
Welcome to the FIG Top 5 at 5
The Top 5 at 5 is a weekly update in which members of the Financial Institutions Group (FIG) identify five of the key legal and regulatory developments relevant to the financial services industry from the preceding week.
Priority is given, in the first instance, to Irish based developments but the update will also include important developments in European law and regulation.
The topics chosen are dictated by the developments during the relevant period but priority is given to cross sectoral developments. The FIG Top 5 at 5 is not intended to represent all developments of note for the relevant period but rather a snap shot of some of the issues which we feel are of particular importance.
Should you have any queries in respect of the contents of the update, please do not hesitate to contact your usual Matheson LLP contact or any member of our team detailed below.
The Top 5 at 5
On 16 September 2026, the Government Legislation Programme for Autumn 2026 was published (“Programme”), identifying the Government’s priorities for the coming 13 week parliamentary session.
The Programme identifies 32 bills to be prioritised for publication and 32 bills to be prioritised for drafting, with 65 additional bills listed under “All Other Legislation”.
There are currently 18 bills on the Dáil and Seanad order paper, while 60 bills have been published and 57 enacted, since the Government came to office on 23 January 2025.
Those of direct relevance to financial services are outlined below:
Legislation for priority publication
- Finance (International Financial Institutions) Bill aims to put in place the legislative authority for the Minister and the Central Bank of Ireland to contribute to the IMF Resilience and Sustainability Trust using a portion of Irelands allocation of IMF Special Drawing Rights. The Bill will also provide a government guarantee to the Central Bank of Ireland for the purpose of contributing to the IMF Trust and make other administrative amendments relating to Ireland’s membership of international financial institutions. The Programme indicates that Heads of Bill were approved in July 2025.
- Violation of Restrictive Measures Bill which will transpose EU Directive 2024/1226 on the definition of criminal offences and penalties for the violation of Union restrictive measures. The Programme indicates that Heads of Bill were approved in March 2025.
- The Judicial Council (Amendment) Bill aims to ensure the process for the adoption of Personal Injuries Guidelines is more transparent and comprehensive. The Programme indicates that Heads of Bill were approved in January 2026.
Legislation for priority drafting
- Co-operative Societies Bill aims to place the co-operative model on a more favourable and clearer legal basis, thereby creating a level playing field with companies and encouraging the consideration of the cooperative model as an attractive formation option for entrepreneurs. The Programme indicates that work is ongoing.
- Asset Covered Securities (Amendment) Bill aims to amend the Asset Covered Securities Act 2001 to facilitate the issuance of asset covered securities (covered bonds) either by specialist covered bond subsidiary entities under a specialist banking model or from non-specialist credit institutions operating under a universal banking model and related matters. The Programme indicates that Heads of Bill were approved in June 2026.
- Criminal Justice (Money Laundering and Terrorist Financing) (Amendment) Bill – this aims to transpose certain aspects of the EU’s sixth Anti-Money laundering package that require primary legislation. The Programme indicates that Heads are in preparation.
All other legislation
- Restrictive Measures Bill aims to create a mechanism by which persons would be obliged to adhere to the asset freezing requirements of certain UN Security Council Resolutions in the period prior to their incorporation in an EU legislative act, in order to meet Ireland’s international obligations and prevent sanctions evasion. The Programme indicates that heads are in preparation.
- Personal Insolvency (Amendment) Bill aims to update aspects of personal insolvency legislation, following statutory review of Personal Insolvency Acts. The Programme indicates that work is ongoing.
Next steps
The FIG Top 5 at 5 will continue to monitor the progress of the legislative initiatives and update clients when appropriate.
1. Governor Makhlouf delivers speech addressing banking fragmentation, capital markets union, and the risks of deregulation
On 17 September 2026, the Governor of the Central Bank of Ireland (“Central Bank“), Gabriel Makhlouf, delivered a speech (“Speech”) at the Eurofi Financial Forum Gala Dinner in Dublin, entitled “Finance for Europe’s Future – Getting the Foundations Right”, in which he addressed the foundational choices facing European financial regulation, including banking market fragmentation, the Savings and Investments Union (“SIU”), and payments modernisation.
The Governor reflected on Ireland’s transformation from a “small, capital-poor economy” into one of the most open economies in the world, attributing this to a deliberate choice to integrate with Europe, which brought with it, stable rules, open markets and credible institutions. He highlighted that “we are not realising the potential of the European economy.” He emphasised that Europe has what it needs to succeed and stated that the question is one as to “whether we will make the foundational choices to deliver on it.”
The Governor focused on a number of key areas in his speech, as follows:
Resilience
The Governor set out that a well-functioning European financial system should be resilient, well-regulated, integrated at European scale, and innovative, noting that these characteristics reinforce rather than compete with one another. He was direct in stating that resilience is not a constraint on competitiveness but rather it is the necessary precondition. The Governor highlighted that the financial crisis showed us “…that when regulators optimise for competitiveness, they miss risks building in the system. And no institution is competitive globally if it is structurally weak, undercapitalised, or prone to failure.”
The banking challenge: fragmentation, not capital
Referring to the European Commission’s (“Commission”) July communication on the competitiveness of the EU banking sector – for more information, see FIG Top 5 at 5 dated 23 July 2026 – the Governor agreed that fragmentation, rather than capital levels, is the main problem facing the banking sector, noting that cross-border corporate lending in the euro area remains at around one-sixth of the total despite having a single market, single currency and single supervisor. He noted that regulation alone will not solve the problem but that it does have a role to play. In that regard, he set out three areas for action:
- completing the Banking Union, including a European deposit insurance scheme;
- addressing the practical barriers to cross-border banking such as divergent insolvency regimes / fragmented digital infrastructure / different employment rules; and
- maintaining a relentless focus on regulating and supervising well, including greater clarity and common methodologies on capital requirements. The Governor cautioned against simplification “that is done poorly”, citing asking supervisors to weigh up promoting competitiveness against their core mandates as an example of poor simplification. He stated that the best contribution to competitiveness is ensuring monetary and financial stability and the safety and soundness of the financial sector.
Connecting savings to investment
Governor Makhlouf identified connecting Europe’s savings to productive investment as the second challenge. On the SIU, the Governor noted that Europe’s venture capital market is a fraction of the size of the United States’, with the shortfall concentrated at the late stage, and welcomed steps such as the Scaleup Europe Fund and the proposed common European 28th regime.
He highlighted the need for a single safe asset as a requirement for a “genuine single capital market”. In addition, the Governor pointed out that the constraint is not the volume of capital in Europe, when it comes to channelling savings to investment. In that regard, he highlighted Mario Draghi’s additional investment estimate of €750 to €800 billion a year by 2030 with the roughly €10 trillion held in European cash deposits. Concluding this matter, Governor Makhlouf stated that, for capital to flow to where it is most productive, we “…need one Single Market – in all its components – and we need to move faster to realise it.”
Modernising payments infrastructure
The Governor noted that, unlike other areas discussed, European authorities are not behind the curve on payments. He identified the two-tier monetary system of central bank and commercial bank money as the anchor that must evolve into a digital and tokenised world. He referenced the Eurosystem’s work on the digital euro and the Central Bank’s discussion paper on distributed ledger technology and tokenisation across funds, markets and payments published this year – for more information, see FIG Top 5 at 5 dated 12 March 2026. The Governor engaged in a more detailed discussion in payments in a subsequent speech – see the update below.
Conclusion
The Governor cautioned against responding to competitive pressure by reversing post-crisis regulatory modernisation, stating that what European banks and capital markets need is not less resilience but a market that is deep, integrated and genuinely barrier-free. He framed the choice facing Europe as one “between doing the hard work now or continuing to forgo the benefits of the union already built”. He advocated for “resisting the siren call of deregulation and the allure of less supervision and not confusing these with simplification.”
2. Governor Makhlouf delivers speech addressing trust, innovation in the future of finance and payments
On 18 September 2026, the Governor of the Central Bank of Ireland (“Central Bank“), Gabriel Makhlouf, delivered a speech (“Speech“) at the Central Bank’s conference entitled “Trust & Innovation: the Future of Finance”. The theme of the Speech centred around payments, particularly the way in which payments are changing, including the pace of that change.
Some of the key points covered by the Governor are as follows:
The Governor described payments as the “circulatory system of the economy”, noting that new forms of payments instruments built around new technologies, raise questions around settlement, redemption, interoperability, and the structure of the broader financial system. He highlighted the fact that new entrants, citing digital banks and non-bank fintechs, are now operating alongside traditional institutions at every stage of the transaction chain. Alongside this, the Governor highlighted the increasing interconnections between the traditional financial system and tokenised finance.
Trust
The Central Bank’s approach to the payments system as being rooted in trust was emphasised, noting that this trust has been built over decades by careful monetary and regulatory stewardship. The Governor identified the challenge as one of being able to respond to rapid change while preserving what makes the system trustworthy, while also serving the future economy.
The Governor stated that this challenge is best understood “through the lens of the two-tier architecture of money” – in the first tier, central bank money must remain as the anchor, providing the settlement asset and unit of account for the entire system. The second tier, being private money, operates effectively because it is ultimately linked to, and convertible into, central bank money. He highlighted that, for this situation to continue, the Eurosystem infrastructure and policy environment needs to be fit for the digital age. In that regard, some of the matters addressed by the Governor are as follows:
- the development of the Pontes and Appia projects, where distributed ledger technology (“DLT“) based settlement capability is being developed that links DLT platforms with TARGET services;
- on the retail side, he stated that cash and, in future, the digital euro, must remain available to underpin public trust that money is safe and references a common value; and
- private money is also essential – one that provides seamless payments, innovative services, and credit for productive investment.
Resilience and risk of fragmentation
The Governor emphasised the importance of operational and financial resilience for private providers of payment services. However, he cautioned that resilience alone is not sufficient, stating that fragmentation, from incompatible systems and competing standards, is a risk that competition alone may not address. In that regard, he highlighted that that is why the Central Bank’s role extends beyond regulation and that through its role operating core payments infrastructure, the Central Bank has a responsibility to help shape how the payments ecosystem develops.
Research
Governor Makhlouf then took the opportunity to highlight new research published by the Central Bank, stating that the research was aimed at deepening its understanding of the evolving payments ecosystem, with its impact assessed through the lenses of consumers, merchants, the financial sector and the broader macroeconomic picture.
The Governor draw attention to that fact that the Central Bank’s household survey reveals a fast-changing payments landscape. He particularly focused on the finding that what matters most to consumers, when choosing a payment instrument, is “security, reliability, trust, and fraud safeguards.”
Some further matters borne out by the research are as follows:
- trust in digital banks remains notably lower than trust in high-street banks, although the gap is less pronounced among younger consumers; and
- the Central Bank estimated the private cost borne by Irish businesses in processing retail payments to be at least €1 billion annually, with smaller businesses facing disproportionately higher per-transaction costs, ultimately passed on to consumers.
Conclusion
The Governor concluded that central banks and regulators will shape the future of payments in partnership with the private sector, enabling innovation while safeguarding trust and stability. He also stated that the monetary system of the future should be an expanded framework in which established and new payment instruments can settle, be redeemed, be interoperable and be trusted.
On 17 September 2026, Director of Insurance at the Central Bank of Ireland (“Central Bank“), Seána Cunningham, delivered a speech (“Speech”) at the UN Environment Programme Global Sustainable Insurance Summit in Dublin.
The Director’s Speech focused on the increasing physical risks associated with climate change, the role of the insurance sector in supporting climate resilience and adaptation, and the Central Bank’s ongoing engagement on the issue.
Some of the key points raised by the Director are set out below.
Climate risk as a present-day challenge
The Director emphasised that the physical risks associated with climate change are not a distant concern but a present-day challenge requiring urgent action from regulators, insurers and policymakers.
By way of illustration, the Director noted that Ireland experienced its most expensive storm-related insurance event on record last year, with storm Éowyn, which gave rise to insurance claims totalling approximately €300 million.
The Director stated that the Central Bank is “led by evidence” and follows the risks, emphasising that the risks arising from climate change will only increase if we delay. She highlighted that we are not yet on a sustainable trajectory, and that a loss of momentum has been observed in some parts of the world.
Response and opportunities
The Director highlighted a number of matters relevant to the insurance sector and the wider financial system, including:
- the Central Bank is staying the course on climate, on the basis that if momentum is lost then the risks increase;
- the continued availability of insurance, provided in a sustainable way in the face of increasing climate risk, is an important matter for the Central Bank. The Director noted that when insurers retreat from high-risk areas, there is resulting reduced investment, lower property values, constrained economic activity and, ultimately, systemic financial instability;
- rather than requiring insurers to cover uneconomic risks, which the Director considered would be unsustainable, the response should instead involve innovative, long-term solutions, including innovative insurance products, improved data sharing across industry and government, better data on climate hazards, and greater integration of adaptation and resilience measures to reduce underlying risk;
- solving these challenges requires collaboration across all relevant stakeholders, and the Director highlighted the Central Bank’s intention to continue its engagement with Government and the insurance industry, including through the new working group being established by the Department of Finance, to address Ireland’s flood protection gap;
- the Director welcomed, the Commission’s plans to establish a Climate Insurance Alliance – for more information, see FIG Top 5 at 5 dated 17 September 2026; and
- the Director pointed to an evolution within the insurance sector, away from a purely reactive model, towards more proactive engagement, with insurers increasingly acting as “risk partners” that help policyholders invest in their own resilience. Ms Cunningham noted that, where insurers require higher resilience standards as a condition of cover, this creates a powerful incentive for risk reduction. In that regard, she acknowledged that this trend is mainly limited to large risks or business insurance but that there is an opportunity for insurers to support households when it comes to understanding their risk and how to reduce it. She pointed to the fact that the Central Bank is participating as one of the pilot countries testing the EIOPA risk awareness tool, which sets out information for policyholders as to what to do before, during and after a flood event.
Adaptation finance
The Director acknowledged that discussion of sustainable investment has, to date, focused primarily on climate mitigation, which she considered should remain the priority, on the basis that a failure to invest in mitigation risks locking in unsustainable levels of global heating.
However, the Director also highlighted the need for adaptation finance to respond to “the levels of heating that are already baked into the system.” She referenced a report co-authored by the Central Bank and the Climate Change Advisory Council on the barriers to adaptation finance. The Director stated that removing these barriers, and unlocking investment in adaptation, by insurers and the broader financial system, is key to building community resilience.
Conclusion
In conclusion, the Director stated that the “insurance industry stands at a crossroads”, and that it can, and should, innovate and embrace its role as a catalyst for resilience by accurately pricing risk, incentivising adaptation, supporting the transition, and investing in the data and infrastructure needed to make markets function effectively.
On 18 September 2026, the European Banking Authority (“EBA”) published its final report on guidelines (“Guidelines”) on the sound management of third-party risks regarding non-ICT services.
The EBA consulted on the Guidelines in July 2025 – for more information, see FIG Top 5 at 5 dated 17 July 2025.
The 2019 guidelines applied exclusively to credit institutions and investment firms subject to directive 2013/36/EU (“CRD”), payment institutions and electronic money institutions. Following the entry into force of directive 2024/1619/EU (“CRD VI”), directive 2019/2034/EU (“IFD”), regulation (EU) 2023/1114 (“MiCA”), and regulation (EU) 2022/2554 on digital operational resilience for the financial sector (“DORA”), the 2019 guidelines on outsourcing needed to be updated in the interests of a more general approach on the management of third-party risks.
The Guidelines aim to clarify the supervisory expectations regarding the management of third-party risks, including towards third-party service providers located in third countries to ensure that third-party arrangements are concluded and monitored appropriately. The Guidelines aim to ensure that competent authorities are able to identify concentration risks based on documentation provided by financial entities, to identify and manage risks to the stability of the financial system.
The aim of the updated Guidelines is to establish a more harmonised framework for the sound management of third-party risk and taking into account the entry into force of DORA. Accordingly, the Guidelines apply to:
- institutions subject to CRD;
- creditors as defined in point (2) of article 4 of directive 2014/17/EU (“MCD”) which are financial institutions;
- investment firms that do not meet all the conditions to qualify as small and non-interconnected under article 12(1) of regulation (EU) 2019/2033 (“IFR”); and
- payment and electronic money institutions (referred to as ‘payment institutions’) and issuers of asset referenced tokens subject to MiCA; and
- the use of third-party arrangements between credit institutions, payment institutions, investment firms, and such entities are within the scope of the Guidelines when such entities act as third-party service providers (“TPSPs”).
The Guidelines include third-party risk management elements that aim to ensure that:
- there is effective day-to-day management by the management body in its management function and senior management;
- there is effective oversight by the management body in its supervisory function;
- there is a written policy on the contractual arrangement regarding the use of non-ICT services supporting critical or important functions provided by TPSPs;
- financial entities have an effective internal control and risk management framework, including with regard to the management of third-party risk;
- all the risks associated with the provision of critical or important functions by TPSPs are identified, assessed, monitored, managed, reported and, as appropriate, mitigated;
- there are appropriate plans for the exit from third-party arrangements regarding critical or important functions, for example, by migrating to another TPSP or by reintegrating the critical or important functions; and
- competent authorities remain able to effectively supervise financial entities, including on non-ICT services supporting functions that are provided by TPSPs.
DORA
The management of ICT risk and the use of TPSPs to provide ICT services as defined in article 3(21) of DORA are excluded from the scope of application of the Guidelines, as they fall within the scope of DORA. In this regard, these Guidelines only cover the use of TPSPs that do not provide ICT services supporting critical or important functions under DORA.
Third country branches
For EU branches of third country credit institutions within the meaning of article 47 of CRD, the Guidelines should be read in conjunction with the EBA guidelines on internal governance under CRD. The Guidelines set out that, as third country branches do not have the legal personality and are not considered as separate legal entities from their head undertaking in the third country, a proportionate approach is appropriate as regards the application of the Guidelines. In this regard, while a written contract between the head undertaking and its EU branch is not possible as they are not legally distinct, the EU branch should have any other arrangement (such as service level arrangement or policies) to formally document the services required by the branch and performed by the head undertaking to enable the branch to comply with the Guidelines.
Consultation feedback
Overall, on foot of feedback from the July 2025 consultation, the Guidelines have been reviewed to provide more proportionality, and more clarity regarding the scope, the focus on critical or important functions, and the alignment with the DORA framework. Furthermore, the transitional period has been adjusted for more flexibility regarding the update of the services provided by TPSPs supporting non-critical functions.
Next steps
The Guidelines will be translated into all official EU languages and published on the EBA’s website. The deadline for competent authorities to report whether they comply with the Guidelines has not been specified in the text, nor has the application date. However, the final guidelines will have a two-year transition period to give in-scope firms time to review and amend their existing third-party arrangements and update the register for non-ICT third-party arrangements.
1. ECB publishes new guide to licence applications under CRR
On 18 September 2026, the European Central Bank (“ECB”) published an updated guide (“Guide”) to licence applications applicable to all applications to become a credit institution under the capital requirements regulation (“CRR”), including, but not limited to:
- initial authorisations for credit institutions;
- bridge bank applications; and
- licence extensions.
The Guide, which replaces the 2019 version, aims to promote awareness and make the legislative framework, the assessment criteria and the processes for establishing credit institutions more transparent and easier to understand. Additionally, it also aims to ensure greater consistency in the licensing of credit institutions across single supervisory mechanism (“SSM”) jurisdictions.
The Guide sets out that the ECB and NCAs will, in assessing a licence application, consider the proposed institution’s size, complexity, business model and risk profile.
Tool
The Guide serves as a practical tool to assist stakeholders involved in licence applications as regards navigating and positioning applications effectively within the currently applicable regulatory framework, including EU regulations or directives and national laws, as well as the technical standards and guidelines issued by the EBA.
Not legally binding
The Guide highlights that it does not lay down legally binding requirements and does not replace the relevant legal requirements under either Union or national law.
Next steps
The Guide will be reviewed regularly, taking into account:
- ongoing developments in the supervisory practices regarding authorisations;
- international and European regulatory developments; and
- new interpretations of CRD by the Court of Justice of the European Union.
2. Commission adopts delegated regulation on third-country branch booking arrangements under CRD IV
On 17 September 2026, the European Commission (“Commission”) adopted a delegated regulation (“Delegated Regulation”) with regard to draft regulatory technical standards (“RTS”) specifying the booking arrangements that third-country branches are to apply for the purposes of article 48h of the capital requirements directive (“CRD”).
The Delegated Regulation relates to the requirement in article 48h(1) of the CRD IV directive to maintain a registry book that enables a third-country branch to track and maintain a record of all the assets and liabilities booked or originated by that branch in the member state, and to manage those assets and liabilities autonomously within the third-country branch.
The Delegated Regulation sets out the methodology that third-country branches should follow to track and keep these records. In particular, it specifies the bookkeeping system third-country branches must have in place to identify their transactions, the minimum set of information to be maintained in the registry book and information to be provided as regards associated risks.
The EBA published its final report on the RTS in January 2026 – for more information, see FIG Top 5 at 5 dated 15 January 2026.
Next steps
The Delegated Regulation is now subject to the scrutiny of the European Parliament and the European Council. If neither institution objects, the Delegated Regulation will be published in the official journal of the EU and will enter into force 20 days after such publication.

Thought Leadership
Matheson Talks Financial Regulation Podcast
The Matheson Financial Institutions Group are delighted to share with you some useful podcasts.


















