How to Obtain a UK Authorised Payment Institution Licence in 2026

An Authorised Payment Institution, or API, is the main FCA authorisation for UK businesses that want to provide payment services at scale. It is commonly used by money transfer companies, payment processors, merchant acquirers and other payment firms that are too large for the Small Payment Institution regime or need payment services that an SPI cannot provide.
For a founder, API authorisation is not primarily a documentation exercise. The FCA wants to see a business that is ready to operate as a regulated payment institution. That means the company, management, capital, safeguarding, compliance, technology, banking and financial model all need to fit together. A strong application simply explains that structure clearly.
The 2026 position is particularly important because the FCA's new CASS 15 safeguarding regime came into force on 7 May 2026. New API applications are now assessed against the strengthened safeguarding standards, so an application based on old payment institution templates can be materially out of date.
What is an Authorised Payment Institution?
An API is a UK body corporate authorised by the Financial Conduct Authority under the Payment Services Regulations 2017 to provide specified payment services. The permissions can cover activities such as money remittance, executing payment transactions, merchant acquiring, issuing payment instruments, payment initiation services and account information services, depending on the application.
An API is not a bank and cannot accept deposits. It also cannot issue electronic money simply because it is authorised as a payment institution. If the product involves customers holding stored monetary value for later use, an Authorised Electronic Money Institution may be the correct regime instead.
When do you need API authorisation?
API authorisation is usually the right route where the business will exceed the SPI threshold, requires payment initiation or account information services, or wants a full payment institution structure capable of supporting a larger operation. The SPI regime is limited to an average monthly amount of payment transactions not exceeding EUR 3 million.
The decision should take account of growth. If your financial model shows the business will move above the SPI limit soon after launch, API authorisation from the outset can be more efficient than obtaining an SPI registration and then preparing a completely new authorisation application.
What can an API do?
The Payment Services Regulations contain eight categories of regulated payment service. An API can apply for the services relevant to its model, including operating payment accounts, cash placement and withdrawal, executing transfers and card payments, issuing payment instruments, merchant acquiring, money remittance, payment initiation and account information services.
You should not apply for every permission simply to keep options open. Each additional service needs to be supported by the programme of operations, risk framework, compliance controls and financial model. The cleanest application asks for the permissions the company genuinely intends to use.
What does the FCA require?
A UK body corporate with the required head office and registered office arrangements.
Some payment services business carried on in the UK.
Adequate initial capital and ongoing own funds.
Directors and managers of good repute with appropriate knowledge and experience.
Fit and proper controllers and qualifying shareholders.
A credible regulatory business plan and financial forecasts.
Robust governance, internal controls and risk management.
AML, sanctions and financial crime controls.
Safeguarding arrangements where the firm receives relevant funds.
Security, incident management, business continuity and outsourcing controls.
Professional indemnity insurance or a comparable guarantee where required for particular services.
How much regulatory capital does an API need?
The initial capital depends on the payment services requested. The principal statutory minimums are EUR 20,000 for money remittance, EUR 50,000 for payment initiation services and EUR 125,000 for the payment services in paragraphs (a) to (e) of Schedule 1, which include operating payment accounts, executing payment transactions and issuing or acquiring payment instruments.
That is only the initial requirement. An API must maintain ongoing own funds after authorisation. The business plan should therefore model the capital position as the company grows rather than showing only that the applicant can deposit the minimum amount before filing.
Do you need a UK management team?
The FCA needs to be able to supervise a genuine UK payment institution. The applicant should have credible management, clear decision-making and enough substance in the UK to run and control the regulated business. There is no value in adding nominal directors who cannot explain the product, risks or controls.
A founder should be able to answer: who runs the business, who owns compliance and AML, who controls safeguarding, who oversees technology and outsourcing, and where material decisions are made. If key functions are provided by a parent or third party, the UK API must still demonstrate that it remains accountable and capable of oversight.
The regulatory business plan
The business plan should explain how the payment institution will operate over at least the first three years. It needs to cover target customers, products, transaction volumes, pricing, countries, currencies, distribution, staffing, technology, banks, payment partners and financial performance.
It should be detailed enough for the FCA to test whether the model is credible, but it should not read like an academic paper. Every section should answer a practical supervisory question: what will the company do, who will do it, what risks arise and how will those risks be controlled?
The flow of funds
The flow of funds is one of the most important parts of an API application. It should show the customer, the API, every bank or payment provider, the relevant accounts, the settlement path and the beneficiary. It should also identify when the firm receives relevant funds and when its payment obligation ends.
This diagram drives the permissions and safeguarding analysis. If the flow of funds suggests one business model but the programme of operations describes another, the FCA will have difficulty understanding what it is being asked to authorise.
Safeguarding under CASS 15 in 2026
Authorised payment institutions that receive or hold relevant funds must safeguard them. Since 7 May 2026, the FCA's CASS 15 rules supplement the Payment Services Regulations and create a much more detailed safeguarding operating framework.
In practical terms, affected firms need clear safeguarding governance, appropriately structured safeguarding accounts, due diligence on relevant third parties, accurate books and records, internal and external safeguarding reconciliations, treatment of discrepancies and unidentified funds, resolution information and the required reporting and assurance. External reconciliations must be performed as frequently as necessary and at least once each reconciliation day in the circumstances set out in CASS 15.
For an applicant, safeguarding should therefore be designed before submission. The FCA will expect more than a statement that customer funds will be kept in a segregated account. The application needs to show how the firm calculates the amount to safeguard, how it reconciles it, who reviews discrepancies and what happens if the safeguarding bank or payment institution fails.
AML, sanctions and transaction monitoring
An API needs a financial crime framework proportionate to its customers, countries, products and transaction profile. This normally includes the business-wide risk assessment, customer risk scoring, KYC and KYB, beneficial ownership, enhanced due diligence, sanctions screening, transaction monitoring, suspicious activity escalation, training and record keeping.
The system needs to be operationally credible. If a company expects tens of thousands of transactions, manual monitoring by one person is unlikely to be sustainable. If it targets high-risk corridors, enhanced due diligence and monitoring need to reflect that risk. The FCA will compare the controls with the commercial plan.
Technology, outsourcing and operational resilience
Most modern payment firms rely heavily on third-party technology. That is acceptable, but outsourcing does not outsource regulatory responsibility. The applicant should know which providers support onboarding, ledgering, payment execution, screening, transaction monitoring, cloud infrastructure and customer support, and how each provider is selected and overseen.
Contracts, due diligence, service monitoring, incident escalation, data arrangements and exit plans should be proportionate to the importance of the provider. A well-known vendor is not a substitute for oversight. The API remains responsible for the regulated service delivered to the customer.
How to apply for an FCA API licence
1. Confirm API is the correct regime. Rule out SPI, EMI and exclusions before building the application.
2. Set the permissions. Identify the exact Schedule 1 payment services the company will provide.
3. Build the UK entity and management structure. Confirm controllers, directors, senior roles and outsourced functions.
4. Prepare the flow of funds. Map every transaction type, account and payment partner.
5. Build the business plan and three-year financial model. Include realistic volumes, revenue, staffing, costs, capital and cash flow.
6. Design safeguarding under the 2026 rules. Put the account structure, reconciliation, governance and resolution framework in place.
7. Prepare AML and compliance controls. Tailor them to the real customers, geographies and transaction profile.
8. Complete the operational framework. Security, business continuity, outsourcing, complaints, incident management and regulatory reporting should be ready.
9. Submit through FCA Connect. Pay the correct application fee and provide a complete application pack.
10. Manage FCA questions. Keep all responses aligned with the original business model and disclose material changes.
11. Prepare for day-one compliance. The people, bank accounts, systems and controls should be capable of operating when authorisation is granted.
How long does FCA API authorisation take?
The FCA states that complete payments and e-money applications are usually assessed within three months. Incomplete applications can take up to 12 months under the statutory framework, with the FCA currently targeting 10 months operationally for incomplete applications.
Preparation comes before that. A well-developed company with experienced management, settled banking and a clear product can prepare an application more efficiently than a startup still changing its model. Trying to start the FCA clock before the company is ready often creates more questions and a longer overall project.
How much is the FCA API application fee?
As at August 2026, an Authorised Payment Institution falls into Category 4 or Category 5 depending on the payment services requested. The current fees are GBP 2,820 for Category 4 and GBP 5,640 for Category 5. These are FCA filing fees only, not the total cost of establishing an API.
What does it really cost to set up an API?
The meaningful cost is the regulated operating company. In addition to the FCA fee and professional preparation, founders should budget for regulatory capital, management, compliance and AML staff, safeguarding and banking, transaction monitoring, sanctions screening, technology, cyber and operational resilience, audit and continuing regulatory reporting.
The right cost base depends on the product. A money remittance API with a limited corridor is a different business from a merchant acquirer processing high transaction volumes across multiple industries. The application should reflect the real resources needed for the proposed model rather than a generic "minimum setup" budget.
Can you buy an existing API instead?
Acquiring an existing Authorised Payment Institution can be faster in some circumstances, but the buyer is acquiring a regulated company, not a detachable licence. FCA change-in-control requirements need to be considered, and the target should be reviewed for historic safeguarding, AML, complaints, regulatory reporting, capital and supervisory issues.
The proposed new business model also matters. An API authorised for one type of activity may not have the permissions or operational framework needed for your product. A proper acquisition therefore combines regulatory due diligence, change-of-control planning and a review of whether permissions or business plans need to change.
Common reasons API applications struggle
The business is still changing while the application is being drafted.
The permissions do not match the payment flow.
The UK entity lacks credible management substance.
Financial forecasts are aggressive but compliance and operations are under-resourced.
Safeguarding documentation does not reflect the live CASS 15 requirements.
AML policies are generic rather than risk-based.
The company outsources critical functions but cannot show effective oversight.
Banking and safeguarding partners have not been thought through.
Different documents contain inconsistent transaction volumes, entities or assumptions.
Frequently asked questions
What is the difference between an API and an EMI?
An API is authorised to provide payment services. An EMI can issue electronic money as well as provide payment services within its permissions. If customers hold stored value in a wallet or account that can later be used for payments, the EMI perimeter should be analysed before applying as an API.
Can an API provide international money transfers?
Yes. Money remittance can be included in an API's permissions. The company still needs appropriate banking, AML, sanctions and local regulatory analysis for the countries and corridors it serves. UK authorisation does not automatically create a licence in every destination country.
Can an API passport into Europe?
No. UK payment institution passporting into the EEA ended following Brexit. A UK API that wants to provide regulated payment services in EEA states needs a separate local regulatory strategy, which may involve an EEA-authorised entity or regulated partner.
Do I need GBP 125,000 of capital for every API?
No. The initial capital depends on the payment services requested. The principal bands are EUR 20,000, EUR 50,000 and EUR 125,000. The firm also has ongoing own-funds requirements, so capital planning should be based on the full permission set and financial model.
Can I outsource the compliance function?
Elements of compliance can be outsourced, but the API remains responsible for meeting its regulatory obligations. The firm must retain enough knowledge and control to oversee the provider and senior management must understand and own the regulatory risks.
Do I need a safeguarding bank before the FCA approves me?
The application needs a credible safeguarding model and the firm should progress suitable banking relationships during the authorisation project. The exact evidence available at submission varies, but leaving safeguarding banking entirely unresolved creates both regulatory and launch risk.
How many staff do I need for an API?
There is no fixed FCA headcount. The team must be proportionate to the size, complexity and risk of the business. The FCA will look at whether compliance, AML, safeguarding, finance, technology, operations and senior management responsibilities can realistically be performed with the proposed resources.
Can a foreign group own a UK API?
Yes. Foreign ownership is possible, but the FCA will assess the controllers and whether the UK entity can be effectively supervised. The UK API should have real governance and operating substance and should not simply rely on the parent for every material decision.
What is the biggest factor in getting an API application approved efficiently?
Completeness and consistency. The strongest applications have a settled business model, credible people, realistic financials and documents that all describe the same transaction flow. Most avoidable delays arise because the FCA has to reconstruct the business from inconsistent or incomplete information.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting has specialised in UK payment institution and e-money authorisation since 2013. We support the full API process, including regulatory perimeter analysis, permissions, programme of operations, business plan, financial forecasts, governance, capital, safeguarding, AML and compliance policies, risk frameworks, application submission and FCA engagement.
Our published work includes supporting Nexpay and Global Send with FCA Authorised Payment Institution applications, including the application, compliance documentation, governance evidence and regulator engagement. Read more about our Authorised Payment Institution service or contact Buckingham Capital Consulting to discuss a new API application, an existing application or the acquisition of an authorised payment institution.


