How UK Startups Can Stay Compliant with PSP and EMI Regulations in 2026

UK fintech founders working on payment platforms or electronic money products face a stricter environment this year. The FCA has raised the bar on how firms handle customer money, file reports, and guard against financial crime. Authorised payment institutions and electronic money institutions need to get the details right. Slip on any of it, and you invite questions from supervisors or worse. Get it embedded properly, and you build something that lasts. The rules sit on the Payment Services Regulations 2017 and the Electronic Money Regulations 2011. What changed everything was PS25/12. Those supplementary safeguarding rules kicked in on 7 May 2026. They came after too many cases where customer funds went missing when firms ran into trouble.

Regdata Submissions: The Reporting Backbone

RegData is where the FCA collects its numbers. PSPs and EMIs file regular returns covering payment volumes, complaints, and now the dedicated monthly safeguarding data under SUP 16.14A.

This year, those monthly returns matter more than ever. You list the relevant funds held, show your reconciliations, and flag any gaps. Miss the deadline or send inconsistent figures, and supervisors notice fast. Many startups start with spreadsheets. That works until transaction volumes climb. At that point, automation becomes necessary. Someone at the board level should read the final numbers before they go in. The FCA watches whether senior people actually understand what their firm reports.

Safeguarding Requirements: Protecting Customer Funds

The biggest practical shift arrived with the new regime. From 7 May, firms must run daily reconciliations, internal checks and external ones with the bank, on every business day. Any shortfall needs fixing straight away.

If you hold more than £100,000 in relevant funds, an independent audit lands on your desk once a year. You also keep a resolution pack ready. That document spells out exactly how customer money would move back if the firm ever had to wind down. The FCA can ask for it with little notice.

In practice, this means opening dedicated accounts, moving customer money immediately, and checking every transfer. Third-party banks or custodians need proper vetting. Documentation must cover every step. Plenty of founders discover the workload only after launch. Dedicated software helps, and clear ownership inside the team prevents things from slipping. The regulator looks for evidence that you catch problems before they grow.

MLR Obligations: A Risk-Based Approach to Financial Crime

The Money Laundering Regulations 2017 still govern this side. Payment and e-money firms sit in a higher-risk category according to the national assessment. Everything starts with a proper firm-wide risk assessment that maps out where problems could arise, specific products, customer profiles, channels, and countries.

From there, you apply customer due diligence, step up to enhanced checks where needed, watch transactions in real time, and file SARs quickly when something looks off. Cross-border flows or anything touching crypto draw extra attention. Staff need regular training. Decisions need records. The FCA has withdrawn authorisations when AML systems looked weak, so boards treat this as a standing item.

Practical Compliance Tips for Payment and Fintech Startups

What separates firms that manage this from those that struggle is how they connect the pieces instead of bolting them on later.

Put the controls into the product from day one. Changing architecture later costs real money and time.

Pick tools that handle reconciliations, monitoring, and RegData output. Test them thoroughly; blind faith in any system creates its own risks.

Give your MLRO real room to operate. Make compliance meetings regular and make sure the right people show up.

Keep the resolution pack up to date. Run practice reconciliations so the real thing never surprises you. Read the latest FCA Approach Document; it now reflects these 2026 rules.

Bring in outside help for audits or policy reviews when your team lacks the specialist background. It buys clarity and lets founders focus on building.

Track FCA announcements and sector updates. Deadlines shift and new expectations appear. The May changes were only one part of a wider picture that includes operational resilience and consumer outcomes.

Rules like these do not stand still. The FCA judges firms on whether they grasp their own risks and deal with them in practice. Done well, that discipline becomes part of what makes a startup credible to banks, investors, and users.

Navigating PSP and EMI rules takes a mix of detailed knowledge and clear thinking about the business. At EveryFront, we work with UK fintech and payment companies on accountancy, compliance setups, and the actual filing work. If you face an upcoming RegData deadline, need help tightening safeguarding, or want a fresh look at your MLR framework, we can help you move forward without losing speed.

Contact us today to arrange a free compliance review and ensure your setup aligns with the 2026 requirements.

footer_logo
Email
info@everyfront.com
apcc_logo