Payment Services Regulations 2017
What is the Payment Services Regulations 2017?
Payment Services Regulations 2017 (PSR 2017) is the UK statutory instrument that governs how payment service providers operate, implementing the EU's second Payment Services Directive () into UK domestic law. It sets the rules for authorizing payment providers, safeguarding customer funds, and handling conduct-of-business obligations for banks, e-money institutions, and payment institutions in the UK.
PSR 2017 came into force on 13 January 2018, replacing the earlier Payment Services Regulations 2009. It's enforced by the Financial Conduct Authority (FCA), which acts as the UK's competent authority for payment services. The regulation also introduced open banking obligations, requiring account-servicing providers to give registered third-party providers secure access to customer account data, and it carried strong customer authentication (SCA) requirements into UK law. After Brexit, PSD2 no longer applies directly in the UK, so PSR 2017 continues as the UK's own standalone framework, separate from any changes the EU makes to PSD2 or its proposed successor. That split matters for cross-border merchants: a payment flow that touches both the UK and the EU can end up subject to two related but separately amendable rulebooks.
Key facts
- Also known as: PSR 2017
- Implements: the UK version of
- In force since: 13 January 2018, replacing the Payment Services Regulations 2009
- Regulator: Financial Conduct Authority (FCA)
- Covers: authorization, safeguarding, conduct of business, open banking access, and strong customer authentication
Who it applies to
PSR 2017 binds any firm providing payment services in the UK: banks, building societies, credit unions, e-money institutions, and authorized or registered payment institutions. It also covers account information service providers (AISPs) and payment initiation service providers (PISPs) – the open banking firms that read account data or trigger payments on a customer's behalf. Merchants and platforms aren't directly regulated under PSR 2017, but any they work with is, which shapes how funds move, how disputes are handled, and how customer data can be shared. A merchant selling into the UK will typically feel PSR 2017 indirectly, through the onboarding checks, safeguarding disclosures, and authentication flows its provider builds to stay compliant.
Key requirements
- Authorization or registration: firms must be authorized or registered with the FCA before offering payment services, meeting minimum capital and governance standards.
- Safeguarding: customer funds held by a payment or e-money institution must be kept separate from the firm's own money, protecting them if the firm fails.
- Conduct of business: providers must give clear pre-contract information, meet execution-time limits for transfers, and follow set rules on refunds and unauthorized payments.
- Strong customer authentication: payment initiation and account access generally require two-factor verification, with defined exemptions for low-value or low-risk transactions.
- Open banking access: account providers must expose secure APIs so authorized AISPs and PISPs can access account data or initiate payments with customer consent.
Penalties for non-compliance
The FCA can use a range of enforcement tools against firms that breach PSR 2017, from requiring a firm to fix a specific failing to varying, restricting, or cancelling its authorization altogether. It can also issue public censures, impose financial penalties, or ban individuals from holding certain roles, with the scale of any penalty depending on the nature and duration of the breach. Because these outcomes are decided case by case, exact fine amounts aren't published as fixed thresholds. Repeated or serious breaches can also trigger closer FCA supervision, including more frequent reporting requirements or a formal skilled-person review of the firm's controls.


