A payment institution or EMI that obtains full authorisation in its home member state can provide services across the entire EEA through the passporting mechanism, without obtaining separate authorisation in each host member state. The process involves the home state NCA notifying the host state NCA of the institution's intention to provide services there, either on a cross border basis or through a branch.
The register reflects passporting by listing the member states in which each institution is providing passported services. An institution passported into a member state has completed the notification procedure and is operating there with a legal basis derived from its home state authorisation. An institution that is not passported into a member state and is not incorporated there has no legal basis under PSD2 for the services it provides into that jurisdiction.
This matters more than it might appear. A payment provider based in Lithuania, for example, may be validly authorised under the Bank of Lithuania's supervision and may have passported across much of the EEA. That passporting is what gives it the legal right to serve clients in France, Germany, or the Netherlands. If it has not completed the passporting notification for a particular member state, its services into that state lack a PSD2 legal basis even if its home state licence is entirely valid. The register is the only reliable way to check which jurisdictions a provider has passported into.
The geography of PSD2 authorisation
The EBA PSD2 register currently lists over 6,600 entities across the EEA. The distribution is heavily concentrated in a small number of member states, for reasons that reflect both the scale of existing financial markets and deliberate regulatory positioning.
Poland accounts for the largest single share of registered entities by a significant margin. The majority of Polish entries are exempted payment institutions: small operators, often individual traders or local businesses, registered to provide basic payment collection services under the lighter national regime. These entities cannot passport and are not equivalent to fully authorised payment institutions; the raw count overstates Poland's significance in the licensed payment services market relative to the number of entities that can provide services cross-border.
Germany and Ireland have large concentrations of fully authorised payment institutions and EMIs. Ireland in particular punches well above its weight, reflecting its position as the EU jurisdiction of choice for many US and UK headquartered payment businesses seeking a PSD2 licence with EEA-wide passporting capability. Many of the largest global payment brands, including several card networks, payment processors, and platform payment services, are authorised in Ireland and passport from there across the EEA.
Lithuania has become a significant hub for licensed payment institutions, particularly among fintech companies. The Bank of Lithuania built a reputation for efficient authorisation processing and a supportive regulatory environment for payment services businesses, attracting a large cluster of licensed institutions that typically passport broadly. A provider authorised in Lithuania is fully authorised under PSD2 and can passport across the EEA; the Lithuania domicile is a feature of the regulatory landscape, not a reason for concern in itself.
The Netherlands, Luxembourg, and Sweden also have notable concentrations of fully licensed institutions relative to their population, reflecting their roles as fintech hubs and the established payment infrastructure in those markets.
What authorisation status means in practice
The most consequential field in the register for anyone conducting counterparty due diligence is the institution's current authorisation status. Licences are not permanent. They are withdrawn by national competent authorities for regulatory failings, surrendered voluntarily by institutions exiting the market, or allowed to lapse through inaction or insolvency.
An institution that no longer holds a valid authorisation is not permitted to provide payment services under PSD2. It may continue to operate systems, maintain client relationships, and process transactions in the period before its status becomes widely known; the register is updated daily, which means a withdrawal that occurred yesterday may already be reflected in the data. An institution operating after withdrawal of its authorisation is doing so without legal basis, and the implications for clients whose funds it holds or whose transactions it processes can be significant.
For organisations that contract with payment service providers, whether as merchants accepting card payments, as platforms embedding payment functionality, or as businesses using corporate payment accounts, verifying authorisation status at the point of contracting and periodically thereafter is basic counterparty due diligence. The register makes this straightforward. The failure to check it is increasingly difficult to characterise as reasonable.
What PSD2 authorisation does and does not guarantee
Authorisation under PSD2 confirms that a payment institution or EMI has met the legal requirements to provide payment services in the EU. It does not assess the quality of those services, the reliability of the institution's technology infrastructure, the competitiveness of its pricing, or its financial strength beyond the minimum regulatory capital requirements.
PSD2 does impose meaningful consumer and client protections. Licensed payment institutions are required to safeguard client funds held in the course of providing payment services, either by holding them in a separate account at a credit institution or by covering them with an insurance policy or bank guarantee. This safeguarding requirement is a structural protection against the commingling of client funds with the institution's own assets, and it distinguishes a licensed payment institution from an unlicensed operator.
The regulation also imposes liability on payment service providers for unauthorised transactions, with defined timelines for refund obligations and a burden that falls on the provider to demonstrate authorisation rather than on the client to prove its absence. These protections exist only where the institution is properly authorised; they cannot be claimed against an unlicensed provider.
How to verify a payment provider before contracting
The verification process against the EBA register is straightforward but requires attention to a few details.
Search by legal entity name rather than trading name or brand. Many payment providers operate consumer-facing brands that differ from their registered legal entity name. The legal entity name is what appears in the register; the institution's own terms and conditions or regulatory disclosures should identify it.
Check the entity type. Confirm not just that the institution is listed, but what category it falls into. An exempted PI or exempted EMI cannot passport and is limited to its home member state. A branch entry requires you to verify the parent institution's home state authorisation. An excluded entity is not authorised to provide payment services to you at all.
Check the passporting coverage. If you are in a member state that is not the institution's home state, confirm that it has passported into your jurisdiction. An institution whose passported countries list does not include your member state does not have a legal basis to provide PSD2-regulated services to you there.
Confirm current status. The register is updated daily. A verification conducted at contract signature does not remain valid indefinitely. For ongoing relationships with payment providers, periodic re-verification, particularly following any news of regulatory action, ownership change, or financial difficulty, is reasonable practice.
Note the competent authority. If you have a complaint or dispute involving a payment institution, the home state NCA is the primary regulatory contact. For Irish-authorised institutions, the Central Bank of Ireland. For Lithuanian-authorised institutions, the Bank of Lithuania. For German-authorised institutions, BaFin. The register entry identifies the home state, from which the supervising authority follows.
The monitoring picture for payment institutions
For payment institutions and EMIs themselves, PSD2 authorisation carries ongoing obligations that do not end at the point of licence grant. Institutions are required to notify their home state NCA of material changes to their business model, governance, and ownership structure. Expansions into new service categories or new member states require either updated authorisation or completed passporting notifications before the activity begins.
PSD3 and the Payment Services Regulation (PSR) are progressing through the EU legislative process and will eventually replace PSD2. The changes they introduce, including adjustments to the liability framework for authorised push payment fraud, revisions to open banking requirements, and updates to the exemption thresholds, will affect both the obligations on licensed institutions and the protections available to their clients. The EBA register will continue to be the reference point for authorisation status under whatever framework succeeds PSD2, but the categories and requirements it reflects will evolve.
For a broader overview of the EU financial regulatory landscape within which PSD2 sits, see EU financial regulation in 2026. For the changes that PSD3 and the PSR will introduce for fintechs and payment institutions, see PSD3 and PSR: what changes for fintechs. For the supervisory architecture that governs how the EBA and national competent authorities interact on payment services oversight, see ESMA, EBA, and EIOPA: who does what.
Forseti monitors EU financial regulation continuously and delivers personalised impact analysis anchored to verified official sources. Start for free.
Legal References
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.