FCA Regulatory Reporting for Payment and E-Money Firms 2026: What PIs and EMIs Must Submit
- 5 days ago
- 13 min read

FCA Regulatory Reporting for Payment and E-Money Firms 2026: What PIs and EMIs Must Submit
Regulatory reporting is one of the areas where Payment Institutions and Electronic Money Institutions can appear compliant on paper while exposing themselves to avoidable FCA risk in practice. The issue is rarely whether a firm knows that a return is due. More often, problems arise because the data submitted does not reconcile with finance records, safeguarding calculations, transaction systems or management information.
The reporting framework for PIs and EMIs has also become more demanding. Alongside established prudential, fraud and operational-risk returns, firms within scope of the new safeguarding regime must now submit monthly safeguarding information to the FCA, giving the regulator much greater visibility over customer funds and the way firms operate their safeguarding arrangements.
For compliance teams and senior management, regulatory reporting should therefore be treated as part of the firm’s control framework rather than an administrative filing exercise. The FCA uses reported data to understand a firm’s business model, financial resources, transaction volumes, safeguarding position, fraud exposure and operational risk, and inconsistencies can lead to supervisory questions even where every return was submitted on time.
What regulatory returns do Payment Institutions and EMIs need to submit?
The exact FCA regulatory reporting obligations for payment and E-money firms depend on the type of firm, the permissions it holds and the activities it carries on. An Authorised Payment Institution does not have exactly the same reporting schedule as an Authorised Electronic Money Institution, and additional returns can apply where the firm provides Open Banking services, safeguards customer funds or falls within financial crime reporting requirements.
The principal returns for payment and e-money firms can include the following:
Return | Main purpose | Typical firms in scope |
FSA056 | Capital adequacy and regulatory information | Authorised Payment Institutions |
FSA057 | Payment activity and registration information | Small Payment Institutions |
FIN060 | E-money and payment activity, financial and prudential information | Authorised and Small Electronic Money Institutions |
FSA065 | Total outstanding electronic money | Small Electronic Money Institutions |
REP027 | Monthly safeguarding information | Firms subject to or opting into the safeguarding regime |
REP017 | Payment transaction and fraud data | Relevant payment service providers |
REP018 | Operational and security risk assessment | Relevant payment service providers |
REP020 | Availability and performance of payment interfaces | Relevant account servicing payment service providers |
REP-CRIM | Annual financial crime information | Firms meeting the applicable reporting criteria |
This is not an exhaustive list. Other reporting and notification obligations can apply depending on the firm’s structure, controllers, close links, products and activities, so firms should confirm their own reporting schedule rather than relying on a generic industry calendar.
The FCA Handbook provisions governing reporting under the Payment Services Regulations and Electronic Money Regulations set out the applicable requirements and deadlines.
FSA056: the Authorised Payment Institution return
Authorised Payment Institutions are required to submit the FSA056 return, which provides the FCA with information about the firm’s business and its compliance with prudential requirements. The return includes capital information and data that allows the FCA to assess whether the firm continues to maintain the financial resources required for the payment services it provides.
For most APIs, the return is annual and is due within 30 business days of the firm’s accounting reference date. The figures reported should be consistent with the firm’s underlying accounting records, regulatory capital calculations and the methodology it uses to determine its own funds requirement.
This is where errors can arise. Payment volumes, income figures and capital calculations may come from different systems or teams, and a figure that appears reasonable in isolation may not correspond with the information used elsewhere in the business. A firm should therefore reconcile the return to its financial statements, management accounts and prudential calculations before submission rather than treating the reporting template as a standalone exercise.
The FCA is not simply collecting historical information. The return helps it assess whether the firm continues to meet the conditions under which it was authorised, including whether its capital resources remain appropriate for the scale and nature of its payment activity.
FSA057: reporting for Small Payment Institutions
Small Payment Institutions have a different reporting framework reflecting their registered rather than authorised status. The FSA057 return captures information about the payment services the firm provides and the volume of transactions processed, helping the FCA assess whether the firm continues to satisfy the conditions for SPI registration.
This is particularly important because the Small Payment Institution regime is subject to quantitative thresholds. If a firm grows beyond the limits permitted for an SPI, regulatory reporting may provide the FCA with evidence that the business should no longer remain within the small institution regime.
An SPI should therefore monitor transaction volumes throughout the year rather than waiting until the annual return is due. Growth can be positive commercially while still creating a regulatory issue if the firm does not plan in sufficient time for a move to Authorised Payment Institution status.
Where a business is approaching the SPI threshold or materially changing its services, the regulatory implications should be considered early. Our Payment Institution authorisation team supports firms moving from registration into full FCA authorisation where their scale or activities require it.
FIN060 and reporting for Electronic Money Institutions
Authorised Electronic Money Institutions and Small Electronic Money Institutions submit the FIN060 questionnaire, which provides the FCA with information about their e-money issuance, payment services, financial position and regulatory compliance. For AEMIs, the return is annual and is generally due within 30 business days of the accounting reference date.
The return is important because an EMI often operates a more complex regulatory model than a straightforward payment institution. A firm may issue electronic money, operate customer accounts, provide cards and also offer payment services unrelated to its e-money activity, each of which can affect the information reported.
The data should therefore distinguish correctly between e-money activity and unrelated payment services where required. This is especially important for capital calculations and safeguarding because the regulatory treatment of the two activities is not always identical.
Small Electronic Money Institutions also need to monitor the limits that allow them to remain within the small institution regime. FSA065 captures total outstanding electronic money at the relevant reporting point, while FIN060 provides the wider annual regulatory picture. A firm approaching the applicable limits should consider the timing and requirements of an AEMI application before growth forces an abrupt change in regulatory status.
REP027: monthly safeguarding reporting
One of the most important changes in 2026 is the introduction of monthly safeguarding reporting under the strengthened CASS 15 regime.
Authorised Payment Institutions, Authorised Electronic Money Institutions and other firms within scope of the safeguarding requirements must submit information about their safeguarding arrangements and relevant funds each month. Small institutions that voluntarily opt into the relevant safeguarding regime can also become subject to the reporting requirement.
The return is due within 15 business days of the end of each calendar month. This gives the FCA regular information about the amount of customer money being safeguarded, the methods used, reconciliation activity and aspects of the firm’s safeguarding arrangements.
The significance is greater than the frequency of the filing. The FCA can now compare safeguarding data month by month and identify unusual movements, recurring problems or inconsistencies between periods much earlier than under the previous framework.
A firm should therefore be able to reconcile REP027 to its daily safeguarding calculations, bank balances, internal records and management information. If the monthly return shows figures that cannot be traced back to the controls used to operate the safeguarding framework, the problem is not simply a reporting error; it may indicate a wider weakness in how relevant funds are being identified and protected.
Our CASS 15 safeguarding services include reviews of safeguarding reporting, reconciliations, governance and audit readiness.
REP017: payment fraud reporting
REP017 requires relevant payment service providers to report statistical information about payment transactions and fraudulent transactions. The information allows the FCA to understand fraud levels across different payment types, authentication methods and transaction channels.
The reporting frequency depends on the type of payment service provider. Larger PSPs generally report every six months, while certain smaller firms report annually, although the underlying data still needs to capture the relevant reporting periods correctly.
The practical challenge is data quality. Fraud data is often held across fraud systems, transaction platforms, chargeback records, customer-service systems and banking or scheme providers. If those sources classify incidents differently, the return can become inconsistent before the compliance team even begins preparing it.
Firms should have a documented methodology explaining how fraudulent transactions are identified and classified and how figures are reconciled to underlying payment volumes. The reporting process should also distinguish between different fraud types and payment methods in accordance with the FCA’s requirements rather than relying solely on internal commercial fraud categories.
A sudden movement in reported fraud rates can attract attention even where the cause is a change in data methodology rather than a genuine increase in fraud. Changes to reporting logic should therefore be controlled and documented so the firm can explain material movements if questioned.
REP018: operational and security risk reporting
REP018 concerns the operational and security risks associated with the payment services a firm provides. Relevant PSPs must provide an updated and comprehensive assessment of those risks and explain whether their mitigation measures and control mechanisms remain adequate.
This should not be treated as an annual form-filling exercise carried out shortly before the deadline. The underlying assessment should reflect the actual technology, systems, outsourced providers, cyber risks, operational dependencies and controls supporting the firm’s payment services.
A common weakness arises when the business changes faster than the risk assessment. A firm may introduce a new core banking platform, cloud provider, payment processor or customer channel while the REP018 assessment continues to describe the previous operating environment. The return may still be submitted on time, but the underlying information no longer reflects the firm’s real risk profile.
Compliance, technology, information security and operational-risk teams should therefore contribute to the assessment. Where material systems or controls change, the firm should consider whether the existing assessment remains current rather than waiting automatically for the next scheduled reporting cycle.
The FCA can require more frequent reporting where appropriate, which reinforces the need to maintain the underlying assessment as a living risk document rather than recreating it from scratch each year.
REP020 and Open Banking interface reporting
REP020 applies to relevant account servicing payment service providers in relation to the availability and performance of dedicated Open Banking interfaces and payment service user interfaces.
The return captures daily statistics and is reported quarterly. It can include data on uptime, downtime, response times and error rates, allowing the FCA to assess whether interfaces used by AISPs and PISPs perform appropriately compared with the interfaces available directly to customers.
This is a more specialised return and will not apply in the same way to every PI or EMI. However, for firms that operate payment accounts accessible online and sit within the Open Banking framework, interface performance is a regulatory issue as well as a technology issue.
The underlying data should therefore be governed carefully. An API outage or performance problem may need to be reflected consistently across technology incident records, published availability statistics, regulatory reporting and any notification made to the FCA.
As the Government develops the next phase of Open Banking regulation, the quality and availability of payment interfaces are likely to remain an important supervisory concern.
Annual financial crime reporting
Certain Payment Institutions and Electronic Money Institutions are also required to submit the FCA’s Annual Financial Crime Report where they fall within the applicable reporting criteria.
The return provides the FCA with information about the nature and scale of a firm’s financial crime exposure, including customer types, jurisdictions, politically exposed persons and other relevant risk indicators. It forms part of the regulator’s wider risk-based approach to supervising money laundering, sanctions and other financial crime risks.
The compliance risk is not simply an incorrect figure. The information submitted should correspond with the firm’s enterprise-wide financial crime risk assessment, customer population, transaction-monitoring data and management information.
If a firm tells the FCA through one return that it has significant exposure to higher-risk jurisdictions while its financial crime risk assessment describes the geographical risk as low, the inconsistency can raise obvious questions about governance and the quality of the underlying controls.
Regulatory reporting should therefore be reviewed in the context of the firm’s wider compliance framework rather than completed independently by whichever team happens to own the filing.
Regulatory returns should reconcile with each other
One of the most important controls for a PI or EMI is cross-return reconciliation.
Different FCA returns often draw on overlapping information. Transaction volumes may appear in prudential returns, fraud reporting and management information. Customer funds may be reflected in safeguarding returns, finance records and daily reconciliations. The size and geographical profile of the business may also appear across several regulatory submissions.
These figures will not always be identical because the definitions and reporting periods can differ, but material differences should be understood and explainable.
A firm should be able to show why a number reported in one return differs from a superficially similar figure reported elsewhere. Where there is no documented explanation, the discrepancy may indicate that different teams are using different data sets, definitions or cut-off rules.
This is particularly important as regulatory reporting becomes more data-driven. The FCA does not need to review each return in isolation to identify an anomaly; it can compare information across submissions and against previous periods to identify trends that merit further investigation.
Governance should begin before the filing deadline
A strong regulatory reporting process starts with ownership.
Each return should have a clearly identified preparer, data owners and reviewer. The business should understand where every material figure comes from, which systems produce it and who is responsible for confirming its accuracy.
Compliance should not automatically be expected to generate every number. Finance may own capital data, operations may own transaction information, fraud teams may own fraud classification and technology may own operational-risk or interface data. Compliance should coordinate the regulatory interpretation and challenge the submission, but the underlying business functions should remain accountable for the accuracy of their information.
The review process should also be proportionate to the significance of the return. A monthly safeguarding return containing information about substantial customer funds warrants meaningful senior review rather than being submitted automatically once the template has been populated.
Where manual spreadsheets or data transformations are used, firms should maintain appropriate version control, evidence of review and a clear audit trail. Regulators and auditors should be able to understand how the final reported figures were derived.
Common regulatory reporting failures
Late submission is the most obvious reporting failure, but it is not necessarily the most serious.
A return can be filed on time and still expose the firm to regulatory risk if the information is incomplete, inconsistent or based on an incorrect interpretation of the reporting requirements. Repeated amendments after submission can also indicate weaknesses in the firm’s control environment.
Problems commonly arise where different teams use different definitions, reporting logic changes without documentation, new products are not incorporated into existing data processes or manual adjustments are made without adequate review. A firm can also continue using a reporting methodology developed several years earlier even though its products, systems and transaction flows have changed materially.
Another risk is treating a regulator-generated schedule as the complete universe of reporting obligations. My FCA and RegData provide firms with scheduled reporting tasks, but firms still need to understand which obligations apply to their activities and whether notifications or additional reports are required when circumstances change.
The most effective control is a regulatory reporting framework that maps each obligation to the relevant rule, frequency, deadline, data source, owner and reviewer. That framework should be reviewed whenever the firm changes permissions, launches a new product or materially alters its operating model.
Notifications are different from periodic regulatory returns
PIs and EMIs also need to distinguish scheduled regulatory reporting from event-driven FCA notifications.
The fact that information will eventually appear in a monthly, quarterly or annual return does not necessarily remove a separate obligation to notify the FCA when a significant event occurs. Material safeguarding breaches, major operational or security incidents, changes affecting authorisation, controllers and other specified events can require separate notification.
This distinction matters because waiting for the next scheduled return can result in the FCA receiving important information too late.
Firms should therefore maintain both a regulatory reporting calendar and a regulatory notification framework. Staff should know which events need escalation to compliance so that the firm can determine promptly whether an FCA notification is required.
Where an issue is material, the question should not be limited to “Which return does this go into?” The firm should also assess whether the FCA needs to be informed separately and sooner.
What should PIs and EMIs review now?
The introduction of monthly safeguarding reporting provides a good reason for firms to review their broader regulatory reporting framework in 2026.
The first step is to confirm that every applicable return has a clear owner, reviewer, data source and documented methodology. Firms should then test whether figures can be traced back to source systems and whether related information across different returns can be reconciled or explained.
Particular attention should be given to returns that depend on data from several functions. REP027, REP017 and REP018 can require input from finance, operations, compliance, technology and financial crime teams, which increases the risk of inconsistent definitions or unclear ownership.
Firms should also review whether their reporting framework has kept pace with business growth. New products, agents, banking partners, currencies, jurisdictions and customer types can all change the data that needs to be captured, even where the formal name of the return remains unchanged.
A short independent review of the reporting framework can often identify weaknesses before they result in inaccurate submissions or FCA questions. The objective should be to ensure that regulatory reporting reflects the business accurately and consistently, rather than simply maintaining a record of filings completed before their deadlines.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting has specialised in payment and electronic money regulation since 2013 and supports Payment Institutions and Electronic Money Institutions with FCA compliance, regulatory reporting, safeguarding and remediation.
We help firms assess whether their regulatory reporting framework is complete, accurate and aligned with the underlying business. This can include reviewing reporting obligations, data sources, governance and submission controls, testing individual returns and reconciling regulatory data against financial, operational and safeguarding records.
Our work also covers REP027 safeguarding reporting, FSA056 and FIN060 prudential returns, fraud and operational-risk reporting, financial crime reporting and the wider compliance framework supporting FCA submissions. Where weaknesses are identified, the focus is on correcting the underlying methodology and ownership rather than simply repairing the next return.
For firms reviewing their wider regulatory framework, our FCA Compliance services support ongoing compliance, independent reviews and remediation, while our Safeguarding and CASS services cover CASS 15, REP027, reconciliations and safeguarding audit readiness.
To discuss an FCA regulatory reporting review, remediation of reporting issues or support with payment and e-money compliance, contact Buckingham Capital Consulting.
Frequently asked questions
What regulatory returns does an Authorised Payment Institution need to submit?
An API will typically have several reporting obligations depending on its activities. These can include the annual FSA056 return, REP017 payment fraud reporting, REP018 operational and security risk reporting and monthly REP027 safeguarding reporting where the firm safeguards relevant funds. Additional returns or notifications may apply depending on the firm’s permissions, structure and business model.
What regulatory returns does an Electronic Money Institution need to submit?
AEMIs generally submit the annual FIN060 questionnaire together with other applicable returns such as REP017, REP018 and monthly REP027 safeguarding reporting. Financial crime, Open Banking or other reporting obligations may also apply depending on the activities carried on. Firms should confirm their individual schedule against the FCA Handbook and their regulatory profile rather than relying on a generic list.
How often is REP027 submitted?
The safeguarding return is submitted monthly and is generally due within 15 business days of the end of each calendar month. It applies to safeguarding institutions within scope of SUP 16.14A, including APIs, AEMIs and other firms required or electing to safeguard relevant funds. The figures should reconcile with the firm’s underlying safeguarding records and daily control framework.
What happens if an FCA regulatory return is incorrect?
A firm that identifies inaccurate or incomplete information should assess the error promptly and take appropriate steps to correct it. The FCA expects regulatory reporting to be complete and accurate, and repeated errors can indicate weaknesses in governance, systems or controls. Depending on the significance of the issue, the firm should also consider whether a separate notification to the FCA is required.
Should compliance prepare every regulatory return?
Compliance should oversee the regulatory interpretation and challenge the submission, but it should not necessarily generate every underlying figure. Finance, operations, technology, fraud and financial crime teams may own different data sets. A strong framework gives each return clear data owners, a responsible preparer and an appropriate reviewer so that regulatory reporting is based on accurate information from across the business.



