top of page

FCA Compliance for Electronic Money Institutions 2026: Complete Guide

  • 5 days ago
  • 15 min read
FCA Compliance for Electronic Money Institutions 2026: Complete Guide

An FCA-authorised Electronic Money Institution operates under a broader regulatory framework than the simple obligation to issue and redeem e-money correctly. UK AEMIs must comply with the Electronic Money Regulations 2011, relevant provisions of the Payment Services Regulations 2017, the FCA's current payment and e-money approach, CASS 15 safeguarding, prudential requirements, financial crime obligations, Consumer Duty where applicable, regulatory reporting, complaints, security and operational requirements. Small Electronic Money Institutions operate under a more limited registration regime but still face substantive requirements relating to e-money, payments, safeguarding and financial crime.


The compliance framework became materially more demanding on 7 May 2026 when the FCA's strengthened safeguarding rules took effect. CASS 15 now provides detailed rules on segregation, records, daily reconciliations, third-party due diligence and safeguarding governance, with monthly REP027 reporting and safeguarding audits applying to relevant firms. The FCA's wider payments priorities also mean an EMI should expect supervisory attention on financial resilience, wind-down, financial crime, Consumer Duty and operational resilience alongside safeguarding.


EMI compliance requirements at a glance

Regulatory area

Main requirement for an EMI

Electronic Money Regulations 2011

Authorisation, issuance, redemption, safeguarding and prudential framework

Payment Services Regulations 2017

Payment services provided by the EMI and relevant conduct obligations

FCA Payment Services and Electronic Money Approach

FCA interpretation of the EMRs and PSRs

CASS 15 and CASS 10A

Safeguarding, daily reconciliations, records and resolution packs

SUP 3A

Safeguarding audit for relevant institutions above the exemption threshold

SUP 16 and REP027

Regulatory reporting and monthly safeguarding return

Initial and ongoing capital

EUR 350,000 initial capital for AEMI plus ongoing own funds

Consumer Duty

Good retail customer outcomes where in scope

Financial crime and MLRs

AML, CTF, sanctions, fraud and related controls

Operational resilience

Formal and broader resilience requirements according to scope

Complaints

DISP and Financial Ombudsman requirements where applicable

Agents and distributors

Oversight, registration where required and continued EMI responsibility

Governance and outsourcing

Effective systems, controls, risk management and oversight


An EMI should map these requirements to the specific services it provides. A simple prepaid product has a different operational risk profile from a multi-currency wallet offering cards, international transfers and merchant services, while an EMI operating significant unrelated payment services can face additional prudential complexity. The compliance framework should therefore be designed around the actual customer journey and flow of funds.


The Electronic Money Regulations remain the core legal framework

The Electronic Money Regulations 2011 govern authorisation and registration of e-money issuers and contain the core legal requirements relating to issuing electronic money. An AEMI must continue satisfying the conditions of authorisation, including appropriate governance, systems and controls, financial resources and suitability of management. Material changes to the business can therefore require regulatory assessment even where the original licence remains valid.


The EMRs also establish important customer rights around issuance and redemption. Electronic money is issued on receipt of funds and must be redeemable in accordance with the regulatory framework and the firm's contractual terms, subject to permitted conditions and charges. Firms should ensure operational systems can distinguish e-money liabilities accurately and support timely redemption throughout the customer lifecycle.


Many EMIs also provide payment services. Those services can bring relevant PSR conduct, security and information requirements into the same customer journey, meaning an EMI needs to manage the EMRs and PSRs together rather than as separate legal silos. The FCA's Payment Services and Electronic Money Approach should therefore be a core reference for ongoing compliance.


E-money issuance and redemption controls need to work operationally

An EMI should know precisely when customer funds create an e-money liability and how that liability is recorded in its ledger. Wallet funding, card loads, refunds, chargebacks and transfers between customers can create accounting and safeguarding consequences that need consistent treatment. Product and finance teams should therefore use the same definitions as the regulatory framework.


Redemption processes should allow customers to exercise their statutory rights without unreasonable friction. Charges, notice requirements and contractual limitations need to remain within the EMR framework and should also be considered under Consumer Duty where the customer is in scope. Complaints and support data can reveal whether customers experience recurring difficulty accessing or redeeming balances.


The firm's terms and operational system should correspond. A contractual promise that e-money is immediately redeemable provides little protection if the actual process requires lengthy manual intervention or depends on a third party that cannot process withdrawals reliably. Compliance monitoring should therefore test live redemption cases as well as legal documentation.


CASS 15 is now central to EMI safeguarding

Funds received in exchange for electronic money must be safeguarded under regulation 20 of the EMRs and the detailed FCA framework in CASS 15. The firm needs a documented methodology for identifying relevant funds, segregating or otherwise protecting them, maintaining records and conducting daily internal and external reconciliations. This is now a core operational discipline rather than an occasional finance process.


The internal reconciliation should establish the amount that should be protected based on the firm's own records and compare it with the safeguarding resources available. The external reconciliation verifies relevant internal records against banks, custodians or other third-party records. Breaks and shortfalls should be investigated promptly and the firm should maintain evidence showing how each material issue was resolved.


EMI models can be particularly complex because the same firm may handle outstanding e-money, pending payment transactions, card settlement and funds associated with unrelated payment services. The safeguarding methodology needs to distinguish those categories correctly while ensuring customer money is not omitted or double counted. Generic spreadsheet models should be challenged where transaction volume or product complexity has outgrown them.


Safeguarding bank and third-party due diligence

CASS 15 requires due skill, care and diligence when selecting and reviewing institutions used to hold relevant funds. The EMI should assess financial strength, market reputation, regulatory status, concentration, legal protections and the suitability of the arrangement. Due diligence should be refreshed periodically and when circumstances change rather than remaining an onboarding document created when the account was first opened.


Concentration risk deserves particular attention. An EMI can become highly dependent on one safeguarding bank even where it has several operational accounts elsewhere, and failure of that institution can create serious customer and liquidity consequences. Management should understand why the concentration remains appropriate and whether credible diversification is available.


Acknowledgement arrangements and account design should also be maintained accurately. Legal documentation, account naming and the firm's internal records need to support the intended safeguarding protection. Changes made by a bank or group entity should therefore trigger regulatory review before they are treated as ordinary treasury administration.


Monthly REP027 reporting increases regulatory visibility

Relevant EMIs submit REP027 each month, giving the FCA detailed information about safeguarding positions and arrangements. The return should be supported by the same underlying books, reconciliations and methodologies the firm uses operationally. Differences between reported figures and internal safeguarding information should be understood before submission rather than explained retrospectively after an FCA question.


Data ownership is particularly important for complex EMI groups. Finance, treasury, safeguarding operations and compliance may each hold parts of the required information, so the firm needs a controlled process for assembling, reviewing and approving the return. Manual adjustments should have clear rationale and evidence.

The FCA can use REP027 alongside audit findings and other returns to target supervision. Accurate reporting therefore contributes directly to regulatory confidence in the firm. BCC's regulatory reporting guide explains the wider set of payment and e-money returns.


Annual safeguarding audits can expose operational weaknesses

Relevant EMIs above the SUP 3A exemption threshold are subject to annual safeguarding audits. The auditor provides reasonable assurance on the adequacy of the firm's systems throughout the audit period and compliance at period end, with individual breaches recorded in the required schedule. This means the audit can expose recurring control weaknesses even where the final balance is correct.


Firms should therefore retain evidence throughout the year. Reconciliations, exception investigations, third-party due diligence, account documentation, resolution packs, breach records and governance should be capable of independent review without extensive reconstruction. An audit readiness assessment can identify gaps before external fieldwork begins.


Where findings arise, management should address root causes and consider whether broader FCA notification or customer remediation is necessary. The objective is not to achieve a cosmetically clean audit but to maintain a safeguarding framework that genuinely protects customer funds. BCC can support the regulatory framework and remediation while the independent auditor retains responsibility for the assurance opinion.


AEMIs must maintain at least EUR 350,000 initial capital

A full Authorised Electronic Money Institution requires minimum initial capital of EUR 350,000 under the current EMR framework. This is regulatory capital held by the institution rather than a fee paid to the FCA, and the firm must continue meeting applicable ongoing own-funds requirements after authorisation. Capital therefore needs active monitoring as the business grows.


For e-money issuance and payment services related to issuance, the ongoing calculation includes Method D, based on 2% of average outstanding electronic money subject to the detailed rules. Unrelated payment services can create additional calculations under the payment-services methodologies. A diversified EMI should therefore model each business line rather than assuming EUR 350,000 remains the permanent requirement regardless of scale.


The FCA also considers broader financial resilience. Capital, liquidity, enterprise risk and wind-down planning should be connected so that management understands whether the firm can survive stress or exit without harming customers. Its multi-firm review of payment and e-money firms identified significant weaknesses in risk management and wind-down planning, making this an important ongoing supervisory area.


Consumer Duty applies to relevant retail e-money services

Consumer Duty applies where an EMI provides products or services within its retail scope. Wallets, prepaid products, cards and associated payment services can create issues around fees, exchange rates, account restrictions, customer support, product design and vulnerability. Firms should map the Duty to each retail journey rather than assuming that e-money products are outside ordinary conduct regulation.


The products and services outcome requires the firm to understand the target market and whether the product meets its needs. Price and value requires consideration of the total economic cost, including account fees, card charges, FX spreads and other pricing. Consumer understanding and support then require clear communications and effective access to help throughout the relationship.


Outcome monitoring should use real operational data. Failed withdrawals, account freezes, complaints, call waiting, fraud cases, dormancy fees and vulnerable-customer outcomes can all show whether the product works as intended. The annual board assessment should explain what management learned from this evidence and what changed as a result.


Account freezes and financial crime controls need careful governance

EMIs can face difficult decisions where financial crime concerns require accounts or transactions to be restricted. The firm needs effective AML and fraud controls while also ensuring customer treatment, communications and escalation are proportionate to legal restrictions. Poorly governed account freezes can create significant complaints and Consumer Duty risk even where the original financial crime concern was legitimate.


The framework should define who can impose restrictions, what information can be communicated, how cases are reviewed and how long unresolved restrictions remain open. Tipping-off and other legal constraints need to be respected, but those constraints do not justify leaving customers without any meaningful process or internal governance. Management information should identify unusually long cases and recurring causes.


Financial crime and customer-outcome teams should therefore share appropriate intelligence. A growing population of restricted accounts may indicate a change in risk, weaknesses in onboarding or a transaction-monitoring issue. Compliance should understand both the crime risk and the customer consequences.


AML, sanctions and transaction monitoring must match the e-money model

EMIs are supervised for compliance with the Money Laundering Regulations and must maintain a risk-based financial crime framework. Customer due diligence, enhanced due diligence, sanctions screening, transaction monitoring and suspicious activity reporting should be designed around the specific customer population and flow of funds. A consumer wallet, payroll product and B2B multi-currency account create different risks and should not use identical control settings without justification.


Transaction monitoring is particularly important because e-money balances can receive and transfer value rapidly. Scenarios should consider velocity, linked accounts, beneficiaries, jurisdictions, third-party funding, device information and other indicators relevant to the product. Thresholds should be calibrated and tested rather than inherited from a vendor's default configuration.


Sanctions controls should cover relevant customers, beneficial owners, counterparties and payments according to the firm's exposure. Data quality and list updates are critical because the best screening engine cannot identify a match if transaction information is missing or mapped incorrectly. Alert handling should be timely and supported by clear escalation.


Payment conduct requirements also apply to EMI payment services

An EMI providing payment services must comply with relevant PSR conduct requirements governing information, consent, execution, liability and security. The firm should map these rules to each payment function within the wallet or account rather than treating e-money issuance as the only regulated activity. Cards, bank transfers, Direct Debits and other features can each create different obligations.


Strong Customer Authentication and security requirements should be incorporated into product design. Where exemptions are used, the regulatory conditions and fraud performance should be monitored. Changes to payment technology can alter the compliance position even when the customer-facing product appears unchanged.


Unauthorised transactions and payment disputes also need appropriate processes. The firm should understand the statutory liability framework and distinguish ordinary complaints, fraud investigations and payment execution issues. Customer support teams should have guidance that allows them to classify and escalate cases correctly.


Operational resilience and technology risk are core EMI issues

An EMI can be operationally dependent on core ledger technology, card processors, sponsor banks, cloud infrastructure, KYC vendors and payment rails. Firms within the formal operational resilience regime should maintain important business service mapping, impact tolerances, testing and remediation. Even where a specific sourcebook rule does not apply, the EMRs and FCA authorisation conditions still require adequate systems, governance and operational capability.


The customer impact of failure can be severe because users may lose access to funds or be unable to make essential payments. Resilience planning should therefore focus on the service experienced by the customer rather than only the recovery time of individual IT systems. Dependency maps should include material third parties and internal group services.


Scenario testing should be severe but plausible and produce concrete remediation. A test that confirms the business continuity plan can be opened is not enough if the firm cannot restore wallet balances, payment functionality or customer communications within acceptable tolerances. Boards should monitor vulnerabilities and investment required to reduce them.


Outsourcing and programme managers require clear responsibility

EMIs often operate through outsourced technology, card programme managers, processors, distributors and group service companies. These arrangements can be legitimate, but the EMI remains responsible for the regulated activities it carries on and should retain sufficient control, information and expertise. The authorisation should not become a regulatory wrapper around a business actually controlled by an unregulated partner.


Due diligence should assess regulatory capability, financial condition, information security, resilience, service quality and sub-outsourcing. Contracts should define roles clearly and support audit, regulatory access, data, incident notification and exit. The EMI should be able to intervene where a provider's conduct creates customer or regulatory risk.


Ongoing monitoring should examine outcomes, not only service-level metrics. Complaints, reconciliation differences, fraud, transaction failures and support issues may reveal weaknesses in a programme partner that are not captured by uptime statistics. Governance should identify when provider performance requires remediation or a change in the operating model.


Agents and distributors need proportionate oversight

EMIs can use agents for payment services and distributors for e-money distribution, but the regulatory treatment of these relationships differs. The firm should classify each arrangement correctly and understand registration, contractual and oversight requirements. Using the wrong label can obscure the regulated activities actually being performed.


Before appointment, the EMI should assess ownership, management, competence, financial crime exposure, customer-facing activity and the operational role of the partner. Ongoing monitoring should consider complaints, CDD quality, sales practices, customer outcomes and whether the partner remains within the agreed scope. The scale of the network should remain proportionate to the EMI's ability to supervise it.


Where partners handle customer funds or information, the flow of funds and records should be mapped carefully. Safeguarding and financial crime responsibility can be affected by timing and control over customer money. The EMI should be able to reconstruct the customer journey across the complete distribution chain.


Governance and SMCR application should be mapped accurately

AEMIs must maintain sound and prudent management, clear organisational arrangements, effective risk procedures and appropriate internal controls. Firms should not assume that the ordinary solo-regulated FSMA SMCR applies automatically solely because the entity is authorised under the EMRs. The precise position depends on the firm's wider regulatory permissions and status and should be assessed explicitly.


The governance standard remains high regardless of that technical classification. Senior management should own safeguarding, financial crime, risk, compliance, finance and operational resilience with enough authority and resources to discharge those responsibilities. Board minutes and MI should show challenge and action rather than merely record that reports were presented.


Where additional FSMA permissions bring SMCR into scope, Statements of Responsibilities, certification, fitness and propriety and Conduct Rules should be integrated into the framework. The entity's complete regulatory profile should determine the accountability structure.


Regulatory reporting for EMIs is broader than safeguarding

EMIs submit periodic returns including information on their business, capital and e-money activity, together with payment-service and fraud returns where applicable. FIN060 and other FCA returns need to be included in a controlled reporting calendar and reconciled to the firm's underlying records. AEMIs should also ensure that outstanding e-money and related capital data are calculated consistently across finance and regulatory reporting.


REP027 adds a monthly safeguarding return, increasing both the frequency and supervisory importance of reporting. Firms should establish clear data owners, review procedures and sign-off standards. Material anomalies should be investigated before filing rather than explained after the FCA identifies them.


Event notifications remain separate from periodic returns. Changes in controllers, important outsourcing, senior management, business model or circumstances affecting authorisation conditions can require FCA engagement. Compliance should therefore operate a regulatory-notification process in addition to the normal reporting calendar.

Wind-down planning needs to protect customer balances

An EMI wind-down plan should explain how the firm would stop issuing e-money, continue essential payment and redemption functions, return customer funds and meet regulatory obligations during an orderly exit. The plan should reflect actual operational dependencies, staffing, banking, technology and the cost of maintaining services long enough to complete the process. A generic document prepared for authorisation can become obsolete quickly as the business grows.


Safeguarding and wind-down are closely connected. The firm needs reliable records of customer entitlements and access to safeguarding resources if it fails, while its resolution pack should help relevant persons understand how funds can be identified and returned. Operational inability to access systems can undermine otherwise sound legal safeguarding arrangements.


Boards should review triggers for wind-down and the financial resources required to execute it. The decision to begin wind-down often needs to occur while the firm still has enough cash and staff to protect customers, so a plan that assumes management can wait until insolvency is imminent is unlikely to be credible.


Compliance monitoring should cover the complete EMI lifecycle

A risk-based compliance monitoring plan should test e-money issuance and redemption, safeguarding, regulatory capital, Consumer Duty, payment conduct, financial crime, complaints, agents, distributors, outsourcing, operational resilience and reporting. Testing should use real transactions and evidence rather than focus primarily on whether policies are up to date. The frequency should increase where products or risk change materially.


Safeguarding and financial crime are particularly suitable for independent re-performance testing because control failures can remain hidden behind completed checklists. Regulatory returns can also be traced back to source data and customer files sampled for communications, complaints or account restrictions. The output should identify root cause and regulatory significance rather than simply list exceptions.


Remediation should be tracked and retested. Repeated manual adjustments, recurring alerts or unresolved complaints can show that the underlying control design remains weak even when each individual case has been closed. Board MI should show the trend and whether corrective action is reducing risk.


How Buckingham Capital Consulting can help

Buckingham Capital Consulting has specialised in electronic money and payment regulation since 2013 and provides ongoing EMI compliance support. We can undertake complete or targeted reviews covering the EMRs, PSRs, CASS 15, safeguarding reconciliations, Consumer Duty, financial crime, capital, governance, outsourcing, agents and distributors, operational resilience, regulatory reporting and wind-down. Each review is built around the actual products, customer flows and operating model of the institution.


We also support remediation where weaknesses have been identified through safeguarding audits, internal assurance or FCA supervision. This can include redesigning safeguarding methodologies, strengthening governance and MI, reviewing financial crime controls, improving reporting processes and preparing regulatory responses. Where the firm is planning a material change to products, ownership or permissions, we can assess the regulatory impact before implementation.


For new entrants, BCC manages complete FCA Electronic Money Institution authorisation projects and can continue supporting the business after approval. To discuss an EMI compliance review, safeguarding project or regulatory remediation programme, contact Buckingham Capital Consulting.


Frequently asked questions

What regulations apply to a UK Electronic Money Institution?

A UK AEMI is principally regulated under the Electronic Money Regulations 2011, with the Payment Services Regulations applying to relevant payment services. CASS 15, SUP 3A, SUP 16, Consumer Duty, financial crime, complaints, capital and operational requirements can also apply depending on the business. The FCA's current Payment Services and Electronic Money Approach is an important practical guide to how these requirements are interpreted.


What is the minimum capital for an Authorised EMI?

The current minimum initial capital requirement for an AEMI is EUR 350,000. The firm must also satisfy ongoing own-funds requirements, including the applicable calculation for average outstanding e-money and any unrelated payment services. The actual amount that needs to be maintained can therefore exceed the initial minimum as the business grows.


Does CASS 15 apply to Electronic Money Institutions?

Yes, safeguarding institutions within scope must comply with the detailed CASS 15 framework in addition to the statutory safeguarding requirement in the EMRs. This includes records, daily safeguarding reconciliations, third-party due diligence and related governance. REP027 reporting and safeguarding audit requirements also apply to relevant firms.


Does Consumer Duty apply to e-money wallets and prepaid products?

It can apply where the product and customer fall within the Duty's retail scope. EMIs should assess target markets, price and value, customer understanding and support and monitor evidence of actual customer outcomes. Account restrictions, fees, redemption, payment failures and customer service can all be relevant to the assessment.


What is the difference between EMI compliance and PI compliance?

Both regimes share significant payment, safeguarding, financial crime and conduct requirements, but an EMI also issues electronic money and must comply with the EMR framework governing e-money liabilities, redemption and prudential requirements. AEMIs have a EUR 350,000 initial capital floor and can face Method D own-funds calculations based on outstanding e-money. The compliance framework should therefore reflect both the e-money and payment-service sides of the business.


#FCA Compliance for Electronic Money Institutions 2026: Complete Guide

 
 
bottom of page