
18 July 2025
by Payments Intelligence
What is this article about?
The UK 2025 National Risk Assessment’s decision to reclassify e-money institutions (EMIs) as high risk for money laundering and terrorist financing.
Why is it important?
This reclassification has significant regulatory and commercial consequences for the EMI sector, potentially raising compliance costs, impacting bank partnerships, and limiting innovation.
What’s next?
EMIs must strengthen their risk frameworks, advocate for more nuanced regulation, and prepare for heightened scrutiny to avoid blanket penalties and operational disruption.
The UK government’s 2025 National Risk Assessment (NRA), published this month, confirms that the risk classification for e-money institutions (EMIs) has been elevated for both money laundering (ML) and terrorist financing (TF). This marks a significant shift from the 2020 assessment, in which EMIs were rated as “medium” risk. According to HM Treasury, the new classification reflects the sector’s increasing exposure to criminal exploitation, particularly through prepaid products, rapid onboarding, and cross-border digital capabilities.
The decision has sparked debate across the payments industry. While some regulators argue that the elevation is a proportionate response to the evolving threat landscape, many EMI leaders believe it is too blunt a categorisation for such a diverse and maturing sector.
In the new 2025 NRA, HMT refers to a “persistent and material vulnerability” for TF and ML in the EMI sector.
The rationale centres on several key factors:
It is worth noting that retail banks were classified as high risk for ML and TF in the most recent NRA. This classification gives precedent for an elevation in EMIs’ risk rating as they appeal to criminals for many of the same reasons, such as rapid onboarding, virtual IBANs, and multi-currency transactions.
While the Money Laundering Regulations (MLRs) apply equally to EMIs, PSPs, and retail banks, traditional banks remain subject to broader regulatory obligations under frameworks such as the Financial Services and Markets Act 2000. This means that while both sectors are bound by anti-money laundering/counter-terrorist financing rules, banks typically operate under stricter governance and capital requirements, making them less attractive to criminals seeking weaker onboarding and monitoring standards.
The 2025 NRA cites this asymmetry as one reason why bad actors have targeted some EMIs and PSPs. However, the report also emphasises that recent years have seen a sharp increase in supervisory focus on the EMI/PSP sector. Between 2020 and 2024, the FCA recorded a 231% rise in MLR-related supervisory activity for EMIs and PSPs. This surge in oversight almost certainly reflects a greater regulatory emphasis on identifying and mitigating financial crime in these organisations rather than material changes in the sector.
The enhanced scrutiny has been supported by improved collaboration between supervisory and enforcement bodies. Information sharing among the FCA, the National Crime Agency (NCA), the National Economic Crime Centre (NECC), and HMRC has become more routine and sophisticated, resulting in a more developed understanding of sector-specific threats than existed in 2020. As a result, the NRA says the government has a better understanding of the threat in 2025 than it did in 2020.
The report acknowledges that risk mitigation has improved, but that the increased exposure and use have necessitated an increase in risk score.
HMT also highlights a pattern of criminal typologies involving EMIs, including money mule networks, synthetic identities, and fraud-linked accounts, all of which can be utilised to quickly and with minimal friction move illicit funds. The report references recent supervisory data and law enforcement casework, which indicate that while some EMIs have strong controls, others continue to exhibit weak governance and insufficient financial crime frameworks.
The NRA does acknowledge sector diversity. It notes that the risk level is not uniform across all EMIs and that specific business models, particularly those involving public disbursement or high-frequency transactions, are subject to more targeted threats. However, this nuance is somewhat lost in the sector-wide “high risk” designation now formalised in the report.
Many EMIs acknowledge that their products are susceptible to exploitation, particularly given their digital-native infrastructure, cross-border capabilities, and the speed of funds movement. The 2025 NRA outlines several well-documented typologies where EMIs have been exploited:
The relative ease of onboarding and real-time fund movement has made these channels attractive to criminals seeking speed and dispersal, particularly in fraud-linked typologies .
The EMI sector is not naive to these risks, with many players taking robust measures to counteract them. Many firms now deploy behavioural analytics, biometric onboarding, device fingerprinting, and automated risk scoring, supported by specialised teams and regtech solutions. Several EMIs argue that their platforms are more transparent and traceable than legacy systems, with full audit trails and real-time visibility into transaction flows.
While some regulators counter that EMIs often lack the depth of resources found in traditional banks, industry leaders stress the importance of not treating the sector as a monolith. Some providers, particularly those focused on social disbursements, corporate services, or public sector partnerships, have robust frameworks that far exceed baseline regulatory standards.
For some in the EMIs, the elevation in risk classification is not just a supervisory issue but a political and competitive one. Industry figures argue that the decision reflects pressure from incumbent banks, who have long questioned the risk appetite and governance of challenger institutions.
This sentiment echoes earlier concerns raised during the October 2024 rollout of the Mandatory Reimbursement policy for APP fraud victims, which some EMIs believe was disproportionately shaped by the interests of legacy players with larger compliance teams and lobbying reach. They suggest that risk-based policymaking is increasingly being influenced by sectoral lobbying rather than neutral assessments of comparative harm or consumer impact.
Before the publication of the 2025 NRA, when the risk elevation had yet to be confirmed but was rumoured, a persistent complaint from EMIs was the lack of data to justify such a recategorisation. Now published, this remains the case: the NRA does not provide specific datasets or quantitative figures to justify its position.
It does point to qualitative, non-public operational sources in the methodology, stating it received more than 250 responses from the regulated sector and utilised more than 300 assessments, datasets and questionnaires from law enforcement agencies and supervisors. This included Suspicious Activity Reports (SARs) analysis, National Crime Agency (NCA) intelligence assessments of money laundering threats and patterns, His Majesty’s Revenue and Customs (HMRC) intelligence and NCA Joint Money Laundering Intelligence Taskforce (JMLIT) alerts.
Additionally, EMIs indicate that all regulated companies must file suspicious activity reports (SARs), are subject to FCA supervision, and operate in many cases with more restricted financial corridors than global banks.
The danger, they warn, is that the elevated rating may now be used to justify de-banking, limit access to critical payment infrastructure, or deter new entrants, despite many EMIs operating in highly compliant and socially valuable sectors.
There is disagreement about the implications of the reclassification across the EMI ecosystem.
EMIs are heavily reliant on traditional banks for safeguarding client funds, accessing payment systems such as Bacs, CHAPS, and faster payments, and card scheme sponsorships through Visa and Mastercard.
A higher risk label may lead to more frequent and intensive due diligence reviews, higher onboarding thresholds, and, in some cases, termination of the relationship. Smaller EMIs or those without direct access to the scheme may be especially vulnerable. The de-risking of EMIs by banks has already been flagged in past FCA reports, and some fear that the 2025 NRA may exacerbate this trend.
Some on the regulatory side disagree that the risk reclassification will hurt established relationships between EMIs and legacy banks. Extensive due diligence will have been conducted before any partnership, and a sector-wide risk recategorisation in the NRA is unlikely to impact this.
Payments Intelligence presented this argument to a senior executive responsible for overseeing risk management at an EMI, who disagreed, stating that big banks will base their due diligence and periodic reviews on data such as national risk assessment ratings.
At an operational level, EMIs may now be subject to stricter customer due diligence, enhanced monitoring, and greater audit requirements. These measures increase compliance costs, raise barriers to entry, and reduce the agility that defines much of the sector. They could also create friction in public-private partnerships, as EMIs involved in government disbursement or community banking face new reputational and onboarding hurdles.
HMT notes in the report that the purpose of the reclassification is not to stifle innovation but to “ensure proportionate mitigation of known risks.” Nonetheless, industry experts warn that unless the regulatory approach begins to distinguish between EMI business models and control maturity, the sector may face one-size-fits-all supervision that fails to reward investment in governance and compliance.
The elevation of EMIs to a high-risk classification for ML and TF in the 2025 NRA is a significant moment for the UK payments sector. Industry stakeholders remain concerned about the implications of a sector-wide designation, particularly for EMIs with robust compliance frameworks and effective governance.
The only point of agreement is that the EMI sector is too broad to be treated as a single risk category. Firms vary widely in their products, clientele, and risk controls. A more granular, control-based approach would better reflect this diversity and avoid penalising innovation.
As regulatory scrutiny tightens, EMIs with mature controls have an opportunity to distinguish themselves, not as part of the problem, but as industry leaders in preventing financial crime. Equally, policymakers face a challenge of their own: ensuring that efforts to combat economic crime do not undermine one of the most dynamic and inclusive segments of the UK’s fintech ecosystem.

TPA’s Q3 UK Payments Regulation Roadmap explains the key UK and international regulatory developments affecting payment firms over the coming years.

New research uncovers the payment habits, preferences and priorities shaping the future of payments in the UK.

New research shows vulnerable customers are strong adopters of AI and digital banking, but are far more likely to experience failed payment journeys and poorer outcomes.
You need to be logged in to do this!