United Kingdom

UK Authorised Payment Institution Licence: FCA API Requirements, Capital, Cost and Timeline

FCA Authorised Payment Institution authorisation: services, EUR 20k to 125k capital, own funds, CASS 15 safeguarding, fees, timeline and SPI comparison.

EUR 20k to 125k capitalGBP 2,820 or 5,640 fee3-month statutory clock

Written and reviewed by the Regulatory Counsel team. Last reviewed: 28 August 2026.

The short answer

An Authorised Payment Institution (API) is a firm authorised by the FCA under regulation 6 of the Payment Services Regulations 2017 to provide one or more of the payment services in Schedule 1. There is no transaction ceiling, and it is the only payments permission that supports payment initiation services and unrestricted growth.

Initial capital is EUR 20,000 for money remittance only, EUR 50,000 for payment initiation services and EUR 125,000 for the account and transaction execution services in paragraphs (a) to (e) of Schedule 1. Account information services alone require no initial capital. Once authorised, own funds must be maintained under Method A, B or C as directed by the FCA. Relevant funds must be safeguarded under regulation 23 and the supplementary safeguarding regime in CASS 15, which took effect on 7 May 2026.

The FCA application fee is GBP 2,820 (Category 4) for money remittance, payment initiation or account information services, and GBP 5,640 (Category 5) where the firm applies for any of the services in paragraphs (a) to (e). The FCA must determine a complete application within three months and an incomplete application within 12 months. A realistic project runs eight to fourteen months from instruction.

Key facts at a glance

RegulatorFinancial Conduct Authority (FCA)
Permission typeAuthorisation as a payment institution under regulation 6, Payment Services Regulations 2017
Who needs itFirms providing payment services in the UK by way of business that exceed the SPI threshold, need open banking permissions, or require full authorisation for commercial reasons
Local entity required?Yes. A body corporate applicant must have its head office, and if it has a registered office that office, in the United Kingdom
Local management required?No fixed statutory headcount, but the FCA expects UK-based effective direction of the payment services business and approved individuals with genuine authority
Initial capitalEUR 20,000 money remittance; EUR 50,000 payment initiation services; EUR 125,000 for Schedule 1 paragraphs (a) to (e); none for account information services alone
Ongoing own fundsThe higher of initial capital and the amount produced by Method A, B or C as directed by the FCA, which may adjust the result by up to 20 per cent
FCA application feeGBP 2,820 (Category 4) or GBP 5,640 (Category 5) depending on the services applied for
Statutory determination periodThree months for a complete application; 12 months maximum for an incomplete application
Realistic end-to-end timelineEight to fourteen months from instruction, of which three to four months is preparation
RenewalNo renewal. Annual periodic fees, regulatory reporting, a safeguarding audit where applicable and continuing threshold conditions apply
Territorial scopeUnited Kingdom. No EEA passporting since the end of the transition period

Get Expert Advice

Whether you need licensing support, compliance advice or regulatory strategy, our team is ready to help. Free initial consultation - no obligation.

Get Expert Advice

Free initial consultation. No obligation.

What is the UK Authorised Payment Institution licence?

The UK Authorised Payment Institution (API) licence authorises firms to provide regulated payment services under Schedule 1 of the Payment Services Regulations 2017 (PSR 2017). These services include money remittance, payment processing, merchant acquisition, payment initiation services (PIS) and account information services (AIS). The licence is issued by the Financial Conduct Authority (FCA).

Operating a payment services business in the United Kingdom without FCA authorisation or registration is a criminal offence under Regulation 138 of the Payment Services Regulations 2017. Persons convicted on indictment face imprisonment for up to two years and/or an unlimited fine.

The API licence is the full authorisation route - as distinct from Small Payment Institution (SPI) registration - and is required by any firm whose average monthly payment transaction volume exceeds €3 million or that wishes to passport into EEA states.

Who Needs UK Authorised Payment Institution licence?

The API licence is required by any firm carrying on payment services business in the UK that exceeds the Small Payment Institution thresholds or requires passporting rights.

  • - Fintech firms processing payments above the €3 million monthly threshold
  • - Money remittance businesses (international transfers, cross-border payments)
  • - Payment processors and payment facilitators
  • - Merchant acquirers
  • - Open banking providers offering PIS or AIS
  • - Firms operating multi-currency payment accounts without e-money issuance
  • - Payment platforms seeking to passport into EEA member states

A common misconception is that firms providing payment-adjacent services - such as software platforms that aggregate payment flows or marketplace platforms that hold funds in transit - are exempt from authorisation. In most cases, these activities fall within the regulatory perimeter. The FCA takes an expansive view of what constitutes a payment service, and firms should seek regulatory advice before concluding they are out of scope.

Which payment services does an API cover?

Schedule 1 to the Payment Services Regulations 2017 lists the regulated payment services. An application must specify each service sought, because permissions, capital and own funds all follow from that list.

  • - Services enabling cash to be placed on, or withdrawn from, a payment account
  • - Execution of payment transactions, including direct debits, card transactions and credit transfers
  • - Execution of payment transactions where the funds are covered by a credit line
  • - Issuing payment instruments or acquiring payment transactions
  • - Money remittance
  • - Payment initiation services
  • - Account information services

When is API authorisation required rather than SPI registration?

  • - The monthly average of payment transactions over 12 months exceeds, or will exceed, EUR 3 million
  • - The business provides payment initiation services, which cannot be carried on under SPI registration
  • - The firm needs to appoint agents at scale or build a distribution network
  • - Banking, card scheme or institutional counterparties require authorised status as a condition of onboarding
  • - The firm intends to hold significant customer funds and wants the safeguarding regime and market credibility that come with authorisation

Initial capital and own funds

Initial capital is set by Schedule 3 and is stated in euros in the legislation, with no fixed sterling conversion. Money remittance requires EUR 20,000, payment initiation services require EUR 50,000, and the services in paragraphs (a) to (e) require EUR 125,000. A firm applying for a combination takes the highest applicable figure.

After authorisation, own funds must be maintained at the higher of the initial capital floor and the amount produced by the applicable own funds method. Method A is based on fixed overheads, Method B on payment volume, and Method C on an income-based indicator. The FCA directs which method applies and may adjust the result by up to 20 per cent either way based on its assessment of the firm.

The practical point that catches firms out is timing. Own funds are a continuing requirement, so a business that scales volume quickly can outgrow its capital base long before it plans its next funding round. Capital planning should be modelled against the own funds method that will actually apply, not against the initial capital figure.

Safeguarding and CASS 15

Regulation 23 requires an authorised payment institution to safeguard relevant funds, either by segregating them in a designated account with an authorised credit institution or by covering them with an insurance policy or comparable guarantee. Segregated funds must be held so that they are protected from the claims of other creditors.

The FCA strengthened the regime through PS25/12, and the CASS 15 chapter of the Handbook took effect on 7 May 2026. The direction of travel is towards CASS-style discipline: specific records and accounts requirements, reconciliation on each reconciliation day, prompt correction of discrepancies, clear acknowledgement letters and independent assurance over the arrangements.

Safeguarding is now the single most examined area of UK payments supervision. Applications that treat it as an account-opening formality rather than an operating model with reconciliation, governance and evidence attract detailed scrutiny.

Governance, UK substance and key individuals

  • - A body corporate applicant must have its head office in the UK and carry on at least part of its payment service business here
  • - Directors and persons responsible for the payment services business must be of good repute and possess appropriate knowledge and experience
  • - Persons with a qualifying holding are assessed for suitability, which in group structures means tracing beneficial ownership to natural persons
  • - A money laundering reporting officer with genuine seniority, UK availability and authority over the AML framework
  • - Clear allocation of responsibilities across risk, compliance, finance and operations, evidenced by terms of reference and management information rather than an organisation chart alone

Business plan, programme of operations and forecasts

The programme of operations must describe each payment service and the exact flow of funds. The business plan must describe the model, the market, the distribution strategy and the operating structure, supported by a forecast budget for the first three financial years that demonstrates the firm can meet own funds requirements throughout.

The FCA reads these documents against each other and against the AML risk assessment. Where a forecast assumes corridors, customer types or volumes that the risk assessment does not address, the application stalls.

AML, operational and security requirements

  • - A business-wide money laundering and terrorist financing risk assessment specific to the firm's products, corridors, customers and delivery channels
  • - Customer due diligence, enhanced due diligence, sanctions and PEP screening, transaction monitoring and suspicious activity reporting procedures that match the systems the firm has actually procured
  • - A security policy document describing the control framework, including a description of security control and mitigation measures for payment services
  • - Operational and security risk management arrangements, incident management and major incident reporting capability
  • - Business continuity, outsourcing governance including exit planning, and complaints handling within Financial Ombudsman Service jurisdiction
  • - Strong customer authentication design for the relevant services, and where applicable the technical arrangements for access to payment accounts

Ongoing reporting and compliance after authorisation

  • - Periodic regulatory returns covering payment volumes, capital adequacy, operational and security risk and financial crime data
  • - Own funds monitoring against the directed method and prompt notification where the position deteriorates
  • - Safeguarding records, reconciliations and independent assurance under the current safeguarding regime
  • - Notification of changes in control, changes to permissions, agent appointments and material outsourcing
  • - Annual periodic fees and Financial Ombudsman Service levies
  • - Complaints reporting and adherence to conduct requirements including the Consumer Duty where the firm serves retail customers

SPI vs API

The choice between registration and authorisation is a commercial decision as much as a regulatory one.

Decision pointSmall Payment InstitutionAuthorised Payment Institution
Transaction ceilingEUR 3 million monthly averageNone
Initial capitalNone prescribedEUR 20,000, EUR 50,000 or EUR 125,000
Payment initiation and account informationExcludedAvailable
SafeguardingNot imposed by regulation 23; voluntary opt-inMandatory under regulation 23 and CASS 15
FCA application feeGBP 1,130GBP 2,820 or GBP 5,640
Typical preparationFour to six weeksThree to four months
Counterparty acceptanceMixedBroadly expected by banks and schemes

API vs EMI: payment services or electronic money?

The dividing line is whether the firm issues stored value. If customers hold a balance that can be spent with third parties, the firm is almost certainly issuing e-money and needs EMI authorisation.

Decision pointAuthorised Payment InstitutionElectronic Money Institution
Core permissionExecuting payment transactions for customersIssuing electronic money, plus payment services
Customer balancesFunds held only transiently to execute a transactionStored monetary value held on issue and redeemable at par
Initial capitalEUR 20,000 to EUR 125,000 by serviceEUR 350,000
Ongoing own fundsMethod A, B or CMethod D for e-money, being 2 per cent of average outstanding e-money, plus the payment services element where relevant
Redemption obligationsNot applicableIssue at par on receipt of funds and redeem at par at any time on request
FCA application feeGBP 2,820 or GBP 5,640GBP 5,640
Typical use caseRemittance, acquiring, payment processing, open bankingWallets, prepaid cards, multi-currency accounts with balances

Key Requirements

Initial Capital

£20,000 for firms providing money remittance services only. £50,000 for firms providing payment initiation or account information services. £125,000 for firms executing payment transactions, operating payment accounts or acquiring payment transactions. Own funds must be maintained on an ongoing basis at the higher of the initial capital floor or a percentage of payment transaction volume.

Governance & Fit and Proper

At least two directors are required. All directors, senior managers and qualifying shareholders (holding 10% or more) must complete FCA Individual Questionnaires. The fit and proper assessment covers criminal history, regulatory history, financial soundness and professional competence. The FCA expects the management body to have collective competence in payments, compliance and risk management.

AML & Financial Crime Controls

A compliant AML programme must be operational from day one of authorisation. This requires appointment of a Money Laundering Reporting Officer (MLRO) under SMF17, a documented business-wide risk assessment, customer due diligence (CDD) procedures proportionate to risk, ongoing monitoring, and a Suspicious Activity Report (SAR) reporting framework. The AML programme must be specifically tailored to the firm's business model and customer risk profile.

Safeguarding

Client funds must be safeguarded by segregation in a designated account at an FCA-approved credit institution, with written acknowledgement obtained from the credit institution before submission. Alternatively, safeguarding may be achieved through insurance or a comparable guarantee. PS25/12 (published August 2025, effective 7 May 2026) significantly strengthens safeguarding requirements - introducing CASS 15 records and accounts requirements, reconciliation on each reconciliation day, and a mandatory annual safeguarding audit.

Operational Requirements

Firms must maintain adequate IT systems, business continuity arrangements, outsourcing governance and complaints handling procedures. The FCA expects documented operational resilience frameworks proportionate to the scale and complexity of the business.

Regulatory Reporting

Authorised payment institutions must submit regular returns to the FCA via the RMAR system, including transaction volume data, capital adequacy reports and annual financial statements audited by an approved auditor.

What does API authorisation cost?

The regulator fee is fixed and published. The rest of the budget is driven by capital, systems and the depth of the compliance framework the model requires.

  • - Regulator fees: GBP 2,820 where the application covers only money remittance, payment initiation or account information services, and GBP 5,640 where it covers any of the services in Schedule 1 paragraphs (a) to (e). Annual periodic fees and Financial Ombudsman Service levies follow authorisation
  • - Capital: EUR 20,000, EUR 50,000 or EUR 125,000 initial capital depending on the services, and thereafter own funds under Method A, B or C. Capital must be in place and evidenced, not merely committed
  • - Third-party costs: safeguarding and operating account onboarding, transaction monitoring, screening and case management tooling, IT security testing, audit support for forecasts, and independent assurance over safeguarding arrangements
  • - Professional fees: we scope and quote a fixed professional fee per engagement, because cost varies materially with the number of services, group structure, agent networks and whether safeguarding is in scope. We do not publish a single headline figure that would be wrong for most applicants
  • - Post-authorisation running cost: compliance staffing, reporting, safeguarding reconciliation and audit, and periodic policy refresh. This is the item most often underestimated at application stage

The Application Process

1

Regulatory Scoping and Permission Selection

Regulatory Counsel maps your business model to the specific PSR 2017 Schedule 1 payment services categories. We determine the correct permission set, initial capital tier and safeguarding methodology. This scoping prevents the most common early-stage error - applying for the wrong permissions. Timeline: 2 weeks.

2

Corporate Structure and Governance Setup

We advise on corporate structure, appoint directors and senior managers who satisfy FCA fit and proper standards, and prepare all Individual Questionnaires. Qualifying shareholders are identified and their disclosure packages prepared. Timeline: 4 weeks.

3

Regulatory Business Plan Drafting

Regulatory Counsel prepares a comprehensive regulatory business plan - the single most important document in the application. This covers the business model, target market, product architecture, revenue model, three-year financial projections, capital adequacy analysis and go-to-market strategy. The FCA cross-references every section; internal inconsistencies trigger information requests. Timeline: 4–6 weeks.

4

Policy and Procedure Suite Preparation

We build the full compliance policy suite: AML/CTF programme, safeguarding methodology, complaints handling, operational resilience, outsourcing governance, data protection and financial promotions procedures. Each policy is tailored to your specific business model - not templated. Timeline: 4–6 weeks.

5

Application Submission via FCA Connect

The completed application is assembled and submitted via the FCA Connect portal. Regulatory Counsel conducts a final quality assurance review to ensure completeness and internal consistency before submission. Timeline: 1 week.

6

FCA Assessment and Determination

The FCA reviews the application and may issue information requests. Regulatory Counsel manages all correspondence, prepares responses and coordinates any required meetings or calls with the FCA case officer. A well-prepared application with proactive relationship management typically results in assessment at the lower end of the timeline range. Timeline: 6–12 months.

Total expected timeline: 8–14 months from instruction to authorisation.

How long does FCA API authorisation take?

Statutory position. The FCA must determine a complete application within three months of receipt, and must determine an incomplete application within 12 months at the latest.

Practical position. The three-month clock reflects a complete application, and completeness is assessed by the FCA. Substantive information requests are routine on payments applications, particularly on safeguarding, financial crime controls, own funds and the credibility of forecasts.

A realistic project plan is three to four months of preparation followed by six to twelve months with the FCA, giving eight to fourteen months in total. Applications that are materially incomplete, or that change business model mid-assessment, sit at the longer end of that range.

No adviser can promise an approval date, and any firm that offers one should be treated with caution. What can be controlled is the quality and internal consistency of the submission and the speed and evidential quality of responses.

Why Applications Fail - and How We Prevent It

Generic AML Programme

Copying AML templates from other firms or sectors without tailoring to the specific business model and customer risk profile is the most common reason applications are delayed or refused. The FCA cross-references the AML programme against the business plan and rejects applications where the risk assessment does not specifically address the risks arising from the applicant's stated business activities and target customers.

Inadequate Safeguarding Arrangements

Failure to obtain written acknowledgement from the safeguarding bank before submission is a critical error. The FCA will not grant authorisation without confirmed safeguarding arrangements. Many applicants underestimate the time required to secure a safeguarding account - banks are increasingly cautious about onboarding payment institutions, and the process can take 8–12 weeks.

Implausible Financial Projections

Day-one profitability with no explanation of client acquisition strategy, or revenue projections that assume market share without evidence of commercial pipeline, trigger immediate FCA challenge. The FCA requires projections grounded in a credible go-to-market strategy with identified customer segments and realistic conversion assumptions.

Undisclosed Individual History

County Court Judgments, prior directorships of failed or regulatory-actioned firms, non-UK regulatory sanctions, or adverse media that applicants assume will not be discovered during the FCA's background checks. The FCA conducts thorough checks including international regulatory databases, credit reference agencies and open-source intelligence. Non-disclosure is treated more seriously than the underlying issue.

Practitioner observations on API applications

  • - Permission scoping done backwards. Firms describe the product, then pick services from Schedule 1 to fit. Doing it the other way round, service by service against the actual flow of funds, prevents both under-permissioning and unnecessary capital
  • - Safeguarding treated as an account, not a system. Under the current regime the FCA expects records, reconciliation, governance and assurance, and an application that cannot describe the reconciliation process in operational detail will be tested on it
  • - Own funds modelled only at the initial capital floor. Fast-growing firms breach their own funds requirement in year one because the applicable method scales with volume or overheads
  • - Financial forecasts inconsistent with the programme of operations. Volumes, corridors and customer numbers must reconcile across every document in the pack
  • - Governance on paper only. Committees with no minutes, an MLRO with no time allocation and outsourced compliance with no internal ownership are visible to an experienced assessor
  • - Group structures where control is opaque. Qualifying holdings must be traced to natural persons, and indirect control through nominee or trust structures needs to be explained before it is asked about

How Regulatory Counsel Can Help

End-to-End Application Management

From initial regulatory scoping through to FCA authorisation, we manage every aspect of your API licence application - business plan, policy suite, FCA correspondence and assessment management.

Regulatory Business Plan

We draft the complete regulatory business plan to FCA standards - the single most scrutinised document in the application. Internally consistent, commercially credible and aligned with your stated business model.

Ongoing Compliance Support

Post-authorisation, we provide ongoing compliance support including RMAR reporting, policy updates, safeguarding reviews, annual compliance monitoring and regulatory change management.

Regulatory Counsel has advised on payment institution licensing across the UK, EU and global markets. Our team combines direct FCA regulatory experience with deep sector expertise in payments, e-money and open banking. Every engagement is led by a senior consultant - not delegated to junior staff.

Frequently Asked Questions

You need API authorisation if you provide payment services in the UK by way of business and either exceed the EUR 3 million monthly average that limits SPI registration, or need payment initiation permissions, or require full authorisation for banking and scheme relationships. Below that threshold, and without open banking, SPI registration may be sufficient.

A body corporate applicant must have its head office in the UK, so overseas groups apply through a UK subsidiary. Foreign ownership is permitted, but persons with qualifying holdings are assessed for suitability and the FCA will expect the UK entity to be genuinely directed and controlled from the UK.

EUR 20,000 for money remittance only, EUR 50,000 for payment initiation services, and EUR 125,000 for the account and transaction execution services in Schedule 1 paragraphs (a) to (e). Account information services alone require no initial capital. After authorisation, own funds must be maintained under Method A, B or C as directed by the FCA.

GBP 2,820 under fee Category 4 where the application covers money remittance, payment initiation or account information services, and GBP 5,640 under Category 5 where it covers any of the services in Schedule 1 paragraphs (a) to (e). The fee is payable on submission and is not refundable.

The FCA must determine a complete application within three months and an incomplete application within 12 months. In practice, allow three to four months of preparation and six to twelve months of assessment. Information requests on safeguarding, financial crime and forecasts are the main variable.

Relevant funds must be safeguarded under regulation 23, by segregation in a designated account with an authorised credit institution or by insurance or comparable guarantee. The supplementary regime in CASS 15, which took effect on 7 May 2026, adds records and accounts requirements, regular reconciliation and independent assurance expectations.

No. UK to EEA passporting ended with the transition period. Serving EEA customers requires authorisation from a national competent authority in an EEA member state, which is a full application rather than a notification.

There is no fixed statutory requirement for a specific number of UK resident directors, but the head office must be in the UK and the FCA assesses whether the payment services business is effectively directed from the UK. In practice, applications with no meaningful UK-based senior presence are challenged.

No. Providing payment services by way of business without authorisation or registration is a criminal offence. Some firms operate lawfully as an agent of an authorised firm during the application period, but that arrangement must itself be registered with the FCA and structured correctly.

An API executes payment transactions. An EMI issues electronic money, meaning stored monetary value held by customers and redeemable at par. If customers hold a spendable balance, EMI authorisation is normally required, with EUR 350,000 initial capital instead of the API tiers.