Is a Payment Processor Legit? 6 Checks Before You Route a Single Transaction

Contents 10
In our piece on whether an affiliate network is legit, the conclusion was uncomfortable: no checklist proves a network will pay you in month 6. With a payment processor the stakes are higher and, oddly, the checks are better. A network is a commercial counterparty. A PSP that holds your customers' money is a regulated business in most countries, and regulated businesses leave records you can read for free.
Those records matter most when something breaks. The UK regulator looked at payment and e-money firms that went insolvent between early 2018 and mid-2023 and found that, on average, they were 65% short of the money they owed their clients. That's money merchants and consumers had already earned.
So before you route a single transaction, whether you're an advertiser picking a processor for an offer or an affiliate launching your own, run these 6 checks. They take an evening and cost nothing.
Check 1: the legal entity, the regulator and the number
A legitimate processor tells you which company you're contracting with, who supervises it and under which number. Stripe's UK terms put it in one sentence:

Checkout.com lists every entity by country, each with its regulator and number:

Adyen, which holds a banking licence, goes further and tells you where to check it:

PayPal's European pages do the same: PayPal (Europe) S.à r.l. et Cie, S.C.A. "is a credit institution (or bank) authorized and supervised by Luxembourg's financial regulator," the CSSF. The pattern is the check: a company name, a regulator and a number. If a provider's site has none of the 3 in its footer, terms or legal page, you've learned the most important fact already.
Check 2: the register, by number, not by name
Copy the number and look it up yourself on the regulator's own site. In the UK that's the FCA's Financial Services Register. Stripe's number brings up the record:

Search by number, not by name, and compare the address, website and phone with what the provider gave you. The FCA warns about clone firms that copy the "name, address, registration number, or other credentials of a genuine authorised firm," mixing real details with their own contacts. Then read the status line: an authorised payment or e-money institution, a small payment institution with a volume cap, or only an agent of another firm. An agent isn't licensed itself; the firm behind it is the one you're relying on.
Outside the UK, the same check runs through other registers:
- UK — FCA Financial Services Register. Authorised and small PIs, EMIs, agents, status since date
- EU, all countries — EBA Payment Institutions Register. PIs, EMIs and agents reported by national regulators, with passporting
- Ireland — Central Bank of Ireland registers. Payment and e-money institutions
- Lithuania — Bank of Lithuania. EMIs and PIs, a common base for fintechs
- Malta — MFSA Financial Services Register. Licensed financial institutions
- Cyprus — Central Bank of Cyprus. PIs and EMIs
- Netherlands — DNB public register. PIs, including passported ones
- US — NMLS Consumer Access. State money transmitter licences
In the US, don't confuse a FinCEN money services business registration with a licence: registration is self-reported, while money transmission needs state licences, which NMLS shows. Checkout.com, for example, prints the NMLS number of its US entity, 1791692.
Check 3: card-network registration and PCI
Visa and Mastercard keep their own lists of service providers that card-network members have registered, with their PCI DSS validation where it applies. Visa's is a public search, the Global Registry of Service Providers. It also shows why you search carefully:

A name search returns unrelated companies with similar names. Match the legal entity and the website, then read the validation type, the "valid through" date and the assessor. Mastercard publishes its equivalent, the SDP registered service provider list, as a PDF you search by text.
Then ask the provider for its PCI DSS Attestation of Compliance (AOC), the signed summary of its PCI assessment, usually signed by a Qualified Security Assessor. It's standard practice for business customers to request it and to check that its scope covers the service you're buying. A line on a website saying "PCI-DSS Level 1" isn't an AOC.
Check 4: where your money sits before payout
Between your customer's payment and your payout, the provider holds your money. What protects it if the provider fails is safeguarding: licensed payment and e-money firms must keep client funds separate from their own, in segregated accounts or covered by insurance or a guarantee. The FCA's numbers show why it matters:

Since May 7, 2026, UK firms have operated under a stricter supplementary regime, CASS 15, with daily reconciliations, monthly reporting and annual audits of their safeguarding. And notice what deposit insurance doesn't do. Even Stripe's FCA record carries this warning:

Money at a payment or e-money firm isn't a bank deposit. Safeguarding is the only protection, and it only exists where there's a licence. When Wirecard collapsed in June 2020, the FCA froze its UK e-money subsidiary, Wirecard Card Solutions, and the fintech apps built on it, among them Curve and Pockit, lost access for several days until the regulator lifted the restrictions on June 30. Ask your provider in writing where your funds are safeguarded and with which bank.
Check 5: who the acquirer is
Somebody in the chain is a card-network member that settles your payments and carries your chargebacks. Adyen is its own acquirer. Many PSPs work through one or several acquiring banks, and an honest provider tells you which one handles your merchant category.
The question matters for 2 reasons. The acquirer decides whether your vertical is acceptable at all, so a provider that "accepts everything" without naming one is promising something it may not control. And if the provider disappears, the acquirer is the regulated party you can still reach. We explain the chain and who carries what in our guide to high risk merchant accounts.
Check 6: the terms, before the first transaction
A processor that publishes no terms of service and no privacy policy is asking you to sign something you can't read. A published agreement tells you what really governs your money:
- Termination: can they close you "at any time," and with what notice?
- Holds and reserves: PayPal's agreement, for example, allows holds of up to 180 days.
- Fees: including chargeback fees and fees for refunds.
- Who you contract with: the same entity you found in the register.
- Governing law: where you'd have to bring a claim.
We cover what happens when accounts are declined or closed, and what holds look like in practice, in Merchant Account Declined or Closed.
Red flags you can spot without a sales call
- No company name, regulator or number anywhere on the site: You can't check who holds your money
- A licence number that leads to a different firm or address: The pattern of a clone firm
- No terms of service or privacy policy: Nothing tells you how holds, fees and closures work
- Product pages copied from another provider: The features may describe someone else's product
- An address in one country, staff and owners in others, no explanation: You can't tell which law protects you
- "No KYC" or "guaranteed approval" for any vertical: Licensed firms can't offer either
- Reviews only in directories that repeat the provider's own text: No independent evidence of payouts
None of these proves fraud. Each one is a reason to stop and ask before money moves.
Checklist: what to do
Questions and answers
How do I check if a payment processor is legit?
Find the legal entity, regulator and licence number on its site, then look the number up in the regulator's own register and compare the details. Add the card networks' registries, a PCI DSS Attestation of Compliance, a written answer on safeguarding and the acquirer, and published terms.
How do I verify that a UK payment firm is FCA authorised?
Search the FCA Financial Services Register by the firm reference number, not the name, and check that the address, website and status match. Look for "Authorised Payment Institution" or "Authorised Electronic Money Institution," and watch for agents and clone firms.
Is my money protected if my payment provider goes bust?
Not by deposit insurance: the FCA register itself warns that the FSCS won't compensate you if a payment or e-money firm fails. Licensed firms must safeguard client funds instead, and UK firms that failed between 2018 and 2023 were on average 65% short.
What is a PCI DSS Attestation of Compliance?
It's the signed summary of a provider's PCI DSS assessment, usually signed by a Qualified Security Assessor, showing that the provider handles card data to the standard. Business customers routinely ask for it; check that its date is current and its scope covers your service.
Why should I ask which acquirer a payment provider uses?
The acquirer is the card-network member that settles your payments and decides which verticals are acceptable. A provider that won't name one can't show you who stands behind your processing if it fails or drops your category.
Author’s conclusion
Checking a payment processor is easier than checking an affiliate network, because regulators publish what networks keep private. The legit ones make it easy: Stripe, Checkout.com and Adyen print the entity, the regulator and the number, and the register confirms them in a minute.
My advice: if a provider can't pass check 1, stop there. If it passes, spend the evening on the rest, start small, and withdraw often. A processor that holds your money should be the easiest company in your stack to find on paper.
Lu Discover, Editor-in-chief
Sources for this article
- stripe.com — Stripe Payments UK Limited legal page (authorised EMI, FCA reference number 900461)
- checkout.com — Checkout.com legal certificates (Checkout Ltd FCA 900816; Checkout SAS ACPR 17208; Checkout US NMLS 1791692)
- adyen.com — Adyen licenses, Europe (Adyen N.V., De Nederlandsche Bank, company number 34259528, UK branch)
- paypal.com — PayPal Europe about page (credit institution supervised by the CSSF)
- register.fca.org.uk — FCA Financial Services Register: Stripe Payments UK Limited, FRN 900461 (authorised EMI since 02/05/2018; FSCS notice)
- fca.org.uk — FCA warning: clone firms copying authorised firms' details
- eba.europa.eu — EBA central register of payment and electronic money institutions under PSD2 (March 18, 2019)
- centralbank.ie — Central Bank of Ireland: payment institutions
- lb.lt — Bank of Lithuania: electronic money institutions
- fsr.mfsa.mt — MFSA Financial Services Register
- dnb.nl — DNB register of payment institutions
- nmlsconsumeraccess.org — NMLS Consumer Access
- visa.com — Visa Global Registry of Service Providers, search for "checkout" (October 8, 2026)
- mastercard.com — Mastercard SDP compliant registered service provider list
- eur-lex.europa.eu — Directive (EU) 2015/2366 (PSD2), Article 10 safeguarding requirements
- fca.org.uk — FCA PS25/12: Changes to the safeguarding regime for payments and e-money firms (August 7, 2025; paragraph 2.3, 65% shortfall; CASS 15 from May 7, 2026)
- fintechfutures.com — FCA lifts restrictions on Wirecard Card Solutions (June 2020)
- financemagnates.com — Wirecard UK customer funds frozen after FCA imposes requirements (June 2020)
- paypal.com — PayPal User Agreement (holds up to 180 days)






Comments
0 commentsNo comments yet.
Add a comment