Payment Initiation Service Providers: Redefining Financial Transactions
- Julien Haye

- Jan 26, 2024
- 16 min read
Updated: 6 days ago

In the evolving landscape of digital banking and financial technology, Payment Initiation Service Providers (PISPs) have emerged as key facilitators in the payment processing ecosystem. PISPs are a product of the open banking revolution, primarily driven by regulatory frameworks like the EU's Second Payment Services Directive (PSD2), adopted in various forms globally, including the UK, to enhance competition and innovation in financial services. With the capability to handle direct bank transfers and facilitate strong customer authentication (SCA), PISPs provide a compelling payments solution for consumers and businesses alike.
This article explores the role, functionality, and impact of PISPs in modern financial services, shedding light on how they work, the regulatory landscape, and the benefits they bring to consumers and businesses.
What is a Payment Initiation Service Provider (PISP)?
A Payment Initiation Service Provider (PISP) is a regulated payment service that enables businesses to initiate online payments directly from a customer's bank account to a merchant or service provider, with the customer's explicit consent. Rather than relying on traditional card networks, PISPs facilitate secure bank-to-bank payments through open banking infrastructure, helping businesses improve payment efficiency, reduce transaction costs and enhance the customer experience.
Unlike Account Information Service Providers (AISPs), which access account information to provide financial insights or aggregation services, PISPs focus solely on initiating payments. They do not hold customer funds or issue electronic money, making them a distinct category of regulated payment service under the UK's Payment Services Regulations.
As open banking continues to evolve, PISPs are becoming an increasingly important part of the payments ecosystem. They enable businesses to develop innovative payment journeys, support embedded finance propositions and offer customers faster, more secure alternatives to traditional payment methods.
Start with Your Business Model, Not the Licence
Many founders begin by asking, "Do I need a PISP licence?" In practice, this is rarely the right starting point.
The first question should be:
"What products and services do I want to offer, and how will payments flow through my business?"
Your business model determines the regulatory permissions you may require, not the other way around. Seemingly small changes to your operating model, such as holding client funds, issuing stored value or providing account information services, can significantly alter your regulatory obligations.
Before deciding whether to pursue PISP authorisation, businesses should clearly define:
The products and services they intend to offer.
How customer funds will flow through the business.
Whether payments will be initiated, executed or held.
Whether customer account information will also be accessed.
Whether the business will operate independently, as an agent or through another delivery model.
Taking time to design the operating model first helps avoid selecting the wrong regulatory permission, reduces implementation costs and creates a stronger foundation for future product development and business growth.
A regulatory perimeter assessment should therefore be viewed as an early strategic exercise rather than simply a compliance requirement. The objective is not to obtain a licence as quickly as possible, but to establish the regulatory model that best supports your commercial strategy.
When Should You Consider Becoming a PISP?
A Payment Initiation Service Provider (PISP) authorisation may be appropriate if your business intends to initiate payments directly from a customer's bank account without holding client funds. It is commonly used by businesses looking to offer secure bank-to-bank payments, reduce reliance on card networks, improve payment efficiency or embed payment functionality within a broader digital proposition.
Typical use cases include:
Merchant checkout and e-commerce payment solutions.
Invoice and bill payment platforms.
Embedded finance and digital marketplaces.
Business-to-business payment solutions.
Account-to-account payment services.
However, obtaining a PISP authorisation should be driven by your business model rather than the technology alone. Before applying, firms should assess the products and services they intend to offer, how customer funds will flow through the business, and whether additional regulated activities are involved.
For example:
Businesses providing account aggregation or financial insights may also require AISP authorisation.
Firms executing other payment services or holding client funds may require Payment Institution (PI) authorisation.
Businesses issuing stored value, prepaid products or digital wallets may require Electronic Money Institution (EMI) authorisation.
Taking time to assess the regulatory perimeter at the outset helps founders select the most appropriate authorisation, avoid unnecessary costs or delays, and build a regulatory strategy that can support future product development and business growth.

How PISP Authorisation Fits Within the UK Regulatory Framework
Payment initiation is one of several regulated payment services in the UK. While a PISP authorisation enables firms to initiate payments directly from a customer's bank account, it does not permit businesses to hold client funds, issue electronic money or provide account information services unless separately authorised.
As businesses develop new products and services, they often discover that multiple regulatory permissions may be relevant depending on how their proposition evolves. For example, a business offering payment initiation today may later wish to aggregate account information, issue digital wallets or provide additional payment services, each potentially requiring different regulatory permissions.
Selecting the appropriate authorisation is therefore not simply a regulatory exercise. It is an important strategic decision that influences product design, customer journeys, operational processes, governance arrangements and future scalability.
Before applying for authorisation, firms should assess their proposed operating model and consider whether a PISP authorisation alone is sufficient or whether an alternative or broader permission, such as an Account Information Service Provider (AISP), Payment Institution (PI) or Electronic Money Institution (EMI), would better support their long-term business objectives.
Taking time to define the regulatory perimeter early can reduce implementation costs, avoid unnecessary variations of permission and provide greater flexibility as the business grows.
Do You Need FCA Authorisation?
Launching a payment proposition does not always mean applying directly for FCA authorisation. The most appropriate regulatory approach depends on your business model, the activities you perform and how your service is delivered to customers.
Before investing in an authorisation application, firms should assess whether they need to become directly authorised or whether another regulatory model better supports their commercial objectives.
Common approaches include:
Direct FCA Authorisation
Firms carrying out regulated payment initiation services in their own name will generally require FCA authorisation as a Payment Initiation Service Provider (PISP). This provides full regulatory control but also requires appropriate governance, risk management, operational resilience and ongoing compliance arrangements.
Agent of an Authorised Payment Institution
Some businesses operate as agents of an authorised Payment Institution rather than becoming directly authorised themselves. This can provide a faster route to market while allowing firms to leverage the principal firm's regulatory permissions, subject to appropriate oversight and contractual arrangements.
Technology or Software Provider
Businesses that develop payment technology without initiating payments or carrying out regulated activities themselves may fall outside the regulatory perimeter. Careful analysis is required, as seemingly small changes to the operating model can alter the regulatory position.
Outsourced Service Provider
Many firms provide operational, technology or support services to authorised payment firms without themselves undertaking regulated activities. While authorisation may not be required, firms should still consider operational resilience, outsourcing expectations, data protection and contractual obligations.
Why a Regulatory Perimeter Assessment Matters
Choosing the wrong regulatory model can result in unnecessary costs, delays and future restructuring. Assessing the regulatory perimeter at an early stage helps ensure your business launches under the most appropriate authorisation model while supporting future product development and growth.
How PISP Business Models Typically Evolve
Many businesses do not start by offering a full suite of payment services.
Instead, they launch with a focused proposition and expand their capabilities as customer demand, product strategy and commercial objectives evolve.
Understanding how your business may develop over time helps ensure that today's regulatory decisions continue to support tomorrow's growth.

Planning Beyond Your Initial Permission
A PISP authorisation should not be viewed as the final destination. As businesses launch new products, enter new markets or introduce additional payment services, they may require broader regulatory permissions.
For example, businesses may choose to:
combine PISP and AISP services to deliver both payment initiation and account information;
become an Authorised Payment Institution (API) to offer additional regulated payment services;
become an Electronic Money Institution (EMI) if they begin issuing electronic money or digital wallets.
Considering these possibilities during the product design stage can help founders avoid unnecessary restructuring, minimise future variations of permission and build a regulatory strategy that supports long-term growth.
Key Functions of PISPs
Payment Initiation Service Providers perform a specific regulated function within the UK's Open Banking ecosystem. Beyond initiating payments, they enable businesses to create faster, more efficient and customer-centric payment experiences while supporting innovation in digital commerce.
Direct Bank-to-Bank Payments
PISPs enable customers to authorise payments directly from their bank accounts without relying on traditional card networks. This provides merchants and payment providers with an alternative payment method that can simplify payment processing while reducing dependency on intermediary payment providers.
Lower Payment Processing Costs
By facilitating direct account-to-account payments, PISPs can help reduce payment processing costs associated with card schemes and other intermediaries. This can be particularly valuable for businesses processing high transaction volumes or operating in sectors with narrow operating margins.
Improved Customer Experience
PISPs can be integrated into digital checkout journeys, allowing customers to complete payments securely through their online banking provider. Streamlined payment journeys help reduce friction during checkout while supporting a faster and more intuitive customer experience.
Secure Payment Authorisation
Payment initiation services operate within the UK's Open Banking framework and require Strong Customer Authentication (SCA) where applicable. Customer consent, secure authentication and regulated access to banking infrastructure help protect both customers and merchants throughout the payment process.
Faster Payment Confirmation
Many payment initiation services support real-time or near real-time bank transfers, allowing businesses to receive confirmation of payment more quickly than many traditional payment methods. Faster payment confirmation can improve cash flow, operational efficiency and the overall customer experience.
Supporting Product Innovation
PISPs also enable businesses to develop new payment propositions, including embedded finance solutions, digital marketplaces, subscription services and account-to-account payment experiences. As Open Banking continues to evolve, payment initiation is becoming an increasingly important component of modern payment strategies and digital commerce.
Become a authorised PISP firm with our expert help! From permission applications to ongoing risk and compliance support, we're here to support you. Discover Aevitium LTD Risk Management Services for FinTech and Payment firms.

Regulatory Framework and Compliance
Operating as a Payment Initiation Service Provider (PISP) involves more than obtaining FCA authorisation. Firms must establish appropriate governance, maintain adequate financial resources, implement effective financial crime controls and demonstrate that they can operate a secure, resilient and well-controlled payment service.
PISP Regulatory Authorisation
Businesses providing regulated payment initiation services in the UK must obtain authorisation from the Financial Conduct Authority (FCA). Payment initiation is regulated under the Payment Services Regulations and forms part of the UK's Open Banking framework.
One area that often causes confusion is the distinction between Registered Small Payment Institutions (SPIs) and Authorised Payment Institutions (APIs). While certain payment services may qualify for the Small Payment Institution regime, this exemption does not apply to payment initiation services.
Any business intending to provide Payment Initiation Services must therefore obtain full FCA authorisation as an Authorised Payment Institution (API), regardless of its transaction volumes or stage of growth.
Obtaining authorisation is only one part of the process. Firms must also demonstrate appropriate governance arrangements, operational readiness, financial crime controls and risk management capabilities before commencing regulated activities.
To learn how PISPs can navigate FCA requirements, explore our article on FCA authorisation and compliance strategies for PISPs, covering risk mitigation approaches, senior staff fit and proper assessment, and governance standards.
Regulatory Capital and Professional Indemnity Insurance
Independent PISPs must also meet prudential and insurance requirements. In the UK, firms providing payment initiation services must hold a minimum of €50,000 in initial capital, or a higher amount where they provide additional payment services.
PISPs must also hold appropriate Professional Indemnity Insurance (PII) or a comparable guarantee. This is designed to protect against liabilities arising from payment initiation services, including unauthorised or fraudulent transactions and failures in service delivery.
The level of PII required is not a generic fixed amount. It depends on the firm's business model, transaction volumes, risk profile, number of clients, and the nature of the payment services provided. Firms should therefore assess insurance requirements early, as PII can influence both application readiness and operating costs.
For founders, this means PISP authorisation is not only about preparing the FCA application. It also requires sufficient financial resources, appropriate insurance coverage, and a realistic understanding of the ongoing cost of operating a regulated payment service.
Operational Resilience and Third-Party Dependency
Unlike many regulated firms, PISPs rely heavily on the APIs provided by Account Servicing Payment Service Providers (ASPSPs), typically banks and building societies. The availability, performance and consistency of these APIs directly influence customer experience and the reliability of payment initiation services.
Customer authentication methods, bank redirection journeys and API performance can also introduce friction into the payment process. Businesses should therefore design payment journeys that balance security, regulatory compliance and a seamless customer experience.
PISPs should establish appropriate monitoring, incident management, business continuity and third-party oversight arrangements to support operational resilience and minimise service disruption.
Financial Crime, Data Protection and Customer Consent
PISPs process sensitive financial information and must comply with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR). Appropriate governance, security controls and data handling procedures are essential to maintaining customer trust.
In addition, firms must establish financial crime controls proportionate to their business model. This includes governance arrangements covering anti-money laundering (AML), counter-terrorist financing (CTF), fraud prevention, sanctions compliance and the reporting of suspicious activity where applicable.
Before initiating a payment, a PISP must obtain the customer's explicit consent and comply with Strong Customer Authentication (SCA) where required. While certain regulatory exemptions may apply in specific circumstances, firms remain responsible for ensuring authentication controls comply with regulatory requirements while delivering a secure and intuitive payment experience.
Governance and Risk Management
Authorisation marks the beginning of a firm's regulatory journey rather than the end. PISPs are expected to maintain proportionate governance arrangements covering risk management, operational resilience, outsourcing oversight, incident management, regulatory reporting and ongoing compliance monitoring.
Building these capabilities before launch helps firms move beyond regulatory approval and establish a sustainable operating model that can support future product development, regulatory change and long-term business growth.
Data Protection and Privacy
Adherence to data protection laws, including GDPR, is paramount for PISPs, ensuring that customer data is secure and confidential. Compliance with these laws helps build consumer trust and fosters a more transparent and accountable financial ecosystem.
Customer Consent
Before initiating payments, PISPs are required to obtain explicit consent from customers, adding an additional layer of security and customer control. This requirement aligns with PSD2’s emphasis on customer empowerment, safeguarding customer accounts from unauthorised transactions.
Registered vs Authorised Payment Institutions
One area that often causes confusion is the distinction between a Registered Small Payment Institution (SPI) and an Authorised Payment Institution (API). Under the UK's Payment Services Regulations, some payment firms with lower transaction volumes may qualify to operate as a Registered Small Payment Institution, benefiting from a simplified regulatory regime.
However, this exemption does not apply to payment initiation services.
Any business intending to provide Payment Initiation Services (PIS) must obtain full FCA authorisation as an Authorised Payment Institution (API), regardless of its size or expected transaction volumes. There is no "small PISP" regime.
For founders and early-stage fintechs, this is an important consideration when planning regulatory strategy. Businesses that expect to provide payment initiation services should factor the full authorisation process, governance requirements, prudential obligations and ongoing regulatory compliance into their business plans from the outset.
The Impact of PISPs on the Payments Ecosystem
Payment Initiation Service Providers are reshaping how businesses accept payments and how consumers interact with financial services. By enabling secure account-to-account payments through Open Banking, PISPs are driving innovation across the payments ecosystem while creating new opportunities for businesses to develop more efficient and customer-focused payment experiences.
Accelerating Payment Innovation
PISPs are enabling new payment propositions that move beyond traditional card-based transactions. From embedded finance and digital marketplaces to subscription services and business payments, payment initiation is supporting the development of more flexible and integrated financial products.
Improving Customer Payment Journeys
By reducing friction at the point of payment, PISPs help businesses create faster, simpler and more intuitive checkout experiences. Secure bank-to-bank payments can improve customer satisfaction while supporting higher payment completion rates.
Increasing Competition in Payments
Open Banking has expanded competition by allowing regulated third-party providers to develop innovative payment solutions alongside traditional financial institutions. This has encouraged greater choice for businesses and consumers while accelerating the development of new payment services.
Supporting Business Growth
For many organisations, payment initiation provides an opportunity to improve operational efficiency, reduce payment processing costs and enhance cash flow through faster payment confirmation. These benefits are particularly valuable for digital businesses seeking to scale efficiently.
Enabling the Future of Open Banking
As Open Banking continues to evolve towards Open Finance, PISPs are expected to play an increasingly important role in connecting payments with broader financial services. This creates opportunities for businesses to develop more integrated customer experiences and innovative digital propositions.
Future Opportunities and Challenges for PISPs
As Open Banking continues to mature, Payment Initiation Service Providers are expected to play an increasingly important role in the evolution of digital payments. Alongside significant commercial opportunities, firms will need to adapt to changing customer expectations, emerging technologies and evolving regulatory requirements.
Commercial Variable Recurring Payments (VRP)
The expansion of Variable Recurring Payments (VRP) has the potential to transform recurring payments by providing a more flexible alternative to traditional direct debits. As commercial VRP develops, PISPs are likely to play an increasingly important role in enabling innovative payment experiences for both consumers and businesses.
Open Finance
Open Banking is widely regarded as the first step towards a broader Open Finance ecosystem. As access to financial products expands beyond payment accounts, PISPs may have opportunities to develop more integrated payment and financial services alongside other regulated providers.
Fraud and Authorised Push Payment (APP) Scams
As account-to-account payments continue to grow, preventing fraud and reducing Authorised Push Payment (APP) scams remain key priorities for regulators and the industry. PISPs will need to invest in robust fraud prevention, transaction monitoring and customer protection measures while maintaining a seamless payment experience.
Operational Resilience
Payment services are increasingly recognised as critical financial infrastructure. Firms must ensure that payment initiation services remain resilient, with effective governance, business continuity, incident management and third-party oversight to minimise operational disruption.
Third-Party Dependency
PISPs rely heavily on banking APIs, cloud infrastructure and other technology providers. Managing third-party relationships, monitoring service performance and maintaining appropriate contingency arrangements are becoming increasingly important as regulatory expectations around outsourcing continue to evolve.
API Standardisation and Interoperability
Although Open Banking has significantly improved connectivity between banks and third-party providers, differences in API implementation and customer journeys remain a challenge. Greater standardisation and interoperability will help improve reliability, reduce implementation complexity and encourage wider adoption of payment initiation services.
Dependence on Banking Infrastructure
Although PISPs deliver innovative payment experiences, they remain dependent on the APIs provided by Account Servicing Payment Service Providers (ASPSPs), typically banks and building societies. The availability, performance and consistency of these APIs directly influence the customer experience and operational reliability of payment initiation services. As a result, PISPs should establish appropriate monitoring, incident management and contingency arrangements to manage third-party dependency and support operational resilience.
Delivering a Consistent Customer Experience
While payment initiation can simplify account-to-account payments, the customer journey is not entirely controlled by the PISP. Authentication methods, redirection processes, biometric verification and the performance of individual banking APIs can all influence the user experience. Businesses should therefore consider customer journey design alongside regulatory compliance, ensuring payment processes remain intuitive while maintaining strong customer authentication and appropriate security controls.
Scaling Beyond the Regulation: What Makes a PISP Successful?
Obtaining an FCA licence is simply a ticket to enter the race; commercial viability requires solving real-world operational and consumer friction. Founders should focus on four strategic pillars:
UX and Redirect Optimisation: PISPs rely on redirecting users to their mobile banking apps. Top-tier platforms minimise checkout drop-off by implementing seamless biometric triggers (FaceID) and predictive bank selection screens.
Solving the Refund Dilemma: Open Banking transfers are inherently one-way. Successful PISPs win merchant clients by building proprietary API tools that automate instant reverse-credit transfers for customer returns.
Aggregator vs. Direct Build Strategy: Building custom connections to every major bank drains startup resources. Founders must weigh the speed of using an open banking aggregator (e.g., Plaid, Tink, Yapily) against the long-term margin savings of building direct bank APIs.
A Value-Driven Go-To-Market: Consumers do not choose payment methods based on regulatory perimeters. Successful platforms pitch merchants on clear financial wins such as capping transaction fees or achieving instant settlement and let merchants drive consumer adoption.
Conclusion
Payment Initiation Service Providers are becoming an increasingly important part of the UK's payments ecosystem. By enabling secure account-to-account payments through Open Banking, PISPs help businesses reduce payment friction, improve customer experiences and support the development of innovative digital payment propositions.
However, obtaining PISP authorisation is only one part of the journey. The most successful firms begin by designing the right business model, understanding their regulatory perimeter and establishing proportionate governance, risk and compliance capabilities that can evolve as the business grows.
Whether you are launching a new payment proposition, expanding into Open Banking or evaluating the most appropriate regulatory model, taking a strategic approach from the outset can reduce implementation costs, accelerate time to market and provide a stronger foundation for long-term growth.
Planning a Payment Proposition?
Whether you are considering PISP authorisation, exploring an agent model, or assessing whether another regulatory permission better supports your business, we help founders and leadership teams make informed strategic decisions before investing in authorisation.
Our support extends beyond FCA applications. We work with firms to define their regulatory strategy, design scalable operating models, establish governance, risk and compliance frameworks, and build resilient foundations for sustainable growth.
Explore our Risk Management Solutions for FinTech & Payment Firms or book a strategy call to discuss your business model, regulatory objectives and growth plans.
FAQs
1. Do I need a PISP authorisation to offer account-to-account payments?
Not necessarily. Whether you require PISP authorisation depends on your business model, your role in the payment journey and whether you are carrying out regulated payment initiation activities. Some firms may instead operate as agents of an authorised payment institution or provide technology services that fall outside the regulatory perimeter.
2. Can a PISP hold customer funds?
No. A PISP authorisation allows firms to initiate payments but does not permit them to hold customer funds or issue electronic money. Businesses wishing to provide these services may require Payment Institution (PI) or Electronic Money Institution (EMI) authorisation.
3. Can a business hold both AISP and PISP permissions?
Yes. Many Open Banking firms combine Account Information Services (AISP) and Payment Initiation Services (PISP) to provide both account aggregation and payment initiation as part of a single customer proposition.
4. Is becoming an agent a viable alternative to direct FCA authorisation?
For some businesses, yes. Operating as an agent of an authorised payment institution can provide a faster route to market while allowing firms to focus on product development and commercial growth. The most appropriate approach depends on the firm's objectives and operating model.
5. How long does it take to become authorised as a PISP?
Timescales vary depending on the quality of the application, the complexity of the business model and the FCA's review process. Firms should also allow sufficient time to develop governance arrangements, operational processes and supporting documentation before submitting an application.
6. What governance arrangements are expected for a PISP?
The FCA expects firms to establish proportionate governance, risk management and compliance arrangements appropriate to the size and complexity of the business. This typically includes documented governance structures, risk management processes, operational resilience, financial crime controls and appropriate oversight by senior management.
7. Can a PISP expand into other regulated payment services?
Yes. As businesses grow, they may decide to broaden their regulatory permissions by becoming an Authorised Payment Institution (API), obtaining AISP authorisation or, where appropriate, becoming an Electronic Money Institution (EMI). Planning for future growth at an early stage can reduce the need for significant restructuring later.
8. What is a regulatory perimeter assessment?
A regulatory perimeter assessment determines which regulated activities a business is carrying out and identifies the most appropriate regulatory model. Completing this assessment before applying for FCA authorisation helps founders avoid pursuing the wrong permission and supports more efficient product development.
9. What are the most common mistakes when launching a PISP proposition?
Common issues include selecting the wrong regulatory permission, underestimating governance and compliance requirements, treating authorisation as a documentation exercise rather than an operating model, and failing to consider how the business may evolve as new products and services are introduced.
10. When should founders seek regulatory advice?
The best time is before significant investment is made in product development or authorisation. Early regulatory advice can help shape the business model, identify the appropriate permissions, reduce implementation costs and create a more scalable foundation for future growth.
11. How long does PISP authorisation take?
The timeframe depends on the complexity of the application, the quality of the supporting documentation and the FCA review process. In practice, firms should allow sufficient time not only for the FCA's assessment but also to prepare governance arrangements, policies, financial resources and operational readiness before submitting an application.
12. Operational Readiness
One of the most common reasons projects take longer than expected is that firms focus on preparing the FCA application rather than preparing the business to operate as a regulated payment institution. Governance arrangements, operational resilience, outsourcing oversight, financial crime controls and appropriate staffing should all be established before authorisation is granted.
.png)