Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚡ TL;DR
The FCA, PRA and PSR regulate different dimensions of UK finance. The FCA focuses on conduct, consumer outcomes, market integrity and competition; the PRA, inside the Bank of England, focuses on the safety and soundness of banks, insurers and major investment firms; and the PSR focuses on access, competition and user outcomes in payment systems. Many firms deal with more than one authority, and the government is moving PSR functions into the FCA without removing the need for specialist payments oversight.

“FCA regulated” is not a complete description of a UK financial business. It tells you that the Financial Conduct Authority has a relationship with the firm, but not necessarily which legal entity, which activities, whether the company may accept deposits or how customer money would be treated in failure. A bank, e-money institution, investment platform and software vendor can all appear in the same fintech market while sitting in materially different regulatory positions.

The regulatory architecture is easier to understand when every authority is linked to a specific risk. This guide separates conduct from solvency, system-wide stability from payment-system competition, and compensation from day-to-day supervision. It then shows how the pieces apply to firms covered by the United Kingdom Finance & Fintech Hub.

Editorial scope: This is business education, not personal financial, legal or investment advice. Rules, permissions and protection depend on the specific regulated entity and product.
Key Takeaways

What is the FCA’s core job?
To make financial markets work well by protecting consumers, supporting market integrity and promoting effective competition.

What is the PRA’s core job?
To protect the safety and soundness of deposit takers, insurers and certain major investment firms through prudential rules and supervision.

Why does the PSR exist separately?
Payment systems have network effects and access bottlenecks that require specialist economic regulation beyond supervision of individual firms.

Match the Regulator to the RiskHM TreasuryLaw & policyPRASolvencyFCAConductPSRPayment systemsThe same product can raise policy, prudential, conduct and infrastructure questions at the same time.
The same product can raise policy, prudential, conduct and infrastructure questions at the same time.

Why did the UK create a split regulatory model?

The post-crisis framework reflects a lesson from 2008: supervising individual firms, protecting consumers and monitoring the financial system are related but not identical tasks. A bank might comply with product-disclosure rules while carrying too little capital, or appear safe alone while contributing to a system-wide credit boom. Dividing mandates makes each question explicit and creates institutional checks when objectives pull in different directions.

The present structure took shape in 2013. The Bank of England gained a wider financial-stability role and the PRA became the prudential supervisor for systemically important firms. The FCA replaced the Financial Services Authority for conduct and markets. The PSR became operational in 2015 to address the special economics of payment networks. The framework evolves, but its organising principle remains risk-based specialisation.

What does the Financial Conduct Authority regulate?

The FCA regulates the conduct of around 35,500 businesses and oversees how financial markets operate. Its perimeter covers activities ranging from payments and consumer credit to investments, insurance distribution and wholesale markets. It authorises firms, writes and enforces rules, supervises ongoing behaviour, maintains the Financial Services Register and can restrict, fine or remove permissions when standards are not met.

Its objectives are practical rather than cosmetic: consumers should receive appropriate products and communications, market abuse should be deterred, competition should produce better outcomes and senior managers should be accountable. The FCA also acts as the prudential regulator for many firms that are not supervised by the PRA, including numerous payment, e-money and investment businesses. Prudential risk does not disappear outside banking; the supervising authority changes.

How does the Consumer Duty change the FCA relationship?

The Consumer Duty shifts attention from whether a firm followed a narrow process to whether its products, support, communications and pricing deliver good outcomes for retail customers. Boards must be able to evidence those outcomes with data. A technically compliant journey can still fail the test if customers cannot understand it, receive poor support at a vulnerable moment or pay fees that are not reasonably related to the benefit delivered.

For digital firms, this makes product design a regulatory control. Defaults, notification language, cancellation paths, complaint handling and how an app distinguishes savings from investments all matter. Growth teams cannot treat compliance as a final legal review after the journey is built. Customer-outcome evidence belongs in product metrics, experimentation governance and board reporting from the start.

What does the Prudential Regulation Authority supervise?

The PRA is part of the Bank of England and supervises roughly 1,300 banks, building societies, credit unions, insurers and major investment firms. Its central question is whether a firm is run safely and can continue delivering critical functions through stress. It sets expectations for capital, liquidity, governance, risk management, recovery planning, operational resilience and—where relevant—protection of insurance policyholders.

PRA supervision is judgement-based and forward-looking. A ratio that meets today’s minimum is not enough if rapid growth, concentrated funding, weak controls or an unrealistic plan makes tomorrow unsafe. Supervisors examine business models, management quality and the way risks interact. This is why obtaining a banking licence is not the end of authorisation work: expectations rise as a new bank becomes larger and more complex.

Why are banks usually dual-regulated?

A UK bank is normally authorised by the PRA with the FCA’s consent and then supervised by both. The PRA assesses the institution’s financial and operational resilience; the FCA assesses its conduct, financial crime framework and treatment of customers and markets. Senior leaders must manage both because an unsafe bank harms customers even when communications are clear, and a solvent bank can still harm customers through unfair products or poor controls.

The split also affects regulatory reporting, approvals and incident notification. A material outage, control weakness or strategic change may concern both authorities for different reasons. Firms need a single internal issue map that identifies prudential, conduct, data and operational consequences rather than separate teams sending fragmented accounts. The regulator sees the legal entity; customers experience the whole product.

💡 Pro Tip: For dual-regulated firms, maintain one issue taxonomy that tags prudential, conduct, operational, data and financial-crime impacts. Separate regulator workstreams should still reconcile to one version of the facts.

What does the Payment Systems Regulator do?

The PSR is the specialist economic regulator for UK payment systems. Its remit includes whether access is fair, competition works, innovation is possible and users receive protection and value. It oversees designated systems and their participants, including the networks behind account transfers, cards and cash access. These markets can concentrate because a payment network becomes more useful as more institutions join.

Supervising individual payment firms cannot solve every network problem. A safe new entrant may still be unable to compete if direct access is too costly, scheme rules favour incumbents or technical standards create avoidable barriers. The PSR can address those system-level conditions. The Bank of England separately supervises payment systems recognised as systemically important and operates CHAPS, so economic and stability oversight coexist.

Is the PSR being abolished in 2026?

The government has decided to consolidate PSR functions within the FCA to reduce duplication and create more coherent payments and digital-finance oversight. In April 2026 it published its response on the streamlined approach. Organisational integration had already begun through shared leadership and an FCA payments and digital-finance department. Legislation and transition work are still required.

It is therefore inaccurate to treat specialist payments regulation as finished. The policy is to move functions, not to pretend payment networks no longer create access, competition, fraud and infrastructure risks. During transition firms should follow current PSR requirements and monitor how responsibilities, enforcement and rulebooks migrate. A legal announcement and an operationally completed regulatory transfer are different events.

Authority Primary lens Typical firm question
FCA Conduct, markets, consumer outcomes, competition Does the journey and business model produce fair outcomes?
PRA Capital, liquidity, governance and safety Can the regulated institution remain safe through stress?
PSR Access and competition in payment systems Do system rules and economics support fair access and innovation?
Bank of England Monetary, systemic and infrastructure resilience Could this risk disrupt critical markets or settlement?
HM Treasury Legislation and government policy What statutory framework and remit should apply?
ℹ️ Context: The planned transfer of PSR functions into the FCA is a transition, not an instant deletion of current obligations. Follow effective rules and formal commencement dates.

Where do HM Treasury and the Bank of England fit?

HM Treasury is not the day-to-day supervisor of a fintech app. It sets the government’s financial-services policy, sponsors legislation, defines regulator remits and makes decisions about the overall architecture. Initiatives such as the National Payments Vision, future open-banking framework and cryptoasset regime require coordination between elected government and operationally independent regulators.

The Bank of England performs several different roles: central bank, operator of RTGS and CHAPS, system-wide stability authority, supervisor of financial-market infrastructure and home of the PRA. Its Financial Policy Committee can act against risks across the system rather than one firm. Keeping these roles distinct in analysis matters, even when they sit within one institution.

What are the FSCS and Financial Ombudsman Service?

The FSCS is a compensation scheme for eligible claims when authorised firms fail; it is not the prudential supervisor and does not certify that a product is good. From December 2025 eligible deposits at UK authorised deposit takers are protected up to £120,000 per person, per authorised firm. Other product categories have their own coverage rules and limits.

The Financial Ombudsman Service resolves eligible disputes between customers and financial businesses after the firm’s complaint process. It is separate from FCA enforcement: an ombudsman decision addresses individual redress, while the FCA looks at broader rule compliance and market harm. A strong complaints function treats ombudsman outcomes as risk intelligence, not merely isolated cases to be administered.

How does authorisation differ from registration?

Authorisation normally involves assessment against threshold conditions, governance, resources, business model and relevant permission-specific requirements. Registration can be a narrower status under a particular regime. Neither word should be used as a generic badge of government approval. The Financial Services Register must be checked for the exact legal entity, reference number, activities, requirements and any restrictions.

A group may contain several entities: a bank, e-money issuer, investment firm and technology company under one brand. Permissions can also vary by country. A customer seeing the same logo in London and another market may contract with different firms and receive different protections. Compliance architecture and customer communication must keep those boundaries visible.

How does the regulatory sandbox support innovation?

The FCA’s sandbox allows eligible firms to test innovative propositions with real customers in a controlled environment, sometimes using restricted permissions or tailored safeguards. It helps the regulator learn about emerging models and helps firms identify regulatory issues before scaling. The sandbox is an evidence-generating process, not an exemption from consumer protection or a commercial endorsement.

Its deeper contribution is cultural. By creating an organised route for dialogue, the regulator can distinguish unfamiliar technology from unacceptable risk and firms can design controls around real behaviour. The UK has extended this approach through innovation services, a scale-up unit pilot and targeted cohorts. The benefit is strongest when testing produces durable governance rather than a one-off launch story.

What do recent challenger-bank fines teach?

FCA enforcement against fast-growing challenger banks shows a recurring failure pattern: customer growth outpaces onboarding, transaction monitoring, sanctions screening and governance. Monzo was fined in 2025 for historic financial-crime control failures and breaches of a restriction; Starling was fined in 2024 for financial-crime and sanctions screening failings. Both cases covered earlier periods and subsequent remediation, but the strategic lesson is current.

Control capacity must scale before or with volume. A bank cannot bolt financial-crime operations onto a product after acquisition succeeds, because every new account expands the population that must be risk-rated, screened and monitored. Automated onboarding is not automatically a control; it is a faster process whose models, data, exceptions and human escalation need testing. Growth without control evidence creates a regulatory liability.

⚠️ Risk: Acquisition velocity is not a defence when controls lag. Regulators expect financial-crime, complaints and operational capacity to scale with the customer base.

What is changing for firms in 2026 and 2027?

Payments oversight is being reorganised, open banking is moving toward a long-term framework and future standards body, and the FCA has published an open-finance roadmap to 2030. A new cryptoasset regime is also moving toward implementation in 2027. These programmes expand the regulatory perimeter and shift governance from temporary implementation arrangements toward durable statutory structures.

Operational resilience is tightening as well. In March 2026 the FCA published incident-reporting and third-party notification requirements that take effect in March 2027. Firms need service maps, impact tolerances, supplier inventories and decision-quality incident data. The direction is clear: regulators expect digital finance to evidence resilience across outsourced and cloud-dependent operations, not merely promise high uptime.

How should a fintech build its regulatory responsibility map?

Begin with activities and legal entities, not product names. For every customer journey, identify who contracts, who holds money, who executes the payment, who provides credit, who makes an investment decision and who handles complaints. Map each activity to permission, applicable rules, safeguarding or capital treatment, reporting and accountable senior manager. Add sponsor banks and material outsourcers rather than stopping at the group boundary.

Then map outcomes and failure. Ask which authority is concerned if the service misleads a customer, the institution becomes insolvent, a rail blocks competition, an outage disrupts the market or customer funds cannot be returned. This converts a list of regulator names into an operating model. The related UK financial-system guide provides the wider institutional map.

Continue the country series: Explore the United Kingdom Finance & Fintech Hub, or compare the underlying concepts in the Fintech & Transfers Hub.

Frequently Asked Questions

What is the main difference between the FCA and PRA?

The FCA focuses primarily on conduct, markets and consumer outcomes. The PRA focuses on the safety and soundness of banks, insurers and certain major firms. Many banks are supervised by both.

Does FCA authorisation mean customer money is FSCS protected?

No. Protection depends on the product, activity and legal entity. A bank deposit can qualify for deposit protection; safeguarded e-money follows a different failure regime.

Is the PSR still operating in July 2026?

Yes. Government policy is to transfer PSR functions into the FCA, but the transition requires legal and operational implementation. Current requirements continue until formally changed.

Who regulates UK open banking?

The framework involves the FCA, PSR, CMA legacy order, government and Open Banking Limited. The FCA is taking a central role in the long-term open-banking and open-finance framework.

Is the FCA sandbox a regulatory approval?

No. It is a controlled testing environment. Participation does not endorse a company, remove applicable rules or guarantee later authorisation.

Primary Sources and Further Reading

This guide prioritises regulators, payment-system operators and company filings. Figures are the latest available at the July 2026 review date.

Last Updated: July 2026 · Reviewed by the Kurums Finance editorial team.

Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading