Cynthia IfebiPayments Governance
Frameworks

The PLG Framework

Two interconnected frameworks for managing payment product compliance across the full regulatory lifecycle.

Framework 01

Payment Lifecycle Governance (PLG)

The PLG Framework provides a structured methodology for mapping every payment scheme obligation to one of six control categories — enabling first-line compliance teams to build, maintain, and audit their obligation landscape systematically.

The framework's core proposition is that no payment obligation falls outside these six categories. Every regulatory requirement, every scheme rulebook clause, every customer-facing duty maps to exactly one of the six controls. This creates a complete, non-overlapping, and mutually exclusive taxonomy for payment compliance.

Read the White Paper →

The Six Control Categories

C1

Customer Journey

Controls governing how payment obligations manifest at the point of customer interaction — onboarding, initiation, authorisation, and dispute resolution.

C2

Failure Handling

Controls governing how the payment system responds when transactions fail, time out, or are rejected — including refund obligations, notification requirements, and remediation timelines.

C3

Monitoring

Controls governing continuous observation of payment flows for regulatory compliance — transaction monitoring, scheme reporting, and audit trail obligations.

C4

Regulatory

Controls that directly implement specific regulatory obligations — PSR, FCA requirements, SEPA regulation, and jurisdiction-specific payment law requirements.

C5

Scheme Control

Controls derived from payment scheme rulebook obligations — EPC rules, Bacs requirements, Faster Payments participation standards, and scheme-specific compliance requirements.

C6

Customer Feedback

Controls governing the capture, handling, and regulatory reporting of customer feedback, complaints, and dispute outcomes related to payment services.

No integration creates a seventh control.

Core axiom of the PLG Framework

Framework Architecture

The payment compliance lifecycle

01

Design

Scheme selection, regulatory scoping, obligation identification

02

Build

Control architecture, six-category mapping, gap analysis

03

Launch

Pre-launch compliance assurance, baseline capture

04

Operate

Continuous monitoring, drift detection, obligation updates

05

Review

Periodic reassessment, RDI scoring, gap remediation

Framework 02

Regulatory Drift & the RDI

Regulatory Drift describes the process by which a payment product that was compliant at launch progressively diverges from its regulatory baseline — not through deliberate non-compliance, but through the accumulation of scheme changes, regulatory updates, and product evolution that governance structures fail to absorb.

The Regulatory Drift Index (RDI) is a composite scoring mechanism that quantifies the degree of drift for a given payment product or scheme participation at a point in time, enabling prioritised remediation.

RDI Score Bands

0–20Minimal Drift
21–40Low Drift
41–60Moderate Drift
61–80High Drift
81–100Critical Drift

RDI Contributing Factors

01
Rulebook change frequencyHigh
02
Control coverage gapsHigh
03
Time since last reviewMedium
04
Obligation complexityMedium
05
Jurisdictional scopeLow

Key Insight

"Regulatory drift is not caused by negligence. It is caused by the absence of a governance structure capable of absorbing continuous change without manual intervention."

— PLG Framework, Publication 001