Evolving money laundering risks for EMIs: Insights from the upcoming NRA

18 July 2025
by Payments Intelligence

LinkedIn
Email
X
WhatsApp

What is this article about?

The UK 2025 National Risk Assessment’s decision to reclassify e-money institutions (EMIs) as high risk for money laundering and terrorist financing.

Why is it important?

This reclassification has significant regulatory and commercial consequences for the EMI sector, potentially raising compliance costs, impacting bank partnerships, and limiting innovation.

What’s next?

EMIs must strengthen their risk frameworks, advocate for more nuanced regulation, and prepare for heightened scrutiny to avoid blanket penalties and operational disruption.

The UK government’s 2025 National Risk Assessment (NRA), published this month, confirms that the risk classification for e-money institutions (EMIs) has been elevated for both money laundering (ML) and terrorist financing (TF). This marks a significant shift from the 2020 assessment, in which EMIs were rated as “medium” risk. According to HM Treasury, the new classification reflects the sector’s increasing exposure to criminal exploitation, particularly through prepaid products, rapid onboarding, and cross-border digital capabilities.
The decision has sparked debate across the payments industry. While some regulators argue that the elevation is a proportionate response to the evolving threat landscape, many EMI leaders believe it is too blunt a categorisation for such a diverse and maturing sector.

Industry commentary

EMI risk reclassification under the 2025 NRA

In the new 2025 NRA, HMT refers to a  “persistent and material vulnerability” for TF and ML in the EMI sector. 

The rationale centres on several key factors:

  • The speed and scale at which EMIs can onboard customers,
  • Their provision of bank-like services (e.g. virtual IBANs, international transfers),
  • And the abuse of prepaid instruments to obscure the origin of funds or facilitate layering.

It is worth noting that retail banks were classified as high risk for ML and TF in the most recent NRA. This classification gives precedent for an elevation in EMIs’ risk rating as they appeal to criminals for many of the same reasons, such as rapid onboarding, virtual IBANs, and multi-currency transactions.

While the Money Laundering Regulations (MLRs) apply equally to EMIs, PSPs, and retail banks, traditional banks remain subject to broader regulatory obligations under frameworks such as the Financial Services and Markets Act 2000. This means that while both sectors are bound by anti-money laundering/counter-terrorist financing rules, banks typically operate under stricter governance and capital requirements, making them less attractive to criminals seeking weaker onboarding and monitoring standards.

The 2025 NRA cites this asymmetry as one reason why bad actors have targeted some EMIs and PSPs. However, the report also emphasises that recent years have seen a sharp increase in supervisory focus on the EMI/PSP sector. Between 2020 and 2024, the FCA recorded a 231% rise in MLR-related supervisory activity for EMIs and PSPs. This surge in oversight almost certainly reflects a greater regulatory emphasis on identifying and mitigating financial crime in these organisations rather than material changes in the sector.

The enhanced scrutiny has been supported by improved collaboration between supervisory and enforcement bodies. Information sharing among the FCA, the National Crime Agency (NCA), the National Economic Crime Centre (NECC), and HMRC has become more routine and sophisticated, resulting in a more developed understanding of sector-specific threats than existed in 2020. As a result, the NRA says the government has a better understanding of the threat in 2025 than it did in 2020.

  • The increased complexity and diversification of services contribute to the sector’s attractiveness for criminals, with additional options to manage and launder funds across borders
  • The increasing exposure to high-risk jurisdictions
  • Greater understanding of the risk now relative to the last NRA.
Understanding the 2025 NRA Reclassification of EMIs
2025 National Risk Assessment – What’s Changed?
The 2025 NRA marks a pivotal regulatory shift, reclassifying e-money institutions (EMIs) from medium to high risk for both money laundering and terrorist financing. This elevation reflects growing concerns about the sector’s exposure to illicit activity amid rapid digital growth.
Why EMIs Were Reclassified as High Risk
HM Treasury cites a mix of structural and operational vulnerabilities: the speed and scale of customer onboarding, the use of prepaid products to obscure fund origins, and EMIs’ ability to provide near-bank-like services across borders—all of which create fertile ground for financial crime.
EMIs vs. Traditional Banks – A Regulatory Contrast
While both EMIs and banks are subject to the UK’s Money Laundering Regulations, traditional banks operate under broader legal and capital requirements. This difference in regulatory architecture is one reason criminals may favour EMIs for faster, less scrutinised access to financial systems.
How Criminals Exploit EMI Channels
Common typologies include the use of money mule accounts, layering through prepaid instruments, synthetic and stolen identities for onboarding, and exploitation of third-party agents—methods that enable fast and dispersed movement of illicit funds with minimal oversight.
Where the NRA Data Comes From
The NRA’s conclusions are drawn from over 300 data sets, including intelligence from the NCA, FCA, HMRC, Suspicious Activity Reports, and sector responses. However, critics note that few of these inputs are publicly disclosed or provide quantitative justification for the rating shift.
EMI Is Not a Monolith
The EMI sector spans everything from simple gift card issuers to sophisticated platforms delivering government disbursements. Risk levels and control sophistication vary widely, yet the NRA assigns a single high-risk designation across this heterogeneous landscape.
Industry Reactions and Concerns
Industry leaders argue the reclassification oversimplifies the sector’s risk profile and may reflect lobbying from traditional banks rather than objective, proportional risk analysis. They call for regulatory nuance and better distinction between business models.
Summary – A Complex Landscape Demands a Nuanced Approach
The NRA’s reclassification signals stronger regulatory intent, but it also underscores the need for policy frameworks that reflect operational realities and control maturity. Without this nuance, there is a risk of unintended consequences for compliance leaders and innovators alike.

The report acknowledges that risk mitigation has improved, but that the increased exposure and use have necessitated an increase in risk score.

HMT also highlights a pattern of criminal typologies involving EMIs, including money mule networks, synthetic identities, and fraud-linked accounts, all of which can be utilised to quickly and with minimal friction move illicit funds. The report references recent supervisory data and law enforcement casework, which indicate that while some EMIs have strong controls, others continue to exhibit weak governance and insufficient financial crime frameworks.

The NRA does acknowledge sector diversity. It notes that the risk level is not uniform across all EMIs and that specific business models, particularly those involving public disbursement or high-frequency transactions, are subject to more targeted threats. However, this nuance is somewhat lost in the sector-wide “high risk” designation now formalised in the report.

The EMI risk profile for terrorist financing and money laundering

Many EMIs acknowledge that their products are susceptible to exploitation, particularly given their digital-native infrastructure, cross-border capabilities, and the speed of funds movement. The 2025 NRA outlines several well-documented typologies where EMIs have been exploited:

  • Money mule networks: Individuals are recruited to open EMI accounts and rapidly move criminal proceeds across platforms.
  • Layering via prepaid instruments: Prepaid cards or wallets are used to obscure the origin of funds and conduct low-value transactions below monitoring thresholds.
  • Synthetic and stolen identity fraud: Used to open multiple EMI accounts for use in authorised push payment (APP) scams and drug-related activity.
  • Third-party agent exploitation: In some cases, inadequate oversight of agents or distributors has enabled criminals to circumvent proper due diligence.

The relative ease of onboarding and real-time fund movement has made these channels attractive to criminals seeking speed and dispersal, particularly in fraud-linked typologies .

The EMI sector is not naive to these risks, with many players taking robust measures to counteract them. Many firms now deploy behavioural analytics, biometric onboarding, device fingerprinting, and automated risk scoring, supported by specialised teams and regtech solutions. Several EMIs argue that their platforms are more transparent and traceable than legacy systems, with full audit trails and real-time visibility into transaction flows.

While some regulators counter that EMIs often lack the depth of resources found in traditional banks, industry leaders stress the importance of not treating the sector as a monolith. Some providers, particularly those focused on social disbursements, corporate services, or public sector partnerships, have robust frameworks that far exceed baseline regulatory standards.

The political economy of risk narratives

For some in the EMIs, the elevation in risk classification is not just a supervisory issue but a political and competitive one. Industry figures argue that the decision reflects pressure from incumbent banks, who have long questioned the risk appetite and governance of challenger institutions.

This sentiment echoes earlier concerns raised during the October 2024 rollout of the Mandatory Reimbursement policy for APP fraud victims, which some EMIs believe was disproportionately shaped by the interests of legacy players with larger compliance teams and lobbying reach. They suggest that risk-based policymaking is increasingly being influenced by sectoral lobbying rather than neutral assessments of comparative harm or consumer impact.

Implications and Strategic Response for EMIs
What the High-Risk Label Means in Practice
Being designated “high risk” brings heightened scrutiny. EMIs may now face enhanced customer due diligence, more frequent audits, tougher onboarding thresholds, and possible hesitancy from banks, partners, and investors engaging with the sector.
EMI Dependence on Traditional Infrastructure
EMIs rely on banks for safeguarding client funds, accessing payment rails like CHAPS and Faster Payments, and obtaining card scheme sponsorship. A sector-wide risk elevation threatens these vital relationships, especially for smaller or newer firms.
Rising Compliance Costs and Operational Pressures
The impact of reclassification will be felt in compliance headcount, onboarding delays, system upgrades, and board-level risk reviews. For many EMIs, this shift could dilute resources otherwise allocated to product development and market expansion.
Using Resilience as a Competitive Advantage
Instead of resisting the reclassification, EMIs can turn compliance maturity into a strategic asset. Firms that can demonstrate robust risk controls, audit readiness, and adaptability are well positioned to differentiate themselves in a crowded market.
Frameworks to Strengthen Governance and Controls
Institutions such as the Institute of Corporate Resilience offer practical models to embed governance, risk management, and financial crime prevention into core operations. This is an opportunity to shift the narrative from vulnerability to resilience.
Why a Blanket Risk Rating Doesn’t Fit
Applying a high-risk label to the entire EMI sector disregards critical differences in business model, control infrastructure, and use case. A more granular, risk-based supervisory approach is essential to avoid overregulating high-performing firms.
Immediate Steps EMIs Should Take
EMIs should reassess their Business Wide Risk Assessments, review third-party relationships, enhance transaction monitoring tools, and prepare documentation that evidences the maturity of their compliance frameworks ahead of new supervisory reviews.
The Road Ahead – Regulation and Innovation in Balance
The challenge now is to ensure that regulatory vigilance doesn’t suppress innovation. EMIs and regulators must work together to build a system that distinguishes between risk and readiness—supporting a sector that plays a vital role in financial inclusion and digital progress.

Consequences of a higher risk classification

Before the publication of the 2025 NRA, when the risk elevation had yet to be confirmed but was rumoured, a persistent complaint from EMIs was the lack of data to justify such a recategorisation. Now published, this remains the case: the NRA does not provide specific datasets or quantitative figures to justify its position.

It does point to qualitative, non-public operational sources in the methodology, stating it received more than 250 responses from the regulated sector and utilised more than 300 assessments, datasets and questionnaires from law enforcement agencies and supervisors. This included Suspicious Activity Reports (SARs) analysis, National Crime Agency (NCA) intelligence assessments of money laundering threats and patterns, His Majesty’s Revenue and Customs (HMRC) intelligence and NCA Joint Money Laundering Intelligence Taskforce (JMLIT) alerts.

Additionally, EMIs indicate that all regulated companies must file suspicious activity reports (SARs), are subject to FCA supervision, and operate in many cases with more restricted financial corridors than global banks.

The danger, they warn, is that the elevated rating may now be used to justify de-banking, limit access to critical payment infrastructure, or deter new entrants, despite many EMIs operating in highly compliant and socially valuable sectors.

“High Risk” – What Does It Really Mean for EMIs?

Despite being labelled high risk in the 2025 NRA, many EMIs have stronger controls, faster detection tools, and more agile compliance frameworks than legacy banks—raising the question: is the sector being judged on exposure or preparedness?

There is disagreement about the implications of the reclassification across the EMI ecosystem.

EMIs are heavily reliant on traditional banks for safeguarding client funds, accessing payment systems such as Bacs, CHAPS, and faster payments, and card scheme sponsorships through Visa and Mastercard.

A higher risk label may lead to more frequent and intensive due diligence reviews, higher onboarding thresholds, and, in some cases, termination of the relationship. Smaller EMIs or those without direct access to the scheme may be especially vulnerable. The de-risking of EMIs by banks has already been flagged in past FCA reports, and some fear that the 2025 NRA may exacerbate this trend.

Some on the regulatory side disagree that the risk reclassification will hurt established relationships between EMIs and legacy banks. Extensive due diligence will have been conducted before any partnership, and a sector-wide risk recategorisation in the NRA is unlikely to impact this. 

Payments Intelligence presented this argument to a senior executive responsible for overseeing risk management at an EMI, who disagreed, stating that big banks will base their due diligence and periodic reviews on data such as national risk assessment ratings.

At an operational level, EMIs may now be subject to stricter customer due diligence, enhanced monitoring, and greater audit requirements. These measures increase compliance costs, raise barriers to entry, and reduce the agility that defines much of the sector. They could also create friction in public-private partnerships, as EMIs involved in government disbursement or community banking face new reputational and onboarding hurdles.

HMT notes in the report that the purpose of the reclassification is not to stifle innovation but to “ensure proportionate mitigation of known risks.” Nonetheless, industry experts warn that unless the regulatory approach begins to distinguish between EMI business models and control maturity, the sector may face one-size-fits-all supervision that fails to reward investment in governance and compliance.

Risk, rhetoric, and the need for nuance

The elevation of EMIs to a high-risk classification for ML and TF in the 2025 NRA is a significant moment for the UK payments sector. Industry stakeholders remain concerned about the implications of a sector-wide designation, particularly for EMIs with robust compliance frameworks and effective governance.

The only point of agreement is that the EMI sector is too broad to be treated as a single risk category. Firms vary widely in their products, clientele, and risk controls. A more granular, control-based approach would better reflect this diversity and avoid penalising innovation.

As regulatory scrutiny tightens, EMIs with mature controls have an opportunity to distinguish themselves, not as part of the problem, but as industry leaders in preventing financial crime. Equally, policymakers face a challenge of their own: ensuring that efforts to combat economic crime do not undermine one of the most dynamic and inclusive segments of the UK’s fintech ecosystem.

LinkedIn
Email
X
WhatsApp

Read more Payments Intelligence

Regulation Roadmap Q3

TPA’s Q3 UK Payments Regulation Roadmap explains the key UK and international regulatory developments affecting payment firms over the coming years.

Read More »

Upload your profile photo

You need to be logged in to do this!

Membership

Merchant Community Membership

Are you a member of The Payments Association?

Member benefits include free tickets, discounts to more tickets, elevated brand visibility and more. Sign in to book tickets and find out more.

Continue reading

UK 2025 NRA elevates EMIs to high-risk ML/TF category, urging strategic compliance revisions. Join The Payments Association to read the full article.

Become a member to continue reading

Member of The Payments Association? Log in to continue reading