The fourteen modules

Every jurisdiction is assessed against the same fourteen payments-integrity domains each cycle, so a module can be read across all 155 jurisdictions or a jurisdiction across all fourteen modules.

W1a Licensing, Authorisation & Market Access

Who is permitted to operate, and on what terms — PI/EMI and bank-PSP authorisation, passporting and outsourcing.

W1b Conduct, Safeguarding & Financial Promotions

How firms must treat customers and protect their funds — Consumer Duty, safeguarding and the promotions regime.

W2 Stablecoins & Digital Money

The emerging regimes for stablecoins, tokenised money and CBDCs.

W3 Operational Resilience & Critical Infrastructure

The rules requiring firms and their critical suppliers to keep payments running — DORA, FCA/PRA resilience and the critical-third-party regime.

W4 Scheme & Network Compliance

The card-scheme and network rulebooks — Visa, Mastercard, PCI-DSS, SCA/3DS.

W5 Payment Corridor Dynamics

The risk attached to specific cross-border routes — sanctions exposure, regulatory divergence and illicit-finance concentration.

W6 Industry Structure & Commercial Dynamics

M&A, market entry and competitive shifts across the sector.

W7 Legal & Litigation

Enforcement actions, structurally significant litigation and asset recovery.

W8 Merchant Acquiring & Risk

The risk carried by acquirers and merchants — category risk, chargebacks and acquirer stress.

W9 Product Innovation & Market Development

Open banking, PSD3, embedded finance and BNPL.

W10 Consumer Protection & APP Fraud

Reimbursement, de-banking rights and consumer redress.

W11 AML/CFT & Financial Crime

Anti-money-laundering, sanctions and the travel rule (sourced from sister monitor Sentinel.gi).

W12 Correspondent Banking, Settlement & Access

The plumbing beneath everything — USD/GBP clearing, CHIPS/FedWire/CHAPS, settlement finality and ISO 20022.

W13 Commercial Intelligence & Fintech

Discrete commercial events across the sector — M&A deals, investment rounds, market entry and exit.

The spine is closed at fourteen and versioned: see modules.json for the machine-readable inventory, or the methodology for how each domain is scoped.