2026 China Payment Regulatory Overhaul: What International Businesses Must Know
2026 marks the most intense year of payment regulation in China’s history. From the Classification Rating Measures to the Financial Law draft and record-breaking fines — if your business interacts with Chinese payment institutions, you need to understand these changes. This guide breaks down every major regulation and its practical implications for foreign enterprises.
1. The Regulatory Backdrop: Why 2026?
China’s third-party payment industry has grown from a fledgling sector to a 576 trillion yuan juggernaut. But with scale comes scrutiny. The regulatory framework that once allowed rapid innovation is now maturing into a comprehensive, multi-layered system designed to ensure stability, security, and accountability.
The foundation was laid with the Regulations on the Supervision and Administration of Non-Bank Payment Institutions in 2024. But 2026 is the year everything accelerated. Within the first seven months of the year, regulators issued a flurry of major policies — from the Classification Rating Measures (effective February 2026) to the draft Financial Law (March 2026), the Financial Product Online Marketing Management Measures (April 2026), and the Financial Industry Cybersecurity Management Measures (征求意见稿, July 2026).
This is not a coincidence. It reflects a deliberate policy direction: moving from reactive, case-by-case enforcement to proactive, systemic, and lifecycle-based regulation. For international businesses, this means the compliance baseline has shifted — and ignorance is no longer an excuse.
2. Key Policies Decoded
Classification Rating Measures
What it is: The People’s Bank of China (PBOC) issued the revised Measures for the Classification Rating of Non-Bank Payment Institutions on December 31, 2025, effective February 1, 2026.
How it works: Payment institutions are rated across seven modules totaling 100 points:
- Business Standards — 25 points (highest weight)
- System Security — 15 points
- Anti-Money Laundering — 15 points
- Operational Soundness — 15 points
- Corporate Governance — 10 points
- Customer Reserve Management — 10 points
- User Rights Protection — 10 points
Ratings are divided into 5 categories and 11 sub-levels, with A being the highest and E the lowest. The rating determines the intensity of regulatory scrutiny — D-rated institutions face mandatory supervisory interviews, enhanced reserve monitoring, and become “key targets” for ongoing supervision.
Critical restriction: Ratings cannot be used for advertising or marketing. This prevents institutions from turning compliance into a competitive differentiator — but it also means you can’t rely on a partner’s self-proclaimed rating.
Financial Law (Draft)
What it is: China’s first comprehensive, foundational financial law, jointly drafted by the Ministry of Justice, PBOC, the National Financial Regulatory Administration, the CSRC, and the State Administration of Foreign Exchange. The public comment period ran from March 20 to April 19, 2026.
11 chapters, 95 articles covering central bank functions, financial institution lifecycle management, financial products and services, markets, infrastructure, regulatory systems, and risk resolution mechanisms.
The game-changer: Article 3 explicitly defines non-bank payment institutions as “financial institutions”. This ends years of ambiguity over whether payment platforms are “tech companies” or “financial entities.”
Implications: Payment institutions will now be subject to the same high standards of corporate governance, capital adequacy, and legal liability as banks and securities firms. The law also mandates that “all financial activities are brought under regulatory oversight”, closing loopholes that previously allowed some institutions to operate in gray areas.
For foreign partners, this means your Chinese payment counterparties are now operating under a legal framework that is more predictable — but also more demanding.
Financial Product Online Marketing Management Measures
What it is: Issued by eight ministries including the PBOC, effective September 30, 2026.
The headline provision (Article 12): Non-bank payment institutions are prohibited from including loans, asset management products, or similar financial products as payment tool options. They are also barred from providing marketing services for such products.
Why this matters: This directly targets the practice of embedding “borrow” or “loan” buttons within payment interfaces — a common feature on many Chinese platforms that allowed users to take out credit with a single tap. The regulation severs the improper link between payment and 信贷.
Business impact: Payment platforms are now required to cleanse their payment interfaces of any lending or investment product references. This reduces the risk of users inadvertently taking on debt through payment apps — but it also changes the revenue models of many platforms that relied on credit cross-selling.
Financial Industry Cybersecurity Management Measures
What it is: Jointly drafted by the PBOC, NFRA, CSRC, and SAFE, with public feedback due by August 3, 2026.
5 chapters, 33 articles establishing unified cybersecurity standards for the entire financial sector.
Who it covers: All licensed payment institutions are fully brought under the scope of this regulation.
Why it’s needed: Payment institutions handle massive volumes of user funds, identity data, and real-time transaction records — making them prime targets for telecom fraud, money laundering, and data breaches. Previously, cybersecurity requirements were scattered across separate regulations for payment settlement, data security, and other areas. This new rule creates a unified, sector-wide standard.
What it means: Payment institutions will need to upgrade systems, strengthen security protocols, and establish ongoing assessment mechanisms. Cybersecurity is being elevated from a back-office concern to a core compliance metric.
Taken together, these four policies form a comprehensive regulatory architecture that covers every dimension of a payment institution’s operations: governance (Classification Rating), legal status (Financial Law), product boundaries (Online Marketing Rules), and infrastructure security (Cybersecurity Measures).
3. Enforcement in Action: Fines & License Revocations
Words on paper are one thing. But 2026 has also been a year of unprecedented enforcement action. The message from regulators is clear: compliance is not optional.
Record-Breaking Penalties
The year has already seen six “million-level” fines (penalties exceeding 10 million yuan), with the largest single penalty reaching approximately 74.45 million yuan.
| Institution | Penalty Amount | Date | Key Violations |
|---|---|---|---|
| Shanghai Hanyin Information Technology | ≈74.45 million | July 2026 | Clearing management & merchant regulation violations |
| Yipiao Union Pay | 48.35 million | June 2026 | Payment settlement, fintech & AML violations |
| Kailiantong Payment | 38.43 million | January 2026 | 7 categories of violations |
| Huichao Payment | 34.22 million | June 2026 | Clearing, account & merchant violations |
What’s notable is the breadth of violations — from clearing and merchant management to AML and account regulations. These are not technicalities; they go to the heart of how payment institutions operate.
License Revocations Accelerate
The PBOC has now revoked 113 payment licenses in total, leaving just 158 licensed institutions standing. In 2026 alone, at least five licenses have been formally revoked, including Kailiantong Payment, Shanglianxin Payment, and Shengya Yunding Payment — all of which were once licensed operators.
Kailiantong is particularly telling: it was among the first 27 institutions to receive a PBOC payment license in 2011, and had nationwide prepaid card issuance and internet payment capabilities. Its license renewal was not accepted, and it was formally delisted in April 2026. Shanglianxin Payment’s license had been suspended since 2021 and was finally revoked in May 2026.
4. Practical Implications for International Businesses
So what does all of this mean for your business — whether you’re a multinational corporation, a law firm, a financial institution, or an investor?
- Re-evaluate your payment partners. The Classification Rating system means not all payment institutions are created equal. A low-rated partner may face heightened regulatory scrutiny, operational restrictions, or even license revocation. Request proof of license status and compliance history as part of your vendor due diligence.
- Understand the new legal status. With non-bank payment institutions now formally classified as “financial institutions” under the Financial Law, they are subject to stricter governance, capital, and liability standards. This affects everything from contract enforceability to dispute resolution.
- Watch for interface changes. The ban on embedding loan products in payment interfaces means payment apps will look different after September 30, 2026. If your business relies on integrated payment-lending features (e.g., for consumer financing), you’ll need to adapt.
- Cybersecurity is now a compliance cornerstone. The Cybersecurity Management Measures impose binding security standards on all licensed payment institutions. Ask your partners about their security certifications, incident response protocols, and data protection frameworks.
- Prepare for more consolidation. With 113 licenses already revoked and more expected, the industry is consolidating around stronger, more compliant players. Your partners should be among the survivors — not the ones being pushed out.
The regulatory overhaul of 2026 is not a one-off event. It represents a fundamental shift in how China governs its payment ecosystem — from a permissive, innovation-first approach to a mature, risk-aware, and rule-based framework.
For international businesses, this is ultimately good news. A clearer, more predictable regulatory environment reduces uncertainty and creates a level playing field. But it also means that due diligence is more important than ever. You can no longer rely on surface-level checks; you need verified, authoritative, and up-to-date information about your Chinese partners.
ChinaBizInsight helps international businesses navigate this complex landscape. We provide direct access to China’s National Enterprise Credit Information Publicity System, delivering government-verified reports that include corporate registration, shareholder structures, legal risks, and operational histories. We also offer notarization and apostille services to ensure your documents are recognized globally.
View Professional Credit Reports → Contact Our Compliance Team
📚 References
- People’s Bank of China. (2025). Measures for the Classification Rating of Non-Bank Payment Institutions. Effective February 1, 2026.
- Ministry of Justice, PBOC, NFRA, CSRC, SAFE. (2026). Financial Law of the People’s Republic of China (Draft). Public comment period: March 20 – April 19, 2026.
- Eight Ministries including PBOC. (2026). Financial Product Online Marketing Management Measures. Effective September 30, 2026.
- PBOC, NFRA, CSRC, SAFE. (2026). Financial Industry Cybersecurity Management Measures (Draft for Comments). Feedback deadline: August 3, 2026.
- 21st Century Business Herald. (2026). “74.45 Million Yuan: The Year’s Largest Third-Party Payment Fine.” July 4, 2026.
- 21st Century Business Herald. (2026). “Six Payment Institutions Deregistered as Industry Consolidation Normalizes.” July 28, 2026.
- Economic Daily. (2026). “Differentiated Supervision of Payment Institutions Further Improved.” January 12, 2026.
ChinaBizInsight
Your strategic bridge to transparent business in China.