top of page

FCA Permissions for FinTech Firms: Which Authorisation Do You Need?

  • Writer: Julien Haye
    Julien Haye
  • Jan 26, 2024
  • 13 min read

Updated: Jul 7

A guide to Understanding UK Payment Licensing Requirements

One of the first questions every fintech founder faces is whether their business requires FCA authorisation and, if so, which permission applies.


The answer depends less on your technology and more on the activities you perform. Holding customer funds, issuing electronic money, initiating payments, accessing bank account data, providing credit, or offering investment services can each trigger different regulatory requirements.


This guide explains the main FCA permissions relevant to fintech firms and provides a framework for identifying which route may be appropriate for your business model.


Start Here: What Does Your Business Want to Do?


One of the most common misconceptions in financial services regulation is that businesses choose a permission first and then build their products around it. In reality, the opposite is true.


The FCA does not regulate firms based on what they call themselves. Instead, it regulates the activities they perform. The appropriate permission depends on how customer funds move through your business, the services you provide, and the role you play within the wider financial ecosystem.


The table below provides a high-level guide to the permissions most commonly used by fintech firms operating in the UK.


Table mapping common fintech business activities to typical FCA permissions. Businesses holding customer balances or issuing stored value typically require an Electronic Money Institution (EMI) permission. Payment processing firms may require an Authorised Payment Institution (API) or Small Payment Institution (SPI) permission. Open Banking providers may require AISP or PISP permissions. Consumer lending businesses typically require Consumer Credit Permission, investment firms require MiFID permissions, and deposit-taking institutions require banking authorisation.

A Few Important Points


This table provides a simplified overview and should not be treated as regulatory advice. Many fintech business models involve multiple regulated activities and may require more than one permission.


For example:

  • A digital wallet provider may require EMI authorisation.

  • An Open Banking platform may operate as an AISP, a PISP, or both.

  • A Buy Now Pay Later (BNPL) provider may require consumer credit permissions.

  • A platform offering both payments and stored-value accounts may require both payment services and e-money permissions.

  • An investment platform may require MiFID permissions alongside payment-related permissions.


The correct regulatory approach depends on the specific features of your product, how customer funds are handled, and the services provided to customers.


***


Choosing the wrong permission can lead to delays, unnecessary costs, and significant regulatory challenges during the authorisation process. Understanding the activities your business performs is often the first and most important step in building a successful and compliant fintech proposition.


If you are unsure which permission applies to your business model, a regulatory perimeter assessment can help identify the most appropriate route before significant time and resources are invested in an FCA application.


Decision tree infographic helping fintech founders identify the most appropriate FCA permission based on their business activities. The diagram maps common activities such as holding customer funds, issuing e-money, processing payments, accessing account information, initiating payments, providing consumer credit, offering investment services, and accepting deposits to permissions including EMI, API, SPI, AISP, PISP, Consumer Credit, MiFID Investment Firm, and Banking Authorisation.

Open Banking Permissions


The introduction of Open Banking has created new opportunities for fintech firms to provide innovative financial services without necessarily holding customer funds. Under the UK's Open Banking framework, two specialised permissions enable firms to access banking data and initiate payments on behalf of customers, subject to their explicit consent.


Account Information Service Provider (AISP)


An Account Information Service Provider (AISP) is authorised to access and aggregate account information from one or more financial institutions on behalf of a customer.


AISPs do not hold customer funds or execute payments. Instead, they use customer-authorised access to banking data to provide services such as:

  • Personal financial management applications

  • Budgeting and spending analysis tools

  • Creditworthiness assessments

  • Multi-bank account aggregation

  • Cash flow and financial reporting solutions


To operate as an AISP in the UK, a firm must be authorised or registered with the Financial Conduct Authority (FCA) and comply with requirements relating to customer consent, data security, operational resilience, and data protection.



Payment Initiation Service Provider (PISP)


A Payment Initiation Service Provider (PISP) is authorised to initiate payments directly from a customer's bank account to a merchant or another recipient.

Rather than relying on traditional card networks, PISPs use Open Banking infrastructure to facilitate account-to-account payments.


Common use cases include:

  • E-commerce checkout solutions

  • Account-to-account payment services

  • Bill payment platforms

  • Merchant payment solutions

  • Subscription and recurring payment services


PISPs must obtain explicit customer consent before initiating a payment and are subject to strict requirements relating to payment security, authentication, and operational resilience.



AISP vs PISP: What's the Difference?


Table comparing AISP and PISP permissions under Open Banking. It shows that AISPs provide account information services, can access customer account data with consent, cannot initiate payments and do not hold customer funds. PISPs initiate payments from customer bank accounts, have limited account data access for payment execution, can initiate payments and do not hold customer funds.

Do You Need an AISP or PISP Permission?


The appropriate permission depends on the services your business provides:

  • If you analyse, aggregate, or display customer banking information, you may require an AISP permission.

  • If you initiate payments directly from customer bank accounts, you may require a PISP permission.

  • Some firms obtain both permissions to offer a broader Open Banking proposition.


It is important to note that neither AISPs nor PISPs issue electronic money or hold customer funds. Businesses seeking to provide digital wallets, stored-value accounts, or prepaid card services will typically require a different regulatory framework, such as Electronic Money Institution (EMI) authorisation or Payment Institution (PI) authorisation, depending on the activities performed.


Common FinTech Business Models and Typical Permissions


Many founders begin by thinking about the product they want to build rather than the regulatory permissions they may require. While this is a natural starting point, the FCA focuses on the activities a business performs rather than the technology it uses.


Understanding how common fintech business models align with regulatory permissions can help businesses identify the most appropriate authorisation pathway at an early stage.


Table showing common fintech business models and the FCA permissions typically associated with them. Digital wallets, prepaid card programmes, and expense management platforms commonly require Electronic Money Institution (EMI) authorisation. Payment gateways typically require Authorised Payment Institution (API) authorisation. Open Banking applications may require AISP permissions, while account-to-account payment solutions may require PISP permissions. Marketplace payment platforms may require API or EMI authorisation depending on how funds flow through the platform. Buy Now Pay Later providers typically require Consumer Credit Permission, and investment platforms commonly require MiFID Investment Firm authorisation.

Examples in Practice


Digital Wallets and Stored-Value Accounts


Businesses that allow customers to hold balances or store funds electronically will often require Electronic Money Institution (EMI) authorisation. Common examples include digital wallets, multi-currency accounts, prepaid card programmes, and corporate spend management solutions.


Payment Processing and Payment Gateways


Businesses that facilitate payments without issuing electronic money may fall within the Payment Institution regime. This is common for payment gateways, merchant acquiring solutions, and payment processing platforms.


Open Banking Solutions


Businesses that aggregate account information or provide personal finance management tools may require an AISP permission. Firms initiating payments directly from customer bank accounts may require a PISP permission.


Marketplace and Platform Payments


Online marketplaces can be particularly complex from a regulatory perspective. The appropriate permission often depends on how customer funds move through the platform and whether the business takes possession of funds or simply facilitates transactions between buyers and sellers.


Lending and BNPL Solutions


Fintech firms offering consumer lending, credit broking, or Buy Now Pay Later services will typically require Consumer Credit permissions and must comply with additional conduct and consumer protection requirements.


Investment Platforms


Businesses providing investment advice, portfolio management, trading services, or investment intermediation may require authorisation under the MiFID framework, depending on the specific services provided.


***


Many FCA applications encounter delays because firms focus on products and technology before fully understanding the underlying regulated activities they are performing.


A clear assessment of the business model, customer journey, and fund flows is often the first step in identifying the most appropriate permission and avoiding costly restructuring later in the authorisation process.


Typical Growth Pathways for Payment Firms


Many successful payment firms do not begin with their final regulatory permission. As products evolve, customer demand increases and new services are introduced, firms often expand their regulatory permissions to support their long-term strategy.


Planning for future growth at the outset can reduce the need for costly restructuring, minimise regulatory disruption and create a more scalable operating model.


The examples below illustrate common regulatory journeys. The most appropriate pathway will always depend on your business model, operating model and strategic objectives.


Table illustrating typical regulatory growth pathways for financial services firms. Examples include Open Banking platforms progressing from AISP to PISP to Authorised Payment Institution (API), payment platforms from Small Payment Institution (SPI) to API to Electronic Money Institution (EMI), embedded finance providers expanding from technology provider to PISP or API and later EMI, digital marketplaces moving from agent to API, and lending platforms progressing from credit broking to full consumer credit permission.

Planning for scalability


Selecting a regulatory permission should not focus solely on today's product. Founders should also consider how their proposition may evolve over the next three to five years. Expanding into new payment services, issuing digital wallets, introducing account information services or launching additional financial products may all require different regulatory permissions.


Taking a strategic view of the regulatory perimeter early helps avoid unnecessary variations of permission, supports faster product development and creates a governance framework capable of growing with the business.


What Does FCA Authorisation Cost?


One of the most common questions asked by fintech founders is how much FCA authorisation will cost. The answer depends on the type of permission being sought, the complexity of the business model, and whether external support is required.


Authorisation costs typically fall into four categories:

  • FCA application fees

  • Regulatory capital requirements

  • Legal and advisory costs

  • Internal implementation and compliance costs


The table below provides a high-level indication of the investment commonly associated with different permissions.



Note - Actual costs vary significantly depending on the complexity of the business model, governance arrangements, documentation quality, and readiness of the applicant.


Beyond Application Costs


Many firms focus exclusively on obtaining authorisation and underestimate the ongoing investment required to maintain compliance.

Common ongoing costs include:

  • Compliance monitoring

  • Risk management

  • Internal audits

  • Regulatory reporting

  • Consumer Duty monitoring

  • Operational resilience programmes

  • Financial crime controls

Building these requirements into financial forecasts from the outset can help avoid surprises after authorisation.


How Long Does FCA Authorisation Take?


The FCA assesses each application individually, and timelines vary depending on the type of permission requested, the quality of the application, and the complexity of the business model.


The following ranges provide a useful guide for planning purposes.



Factors That Influence Approval Timelines


Several factors can significantly affect how long the authorisation process takes:

  • Selection of the correct permission

  • Quality of the business plan

  • Strength of governance arrangements

  • Completeness of policies and procedures

  • Financial forecasts and capital adequacy assessments

  • FCA requests for additional information

  • Changes to the business model during the review process


Planning for Success


FCA authorisation should be viewed as a strategic project rather than a regulatory formality. Firms that invest time in understanding their regulatory obligations, building appropriate governance arrangements, and preparing comprehensive documentation are typically better positioned for a smoother and more efficient authorisation process.


Navigating Common Licensing Hurdles for UK Financial Firms

 

The Challenges in Obtaining a UK Financial Licence Infographic

Obtaining a financial license in the UK, whether it's for a bank, EMI, PI, or any other financial institution, can be a complex process. Here are some key challenges to be aware of:

 

  • Regulatory Requirements: Understanding and correctly interpreting the extensive regulatory requirements set by bodies like the FCA and PRA can be daunting. Misinterpretation can lead to significant setbacks in the application process.

  • AML and KYC Compliance: Ensuring compliance with Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations is often challenging, requiring robust systems and continuous monitoring.

  • Capital and Financial Stability: Meeting the stringent capital adequacy requirements and proving financial stability is a hurdle for many applicants, especially for start-ups and smaller institutions.

  • Risk Management and Governance: Establishing effective risk management frameworks and governance structures that satisfy regulatory standards can be complex and resource-intensive.

  • Technology and Security: Implementing secure and compliant technological solutions is critical, particularly for EMIs and PISPs, and poses both operational and financial challenges.

  • Application Process: The application process itself can be challenging due to the need for detailed documentation, comprehensive business plans, and often a lengthy approval timeline. You also need to ensure your leadership team meets FCA standards with our Key Personnel Assessment Checklist—a practical resource for evaluating fitness, propriety, and accountability during the authorisation process.

  • Ongoing Compliance: Maintaining compliance with ever-evolving regulatory standards demands continuous effort and resources, necessitating regular audits and updates to policies and procedures.

  • Consumer Protection and Transparency: Upholding high standards of consumer protection and ensuring transparency in services are essential but can be challenging amidst complex regulatory demands.


For more detailed insights into common pitfalls in FCA authorisation and how to avoid them, check out our comprehensive risk mitigation strategies tailored to regulated firms.


Should You Build or Partner?


One of the most important strategic decisions facing fintech founders is whether to obtain their own FCA permission or launch using the permissions of an existing regulated firm.


There is no universal right answer. The optimal approach depends on your business model, available funding, growth plans, regulatory ambitions, and desired speed to market.


In many cases, firms begin by partnering with an existing regulated provider before pursuing their own authorisation as the business matures.


Option 1: Obtain Your Own FCA Permission


Under this model, your business becomes directly authorised by the Financial Conduct Authority (FCA) and assumes responsibility for meeting all regulatory obligations.


This approach provides the highest degree of control and independence but typically requires the greatest investment of time, resources, and expertise.


Advantages include:

  • Full control over products and customer experience

  • Direct relationship with the FCA

  • Greater strategic flexibility

  • Increased credibility with investors and partners

  • Ability to scale without reliance on a third party


Considerations include:

  • Higher authorisation costs

  • Longer time to market

  • Ongoing compliance obligations

  • Regulatory capital requirements

  • Governance and reporting responsibilities


This route is often chosen by firms seeking long-term independence and those planning significant growth.


Option 2: Operate as an EMI Agent


Some fintech firms choose to operate under the permissions of an authorised Electronic Money Institution (EMI) through an agency arrangement.


Under this model, the principal EMI remains responsible for regulatory compliance while the agent delivers services under the principal's oversight.


Advantages include:

  • Faster route to market

  • No need for immediate EMI authorisation

  • Reduced regulatory burden

  • Lower initial costs

  • Ability to test the market before pursuing authorisation


Considerations include:

  • Ongoing oversight by the principal EMI

  • Restrictions on product design and operations

  • Commercial dependency on the principal

  • Agency due diligence and monitoring requirements

  • Potential limitations on future flexibility


This approach is commonly used by early-stage fintech firms looking to launch quickly.


Option 3: Banking-as-a-Service (BaaS)


Banking-as-a-Service providers allow fintech firms to integrate regulated banking and payment functionality through APIs without becoming a bank themselves.


Common services include:

  • Payment accounts

  • Card issuing

  • Payments processing

  • Foreign exchange services

  • Customer onboarding

  • Embedded banking capabilities


Advantages include:

  • Rapid deployment

  • Reduced infrastructure requirements

  • Access to established banking capabilities

  • Lower initial investment


Considerations include:

  • Dependence on third-party providers

  • Contractual and operational risks

  • Potential regulatory complexity

  • Vendor management requirements


Many modern fintech businesses use Banking-as-a-Service as part of their operating model, either permanently or during their initial growth phase.


Option 4: Appointed Representative Models


In some regulated sectors, firms may operate as an Appointed Representative (AR) under the supervision of an authorised principal firm.


This model is most commonly associated with investment and consumer credit activities rather than payment services or e-money issuance.


Advantages include:

  • Faster market entry

  • Reduced authorisation burden

  • Access to regulatory expertise

  • Lower initial compliance costs


Considerations include:

  • Principal oversight and monitoring

  • Restrictions on activities

  • Commercial dependency

  • Potential limitations on future expansion


The availability and suitability of AR arrangements depend on the specific regulated activities being undertaken.


Which Approach Is Right for Your Business?


Table comparing different fintech market entry models, including direct FCA authorisation, EMI agency arrangements, Banking-as-a-Service providers, and Appointed Representative models. The comparison evaluates speed to market, regulatory control, upfront costs, operational flexibility, and long-term independence to help fintech founders determine the most appropriate route to market.

A Common Growth Path


Many successful fintech firms follow a staged approach:

Phase 1: Launch using an EMI agent or Banking-as-a-Service provider.

Phase 2: Validate the business model and achieve product-market fit.

Phase 3: Build internal governance, risk, and compliance capabilities.

Phase 4: Apply for direct FCA authorisation when the scale and economics justify the investment.


This approach can accelerate market entry while creating a clear pathway towards long-term regulatory independence.


Choosing the Right Regulatory Path


Selecting the appropriate FCA permission is one of the most important decisions a fintech founder will make. The choice influences everything from funding requirements and time to market to governance expectations and long-term growth opportunities.


While many firms begin by focusing on products and technology, the FCA's starting point is always the activities being performed. Holding customer funds, issuing electronic money, processing payments, accessing account information, providing credit, or offering investment services can each lead to very different regulatory outcomes.


The good news is that obtaining your own authorisation is not the only route available. Depending on your objectives, partnering with an authorised institution, operating as an agent, or leveraging Banking-as-a-Service solutions may provide a faster and more cost-effective route to market while your business grows.


The most successful firms typically take the time to assess their business model, customer journey, fund flows, growth plans, and regulatory obligations before committing to a particular approach. Getting this decision right early can significantly reduce costs, accelerate launch timelines, and avoid unnecessary regulatory challenges later.


Whether you are launching a new fintech venture, expanding into additional regulated activities, or reviewing your current regulatory structure, a clear understanding of the available permissions is the first step towards building a scalable and compliant business.



 

Need Expert Guidance? We Can Help!

 

Are you considering applying for a License and feeling overwhelmed by the complexity? Our consultancy specialises in guiding businesses through the intricacies of obtaining a License. With our expertise in regulatory compliance, financial planning, and strategic consultation, we can streamline your application process, ensuring that you meet all the necessary requirements with ease.

 

Don't navigate this journey alone. Contact us today for a consultation, and let us help you to unlock the potential of your business in the financial services sector. With Aevitium LTD's support, your path to obtaining a License can be clear and achievable.



Frequently Asked Questions


Can I launch a fintech without FCA authorisation?


Possibly. Not every fintech business requires direct FCA authorisation from day one.


Many early-stage firms launch using alternative models such as:

  • Operating as an agent of an authorised Electronic Money Institution (EMI)

  • Partnering with a Banking-as-a-Service (BaaS) provider

  • Acting under another regulated firm's permissions where permitted


The appropriate approach depends on your business model, customer journey, and regulatory perimeter. While these models can accelerate market entry, they often involve contractual dependencies and regulatory oversight from the principal firm.


What is the difference between an EMI and an EMI Agent?


An Electronic Money Institution (EMI) is authorised by the FCA to issue electronic money and provide certain payment services.


An EMI Agent operates under the permissions of an authorised EMI rather than holding its own authorisation.


The principal EMI remains responsible for regulatory compliance and oversight, while the agent delivers services within the scope agreed with the principal.

Many fintech firms use an agency model as an interim step before obtaining their own authorisation.


What is Banking-as-a-Service (BaaS)?


Banking-as-a-Service allows fintech firms to access regulated banking and payment functionality through APIs provided by authorised institutions.


Typical services include:

  • Payment accounts

  • Card issuing

  • Payment processing

  • Foreign exchange services

  • Customer onboarding


BaaS can significantly reduce time to market by allowing firms to leverage existing regulated infrastructure rather than building it themselves.


Can I apply for multiple FCA permissions at the same time?


Yes. Some business models require more than one permission.

For example:

  • An EMI may also require consumer credit permissions.

  • An Open Banking provider may require both AISP and PISP permissions.

  • An investment platform may require investment permissions alongside payment-related permissions.

Applying for multiple permissions can increase the complexity of the authorisation process and requires careful planning to ensure the regulatory scope is correctly defined.


Can I upgrade from an SPI to an API or EMI later?


Yes.


Many firms begin as a Small Payment Institution (SPI) before transitioning to an Authorised Payment Institution (API) as transaction volumes grow or business requirements evolve.


Similarly, some firms initially operate under an agency model before pursuing their own EMI authorisation.


However, moving to a broader permission typically requires a new FCA application and additional governance, capital, and compliance arrangements.


Do I need a Compliance Officer or MLRO before applying?


In most cases, the FCA expects firms to demonstrate that appropriate compliance and financial crime responsibilities will be performed from the outset.


Depending on the type of permission sought, firms may need individuals responsible for:

  • Compliance oversight

  • Financial crime controls

  • Risk management

  • Operational resilience

  • Consumer Duty monitoring


These roles can sometimes be fulfilled internally, outsourced, or provided through a secondment arrangement, provided the firm maintains effective oversight and accountability.


What are the ongoing compliance obligations after authorisation?


Authorisation is only the beginning of the regulatory journey.


Ongoing obligations commonly include:

  • Regulatory reporting

  • Financial crime monitoring

  • Consumer Duty compliance

  • Governance and board oversight

  • Risk management activities

  • Operational resilience requirements

  • Regulatory change management

  • Internal control monitoring


The scope of these obligations varies depending on the permission held and the nature of the firm's activities.


Does FCA authorisation allow a fintech to operate internationally?


Not automatically.


FCA authorisation allows firms to conduct regulated activities within the scope of their UK permissions. Operating in other jurisdictions may require additional regulatory analysis, local registrations, authorisations, or partnerships depending on the countries involved and the services being provided.


Firms planning international expansion should assess regulatory requirements in each target market before launch.

 
 
bottom of page