Payments View – Summer 2026

This edition covers HMT’s consultation on modernising payment services regulation and other updates

12 August 2026

Publication

Loading...

Listen to our publication

0:00 / 0:00

Payments View – Summer 2026

Welcome back to Payments View. Our main update this month is HMT’s consultation on the proposed modernisation of the UK payments regime – while European regulators have been having all of the fun so far with PSD3, it’s now the UK’s turn with the proposed changes taking quite a different approach as we explore below.

This edition of Payments View also covers updates on

  • FCA cryptoasset policy statements and joint BoE/FCA approach on systemic stablecoins;
  • Financial Services AI adoption plan and Mansion House 2026;
  • PSR APP scam roadmap and independent evaluation;
  • BaFin: AML expectations for virtual IBANs;
  • HMT designation of first critical third parties;
  • FCA multi-firm review of basic bank account access; and
  • Mortgage Rule Review.

As always, don't hesitate to reach out to us if you would like to discuss any of the developments in this edition.

HMT consultation on Modernising Payment Services Regulation

If a slightly open-ended consultation on the need to modernise the UK’s payments regime and move large amounts into FCA-facing rules inspires some 2023-inspired déjà vu, then you’re not alone. However, the latest consultation on the topic from HMT starts afresh and has plenty of interesting ideas it asks respondents to grapple with.

The January 2023 "Payment Services Regulations: Review and Call for Evidence" was a statutory review of the PSR 2017 and identified the possibility of delegating firm-facing requirements to the FCA as one of a few options. This approach has now been taken up as the core of the new regime, with proposals to delegate most firm-facing PSR and EMR requirements to the FCA through the Rulebook, while retaining the perimeter and core definitions in secondary legislation.

Many of the wider issues that the 2023 consultation sought to deal with – from matters like safeguarding and the termination of framework contracts, to Strong Customer Authentication – have also now been addressed. The current consultation is therefore able to focus on (some may say) the ‘cooler’ issues for payments firms – such as Open Banking, tokenised payments, and AI. HMT has also opened up the consultation to seek views on whether any existing legislative provisions need updating, so if readers have a grudge against a particular regulation (and we would, quite frankly be shocked if you don’t), now is the chance. There’s nothing stopping us having a go at PERG as well while we’re at it!

Under the proposals, the perimeter and key definitions would remain in legislation, but the firm-facing requirements currently in the Payment Services Regulations 2017 and the Electronic Money Regulations 2011 – authorisation, conduct of business, information requirements – would be removed and brought into FCA rules. The FCA would then consult on carrying over existing requirements to the new regime and on introducing changes or new requirements where needed. The proposals also include changes to the actual regulated payment services that firms are authorised for – finally splitting out issuing and acquiring (in line with the approach of most European regulators over the last few years) and combining servicing that enables ‘cash’ (hopefully with a view on what this actually means) placement and withdrawal with execution with or without a credit line.

Alongside this, HMT identifies four areas of substantive reform:

  • Tokenised payments – where the government focuses on the potential benefits including programmable finance; increased efficiencies; reduced costs; and improved settlement processes, particularly in wholesale financial services. In terms of approach, the government proposes to regulate tokenised versions of financial instruments in the same way as it does the traditional versions of the asset, on the basis of a ‘same risk, same regulatory outcome’ approach. Here, the proposal seeks views about whether the current regulatory framework presents any barriers for stablecoins / tokenised deposits in retail payments, such as whether UK stablecoin issuers (i.e. UK- issued, FCA- regulated and potentially some “recognised” overseas that would be treated as “money- like”) should be allowed to offer payment services without separate permissions and whether adjustments are needed for smart contracts and programmable payments.
  • Agentic payments – this is a topic that the government continues to stress as a priority and so is unsurprisingly one of the core points raised in the proposals. Detail, however, remains slightly lacking outside of the proposal looking to lay the foundations for the development of agentic payments, specifically calling out authentication standards and liability requirements.
  • Financial inclusion – here the government acknowledges the need to monitor and address increased risk of exclusion for those unable to or who refuse to use digital payments as per its Financial Inclusion Strategy. The government welcomes views on “whether reforms proposed in this consultation could create financial inclusion risks as it seeks to ensure that any changes continue to support everyone to access the financial products and services they need and engage with confidence in our modern digital society and economy.”
  • Managing sector risks – changes to the payment sector have meant increased and additional vulnerabilities, through increasing use of new technologies and payment models, and the growth in the number and diversity of firms and especially the rapid scaling of the sector. The proposal explains that the FCA, under the current framework, has utilised its powers to take action where it sees firms falling short of the required standards, but the government is seeking views on whether additional safeguards are needed in the payments sector. Here, the proposals seem to be driving at a possible expansion of SMCR to payments firms (which the FCA has pushed and always rowed back on for some time now) but also includes a very broad reference to risks “associated with new products and business models” which aligns with a similar broad ‘catch-all’ that we’ve seen in the proposals for PSD3 for Europe.

On Open Banking, proposals include modernising the provisions in the PSRs (including a new statutory right of access for variable recurring payments and provision for fair commercial pricing arrangements) and providing the FCA with powers to regulate open banking under the Data (Use and Access) Act 2025. This includes powers to regulate the “Future Entity” as an interface body, together with monitoring and enforcement powers.

Alongside the PSR and EMR, HMT has also specifically called out the current framework for cross-border payments under CBPR2 and Euro payments under SEPA; both areas, in our experience, with an awful lot of grey that would benefit from clearer guidance.

The consultation closes on 6 October 2026 and it’s difficult to overstate the importance of what happens next for the UK as a key centre for payments firms. The changes being consulted on here will affect pretty much every firm operating in the UK so, if you would like to discuss the proposals – with us or your peers – please get in touch.

FCA cryptoasset policy statements (PS26/9 to PS26/13) and joint BoE/FCA approach on systemic stablecoins

While many in the UK are working through the 12,000 lines of the Odyssey on the back of Nolan's latest blockbuster, our Crypto View colleagues have been on an odyssey of their own, working through around 1,000 pages of policy statements finalising the UK cryptoasset regulatory regime.

We will defer to them to give the full breakdown but the policy statements cover:

  • PS26/9 on the regimes for cryptoasset admissions and disclosures, and market abuse;
  • PS26/10 on rules and guidance for UK authorised stablecoin issuers (covering issuance, backing assets, redemption, cryptoasset safeguarding and disclosures);
  • PS26/11 on regulated cryptoasset activities;
  • PS26/12 on the prudential regime for cryptoasset firms (which is supplemented by consultation on non-Handbook guidance relating to COREPRU and CRYPTOPRU); and
  • PS26/13 on the application of the FCA Handbook for regulated cryptoasset activities and finalised guidance.

The new rules will come into force on 25 October 2027, with authorisation applications opening on 30 September 2026 and closing on 28 February 2027.

On the same day, the BoE and the FCA published a joint approach document setting out how the two regulators will apply the UK stablecoin regime jointly to systemic stablecoin issuers. This complements the BoE’s June 2026 policy statement and draft Code of Practice for systemic stablecoin issuers (see our June edition) and covers the allocation of supervisory responsibilities where issuers fall within more than one regulator’s remit.

For firms already operating cryptoasset businesses, or preparing FSMA authorisation applications, the priority will obviously be to map the finalised rules to their business model, permissions, safeguarding, prudential requirements and disclosures, and to prepare their applications ahead of the 30 September 2026 opening.

We are working across the market here so, if you would like to discuss the finalised rules or the joint approach document, please get in touch.

Financial Services AI adoption plan and Mansion House 2026

Following up on the AI announcement covered in our last edition, the government has now published a further AI update in the form of the Financial Services AI adoption plan which sets out ten recommendations for industry, the regulators and government. As the plan sets out, the aim is “to ensure AI adoption does not stall or become uneven, the next phase of regulatory policy must focus on scaling the reach of these existing successes. The priority now should be to establish a clear, authoritative single source of cross-regulator guidance, enabling firms to navigate requirements confidently and scale adoption consistently across the sector”.

Topics covered in the recommendations include:

  • the regulatory framework;
  • AI financial advice and the regulatory perimeter;
  • a consumer disclosure for AI-driven services;
  • resilience, including critical third parties and an industry-wide AI incident and “near-miss” repository;
  • skills and talent; and
  • agentic payment readiness.

What jumped out to us was obviously the focus on agentic payments, which the Plan ranks as ‘high’ priority and argues they “have significant potential to transform the global transaction landscape”. While interesting, the Plan does highlight the “complex, systemic challenges” that HMT’s own PSR modernisation proposal must deal with. Here, the Plan focuses on the following core elements:

  • Legal & Liability Frameworks: Defining clear legal constructs and dispute mechanisms to unambiguously assign accountability when autonomous agents transact.
  • Know Your Agent (KYA) Protocols: Establishing standardised identity and verification frameworks specifically designed for AI and autonomous software agents.
  • Authentication & Governance: Creating interoperable technical standards that ensure safe, frictionless, and trusted machine-to-machine authentication.

Agentic payments were also a focus of a speech by Andrew Bailey, delivered at Mansion House (alongside the government’s economic strategy), on how well-designed regulation can support sustainable economic growth.

Beyond addressing bank capital, payments and tokenisation, plus the opportunities and risks posed by AI, Bailey observes the challenges of drawing parallels with ‘traditional agency’, where the principal is responsible for an agent while the agent operates within the principal’s remit, and that this framework has depended on the agent having a legal persona. Where the agent has no legal persona, the question whether the principal is responsible at all times raises policy issues that will need to be resolved.

Beyond this, Bailey also touched on the always riveting topics of capital buffers, the essential purpose of regulation (and the balancing between modernising to enhance efficiency, but also ensuring operational resilience), and the twin anchors of the singleness of money and finality of settlement – fun stuff.

PSR APP scam roadmap and independent e valuation

Late in July, the PSR published a roadmap setting out the scope and timing of its planned work to address authorised push payment (APP) fraud, together with the long-promised independent evaluation of the PSR’s APP scam policies.

While we imagine some in the industry would come to a rather different conclusion, the PSR’s number crunchers submit that the reimbursement scheme has been a huge success and has delivered benefits that outweigh its costs. The report goes into an admirable degree of detail to show that, in the report’s view, APP fraud fell materially and consumer protection improved overall following the regime coming into force.

We would hazard a guess that a sizeable chunk of you went into the legal industry so that you didn’t have to continue with maths, but our reading of the data is a little more nuanced. Also, as the report pulls out, outcomes have clearly not been consistent across payment service providers and a key area of concern is that fraud may now have just moved outside the scope of the scheme, with the longer-term market impacts not yet being clear. Time yet to dust off the car crash emojis.

In response to the evaluation and stakeholder feedback, the PSR has confirmed the following next steps:

  • August 2026, the PSR will engage with industry and consumer representatives to support the development of its APP scam policy;
  • December 2026, the PSR will consult on policy proposals and any necessary amendments to the relevant legal instruments;
  • December 2026, the PSR will publish a data report on the platforms and services commonly used for APP scams – we are sure that tech firms are delighted; and
  • May 2027, the PSR will confirm its decision following the consultation, publish revised legal directions and confirm an implementation date within six months of publishing the decision.

We engaged with a number of readers across their own APP scam implementation projects, so please do let us know if it would be useful to discuss the findings of this report and next steps.

BaFin: AML expectations for virtual IBANs

With it being a topic close to our interests, we wanted to flag that BaFin has published a supervisory communication (Aufsichtsmitteilung 06/2026) focusing on money laundering and terrorist financing risks associated with virtual IBAN (vIBAN) structures and setting out its expectations regarding appropriate control and monitoring measures.

In a very similar tone to the previous EBA / Belgian presidency position paper, while acknowledging the operational benefits of vIBANs, BaFin highlights that complex and cross-border structures may create transparency challenges, particularly where the account-holding institution has limited visibility over the end customers using the vIBAN.

The communication is particularly relevant for payment service providers operating vIBAN models and for credit institutions providing master accounts and vIBAN infrastructure to PSPs. BaFin focuses on multi-layered PSP structures, including re-issuing models, where information on end customers and beneficial owners may not be readily available throughout the payment chain.

We think the risk indicators highlighted by BaFin are particularly interesting, including those on the extensive use of vIBANs linked to a single master account, incomplete customer information, complex cross-border payment flows, multiple PSP layers and economically implausible transaction patterns. These are nuanced points and arguably have very little to do with vIBANs, and more to do with alignment of a firm with its wider regulatory and financial crime controls.

While the communication does not introduce new legal requirements, it provides useful insight into BaFin's current supervisory expectations in relation to vIBAN models – particularly with AMLR on the horizon.

If you would like to discuss the implications for your vIBAN arrangements, please get in touch.

HMT designation of first critical third parties

We also wanted to raise the designation of the first four critical third parties (CTPs) to the UK financial system: Microsoft Ireland Operations, Google Cloud EMEA, Amazon Web Services EMEA SARL and Oracle Corporation UK. The designations took effect from 13 July 2026 and bring each of these providers within the oversight of the BoE, PRA and FCA under the CTP regime introduced by the Financial Services and Markets Act 2023.

As designated CTPs, the four providers will be subject to regulator oversight to ensure robust arrangements for identifying, managing and recovering from operational disruptions affecting critical services used across financial services. For payments firms whose infrastructure depends on these providers, the designations are likely unsurprising but are key developments to watch as the UK grapples with the regulation of tech firms.

FCA multi-firm review of basic bank account access

The FCA has published the findings of its multi-firm review of basic bank accounts (BBAs) following a mystery shopping exercise of the nine largest current account providers required to offer BBAs under the Payment Accounts Regulations 2015.

The FCA found that, although firms can deliver good outcomes, they do not do so consistently, and poor practice remains widespread. In particular, there is a significant risk that consumers who might need a BBA are turned away in branch, online or by call centre before they can apply. Firms have been given specific feedback and required to develop remedial plans with senior manager accountability.

Industry, via UK Finance, will focus on three priority areas: identifying and offering BBAs promptly; removing barriers for consumers with non-standard identification or no fixed address; and recognising and responding to vulnerability. UK Finance will lead sector reviews at six and twelve months.

For BBA providers, the immediate action is to review customer journeys against the FCA’s findings and prepare for the UK Finance six-month check-in. If you would like to discuss, please get in touch.

Mortgage Rule Review

On 9 June 2026, the FCA launched its Mortgage Rule Review consultation (CP26/18), proposing permissive changes aimed at better supporting first-time buyers and other underserved consumers. The proposals span six areas:

  • interest-only mortgages (including new thresholds for credible repayment strategies and a tailored interactive dialogue option),
  • retirement interest-only mortgages,
  • borrowers with variable or irregular income,
  • credit-impaired customers,
  • foreign currency loans, and
  • bridging loans (doubling the maximum regulated term to 24 months).

The consultation closed on 28 July 2026, with a policy statement expected later this year. For our full analysis of what each strand means for lenders and intermediaries, see our insight article here.

News flash

  • The FCA is understood to be developing a regulatory framework for tokenised gold, with the regulator having held early discussions with major banks and other industry participants on how tokenised gold could operate within the UK regime. The particular focus is on whether tokenised gold – digital representations of ownership rights over physical bullion held in custody – could function efficiently as collateral in wholesale markets, sitting alongside tokenised money market funds as eligible collateral for uncleared OTC derivatives.
  • OFAC and OFSI jointly published a comparative overview of the US and UK sanctions regimes as part of the OFAC-OFSI Enhanced Partnership. The overview covers terminology, sanctions lists, jurisdiction, licensing, recordkeeping, reporting and enforcement.
  • The Wolfsberg Group published guidance on the provision of banking services to non-bank payment service providers. The guidance provides a risk-based framework to help banks assess and manage the financial crime risks arising from providing services to non-bank PSPs, including diagrams of third-party payment flows.
  • HMT published a consultation on revising the fee regime for recognised payment systems and digital settlement asset service providers. HMT proposes to extend the Banking Act 2009 fee regime to DSA service providers and related service providers, and to raise the supervision fee cap for operators of recognised payment systems, DSA service providers and related service providers to £1.7 million in any one year period. The consultation closes shortly on 31 August 2026.
  • Finally, a general update that the FCA has just launched an API connection to the FCA Handbook – providing access to the Handbook in a machine-readable format. This opens the data up to greater LLM-driven reviews (such as those we’ve been assisting a number of clients with) – it’s a shame the new Handbook format looks to be here to stay though.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.