Whether your firm needs FCA consumer credit authorisation depends on what it actually does, not what it calls itself. Businesses often describe themselves as “introducers”, “platforms” or “technology providers”, but the FCA looks beyond those labels and assesses the activities they perform in practice.
As firms launch new products, embed finance into customer journeys and respond to regulatory change – including the regulation of deferred payment credit, commonly known as Buy Now Pay Later (BNPL), in July 2026 – more businesses are finding that activities they once considered unregulated now fall within scope.
This blog is the second of two on where firms most commonly get the consumer credit regulatory perimeter wrong. Part 1 covered consumer hire, white-label lending and appointed representative models, the routes businesses often do not realise they are on. Here we turn to direct lending and credit broking, the two routes most firms recognise but still misjudge
This article is a high-level summary intended to help firms identify where a closer look is needed. It is not a complete statement of the regulatory perimeter, and whether a particular arrangement is regulated will always depend on its specific facts.
Why does the route to market matter?
In our experience, firms rarely set out to cross the regulatory perimeter. More often, they expand into new customer segments, introduce additional product features or redesign their customer journey without reassessing whether their regulatory position has changed.
Perimeter analysis should therefore not be treated as a one-off exercise undertaken at launch or authorisation. Significant changes to products, customers or distribution models should trigger a review of whether the firm’s activities and permissions still align.
When is a firm carrying on direct lending?
A firm is generally carrying on direct lending where it provides the credit and contracts directly with the customer. This requires the appropriate FCA permission, depending on the type of credit being provided, whether fixed-sum credit, running-account credit, hire purchase or conditional sale.
Where do firms get this wrong?
- Assuming overseas firms sit outside the UK perimeter
One of the most common misconceptions is that authorisation depends on where the lender is based. It does not.
Being based overseas does not, by itself, place a lender outside the UK regulatory perimeter. Territorial scope depends on where the regulated activity is carried on, so overseas lenders serving UK customers should assess their position rather than assume their location determines the answer. This frequently arises where overseas lenders expand into the UK without reviewing their permissions position.
- Expanding into sole traders
Another common issue occurs where firms begin lending to sole traders.
Many assume these remain commercial lending arrangements. However, sole traders are individuals for the purposes of much of the Consumer Credit Act, so lending to them can fall within the regulated regime. It does not follow automatically: whether it does will depend on the agreement itself and on whether any exemption applies.
- Product evolution
Products rarely remain static.
A business may begin with an unregulated proposition before gradually introducing deferred payment options, instalment plans or revolving credit features. Each enhancement may seem incremental, but together they can fundamentally change the regulatory position.
BNPL provides a recent example of how product evolution can change the regulatory position. From 15 July 2026, third-party lender deferred payment credit (DPC), commonly known as Buy Now Pay Later, became regulated.
Merchant-provided DPC can remain exempt where the relevant conditions are met. A separate exemption from authorisation may be available to merchants broking DPC arrangements. However, exempt does not mean unaffected: financial promotion requirements can still apply, and the structure of the arrangement matters.
For affected firms, the regulatory position changed fundamentally. It demonstrates why significant changes to products, distribution models or customer journeys should trigger a fresh perimeter assessment.
The key lesson is simple: every significant product or customer journey change should trigger a fresh regulatory permissions assessment.
What does Consumer Duty mean for direct lenders?
For direct lenders, getting the permissions position right is only the starting point. Where Consumer Duty applies, firms should be able to demonstrate that their product design, pricing, underwriting, communications and servicing support good customer outcomes.
That requires meaningful management information, effective governance and evidence that poor outcomes are identified and addressed in practice, rather than relying on policies alone.
When is a firm carrying on credit broking?
A firm may be carrying on credit broking where it brings about, arranges or plays a meaningful role in helping a customer enter into a credit agreement. Importantly, firms do not need to be the lender to fall within scope.
Where do firms get this wrong?
- “We’re only introducing customers”
This is one of the most common assumptions we encounter during perimeter reviews.
Many firms believe that simply referring customers to a lender sits outside regulation. In practice, introducing customers to a lender will often amount to credit broking unless a specific exemption applies.
Once again, the FCA’s assessment focuses on the activity performed rather than the description the business uses.
- “The lender owns the compliance risk”
Another misconception is that because the lender makes the lending decision, the broker carries little regulatory responsibility. That is not the FCA’s view.
The broker has its own responsibilities for the parts of the customer journey it controls or influences, including the disclosures it makes and the outcomes its own service delivers.
- Embedded finance at the point of sale
Retailers increasingly offer credit through online checkout journeys. Many assume they are simply making finance available.
However, presenting or arranging regulated credit at the point of sale may itself amount to credit broking.
Whether the retailer requires permission, operates as an appointed representative or benefits from an exemption will depend on the structure adopted.
The BNPL change is a useful illustration of how precise these questions are. A retailer presenting BNPL at checkout may be carrying on credit broking. A specific exemption may mean it does not require authorisation for that activity, but the exemption is limited to DPC. Arranging finance for other products is a separate question, and so are financial promotions. What matters is the activity being performed and the structure of the arrangement, not simply how the business describes its role.
What does Consumer Duty mean for credit brokers?
Credit brokers have their own Consumer Duty responsibilities for the aspects of the customer journey and outcomes they can determine or materially influence. Firms should consider whether their customer journey, disclosures, remuneration arrangements and communications support informed decision-making and good customer outcomes.
Commission and other remuneration arrangements also require appropriate governance. Firms should be able to demonstrate that relevant conflicts are identified and managed, disclosures are clear and customers are given the information they need to make informed decisions.
The fact that another firm ultimately provides the credit does not remove the broker’s responsibility for the service it provides.
What are we seeing in practice?
The firms most at risk of getting the perimeter wrong are not necessarily those launching entirely new businesses. Often, the regulatory position changes incrementally as an existing firm adds a new customer type, product feature, lender relationship or distribution channel.
The underlying permissions may not have changed for years, while the operating model has. That gap between the permissions on the FCA Register and what the business does in practice is where problems can emerge.
Consumer credit perimeter readiness check
Ask yourself:
✔ Have we introduced new products, customer types or payment options since our permissions were last reviewed?
✔ Do our permissions reflect the activities we actually perform today?
✔ If we serve UK customers from overseas, have we assessed the territorial perimeter rather than relying on where the business is based?
✔ Do we understand whether introductions, checkout journeys or other customer interactions amount to credit broking?
✔ Are responsibilities between lenders, brokers and other parties clear in practice as well as contractually?
✔ Can we evidence good customer outcomes across the parts of the journey we control or influence?
If any of these questions are difficult to answer, it may be time to reassess the operating model against the consumer credit perimeter.
Key takeaway
Across both direct lending and credit broking, the same principle applies: the FCA assesses what your firm actually does, not how it describes itself.
Understanding where the regulatory perimeter sits before those changes occur is considerably easier – and less costly – than correcting permissions after the event.
If you missed Part 1
Part 1 covers consumer hire, white-label lending and appointed representative models, including where firms commonly misjudge the perimeter and what happens when the regulatory position no longer reflects the operating model.
How fscom can help
Whether you’re launching a new consumer credit proposition, reviewing an existing customer journey or assessing whether your activities fall within the regulatory perimeter, fscom can help.
Our specialists support firms with regulatory perimeter analysis, FCA authorisation applications, permissions reviews and Consumer Duty implementation. We can help you identify potential issues early and determine the appropriate regulatory route before they become more difficult to resolve.
This post contains a general summary of advice and is not a complete or definitive statement of the law. Specific advice should be obtained where appropriate.