PSD2 is the rulebook that prised open Europe’s bank accounts. The revised Payment Services Directive forces banks to let regulated third parties read account data and start payments on a customer’s instruction, and requires stronger security checks on electronic payments. What is PSD2 in the UK? Not the directive itself. It reaches firms here through a domestic statutory instrument, supervised by the Financial Conduct Authority, alongside onshored technical standards already drifting from the European version.
A Legal Entity Identifier can also become relevant for some payment firms through adjacent regulatory and payment-infrastructure requirements, and at LEI24 we help companies obtain and manage LEIs where they are needed.
What Is PSD2?
PSD2 is Directive (EU) 2015/2366. It replaced the first Payment Services Directive of 2007, widened the definition of a payment service, and created licensed roles for firms that touch accounts held somewhere else. Three goals shaped the text: more competition in retail payments, less fraud on electronic transactions, and clearer rights for the people making them.
What PSD2 Changed for Payments
Five shifts account for most of the practical effect.
- Account access. A bank must let a licensed provider read account data or initiate a payment where the customer has given explicit consent, without demanding a commercial contract first.
- Two new licences. Account information and payment initiation became regulated payment services in their own right.
- Stronger authentication. Electronic payments and online account access require two independent elements unless an exemption applies.
- Sharper liability. Refund rules for unauthorised transactions tightened, with the burden of proof on the provider.
- No card surcharges. Businesses can no longer charge consumers extra for card payments.
When PSD2 Came Into Force
PSD2 did not commence on a single date. Different provisions bit at different times, across the seven years between adoption and full enforcement.
| Date | What happened |
| 25 November 2015 | PSD2 adopted in the EU |
| 18 July 2017 | The Payment Services Regulations 2017 made by the Treasury |
| 13 January 2018 | Most of the Regulations in force, matching the EU application date |
| 14 September 2019 | Authentication and secure communication provisions apply (regulation 100) |
| 31 December 2020 | The directive stops applying to the UK; the Regulations continue as domestic law |
| 14 March 2022 | End of the FCA’s managed rollout for e-commerce card authentication |
Regulation 1(5) held the authentication provisions back until the technical standards were ready, and the FCA then ran a further managed rollout for online card payments. Most of the friction people associate with PSD2 arrived years after the law did.
PSD2 in the UK: The Payment Services Regulations 2017
PSD2 does not apply in the UK. The Payment Services Regulations 2017 (SI 2017/752) do, and the distinction decides almost every practical question about scope, supervision and enforcement.
A directive binds member states to a result and is implemented through domestic law and regulatory rules, so in practice, UK firms were governed through the Payment Services Regulations 2017 and the FCA framework rather than by PSD2 as a standalone rulebook. The Treasury made them under section 2(2) of the European Communities Act 1972. The explanatory note published with them on legislation.gov.uk is explicit that they transpose the directive only in part, with the FCA responsible for transposing the rest through its own rules. UK payments law has been split between statute and regulator from day one.
Since the end of the transition period, the directive has no application here at all. What remains is a domestic instrument, amended for exit by the Electronic Money, Payment Services and Payment Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018, with EEA references stripped out and passporting gone.
Four features of the UK framework decide how far it reaches.
- The FCA is the competent authority. Regulation 106 sets out its functions. It authorises payment institutions under regulation 6, registers account information service providers under regulation 18, and maintains the public register under regulation 4.
- The security standards were onshored. The regulatory technical standards on strong customer authentication and common and secure methods of communication, the SCA-RTS, now sit in the FCA Handbook as UK technical standards, in force from the end of the transition period. The EU standards on the same subject were revoked. The FCA amends the UK version, and the European Commission has no say.
- Divergence is already visible. The FCA has added exemptions with no European twin and rewritten others the Commission left alone, so the two authentication regimes no longer match.
- Enforcement is domestic. Decisions are referred to the Upper Tribunal, and the offences for misleading the FCA sit at regulations 142 to 146.
Schedule 1 to the Financial Services and Markets Act 2023 lists the Regulations as assimilated law marked for revocation. Only regulation 158 has gone so far, and the rest waits on a commencement instrument.
PSD2 vs Open Banking: What Is the Difference?
PSD2 is the law. Open banking is the UK’s implementation of one part of it.
The Regulations give licensed providers a right of access and leave each bank free to design its own interface, provided that interface clears the minimum requirements in the technical standards. British open banking exists because a competition regulator, rather than a payments regulator, ordered nine large providers to build to a single standard.
| Payment Services Regulations 2017 | UK open banking | |
| Legal source | Statutory instrument transposing PSD2 | CMA Retail Banking Market Investigation Order 2017 |
| Who it binds | Every payment service provider in the UK | The nine largest current account providers |
| What it requires | A compliant access interface | A common API standard set by Open Banking Limited, plus a directory, conformance testing and dispute management |
| Regulator | FCA | CMA |
PSD2 open banking is shorthand for the pairing, and the seam between the law and the standard is where the coverage gap sits. Plug into one of the nine and you meet a published specification. Plug into a smaller building society and you meet whatever that firm chose to build.
Where UK Open Banking Came From
In 2016 the Competition and Markets Authority finished a two-year investigation into retail banking and concluded that current account customers rarely switched, because comparing what they were getting was close to impossible. The remedy was the Retail Banking Market Investigation Order 2017, which required the nine largest providers, known across the industry as the CMA9, to fund an implementation entity, publish open APIs to a common standard, and submit to conformance testing.
The Order has never been revoked. Open Banking Limited still runs the standard and the directory, and the Joint Regulatory Oversight Committee is designing the framework meant to replace it.
Who Does PSD2 Apply To in the UK, and Who Are the Key Players?
The Regulations catch anyone providing a payment service in the UK as a regular occupation or business activity. Schedule 1 lists what counts: cash placement and withdrawal, direct debits, card transactions, credit transfers, issuing payment instruments, acquiring, money remittance, payment initiation and account information.
Regulation 3 puts credit unions, municipal banks and the National Savings Bank outside the Regulations altogether. Everyone else falls into one of the four roles below.
Account Information Service Providers (AISPs)
An account information service provider runs an online service that consolidates information on one or more payment accounts a customer holds elsewhere. Regulation 2 supplies the definition, and registration is the route in rather than full authorisation.
Budgeting apps, accounting software reconciling a business current account feed, lenders running affordability checks, and any dashboard showing balances across several banks are all doing exactly this. An AISP holds no money and moves nothing. It reads.
Regulation 18 requires professional indemnity insurance covering liability to banks and to customers for unauthorised or fraudulent access to account data, and the FCA lists the firm on its public register.
Payment Initiation Service Providers (PISPs)
A payment initiation service provider starts a payment order at the customer’s request from an account held at another provider. The funds never touch the PISP.
The bar sits higher here. Initiation requires full authorisation as a payment institution under regulation 6 rather than the lighter registration route open to an AISP, plus professional indemnity insurance covering liability for unauthorised, defective or late transactions.
The checkout that offers to pay direct from your bank instead of by card is a PISP moving a Faster Payment while the merchant waits.
Account Servicing Payment Service Providers (ASPSPs)
An account servicing payment service provider provides and maintains a payment account for a payer. Banks, building societies and many e-money firms qualify.
The duties here run in one direction. Regulations 68 and 69 require an ASPSP with an online accessible payment account to let a licensed initiation or information provider in once the customer consents, with no contract as a precondition. Regulation 100 requires the ASPSP to apply authentication. Regulation 71 sets the narrow grounds for denying access and the duty to notify the FCA when it does.
Merchants and Businesses Taking Online Payments
A shop is not a payment service provider. A retailer selling its own goods needs no FCA permission at all.
The effects arrive anyway, through the acquirer contract and the checkout.
- Authentication at the till and online. The card issuer decides whether to challenge a transaction. A merchant may request an exemption, and the issuer grants or refuses it.
- 3-D Secure. Full e-commerce enforcement landed on 14 March 2022 after the FCA’s extended rollout.
- No surcharging. Consumer card payments cannot carry an extra fee.
- Execution timing. For most sterling transfers, funds must reach the payee’s provider by the end of the next business day.
Strong Customer Authentication (SCA)
Strong customer authentication is a check built on two or more independent elements from different categories, designed so that breaching one element leaves the others intact. Regulation 2 defines it and regulation 100 makes it compulsory.
It applies where a payer accesses a payment account online, initiates an electronic payment transaction, or carries out any action through a remote channel that carries a fraud risk. Remote transactions also require a dynamic link between the authentication code, the amount and the payee.
The Three SCA Factors
The elements come from three categories.
- Knowledge. Something only the user knows: a password, a PIN, a memorable answer.
- Possession. Something only the user holds: a registered handset, a card reader, a device with a bound app.
- Inherence. Something the user is: a fingerprint, a face scan, a behavioural pattern.
Two passwords fail the test. A PIN plus a card reader passes. Face ID on a registered phone passes, because the device supplies possession and the biometric supplies inherence.
Independence is the part firms miss. A one-time code sent by text to the same handset running the banking app strains the requirement, since compromising the phone compromises both elements at once. The FCA has also taken a wider view of inherence than the European Banking Authority, accepting that behavioural characteristics may qualify.
When SCA Does Not Apply: Exemptions
Chapter 3 of the SCA-RTS lists the exemptions. Each one belongs to the payer’s provider rather than the merchant.
- Contactless at the point of sale. Article 11 changed on 19 March 2026. Fixed regulatory limits gave way to a risk-based test, so a provider may skip the challenge where it reasonably identifies a transaction as low risk under its own monitoring. Firms may still set their own limits, and on the FCA’s reading of industry feedback most are likely to keep £100 for a single tap and £300 cumulative or five consecutive taps for the foreseeable future. The EU kept the fixed-limit approach, capped at €50.
- Unattended terminals. Article 12 survives untouched for transport fares and parking.
- Low value remote payments. Article 16 covers small amounts, subject to cumulative and consecutive counters.
- Transaction risk analysis. Article 18 allows exemptions at higher values where the provider’s fraud rate stays below the reference thresholds, monitored through fraud reporting.
- Trusted beneficiaries and recurring payments. Articles 13 and 14 cover a list the customer has approved and a series of identical amounts to the same payee.
- Account information access. Articles 10 and 10A govern balance and 90-day transaction history, with the account information provider reconfirming consent every 90 days under Article 36(6) since March 2022. Article 10A is a UK addition with no direct European twin.
What Is PSD3, and Does It Affect the UK?
PSD3 is the EU’s proposed third Payment Services Directive, paired with a directly applicable Payment Services Regulation. Together they repeal PSD2 and the Second E-Money Directive.
The Commission proposed both on 28 June 2023. Parliament and Council agreed a text in November 2025, and the Parliament’s economic affairs committee approved the final version in May 2026, pressing for adoption by September 2026 at the latest. Formal adoption and publication in the Official Journal are both still outstanding. Most substantive provisions apply roughly 21 months after publication, which points at 2028.
The split matters more than the content. Licensing, supervision and safeguarding stay in a directive that member states transpose. Conduct rules move into a regulation that applies directly, which removes the national variation PSD2 produced.
What changes for firms inside the EU:
- Payment institutions and e-money institutions merge into a single licensing regime.
- Banks must run a dedicated access interface performing at least as well as their own app, measured against harmonised standards.
- Payee name and account number verification becomes general across credit transfers.
- Liability moves to providers where fraud prevention falls short, with obligations reaching very large online platforms.
- Account information providers gain passporting on a single home-state registration.
Does any of it reach the UK? Not directly. An EU regulation has no effect here, and a directive binds member states rather than Britain. Three groups still feel it: firms with EEA subsidiaries or branches, firms serving EEA customers, and card businesses whose transactions carry a European leg.
How to Prepare for PSD2 Compliance
PSD2 compliance in the UK means compliance with the Payment Services Regulations 2017, the FCA Handbook and the UK technical standards. The directive is a source of those rules, not the rules themselves.
Two questions come before the product. Which payment services are you providing, as defined in Part 1 of Schedule 1? And does an exclusion catch you, such as the limited network or commercial agent carve-outs in Part 2 of that Schedule? Firms get both wrong, and providing payment services without the right permission is an offence, so perimeter analysis comes first.
FCA Authorisation and Registration
Payment initiation is the dividing line. Reading an account needs only registration. Moving money needs authorisation.
| Permission | Route | Typical firm |
| Authorised payment institution | Regulation 6 | Any firm initiating payments, including every PISP |
| Small payment institution | Regulation 14 | Firms under the turnover threshold, with limits on what they may do |
| Registered account information service provider | Regulation 18 | AISP-only businesses |
Regulation 6 sets the conditions for authorisation:
- Capital. Initial capital under Schedule 3.
- Location. Head office and registered office in the UK, with part of the payment business carried on here.
- Governance. Clear lines of responsibility, risk procedures and internal controls proportionate to the business.
- Safeguarding. Customer funds protected under regulation 23.
- People. Directors and managers of good repute with relevant knowledge and experience, and controllers who are fit and proper.
- Business plan. Carrying a three-year forecast budget.
- Insurance. Professional indemnity cover for initiation and information services.
- Financial crime. Registration under the Money Laundering Regulations where it applies.
Regulation 9 fixes the timing: three months for a complete application, twelve for an incomplete one. The obligations continue after that, through operational and security risk management under regulation 98, incident reporting under regulation 99 and regular reporting under regulation 109. Safeguarding is under active reform, with the FCA moving payment and e-money firms onto client-asset-style rules, and a payment institution that also holds an investment permission picks up FCA transaction reporting under UK MiFIR on top.
How an LEI Supports Payment Firms Under PSD2
Nothing in the Regulations requires a Legal Entity Identifier. The requirement for the 20-character code arrives from the systems a payment firm has to connect to.
Since 1 May 2025 the Bank of England has mandated LEIs in CHAPS payments between financial institutions, for messages sent through channels a direct participant controls. Its September 2025 policy statement widens that to further message types from November 2027. The identifier travels inside the ISO 20022 message alongside purpose codes and structured remittance data.
Three things follow for a payment firm. A missing or lapsed identifier surfaces as an exception on a CHAPS message long before anyone frames it as a compliance problem. A bank assessing a new payment institution as a client wants to know who owns whom, and GLEIF Level 2 data records the direct and ultimate accounting consolidating parent, which is the same ownership picture the FCA examines when it tests qualifying holdings under regulation 6. And status decays quietly: twelve months after issuance without renewal a record moves from issued to lapsed, and stays visible to anyone running an LEI search.
Where PSD2 and UK Open Banking Go Next
Replacing the Payment Services Regulations 2017 is a programme rather than a single event, and most of it is still in Parliament or out for consultation.
HM Treasury published a payments modernisation package on 21 April 2026. Four commitments stand out.
- One regulator. The Payment Systems Regulator will be consolidated into the FCA. The Financial Services and Markets Bill carrying that clause started in the Lords on 19 May 2026 and completed Grand Committee on 8 July, with the Commons stages and Royal Assent still ahead.
- One perimeter. Payment services and e-money regulation will be integrated with the Financial Services and Markets Act 2000 framework.
- Open banking on a statutory footing. The FCA gains new powers over its future, with secondary legislation under the Data (Use and Access) Act 2025 due before Parliament in the fourth quarter of 2026.
- Payments initiated by AI agents. The Treasury will examine how consent under regulation 67 works when software rather than a person authorises a payment.
The endpoint is a statutory instrument revoking the Payment Services Regulations 2017 and the Electronic Money Regulations 2011, with the detail moving into FCA rules. Officials have pointed at 2027 to 2028, and that depends on parliamentary time.
None of it changes what binds today. The Regulations still apply, the FCA still authorises, and the technical standards still govern authentication. The Bank of England keeps widening where it requires identifiers in high-value sterling payments, whatever else changes around them, which makes entity identification one of the few fixed points in the programme. You can register, renew or transfer an LEI with us and have the record current before a payment message or an onboarding check finds the gap.
Frequently Asked Questions
Is PSD2 still in force in the UK after Brexit?
The directive no longer applies. Its rules survive in domestic law through the Payment Services Regulations 2017, which the FCA supervises and amends independently of the European Union.
Who enforces PSD2 rules in the UK?
The Financial Conduct Authority. Regulation 106 sets out its functions, covering authorisation, supervision, the public register and enforcement. Appeals against its decisions go to the Upper Tribunal.
Does PSD2 apply to businesses that only take card payments?
Not as regulated firms. A retailer selling its own goods needs no permission, though authentication at checkout, the surcharging ban and acquirer contract terms all reach it.
Is open banking safe?
Access requires FCA authorisation or registration, explicit customer consent, strong authentication and professional indemnity insurance. Consent is reconfirmed periodically, and the customer can withdraw it at any time.
Do payment firms need an LEI under PSD2?
The Regulations do not require one. Since May 2025 the Bank of England has mandated LEIs in CHAPS payments between financial institutions, which catches many payment firms anyway.



