Discover Where Your Business Really Sits Within the FCAs Perimeters.

There are over 4,000 firms that call themselves fintechs in the UK. Ask a hundred founders what theirs does, and you'll get a hundred different answers, "the Stripe for X," "the Monzo for Y," "an AI-first platform that reimagines whatever."
Ask the FCA what those same hundred firms do, and you'll get one of about a dozen answers. Which dozen you fall into determines almost everything that follows: which permissions you need, how long your application takes, how much capital you'll have to hold, what your safeguarding obligations look like, and, frankly, whether the business model you've been pitching to investors is even legal in the shape you've drawn it.
So, before you write a single line of an FCA application, you need to know what kind of fintech you actually are. Not the marketing version. The regulatory version.
This guide walks through the main fintech business models in the UK market, what each one tends to need from the FCA, and, most usefully for early-stage founders, where the perimeter sits between them. It's the piece we wish more founders had read before their first call with us, because half the time the first hour of a conversation is unpicking which category someone thought they were in versus the one they're actually in.
At a Glance
The FCA doesn't authorise "fintechs." It authorises specific regulated activities. The category you fall into depends on what your product does, not what you call it.
Payment Institutions (PIs) move money. Electronic Money Institutions (EMIs) issue stored value. AISPs read account data. PISPs initiate payments. These are the four most common fintech permission types.
Consumer lenders need permissions under the Consumer Credit Act. SME-only lenders often sit outside the FCA's perimeter, but not always. BNPL is increasingly being brought into scope.
Wealthtech, robo-advisers and investment platforms are MiFID investment firms. Their applications are longer and the CASS rules for client money apply.
Insurance intermediaries are regulated under the Insurance Distribution regime. Insurance underwriters sit under a separate, heavier regime.
Cryptoasset firms must register with the FCA for AML purposes. A broader conduct regime is being phased in.
RegTech firms are usually unregulated — unless their product itself performs a regulated activity.
Neobanks are either banks (full FCA + PRA licence) or EMIs wearing banking marketing. The two are very different.
The single most expensive mistake founders make is applying for the wrong permission. A feasibility assessment before the application reduces this risk significantly.
"Fintech" isn't a regulatory category
Let's get this out of the way. The FCA does not authorise "fintechs." There is no fintech licence. There is no fintech application form. The word "fintech" is a useful piece of marketing shorthand.
What the FCA authorises is regulated activities. These are specific things you can do with money, credit, investments, insurance, or payments and are defined in legislation that mostly predates the iPhone. The Financial Services and Markets Act 2000, the Payment Services Regulations 2017, the Electronic Money Regulations 2011, the Consumer Credit Act 1974, MiFID II, the Insurance Distribution Directive. These are the texts that actually matter. If your product performs an activity defined in those texts, you need permission to do it. If it doesn't, you don't.
The label on your pitch deck is irrelevant to the FCA. What you actually do with the money, the data, or the risk is everything.
With that in mind, here are the main fintech business models in the UK, and what the FCA tends to call each of them.
Payments Fintechs
What they do: Move money from one place to another. Cross-border remittance, B2B payment platforms, expense management tools, payment acceptance for merchants, payroll fintechs, embedded payments in vertical SaaS, all of these usually fall here.
What the FCA calls them: Payment Institutions (PIs), regulated under the Payment Services Regulations 2017 (the PSRs).
There are two flavours. A Small Payment Institution can move up to an average of €3 million per month in payment transactions; it's a lighter-touch regime designed for early-stage or limited-scope firms. An Authorised Payment Institution has no volume cap, but the capital, safeguarding, governance and ongoing reporting requirements are meaningfully heavier. Most founders start with the small PI route and graduate.
Specific permissions sit underneath PI status. You might apply for money remittance, execution of payment transactions, merchant acquiring, or a combination. Which ones you need depends on the precise mechanics of how money flows through your product, not how you describe it on the homepage.
Where founders get this wrong: Assuming they need to be an EMI because they hold balances, when actually they're a PI executing payments and just look like they're holding money. The distinction matters enormously for capital requirements.
E-money Fintechs
What they do: Issue stored value. Wallets, prepaid cards, accounts that hold customer funds for later spending, gift card products, multi-currency accounts where customers top up and draw down over time.
What the FCA calls them: Electronic Money Institutions (EMIs), regulated under the Electronic Money Regulations 2011.
Again, two flavours: Small EMI (capped at €5 million in average outstanding e-money) and Authorised EMI. Authorised EMIs can also do everything a PI can do, which is why many wallet-style propositions go straight for EMI status rather than stacking permissions.
The core test is this: are you issuing something that represents a monetary claim on you, that the customer can spend later? If yes, you're issuing e-money, and you need EMI permissions. If you're just executing payments on the customer's instruction without holding a balance that belongs to them, you're a PI.
Where founders get this wrong: They think holding customer money for any length of time means they're an EMI. Sometimes that's right. Often it isn't. There's a meaningful difference between safeguarding funds during a payment execution and issuing e-money against them.
Open Banking and Data Fintechs
What they do: Read customer account data or initiate payments on the customer's behalf, using the regulated APIs that PSD2 forced the banks to expose.
What the FCA calls them:
AISPs — Account Information Service Providers. You read account data. Lighter regime, lower capital, faster to authorise.
PISPs — Payment Initiation Service Providers. You initiate payments. Heavier regime, more like a full PI, because you're touching the payment itself rather than just observing it.
Many open banking propositions are stacked, you're an AISP and a PISP, because reading the data is what lets you initiate the payment intelligently. Each layer needs its own permission.
Where founders get this wrong: Building a "read-only" data product and forgetting that the moment you offer a "pay now" button connected to that data, you've become a PISP and the application got considerably longer.
Lending Fintechs
This is where the category fragments the most, because lending is regulated very differently depending on who you lend to, what you lend for, and how the loan is structured.
Consumer lending (lending to individuals for personal, non-business purposes) is regulated under the Consumer Credit Act 1974 and the FCA's Consumer Credit sourcebook (CONC). You need consumer credit permissions, which come in flavours: lending, credit broking, debt collecting, debt counselling, and so on. A direct lender needs different permissions to a comparison site, which needs different permissions to a loan servicer.
Buy Now, Pay Later is the moving target. Historically, interest-free BNPL products often relied on a specific exemption from the Consumer Credit regime. That exemption has been narrowing, and BNPL is increasingly being brought within the FCA's perimeter. If you're building anything in this space, treat the regulatory position as something to confirm with current rules, not something to assume.
SME lending, unsecured business lending to limited companies, sits largely outside the FCA's consumer credit perimeter, but the moment you lend to sole traders, small partnerships, or any borrower below certain thresholds, you're back inside it. "We only lend to businesses" is a sentence that must survive contact with the legal definition of "business" before you can rely on it.
Peer-to-peer platforms are regulated as firms "operating an electronic system in relation to lending." This is a permission category created specifically to capture marketplace lending. The platform itself is regulated, even when the underlying loans are between two individuals.
Mortgages are a separate regulatory regime entirely (MCOB — the Mortgages and Home Finance Conduct of Business sourcebook). Don't go anywhere near consumer mortgages assuming consumer credit permissions will cover you. They won't.
Where founders get this wrong: Assuming "B2B lending isn't regulated." Sometimes true. Often not. Always worth checking before you've spent six figures building the product.
Wealthtech and Investment Platforms
What they do: Help people invest, manage portfolios, receive financial advice, or trade financial instruments.
What the FCA calls them: MiFID investment firms, regulated under the UK's onshored version of the Markets in Financial Instruments Directive (MiFID II), with permissions varying enormously by activity.
The main flavours:
Robo-advisers - typically need permission for advising on investments and arranging deals in investments. If you're holding client money or assets, add safeguarding permissions and the joy of the CASS rules.
Execution-only trading platforms - dealing in investments as agent or principal, arranging deals, and almost certainly safeguarding client assets.
Discretionary investment managers - managing investments on behalf of clients.
Custodians - safeguarding and administering investments.
Crowdfunding platforms (investment-based) - arranging deals, often with promotion restrictions baked in.
Fund managers - depending on what and how much you manage, you might fall under the Alternative Investment Fund Managers regime (AIFMD), with its own thresholds and sub-categories (small registered, small authorised, full-scope).
This is one of the more permission-heavy fintech categories. The applications are longer, the prudential requirements are tighter, and the CASS rules, which govern how you handle client money and client assets, are not the kind of thing you want to learn as you go. If a CASS audit comes at you and you weren't ready, it's not a fun quarter.
Where founders get this wrong: Assuming "we're not giving advice, we're just providing information" is a clean line. It very rarely is. The FCA's perimeter guidance on what counts as a personal recommendation is more nuanced than most founder pitch decks acknowledge.
Insurtech
What they do: Distribute, broker, underwrite, or administer insurance, usually via a slicker digital experience than the incumbents.
What the FCA calls them: Depends on whether you're an intermediary or a carrier.
Insurance intermediaries and brokers - regulated under the Insurance Distribution regime. Permissions include arranging, dealing as agent, and assisting in administration and performance of contracts of insurance.
Managing General Agents (MGAs) - you sit between the broker and the underwriter, often with delegated underwriting authority. Same intermediary regime, plus the contractual layer with the carrier.
Insurance underwriters / carriers - actually taking on the risk. A separate, far heavier regulatory regime, often involving the PRA and (in many cases) the Lloyd's market.
Most fintech-shaped insurance businesses are intermediaries or MGAs. Building a digital broker is hard but achievable. Building a digital underwriter is a different scale of undertaking entirely.
Cryptoasset Firms
What they do: Trade, exchange, custody, or facilitate transactions involving cryptoassets. This includes exchanges, custody wallets, OTC desks, payment-adjacent crypto products.
What the FCA calls them: This is the most actively evolving area in UK fintech regulation. At the time of writing, cryptoasset firms operating in the UK must register with the FCA for anti-money-laundering and counter-terrorist-financing purposes under the Money Laundering Regulations. A broader regulatory regime, bringing cryptoasset activities into the conduct perimeter, has been progressing through consultation and legislation in stages.
The honest answer for anyone building in this space: the perimeter is being redrawn in real time. Whatever the position is when you read this, check it again before you incorporate.
RegTech
What they do: Build software for regulated firms. Think KYC platforms, transaction monitoring, regulatory reporting, compliance workflow tools.
What the FCA calls them: Usually nothing. Most RegTech is unregulated B2B SaaS. You sell to regulated firms, but you're not yourself performing a regulated activity.
The exception is when your product crosses the line from facilitating a regulated activity to performing one. If your KYC tool gathers documents and presents them, fine. If it makes the customer onboarding decision, you may have wandered into territory the FCA cares about. The test isn't what you call the product. It's what it actually does.
Challenger banks and neobanks
What they do: Banking, taking deposits, making loans, running current accounts, usually with a mobile-first interface and an aversion to the word "branch."
What the FCA calls them: Banks. Regulated jointly by the FCA and the PRA (the Prudential Regulation Authority, which sits within the Bank of England).
A full banking licence is a different beast from a PI or EMI application: longer, harder, capital-intensive, and with a level of governance and operational resilience scrutiny that early-stage teams almost never appreciate at the outset.
Worth noting: a significant number of firms that market themselves as "neobanks" are not banks at all. They're EMIs wearing banking marketing. That's not a criticism, the EMI structure works well for many use cases, but if you're describing yourself as a bank without holding a banking licence, the FCA's view on what you can and can't say is worth reading carefully.
The grey areas where founders get caught out
A few patterns we see repeatedly:
"We don't touch customer money, so we don't need authorisation." Depends entirely on what "touch" means. Receiving funds for even a few seconds during a payment flow can put you in scope. Routing money through your accounts on the way to a partner can put you in scope. Holding money in a partner's safeguarded account doesn't necessarily get you out of scope.
"We're just a marketplace." Sometimes true. Sometimes a comforting story that doesn't survive contact with the definition of arranging deals or operating an electronic system.
"It's a closed loop, so it's not regulated." Closed-loop e-money has genuine exemptions — gift cards used only within a limited network of merchants, for example. But the exemptions are narrower than founders typically assume, and the moment the loop opens slightly, the exemption collapses.
"We'll add the regulated bit later." Sure. But the technical, contractual, and corporate architecture you build now determines whether "later" is a six-week add-on or a sixteen-month rebuild.
How to actually work out what you are
Four questions, in roughly this order:
Whose money are you touching, and when? Customer money, partner money, merchant money, your own money. The answer here changes your regulatory position completely.
What are you doing with it? Moving it, holding it, lending it, investing it, insuring against losses on it?
Who's the customer? Consumer protection regimes are heavier than business-to-business ones, in most categories.
Where are you doing it from, and where are your customers? UK authorisation gives you permission to do regulated activities in the UK. Selling cross-border opens up a whole separate set of questions.
If you can answer those four questions precisely, you can usually narrow the regulatory category down to one or two candidates. Narrowing it from two to one, and then mapping it to specific permissions, is where most founders benefit from external help.
Where we come in
We help fintech and regulated technology firms work through exactly this question, then take them through the FCA application end to end. Most of our authorisation work starts with a feasibility assessment, a focused piece of work that takes your specific product, customer flow, and commercial model, and confirms which regulatory category you're actually in, what permissions you'll need, and what the realistic application timeline and cost looks like. If you go on to do the full authorisation with us, we credit the feasibility fee against the application.
We do this because nine times out of ten, the founders who run into problems during FCA applications are the ones who started with a wrong assumption about which category they were in and tried to fix it on the fly. It's a much shorter and cheaper conversation if we have it before the application goes in, rather than three months into FCA queries.
In summary
"What kind of fintech are you?" is one of those questions that sounds like marketing but is actually law. The label you use on your website is yours to choose. The regulatory category you fall into isn't. The sooner you know which one applies to you the cheaper, faster, and less stressful everything else becomes.
If you've read this far and you're still not sure which category you're in, that's a useful piece of information in itself. It usually means you're in one of the grey areas, and the grey areas are where founder time and founder money get spent in the largest quantities. That's worth a conversation before you go any further.
If you'd like to talk through where your business sits in the FCA's perimeter, or what a feasibility assessment would look like for your model, get in touch. We work with fintech and regulated technology firms across the UK on FCA authorisations, ongoing compliance, and everything that sits between launch and scale.
Frequently asked questions
Do I need FCA authorisation for my fintech? Probably, but it depends entirely on what your product does, not what you call it. If your business model involves moving money, issuing stored value, lending to consumers, advising on investments, distributing insurance, or initiating payments, you almost certainly need FCA authorisation. If you're building B2B software for regulated firms (RegTech) without performing a regulated activity yourself, you typically don't. The only way to be certain is to map your customer flow against the FCA's regulated activities.
What is the difference between a Payment Institution (PI) and an Electronic Money Institution (EMI)? A Payment Institution executes payment transactions, moving money from A to B on a customer's instruction. An Electronic Money Institution issues e-money, which is stored value that represents a monetary claim on the issuer (think wallets, prepaid cards, multi-currency accounts). EMIs can do everything PIs can do, plus issue e-money, which is why wallet-style fintechs typically apply for EMI status. The capital, safeguarding and ongoing obligations are heavier for EMIs.
What is the difference between a Small EMI and an Authorised EMI? A Small EMI is capped at an average of €5 million in outstanding e-money and operates under a lighter regulatory regime. An Authorised EMI has no volume cap but faces higher capital requirements, more detailed safeguarding obligations, broader governance expectations and more reporting. Most fintechs start as a Small EMI and graduate to Authorised EMI as they scale. The same Small/Authorised split applies to Payment Institutions.
How long does FCA authorisation take? The FCA's statutory determination period is six months from a complete application, and twelve months from receipt of an incomplete one. In practice, most fintech authorisation applications take between six and twelve months end to end, with the variance driven mostly by application quality, the complexity of the business model and the FCA's caseload. Strong applications with clear, well-evidenced business plans typically move faster.
How much does FCA authorisation cost? There are three cost layers: the FCA's application fee (which varies by application type, generally between a few hundred and several thousand pounds), the cost of any external advisers supporting the application, and the internal time cost. Consultancy support on a fintech authorisation typically ranges from £5,000 to £30,000 depending on complexity, with payments and e-money applications generally sitting in the middle of that range.
Can I start operating before I am FCA authorised? No, not for any activity that requires authorisation. Performing a regulated activity without permission is a criminal offence under the Financial Services and Markets Act 2000. You can build the product, run closed beta tests that don't involve real regulated activity, sign letters of intent, and prepare commercially. You cannot take real customer money, lend real funds, or execute real payments until you have the relevant permission in place.
What is the difference between an AISP and a PISP? An Account Information Service Provider (AISP) reads customer account data through regulated open banking APIs. A Payment Initiation Service Provider (PISP) initiates payments on a customer's behalf. AISPs operate under a lighter regulatory regime because they don't touch the payment itself; PISPs sit closer to a full Payment Institution because they do. Many open banking fintechs are authorised as both.
Do crypto firms need FCA authorisation? At present, cryptoasset firms operating in the UK must register with the FCA for anti-money-laundering purposes under the Money Laundering Regulations. This is a registration regime, not a full authorisation regime. A broader conduct regulation framework for cryptoassets is being introduced in stages, which will eventually require certain cryptoasset activities to be fully authorised. The position is moving and should be confirmed against current rules before any product launch.
Is Buy Now Pay Later regulated by the FCA? Some BNPL products have historically relied on an exemption from the Consumer Credit Act for interest-free, short-term credit. That exemption has been narrowing and BNPL is increasingly being brought within the FCA's regulatory perimeter. If you are building anything in the BNPL space, treat the regulatory position as something to confirm against the current rules at the point of product design rather than something to assume.
Do RegTech companies need FCA authorisation? Usually not. Most RegTech businesses are unregulated business-to-business software companies. they sell tools to regulated firms but do not themselves perform regulated activities. The exception is when a RegTech product crosses the line from facilitating a regulated activity to performing one (for example, making a credit decision rather than just supporting one). The test is what the product actually does, not how it is marketed.
Do I need a consumer credit licence for business-to-business lending? Often not, but the exemptions are narrower than founders typically assume. Unsecured lending to limited companies above certain thresholds usually sits outside the consumer credit regime. Lending to sole traders, small partnerships, or unincorporated businesses can bring you back inside it. Lending secured against a borrower's home is regulated separately. Anyone building a business lender should map their customer profile carefully against the Consumer Credit Act's definitions before assuming they are exempt.
What is a CASS audit? CASS stands for the FCA's Client Assets sourcebook, the rules governing how regulated firms handle client money and client assets. Firms holding client money above certain thresholds must arrange an annual independent CASS audit, typically conducted by an accountancy firm with specific FCA-registered CASS auditors. A CASS audit examines whether the firm's systems, controls, policies and procedures comply with the CASS rules. For a CASS Medium firm, a compliance-led CASS audit (separate from the accountancy audit) typically costs around £5,000.





Comments