Card Scheme and Processing Separation: The IFR Independence Rules

For payment card schemes within Article 7 of Regulation (EU) 2015/751, Commission Delegated Regulation (EU) 2018/72, in force since 7 February 2018, specifies the card scheme processing separation requirements: the accounting, organisational and decision-making independence applying between schemes and processing entities. Article 7 does not apply to three-party payment card schemes unless the scheme is treated as a four-party payment card scheme under Article 1(5) of the IFR. The relevant competent authorities may request the information and arrangements that the IFR and the delegated regulation require to be made available on request.

The direct subjects of the RTS are payment card schemes and processing entities within that Article 7 scope. Acquirers and other market participants are affected by the broader Article 7 framework according to the functions they perform.

The obligation has been live for years, which is precisely why it drifts out of view. The delegated regulation prescribes no quarterly supervisory return or submission portal. The evidence sits in your own documentation, and the moment of truth arrives when a supervisor requests it.

Related reading: our guide to PSD2 reporting requirements.

The dates that fixed the separation regime

Card scheme separation is a long-standing obligation, and the file stays open. The calendar behind it is short, and worth having in front of you because it explains why the rulebook and the binding standard carry different dates.

  • 8 June 2015: the IFR entered into force.
  • 9 June 2016: the IFR became applicable, including the independence obligation in Article 7(1)(a). From this date card schemes and processing entities had to ensure their independence, whether or not the technical standards were finalised.
  • 27 July 2016: the EBA published its final draft Regulatory Technical Standards, EBA/RTS/2016/05, and submitted them to the European Commission.
  • 4 October 2017: the Commission adopted the standards as Commission Delegated Regulation (EU) 2018/72.
  • 18 January 2018: the delegated regulation was published in the Official Journal (OJ L 13).
  • 7 February 2018: the RTS entered into force, on the twentieth day after publication (Article 18).

The duty to be independent bit first, under the IFR itself. The detailed tests came later, in the delegated regulation. A scheme that treated the RTS entry-into-force date as the start of its obligation was already almost two years behind the primary rule.

What Article 7 requires: card scheme processing separation in three parts

Article 7(1)(a) of the IFR requires payment card schemes and processing entities to be independent in terms of accounting, organisation and decision-making processes. Those three words carry the whole regime. Everything in Commission Delegated Regulation (EU) 2018/72 is an elaboration of one of them.

It helps to be precise about the two roles. A payment card scheme is the body that owns the rules, practices and standards for executing card-based payment transactions, the commercial and contractual framework of the card. Processing, defined in Article 2(27) of the IFR, is the performance of payment transaction processing services in terms of the actions required to handle a payment instruction between the acquirer and the issuer. Separately, Article 7(3) requires schemes to allow the authorisation and clearing messages for a single card-based payment transaction to be separated and processed by different processing entities.

Article 7 goes wider than independence alone. The IFR also requires separate presentation of scheme fees and processing fees, with the two activities kept financially independent of each other (Article 7(1)(b)). It requires schemes to allow the authorisation and clearing messages of a single transaction to be separated and handled by different processing entities (Article 7(3)), prohibits territorial discrimination in processing rules (Article 7(4)), and requires technical interoperability between processing entities in the Union, barring scheme rules that restrict it (Article 7(5)). The RTS implements the independence limb specifically. Article 7(6) is the provision that handed the EBA the mandate to write it.

One structural point bears stating at the outset: the RTS is neutral about corporate form. A scheme and its processing entity can sit inside the same legal person and the same group, provided the separation tests are met. Where they are not two separate legal entities, Article 7 of the delegated regulation requires them to be organised as two separate internal business units. The obligation is behavioural and structural; independence here does not require spinning off a subsidiary.

Accounting independence: a separated P&L, not a separated balance sheet

The accounting chapter, Articles 3 to 6, is the part a reporting function will recognise most quickly, because it produces something close to a report. Payment card schemes and participating processing entities must have accounting processes that produce financial information on separated profit and loss accounts, with explanatory notes (Article 3). That information has to follow the accounting framework the entity already uses for its financial statements, so this is a separation exercise layered on top of existing accounts rather than a parallel ledger.

Article 4 is where the real work is. Expenses and revenues that are directly attributable to processing go to the processing entity, and those directly attributable to the scheme go to the scheme. Costs and revenues that are not directly attributable are allocated using activity-based costing, meaning indirect items are split according to actual consumption by each side. Only where an item cannot be allocated on an activity-based basis may an alternative method be used, and that alternative has to be written down in a supporting note that states the basis for the allocation and the rationale for that basis. The methodology is auditable by design.

Article 5 requires specific explanatory notes for transfers of financial resources between the scheme and the processing entity for the provision of services or the use of shared services, with those notes specifying the prices and fees for the services. Where the payment card scheme and processing entity belong to the same legal entity or group, Article 5(2) requires those notes to provide evidence that the prices and fees for the services do not differ from prices and fees for the same or, in their absence, comparable services charged between payment card schemes and processing entities that do not belong to the same legal entity or group.

Article 6 requires the financial information produced under Articles 3 to 5 to be reviewed by an independent and certified auditor. The review report must ensure a trustworthy and fair view, consistency and comparability with the applicable accounting frameworks, and consistency with previous years’ allocation policies. Where that consistency is lacking, the report must provide both an explanation of why the allocation policy changed and a restatement of previous years’ figures. The financial information is submitted to the auditor annually and made fully available to competent authorities on request together with the auditor’s review.

The final delegated regulation requires financial information on separated profit and loss accounts with explanatory notes. The December 2015 consultation draft had proposed annual audited information covering separated balance sheets as well, but the EBA deleted that element from the adopted regulation.

Organisation: two units, separate desks, independent people

The organisation chapter, Articles 7 to 15, requires functional and personnel separation. Where the scheme and processor are not established as two separate legal entities, they must be organised as two separate internal business units (Article 7). Where they share premises, they must occupy separate workspaces with restricted and controlled access (Article 8). Senior management must be different and act autonomously, and Article 9 also prevents senior management of either side from taking work for the other side for at least one year after leaving the entity for which they worked. Article 10 requires different staff, subject to its express qualifications for shared services and specified scheme-rule design work.

Article 10 contains two qualifications to staff separation. Under Article 10(2), staff of payment card schemes and processing entities may perform tasks related to shared services under Article 12. Under Article 10(3), staff of a processing entity may perform tasks related to designing the scheme’s single set of rules, practices, standards and implementation guidelines, provided those tasks may be performed by other processing entities on a non-discriminatory basis and the design involves a representative sample of all processing entities participating in the scheme.

Article 11 requires processing entities to adopt remuneration policies that do not incentivise staff to give a payment card scheme preferential treatment or privileged information unavailable to competitors, and requires their remuneration to reflect the processing entity’s performance rather than being directly or indirectly linked to the scheme’s performance. The corresponding rule applies to scheme staff in relation to processing entities. The final delegated regulation contains no express safe harbour for general all-employee share plans or benefit arrangements; any such arrangement must therefore be assessed against the Article 11 requirements themselves.

Article 15 requires payment card schemes and processing entities belonging to the same legal entity or group to define and publicly disclose on their website a code of conduct setting out how their respective staff act to ensure compliance. The code must include effective enforcement mechanisms and, in particular, rules preventing the sharing of sensitive information. It is subject to review by competent authorities. That publication requirement is one of the few outward-facing signals of compliance, and its absence is a straightforward thing for a supervisor to observe.

The information wall: shared services without sensitive leakage

Articles 12 and 13 expressly allow shared services and even a shared information management system. The line the regulation draws sits around sensitive information; cooperation is permitted within the boundaries the regulation specifies.

Shared services are permitted where their use does not disclose sensitive information between the scheme and the processor, and where the two describe the list of shared services and the financial conditions for them in a single document, available to competent authorities on request (Article 12). A shared information management system must separately identify scheme and processing-entity staff through authentication and restrict each user to information that the user is entitled to access. Article 13 expressly prevents each side’s staff from accessing the other side’s sensitive information, while Article 14 separately prohibits sharing sensitive information that gives either side a competitive advantage where it is not shared with other competitors.

Article 14 does not provide a closed list of sensitive information. Instead, it prohibits payment card schemes and processing entities from sharing information of a sensitive nature that gives either the scheme or the processing entity a competitive advantage where that information is not shared with other competitors. Article 13 separately restricts access to each side’s sensitive information within a shared information management system.

Decision-making: management bodies and separate operating plans

The final substantive chapter, Articles 16 and 17, governs how decisions get made. Article 16 requires the composition of the management bodies to mitigate conflicts of interest, including through clear and objective criteria governing when the same person may hold directorships simultaneously in the scheme and processing entity. Those criteria must be public and are subject to competent-authority review. Where the scheme and processing entity belong to the same legal entity or group, their management bodies must approve and periodically review conflict-of-interest policies. Where the same person may hold directorships in both management bodies, Article 16(3) requires a separate management body for scheme-related decisions and a separate management body for processing-related decisions (each with the exemption of shared services decisions under Article 12), together with independent reporting lines from senior management. The organisational arrangements must be available to competent authorities on request, and the management body retains overall responsibility for compliance.

Article 17 adds a planning discipline that is easy to satisfy on paper and easy to fail in practice. The scheme and the processor must have separate annual operating plans setting their own budgets, including capital and operating expenditure and any delegated authority to commit that spend, each submitted to the relevant management body for approval. Article 17 requires the scheme and processing entity to have separate annual operating plans determining their respective budgets, including capital and operating expenditure and possible authority delegations to engage that expenditure, with each plan submitted to the relevant management body for approval.

There is no template and no portal: how this is actually tested

RegReportingDesk usually deals with returns that have a form, a frequency and a submission channel. This regime has none of those, and mistaking it for a filing misrepresents what compliance here requires. Commission Delegated Regulation (EU) 2018/72 creates no periodic template, no XBRL taxonomy and no reporting deadline. Several documentary requirements are expressly subject to competent-authority access on request, including the financial information and auditor review under Article 6(3), remuneration policies under Article 11(3), the shared-services document under Article 12(2), the Article 16(3) organisational arrangements under Article 16(4), and the annual operating plans under Article 17(2).

The delegated regulation creates no periodic supervisory return or prescribed filing template, but it does contain recurring and continuing requirements. The financial information under Articles 3 to 5 is submitted to the independent auditor annually under Article 6, and Article 17 requires separate annual operating plans. Where the scheme and processing entity belong to the same legal entity or group, Article 16(2) also requires management bodies to approve and periodically review conflict-of-interest policies. Other provisions impose public-disclosure or on-request documentation requirements, including the Article 15 code of conduct and the records expressly required to be made available to competent authorities.

The practical consequence is that compliance gaps in this framework do not announce themselves. A COREP return that is late announces itself. A separation file that was last refreshed in 2019, with an allocation methodology that no longer matches how the group actually runs its shared platform, looks fine until a supervisor asks for it. The maintenance task is to keep the evidence current for the day it is requested.

Where acquirers fit: buying processing on a level playing field

The RTS attaches obligations to the functions of payment card scheme and processing entity rather than excluding an entity merely because it is also an acquirer. An acquirer is not subject to the RTS solely by virtue of its acquiring role, but an entity that also qualifies as a processing entity must assess the RTS in that processing capacity. Article 2(28) of the IFR defines a processing entity as any natural or legal person providing payment transaction processing services.

The regime affects acquirers through the broader Article 7 framework. Article 7(3) requires schemes to allow the possibility that authorisation and clearing messages for a single transaction are separated and processed by different processing entities, while Article 7(5) requires technical interoperability between processing entities within the Union and prevents scheme business rules from restricting it. Recital 33 explains that separation of scheme and infrastructure should allow processors to compete for schemes’ customers. Those provisions support competitive processor choice, but do not themselves state an unrestricted unilateral routing right for every acquirer.

There is a scope consideration on the other side. An acquirer is not brought within the RTS merely because another entity in its group is a processing entity; the RTS applies to the acquirer itself only to the extent that it also performs a function that makes it a payment card scheme or processing entity within Article 7 scope. The trigger is the processing function’s relationship with a scheme, which can exist quite independently of the acquiring licence. The deciding factor is what the processing function does and whom it serves, whatever the entity is called.

Frequently Asked Questions

Does the separation regime apply to three-party card schemes?

Legal form does not determine how the independence requirements are implemented, but the IFR’s scheme classification does determine Article 7 scope. Article 1(4) provides that Article 7 does not apply to three-party payment card schemes. Under Article 1(5), however, a three-party scheme is treated as a four-party scheme where it licenses other payment service providers for issuing or acquiring, or issues card-based payment instruments with a co-branding partner or through an agent. The RTS applies to payment card schemes and processing entities within that Article 7 scope.

Who has to sign off the separated financial information?

Article 6 requires an independent and certified auditor to review the financial information produced under Articles 3 to 5. The report must ensure a trustworthy and fair view, consistency and comparability with the applicable accounting frameworks, and consistency with previous years’ allocation policies; where the allocation policy has changed, it must include an explanation of the change and a restatement of previous years’ figures. The information goes to the auditor annually, and both the information and the review are made available to competent authorities on request.

What actually counts as sensitive information?

The RTS does not give a closed list. Article 14 defines sensitive information functionally: information whose non-availability to competitors would give either the scheme or the processing entity a competitive advantage. In practice the test is whether disclosing the item to the affiliated side, while withholding it from rival competitors, would tilt the market. If yes, the shared systems and shared services have to be designed so it cannot cross.

Can the same people work on both the scheme and the processing side?

Senior management and staff must be different between the two sides, subject to the express qualifications in Articles 9 and 10. Article 10(2) permits staff of either side to perform tasks related to shared services under Article 12. Article 10(3) permits staff of a processing entity to work on the design of the scheme’s single set of rules, practices, standards and implementation guidelines where those tasks may be performed by other processing entities on a non-discriminatory basis and the design involves a representative sample of all processing entities participating in the scheme.

Do group-wide share plans breach the remuneration rule?

Article 11 does not contain a specific exemption or safe harbour for group-wide share plans or benefit arrangements. A processing entity’s remuneration must reflect the processing entity’s performance and must not be directly or indirectly linked to the performance of the relevant payment card scheme; the corresponding rule applies to scheme staff in relation to processing entities. Any group-wide arrangement therefore has to be tested against those requirements.

Is there a reporting deadline or a return to submit?

The delegated regulation creates no prescribed periodic supervisory return, reporting template or submission portal. It does, however, contain recurring requirements: Articles 3 to 5 financial information is submitted to the independent auditor annually under Article 6; Article 17 requires separate annual operating plans; and Article 16(2) requires periodic review of conflict-of-interest policies where the scheme and processing entity belong to the same legal entity or group. Several other records must be available to competent authorities on request or disclosed publicly.

Does PSD3 or the Payment Services Regulation change this?

The separation regime lives in the IFR and Commission Delegated Regulation (EU) 2018/72, which remain the operative rules. The broader overhaul of the payments framework is a separate track; teams tracking those proposals can follow our coverage of PSD3 for payment institutions and e-money, but nothing there displaces the card-scheme independence duty as it stands.

Key Takeaways

  • The separation regime is Article 7(1)(a) of the IFR, Regulation (EU) 2015/751, specified by Commission Delegated Regulation (EU) 2018/72, in force since 7 February 2018.
  • Within the scope of Article 7 of the IFR, the RTS binds payment card schemes and processing entities. Acquiring status by itself does not create the RTS obligations, but an acquirer that also acts as a processing entity must assess the requirements in that processing capacity.
  • Accounting test: separated profit and loss accounts with explanatory notes, activity-based allocation of indirect items where possible, Article 5 transfer-of-resources notes including the same/comparable-service price-and-fee benchmark where the scheme and processor belong to the same legal entity or group, and an annual independent-auditor review including restatement of previous years’ figures where the allocation policy changed (Articles 3 to 6).
  • The RTS requires a separated profit and loss account, not a separated balance sheet. The balance-sheet element was in the December 2015 consultation draft but is absent from the final regime.
  • Organisation test: two internal business units where the activities are not established as two separate legal entities, separate restricted-access workspaces where co-located, and different autonomous senior management and staff. Article 9 also imposes a minimum one-year restriction on senior management moving to the other side, while Article 10(2) permits shared-service tasks and Article 10(3) permits specified scheme-rule design tasks by processing-entity staff subject to its conditions.
  • Articles 13 and 14 restrict access to and sharing of sensitive information as specified there, including the Article 14 condition concerning information that is not shared with other competitors; where the payment card scheme and processing entity belong to the same legal entity or group, Article 15 requires them to publish on their website a code of conduct with effective enforcement mechanisms.
  • Decision-making test: management-body composition that mitigates conflicts through public, objective criteria for simultaneous directorships; periodic conflict-of-interest policy review where the entities belong to the same legal entity or group; the Article 16(3) governance arrangements where simultaneous directorships may be held; and separate annual operating plans under Article 17.
  • Commission Delegated Regulation (EU) 2018/72 prescribes annual submission of the Articles 3 to 5 financial information to the independent auditor, separate annual operating plans, and periodic review of conflict-of-interest policies in the circumstances set out in Article 16(2), rather than a periodic supervisory filing. Other specified documents must be disclosed publicly or made available to competent authorities on request.

Sources and References

  • Regulation (EU) 2015/751 of the European Parliament and of the Council of 29 April 2015 on interchange fees for card-based payment transactions (the IFR), Articles 1(4), 1(5), 2(27), 2(28) and 7: https://eur-lex.europa.eu/eli/reg/2015/751/oj
  • Commission Delegated Regulation (EU) 2018/72 of 4 October 2017 supplementing Regulation (EU) 2015/751 with regard to regulatory technical standards on independence requirements for payment card schemes and processing entities (OJ L 13, 18.1.2018, p. 1): https://eur-lex.europa.eu/eli/reg_del/2018/72/oj
  • EBA, Final draft Regulatory Technical Standards on separation of payment card schemes and processing entities under Article 7(6) of Regulation (EU) 2015/751 (EBA/RTS/2016/05, 27 July 2016): EBA final draft RTS (PDF)
  • EBA activity page, Regulatory Technical Standards on payment card schemes and processing entities under the IFR: EBA single rulebook page

Keeping the two businesses provably apart

A scheme that keeps its separated profit and loss account current, its allocation methodology honest, its shared-systems access controls tight and its two operating plans genuinely distinct has already done the substantive work. The remaining task is ensuring that, when a competent authority exercises its IFR enforcement powers or requests documentation under the applicable provisions of Commission Delegated Regulation (EU) 2018/72, the file it receives describes the business as it actually runs today.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • EBA 2025 Benchmarking of Internal Approaches: What the IRB and Market Risk Findings Mean for Prudential Reporting Teams

    Updated July 2026In this guideWhat the EBA IRB benchmarking exercise actually isWhat CRD VI changed about the assessmentThe headline credit risk findings, in reporting termsThe IRB roadmap is still being closed outHow benchmarking actually feeds supervisionMarket risk: IMA and ASA in the same packageReconciling benchmarking to your COREP returnsWhat is coming under CRR3 and the…

  • AMLA Direct Supervision: Which Obliged Entities the CSSF Will Identify

    Updated July 2026In this guideWhat AMLA direct supervision actually meansThe two-part test: cross-border footprint plus risk profileWhich entity types the methodology coversHow the 2026 identification process worksThe 40-entity cap and the one-per-Member-State ruleThe timeline and the three-year lock-inThe exceptional route, and what Luxembourg firms should prepareFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesWhat a Luxembourg compliance…

  • ESMA Joins the Global CCP Fire Drill: What the Default Simulation Means for Clearing Members and EMIR Reporting Teams

    Updated July 2026In this guideWhat the CCP fire drill is, and what it is notHow the simulation maps to EMIR default managementWhat EMIR 3 changed for the receiving clearing memberThe operational gaps the 2025 simulation flaggedWhat this changes for reporting teams, and what it does notFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesReading the drill before…

  • ECB Legal Framework Volume III: The SSM Internal Rulebook, Mapped

    In August 2026 the European Central Bank issued a new edition of Volume III of its Legal Framework for Banking Supervision, the digital compilation that gathers the internal-organisation rules of the Single Supervisory Mechanism. Volume III is the part supervised banks meet when they interact with the ECB itself: it holds the rules of procedure…

  • CSSF Remuneration Reporting: Who the Guide Really Covers

    Updated July 2026In this guideWhat the CSSF updated on 3 June 2026The legal basis: CRD Article 75 and IFD Article 34Who actually files CSSF remuneration reporting, and who does notThe high earners collection and the EUR 1 million thresholdWhere UCITS managers and AIFMs report remuneration insteadWhat to check before this cycle’s submissionFrequently Asked QuestionsRelated ArticlesKey…

  • MMF Weekly Liquid Assets: What the CSSF Consultation Means for Luxembourg Managers

    Updated July 2026In this guideWhat the CSSF published on 8 June 2026The statutory MMF weekly liquid assets minimums the guidance leaves untouchedThe notification trigger most managers will need to wire inWhat the resilience levels do not meanHow this connects to stress testing under Article 28What Luxembourg managers should review before 3 August 2026Frequently Asked QuestionsRelated…