Bank of Lithuania

[[#ex]]

Consultations

A series of consultation events for payment institutions and electronic money institutions took place in 2024. Find the presentation here:

Regulation of the activities of PIs, EMIs through third parties, including agents, distributors, outsourcing, and white labelling (608.6 KB )

Prudential developments in electronic money and payment institutions (739.6 KB )

In 2023, the Bank of Lithuania conducted an anonymous survey of EMIs and PIs, aimed at assessing whether their governance adheres to best practice principles. Here are the slides from the presentation of the survey results:

Application of the best practice principles in the governance (489.4 KB )

Presentation on own funds requirements for payment institutions and electronic money institutions prepared in 2023:

Capital formation options for the EMI and PI sector (419.6 KB )

A series of consultation events for payment institutions and electronic money institutions took place in 2023. Find the presentation here:

Prudential developments in electronic money and payment institutions (474.6 KB ) 

Issues in payment service provision (699 KB )


Annual meetings with representatives of the EMI and PI sector

In 2024, the annual meeting of the representatives of the Bank of Lithuania and Electronic Money and Payment Institutions was held, where the strategy of the Bank of Lithuania for 2024-2026, the review of the EMI and PI sector for 2023, the priorities and emphasis of supervision for 2024 and the progress of the transformation of reporting data acceptance systems were presented.


Enhancement of corporate governance, internal control and compliance culture

In 2025, Lietuvos bankas prepared the Guidelines for Electronic Money and Payment Institutions Regarding the Organisation of the Risk Management Process, aimed at detailing and helping electronic money and payment institutions understand the applicable requirements for organizing the risk management process as set out in the current legislation, demonstrating their connection to the activities of these institutions, providing Lietuvos bankas recommendations on enhancing the maturity of the risk management process in view of the life cycle of electronic money and payment institutions, and highlighting best practice examples.

In 2025, Lietuvos bankas issued a recommendation letter reminding about key and relevant legislative changes taking effect in 2025 in the areas of operational management, internal control, and the strengthening of compliance culture. It also draws attention to current risks and common situations that electronic money and payment institutions should consider in their day-to-day operations.

In 2025, the Bank of Lithuania published a Dear CEO letter addressed to electronic money and payment institutions regarding improving the information experience of payment service users when the business model involves third parties engaged by electronic money and payment institutions licensed by the Bank of Lithuania to act on their behalf, or other entities. The letter highlights certain shortcomings in the activities of financial institutions as well as provides recommendations and proposals in line with good market practice, which, in the opinion of the Bank of Lithuania, will help to better provide payment services, inform payment service users and ensure the protection of their rights and legitimate interests. 

With a view of facilitating cooperation and dialogue, in 2024, the Bank of Lithuania hereby applies to institutions intending to publicly offer or seek admission to trading of asset-referenced tokens (ART) or electronic money tokens (EMT) in the future, and draws the attention of the institutions to certain requirements of Regulation (EU) No 2023/1114 of the European Parliament and of the Council on markets in crypto-assets (hereinafter – MiCAR) and encourages the institutions to make timely preparations for the implementation of MiCAR.

In 2023, the Bank of Lithuania published its second Dear CEO Letter on "Improving the Provision of Payment Services and the Experience of Users of Payment Services" addressed to financial institutions. It draws attention to certain shortcomings in the performance of financial institutions and provides recommendations that the Bank of Lithuania believes will help improve the seamless provision and quality of payment services.

In 2023, the Bank of Lithuania has developed the Principles of Good Governance Practices for Electronic Money and Payment Institutions.

In 2023, the Bank of Lithuania published its third Dear CEO Letter to heads of EMIs and PIs. It provides observations and recommendations related to licensing services provision, proper governance, equity requirements, risk management, client funds protection, and other relevant issues.

In 2022, the Bank of Lithuania delivered specific proposals to payment service providers on how to improve customer service, accessibility of services and strengthen protection against fraud. The proposals were the result of the assessment of information on supervision of financial market participants, consumer complaints and disputes covering nearly two years.

In 2022, the Bank of Lithuania published its second Dear CEO Letter to heads of EMIs and PIs. It provides observations and recommendations related to the provision of licensing services, risk management, safeguarding customer funds and other relevant issues. The Dear CEO Letter presents an overview of issues related to the implementation of business plans, provision of licensing services, change of business model, safeguarding of customer funds, internal audit and internal control, risk management (including money laundering and terrorist financing, information and communication technologies, and security) and reporting.

In 2021, the Bank of Lithuania addressed representatives of the fintech sector, emphasised the requirements related to money laundering and terrorist financing risk management, equity capital, internal control, protection of customer funds, investigation of customer complaints, information and communication technology and security risk management, notification of the changes of managers and shareholders, reporting, data reliability, timely submission of reports and outsourcing.


Recommendations on the publication of standard information

List of standard information that electronic money and payment institutions (fintech companies) should make public about their activities and risk management:

Rekomendacijos dėl EPĮ/MĮ veiklos reikalavimų ir valdymo 1. Information on activities
All information about the main licensed activities carried out by the electronic money or payment institution should be presented, listing all the services provided. Where electronic money or payment institutions carry out their activities through the engagement of partners, distributors and/or intermediaries, all persons involved in the activities should be listed and a link to www.lb.lt should be provided. Any information on other activities carried out by the electronic money or payment institution which are not related to the licensed activities should also be provided.
Rekomendacijos dėl EPĮ/MĮ veiklos reikalavimų ir valdymo 2. Correct contact details
Regularly updated contact details (phone numbers, email addresses and other channels for reporting potential breaches) should be provided on the websites of electronic money or payment institutions to enable consumers to actually contact the institution and express their concerns (in case of fraud, complaint handling, card blocking, and other general issues).
Rekomendacijos dėl EPĮ/MĮ veiklos reikalavimų ir valdymo 3. Language of the information
Information on the payment services provided, commission and other related fees should be provided in the national language and in another language understandable to consumers (publication of information in Lithuanian is particularly relevant where payment services are provided to Lithuanian residents and legal entities, unless there is a separate agreement on the provision of information in another understandable language).  
Rekomendacijos dėl EPĮ/MĮ veiklos reikalavimų ir valdymo 4. Information on the terms and conditions of payment services provided to consumers, including on the provision of such services
The payment service user must be properly informed of the terms and conditions of payment services provided to them, including on the provision of such services, such as pricing, lime limits, liability, etc. The information (publication of standard terms and conditions on websites, archive of current and previous versions of standard terms and conditions) must be presented in a clear and understandable manner, without misleading the customer, i.e. in such a way that the consumer can easily grasp its meaning, features of the service, and the associated risks.
Rekomendacijos dėl EPĮ/MĮ veiklos reikalavimų ir valdymo 5. Information on complaint handling
Clear and accurate information should be provided on which entity should be contacted and by which means in the event of questions or claims relating to improperly provided payment services, specifying which country’s law is applicable. This is particularly relevant where electronic money or payment institutions carry out their activities through the engagement of partners or intermediaries. The consumer should also be informed that electronic money or payment institutions are liable for the answer provided and the situation arising from possibly wrong resolution of an issue related to the provision of payment services and the resulting damages.
Rekomendacijos dėl EPĮ/MĮ veiklos reikalavimų ir valdymo ​6. Information on the safeguarding of customer funds
Information on the methods applied by electronic money or payment institutions for the safeguarding of customer funds as laid down in the Republic of Lithuania Law on Electronic Money and Electronic Money Institutions and the Republic of Lithuania Law on Payment Institutions, as well as information on which country’s insolvency law would apply in the event of insolvency of the credit institution should be provided in an easily legible and understandable form.
Rekomendacijos dėl EPĮ/MĮ veiklos reikalavimų ir valdymo 7. White paper on electronic money tokens (EMTs)
Before publicly offering EMTs, the EMT issuer (electronic money institution) must publish on its website the white paper on crypto-assets and marketing communications related to the offering or listing of EMTs. The marketing communications must be clearly identifiable, contain correct, clear and non-misleading information and clearly state that the EMT white paper has been published, providing the website address.
Rekomendacijos dėl EPĮ/MĮ veiklos reikalavimų ir valdymo 8. Prevention of money laundering and terrorist financing
Information that electronic money or payment institutions, acting in accordance with the Republic of Lithuania Law on the Prevention of Money Laundering and Terrorist Financing and provisions of other legislation, are obliged to implement measures for the prevention of money laundering and/or terrorist financing, such as due diligence on and verification of the customer and the beneficiary, determination of the purpose and the intended nature of the business relationship, ongoing monitoring of business relationships, etc., should be provided.

[[#ex]]

Deficiencies identified during inspections

The Bank of Lithuania imposed sanctions on financial market participants for breaches of requirements for safeguarding client funds and own funds requirements as well as non-compliance with internal audit requirements. Below are the fundamental deficiencies that we encourage all financial market participants to pay attention to.

[[#ex]]

Requirements for the safeguarding of customer funds and internal controls in this area

The inspection revealed that the electronic money institution (EMI) failed to safeguard a portion of its customers’ funds because, when performing reconciliation procedures and calculating the amount to be safeguarded, it did not treat certain liabilities to its customers as funds subject to mandatory safeguarding, i.e. the EMI included in the calculations of the amount to be safeguarded only data on balances of electronic money issued to customers and not redeemed in accounts, the EMI did not include in the calculations of the amount to be safeguarded: liabilities to customers recorded in technical accounts; liabilities to customers whose accounts have been closed; liabilities to customers whose amounts have been withheld due to inspections conducted for the purposes of AML/CFT; liabilities for amounts subject to clarification included in technical accounts (pending refunds and other withheld funds), and other amounts related to deferred payments and settlements with merchants. Article 25(1)(1) of the Republic of Lithuania Law on Electronic Money and Electronic Money Institutions (LEMEMI) stipulates that funds must be separated upon receipt thereof. Article 25(3) of the LEMEMI provides that funds must be safeguarded as from crediting them to the EMI or being otherwise made available to the EMI. Thus, in accordance with the provisions of the LEMEMI, customer funds must be safeguarded from the moment they are credited to the EMI’s account. Therefore, the EMI must include in the amount to be safeguarded not only the electronic money issued to customers and credited to their accounts (e-wallets), but also the liabilities to customers recorded in the internal accounting (technical, transit, and similar accounts) of the Institution.

The Institution transferred a portion of the customers’ funds, which were supposed to be safeguarded, from the safeguarding account to an overnight deposit account. Each morning, the deposit amount plus interest was paid back to the safeguarding account. The term of the deposits was 1 day (for weekends, a three-day deposit agreement was concluded). The Institution did not provide evidence that the overnight deposit accounts were subject to the terms and conditions for safeguarding accounts as detailed in paragraph 29 of the Description of Requirements for Electronic Money Institutions and Payment Institutions Regarding the Governance Arrangements and Safeguarding of Received Funds, approved by Resolution No. 247 of the Board of the Bank of Lithuania of 30 December 2009 on the approval of the description of requirements for electronic money institutions and payment institutions regarding the governance arrangements and safeguarding of received funds. Given that the deposit accounts were not subject to the terms and conditions for safeguarding accounts, it should be concluded that on the days when customer funds were transferred to deposit accounts, the Institution failed to safeguard them, i.e. violated the provisions of Article 25(1)(1) of the LEMEMI.

A higher not adequately contained risk of loss of safeguarding accounts due to their being held at a single credit institution (CI), i.e. a higher concentration risk, has been identified in the EMI. Even prior to the inspection, Lietuvos bankas drew the EMI’s attention to the fact that if this CI were to terminate its relationship with the EMI and the EMI were unable to open a safeguarding account elsewhere within the specified notice period, this may lead to non-compliance with the requirements of Article 25 of the Republic of Lithuania Law on Electronic Money and Electronic Money Institutions (LEMEMI). During the period of inspection, this issue was not discussed by the EMI, and the CI’s account did not meet the requirements for a safeguarding account; thus, the concentration risk at the Institution remained relevant.

The EMI did not assess the credit risk of the counterparty – two credit institutions (CIs). Although the EMI submitted a risk assessment for one of the CIs, it was prepared from the perspective of another EMI belonging to the same group of companies as the EMI supervised by Lietuvos bankas, and both CIs were unreasonably assessed as a single entity. The EMI violated the requirements set forth in paragraph 12 of the Description of Requirements for Electronic Money Institutions and Payment Institutions Regarding the Governance Arrangements and Safeguarding of Received Funds, approved by Resolution No. 247 of the Board of the Bank of Lithuania of 30 December 2009 on the approval of the description of requirements for electronic money institutions and payment institutions regarding the governance arrangements and safeguarding of received funds.

The institution held in the same account not only client funds but also funds of partners (i.e. persons distributing and/or redeeming electronic money issued by the institution), which were allocated to the future card payments by institution’s clients. As required by the institution, partners held funds for the purpose of reducing settlement risk. The funds in question did not yet have the characteristics of electronic money (they were not intended for payment transactions). This means that the funds of the institution’s clients were not separated from the funds of other persons who were not holders of electronic money, therefore the institution violated the Republic of Lithuania Law on Electronic Money and Electronic Money Institutions. Moreover, for some time, the institution had not regulated the process of safeguarding client funds at all, and subsequently internal documentation in this area had substantial deficiencies: not all provisions were aligned with the requirements for safeguarding client funds established by the legal acts of the Republic of Lithuania and/or corresponded to the specifics and organisational structure of the institution’s activities. According to the law, if one of the methods of safeguarding is chosen, client funds must be held in separate accounts with credit institutions.

The institution’s controls over the safeguarding of client funds were not separated from other group companies and were carried out on a group-wide basis. The outsourcing contract did not clearly and comprehensively identify the activities and tasks delegated to the group companies for the control of the requirements for safeguarding of client funds and the organisational chart of the institution did not clearly indicate that some of the staff members identified in the chart are employed by the group and perform functions under the outsourcing contract, i.e. it did not indicate that an operational function had been delegated and did not indicate the name of the company in which they are employed.

The institution had not segregated the funds of one of its customers, who is a registered intermediary of the institution, but received and held them in a special account for the company of the group to which the institution belongs. This infringement was identified by the institution and registered in the incident register, but it continued for more than six months and the institution did not take appropriate internal controls to resolve it in a timely manner, such as failing to notify in time the responsible person designated under the internal documents, who was obliged to inform the head of the institution. The incident was also not reported to the Management Board, which did not take the necessary and timely decisions to ensure that the customer funds were adequately safeguarded. It should be concluded that the decision to continue the infringement was taken by the institution’s controlling officers, i.e. the amount needed to protect the customer funds was not immediately transferred to the institution’s special account for customer funds. It was also determined that the institution had not adopted internal documents establishing the process for the safeguarding of funds of electronic money holders and/or payment service users, the procedures for the accounting of such funds and the procedures for the internal control of such funds.

The inspection revealed that the institution, together with another company of the group to which the institution belongs, which is an electronic money institution, provides payment services to its customers using payment card payment schemes (VISA/MasterCard). The institution provides/issues cards to its customers and the group company has the status of the principal member of the VISA/MasterCard scheme. As a participant in the VISA/MasterCard scheme, it is obliged to reserve funds in the bank accounts specified in the contracts with VISA/MasterCard. Under informal arrangements, the institution also formed part of the reserves in accordance with the proportions of transactions of customers who received services through the VISA/MasterCard systems. The cooperation between the institution and the group company was not formalised in law during the period under review, i.e. there were no cooperation agreements signed between the institution and the group company in this area, the principles of cooperation between the parties were not established, the responsibilities of the parties were not defined, the conditions for the provision of services to the institution’s customers, the grounds for the receipt and use of funds of the institution’s customers, the restrictions, controls and other aspects of the cooperation were not laid down. The institution transferred part of its customer funds to accounts belonging to another legal entity without ensuring their protection and without any legal basis for doing so. The institution indicated that the process of building up the institution’s share of the reserves was as follows: the institution’s customers transferred their own funds to the institution’s operational accounts, and the institution transferred these funds to the group company’s accounts for the purpose of building up the VISA/MasterCard system reserves. The inspection revealed that, in the case of one of the institution’s customers (and intermediary), a different practice was followed: the customer transferred funds to the institution’s customer funds account with a credit institution, the institution treated these funds as an amount to be safeguarded and, in turn, made periodic transfers directly to the group company’s account with the bank for the purpose of building up the reserves under the MasterCard system participant’s obligations. Thus, the institution did not use its own funds to cover the obligations of the other group company under the latter’s contractual relationship with MasterCard, but used its customer funds to be safeguarded. In the light of these circumstances, whereby the institution received funds from one of its customers, held them in another electronic money institution and failed to safeguard them properly, i.e. the institution failed to safeguard a significant part of the customer funds to be safeguarded, and also used part of the funds of its own customers to create reserves in the accounts of the other electronic money institution, without any legal basis for doing so, in order to secure the obligations of the other company in respect of its contractual relationship with the latter.

The inspection revealed that part of the client funds held in the deposit account was not safeguarded. While keeping the safeguarded client funds in a time deposit account opened with bank X, the institution failed to ensure the protection of the funds received by electronic money holders for the issued electronic money (i.e. safeguarded client funds) and transferred to the institution, as the contract with bank X excluded the conditions for the protection of the safeguarded client funds, and the deposit account No LT0000 does not comply with the requirements of subparagraph 28.1 and paragraph 29 of the Description of Requirements for Electronic Money Institutions and Payment Institutions Regarding the Governance Arrangements and Safeguarding of Received Funds, approved by Resolution No 247 of the Board of Lietuvos bankas of 30 December 2009 on the approval of the description of requirements for electronic money institutions and payment institutions regarding the governance arrangements and safeguarding of received funds, and therefore it cannot be considered as a safeguarded client funds account. Moreover, the institution’s time deposit agreements with credit union Y did not clearly disclose that they were intended specifically for the safeguarded client funds, and that these accounts contained the funds transferred to the institution for the issued electronic money and/or the provision of payment services. The institution thus did not sufficiently disclose who was to benefit from the conclusion of the time deposit agreements, nor did it explicitly or implicitly refer to the law under which such accounts were opened.

The institution invested part of its client funds in securities that did not comply with the legal requirements. By investing safeguarded client funds this way, the institution ignored the fact that the securities did not comply with the requirement of subparagraph 36.1 of the Description of Requirements for Electronic Money Institutions and Payment Institutions Regarding the Governance Arrangements and Safeguarding of Received Funds, approved by Resolution No 247 of the Board of Lietuvos bankas of 30 December 2009 on the approval of the description of requirements for electronic money institutions and payment institutions regarding the governance arrangements and safeguarding of received funds, according to which the institution may invest client funds in debt securities which, according to Chapter 2, Title II of Regulation (EU) No 575/2013, are subject to the 0%, 20% or 50% risk weights. Accordingly, by investing part of the safeguarded client funds in securities of company X with the 100% risk weight, the institution invested the safeguarded client funds in assets other than safe, liquid and low-risk assets. The inspection also revealed that the institution failed to fully safeguard the invested client funds, as the amount of client funds invested by the institution and the funds held in special accounts were not sufficient to provide adequate protection of the safeguarded client funds on all dates of the reporting period. As a result, the institution failed to safeguard sufficient funds, to monitor and secure an adequate liquidity buffer, to have in place a valuation procedure for such monitoring, to identify that the value of the client funds invested by the institution was less than the investment amount and to fully protect the safeguarded client funds.

The institution did not carry out a reconciliation procedure in respect of client funds, as it only reconciled the amounts of client funds held with the electronic money issued to them in an account opened with Lietuvos bankas, even though it also held client funds in other special accounts and safeguarded part of the client funds through investments.


Equity capital requirements and internal controls in this area

The Institution incorrectly calculated its own funds requirement using Method D, i.e. the EMI did not include in the calculations: liabilities to customers recorded in technical accounts, liabilities to customers whose accounts have been closed, liabilities to customers whose amounts have been withheld due to inspections conducted for the purposes of AML/CFT, liabilities for amounts subject to clarification included in technical accounts (pending refunds and other withheld funds), and other amounts related to deferred payments and settlements with merchants.

The institution incorrectly calculated the own funds requirement under Method D, i.e. in the sample of the previous six months the institution included the days of the current month as well as the days when it had not yet issued electronic money and calculated the average of the six-month averages for each month but not the average of the six-month averages for each day, resulting in non-compliance with the own funds requirements, in addition to failure to ensure adequate internal control in this area. Using Method D, electronic money institutions have to calculate the own funds requirement on the basis of the average outstanding electronic money, i.e. the average total amount of financial liabilities of an electronic money institution related to electronic money issued at the end of each day during the last six months, calculated on the first day of each month and applicable for that month.

The capital calculation process was not regulated in the institution and the efforts of the CFO in another country and the institution’s accounting partner in Lithuania were not sufficient to ensure proper internal control of the process, and the persons employed by the institution were not involved in the management of the process in any way. The inadequate internal control of the process resulted in the equity capital requirement being calculated in accordance with paragraph 13 of the Regulations for the Calculation of Own Funds of Electronic Money Institutions and Payment Institutions approved by Resolution No 03-83 of 24 May 2018 of the Board of the Bank of Lithuania On the Approval of the Regulations for the Calculation of Own Funds of Electronic Money Institutions and Payment Institutions and the Forms of Reports on the Calculation of Initial Capital and Own Funds of Electronic Money Institutions (Payment Institutions) and that the information related to the institution’s own funds used within the institution and provided to the supervisory authority in the respective reports is reliable and appropriate, and the activities of the institution comply with the requirements of the legislation.

The institution failed to ensure the required level of its own funds at all times. To calculate the average outstanding amounts of electronic money, the institution used a mathematical formula, which is taken into account in the calculation of the own funds requirement using method D, i.e. it calculated the average outstanding electronic money amount on the 30th day of each month in the preceding six months, without having regard to the fact that some months have 28, 29 or 31 days, which led to discrepancies as compared to the calculation of the average outstanding electronic money amount according to Article 2(12) of the Republic of Lithuania Law on Electronic Money and Electronic Money Institutions. The institution also used its own calculation method for own funds, which determined own funds by calculating the actual own funds and deducting other fixed assets from the balance sheet, but failed to observe the provisions of Articles 2(4) and 24 of the Republic of Lithuania Law on Electronic Money and Electronic Money Institutions. The inspection showed that the institution calculated the additional own funds requirement without any solid reason, i.e. it calculated the additional own funds requirement using method A for all reporting quarters, although the institution did not provide any payment services that were unrelated to the issue of electronic money. The institution wrongly used methods A and D in determining the total own funds requirement, thereby adjusting (increasing) the total own funds requirement.

The institution did not maintain an information register to record and exchange information and decisions concerning capital adequacy management. Further, the institution failed to ensure immediate entry of incidents in the incident register, which means that incidents were not recorded at the moment of their detection. In addition, incidents were not handled within significant time periods. Out of 22 cases, 20 incidents were resolved following the deadline indicated in the incident register (the difference between the date of resolution and the deadline was more than a year in 5 cases, between 6 months and 1 year (inclusive) in 9 cases, more than 3 months in 2 cases, and less than 3 months in only 4 cases), even though no action for incident prevention or control was indicated in the incident register with regard to these periods. Given the failure of the institution to establish procedures for recording information in this register, the incident register could not be used effectively to ensure the functioning of the internal control system.

The institution failed to ensure the compliance with the Regulations for the Calculation of Initial Capital and Own Funds of Electronic Money Institutions and Payment Institutions, approved by Resolution No 03-83 of the Board of Lietuvos bankas of 24 May 2018 on the approval of the regulations for the calculation of initial capital and own funds of electronic money institutions and payment institutions and the forms of the report on the calculation of initial capital and own funds of electronic money institutions (payment institutions), had no duly drawn up internal documents approved by the management body for ensuring the own funds requirements, did not approve procedures for internal control of the implementation of own funds requirements, which would specify the manner in which the periodic and regular internal control is carried out in this area, the information about the frequency of such control and the human resources allocated to this end. The institution’s internal control procedures were insufficient to ensure the timely implementation of effective capital adequacy management measures. The institution did not have in place an internal control system to ensure that financial and other information used internally and reported to the supervisory authority is reliable, appropriate and that the institution’s operations comply with the requirements of the legislation, resolutions of Lietuvos bankas and other regulations.

The institution had insufficient capital adequacy planning procedures to allow for the early identification and timely activation of capital adequacy management measures. Although the institution’s Procedure for Internal Governance and Internal Control stipulated that a capital stress-testing exercise should be carried out at least once a year, the institution did not establish the procedures for the stress-testing exercise or the procedure for assessing its results and did not identify persons in charge. During the inspection, the institution pointed out that no stress-testing exercise took place and that, given the institution’s profitability, there was no need to do so. It should be noted that the decision not to follow a stress-testing procedure was not approved by the management bodies and was only taken in view of the profitability performance.

The forecasting of financial data allowing to forecast and plan capital adequacy was not linked to the institution’s business strategy, since the institution operated without any such strategy (although a business strategy must include, inter alia, financial forecasts). The management body of the institution was therefore not in a position to regularly assess and discuss this strategy with the institution’s supervisory body. The assessment of the capital adequacy planning for 2022 showed that the planning of the financial results for the period 2021 to 2023 was limited to budget planning (only operational expenditure was planned), with no capital adequacy planning and forecasting.

The institution failed, without any solid reason, to follow the stress-testing procedures set out in its internal documents for capital adequacy, to plan capital adequacy for 2022, to ensure an adequate periodicity of forecasts for 2023, and, as a result, was unable to plan capital adequacy on a monthly basis. The management bodies of the institution did not take decisions to identify capital adequacy management measures for 2023 in accordance with the forecasts and did not submit them to the general meeting of shareholders for approval. The institution failed to identify forward-looking measures based on forecasts to ensure day-to-day compliance with the capital adequacy requirements.

The capital adequacy management measure adopted at the meeting of the management bodies of the institution, namely contacting the auditors with regard to the earliest possible submission of audit results for financial statements 2022 in order to allow the audited profits to be taken into Tier I equity capital, was not implemented in a timely manner. It should be noted that contacting the auditors cannot be considered as a sufficient and effective measure, as audit services are subject to the terms of the audit services agreement between the institution and the audit service provider, and the institution should have assessed the need and the procedures for obtaining the information from the audit firm, including the deadlines set in the agreement.

The institution’s capital adequacy management has not been part of the internal audit plans since the start of the institution’s operations. This led to the absence of any independent assessment and recommendations, and the institution was not in a position to improve the effectiveness of its internal control in this area in line with the internal audit observations.


Governance arrangements

By failing to clearly designate a supervisory body and to define its functions in its internal documents, the institution has failed to ensure clear and reliable governance arrangements.

By appointing a person performing control functions (risk management and/or compliance with the requirements for safeguarding of customer funds) and a member of the Management Board of the institution, the institution did not establish procedures for the management of conflicts of interest, did not manage the risks arising from conflicts of interest, did not ensure that the member of the Management Board would not be involved in the decision-making process related to the relevant control function he/she performs as stated in subparagraph 9.4 of the Description of Requirements for Electronic Money Institutions and Payment Institutions regarding the Governance Arrangements and Safeguarding of Received Funds approved by Resolution No 247 of 30 December 2009 of the Board of the Bank of Lithuania On Approval of the Description of Requirements for Electronic Money Institutions and Payment Institutions regarding the Governance Arrangements and Safeguarding of Received Funds.

The institution failed to properly separate the internal control of the functions of the board and the manager as the management bodies, on the one hand, and the supervisory and management functions, on the other hand. The institution did not establish and maintain a sound, effective and properly functioning internal control system. As the direct and/or indirect shareholders of the institution (both decision-makers of the supervisory body (general meeting of shareholders) of the institution) are also members of the management body (the board) of the institution (two out of three), i.e. there is an overlap between the supervisors and the supervised, the proper and effective exercise of the functions of the supervisory body is not possible due to the constant conflict of interest. In this regard, the supervisory function of the members of the board, who are also the decision-makers of the general meeting of shareholders, could not be effectively exercised by the general meeting of shareholders of the institution, and the institution did not distinguish between its supervisory and its managerial functions, which in turn had a negative impact on the institution’s internal control. While the decision-makers of the general meeting of shareholders of the institution constituted the majority (two out of three) in the board of the institution, any real management of conflict of interest was not possible.

The head of the institution was responsible for establishing the institution’s internal control system and the institution’s board was entrusted with the approval of the main documents establishing the institution’s internal control. The roles of these management bodies in putting in place the institution’s internal control system should not be regarded as separated or well defined. By delegating the establishment of the internal control system to its manager, the institution created a situation where the manager, being accountable to and controlled by the board of the institution, had to determine the place of the board in the institution’s internal control system, i.e. while laying down the key points concerning the internal control system in its internal documents, the institution did not properly consider the fact that it had not only a one-man management body, but also a collegiate body, neither did it take into account the relations and reporting duties between those two bodies.

The inspection found that the institution faces a constant conflict of interest, which is different from that which could be resolved by withdrawing, as the direct shareholders of the institution, who take the decisions of the institution’s supervisory body (the general meeting of shareholders), are also members of the institution’s management body (the board) (two out of three), which means that there is overlap between the supervisors and the supervised. As a result, the functions of the institution’s supervisory body could not be exercised in a proper and effective manner. The institution’s conflict of interest management procedure stipulates that separation of functions is an essential condition for avoiding any conflict of interest, but in practice the management structure of the institution is designed in such a way that it has not been possible to separate the functions of the supervisory bodies and the management bodies due to the influence and involvement of a single person at all levels of management bodies. It should also be noted that the above procedure did not provide for any measures to handle conflicts of interest that could be used in the governance model of the institution to ensure the effective functioning of the supervisory body and the collegiate management body.


Requirements for the implementation of the internal audit function

The institution did not have a formally appointed internal auditor eligible according to subparagraph 9.4 of the Description of Requirements for Electronic Money Institutions and Payment Institutions Regarding the Governance Arrangements and Safeguarding of Received Funds, approved by Resolution No 247 of the Board of Lietuvos bankas of 30 December 2009 on the approval of the description of requirements for electronic money institutions and payment institutions regarding the governance arrangements and safeguarding of received funds, and did not have an annual internal audit plan, taking into account the results of the risk assessment of business areas as laid down in paragraph 19 of this procedure, nor was it subject to internal audit.

The internal audit procedure governing the internal audit of the institution did not require that the internal auditor prepare and document a plan covering the objectives, scope, duration and resources required for the internal audit prior to conducting an internal audit of the relevant business area. The institution failed to ensure objectivity and impartiality of the internal audit function in accordance with the requirements of the Description of Requirements for Electronic Money Institutions and Payment Institutions Regarding the Governance Arrangements and Safeguarding of Received Funds, approved by Resolution No 247 of the Board of Lietuvos bankas of 30 December 2009 on the approval of the description of requirements for electronic money institutions and payment institutions regarding the governance arrangements and safeguarding of received funds, while the internal audit function in the area of compliance with the own funds requirements was not properly established and performed in accordance with the established procedures.

There was no indication of the institution’s internal audit function, i.e. an internal audit plan was not drawn up and approved by the general meeting of shareholders in the light of the risk analysis of the business areas and the annual internal audit report was not drafted and submitted to the general meeting of shareholders at the end of the year. Nor has any internal document defining the internal audit process and procedures been developed and approved by the institution.

The management model developed by the institution, where one person, as the largest shareholder, holds both the position of the chair of the board and that of the CEO of the institution, makes it impossible for the institution to implement the principle of independence of internal audit, which is considered to be among the key principles. The internal auditor is accountable to the institution’s supervisory body, but the appropriateness of the functions performed, decisions taken and processes established by both the institution’s board and the CEO (including the assessment of the decision-making, monitoring and oversight by the management bodies in this area, the supervision of the performance of the management bodies and their members, the monitoring of the implementation of the institution’s business strategy and objectives) is the subject of the assessment carried out by the internal auditor. Hence the internal auditor, while being accountable to the general meeting of shareholders and auditing the functions carried out by the board and the CEO, expresses an opinion on the adequacy of the functions carried out by the same persons who have powers to take decisions on the appointment and dismissal of the internal auditor, to whom the internal auditor is accountable and who approve the documents and plans produced by the internal auditor. Once the internal audit function was resumed, the institution failed to make sure that the independence and objectivity of the person performing the internal audit function was secured.


Failure to provide information to the Bank of Lithuania and/or submission of incorrect and inaccurate information

The information sent for supervisory purposes was inaccurate and was not provided in a timely manner, i.e. the institution submitted to the Bank of Lithuania the report on material changes in the requirements for the safeguarding of the funds of electronic money holders and/or payment service users (form EM008_12) concerning the agreement concluded with the credit institution X on 19 August 2022 to safeguard the funds of the institution’s clients only on 19 October 2022, thereby violating paragraph 141 of the Description of the Procedure for the Preparation of Financial and Activity Reports of Electronic Money and Payment Institutions for Supervisory Purposes and for the Submission of the Reports and Other Information to the Bank of Lithuania approved by Resolution No 03-259 of the Board of the Bank of Lithuania of 20 December 2018 on the approval of the description of the procedure for the preparation of financial and activity reports of electronic money and payment institutions for supervisory purposes and for the submission of the reports and other information to the Bank of Lithuania and on the approval of supervisory report forms. In addition, in the report on performance indicators and safeguarding of received funds (form EM008_05) for the reporting period of 30 September 2022, the institution unduly increased the amount of client funds to be safeguarded without deducting the funds paid by the institution during the last business day, thus providing incorrect information to the Bank of Lithuania and infringing subparagraph 21.1 of this Description.

The institution provided Lietuvos bankas with incorrect information about the average outstanding electronic money amount for the reporting periods when submitting the reports on the calculation of initial capital and own funds (forms EM007_2 and EM007_3) and the report on performance indicators and safeguarding of received funds (form EM008_05). The institution provided incorrect information about the calculated own funds requirement using method D in the reports on the calculation of initial capital and own funds (forms EM007_2 and EM007_3) and incorrect information about the total own funds requirement and the available own funds ratio in forms EM007_2 and EM007_3.

The institution failed to provide and/or improperly provided Lietuvos bankas with information about newly concluded agreements aimed at safeguarding the funds of holders of electronic money and/or users of payment services, i.e. the institution did not deliver to Lietuvos bankas a report (form EM008_12) with regard to the time deposit agreement concluded with credit union Y. The fact that the institution had concluded this agreement was unknown to Lietuvos bankas until the inspection.

The institution did not properly report on the wealth management services contract concluded with a brokerage firm. On 27 July 2021, when revising form EM008_12 submitted on 4 July 2021, the institution enclosed the wealth management services agreement concluded with the brokerage firm on 21 May 2021 and the supplementary agreement to this agreement. Accordingly, as regards form EM008_12, the institution failed to provide the information required in relation to the agreement concluded with the brokerage firm, as stipulated in paragraph 141 of the Description of the Procedure for the Preparation of Financial and Activity Reports of Electronic Money and Payment Institutions for Supervisory Purposes and for the Submission of the Reports and Other Information to the Bank of Lithuania, approved by Resolution of the Board of Lietuvos bankas of 20 December 2018 No 03-259 on the approval of the description of the procedure for the preparation of financial and activity reports of electronic money and payment institutions for supervisory purposes and for the submission of the reports and other information to Lietuvos bankas and on the approval of supervisory report forms. As a result, the institution’s report (form EM008_12) was rejected. The institution should have submitted the information on the wealth management services agreement concluded with the brokerage firm on 21 May 2021 in accordance with the procedures laid down by Lietuvos bankas before 28 May 2021, but failed to do so.

The inspection revealed that the institution failed to submit to Lietuvos bankas, within three days of the decision of the general meeting of shareholders of the financial institution on the approval of the set of annual financial statements, the set of annual financial statements and the decision on profit distribution approved by the said general meeting of shareholders of the financial institution.

[[#ex]]

Analyses and reports

[[#ex]]

Analysis of the implementation of internal control and governance arrangements reliability requirements

In carrying out the supervision of electronic money institutions (EMIs) and payment institutions (PIs), the Bank of Lithuania increasingly identifies deficiencies in the internal control, risk management and governance systems of the institutions during various inspections, documentary analyses and investigations. Therefore, as part of one of its strategic directions, to enhance the maturity and compliance culture of the fintech sector, it has analysed the implementation of the reliability requirements of the internal control and governance system by EMIs and PIs. The analysis assessed the state of play in the EMI and PI sector, looked at the related issues, identified potential risks and presented recommendations for further action.

The summary of the analysis provides succinct examples of good practices and practices to be improved by EMIs and PIs in the implementation of the reliability requirements of the internal control, risk management and governance system laid down in Resolution No 03-106 of the Board of the Bank of Lithuania of 23 July 2020 on the requirements for electronic money and payment institutions concerning internal control, risk management and protection of received funds. The sample of the analysis consists of documents and information provided by 6 institutions (5 EMIs and 1 PI).


Analysis of internal audit function adequacy

When carrying out the supervision of EMIs and PIs through various inspections, documentary analyses and investigations, the Bank of Lithuania observes cases where the internal audit function is implemented inadequately or not put in place at all. Therefore, as part of one of its strategic directions, to enhance the maturity and compliance culture of the fintech sector, it has analysed and assessed the compliance of selected EMIs and PIs with the requirements of the performance of the internal audit function.

The analysis involved an overview of the main deficiencies in the performance of the internal audit function in the EMI and PI sector, identification of potential risks associated with the inadequate performance of the function, overview of the related problems and recommendations for further action.

The summary of the analysis provides its results and examples of good practices and practices to be improved in the implementation of the requirements for internal audit set forth in Section 4 of the Description of the Requirements for Electronic Money Institutions and Payment Institutions Concerning Governance Systems and Protection of Received Funds approved by Resolution No 03-106 of the Board of the Bank of Lithuania of 23 July 2020 on the requirements for electronic money and payment institutions concerning governance systems and protection of received funds. The sample of the analysis consists of documents and information provided by 15 institutions (11 EMIs and 4 PIs).


Analysis of agreements concluded with credit institutions for custody of client funds

In carrying out the supervision of EMIs and payment institutions PIs and as part of one of its strategic directions, to enhance the maturity and compliance culture of the fintech sector, the Bank of Lithuania conducted a documentary analysis of the safekeeping agreements concluded by EMIs and PIs with credit institutions and assessed whether the provisions of the safekeeping agreements concluded by the EMIs and PIs with credit institutions ensure adequate and effective protection of customer funds in the course of the institutions’ operations or in the event of their insolvency, in accordance with Article 25 of the Republic of Lithuania Law on Electronic Money and Electronic Money Institutions and Article 17 of the Republic of Lithuania Law on Payment Institutions.

The summary of the analysis provides brief information on the implementation of the requirements for the protection of customer funds by the institutions as laid down by Resolution No 03-106 of the Board of the Bank of Lithuania of 23 July 2020 on the requirements for electronic money and payment institutions concerning internal control, risk management and protection of received funds. The sample of the analysis consists of documents and information provided by 42 institutions (24 EMIs and 18 PIs).

[[#ex]]

Last update: 19-03-2026