top of page

FCA Compliance for UK Payment Institutions 2026: Complete Guide

  • 3 days ago
  • 15 min read
FCA Compliance for UK Payment Institutions 2026: Complete Guide

Maintaining FCA compliance after Payment Institution authorisation is an ongoing regulatory programme, not a continuation of the application exercise. A UK Authorised Payment Institution must continue meeting the conditions of authorisation while complying with the Payment Services Regulations 2017, the FCA's current payment-services approach, safeguarding rules, conduct requirements, financial crime obligations, regulatory reporting, capital and financial-resilience expectations, complaints rules and operational requirements. Small Payment Institutions operate under a more limited registration regime, but they still need to comply with the rules that apply to their activities and registration conditions.


The compliance burden became materially more demanding on 7 May 2026 when the strengthened safeguarding regime under CASS 15 took effect. Payment firms now operate under formal FCA rules covering safeguarding records, daily reconciliations, resolution packs, third-party due diligence, monthly REP027 reporting and, for relevant firms above the exemption threshold, independent safeguarding audits. The FCA's 2026 Payments Regulatory Priorities also make clear that financial crime, Consumer Duty, operational resilience, safeguarding, financial resilience and preparation for regulatory reform remain central supervisory themes.


Payment Institution compliance requirements at a glance

Regulatory area

Main requirement

Payment Services Regulations 2017

Authorisation conditions, payment services conduct, safeguarding and operational requirements

FCA Payment Services and Electronic Money Approach

FCA interpretation and supervisory expectations

CASS 15 and CASS 10A

Safeguarding, reconciliations, records and resolution packs

SUP 3A

Annual safeguarding audit for relevant firms above the exemption threshold

SUP 16 and REP027

Periodic and monthly regulatory reporting

Consumer Duty

Good outcomes for retail customers where the Duty applies

Financial crime and MLRs

AML, CTF, sanctions, fraud and related controls

Operational resilience

Formal SYSC 15A requirements for firms within scope and broader resilience expectations

Capital and own funds

Initial and ongoing financial resource requirements for APIs

DISP and FOS

Complaints handling and Ombudsman access where applicable

SCA and security

Strong Customer Authentication, secure payment execution and incident controls

Agents and outsourcing

Due diligence, registration, oversight and continued responsibility

Governance

Fit and proper management, effective systems, controls and risk management


A PI should not assume that every FCA Handbook sourcebook applies in the same way as it does to a mainstream FSMA investment firm. Payment Institutions sit within a specialist statutory regime under the PSRs, with selected Handbook provisions applied through FCA rules and guidance. Compliance mapping therefore needs to begin with the PSRs and the FCA's March 2026 Payment Services and Electronic Money Approach, then add the Handbook requirements that apply to the firm's specific status and activities.


The Payment Services Regulations remain the core legal framework

The Payment Services Regulations 2017 govern authorisation, registration and the provision of regulated payment services in the UK. An API must continue satisfying requirements relating to governance, internal controls, financial resources, safeguarding, security and the suitability of persons responsible for managing the business. Material changes to the business can therefore affect whether the firm continues to meet the conditions on which the FCA granted authorisation.


The PSRs also contain conduct requirements governing the relationship between Payment Service Providers and users. Depending on the service and customer type, these can cover information requirements, consent, execution, value dating, charges, unauthorised transactions and liability. Firms should therefore map conduct obligations to the actual customer journey rather than treating the PSRs solely as an authorisation statute.

The FCA's approach document is particularly important because it explains how the regulator interprets the statutory framework in practice. Compliance teams should use the current version rather than historical guidance written before the May 2026 safeguarding reforms. Policies and monitoring should be refreshed when the FCA materially updates its interpretation.


CASS 15 now governs the detailed safeguarding framework

Payment Institutions required to safeguard relevant funds must comply with regulation 23 of the PSRs and the detailed FCA rules in CASS 15. The regime requires firms to identify relevant funds correctly, maintain appropriate segregation or other permitted safeguarding arrangements, keep adequate records and perform internal and external safeguarding reconciliations at least once each reconciliation day. These requirements are now central to post-authorisation compliance.


A safeguarding framework should begin with the actual flow of customer money. The firm needs to know when money becomes relevant funds, which entity receives it, where it is held, how fees and pending transactions are treated and when the safeguarding obligation ends. This becomes particularly important for card acquiring, remittance, prefunding, agent networks and business models where payment flows pass through several accounts or providers.


The reconciliation process should independently establish what the firm owes customers and compare that with the safeguarding resource available. Exceptions, shortfalls and unexplained differences need investigation and documented resolution rather than manual adjustment simply to make the numbers agree. Board or senior management reporting should identify recurring issues and their root causes.


REP027 creates monthly safeguarding reporting

Since 7 May 2026, relevant payment and e-money firms submit monthly safeguarding information through REP027. The return gives the FCA much more regular visibility over the amount of relevant funds, safeguarding arrangements and key aspects of the firm's control environment. This means data quality and consistency between internal records, reconciliations and regulatory reporting have become more important.


Firms should document how each REP027 data item is derived and who owns the underlying source data. Where adjustments are required, the rationale should be recorded and reviewed before submission. Repeated differences between REP027 and management information can indicate weaknesses in the underlying safeguarding methodology or data architecture.


Regulatory reporting should therefore not be treated as a separate compliance function. The figures submitted to the FCA should be reconcilable to the same operational records used to run the business and perform safeguarding calculations. BCC's detailed guide to FCA regulatory reporting for payment and e-money firms explains the principal returns in more detail.


Safeguarding audits are now a direct supervisory information source

SUP 3A introduces a mandatory annual safeguarding audit for relevant authorised Payment Institutions and e-money institutions that do not qualify for the applicable exemption. The audit is a reasonable assurance engagement and considers whether the firm maintained systems adequate to comply with the relevant funds regime throughout the period and whether it complied at period end. Individual breaches identified during the audit are also reported in the prescribed breaches schedule.


An audit therefore tests much more than the year-end safeguarding account balance. Daily reconciliation evidence, account structures, relevant-funds methodology, third-party due diligence, resolution packs, governance and breach management can all become part of the audit trail. Firms should maintain audit readiness continuously rather than reconstructing evidence at the end of the year.


Where an audit identifies weaknesses, the board should understand both the immediate breach and its underlying cause. Remediation should be tracked to completion and retested, with FCA notification considered where required. BCC's safeguarding work supports firms before and after the independent audit while preserving the auditor's required independence.


Consumer Duty applies where retail payment services are in scope

The Consumer Duty applies to relevant retail payment products and services and requires firms to deliver good outcomes across products and services, price and value, consumer understanding and consumer support. Payment firms should identify which customer populations and services fall within scope and avoid applying the Duty mechanically to wholly out-of-scope business. Where the Duty applies, it should be integrated into product governance and compliance monitoring rather than maintained as a standalone annual exercise.


For a payment firm, customer outcomes can be affected by fees, foreign exchange margins, failed payments, fraud handling, account restrictions, complaints, withdrawal processes and customer support. Outcome monitoring should therefore use operational data that reveals what customers actually experience. The FCA's 2026 payments priorities identify pricing transparency and consumer outcomes as continuing areas of focus.

The annual Consumer Duty board assessment should be evidence-based. Senior management should understand where outcomes differ by customer group, product or distribution channel and what action the firm took in response. A board pack dominated by policy statements without operational evidence provides limited assurance.


Payment pricing and foreign exchange transparency need particular attention

Cross-border payment firms often earn revenue through a combination of explicit transaction fees and foreign exchange margins. Consumer Duty and payment-services conduct requirements mean firms should consider whether customers understand the total economic cost of the transaction rather than only whether individual fees are disclosed somewhere. The customer's decision should be supported by information that is timely, clear and not misleading.


The FCA has repeatedly highlighted international payment pricing as an area where firms can improve transparency. Firms should review how rates are presented, whether comparisons use appropriate reference points and whether marketing claims such as "zero fee" create a misleading impression where revenue is embedded in the exchange rate. Testing should focus on the overall customer journey and not just the legal wording of the terms.


Pricing governance should also consider business customers where Consumer Duty does not apply but PSR information and contractual requirements remain relevant. The regulatory framework should therefore identify which conduct obligations apply to each customer category rather than using one retail disclosure model for every payment user.


Financial crime controls must reflect the payment business

Payment Institutions are exposed to money laundering, fraud, sanctions evasion, mule activity and other financial crime because they sit directly in the movement of funds. The framework should begin with a business-wide risk assessment covering customers, products, jurisdictions, delivery channels and transaction flows, then use that assessment to design due diligence, enhanced due diligence, transaction monitoring, sanctions controls and investigation processes. Generic AML documentation that could apply to any fintech will not demonstrate that the firm understands its own risk.


The FCA's Financial Crime Guide notes an important legal nuance for payment and e-money firms: not every FCA Handbook financial crime provision applies in the same way as it does to FSMA firms, but the FCA supervises relevant firms for compliance with the Money Laundering Regulations and expects robust governance, risk procedures and internal controls. The practical compliance standard therefore remains demanding. Firms should map the legal source of each obligation accurately rather than overstating or understating Handbook application.


Transaction monitoring should reflect the firm's payment flows and evolve with the business. Remittance corridors, merchant acquiring, payment accounts and B2B international payments create different typologies and need different scenarios and thresholds. Alert backlogs, weak calibration and incomplete data feeds can undermine the effectiveness of an otherwise sophisticated system.


Fraud and mule-account controls should connect with AML

Fraud and AML risks frequently overlap in payments. A customer account used to receive APP fraud proceeds may begin as a fraud issue but immediately create money laundering concerns when the funds are moved onward. Firms that run separate fraud and AML teams should therefore ensure relevant intelligence can be shared and escalated across both functions.


Onboarding data, device information, linked beneficiaries, transaction velocity and behavioural changes can all assist with mule detection. Controls should be proportionate to the firm's position in the payment chain and the types of accounts or services it provides. Management information should show trends and recurring patterns rather than only the number of alerts closed.


Fraud controls should also be connected to customer support and complaints. Delaying or blocking a payment can protect a customer but can also create harm where the process is opaque or excessively slow. Governance should therefore balance prevention, regulatory requirements and fair customer treatment.


Strong Customer Authentication and secure payment execution

The PSRs and associated regulatory technical standards contain security and Strong Customer Authentication requirements for relevant electronic payments. Firms need to understand when SCA applies, when an exemption can be used and how authentication, transaction-risk analysis and fraud controls interact. A customer journey should not rely on an exemption simply because it improves conversion if the regulatory conditions are not met.


Security incidents and authentication failures should feed into operational and fraud risk management. Firms should monitor whether exemptions produce materially higher fraud, whether customer authentication fails disproportionately for particular groups and whether third-party technology remains reliable. Changes to authentication logic should be controlled and tested before release.


The future UK payments reform programme may change parts of the framework, but current requirements continue to apply until legislation or FCA rules are formally changed. Compliance teams should distinguish proposed reform from live obligations and maintain horizon scanning accordingly.


Operational resilience is a continuing requirement

Payment services are highly dependent on technology, banks, processors, cloud services and other third parties, making operational resilience a core compliance issue. Firms within the formal FCA operational resilience regime should maintain their important business services, impact tolerances, mapping, scenario testing and remediation in accordance with SYSC 15A. The FCA's 2026 observations emphasise that the framework should continue evolving after the March 2025 transition deadline.


Even where a particular firm falls outside a formal rule, the PSRs still require appropriate governance, security and operational arrangements. Payment firms should therefore understand critical dependencies, recovery capability, customer impact and incident escalation regardless of the precise sourcebook classification. A business continuity plan alone is not enough where the firm has never tested whether it can maintain critical payment services during a major provider outage.


The FCA's new operational incident and material third-party reporting framework takes effect in March 2027 for firms within scope. Firms should use 2026 to map current reporting processes and ensure that governance, data capture and escalation can meet the future requirements without confusing them with existing payment incident obligations.


Outsourcing and important operational functions require active oversight

The PSRs contain requirements around outsourcing important operational functions, and the FCA's approach document explains that material changes to important outsourcing can be relevant to continued compliance with authorisation conditions. Firms should therefore identify which providers perform important functions and ensure due diligence, contracts, oversight and exit planning are proportionate to the dependency. Outsourcing does not transfer regulatory responsibility to the supplier.


Payment institutions commonly depend on sponsor banks, processors, card platforms, cloud providers, KYC vendors and technology infrastructure. The compliance framework should understand not only the direct supplier but material concentration or sub-outsourcing where several critical services depend on the same underlying provider. A supplier inventory becomes useful only when management understands the risk represented by each dependency.


Ongoing oversight should use performance and risk information, not only annual questionnaires. Operational incidents, service deterioration, security issues and regulatory changes should trigger reassessment where necessary. Contractual rights should support audit, information access, business continuity and an orderly exit.


APIs must maintain ongoing capital and financial resources

Authorised Payment Institutions are subject to initial and ongoing capital requirements. The initial capital floor depends on the payment services provided, with current requirements of EUR 20,000 for money remittance, EUR 50,000 for payment initiation and EUR 125,000 for the broader payment services in the highest capital category. Ongoing own funds can exceed those initial amounts as the business grows.


The FCA also expects appropriate enterprise risk management, liquidity and wind-down planning. Its multi-firm review of e-money and payment firms found significant weaknesses in those areas, showing that mechanical compliance with a minimum capital formula does not by itself demonstrate financial resilience. Boards should understand what could cause the business to fail and how much cash and capital would be needed to continue operating or exit in an orderly manner.


Financial forecasts should therefore be connected to regulatory capital and liquidity monitoring. Growth, lower revenue, higher compliance expenditure or loss of a banking partner can change the firm's financial position quickly. Thresholds and escalation triggers should be defined before financial resources become critical.


Governance and senior management remain central even where SMCR mapping differs

Payment Institutions must have robust governance, effective risk procedures and adequate internal controls, with fit and proper persons responsible for management. Firms should be careful about assuming that the ordinary solo-regulated FSMA SMCR framework applies automatically simply because they are authorised as PIs under the PSRs. The precise SMCR position depends on the firm's wider regulatory status and permissions and should be checked rather than stated generically.


Regardless of that classification, the FCA expects clear individual ownership of compliance, safeguarding, financial crime, risk and operational responsibilities. Board minutes and management information should demonstrate active oversight, challenge and remediation. Nominal appointments without the time, competence or authority to discharge the role create regulatory risk even where formal job titles appear correct.


Where the firm also holds FSMA permissions or falls into another regime that brings SMCR into scope, the additional Senior Manager, Certification and Conduct Rules requirements should be mapped explicitly. The compliance framework should therefore follow the legal entity's complete regulatory profile rather than one licence label.


Complaints and the Financial Ombudsman Service

Payment firms must operate appropriate complaints procedures under the applicable DISP and payment-services framework, with Financial Ombudsman access for eligible complainants. Complaints can involve execution errors, account restrictions, fraud, exchange rates, fees, customer support or the handling of unauthorised transactions. Firms should use complaints as a source of regulatory intelligence rather than treating them only as customer-service cases.


Root-cause analysis should identify whether the same process or product feature affects a wider customer population. Where systemic harm is identified, remediation may need to extend beyond customers who complained. Consumer Duty reinforces this approach for in-scope retail business by requiring firms to monitor and act on poor outcomes.


Complaint data should be integrated with operational incidents, fraud and Consumer Duty MI. A rise in account-closure complaints may indicate a financial crime control issue, while repeated failed-payment complaints may expose operational resilience weaknesses. Connected governance produces more useful regulatory insight than separate dashboards owned by different departments.


Agents remain the PI's responsibility

Payment Institutions can provide services through registered agents, but the principal remains responsible for the regulated payment services carried on through them. Appointment should therefore include appropriate due diligence on ownership, management, competence, financial crime risk and the activities the agent will perform. The agent should operate only within the scope registered with the FCA and permitted by the principal's own authorisation.


Ongoing monitoring should consider complaints, transaction patterns, CDD quality, financial promotions, training and other indicators of risk. A network can become difficult to supervise where growth outpaces the principal's compliance resources, so governance should consider both the risk of individual agents and the aggregate scale of the network. Material weaknesses should lead to remediation, restriction or termination where appropriate.

Where agents collect customer information or perform elements of due diligence, the PI should retain access to records and assurance over the quality of the process. Delegating the operational step does not remove the principal's accountability for the regulated service.


Regulatory reporting is an ongoing governance obligation

Payment Institutions submit a range of FCA returns depending on status and permissions, covering matters such as capital, payment services activity, fraud, operational risk and safeguarding. The exact reporting schedule should be maintained in a regulatory obligations register with responsible owners and internal review before submission. Returns should be derived from controlled data sources and reconciled to financial and operational records where appropriate.


The FCA increasingly uses data to target supervisory attention, so inaccurate or inconsistent reporting can create risk beyond the immediate filing error. Repeated corrections may indicate weaknesses in governance or systems and can undermine confidence in the information the firm provides. Senior management should understand material returns rather than treating regulatory reporting as an administrative task performed only by compliance.


Event-driven notifications are equally important. Significant operational incidents, material business changes, changes to important outsourcing or circumstances affecting authorisation conditions can require engagement with the FCA outside the regular reporting cycle. Escalation procedures should help staff identify when an issue may have regulatory significance.


Compliance monitoring should test how the firm really operates

A PI compliance monitoring programme should be based on its permissions, risks and actual transaction model. Safeguarding, financial crime, Consumer Duty, payment conduct, complaints, agents, outsourcing, operational resilience, regulatory reporting and capital should be tested at a frequency proportionate to risk. The programme should not consist only of annual policy reviews because many of the most serious weaknesses arise in operational execution.


Testing should use real data and transactions. A safeguarding reconciliation can be reperformed, transaction-monitoring alerts can be sampled, complaints can be traced to root causes and regulatory returns can be reconciled to source systems. This produces evidence about control effectiveness rather than merely confirming that a documented procedure exists.


Findings should be prioritised and retested. Where the same issue recurs, management should investigate the design of the underlying process rather than repeatedly correcting individual cases. Board reporting should show whether remediation has reduced the risk materially.


How Buckingham Capital Consulting can help

Buckingham Capital Consulting has specialised in UK and European payment regulation since 2013 and provides payment and e-money compliance support to authorised and registered firms. We can conduct complete or targeted reviews covering PSR compliance, CASS 15 safeguarding, Consumer Duty, financial crime, operational resilience, capital, governance, agents, outsourcing, regulatory reporting and complaints. The review is built around the firm's actual products, payment flows and customer base rather than a generic PI checklist.


We also support firms with remediation following FCA supervisory engagement, audit findings or internal reviews. This can include redesigning safeguarding and reconciliation processes, strengthening financial crime controls, improving regulatory reporting, updating governance and management information and preparing regulatory responses. Where a business is expanding or changing its activities, we can assess whether a Variation of Permission or other FCA engagement is required.


For firms entering the market, BCC manages complete Authorised Payment Institution applications as well as ongoing compliance after authorisation. To discuss a PI compliance review, remediation programme or regulatory change project, contact Buckingham Capital Consulting.


Frequently asked questions

What regulations apply to a UK Payment Institution?

The principal framework is the Payment Services Regulations 2017, supported by the FCA's payment-services approach and applicable Handbook rules. Depending on the firm, this includes CASS 15, SUP 3A, SUP 16, Consumer Duty, complaints, financial crime, operational resilience and capital requirements. The exact obligations depend on whether the firm is an API or SPI and which payment services it provides.


What changed for Payment Institutions on 7 May 2026?

The FCA's strengthened safeguarding regime took effect, bringing detailed CASS 15 requirements into force. Relevant firms now operate under enhanced record keeping, daily internal and external safeguarding reconciliations, resolution-pack requirements, monthly REP027 reporting and, for firms above the applicable exemption threshold, annual safeguarding audits. These rules should now be treated as business-as-usual controls rather than an implementation project.


Does Consumer Duty apply to Payment Institutions?

It applies to relevant retail products and services within scope. Payment firms should assess which customers and services are covered and then monitor products, value, understanding and support using evidence of actual outcomes. The Duty does not replace the PSRs or other payment-specific rules.


Are Payment Institutions subject to SMCR?

A PI should not assume that the standard solo-regulated FSMA SMCR automatically applies solely because it is authorised under the PSRs. The position depends on the firm's complete regulatory status and any additional permissions or classifications. The PI must nevertheless maintain robust governance, fit and proper management and clear ownership of compliance responsibilities.


How often should a Payment Institution carry out a compliance review?

There is no single interval that replaces ongoing compliance monitoring. Firms should maintain a risk-based programme throughout the year and increase testing where products, volumes, agents or risks change. An independent annual or periodic review can provide useful assurance, particularly before safeguarding audits, FCA engagement or significant business expansion.


#FCA Compliance for UK Payment Institutions 2026: Complete Guide

 
 
bottom of page