No spam - just the latest insights!
Join over 30,000 industry professionals who subscribe for free
Subscribe for free!
We'll never share your information or send you spam
Tom Moore is a leading voice in the UK’s fintech sector, heading Moore Kingston Smith’s financial services team. With over 20 years’ experience advising recognised names in the industry, he combines technical precision with commercial insight to help clients scale, adapt and lead. His work spans personal finance platforms, embedded finance providers, cross-border payments, and next-generation tech ventures, delivering strategic audit, tax and advisory support tailored to the sector’s pace and regulation. Known for his clear thinking and calm approach, Tom translates complexity into confident decision-making. Actively involved in the fintech ecosystem since its early days, he works closely with founders, CFOs and boards navigating growth, investment and international expansion – particularly between the UK and North America – bringing a global perspective and strategic vision to firms shaping the future of financial services.
UK fintech goes into 2026 with core rules bedded in: stronger protection of customer funds, tougher expectations on uptime and recovery, and clearer guardrails on how customer data is used. Capital is also more selective. That mix rewards firms that are well run. Boards that can show, quickly and plainly, how their controls work in real life will close enterprise deals faster, hold pricing and raise on better terms. The job in 2026 is practical: turn compliance and reliability into profit, move procurement with clear evidence and keep funding costs down with disciplined planning.
Recent numbers back that up. Buyers and investors want evidence, not stories. After a bruising reset in 2023 to 2024, funding began to stabilise through 2025. Innovate Finance, the UK’s independent industry body, tracked about $24 billion across 2,597 VC equity deals in the first half of 20251https://www.innovatefinance.com/capital/fintech-investment-landscape-2025/, up six per cent on the previous six months.
The UK ranked third globally with around $1.5 billion across 240 deals and stayed number one in Europe. The UAE’s rise to second was mostly a single $2 billion Binance round, an outlier that skewed half-year tables. More importantly, 11 UK fintechs (including Allica, Monzo, OakNorth, Revolut, Starling, Wise and Zopa) delivered $3.3 billion pre-tax profit in 2024 and employed 26,000-plus people, providing evidence that investors are backing durable economics.
The emphasis in 2026 is less ‘what are the rules?’ and more ‘show me how you meet them?’. The Financial Conduct Authority’s (FCA) new safeguarding rules for payment and e-money firms, known as CASS 152https://www.fca.org.uk/publication/policy/ps25-12.pdf under its Client Assets Sourcebook, take effect on 7 May 2026.
It strengthens segregation, reconciliation and wind-down expectations so customer funds can be returned quickly if a firm fails. Commercially, that moves safeguarding evidence to the front of diligence, because it determines counterparty risk as volumes scale. We’re already supporting a growing number of fintechs with their readiness assessments and safeguarding audits, helping boards evidence compliance in real terms and prepare for these upcoming changes with confidence.
Across the Channel, the EU’s payments package, PSD33https://www.payment-services-directive-3.com/ (a new directive focused on authorisation and supervision of payment and e-money institutions), together with the directly applicable Payment Services Regulation (PSR), is into trilogues after Parliament set its position in 2024 and Council agreed its mandate in mid-2025. It tightens fraud-prevention and consumer-information duties and consolidates much of PSD2 into a single enforceable rulebook.
For UK firms selling into the EU, 2026 is the alignment year. Firms need to tighten payee verification and fraud data-sharing, keep APIs reliable to PSR expectations, and make sure safeguarding and authorisation practices read across cleanly so procurement doesn’t stall as the texts phase in.
Operational resilience is now in the ‘prove it’ phase. The FCA, Prudential Regulation Authority (PRA) and Bank of England required firms to be within impact tolerances by 31 March 2025. In 2026 the ask in live, rolling evidence. Buyers, banks and supervisors should be open with the numbers: time to detect, time to recover, the date and scope of the last live failover, and clear maps of critical third-party dependencies. When payments and data sit inside other people’s customer journeys, these metrics decide whether a pilot becomes a contract, and on what terms.
For cross-border propositions, the EU’s Digital Operational Resilience Act (DORA)4https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en has applied since 17 January 2025. It standardises ICT-risk governance, incident classification and reporting timelines, continuous testing (including threat-led exercises for larger institutions), and third-party oversight across the bloc, with direct supervision of critical ICT providers by the European Supervisory Authorities. If you have EU customers or entities, 2026 is about operating to the DORA benchmark so sales cycles and supervisory reviews stay straightforward.
Trust has also moved from virtue to metric after a year of headlines. Supermarket Co-op put a figure on its April 2025 cyberattack:5https://www.bbc.co.uk/news/articles/ckgq9dke4e5o £206 million in lost revenue and an £80 million hit to operating profit and cash in H1. UK department store Harrods warned customers about data exposed via a third-party provider6https://www.theguardian.com/business/2025/sep/26/harrods-warns-customers-their-data-may-have-been-stolen-in-it-breach. Retail giant Marks & Spencer paused online orders in the spring after a cyber incident.7https://www.theguardian.com/business/2025/jun/10/m-s-marks-and-spencer-website-online-orders-cyber-attack These aren’t fintech breaches. That’s the point. Your customers’ customers learned how dependent they are on suppliers, and they now benchmark vendors, fintechs included, on recovery evidence and data hygiene, not slogans. We’re helping fintechs deal with that scrutiny, supporting boards with data strategy, breach readiness and audit-grade hygiene. For many, that includes SOC 2: a framework that translates operational rigour into third-party assurance across security, availability and privacy. In a market where trust drives procurement and funding, SOC 2 isn’t just a compliance badge, it’s a commercial asset.
Against that backdrop, the UK fintech proposition in 2026 looks less like ‘disruption’ and more like exportable reliability. London sits close to the plumbing of money movement – issuers and acquirers, open-banking rails, capital markets – and remains the densest European cluster of bank-grade vendors. For international buyers and investors, that proximity only helps when matched by clarity.
The firms converting meetings into contracts this year present their assurance story as cleanly as their product story. It isn’t a new strategy; it’s a new order of operations. That clarity now extends into the infrastructure itself. Smart data, open finance and digital verification are shaping how firms demonstrate control, through faster onboarding, cleaner permissions and audit-ready identity.
The UK has moved beyond open banking 1.0. The Data (Use and Access) Act 20258https://www.gov.uk/government/collections/data-use-and-access-act-2025 gives government the power to create smart data schemes across sectors (including open finance) and to establish a statutory framework for digital verification services. In practice, 2026 is the year to make consent, permissions and audit trails inspection-ready so onboarding is faster, and fraud and identity hurdles are reduced in enterprise procurement.
Supervisors are already turning the taps on. The FCA’s Open Finance Sprint 20259https://www.fca.org.uk/publication/corporate/open-finance-sprint-outcomes-report-2025.pdf set out priority use cases (financial wellbeing, growth, resilience, digital identity) and the FCA has launched a Smart Data Accelerator to move pilots into live-able services. For sales, this is simple: if your permissions ledger, revocation flow and third-party access logs are clear and current, risk and compliance teams say yes faster.
That same clarity is now expected in product delivery. Launches that land in 2026 lead with outcomes buyers already track, whether it’s fraud loss per amount processed, settlement availability, reconciliation reliability on good and bad days, or onboarding time that still survives audit. Buyers and lenders look at those measures in their regular reviews. If they move in the right direction, you keep your price.
AI sits in the same ‘prove it’ frame. The uses that last are practical and auditable: reading documents in onboarding and KYB, helping analysts triage fraud and disputes, pulling context for service teams, and keeping finance plans tied to the ledger. Supervisors are explicit that models are controls: the PRA treats model risk as a discipline10https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks in its own right and the FCA’s AI Update11https://www.fca.org.uk/publication/corporate/ai-update.pdf anchors deployment to testing, validation and explainability.
Very simply, if a model touches customers or the numbers you should be able to say what it does, what data it sees, when a person must decide, and how you check for drift. The teams that answer those points cleanly find AI adds credibility rather than controversy. For context on current supervisory thinking, see the FCA’s AI Live Testing blog.
Stablecoins are being handled with the same pragmatism. With the UK regime for fiat-backed tokens taking shape, the FCA’s consultation12https://www.fca.org.uk/publication/corporate/ai-update.pdf and the Bank of England’s July 2025 Financial Stability Report13. https://www.bankofengland.co.uk/financial-policy-committee-record/2025/july-2025, boards are running narrow, testable use cases such as marketplace payouts, awkward B2B receivables and intra-group sweeps under auditor-ready controls. A corridor-by-corridor rollout reads as discipline, not caution.
If the rulebook is the filter, evidence is the currency. In funding, the companies getting fair terms in London start with clear unit economics and payback that includes churn, separate real expansion from simple repricing, and keep enough runway with headroom on covenants. That matches what investors rewarded through 2025, stabilising flows and a premium for firms that can show how cash turns into durable margin. Stronger controls here, lower that counterparty risk.
There is also a change in how supervisors engage with growth. In October 2025, the FCA and PRA launched a joint Scale-up Unit14https://www.fca.org.uk/news/news-stories/chancellor-launches-scale-up-unit, a single point of contact for fast-growing regulated firms to plan variations of permission, coordinate supervisory interactions and understand how new policy proposals might intersect with a scale plan.
It is not a shortcut, not an endorsement, and not a lowering of standards. It is process clarity. For late-stage fintechs adding adjacent permissions or preparing cross-border partnerships, that clarity reduces timeline risk and the chance of discovering a regulatory question at the last minute. In a year when boards and lenders want fewer surprises, these things matter.
Fraud policy has tightened in a way that concentrates the mind. The APP reimbursement regime15https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf, live since 7 October 2024 and consolidated during 2025, sets minimum protections across Faster Payments (and now covers CHAPS), establishes a reimbursement framework and caps for eligible claims, and formalises monitoring. Whatever your view of liability sharing, the practical effect is straightforward. Prevention and recovery metrics have moved next to revenue and margin in board packs, and counterparties are more likely to ask how those metrics are trending than to discuss slogans about ‘safety.’ It is another nudge toward the same destination. Proof.
The people picture is mixed in ways that favour focus. Scarcity persists in a few specialist roles (product risk, financial crime, applied data and security engineering), while the generalist market is looser. Many UK fintechs are settling on a pragmatic split that reads well in procurement and in funding, keep differentiating capabilities close to home and buying capacity for process-heavy tasks that can be specified and measured. That approach is not about hollowing teams out. It’s about predictability. Enterprise buyers prefer suppliers whose variable work (reconciliation, first-line monitoring, pieces of finance operations) runs to clear standards and is reported in the same tone as commercial metrics. In a market that has grown cautious, predictability is a virtue.
A word on the macro setting too. The UK’s slower growth, persistent cost pressure, and tax that bites harder on some structures, means scenario planning isn’t optional. Boards and lenders expect to hear how a plan moves resources under base, downside and upside, and how it responds to the real failure modes of modern financial infrastructure such as a cloud zone loss, an issuer or acquirer outage, an abrupt drop in authorisation rates, an FX jolt, or a fraud spike. That expectation tracks with the operational resilience regime and with recent retail headlines, and it has a commercial upside. Companies that can explain how they manage volume, communicate with customers and pull liquidity levers under stress tend to negotiate better terms precisely because they demonstrate control.
Internationally, the UK remains a practical base for expansion because of its proximity to counterparties and a supervisory culture that understands the plumbing of payments and data. But the pattern of expansion is narrowing from ‘new countries’ to ‘workable corridors’.
The strategies that read best in 2026 pick lanes where a proposition has a right to win – UK-US collections for B2B SaaS, UK-EU for marketplace payouts, tightly defined APAC routes for platform disbursements – and build licensing, banking relationships and multilingual support around those lanes before adding more. It is an approach that suits UK strengths and aligns with how procurement now thinks. Proof in two places is preferred over light claims in ten.
What, then, does a strong UK fintech look like from the outside this year? It looks settled without being slow. Product strategy describes outcomes in the buyer’s metrics. The assurance story is short, current and calm. Unit economics are visible and survive basic questions about churn, pricing and payback. AI shows up where it plainly reduces time and error in regulated work, and the governance story is as straightforward as the technology.
International exposure appears as a couple of fully built corridors rather than a scatter of flags. And conversations about price lean on the buyer’s dashboards because that’s where value lives and where sceptical committees can be persuaded.
None of this is flashy. All of it compounds. Evidence earns trust; trust unlocks bigger customers and cheaper capital; scale makes the evidence easier to collect and present; and the loop tightens. The UK remains a good place for that loop to run because of its dense counterparties, its experienced supervisors and its operator base. With the rulebook embedded and scrutiny higher, the opportunity for UK fintech in 2026 is not to rename the category. It’s to prove it. Consistently. Commercially. And at a level that makes the next decision easy for the people across the table.