Hand paying a bill with a smartphone, representing embedded payments infrastructure.
How UK Platforms Choose a Regulated Embedded Payments Partner
Picture a UK platform CTO in a board meeting. Their FCA auditor has just issued a PS25/12 safeguarding audit requirement. When the CTO forwards it to their embedded payments provider, the response comes back: "We are working through the requirements."
That response is not a minor inconvenience. It is the moment the CTO realises their product runs on infrastructure they have no direct oversight of. A compliance process they are entirely dependent on belongs to someone else, and that someone else does not appear ready for it.
The UK embedded payments landscape is changing in ways that make this kind of exposure harder to accept. The Payment Systems Regulator is being absorbed into the FCA, concentrating regulatory authority for payment systems, conduct, and innovation policy in a single body. Safeguarding requirements for UK payment firms and electronic money institutions have been tightened under PS25/12, with the new rules live from May 2026. And QED Investors, in their most recent cycle analysis, identified infrastructure-first fintechs as the category best positioned to compound value over the coming years, outpacing the consumer-facing players that were built on their infrastructure.
For heads of product, CTOs, and founders at UK platforms evaluating embedded payments infrastructure, the selection criteria have shifted. This article explains what the current regulatory environment means for that decision, and what to assess when choosing a partner.
What the PSR-FCA Merger Means for Your Embedded Payments Partner
The UK Payment Systems Regulator is being consolidated into the Financial Conduct Authority. Once complete, the FCA will hold regulatory authority over payment system obligations, conduct requirements, and payments innovation policy in a single framework.
For platforms building on embedded payments infrastructure, the practical effect of this shift is direct.
Previously, a payments provider might have maintained separate regulatory relationships: one with the PSR for payment system obligations, another with the FCA for e-money conduct. After the merger, both fall under a single regulator with historically higher supervision expectations than the PSR applied.
The partner selection implication is this: a provider whose FCA relationship is indirect, out-of-date, or built on an arrangement that no longer carries the same weight (for example, an EEA passport that became void after Brexit, or an agent arrangement under another firm's FCA authorisation) now presents a regulatory risk to your product, not simply a commercial one.
UK platforms need a partner whose FCA authorisation is direct, current, and held in a legal entity that can be verified on the FCA Financial Services Register.
What PS25/12 Safeguarding Requires of Your Payments Partner
PS25/12 came into effect in May 2026. It requires UK payment firms and electronic money institutions to demonstrate robust safeguarding of customer funds, backed by a mandatory annual audit conducted by a registered audit firm.
For platforms operating on an embedded payments provider, the implications run through to your product's users. Their funds are safeguarded under your provider's licence and safeguarding arrangements. If that provider fails its PS25/12 audit, or its safeguarding accounts are found to be inadequate, the exposure falls on your users, and by extension on your platform.
Before committing to any embedded payments partner, ask these three due diligence questions:
#Due Diligence QuestionWhat a Satisfactory Answer Looks Like
1Which registered audit firm is conducting your PS25/12 annual safeguarding audit?A named, registered firm is cited immediately, with a timeline for the current audit cycle.
2Can you provide written confirmation of your safeguarding account arrangements?The provider can share documented account references and the financial institution holding segregated funds.
3What is your contingency plan if your safeguarding audit identifies gaps?A written remediation protocol exists and is available to enterprise clients on request.
Providers who cannot answer these questions with specific names, account references, and documented processes are not positioned for the current regulatory environment. That is a factual assessment, not a commercial one.
The Embedded Payments Capability Stack: What to Evaluate
Regulatory standing sets the floor. The capability stack determines how much your platform can build above it. Below are the two categories that matter most for UK product teams making infrastructure decisions in 2026.
Regulatory Depth
Your embedded payments provider's licence is, in effect, your product's licence. The minimum requirement for any UK platform is a partner with a direct FCA authorisation. Agent arrangements and passported EEA licences introduce a layer of dependency that has become a concrete regulatory risk following Brexit and the forthcoming PSR-FCA merger.
For platforms with users across multiple markets, this extends beyond the UK. Multi-jurisdiction coverage through direct licences, rather than local agent arrangements, removes an entire category of operational and compliance risk from your infrastructure layer.
The right partner also carries KYC, AML, transaction monitoring, and PCI-DSS compliance obligations on your behalf. This is what allows a platform to offer financial products to users without applying for its own FCA authorisation, which for most product teams is neither a viable nor a desirable path.
Unified API Architecture
A unified embedded payments API, covering payment acceptance, payouts, embedded accounts, and foreign exchange, removes the integration complexity that comes from assembling separate providers for each function. It also concentrates your compliance oversight within a single partner relationship rather than distributing it across several counterparties.
Two specific technical factors are worth evaluating at the API level in 2026.
ISO 20022 readiness. The UK's Faster Payments System and CHAPS are both transitioning to ISO 20022 structured data messaging. A provider with legacy message handling will require your engineering team to manage data transformation, adding maintenance overhead and potential points of failure over time.
Programmatic API design. The FCA has confirmed it is actively reviewing the regulatory framework for agentic AI in payments. Providers whose APIs are built for machine-speed, programmatic instruction are ahead of this regulatory development. Those built primarily for human-initiated transaction flows will require significant engineering effort to adapt when the framework lands.
ONERWAY as a UK Embedded Payments Infrastructure Partner
ONERWAY holds more than 12 direct regulatory licences, including FCA authorisation in the UK, MAS authorisation in Singapore, MSB registration in the United States, and nine further jurisdictions. For UK platforms with international user bases, this means the infrastructure underpinning your product carries direct regulatory coverage across every major financial hub where your users are likely to operate.
CapabilityDetail
Regulatory Licences12+ direct licences including FCA (UK), MAS (Singapore), and MSB (US). All verifiable on each jurisdiction's public register.
PS25/12 ComplianceSafeguarding arrangements meet the May 2026 requirements in full. Annual audit engagement with a registered audit firm is in place.
Unified APISingle integration for payment acceptance, global payouts, and embedded finance. ISO 20022 native architecture with no legacy message transformation required.
Scheme MembershipPrincipal membership with Mastercard and Visa for direct acquiring. No intermediary acquiring layer, which supports higher authorisation rates for platform clients.
Enterprise SupportNamed account managers and direct compliance team access for platform and enterprise clients. No general support queues for accounts at this tier.
For UK product teams assessing embedded finance infrastructure, ONERWAY's position is built on a direct regulatory footprint, not on passported licences or indirect arrangements that carry residual post-Brexit risk.
Conclusion
The UK embedded payments landscape has moved past the point where feature comparisons or pricing sheets are the primary selection criteria. Regulatory architecture is now a structural requirement, and the combination of the PSR-FCA merger and PS25/12 safeguarding creates a specific and testable due diligence checklist for any platform making this decision.
Verify direct FCA authorisation. Confirm PS25/12 audit readiness with specifics. Assess compliance ownership across KYC, AML, and PCI-DSS. And evaluate whether the API architecture is built for where payments regulation is heading, not only where it is today.
ONERWAY's infrastructure is built around direct regulatory licences in 12+ jurisdictions, a unified API covering payment acceptance, global payouts, and embedded accounts, and a compliance-first approach to enterprise relationships. If you are assessing your embedded payments infrastructure ahead of the regulatory transition, our UK team is available for a direct technical and compliance briefing.
Frequently Asked Questions
What is an embedded payments platform and how does it work for UK platforms?
An embedded payments platform gives non-regulated businesses the ability to offer payment acceptance, payouts, and financial accounts to their users by building on the infrastructure and regulatory authorisation of a specialist provider. UK platforms access this capability through an API integration, with the embedded payments partner carrying the FCA licence and associated compliance obligations. The platform offers the financial product; the provider holds the regulatory responsibility for it.
What should UK platforms look for in an embedded payments provider following the PSR-FCA merger?
After the PSR's consolidation into the FCA, UK platforms should give priority to providers holding a direct FCA authorisation in a named legal entity that can be verified on the FCA Financial Services Register. Providers relying on pre-Brexit EEA passports or indirect agent arrangements now carry additional regulatory risk, because the FCA's oversight expectations are higher than the PSR's were. The merger concentrates authority, which makes the quality of your provider's direct FCA relationship more important, not less.
How does FCA PS25/12 affect embedded payments providers and their platform clients?
PS25/12 requires UK payment firms and electronic money institutions to conduct mandatory annual safeguarding audits by a registered audit firm, with the rules in force from May 2026. For platforms using embedded payments infrastructure, this matters because their end users' funds are held under the provider's safeguarding arrangements. A provider that fails its PS25/12 audit, or cannot demonstrate adequate safeguarding account documentation, exposes client platforms and their users to direct financial risk.
What is the difference between a provider with a direct FCA licence and one operating as an agent?
A provider with a direct FCA authorisation holds its own licence and is independently accountable to the FCA for compliance, conduct, and safeguarding. An agent operates under a principal firm's licence, meaning its regulatory standing depends entirely on the principal's continued authorisation and compliance posture. For platforms building on embedded payments infrastructure, a direct FCA licence offers a cleaner regulatory relationship and simpler due diligence, particularly as the FCA increases scrutiny following the PSR merger.
How does a platform offer financial products without becoming a regulated entity?
By building on the infrastructure of a regulated embedded payments provider, a platform can offer payment accounts, card issuance, and payouts to its users without applying for its own FCA authorisation. The provider carries the KYC, AML, transaction monitoring, and PCI-DSS obligations, while the platform integrates through an API and manages the user relationship. This model remains valid as long as the platform's own activities do not independently cross the threshold that triggers direct FCA authorisation requirements.
Ready to assess your embedded payments infrastructure?
ONERWAY is a UK FCA-licensed embedded payments and embedded finance infrastructure partner, with direct regulatory coverage across 12+ jurisdictions, PS25/12-compliant safeguarding, and a unified API covering payment acceptance, global payouts, and embedded accounts. If you are evaluating your payments infrastructure ahead of the PSR-FCA merger, our UK team is available for a direct technical and compliance briefing.