Authorisation and Licensing Cover - Bratby Law Payments Regulation

Payment Institution Authorisation and Licensing

Short answer: a firm providing payment services in the United Kingdom as a regular occupation or business needs FCA authorisation as an authorised payment institution or registration as a small payment institution under the Payment Services Regulations 2017 (PSRs 2017), unless it is another permitted provider or an exclusion applies. Small payment institution registration is available only while average monthly payment transactions over the preceding 12 months do not exceed EUR 3,000,000 and the firm provides neither payment initiation nor account information services. Providing payment services without the right permission is a criminal offence under regulation 138, carrying up to two years’ imprisonment on indictment.

Last updated 26 July 2026.

What counts as a regulated payment service?

Your business needs FCA permission if it carries out any activity listed in Part 1 of Schedule 1 to the PSRs 2017 as a regular occupation or business: operating payment accounts, executing payment transactions, merchant acquiring, money remittance, payment initiation services and account information services. Part 2 of the same Schedule carries the exclusions, including payment transactions executed by commercial agents acting on behalf of a principal, limited network instruments and intra-group transactions. The exclusions are narrow and the FCA construes them narrowly.

The FCA’s perimeter guidance for payment services is published at PERG 15, in question and answer form. Perimeter analysis comes before any application: whether each money flow in the product is a payment service, and who provides it, determines which permission the firm needs and whether it needs one at all. Our regulatory perimeter and market entry service covers this assessment.

What is the difference between an Authorised Payment Institution and a Small Payment Institution?

An authorised payment institution (API) may provide any payment service in Schedule 1, including payment initiation and account information services, with no transaction volume ceiling. Authorisation requires the applicant to satisfy the conditions in regulation 6 of the PSRs 2017: a UK body corporate with its head office in the United Kingdom, robust governance arrangements, effective risk management and internal controls, fit and proper controllers, directors of good repute with appropriate knowledge and experience, a business plan with a three-year forecast budget, and adequate safeguarding measures under regulation 23. Initial capital under Schedule 3 is EUR 125,000 for the main payment services, EUR 50,000 for payment initiation only and EUR 20,000 for money remittance only, with ongoing own funds calculated under Method A, B or C as the FCA directs.

A small payment institution (SPI) is registered rather than authorised, under the conditions in regulation 14: average monthly payment transactions over the preceding 12 months (or projected, for a new business) must not exceed EUR 3,000,000, the business must not include payment initiation or account information services, and no one responsible for managing the business may have a relevant financial crime conviction. An SPI holds no initial capital and the mandatory safeguarding duty in regulation 23 does not apply, although an SPI may safeguard voluntarily. A firm providing only account information services can instead apply as a registered account information service provider (RAISP).

APIs and SPIs are not FSMA-authorised persons; FCA Handbook regimes that attach to Part 4A authorisation, including the Senior Managers and Certification Regime, do not apply. See our post on SM&CR reform and payment firms: scope before substance for the scope analysis. An SPI that outgrows the regulation 14 conditions must apply for authorisation under regulation 16 within 30 days of becoming aware it no longer meets them; the application is the firm’s to make in time, because the ceilings are measured on a rolling 12-month average and breach is a matter of arithmetic, not discretion.

How does e-money authorisation relate to payment institution status?

A payment institution moves funds the customer already controls; an electronic money institution issues stored value redeemable against itself. A firm whose product holds customer balances for future payments, such as a wallet or prepaid card programme, is likely issuing electronic money under the Electronic Money Regulations 2011 and needs EMI authorisation or small EMI registration rather than, or as well as, payment institution status. An EMI may provide payment services without separate PSRs 2017 permission. The EMI and small EMI regime, including the EUR 350,000 initial capital requirement and the safeguarding rules, is covered in depth on our EMI Authorisation and E-Money Regulation page.

Can I provide payment services as an agent instead of getting authorised?

Yes, by becoming a registered agent of an authorised firm. Under regulation 34 of the PSRs 2017, an authorised payment institution, small payment institution or RAISP may not provide payment services through an agent unless the agent is on the FCA register. The principal applies for the agent’s registration, providing the agent’s identity, its directors, its anti-money laundering controls and the payment services for which it is appointed; the FCA must give notice on a completed agent application within two months. The agent reaches the market on the principal’s permission, and the principal carries regulatory responsibility for the agent’s conduct, so agency terms need real substance on compliance, safeguarding of flows and termination.

The agent route suits firms that want to launch while their own authorisation is prepared, and firms whose volumes do not yet justify the cost of standalone permission. It is a commercial dependency as well as a regulatory one: the principal’s appetite, pricing and oversight standards shape what the agent can offer.

What does the FCA application process look like and how long does it take?

An application for authorisation is made under regulation 5 with the information the FCA requires, through the FCA’s Connect system; the FCA’s application guidance sets out the expected contents, including the regulatory business plan, programme of operations, safeguarding arrangements, governance map and financial projections. Under regulation 9 the FCA must determine a completed application within three months, and an incomplete application within twelve months. The three-month period runs only from receipt of the completed application, so FCA information requests extend the overall process; a well-prepared application in which the business plan, safeguarding documentation and financial projections agree with each other is the single biggest driver of a shorter timeline. Application fees depend on the FCA fee category for the permission sought; the current amounts are on the FCA fees page.

What are the ongoing obligations once authorised?

Authorisation is the start of supervision, not the end of scrutiny. An API must comply with the conduct requirements in Parts 6 and 7 of the PSRs 2017, the strong customer authentication requirements under regulation 100, the safeguarding regime in regulation 23 as supplemented by CASS 15, and the duty under regulation 20 to notify the FCA of changes to the information supplied at authorisation. The FCA also expects firms to disclose anything relating to the firm of which it would reasonably expect notice, reflecting Principle 11, and applies the Consumer Duty to payment firms’ retail business. Data protection obligations under the UK GDPR and Data Protection Act 2018 run alongside the payments regime.

Does UK authorisation cover the EEA?

No. UK authorisation has not passported into the EEA since the end of the Brexit transition period, and the UK’s own transitional regimes for inbound EEA firms have closed. A firm serving customers in both markets needs a UK permission and an EEA one, typically through an EU subsidiary authorised in a member state. Structuring the group so that each entity’s permission matches its customer base is a design question best settled before the UK application is submitted, not after.

When do you need to apply?

The practical triggers are taking control of customer funds in the payment flow rather than acting as a pure technology provider; contracting as principal with merchants or payers rather than as the agent of an authorised firm; launching a product whose money flows no longer fit within a Schedule 1 Part 2 exclusion; approaching the SPI ceilings; or adding payment initiation or account information services, which an SPI cannot provide. Each trigger changes the perimeter analysis, and the cost of getting it wrong is regulation 138.

How does safeguarding affect your operational model?

An API must safeguard relevant funds under regulation 23 of the PSRs 2017, by segregation or by insurance or comparable guarantee. The FCA’s CASS 15 rules, in force since 7 May 2026 under Policy Statement PS25/12, supplement the statutory duty with daily reconciliation, monthly returns, an annual safeguarding audit and a designated individual responsible for safeguarding. An SPI is outside the mandatory regime but may elect to safeguard, in which case CASS 15 applies to it. Safeguarding design decides the firm’s banking arrangements, so it belongs in the application architecture from the start; our Safeguarding and Consumer Duty page covers the regime in depth.

Authorisation route comparison

The four FCA permissions for payments and e-money businesses compare as follows.

FeatureAuthorised PI (API)Small PI (SPI)Authorised EMI (AEMI)Small EMI
Scale limitNoneAverage monthly payment transactions not above EUR 3m (PSRs reg 14(3))NoneAverage outstanding e-money not above EUR 5m; unrelated payment transactions not above EUR 3m monthly average (EMRs reg 13)
ServicesAny Schedule 1 service, including PIS and AISSchedule 1 services other than PIS and AISE-money issuance plus payment servicesE-money issuance plus payment services, other than PIS and AIS, within the caps
Initial capitalEUR 20,000, 50,000 or 125,000 by service (PSRs Sch 3)NoneEUR 350,000 (EMRs Sch 2)None below EUR 500,000 average outstanding e-money; 2% of average outstanding at or above it
Ongoing own fundsMethod A, B or C as FCA directsNoneMethod D: 2% of average outstanding e-money2% of average outstanding e-money where required
FCA determination3 months complete; up to 12 months incomplete3 months complete; up to 12 months incomplete3 months complete; up to 12 months incomplete3 months complete; up to 12 months incomplete
SafeguardingMandatory (PSRs reg 23), supplemented by CASS 15Voluntary election available; CASS 15 applies if electedMandatory (EMRs regs 20 to 22), supplemented by CASS 15Mandatory (EMRs regs 20 to 22), supplemented by CASS 15
FCA authorisation routes for payment and e-money firms compared

Key regulatory references

The Payment Services Regulations 2017 carry the whole regime: regulation 5 (application for authorisation), regulation 6 (conditions for authorisation), regulation 9 (determination), regulation 13 (application for SPI registration), regulation 14 (conditions for SPI registration), regulation 16 (duty to apply for authorisation where SPI conditions cease to be met), regulation 23 (safeguarding), regulation 34 (agents), regulation 100 (strong customer authentication), regulation 138 (criminal offence of unauthorised provision), Schedule 1 (payment services and exclusions) and Schedule 3 (capital). The Electronic Money Regulations 2011 govern EMI authorisation and small EMI registration, with the conditions in regulations 6 and 13, capital requirements in Schedule 2 and safeguarding in regulations 20 to 22.

The FCA’s Approach Document sets its supervisory expectations for payment services and e-money, PERG 15 carries the perimeter guidance, and PS25/12 contains the CASS 15 safeguarding rules. We advise payment firms across the whole framework; see our payments regulation pages.

Need advice on FCA authorisation for payment services?

Frequently asked questions about payments authorisation

Do I need FCA authorisation to provide payment services?

If you provide any service listed in Part 1 of Schedule 1 to the PSRs 2017 as a regular occupation or business in the United Kingdom, and no exclusion applies, you need FCA authorisation or registration. Providing payment services without it is a criminal offence under regulation 138, carrying up to two years’ imprisonment on indictment, alongside FCA enforcement exposure.

What is the difference between a payment institution and an electronic money institution?

A payment institution executes payments with funds the customer controls; an electronic money institution issues stored value on account, redeemable at par. Products that hold customer balances for future spending are usually e-money and need the EMI route, which carries higher capital and stricter safeguarding. The full regime is on our EMI Authorisation and E-Money Regulation page.

How long does the FCA authorisation process take?

The statutory determination period under regulation 9 is three months from receipt of a complete application and up to twelve months for an incomplete one. That is a determination clock, not a promise: preparation time, FCA information requests and completeness disputes mean firms should realistically plan for six to twelve months from starting the application to holding the permission.

Can I operate as a small payment institution to avoid full authorisation?

Only while you meet the regulation 14 conditions, including the EUR 3,000,000 average monthly transaction ceiling, and only if you do not provide payment initiation or account information services. Once the conditions cease to be met, regulation 16 requires an application for authorisation within 30 days of becoming aware of the change. SPI registration works as a launch route, not a destination, for a growing firm.

Can I operate as an agent of an authorised firm instead?

Yes. Under regulation 34 an authorised payment institution, SPI or RAISP may provide payment services through an agent once the agent is on the FCA register; the principal applies and the FCA must give notice on a completed agent application within two months. The principal remains responsible for the agent’s conduct, so the commercial terms carry the compliance obligations.

How does PS25/12 affect safeguarding for authorised firms?

PS25/12 introduced the CASS 15 rules, in force since 7 May 2026, which specify how firms comply with the statutory safeguarding duties in the PSRs 2017 and EMRs 2011: daily reconciliation, monthly returns, an annual audit and a designated safeguarding individual. An SPI that elects to safeguard voluntarily is subject to CASS 15 in the same way.

Why do FCA applications fail?

The recurring causes are inconsistency between the business plan, financial projections and safeguarding documentation; governance maps that do not show who is responsible for what; safeguarding arrangements described in principle but not operationalised; and perimeter analysis that misclassifies the product. Each is avoidable at the drafting stage, and each is expensive once the FCA has raised it.

When should I engage a specialist payments lawyer?

Before the perimeter analysis, because the classification decision shapes everything that follows: the permission applied for, the capital held, the safeguarding model and the group structure. Specialist input at the application stage costs a fraction of unwinding a wrong classification, a refused application or a regulation 138 exposure later.

Related payments regulation pages

See also our other payments regulation pages:

Related insight

The hidden architecture of UK open banking: the directory entry that follows FCA authorisation is what makes an AISP or PISP licence operational across the ecosystem.

Independent directory rankings

Our specialist expertise is recognised in major independent legal directories:

  • Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
  • The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
  • Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology
Chambers and Partners accreditation
Legal 500 accreditation
Lexology Global Elite Thought Leader accreditation