Skip to content

Global payments intelligence

Updated Aug 24, 2026 · 23:32 UTC

Now tracking SEC Proposes Crypto Offering Exemptions and Conditional Safe Harbor
Payments intelligence
Company News

Mastercard’s Vocalink Fined £11.9M Over UK Payments-Control Failures

The Bank of England imposed its first financial-market-infrastructure fine after finding that Mastercard-owned Vocalink failed to complete required controls remediation on time. The sanction puts governance, not an outage, at the center of payments resilience.

The Bank of England fined Mastercard-owned Vocalink £11.9 million on July 9, 2025, after finding that the UK payments-infrastructure operator failed to complete required systems-and-controls remediation by a regulatory deadline.

The action is significant beyond the size of the penalty. It was the Bank’s first fine against a financial market infrastructure firm, and it concerned the internal machinery meant to ensure that risks are identified, escalated and resolved. The regulator did not describe a payments outage or customer loss. Instead, it found that weaknesses in risk management, governance and escalation prevented Vocalink from complying fully with a formal direction.

A remediation program that missed its deadline

The Bank had directed Vocalink under section 191 of the Banking Act 2009 to remedy previously identified systems-and-controls issues. Vocalink established a remediation program and was required to meet the direction’s requirements by February 28, 2022.

According to the Bank, Vocalink did not comply in full by that deadline. The regulator identified an insufficiently integrated risk-management framework as the root cause. It said the framework did not enable program risks to be properly understood, monitored and shared among the firm’s three lines of defence and external assurance providers. The investigation also found failures to escalate key risks and information to senior committees.

“Vocalink fell short of its obligation to have adequate risk management and governance arrangements when responding to the Bank’s Direction,” Sarah Breeden, the Bank’s deputy governor for financial stability, said in the enforcement announcement.

Why Vocalink’s infrastructure role raises the stakes

Vocalink designs, builds and operates bank-account-based payments infrastructure in Britain. The Bank has regulated it since April 2018 as a specified service provider involved in UK payment systems. The regulator describes recognised payment systems as critical to financial markets and the economy because they transfer funds among individuals and businesses.

Reuters reported that Vocalink is owned by Mastercard and, citing the company’s website, said its infrastructure processes more than 90% of UK salaries, more than 70% of household bills and 98% of state benefits. Those company-sourced figures illustrate why deficient oversight at an infrastructure provider matters even when no service disruption is identified: control failures can sit inside systems on which routine economic activity depends.

The Bank specified that the penalty was imposed on Vocalink Limited only. It did not announce a sanction against Mastercard Incorporated. Still, the case is material company news for Mastercard because Vocalink is part of its strategy beyond the card network, extending the group into account-to-account payment infrastructure and the operational obligations that come with it.

Admissions and settlement reduced the fine

The Bank said Vocalink’s cooperation and early admission of a compliance failure reduced the penalty by 15%. The company received a further 30% reduction for agreeing to resolve the matter. Without those reductions, the fine would have been £20 million.

Vocalink told Reuters that it was pleased to resolve a matter involving issues identified in 2020 and had since delivered improvements. The company said the historical control issues had no impact on services delivered to UK consumers and businesses. That no-impact statement is Vocalink’s position; the regulator’s published finding focused on deficient governance and incomplete compliance rather than an outage or consumer-loss assessment.

The accountability lesson for payment operators

Operational resilience is often discussed in terms of uptime, cyberattacks and incident recovery. This enforcement action shows that regulators also treat the governance around remediation as part of resilience. A program can exist, attract investment and still fail if risks do not move through assurance functions and reach senior decision-makers in time.

For payment groups expanding from network services into critical infrastructure, acquisition broadens the accountability perimeter. The relevant test is not only whether transactions continue to clear, but whether the operator can prove that identified weaknesses are owned, escalated and fixed by the deadline a supervisor has set.