Expert Perspectives | LIA Webinar, 11 March 2026 Presented by Barry Rojack BL, BCL(Int), Head of Regulatory Compliance and Risk (Banking), Uniquely
Barry Rojack BL, BCL(Int.) is Head of Regulatory Compliance and Risk (Banking) at Uniquely, with over 25 years' experience in governance, risk, and compliance across Irish, UK, and EU financial services. A qualified Barrister-at-Law and former regulator at the Central Bank of Ireland, Barry has extensive practical expertise in conduct risk, banking regulation, and consumer protection frameworks.
Key Takeaways
- The revised Consumer Protection Code (CPC) 2025 came into effect on 24 March 2026, restructured into two sets of Regulations and four guidance documents — augmenting the previous binary compliance model with increased outcome-focused standards.
- Several provisions have proven operationally challenging to implement, including Trusted Contact Person (TCP) disclosures and engagement, sustainability assessments in the KYC process, changes in error reporting thresholds, a new requirement to notify covered parties (but not policyholders) of lapse of health insurance.
- The Central Bank of Ireland (CBI) has signalled a busy supervisory agenda for 2026–2027, with multiple sector-specific reviews planned across banking, insurance, retail intermediaries, and payments, many of which cross over new requirements in the CPC.
- Post-implementation, firms must now shift focus from meeting the deadline to embedding changes effectively and preparing for regulatory scrutiny.
- Credit unions are on a separate timeline, with the CPC expected to apply to all their services and products from Q3 2027.
How Consumer Protection Regulation Evolved in Ireland
From Caveat Emptor to Consumer-Centred Outcomes
Ireland's approach to consumer protection in financial services has undergone significant transformation over the past five decades. What began in the 1970s and 1980s as a patchwork of disclosure-focused statutes — including the Family Home Protection Act and early thematic directions — has progressively evolved into a comprehensive regulatory framework built around consumer outcomes.

An important legislative milestone running alongside this timeline was the Central Bank Reform Act 2010, which introduced Section 17A standards and strengthened the Central Bank's powers to set and enforce conduct of business rules for regulated firms.
Running in parallel throughout this period has been the transposition of European product- and service-specific Directives and Regulations, including MiFID I and II, IDD, PRIIPs, MICAR, and others — each adding a further layer of requirements for regulated firms.
This layered regulatory evolution reflects a broader shift: from telling consumers what they are buying, to requiring firms to actively demonstrate that what they sell and how the sell it genuinely helps consumers make informed decisions in their best interest.
Structure of the Revised Consumer Protection Code
Two Regulations, Four Guidance Documents
The newly revised CPC represents a significant structural departure from its predecessors.

Rather than a single monolithic code, it is now built around two sets of Regulations supported by four dedicated guidance documents:
- Consumer Protection Regulations
- Standards for Business Regulations
- Guidance A: Securing Customers' Interests
- Guidance B: Protecting Customers in Vulnerable Situations
- Guidance C: General CPC Guidance & FAQs
- Guidance D: Criteria and Expectations on Appropriate and Sustainable Alternative Repayment Arrangements
This structure is intentional. The CBI has deliberately moved away from a purely prescriptive, tick-box model towards a framework that distinguishes between hard binary requirements on one hand and high-level, outcome-oriented standards with supporting guidance on the other.
Where binary fixed requirements leave no room for interpretation, the outcome-focused provisions give regulated firms the flexibility to design solutions that reflect their own governance structures, business models, and customer demographics, provided they can demonstrate those solutions genuinely secure customers' interests.
This is a meaningful shift from the existing consumer protections in the Consumer Protection Code 2012. Compliance is clearly more athat just following a checklist.
Key Changes: What Has Actually Changed in Practice
The Headlines and the Detail Beneath Them
The revised CPC introduces changes across several major thematic areas. At a headline level, some of these include:
- Securing Customers' Interests — Firms need to look out for customers throughout the life of a product, not just when selling it.
- Protecting Customers in Vulnerable Circumstances — Firms must identify customers who need extra support. A new Trusted Contact Person (TCP) system lets customers nominate someone to be contacted in certain cirucmstances.
- Distinguishing regulated and unregulated products / services – if you offer both regulated and unrelated products and services, these must be provided and advertised distinctly such that customers fully understand what products and services are regulated (and are thereby supported by the protections associated with such regulation, such as access to the Financial Services and Pensions Ombudsman for complaints, or deposit / investment protection) and those that are not.
- Digitalisation — If you offer products and services through a digital platform, you need to ensure effective customer engagement and positive customer outcomes are built into the design, delivery and ongoing continuous review of the way the delivery channel operates, including consideration of customers who may not be as digitally literate as others or who may have limited accessibility. Additional planning, disclsoure and governance requirements also apply when introducing new digital channels and / or replace / winding down physical channels with digital channels.
- Informing Effectively — Risks and benefits must be shown with equal prominence in advertising: customers should understand what they are being offered.
- Sustainability Preferences — Before offering a relevant product, firms must ask customers about their sustainability preferences and consider the answer in order to determine (and disclose where it is the case) if the product or service being offered meets the customer’s preferences.
- Insurance Renewals — Auto-renewal is no longer permitted for certain types of general insurance, and new / increased mandatory disclosures are required for other insurance products prior to them renewing (e.g. an "Important Information" box with certain key information is now required by the Code for health insurance renewals)
- Error & Complaint Management — regulated entities are required to set their own materiality threshold for reporting of significant errors to the board, and changes have been introduced around the timing and scope of errors that need to reported to the Central Bank. Changes in respect of the logging and management of complaints have also been introduced.
Four Immediate Priorities Firms Should Be Acting On
Post-Deadline, the Focus Shifts to Evidence and Outcomes
With the 24 March 2026 deadline now passed, the immediate question for regulated firms is not simply whether they met it — but what happens next. Barry Rojack highlighted four priorities that firms should have been. In many cases they are still working through.

- Identifying Areas of Non-Compliance — Where a firm could not meet the deadline in full, it needs a clear log of what was outstanding, why, and what the remediation plan is.
- Managing Pipeline Customers — Customers who were mid-process at the point of implementation need to be handled carefully.
- Proactive Communication with Existing Customers — Firms should be assessing which customer cohorts are affected by new entitlements or information arising from the revised Code and communicating proactively.
- Customers in Arrears or Legal Proceedings — Firms need a clear, documented position on how existing cases are being managed under the new framework.
These are not hypothetical future considerations — they are live questions that compliance teams, product governance committees, and senior management need to have answered and documented now.
What to Expect from the Regulator
A Busy Supervisory Agenda for 2026 and 2027
The CBI has a full programme of thematic reviews planned across 2026 and into 2027. The topics span most regulated sectors — if your firm is not on this list this year, it likely will be next.
The areas under review include how firms handle errors and complaints, how they treat vulnerable customers, and whether they are informing customers effectively under the revised Code. The regulator is also looking closely at digital product sales, commission arrangements, fraud controls, and mortgage lending practices.
For insurance firms specifically, reviews are planned on claims handling, product oversight, automatic renewal, and value for money. Retail intermediaries can expect scrutiny on unregulated activities and commission structures.
What Regulated Entities Should Be Doing Now
Embedding, Assuring, and Preparing for Scrutiny
The following actions should be on every compliance team's agenda:
- Internal effectiveness reviews: Assurance and audit activity to verify that changes have been successfully embedded.
- Testing customer outcomes: If unexpected findings emerge, relevant product governance committees need to be involved in determining the response
- Engaging proactively with the CBI: Firms subject to planned review activity over the next two years should be preparing now.
- Preparing for Dear CEO letters: Firms should have a clear process for reviewing findings, assessing applicability to their own operations, and making improvements or reporting as required.
Final Thoughts
The revised Consumer Protection Code 2025 represents a genuine step-change in the expectations placed on Irish financial services firms. The shift towards outcome-focused regulation means that compliance is no longer a destination.
Regulated firms that are building flexible, outcome-focused compliance frameworks now will be better positioned to absorb further changes as they come.
Frequently Asked Questions
Consumer Protection Code (CPC) is the Central Bank of Ireland's primary framework governing how regulated firms must treat consumers.
Binary requirements are fixed, prescriptive obligations that must be met in a specific way. Outcome-focused requirements, by contrast, set a high-level standard that firms must achieve but allow latitude in how they design their solution, provided they can demonstrate it genuinely secures customer interests (and can evidence how relevant decisions were reached in this regard).
A Trusted Contact Person is an individual nominated by a customer — particularly one who may be in vulnerable circumstances — whom a firm can contact in certain situations.
The CBI is currently engaged in a consultation process with credit unions and their members. Subject to that process, the CPC is expected to apply to all services and products of credit unions from Q3 2027 (at present it only applies to a limited extent here they are acting as insurance intermediaries).
The CBI has signalled a wide range of thematic reviews across 2026 and into 2027, covering areas including root cause analysis of errors, vulnerable customer treatment, informing customers effectively, fraud controls, commission arrangements, and product oversight. Firms should be reviewing their own operations now in anticipation.
A proactive, managed approach to addressing gaps is significantly important. Firms should also consider whether any gap creates immediate consumer risk that needs to be addressed as a priority, and whether it needs to be escalated internally or to the regulator.