Regulatory Licencing and Compliance Advisory for Payment Institutions
Regulatory Counsel advises payment institutions on regulatory licencing, authorisation and ongoing compliance. We work with firms applying for FCA authorisation for the first time, firms varying existing permissions, and authorised firms that need their compliance framework, safeguarding arrangements and financial crime controls to hold up under supervision.
FCA authorisation and registration under the Payment Services Regulations 2017
Small payment institution to authorised payment institution upgrades
Safeguarding design, reconciliation and audit readiness
AML and financial crime frameworks proportionate to the payment model
Ongoing compliance, regulatory reporting and regulator engagement
International expansion across the EU, Canada, the United States, Australia, Singapore and Hong Kong
How we advise payment institutions
A payment institution is a firm authorised or registered to provide payment services. In the United Kingdom that means authorisation or registration under the Payment Services Regulations 2017, supervised by the Financial Conduct Authority. Across the European Union the equivalent regime derives from the second Payment Services Directive and is applied by each national competent authority.
Our work concentrates on the operating reality behind the permission: how funds move, who holds them, where the relevant payment service ends, and whether the controls described in the application are the controls the business will actually run.
What regulatory permission does a payment firm need?
A firm that provides payment services as a regular occupation or business activity in the UK must be either an authorised payment institution, a small payment institution, an authorised or small electronic money institution, a credit institution, or a registered agent of an authorised firm.
The correct route depends on the payment services provided, projected transaction volume, and whether the firm issues electronic money. Firms that only distribute or redeem e-money on behalf of another institution, or that act as an agent of an authorised firm, are subject to a different registration route again.
Getting this classification right is the single most consequential decision in the process. An application submitted under the wrong permission is not simply refused; it consumes months of runway and creates a regulatory history the firm has to explain in every subsequent application.
| Route | Typical fit | Key constraint |
|---|---|---|
| Authorised payment institution (API) | Firms with no volume ceiling, passport-free UK operations, agent networks | Full authorisation assessment, initial capital and own funds requirements |
| Small payment institution (SPI) | Early-stage firms below the monthly average transaction threshold in the PSRs | Volume threshold, no payment initiation or account information services |
| Electronic money institution (EMI) | Firms issuing stored value or wallet balances rather than executing single transactions | Higher capital, e-money issuance and redemption obligations |
| Agent of an authorised firm | Distribution-led models operating under a principal | Principal carries regulatory responsibility; the model constrains growth |
When is a small payment institution the wrong choice?
A small payment institution registration suits a firm that will genuinely stay below the transaction threshold and does not need payment initiation or account information permissions. It is the wrong choice where the business plan, funding round or commercial pipeline assumes growth beyond that ceiling within the first eighteen months.
We regularly see firms register as an SPI to reach market quickly, then face a full authorisation application at the exact moment they are scaling, hiring and integrating partners. The upgrade is not a formality: it is a fresh assessment of governance, capital, safeguarding and financial crime controls.
Where growth is the plan, we usually recommend building the compliance framework to authorised standard from the outset, even if the initial registration is small. That way the variation of permission is an evidence exercise rather than a rebuild.
How does safeguarding apply to payment institutions?
Authorised payment institutions must safeguard relevant funds received for the execution of payment transactions, either by segregating them in a designated safeguarding account or by covering them with an insurance policy or comparable guarantee.
Safeguarding is where supervisory attention concentrates, because it determines what happens to customer funds if the firm fails. The FCA has strengthened the regime and firms are expected to evidence daily internal and external reconciliations, a documented safeguarding method, clear records of relevant funds, and a resolution pack that would allow an insolvency practitioner to return funds promptly.
The common failure is not the absence of a safeguarding policy. It is a policy that does not match the payment flow, so relevant funds enter the operating account before they reach segregation, or reconciliations run on a cycle that cannot detect a shortfall the same day it arises.
- -Mapping every payment flow to the point at which funds become relevant funds
- -Selecting and documenting the safeguarding method for each flow
- -Designing daily internal and external reconciliation with a defined break process
- -Preparing the safeguarding resolution pack and keeping it current
- -Preparing for the annual safeguarding audit and responding to findings
What ongoing compliance does an authorised payment firm need?
Authorisation is the beginning of the supervisory relationship. An authorised payment institution must maintain governance and systems and controls, safeguard relevant funds, run a financial crime framework, submit regulatory returns accurately and on time, notify the regulator of material changes, and demonstrate that its compliance monitoring actually tests the risks in its business.
Launch compliantly
Operationalise the framework described in the application before the first live transaction, not after.
Maintain controls
Compliance monitoring, safeguarding reconciliation, transaction monitoring calibration and periodic risk assessment.
Report accurately
Regulatory returns, safeguarding reporting and data quality governance across the return set.
Engage with the regulator
Information requests, notifications, supervisory correspondence and skilled person reviews.
Adapt to change
Horizon scanning and a regulatory change process that converts new rules into control changes with owners and deadlines.
How does Regulatory Counsel support a payment institution?
We support payment institutions across the full regulatory lifecycle: perimeter and permission analysis, licence selection, application preparation and submission management, safeguarding and financial crime design, ongoing compliance support, regulatory reporting, and remediation when supervision escalates.
For firms expanding internationally, we work through the sequence of obligations that a single product can create: a UK authorised payment institution offering remittance into North America may need to consider money services business registration in Canada and federal and state requirements in the United States before it can lawfully serve those corridors.
Practitioner observations from payment institutions engagements
Applications fail on operating detail, not on drafting
The most common reason a payment application stalls is that the programme of operations describes an idealised flow of funds while the technical integration, partner contracts and settlement arrangements describe a different one. Regulators read both.
Outsourcing does not move the obligation
Using a banking-as-a-service partner, a processor or an offshore operations team does not transfer regulatory responsibility. The firm still has to evidence oversight, exit planning and its own view of the controls performed on its behalf.
Compliance design must match the commercial model
Merchant acquiring, marketplace settlement, payroll disbursement and consumer remittance carry materially different safeguarding, financial crime and conduct risk. A generic framework signals to a supervisor that the firm has not analysed its own risk.
Licences and registrations for this sector
UK Authorised Payment Institution
Full FCA authorisation under the Payment Services Regulations 2017.
View licenceUK Small Payment Institution
Registration route for firms below the PSRs transaction threshold.
View licenceUK Electronic Money Institution
Where the model requires e-money issuance rather than payment execution alone.
View licenceUS Money Transmitter Licence
State licencing for payment firms serving United States customers.
View licenceHow we support firms in this sector
Regulatory Licencing & Authorisation
Permission analysis, application preparation and submission management.
Safeguarding & Client Money
Safeguarding design, reconciliation and audit readiness.
AML & Financial Crime
Financial crime frameworks proportionate to the payment model.
Ongoing Compliance Support
Monitoring, reporting, governance and regulator engagement after authorisation.
Discuss a payment institution application or compliance review
Tell us your business model, the markets you serve and the permissions you hold. We will tell you what is actually in scope and what the credible route looks like.
Get Expert Advice
Related insights
Lithuania vs Ireland for a Payment Institution Licence: Which Should You Choose?
A detailed comparison of Lithuania and Ireland for EU payment institution licensing - speed, cost, substance requirements and passporting after Brexit.
LicensingFCA Authorisation - Step-by-Step Guide to the Application Process
A detailed walkthrough of the FCA authorisation process - from pre-application planning through to determination and post-authorisation obligations.
LicensingPassporting and Cross-Border Licensing Post-Brexit - UK Firms' Options
How UK financial services firms can serve EU/EEA customers after the loss of passporting rights, including subsidiary options, equivalence and reverse solicitation.
Frequently asked questions
The FCA has three months to determine a complete application and up to twelve months where an application is incomplete. In practice, the elapsed time depends on how quickly the firm can answer information requests with evidence rather than intention, so preparation quality drives the timeline more than the statutory period does.
An authorised payment institution has no transaction volume ceiling, is subject to initial capital and own funds requirements, and undergoes a full authorisation assessment. A small payment institution is a registration route limited by the average monthly payment transaction threshold in the Payment Services Regulations 2017 and cannot provide payment initiation or account information services.
Yes. Safeguarding obligations apply to relevant funds from the moment the firm begins providing payment services. Safeguarding arrangements, the designated account and the reconciliation process should be live and tested before the first customer transaction, not built afterwards.
No. UK authorisation no longer confers EEA passporting rights. A UK payment institution that wants to serve EEA customers generally needs authorisation from an EEA national competent authority, with the substance, governance and local presence that authority expects.
Adding payment services, moving from small payment institution registration to full authorisation, changing the safeguarding method materially, or altering the business model in a way that goes beyond the permissions granted. Operating outside granted permissions is a regulatory breach even where the activity itself would have been approvable.
Not necessarily. Operating as an agent or distributor of an authorised firm can be a legitimate route to market, but it constrains the model and leaves regulatory responsibility with the principal. Firms that control the customer relationship, the funds flow and the product economics usually reach a point where their own authorisation is required.
Internal consistency. The business plan, programme of operations, financial forecasts, safeguarding arrangements and financial crime risk assessment must describe the same firm, with volumes, corridors, customer types and control capacity that reconcile with each other.
Primary regulatory sources
This page summarises regulatory requirements for orientation. It is not legal advice. The primary sources below govern.