EU Payment Institution License: Requirements, Process, Capital Rules (2026)
An Payment Institution license authorises an entity to provide regulated payment services within the EU. Its purpose is to ensure that market participants operate with robust governance, sound financial and operational controls, and effective safeguards against money laundering, fraud, and other risks to clients and the financial system.
The requirements are detailed, the process long, and capital rules apply, here is what corporates and fintechs need to know about the EU Payment Institution license:
Permitted services under EU regulations
Under EU Payment Services regulations, a payment service is defined as:
- Services enabling cash to be placed on a payment account as well as all the operations required for operating a payment account.
- Services enabling cash withdrawals from a payment account as well as all the operations required for operating a payment account.
- Execution of payment transactions, including transfers of funds on a payment account with the user’s payment service provider or with another payment service provider:
- execution of direct debits, including one-off direct debits;
- execution of payment transactions through a payment card or a similar device;
- execution of credit transfers, including standing orders.
- Execution of payment transactions where the funds are covered by a credit line for a payment service user:
- execution of direct debits, including one-off direct debits;
- execution of payment transactions through a payment card or a similar device;
- execution of credit transfers, including standing orders.
- Issuing payment instruments and/or acquiring payment transactions.
- Money remittance.
- Payment initiation services (see Payment Information Service Provider).
- Account information services (see Account Information Service Provider).
Excluded activities
Payment Institutions are not permitted to hold client funds for extended periods, whether in cash or electronic money form.
“A Payment Institution license is a regulatory authorisation allowing firms to provide payment services such as money remittance, card issuing, acquiring, and payment initiation.”
Commercial uses for an authorised Payment Institution
An authorised Payment Institution (also Payment Services Provider or PSP) can offer a wide range of payment services:
- Money transfer: remitting money from one country to another.
- Foreign exchange: converting currencies and hedging forward positions.
- Card schemes: providing debit and credit cards.
- Payment processing: providing online and mobile payment solutions.
- Payment acquiring: accepting payments from merchants, marketplaces and payment gateways.
- Payment gateway operations: specialist technology solution to accept and process payments.
- Open Banking: providing data and payment initiation on 3rd party bank accounts.
Buy Now Pay Later is changing, see FAQ.
Payment Institution licensing process
Licensing varies by jurisdiction, but the typically occurs in three phases:
| 1. Exploration | 2. Assessment | 3. Decision |
| The applicant will participate in a sandbox, have an initial meeting, and then submit application. | The competent authority assesses the submission in line with guidance and SLA. | The applicant receives an authorisation or decline. Marginal cases may be given the opportunity to make adjustments. |
How to apply for Payment Institution licensing
To secure a Payment Institution license, applicants must submit a comprehensive application to the competent authority in their home jurisdiction.
Applicants must demonstrate operational readiness at the time of application, including business plans, financial models, technology architecture, risk frameworks, and governance structures. Start-ups face extra scrutiny as they lack financial and client conduct history.
Key areas the competent authority will assess include:
- Entity: what is the legal status of the entity, group structure, financial history, compliance history, licensing history, etc.
- Local Substance: does the business have a rationale for applying in that market, and a suitable local presence, including key personnel in-country.
- Business Model: a clear description of how the business will make money and operate. this must define services, clients, locations, channels to market, technology, service structure, compliance structure, etc. Volumes are expected.
- Financial Viability: a financial model showing profit and loss, balance sheet, and cash flow for a minimum of 3yrs. The applicant must demonstrate an ability to reach break-even, and fund losses until then. Base, worst and best cases are advised.
- Capital: a Payment Institution must meet regulatory capital and own funds requirements, and demonstrate adequate (treasury) skills to measure and manage capital. Stress testing of capital buffers and ability to raise are advised. See FAQ.
- Risk Assessment: applicants must define the inherent risks in the business and those that arise in operation, for example money laundering or technological. A risk management framework is required registering risks, defining risk appetite, and how risk will be monitored, managed and mitigated. Risks must be specific to the business model and jurisdiction rather than generic.
- Outsourcing: outsourcing is usually permitted to group or external parties, but applicants must show that have appropriate management, especially in key functions like compliance and technology.
- Safeguarding: detailed forecast of client fund volumes, a framework for how these will be managed, and by which reputable partner. Formal policies and procedures are expected.
- Business Continuity: applicants must demonstrate they can maintain service, and have an orderly plan to wind down in the event of failure.
- Management: an organisation chart is required detailing functions, roles and reporting lines. Staffing plans are required, especially if the business is scaling. Profiles for senior management are required, with some regulators requiring professional qualifications for ‘Pre-Approval Controlled Functions’ (PCFs) and/or ‘fitness and probity’ checks.
- Governance: applicants must demonstrate governance commensurate with the nature, scale and complexity of the business. Factors considered include the size and expertise of board members; the balance of power between management, executive and non-executive decision makers; with some regulators requiring professional qualifications for ‘Pre-Approval Controlled Functions’ (PCFs) and/or ‘fitness and probity’ checks. Succession planning is considered in some cases.
- Ownership: all shareholders up to and including the ultimate beneficial owner (UBO) are required, including their % ownership and control. Owners appears on sanctions or PEP lists create additional complexity.
- Timeline: applicants should define when they will start operations and make their full submission.
Adjacent regulations such as DORA are applicable, overlooking these will lead to rejection.
Passporting payment services in the EU
Once approved in its home jurisdiction, an authorised Payment Institution can apply to offer services in other EU countries. This is achieved by establishing branch offices, engaging agents, or the provision of cross‑border services without physical presence
An authorised Payment Institution must apply to their home competent authority who will assess the application, on approval this will be transmitted to the equivalent authority in other countries.
Compliance obligations for authorised Payment Institution
Payment Institutions are subject to continuous supervision to ensure compliance with their stated plans, legislation and regulatory obligations.
Key areas the competent authority will assess include:
- Risk Management: PIs must implement comprehensive compliance programs, including AML (Anti-Money Laundering) and KYC (Know Your Customer) measures. Risk management systems must address operational, credit, and other risks in line with regulatory requirements.
- Governance: is there strong management, appropriate segregation of duty, and an appropriate framework of policies and procedures. Roles should be clearly defined and compliance and internal audit operate independently, while having board access.
- Technology: do the systems and their providers meet requirements about information security, PSD2 and DORA.
- Safeguarding: are client funds adequately safeguarded, can Payment Institution easily quantify these and separate them from own funds. Is accoutnng correct.
- Consumer Protection: does the Payment Institution have defined and effective approaches to ensure the interests of clients, meet service requests, and resolve disputes.
- People: does the business ensure senior managersand directorshave access to training and CPD, is there rotation, do new joiners have the qualifications, experience, and knowledge to perform their function. Is their past behaviour clear.
- Reporting: Payment Institution’s have extensive reporting obligations including volumes, suspicious payment activity, fraud, operational incidents and financial statements. Frequency may vary but is trending to daily via automated channels.
- Annual Accounts: annual audited accounts are typically submitted within 6mths of the end of the relevant financial year end.
- External Audit: auditors must audit the financial statements. FinTech consultants are increasingly required to undertake periodic independent GRC audits.
FAQs
PIs are prohibited from accepting deposits or paying interest on client funds. They may only hold funds directly related to payment transactions, typically for short periods.
It depends on the nature of the transaction, for example Merchant Card Advances are different to Credit Cards are permitted,
Deferred payment models such as Buy Now Pay Later (BNPL) are moved into credit regulation, such as the Consumer Credit Directive (CCD2).
It depends on the business model and regulator, but 9-12mths is not unusual. Acquisition of an existing PI may be faster but requires change‑of‑control approval.
This depends on the nature of the payment services being provided:
- Small Payment Institution (SPI): EUR 0 however SPIs are restricted to average monthly transaction volumes of under EUR 3m.
- Authorised Payment Institution (API), lower: EUR 20k for PIs offering money remittance services.
- Authorised Payment Institution (API), med: EUR 50k for PIs offering execution of payment transactions.
- Authorised Payment Institution (API), upper: EUR 125k for full-service PIs (payment accounts, issuing cards, direct debits, acquiring).
A Payment Institution’s own funds must not fall below initial capital or the calculated amount using one of three methods:
- Overhead Based: capital must equal at least 10% of prior-year fixed overheads.
- Volume Based: scales with total payment volume (most common).
- Income Based: scales based on the net earnings.
Payment Institution license: Summary
A Payment Institution license provides access to a rapidly expanding and profitable market. While barriers to entry remain manageable, regulatory expectations are increasing.
Selecting the right license type jurisdiction is critical; Sure FinTech supports clients end‑to‑end — strategy, licensing, technology sourcing, and ongoing compliance.
Whether you are looking to secure a Payments Institution license, or an authorised Payment Institution looking to improve compliance, contact us for an exploratory call.


