Reporting

Multi-Jurisdiction Regulatory Reporting for Payment and E-Money Firms: UK, EU, Canada, US, Australia and Hong Kong

Published September 2026 · Last reviewed September 2026 · 18 min read

Key Takeaways

  • Regulatory obligations attach to the licensed legal entity, even where reporting operations are centralised.
  • A common data model can serve several regulators, but local calculations and forms remain necessary.
  • The United Kingdom now includes monthly REP027 safeguarding reporting for in-scope firms under CASS 15.
  • European Union payment and e-money reporting is materially shaped by each national competent authority, alongside European rules.
  • Canada combines Bank of Canada Retail Payment Activities Act reporting with separate anti-money-laundering obligations where applicable.
  • United States money transmission reporting remains state-led, commonly using the Nationwide Multistate Licensing System but with material state variation.
  • Australia and Hong Kong have different licence categories and reporting regimes, so group labels must not replace local analysis.

A payment group licensed in several countries cannot operate regulatory reporting as one global return. It can standardise data, reconciliations, controls and evidence, but each licensed entity remains subject to local definitions, deadlines, submission systems and accountable management.

The effective model is therefore global control with local regulatory logic. This guide compares the principal reporting families across six priority markets and explains how a group can build one controlled reporting architecture without pretending the laws are identical.

## The group reporting problem

An international payments group may have a United Kingdom electronic money institution, a European Union payment institution, a Canadian payment service provider, several United States money-transmitter licences, an Australian remittance registration and a Hong Kong money service operator or stored-value-facility entity.

Commercially, those businesses may use one brand and one product. Legally, they do not create one reporting perimeter. Each regulator needs data about a defined entity, service, customer population, funds flow and reference period.

The group therefore needs to answer four questions for every reported figure:

  1. Which legal entity owns the obligation?
  2. Which products, customers and transactions are included?
  3. Which local rule defines the calculation?
  4. Which approved source and reconciliation supports the answer?

Comparison of the six markets

MarketPrincipal payment-firm regulator or systemCommon reporting familiesStructural issue
United KingdomFinancial Conduct AuthoritySafeguarding, prudential, complaints, fraud, financial-crime and statistical returnsCASS 15 connects daily controls to monthly REP027
European UnionHome-state national competent authority, with European rulesPrudential, safeguarding, payment statistics, fraud, incidents and local supervisory returnsForms and frequency vary by member state
CanadaBank of Canada and, where applicable, FINTRACRetail Payments Activities Act annual and incident reporting, safeguarding and operational risk information, anti-money-laundering reportsFederal regimes have different purposes and data
United StatesState regulators, Nationwide Multistate Licensing System and FinCENMoney Services Businesses Call Report, state financial and activity returns, suspicious-activity and currency reportsLicensing and reporting remain state-specific
AustraliaAUSTRAC and other regulators depending on serviceInternational funds-transfer, suspicious-matter, threshold-transaction and compliance reportingAnti-money-laundering reporting is event-driven and time-sensitive
Hong KongCustoms and Excise Department or Hong Kong Monetary Authority, depending on activityMoney-service records and anti-money-laundering reporting; stored-value supervisory, float and financial informationMoney service operator and stored-value facility are different regimes

This is an operating comparison, not an exhaustive legal inventory. A group must maintain an obligation register tailored to its actual permissions and services.

United Kingdom

Authorised payment institutions and electronic money institutions report to the Financial Conduct Authority under the Payment Services Regulations, Electronic Money Regulations and the FCA Handbook. The returns applicable to a firm depend on its status, permissions and activities.

CASS 15 added a particularly important connection between operations and reporting. In-scope safeguarding institutions perform daily internal and external safeguarding reconciliations and submit the monthly REP027 safeguarding return within 15 business days after calendar month end under SUP 16.14A.

The group data model should retain client liabilities, safeguarded balances, accounts, currencies, reconciliation outcomes, shortfalls and control information at the United Kingdom legal-entity level. It should not derive the return from a global treasury position.

Other reporting may include prudential, complaints, payment-services, fraud and financial-crime information. The exact schedule should be confirmed against the firm's RegData reporting schedule and current Handbook requirements.

Read our complete CASS 15 compliance guide for the safeguarding framework.

European Union

The European Union framework establishes common requirements through payment-services and electronic-money law, but supervisory reporting is not one completely harmonised return set for every payment institution and electronic money institution.

The home-state national competent authority sets or administers important local templates, frequencies and portals. A firm authorised in Ireland may report through the Central Bank of Ireland's systems; a Luxembourg entity reports to the Commission de Surveillance du Secteur Financier; another member state will have its own supervisory implementation.

Common reporting families can include own funds and capital, safeguarding, payment volumes, fraud data, financial information and operational or security incidents. The Digital Operational Resilience Act has also changed incident-management and reporting architecture for financial entities within its scope since 17 January 2025.

The correct group approach is to maintain a European canonical data model and then document each national return. Passporting or cross-border provision does not justify assuming that the home-state return captures every host-state or statistical obligation.

Canada

The Retail Payment Activities Act established Bank of Canada supervision of payment service providers performing prescribed retail payment activities. Operational-risk and end-user-funds safeguarding requirements took effect in September 2025.

Registered payment service providers have annual reporting obligations. The Bank of Canada's annual reporting framework covers prescribed information about retail payment activities, operational risk and the safeguarding of end-user funds. The annual report is generally due by 31 March for the previous calendar year, subject to the rules applying to the provider and its registration timing.

Payment service providers must also notify the Bank of Canada of certain incidents under the Retail Payment Activities Act framework. Incident identification therefore needs to connect technology, operations, compliance and regulatory reporting rather than sit in a separate service desk.

The Retail Payment Activities Act is not a substitute for Financial Transactions and Reports Analysis Centre of Canada obligations. A firm that is also a money services business may have separate registration, record-keeping, suspicious-transaction, large-cash, large-virtual-currency or electronic-funds-transfer reporting duties depending on its activities.

See our Canada Retail Payment Activities Act registration guide and Canada money services business guide.

United States

United States money transmission regulation is primarily state-based. A nationwide operator may hold licences across many states, each with its own legal requirements, regulator expectations and licence conditions.

The Nationwide Multistate Licensing System provides the Money Services Businesses Call Report used by participating regulators. It captures company and state-level information, but use of a common system does not eliminate state variation. States can require additional reports, financial statements, permissible-investment information, surety-bond maintenance and other filings.

The reconciliation challenge is significant because permissible investments and outstanding obligations must be understood under applicable state law and entity structure. A group-level cash balance cannot show whether a particular licensee met the required coverage in a state.

Federal Financial Crimes Enforcement Network registration and Bank Secrecy Act reporting operate alongside state licensing. Suspicious Activity Reports, Currency Transaction Reports and other federal obligations should not be confused with prudential or licence reporting to state regulators.

The reporting inventory should therefore be built state by state, including the form, frequency, submission system, statutory definition and relationship to the Nationwide Multistate Licensing System.

Australia

Australian remittance and payment businesses can have obligations to the Australian Transaction Reports and Analysis Centre under anti-money-laundering and counter-terrorism-financing legislation. The exact perimeter depends on the designated services provided and any other applicable financial-services framework.

International Funds Transfer Instruction reports are a central operational obligation for businesses sending or receiving qualifying transfer instructions. AUSTRAC states that the report must generally be submitted within 10 business days after the instruction is sent or received. Reporting populations and message details should be derived from controlled transaction data rather than assembled retrospectively.

Suspicious Matter Reports operate to shorter deadlines based on the type of suspicion, while Threshold Transaction Reports generally cover physical-currency transactions at or above the statutory threshold. Firms may also have compliance-report obligations when AUSTRAC requires a report for the relevant year.

The reporting system should distinguish transaction reporting from case-based suspicious-matter decisions. Automating data extraction does not automate the judgement required to form and report a suspicion.

See our Australia AUSTRAC remittance registration guide.

Hong Kong

Hong Kong has distinct regimes for different payment activities. A money service operator providing money changing or remittance services is licensed by the Customs and Excise Department. A stored value facility is supervised by the Hong Kong Monetary Authority under the Payment Systems and Stored Value Facilities Ordinance.

Money service operators must maintain records and comply with anti-money-laundering and counter-terrorist-financing requirements. Suspicious transaction reports are made to the Joint Financial Intelligence Unit. The precise control framework should reflect the business's services, delivery channels, agents and cross-border flows.

Stored value facility licensees face supervisory expectations concerning float protection, segregation, reconciliation, financial resources, risk management and information supplied to the Hong Kong Monetary Authority. The float is not simply the balance of one bank account. The licensee needs a controlled record of obligations to users and the assets protecting those obligations.

Groups must not treat a money service operator licence as equivalent to a stored value facility licence. The products, regulator, safeguarded or protected value and reporting obligations differ.

See our Hong Kong money service operator licence guide.

What can be standardised globally?

The group can standardise the control architecture even where returns differ:

  • source-data ingestion and completeness monitoring;
  • entity, product, customer, account and currency identifiers;
  • ledger-to-bank and transaction reconciliations;
  • version-controlled calculation rules;
  • exception, incident and correction workflows;
  • maker-checker approvals and attestations;
  • deadline calendars and escalation;
  • immutable evidence and submission receipts; and
  • governance reporting about late, corrected or high-risk returns.

Local modules then define scope, fields, formulas, thresholds, forms and submission methods.

The canonical data model

A scalable reporting platform starts with common atomic facts rather than a global spreadsheet. These facts can include transaction identifier, legal entity, product, customer, payer and payee countries, amount, currency, timestamp, payment rail, status, fee, account, ledger posting and safeguarding classification.

Regulatory rules transform those facts into local outputs. The original fact remains unchanged, while the platform records the rule and version used for each return.

This structure improves consistency without forcing false equivalence. It also makes a regulatory interpretation testable: a reviewer can see exactly which records a local rule included or excluded.

Entity-level governance

Centralisation can improve quality, but accountability must remain clear. Each licensed entity should have an approved reporting inventory, local owner, review route and evidence of submission.

Service-level agreements between the licensed entity and a group reporting team should cover data delivery, correction, deadlines and escalation. The local board or governing body needs information about its own returns, not only group-wide performance.

Where a regulator or auditor asks how a number was produced, the entity should be able to answer without relying on undocumented group knowledge.

How Safeheld supports the operating model

Safeheld is a specialist regulatory technology platform. The strategic role is to provide a controlled layer for reconciliation, evidence and reporting workflows while local regulatory rules remain explicit.

Regulatory Counsel can help a group define the obligation inventory and jurisdiction-specific interpretation. Safeheld can support the shared data and workflow layer. Firms should confirm which country modules, returns and connectors are currently available before procurement and should not assume that one deployment submits every local return.

The strongest starting point is a high-value workflow where local obligations are already clear, such as United Kingdom CASS 15 reconciliation and REP027 evidence, followed by controlled expansion to further entities and returns.

Twelve-step group implementation plan

  1. List every licensed or registered legal entity.
  2. Map its products, customer types, money flows and regulators.
  3. Build the obligation register from current official sources.
  4. Assign a local accountable owner and group process owner.
  5. Define canonical transaction and balance data.
  6. Map each return field to sources and local rules.
  7. Reconcile reported populations with ledgers, banks and prior returns.
  8. Configure deadlines, validation and approval.
  9. Test corrections, incidents and failed data feeds.
  10. Run parallel reporting before cutover.
  11. Provide entity-level board information and evidence access.
  12. Operate formal regulatory-change control in each jurisdiction.

Discuss a multi-jurisdiction reporting review

Regulatory Counsel's regulatory reporting team can map obligations across licensed entities and identify conflicting definitions, gaps and duplicated work. Safeheld can demonstrate the technology architecture for the reconciliation, evidence and reporting layer.

The review is particularly relevant to groups adding a new licence, acquiring a regulated entity or relying on locally maintained workbooks that cannot be reconciled at group level.

Frequently Asked Questions

Yes, it can use one shared control and data platform, but it still needs jurisdiction-specific logic, forms, approvals and submission routes.

No. European law creates common obligations, but national competent authorities retain important local templates, frequencies and supervisory processes.

No. Bank of Canada supervision and Financial Transactions and Reports Analysis Centre of Canada obligations have different legal purposes and can both apply.

No. The system provides common infrastructure and the Money Services Businesses Call Report, but states retain additional requirements and legal definitions.

It should standardise entity and transaction identifiers, source-data controls, reconciliation, lineage, approvals and evidence before attempting to automate many local forms.

Official sources

This article is a high-level comparison, not a complete statement of any entity's obligations. Local requirements depend on the licence, products, customers and current rules. Obtain jurisdiction-specific advice before relying on a reporting design.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert