GCC Licensing Jurisdictions
Each GCC central bank operates its own licensing framework for payment service providers, with distinct capital requirements, governance standards, AML/CFT programme expectations, and supervisory engagement processes. The jurisdictions are not interchangeable: a licence in one GCC state does not confer passporting rights in another. A firm building a GCC-wide payments business typically requires separate authorisation in each operating market, with a licensed entity or registered branch in each.
Qatar Central Bank (QCB)
Payment Systems Law No. 15 of 2021. Payment Service Provider categories A and B; Exchange House licence. Data localisation mandatory. Himyan QR mandate for merchants. Typical authorisation timeline: 6–12 months.
Saudi Arabian Monetary Authority (SAMA)
Payment Service Provider Regulations. Tiered licence structure (Tiers 1–4) by service scope. mada scheme participation requirements. Data residency in-Kingdom. Circular 472047719 governance requirements effective March 2026. Timeline: 9–15 months.
Central Bank of the UAE (CBUAE)
Stored Value Facility and Payment Service Provider licence categories. Aani instant payment connectivity. April 2026 AML/CFT update imposes enhanced obligations on cross-border payment firms. VASP registration for crypto-asset payment services. Timeline: 9–14 months.
Central Bank of Bahrain (CBB)
Ancillary Service Provider and Money Changer licences. Most mature open banking framework in the GCC. FAWRI+ instant payment connectivity. CBB sandbox available for innovative business models. Timeline: 6–10 months.
Central Bank of Kuwait (CBK)
Payment and settlement systems regulatory framework. KNET domestic debit network participation requirements for acquiring businesses. FX and remittance regulations for cross-border payment firms. Timeline: 10–18 months.
Central Bank of Oman (CBO)
Payment Service Provider framework under the Banking Law. Oman's instant payment infrastructure (OmanNet) connectivity. Open banking framework under development. Timeline: 9–14 months.
We maintain current working knowledge of each regulator's application process, current processing timelines, documentation requirements, and supervisory priorities. Applicants who engage their target regulator before submitting a formal application: to clarify scope, confirm capital structure acceptability, and preview AML programme design , consistently achieve better outcomes and shorter overall timelines than those who submit cold applications.
Discuss GCC licensing →European Licensing
Post-Brexit, a payments business serving both UK and EU customers requires separate regulatory authorisations: FCA authorisation in the UK and authorisation by a national competent authority within the EU (typically Ireland, Luxembourg, Lithuania, or the Netherlands for English-language operations). The two regulatory regimes have diverged since 2020: PSD2 remains the EU framework, with PSD3 and PSR now in final legislative phase; the UK has developed its own Payment Services Regulations 2017 amendment programme, with HM Treasury's PSR reform expected to complete in 2026.
UK: Financial Conduct Authority (FCA)
FCA authorisation as a Payment Institution or Electronic Money Institution is required for UK-based payment service activity. The FCA's authorisation process requires a detailed business plan, financial projections covering three years, governance documentation (including individual regulatory accountability under the Senior Managers & Certification Regime), AML/CFT programme documentation, IT security and operational resilience evidence, and safeguarding arrangements for customer funds.
- Authorised Payment Institution (API): full payment services permission
- Small Payment Institution (SPI): available for firms with monthly average transaction volumes below €3 million; registration rather than full authorisation
- Electronic Money Institution (EMI): required where the business model involves issuing e-money
- Senior Managers & Certification Regime: individual fitness and propriety requirements for all SMF holders
EU: Central Bank of Ireland and Other NCAs
Ireland remains the preferred EU authorisation jurisdiction for English-speaking payment firms post-Brexit, given the CBI's established process for payment institution applications, the depth of the Dublin fintech ecosystem, and EU passporting rights. Lithuania's Bank of Lithuania (Lietuvos bankas) offers a faster, lower-cost process suited to smaller firms and has processed a high volume of fintech authorisations. The choice of EU jurisdiction depends on target market, operational model, and appetite for regulatory relationship complexity.
- Payment Institution and Electronic Money Institution authorisation under PSD2 / PSD3
- EU passporting notifications: establishing branches or providing services on a cross-border basis in other EEA states
- AML/CFT programme design aligned with EBA guidelines and national transposition
- Governance structure: board composition, independent directors, compliance function requirements
The Authorisation Process: What to Expect
Successful payment institution authorisation is not primarily a legal or compliance exercise: it is a regulatory relationship management exercise in which the quality of the business plan, the credibility of the management team, and the rigour of the pre-application engagement with the regulator determine the outcome as much as the formal documentation. Regulators in all GCC and European jurisdictions prefer applicants who arrive having thought through their business model thoroughly and who can demonstrate that they understand the risks their proposed services create and have a credible plan to manage them.
Pre-application strategy
Define target licence category, assess capital requirements, map governance structure against fit-and-proper requirements, identify data localisation and outsourcing implications, and prepare pre-application briefing for regulator engagement.
Documentation preparation
Business plan, financial projections, governance framework, AML/CFT programme documentation, IT security and operational resilience evidence, safeguarding arrangements, and shareholder/UBO due diligence packages.
Supervisory engagement
Pre-application meetings with the licensing team, responses to information requests, and management of the regulator's questions and clarification process. This stage is where applications are most commonly delayed: experienced engagement management materially reduces timeline.
Conditions and implementation
Authorisation is typically granted subject to conditions: minimum capital deployment, AML system go-live, appointment of named individuals. Managing the conditions discharge process efficiently is the final step before trading commencement.
Post-authorisation compliance
Ongoing regulatory reporting, annual AML programme review, material change notifications, and supervisory visit preparation. Firms that maintain the quality of engagement with their regulator post-authorisation avoid enforcement action and build the relationship capital that supports future business model extensions.
Common application failure points: Incomplete UBO disclosure (complex ownership chains with unresolved beneficial ownership gaps), AML programme documentation that describes a future state rather than an implemented system, capital structure that does not meet the jurisdiction's minimum requirements at the time of assessment, and failure to address data localisation requirements. We review applications against these failure points before submission.
Regulatory Sandbox Support
Most GCC central banks and both the FCA and CBI operate regulatory sandbox programmes that allow fintech businesses to test innovative payment services under a controlled supervisory environment before applying for a full licence. The sandbox is particularly relevant for firms with novel business models: embedded payment platforms, BNPL providers, open banking aggregators, crypto-asset payment services , where the applicable licence category is not immediately clear or where the regulator's position on a specific activity has not yet been formally stated.
- SAMA FinTech Sandbox: open to payment fintechs testing new services in the Saudi market under temporary authorisation
- QCB Regulatory Sandbox: available for innovative payment services in Qatar; MENA Advisory is headquartered in Doha and has direct familiarity with the QCB sandbox process
- CBUAE RegLab: UAE sandbox with structured engagement process and defined testing parameters
- CBB FinTech Regulatory Sandbox: Bahrain's sandbox: one of the earliest in the GCC: offers a streamlined process for licensed testing ahead of full authorisation
- FCA Innovation Pathways: includes sandbox, direct support, and digital sandbox options for UK fintech applicants
Sandbox participation does not guarantee subsequent full authorisation, but firms that use the sandbox period to build their regulatory relationship, demonstrate operational capability, and refine their AML programme design are materially better positioned for the full application than those who approach authorisation cold.
Discuss sandbox strategy →Correspondent Banking Access
For cross-border payment businesses, licensing is a necessary but not sufficient condition for operation. Access to correspondent banking: the bank accounts and settlement relationships through which cross-border payments are executed , is equally critical and increasingly difficult to obtain. Global banks have reduced their correspondent banking exposure to money service businesses on de-risking grounds throughout the past decade; the number of accessible correspondents for new payment market entrants has contracted materially.
Securing correspondent banking access requires demonstrating to a prospective correspondent bank that the applicant has a credible AML programme, a realistic understanding of its customer base's risk profile, a viable business model with sustainable compliance spending, and management that the correspondent bank's compliance team can trust. The correspondent bank's decision is a commercial credit and compliance risk assessment, not an administrative process.
- Correspondent bank identification and prioritisation by corridor and currency
- Correspondent bank due diligence response preparation: AML programme summary, beneficial ownership documentation, management profiles, and compliance infrastructure evidence
- Commercial negotiation: account terms, transaction pricing, and operational connectivity
- De-risking contingency: alternative settlement structures where traditional correspondent access is unavailable: partner bank models, payment aggregators, and regional bank relationships
Ready to Start Your Authorisation Process?
MENA Advisory has supported payment institution licensing across QCB, SAMA, CBUAE, CBB, FCA, and Central Bank of Ireland. We work on the full cycle: from pre-application strategy through supervisory engagement to conditions discharge , and bring practitioner-level familiarity with each regulator's current priorities and documentation expectations. Speak with us before you start preparing your application.
Get in Touch