Resources · Ireland
Ireland · Consumer Protection Code

How to manage errors and incidents

How to log, triage, remediate and evidence errors that affect customers — and when an incident also has to go to the Central Bank.

1 Obligations under the regulations

From 24 March 2026, error handling for Irish regulated firms sits in Chapter 11 of the Consumer Protection Code 2025 (Central Bank (Supervision and Enforcement) Act 2013 (Section 48) (Consumer Protection) Regulations 2025, S.I. No. 81 of 2025).

CPC 2025 Regulations 96–100

You must have written procedures for errors that affect consumers (Reg. 96), resolve them speedily and no later than six months after discovery (Reg. 97), refund overpayments or losses with appropriate interest (Reg. 98), keep an up-to-date error log with prescribed fields (Reg. 99), and keep a record of the steps you took to resolve each error (Reg. 100).

Regulation 96 also requires you to identify cause and consumer impact, find all potentially affected consumers, escalate significant errors to the board, analyse patterns at least every six months, and report aggregated volumes to compliance, risk and the board.

Separate clocks can run at the same time:

  • DORA (Regulation (EU) 2022/2554) — major ICT-related incidents must be reported to the Central Bank (initial notification within four hours of classifying the incident as major, and no later than 24 hours after awareness; intermediate report within 72 hours; final report within one month).
  • GDPR Article 33 — personal-data breaches to the Data Protection Commission without undue delay and, where feasible, within 72 hours.

2 What do I need to do

Run one intake for “something went wrong”, then classify. An IT outage, a pricing error and a data leak may share a register but they do not share a regulator clock.

1. Capture the event immediately

Who found it, when, which products and customers, and the first description of what happened. Do not wait for a perfect root cause. Regzact can assist: record the event on the Errors register as soon as it is raised.

2. Triage: consumer error, ICT incident, data breach — or all three

Ask: does it affect consumers (CPC)? Is it a major ICT incident (DORA)? Is personal data compromised (GDPR)? Escalate significant consumer errors to the board as Regulation 96 requires. Regzact can assist: categorise the entry, generate tasks, and alert the right owners.

3. Contain, identify all affected customers, and remediate

Fix the control failure, prevent recurrence, refund with interest, and notify current and former customers where the error hit cost or value (Reg. 97). Aim well inside six months. Regzact can assist: track actions, send customer emails, and chase outstanding tasks with reminders.

4. Find the root cause and report the pattern

Regulation 96 expects regular analysis of occurrence rates and causes, at least every six months, plus aggregated reporting to the board. Regzact can assist: record root causes, run management reporting and risk analysis, and export the log.

3 What records do I need to keep

Regulation 99 tells you exactly what the error log must contain. Build your register to that list so you are not reconstructing it from email at year end.

  • Details of each error, how and when it was discovered, and the period it ran
  • Number of consumers affected and overall monetary amounts
  • Status — fully resolved, partially resolved, or unresolved — and the date fully resolved
  • Number of consumers refunded and the total amount refunded
  • Any charitable donations of refund amounts that could not be repaid
  • Other remediation steps, including where customers were dissatisfied or could not be contacted (Reg. 100)
  • Board and compliance reports of volumes, patterns and significant escalations
  • DORA and GDPR notifications where those regimes also applied

4 Using AI to streamline the process

The CPC already expects classification, root-cause thinking and pattern analysis. AI can take the first pass:

  • Suggest a category (pricing, documentation, system, advice, claims) from the free-text description
  • Draft a root-cause note and a list of controls that may have failed
  • Cluster similar errors so the six-monthly pattern review is not a spreadsheet exercise
  • Flag events that may also be DORA or GDPR notifiable, for a human to confirm

Do not let a model decide whether an error is “significant” for the board, or whether DORA thresholds are met. Use it to draft; keep the judgement with compliance and the business owner.

5 How Regzact can help

The Errors register is built for this process: record the incident, triage it, work it through, and report on quality and trends.

  • Structured capture of operational events, including consumer errors and incidents
  • Task generation, email, reminders and alerts so owners do not drop a six-month clock
  • Root-cause fields, evidence attachments and a full audit trail
  • Management reporting and risk analysis across the register

If the incident involves partners, staff or sanctions matches, those profiles already sit in Regzact. Regzact can assist with each step of this process.

Open the Registers solution · Book a demo

This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.

Keep going

Other how-tos for Ireland compliance teams.

Start Your Trial Today.

Join insurers, MGAs, and brokers across the UK and Ireland who have made compliance a strategic advantage. Book a personalised demo and see Regzact working with your own network.

No credit card required All regulatory frameworks included Set up in under a day

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.