United Kingdom

UK Authorised Payment Institution Licence (API Licence)

Expert advisory on obtaining a UK Authorised Payment Institution (API) licence from the FCA. From regulatory scoping to authorisation.

From £20,000 capital6–12 monthsFCA

Get Expert Advice

Whether you need licensing support, compliance advice or regulatory strategy, our team is ready to help. Free initial consultation — no obligation.

Get Expert Advice

Free initial consultation. No obligation.

What is the UK Authorised Payment Institution Licence?

The UK Authorised Payment Institution (API) licence authorises firms to provide regulated payment services under Schedule 1 of the Payment Services Regulations 2017 (PSR 2017). These services include money remittance, payment processing, merchant acquisition, payment initiation services (PIS) and account information services (AIS). The licence is issued by the Financial Conduct Authority (FCA).

Operating a payment services business in the United Kingdom without FCA authorisation or registration is a criminal offence under Regulation 138 of the Payment Services Regulations 2017. Persons convicted on indictment face imprisonment for up to two years and/or an unlimited fine.

The API licence is the full authorisation route — as distinct from Small Payment Institution (SPI) registration — and is required by any firm whose average monthly payment transaction volume exceeds €3 million or that wishes to passport into EEA states.

Who Needs UK Authorised Payment Institution Licence?

The API licence is required by any firm carrying on payment services business in the UK that exceeds the Small Payment Institution thresholds or requires passporting rights.

  • Fintech firms processing payments above the €3 million monthly threshold
  • Money remittance businesses (international transfers, cross-border payments)
  • Payment processors and payment facilitators
  • Merchant acquirers
  • Open banking providers offering PIS or AIS
  • Firms operating multi-currency payment accounts without e-money issuance
  • Payment platforms seeking to passport into EEA member states

A common misconception is that firms providing payment-adjacent services — such as software platforms that aggregate payment flows or marketplace platforms that hold funds in transit — are exempt from authorisation. In most cases, these activities fall within the regulatory perimeter. The FCA takes an expansive view of what constitutes a payment service, and firms should seek regulatory advice before concluding they are out of scope.

Key Requirements

Initial Capital

£20,000 for firms providing money remittance services only. £50,000 for firms providing payment initiation or account information services. £125,000 for firms executing payment transactions, operating payment accounts or acquiring payment transactions. Own funds must be maintained on an ongoing basis at the higher of the initial capital floor or a percentage of payment transaction volume.

Governance & Fit and Proper

At least two directors are required. All directors, senior managers and qualifying shareholders (holding 10% or more) must complete FCA Individual Questionnaires. The fit and proper assessment covers criminal history, regulatory history, financial soundness and professional competence. The FCA expects the management body to have collective competence in payments, compliance and risk management.

AML & Financial Crime Controls

A compliant AML programme must be operational from day one of authorisation. This requires appointment of a Money Laundering Reporting Officer (MLRO) under SMF17, a documented business-wide risk assessment, customer due diligence (CDD) procedures proportionate to risk, ongoing monitoring, and a Suspicious Activity Report (SAR) reporting framework. The AML programme must be specifically tailored to the firm's business model and customer risk profile.

Safeguarding

Client funds must be safeguarded by segregation in a designated account at an FCA-approved credit institution, with written acknowledgement obtained from the credit institution before submission. Alternatively, safeguarding may be achieved through insurance or a comparable guarantee. PS25/12 (published August 2025, effective 7 May 2026) significantly strengthens safeguarding requirements — introducing daily reconciliation, a statutory trust structure, and mandatory annual independent audit.

Operational Requirements

Firms must maintain adequate IT systems, business continuity arrangements, outsourcing governance and complaints handling procedures. The FCA expects documented operational resilience frameworks proportionate to the scale and complexity of the business.

Regulatory Reporting

Authorised payment institutions must submit regular returns to the FCA via the RMAR system, including transaction volume data, capital adequacy reports and annual financial statements audited by an approved auditor.

The Application Process

1

Regulatory Scoping and Permission Selection

Regulatory Counsel maps your business model to the specific PSR 2017 Schedule 1 payment services categories. We determine the correct permission set, initial capital tier and safeguarding methodology. This scoping prevents the most common early-stage error — applying for the wrong permissions. Timeline: 2 weeks.

2

Corporate Structure and Governance Setup

We advise on corporate structure, appoint directors and senior managers who satisfy FCA fit and proper standards, and prepare all Individual Questionnaires. Qualifying shareholders are identified and their disclosure packages prepared. Timeline: 4 weeks.

3

Regulatory Business Plan Drafting

Regulatory Counsel prepares a comprehensive regulatory business plan — the single most important document in the application. This covers the business model, target market, product architecture, revenue model, three-year financial projections, capital adequacy analysis and go-to-market strategy. The FCA cross-references every section; internal inconsistencies trigger information requests. Timeline: 4–6 weeks.

4

Policy and Procedure Suite Preparation

We build the full compliance policy suite: AML/CTF programme, safeguarding methodology, complaints handling, operational resilience, outsourcing governance, data protection and financial promotions procedures. Each policy is tailored to your specific business model — not templated. Timeline: 4–6 weeks.

5

Application Submission via FCA Connect

The completed application is assembled and submitted via the FCA Connect portal. Regulatory Counsel conducts a final quality assurance review to ensure completeness and internal consistency before submission. Timeline: 1 week.

6

FCA Assessment and Determination

The FCA reviews the application and may issue information requests. Regulatory Counsel manages all correspondence, prepares responses and coordinates any required meetings or calls with the FCA case officer. A well-prepared application with proactive relationship management typically results in assessment at the lower end of the timeline range. Timeline: 6–12 months.

Total expected timeline: 8–14 months from instruction to authorisation.

Why Applications Fail — and How We Prevent It

Generic AML Programme

Copying AML templates from other firms or sectors without tailoring to the specific business model and customer risk profile is the most common reason applications are delayed or refused. The FCA cross-references the AML programme against the business plan and rejects applications where the risk assessment does not specifically address the risks arising from the applicant's stated business activities and target customers.

Inadequate Safeguarding Arrangements

Failure to obtain written acknowledgement from the safeguarding bank before submission is a critical error. The FCA will not grant authorisation without confirmed safeguarding arrangements. Many applicants underestimate the time required to secure a safeguarding account — banks are increasingly cautious about onboarding payment institutions, and the process can take 8–12 weeks.

Implausible Financial Projections

Day-one profitability with no explanation of client acquisition strategy, or revenue projections that assume market share without evidence of commercial pipeline, trigger immediate FCA challenge. The FCA requires projections grounded in a credible go-to-market strategy with identified customer segments and realistic conversion assumptions.

Undisclosed Individual History

County Court Judgments, prior directorships of failed or regulatory-actioned firms, non-UK regulatory sanctions, or adverse media that applicants assume will not be discovered during the FCA's background checks. The FCA conducts thorough checks including international regulatory databases, credit reference agencies and open-source intelligence. Non-disclosure is treated more seriously than the underlying issue.

How Regulatory Counsel Can Help

End-to-End Application Management

From initial regulatory scoping through to FCA authorisation, we manage every aspect of your API licence application — business plan, policy suite, FCA correspondence and assessment management.

Regulatory Business Plan

We draft the complete regulatory business plan to FCA standards — the single most scrutinised document in the application. Internally consistent, commercially credible and aligned with your stated business model.

Ongoing Compliance Support

Post-authorisation, we provide ongoing compliance support including RMAR reporting, policy updates, safeguarding reviews, annual compliance monitoring and regulatory change management.

Regulatory Counsel has advised on payment institution licensing across the UK, EU and global markets. Our team combines direct FCA regulatory experience with deep sector expertise in payments, e-money and open banking. Every engagement is led by a senior consultant — not delegated to junior staff.

Frequently Asked Questions

Capital ranges from £20,000 to £125,000 depending on payment services offered. Firms providing account information services only require £20,000; payment initiation services require £50,000; all other payment services require £125,000. Capital must be maintained on an ongoing basis.

Application preparation with Regulatory Counsel takes 6–10 weeks. The FCA then has a statutory 3-month assessment period from receipt of a complete application, extendable to 12 months in complex cases. Most applicants should plan for a 6–12 month total assessment period.

APIs must safeguard relevant funds per PS25/12 — the FCA's updated safeguarding regime published August 2025. Requirements include a statutory trust structure, daily reconciliation, annual independent third-party audit, board-level oversight of safeguarding, and a monthly safeguarding return to the FCA.

Yes. The FCA imposes no nationality or domicile requirements on shareholders. However, the firm must be UK-incorporated and genuinely managed and controlled from the UK — the FCA assesses whether the entity has real UK substance, not just a registered address.

An SPI operates without capital requirements but is subject to a €3 million monthly transaction volume ceiling and cannot passport into EEA states. An API has capital requirements but no volume ceiling and benefits from EEA passporting. Growing payment firms typically start as SPIs and upgrade to API as volume increases.