Market · In-house legal talent

FinTech and payments regulatory lawyers: the seat your screen discards.

A supervisor-facing payments or e-money lawyer without a City transactional pedigree is the profile most in-house hiring committees pass over. Four live files say that is the wrong call, and the cost of the mistake arrives as supervisory correspondence.

Hire in-house counsel Submit your CV
01 Start here

Which of these four files is already on your desk?

Across 750 structured interviews with London legal buyers, 118 respondents sat inside payment and e-money institutions, and none of them arrived with an abstract question. They arrived asking who inside the company owns payments compliance when the supervisor writes. Pick the lens that matches the letter, the audit or the requisition in front of you.

Lens 01 · The named owner The rulebook now asks for a person, not a policy.

FCA Policy Statement PS25/12, published 7 August 2025 and in force from 7 May 2026, requires a single director or senior manager with sufficient skill and authority to own safeguarding compliance and report annually to the governing body. An accountability, not a workstream.

Each lens is one file inside a single job. All four are mapped in section 03.

7 May 2026
FCA supplementary safeguarding regime in forceAnnual external audit, monthly returns, 48-hour resolution pack
FCA PS25/12, 7 August 2025
65%
Average customer money lost at failed payment and e-money firmsFirms that failed Q1 2018 to Q2 2023
FCA, 7 August 2025
18 months
Payment Services Regulation application, after entry into forcePayee-name verification at 24 months; texts agreed 23 April 2026
Norton Rose Fulbright, 2026
50:50
APP fraud reimbursement cost split, sending and receivingLive 7 October 2024; capped at £85,000 per claim
Osborne Clarke, 6 September 2024
02 The screen

The candidate the shortlist discards, and the file nobody inherits.

The rejection is rarely explicit. It happens at the first filter, where a hiring committee reads two resumes and reaches for the one with the recognizable firm on it.

Two lawyers reach the second round for the same in-house payments seat. The first trained at a City firm, spent four years on acquisition finance, and moved into a bank-owned payments business eighteen months ago. The second qualified into a financial-services regulatory practice, has never closed a financing, and has spent six years writing authorization applications, answering supervisory correspondence and sitting through safeguarding audits at payment and e-money institutions. The committee takes the first. It almost always takes the first. The pedigree is legible, the second resume is not, and no one in the room can price the difference between them.

Our quarterly survey of London in-house legal buyers, running since 2019, read 97 job specifications for payments or e-money seats across its four most recent waves. In 62 of the 97, the pedigree filter was written into the document itself: a named tier of training contract, a City firm, or a phrase to the same effect. Only 21 of the 97 asked for evidence of a regulator-facing file — an authorization, a supervisory response, an audit finding closed. The document that will be used to grade the shortlist is, in most cases, screening for the wrong thing before a single resume arrives.

The buyer’s question is not who has the better training. It is who owns four things when they land at once: a PSD3 and Payment Services Regulation readiness file, a safeguarding and wind-down plan, an open-banking access dispute and a fraud-liability allocation. That list is not a practice area. It is a set of deliverables with dates attached, and a company that grades the seat on pedigree discovers the gap the first time a regulator writes and the person who has to reply has never done it.

What the screen readsWhat the file demands

  1. Pedigree Firm name, training contract, deal list. Legible in ninety seconds and correlated with drafting speed on documents this seat does not produce.
  2. Adjacency Financial services somewhere on the resume. Banking, funds, capital markets, digital assets. Comfortable with the vocabulary, untested against a supervisor.
  3. Supervisory ownership A named owner who has filed, answered, been audited and been found wanting, and who closed the finding. Illegible on paper, decisive in the seat.

Why the label itself defeats the search

Part of the failure is mechanical. There is no single practice name to search for. Chambers UK 2026 ranks this work under two separate categories, Financial Services: Payments Law and FinTech Legal: Payments and Lending, and the firms themselves do not converge either: Travers Smith brands its team Fintech, Market Infrastructure and Payments, while CMS serves payments work from inside a broader financial-services regulatory bench rather than a standalone payments group. A search built on the phrase a company happens to use will miss the practitioners filed under the other three.

The second reason is that these are not scaled-down banks. The European Banking Authority’s register, as tracked by Helms Advisory on 7 July 2026, recorded 1,003 authorised payment institutions and 422 e-money institutions across the European Economic Area, and they sit outside the Senior Managers and Certification Regime. Linklaters reported in October 2021 that individuals responsible for payment services are instead treated as PSD or EMD Individuals under a lighter framework, and that extending the regime would require Treasury consultation and legislation. The internal accountability map a bank lawyer takes for granted does not exist here, which is why the safeguarding rulebook has stepped into the gap and named a single senior owner itself.

A hiring committee that has only ever bought bank-shaped lawyers reads that as a downgrade. It is closer to the opposite. A bank has three lines of defense and a regulatory affairs function to absorb a supervisory letter. A payment institution with 200 staff has a head of legal, a compliance lead, and a board that will ask both of them the same question in the same meeting.

A pedigree is legible in ninety seconds. A closed supervisory finding is not, and only one of the two answers the letter.
On the first filter
03 The four files

Four deliverables, four dates, and not a financing among them.

Each of these arrived on a public date with a public instrument behind it. Together they are the job. Separately, each one is the reason a requisition that was written as a finance seat comes back open.

Start with safeguarding, because it is the one already binding. The FCA published Policy Statement PS25/12 on 7 August 2025 and its supplementary regime took effect on 7 May 2026, in a new chapter of the client-asset sourcebook, CASS 15. Ashurst set out the operative pieces: a resolution pack, distinct from an existing wind-down plan, retrievable within 48 hours, plus monthly safeguarding returns due within 15 business days of month-end. Norton Rose Fulbright added in March 2026 that firms holding more than £100,000 of relevant funds need an annual independent audit, and that the FCA estimated the exemption below that threshold covers about 23 percent of payments firms that hold funds.

The reason the regulator moved is in the same 7 August 2025 announcement: payment and e-money firms that failed between the first quarter of 2018 and the second quarter of 2023 lost, on average, 65 percent of the customer money they were required to safeguard. That is a prudential failure rate, and it explains the FCA warning reported in its March 2026 payments priorities, that it expects an initial increase in adverse safeguarding-audit opinions once the regime beds in. An adverse opinion is a document with a company’s name on it, and somebody in-house has to have written the response before the board reads it.

Sortable. The four workstreams that make up the perimeter of this seat, the dated instrument behind each, and the misreading each one attracts on a pedigree-first shortlist.
File Dated trigger What the owner actually does What a transactional screen sees
PSD3 and Payment Services Regulation readiness Provisional agreement 27 November 2025; final texts agreed 23 April 2026; Regulation applies 18 months after entry into force Authorization gap analysis against the new categories, re-application inside the 24-month grandfathering window, contract and liability remapping, Strong Customer Authentication scope A directive on a slide, filed under regulatory change and assigned to whoever is free
Safeguarding and wind-down FCA PS25/12 published 7 August 2025; supplementary regime in force 7 May 2026 Named senior owner, annual external audit, monthly returns, daily reconciliation policy, 48-hour resolution pack, third-party diversification Client money, treated as a finance-team control rather than a legal obligation with an audit opinion attached
Open banking access and API disputes FCA Feedback Statement FS25/4, 8 August 2025; PSD3 documented-justification duty before restricting third-party access Access terms, refusal justifications, dispute correspondence with third-party providers, re-authentication cycles A product and engineering matter, escalated to Legal only after a provider complains
Fraud-liability allocation Mandatory reimbursement live 7 October 2024, cap £85,000, cost split 50:50 between sending and receiving providers Reimbursement determinations, excess policy, vulnerable-customer carve-outs, receiving-side claims and their evidence trail An operations queue with a service-level target, not a liability the company allocates

The legislative file, with its stage attached

PSD3 and the Payment Services Regulation are a package in train. Norton Rose Fulbright’s 2026 account of the file records provisional political agreement on 27 November 2025, final versions agreed by the three institutions on 23 April 2026, and Official Journal publication expected towards the end of the second quarter of 2026 with a possible slip to September. Regulation Tomorrow reported COREPER’s endorsement of the trilogue compromise texts on 22 April 2026, and the European Parliament’s own legislative record shows the ECON Committee approving the agreed text on 5 May 2026. On the same Norton Rose Fulbright reading, the Regulation then applies 18 months after entry into force, the payee-name verification obligation and its liability regime at 24 months, and PSD3 must be transposed by member states within 18 months. None of it is in application today.

What makes it a hiring question rather than a diary entry is the grandfathering term. On the same reading, existing payment and e-money authorizations stay valid for 24 months, extendable to 30, and inside that window a firm must re-apply and demonstrate PSD3 compliance to keep its license: an authorization project with a company’s permission to operate at the end of it. Linklaters noted that the European Banking Authority is expected to issue roughly forty implementation mandates, with a roadmap due in the second quarter of 2026, so the detail lands progressively rather than in one release.

The substance is not neutral for headcount either. On Freshfields’ reading of 4 May 2026, the agreed package brings impersonation fraud into scope with a duty to refund in full unless the provider proves consumer fraud or gross negligence, requires payee-name verification before execution with a refund obligation on mismatch, extends Strong Customer Authentication to tokenized-instrument creation and contact-detail changes, requires account information services to re-authenticate consumers every 180 days, and requires banks to give documented justification before restricting third-party access. Every one of those is a policy, a contract change and a customer-facing disclosure, and each is drafted by somebody.

Fraud allocation is an operating file, not a policy position

The UK mandatory reimbursement regime went live on 7 October 2024. Osborne Clarke recorded in September 2024 that the maximum had been cut from the proposed £415,000 to £85,000 per claim, that sending providers may apply an excess of up to £100, and that the cost is split evenly between sending and receiving provider. The evenness is what changes a legal function: a company is on both sides of the ledger, paying as a sender and defending as a receiver, and somebody sets the policy for both.

The volumes are public. The Payment Systems Regulator’s reimbursement dashboard, covering the eighteen months to 31 March 2026, recorded 82 percent of first-quarter 2026 claims resolved within five business days. The independent evaluation by Frontier Economics, published by that regulator on 1 July 2026, found losses on Faster Payments down by an estimated £73 million a year and roughly 35,000 fewer scam cases, with the reimbursement rate rising from 54 percent to 65 percent — and, in the same release, that implementation remains inconsistent across firms, with a consultation promised before the end of 2026. Inconsistency across firms means the determination sits with an individual company, and that the company is being watched while it makes it.

The backdrop is not shrinking. UK Finance’s Annual Fraud Report 2026, as reported by Neopay on 22 June 2026, put total UK payment fraud losses at £1.28 billion in 2025, of which authorised push payment fraud accounted for £576.4 million across 248,070 cases. A general counsel who has never had to write a reimbursement policy is about to.

Authorised push payment claims under the UK mandatory reimbursement regime, over the eighteen months to 31 March 2026: the gap between claims reported and claims that qualified is the space in which an in-house determination is made.

Payment Systems Regulator, APP scams reimbursement dashboard, data to 31 March 2026.

The open-banking file has no referee

The fourth file is the one buyers most often assume belongs to somebody else. The FCA published Feedback Statement FS25/4 on 8 August 2025 setting the design of the Future Entity that will replace Open Banking Limited as the standards-setter for UK open-banking interfaces: a not-for-profit company limited by guarantee covering common API standards, performance monitoring, certification and a directory, and — the line that matters here — no independent enforcement powers. A standards body without enforcement powers does not settle a dispute between an account-holding institution and a third-party provider. The parties settle it, and the person drafting the refusal justification is in-house. PSD3’s documented-justification duty then turns that decision into evidence: a company that has declined access requests informally for four years needs a lawyer who can reconstruct why, and write the next one so it survives being read back.

04 Where the seat sits

Four employer shapes, and the one your job specification assumes.

The same four files report to four different places depending on who is buying. Every shape fails differently, and the shape decides what the hire can actually reach.

Six employer postings read in September 2026 show a consistent pattern, and it is not the pattern most job specifications assume. Where payments is the whole business, it gets its own legal or regulatory line with a director above it. Where payments is one product inside a bank, it shares a legal team with retail and wealth. And in at least one large e-money business the function is owned by Compliance rather than by Legal, which changes who the supervisor speaks to — a chief compliance officer rather than a general counsel — and who is in the room when the audit opinion lands.

Held by LegalHeld by Compliance

  1. Dedicated legal sub-line Payments has a director of legal of its own, with counsel underneath. The file has an owner, a budget and an escalation path that ends in the general counsel.
  2. Shared legal bench Payments sits inside a combined banking team. The lawyer is competent and outnumbered; the supervisory file competes with three other businesses for the same hours.
  3. Compliance-owned function The regulatory relationship runs through Risk and Compliance, spanning product and treasury. Legal reviews the output and does not hold the pen. Neither shape is wrong; only one matches your specification.
01

Monoline payment or e-money institution

Payments has its own legal sub-line. A Monzo posting read in September 2026 placed a senior legal counsel for digital assets and payments under a director of legal for payments and business banking, asking for five years of relevant experience rather than generic City time.

02

Large non-bank acquirer or processor

A layered in-house structure. Checkout.com advertised a legal counsel for product and regulatory reporting to an associate general counsel in London at three to seven years, with payments experience marked desirable, not essential.

03

Bank-owned payments arm

The opposite structure. NatWest runs a combined banking and payments legal team covering retail, private banking and wealth, so the supervisory file shares a bench with three other businesses and competes with them for attention.

04

Compliance-owned function

The fork a pedigree screen never sees. Wise advertised a regulatory compliance manager for its UK e-money business inside a team spanning risk, legal, product and treasury, naming the 2017 payment services rules and the 2011 e-money rules as the working framework.

The comparison the requisition never makes

The same perimeter under three reporting structures, with the failure each one produces first when the seat is filled against the wrong assumption.
Employer shape Where the supervisory file reports What breaks first
Monoline payment or e-money institution A payments-specific legal line, escalating to the general counsel Bandwidth. One or two lawyers hold four files and every product question in the building
Bank-owned payments arm A combined banking and payments legal team serving several businesses Priority. The safeguarding calendar loses to whichever business is loudest that quarter
Compliance-owned function Risk and Compliance, alongside product and treasury Visibility. Legal learns the audit finding after the auditor has written it

Dublin and Frankfurt are separate seats, and the license map says why

A London head of legal cannot carry a European entity from a distance, because neither regulator will let the governance sit abroad. The Central Bank of Ireland’s authorization pages, as they stood in September 2026, require decision-making at board and executive level to take place within the State, with the assessment covering business model, governance, risk management including safeguarding, anti-money-laundering controls and resolution planning. The same pages publish a three-stage framework with a service standard of completing the assessment stage within 90 business days for 90 percent of cases, and state in the same breath that it can take firms over twelve months to provide all the necessary information. That is a hiring timetable disguised as a process note.

Germany is a separate procedure and a separate relationship. BaFin authorizes payment institutions under section 10 of the Zahlungsdiensteaufsichtsgesetz and e-money institutions under section 11, and its supervisory attention has moved toward payments specifics: Risks in Focus 2026, published on 28 January 2026, names payment-service-provider safeguarding controls as an escalating concern and announces more than 75 special anti-money-laundering inspections for the year. On 27 July 2026 it issued Supervisory Notice 06/2026 on virtual IBANs, tightening transparency expectations for master-account banks, payment and e-money institutions and banking-as-a-service providers — effective immediately, and superseded when the EU Anti-Money Laundering Regulation applies from 10 July 2027, per PwC Legal Germany’s account of 3 August 2026.

The euro-area calendar adds one entry that lands on this employer type rather than on banks. Under the Instant Payments Regulation, as set out by the European Central Bank, euro-area payment institutions and e-money institutions must be able to send instant credit transfers from 9 April 2027, with non-euro-area providers following on 9 July 2027 — later than the date banks worked to, and inside the window in which the PSD3 re-application has to be made.

Where payment and e-money licenses actually sit in the European Economic Area, by count of licensed institutions per country. The distribution explains why a European entity build is a Vilnius, Dublin or Frankfurt conversation before it is a London one.

European Banking Authority register as tracked by Helms Advisory, 7 July 2026.

Neither Dublin nor Frankfurt accepts governance at a distance. That is two hires described in the budget as one.
On the European build
05 Why it stays open

The requisition is not short of candidates. It is pointed at the wrong ones.

Our London in-house book is small enough to read case by case, and the payments segment inside it behaves differently from the rest of the market we cover.

Sartori has worked the London in-house market for more than 10 years. Our mandate telemetry across the trailing three years records 24 closed in-house searches in this city, with a completion rate of 93 percent, counter-offer incidence of 32 percent, and a median of 13 working days between offer and signature. Typical timelines run four to seven months. Of those 24 mandates, 9 carried a payments or e-money regulatory perimeter, and in 6 of the 9 the lawyer hired had never held a City transactional seat. Three of the nine ran into a counter-offer, which is the book’s own rate rather than an exception to it, and none of them moved the median from offer to signature.

The interview record says the same thing from the buyer’s side. Across the 750 structured interviews that make up our London cohort, 118 respondents sat inside payment and e-money institutions in legal or compliance roles. Over a rolling 24-month window, 74 of those 118 said no single named individual had owned the safeguarding file before the rulebook required one, and 41 of the same 118 — heads of legal and general counsel, not compliance managers — said their most recent regulatory requisition had been graded against a transactional pay comparator drawn from a different function.

A general counsel at a London e-money institution told us that the first external safeguarding audit was the first document a non-executive director had ever asked her to walk through line by line, and that she had built the response with an outside firm because nobody internal had done one. The head of legal at a bank-owned payments arm described the same requisition being re-graded twice, once as a financing seat and once as a regulatory one, with two salary bands between the versions and no change at all to the work described underneath.

The number that does not flatter us

Two of those 9 payments-perimeter mandates ran past the seven-month upper edge of our own typical timeline, and both did so for the same reason: the buyer needed in-country governance in Dublin or Frankfurt and we spent the extra weeks on residency and language rather than on legal capability. There is a second and more uncomfortable gap. We map roughly 30,000 lawyers in London, and a compliance-titled owner of a safeguarding file is frequently not one of them, because our map is a map of lawyers. In the employer shape where this function reports into Compliance, our coverage is at its thinnest exactly where the decision-maker sits. We say so to buyers at the outset, and it is the reason those searches start with a mapping exercise rather than a shortlist.

Three engagements, as they actually ran

  • A monoline e-money institution, roughly 240 staff, head of legal Two prior attempts had failed against transactional shortlists. We rebuilt the brief around the four files and closed in five months. The lawyer hired came from a financial-services regulatory practice, had run two external safeguarding audits and drafted one wind-down plan, and had never worked on a financing. One counter-offer, declined. Signature came inside the 13-working-day median our London book records.
  • A bank-owned payments arm, senior counsel inside a combined legal team The requisition had been open with an internal talent team for four months against a finance-seat grade. Re-scoped to a supervisory brief, it closed at the seven-month edge of our four-to-seven-month window, and the delay was entirely internal: the grade had to be moved before an offer could be made to anyone the brief now described.
  • A private-equity-backed acquirer building a second European entity The company assumed its London head of legal could carry the new entity. Authorization governance requirements meant it could not. We placed one lawyer in-country and left the London seat unchanged. The mandate is in the 24 closed searches; the two months it lost were spent proving to the board that the original plan was not available.
Our coverage is thinnest exactly where this function reports into Compliance, because we map lawyers and the owner may not be one.
On what the map misses
06 Grading the seat

Grading a payments compliance seat when no published band exists.

Two decisions sit in front of the buyer: what the seat is worth, and how to test whether a candidate can hold it. Neither is answered by a market report, because for this seat there is not one.

The honest starting point is an absence. There is no published compensation band for an in-house payments regulatory lawyer, in London or anywhere else. What is published is private-practice entry pay: Legal Cheek reported Quinn Emanuel raising newly qualified pay to £189,000 in June 2026, Macfarlanes matching the magic circle at £150,000 and DLA Piper moving to £140,000 in July 2026, and Eversheds Sutherland to £120,000 that same month. Those are firm-wide scales for lawyers at the start of their careers. Reaching for them to price a supervisory seat imports a number attached to the wrong job, and it is how a requisition ends up two bands away from the work it describes.

The workable alternative is to price the perimeter. Decide which of the four files the seat owns outright, which it shares and which it only reviews, then grade against the internal role that already owns comparable regulatory exposure — which in most payment institutions is a risk or compliance director rather than a commercial counsel. That comparison is internal, defensible in a remuneration committee, and does not depend on a market survey that does not exist.

The cost of getting it wrong is on the public record, and it is rarely a fine. Grant Thornton reported on 11 November 2025 that in an FCA multi-firm review only half of the payment service providers examined met Consumer Duty expectations. The FCA fined CB Payments Ltd £3,503,546 on 25 July 2024 in its first action under the 2011 e-money regulations, after the firm onboarded 13,416 high-risk customers in breach of a voluntary requirement and the failure ran undetected for close to two years. More typically, it acts by restriction: a First Supervisory Notice against BeAccount Ltd on 17 December 2025 required that firm to stop services, return customer funds and notify every customer within a week. A restriction is not a line in an enforcement table. It is a business stopping.

Sortable. Six interrogation points this desk uses on a payments regulatory shortlist, with the employer type each one separates hardest.
Evidence point The question to ask Separates hardest for
The audit opinion Walk me through the last external safeguarding audit you were in the room for. What was the finding, and what did you change? Every payment and e-money institution above the threshold
The supervisory letter Show me a piece of correspondence you drafted to a regulator that answered a finding rather than acknowledged it. Firms with an open supervisory file
Reimbursement judgment Describe a reimbursement determination you refused, and how the receiving-side claim against you was handled. Anyone in the UK Faster Payments perimeter
Authorization work Which variation, notification or new authorization have you filed, and how long did it sit with the regulator? Firms building an EU or UK entity
Wind-down literacy What is in your resolution pack, and who retrieves it if you are unavailable for 48 hours? Post-7-May-2026 UK firms
Second jurisdiction Have you carried a file in front of a regulator other than the FCA, and in which language? Dublin, Frankfurt and multi-entity builds

Write the specification from the four files, then grade it against the internal role that already carries comparable regulatory exposure.

  • Name the owner before you write the ad. The safeguarding rulebook already requires a single senior individual; decide whether that is the hire, the hire’s manager, or somebody in Compliance the hire will never manage.
  • Delete the pedigree line. In 62 of 97 job specifications we read across four survey waves it was doing the screening, and it screens for drafting speed on documents this seat does not produce.
  • Ask for one closed finding. An audit finding, supervisory response or authorization variation the candidate personally carried is worth more than a deal list, and takes one question to test.
  • Budget the second entity separately. Dublin and Frankfurt governance requirements make a European build two hires, and the authorization clock runs in months rather than weeks.
  • Decide the fraud policy owner now. A 50:50 liability split means the company is a claimant as well as a payer, and the position needs an author before the next claim arrives.

Your value is a file you carried in front of a regulator. Most resumes bury it under a practice-area label the buyer does not search for.

  • Lead with the supervisory artifact. The audit you answered, the notice you responded to, the authorization you filed. Put it above the firm name, which is what gets you compared to a financing lawyer.
  • Name the four files explicitly. A resume that says financial services regulatory is read as adjacency. One that says safeguarding audit, wind-down plan, access dispute and reimbursement determination is read as ownership.
  • Say which side you sat on. Sending or receiving in a fraud allocation, account-holding institution or third-party provider in an access dispute. Buyers screen on it and rarely ask.
  • Decide whether you are a fintech lawyer or an entity lawyer. One follows the product across borders; the other holds a license in one jurisdiction and cannot be moved without breaking it.
  • Explore quietly. A no-names search that circulates nothing without consent protects your seat while you test whether the perimeter on offer is real.

Common questions about hiring payments regulatory counsel

Who owns payments compliance inside a payment institution, Legal or Compliance?

Both shapes are live. Across six employer postings read in September 2026, monoline firms gave payments its own director-led legal sub-line; one large e-money institution ran it from Compliance. The distinction decides who answers the supervisor. Where the function is Compliance-owned, a head of legal often has no line of sight into the safeguarding file until an audit opinion arrives. Where it is Legal-owned, the risk runs the other way: a lawyer holds the file without the operational reporting that would let him verify the reconciliation underneath it. Settle which one you are hiring into before the job specification is written.

What does PSD3 require, and when does it actually apply?

PSD3 and the Payment Services Regulation are not in force. Provisional political agreement was reached on 27 November 2025, and the Regulation applies 18 months after entry into force. The three institutions agreed final versions on 23 April 2026 and the ECON Committee approved the agreed text on 5 May 2026, with Official Journal publication expected around mid-2026 on Norton Rose Fulbright’s reading. On Freshfields’ account of 4 May 2026 the package brings impersonation fraud into scope, adds a payee-name verification duty with a refund obligation on mismatch, and extends Strong Customer Authentication. Existing authorizations are grandfathered for 24 months, extendable to 30, and a firm must demonstrate compliance inside that window to keep its license.

What changed on 7 May 2026 for safeguarding, and why is it a hiring question?

The FCA’s supplementary safeguarding regime took effect that day, adding annual external audits, monthly returns and a resolution pack retrievable within 48 hours. Policy Statement PS25/12, published on 7 August 2025, also requires a single director or senior manager with sufficient skill and authority to own safeguarding compliance and report annually to the governing body. That is a rulebook naming an individual inside your company, and most firms found on publication that they did not have one. Norton Rose Fulbright reported in March 2026 that the audit obligation bites above £100,000 of relevant funds.

Is a City finance associate a substitute for a payments regulatory lawyer?

Rarely. Of the 24 closed London in-house mandates on our three-year record, 9 carried a payments perimeter, and 6 of those went to lawyers with no City transactional seat. A financing associate has drafted facilities, security packages and intercreditor terms. None of those is a safeguarding reconciliation, a resolution pack, an authorization variation or a reimbursement determination under a 50:50 liability split. The overlap is real at the level of financial literacy and absent at the level of the files.

What does this seat pay in London, and is there a published band?

No published band exists for this seat. The dated London figures published in 2026 are firm-wide newly qualified scales running from 120,000 to 189,000 pounds. Those are private-practice entry grades reported by Legal Cheek through 2026, describing a different population. Grade this seat on the perimeter it inherits, then price it against the internal role that already carries comparable regulatory exposure.

Do Dublin and Frankfurt seats duplicate the London one?

No. Both are separate legal-entity governance roles. The Central Bank of Ireland requires board and executive decision-making within the State; BaFin authorizes under two separate ZAG sections. The Irish authorization pages, as they stood in September 2026, assess governance, safeguarding, financial-crime controls and wind-down planning in-country. Germany runs payment institutions under section 10 and e-money institutions under section 11 of the Zahlungsdiensteaufsichtsgesetz, so a Frankfurt seat answers a different regulator, in German, under a different statute. A European build is two or three hires, not one.

07 Sources

The rulebook chapters, the regulator dashboards, the supervisory notices and our own London telemetry.

Dates and mechanics come from the FCA, the Payment Systems Regulator, the Central Bank of Ireland, BaFin, the European Central Bank and the European Parliament. Legislative stage comes from law-firm alerts carrying their own publication dates. Pay figures are private-practice scales from the legal press.

Sources & further reading

39 references
  1. Sartori & Partners — London Legal Talent Research Programme (750 structured interviews; ~30,000 lawyers mapped; quarterly surveys since 2019; mandate telemetry) sartoriglobal.com ↗
  2. FCA — PS25/12: Changes to the safeguarding regime for payments and e-money firms fca.org.uk ↗
  3. FCA — Payment firms told to strengthen safeguarding of customer money (7 August 2025) fca.org.uk ↗
  4. FCA — Safeguarding requirements for payment institutions and electronic money institutions fca.org.uk ↗
  5. Norton Rose Fulbright — Preparing for the FCA's New Safeguarding Rules: A Countdown to 7 May 2026 nortonrosefulbright.com ↗
  6. Ashurst — UK e-money and payment institutions must comply with new safeguarding rules from 7 May 2026 ashurstperkinscoie.com ↗
  7. Norton Rose Fulbright — PSD3 and PSR: From provisional agreement to 2026 readiness nortonrosefulbright.com ↗
  8. Freshfields — PSD3/PSR: What the EU's new payments rules mean for your business (4 May 2026) freshfields.com ↗
  9. European Parliament — Legislative Train Schedule: revision of EU rules on payment services europarl.europa.eu ↗
  10. Linklaters — Payments in 2026 #3: PSD3 financialregulation.linklaters.com ↗
  11. Regulation Tomorrow — Council issues 'I' Item Note on PSD3 (23 April 2026) regulationtomorrow.com ↗
  12. Payment Systems Regulator — APP scams reimbursement dashboard (data to 31 March 2026) psr.org.uk ↗
  13. Payment Systems Regulator — Payment fraud falls by £73m following PSR reimbursement scheme (1 July 2026) psr.org.uk ↗
  14. Osborne Clarke — Mandatory reimbursement for UK authorised push payment fraud: the countdown (6 September 2024) osborneclarke.com ↗
  15. Neopay — UK Finance Fraud Report 2026: payment fraud losses reach £1.28 billion (22 June 2026) neopay.co.uk ↗
  16. FCA — FS25/4: Design of the Future Entity for open banking (8 August 2025) fca.org.uk ↗
  17. Norton Rose Fulbright — HM Treasury responds to consultation on merging Payment Systems Regulator functions into the FCA (7 May 2026) nortonrosefulbright.com ↗
  18. FCA — First enforcement action against a firm enabling cryptoasset trading (25 July 2024) fca.org.uk ↗
  19. CMS — FCA First Supervisory Notice: BeAccount Ltd cms.law ↗
  20. Regulation Tomorrow — Regulatory priorities report: payments (25 March 2026) regulationtomorrow.com ↗
  21. Linklaters — FCA suggests applying the Senior Managers Regime to e-money and payments firms (21 October 2021) financialregulation.linklaters.com ↗
  22. Central Bank of Ireland — Electronic Money Institutions centralbank.ie ↗
  23. Central Bank of Ireland — Payment authorisation centralbank.ie ↗
  24. BaFin — Payment services and PSD2: authorisation procedure and ongoing supervision bafin.de ↗
  25. BaFin — Risiken im Fokus 2026 (28 January 2026) bafin.de ↗
  26. PwC Legal Germany — BaFin tightens compliance requirements for virtual IBANs (3 August 2026) legal.pwc.de ↗
  27. European Central Bank — Instant Payments Regulation ecb.europa.eu ↗
  28. Helms Advisory — EU EMI and Payment Institution Register by country (7 July 2026) helmsadvisory.com ↗
  29. Grant Thornton — Top themes for the payments sector in 2026 (11 November 2025) grantthornton.co.uk ↗
  30. Travers Smith — Fintech, Market Infrastructure and Payments practice traverssmith.com ↗
  31. CMS — Payments expertise cms.law ↗
  32. Monzo careers — Senior Legal Counsel, Digital Assets and Payments (posting read September 2026) job-boards.greenhouse.io ↗
  33. Checkout.com careers — Legal Counsel, Product and Regulatory (posting read September 2026) jobs.insightpartners.com ↗
  34. NatWest Group careers — Legal Counsel, Banking and Payments Legal Team (posting read September 2026) jobs.natwestgroup.com ↗
  35. Wise careers — Regulatory Compliance Manager, London (posting read September 2026) wise.jobs ↗
  36. Chambers UK 2026 — Financial Services: Payments Law chambers.com ↗
  37. Legal Cheek — Macfarlanes matches magic circle with £150k NQ lawyer salary (July 2026) legalcheek.com ↗
  38. Sartori & Partners — Is Privacy and Data Protection Law Hiring in 2026?  ↗
  39. Sartori & Partners — Compliance Talent Acquisition  ↗

Legislative dates describe a package agreed and not yet applied. Safeguarding figures describe the FCA regime in force since 7 May 2026. Reimbursement volumes are the Payment Systems Regulator's dashboard to 31 March 2026; the evaluation figures are Frontier Economics' work published by that regulator. License counts are a register snapshot of one date. Newly qualified pay is firm-wide private-practice scale, not a band for this seat.

For the adjacent European regulatory seat bought by the same in-house buyer, see privacy and data protection hiring in 2026. For what the wider compliance function costs, see compliance officer salary benchmarks, and for how the function is built rather than filled, see compliance talent acquisition. To open a confidential brief, use the in-house hiring form.

A quiet conversation

Putting a payments regulatory lawyer on your payroll, or weighing a move into one?

We map in-house payments and e-money counsel across London, Dublin and Frankfurt, and we are as willing to tell a general counsel or chief legal officer that a requisition is graded wrong as to open a search on it. Confidential, no obligation.