Skip to main content

PSCR PUBLIC GUIDE

How to identify the legal entity and permission behind a payment service

A brand, app, agent, merchant and authorised institution can occupy different positions in the same customer journey.

01

Plain-language summary

Begin with the contract and the exact legal name, not the logo. Record the official identifier, jurisdiction and institution category. Then identify the permission and activity relevant to the service actually used. Only after that should agents, distributors, merchants, brokers and group companies be mapped.

The purpose is not to decide that an institution is good or bad. It is to avoid attributing a permission, safeguarding responsibility or complaint route to the wrong entity.

02

Brand and legal entity

A customer-facing name can be owned or used by one company while another provides the regulated payment service. Terms, statements, receipts, account information and official sources may each reveal part of the relationship. Similar names and shared ownership do not create one legal identity.

An exact-entity record should preserve current and former names, official identifiers and material changes. Where a group contains several regulated and unregulated companies, each role should be stated separately.

03

Permission and service perimeter

Permission is entity-specific and activity-specific. A broad description such as “regulated” does not explain which services, restrictions, territories or customer categories are relevant. The analysis should connect the permission to the service in question and preserve the source date.

An agent may act for a principal without holding the principal’s full permission in its own right. A merchant may accept a payment without becoming the institution holding customer funds. A broker or technology provider may facilitate access while occupying another contractual role.

04

Evidence questions

Read the customer journey as a relationship map.

  • Which entity appears in the contract and account information?
  • Which official identifier resolves that entity?
  • What permission covers the service actually provided?
  • Are restrictions, territories or customer categories material?
  • Which agents or distributors are involved and for which principal?
  • Who receives funds, handles complaints and owes the return obligation?
  • Has the relationship changed since the source date?
05

What not to assume

Do not transfer a permission across a group. Do not treat an agent as holding every permission of its principal. Do not treat a brand as the contracting institution without evidence. Do not infer that a commercial relationship creates shared PSCR or RMCA status.

A precise map may still contain gaps. Those gaps should be labelled rather than filled with inference. Official sources, contractual documents and institution-owned evidence can differ in date and purpose.

06

Continue the entity trail

Use Entity and Permissions for the six core checks. The PSCR Register architecture explains how a future programme record would connect to canonical RMCA identity while preserving programme separation. RCEF describes evidence character and change control.