Contadores e assessores de IA habilitados, integrados ao ESG e globalmente conectados. Auditoria, impostos, consultoria, finanças corporativas e 16 pilares de serviços especializados.Contadores e assessores de IA habilitados, integrados ao ESG e globalmente conectados. Auditoria, impostos, consultoria, finanças corporativas e 16 pilares de serviços especializados.Contadores e assessores de IA habilitados, integrados ao ESG e globalmente conectados. Auditoria, impostos, consultoria, finanças corporativas e 16 pilares de serviços especializados.Contadores e assessores de IA habilitados, integrados ao ESG e globalmente conectados. Auditoria, impostos, consultoria, finanças corporativas e 16 pilares de serviços especializados.
All insights

FCA Authorisation Requirements UK: Fintech Guide

Understand FCA authorisation requirements in the UK, compare direct authorisation with AR, and prepare a stronger fintech application.

14 September 2026

The FCA authorisation requirements UK fintech founders need to meet depend on the activities, customers, permissions, and operating model they intend to run. A payments platform, e-money issuer, investment business, cryptoasset firm, and credit provider may face different routes and evidence requirements. The first task is therefore not to complete a form. It is to define the regulatory perimeter, choose the right route, and show that the business is ready to operate responsibly.

This guide sets out a practical sequence for founders, CFOs, legal teams, and compliance leads. It covers direct authorisation, appointed representative arrangements, business-plan evidence, governance, SM&CR, financial resources, and the issues that commonly delay applications. It is general information, not legal advice or a guarantee of authorisation. Always check the latest FCA rules and the requirements for the specific permission you seek.

Book a consultation to map your fintech's regulatory route and application readiness.

Why FCA authorisation matters for UK fintechs

Most firms carrying on regulated financial services in the UK must be authorised or registered before they begin the relevant activity. The FCA distinguishes between authorisation, which gives a firm permission to conduct specified regulated activities, and registration, which applies to certain regimes where the firm must meet defined requirements without receiving the same form of permission.

That distinction affects product design, marketing, customer onboarding, capital planning, governance, and launch timing. The FCA states that a firm must not perform regulated activities while an application is under review unless an exemption or temporary permission applies. Treating authorisation as an administrative step after launch can create enforcement risk and force expensive changes to a product that has already been built.

For a startup, the application is also a test of whether the business can explain how it will operate in practice. The FCA expects applicants to be ready, willing, and organised to comply with current and future rules. That means the application should connect the proposition, customer journey, people, controls, technology, finances, and oversight rather than present disconnected policy documents.

The starting point is the FCA's authorisation and registration guidance and the Perimeter Guidance Manual. These help a firm determine whether its activities are regulated, excluded, or subject to a different registration route.

Step 1: Define the regulatory perimeter and permission set

Write down what the fintech will do, who will use it, how money or assets will move, and which entity will provide each service. Describe the activity in operational terms, not only with product language. For example, "a wallet app" does not identify whether the business issues e-money, provides payment services, arranges investments, gives advice, holds client money, or performs another regulated activity.

Build a permission map that answers:

  • What products and services will be offered at launch and later phases?
  • Will the business hold, safeguard, transmit, or issue customer money?
  • Will it execute, arrange, advise on, or manage investments?
  • Will it serve retail customers, professional clients, or both?
  • Which legal entity contracts with customers and controls the relevant systems?
  • Will third parties, agents, distributors, or group companies perform material activities?

Then test the proposed scope against the FCA's perimeter guidance and the specific application route. A firm that asks for too little permission may need a variation later. A firm that asks for permissions it cannot evidence may create avoidable scrutiny and delay.

Step 2: Choose the right route: direct authorisation, registration, or AR

There is no universal route for a UK fintech. The appropriate option depends on the activities and the degree of control the business needs. The main choices are:

Route

When it may apply

Key implication

Direct FCA authorisation

The firm will conduct regulated activities in its own name under FSMA or another applicable regime.

The firm must demonstrate its own governance, people, controls, resources, and ability to meet the relevant conditions.

Payment or e-money registration/authorisation

The model involves payment services, e-money, or certain account information services.

The firm must select the correct PSRs or EMRs route and evidence matters such as safeguarding, governance, financial resources, and operational capability.

Appointed representative

The business carries out specified regulated activities under the responsibility of a principal with the relevant permission.

A written agreement and principal oversight are required. The arrangement does not remove the need for careful governance and due diligence.

Introducer appointed representative

The business has a limited role, such as introductions or distributing financial promotions.

The permitted activity is narrower than a full AR model and must remain within the agreed boundary.

The FCA explains that an AR should identify the activities it wants to carry out, find a principal with the right permission, agree a written contract, and provide information for the principal's notification. The principal must notify the FCA 30 calendar days before the appointment. Use the FCA's appointed representative guidance when evaluating this route.

An AR arrangement can be appropriate for a narrowly defined proposition or an early-stage business that needs to operate within a principal's framework. It is not a shortcut around regulatory responsibility. The principal must oversee the AR, while the AR must comply with the agreed scope and provide the information needed for oversight. If the fintech expects to control its own permissions, product governance, and customer proposition over the long term, it should assess direct authorisation early rather than treat AR status as an automatic bridge.

Step 3: Build the regulatory business plan around the real operating model

A strong regulatory business plan is not an investor deck with compliance language added at the end. The FCA's sample business plan says the document must be tailored to the firm's specific business model and permissions. It should show how the business will work in normal conditions, under stress, and when customers need support.

At a minimum, structure the plan around:

  • Company and ownership: legal status, principal place of business, group structure, controllers, and close links.
  • Business model: products, revenue model, target markets, distribution, outsourcing, and the activities for which permission is requested.
  • Customer journey: marketing, onboarding, product use, support, complaints, vulnerable customers, and exit or account closure.
  • Consumer Duty: how the firm will deliver good outcomes, identify foreseeable harm, support understanding, and demonstrate fair value where relevant.
  • Governance: board and committee responsibilities, senior managers, compliance oversight, risk ownership, and escalation.
  • Financial resources: capitalisation, forecasts, liquidity assumptions, stress scenarios, and the funding required to operate responsibly.
  • Policies and controls: financial crime, conflicts, complaints, data protection, outsourcing, incident management, record keeping, and relevant conduct controls.
  • People and training: skills, capacity, recruitment plans, supervision, incentives, and continuing competence.

For payments and e-money firms, the FCA directs applicants to additional material and specific application forms. Depending on the model, the evidence may include safeguarding arrangements, governance and risk controls, financial forecasts, customer-flow diagrams, qualifying-holder information, and appropriate indemnity cover for account information or payment initiation services.

Keep the narrative consistent across the application, business plan, financial model, policies, website, and customer terms. A regulator should not have to reconcile different product descriptions or discover that the stated headcount cannot support the proposed control environment.

Review your regulatory controls and evidence plan with Aureliant Global's partner-led compliance advisory team.

Step 4: Prepare governance, systems, and control evidence

The FCA's good-practice guidance highlights three recurring areas: appropriate staff capability, robust policies and procedures, and financial resources appropriate to the nature and scale of the business. It also warns against applicants that rely so heavily on a consultant that they cannot explain their own obligations.

For a fintech startup, evidence should show both design and ownership. A policy is not enough if nobody is accountable for operating it, testing it, recording exceptions, and escalating failures. Prepare an evidence matrix that links each material risk to an owner, control, frequency, record, and management forum.

Depending on the permissions and business model, the matrix may cover:

  • Product governance, customer communications, and financial promotions.
  • Customer due diligence, transaction monitoring, sanctions, and suspicious-activity escalation.
  • Safeguarding or client-money arrangements, reconciliations, and exception management.
  • Operational resilience, cyber security, incident response, and critical third-party dependencies.
  • Complaints, customer support, vulnerability, and remediation of poor outcomes.
  • Data protection, access controls, record retention, and management information.
  • Outsourcing oversight, service-level monitoring, business continuity, and exit plans.
  • Change management for new products, permissions, markets, or material technology changes.

Evidence should be proportionate, but proportionate does not mean informal. A small team can use a lean governance structure if it can show who decides, who challenges, what is reviewed, and what happens when a control fails.

Step 5: Address fit and proper requirements under SM&CR

The Senior Managers and Certification Regime is designed to make individuals more accountable for their conduct and competence. The FCA describes three parts: the Senior Managers Regime, the Certification Regime, and the Conduct Rules. A fintech should consider the regime during design of its governance model, not after the application has been submitted.

For relevant senior managers and certification staff, the FCA identifies three core elements of fitness and propriety:

  1. Honesty, integrity, and reputation.
  2. Competence and capability.
  3. Financial soundness.

Prepare role profiles, reporting lines, employment histories, regulatory references, qualifications, conflicts information, and explanations of how each person has the capacity and experience to perform the proposed role. Where one founder holds several responsibilities, explain how the arrangement works in practice and how conflicts, absence, challenge, and escalation will be managed.

The FCA's F&P guidance makes clear that assessments should be regular, thorough, and consistent. A rubber-stamp exercise is not persuasive evidence. Keep records showing what was assessed, what information was considered, what development needs were identified, and what happens if an individual no longer meets the standard.

For the application, make accountability visible. A simple responsibility map can connect each senior manager to the relevant business area, decision rights, key controls, committee reporting, and management information. This is especially important where a startup uses outsourced compliance, technology, or operations support.

Step 6: Submit through Connect and manage the review properly

Applications are submitted through the FCA's Connect system after the firm has registered. Before submission, complete a final consistency review across every attachment and answer. Confirm that the named internal contact understands the application and can respond without placing the whole process on an external adviser.

A practical submission sequence is:

  1. Confirm the permission map and legal entity.
  2. Complete the applicable FCA forms and business plan.
  3. Attach policies, forecasts, diagrams, governance information, and supporting evidence.
  4. Check disclosures, controllers, qualifying holdings, senior managers, and close links.
  5. Pay the correct application fee and retain the submission record.
  6. Prepare a question log and allocate owners for FCA follow-up.
  7. Respond clearly, consistently, and promptly to requests for clarification.

The FCA's general guidance gives indicative assessment periods of about six months for FSMA firms and about three months for payments or e-money firms. Incomplete applications can take considerably longer, with the FCA noting that some may take up to 12 months. These are planning indications, not guaranteed decision dates. Build contingency into the launch plan and do not announce a regulated launch date before the permissions and operational conditions are clear.

See how Aureliant Global supports fintech and digital-asset businesses with regulatory, audit, and growth advice.

Common reasons FCA applications are delayed or rejected

Most avoidable problems are not caused by a single missing sentence. They arise when the application does not give the FCA confidence that the proposed business can be controlled in reality. Review these risks before submission:

  • Generic business plan: the document describes the sector but not the firm's actual products, customers, money flows, risks, and permissions.
  • Permission mismatch: the form, website, customer terms, and operating model describe different activities.
  • Unclear accountability: senior roles overlap without a credible explanation of responsibility, capacity, challenge, and absence cover.
  • Consultant dependence: the founders cannot explain the business model or regulatory obligations without an adviser present.
  • Weak financial model: forecasts do not connect to headcount, transaction volumes, capital, liquidity, safeguarding, or stress assumptions.
  • Incomplete customer journey: marketing, complaints, vulnerable-customer support, and post-sale service are treated as future work.
  • Unproven controls: policies exist, but there is no evidence of owners, testing, management information, or remediation.
  • Insufficient disclosure: ownership, previous roles, adverse information, close links, or material outsourcing arrangements are omitted or unclear.

Use the FCA's good-practice and areas-for-improvement guidance as a pre-submission challenge. The objective is not to create a large document library. It is to demonstrate that the business understands its risks and has the people, resources, and controls to manage them.

How a regulatory adviser can accelerate readiness

An adviser cannot guarantee an FCA decision and cannot transfer the firm's regulatory responsibilities. The FCA remains focused on whether the applicant itself understands and can operate the proposed model. The useful role of an adviser is to bring structure, challenge, technical depth, and implementation discipline before the application reaches the regulator.

A focused readiness engagement may include:

  • Regulatory-perimeter and permission mapping.
  • Application gap assessment against the relevant FCA route.
  • Business-plan review and consistency testing.
  • Governance, SMCR, and fitness-and-propriety preparation.
  • Risk, control, safeguarding, outsourcing, and operational-resilience design.
  • Financial forecast challenge and evidence planning.
  • Mock FCA questions, response tracking, and management reporting.

For growing firms, the best support remains connected to the operating model. A readiness review should leave management with named owners, realistic milestones, usable controls, and a clear view of what must be in place before launch. That approach is more durable than treating authorisation as a one-off document exercise.

Aureliant Global provides regulatory compliance advisory for UK and international financial services businesses, with partner-led delivery and experience across governance, controls, financial services, fintech, and cross-border requirements. Explore the firm's regulatory compliance advisory guide for broader ongoing obligations and support options.

Frequently asked questions

How long does FCA authorisation take for a fintech?

The FCA gives indicative periods of about six months for FSMA firms and about three months for payments or e-money firms. Incomplete or unclear applications can take longer, potentially up to 12 months. Treat these as planning indications rather than guaranteed timelines.

Can a fintech start trading while its FCA application is being reviewed?

Generally, no. The FCA states that a firm must not perform regulated activities while its application is under review unless an exemption or temporary permission applies. Confirm the position for the exact activity before launch.

Is an appointed representative the same as being FCA authorised?

No. An AR operates under a principal's responsibility for specified activities and needs a written agreement within the FCA rules. An IAR has a narrower role. The route should be assessed against the fintech's activities, desired control, customers, and longer-term plan.

What should a fintech include in its FCA business plan?

Include the legal and ownership structure, business model, permissions, customer journey, Consumer Duty approach where relevant, governance, senior roles, compliance framework, complaints, training, financial resources, outsourcing, and supporting policies. Tailor the plan to the actual model rather than copying a generic template.

What does the FCA assess under fitness and propriety?

The core areas are honesty, integrity and reputation; competence and capability; and financial soundness. Firms should make regular, thorough, and consistent assessments for relevant senior managers and certification staff, with evidence of oversight and action where development needs arise.

Book a call with Aureliant Global to discuss your FCA authorisation readiness. Call +44 20 7967 1177 or contact the team online for a partner-led assessment.