
Payment Institution Authorisation and Licensing
FCA authorisation, registration and permissions for payment service providers and e-money issuers
Short answer: a firm providing payment services in the United Kingdom as a regular occupation or business needs FCA authorisation as an authorised payment institution or registration as a small payment institution under the Payment Services Regulations 2017 (PSRs 2017), unless it is another permitted provider or an exclusion applies. Small payment institution registration is available only while average monthly payment transactions over the preceding 12 months do not exceed EUR 3,000,000 and the firm provides neither payment initiation nor account information services. A firm that provides payment services without the required authorisation or registration commits a criminal offence under regulation 138, carrying up to two years’ imprisonment on indictment.
Last updated 19 August 2026.
Activities that count as regulated payment services
A firm needs authorisation or registration under the PSRs 2017 if it carries out any activity listed in Part 1 of Schedule 1 to the PSRs 2017 as a regular occupation or business: operating payment accounts, executing payment transactions, merchant acquiring, money remittance, payment initiation services and account information services. Part 2 of the same Schedule carries the exclusions, among them payment transactions executed by commercial agents acting for a principal, limited network instruments and intra-group transactions. The FCA sets out how it reads those exclusions in PERG 15.
A firm settles the perimeter before it applies for anything. Whether each money flow in the product is a payment service, and who provides it, decides which permission the firm needs and whether it needs one at all. The FCA publishes its perimeter guidance for payment services at PERG 15, in question and answer form. A firm can take that assessment as a discrete piece of work through regulatory perimeter and market entry.
The difference between an authorised payment institution and a small payment institution
An authorised payment institution (API) may provide any payment service in Schedule 1, including payment initiation and account information services, with no transaction volume ceiling. An applicant must satisfy the conditions in regulation 6 of the PSRs 2017: it must be a UK body corporate with its head office in the United Kingdom, with robust governance arrangements, effective risk management and internal controls, fit and proper holders of any qualifying holding, directors of good repute with appropriate knowledge and experience, a business plan with a three-year forecast budget, and adequate safeguarding measures under regulation 23. It must also carry on, or intend to carry on, at least part of its payment service business in the United Kingdom, under regulation 6(5). It must hold initial capital under Schedule 3 of EUR 125,000 for the main payment services, EUR 50,000 for payment initiation only or EUR 20,000 for money remittance only, and must calculate ongoing own funds under Method A, B or C as the FCA directs.
A small payment institution (SPI) is registered rather than authorised. It applies under regulation 13 and must meet the conditions in regulation 14, on which alone the FCA may refuse registration: its average monthly payment transactions over the preceding 12 months, or projected for a new business, must not exceed EUR 3,000,000, its business must not include payment initiation or account information services, and none of the individuals responsible for the management or operation of the business may have a conviction of the kind listed in regulation 14(5). An SPI holds no initial capital, and the mandatory safeguarding duty in regulation 23 does not apply to it, although it may safeguard voluntarily. A firm providing only account information services can instead apply as a registered account information service provider (RAISP).
An API and an SPI are not FSMA-authorised persons, so the FCA Handbook regimes that attach to Part 4A authorisation, including the Senior Managers and Certification Regime, do not apply to them. The scope analysis is on SM&CR reform and payment firms: scope before substance. An SPI that no longer meets a condition in regulation 14(3), (5) or (10), or that intends to provide services beyond those permitted by regulation 32, must apply within 30 days of becoming aware of the change. Under regulation 16, an SPI that intends to continue providing payment services applies for authorisation under regulation 5 or for registration as an account information service provider under regulation 17. The ceilings are measured on a rolling 12-month average, so the firm can calculate for itself when the duty arises. Applying before a ceiling is reached is prudent sequencing; the statutory deadline starts only once a condition has ceased to be met.
E-money authorisation and payment institution status
A payment institution executes payment transactions; an electronic money institution issues electronic money and may provide payment services as well. That is commercial shorthand, not the legal test: a payment institution also holds customer money, as relevant funds it must safeguard under regulation 23, and what matters is whether the product involves issuing electronic money, not who controls the balance. A product is electronic money only where it meets four cumulative elements under regulation 2(1) of the Electronic Money Regulations 2011: monetary value stored electronically, including magnetically; represented by a claim on the electronic money issuer; issued on receipt of funds for the purpose of making payment transactions; and accepted by a person other than the issuer. It must also fall outside the exclusions, regulation 3 taking out limited network instruments and certain electronic communications billing, and regulation 3ZA, inserted by the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 with effect from 25 February 2026 for specified purposes, taking out stablecoins and the assets held to back them. A wallet or prepaid card programme that holds customer balances for future payments is therefore assessed against those four elements, and where it does involve issuing electronic money the firm needs EMI authorisation or small EMI registration, instead of or as well as payment institution status. An EMI may provide payment services without a separate PSRs 2017 authorisation, and regulation 39 separately requires an issuer to issue at par on receipt of funds and to redeem at par at any time on the holder’s request. The EMI Authorisation and E-Money Regulation page covers the EMI and small EMI regime in depth, including the EUR 350,000 initial capital requirement and the safeguarding rules.
Providing payment services as the agent of an authorised firm
A firm may provide payment services as the registered agent of an authorised firm rather than holding its own permission. Under regulation 34 of the PSRs 2017, an authorised payment institution, small payment institution or RAISP may not provide payment services through an agent unless the agent is on the FCA register. The principal applies for the agent’s registration and gives the agent’s identity, its directors, its anti-money laundering controls and the payment services for which it is appointed; the FCA must give notice on a completed standalone agent application within two months, under regulation 34(11). Where the firm combines the agent application with an application under regulation 5, 13 or 17, regulation 34(15) requires the combined application to be determined under regulation 9, so the authorisation or registration timetable governs and the standalone two-month period does not apply. The agent trades on the principal’s permission. Under regulation 34 the principal makes the registration application, notifies the FCA without undue delay of any change in the information given, and ensures the agent tells users of the agency arrangement, so the agency terms must deal with compliance, safeguarding of flows and termination.
The agent route suits a firm that wants to launch while its own authorisation is prepared, and a firm whose volumes do not yet justify the cost of standalone permission. The principal’s appetite, pricing and oversight standards set what the agent can offer.
The FCA application process and the determination periods
An applicant applies under regulation 5 through the FCA’s Connect system and gives the information the FCA requires. The FCA’s application guidance lists the expected contents: the regulatory business plan, the programme of operations, the safeguarding arrangements, the governance map and the financial projections. Under regulation 9 the FCA must determine a completed application within three months, and an incomplete application within twelve months. The three-month period runs only from receipt of the completed application, so a firm answering FCA information requests extends its own timeline; an applicant whose business plan, safeguarding documentation and financial projections agree with each other answers fewer of them. Application fees depend on the FCA fee category for the permission sought, and the current amounts are on the FCA fees page.
Ongoing obligations after authorisation
Supervision starts at authorisation. An API must comply with the conduct requirements in Parts 6 and 7 of the PSRs 2017, the strong customer authentication requirements under regulation 100, the safeguarding regime in regulation 23 as supplemented by CASS 15, and the duty under regulation 37 to notify the FCA of any major change in circumstances relevant to the conditions for authorisation. A payment institution must disclose to the FCA anything relating to the firm of which the FCA would reasonably expect notice, under Principle 11, applied to it by PRIN 3.1.1AR. It must also act to deliver good outcomes for retail customers under the Consumer Duty, the obligations in Principle 12 and PRIN 2A applied to its retail market business by PRIN 3.2.6R. Its data protection obligations under the UK GDPR, which is Regulation (EU) 2016/679 as it forms part of UK law under section 3 of the European Union (Withdrawal) Act 2018 and is defined at section 3(10) of the Data Protection Act 2018, and under the Data Protection Act 2018 itself, apply alongside the payments regime.
UK authorisation and EEA market access
UK authorisation has not passported into the EEA since the end of the Brexit transition period, and the UK’s own transitional regimes for inbound EEA firms have closed. A firm serving customers in both markets needs a UK permission and an EEA one, typically through an EU subsidiary authorised in a member state. It should match each entity’s permission to its customer base before it submits the UK application.
Triggers for an authorisation application
A firm has to test its permission again when it takes control of customer funds in the payment flow rather than acting as a technology provider; when it contracts as principal with merchants or payers rather than as the agent of an authorised firm; when it launches a product whose money flows no longer fit within a Schedule 1 Part 2 exclusion; when it approaches the SPI ceilings; and when it adds payment initiation or account information services, which an SPI cannot provide. Each of those changes reopens the perimeter analysis, and a firm that provides payment services without the required authorisation or registration commits the offence in regulation 138.
Safeguarding and the firm’s operating model
An API must safeguard relevant funds under regulation 23 of the PSRs 2017, by segregation or by insurance or comparable guarantee. Under the FCA’s safeguarding rules, in force since 7 May 2026 under Policy Statement PS25/12, it must also perform an internal safeguarding reconciliation as frequently as necessary and no less than once each reconciliation day under CASS 15.8.19R, submit a safeguarding return to the FCA within 15 business days of the end of each month under SUP 16.14A.3R, appoint an auditor and obtain a safeguarding audit under SUP 3A unless it is exempt, and allocate oversight of its safeguarding compliance to a single director or senior manager under CASS 15.2.4R. An SPI is outside the mandatory regime but may elect to safeguard, in which case CASS 15 applies to it. The safeguarding model determines the firm’s banking arrangements, so a firm settles it before it drafts the application; the Safeguarding and Consumer Duty page covers the regime in depth.
Authorisation route comparison
The four FCA permissions for payments and e-money businesses compare as follows.
| Feature | Authorised PI (API) | Small PI (SPI) | Authorised EMI (AEMI) | Small EMI |
|---|---|---|---|---|
| Scale limit | None | Average monthly payment transactions not above EUR 3m (PSRs reg 14(3)) | None | Average outstanding e-money not above EUR 5m; unrelated payment transactions not above EUR 3m monthly average (EMRs reg 13) |
| Services | Any Schedule 1 service, including PIS and AIS | Schedule 1 services other than PIS and AIS | E-money issuance plus payment services | E-money issuance plus payment services, other than PIS and AIS, within the caps |
| Initial capital | EUR 20,000, 50,000 or 125,000 by service (PSRs Sch 3) | None | EUR 350,000 (EMRs Sch 2) | None below EUR 500,000 average outstanding e-money; 2% of average outstanding at or above it |
| Ongoing own funds | Method A, B or C as FCA directs | None | Method D (2% of average outstanding e-money) for e-money and related payment services; Method A, B or C for unrelated payment services | 2% of average outstanding e-money where required |
| FCA determination | 3 months complete; up to 12 months incomplete | 3 months complete; up to 12 months incomplete | 3 months complete; up to 12 months incomplete | 3 months complete; up to 12 months incomplete |
| Safeguarding | Mandatory (PSRs reg 23), supplemented by CASS 15 | Voluntary election available; CASS 15 applies if elected | Mandatory (EMRs regs 20 to 22), supplemented by CASS 15 | Mandatory (EMRs regs 20 to 22), supplemented by CASS 15 |
Key regulatory references
The Payment Services Regulations 2017 carry the whole regime: regulation 5 (application for authorisation), regulation 6 (conditions for authorisation), regulation 9 (determination), regulation 13 (application for SPI registration), regulation 14 (conditions for SPI registration), regulation 16 (duty to apply for authorisation where SPI conditions cease to be met), regulation 23 (safeguarding), regulation 34 (agents), regulation 100 (strong customer authentication), regulation 138 (criminal offence of unauthorised provision), Schedule 1 (payment services and exclusions) and Schedule 3 (capital). The Electronic Money Regulations 2011 govern EMI authorisation and small EMI registration, with the conditions in regulations 6 and 13, capital requirements in Schedule 2 and safeguarding in regulations 20 to 22.
The FCA’s Approach Document sets its supervisory expectations for payment services and e-money, and a firm should read it alongside the draft revision the FCA published with PS25/12. PERG 15 carries the perimeter guidance, and PS25/12 contains the CASS 15 safeguarding rules. The payments regulation pages cover how those requirements apply across authorisation, safeguarding, scheme participation and enforcement.
Advice on FCA authorisation for payment services
Frequently asked questions about payments authorisation
Do I need FCA authorisation to provide payment services?
If you provide any service listed in Part 1 of Schedule 1 to the PSRs 2017 as a regular occupation or business in the United Kingdom, and no exclusion applies, you need FCA authorisation or registration. Providing payment services without it is a criminal offence under regulation 138, carrying up to two years’ imprisonment on indictment, alongside FCA enforcement exposure.
What is the difference between a payment institution and an electronic money institution?
A payment institution executes payment transactions; an electronic money institution issues electronic money and may provide payment services too. That commercial shorthand is not the legal test, which is the four-element definition in regulation 2(1) of the Electronic Money Regulations 2011, read with the exclusions in regulations 3 and 3ZA. The test depends on whether the product involves issuing electronic money, not on whether a balance is held. Where it does, the EMI route applies, with higher capital and its own safeguarding regime. The full regime is on the EMI Authorisation and E-Money Regulation page.
How long does the FCA authorisation process take?
The statutory determination period under regulation 9 is three months from receipt of a complete application and up to twelve months for an incomplete one. That period is a determination clock, and it starts only once the FCA holds a completed application, so the elapsed time from first submission to holding the permission depends on how quickly the firm answers the FCA’s information requests.
Can I operate as a small payment institution to avoid full authorisation?
Only while you meet the regulation 14 conditions, including the EUR 3,000,000 average monthly transaction ceiling, and only if you do not provide payment initiation or account information services. Once the conditions cease to be met, regulation 16 requires an application for authorisation within 30 days of becoming aware of the change. A growing firm uses SPI registration as a launch route and applies for authorisation before it reaches the regulation 14 ceilings, as prudent sequencing. The statutory deadline itself runs from becoming aware that a condition has ceased to be met, not from reaching a ceiling.
Can I operate as an agent of an authorised firm instead?
Yes. Under regulation 34 an authorised payment institution, SPI or RAISP may provide payment services through an agent once the agent is on the FCA register; the principal applies and the FCA must give notice on a completed standalone agent application within two months (regulation 34(11)). An agent application combined with an application for authorisation or registration is determined on the regulation 9 clock instead (regulation 34(15)). Under regulation 34 the principal makes the registration application, notifies the FCA of any change in the information given and ensures the agent discloses the agency arrangement, so the commercial terms carry the compliance obligations.
How does PS25/12 affect safeguarding for authorised firms?
Since 7 May 2026, under the rules introduced by PS25/12, a firm must perform an internal safeguarding reconciliation as frequently as necessary and no less than once each reconciliation day under CASS 15.8.19R, submit a safeguarding return to the FCA within 15 business days of the end of each month under SUP 16.14A.3R, appoint an auditor and obtain a safeguarding audit under SUP 3A unless it is exempt, and allocate oversight of its safeguarding compliance to a single director or senior manager under CASS 15.2.4R. Those rules specify how a firm complies with the statutory safeguarding duties in the PSRs 2017 and the EMRs 2011. An SPI that elects to safeguard voluntarily is subject to CASS 15 in the same way.
Why do FCA applications fail?
The FCA refuses or delays applications where the business plan, financial projections and safeguarding documentation do not agree with each other; where the governance map does not show who is responsible for what; where the firm has described its safeguarding arrangements in principle but not operationalised them; and where the perimeter analysis misclassifies the product. Each is cheaper to settle at the drafting stage than after the FCA has raised it.
When should I engage a specialist payments lawyer?
Before the perimeter analysis, because the classification decides the permission applied for, the capital held, the safeguarding model and the group structure. Unwinding a wrong classification, a refused application or a regulation 138 exposure later costs more than settling the classification at the start.
Related payments regulation pages
These pages cover the rest of the payments regime. A firm unsure whether it needs authorisation at all should start with the perimeter and exclusions page, which sets out the scope of the regime and the activities the PSRs 2017 exclude.
Payments Regulation
EMI Authorisation and E-Money Regulation
Open Banking and Variable Recurring Payments
PSR and Scheme Governance
Operational Resilience and DORA
Safeguarding and Consumer Duty
FCA Investigations and Enforcement
The PSRs 2017 Explained: Payment Authorisation, Liability and Execution Times
The PSRs 2017 Explained: Information Requirements and Framework Contracts
Digital Money and Central Bank Digital Currencies
The PSRs 2017 Explained: the Payment Services Perimeter and the Exclusions
Related insight
The hidden architecture of UK open banking: an AISP or PISP licence becomes usable across the market only once the firm is entered in the open banking directory that follows FCA authorisation.
Credentials
Rob Bratby is Managing Partner of Bratby Law and Fractional General Counsel to UK Payments Initiative Limited, the industry body developing the UK’s commercial account-to-account payments scheme. He also holds Fractional General Counsel appointments at The One Touch Switching Company, TelXL and Core. He is ranked Band 2 for Telecommunications in Chambers UK 2026, listed by The Legal 500 as a Leading Partner for IT and telecoms in London, and recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media and a Thought Leader for data privacy and protection.
