UK Authorised Payment Institution Licence: FCA API Requirements, Capital, Cost and Timeline
FCA Authorised Payment Institution authorisation: services, EUR 20k to 125k capital, own funds, CASS 15 safeguarding, fees, timeline and SPI comparison.
Written and reviewed by the Regulatory Counsel team. Last reviewed: 28 August 2026.
The short answer
An Authorised Payment Institution (API) is a firm authorised by the FCA under regulation 6 of the Payment Services Regulations 2017 to provide one or more of the payment services in Schedule 1. There is no transaction ceiling, and it is the only payments permission that supports payment initiation services and unrestricted growth.
Initial capital is EUR 20,000 for money remittance only, EUR 50,000 for payment initiation services and EUR 125,000 for the account and transaction execution services in paragraphs (a) to (e) of Schedule 1. Account information services alone require no initial capital. Once authorised, own funds must be maintained under Method A, B or C as directed by the FCA. Relevant funds must be safeguarded under regulation 23 and the supplementary safeguarding regime in CASS 15, which took effect on 7 May 2026.
The FCA application fee is GBP 2,820 (Category 4) for money remittance, payment initiation or account information services, and GBP 5,640 (Category 5) where the firm applies for any of the services in paragraphs (a) to (e). The FCA must determine a complete application within three months and an incomplete application within 12 months. A realistic project runs eight to fourteen months from instruction.
Key facts at a glance
| Regulator | Financial Conduct Authority (FCA) |
|---|---|
| Permission type | Authorisation as a payment institution under regulation 6, Payment Services Regulations 2017 |
| Who needs it | Firms providing payment services in the UK by way of business that exceed the SPI threshold, need open banking permissions, or require full authorisation for commercial reasons |
| Local entity required? | Yes. A body corporate applicant must have its head office, and if it has a registered office that office, in the United Kingdom |
| Local management required? | No fixed statutory headcount, but the FCA expects UK-based effective direction of the payment services business and approved individuals with genuine authority |
| Initial capital | EUR 20,000 money remittance; EUR 50,000 payment initiation services; EUR 125,000 for Schedule 1 paragraphs (a) to (e); none for account information services alone |
| Ongoing own funds | The higher of initial capital and the amount produced by Method A, B or C as directed by the FCA, which may adjust the result by up to 20 per cent |
| FCA application fee | GBP 2,820 (Category 4) or GBP 5,640 (Category 5) depending on the services applied for |
| Statutory determination period | Three months for a complete application; 12 months maximum for an incomplete application |
| Realistic end-to-end timeline | Eight to fourteen months from instruction, of which three to four months is preparation |
| Renewal | No renewal. Annual periodic fees, regulatory reporting, a safeguarding audit where applicable and continuing threshold conditions apply |
| Territorial scope | United Kingdom. No EEA passporting since the end of the transition period |
Get Expert Advice
Whether you need licensing support, compliance advice or regulatory strategy, our team is ready to help. Free initial consultation - no obligation.
Get Expert Advice
What is the UK Authorised Payment Institution licence?
The UK Authorised Payment Institution (API) licence authorises firms to provide regulated payment services under Schedule 1 of the Payment Services Regulations 2017 (PSR 2017). These services include money remittance, payment processing, merchant acquisition, payment initiation services (PIS) and account information services (AIS). The licence is issued by the Financial Conduct Authority (FCA).
Operating a payment services business in the United Kingdom without FCA authorisation or registration is a criminal offence under Regulation 138 of the Payment Services Regulations 2017. Persons convicted on indictment face imprisonment for up to two years and/or an unlimited fine.
The API licence is the full authorisation route - as distinct from Small Payment Institution (SPI) registration - and is required by any firm whose average monthly payment transaction volume exceeds €3 million or that wishes to passport into EEA states.
Who Needs UK Authorised Payment Institution licence?
The API licence is required by any firm carrying on payment services business in the UK that exceeds the Small Payment Institution thresholds or requires passporting rights.
- - Fintech firms processing payments above the €3 million monthly threshold
- - Money remittance businesses (international transfers, cross-border payments)
- - Payment processors and payment facilitators
- - Merchant acquirers
- - Open banking providers offering PIS or AIS
- - Firms operating multi-currency payment accounts without e-money issuance
- - Payment platforms seeking to passport into EEA member states
A common misconception is that firms providing payment-adjacent services - such as software platforms that aggregate payment flows or marketplace platforms that hold funds in transit - are exempt from authorisation. In most cases, these activities fall within the regulatory perimeter. The FCA takes an expansive view of what constitutes a payment service, and firms should seek regulatory advice before concluding they are out of scope.
Which payment services does an API cover?
Schedule 1 to the Payment Services Regulations 2017 lists the regulated payment services. An application must specify each service sought, because permissions, capital and own funds all follow from that list.
- - Services enabling cash to be placed on, or withdrawn from, a payment account
- - Execution of payment transactions, including direct debits, card transactions and credit transfers
- - Execution of payment transactions where the funds are covered by a credit line
- - Issuing payment instruments or acquiring payment transactions
- - Money remittance
- - Payment initiation services
- - Account information services
When is API authorisation required rather than SPI registration?
- - The monthly average of payment transactions over 12 months exceeds, or will exceed, EUR 3 million
- - The business provides payment initiation services, which cannot be carried on under SPI registration
- - The firm needs to appoint agents at scale or build a distribution network
- - Banking, card scheme or institutional counterparties require authorised status as a condition of onboarding
- - The firm intends to hold significant customer funds and wants the safeguarding regime and market credibility that come with authorisation
Initial capital and own funds
Initial capital is set by Schedule 3 and is stated in euros in the legislation, with no fixed sterling conversion. Money remittance requires EUR 20,000, payment initiation services require EUR 50,000, and the services in paragraphs (a) to (e) require EUR 125,000. A firm applying for a combination takes the highest applicable figure.
After authorisation, own funds must be maintained at the higher of the initial capital floor and the amount produced by the applicable own funds method. Method A is based on fixed overheads, Method B on payment volume, and Method C on an income-based indicator. The FCA directs which method applies and may adjust the result by up to 20 per cent either way based on its assessment of the firm.
The practical point that catches firms out is timing. Own funds are a continuing requirement, so a business that scales volume quickly can outgrow its capital base long before it plans its next funding round. Capital planning should be modelled against the own funds method that will actually apply, not against the initial capital figure.
Safeguarding and CASS 15
Regulation 23 requires an authorised payment institution to safeguard relevant funds, either by segregating them in a designated account with an authorised credit institution or by covering them with an insurance policy or comparable guarantee. Segregated funds must be held so that they are protected from the claims of other creditors.
The FCA strengthened the regime through PS25/12, and the CASS 15 chapter of the Handbook took effect on 7 May 2026. The direction of travel is towards CASS-style discipline: specific records and accounts requirements, reconciliation on each reconciliation day, prompt correction of discrepancies, clear acknowledgement letters and independent assurance over the arrangements.
Safeguarding is now the single most examined area of UK payments supervision. Applications that treat it as an account-opening formality rather than an operating model with reconciliation, governance and evidence attract detailed scrutiny.
Governance, UK substance and key individuals
- - A body corporate applicant must have its head office in the UK and carry on at least part of its payment service business here
- - Directors and persons responsible for the payment services business must be of good repute and possess appropriate knowledge and experience
- - Persons with a qualifying holding are assessed for suitability, which in group structures means tracing beneficial ownership to natural persons
- - A money laundering reporting officer with genuine seniority, UK availability and authority over the AML framework
- - Clear allocation of responsibilities across risk, compliance, finance and operations, evidenced by terms of reference and management information rather than an organisation chart alone
Business plan, programme of operations and forecasts
The programme of operations must describe each payment service and the exact flow of funds. The business plan must describe the model, the market, the distribution strategy and the operating structure, supported by a forecast budget for the first three financial years that demonstrates the firm can meet own funds requirements throughout.
The FCA reads these documents against each other and against the AML risk assessment. Where a forecast assumes corridors, customer types or volumes that the risk assessment does not address, the application stalls.
AML, operational and security requirements
- - A business-wide money laundering and terrorist financing risk assessment specific to the firm's products, corridors, customers and delivery channels
- - Customer due diligence, enhanced due diligence, sanctions and PEP screening, transaction monitoring and suspicious activity reporting procedures that match the systems the firm has actually procured
- - A security policy document describing the control framework, including a description of security control and mitigation measures for payment services
- - Operational and security risk management arrangements, incident management and major incident reporting capability
- - Business continuity, outsourcing governance including exit planning, and complaints handling within Financial Ombudsman Service jurisdiction
- - Strong customer authentication design for the relevant services, and where applicable the technical arrangements for access to payment accounts
Ongoing reporting and compliance after authorisation
- - Periodic regulatory returns covering payment volumes, capital adequacy, operational and security risk and financial crime data
- - Own funds monitoring against the directed method and prompt notification where the position deteriorates
- - Safeguarding records, reconciliations and independent assurance under the current safeguarding regime
- - Notification of changes in control, changes to permissions, agent appointments and material outsourcing
- - Annual periodic fees and Financial Ombudsman Service levies
- - Complaints reporting and adherence to conduct requirements including the Consumer Duty where the firm serves retail customers
SPI vs API
The choice between registration and authorisation is a commercial decision as much as a regulatory one.
| Decision point | Small Payment Institution | Authorised Payment Institution |
|---|---|---|
| Transaction ceiling | EUR 3 million monthly average | None |
| Initial capital | None prescribed | EUR 20,000, EUR 50,000 or EUR 125,000 |
| Payment initiation and account information | Excluded | Available |
| Safeguarding | Not imposed by regulation 23; voluntary opt-in | Mandatory under regulation 23 and CASS 15 |
| FCA application fee | GBP 1,130 | GBP 2,820 or GBP 5,640 |
| Typical preparation | Four to six weeks | Three to four months |
| Counterparty acceptance | Mixed | Broadly expected by banks and schemes |
API vs EMI: payment services or electronic money?
The dividing line is whether the firm issues stored value. If customers hold a balance that can be spent with third parties, the firm is almost certainly issuing e-money and needs EMI authorisation.
| Decision point | Authorised Payment Institution | Electronic Money Institution |
|---|---|---|
| Core permission | Executing payment transactions for customers | Issuing electronic money, plus payment services |
| Customer balances | Funds held only transiently to execute a transaction | Stored monetary value held on issue and redeemable at par |
| Initial capital | EUR 20,000 to EUR 125,000 by service | EUR 350,000 |
| Ongoing own funds | Method A, B or C | Method D for e-money, being 2 per cent of average outstanding e-money, plus the payment services element where relevant |
| Redemption obligations | Not applicable | Issue at par on receipt of funds and redeem at par at any time on request |
| FCA application fee | GBP 2,820 or GBP 5,640 | GBP 5,640 |
| Typical use case | Remittance, acquiring, payment processing, open banking | Wallets, prepaid cards, multi-currency accounts with balances |
Key Requirements
Initial Capital
£20,000 for firms providing money remittance services only. £50,000 for firms providing payment initiation or account information services. £125,000 for firms executing payment transactions, operating payment accounts or acquiring payment transactions. Own funds must be maintained on an ongoing basis at the higher of the initial capital floor or a percentage of payment transaction volume.
Governance & Fit and Proper
At least two directors are required. All directors, senior managers and qualifying shareholders (holding 10% or more) must complete FCA Individual Questionnaires. The fit and proper assessment covers criminal history, regulatory history, financial soundness and professional competence. The FCA expects the management body to have collective competence in payments, compliance and risk management.
AML & Financial Crime Controls
A compliant AML programme must be operational from day one of authorisation. This requires appointment of a Money Laundering Reporting Officer (MLRO) under SMF17, a documented business-wide risk assessment, customer due diligence (CDD) procedures proportionate to risk, ongoing monitoring, and a Suspicious Activity Report (SAR) reporting framework. The AML programme must be specifically tailored to the firm's business model and customer risk profile.
Safeguarding
Client funds must be safeguarded by segregation in a designated account at an FCA-approved credit institution, with written acknowledgement obtained from the credit institution before submission. Alternatively, safeguarding may be achieved through insurance or a comparable guarantee. PS25/12 (published August 2025, effective 7 May 2026) significantly strengthens safeguarding requirements - introducing CASS 15 records and accounts requirements, reconciliation on each reconciliation day, and a mandatory annual safeguarding audit.
Operational Requirements
Firms must maintain adequate IT systems, business continuity arrangements, outsourcing governance and complaints handling procedures. The FCA expects documented operational resilience frameworks proportionate to the scale and complexity of the business.
Regulatory Reporting
Authorised payment institutions must submit regular returns to the FCA via the RMAR system, including transaction volume data, capital adequacy reports and annual financial statements audited by an approved auditor.
What does API authorisation cost?
The regulator fee is fixed and published. The rest of the budget is driven by capital, systems and the depth of the compliance framework the model requires.
- - Regulator fees: GBP 2,820 where the application covers only money remittance, payment initiation or account information services, and GBP 5,640 where it covers any of the services in Schedule 1 paragraphs (a) to (e). Annual periodic fees and Financial Ombudsman Service levies follow authorisation
- - Capital: EUR 20,000, EUR 50,000 or EUR 125,000 initial capital depending on the services, and thereafter own funds under Method A, B or C. Capital must be in place and evidenced, not merely committed
- - Third-party costs: safeguarding and operating account onboarding, transaction monitoring, screening and case management tooling, IT security testing, audit support for forecasts, and independent assurance over safeguarding arrangements
- - Professional fees: we scope and quote a fixed professional fee per engagement, because cost varies materially with the number of services, group structure, agent networks and whether safeguarding is in scope. We do not publish a single headline figure that would be wrong for most applicants
- - Post-authorisation running cost: compliance staffing, reporting, safeguarding reconciliation and audit, and periodic policy refresh. This is the item most often underestimated at application stage
The Application Process
Regulatory Scoping and Permission Selection
Regulatory Counsel maps your business model to the specific PSR 2017 Schedule 1 payment services categories. We determine the correct permission set, initial capital tier and safeguarding methodology. This scoping prevents the most common early-stage error - applying for the wrong permissions. Timeline: 2 weeks.
Corporate Structure and Governance Setup
We advise on corporate structure, appoint directors and senior managers who satisfy FCA fit and proper standards, and prepare all Individual Questionnaires. Qualifying shareholders are identified and their disclosure packages prepared. Timeline: 4 weeks.
Regulatory Business Plan Drafting
Regulatory Counsel prepares a comprehensive regulatory business plan - the single most important document in the application. This covers the business model, target market, product architecture, revenue model, three-year financial projections, capital adequacy analysis and go-to-market strategy. The FCA cross-references every section; internal inconsistencies trigger information requests. Timeline: 4–6 weeks.
Policy and Procedure Suite Preparation
We build the full compliance policy suite: AML/CTF programme, safeguarding methodology, complaints handling, operational resilience, outsourcing governance, data protection and financial promotions procedures. Each policy is tailored to your specific business model - not templated. Timeline: 4–6 weeks.
Application Submission via FCA Connect
The completed application is assembled and submitted via the FCA Connect portal. Regulatory Counsel conducts a final quality assurance review to ensure completeness and internal consistency before submission. Timeline: 1 week.
FCA Assessment and Determination
The FCA reviews the application and may issue information requests. Regulatory Counsel manages all correspondence, prepares responses and coordinates any required meetings or calls with the FCA case officer. A well-prepared application with proactive relationship management typically results in assessment at the lower end of the timeline range. Timeline: 6–12 months.
Total expected timeline: 8–14 months from instruction to authorisation.
How long does FCA API authorisation take?
Statutory position. The FCA must determine a complete application within three months of receipt, and must determine an incomplete application within 12 months at the latest.
Practical position. The three-month clock reflects a complete application, and completeness is assessed by the FCA. Substantive information requests are routine on payments applications, particularly on safeguarding, financial crime controls, own funds and the credibility of forecasts.
A realistic project plan is three to four months of preparation followed by six to twelve months with the FCA, giving eight to fourteen months in total. Applications that are materially incomplete, or that change business model mid-assessment, sit at the longer end of that range.
No adviser can promise an approval date, and any firm that offers one should be treated with caution. What can be controlled is the quality and internal consistency of the submission and the speed and evidential quality of responses.
Why Applications Fail - and How We Prevent It
Generic AML Programme
Copying AML templates from other firms or sectors without tailoring to the specific business model and customer risk profile is the most common reason applications are delayed or refused. The FCA cross-references the AML programme against the business plan and rejects applications where the risk assessment does not specifically address the risks arising from the applicant's stated business activities and target customers.
Inadequate Safeguarding Arrangements
Failure to obtain written acknowledgement from the safeguarding bank before submission is a critical error. The FCA will not grant authorisation without confirmed safeguarding arrangements. Many applicants underestimate the time required to secure a safeguarding account - banks are increasingly cautious about onboarding payment institutions, and the process can take 8–12 weeks.
Implausible Financial Projections
Day-one profitability with no explanation of client acquisition strategy, or revenue projections that assume market share without evidence of commercial pipeline, trigger immediate FCA challenge. The FCA requires projections grounded in a credible go-to-market strategy with identified customer segments and realistic conversion assumptions.
Undisclosed Individual History
County Court Judgments, prior directorships of failed or regulatory-actioned firms, non-UK regulatory sanctions, or adverse media that applicants assume will not be discovered during the FCA's background checks. The FCA conducts thorough checks including international regulatory databases, credit reference agencies and open-source intelligence. Non-disclosure is treated more seriously than the underlying issue.
Practitioner observations on API applications
- - Permission scoping done backwards. Firms describe the product, then pick services from Schedule 1 to fit. Doing it the other way round, service by service against the actual flow of funds, prevents both under-permissioning and unnecessary capital
- - Safeguarding treated as an account, not a system. Under the current regime the FCA expects records, reconciliation, governance and assurance, and an application that cannot describe the reconciliation process in operational detail will be tested on it
- - Own funds modelled only at the initial capital floor. Fast-growing firms breach their own funds requirement in year one because the applicable method scales with volume or overheads
- - Financial forecasts inconsistent with the programme of operations. Volumes, corridors and customer numbers must reconcile across every document in the pack
- - Governance on paper only. Committees with no minutes, an MLRO with no time allocation and outsourced compliance with no internal ownership are visible to an experienced assessor
- - Group structures where control is opaque. Qualifying holdings must be traced to natural persons, and indirect control through nominee or trust structures needs to be explained before it is asked about
How Regulatory Counsel Can Help
End-to-End Application Management
From initial regulatory scoping through to FCA authorisation, we manage every aspect of your API licence application - business plan, policy suite, FCA correspondence and assessment management.
Regulatory Business Plan
We draft the complete regulatory business plan to FCA standards - the single most scrutinised document in the application. Internally consistent, commercially credible and aligned with your stated business model.
Ongoing Compliance Support
Post-authorisation, we provide ongoing compliance support including RMAR reporting, policy updates, safeguarding reviews, annual compliance monitoring and regulatory change management.
Regulatory Counsel has advised on payment institution licensing across the UK, EU and global markets. Our team combines direct FCA regulatory experience with deep sector expertise in payments, e-money and open banking. Every engagement is led by a senior consultant - not delegated to junior staff.
Related Licences
UK Small Payment Institution
Lighter registration route for firms below the EUR 3 million monthly threshold.
UK Electronic Money Institution
Required where the business issues e-money balances rather than only executing payments.
Canada MSB Registration
FINTRAC registration for UK payment firms expanding into Canada.
Frequently Asked Questions
You need API authorisation if you provide payment services in the UK by way of business and either exceed the EUR 3 million monthly average that limits SPI registration, or need payment initiation permissions, or require full authorisation for banking and scheme relationships. Below that threshold, and without open banking, SPI registration may be sufficient.
A body corporate applicant must have its head office in the UK, so overseas groups apply through a UK subsidiary. Foreign ownership is permitted, but persons with qualifying holdings are assessed for suitability and the FCA will expect the UK entity to be genuinely directed and controlled from the UK.
EUR 20,000 for money remittance only, EUR 50,000 for payment initiation services, and EUR 125,000 for the account and transaction execution services in Schedule 1 paragraphs (a) to (e). Account information services alone require no initial capital. After authorisation, own funds must be maintained under Method A, B or C as directed by the FCA.
GBP 2,820 under fee Category 4 where the application covers money remittance, payment initiation or account information services, and GBP 5,640 under Category 5 where it covers any of the services in Schedule 1 paragraphs (a) to (e). The fee is payable on submission and is not refundable.
The FCA must determine a complete application within three months and an incomplete application within 12 months. In practice, allow three to four months of preparation and six to twelve months of assessment. Information requests on safeguarding, financial crime and forecasts are the main variable.
Relevant funds must be safeguarded under regulation 23, by segregation in a designated account with an authorised credit institution or by insurance or comparable guarantee. The supplementary regime in CASS 15, which took effect on 7 May 2026, adds records and accounts requirements, regular reconciliation and independent assurance expectations.
No. UK to EEA passporting ended with the transition period. Serving EEA customers requires authorisation from a national competent authority in an EEA member state, which is a full application rather than a notification.
There is no fixed statutory requirement for a specific number of UK resident directors, but the head office must be in the UK and the FCA assesses whether the payment services business is effectively directed from the UK. In practice, applications with no meaningful UK-based senior presence are challenged.
No. Providing payment services by way of business without authorisation or registration is a criminal offence. Some firms operate lawfully as an agent of an authorised firm during the application period, but that arrangement must itself be registered with the FCA and structured correctly.
An API executes payment transactions. An EMI issues electronic money, meaning stored monetary value held by customers and redeemable at par. If customers hold a spendable balance, EMI authorisation is normally required, with EUR 350,000 initial capital instead of the API tiers.
Primary sources
The requirements, fees and timeframes on this page are taken from the following primary regulatory and legislative sources. Rules change, and firms should confirm the current position before relying on any figure.
- Payment Services Regulations 2017, regulation 6 (conditions for authorisation)
- Payment Services Regulations 2017, Schedule 3 (capital requirements)
- Payment Services Regulations 2017, regulation 23 (safeguarding requirements)
- Payment Services Regulations 2017, regulation 9 (determination of applications)
- FCA: application fees for payment services and e-money firms
- FCA Handbook, CASS 15: payment services and electronic money, relevant funds
- FCA PS25/12: changes to the safeguarding regime for payments and e-money firms
Last reviewed by the Regulatory Counsel team on 28 August 2026.