TL;DR
-
On 7 May 2026, the FCA’s PS25/12 Supplementary Regime went live. UK-authorised payment institutions and e-money institutions now have to perform daily internal and external reconciliation of safeguarded funds, file a monthly safeguarding return to the FCA, maintain a resolution pack for insolvency, and submit an annual safeguarding audit when they hold more than £100,000 of customer funds.
-
The audit threshold exempts roughly 23% of in-scope firms but covers about 99% of the £27 billion of customer funds inside the regime. The rules harden the regulatory floor; they do not remove the failure mode of a single-PSP setup — they make it more concrete.
-
For global subscription businesses that clear through a single UK EMI, the operational profile of that vendor has shifted. The structural hedge is a multi-PSP, multi-jurisdiction architecture so a regulatory event at one provider does not stop settlement to merchants of record.
Context: what PS25/12 actually changes
Safeguarding is the obligation, under the UK Electronic Money Regulations 2011 and the Payment Services Regulations 2017, for payment institutions (PIs) and e-money institutions (EMIs) to hold customer funds segregated from their own funds, so that customers can be repaid in full if the firm fails.
The FCA’s view, going into this rule cycle, was that “some payments firms do not currently have sufficiently robust safeguarding practices.” PS25/12 — the Supplementary Regime — is the FCA’s near-term answer. It does not replace the existing legislative regime; it sits on top of it and tightens the operational requirements. A later “Post-Repeal Regime,” modelled on CASS-style protections used in the broader financial services sector, is still on the FCA’s horizon but not yet implemented.
PS25/12 went into force on 7 May 2026 for:
- Authorised payment institutions (excluding firms providing only payment initiation or account information services).
- Authorised e-money institutions.
- Small e-money institutions.
- UK credit unions issuing e-money.
- Small payment institutions may opt in voluntarily.
The four operational requirements that matter for any merchant clearing through one of these firms:
- Daily reconciliation. Firms must perform internal and external safeguarding reconciliations at least once each business day. The FCA defines “reconciliation day” to exclude Saturdays, Sundays, Christmas Day, Good Friday, UK bank holidays, and days when relevant foreign markets are not normally open.
- Monthly safeguarding return. A new regulatory return to the FCA describing the firm’s safeguarding arrangements. Filed monthly.
- Resolution pack. Documents and records that allow the firm — and an insolvency practitioner stepping into its shoes — to return relevant funds to customers in a timely way if the firm enters insolvency.
- Annual safeguarding audit. Required for any firm that has safeguarded more than £100,000 of customer funds in the previous 53 weeks. Reports use a “reasonable assurance engagement” standard and must be filed within four months — six months for the first audit cycle.
The £100,000 threshold exempts roughly 23% of in-scope payments firms, but the exempt firms hold only about £3.2 million of customer funds out of more than £27 billion inside the regime. The audit covers about 99% of the money even though it exempts almost a quarter of the firms.
Analysis: why this is a subscription-billing story, not just a PSP story
On its surface, PS25/12 is a rulebook change for a specific set of UK-regulated firms. The merchant of record clearing through one of those firms does not pick up any new direct obligation.
That framing misses the structural point. For a global subscription business — SaaS, streaming, fitness, language-learning, any product with recurring revenue clearing through a UK PSP or EMI — the operational profile of that vendor has changed in three ways that matter:
- Higher day-to-day operational load on the PSP/EMI. Daily reconciliations, monthly returns, audit-grade record-keeping, and a maintained resolution pack are not free. Smaller and mid-tier firms will absorb that cost in fees, in tighter onboarding, or in a narrower view of which merchants are commercially worth the risk. Subscription verticals that look “ops-heavy” to a PSP — high refund rates, mid-cycle pricing changes, dunning retries — are exactly the merchants whose marginal cost just went up.
- More visible failure path. The Supplementary Regime is, in part, the FCA’s pre-emptive answer to a wind-down it wants to be ready for. The resolution pack and the monthly return exist to make a regulatory pause or insolvency event faster and cleaner. From the merchant’s side, “faster and cleaner” is still a pause. Settlement to the merchant of record stops during the process. In subscription billing, the unit that takes the hit is not next quarter’s pipeline — it is this week’s MRR landing in the operating account.
- Concentration risk surfaces. Multi-jurisdictional regulatory shocks happen on the regulator’s calendar, not the merchant’s. A subscription business with a single UK EMI relationship for global billing has now stacked the entire revenue line behind one supervisory regime. The new rules make that stack safer in the average case and more concrete in the tail case.
The right question for a Head of Payments or CFO is not “is our UK PSP PS25/12-compliant?” The right question is “what is our settlement-continuity plan for the week our UK PSP is paused?”
Why “switch to a different UK PSP” is the wrong answer
The intuitive move is to swap one UK PSP for a more robust one. That is a single-PSP migration: it changes the name on the door, not the structural exposure.
A global subscription business optimising for revenue continuity is not optimising against vendor quality. It is optimising against jurisdictional concentration, scheme concentration, and acquirer concentration — all at the same time, all on the regulator’s clock. PS25/12 is a UK story today. The next quarter will produce an EU story (PSR and PSD3 implementation), an EU member-state story (national supervisor enforcement), and a US story (CFPB, state money-transmitter changes). The structural exposure is not “are we using the right UK EMI.” It is “is our billing tightly coupled to any single one.”
How SGW’s local-processing architecture absorbs this
The architecture that survives a regulatory event at one provider is one where each market already runs on its own local payments stack — and a single integration ties them together. That is the model SGW Payment operates for global subscription businesses, mapped to PS25/12 below.
- Local processing in every market, not cross-border. SGW stands up the local payments setup in each country a subscription business sells into — incorporating entities where required, opening banking and acquiring relationships, negotiating PSP contracts in the jurisdiction, and running the downstream finance operations. UK renewals process on UK rails; EU renewals on EU rails; US renewals on US rails. A regulatory pause at a UK PSP or EMI does not touch the EU or US legs because they were never running through it. As a side effect, processing locally rather than cross-border lifts issuer approval rates significantly on its own — the success-rate lever and the continuity hedge are the same architectural choice.
- One SDK and API across the provider network. The merchant integrates once. Behind that integration, transactions clear through SGW’s network of payment providers. Swapping a paused PSP, rebalancing volume between providers in a market, or adding a new market is a routing-layer change, not a release on the merchant’s side.
- Routing to the provider most likely to approve. Each transaction is routed to the provider with the highest probability of approval in that market. In a steady state, this lifts success rates and lowers fees. In a PS25/12-style event, the same routing engine simply stops sending UK-issued cards down the paused acquirer’s path.
- End-to-end finance ops per jurisdiction. Reconciliation, cash flow, reporting, and local tax clearance live inside the same layer for every jurisdiction we process in. The merchant retains visibility into the legs that are still running while a single PSP is mid-event, and the daily-reconciliation discipline PS25/12 puts on the PSP is mirrored, on the merchant side, by reconciliation across providers.
The point is not that orchestration is “better.” The point is that a subscription billing stack already running on local rails in multiple jurisdictions, with finance operations consolidated above it, absorbs a regulatory event at one provider as a routing-rule change rather than a revenue interruption.
Takeaways: five questions to ask your UK PSP/EMI this quarter
- Reconciliation evidence. Can the firm show us its internal and external reconciliation outputs for a recent business day, and the variance investigation process?
- Resolution pack scope. What is in the firm’s resolution pack, who maintains it, and how quickly would funds clear back to merchants if the firm entered insolvency tomorrow?
- Audit status. Has the firm completed (or scheduled) its first PS25/12 safeguarding audit, and which firm is conducting it?
- Settlement-continuity plan on the merchant side. Inside our own stack, if this PSP is paused for two weeks, what percentage of our renewals can route to a non-UK PSP without a deploy?
- Jurisdictional concentration check. What share of our annual subscription billing volume is currently sitting behind a single UK PSP/EMI, and is that share consistent with our risk appetite?
- Build vs. partner on local processing. If the answer is “diversify to local processing in two or three more markets,” the realistic in-house timeline is 6 to 12 months per market — entity setup, banking, acquiring, contract negotiation, and the finance operations on top. A payments orchestration / infrastructure partner that already runs that stack converts a year of work into a routing-rule update.
Sources
- FCA — PS25/12: Changes to the safeguarding regime for payments and e-money firms
- Norton Rose Fulbright — Preparing for the FCA’s new safeguarding rules: a countdown to 7 May 2026
- FCA — Safeguarding customer funds (firm guidance)
- UK Electronic Money Regulations 2011 (SI 2011/99)
- UK Payment Services Regulations 2017 (SI 2017/752)



