Regulation
53.0 What this chapter gives you#
- You will be able to explain why a firm holding £900,000 of other people’s money on an ordinary Tuesday is required to have only 125,000 euros of its own capital, and why that is not the mismatch it looks like.
- You will be able to work out which licence a firm needs — authorised payment institution, small payment institution, authorised or small e-money institution, or registered account information service provider — from its volumes and the services it intends to provide.
- You will be able to explain what safeguarding actually is, why it dominates everything else in this sector, and what changed on 7 May 2026 when CASS 15 came into force.
- You will be able to tell somebody why safeguarded money is not insured money, and why the average shortfall across twelve failed payments firms was 65 per cent with distributions taking 2.3 years.
- You will be able to distinguish the £85,000 that appears in scam reimbursement from the £85,000 people wrongly imagine sits behind safeguarded balances.
- You will be able to explain why a merchant’s card costs keep rising even though interchange is capped at 0.2% on consumer debit and 0.3% on consumer credit.
- You will be able to name the four public bodies and one department that share the United Kingdom’s payments perimeter, and say which statute each draws its powers from.
- You will be able to say why “PSD2 applies in the UK” is false, and what to say instead when quoting a rule.
- You will be able to describe what an important business service and an impact tolerance are, and why a service is not made unimportant by being well protected.
- You will be able to separate what is law from what is announced policy — the abolition of the PSR, the PSD3 package, the repeal of assimilated law — and date any statement you make about this field.
The plain version#
Imagine a left-luggage office at a railway station. You arrive with a suitcase, hand it over, and get a paper ticket with a number on it. When you come back you hand over the ticket and you expect the same suitcase.
Now ask what could go wrong, and notice that there are two completely different kinds of wrong.
The first kind: the office runs out of money. Rent goes up, custom falls away, and one morning the shutters stay down. That is a business failing. It is sad, it is common, and mostly the world copes.
The second kind: you come back and your suitcase is gone, because the owner sold it. Or because the owner kept all the suitcases in one heap, lost track of whose was whose, and used a few to prop open a door. That is a different sort of failure entirely, and no amount of the owner’s own money in the till would have prevented it, because the problem was never the till. The problem was the room out the back.
Almost everything in payments regulation attempts to make the second kind of failure impossible. When a firm holds your money on its way somewhere else, your money is the suitcase and the firm’s own money is the till. Regulators care about the till, because a firm that runs out of cash stops working. They care far more about the room out the back, because that is where your money actually is.
So let us follow a firm through it.
Rina runs a small business called Northgate Pay. Her customers are letting agents. When a tenant pays rent, the money comes to Northgate Pay first, sits for a day or two while the agent’s software matches it to a property, and then goes out to the landlord. Northgate Pay never owns that money; it holds it in transit. On an average day about £900,000 belonging to other people is sitting in Rina’s accounts, and across a month roughly £27 million passes through.
Four things now happen to Rina, and they are the four things this chapter is about.
She needs permission. Moving other people’s money as a business is not something you may simply do. You have to be licensed by the Financial Conduct Authority, the FCA, and the licence comes in different sizes. Because Rina’s monthly volume is well over the small-firm threshold, she needs the full version: authorisation as what the law calls an authorised payment institution. That is not a form you fill in over a weekend. It is a business plan, a three-year financial forecast, background checks on everyone who runs or owns the firm, and written descriptions of how she will handle complaints, spot money laundering, cope when her systems break, and keep customer money separate. The regulator has three months to decide, but only once the application is genuinely complete, and most first drafts are not.
She needs starting money of her own. As things stood at the time of writing in August 2026, the law required a firm doing what Rina does to hold initial capital of 125,000 euros. Note the currency: British law here is still written in euros, a leftover from where these rules came from. And note the size: 125,000 euros against £900,000 of customer money sitting there on a normal Tuesday. The capital is not there to cover the customer money and could not possibly cover it. It is there so the firm has a cushion of its own, enough to absorb an ordinary bad year without immediately becoming somebody else’s problem.
She must keep the customer money somewhere else entirely. This is the room out the back, and in the trade it is called safeguarding. Rina must hold the rent money in a separate account, at a different bank, clearly marked as containing other people’s money, with a letter from that bank acknowledging in writing that it has no right to grab the money to settle Rina’s overdraft. Anything she is still holding at the end of the working day after the day it arrived has to be in there. Not most of it. All of it. And under rules that came into force on 7 May 2026, she must count it every business day, twice over: once against her own records, once against what the bank says is actually there. Differences are fixed the same day. Once a month she sends the regulator a return. Once a year an outside auditor checks the arrangement, unless she is small enough to be exempt, and the exemption line was drawn at £100,000 of customer money over a fifty-three week look-back.
And she must decide, in advance, how long she is allowed to be broken. The regulator does not ask Rina to promise her systems will never fail. It asks her to name the handful of things she does that would genuinely hurt somebody if they stopped — for her, getting rent to landlords — and then to write down the longest outage a customer could survive. Four hours. Twelve. A day. Then she must map everything that service depends on, including other people’s computers she does not control, and test whether she could really stay inside her own number when things go badly wrong. The regulator’s interest is not in the promise. It is in whether she has done the arithmetic honestly.
Now the fifth thing, which is not about Rina at all, but about the price of card payments.
When you buy a £50 pair of shoes with a debit card, the shop does not get £50. A small slice is taken out and passed back to the bank that issued your card. That slice is called interchange. Left alone it would be set by the card networks, who are in the odd position of setting a fee paid by one of their customers to another, with no particular pressure to keep it low.
So the law caps it. As the rules stood at the time of writing in August 2026, interchange on a consumer debit card transaction within the UK was capped at 0.2% of the value, and on a consumer credit card at 0.3%. On your £50 shoes, that is ten pence on debit and fifteen pence on credit. It sounds trivial. Across the country it is billions of pounds a year, which is why it is one of the most bitterly litigated numbers in British commerce.
And finally, the thing that makes this chapter the one most likely to date: the map of who is in charge is itself being redrawn. There were, at the time of writing, two payments regulators in the UK. The FCA licenses and supervises firms. The Payment Systems Regulator, the PSR, regulates the shared plumbing, and it was the PSR that set the interchange rules and the rules on refunding scam victims. In March 2025 the government announced it would abolish the PSR and move its work into the FCA, and the consultation response confirming that decision was published on 21 April 2026. As at the time of writing in August 2026 the PSR still existed and still had its powers, because the merger needs an Act of Parliament that had not yet been passed.
That is the plain version. Permission, capital, the room out the back, an honest number for how long you may be broken, a cap on the card fee, and two regulators becoming one.
Where the plain version stops being true#
Safeguarded is not insured, and the £85,000 you have heard of is not this £85,000. The analogy suggests that if the office closes you walk round the back and collect your suitcase. It is not that clean. Money held by a payment institution or an e-money institution is not a bank deposit and is not covered by the Financial Services Compensation Scheme. There is no government-backed £85,000 guarantee behind it. What safeguarding creates is a pool of assets meant to be paid out to customers ahead of the failed firm’s ordinary creditors, and whether that pool is full is a question of fact. Historically it very often was not. The FCA stated in its September 2024 consultation CP24/20 that of the twelve payments firms that became insolvent between the first quarter of 2018 and the second quarter of 2023, the average shortfall between funds owed to customers and funds actually safeguarded was 65%, and for e-money institutions alone 80%. Where money was eventually distributed it took on average 2.3 years to reach customers. Sixty-five pence in the pound, two and a bit years late, is a materially different outcome from collecting your suitcase. Separately, the £85,000 that appears in British payments conversation usually refers to something else entirely: the maximum reimbursement per claim under the mandatory refund rules for authorised push payment scams, confirmed by the PSR in policy statement PS24/7 and applying since 7 October 2024. Same number, different mechanism, different money, no connection.
There is no single “payments regulator”, and several of the most binding rulebooks are not law at all. The plain version names two regulators and implies they cover the field. They do not. The Bank of England supervises the payment systems that matter most to financial stability under Part 5 of the Banking Act 2009; the Prudential Regulation Authority supervises banks’ safety and soundness; anti-money-laundering supervision runs on its own track under the Money Laundering Regulations 2017; data protection sits with the Information Commissioner’s Office. And running alongside all of it are rulebooks that bind harder than most legislation while being nobody’s law: the Visa and Mastercard operating rules, private contracts revised at least annually and enforced with fines through the acquiring chain; Pay.UK’s scheme rules for Bacs, Faster Payments and Direct Debit; the PCI Data Security Standard, published by an industry council with no statutory authority whatsoever, which nonetheless determines whether a merchant may accept cards at all. A firm can be perfectly compliant with the Payment Services Regulations and be shut down in a fortnight by a card scheme. Practitioners spend more of their week on the private rulebooks than on the statutes.
PSD2 is not, and never was, the law in the United Kingdom, and the British copies of the European rules are actively drifting. People say “PSD2 applies in the UK” as shorthand and it is false in a way that matters. The Second Payment Services Directive was a directive: an instruction to member states to legislate. The United Kingdom’s legislation was the Payment Services Regulations 2017 and a set of FCA rules, and after departure from the European Union what remains is assimilated law that Parliament and the FCA can change unilaterally, and have. The Financial Services and Markets Act 2023 provides for the wholesale repeal of assimilated financial services law, to be replaced by FCA Handbook rules, on a timetable still running. Divergence already exists: on 19 March 2026 FCA rule changes took effect removing the mandatory £100 single-transaction contactless limit and allowing firms with strong fraud controls to set their own, a change with no European equivalent. Meanwhile the European Union is replacing PSD2 outright. Anyone quoting an article number should say which body of law they are quoting and on what date.
The interchange cap does not cap what a merchant pays, and it does not apply to most of the transactions merchants complain about. Interchange is one component of the merchant service charge. The other two are the scheme fees, charged directly by the card networks and not capped at all, and the acquirer’s own margin. Capping interchange at 0.2% has never stopped the total cost of card acceptance rising. Further, the caps apply to consumer debit and credit cards on transactions within the relevant territory. They do not apply to commercial cards, nor where the issuer is outside the territory, and three-party schemes such as American Express fall outside them except in defined circumstances. This is not a loophole; it is the deliberate scope of the rule. It is also why the most expensive card in a merchant’s mix is usually a foreign-issued commercial credit card, on which no cap bites at all.
The technical version#
The institutional map, as at August 2026#
Four public bodies and one department share the United Kingdom’s payments perimeter, and they derive their powers from four different statutes.
The Financial Conduct Authority authorises, registers and supervises payment service providers under the Payment Services Regulations 2017 (SI 2017/752) and electronic money issuers under the Electronic Money Regulations 2011 (SI 2011/99). For banks and building societies it acts as conduct regulator under the Financial Services and Markets Act 2000. It also publishes the finalised guidance Payment Services and Electronic Money — Our Approach, not binding but the document practitioners actually read; version 6 appeared in November 2024 and an amended version was published in draft alongside PS25/12 for May 2026.
The Payment Systems Regulator is the economic regulator of designated payment systems under Part 5 of the Financial Services (Banking Reform) Act 2013. It is also the competent authority for the interchange fee caps under the Payment Card Interchange Fee Regulations 2015 (SI 2015/1911), and holds functions under Part 8 of the PSRs 2017 on access to payment systems and under the Payment Accounts Regulations 2015 on the Current Account Switch Service.
The Bank of England supervises recognised payment systems and specified service providers under Part 5 of the Banking Act 2009, and operates CHAPS and the real-time gross settlement infrastructure. The Prudential Regulation Authority supervises deposit-takers and designated investment firms. HM Treasury sets the framework: its November 2024 National Payments Vision and the associated Payments Forward Plan set the direction, and the Payments Vision Delivery Committee coordinates.
On 11 March 2025, as part of its Regulation Action Plan, the government announced its intention to abolish the PSR and consolidate its functions primarily within the FCA. It consulted in September 2025 in A Streamlined Approach to Payment Systems Regulation and published the consultation response on 21 April 2026. The response confirms the intention to transfer the PSR’s functions entirely to the FCA, integrating them into the FSMA framework so far as practicable; to retain a designation regime for bringing payment systems in and out of scope; to carry over objectives equivalent in substance to the PSR’s competition, innovation and service-user objectives; to transfer its functions under the PSRs 2017, the Payment Card Interchange Fee Regulations 2015 and the Payment Accounts Regulations 2015, together with the authorised push payment reimbursement requirements; to create a single access regime by removing the Part 8 PSRs route in favour of the FSBRA one; and to make specific directions appealable to the High Court rather than the Competition Appeal Tribunal. Consolidation requires primary legislation, and the response says only that the government will legislate “as soon as parliamentary time allows”. As at the time of writing in August 2026 that legislation had not been introduced and the PSR remained a separate body.
Authorisation categories under the PSRs 2017 and EMRs 2011#
Five categories matter. The distinctions are about scale, about whether the firm issues e-money, and about which of the payment services in Schedule 1 to the PSRs 2017 it intends to provide.
| Category | May do | Scale limit | Initial capital | Ongoing own funds |
|---|---|---|---|---|
| Authorised payment institution | Any Schedule 1 payment service, including payment initiation and account information | None | EUR 125,000 general; EUR 50,000 payment initiation only; EUR 20,000 money remittance only; none for account information only | Method A, B or C as the FCA directs |
| Small payment institution | Schedule 1 services other than payment initiation and account information | Monthly average of payment transactions over the preceding 12 months not exceeding EUR 3 million | None | None |
| Authorised e-money institution | Issue e-money and provide payment services | None | EUR 350,000 | 2% of average outstanding e-money; Method A, B or C for unrelated payment services |
| Small e-money institution | Issue e-money and payment services other than payment initiation and account information | Average outstanding e-money not exceeding EUR 5 million; unrelated payment transactions not exceeding EUR 3 million monthly average | Set by Schedule 2 EMRs | 2% of average outstanding e-money where required |
| Registered account information service provider | Account information services only | None | None | None |
All figures in that table are as they stood at the time of writing in August 2026, and all are stated in euros in the United Kingdom’s own legislation, the amounts having been carried across from the European originals without conversion.
Three points a practitioner will insist on. First, a payment institution may not issue e-money; an e-money institution may do both, which is why firms issuing prepaid cards, wallets or stored balances need the EMI licence and the higher capital. Second, initial capital is a floor applying from day one, whereas own funds is a continuing calculation. Method A is 10% of the previous financial year’s fixed overheads. Method B is a tiered percentage of payment volume: 4% of the first EUR 5 million of monthly volume annualised, 2.5% of the next EUR 5 million, 1% of the next EUR 90 million, 0.5% of the next EUR 150 million and 0.25% of the remainder, times a scaling factor of 0.5 for money remittance and 1 otherwise. Method C applies tiered percentages to a relevant indicator built from interest income and expense, commissions and other operating income, with a floor of 80% of the three-year average. The FCA directs which applies. Third, providing payment services in the UK without authorisation or registration is a criminal offence under regulation 138 of the PSRs 2017, not a technical breach.
On process: under regulation 9 of the PSRs 2017 and regulation 9 of the EMRs, the FCA must determine a complete application within three months of receiving it, and an incomplete one within twelve months. The clock runs from completeness, not submission, which is why published median timelines bear little relation to the statutory figure; the Approach Document confirms the point at paragraph 3.196. Agents are separately registered under regulation 34 and the principal remains fully responsible for their acts and omissions, while distributors of e-money are not registered in the same way, a difference that has caused repeated supervisory difficulty.
Safeguarding, and why it dominates everything else#
The prudential logic here is unusual. Capital requirements in banking exist to absorb losses so the institution continues as a going concern. In payments the capital numbers are deliberately small relative to the customer balances held, because these firms do not take credit risk on customer money as a bank does. The regulatory weight therefore falls almost entirely on the gone-concern question: when this firm fails, do its customers get their money back, in full, quickly?
Under regulation 23 of the PSRs 2017, an authorised payment institution must safeguard “relevant funds”: broadly, sums received from or for the benefit of a payment service user for the execution of a payment transaction, and sums received from another provider for that purpose. Regulations 20 to 22 of the EMRs impose the equivalent obligation on e-money institutions for funds received in exchange for e-money issued.
There are two permitted methods and a firm may use each for different funds. The segregation method requires relevant funds to be kept separate from the firm’s own money and, where still held at the end of the business day following the day of receipt, placed in a separate account with an authorised credit institution or the Bank of England, or invested in secure liquid assets. The insurance or guarantee method requires cover by a policy with an authorised insurer, or a comparable guarantee from an authorised insurer or credit institution, with proceeds payable into a separate account on insolvency. In practice the overwhelming majority segregate, because insurers write very little of this cover and price it punitively.
The gap between what the regulations say and what happens in insolvency was exposed by Re Ipagoo LLP [2022] EWCA Civ 302, decided on 9 March 2022. Ipagoo was an authorised e-money institution that went into administration having failed to safeguard sufficient relevant funds. The FCA argued that the EMRs impose a statutory trust over relevant funds from the moment of receipt. The Court of Appeal held that they do not. It did hold that the regulations create a statutory asset pool for the benefit of e-money holders, and that where relevant funds should have been safeguarded but were not, the pool falls to be topped up from the general estate. Customers therefore rank ahead of ordinary creditors in respect of the pool, but without the proprietary certainty a trust would give, and insolvency costs can bite in ways they would not under a clean trust.
That case, together with the insolvency data, drove consultation CP24/20, published on 25 September 2024 and closed on 17 December 2024, which proposed two stages: an interim set of rules to raise compliance with the existing statutory requirements, and an end-state regime replacing the statutory safeguarding provisions with a sourcebook modelled on the Client Assets Sourcebook, including an express statutory trust.
The outcome was policy statement PS25/12, published on 7 August 2025, with the interim rules renamed the Supplementary Regime and the end-state rules the Post-Repeal Regime. The Supplementary Regime, made by the Payments and Electronic Money (Safeguarding) Instrument 2025 and inserted into the Handbook as CASS 15, came into force on 7 May 2026. Its principal requirements, as stated in PS25/12 and accurate at the time of writing in August 2026, are internal and external reconciliations of safeguarded funds on each business day, not required on weekends, public holidays and days when relevant foreign markets are closed, with discrepancies resolved promptly; a new monthly safeguarding return, revised after a pilot exercise; an annual safeguarding audit by a qualified auditor for authorised payment institutions and authorised e-money institutions, subject to an exemption where the firm has not been required to safeguard more than £100,000 of relevant funds at any time over a period of at least fifty-three weeks; a contingency plan at least three months before the expiry of any safeguarding insurance policy or comparable guarantee, that lead period retained despite industry objection; retention of the existing range of permitted secure liquid assets, the FCA explicitly maintaining a low risk tolerance towards broadening it; and resolution pack requirements aligned to CASS practice. The FCA also removed the proposed limited assurance engagement for firms claiming to hold no relevant funds, replacing it with guidance that a statutory auditor should notify the FCA if a firm has failed to safeguard.
Two significant CP24/20 proposals did not proceed at this stage: the requirement to receive relevant funds directly into a designated safeguarding account, and the corresponding treatment of funds received through agents and distributors. Both were held back pending further consideration alongside the statutory trust proposal. The FCA has said it will not proceed with the Post-Repeal Regime without further consultation, and will review implementation once a full audit period has been completed.
The regime applies to authorised payment institutions other than those providing only payment initiation or account information services, authorised e-money institutions, small e-money institutions, and credit unions issuing e-money in the UK. Small payment institutions may opt in.
Underneath all of this sits the Payment and Electronic Money Institution Insolvency Regulations 2021 (SI 2021/716), a bespoke special administration regime for these firms with the return of relevant funds as a statutory objective and a court-approved distribution plan mechanism. HM Treasury launched an independent review of it in 2024 and the report has since been published.
Interchange regulation#
The caps entered European law through Regulation (EU) 2015/751 on interchange fees for card-based payment transactions, applying from 9 December 2015. That regulation was assimilated into United Kingdom law and amended so that its operative provisions now refer to UK transactions.
As the assimilated regulation stood at the time of writing in August 2026, Article 3 provides that payment service providers must not offer or request a per-transaction interchange fee of more than 0.2% of transaction value for any UK debit card transaction, with a Treasury power to lower that percentage, impose a fixed maximum, or permit an alternative not exceeding the sterling equivalent of EUR 0.05 per transaction, provided the scheme’s aggregate annual interchange stays within 0.2% of annual transaction value. Article 4 sets the equivalent cap for any UK credit card transaction at 0.3%, again with a Treasury power to lower but not raise it. Legislation.gov.uk records the regulation as subject to revocation under Schedule 1 to the Financial Services and Markets Act 2023, a change not yet applied at the time of writing.
The regulation is not only about price. Articles 6 to 11 carry the business rules that shape the acquiring market: licensing, prohibiting territorial restrictions; separation of payment card scheme and processing entities; co-badging and the payer’s right to choose the brand or application at the point of sale; unblending, which requires acquirers to offer merchant service charges itemised by category and brand of card rather than a single blended rate; the Honour All Cards rule, which prevents schemes obliging merchants to accept every card of a brand irrespective of category; and steering, which permits merchants to steer customers towards cheaper instruments. Unblending made the true cost of card acceptance visible to merchants, and is the reason interchange-plus pricing exists at all. Separately, regulation 166 of the PSRs 2017 prohibits surcharging on most consumer card payments in the UK.
The post-departure history is the interesting part. After the end of the transition period, Mastercard and Visa increased interchange on card-not-present transactions between the UK and the European Economic Area, for consumer debit and credit cards, from 0.2% and 0.3% to 1.15% and 1.5% respectively. The PSR opened market review MR22/2. Its final report, MR22/2.7, found that Mastercard and Visa, which between them account for 99% of UK debit and credit card payments, were not subject to effective competitive constraints; that the increases were costing UK businesses an additional £150 million to £200 million annually; and that neither scheme could demonstrate any specific assessment underpinning the decision. The PSR consulted on a two-stage remedy: an interim cap followed by a longer-term cap.
Visa, Mastercard and Revolut challenged the PSR’s power to impose such a cap by judicial review. The High Court dismissed all three challenges on 15 January 2026, in [2026] EWHC 64, upholding the PSR’s statutory power to impose price caps on cross-border interchange fees. The PSR then decided, in MR22/2.9, not to proceed with an interim cap, preferring to move directly to a longer-term cap once it had developed a robust methodology, on which it consulted in MR22/2.8. As at the time of writing in August 2026, no cap on UK-EEA cross-border interchange had been imposed. HM Treasury’s April 2026 consultation response states that the ability to impose price controls will carry over to the FCA on consolidation.
Running in parallel, and quite separately, is the private litigation. The Competition Appeal Tribunal’s judgment of 27 June 2025 in the umbrella interchange proceedings, brought by over two thousand merchant claimants, held that the schemes’ default interchange fee arrangements restricted competition in the acquiring market contrary to Article 101(1) of the Treaty on the Functioning of the European Union in respect of inter-regional and commercial card transactions. Permission to appeal was sought in August 2025 and the appellate proceedings were live at the time of writing. Interchange is therefore regulated on two tracks at once — a regulatory cap track and a competition law damages track — and they can reach different answers about the same fee.
Operational resilience#
The FCA’s operational resilience regime was made by policy statement PS21/3, published in March 2021, with the rules in SYSC 15A taking effect on 31 March 2022 and a transitional period ending on 31 March 2025. Its scope expressly includes entities authorised and registered under the PSRs 2017 and the EMRs, alongside banks, building societies, insurers, enhanced-scope Senior Managers and Certification Regime firms and recognised investment exchanges.
The regime rests on four obligations. A firm must identify its important business services, defined as services provided to clients which, if disrupted, could cause intolerable levels of harm to one or more clients or pose a risk to the soundness, stability or resilience of the UK financial system. It must set an impact tolerance for each, being the maximum tolerable level of disruption, measured as a length of time and any other relevant metric. It must map the people, processes, technology, facilities and information supporting each service, test its ability to remain within tolerance under severe but plausible scenarios, and produce a board-approved self-assessment.
By 31 March 2025 firms were required to have completed mapping and testing to the sophistication necessary to demonstrate that they can remain within impact tolerances. The FCA’s supervisory observations emphasise several things firms routinely get wrong: that a service should not be excluded from the list on the strength of a single factor; that identification must be done without reference to the firm’s response and recovery capabilities, so a service is not made unimportant by being well protected; that interdependencies and sub-contracting chains must be considered; and, critically, that the firm remains responsible for staying within its impact tolerance even where a third party delivers the service. A firm may rely on a third party’s own testing, but must satisfy itself that the methodology and scenarios are adequate.
Two further layers sit on top.
Incident and third-party reporting. Regulation 98 of the PSRs 2017 requires payment service providers to maintain a framework for managing operational and security risks with an annual assessment, and regulation 99 requires notification of major operational or security incidents without undue delay. Following consultation CP24/28, published 13 December 2024 and closed 13 March 2025, the FCA published policy statement PS26/2 on 18 March 2026, with finalised guidance FG26/3 and FG26/4. PS26/2 creates a single regime shared across the FCA, the PRA and the Bank of England, and its rules come into force on 18 March 2027. It defines an operational incident, sets reporting thresholds, and introduces a standardised single submission regardless of which regulator the report is for, with a two-tier model of standard and enhanced reporting. The FCA threshold is that the firm reasonably believes the incident poses a risk of intolerable harm to consumers from which they cannot easily recover, or a risk to the safety and soundness of the firm or other market participants, or a risk to market stability, integrity or confidence in the UK financial system. Reportability is not limited to incidents affecting an important business service, and payment service providers will discharge their regulation 99 obligations through this regime. The third-party rules apply to a narrower population expressly including authorised e-money institutions and authorised payment institutions, requiring notification of new or significantly changed material third party arrangements and an annually submitted register.
Critical third parties. The Financial Services and Markets Act 2023 gave HM Treasury power to designate a third party providing services to regulated firms as a critical third party, and gave the regulators rule-making and enforcement powers over designated entities. The final rules, published jointly as FCA PS24/16 and PRA PS16/24 on 12 November 2024, took effect on 1 January 2025, but apply to a provider only from the date its designation order comes into force. On 10 July 2026 HM Treasury designated the first critical third parties, with effect from 13 July 2026: Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL and Oracle Corporation UK Limited. Designation does not reduce the responsibility of the firms relying on those providers; it adds a supervisory relationship with the provider itself.
The European Union position, and where the two regimes now differ#
The Second Payment Services Directive, Directive (EU) 2015/2366, applied from 13 January 2018, with the regulatory technical standards on strong customer authentication and common and secure communication, Delegated Regulation (EU) 2018/389, applying from 14 September 2019. The Second Electronic Money Directive, 2009/110/EC, sits alongside it. The European Banking Authority issues guidelines and technical standards; national competent authorities supervise.
On 28 June 2023 the European Commission published two proposals: PSD3, COM(2023)366, a directive covering licensing, prudential requirements and supervision, and the Payment Services Regulation, COM(2023)367, a directly applicable regulation covering conduct, transparency and rights and obligations. Splitting the regime this way is the point: conduct rules become uniform without national transposition, while authorisation remains a directive.
The legislative position, as at the time of writing in August 2026: Parliament adopted its first-reading position on 23 April 2024; Parliament and Council reached provisional political agreement on 27 November 2025; and the text agreed at early second-reading negotiations was approved in the ECON committee on 5 May 2026. The European Parliament’s legislative train summary, updated 20 June 2026, records that the deal still needs formal adoption by Parliament and Council before it can enter into force, and the Parliament’s own Legislative Observatory still shows the file as awaiting the Council’s first-reading position, with an indicative plenary sitting date of 14 December 2026. Nothing has therefore reached the Official Journal, and the practitioner expectation of publication in the first half of 2026 has already been overtaken. The application clock itself is not speculation: the final compromise texts published in the Council’s public document register, 8221/26 for the Regulation and 8222/26 for the Directive, both dated 17 April 2026, provide that the Regulation applies twenty-one months after its entry into force, that member states must adopt, publish and apply their transposing measures within the same twenty-one months, and that the payee verification provisions in Articles 50 and 57 of the Regulation apply only from twenty-seven months. Entry into force is twenty days after Official Journal publication, so the whole calendar can be counted precisely from the day that publication happens, and not a day before.
The substantive changes that matter most, as reported in the agreed texts: e-money institutions cease to exist as a separate category and become a sub-category of payment institutions, with e-money issuance treated as a payment service in the annex to PSD3 and the Second Electronic Money Directive repealed; payment institutions gain an option, at national discretion, to safeguard customer funds at a central bank; providers must offer a payee verification service and inform the payer of discrepancies; liability extends to failures to implement appropriate fraud prevention mechanisms, and to impersonation fraud where the customer has reported the matter to the police and the provider; online platforms that fail to remove fraudulent financial content after notification become liable to providers that have reimbursed defrauded customers; advertisers of financial services must demonstrate to very large online platforms and search engines that they are authorised or exempt; and users gain a right of access to human customer support.
Separately, and already in force, the Instant Payments Regulation (EU) 2024/886, adopted on 13 March 2024, amends the SEPA Regulation to require euro instant credit transfers, charge parity with ordinary transfers, a free verification of payee service, and at-least-daily sanctions screening of customers rather than transaction-by-transaction screening. Its deadlines, as published by the European Central Bank, are staggered:
| Requirement | Applies to | Deadline |
|---|---|---|
| Receiving instant payments, and equality of charges | Euro area member states | 9 January 2025 |
| Sending instant payments, and verification of payee | Euro area member states | 9 October 2025 |
| Receiving instant payments, and equality of charges | Non-euro area member states | 9 January 2027 |
| Receiving instant payments | EMIs and PIs, euro and non-euro area | 9 April 2027 |
| Sending instant payments | EMIs and PIs in euro area member states | 9 April 2027 |
| Sending instant payments, and verification of payee | Non-euro area member states, and their EMIs and PIs | 9 July 2027 |
| Sending outside business hours from national currency accounts | Non-euro area member states | 9 June 2028 |
The same regulation, through amendments to PSD2 and the Settlement Finality Directive, makes payment institutions and e-money institutions eligible to participate directly in designated payment systems. Since October 2025 non-bank payment service providers meeting the TARGET Guideline requirements have been able to access TARGET services including T2 and TIPS. That is a structural change of the first order: it removes the requirement for a non-bank to hold its settlement position at a commercial bank that is also its competitor.
On operational resilience, the European regime is the Digital Operational Resilience Act, Regulation (EU) 2022/2554, which has applied since 17 January 2025. It covers ICT risk management, incident classification and reporting, resilience testing including threat-led penetration testing for significant entities, ICT third-party risk management with prescribed contractual terms, and direct oversight of critical ICT third-party providers by the European Supervisory Authorities. Firms operating on both sides will find the UK and EU regimes conceptually similar and mechanically incompatible: impact tolerances and important business services on one side, ICT risk management and register-of-information reporting on the other, with different thresholds and different clocks.
The United Kingdom’s own moving parts#
Three UK changes bear directly on how a payments firm operates, and each has an explicit date.
The Payment Services (Amendment) Regulations 2024 came into force on 30 October 2024, permitting a payment service provider to delay execution of an outbound sterling payment within the UK where it has reasonable grounds to suspect fraud or dishonesty and needs to make further enquiries. The delay must be no longer than necessary and in any event no longer than the end of the fourth business day from receipt of the payment order. The provider must tell the customer of the delay and its reasons unless disclosure would be unlawful, and is liable for any charges or interest the customer incurs.
The authorised push payment reimbursement requirement has applied since 7 October 2024, imposed by the PSR through Specific Direction 20 for Faster Payments and mirrored by the Bank of England for CHAPS. The maximum reimbursement is £85,000 per claim, confirmed in PSR policy statement PS24/7 in October 2024, which reduced a previously confirmed maximum of £415,000 before go-live. The PSR estimated that £85,000 fully covers 99.8% of Faster Payments authorised push payment scams by volume and 90% by value.
The contactless rule changes announced by the FCA in December 2025 took effect on 19 March 2026, removing the mandatory £100 single-transaction limit and the cumulative limit and giving firms with strong fraud controls the flexibility to set their own. Nothing obliges a firm to change anything, and terminal and scheme-rule changes are also needed before higher-value contactless card transactions can be processed. The pattern will recur: a fixed numerical rule replaced by a risk-based standard, with the supervisory question shifting from compliance with a threshold to the demonstrable quality of a firm’s own fraud monitoring.
What this means for a firm actually operating#
The standing obligations of a mid-sized authorised payment institution, as at August 2026, run wider than most people building a payments product expect: own funds on the applicable method; daily safeguarding reconciliation and the monthly return; the annual safeguarding audit; the regulation 98 risk framework and its annual assessment; the SYSC 15A self-assessment, mapping and testing; professional indemnity insurance for payment initiation or account information services; the Money Laundering Regulations 2017; the Consumer Duty in PRIN 2A where it applies; complaints under DISP; strong customer authentication; the reporting cycle under SUP 16.13; registration of agents before they act; and, from 18 March 2027, notification of material third party arrangements and the register.
The single most common cause of serious regulatory difficulty in this sector is not any of those in isolation. It is the gap between what a firm’s safeguarding documentation says and what its bank accounts actually contain, discovered late. Everything the FCA has done since CP24/20 shortens the interval at which a discrepancy becomes visible: from an annual audit, to a monthly return, to a daily reconciliation. A firm that treats the daily reconciliation as a compliance chore has misunderstood it. It is the early warning system for the only failure mode that genuinely destroys customers.
What is most likely to be wrong in this chapter first#
Three things, and it is better to name them than to pretend otherwise.
The abolition of the Payment Systems Regulator is government policy with a published consultation response but no Act of Parliament. When the legislation passes, every reference here to the PSR as a separate body becomes historical, and the statutory basis for interchange regulation and for the reimbursement rules will move.
The European Union’s PSD3 and Payment Services Regulation package had reached committee approval of an agreed text but, on the author’s checking in August 2026, had not been verified as adopted and published in the Official Journal. Once it applies, e-money institutions cease to be a separate category in the European Union while remaining one in the United Kingdom: the largest structural divergence between the two regimes since departure.
And the whole of the United Kingdom’s assimilated payment services law is subject to repeal under the Financial Services and Markets Act 2023, with firm-facing requirements expected to move into FCA rules. When that happens, the regulation numbers used throughout this chapter — regulation 23 for safeguarding, regulation 98 for security risk, regulation 138 for the criminal offence, Schedule 3 for capital — will cease to exist even where the substance survives in renumbered form. Every figure and deadline here should be checked against the source before it is relied on, and the sources are named below precisely so that it can be.
53.98 Common wrong ideas#
Wrong: Money held by a payment institution or e-money institution is protected up to £85,000 like a bank deposit. Right: It is not a deposit and the Financial Services Compensation Scheme does not cover it; safeguarding creates a pool meant to be paid to customers ahead of ordinary creditors, and whether that pool is full is a question of fact.
Wrong: The £85,000 figure in British payments is the safeguarding guarantee. Right: It is the maximum reimbursement per claim under the mandatory authorised push payment scam rules confirmed in PSR policy statement PS24/7, applying since 7 October 2024 — the same number attached to a different mechanism, with no connection between them.
Wrong: Safeguarded funds are held on trust from the moment they are received. Right: Re Ipagoo LLP held that the Electronic Money Regulations impose no statutory trust; they create a statutory asset pool topped up from the general estate, so customers rank ahead of ordinary creditors but without the proprietary certainty a trust would give.
Wrong: There is a payments regulator, and complying with its rules is what keeps you trading. Right: The FCA, the PSR, the Bank of England, the PRA and HM Treasury all hold pieces of the perimeter, and the private rulebooks — the Visa and Mastercard operating rules, Pay.UK’s scheme rules, the PCI Data Security Standard — bind harder than much legislation; a firm perfectly compliant with the Payment Services Regulations can be shut down in a fortnight by a card scheme.
Wrong: PSD2 applies in the United Kingdom. Right: PSD2 was a directive instructing member states to legislate; the United Kingdom’s legislation was the Payment Services Regulations 2017 plus FCA rules, now assimilated law that Parliament and the FCA can and do change unilaterally, as the removal of the mandatory £100 contactless limit on 19 March 2026 demonstrates.
Wrong: Capping interchange caps what a merchant pays to accept cards. Right: Interchange is one component of the merchant service charge alongside uncapped scheme fees and the acquirer’s own margin, and capping it has never stopped the total cost of acceptance rising.
Wrong: The interchange caps apply to all cards. Right: They apply to consumer debit and credit cards on transactions within the relevant territory; commercial cards, foreign-issued cards and three-party schemes such as American Express fall outside them by design, which is why the most expensive card in a merchant’s mix is usually one on which no cap bites at all.
Wrong: The FCA has three months to decide an authorisation application, so budget three months. Right: The clock runs from completeness rather than submission, an incomplete application attracts a twelve-month deadline, and most first drafts are not complete.
Wrong: Outsourcing an important business service moves the resilience obligation to the supplier. Right: The firm remains responsible for staying within its own impact tolerance even where a third party delivers the service, and the designation of a critical third party adds supervision of the provider without reducing anybody else’s responsibility.
Wrong: The daily safeguarding reconciliation is a compliance chore. Right: It is the early warning system for the only failure mode that genuinely destroys customers, which is why the FCA has shortened the interval at which a discrepancy becomes visible from an annual audit to a monthly return to a daily count.
53.99 Chapter summary in 20 lines#
- Payments regulation is built around one failure in particular: a firm losing the customer money it was only holding in transit, which no amount of the firm’s own capital would have prevented.
- Moving other people’s money as a business requires a licence from the Financial Conduct Authority, and the licence comes in sizes.
- Five categories matter, distinguished by scale, by whether the firm issues e-money, and by which of the Schedule 1 payment services it provides.
- Initial capital ranges from nothing for an account information service provider to EUR 350,000 for an authorised e-money institution, and the amounts are still stated in euros in British legislation because they were carried across from the European originals without conversion.
- Initial capital is a floor from day one, whereas ongoing own funds is a continuing calculation under Method A, B or C as the FCA directs.
- Providing payment services without authorisation or registration is a criminal offence under regulation 138 of the Payment Services Regulations 2017, not a technical breach.
- The statutory three-month determination period runs from the point an application is complete, which is why published timelines bear so little relation to it.
- Safeguarding carries far more regulatory weight than capital, because the question these rules ask is a gone-concern question: when this firm fails, do its customers get their money back, in full, quickly?
- The honest answer historically was no — an average shortfall of 65 per cent across twelve insolvencies, 80 per cent for e-money institutions alone, and 2.3 years to distribution.
- Re Ipagoo LLP established that the regulations create a statutory asset pool rather than a trust, which is why customers rank ahead of ordinary creditors without proprietary certainty.
- Consultation CP24/20 and policy statement PS25/12 followed, and the Supplementary Regime in CASS 15 came into force on 7 May 2026 with daily internal and external reconciliations, a monthly return and an annual audit subject to a £100,000 exemption.
- Two proposals were held back for further work: receiving relevant funds directly into a designated safeguarding account, and the express statutory trust of the Post-Repeal Regime.
- Operational resilience under SYSC 15A asks a firm to identify its important business services, set an impact tolerance in time for each, map the dependencies, test against severe but plausible scenarios and self-assess at board level.
- A service is not made unimportant by being well protected, and the firm stays responsible for its tolerance even where a third party delivers the service.
- A single incident and third-party reporting regime under PS26/2 comes into force on 18 March 2027, and HM Treasury designated the first critical third parties with effect from 13 July 2026.
- Interchange on UK consumer debit is capped at 0.2% of value and on consumer credit at 0.3% under the assimilated Regulation (EU) 2015/751, with a Treasury power to lower but not to raise.
- That cap reaches only one component of one part of the market, which is why total card acceptance costs have kept rising and why the priciest cards escape it entirely.
- Interchange is contested on two tracks at once — the PSR’s cross-border market review, whose capping power the High Court upheld on 15 January 2026, and the competition damages litigation in the Competition Appeal Tribunal — and the two can reach different answers about the same fee.
- The institutional map is being redrawn: the government confirmed on 21 April 2026 that the PSR’s functions will transfer to the FCA, but consolidation needs an Act of Parliament that had not been introduced by August 2026.
- The whole body of assimilated payment services law is subject to repeal under the Financial Services and Markets Act 2023, so the regulation numbers used here may survive only in renumbered form, and every figure and date should be checked against the named source before it is relied on.
Sources: the Payment Services Regulations 2017, the Electronic Money Regulations 2011, the Payment and Electronic Money Institution Insolvency Regulations 2021, the Payment Card Interchange Fee Regulations 2015 and assimilated Regulation (EU) 2015/751, all via legislation.gov.uk; FCA CP24/20, PS25/12, CP24/28, PS26/2, PS24/16, PS21/3, the December 2025 contactless statement and the Approach Document Payment Services and Electronic Money — Our Approach; PRA and Bank of England PS16/24; PSR MR22/2.7, MR22/2.8, MR22/2.9 and PS24/7; HM Treasury’s National Payments Vision, its April 2026 consultation response A Streamlined Approach to Payment Systems Regulation and its July 2026 critical third party designations; Re Ipagoo LLP [2022] EWCA Civ 302 and the High Court judgment of 15 January 2026; the European Parliament legislative train file on the payment services regulation; and the European Central Bank’s Instant Payments Regulation implementation table.