Compliance

European Payments Initiative (EPI) develops and operates the Wero payment solution including the Wero payment scheme and its regulated payment services. This page aim to provide an overview of the principal compliance, regulatory, governance and security frameworks applicable to EPI Company SE and, where relevant, to the operation of the Wero ecosystem.

EPI is committed to delivering secure, innovative and trusted European payment solutions while maintaining the highest standards of regulatory compliance, operational resilience, information security and corporate governance. As a regulated payment institution and operator of the Wero payment solution, compliance is embedded across EPI's governance framework and day-to-day operations.

The following overview explains how the principal regulatory frameworks and industry standards apply to EPI's different services and roles.

Prudential Supervision

EPI Company SE is incorporated in Belgium, authorised and supervised by the National Bank of Belgium as a Payment Initiation Service Provider (PISP) and an Account Information Service Provider (AISP). EPI continuously reviews its governance, risk management and compliance framework to respond to evolving regulatory requirements, supervisory expectations and industry best practices.

Other Regulatory Frameworks Applicable to EPI
The compliance frameworks described on this page primarily relate to the payment services provided through the Wero app. In addition, EPI performs a separate role as operator of the Wero payment scheme. In that capacity, EPI is subject to specific scheme oversight requirements, including the Eurosystem's PISA framework. As operator of the Wero payment scheme, EPI maintains governance, oversight and operational controls designed to ensure the safety, efficiency and resilience of its payment ecosystem.

Payment Instruments, Schemes and Arrangements (PISA)
The Eurosystem's PISA framework establishes oversight expectations for payment instruments, payment schemes and payment arrangements. In its capacity as operator of the Wero payment scheme, EPI is subject to oversight under the PISA framework and maintains governance, risk management and operational arrangements designed to support the safety, efficiency and resilience of the scheme.

For PISA, EPI Company SE is subject to oversight by the Eurosystem - JOT (Joint Oversight Team) composed from representatives of the following National Central Banks:

  • Belgium: National Bank of Belgium (NBB)
  • France: Banque de France
  • Germany: Deutsche Bundesbank (BuBa)
  • Luxemburg: Commission de surveillance du secteur financier (CSSF)
  • The Netherlands: the Dutch National Bank (DNB), as lead overseer
  • Europe: European Central Bank (ECB)

Payment Services

WERO standalone app
EPI's payment services and wallet capabilities are delivered within a regulated environment designed to provide secure, seamless and user-centric payment experiences.

The following regulatory requirements apply to the payment services provided through the Wero Standalone App.

Payment Services Directive (PSD2)
PSD2 establishes the regulatory framework governing payment initiation and account information services within the European Economic Area. EPI Company SE is authorised and supervised by the National Bank of Belgium as a PISP and AISP and maintains governance, security and operational controls designed to support compliance with applicable PSD2 requirements.

AML/CFT
As a regulated payment institution, EPI has implemented an anti-money laundering and counter-terrorist financing (AML/CFT) framework in accordance with applicable Belgian legislation and European legal and regulatory requirements. The framework includes governance, risk assessment, customer due diligence, monitoring and reporting measures proportionate to EPI's activities and regulatory obligations.

The EPI AML/CFT Policy summarizes the obligations applicable to EPI.

Customer complaints
EPI is committed to delivering high levels of customer service and has established a dedicated complaints handling process designed to ensure that customer concerns are addressed fairly, transparently and efficiently.

Customer complaints can be submitted through the chatbot function available on EPI’s website.

PCI DSS
Where applicable, EPI operates controls aligned with the requirements of the Payment Card Industry Data Security Standard (PCI DSS) and incorporates these controls into its broader information security framework. These controls include robust technical safeguards, continuous monitoring and secure handling of payment data, supporting the protection and resilience of EPI's payment services.

Data Privacy, Information Security, Operational Resilience & Ethics

Secure technology, resilient operations and effective cybersecurity underpin EPI's payment services. EPI applies internationally recognized standards and regulatory requirements to strengthen the resilience of its technology environment.

The following apply for both standalone app and mobile banking app users.

General Data Protection Regulation (GDPR)
EPI is committed to protecting personal data and respecting the privacy rights of individuals. Personal data is processed in accordance with the GDPR through appropriate technical and organisational measures designed to ensure confidentiality, integrity and availability. Privacy considerations are integrated into governance processes, information security and risk management practices.

https://epicompany.eu/privacy-policy/

Further information regarding EPI's processing of personal data and the exercise of data subject rights is available in EPI's Privacy Notice.

Digital Operational Resilience Act (DORA)
EPI recognises operational resilience as a cornerstone of trusted payment services. To support compliance with the Digital Operational Resilience Act (DORA), EPI maintains a comprehensive operational resilience framework covering ICT risk management, cyber resilience, incident management, business continuity, disaster recovery and third-party risk management. 
These measures support the continuity of critical services while strengthening preparedness for operational disruptions across the digital payment ecosystem.

Information security: ISO/IEC 27001
EPI has established an Information Security Management System (ISMS) aligned with the requirements of ISO/IEC 27001:2022, the internationally recognised standard for information security management. The ISMS provides a structured and risk-based framework for identifying, assessing and managing information security risks, while supporting the continual improvement of security controls across the organisation.

EPI is currently progressing the renewal of its ISO/IEC 27001 certification, reinforcing its commitment to protecting information assets, strengthening cyber resilience and maintaining effective information security governance.

ISO/IEC 27001 Certificate

NIST Cybersecurity Framework
EPI aligns its cybersecurity governance and risk management practices with the NIST Cybersecurity Framework. The framework complements EPI's Information Security Management System by supporting a structured and risk-based approach to identifying, protecting, detecting, responding to and recovering from cybersecurity threats. Together with recognised international standards, it supports the continual enhancement of EPI's cybersecurity posture and operational resilience.

Ethics
EPI promotes a culture of integrity, accountability and ethical conduct. Employees and directors are expected to comply with the Ethics Policy, which sets out the principles governing professional conduct, conflicts of interest, confidentiality and compliance with applicable laws and regulations. EPI encourages employees and stakeholders to raise concerns regarding misconduct breaches of applicable law or violations of policies through our whistleblowing channel.

Whistleblowing channel

Corporate Governance

Effective governance underpins EPI's compliance framework.

The EPI Board of Directors establishes the Company's strategic direction and risk appetite while overseeing governance, regulatory compliance, internal controls, operational resilience and enterprise risk management.

Dedicated Advisory Committees support the Board by providing focused oversight and recommendations across their respective areas of responsibility, namely:

Governance & Remuneration Committee
The Governance & Remuneration Committee is responsible for ensuring the proper composition and functioning of the Board, including compliance with applicable laws, the Articles of Association, and conflict-of-interest procedures. It advises on candidates for the CEO position and reviews candidates nominated by Shareholders for Board roles, taking into account expertise, gender balance, nationality mix, and seniority. The Committee recommends Independent Director candidates and provides guidance on remuneration policies for Executive Management and Independent Directors, as well as permissible expense claims.

Finance Committee
The Finance Committee oversees the Company’s financial reporting processes, monitors financial compliance, and follows the execution of the budget. It makes recommendations to the Board regarding the appointment or removal of the statutory auditor and the approval of the auditor’s remuneration. The Committee may initiate special investigations within its remit, supported by internal or external parties, and ensures that financial information and controls are reliable and aligned with regulatory expectations.

Risk, Compliance & Audit Committee
The Risk, Compliance & Audit Committee supports the Board in overseeing enterprise-wide risk management, including AML/CFT risk, operational risk, compliance risk, and internal control effectiveness. The Committee reviews permanent and periodic controls, validates the annual audit plan, oversees the internal audit function, and follows the implementation of remediation actions from internal and external audits. It monitors regulatory compliance not covered by other committees and ensures the effectiveness of the Company’s risk management framework. In accordance with the Governance Charter, the Committee is chaired by an Independent Director.

Senior Management
The Board is supported by EPI's executive management team, led by Martina Weimert, Chief Executive Officer, and Carmen Carnero, Chief Strategy Officer, who oversee the Company's day-to-day operations, strategic initiatives and implementation of the Board's decisions.