Home / EMI & payments authorisation
E-money & payments
EMI and payment institution authorisation
Authorisation for e-money institutions and payment firms — the FCA in the UK, EU licensing under PSD2 and the E-Money Directive, and payment and stored-value regimes worldwide.
E-money and payments is where most of our hands-on experience sits. We take firms from a product idea to an authorised institution — settling the permission perimeter, building the application, and standing up the safeguarding and financial-crime controls a regulator will examine most closely.
Payments applications fail for predictable reasons. The business model is described in marketing language rather than regulatory language. The safeguarding arrangement is asserted rather than evidenced. Transaction-monitoring rules are copied from a template with no reference to the actual customer base. The financial model shows revenue but not the own-funds position through to break-even. We write the pack so that a case officer can trace every claim to a control, a document or a number.
Who we do this for
- Wallet, card programme and stored-value businesses
- Money remittance and cross-border payment firms
- Merchant acquirers, payment facilitators and marketplaces
- Open banking firms seeking PISP or AISP permissions
- Banking-as-a-service providers and their programme managers
- Payroll, treasury and embedded-finance platforms
Getting the permission right the first time
The choice between an authorised payment institution, a small payment institution, an authorised e-money institution and a small EMI drives your capital, your passporting position and how long the process takes. Small EMI status is available while average outstanding e-money stays below the statutory threshold, but it does not passport and it caps growth — firms that take it as a shortcut frequently return within eighteen months for a full application. Initial capital sits at £350,000 for an authorised EMI, £125,000 for most authorised payment institutions, and lower figures for money remittance and payment initiation. Acting as an agent or distributor of an existing institution is a legitimate route to market, and sometimes the right one, but it is a commercial dependency rather than a licence.
Safeguarding is the control regulators test hardest
Relevant funds must be segregated or covered by an insurance policy or comparable guarantee, and the FCA has consulted on moving the regime towards a CASS-style framework with tighter records, reconciliations and reporting. What matters in an application is evidence: named safeguarding accounts, executed acknowledgement letters, a documented daily reconciliation with a defined break-resolution process, and a written explanation of exactly when funds become relevant funds in your flow of money. A diagram of the money flow does more for an application than three pages of policy prose.
Financial crime proportionate to your actual risk
A business-wide risk assessment that reflects your corridors, customer types and channels. An MLRO with genuine capacity for the role. Transaction-monitoring thresholds you can justify against your own expected volumes rather than a vendor default. Sanctions screening covering the payment chain, not just onboarding. Where a firm serves higher-risk corridors or high-volume low-value flows, we expect and prepare for a longer conversation with the case officer.
Capital, resilience and wind-down
Own funds calculated on the appropriate method and forecast forward, not just stated at day one. A financial model that survives a downside case. An operational resilience position covering important business services and impact tolerances. And a wind-down plan that shows how customer funds are returned and the business stops in an orderly way — increasingly the section that draws the sharpest follow-up questions.
Where we authorise
United Kingdom
Authorised and small EMI and payment institution permissions, including PISP and AISP.
European Union & EEA
Authorise in one member state and passport across the EEA. Lithuania and Ireland are common bases.
Rest of world
Payment and stored-value licences in major hubs.
How the process runs
Perimeter and structure
Which regulated activities you are actually performing, which permission fits, and whether the group structure and ownership will pass the controller assessment.
Building the pack
Regulatory business plan, programme of operations, safeguarding and financial-crime frameworks, financial model and own-funds forecast, governance map and individual applications.
Submission and case officer
Submission through Connect, then managing the information requests. The statutory clock for a complete application is three months; incomplete applications run to twelve.
Getting operational
Safeguarding accounts live, monitoring calibrated, reporting obligations diarised, and the platform ready to transact on day one rather than three months later.
Common questions
How long does FCA authorisation for an EMI or payment institution take?
The FCA has three months to determine a complete application and up to twelve months for an incomplete one. In practice, plan for six to twelve months end to end: preparation is usually two to three months, and almost every application attracts at least one substantive round of questions.
Should I apply as a small EMI or an authorised EMI?
Small EMI registration is faster and cheaper, but it caps average outstanding e-money at the statutory threshold, carries no passporting rights and limits how you can raise money against the licence. If your plan reaches the threshold within two years, applying for full authorisation now is usually cheaper than doing it twice.
What is the difference between a payment institution and an e-money institution?
A payment institution executes payment transactions. An e-money institution issues electronic money — a stored balance that the holder can spend later. If customers hold a balance with you before they spend it, you are almost certainly issuing e-money, and an EMI permission also lets you carry out payment services.
Can I use an agent or distributor arrangement instead of applying?
Yes, and for some business models it is the right first step. You operate under an authorised principal's permission, which is faster to market. The trade-offs are commercial dependency, the principal's risk appetite governing your product, and limited enterprise value in the arrangement itself.
What does the FCA scrutinise most closely?
Safeguarding arrangements, financial-crime controls calibrated to your actual risk, and whether the business model is viable enough to meet the threshold conditions on an ongoing basis. Applications rarely fail on legal drafting; they fail on evidence.
More on how we work, fees and timelines is on the FAQ page, and the regimes we cover are set out under jurisdictions.
Why firms use Pitchsd
Payments authorisations are the work we have done most often, on both sides of the table — leading applications, running the compliance function afterwards, and dealing directly with regulators and the Financial Ombudsman when things are contested. The safeguarding and financial-crime frameworks in our applications are written by people who have had to operate them.
We also build the technology the business runs on, so the platform and the permission arrive together rather than being someone else's problem. And we can put senior people into the business — a fractional MLRO, non-executive directors, a CFO — through our network. Get in touch to talk through where your application stands.