Authorisation
FCA Payment Institution Authorisation: What Founders Commonly Underestimate
A credible application is a joined-up account of how the firm will operate. Documents matter, but consistency, ownership and evidence usually determine whether the proposition is genuinely ready for scrutiny.
Key takeaways
- Completeness is not a document-counting exercise: the business model, financials, governance and controls must tell the same story.
- Generic policies and unresolved partner dependencies tend to expose design gaps rather than demonstrate readiness.
- A complete payments or e-money application is usually assessed within three months; an incomplete application can take up to 12 months.
- Pre-submission challenge should test whether named owners can explain and evidence how arrangements will work from day one.
For founders, the authorisation programme can appear to be a drafting exercise: assemble the forms, write the policies, upload the supporting material to FCA Connect and respond to questions. That view understates the work. The application is also an assessment of whether the proposed firm is ready, willing and organised to conduct its regulated business.
The practical question is not simply whether every attachment exists. It is whether the application describes one coherent business, operated by people with the capability, resources and authority to deliver it.
Completeness is necessary, but it is not the whole test
The FCA can reject a submission without assessment when required minimum information is missing. Even where the submission passes that threshold, a case officer will need to understand how the proposition, permissions, customer journey, money flows, risk profile and control environment fit together.
A strong application therefore works across several connected layers:
- Business model: a precise account of customers, products, jurisdictions, distribution, revenue, transaction flows and dependencies.
- Governance: decision rights, reporting lines, challenge, committee structure and evidence that senior management has sufficient time and competence.
- Financial crime: a risk-based framework covering customer risk, due diligence, sanctions, transaction monitoring, escalation and suspicious activity reporting.
- Safeguarding: where relevant funds arise, how they move, how they are segregated and reconciled, and who owns exceptions.
- Operational and security controls: resilient processes, incident management, access control, data protection, change management and oversight of critical providers.
- Financial resources: capital and forecasts that reflect the same volumes, staffing, costs and launch assumptions used elsewhere in the application.
- Management capability: people who can explain the model and show how they will oversee it in practice.
Where applications lose coherence
Generic policies
A policy copied from a different model may be polished but unhelpful. Warning signs include roles that do not exist, controls the proposed systems cannot perform, review frequencies unsupported by staffing, and risk categories that do not match the target market. Each policy should connect to an actual workflow, owner, record and escalation route.
Financials and volumes that tell a different story
Revenue assumptions, customer numbers, payment volumes, average transaction values and geographic exposure should reconcile across the business plan, programme of operations, safeguarding analysis, financial crime assessment and forecasts. A change in one place should trigger a consistency check everywhere else.
Unclear outsourcing and partner dependencies
Banking, payment processing, screening, cloud, identity and ledger providers may be central to delivery, but responsibility remains a management question. The application should identify what each provider does, how the firm selected it, what information the firm receives, how performance is monitored and what happens if service deteriorates or ends.
Thin governance
An organisation chart is not a governance framework. The submission should make clear who decides, who challenges, what information reaches the board, how conflicts are managed and how the firm maintains effective oversight as it grows.
Evidence that starts after authorisation
Some controls can only become fully operational when the business launches, but implementation should not be deferred wholesale. Draft management information, training plans, control test scripts, provider due diligence, sample reconciliations and documented walkthroughs can all demonstrate that the model has moved beyond intent.
FCA Connect and realistic timing
Applications are submitted through FCA Connect, with forms and supporting material determined by the status and services sought. The FCA states that a complete payments or e-money application is usually assessed within three months, while the statutory period for an incomplete application can run to 12 months. These are assessment periods, not promises of approval or launch dates.
The timetable should also allow for preparation, internal approval, possible clarification questions, recruitment, provider contracting and implementation. Building a commercial launch plan around the shortest regulatory period creates avoidable pressure and can encourage premature commitments to customers or partners.
A practical pre-submission readiness checklist
- Confirm the activities, permissions and status sought match the end-to-end customer proposition.
- Walk through customer, data and money flows and resolve every unclear hand-off.
- Reconcile volumes, revenue, costs, capital, staffing and launch assumptions across every document.
- Map each material risk to a control, accountable owner, record, monitoring method and escalation route.
- Review every policy against the actual systems, providers and roles available at launch.
- Evidence due diligence and oversight arrangements for critical outsourced and partner services.
- Test safeguarding calculations and reconciliations with realistic sample data where applicable.
- Prepare governance calendars, board and committee terms, management information and decision thresholds.
- Challenge whether senior managers can explain the model without relying on advisers or policy text.
- Run a final cross-document review before submitting through FCA Connect.
Readiness does not remove regulatory judgement, and no adviser can guarantee authorisation. It does reduce avoidable inconsistency and helps management present a business it is genuinely prepared to run.
Sources and further reading
Important: This article is general information only and does not constitute legal advice. Regulatory requirements depend on a firm’s specific model and circumstances.
Start a conversation