If you run a fintech that is not an account-information or payment-initiation firm, start on Fintech Insurance UK. That page owns the wider programme.
This page is the insurance the FCA asks for when you want to read a customer’s payment accounts, or start a payment from them. People call it PSD2 insurance. It is not a licence. It is not a product insurers sell on its own. It is professional indemnity, written so it matches the Payment Services Regulations, plus a certificate your lawyer can send with the application.
Meshed is an FCA-regulated UK broker. We place this cover for UK limited companies and partnerships, from a panel of insurers. Broker fee is a flat 10%, with no admin add-ons.
If you want the wider “what does a UK company need” list, that sits on the business insurance hub.
Who this is for
UK limited companies and partnerships that need the insurance the FCA asks for on a payments permission, including:
Account information service providers (AISPs), including registered-only firms (RAISPs)
Payment initiation service providers (PISPs)
Payment institutions and e-money firms that also hold those permissions
Firms putting the pack together for an application, not only firms already on the register
We work with limited companies and partnerships. We do not currently place cover for sole traders.
If the model is lending, wealth, crypto, or another regulated financial-services business that is not this permission, use Fintech Insurance UK. If a lawyer has already said a standard tech PI schedule will do, check that before you spend a week on forms. We will say whether a market can paper what the FCA asked for.
Who we have helped
We place this cover for UK limited companies and partnerships: firms that need the certificate in an FCA application, authorised payment institutions whose current PI wording will not satisfy the lawyer, and AISPs or PISPs whose existing schedule excludes financial services, employee fraud, or the territories they actually operate in.
What the FCA actually asks for
In the UK the rule sits in the Payment Services Regulations. People still search “PSD2” because that is the name the market uses.
If you want to provide account information services or payment initiation services, the FCA will not authorise or register you without professional indemnity insurance — or a comparable guarantee — already in place. You have to keep it while you hold the permission.
The certificate has to match the service:
Account information (AISP / RAISP). Cover if someone says you accessed, or used, payment-account information without authority, or fraudulently.
Payment initiation (PISP). Cover if a payment goes out without authority, does not go out, goes out late, or goes out wrong — and the charges and interest that sit on that.
It has to apply in every territory you offer the service. The minimum limit is worked out from a formula the European Banking Authority published, which the FCA still uses: risk, type of activity, and size (how many accounts you touch, or how much payment volume you start). You can buy more than the minimum. You cannot buy less and hope the application squeaks through.
A comparable guarantee is allowed instead of insurance. Most applicants buy a policy. We will say if a guarantee is even on the table.
We do not issue the permission. The FCA does. We place the insurance the application asks for, with a market that will issue a certificate your lawyer can send.
AISP and PISP, in plain English
An AISP reads payment accounts, with the customer’s consent, and shows that information back — a money app, a lending check, a balance dashboard. It does not move the money.
A PISP starts a payment from a customer’s account at another provider, with the customer’s consent — pay-by-bank at checkout, a sweep between accounts.
A firm that only does account information can register as a RAISP. No capital floor. It still needs the insurance.
A firm that starts payments has to be authorised, and has to hold the insurance plus the capital the regulations set (from €50,000, more if it also does other payment services).
A payment institution or e-money firm that also wants those permissions needs the same insurance on top of whatever else the licence already demanded.
If you do not do either of those things, this is the wrong page. Go to Fintech Insurance UK.
Why a normal PI policy often fails
Professional indemnity is the right class. A generic tech or consultancy wording is often the wrong wording.
Typical holes the lawyer sends back:
A financial-services or regulated-activity exclusion
No cover for unauthorised access to payment-account information, or for a payment that was not made, made late, or made wrong
Employee, director, or contractor fraud carved out — the FCA still wants that liability on the paper
Territory that does not match where you actually offer the service
A limit that does not meet the formula, or a limit that other claims can eat so the PSD2 bit falls below the minimum
An excess that could leave a customer refund unpaid
The full PI guide — claims-made, retroactive dates, run-off — lives on that page. Do not treat a professional-body or MSA certificate as the same document. This one has to say the things the Payment Services Regulations named.
What else buyers are asked for
The compulsory bit is the professional-indemnity certificate. Applications and enterprise contracts usually ask for more.
Cyber. The PI pays if a customer or a bank says your service cost them money. It does not pay if you are the one who got hit — ransomware, a mailbox takeover, incident response, your own outage. That sits on a cyber policy. Some PSD2 packs put a data-security section next to the PI so one event is not bounced between two wordings. We will say if they should be placed together.
Directors’ and officers’. A regulatory investigation can name the people, not only the company. D&O is personal liability for how the firm was run. It is not a substitute for the PI certificate. Boards and investors often want it on the same programme.
Safeguarding-related insurance. This is a different ask. If you hold customer money, the FCA requires you to protect it if the firm fails. Most firms put the money in a segregated bank account. Some use an insurance policy or a guarantee instead. That policy has to pay out on insolvency, into a safeguarding account, with almost no get-outs. New rules from May 2026 make that tighter. It is not the AISP/PISP PI certificate. Do not buy one and assume it does the other job. We will say if a market can paper a safeguarding wording. We will not pretend every quote includes one.
Crime and fidelity for payment fraud, and the rest of a payments programme, stay on Fintech Insurance UK.
How much cover do I need?
Enough to meet the formula, then at least whatever your lawyer, the FCA pack, or a customer contract has already named.
The formula looks at the kind of service, how risky it is, and the size — accounts accessed, payments started, volume. If you are not live yet, the underwriter will use your forecasts. If you also do other work, the PSD2 minimum should not be eaten by those other claims. That is a wording point, not a bigger number on a comparison site.
In the UK market you will usually see limits from a few hundred thousand pounds to several million. We size it to the formula and the contracts, not to a default.
What it costs
Premium follows the model: AISP or PISP or both, volumes, territories, whether you hold customer money, claims, the limit, and the excess. A registered account-information firm and a payment institution moving real value will not price the same.
We will not publish a “from £X a month” figure. There is no useful average on this class.
What you can control: a proposal that describes the service you will actually provide, honest forecasts, and the current schedule if you already have PI. Underwriters load the files that are vague.
How Meshed works
You tell us the model: what you do, the permission you hold or want, volumes or forecasts, territories, headcount, and current cover.
We review the documents and flag gaps in wording, limit, territory, fraud, and whether the lawyer will accept the certificate. We will also say if cyber, D&O, or a safeguarding wording is a separate ask.
We go to our panel and come back with options.
You bind. We stay on for mid-term changes, volume changes, and renewal — the permission assumes the insurance stays in force.
Straightforward SME risks are often quoted in minutes. New authorisations, mixed permissions, or a safeguarding wording can take longer. We will say that up front.
FAQs
What is PSD2 insurance?
The insurance the FCA asks AISPs and PISPs to hold. It is professional indemnity written for that permission, plus a certificate your lawyer can send. Insurers do not usually sell it as a product on its own. It sits inside a payments or fintech wording.
Do I need PSD2 insurance in the UK?
Yes, if you want to provide account information services or payment initiation services. It is a condition of authorisation or registration under the Payment Services Regulations. You have to keep it while you hold the permission. If you do not do those services, you do not need this certificate.
Is PSD2 insurance a licence?
No. The FCA issues the permission. A broker places the insurance the application asks for. Meshed is a broker. We do not issue PSD2, AISP, PISP, or payment-institution permissions.
What is the difference between an AISP and a PISP?
An AISP reads payment accounts, with consent. A PISP starts a payment from those accounts, with consent. Both need the insurance. The wording has to match the service.
Is this the same as professional indemnity?
It is the same class of insurance, with a specific job. A generic PI policy often excludes the very liabilities the FCA named. The general PI page is Professional Indemnity Insurance UK.
Is this the same as fintech insurance?
No. Fintech insurance is the wider programme — PI, D&O, cyber, crime — for firms that combine software with a financial product. PSD2 insurance is the specific certificate for AISP and PISP permissions. If you need both, start here for the certificate and use Fintech Insurance UK for the rest.
What about safeguarding insurance?
Different product. Safeguarding is how you protect customer money if the firm fails — usually a segregated account, sometimes an insurance policy or a guarantee. It is not the PI certificate. Say if you hold customer funds. We will tell you which ask you actually have.
Will my current PI policy do?
Often not. Check financial-services exclusions, fraud, territory, and whether the limit still meets the formula after other claims. Send us the schedule. We will say if it works or if it needs to be rewritten.
How much cover do I need?
The minimum comes from the regulator’s formula. Buy more if a contract or a realistic claim is bigger than that. We work it out from the service and the volumes, including forecasts if you are not live yet.
I am a sole trader. Can you help?
Not currently. We place cover for limited companies and partnerships only. A payments permission is a company process in any case.
Are you an insurer?
No. Meshed is a broker. Mesh'd Limited trading as Meshed is authorised and regulated by the Financial Conduct Authority under firm reference number 1033248.
How fast can we bind?
Clean renewals and a straightforward AISP certificate can be same-week. New authorisations, mixed payment-institution permissions, claims histories, or a safeguarding wording take longer.

Vincent Liu
Co-founder & CTO



