This guide sets out the current picture by sector, covering what is already live, what is coming, and what each type of firm actually needs to have to hand before sitting down to complete its submission.
For background on what the REQ is and why the Central Bank uses it, see our companion article: The Central Bank of Ireland's Risk Evaluation Questionnaire: What It Is and Why It Matters.
The general REQ remains the current format for credit and financial institutions that have not yet been migrated to a sector-specific version. This includes credit institutions, investment firms, insurance undertakings, fund service providers, and a range of other regulated entities. If your firm has been notified to submit a REQ and has not been specifically directed to a sector-specific version, the general format is what applies.
The general REQ is a structured spreadsheet submitted through the Central Bank Portal. Selection for submission and the specific deadline are communicated by the Central Bank through the Portal when the firm is notified.
It is worth noting that the Central Bank has signalled clearly, including in its 2026 Regulatory and Supervisory Outlook, that it intends to extend sector-specific REQs across further firm types over the coming years. The general format should therefore be understood as a transitional position for many sectors rather than the permanent state of affairs.
The general REQ is organised into seven sections, and while the questions are adapted to the firm's specific type, the overall structure is consistent.
Firm Detail covers basic information about the firm, including total assets, and where applicable, assets under management, assets under administration, and money throughput. All financial figures are reported in euro thousands, rounded to the nearest thousand, with no currency symbols.
Governance asks about board and senior management oversight of AML/CFT/FS, the firm's risk assessment process, its policies and procedures, its training programme, and its record-keeping arrangements. This section is testing whether AML/CFT governance is genuinely embedded at a senior level, not simply delegated downward and forgotten.
Risk Profile 1 covers the products and services the firm offers, the countries it operates in or serves customers from, and its distribution channels. Firms need to indicate clearly whether their customer base is restricted to Ireland, extends across the EU/EEA, or is broader still.
Risk Profile 2 asks about customer exposure, specifically the breakdown between simplified and standard due diligence measures applied to the customer base, alongside specific information on Politically Exposed Persons and financial sanctions screening.
RBA Monitoring stands for risk-based approach monitoring, and covers the firm's ongoing monitoring policies and procedures, its assurance testing, and any third-party reliance or outsourcing arrangements relevant to AML/CFT, including outsourcing to a parent company or group entity.
SA (Suspicious Activity) covers the firm's processes for investigating and escalating suspicious activity, including the number of Suspicious Transaction Reports raised. Note that STR figures relate specifically to the previous calendar year, running 1 January to 31 December, a different reference period from most of the rest of the REQ.
MI (Management Information) asks how the firm reports AML/CFT/FS management information to its board or senior management, including the frequency and format of that reporting.
Finally, a Statement of Compliance closes the return, requiring sign-off from a person duly authorised by the board, ideally the individual with responsibility for AML/CFT/FS within the firm.
The first sector-specific REQ has been introduced for Payment Institutions (PIs) and Electronic Money Institutions (EMIs), with guidance published in June 2025. This is a substantially different exercise from the general REQ, more granular, more technically demanding, and submitted in a different format entirely.
The reference date for the first submission is 31 December 2024. The submission deadline is 13 February 2026.
The Central Bank has been unambiguous that this is a hard deadline and that no extensions will be granted. Given the complexity of the submission and the technical format involved, firms working toward this deadline need to have started their preparation well in advance.
If an institution is part of a group with multiple separately regulated entities under the Central Bank's supervision, each individual entity must submit its own REQ. A single consolidated group return is not acceptable.
This is one of the most significant practical differences from the general REQ. The PIEMI sector-specific REQ must be submitted as an XML file, built according to a specific XSD schema that the Central Bank has published alongside its guidance. The Portal does also make an Excel version of the questions available, but this is provided solely to help firms understand what information is being asked for. The Central Bank will only accept XML format submissions.
This means that completing the PIEMI REQ is, in substance, both a compliance exercise and a technical data project. Firms need either genuine XML and schema expertise in-house or close coordination between their compliance and IT functions, or a specialist external partner, to produce a valid submission file.
The sector-specific REQ for Payment and Electronic Money Institutions is considerably more detailed than the general version, with questions organised into fourteen main areas.
General information covers the firm's legal structure, its business model, its international presence across countries, and the Statement of Compliance.
Inherent risk is broken down in significant detail across the firm's customer segments and the specific sectors those customers operate in. It covers whether customers are onboarded remotely, the level of anonymity involved in the firm's products, whether the firm offers merchant acquiring, money remittance, e-money, virtual IBAN accounts, currency exchange, crypto-asset services, lending, correspondent relationships, deposits and withdrawals, or crowdfunding. The firm also provides information on intermediaries and distribution channels, funding sources, and geographic reach.
Mitigation and control is where the REQ goes into depth on the firm's AML/CFT framework. This section covers the firm's business-wide risk assessment, its policies and procedures, its customer onboarding and offboarding processes, customer due diligence approach, transaction monitoring, how alerts and transaction rejections are handled, suspicious transaction reporting processes, sanctions screening, outsourcing arrangements, training and education, compliance and assurance testing, audit, internal controls and reporting systems, governance, and compliance with Fund Transfers Regulation requirements.
Beyond these headline areas, the REQ then includes a series of detailed, product-specific tables. These cover the firm's physical presence, the residence and establishment of its customers, beneficial ownership data, digital accounts, prepaid cards and vouchers, merchant acquiring activity, correspondent relationships, money remittance, the geography of funds flows, and transaction monitoring in granular detail.
One important practical point: all questions in the PIEMI REQ are mandatory, even where a particular product or service is not relevant to the firm's business model. Where a question genuinely does not apply, the guidance specifies how each field type should be populated to indicate non-applicability, integer fields as zero, string fields as N/A, country codes as 00, and so on. Leaving fields blank or omitting sections entirely will cause the submission to fail validation.
All monetary values in the PIEMI REQ are reported in euro unit values, unlike the general REQ which uses euro thousands.
The Central Bank has confirmed in its 2026 Regulatory and Supervisory Outlook that trading firms and Crypto-Asset Service Providers (CASPs) will be required to complete enhanced REQs in the second half of 2026. These will capture both quantitative and qualitative risk information on money laundering and terrorist financing controls, in a format that goes beyond the current general REQ.
Full guidance for these sector-specific submissions has not yet been published at the time of writing. Firms in these sectors should monitor the Central Bank's AML/CFT section of its website and should begin reviewing the adequacy of their existing AML/CFT data and documentation now, given that the enhanced REQ will request detailed information across many of the same substantive areas as the PIEMI version.
Firm typeFormatKey datePayment Institutions & E-Money InstitutionsSector-specific, XMLReference date 31 December 2024; submission deadline 13 February 2026 (no extensions)Credit and financial institutions on the general REQGeneral, Excel via PortalNotified individually through the Central Bank PortalTrading firms & Crypto-Asset Service ProvidersEnhanced REQ (guidance pending)Expected second half of 2026
Regardless of which REQ format applies, certain things need to be in place before a firm can complete a credible submission.
A current, board-approved risk assessment. The REQ asks specifically whether this exists, when it was last approved, and what risk ratings have been applied to the firm's inherent risks. If the firm's risk assessment is significantly out of date or has never been formally approved at board level, this will be visible in the submission.
Up-to-date policies and procedures. These need to cover customer due diligence, suspicious transaction reporting, transaction monitoring, financial sanctions screening, record keeping, and training. The REQ does not simply ask whether policies exist, it asks whether they address the specific elements required, and whether they are sufficiently detailed for operational use.
Accurate data on the customer book. Both the general and PIEMI REQs ask for specific figures on the number and type of customers, the split between simplified and standard due diligence, PEP numbers, and similar data. This information needs to come from reliable systems, not from estimates.
STR data for the prior calendar year. Information on Suspicious Transaction Report activity relates specifically to the calendar year 1 January to 31 December, not the broader twelve-month period used for most of the REQ. Having this data to hand in a readily accessible format avoids delays.
Evidence that training is happening. The REQ asks about training format, frequency, and completion records. Firms need to be able to describe their training programme and confirm that records are maintained.
A clear picture of any outsourcing or third-party reliance. If any AML/CFT functions are outsourced to a parent company, group entity, or external third party, this needs to be documented and disclosed.
For PIEMI firms specifically: having IT resource available to build and validate the XML submission file needs to be built into the project plan from the outset, not treated as a final step after the compliance questions have been answered.
The firms that find REQ completion most straightforward are those that treat it as a structured review of their AML/CFT position rather than a last-minute documentation scramble. The questions the Central Bank asks are, for the most part, questions that well-governed firms should be able to answer from their normal management information, because the information being requested is information that a properly run AML/CFT programme should be producing as a matter of course.
The challenge for firms where AML/CFT governance is less mature is that the REQ process itself can surface gaps that take time to address. Finding those gaps six months before the deadline is manageable. Finding them in the final weeks before submission is considerably more stressful, and the Central Bank has been consistent in its message that deadlines will not be extended.
For firms that want to build a well-organised, evidence-based approach to compliance monitoring that makes regulatory submissions like the REQ significantly less demanding, our compliance monitoring platform supports exactly this kind of structured, year-round compliance management.
For a full explanation of what the REQ is, its legal basis, and how the Central Bank uses it within its broader supervisory approach, see our companion article.
Read more: The Central Bank of Ireland's Risk Evaluation Questionnaire: What It Is and Why It Matters