
Regulatory Reporting and AML Central Contact Point Services
We prepare and file the recurring reports that EMIs, payment institutions, CASPs and Canadian MSBs owe to supervisors and FIUs.Where a host country requires a local AML central contact point, we help you set it up and run it.
- Local compliance teams in 4 EU hubs
- EU and Canadian reporting regimes
- 500+ licensing projects
Free, no-obligation assessmentWe reply within 1 business day
- 6 months
- PSD2 fraud reporting cycle
- 4 hours
- DORA notice after classification
- 5 working days
- FIU requests under the AMLR
- 10+ establishments
- Can trigger a contact point
- EU + Canada
- Regimes covered
Overview
Recurring reports, filed on time and on record

Regulated fintechs owe a steady stream of reports: supervisory returns to the national authority, fraud statistics under PSD2, suspicious transaction reports and answers to the FIU, DORA incident reports and, in Canada, FINTRAC reports. MAXCORP maps what you owe, sets up the calendar and files with you, from the first report onwards.

A reporting calendar of every obligation, deadline and owner, reviewed when the rules change
Supervisory returns prepared from your data, reconciled and submitted, with queries answered
STR drafting, quality review and answers to FIU requests within the deadlines that apply
DORA incident reports drafted on the 4-hour, 72-hour and one-month clock when it matters
Setup and operation of an AML central contact point where a host country requires one
A parallel run on your first reporting cycle before we take over business‑as‑usual filing
Supervisors track late and inaccurate reports, and the deadlines are short: some FIU reports are due within two working days, DORA notices within hours. The AMLR also brings new EU-wide rules from 10 July 2027. We map every obligation into one calendar, run the first cycle with your team, then file on schedule and review the calendar every year as the rules change. We keep your reports on time, consistent and on record.
Reports
What we report for you
Obligations depend on your licence, your home country and where you operate. These are the main regimes we cover; the first step is a map of what you actually owe.
Supervisory reporting
Periodic returns to your national competent authority, such as financial statements, own funds and capital, and safeguarding information, on the calendar your supervisor sets.
What we do
- Map every return, its frequency and its deadline
- Collect and reconcile the data with your finance team
- Prepare and submit the returns and answer the authority's questions
PSD2 fraud reporting
Payment service providers report fraud data every six months under the EBA Guidelines on fraud reporting (EBA/GL/2018/05). Exempted small PIs and EMIs report once a year, split into two six-month periods. Each national authority sets its own submission deadline.
What we do
- Set up the data extraction and the report template
- Check the data for consistency before submission
- File on your authority's deadline
AML reporting to the FIU
Suspicious transaction reports and threshold reports go to the national FIU. In Estonia, suspicions must be reported without delay and no later than two working days, through the FIU's RABIS web portal; in Latvia, immediately, through goAML. From 10 July 2027 the AMLR requires answers to FIU requests within 5 working days, unless the FIU sets another deadline.
What we do
- Draft and quality-review STRs with a clear rationale
- Set up portal access and reporting procedures
- Prepare answers to FIU information requests
Your MLRO keeps the decision to file. For case work at volume, see AML team outsourcing.
DORA incident reporting
For a major ICT incident: the initial notification within 4 hours of classifying it as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours, and a final report within one month (Delegated Regulation (EU) 2025/301).
What we do
- Support with classifying incidents against the DORA criteria
- Draft the initial, intermediate and final reports
- Keep a playbook and register ready for the clock
To build the wider framework, see DORA compliance.
MiCA reporting for CASPs
CASPs that professionally arrange or execute transactions must report reasonable suspicions of market abuse to their authority without delay (MiCA Art 92). They must also keep the information held by their supervisor up to date.
What we do
- Set up the suspicious order and transaction reporting process
- Draft reports for your review
- Track notifications owed to your supervisor
FINTRAC reporting (Canada)
Canadian MSBs file STRs as soon as practicable, large cash transaction reports within 15 calendar days, electronic funds transfer reports within 5 working days and large virtual currency transaction reports within 5 working days, applying the 24-hour rule for amounts of CAD 10,000 or more.
What we do
- Set up the reporting processes and the 24‑hour rule aggregation
- Prepare and file the reports
- Keep the records for FINTRAC examinations
For a Compliance Officer registered with FINTRAC, see Canada.
Contact point
AML central contact point
An EMI or payment institution that operates in another EU country through agents or distributors (not a branch) may be required by that host country to appoint a central contact point.
What it is
A person or function in the host country that makes sure your agents and distributors there comply with local AML rules, and that deals with the local authority and FIU (AMLD Art 45(9), Delegated Regulation (EU) 2018/1108).
When it can be required
- 10 or more establishments in the host country, or
- More than €3 million a year of e-money distributed and redeemed or payment transactions executed there, or
- The information needed to check this is not provided, or the host country requires it on risk grounds
What it does
- Oversees the AML compliance of your agents and distributors
- Represents you before the host authority and FIU
- Answers requests and facilitates on‑site inspections
- Where the host country requires it, files STRs and scrutinises transactions
How we help
We assess whether a contact point is required in each host country, set up the function, procedures and agent oversight, train your agents and support the day-to-day contact with the authority and FIU.
Process
From reporting map to business as usual
We map your obligations, set up the data and templates, run the first reporting cycle in parallel with your team, then take over filing with a monthly status report.
Indicative timeline
3 to 6 weeks
Weeks 1 to 2
Obligations map
Every report, deadline and owner in one calendar.
Weeks 2 to 6
Setup
Data sources, templates and portal access in place.
First cycle
Parallel run
The first reports prepared and reviewed together.
Ongoing
Business as usual
Filing on the calendar, with a monthly status report.
Yearly
Annual review
The calendar updated for rule changes such as the AMLR.
Durations are indicative; the setup depends on the number of reports and how quickly data and access are provided.
FAQ
Regulatory reporting: frequently asked questions
How often do PSPs report fraud data?
Every six months under the EBA Guidelines on fraud reporting (EBA/GL/2018/05). Exempted small PIs and EMIs report once a year, split into two six-month periods. Each national authority sets its own submission deadline.
What are the DORA incident deadlines?
For a major ICT incident: the initial notification within 4 hours of classifying it as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report within one month of the latest intermediate report.
What is an AML central contact point?
A person or function in a host EU country that makes sure the agents and distributors of an EMI or payment institution comply with local AML rules there, and that deals with the local authority and FIU (Delegated Regulation (EU) 2018/1108).
When can a host country require one?
When you have 10 or more establishments there, or more than €3 million a year in volume, or you do not provide the information needed to check this, or on risk grounds.
Does the contact point rule cover branches?
No. It covers establishments in forms other than a branch, such as agents and distributors.
How fast must STRs be filed?
It depends on the country: in Estonia without delay and no later than two working days, in Latvia immediately. From 10 July 2027 the AMLR sets an EU-wide standard of reporting promptly.
How fast must we answer the FIU?
From 10 July 2027, the AMLR requires answers to FIU information requests within 5 working days, unless the FIU sets a shorter or longer deadline.
Which reporting systems do FIUs use?
It varies by country: the Latvian FIU uses goAML, while the Estonian FIU uses its own RABIS web portal. MAXCORP sets up access and procedures for the systems you need.
What does a Canadian MSB report?
STRs as soon as practicable, large cash transaction reports within 15 calendar days, electronic funds transfer reports within 5 working days and large virtual currency transaction reports within 5 working days, with the 24‑hour rule applied.
Do CASPs report market abuse?
Yes. Under MiCA Art 92, CASPs that professionally arrange or execute transactions must report reasonable suspicions of market abuse to their authority without delay.
Contact
Plan your regulatory reporting
Tell us your licence, home country and where you operate. We reply with a first view of your reporting obligations and how we can take them on.
