A straightforward compliance guide for PSP founders navigating FCA obligations
A lot of founders treat FCA registration as the end of the compliance journey. In reality, it is more like receiving a driver's licence — you are now permitted to be on the road, but you are expected to follow every rule on every day you operate.
“Compliance becomes the thing you keep telling yourself you will properly sort out next week — until a Regdata deadline lands in your inbox.”
For payment service providers and electronic money institutions, ongoing obligations include keeping proper records of all transactions, safeguarding customer funds, and actively working to prevent financial crime — not merely responding to it.
Regdata is the FCA's primary reporting system — your regular check-in with the regulator. You will be required to submit transaction volumes, revenue figures, customer activity data, and various risk- related metrics on a fixed schedule.
Missing deadlines is not a minor inconvenience. Warning letters, financial penalties, and in serious cases, questions about your continued authorisation are all live possibilities. Most founders don't struggle because the data is hard to pull — they struggle because no one ever clearly explained what needs to be submitted and when.
You carry the full weight of compliance responsibility. More control, more pressure — every reporting cycle, audit, and obligation lands squarely with your team.
You operate under another authorised firm's licence. They absorb significant compliance work in exchange for some independence. Faster to market, less administrative overhead early on.
An MLR (Money Laundering Regulations) audit is a structured review of your compliance programme — not a dramatic investigation. Auditors want to see consistency and genuine awareness of risk, not perfection
KYC processes must match the real volume and risk profile of your customer base — not just a policy document from launch day.
Systems must be calibrated to the actual activity level of the business, and records must show they are being used.
Staff must be trained on financial crime risks, and there must be a clear, documented process for identifying and filing suspicious activity reports.
WHERE FOUNDERS TYPICALLY FAIL
Auditors find problems when written policies are not being followed in practice, when systems don't match the real size of the business, or when there is an obvious gap between what documentation says and what is actually happening day to day.
Most founders don't fail at compliance because they are careless. They fail because they are already stretched thin — building the product, closing deals, fixing bugs, hiring. Compliance becomes the item that perpetually moves to next week's list.
“Once you properly understand how the regulatory system works, it stops feeling like constant chaos and starts feeling like a clear, manageable structure.”
The FCA wants real evidence that your business is stable, transparent, and not putting customers or the financial system at risk. That requires a compliance setup that grows with your business — not one frozen at the point of initial authorisation.