Last reviewed 29 August 2026
Financial services regulation in the UK is activity-based. Whether you need Financial Conduct Authority authorisation depends on what you actually do, for whom, and how money and data move through your product — not on how you describe yourself.
Two products that look identical to a user can sit on opposite sides of the perimeter. A platform that introduces users to a regulated provider is in a very different position from one that holds funds, initiates payments or gives advice.
This guide outlines the main regimes a UK fintech encounters, the routes to market, and the compliance infrastructure expected from day one.
Is your activity regulated?
Start with the regulated activities set out in the Financial Services and Markets Act 2000 (Regulated Activities) Order 2001, and the separate regimes for payment services and electronic money. Common triggers include accepting deposits, issuing e-money, executing payment transactions, arranging or advising on investments, credit broking, consumer lending, and operating a claims management or insurance distribution business.
Carrying on a regulated activity by way of business in the UK without authorisation or exemption is a criminal offence under the general prohibition, and agreements made in breach may be unenforceable. Map the money flow and the contractual relationships precisely before concluding you are outside the perimeter.
Payment services and e-money
The Payment Services Regulations 2017 govern activities such as money remittance, payment initiation, account information services and acquiring. The Electronic Money Regulations 2011 apply where you issue stored value redeemable for funds.
Firms can register as a small payment institution or small e-money issuer below defined thresholds, with lighter requirements, or seek full authorisation with initial capital, own funds calculations and safeguarding obligations. Safeguarding — keeping relevant funds segregated or covered by insurance — is an area of close supervisory attention, so design the account structure with your bank and your adviser before launch.
Authorisation and the appointed representative route
A direct FCA application requires a detailed regulatory business plan, financial projections, governance and organisational structure, compliance and risk frameworks, policies, and senior manager applications. Preparation typically takes months, and the FCA has up to twelve months to determine a complete application.
Becoming an appointed representative of an authorised principal is faster and is a legitimate route to market for some models, but the principal takes regulatory responsibility for your activities and the FCA has tightened its expectations of principals considerably. Diligence the principal properly, and treat it as a stepping stone with a defined plan to direct authorisation.
Financial crime and anti-money laundering
Firms within scope of the Money Laundering Regulations 2017 must carry out a written firm-wide risk assessment, apply customer due diligence proportionate to risk, conduct enhanced due diligence for higher-risk relationships and politically exposed persons, screen against sanctions lists, monitor transactions, and report suspicions to the National Crime Agency.
Appoint a nominated officer and, where required, a money laundering reporting officer, and train staff. Sanctions compliance is a strict-liability regime largely independent of AML, so screening must be continuous rather than onboarding-only.
Conduct, consumer duty and financial promotions
The Consumer Duty requires firms serving retail customers to deliver good outcomes across products and services, price and value, consumer understanding and consumer support, supported by outcomes monitoring and board reporting.
Financial promotions are tightly controlled: communicating an invitation or inducement to engage in investment activity in the course of business requires authorisation or approval by an authorised person, and the approver must now itself be permitted to approve promotions. Cryptoasset promotions are within scope and carry additional rules, including cooling-off periods and risk warnings.
Building compliance infrastructure early
Investors and banking partners will ask for evidence of governance long before the FCA does. The baseline is a compliance manual, a risk register, a complaints procedure meeting DISP requirements, a training log, a conflicts policy, an outsourcing and third-party risk framework, operational resilience planning and a documented senior management responsibilities map.
Data protection sits alongside all of this: fintech products process substantial personal and financial data, so UK GDPR compliance is part of the regulatory story rather than a separate workstream. Build both together and the diligence questionnaires answer themselves.
Key points
- Regulation follows the activity, not the label — map the money flow first.
- Unauthorised regulated activity is a criminal offence and can make agreements unenforceable.
- Safeguarding of customer funds is an area of intense supervisory focus.
- Appointed representative status is faster but the principal owns the regulatory risk.
- AML and sanctions screening must be ongoing, not just at onboarding.
- Consumer Duty requires evidenced outcomes monitoring for retail firms.
Frequently asked questions
- How long does FCA authorisation take?
- The statutory maximum is six months for a complete application and twelve months for an incomplete one. In practice, well-prepared applications commonly take six to nine months from submission, plus preparation time beforehand.
- Do we need authorisation if we only refer customers?
- Possibly. Introducing or arranging can itself be a regulated activity depending on the product and the degree of involvement. Passive, non-remunerated introductions may fall within exclusions, but the analysis is fact-specific.
- Are cryptoasset businesses regulated in the UK?
- Cryptoasset businesses must register with the FCA for anti-money laundering purposes, and cryptoasset financial promotions are within the promotions regime. The wider regulatory framework continues to develop, so check the current position before launch.
- What is the regulatory sandbox?
- An FCA scheme allowing firms to test innovative propositions with real customers under restrictions and supervision. It can be useful for novel models, but it is not a shortcut around authorisation requirements.
