How to verify pii meets fca regulatory minimums
Ensuring your Professional Indemnity Insurance (PII) meets regulatory standards is a mandatory step for securing and maintaining your FCA authorisation.
To verify your Professional Indemnity Insurance (PII) meets FCA standards, you must cross-reference your policy schedule against the specific financial limits and wording requirements found in the FCA Handbook. For most fintech firms, this means ensuring your policy covers the minimum euro or sterling amounts required for your specific activity (such as PISP or AISP) and that any 'excess' you have agreed to pay is within the limits the regulator allows for your firm's capital profile.
Identify your specific regulatory requirements
The first step is to know which part of the FCA Handbook applies to you. For payment services and e-money firms, the rules are generally found in the Payment Services Regulations or the Electronic Money Regulations. The FCA requires a minimum level of cover for any single claim and an aggregate limit for the entire year.
| Regulated Activity | Common Minimum Requirement |
|---|---|
| AISP (Account Information) | Calculation based on the number of users and risk profile. |
| PISP (Payment Initiation) | Minimum of €1,000,000 per claim and €1,500,000 in aggregate. |
| General Financial Advice | Varies based on income, but often £1,000,000+ per claim. |
Note: Figures are often set in Euros by European directives but are converted to GBP. Always check the latest FCA exchange rate guidance.
Check the 'excess' and 'retroactive' wording
The FCA is very particular about the fine print. Review your policy for the following two critical components:
- The Excess: This is the amount you pay towards a claim before the insurer steps in. The FCA generally requires that your firm has enough 'own funds' (capital) to cover this excess. If your excess is £10,000, you must be able to prove you have that £10,000 available at all times.
- Retroactive Date: This date should ideally be set to the date your business first started its regulated activities. If the retroactive date is too recent, you won't be covered for claims arising from work done in the past, which is a major red flag for the regulator.
Review exclusions and territorial limits
Standard PII policies often contain 'carve-outs' or exclusions that could leave you non-compliant. You must ensure that your policy does not exclude the specific regulated activities you are authorised for. Additionally, check that the 'Territorial Limits' cover the United Kingdom and any other regions where you provide services. If your policy only covers the UK but you have customers in the EEA, you are likely in breach of regulatory requirements.
Top Tip: Don't use a generic business insurer. Work with a specialist broker who understands the UK fintech space. They will be familiar with 'FCA-compliant wording' and can provide a letter of confirmation that the policy meets the requirements of the specific FCA Handbook module relevant to your business.
Ongoing monitoring
Your PII is not a 'set and forget' task. You must review your cover annually or whenever your business model changes significantly (for example, if your transaction volume grows beyond your current policy limits). The FCA requires you to report your PII details as part of your regular regulatory returns, so keeping an organized record of your policy schedule and renewal dates is essential for your compliance health.
Created by hatch. • Updated on April 28, 2026