New Financial Conduct Authority rules governing Buy Now Pay Later came into force on 15 July 2026, requiring providers of Deferred Payment Credit agreements to conduct affordability checks and bringing UK BNPL into the mainstream consumer credit regime. The consumer-facing obligations have drawn most public attention, but payments industry veterans argue the deeper operational challenge sits one layer down the stack, inside the acquiring and processing infrastructure that moves every transaction.

Robert Kraal, co-founder of cloud-native processing platform Silverflow and a former chief operating officer at Adyen, says the structural problem is one of data granularity. Under the new framework, whether a DPC agreement is regulated depends on the lender-merchant relationship and the date the agreement was signed. That means regulated and unregulated BNPL payments will continue to travel on the same processing rails, and acquirers must now distinguish between them at the level of the individual transaction rather than the product category.
“Acquirers and processors now have to distinguish regulated from unregulated DPC at the level of the individual transaction, account for new Section 75 refund exposure, and support the dispute, reporting and consumer duty obligations that follow,” Kraal said. “If an acquirer or processor doesn’t have that information then they can’t be compliant.”
The infrastructure gap
The compliance challenge Kraal describes is not unique to BNPL, but the new rules expose it more sharply than most regulatory changes have. Legacy processing platforms, many built before the era of real-time data demands, were designed to move money efficiently rather than to tag, trace and report at the resolution that modern regulation increasingly assumes. The result, as Kraal frames it, is compliance cost absorbed as manual reconciliation work rather than captured in the platform itself.
Section 75 liability is the most immediate pressure point. Under the Consumer Credit Act, Section 75 gives consumers a claim against the creditor as well as the merchant in the event of a breach of contract or misrepresentation. Extending that protection to regulated BNPL means acquirers need to know in real time which agreements carry that liability and which do not. Processing infrastructure that cannot make that determination cannot reliably apportion exposure or file the required reports.
Kraal’s argument maps onto a broader structural debate in payments: the gap between what regulators now assume processing platforms can do and what the installed base of infrastructure actually does. Several established processors are mid-way through multi-year core platform modernisation programmes, and the BNPL rules arrive before those programmes are complete.
Regulatory read-across
The FCA’s move to bring BNPL into regulated consumer credit follows years of consultation and multiple missed legislative windows since the Woolard Review of 2021 first identified the sector as a priority. The rules apply to agreements where a third-party lender pays the merchant and the consumer repays the lender, the model used by the major standalone BNPL providers. Merchant-funded instalment products sit in a different regulatory category and are not caught by the same obligations.
Firms that have invested in cloud-native, API-first infrastructure argue they are better placed to absorb the tagging and reporting requirements because those capabilities were built in from the start rather than retrofitted. For processors still running on older platforms, the near-term cost is likely to be headcount in compliance and reconciliation rather than a technology replacement cycle. Kraal’s broader point is that the two trajectories will diverge materially as the FCA and other regulators continue to raise the data and reporting bar across consumer credit products.
The post BNPL Regulation Shifts Compliance Burden Onto Payment Processors appeared first on The Fintech Times.