> EMIs and payment institutions must operate an internal reporting channel regardless of headcount. The 50-employee threshold does not apply to them. What the obligation is, which regulator enforces it, and what DORA adds at procurement.

Source: https://ethicsportal.eu/ro/industries/e-money-and-payment-institutions/
Updated: 2026-09-23

---

# Whistleblower compliance for e-money and payment institutions

**The 50-employee threshold does not apply to you.** A licensed e-money institution or payment institution with 18 staff carries the same internal reporting channel obligation as a bank with 18,000. Headcount is not the trigger — your licence is.

This is the single most misread point in the Directive. Most guidance leads with "50 or more employees", which is correct for ordinary private-sector companies and wrong for regulated financial entities.

## Why headcount does not apply

The obligation runs through three steps:

1. **Your licence** places you within the scope of a Union financial-services act — the E-Money Directive (2009/110/EC) for EMIs, the Payment Services Directive (PSD2, (EU) 2015/2366) for payment institutions.
2. **Part I.B of the Annex** to Directive 2019/1937 enumerates the Union acts governing financial services, products and markets, and the prevention of money laundering and terrorist financing. The E-Money Directive is point (i) on that list; PSD2 is point (ix).
3. **<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 8(4)</a>
** provides that the threshold in <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 8(3)</a>
 "shall not apply to the entities falling within the scope of Union acts referred to in Parts I.B and II of the Annex". Article 8(3) is what sets the 50-worker trigger for private-sector entities generally.

Part II of the Annex is a different list — the sector-specific acts that lay down their own reporting rules, which take precedence over this Directive under <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 3(1)</a>
. Several financial-services acts sit there, so a licensed firm may be answering to sector rules and this Directive at once, with the Directive filling whatever the sector act does not mandate.

The practical result: there is no size at which a licensed EMI or payment institution is out of scope. A newly authorised firm is in scope from the day it holds the licence.

**PSD3 and the PSR do not remove this.** The agreed texts were published in April 2026 and will in time repeal and replace both PSD2 and the E-Money Directive, merging the payment-institution and e-money-institution regimes into a single framework. Application is not expected before late 2027. Until then PSD2 and EMD2 remain the operative acts and the analysis above is unchanged. How the Annex to Directive 2019/1937 comes to reference the successor acts is a point to watch — not a reason to defer, because the obligation applies now.

Member states transpose this in their own drafting. Romania, for example, places financial services, anti-money-laundering and insurance entities in Annex 3 to [Legea nr. 361/2022](/whistleblower-laws/romania/) and applies the obligation to them regardless of employee count. Confirm your own national transposition — the mechanism is uniform, the drafting is not.

## Who supervises this

Whistleblowing obligations for licensed firms are enforced by your prudential or conduct regulator, independently of the national whistleblower authority. Both can act on the same failure.

| Country | Regulator for EMIs / PIs |
|---------|--------------------------|
| [Lithuania](/whistleblower-laws/lithuania/) | Bank of Lithuania |
| [Ireland](/whistleblower-laws/ireland/) | Central Bank of Ireland |
| [Malta](/whistleblower-laws/malta/) | MFSA |
| [Luxembourg](/whistleblower-laws/luxembourg/) | CSSF |
| [Netherlands](/whistleblower-laws/netherlands/) | DNB |
| [Germany](/whistleblower-laws/germany/) | BaFin |
| [France](/whistleblower-laws/france/) | ACPR |
| [Poland](/whistleblower-laws/poland/) | KNF |
| [Romania](/whistleblower-laws/romania/) | BNR |

## What the obligation actually requires

- Channels designed, established and operated securely, so that the reporter's confidentiality is protected (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 9(1)(a)</a>
). Reports may be accepted in writing, orally, or both (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 9(2)</a>
).
- **Acknowledgement within seven days** of receipt (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 9(1)(b)</a>
).
- A designated impartial person or function to follow up (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 9(1)(c)</a>
).
- **Feedback within three months** (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 9(1)(f)</a>
).
- The reporter's identity not disclosed to anyone beyond the staff authorised to receive and follow up reports, absent their explicit consent (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 16</a>
).
- Records of every report, retained no longer than necessary and proportionate (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 18</a>
).

Small licensed firms usually fail on the same point: the person who would receive a report is also the person a report is most likely to concern. Article 9 requires the channel to prevent exactly that conflict, which is difficult to satisfy with a shared mailbox.

## What DORA adds at procurement

Regulation (EU) 2022/2554 (DORA) has applied since 17 January 2025. It does not create a whistleblowing obligation — but it governs how you buy the software that satisfies one. Whistleblowing software is an ICT service, so the engagement runs through your ICT third-party risk process rather than as an ordinary software purchase: an entry in your Register of Information, and the baseline contractual provisions in Article 30(2), including access, inspection and audit rights.

A second, heavier tier — the extended provisions in Article 30(3), and the documented exit strategy required by Article 28(8) — applies where the service supports a **critical or important function**. The financial entity makes that regulatory classification, but the classification does not unilaterally amend the supplier contract. See [procurement under DORA](/industries/financial-services/#procurement-under-dora) for the framing, the [DORA ICT third-party map](/dora/) for provider-side evidence, and the non-binding [DORA contracting template](/dora-addendum/). Customer-specific DORA commitments require an order signed by both parties.

## Reviewing EthicsPortal

The documentation a licensed firm's third-party assessment asks for is published rather than released on request: [security architecture](/security/), [subprocessors](/subprocessors/), [business continuity plan](/policies/business-continuity/), [incident register](/incidents/), [DPA](/dpa/), and the [ISO/IEC 27001:2022 control map](/iso-27001/). A pre-filled [DPIA template](/dpia/) is available for you to adapt and sign as controller.

---

[Deploy your reporting channel →](/pricing/)
