AISP Licence Explained: Requirements and Process in the UK

Introduction

An Account Information Service Provider (AISP) registration is the UK regulatory permission that allows a business to access and consolidate payment account information with a customer's explicit consent, without touching their money.

If you're building a fintech, an open banking product, a lending platform or an accounting tool in the UK, you need to know whether Financial Conduct Authority (FCA) registration is required before you launch.

Getting the regulatory perimeter wrong is expensive. Launching an unregistered regulated activity can mean enforcement action, forced product withdrawal and reputational damage with banking partners who won't touch an unlicensed counterparty.

AISP licensing is often named alongside open banking and PISP permissions, but the operational detail is rarely spelled out. This guide covers what the permission allows, the evidence the FCA expects, the application steps, where AISP registration stops being enough, and the mistakes that trip up applicants.

Key Takeaways

  • AISPs get consent-based, read-only access to account data; they cannot initiate payments or hold customer funds.
  • Whether registration is required depends on your actual activities, not just your use case or industry label.
  • Applications need evidence on governance, security, data protection, complaints handling and professional indemnity insurance.
  • Fees, forms and timelines change, so always confirm current requirements directly with the FCA before submitting.

What an AISP Licence Is and Why It Matters

An Account Information Service Provider (AISP) is a registered firm that pulls balance and transaction data from payment accounts a customer holds elsewhere. It presents that data back in a consolidated, usable form.

The data can be processed, analysed or passed to a third party, such as a lender, but only on the user's instruction. That is why the licence matters: without AISP registration, a firm cannot lawfully offer these open-banking data services in the UK.

Three parties sit in this chain: the customer, the AISP, and the account-servicing payment service provider (ASPSP), typically a bank or building society. The ASPSP must provide secure API access without discriminating against legitimate AISP requests, and it cannot demand a separate commercial contract as a condition of access.

Three-party AISP open banking data access relationship diagram

AISP vs PISP: The Key Difference

AISP and PISP permissions get bundled together constantly, but they authorise different things:

  • AISP: read-only access to consolidated account information.
  • PISP: initiates a payment order from the customer's account on their instruction.

Neither permission, on its own, lets the provider take custody of customer funds. A firm registered purely as an AISP cannot also run PISP activity under that same registration; it would need full payment institution authorisation instead. Always check the current FCA definitions directly, since terminology and scope get refined over time.

Common Use Cases

Typical AISP-driven products include:

  • Personal finance management dashboards that pull balances across multiple banks
  • Affordability and credit assessment tools used by lenders
  • Accounting feeds that sync transaction data into bookkeeping software
  • Consent-based identity or income verification

None of these use cases automatically confirm the regulatory outcome. The actual data flow and customer relationship decide whether registration is required, not the product category.

AISP Requirements and Eligibility Factors

The Regulatory Perimeter Test

Map exactly what your business does with account data: what you collect, display, analyse, store, share, and for what purpose. If you access a customer's payment account and present consolidated information back to them (or to a party they've instructed), you're likely inside the regulated perimeter.

Core Application Evidence

The FCA typically expects a complete application pack covering:

  • A programme of operations and detailed business plan
  • Organisational structure, governance arrangements and clear lines of responsibility
  • Details of qualifying shareholders, directors and individuals managing the business
  • A wind-down plan and financial projections

Confirm the exact current checklist against the FCA's own published guidance, since documentation requirements are periodically updated.

Insurance, Security and Data Protection

Regulation 18 of the Payment Services Regulations 2017 requires professional indemnity insurance (or a comparable guarantee) covering liability to ASPSPs and users for unauthorised or fraudulent account access. There is no single universal minimum figure. The FCA directs firms to calculate cover using its specified guidelines and submit the proposed policy terms for assessment.

On security, applicants need to demonstrate:

  • Access controls, encryption and secure API integration
  • Authentication processes aligned with FCA technical standards
  • Incident detection and reporting procedures (notifiable to the FCA without undue delay)
  • Business continuity and outsourcing oversight

Under regulation 70 of the Payment Services Regulations 2017, an AISP must identify itself in every communication session and access only designated accounts. It may use the information solely for the service the customer explicitly requested.

Customer consent under payment services rules does not replace a proper UK GDPR lawful basis for processing personal data. Document that basis in a clear privacy notice and provide an easy withdrawal mechanism.

Conduct and Ongoing Controls

Registration is only the start. Ongoing obligations typically include:

  • Complaints handling that meets FCA expectations
  • Senior-management accountability and clear ownership of controls
  • Timely regulatory reporting and incident notifications

These continuing duties are covered in more detail further below.

The FCA AISP Application Process

  1. Define the service and confirm the permission needed. Decide whether your model needs AISP registration, a different payment-services permission, or authorisation through a regulated partner. Specialist legal advice is worth the cost here if the perimeter looks unclear.
  2. Build a regulatory gap analysis. Map your business model, customer journey, data flows, third-party providers, governance, security and insurance arrangements against FCA expectations.
  3. Prepare the application pack. Pull together the programme of operations, business plan, financial information, ownership details, policies, risk assessments, security documentation and insurance evidence.
  4. Submit and pay the fee. The current initial application fee for AIS-only (RAISP) registration is £1,130, under category 3 of the FCA's fee schedule. That figure is separate from ongoing periodic fees.
  5. FCA assessment. The regulator tests whether your proposed activities are clearly defined, whether controllers and managers are fit and proper, and whether your systems and controls are adequate for the activity proposed.
  6. Post-submission and post-registration actions. Respond promptly to FCA information requests, notify material changes, and maintain your insurance and controls once registered.

Six-step FCA AISP registration application process timeline

The FCA states that a complete application is usually assessed within three months. An incomplete one can take up to 12 months. That three-month clock starts from a completed application, not from opening a Connect account: incomplete submissions are the single biggest cause of delay.

Where AISP Registration Applies and When It Is Not Enough

AISP registration usually covers:

  • Account aggregation and multi-bank dashboards
  • Personal or business finance management tools
  • Consent-based transaction analysis for underwriting
  • Accounting software integrations pulling bank feeds
  • Certain affordability assessment workflows for lenders

AISP registration stops being enough the moment your business does more than view and present data. If you initiate payments, hold or safeguard customer funds, issue payment instruments, or provide any other regulated payment service, you'll need to assess PISP, payment institution, e-money or another permission entirely.

There's also a subtler trap: using a regulated AISP technology or connectivity provider is not the same as operating as the regulated AISP yourself. Outsourcing the technical API connection can reduce your build effort considerably, but it doesn't transfer your regulatory responsibility.

If your business is the one facing the customer and presenting the consolidated information, you likely still need your own registration — even if a third party handles the plumbing.

AISP registration scope and regulatory responsibility comparison

Common Issues and Misconceptions

A few assumptions and weak spots catch applicants out repeatedly:

  • "Every business using bank-data APIs needs its own AISP registration." Not necessarily — it depends on the service, the contractual model and who's actually customer-facing. Some models genuinely sit behind a registered partner.
  • "AISP access permits moving money." It doesn't. Read-only account information access is entirely separate from payment initiation, and your consent flow must match what the business actually does.
  • Weak application pack basics. The FCA repeatedly flags thin packs, especially:
    • Vague service descriptions and incomplete data-flow maps
    • Thin outsourcing controls and missing incident procedures
    • Insurance that does not match the real business model
  • Treating registration as a one-off event. Governance, security, data protection, complaints handling and reporting all need maintaining as your user base, data sources and suppliers evolve.

Conclusion

UK AISP registration fits a specific, narrow activity: consent-based, read-only access to account information. It suits only services that genuinely sit within that perimeter. You also need solid governance, security, data protection and complaints arrangements before you apply.

For UK businesses also setting up or operating in India alongside open banking or fintech work, VJM Global supports the business setup, accounting, tax and compliance side of that expansion. That includes entity formation, bookkeeping, FEMA/FDI advisory and ongoing tax filings.

This is separate from, and no substitute for, FCA authorisation or AISP registration. Those must go through the FCA directly or specialist UK regulatory counsel.

Frequently Asked Questions

What is AISP and PISP?

AISP provides read-only access to consolidated account information with customer consent. PISP initiates payments from a customer's account on their instruction. They are distinct permissions, so a business must assess which one, or both, matches its actual activity.

Do I need an AISP licence in the UK?

It depends on whether your business provides regulated account information services, which requires mapping your data flows and customer journey. Check the FCA's current perimeter guidance and get professional advice if the answer isn't obvious.

What are the requirements for an AISP licence in the UK?

You must evidence your business model, programme of operations, governance, management suitability, security and data protection controls, complaints procedures, and professional indemnity insurance.

How long does an AISP application take in the UK?

The FCA says a complete application is usually assessed within three months, but incomplete submissions can take up to 12 months. Always check the FCA's current indicative timetable before planning your launch date.

Can an AISP initiate payments?

No. AISP activity is limited to account information access. Initiating payments requires separate PISP or payment institution permission, or an appropriately authorised partner arrangement.

What happens after an AISP is registered?

Ongoing obligations include maintaining insurance and security controls, handling complaints under FCA rules, protecting personal data, reporting incidents without undue delay, and keeping your FCA record accurate as your business changes.