United Kingdom: fintech & payments regulation

Regulated

FCA-regulated VASP regime; PRA co-supervises; PSR oversees payment systems

Also involved
PRA (prudential) · PSR (payment systems) · NCA (AML)
Core law
Financial Services and Markets Act 2000 (FSMA)
Entry capital
GBP 0 (VASP); GBP 20,000 (Small PI)
Approval timeline
3-6 months
Customer assets
Safeguarded in segregated client accounts
Data protection
UK GDPR / Data Protection Act 2018 · ICO
Sandbox
Yes - FCA Regulatory Sandbox

The UK regulates fintech and payments primarily through the FCA under FSMA 2000. The regime is mature, requiring authorisation for payment services and e-money. A comprehensive cryptoassets regime was established in 2026, bringing stablecoins and custodial services under FCA supervision. The PRA co-supervises prudential aspects for larger firms.

Which licence do you need?

Your activityRequirementCapitalTimelineAuthority
Payment processing / gatewayLicenceAuthorised Payment Institution[1]

Requires authorisation under Payment Services Regulations 2017

FCA
E-money & wallet issuanceLicenceAuthorised E-money Institution[1]

Requires authorisation under E-money Regulations 2011

FCA
Domestic money transferLicenceAuthorised Payment Institution[1]

Domestic transfers covered under Payment Services Regulations 2017

FCA
Cross-border remittanceLicenceAuthorised Payment Institution[1]

Cross-border payments require FCA authorisation

FCA
Agent networkLicenceAuthorised Payment Institution[1]

Agent networks must be covered by the firm's permission

FCA
Open banking / account informationLicenceAuthorised Payment Institution[1]

Account Information Service Providers require FCA authorisation

FCA
Foreign-exchange servicesLicenceAuthorised Payment Institution[1]

FX services are payment services requiring FCA authorisation

FCA

New — what changed recently

  • 2026-06-26FCA Cryptoassets Regime Policy StatementsEstablished comprehensive FCA regulation for cryptoasset firms under FSMA 2000, including stablecoins and custodial services.[2]
  • 2024-09-19PS25/12: Safeguarding regime changesFinalised changes to safeguarding requirements for payments and e-money firms, enhancing prudential risk management.[1]
  • 2024-09-06FG24/6: Risk-based approach guidanceIssued finalised guidance requiring firms to adopt a risk-based approach for managing payment services.[3]

Market-entry checklist

  1. 1Apply for FCA AuthorisationSubmit application under Payment Services Regulations 2017 or E-money Regulations 2011.
  2. 2Establish SafeguardingImplement segregated client account arrangements as per PS25/12.
  3. 3Register for AMLRegister with the National Crime Agency for anti-money laundering supervision.
  4. 4Prepare Risk FrameworkDevelop risk-based protocols for payment services as required by FG24/6.
  5. 5Engage with PSRIf operating payment systems, engage with the Payment Systems Regulator.
This guide is compiled automatically from 3 primary-source documents published by United Kingdom's regulators, reviewed by RegAlert, and refreshed monthly (last updated 2026-07-12). It is not legal advice — always confirm requirements with the regulator or local counsel before acting.