Payment Services Regulations 2017: Authorization, SCA, and Refunds

The Payment Services Regulations 2017 are the UK’s core rulebook for firms that move money electronically. They set out who needs authorization from the Financial Conduct Authority, how much capital a payment firm must hold, what it must tell customers before and after a transaction, how it must authenticate users, and what it owes a customer whose account is hit by an unauthorized or mistaken payment. The regulations implemented the EU’s Second Payment Services Directive into UK law and remain the primary framework today.1Financial Conduct Authority. Payment Services Regulations and Electronic Money Regulations

Who the Rules Cover

The regulations reach a broad range of firms. Banks, building societies, and electronic money issuers are the obvious ones, but the rules also apply to money remitters, non-bank credit card issuers, and merchant acquirers that process card payments for retailers.1Financial Conduct Authority. Payment Services Regulations and Electronic Money Regulations The 2017 update brought in two newer categories: Payment Initiation Service Providers and Account Information Service Providers. These are the firms behind apps that let a user view balances across multiple banks or trigger a payment directly from an account without going through the bank’s own interface.

The rules are written to be technology-neutral. They apply based on what a firm does, not how its software works. A firm that facilitates the execution of payment transactions, issues debit or credit cards, or supplies the information layer that lets a third-party app connect to a bank account is inside the scope. Even businesses that never touch the funds themselves, only the data needed to start a transaction, must comply. Cross-border payments are covered whenever at least one provider sits within UK jurisdiction.

FCA Authorization and Capital Requirements

A firm cannot operate under the regulations without first obtaining authorization from the FCA. There are two routes: Authorized Payment Institution status, and the lighter Small Payment Institution registration, which is only open to firms below a set transaction volume threshold.2Financial Conduct Authority. Small Payment Institution

Every applicant must show it holds enough initial capital. The amount depends on the services offered. Money remittance providers need at least 20,000 euros. Payment initiation services need 50,000 euros. Firms offering broader payment services, such as executing transfers or operating payment accounts, need 125,000 euros.3legislation.gov.uk. The Payment Services Regulations 2017 – Schedule 3 Where a firm offers services in more than one category, the highest applicable figure controls.

Capital is not a one-time hurdle. Authorized firms must maintain adequate capital continuously and submit regular financial reports proving they remain solvent. The application itself calls for a detailed business model description, a list of every agent and branch, and evidence that management has passed a fit and proper assessment covering competence, financial soundness, and criminal background. Internal controls for preventing money laundering must be documented, and the firm must appoint a designated compliance officer with reporting responsibilities to the National Crime Agency.

Firms that provide account information services face an additional condition. They must carry professional indemnity insurance, or an equivalent guarantee, to cover liabilities from data breaches or technical failures. Inaccurate information supplied during authorization can result in outright rejection, and the FCA can revoke authorization later if the firm stops meeting the original conditions. A weak anti-money-laundering framework is a stated ground for both.

Information the Provider Must Give the Customer

Part 6 of the regulations sets out what a payment firm must disclose. Before any contract is signed, the provider must give the user clear information about all fees, exchange rates, and execution timelines.4legislation.gov.uk. The Payment Services Regulations 2017 – Part 6 For framework contracts, meaning the ongoing agreements that govern a payment account, the disclosure must also cover termination rights, complaint procedures, and the methods available for reporting unauthorized transactions. The documents must be provided in an accessible format such as a downloadable file or a paper copy.

Before a single payment is initiated, the provider must disclose the maximum time the transfer will take to reach the recipient and a breakdown of any charges. If a currency conversion is involved, the exact exchange rate applied must be shown. After the transaction, the customer is entitled to a statement showing the reference number, the total amount debited, the date, and any fees. For international payments, the exchange rate used and the pre-conversion amount must also appear.

Providers cannot change the terms of a framework contract on short notice. Any change requires at least two months’ written notice to the customer.5legislation.gov.uk. The Payment Services Regulations 2017 That window gives the customer time to decide whether to accept the new terms or close the account.

Strong Customer Authentication

The security rules require Strong Customer Authentication whenever a user accesses their account online, initiates an electronic payment, or carries out any remote action that could expose them to fraud.6Financial Conduct Authority. Strong Customer Authentication Authentication must use at least two independent factors drawn from three categories: something the user knows (a password or PIN), something the user has (a phone or hardware token), and something the user is (a fingerprint or facial recognition). The factors must be independent enough that a breach of one does not compromise the other.

Beyond authentication, providers must protect stored credentials using encryption and secure storage, monitor for unusual behavior patterns, and notify the regulator, along with any affected users, without unnecessary delay when a breach occurs.

Open Banking Interfaces

Under the open banking rules, banks must maintain dedicated interfaces that let authorized third-party apps communicate securely with customer accounts. The customer never hands over their login credentials to the third party. These interfaces must be tested for performance and security, and a bank cannot block an authorized third-party app’s access without documenting specific security grounds.7Open Banking Standards. Dedicated Interface Requirements

Unauthorized Payments and the Refund Duty

The regulations set a strict rule when a user reports that a payment from their account was not authorized. The provider must refund the full amount no later than the end of the business day after it becomes aware of the transaction.8legislation.gov.uk. The Payment Services Regulations 2017 – Regulation 76 The provider must also restore the account to the state it would have been in had the unauthorized transaction never happened, including correcting interest or charges that flowed from the missing funds. The only exception is where the provider has reasonable grounds to suspect the user of fraud and has notified the appropriate authority in writing.

Even after refunding the user, the provider can hold the payer responsible for up to £35 in losses from unauthorized transactions caused by a lost, stolen, or misappropriated payment instrument.9legislation.gov.uk. The Payment Services Regulations 2017 – Regulation 77 That cap drops to zero if the loss was not detectable by the payer before the payment went through, or if the loss was caused by an employee or agent of the provider. The cap disappears entirely in the other direction too: a payer who acted with gross negligence or fraud can be liable for the full amount.

One rule matters more than most. If the provider failed to require Strong Customer Authentication when the regulations demanded it, the user bears no liability at all. The entire loss falls on the provider. That structure gives providers a direct financial incentive to keep security current.

The burden of proof also sits with the provider. When a customer claims a payment was unauthorized, the firm must show the transaction was properly authenticated and executed. Showing that the correct credentials were used is not, on its own, enough to prove the customer authorized the payment.

Mistaken and Incorrectly Executed Payments

Part 7 addresses payments that reach the wrong destination or the wrong amount. Where a user supplies an incorrect account identifier, the provider is not automatically required to return the funds immediately, but it must make reasonable efforts to recover them. That means contacting the receiving institution and sharing information the user can then use to reclaim the money.10legislation.gov.uk. The Payment Services Regulations 2017 – Part 7

Where the provider itself causes the error, by routing funds to the wrong account, applying the wrong amount, or executing a payment late, it bears full responsibility for correcting the mistake and refunding any fees the error generated. The distinction between customer-supplied wrong details and provider-caused errors decides who carries the loss.

Complaints and the Financial Ombudsman Service

A payment services provider must issue a final response to any complaint within 15 business days of receiving it.11Financial Conduct Authority Handbook. DISP 1.6 Complaints Time Limit Rules In exceptional circumstances beyond the provider’s control, the deadline can extend to 35 business days, but the firm must send a holding response within the original 15-day window explaining the delay.12Financial Ombudsman Service. Time Limits

If the customer is not satisfied with the final response, or if the provider misses the deadline, the customer can escalate to the Financial Ombudsman Service for a binding decision. Providers must inform customers of these rights at the start of the relationship and whenever a dispute arises. Failing to signpost the Ombudsman route is itself a compliance breach.

Penalties for Breach

The FCA can impose unlimited financial penalties on firms that breach the regulations, and it can revoke authorization entirely. For individuals within a firm, especially those in senior management, personal liability can include prohibition orders that bar them from working in financial services. Providers that fail to maintain their dedicated open banking interfaces, deny third-party access without documented security grounds, or neglect their authentication and security obligations face the same range of sanctions.

Direct regulatory action is only part of the exposure. Card networks can revoke processing privileges where a firm’s card-data handling falls short of PCI DSS. Correspondent banks can end relationships with firms whose anti-money-laundering controls are inadequate. And the reputational cost of a published enforcement notice tends to reach customers faster than the fine itself.

Two boundaries are worth naming. The regulations govern UK payment services; firms operating in the United States are subject to a different framework built around the Electronic Fund Transfer Act, Regulation E, and FinCEN’s money services business rules, none of which are interchangeable with the UK regime. And the 2017 regulations sit alongside, not on top of, the separate Money Laundering Regulations, which impose the customer due diligence and transaction monitoring duties that authorized firms must build into their compliance programs.