
Guide to Acquiring a Licensed Payment Institution

Buying an authorised payments business can put a fintech product in market far sooner than building a licence application from zero. But a guide to acquiring a licensed payment institution must start with a hard truth: you are not buying a certificate. You are acquiring a regulated operating model, its regulatory history, its controls, its liabilities and its relationship with the supervisor.
A transaction that looks quick on a term sheet can fail at change-of-control approval, banking onboarding or post-completion remediation. The commercial value lies in acquiring an entity whose permissions, governance and compliance framework genuinely support your planned business - not simply one that once received authorisation.
Why acquire a licensed payment institution?
For founders facing a long authorisation timetable, acquiring an existing payment institution can be the more practical route to market. The company may already have regulatory permissions, experienced directors, safeguarding arrangements, approved policies and operational infrastructure. This can reduce the build period materially when compared with a new application.
The trade-off is diligence. A fresh application lets you design the firm around your product, customer base and target countries. An acquisition gives you an existing framework that may need significant rebuilding. If the seller’s business model is dormant, narrowly scoped or poorly documented, its authorisation may have limited value.
The right route depends on your intended activities. A firm planning payment initiation or account information services has different requirements from a business handling customer funds, operating wallets, issuing payment instruments or supporting merchant acquiring. If e-money issuance is central to the model, a payment institution may not be sufficient. An electronic money institution may be required instead.
Guide to acquiring a licensed payment institution: start with scope
Before reviewing a target, prepare a precise regulatory perimeter memo. It should identify what the buyer will do, where it will do it, who its customers are, how funds move and which third parties perform regulated or critical functions.
This exercise prevents a common and expensive mistake: buying a licence because it has an attractive label, then discovering that it does not cover the intended services. Regulators assess actual activity, not marketing language. A licence for limited payment services does not automatically support card programmes, cross-border merchant acquiring, digital asset settlement flows or e-money issuance.
For UK transactions, examine the entity’s status under the Payment Services Regulations 2017 and its permissions with the Financial Conduct Authority. In the EU, review the applicable PSD2 authorisation, the home-state regulator’s interpretation of the services and any passporting position. Post-Brexit, UK and EU market access must be assessed separately. A UK-authorised payment institution does not create an automatic EU operating right, and the reverse is equally true.
You should also map planned outsourcing. Many payment businesses rely on cloud providers, processors, KYC vendors, card scheme partners and safeguarding banks. Outsourcing does not transfer regulatory responsibility. The buyer must be able to oversee these providers, document the arrangements and demonstrate operational resilience.
Test the target as a regulated business, not a corporate shell
Corporate due diligence is essential, but it is only one part of the review. Share capital, beneficial ownership, contracts, tax and litigation matter. In a regulated acquisition, the more decisive questions often sit in the compliance files, management information and regulator correspondence.
Request the full authorisation file, all material communications with the regulator, past audit reports, complaints data, incident registers, financial crime monitoring records and evidence of safeguarding reconciliations. If records are incomplete, assume the gap will require work and price that work into the deal.
Pay particular attention to four areas:
Safeguarding: Establish where relevant customer funds are held, whether accounts are properly designated, how reconciliations are performed and whether there have been breaks, delays or shortfalls.
Financial crime controls: Review the customer risk assessment, onboarding procedures, sanctions screening, transaction monitoring, suspicious activity escalation and evidence that controls are used in practice.
Capital and financial position: Confirm own-funds requirements, historical capital calculations, liquidity, intercompany balances and any dependency on shareholder funding.
Governance: Assess whether directors and senior managers are genuinely capable of running the enlarged business, and whether decision-making, compliance oversight and internal reporting are documented.
A licence with a weak safeguarding history or poor AML evidence is not a shortcut. It is a remediation project with a regulator already watching.
Treat change of control as a critical path item
Acquiring shares in a regulated payment institution will usually trigger a change-of-control process. Do not regard this as a post-signing formality. The regulator will assess the proposed acquirer, beneficial owners, funding source, business plan, governance arrangements and the impact on the target’s prudent management.
The proposed owners must be ready to explain their background and financial standing. Complex holding structures, opaque funding, unresolved litigation or adverse media can delay the process or create refusal risk. The same applies where the buyer is active in sectors considered higher risk, including cryptoassets, high-risk merchant acquiring, forex or gambling-related payments. These sectors are not automatically prohibited, but they require a clear risk rationale and credible controls.
Transaction documents should reflect this reality. Completion should be conditional on all required regulatory approvals. The share purchase agreement should allocate responsibility for pre-completion compliance, identify disclosure obligations and provide meaningful protection if diligence reveals undisclosed regulatory issues. A low purchase price does not compensate for unquantified enforcement exposure.
Build the post-acquisition operating plan before signing
The regulator may approve a change in ownership, but that does not mean it has approved every future product, market or outsourcing arrangement. A buyer that intends to transform the business needs a practical first-100-days plan.
This plan should cover senior management appointments, policy updates, safeguarding bank confirmation, technology and data migration, outsourcing reviews, AML tuning and communications with customers and counterparties. If the business will change materially, engage with the regulator early and document the rationale for each change.
Banking deserves its own workstream. Payment institutions often rely on a small number of safeguarding and operational banking relationships. A new ownership structure, revised client profile or exposure to digital assets can lead the bank to reassess its appetite. Confirm the continuity of these relationships before completion and prepare alternatives where concentration risk is high.
Data protection and operational resilience should also be examined closely. Payment firms hold sensitive personal and transactional data, often across multiple vendors and jurisdictions. Review access rights, incident management, business continuity testing and contractual provisions. For firms serving EU markets, DORA-related expectations may affect how ICT risk and third-party dependencies are managed.
Price the licence realistically
An authorised entity is valuable when its permissions are usable, its records are clean and its infrastructure fits the buyer’s plan. It is less valuable when the buyer must replace management, rebuild AML controls, renegotiate banking, remediate safeguarding and seek additional approvals immediately after completion.
The most reliable valuation approach separates the value of the corporate vehicle from the cost of making it operational for the intended model. This means budgeting for legal work, regulatory notifications, audit support, compliance staffing, technology remediation, professional indemnity arrangements and capital. It also means resisting sellers who present authorisation alone as proof of readiness.
For acquisition-minded operators, the fastest route is often a targeted transaction supported by regulatory, legal and operational diligence conducted in parallel. NUR Legal approaches these projects as execution work: identify the correct jurisdiction and entity, test the licence against the business plan, manage the approval process and address the controls that make the authorisation bankable after completion.
A regulated acquisition should leave you with more than a company that can trade on paper. The worthwhile deal is one that gives your board, banking partners and regulator confidence that the business can trade responsibly from day one.



Comments