Regulated Products
You rarely need your own licence to launch a payments or e-money product. Here are the routes that let you go live in weeks instead of a year, what you still own, and the safeguarding change landing in May 2026.
A UK Authorised Electronic Money Institution is authorised by the FCA under the Electronic Money Regulations 2011. It needs around £350,000 of initial capital, a safeguarding arrangement for customer funds, senior managers under the SMCR regime, and, from May 2026, a bank-style client-money framework. The application typically takes six to twelve months. For a product that hasn't proven demand yet, that's a lot of time and capital spent before you know if anyone wants it.
So most fintechs launch on someone else's authorisation first.
An EMD agent (for e-money) or a payments agent (for payment services) distributes and redeems the regulated product on behalf of an authorised principal (an EMI or PI). You're listed on the FCA's public register under that principal, you are not individually authorised, and the capital, safeguarding, SMCR, and CASS obligations sit with the principal, not you. The FCA processes an agent notification in roughly 30 to 60 days.
This is how a branded card, wallet, or payout product can go live quickly. You build the experience; the principal provides the regulated rails and supervises your conduct.
A banking-as-a-service provider packages compliant accounts, cards, and payments behind an API. You integrate, they hold the authorisation and often the agent relationship too. It's the fastest route to a working product. The trade-offs are a monthly platform cost, less control over the underlying features and economics, and concentration risk: if the provider has an outage or a regulatory problem, so do you. Choose one with a track record and a clear plan for the 2026 safeguarding rules.
“Someone else holds the licence” does not mean “someone else runs your company.” You are still responsible for:
The principal supervises you, audits you, and can terminate the relationship. Treat them as a regulator you have a contract with, because functionally that's what they are.
The FCA's Policy Statement PS25/12, published August 2025 and in force from 7 May 2026, replaces the old light-touch safeguarding regime with a bank-style client-money framework under a new CASS 15 chapter. It brings in stricter record-keeping, daily reconciliation, external safeguarding audits, and more reporting.
If you're an agent, this is your principal's obligation, not yours directly, but it affects you: it raises their costs, their audit burden, and their scrutiny of agents. When you pick a principal or a BaaS provider in 2026, ask directly how ready they are for CASS 15. A principal that's scrambling in April 2026 is a risk to your launch.
| Model | Capital | Time to launch | Control | Ongoing burden |
|---|---|---|---|---|
| Your own Authorised EMI | ~£350,000 | 6 to 12 months | Full | High: safeguarding, SMCR, CASS 15, audits |
| Agent of an EMI or PI | None of your own | ~30 to 60 days | High on product, limited on rails | Medium: KYC/AML ops, principal oversight |
| Banking-as-a-service | None | Weeks | Lower: provider sets the rails | Low to medium: platform fees, provider risk |
The usual path: validate with the smallest regulated surface you can, launch as an agent or on BaaS, and only pursue your own authorisation once volume and economics clearly justify carrying the capital and the compliance function yourself.
Even on someone else's licence, the operational anti-money-laundering and know-your-customer work is yours to run, inside the principal's framework. In practice that means:
Budget for a compliance hire or a fractional Money Laundering Reporting Officer earlier than feels comfortable. The principal will expect one before they let you scale.
Your principal is effectively part of your infrastructure and part of your risk. Before you commit, ask:
The one place not to save money is working out exactly which regulated activities your product performs and which permissions cover them. Get a payments-specialist compliance consultant or regulatory lawyer involved before you design the flows, not after. Misjudging the perimeter (holding funds you're not permitted to hold, or describing the product in a way that implies permissions you don't have) is the kind of mistake that ends companies, not sprints.
If you're scoping a payments or e-money product, tell us what you're building and we'll help you shape an MVP around the lightest regulatory route that fits. It's how we approach fintech work.
Bobby
Bobby watches what a build actually costs against what it was quoted, and where the two tend to drift apart.
Turn an idea into a product, brand, or campaign, with one team from strategy to launch.
start a projectEngineering
The best tech stack for a first build is a boring one: proven, well-documented, and easy to hire for. Here's what “boring” actually means in 2026, the traps that sink second years, and a sensible default to start from.
11 Sep 2026 · 10 min read
Product Strategy
Every founder asks it, and “it depends” is a useless answer. Here's the real 2026 range for a UK build, the five things that actually set your number, how offshore and native change it, and the three places budgets quietly leak.
2 Sep 2026 · 11 min read
Regulated Products
If an NHS organisation is going to use your product, you have to clear DTAC before the pilot, not just before procurement. Here's what that involves in 2026, the roles you'll need, and how to sequence it so it doesn't derail the build.
27 Aug 2026 · 11 min read