FCA Permissions for FinTech Firms: Which Authorisation Do You Need?
- Julien Haye

- Jan 26, 2024
- 13 min read
Updated: Jul 7

One of the first questions every fintech founder faces is whether their business requires FCA authorisation and, if so, which permission applies.
The answer depends less on your technology and more on the activities you perform. Holding customer funds, issuing electronic money, initiating payments, accessing bank account data, providing credit, or offering investment services can each trigger different regulatory requirements.
This guide explains the main FCA permissions relevant to fintech firms and provides a framework for identifying which route may be appropriate for your business model.
Start Here: What Does Your Business Want to Do?
One of the most common misconceptions in financial services regulation is that businesses choose a permission first and then build their products around it. In reality, the opposite is true.
The FCA does not regulate firms based on what they call themselves. Instead, it regulates the activities they perform. The appropriate permission depends on how customer funds move through your business, the services you provide, and the role you play within the wider financial ecosystem.
The table below provides a high-level guide to the permissions most commonly used by fintech firms operating in the UK.

A Few Important Points
This table provides a simplified overview and should not be treated as regulatory advice. Many fintech business models involve multiple regulated activities and may require more than one permission.
For example:
A digital wallet provider may require EMI authorisation.
An Open Banking platform may operate as an AISP, a PISP, or both.
A Buy Now Pay Later (BNPL) provider may require consumer credit permissions.
A platform offering both payments and stored-value accounts may require both payment services and e-money permissions.
An investment platform may require MiFID permissions alongside payment-related permissions.
The correct regulatory approach depends on the specific features of your product, how customer funds are handled, and the services provided to customers.
***
Choosing the wrong permission can lead to delays, unnecessary costs, and significant regulatory challenges during the authorisation process. Understanding the activities your business performs is often the first and most important step in building a successful and compliant fintech proposition.
If you are unsure which permission applies to your business model, a regulatory perimeter assessment can help identify the most appropriate route before significant time and resources are invested in an FCA application.

Open Banking Permissions
The introduction of Open Banking has created new opportunities for fintech firms to provide innovative financial services without necessarily holding customer funds. Under the UK's Open Banking framework, two specialised permissions enable firms to access banking data and initiate payments on behalf of customers, subject to their explicit consent.
Account Information Service Provider (AISP)
An Account Information Service Provider (AISP) is authorised to access and aggregate account information from one or more financial institutions on behalf of a customer.
AISPs do not hold customer funds or execute payments. Instead, they use customer-authorised access to banking data to provide services such as:
Personal financial management applications
Budgeting and spending analysis tools
Creditworthiness assessments
Multi-bank account aggregation
Cash flow and financial reporting solutions
To operate as an AISP in the UK, a firm must be authorised or registered with the Financial Conduct Authority (FCA) and comply with requirements relating to customer consent, data security, operational resilience, and data protection.
Please read our detailed article: The Role and Significance of Account Information Service Providers in Financial Services
Payment Initiation Service Provider (PISP)
A Payment Initiation Service Provider (PISP) is authorised to initiate payments directly from a customer's bank account to a merchant or another recipient.
Rather than relying on traditional card networks, PISPs use Open Banking infrastructure to facilitate account-to-account payments.
Common use cases include:
E-commerce checkout solutions
Account-to-account payment services
Bill payment platforms
Merchant payment solutions
Subscription and recurring payment services
PISPs must obtain explicit customer consent before initiating a payment and are subject to strict requirements relating to payment security, authentication, and operational resilience.
Please read our detailed article: Payment Initiation Service Providers: Redefining Financial Transactions
AISP vs PISP: What's the Difference?

Do You Need an AISP or PISP Permission?
The appropriate permission depends on the services your business provides:
If you analyse, aggregate, or display customer banking information, you may require an AISP permission.
If you initiate payments directly from customer bank accounts, you may require a PISP permission.
Some firms obtain both permissions to offer a broader Open Banking proposition.
It is important to note that neither AISPs nor PISPs issue electronic money or hold customer funds. Businesses seeking to provide digital wallets, stored-value accounts, or prepaid card services will typically require a different regulatory framework, such as Electronic Money Institution (EMI) authorisation or Payment Institution (PI) authorisation, depending on the activities performed.
Common FinTech Business Models and Typical Permissions
Many founders begin by thinking about the product they want to build rather than the regulatory permissions they may require. While this is a natural starting point, the FCA focuses on the activities a business performs rather than the technology it uses.
Understanding how common fintech business models align with regulatory permissions can help businesses identify the most appropriate authorisation pathway at an early stage.

Examples in Practice
Digital Wallets and Stored-Value Accounts
Businesses that allow customers to hold balances or store funds electronically will often require Electronic Money Institution (EMI) authorisation. Common examples include digital wallets, multi-currency accounts, prepaid card programmes, and corporate spend management solutions.
Payment Processing and Payment Gateways
Businesses that facilitate payments without issuing electronic money may fall within the Payment Institution regime. This is common for payment gateways, merchant acquiring solutions, and payment processing platforms.
Open Banking Solutions
Businesses that aggregate account information or provide personal finance management tools may require an AISP permission. Firms initiating payments directly from customer bank accounts may require a PISP permission.
Marketplace and Platform Payments
Online marketplaces can be particularly complex from a regulatory perspective. The appropriate permission often depends on how customer funds move through the platform and whether the business takes possession of funds or simply facilitates transactions between buyers and sellers.
Lending and BNPL Solutions
Fintech firms offering consumer lending, credit broking, or Buy Now Pay Later services will typically require Consumer Credit permissions and must comply with additional conduct and consumer protection requirements.
Investment Platforms
Businesses providing investment advice, portfolio management, trading services, or investment intermediation may require authorisation under the MiFID framework, depending on the specific services provided.
***
Many FCA applications encounter delays because firms focus on products and technology before fully understanding the underlying regulated activities they are performing.
A clear assessment of the business model, customer journey, and fund flows is often the first step in identifying the most appropriate permission and avoiding costly restructuring later in the authorisation process.
Typical Growth Pathways for Payment Firms
Many successful payment firms do not begin with their final regulatory permission. As products evolve, customer demand increases and new services are introduced, firms often expand their regulatory permissions to support their long-term strategy.
Planning for future growth at the outset can reduce the need for costly restructuring, minimise regulatory disruption and create a more scalable operating model.
The examples below illustrate common regulatory journeys. The most appropriate pathway will always depend on your business model, operating model and strategic objectives.

Planning for scalability
Selecting a regulatory permission should not focus solely on today's product. Founders should also consider how their proposition may evolve over the next three to five years. Expanding into new payment services, issuing digital wallets, introducing account information services or launching additional financial products may all require different regulatory permissions.
Taking a strategic view of the regulatory perimeter early helps avoid unnecessary variations of permission, supports faster product development and creates a governance framework capable of growing with the business.
What Does FCA Authorisation Cost?
One of the most common questions asked by fintech founders is how much FCA authorisation will cost. The answer depends on the type of permission being sought, the complexity of the business model, and whether external support is required.
Authorisation costs typically fall into four categories:
FCA application fees
Regulatory capital requirements
Legal and advisory costs
Internal implementation and compliance costs
The table below provides a high-level indication of the investment commonly associated with different permissions.

Note - Actual costs vary significantly depending on the complexity of the business model, governance arrangements, documentation quality, and readiness of the applicant.
Beyond Application Costs
Many firms focus exclusively on obtaining authorisation and underestimate the ongoing investment required to maintain compliance.
Common ongoing costs include:
Compliance monitoring
Risk management
Internal audits
Regulatory reporting
Consumer Duty monitoring
Operational resilience programmes
Financial crime controls
Building these requirements into financial forecasts from the outset can help avoid surprises after authorisation.
How Long Does FCA Authorisation Take?
The FCA assesses each application individually, and timelines vary depending on the type of permission requested, the quality of the application, and the complexity of the business model.
The following ranges provide a useful guide for planning purposes.

Factors That Influence Approval Timelines
Several factors can significantly affect how long the authorisation process takes:
Selection of the correct permission
Quality of the business plan
Strength of governance arrangements
Completeness of policies and procedures
Financial forecasts and capital adequacy assessments
FCA requests for additional information
Changes to the business model during the review process
Planning for Success
FCA authorisation should be viewed as a strategic project rather than a regulatory formality. Firms that invest time in understanding their regulatory obligations, building appropriate governance arrangements, and preparing comprehensive documentation are typically better positioned for a smoother and more efficient authorisation process.
Navigating Common Licensing Hurdles for UK Financial Firms

Obtaining a financial license in the UK, whether it's for a bank, EMI, PI, or any other financial institution, can be a complex process. Here are some key challenges to be aware of:
Regulatory Requirements: Understanding and correctly interpreting the extensive regulatory requirements set by bodies like the FCA and PRA can be daunting. Misinterpretation can lead to significant setbacks in the application process.
AML and KYC Compliance: Ensuring compliance with Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations is often challenging, requiring robust systems and continuous monitoring.
Capital and Financial Stability: Meeting the stringent capital adequacy requirements and proving financial stability is a hurdle for many applicants, especially for start-ups and smaller institutions.
Risk Management and Governance: Establishing effective risk management frameworks and governance structures that satisfy regulatory standards can be complex and resource-intensive.
Technology and Security: Implementing secure and compliant technological solutions is critical, particularly for EMIs and PISPs, and poses both operational and financial challenges.
Application Process: The application process itself can be challenging due to the need for detailed documentation, comprehensive business plans, and often a lengthy approval timeline. You also need to ensure your leadership team meets FCA standards with our Key Personnel Assessment Checklist—a practical resource for evaluating fitness, propriety, and accountability during the authorisation process.
Ongoing Compliance: Maintaining compliance with ever-evolving regulatory standards demands continuous effort and resources, necessitating regular audits and updates to policies and procedures.
Consumer Protection and Transparency: Upholding high standards of consumer protection and ensuring transparency in services are essential but can be challenging amidst complex regulatory demands.
For more detailed insights into common pitfalls in FCA authorisation and how to avoid them, check out our comprehensive risk mitigation strategies tailored to regulated firms.
Should You Build or Partner?
One of the most important strategic decisions facing fintech founders is whether to obtain their own FCA permission or launch using the permissions of an existing regulated firm.
There is no universal right answer. The optimal approach depends on your business model, available funding, growth plans, regulatory ambitions, and desired speed to market.
In many cases, firms begin by partnering with an existing regulated provider before pursuing their own authorisation as the business matures.
Option 1: Obtain Your Own FCA Permission
Under this model, your business becomes directly authorised by the Financial Conduct Authority (FCA) and assumes responsibility for meeting all regulatory obligations.
This approach provides the highest degree of control and independence but typically requires the greatest investment of time, resources, and expertise.
Advantages include:
Full control over products and customer experience
Direct relationship with the FCA
Greater strategic flexibility
Increased credibility with investors and partners
Ability to scale without reliance on a third party
Considerations include:
Higher authorisation costs
Longer time to market
Ongoing compliance obligations
Regulatory capital requirements
Governance and reporting responsibilities
This route is often chosen by firms seeking long-term independence and those planning significant growth.
Option 2: Operate as an EMI Agent
Some fintech firms choose to operate under the permissions of an authorised Electronic Money Institution (EMI) through an agency arrangement.
Under this model, the principal EMI remains responsible for regulatory compliance while the agent delivers services under the principal's oversight.
Advantages include:
Faster route to market
No need for immediate EMI authorisation
Reduced regulatory burden
Lower initial costs
Ability to test the market before pursuing authorisation
Considerations include:
Ongoing oversight by the principal EMI
Restrictions on product design and operations
Commercial dependency on the principal
Agency due diligence and monitoring requirements
Potential limitations on future flexibility
This approach is commonly used by early-stage fintech firms looking to launch quickly.
Option 3: Banking-as-a-Service (BaaS)
Banking-as-a-Service providers allow fintech firms to integrate regulated banking and payment functionality through APIs without becoming a bank themselves.
Common services include:
Payment accounts
Card issuing
Payments processing
Foreign exchange services
Customer onboarding
Embedded banking capabilities
Advantages include:
Rapid deployment
Reduced infrastructure requirements
Access to established banking capabilities
Lower initial investment
Considerations include:
Dependence on third-party providers
Contractual and operational risks
Potential regulatory complexity
Vendor management requirements
Many modern fintech businesses use Banking-as-a-Service as part of their operating model, either permanently or during their initial growth phase.
Option 4: Appointed Representative Models
In some regulated sectors, firms may operate as an Appointed Representative (AR) under the supervision of an authorised principal firm.
This model is most commonly associated with investment and consumer credit activities rather than payment services or e-money issuance.
Advantages include:
Faster market entry
Reduced authorisation burden
Access to regulatory expertise
Lower initial compliance costs
Considerations include:
Principal oversight and monitoring
Restrictions on activities
Commercial dependency
Potential limitations on future expansion
The availability and suitability of AR arrangements depend on the specific regulated activities being undertaken.
Which Approach Is Right for Your Business?

A Common Growth Path
Many successful fintech firms follow a staged approach:
Phase 1: Launch using an EMI agent or Banking-as-a-Service provider.
Phase 2: Validate the business model and achieve product-market fit.
Phase 3: Build internal governance, risk, and compliance capabilities.
Phase 4: Apply for direct FCA authorisation when the scale and economics justify the investment.
This approach can accelerate market entry while creating a clear pathway towards long-term regulatory independence.
Choosing the Right Regulatory Path
Selecting the appropriate FCA permission is one of the most important decisions a fintech founder will make. The choice influences everything from funding requirements and time to market to governance expectations and long-term growth opportunities.
While many firms begin by focusing on products and technology, the FCA's starting point is always the activities being performed. Holding customer funds, issuing electronic money, processing payments, accessing account information, providing credit, or offering investment services can each lead to very different regulatory outcomes.
The good news is that obtaining your own authorisation is not the only route available. Depending on your objectives, partnering with an authorised institution, operating as an agent, or leveraging Banking-as-a-Service solutions may provide a faster and more cost-effective route to market while your business grows.
The most successful firms typically take the time to assess their business model, customer journey, fund flows, growth plans, and regulatory obligations before committing to a particular approach. Getting this decision right early can significantly reduce costs, accelerate launch timelines, and avoid unnecessary regulatory challenges later.
Whether you are launching a new fintech venture, expanding into additional regulated activities, or reviewing your current regulatory structure, a clear understanding of the available permissions is the first step towards building a scalable and compliant business.
Need Expert Guidance? We Can Help!
Are you considering applying for a License and feeling overwhelmed by the complexity? Our consultancy specialises in guiding businesses through the intricacies of obtaining a License. With our expertise in regulatory compliance, financial planning, and strategic consultation, we can streamline your application process, ensuring that you meet all the necessary requirements with ease.
Don't navigate this journey alone. Contact us today for a consultation, and let us help you to unlock the potential of your business in the financial services sector. With Aevitium LTD's support, your path to obtaining a License can be clear and achievable.
Frequently Asked Questions
Can I launch a fintech without FCA authorisation?
Possibly. Not every fintech business requires direct FCA authorisation from day one.
Many early-stage firms launch using alternative models such as:
Operating as an agent of an authorised Electronic Money Institution (EMI)
Partnering with a Banking-as-a-Service (BaaS) provider
Acting under another regulated firm's permissions where permitted
The appropriate approach depends on your business model, customer journey, and regulatory perimeter. While these models can accelerate market entry, they often involve contractual dependencies and regulatory oversight from the principal firm.
What is the difference between an EMI and an EMI Agent?
An Electronic Money Institution (EMI) is authorised by the FCA to issue electronic money and provide certain payment services.
An EMI Agent operates under the permissions of an authorised EMI rather than holding its own authorisation.
The principal EMI remains responsible for regulatory compliance and oversight, while the agent delivers services within the scope agreed with the principal.
Many fintech firms use an agency model as an interim step before obtaining their own authorisation.
What is Banking-as-a-Service (BaaS)?
Banking-as-a-Service allows fintech firms to access regulated banking and payment functionality through APIs provided by authorised institutions.
Typical services include:
Payment accounts
Card issuing
Payment processing
Foreign exchange services
Customer onboarding
BaaS can significantly reduce time to market by allowing firms to leverage existing regulated infrastructure rather than building it themselves.
Can I apply for multiple FCA permissions at the same time?
Yes. Some business models require more than one permission.
For example:
An EMI may also require consumer credit permissions.
An Open Banking provider may require both AISP and PISP permissions.
An investment platform may require investment permissions alongside payment-related permissions.
Applying for multiple permissions can increase the complexity of the authorisation process and requires careful planning to ensure the regulatory scope is correctly defined.
Can I upgrade from an SPI to an API or EMI later?
Yes.
Many firms begin as a Small Payment Institution (SPI) before transitioning to an Authorised Payment Institution (API) as transaction volumes grow or business requirements evolve.
Similarly, some firms initially operate under an agency model before pursuing their own EMI authorisation.
However, moving to a broader permission typically requires a new FCA application and additional governance, capital, and compliance arrangements.
Do I need a Compliance Officer or MLRO before applying?
In most cases, the FCA expects firms to demonstrate that appropriate compliance and financial crime responsibilities will be performed from the outset.
Depending on the type of permission sought, firms may need individuals responsible for:
Compliance oversight
Financial crime controls
Risk management
Operational resilience
Consumer Duty monitoring
These roles can sometimes be fulfilled internally, outsourced, or provided through a secondment arrangement, provided the firm maintains effective oversight and accountability.
What are the ongoing compliance obligations after authorisation?
Authorisation is only the beginning of the regulatory journey.
Ongoing obligations commonly include:
Regulatory reporting
Financial crime monitoring
Consumer Duty compliance
Governance and board oversight
Risk management activities
Operational resilience requirements
Regulatory change management
Internal control monitoring
The scope of these obligations varies depending on the permission held and the nature of the firm's activities.
Does FCA authorisation allow a fintech to operate internationally?
Not automatically.
FCA authorisation allows firms to conduct regulated activities within the scope of their UK permissions. Operating in other jurisdictions may require additional regulatory analysis, local registrations, authorisations, or partnerships depending on the countries involved and the services being provided.
Firms planning international expansion should assess regulatory requirements in each target market before launch.
.png)