Payment Institutions

FCA Compliance for UK Payment Institutions: Requirements, Safeguarding and Supervisory Expectations

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 14 min read

Key Takeaways

  • Payment institutions are authorised under the Payment Services Regulations 2017, with authorised payment institutions and small payment institutions subject to materially different requirements.
  • CASS 15 came into force on 7 May 2026, introducing daily internal and external safeguarding reconciliations, a monthly regulatory return under SUP 16.14A, an annual safeguarding audit under SUP 3A, and a resolution pack under CASS 10A.
  • Reconciliation is required on each reconciliation day, which excludes weekends, UK bank holidays and days on which a relevant foreign market is closed.
  • Responsibility for safeguarding compliance must sit with a director or senior manager of sufficient skill and authority.
  • Financial crime remains a principal supervisory focus, with the FCA identifying weak business-wide risk assessments and over-reliance on third-party due diligence across the wider regulated population.
  • Firms using agents or distributors retain responsibility for their conduct and for funds flowing through them.

Payment institutions operate under a regulatory framework that combines the Payment Services Regulations 2017, the FCA Handbook, and the FCA's Approach Document for payment services and electronic money. Since May 2026, safeguarding has been governed by a detailed set of Handbook rules in CASS 15, representing the most significant change to the regime since the implementation of the second Payment Services Directive.

This article sets out the requirements applying to payment institutions, the safeguarding obligations introduced by the Supplementary Regime, the areas where supervisory attention concentrates, and the practical components of a compliance framework.

Authorisation and permissions

The Payment Services Regulations 2017 provide for two categories of payment institution.

Authorised payment institutions. Firms exceeding the thresholds for small payment institution status, or electing full authorisation. APIs may passport into the UK market from an overseas jurisdiction only under specific arrangements, and must meet initial capital requirements determined by the payment services provided.

Small payment institutions. Firms whose average monthly payment transactions over the preceding twelve months do not exceed the prescribed threshold. SPIs are registered rather than authorised, are subject to reduced requirements, and are not required to safeguard, although they may opt in.

Payment services are defined by reference to the activities listed in the Regulations: services enabling cash placement and withdrawal, execution of payment transactions, issuing payment instruments, acquiring payment transactions, money remittance, payment initiation services and account information services.

The scope of a firm's permission matters operationally. Firms conducting activities outside their permitted scope, or exceeding SPI thresholds without varying to full authorisation, face a straightforward perimeter breach.

Safeguarding under CASS 15

CASS 15 came into force on 7 May 2026 as part of the FCA's Supplementary Regime, introduced by Policy Statement PS25/12 and supplementing rather than replacing the safeguarding requirements in the Payment Services Regulations 2017.

The regime applies to authorised payment institutions, authorised electronic money institutions, small electronic money institutions and credit unions issuing electronic money. Small payment institutions may opt in.

Relevant funds

Relevant funds are sums received from or for a payment service user for the execution of a payment transaction, sums received from another payment service provider for the execution of a payment transaction, and, for e-money issuers, sums received in exchange for electronic money issued.

The practical difficulty is application rather than definition. Firms must determine and document when the safeguarding obligation begins and ends, how fees once due are treated, how foreign exchange is handled where linked to a payment service, how funds held through agents and distributors are treated, and how long unclaimed funds must continue to be safeguarded.

These determinations should be recorded in the firm's safeguarding policy, and the reconciliation performed must be consistent with the position taken.

Reconciliation

On each reconciliation day, a firm must perform an internal safeguarding reconciliation, comparing the relevant funds that should be safeguarded against its own records, and an external safeguarding reconciliation, comparing those records against third-party records including safeguarding account statements and custodian records.

A reconciliation day is any day other than a Saturday or Sunday, a UK bank holiday, or a day on which a relevant foreign market is closed. Firms must determine which foreign markets are relevant to their business and apply that determination consistently.

The comparison is between the D+1 segregation requirement, being the relevant funds that should be held, and the D+1 segregation resource, being the balance of the relevant accounts. Where the resource falls short, the firm must remedy the shortfall, using its own funds where relevant funds are unavailable. Where it exceeds the requirement, the excess must be withdrawn.

Firms holding funds in respect of both electronic money and unrelated payment services must treat those as separate asset pools, reconciled and reported separately.

Regulatory reporting

A monthly safeguarding return is required under SUP 16.14A, submitted through RegData. The return covers relevant funds held, the segregation position across the reporting period, reconciliation performance, shortfalls identified and remedied, safeguarding accounts and assets, safeguarding method, and breaches and notifications.

The annual safeguarding audit

Authorised payment institutions must arrange an annual safeguarding audit under SUP 3A unless they safeguarded less than £100,000 throughout a relevant period of at least 53 weeks. The audit period must not exceed 53 weeks. The first report is due within six months of the end of the audit period, and subsequent reports within four months.

Firms should note that guidance issued by the Financial Reporting Council provides for auditors to report all breaches to the FCA rather than only material ones, and that IT general controls covering change management, user access and IT operations form part of the audit.

The resolution pack

Firms must maintain a resolution pack under CASS 10A, retrievable within 48 hours, containing the records needed to enable relevant funds to be returned to customers in an insolvency procedure. The requirement assumes an existing and current pack rather than one assembled on request.

Notification

A firm must notify the FCA without delay where its internal records are materially out of date, inaccurate or invalid; where it will be unable to perform a reconciliation; where it will be unable to remedy a discrepancy; or where there has been a material difference between the amount safeguarded and the amount that should have been safeguarded at any time during the preceding year.

Governance and third parties

Responsibility for safeguarding compliance must sit with a director or senior manager of sufficient skill and authority. Firms must carry out and document due diligence on banks, custodians, insurers and guarantors involved in safeguarding arrangements, subject to periodic review, and consider whether diversification is appropriate.

Acknowledgement letters must be obtained from institutions holding safeguarding accounts, confirming that funds are held for safeguarding purposes, that the institution has no right of set-off or counterclaim, and that it will not combine the account with any other.

Capital requirements

Authorised payment institutions must hold initial capital determined by the payment services provided, and ongoing own funds calculated under one of the three methods set out in the Regulations. Firms must monitor their own funds position on an ongoing basis rather than at reporting dates, and hold a wind-down plan demonstrating that they can cease operations in an orderly manner.

Financial crime

Payment institutions are subject to the Money Laundering Regulations 2017 and to the FCA's financial crime expectations.

The FCA has identified weaknesses across the wider regulated population, including business-wide risk assessments that are weak or generic, over-reliance on third-party due diligence, and underestimation of money laundering risk. In payments specifically, transaction monitoring data completeness, agent oversight, and sanctions screening across the payment chain attract attention.

The business-wide risk assessment should reflect the firm's actual customer base, products, jurisdictions, delivery channels and agent network, and should be updated when those change rather than on a fixed annual cycle.

Agents and distributors

Payment institutions may provide payment services through agents, subject to registration. The firm remains responsible for the regulated activities carried on by its agents and for the funds flowing through them.

Practical obligations include due diligence before appointment, ongoing monitoring proportionate to the agent's activity and risk, ensuring agents' staff are fit and properly trained, and ensuring that relevant funds held by or flowing through agents are properly safeguarded.

Agent networks are a recognised source of financial crime and safeguarding risk, and firms with substantial agent populations should expect supervisory interest in how oversight is exercised in practice rather than how it is documented.

Operational resilience

Firms must identify important business services, set impact tolerances for each, map the resources supporting them, and test their ability to remain within tolerance in severe but plausible scenarios. Payment institutions are also subject to incident reporting requirements under the Regulations, with major operational and security incidents reportable to the FCA within prescribed timescales.

Building a defensible compliance framework

Safeguarding operations. Daily internal and external reconciliation with the segregation requirement and resource calculated and compared, breaks investigated and resolved with recorded approval, and the reconciliation calendar defined in advance.

Safeguarding evidence. Records created as controls operate rather than assembled at audit, retrievable by date, with the monthly returns, the resolution pack, board reporting and audit evidence drawn from the same underlying records.

Financial crime. A business-wide risk assessment reflecting the firm's actual risk profile, customer due diligence proportionate to risk, transaction monitoring with complete data, sanctions screening across the payment chain, and agent oversight.

Capital and wind-down. Own funds monitored continuously, with a wind-down plan that is tested rather than filed.

Governance. Clear allocation of safeguarding responsibility, board or committee oversight with information sufficient to challenge, and compliance monitoring that tests controls.

Regulatory reporting. Returns produced from operational records, reviewed and approved before submission, and retained with supporting evidence.

Where firms most often have difficulty

External reconciliation performed less rigorously than internal. Both are required on each reconciliation day, and the difference in rigour is visible in the records.

The relevant funds boundary undocumented. Judgements on fees, foreign exchange, agent funds and unclaimed balances applied in practice without being recorded in policy, producing inconsistency between the stated position and the reconciliation performed.

Resolution pack maintained as a document. Assembled once and not updated, describing arrangements that have since changed.

Agent oversight documentary rather than operational. Due diligence performed at appointment with limited ongoing monitoring and no evidence of action where standards fall short.

Business-wide risk assessment generic. A template populated with sector-level risk rather than an assessment of the firm's own customers, corridors, products and channels.

Wind-down plan untested. A document prepared for authorisation and not revisited, with assumptions that no longer reflect the business.

Regulatory developments to track

The FCA's intended Post-Repeal Regime, under which the safeguarding provisions of the Payment Services Regulations and Electronic Money Regulations would be replaced by a full CASS-style regime with relevant funds held on statutory trust. This was consulted on and deferred for further consultation; firms designing frameworks now should anticipate the end state.

Continued FCA supervisory work on financial crime controls across the payments sector.

Developments in the UK's approach to cryptoassets and stablecoins, relevant to payment firms with adjacent activity.

Dates and scope may change. Firms should confirm the current position against FCA publications.

About Regulatory Counsel

Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.

Our work with payment institutions covers FCA authorisation and variation of permission, safeguarding framework design and CASS 15 gap analysis, safeguarding audit preparation, financial crime frameworks and business-wide risk assessment, agent and distributor oversight, capital adequacy and wind-down planning, operational resilience, regulatory reporting review, compliance monitoring programme development, remediation, and preparation for supervisory engagement.

Contact our regulatory team at info@regulatorycounsel.co.uk.

This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.

Frequently Asked Questions

Authorised payment institutions are fully authorised, subject to capital requirements, safeguarding obligations and the full conduct framework. Small payment institutions are registered rather than authorised, are subject to a threshold on average monthly payment transaction volume, and are not required to safeguard, although they may opt in.

Not automatically. Small payment institutions are not required to safeguard. An SPI that opts in to safeguarding becomes subject to the regime.

Internal and external safeguarding reconciliations must each be performed at least once on every reconciliation day. A reconciliation day is any day other than a Saturday or Sunday, a UK bank holiday, or a day on which a relevant foreign market is closed.

The amount of relevant funds that should be held in safeguarding accounts or as relevant assets. It is compared against the D+1 segregation resource, being the balance of those accounts. Shortfalls must be remedied and excess withdrawn.

Authorised payment institutions must arrange an annual safeguarding audit unless they safeguarded less than £100,000 throughout a relevant period of at least 53 weeks. The first report is due within six months of the end of the audit period, and subsequent reports within four months.

A director or senior manager of sufficient skill and authority. CASS 15 does not create a defined safeguarding officer role or require board-level appointment, but the individual must have genuine oversight of the arrangements.

Agents must be registered, and the firm remains responsible for the regulated activities they carry on and for relevant funds flowing through them. Obligations include due diligence before appointment, ongoing monitoring proportionate to risk, and ensuring that funds held by agents are properly safeguarded.

The FCA has stated its intention to move to a Post-Repeal Regime replacing the safeguarding provisions of the Payment Services Regulations and Electronic Money Regulations with a full CASS-style regime under which relevant funds would be held on statutory trust. This was consulted on and deferred for further consultation.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert