## EXECUTIVE SUMMARY

## Source details

**Canonical URL:** [EXECUTIVE SUMMARY](https://www.imf.org/-/media/files/publications/cr/2022/english/1irlea2022009.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2022/english/1irlea2022009.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2022/english/1irlea2022009.pdf.json)

---

### Fintech industry overview and context
- Sector dynamics:
  - Ireland’s fintech sector is growing in importance through the entry of innovative new players and digital transformation of incumbents’ business models and products.
  - The largest sub-sector is represented by payment and e-money institutions (PIEMIs).
- Recent data:
  - 65 percent of Irish adults are using non-cash payments multiple times a week (2020).
  - 24 percent use their mobile phone for contactless payments (2020).
  - 11 percent of Irish citizens with investments hold crypto-assets; this increases to 25 percent among those aged 25-34.
  - Between Q4 2019 and Q2 2021 the number of authorized PIEMIs and the value of transactions increased by 45 percent and 53 percent respectively.
  - Between Q4 2019 and Q4 2021, the number of authorized firms increased by 45 percent while the volume and value of transactions increased by 47 percent and 83 percent respectively.
  - A 2018 survey by the Central Bank indicated that 40 percent of regulated firms were using cloud service providers (CSPs).
- Ireland for Finance Action Plan 2022 fintech priorities:
  - implement second phase of the Department of Finance’s (DoF) Fintech Steering Group;
  - develop educational resources to support consumers to engage with fintech (CCPC responsibility);
  - develop the instech.ie insurtech hub;
  - deliver a program to support Irish-owned fintech companies’ international growth;
  - develop a coordinated program to raise Ireland’s global visibility as a hub for fintech.

### Regulatory approach and supervisory tools
- Central Bank role and Innovation Hub:
  - The Central Bank of Ireland is the integrated financial services regulator responsible for authorization, supervision, enforcement and regulatory policy development.
  - Innovation Hub:
    - provides a single point of contact (not a regulatory sandbox) and facilitates early engagement and access for fintechs and incumbents;
    - since establishment in 2018 the Hub has received 266 enquiries from innovative firms.
    - Profile of enquiry firms: small and micro-sized enterprises comprise ~75 percent; early stage start-ups ~40 percent; ~92 percent of enquiry firms operate outside the Central Bank’s regulatory perimeter.
    - published guidance on authorization processes and expectations and prioritizes early engagement including preliminary or speculative engagement.
  - Recommendation (¶12): The Central Bank should use the experience gained with the Innovation Hub to inform reflections on the future development of the regulatory framework for fintech in Ireland. Addressee: Central Bank. Timing: ST. Priority: M.

### Crypto-assets: scope, risks, and监管 readiness
- Key characteristics and data gaps:
  - Most crypto-assets and services provided on them do not fall within the scope of existing EU legislation, except for AML/CFT requirements under 5AMLD.
  - Lack of comprehensive and reliable data on the crypto sector, including interconnections with regulated financial services providers.
  - Finder Cryptocurrency Adoption Index: approximately 12 percent of internet users in Ireland own crypto-assets.
  - World Bank / Statista estimate: approximately 10 percent.
- Regulatory posture:
  - Ireland has supported a harmonized EU-level regulatory framework (MiCA — Markets in Crypto-Assets Regulation) rather than a bespoke national framework.
  - MiCA rules are expected to take effect in H2 2023 at the earliest; parts of the new framework expected to start to apply in H2 2023, with full application in 2024.
  - All VASPs established in Ireland are required to register with the Central Bank for AML/CFT purposes only; there are currently no VASPs registered in Ireland but the Central Bank is processing a number of applications.
- Prudential and supervisory stance:
  - Central Bank has not put in place national prudential requirements for banks’ crypto-asset exposures pending international discussions (BCBS consultation grouping: Group 1 and Group 2).
  - Rules on permissibility of exposures vary by regulated entity and prior approval by the Central Bank is likely required in most cases.
  - Investment funds (UCITS and AIFs): UCITS or retail AIFs proposing direct crypto exposure are "highly unlikely" to be approved.
  - Insurance sector: currently seven companies hold extremely small relative exposures to crypto-assets through unit-linked products.
  - Improvements to data reporting under Solvency II due year-end 2023 will provide asset-by-asset reporting and a breakdown of crypto-asset categories.
- Recommendations:
  - Recommendation 2 (¶27): Prepare to introduce domestic legislation in the event of significant delay or material gaps in the MiCA framework. Addressee: DoF, Central Bank. Timing: ST. Priority: M.
  - Recommendation 3 (¶28): Further intensify monitoring of crypto-assets through systematic data collection within scope of powers and, where unacceptable risks remain, issue carefully targeted warnings and investor communications. Addressee: Central Bank. Timing: ST. Priority: M.

### Payments, PIEMIs, and retail bank business models
- PIEMI sector dynamics:
  - PIEMIs represent one of the largest fintech sub-sectors in Ireland and the number of entities is continuing to grow.
  - PIEMIs operate cross-border across the EU; many are small firms attracting personal and business customers.
  - A number of PIEMI firms hold client monies subject to safeguarding but not covered by the Irish Deposit Guarantee Scheme (DGS).
- Regulatory framework and risks:
  - PIEMIs are regulated under PSD2 and the Electronic Money Directive (EMD).
  - EMIs are prohibited from taking deposits (Regulation 28 of the EMR: “an electronic money institution shall not engage in the business of taking deposits or other repayable funds”).
  - E-money wallets are being used in ways comparable to banking-type services and can be an on-ramp to crypto-assets.
  - Central Bank strengthened governance expectations drawing on best practice (e.g., Corporate Governance Requirements for Credit Institutions).
  - The methodology for capital requirements is not fully sensitive to the nature, scale and complexity of the PIEMI sector.
  - Central Bank sees merit in introduction of a bespoke corporate insolvency regime for PIEMIs.
- Recommendations:
  - Recommendation 4 (¶35): Actively contribute to the EC’s review of PSD2 and push for strengthening (corporate insolvency regime, clarification of safeguarding rules, stronger governance and risk management obligations); if absent at EU level, introduce corresponding national reforms compatible with EU law. Addressee: Central Bank, DoF. Timing: MT. Priority: M.
  - Recommendation 5 (¶36): Consider prioritizing PIEMIs for roll-out of the Senior Executive Accountability Regime (SEAR) subject to progress on governance standards. Addressee: Central Bank. Timing: MT. Priority: L.

### Market structure, competition, open banking, and IBAN discrimination
- Bank digitalization and open banking:
  - Incumbent retail banks have spent more than EUR 3bn on digital innovation over the last five years.
  - Take-up of open banking in Ireland has been slow; obstacles include legacy systems, few third-party providers, low consumer interest, and API harmonization challenges.
- Instant payments:
  - In Q1 2021, SCT Inst was used for just 8.57 percent of all SEPA credit transfer transactions.
  - Major Irish banks are forming Synch Payments DAC (joint venture) to deliver mobile money-transfer services; proposal under CCPC assessment.
- IBAN discrimination:
  - SEPA Regulation (effective 2014) mandates acceptance of all SEPA IBANs but technical limitations and payer awareness have delayed full implementation in Ireland.
  - Central Bank and CCPC roles: CCPC handles certain consumer-trader complaints; Central Bank is competent authority for other cases.
  - Recommendation 8 (¶55): Central Bank, working with the CCPC, should continue efforts to address IBAN discrimination, seek legislative change if expansion of powers is necessary, encourage adoption of instant payments and identify obstacles to open banking. Addressee: Central Bank. Timing: MT. Priority: M.

### Outsourcing, cloud service providers (CSPs), and operational resilience
- Outsourcing landscape:
  - Regulated firms increasingly rely on outsourced service providers (OSPs) and intragroup/third-party OSPs for critical activities.
  - Central Bank research (2018): all regulated firms surveyed used OSPs; 40 percent planned further outsourcing in the following 12 to 18 months.
  - Central Bank is operationalizing an online portal in 2022 for firms to register their OSPs to identify concentration risks.
- Cloud concentration and DORA:
  - Reliance on a limited number of large CSPs could be a single point of failure, especially for fintechs.
  - CSPs often sit outside the regulatory perimeter in Ireland.
  - Digital Operational Resilience Act (DORA) will create a Union Oversight Framework potentially bringing critical ICT third parties (including cloud computing services) into direct oversight by the ESAs; current expectation is agreement under the French Presidency with rules starting to apply towards the end of 2024.
- Recommendation:
  - Recommendation 6 (¶44): Continue to advocate for CSPs of systemic importance to the Irish financial services sector to be included in the Union Oversight Framework under DORA; failing which, seek additional statutory powers to review and examine the resilience of systemic CSPs. Addressee: DoF, Oireachtas, Central Bank. Timing: MT. Priority: M.

### RegTech and BigTech implications
- RegTech applications:
  - Main applications: AML/CFT (sanction screening, remote onboarding), fraud prevention, prudential reporting, ICT security, creditworthiness assessments.
  - Central Bank guidance: the added value of RegTech must be clear; use of innovative technology is not justification in itself.
- BigTech risks and modes of entry:
  - BigTech can scale financial services using existing user bases, big data, AI/ML, cross-subsidization and economies of scale, raising concentration and operational risks.
  - Entry modes: licensed entities, partnerships with regulated providers, or Mixed Activity Groups (MAGs).
  - Central Bank supports a technology-neutral, activities-based regulatory approach and contributed to ESA working groups addressing BigTech risks.

### Buy Now Pay Later (BNPL) and non-bank lending
- Market status and regulatory change:
  - BNPL is the most significant fintech development in non-bank lending in Ireland.
  - Market size: approximately USD 267 million.
  - BNPL products currently unregulated but will be brought into the regulatory perimeter via an amendment to the Consumer Protection (Regulation of Retail Credit and Credit Servicing Firms) Act 2022; thereafter BNPL activity must be provided by a regulated entity such as a bank or retail credit firm (RCF).
  - Regulatory priorities include ensuring transparency of the credit agreement element and oversight of algorithmic/statistical creditworthiness assessments.

### Supervisory cooperation, passporting, and data sharing
- Passporting activity (2021):
  - Central Bank received four notifications from firms seeking to passport outwards on a freedom of services basis.
  - 56 notifications relating to the appointment of agents (four) and distributors (52).
  - 102 notifications from EU-based firms passporting into Ireland on a freedom of services basis.
  - 120 notifications relating to the appointment of agents (95) and distributors (25).
  - Roughly 3,500 firms actively passporting into Ireland; host regulators receive limited systematic information on passporting entities’ activities and must liaise bilaterally with home regulators.
- Recommendation:
  - Recommendation 7 (¶50): The Central Bank should engage with the ESAs on how to expand the set of information that host regulators receive systematically from home regulators. Addressee: Central Bank. Timing: C. Priority: M.

### Cyber risk and operational resilience initiatives
- Central Bank cyber approach and tools:
  - Cyber risk treated consistently across fintech and established financial services; IT security a focus since 2015.
  - IT Risk Questionnaire (ITRQ) used for authorization and supervisory assessments; Central Bank uses SSM’s ITRQ enhanced with 17 additional cyber-related questions.
  - In 2019, Operational and Cyber Resilience Teams established within the Governance and Operational Resilience Division (GOR).
- Sector initiatives:
  - TIBER-IE (launched 2019): intelligence-led ethical red-team tests of critical live production systems; Central Bank’s Cyber Resilience Team manages TIBER tests and coordinates cross-jurisdictional tests.
  - CIISI-IE (launched 2021): peer-to-peer trusted sharing community modelled on CIISI-EU and includes the National Cyber Security Centre.

### Main recommendations (summary from Table 1)
- 1. Use the experience gained with the Innovation Hub to inform reflections on the future development of the regulatory framework for fintech in Ireland (¶12). Addressee: Central Bank. Timing: ST. Priority: M.
- 2. Prepare to introduce domestic legislation in the event of significant delay or material gaps in the MiCA framework (¶27). Addressee: DoF, Central Bank. Timing: ST. Priority: M.
- 3. Further intensify efforts to monitor developments on crypto-assets through systematic data collection within the scope of its powers and, where unacceptable risks remain, issue carefully targeted warnings and investor communications (¶28). Addressee: Central Bank. Timing: ST. Priority: M.
- 4. Actively contribute to the EC’s review of PSD2 and push for the regime to be strengthened through the introduction of a corporate insolvency regime, clarification of safeguarding rules and stronger obligations on governance and risk management as appropriate; in the absence of such changes, introduce corresponding reforms at national level to the extent compatible with EU legislation (¶35). Addressee: Central Bank, DoF. Timing: MT. Priority: M.
- 5. Consider prioritizing payment and e-money institutions for the roll-out of the Senior Executive Accountability Regime (¶36). Addressee: Central Bank. Timing: MT. Priority: L.
- 6. Continue to advocate for cloud service providers (CSPs) of systemic importance to the Irish financial services sector to be included in the Union Oversight Framework under DORA; failing which, seek additional statutory powers to review and examine the resilience of systemic CSPs (¶44). Addressee: DoF, Oireachtas, Central Bank. Timing: MT. Priority: M.
- 7. Engage with the ESAs on how to expand the set of information that host regulators receive systematically from home regulators (¶50). Addressee: Central Bank. Timing: C. Priority: M.
- 8. Continue efforts to address IBAN discrimination, encourage adoption of instant payments and identify obstacles to the take-up of open banking (¶55). Addressee: Central Bank. Timing: MT. Priority: M.

*Source: 1irlea2022009 - EXECUTIVE SUMMARY; Excerpts from IMF country report chapter on Central Bank and fintech/crypto-assets.*

### EXECUTIVE SUMMARY ___________________________________________________________________________ 5

### EXECUTIVE SUMMARY

### Fintech industry overview and context
- Ireland’s fintech sector is growing in importance through the entry of innovative new players and digital transformation of incumbents’ business models and products.
- The largest sub-sector is represented by payment and e-money institutions (PIEMIs).
- Recent data show:
  - 65 percent of Irish adults are using non-cash payments multiple times a week (2020).
  - 24 percent use their mobile phone for contactless payments (2020).
  - 11 percent of Irish citizens with investments hold crypto-assets; this increases to 25 percent among those aged 25-34.
  - Between Q4 2019 and Q2 2021 the number of authorized PIEMIs and the value of transactions increased by 45 percent and 53 percent respectively.
  - A 2018 survey by the Central Bank indicated that 40 percent of regulated firms were using cloud service providers (CSPs).
- Ireland has adopted an “Ireland for Finance” Strategy implemented by annual action plans; Action Plan 2022 priority fintech actions include:
  - implementing the second phase of the Department of Finance’s (DoF) Fintech Steering Group;
  - developing educational resources to support consumers to engage with fintech (CCPC responsibility);
  - developing the instech.ie insurtech hub;
  - delivering a program of activities to support Irish-owned fintech companies’ growth in international markets;
  - developing a coordinated program to raise Ireland’s global visibility as a hub for fintech.

### Regulatory approach and supervisory tools
- The Central Bank of Ireland (the Central Bank) is the integrated financial services regulator and engages with new entrants to secure consumer interests and safeguard financial system resilience.
- The Central Bank has an Innovation Hub that provides a single point of contact for stakeholders on fintech-related issues. It is not a regulatory sandbox, but:
  - facilitates engagement and access by providing a direct point of contact for fintechs and incumbents;
  - provides early intelligence on innovative products and services;
  - offers published guidance on authorization processes and expectations;
  - prioritizes early engagement with firms, enabling preliminary or speculative engagement for information and guidance about authorization.
- The Central Bank plans an upcoming review of the Innovation Hub and should assess experience and stakeholder feedback to inform future development of the fintech regulatory framework in Ireland (¶12).

### Crypto-assets
- Most crypto-assets and services provided on them do not fall within the scope of existing EU legislation, except for AML/CFT requirements.
- The Central Bank has issued warnings to consumers on crypto risks and published consumer explainers; authorities are working together to improve consumer education on crypto and fintech.
- Ireland has supported a harmonized EU-level regulatory framework (MiCA — Markets in Crypto-Assets Regulation) instead of a bespoke national framework.
  - MiCA rules are expected to take effect in H2 2023 at the earliest.
- There is a lack of comprehensive and reliable data on the crypto sector, including interconnections with regulated financial services providers.
- Recommendations:
  - DoF and Central Bank should prepare to introduce domestic legislation in the event of significant delay or material gaps in the MiCA framework (¶27).
  - The Central Bank should further intensify monitoring of crypto-assets through systematic data collection within the scope of its powers and, where unacceptable risks remain, issue carefully targeted warnings and investor communications (¶28).

### Outsourcing, cloud service providers (CSPs), and operational resilience
- Irish regulated entities rely on a limited number of CSPs; technological resilience is particularly key for fintech providers.
- The EBA/ESMA/EIOPA and Central Bank guidelines on outsourcing and operational resilience provide a strong framework for indirect supervision of CSPs.
- CSPs themselves are not within the regulatory perimeter in many cases; some CSPs may be systemically important to the financial sector.
- The EU’s Digital Operational Resilience Act (DORA) will introduce a Union Oversight Framework. Recommendations:
  - Central Bank should continue to advocate for CSPs of systemic importance to the Irish financial services sector to be included in the Union Oversight Framework; failing which, the authorities should seek additional statutory powers to review and examine the resilience of systemic CSPs (¶44).
  - The outsourcing register currently being compiled by the Central Bank will facilitate identification of systemic CSPs.

### Payments, PIEMIs, and retail bank business models
- PIEMIs represent one of the largest fintech sub-sectors in Ireland and the number of entities is continuing to grow.
- A growing number of PIEMIs are offering services comparable to banking-type services, including e-money wallets into which customers are encouraged to lodge monies; funds in these wallets are not covered by the Irish Deposit Guarantee Scheme.
- The Central Bank has proactively strengthened governance expectations for PIEMIs, informed by best practice corporate governance requirements (e.g., Corporate Governance Requirements for Credit Institutions) and supervisory learnings.
- The Central Bank and DoF should actively contribute to the European Commission’s (EC) review of the Payment Services Directive 2 (PSD2) and push for the regime to be strengthened, particularly in:
  - governance and risk management;
  - safeguarding;
  - crisis management; and
  - corporate insolvency (equivalent changes should also be made to the Electronic Money Directive).
- If such changes are not adopted at EU level, the authorities should work together to introduce corresponding reforms at national level to the extent compatible with EU legislation.
- The Central Bank could consider accelerating the timetable for application of the full Senior Executive Accountability Regime (SEAR) to PIEMIs (¶36).

### Market structure, competition, and open banking
- Incumbent retail banks are dedicating significant resources to digital transformation; fintechs are increasing consumer choice through innovative services.
- To facilitate modernization and enable new entrants to compete, the Central Bank, working with the Competition and Consumer Protection Commission, should:
  - continue efforts to address IBAN discrimination;
  - where necessary, seek legislative change to expand powers to impose remedial action;
  - encourage adoption of instant payments and help consumers realize the full benefits of open banking;
  - identify obstacles to the take-up of open banking (¶55).

### Supervisory cooperation and data sharing
- Under the EU passporting framework, host regulators receive limited information on activities that passporting entities carry out in their jurisdiction.
- Recommendation: The Central Bank should engage with the European Supervisory Authorities (ESAs) on how to expand the set of information that host regulators receive systematically from home regulators (¶50).

### Main recommendations (Table 1 summary)
- 1. Use the experience gained with the Innovation Hub to inform reflections on the future development of the regulatory framework for fintech in Ireland (¶12). Addressee: Central Bank. Timing: ST. Priority: M.
- 2. Prepare to introduce domestic legislation in the event of significant delay or material gaps in the MiCA framework (¶27). Addressee: DoF, Central Bank. Timing: ST. Priority: M.
- 3. Further intensify efforts to monitor developments on crypto-assets through systematic data collection within the scope of its powers and, where unacceptable risks remain, issue carefully targeted warnings and investor communications (¶28). Addressee: Central Bank. Timing: ST. Priority: M.
- 4. Actively contribute to the EC’s review of PSD2 and push for the regime to be strengthened through the introduction of a corporate insolvency regime, clarification of safeguarding rules and stronger obligations on governance and risk management as appropriate; in the absence of such changes, introduce corresponding reforms at national level to the extent compatible with EU legislation (¶35). Addressee: Central Bank, DoF. Timing: MT. Priority: M.
- 5. Consider prioritizing payment and e-money institutions for the roll-out of the Senior Executive Accountability Regime (¶36). Addressee: Central Bank. Timing: MT. Priority: L.
- 6. Continue to advocate for cloud service providers (CSPs) of systemic importance to the Irish financial services sector to be included in the Union Oversight Framework under the new Digital Operational Resilience Act; failing which, seek additional statutory powers to review and examine the resilience of systemic CSPs (¶44). Addressee: DoF, Oireachtas, Central Bank. Timing: MT. Priority: M.
- 7. Engage with the ESAs on how to expand the set of information that host regulators receive systematically from home regulators (¶50). Addressee: Central Bank. Timing: C. Priority: M.
- 8. Continue efforts to address IBAN discrimination, encourage adoption of instant payments and identify obstacles to the take-up of open banking (¶55). Addressee: Central Bank. Timing: MT. Priority: M.

*IRELAND: International Monetary Fund technical note content summarized above.*

*Source: 1irlea2022009 - EXECUTIVE SUMMARY*

### 6.      The Central Bank is an integrated regulator with responsibility for almost all of the

### 6.      The Central Bank is an integrated regulator with responsibility for almost all of the financial services sector in Ireland.

### Central Bank mandate and structure
- Mission: serve the public interest by maintaining monetary and financial stability while ensuring that the financial system operates in the best interests of consumers and the wider economy.
- Legal basis: functions, responsibilities and powers are clearly defined and enshrined in the Central Bank of Ireland Act of 1942 (as amended) and in other primary and secondary legislation.
- Responsibilities:
  - Regulatory and supervisory responsibilities across authorization (licensing), supervision, enforcement and regulatory policy development.
  - Macroprudential authority for Ireland: monitors risks to financial stability and implements policies to mitigate impacts on the financial system and the real economy.
  - National resolution authority under the European Single Resolution Mechanism framework.

### Regulatory and supervisory approach to fintech
- Strategic focus areas: harness benefits of fintech while managing additional risks from fintech, BigTech, non-bank financial intermediation, and increased technology use in financial services.
- Identified risks from innovation:
  - robustness of underlying business models;
  - cyber-related threats;
  - too-big-to-fail concerns;
  - interconnectedness and operational concerns;
  - procyclicality;
  - impacts on incumbents’ business models and consumers.

- Institutional arrangements established in 2018:
  - Innovation Steering Group (ISG):
    - internal structure coordinating prioritization and operationalization of fintech and technological innovation-related activities across the Central Bank.
    - comprises senior staff from central banking, prudential regulation, conduct regulation and operations.
    - current strategic priorities include protection of consumers in an increasingly digitalized financial services landscape and contribution to EU and international innovation agenda.
  - Fintech Network:
    - working-level cross-Central Bank group of specialists supporting the Innovation Hub and sharing information informally.

- Innovation Hub:
  - facilitates engagement and access by providing a direct point of contact for fintechs and incumbents and early intelligence on innovative products and services.
  - open to enquiries from providers or potential providers of financial products or services that are innovative and sufficiently mature.
  - authorization/registration enquiries driven by changes to the regulatory perimeter (e.g., Virtual Asset Services Providers (VASPs) and Crowdfunding Service Providers).
  - Since establishment in 2018 the Hub has received 266 enquiries from innovative firms.
  - Profile of enquiry firms:
    - small and micro-sized enterprises comprise ~75 percent;
    - early stage start-ups ~40 percent;
    - ~92 percent of enquiry firms operate outside the Central Bank’s regulatory perimeter.
  - Other outreach tools: engagement with industry bodies, published guidance on authorization processes and expectations, and prioritized early engagement (including preliminary or speculative phase).

- International and EU engagement:
  - Active participant in the European Forum for Innovation Facilitators (EFIF) to share experiences and technological expertise and to reach common views on regulatory/supervisory treatment of innovative products, services and business models.
  - Considering participation in cross-border testing framework building on Global Financial Innovation Network approaches.

- Review and potential sandbox:
  - Upcoming review of the Innovation Hub to assess experience since establishment.
  - Feedback indicates some measure of support in Ireland for introduction of a regulatory sandbox; other jurisdictions have found innovation facilitators to be equally effective.

- Recommendation:
  - Recommendation 1: The Central Bank should use the experience gained with the Innovation Hub to inform its reflections on the future development of the regulatory framework for fintech in Ireland.

### Fintech monitoring and intelligence gathering
- Monitoring methods:
  - participation in EU and international fora;
  - monitoring and horizon scanning exercises;
  - gathering intelligence from the Innovation Hub and other regulatory activities.
- ISG annual exercise:
  - reviews trends in technological innovation and identifies risks and opportunities.
  - horizon-scanning gathers desk-based research, Innovation Hub insights, and reviews of planned activities by the ESAs and other relevant agencies.
  - Key themes for 2022 include crypto-assets and their underlying technology, progress of and plans for global stablecoins, and monitoring the development of Decentralized Finance (DeFi).
- Social media monitoring:
  - since 2013, monitoring social media and online platforms to understand consumers’ experiences and concerns.
  - uses a third-party provider to collate information in real-time from social and online media, including material published to online public forums by Irish consumers, potential customers and representatives of regulated firms.
  - insights feed into ongoing risk assessment processes and interventions with individual firms on live issues.
- Inter-agency monitoring:
  - DoF, the Central Bank, and the National Treasury Management Agency use the Financial Stability Group (FSG) to present research and discuss topics such as: Digital Euro and EU Digital Proposals (January 2021); Evolution of Banking Services (June 2021); Financial Stability Risks of new Institutions Establishing in Ireland (March 2019); Update on Stablecoins (September 2019); Cryptocurrencies (March 2018).
- EU-level monitoring:
  - Central Bank membership of EU fora that report on fintech developments (e.g., ECB’s Financial Stability Review, ESMA’s Trends, Risks and Vulnerabilities Report, EIOPA’s Financial Stability Report).
  - EBA Standing Committees incorporate monitoring of innovation and technological change into their mandates.

### Areas of focus — A. Crypto-Assets
- Adoption and data limitations:
  - Interest in and ownership of crypto-assets is growing globally, including in Ireland.
  - Lack of comprehensive and reliable data on crypto-asset activity in Ireland due to unregulated nature of large parts of the sector.
  - Finder Cryptocurrency Adoption Index indicates that approximately 12 percent of internet users in Ireland own crypto-assets.
  - A recent World Bank Working Paper, citing a Statista Global Consumer Survey, put the figure at approximately 10 percent.
  - Trend of payments institutions increasingly providing an on-ramp for crypto-assets is likely to encourage further growth.

- EU regulatory framework and gaps:
  - Where crypto-assets qualify as transferable securities or other types of financial instrument under MiFID, a full set of EU financial rules apply; ESMA’s 2019 work suggested only 10 to 30 percent of crypto-assets at that time might be covered by MiFID.
  - Crypto-assets not qualifying as MiFID financial instruments can give rise to consumer protection and market integrity risks due to absence of rules; EC’s proposed MiCA aims to address this gap.

- AML/CFT scope:
  - Current EU regulatory framework for crypto-assets that do not fall within MiFID extends only to AML and CFT obligations under the Fifth Anti-Money Laundering Directive (5AMLD).
  - Definition of virtual asset service providers (VASPs) includes services such as:
    - exchange between virtual assets and fiat currencies;
    - exchange between one or more forms of virtual assets;
    - transfer of virtual assets on behalf of another person;
    - custodian wallet provider;
    - participation in, and provision of, financial services related to an issuer's offer or sale of a virtual asset or both.
  - All VASPs established in Ireland are required to register with the Central Bank for AML/CFT purposes only.
  - If a firm already authorized by the Central Bank for prudential and/or conduct of business services plans to carry on business as a VASP, the firm is obliged to seek registration as a VASP.
  - There are currently no VASPs registered in Ireland but the Central Bank is processing a number of applications.

- Prudential treatment of banks’ crypto-asset exposures:
  - The Central Bank has not put in place national requirements and is awaiting outcome of international discussions.
  - BCBS consultation proposes categorizing crypto-asset exposures into two groups:
    - Group 1: tokenized traditional assets and crypto-assets with stabilization mechanisms (e.g., stablecoins).
    - Group 2: crypto-assets that do not qualify under Group 1 (e.g., Bitcoin).
  - Central bank digital currencies are out of scope.
  - Consultation outlines proposed treatment across credit and market risk requirements, other minimum requirements (leverage ratio, large exposures, liquidity ratios), supervisory review, and disclosure.
  - EBA has not yet communicated its position on prudential treatment.

- Prohibitions and supervisory approach to exposures:
  - Rules on permissibility of exposures to crypto-assets vary by type of regulated entity; prior approval by the Central Bank is likely required in most cases.
  - Investment funds (UCITS and AIFs):
    - any proposal for exposure to crypto-assets requires a detailed submission outlining:
      - how risks associated with exposure to crypto-assets could be managed in its risk management process;
      - for UCITS seeking to invest directly in crypto-assets, detailed analysis showing eligibility of direct investment.
    - For UCITS or retail AIFs, due to potential inability of retail investors to assess risks, the Central Bank has indicated it is highly unlikely to approve a fund proposing such exposure.
  - Insurance sector:
    - currently seven companies hold extremely small relative exposures to crypto-assets through unit-linked products, where market risk is entirely borne by the end-investor.
    - Improvements to data reporting under the Solvency II framework due for year-end 2023 will provide asset-by-asset reporting and give a breakdown of crypto-asset categories; pending the new approach, the Central Bank uses a workaround that gives a reasonably accurate view of crypto-asset exposures.

### Box: Markets in Crypto-Assets Regulation (MiCA) — key points
- MiCA objectives: i) legal certainty; ii) supporting innovation; iii) ensuring appropriate levels of consumer protection and market integrity; iv) ensuring financial stability.
- Scope: expected to cover all crypto-assets not covered elsewhere in EU financial services legislation, categorizing them as:
  - utility tokens;
  - asset-referenced tokens (ARTs, commonly known as multi-currency stablecoins);
  - e-money tokens (EMTs, commonly known as single currency stablecoins).
- Issuers and crypto-asset service providers in scope will be subject to prudential requirements and rules on complaints handling, conflicts of interest and conduct.
- MiCA differentiates regimes based on significance of the crypto-asset and calibrates requirements accordingly; determination of significance will consider size of customer base, token value or market capitalization, number and value of transactions, size of reserve of assets, significance of cross-border activities and interconnectedness with the financial system.
- Supervision debates: original proposal envisaged centralized supervision by the EBA with a college of supervisors for issuers of significant ARTs and EMTs; subsequent negotiations consider allocation of powers between EBA and ESMA and treatment of credit institutions supervised by the SSM that issue significant EMT/ART.
- ECB role: MiCA foresees a strong role for the ECB to mitigate monetary policy and financial stability risks; ECB (or National Central Bank in non-Euro area countries) empowered to issue a binding opinion refusing authorization on grounds of smooth operation of payment systems, monetary policy transmission, or monetary sovereignty.
- Timeline expectations: parts of the new framework expected to start to apply in H2 2023, with full application in 2024; some crypto-assets may remain outside the perimeter of MiFID and MiCA.

*Source: Excerpt from IMF country report section on Ireland (chapter on Central Bank and fintech/crypto-assets).*

### 26.      Unlike several other jurisdictions (e.g., France, Germany, Malta and Switzerland),

### 1irlea2022009 - 26.      Unlike several other jurisdictions (e.g., France, Germany, Malta and Switzerland),

### Crypto-assets: risks, consumer protection, and data gaps
- Ireland has not put in place a bespoke framework at national level for crypto-assets not covered by existing securities laws.
- Investor risks and supervisory responses:
  - Investors in these assets are exposing themselves to risks of which they may not be fully aware.
  - The Central Bank has issued warnings to consumers on the risks of investing in crypto-assets and issued consumer explainers.
  - The absence of regulation leads to a lack of reliable data on the sector, including on possible interconnections with the regulated financial services sector.
- Payments institutions as an on-ramp:
  - Payments institutions are increasingly providing an on-ramp for crypto-assets, creating a risk of investors conflating regulated and unregulated services.
  - The Central Bank requires disclaimers be displayed to consumers when they move between regulated and unregulated product offerings.
  - The Central Bank seeks to ensure that funds used for crypto-trading that are moved back to a customer’s e-money wallet are immediately safeguarded.

### Recommendations on crypto-assets
- Recommendation 2:
  - The Irish authorities have contributed actively to the MiCA negotiations and advocated for the earliest possible introduction of the new rules.
  - The authorities should continue to do so and prepare to introduce domestic legislation in the event of significant delay or material gaps in the MiCA framework.
- Recommendation 3:
  - The Central Bank should further intensify its efforts to monitor developments on crypto-assets through systematic data collection (including on consumer trends) within the scope of its powers and, where unacceptable risks remain, issue carefully targeted warnings and investor communications.

### Payments (PIEMI sector): growth and structure
- Sector growth and cross-border nature:
  - The payment institution and e-money institution (PIEMI) sector has experienced material growth in recent years.
  - PIEMIs operate on a cross-border basis, servicing customers in Ireland and across the EU.
  - Between Q4 2019 and Q4 2021, the number of authorized firms increased by 45 percent while the volume and value of transactions increased by 47 percent and 83 percent respectively.
- Composition and customer base:
  - The PIEMI sector consists of a growing number of small firms that attract a personal and business customer base.
  - A number of PIEMI firms hold client monies; these monies are subject to safeguarding requirements but are not covered by the Irish Deposit Guarantee Scheme (DGS).
- Central Bank supervisory stance:
  - The Central Bank expects regulated firms to be well-governed, with appropriate cultures, effective risk management and control arrangements.
  - The Central Bank has no tolerance for widespread consumer or investor harm.
  - The PIEMI sector is not as mature as other sectors and consists of many new entrants both in terms of operating in the financial services sector and as regulated entities.

### Regulatory definitions and services (PSD2 and EMD)
- Legal framework:
  - PIEMIs are regulated under the Irish legislation implementing the Payment Services Directive 2 (PSD2) and the Electronic Money Directive (EMD).
- Examples and roles:
  - PIs: merchant acquirers, payment account operators, money remitters and credit card issuers (provide money remittance services, issue payment instruments, acquire payment transactions).
  - EMIs: gift card issuers and e-wallet providers (authorized to issue e-money).
  - AISPs allow consumers to share financial details with third party providers.
  - PISPs allow payments to be initiated directly from a customer’s bank account.
- E-money wallets and risks:
  - EMIs are prohibited from taking deposits (Regulation 28 of the EMR: “an electronic money institution shall not engage in the business of taking deposits or other repayable funds”).
  - A growing number of EMIs offer services comparable to banking-type services by encouraging customer lodgement into e-money wallets; funds in these wallets are not covered by the Irish DGS.
  - E-money wallets can potentially be used as an on-ramp to investment in crypto-assets.

### Regulation and supervision of PIEMIs: challenges and priorities
- Supervisory approach and coordination:
  - The Central Bank adopts an integrated approach to supervising the PIEMI sector, given its prudential, conduct and AML mandate.
  - Three supervisory engagement models deliver the prudential, conduct and AML mandates, with joined-up planning and regular collaboration between supervisors.
  - The level of supervisory engagement is largely determined by each firm’s rating under the Central Bank’s PRISM framework.
  - The impact model for the PIEMI sector was updated in 2019 and refined further in 2021.
  - Authorization approach aims to be risk based, proportionate, and focused on a firm’s ability to continuously comply post-authorization.
- Key supervisory priorities and gaps:
  - Safeguarding of client funds is a key supervisory priority because safeguarded monies are not covered by the Irish DGS.
  - The Central Bank expects robust, board-approved safeguarding risk frameworks.
  - The methodology for calculation of capital requirements is not fully sensitive to the nature, scale and complexity of this sector.
  - Governance, conduct risk and technological developments require heightened supervisory regard.
  - Many PIEMIs are technology firms whose internal culture may not be aligned with financial services regulatory expectations.
  - The Central Bank has strengthened governance expectations drawing on best practice (e.g., Corporate Governance Requirements for Credit Institutions) but sees room for further progress on governance expectations and aspects of safeguarding rules (including suitability of insurance policies, acceptable guarantees, definition of low-risk assets and the process for repayment of funds in case of failure).
  - The Central Bank sees merit in introduction of a bespoke corporate insolvency regime for PIEMIs that takes due account of these entities’ business models.
  - The review of PSD2 underway as part of the EC’s Retail Payments Strategy is an important opportunity to address these shortcomings.

### Recommendations on PIEMIs and governance
- Recommendation 4:
  - The Irish authorities should actively contribute to the EC’s review of PSD2 and push for the regime to be strengthened through:
    - the introduction of a corporate insolvency regime,
    - clarification of safeguarding rules, and
    - stronger obligations on governance and risk management.
  - In the absence of such changes, the authorities should introduce corresponding reforms at national level to the extent compatible with EU legislation.
  - Equivalent changes should also be made to the EMD.
- Recommendation 5:
  - Subject to sufficient progress being made on PIEMIs’ governance standards, the Central Bank could consider accelerating the timetable for application of the full Senior Executive Accountability Regime (SEAR) to PIEMIs.

### BigTech: risks, market power, and regulatory approach
- Presence and capabilities:
  - BigTech firms are a significant presence in Ireland and can quickly scale up their role in provision of financial services using existing user bases, big data, advanced analytical technologies (AI and ML), cross-subsidization, and economies of scale.
- Risks and market structure:
  - Expansion into financial services can bring benefits and risks, including concentration risk where a small number of companies dominate service provision (evident in increasing use of the cloud and the small number of CSPs).
- Modes of market entry:
  - BigTechs can become active as licensed entities or through partnerships with regulated providers, forming Mixed Activity Groups (MAGs) offering both financial and non-financial services.
  - Partnerships may create additional layers on top of existing financial infrastructures, leveraging network effects and data collection to create ‘one-stop-shops’.
- Regulatory stance:
  - Recent advice from the ESAs to the EC sets out measures to address risks from BigTech moves into financial services, covering operational resilience, consumer protection, AML/CFT and financial stability risks.
  - The Central Bank contributed to ESA working groups and supports a technology-neutral, activities-based regulatory approach: entities carrying on the same business and creating the same risks should be subject to the same rules.
  - Particular focus is required on the additional and heightened risks from indirect participation of BigTechs in financial services.

### Outsourcing and third-party relationships: scope and risks
- Prevalence and planned action:
  - Regulated financial services providers in Ireland are increasingly reliant on outsourced service providers (OSPs), including intragroup and third-party OSPs for critical activities.
  - Central Bank research in 2018 found all regulated firms surveyed were using OSPs and that 40 percent of firms were planning further outsourcing activity in the following 12 to 18 months.
  - In 2022, the Central Bank will operationalize an online portal for regulated firms to register their OSPs to provide a more up-to-date picture of outsourcing and highlight concentration risks.
- Cross-industry guidance and identified risks:
  - The Central Bank’s 2021 cross-industry guidance identifies key risks: sub-outsourcing, sensitive data risk, data security, offshoring risk, and concentration risk (dependency on a single or small number of OSPs for critical functions).

### Cloud service providers (CSPs) and systemic concentration risk
- Cloud adoption and vulnerabilities:
  - The use of cloud computing has become increasingly widespread across the financial services sector; CSPs eliminate the need for traditional in-house IT data storage and generate significant cost savings.
  - Reliance on a relatively small number of large CSPs could evolve to be a single point of failure; this is particularly relevant for fintech given the importance of technological resilience.
- Supervisory perimeter and DORA opportunity:
  - EBA/ESMA/EIOPA and Central Bank guidelines provide a strong framework for indirect supervision of CSPs, but the CSPs themselves remain outside the regulatory perimeter in Ireland.
  - The EU’s upcoming Digital Operational Resilience Act (DORA) provides an opportunity to bring CSPs under direct supervisory oversight.

### Box 2 — Digital Operational Resilience Act (DORA): scope and status
- Background and aims:
  - On September 24, 2020, the EC issued a regulatory proposal on Digital Operational Resilience for the financial sector (DORA) as part of a Digital Finance Package.
  - DORA aims to introduce a harmonized and comprehensive framework on digital operational resilience for European financial institutions.
  - When adopted, DORA will also bring critical third-party service providers – such as cloud computing services – within direct oversight of the ESAs.
- Structure and obligations:
  - DORA is divided into two parts:
    - Part 1 applies to a wide spectrum of EU “financial entities” (including banks, insurers, payment service providers, crypto-asset issuers and service providers, and crowdfunding service providers) and would impose obligations including ICT risk management, incident reporting and information sharing. ICT third-party risk with financial entities identified as “significant and cyber-mature” is subject to the most onerous obligations.
    - Part 2 affects businesses providing ICT services to financial entities; DORA would allow the ESAs to designate certain service providers (including providers of cloud computing services, software, and data analytics) as “critical” to the functioning of the financial sector.
  - DORA proposes a new Union Oversight Framework where one of the ESAs will be appointed as lead overseer for each critical third-party ICT service provider to monitor whether the ICT service provider has in place comprehensive, sound and effective rules to manage ICT risks.
- Timeline and status:
  - DORA is currently under discussion in the “trilogues” involving the EC, the European Council and the European Parliament.
  - The current expectation is that agreement on the text will be reached under the French Presidency, with the rules starting to apply towards the end of 2024.

### Recommendation on CSPs and DORA
- Recommendation 6:
  - The Irish authorities should continue to advocate that CSPs of systemic importance to the Irish financial services sector (the identification of which will be facilitated by the Central Bank’s upcoming outsourcing register) be included in the Union Oversight Framework under DORA; failing which, the authorities should seek additional statutory powers to review and examine the resilience of these entities.

### RegTech: applications and supervisory view
- RegTech applications most evident in:
  - AML/CFT – sanction screening or remote onboarding of customers;
  - Fraud prevention – automated behavior and transaction monitoring;
  - Prudential reporting – supporting institutions in their regulatory submissions;
  - ICT security – detection mechanisms for operational security; and
  - Creditworthiness assessments – new capabilities for assessing client creditworthiness.
- Central Bank guidance:
  - The Central Bank emphasizes that the added value of any RegTech solutions needs to be clear (use of innovative technology is not justification in itself).
  - There is a growing trend of partnerships between regulated entities and RegTech providers, some of which have been categorized as OSPs depending on the activity provided.

*Source: IMF country report content unit 1irlea2022009.*

### 45.      The most significant fintech development in the non-bank lending sector in Ireland is

### The most significant fintech development in the non-bank lending sector in Ireland

### Buy Now Pay Later (BNPL): emergence and implications
- The most significant fintech development in the non-bank lending sector in Ireland is the emergence of new business models for Buy Now Pay Later (BNPL) products.
- Regulatory status:
  - BNPL products are currently unregulated but will be brought into the regulatory perimeter by an upcoming legislative change, via an amendment to the Consumer Protection (Regulation of Retail Credit and Credit Servicing Firms) Act 2022.
  - Following the legislative change, the activity of BNPL will need to be provided by a regulated entity such as a bank or retail credit firm (RCF).
  - RCFs are defined as firms authorized to provide credit to natural persons.
- Market size and growth potential:
  - Market size is currently approximately USD 267 million.
  - The market is in the early stages but has the potential for significant growth over the medium term.
- Consumer and provider dynamics:
  - BNPL offers retailers the ability to integrate different payment solutions into their product offerings, particularly online.
  - BNPL offerings are likely to increase consumers’ access to credit for purchases (generally of a lower value nature) for which they may not have previously considered obtaining credit.
  - BNPL providers may use algorithms and statistical models to assess creditworthiness.
- Regulatory challenges and priorities:
  - The ease of access to credit and differing methods of assessing creditworthiness may present regulatory challenges.
  - It will be important that the credit agreement element of the transaction is sufficiently transparent to consumers in their dealings with BNPL providers.

### Supervisory cooperation and passporting activity
- Central Bank coordination:
  - The Central Bank has extensive arrangements to coordinate fintech work internally through internal committees and working groups to ensure a consistent approach across supervision and regulation.
  - The Central Bank engages with counterpart regulators at international level, notably through IOSCO, and has bilateral arrangements with peer agencies to facilitate cooperation and information-sharing.
- EU passporting framework and activity (2021 data):
  - Passporting can occur via freedom of services (FOS) or freedom of establishment (FOE).
  - For PIEMIs operating on a FOE basis, home MS is responsible for prudential supervision and host MS for conduct supervision.
  - In 2021, Central Bank received:
    - four notifications from firms seeking to passport outwards on a freedom of services basis,
    - 56 notifications relating to the appointment of agents (four) and distributors (52),
    - 102 notifications from EU-based firms passporting into Ireland on a freedom of services basis,
    - 120 notifications relating to the appointment of agents (95) and distributors (25).
  - Cross-border activity is typical of many fintechs’ business models.
- Information limitations and scale:
  - Host regulators currently receive limited information on the activities passporting entities carry out in their jurisdiction once the initial notification has taken place.
  - To obtain more information on the activities of the roughly 3,500 firms actively passporting into Ireland, the Central Bank would have to liaise with the home regulator bilaterally.
- Recommendation 7:
  - The Central Bank should engage with the ESAs on how to expand the set of information that host regulators receive systematically from home regulators.

### Open banking, retail bank business models, and IBAN discrimination
- PSD2 and open banking:
  - One of the principal aims of PSD2 was to encourage the development of “open banking” by enabling third-party payment service and financial service providers to access consumer banking information via APIs.
  - Open banking is designed to promote competition by giving consumers greater choice and facilitating the entry of new players.
- Take-up and barriers in Ireland:
  - With one notable exception, take-up of open banking opportunities has been slow in Ireland.
  - Possible explanations: issues upgrading legacy systems, a relative absence of third-party providers operating in Ireland, general lack of interest among Irish consumers, and challenges around harmonization of APIs.
  - The EBA established an industry working group on APIs under PSD2 from January 2019 to December 2021 and produced seven sets of clarifications.
- Bank digital transformation and payments infrastructure:
  - Incumbent retail banks in Ireland are dedicating significant resources to digital transformation.
  - Figures from the Banking & Payments Federation Ireland indicate that Irish retail banks have spent more than EUR 3bn on digital innovation over the last five years.
  - One element missing from the retail banking landscape in Ireland is instant payments (see Box 3).
- IBAN discrimination:
  - SEPA Regulation (effective 2014) mandates acceptance of all SEPA IBANs, but technical limitations in legacy core banking systems and payer awareness have delayed full implementation in Ireland.
  - The CCPC is responsible for complaints where payee is a consumer and payer is a trader, or vice versa; the Central Bank is the competent authority for all other cases of IBAN discrimination.
  - The Central Bank has actively engaged with non-compliant institutions and has sometimes relied on moral suasion; it has begun discussions with DoF on whether additional legislative powers are needed.
- Box 3 — Instant Payments (highlights):
  - Eurosystem retail payments strategy aims for full deployment of instant payments via the EPC’s SEPA instant credit transfer (SCT Inst) scheme, instant payment clearing services, and the TARGET Instant Payment Settlement (TIPS) service.
  - ECB ensured TIPS pan-European reach at the end of 2021.
  - Adoption of instant payments has been slow and uneven across the EU:
    - In Q1 2021, SCT Inst was used for just 8.57 percent of all SEPA credit transfer transactions.
  - A possible revision of the SEPA Regulation to mandate instant payments is under consideration by the EC.
  - Pending mandated adoption, main Irish banks are in the early stage of setting up a mobile money-transfer system called Synch Payments via Synch Payments DAC, a joint venture whose founding shareholders are Allied Irish Banks P.L.C, Bank of Ireland, Permanent TSB P.L.C and KBC Bank Ireland P.L.C. The proposal is currently being assessed by the CCPC.
- Recommendation 8:
  - The Central Bank, working with the CCPC, should continue efforts to address IBAN discrimination and, where it considers an expansion of its powers to impose remedial action necessary, actively seek legislative change.
  - The Central Bank should also continue to encourage the adoption of instant payments and identify obstacles to the take-up of open banking.

### Approach to cyber risk and resilience initiatives
- Central Bank approach:
  - The Central Bank’s approach to cyber risk does not differentiate between fintech and more established financial services activities.
  - IT security and cyber risk have been a focus across all sectors since 2015.
- IT Risk Questionnaire (ITRQ):
  - An ITRQ forms the basis for all Central Bank assessments of IT risk, including cyber risk, and is used for authorization and supervisory assessments.
  - The tool evolved from a questionnaire issued to banks in 2015 to become part of the SSM’s ITRQ developed in 2016/17.
  - The Central Bank uses the SSM’s ITRQ and enhances it with 17 additional cyber-related questions for the firms it supervises.
  - Both institutions’ ITRQs are updated annually; the resulting Annual Report is published on the ECB website.
- Organizational structures and initiatives:
  - In 2019, the Central Bank established Operational and Cyber Resilience Teams within the Governance and Operational Resilience Division (GOR).
  - The Technology Risk Team supports supervisors on supervisory and authorization aspects of IT security and cyber risk.
  - The Cyber Resilience Team focuses on sector engagement and manages two key initiatives: Threat Intelligence Based Ethical Red-teaming (TIBER-IE) and Cyber Information and Intelligence Sharing Initiatives (CIISI-IE), in a catalyst rather than supervisory capacity.
- TIBER-IE:
  - Launched in Ireland in 2019, based on the TIBER-EU framework.
  - TIBER tests are controlled, bespoke, intelligence-led red team tests (ethical hacking) of critical live production systems to reveal strengths and weaknesses; the outcome is not a pass or fail.
  - The Central Bank’s Cyber Resilience Team manages TIBER tests on Irish entities and coordinates cross-jurisdictional tests.
  - The Cyber Resilience Team is part of the EU’s TIBER Knowledge Centre.
- CIISI-IE:
  - Launched in 2021 and modelled on CIISI-EU (launched in 2020).
  - CIISI-IE facilitates a peer-to-peer, trusted sharing community for financial institutions recognized as delivering critical services to the Irish economy and includes the National Cyber Security Centre.

*Source: Chapter content from the provided IMF document.*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1irlea2022009.pdf_
