FCA Regulatory Priorities for Payment Firms 2026: What Boards and Compliance Teams Should Focus On
- Jul 7
- 17 min read

FCA Regulatory Priorities for Payment Firms 2026: What Boards and Compliance Teams Should Focus On
The FCA has set out its regulatory priorities for UK payment and electronic money firms for 2026, providing one of the clearest indications of where supervisory attention will be directed over the coming year.
For Payment Institutions and Electronic Money Institutions, the priorities go considerably beyond technical compliance with the Payment Services Regulations 2017 or Electronic Money Regulations 2011. The FCA is focusing on whether firms have effective governance and financial crime controls, protect customer money properly, implement the Consumer Duty where applicable, maintain sufficient financial and operational resilience and prepare for substantial changes to the UK payments regulatory framework.
The regulatory environment is also changing quickly. CASS 15 and the strengthened safeguarding regime took effect on 7 May 2026, new operational incident reporting requirements take effect in March 2027, HM Treasury is consulting on a major modernisation of payment services regulation, and the FCA is developing the future regulatory treatment of Open Banking, stablecoins and agentic payments.
Boards and compliance teams should therefore use the FCA’s 2026 priorities as more than a regulatory reading list. They provide a practical framework for deciding where governance, compliance monitoring and remediation should be concentrated during the remainder of 2026 and into 2027.
FCA payment sector priorities at a glance
FCA priority | What payment and e-money firms should focus on |
Preparing for the future | Regulatory reform, Open Banking, stablecoin payments, agentic payments and authorisation readiness |
Consumer Duty | Product outcomes, pricing transparency, vulnerable customers and ongoing monitoring |
Financial system integrity | Financial crime, fraud, governance, systems and controls and operational resilience |
Keeping customer money safe | CASS 15, safeguarding reconciliations, audits, financial resilience and wind-down planning |
Authorisation standards | Senior management competence, governance and adequate systems and controls |
Operational resilience | Incident management, third-party dependencies and preparation for March 2027 reporting changes |
The FCA’s priorities are interconnected. Weak governance can lead to poor safeguarding, ineffective financial crime controls, inadequate Consumer Duty monitoring and poor operational resilience. Firms should therefore avoid treating each regulatory requirement as an isolated compliance project.
The FCA has changed how it communicates its supervisory priorities
In 2026, the FCA introduced annual Regulatory Priorities reports as a new sector-specific approach to communicating its expectations, replacing the traditional portfolio-letter model. The payments report applies broadly to firms authorised or registered under the Payment Services Regulations and Electronic Money Regulations and sets out both what the FCA expects firms to do and where it intends to direct supervisory attention.
This matters because the document should be read as a forward-looking supervisory signal rather than simply a policy summary. The FCA has identified areas where it believes weaknesses continue to exist across the payments sector and has made clear that it will assess firms against those expectations.
The regulator is also moving towards more proactive and targeted supervision. Firms should assume that regulatory returns, safeguarding audit findings, complaints data, financial crime intelligence, incident notifications and other regulatory information can increasingly be used together to identify firms presenting elevated risk.
A board that waits for a direct FCA information request before assessing these areas is therefore taking an unnecessary risk. The better approach is to compare the firm’s current framework against the FCA’s published priorities and address significant gaps before they become supervisory issues.
The FCA’s 2026 Regulatory Priorities: Payments report provides the regulator’s full sector assessment.
Priority 1: preparing for major changes to UK payment regulation
The UK payments framework is entering a period of significant reform.
HM Treasury published its consultation on modernising payment services regulation in July 2026. The proposals consider the future structure of the Payment Services Regulations and Electronic Money Regulations, the role of the FCA Handbook, changes to regulated payment activities and how emerging models such as stablecoins, tokenised payments and agentic payments should fit within the framework.
The FCA’s expectation is not that firms predict the final rules before they exist. It is that firms remain informed, engage with regulatory change and ensure their businesses are capable of adapting when requirements change.
This is particularly important for firms planning new products or significant technology investment. A PI or EMI developing a stablecoin payment product, AI-driven payment agent or new Open Banking service should consider how the regulatory direction may affect permissions, customer consent, authentication, liability, safeguarding and governance before the product becomes technically or commercially difficult to change.
Existing firms should also consider whether future changes could affect their permission profile. The Government is examining how regulated payment activities should be organised and how firms moving into tokenised payment services may need to interact with the FCA permissions framework.
Our guide to UK Payment Services Regulation 2026 explains the wider direction of these reforms and what they could mean for existing PIs, EMIs and new market entrants.
Regulatory change should be owned at board level
Regulatory horizon scanning is often delegated almost entirely to compliance. That is not sufficient where reform can affect the fundamental business model. Changes involving stablecoins, Open Banking, agentic payments or the future structure of payment permissions can affect technology strategy, partnerships, capital allocation and product design. These are board and executive decisions as much as compliance matters.
Firms should maintain a structured regulatory-change process that identifies significant developments, assesses whether they affect the business and assigns responsibility for implementation. The process should distinguish between consultations, final rules and requirements already in force so that management attention is proportionate to the stage of development.
The board should receive enough information to understand the commercial and regulatory consequences. A long list of regulatory publications is less useful than a concise assessment explaining what has changed, which parts of the business are affected, what decisions are required and by when. The pace of payments reform during 2026 makes this discipline increasingly important.
Priority 2: Consumer Duty remains an active supervisory issue
The FCA has made clear that implementation of the Consumer Duty remains a priority for payment and e-money firms where the Duty applies.
The regulator expects firms to assess products, services and processes against the relevant Duty requirements on an ongoing basis rather than treating implementation as a completed project. Where evidence identifies poor outcomes or control gaps, firms are expected to address them promptly.
For payment firms, the FCA has highlighted particular concerns around international payment pricing transparency and the treatment of consumers in vulnerable circumstances. These areas are commercially significant because pricing models involving exchange-rate margins, transfer fees and intermediary charges can make it difficult for customers to understand the true cost of a transaction.
The regulatory question is not simply whether individual fees have been disclosed somewhere in the customer journey. Firms should consider whether the overall information enables customers to understand what they are paying and make informed comparisons. This is especially relevant to remittance firms, multi-currency wallets and cross-border payment providers whose revenue may combine explicit charges with foreign exchange spreads.
Consumer Duty monitoring needs evidence
Boards should be cautious about relying on policy documents as evidence that Consumer Duty is working.
The FCA expects firms to monitor customer outcomes. For a payments business, this can involve analysing complaints, transaction failures, customer support interactions, pricing outcomes, service availability, fraud cases, vulnerable-customer journeys and other data capable of showing whether customers are experiencing foreseeable harm.
Management information should be useful enough to drive decisions. A dashboard showing that complaint volumes are “green” provides limited assurance if it does not identify why customers complain, whether certain products or customer groups experience worse outcomes and whether recurring issues are being addressed.
The Duty should also be considered during product development and material product changes. A new payment feature should not pass through commercial and technology approval only to be reviewed by compliance shortly before launch. Product governance should build regulatory and customer-outcome considerations into the design process from the beginning.
International payment pricing remains a specific FCA concern
Cross-border payments remain an area of particular FCA attention. The FCA has previously identified weaknesses in how some payment firms communicate the cost of international payments. Customers may see an explicit transfer fee but have less visibility over the exchange rate applied, the margin embedded within that rate or other costs affecting the final amount received.
Firms should review customer journeys from the perspective of the person making the transaction rather than from the perspective of internal pricing systems. The question is whether the customer can understand the total economic cost sufficiently clearly before committing to the payment.
This does not require every pricing model to operate identically. It does require transparency that supports informed decision-making and does not create a misleading impression that a transfer is cheaper than it really is.
Boards of firms with significant remittance or FX activity should therefore ensure that pricing transparency is specifically included within Consumer Duty monitoring rather than assumed to be covered by general disclosure controls.
Priority 3: financial crime and fraud controls remain under scrutiny
The FCA continues to treat protection of financial system integrity as a core priority for the payments sector.
Payment firms can sit at critical points in the movement of money and may be exposed to money laundering, fraud, sanctions evasion, mule accounts and other forms of financial crime. The regulator expects effective governance, appropriate capability and systems and controls that identify, assess and mitigate these risks.
The FCA has also indicated that it will continue assessing firms’ governance and controls relating to financial crime and use supervisory and enforcement tools where firms consistently fail to meet expected standards.
This can include restrictions on higher-risk activity, formal remediation requirements and the appointment of independent skilled persons to review systems and controls. Financial crime weaknesses should therefore not be viewed solely as matters for the MLRO; they can affect the firm’s ability to continue growing or operating particular parts of its business.
The quality of the control framework should evolve with the firm. A transaction-monitoring system that was proportionate when a business processed £10 million annually may no longer be adequate when the same firm processes billions across multiple jurisdictions, products and customer types.
Financial crime controls should reflect the actual business model
Generic AML frameworks remain a recurring weakness across financial services. A payment firm should be able to explain how its financial crime risks arise from its specific customers, products, jurisdictions, delivery channels and transaction flows. The enterprise or business-wide risk assessment should then drive customer due diligence, enhanced due diligence, transaction monitoring, sanctions controls and management oversight.
This is particularly important for businesses exposed to higher-risk corridors, agents, nested payment relationships, cryptoasset on- and off-ramps or complex B2B payment chains. The FCA has also identified inadequate systems and controls, including financial crime controls, among the reasons some payment and e-money authorisation applications have been unsuccessful. New applicants should therefore demonstrate that the framework has been designed around the proposed business rather than relying on standard templates.
Existing firms should apply the same standard when their model changes. A new product, jurisdiction or distribution arrangement should trigger a reassessment of financial crime risk before launch.
APP fraud remains part of the supervisory agenda
Authorised Push Payment fraud remains a significant issue across the UK payments ecosystem. Although reimbursement obligations and payment-system rules involve several regulatory bodies and market participants, the FCA’s payments priorities make clear that firms are expected to contribute actively to reducing fraud and protecting financial system integrity.
For payment firms, this requires more than responding after fraudulent transactions have occurred. Fraud risk should be considered across onboarding, account monitoring, payment execution, customer communications and intelligence sharing.
Controls should also distinguish between different roles within the payment chain. A firm operating customer payment accounts faces different risks from a remittance provider or merchant acquirer, and the control framework should reflect where the firm can realistically prevent or detect harm. Governance should ensure that fraud data is analysed alongside AML information where the two overlap. Firms that separate fraud and financial crime functions too rigidly can miss patterns visible only when information is considered together.
Priority 4: operational resilience is becoming more important
The FCA expects payment firms to continue strengthening operational resilience. Payments are increasingly dependent on cloud infrastructure, core payment technology, banking partners, card processors, API providers and other third parties. A failure in one part of that chain can prevent customers from accessing money or completing time-sensitive transactions.
Firms should therefore understand which services are critical, what dependencies support them and how disruption would affect customers. Operational resilience should also be considered when designing new products rather than treated only as an IT recovery exercise after the product has launched.
The FCA’s new operational incident and third-party reporting rules were finalised in March 2026 and take effect on 18 March 2027. Payment service providers should use the implementation period to understand how the new regime interacts with their current incident-reporting obligations and ensure their processes, escalation criteria and reporting technology are ready.
The FCA’s operational incident reporting guidance explains the transition to the new framework.
Third-party dependency needs active governance
Many fintech payment firms operate highly outsourced models. Outsourcing itself is not a weakness. Specialist providers can improve technology, scalability and access to infrastructure, but the regulated firm remains responsible for its regulatory obligations. Boards should understand which third parties are critical to the firm, what would happen if they failed and whether credible alternatives exist. Contracts, data access, service monitoring and exit arrangements should support that understanding.
Concentration risk is particularly important where several critical services ultimately depend on the same provider or infrastructure. A firm may appear to use multiple vendors while still being exposed to one underlying cloud provider, sponsor bank or technology platform. Operational resilience should therefore map dependencies beyond the first contractual layer where they are material.
Priority 5: keeping customer money safe remains central
Safeguarding is one of the clearest supervisory priorities for payment and e-money firms in 2026.
The strengthened regime under PS25/12 and CASS 15 took effect on 7 May 2026. Firms within scope are now operating under requirements including daily safeguarding reconciliations, enhanced record keeping, third-party due diligence, monthly REP027 reporting, resolution-pack requirements and mandatory safeguarding audits for relevant institutions.
The FCA has stated that it will assess governance, oversight and systems and controls relating to safeguarding and financial resilience. It will also consider safeguarding audit outcomes and address problems identified through those audits.
For firms, the emphasis has therefore shifted from implementation to evidence. The question is no longer whether the organisation has produced a CASS 15 project plan; it is whether the new controls work consistently in day-to-day operations.
Our CASS 15 safeguarding services support firms with implementation, gap assessments, reconciliation frameworks, audit readiness and remediation.
Reconciliations are likely to remain a key supervisory indicator
Daily internal and external safeguarding reconciliations provide one of the clearest indicators of whether a firm understands and controls customer money.
Recurring breaks, unexplained manual adjustments or delays in correcting shortfalls can reveal broader weaknesses in data, systems and governance. Firms should therefore monitor reconciliation trends rather than simply checking whether each daily process was marked complete.
Management should understand why breaks arise and whether the same root causes recur. A firm that repeatedly fixes individual discrepancies without addressing the underlying process is unlikely to demonstrate a robust control framework.
The reconciliation process should also connect to REP027, management information and safeguarding audit evidence. Different regulatory processes should not produce inconsistent versions of the same underlying safeguarding position.
Where systems cannot generate reliable daily data without significant manual intervention, boards should consider whether investment is required before transaction volumes or complexity increase further.
Safeguarding audit findings will give the FCA more visibility
The mandatory safeguarding audit regime creates a new supervisory information source for the FCA.
Auditors provide reasonable assurance on whether relevant institutions maintained adequate systems throughout the audit period and whether they complied with the safeguarding regime at period end. Individual regulatory breaches identified during the audit are also recorded in the required breaches schedule.
The FCA has acknowledged that stronger standards may initially result in more adverse audit findings. Firms should not interpret this as permission to tolerate weaknesses; rather, it reflects the regulator’s expectation that the new regime will expose issues that previously remained unidentified. Boards should therefore prepare for the possibility that audit findings generate direct regulatory scrutiny. The quality and speed of remediation will matter alongside the underlying finding.
Our guide to Safeguarding Audits under CASS 15 explains the areas firms should prepare before their first audit under the strengthened regime.
Priority 6: financial resilience and wind-down planning remain weak across the sector
The FCA has repeatedly highlighted weaknesses in risk management and wind-down planning among payment and e-money firms. In its multi-firm review, the regulator found that none of the firms reviewed fully met its expectations. Areas requiring improvement included enterprise-wide risk management, liquidity risk management and the treatment of risks arising from wider corporate groups.
The practical concern is that a regulated payments business can appear financially healthy during normal conditions but still fail quickly when transaction volumes fall, a major partner exits, liquidity becomes constrained or a significant operational event occurs.
Risk management should therefore connect directly to financial resources and wind-down planning. Firms should identify material risks, quantify stress where possible and understand what level of resources is needed both to continue operating and to execute an orderly exit if necessary.
A wind-down plan should not be a static document produced for authorisation and then updated annually by changing dates. It should reflect the current business, current cost base, current dependencies and credible triggers for deciding when wind-down must begin.
Group risk deserves particular attention
Many payment firms sit within wider fintech groups. The regulated PI or EMI may depend on its parent or affiliates for capital, technology, staff, marketing, intellectual property or operational support. These relationships can create material risk if the wider group encounters financial or operational difficulty. The FCA expects regulated firms to understand these dependencies and assess whether the resources they rely on would remain available during stress.
A parent-company commitment to provide funding is not equivalent to cash or capital already available to the regulated entity. Similarly, a group technology platform may become a critical vulnerability if the PI or EMI has no realistic ability to continue operating when another group company fails. Boards should therefore consider risk at the level of the regulated firm rather than assuming that strength elsewhere in the group automatically protects it.
The authorisation gateway remains a regulatory priority
The FCA continues to place significant emphasis on standards at the point of authorisation.
Its payments priorities highlight senior management competence and inadequate systems and controls, including financial crime controls, as areas that have contributed to unsuccessful applications.
This is important for both new applicants and existing firms seeking to expand permissions. The FCA expects a business to demonstrate that it is ready to operate compliantly rather than presenting authorisation as permission to begin building the regulatory framework.
Applicants should therefore ensure that the governance structure, business plan, financial forecasts, safeguarding arrangements, financial crime framework and operational systems tell one consistent story.
A strong application is not simply one that contains every document on a checklist. The FCA needs to understand who will run the firm, how the business will operate, what risks it creates and whether the people, systems and financial resources are adequate for the proposed scale.
Buckingham Capital Consulting supports businesses seeking Authorised Payment Institution and Electronic Money Institution authorisation, including the complete regulatory application and supporting framework.
Open Banking remains a strategic growth priority
The FCA continues to support the expansion of UK Open Banking and the development of a long-term regulatory framework. The next phase includes work around the future Open Banking entity, commercial models for variable recurring payments and the broader development of Open Finance. These changes are intended to move Open Banking beyond its original account-information and payment-initiation framework into a more sustainable commercial ecosystem.
For existing PISPs, AISPs, banks and fintech firms, the opportunity is significant, but regulatory responsibilities remain important. Customer consent, authentication, data security, operational resilience and allocation of responsibility across multiple providers all need to work as new use cases expand.
Firms should also consider whether new commercial models alter their regulatory perimeter or permission requirements. Open Banking should therefore be treated as both a growth opportunity and a regulatory change programme.
Stablecoins and tokenised payments are moving closer to mainstream payments regulation
Stablecoins are no longer being considered solely as a cryptoasset issue. The FCA and Government are examining how stablecoins and other tokenised forms of money can be integrated into regulated payments. The FCA’s payments priorities specifically identify this as an area of development, while HM Treasury’s July 2026 consultation considers how the future payment-services framework should accommodate tokenised payment instruments.
For existing PIs and EMIs, this could create significant opportunities to provide fiat payment services, conversion, settlement or payment-account functionality around stablecoin products. It can also create new regulatory questions where the same business model combines cryptoasset activities with regulated payment services.
Firms should map those activities carefully before launching. A cryptoasset permission does not automatically cover payment services, just as an EMI or PI permission does not automatically authorise every stablecoin activity.
The regulatory structure should follow the complete customer journey and flow of funds.
Agentic payments are now part of the regulatory agenda
The FCA’s 2026 payments priorities expressly recognise agentic AI payments as an area where future regulation may need to evolve. AI agents capable of selecting products, initiating transactions or acting autonomously within customer-defined mandates create new questions around consent, authentication, liability and payment initiation.
For payment firms, the immediate requirement is to comply with the current regulatory framework while monitoring how the future rules develop. Existing payment law does not cease to apply simply because an AI system performs part of the transaction journey.
Firms experimenting with agentic payments should therefore involve regulatory and risk functions early. Product architecture can determine whether the business is providing a regulated payment service and how responsibility is allocated when an autonomous system acts on behalf of a customer.
The FCA’s inclusion of agentic payments within its future priorities indicates that this will become a significant regulatory issue rather than remaining a purely technological development.
What should boards prioritise during the remainder of 2026?
Boards should begin with an honest assessment of where the firm is most exposed against the FCA’s priorities. The objective is not to create another compliance checklist but to identify areas where weaknesses could cause customer harm, regulatory intervention or threaten the sustainability of the business.
For many firms, safeguarding should remain near the top of the agenda because the strengthened regime is now live and the first audit cycle is beginning. Boards should understand whether daily reconciliations are reliable, whether REP027 reporting is consistent with underlying records and whether known weaknesses have credible remediation plans.
Financial crime, Consumer Duty and operational resilience should then be assessed against current evidence rather than policy documents. Management information should show whether controls are producing the intended outcomes and whether recurring issues are being escalated appropriately.
Finally, boards should consider future readiness. Payment regulation is being redesigned at the same time that stablecoins, Open Banking and AI are changing how payments are delivered. Firms that treat regulatory change as a strategic issue will be better placed to adapt than those waiting for each final rule before considering the impact.
A practical 2026 regulatory review
A useful regulatory review should connect the FCA’s priorities to the firm’s actual business model. The review should consider whether governance remains appropriate for the current scale of the firm, whether financial crime controls reflect its products and customer base, and whether Consumer Duty monitoring identifies real customer outcomes. Safeguarding, liquidity, financial resources and wind-down should be reviewed together because weaknesses in one area can quickly create problems in another.
Operational resilience should examine the firm’s real dependencies, including outsourced providers, banks, processors and group entities. The review should also identify what needs to change before the March 2027 incident-reporting regime and other forthcoming reforms take effect.
Regulatory horizon scanning should then translate future developments into decisions. The July 2026 HM Treasury consultation on modernising payment services regulation is particularly important for firms planning products involving stablecoins, tokenised payments, Open Banking or agentic payments. The output should be a prioritised remediation and change plan owned by senior management, with clear deadlines and board oversight.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting specialises in UK and European payment and electronic money regulation and has advised fintechs, Payment Institutions and Electronic Money Institutions since 2013.
We support existing regulated firms with FCA compliance, regulatory gap assessments, safeguarding and CASS 15 reviews, financial crime frameworks, risk management, wind-down planning, governance, regulatory reporting and preparation for FCA supervisory engagement.
A regulatory priorities review can assess the firm against the FCA’s 2026 expectations and identify material gaps across governance, Consumer Duty, financial crime, operational resilience, safeguarding and financial resilience. We then provide a prioritised remediation plan focused on the areas most likely to create regulatory or customer risk.
We also support firms developing new products or changing their regulatory model, including Variation of Permission applications, stablecoin and tokenised payment structures, Open Banking services and wider payment regulatory strategy.
For new market entrants, we manage complete API and EMI authorisation projects from initial regulatory structuring through business plans, financial forecasts, governance, policies and FCA engagement.
To discuss an FCA compliance review, regulatory remediation project or payment-services authorisation, contact Buckingham Capital Consulting.
Frequently asked questions
What are the FCA’s main priorities for payment firms in 2026?
The FCA’s core payments priorities cover preparing for future regulatory change, effective implementation of the Consumer Duty where applicable, protecting financial system integrity and keeping customer money safe. In practice, this means particular attention to governance, financial crime, fraud, operational resilience, safeguarding, financial resilience, wind-down planning and readiness for changes to UK payments regulation.
Is safeguarding still a major FCA priority after CASS 15 took effect?
Yes. The focus has shifted from preparing for implementation to demonstrating that the regime works in practice. The FCA intends to assess safeguarding governance and controls, consider safeguarding audit outcomes and take action where firms consistently fail to meet expected standards.
What should payment firms do about the new operational incident reporting rules?
The new FCA operational incident reporting framework takes effect on 18 March 2027. Firms should use 2026 to assess their incident-identification, escalation, data and reporting processes and understand how the new framework changes current reporting obligations for payment service providers.
What financial crime issues is the FCA focusing on in payments?
The FCA is focusing on effective governance, financial crime systems and controls, money laundering and fraud, including APP fraud. Firms should ensure their risk assessments, due diligence, transaction monitoring and fraud controls reflect their actual business model and have evolved with changes in customers, products, jurisdictions and transaction volumes.
How should boards use the FCA’s 2026 Payments Regulatory Priorities?
Boards should use the priorities as a framework for assessing whether the firm’s current controls and resources remain appropriate. The review should focus on evidence of actual outcomes rather than policies alone, identify material weaknesses and create a prioritised remediation plan covering current compliance and forthcoming regulatory change.



