The Complete Guide to Retail Payment Services & Card Schemes Under the CBUAE (2026 Edition)

By CRYPTOVERSE Legal Consultancy
Advising Fintech, Payment Institutions & Cross-Border Remittance Operators on CBUAE Licensing & Regulatory Strategy

The Regulatory Backbone of the UAE Payment Ecosystem

If you are building a payment company in the UAE, there is one regulatory framework you cannot afford to misunderstand:

The Retail Payment Services and Card Schemes Regulation (RPSCS) under the Central Bank of the UAE (CBUAE).

Whether you are:

  • Launching a payment gateway
  • Operating a remittance platform
  • Providing cross-border transfers
  • Acting as a merchant acquirer
  • Offering payment aggregation services
  • Building open banking infrastructure
  • Integrating payment token functionality

RPSCS likely governs your activity.

And unlike many fintech founders assume, RPSCS is not just a licensing formality.

It is a prudential, governance, capital, and compliance framework that defines how your business must operate, before and after approval.

This guide breaks down:

  • What RPSCS regulates
  • How licence categories work
  • Capital thresholds and escalation triggers
  • Supervisory expectations
  • Common structuring errors
  • Cross-border implications
  • How to secure approval efficiently
  • Ongoing compliance architecture

If you want to build a sustainable payment business in the UAE, this is your blueprint.

Part I — What Is RPSCS and Why It Matters

The RPSCS Regulation governs the provision of Retail Payment Services and Card Schemes in the UAE (outside financial free zones such as DIFC and ADGM).

It was introduced to:

  • Strengthen payment system stability
  • Protect consumers
  • Reduce systemic risk
  • Align with international standards
  • Formalise digital payment infrastructure

It applies to entities performing defined payment activities, regardless of whether they label themselves as fintech, remittance provider, payment gateway, or digital platform.

Classification is based on activity, not branding.

Part II — Activities Regulated Under RPSCS

RPSCS captures a wide spectrum of payment services, including:

1️. Payment Account Issuance

Opening and maintaining payment accounts.

2️. Payment Instrument Issuance

Issuing debit cards, prepaid cards, or other payment instruments.

3️. Merchant Acquiring

Contracting merchants and processing card payments.

4️. Payment Aggregation

Aggregating merchant transactions under a single acquiring arrangement.

5️. Domestic Fund Transfers

Local payment transfers within the UAE.

6️. Cross-Border Fund Transfers

International remittance services.

7️. Payment Initiation Services

Open banking-based initiation of payments.

8️. Account Information Services

Access to consolidated account data (open banking).

9️.  Payment Token Services (Category I reference scope)

If your business executes the movement of funds on behalf of customers, RPSCS likely applies.

Part III — Licence Categories Explained

RPSCS divides licensing into four categories.

Understanding the difference is critical for structuring capital and compliance.

Category IV — Payment Initiation & Account Information

  • Limited scope
  • Open banking services
  • No direct holding of client funds
  • Lowest capital requirement (approx. AED 100,000)

Lower systemic risk profile.

Category III — Domestic Retail Payment Services

  • Domestic transfers
  • Payment aggregation
  • Merchant services (limited scope)
  • Capital: AED 500,000 – 1,000,000

Suitable for UAE-only payment platforms.

Category II — Cross-Border Retail Payment Services

  • Cross-border remittance
  • International transfer facilitation
  • Higher AML risk exposure
  • Capital: AED 1,000,000 – 2,000,000

Significantly heightened supervisory scrutiny.

Category I — Full-Scope Retail Payment Services

  • Comprehensive payment activity
  • May include merchant acquiring
  • May intersect with Payment Token Services
  • Capital: AED 1,500,000 – 3,000,000

Highest prudential tier under RPSCS.

Part IV — Capital Requirements: The Transaction-Based Model

Unlike SVF, which scales capital by Float, RPSCS capital scales by:

  • Licence category
  • Transaction scope
  • Cross-border exposure

Capital must be:

  • Fully paid-up
  • Unencumbered
  • Deposited in UAE bank
  • Transparent in source

In addition to initial capital, licensees must maintain aggregate capital funds on an ongoing basis.

Part V — Escalation Triggers Founders Often Miss

RPSCS classification can escalate due to:

  • Introduction of cross-border transfers
  • Rapid transaction growth
  • Expansion into merchant acquiring
  • Addition of payment token functionality
  • Holding client funds longer than expected

A domestic-only PSP that adds international remittance functionality may automatically move from Category III to Category II.

That shift doubles capital exposure and supervisory intensity.

Part VI — Client Fund Safeguarding

While RPSCS is transaction-focused, it still imposes safeguarding obligations.

If your business:

  • Holds customer funds
  • Delays settlement
  • Operates aggregation

You must implement:

  • Client fund segregation
  • Reconciliation controls
  • Liquidity management
  • Operational risk safeguards

Safeguarding expectations vary by category but are always material.

Part VII — Cross-Border Remittance: The High-Risk Layer

Cross-border transfers significantly increase supervisory focus due to:

  • AML/CFT exposure
  • Sanctions compliance
  • Fraud risk
  • Correspondent banking risk

Category II and I licensees must demonstrate:

  • Enhanced AML systems
  • Robust transaction monitoring
  • Cross-border partner due diligence
  • Sanctions filtering

Weak AML architecture is a common rejection factor.

Part VIII — Merchant Acquiring & Payment Aggregation

Merchant acquiring introduces:

  • Settlement risk
  • Chargeback exposure
  • Fraud liability
  • Card scheme governance

Aggregators must:

  • Conduct merchant due diligence
  • Monitor merchant activity
  • Maintain fraud controls
  • Structure acquiring agreements carefully

Acquiring expands systemic risk footprint significantly.

Part IX — Payment Token Services & RPSCS

Payment Token Services (PTS) fall within Category I reference scope.

If you:

  • Facilitate stablecoin payments
  • Provide token exchange
  • Enable merchant acceptance of tokens

You may require Category I licensing in addition to PTS compliance.

Dual analysis is often required.

Part X — Governance & Fit and Proper Requirements

CBUAE evaluates:

  • Board competence
  • Senior management experience
  • Compliance Officer appointment
  • MLRO appointment
  • Financial oversight capability

Controllers require prior approval.

Weak governance structures delay approval.

Part XI — AML & Financial Crime Controls

RPSCS licensees must implement:

  • Risk-based AML framework
  • Enterprise-wide risk assessment
  • Sanctions screening
  • Transaction monitoring
  • Suspicious activity reporting
  • Ongoing customer due diligence

Cross-border PSPs face elevated AML scrutiny.

Part XII — Technology & Operational Resilience

Payment systems must demonstrate:

  • Secure infrastructure
  • Access controls
  • Business continuity planning
  • Disaster recovery capabilities
  • Incident reporting protocols

Operational disruption in payment systems has systemic impact.

Part XIII — Pre-Application Strategy for RPSCS

Before submission, founders should:

  1. Confirm licence category
  2. Model transaction growth
  3. Stress-test capital thresholds
  4. Draft regulator-grade business plan
  5. Build AML framework tailored to activity
  6. Prepare source-of-funds documentation
  7. Structure governance early
  8. Conduct regulatory engagement meeting

Filing without preparation invites delay.

Part XIV — Common Structuring Errors

Underestimating cross-border impact
Misclassifying payment aggregation
Weak AML documentation
Inadequate merchant due diligence
Over-optimistic revenue forecasts
Adding stablecoin features without reassessment

RPSCS enforcement risk increases with systemic impact.

Part XV — Post-Licensing Supervision

Once licensed, you must maintain:

  • Capital adequacy
  • Regulatory reporting
  • Incident notification
  • Ongoing AML monitoring
  • Governance oversight
  • Regulatory communication

Licensing is the beginning of supervision.

Part XVI — Investor Perspective

Investors evaluating a UAE PSP should ask:

  • Is the correct category selected?
  • Has cross-border exposure been stress-tested?
  • Are AML systems mature?
  • Is capital buffer adequate?
  • Are merchant risks managed?

Regulatory clarity strengthens valuation.

Part XVII — The Future of Retail Payments in the UAE

The UAE is rapidly digitising payments.

Expect:

RPSCS will remain central to this ecosystem.

Final Thoughts: Designing for Sustainable Growth

RPSCS licensing is not about securing approval.

It is about building trust:

  • With the regulator
  • With customers
  • With banks
  • With investors

The most successful PSPs are those that:

  • Classify correctly
  • Model capital early
  • Build AML maturity
  • Structure governance professionally
  • Anticipate growth triggers

Regulatory strategy is growth strategy.

Why CRYPTOVERSE Legal Consultancy

We advise fintech, remittance operators, and payment institutions on:

  • RPSCS licence classification
  • Category escalation modelling
  • Capital planning
  • AML framework implementation
  • Governance structuring
  • Regulatory engagement strategy
  • Ongoing compliance advisory

Our approach is structural and strategic.

We design payment businesses to scale safely.

Key Takeaways

  • RPSCS governs retail payment execution in the UAE.
  • Four categories define capital and scope.
  • Cross-border exposure increases supervisory intensity.
  • Capital is tier-based, not Float-based.
  • AML maturity is critical for approval.
  • Misclassification causes delays and capital shock.
  • Pre-application structuring determines approval success.

Legal Disclaimer: This article is provided for informational purposes only and does not constitute legal advice. RPSCS licensing requirements depend on the specific services, transaction scope, cross-border exposure, governance structure, and operational model of the applicant. Formal legal analysis should be undertaken prior to engagement with the Central Bank of the UAE.

FAQs

1. What is RPSCS licensing in the UAE?

RPSCS licensing is the regulatory framework issued by the Central Bank of the UAE (CBUAE) for businesses providing retail payment services, including payment gateways, remittance services, merchant acquiring, and payment aggregation.

2. Who needs an RPSCS licence in the UAE?

Any business offering regulated payment services such as domestic or cross-border fund transfers, payment account issuance, merchant acquiring, payment aggregation, or payment initiation services may require an RPSCS licence.

3. What are the RPSCS licence categories?

The CBUAE RPSCS framework has four licence categories based on the type of payment services offered, transaction scope, and risk profile. Each category has different capital and compliance requirements.

4. What are the capital requirements for an RPSCS licence?

Capital requirements vary depending on the licence category and the nature of the payment services provided. Businesses must maintain fully paid-up capital and meet ongoing capital adequacy obligations under the CBUAE regulations.

5. How can businesses improve their chances of RPSCS licence approval?

Businesses should select the correct licence category, establish a robust AML/CFT compliance framework, implement strong governance and risk management systems, maintain adequate capital, and prepare comprehensive regulatory documentation before applying.