Understanding the Consumer Credit Permission in the UK Financial Landscape
- Julien Haye

- Jan 26, 2024
- 20 min read
Updated: Jul 23

Consumer Credit Permission is one of the most widely used, yet often misunderstood, FCA authorisations in the UK. Many businesses assume that offering lending, Buy Now Pay Later (BNPL), retail finance, or credit broking automatically requires authorisation. In reality, the answer depends on your business model, the regulated activities you perform, and your role in the customer journey.
Selecting the correct regulatory permission is about more than meeting legal requirements. It influences how your products are designed, how customers interact with your business, how risks are managed, and how your organisation can scale as it grows. Choosing the wrong regulatory model can lead to unnecessary costs, implementation delays, and future restructuring.
This guide explains what Consumer Credit Permission is, when FCA authorisation may be required, the difference between Limited and Full Permission, how it fits within the wider UK regulatory framework, and the key governance, risk, and compliance considerations for building a sustainable consumer credit business. Whether you are launching a new proposition or expanding into regulated credit activities, this guide will help you make more informed strategic decisions before investing in FCA authorisation.
What Is a Consumer Credit Permission?
A Consumer Credit Permission is an authorisation granted by the Financial Conduct Authority (FCA) that allows businesses to carry out regulated consumer credit activities in the UK. Depending on a firm's business model, this may include lending money, brokering credit, offering consumer hire, providing debt-related services, or carrying out other regulated credit activities.
Unlike Payment Institution (PI) or Electronic Money Institution (EMI) authorisations, a Consumer Credit Permission regulates activities involving the provision, arrangement or management of consumer credit rather than payment services or electronic money.
Businesses commonly require Consumer Credit Permission to provide:
Personal loans and consumer lending
Buy Now Pay Later (BNPL) products
Credit broking and finance comparison services
Motor finance and hire purchase agreements
Retail finance and point-of-sale credit
Consumer hire and leasing arrangements
Debt counselling and debt adjusting services
Debt collection and credit information services
Because consumer credit firms handle activities that can have a significant impact on customers' financial wellbeing, they must comply with the FCA's regulatory framework, including the Consumer Credit Act, the FCA Handbook (particularly CONC), the Consumer Duty, financial crime requirements, governance expectations, and ongoing obligations relating to operational resilience, complaints handling, and consumer protection.
Start with Your Business Model, Not the Consumer Credit Permission
Many founders begin by asking, "Do I need Consumer Credit Permission?" In practice, this is rarely the right starting point.
The first question should be:
"What products and services do I want to offer, and what role will my business play in providing consumer credit?"
Your business model determines the regulatory permissions you may require, not the other way around. Seemingly small changes to your operating model, such as lending money directly, introducing customers to lenders, offering Buy Now Pay Later (BNPL) products, or combining credit with payment services, can significantly alter your regulatory obligations.
Before deciding whether to apply for Consumer Credit Permission, businesses should clearly define:
The products and services they intend to offer.
Whether they will lend money, arrange credit, broker credit, or provide other regulated consumer credit activities.
Whether they will offer Limited Permission or require Full Permission activities.
How customers will apply for, access and repay credit.
Whether the business will operate independently, as an appointed representative, or through another delivery model.
How the product roadmap may evolve over the next two to three years.
Taking time to design the operating model first helps avoid selecting the wrong regulatory permission, reduces implementation costs, and provides a stronger foundation for future product development and business growth.
For example, a retailer may initially require only Limited Permission to offer finance at the point of sale but later decide to introduce a broader lending proposition. Similarly, a FinTech launching a BNPL solution may subsequently expand into payment services, electronic money or Open Banking. Building the regulatory strategy around the longer-term vision can help avoid unnecessary variations of permission or costly restructuring as the business grows.
Buy Now Pay Later (BNPL)
Buy Now Pay Later —legally classified in the UK as Deferred Payment Credit (DPC)—is a fully regulated consumer credit framework.
Since 15 July 2026, third-party lenders offering interest-free DPC must hold formal FCA Consumer Credit Permission. Firms transitioning must actively operate under the Temporary Permissions Regime (TPR) and comply with all FCA credit rules. This change aligns the BNPL sector directly with the wider consumer credit regime.
Understanding the Perimeter Boundary:
Regulated: Third-party BNPL providers financing purchases through external merchant networks.
Exempt: Short-term interest-free credit offered directly by a merchant to its own customers.
Mandatory Authorized BNPL Compliance Rules:
Provide clear pre-contract information disclosures.
Execute proportionate, mandatory affordability assessments.
Embed dedicated support for vulnerable or distressed borrowers.
Align all products with strict Consumer Duty outcomes.
Grant dispute escalation rights to the Financial Ombudsman Service (FOS).
Provide statutory consumer protections under Section 75 of the Consumer Credit Act.
For firms developing embedded finance or retail finance propositions, confirming your DPC status must be a Day 1 priority during your initial regulatory perimeter assessment.
A regulatory perimeter assessment should therefore be viewed as a strategic planning exercise rather than simply a compliance requirement. The objective is not to obtain Consumer Credit Permission as quickly as possible, but to establish the regulatory model that best supports your commercial strategy while remaining scalable as your proposition evolves.
Many firms spend months preparing an FCA application before confirming that they have selected the correct regulatory permission. Defining the regulatory perimeter first often saves significant time, cost and future restructuring.
When Should You Consider Obtaining Consumer Credit Permission?
Consumer Credit Permission may be appropriate if your business intends to carry out regulated consumer credit activities in the UK. Depending on your business model, this may include lending money, arranging or brokering credit, offering consumer hire agreements, providing debt-related services, or facilitating credit products such as BNPL.
Typical use cases include:
Consumer lending and personal loan providers.
Buy Now Pay Later (BNPL) solutions.
Credit broking and finance comparison platforms.
Retail finance and point-of-sale credit.
Motor finance and hire purchase providers.
Consumer hire and leasing businesses.
Debt counselling, debt adjusting and debt collection services.
However, obtaining Consumer Credit Permission should be driven by your business model rather than the product alone. Before applying, businesses should assess the products and services they intend to offer, the regulated activities they will perform, and whether their proposition includes any additional regulated financial services.
For example:
Businesses providing payment services or executing payment transactions may also require Payment Institution (PI) authorisation.
Firms issuing payment accounts, prepaid products or digital wallets may require Electronic Money Institution (EMI) authorisation.
Businesses accessing customer payment account information through Open Banking may require Account Information Service Provider (AISP) authorisation.
Firms initiating payments directly from customers' bank accounts may require Payment Initiation Service Provider (PISP) authorisation.
Many FinTechs begin with a single regulated activity before expanding into additional products and services. A business initially offering consumer credit may later introduce payment services, digital wallets, Open Banking capabilities or embedded finance. Considering your longer-term product roadmap from the outset can help avoid unnecessary variations of permission and reduce the cost and complexity of future regulatory change.
Taking time to assess the regulatory perimeter early helps founders select the most appropriate authorisation, avoid unnecessary costs or delays, and establish a regulatory strategy that supports sustainable growth as the business evolves.
Operating Without the Appropriate Permission
Carrying out regulated consumer credit activities without the appropriate FCA permission can have significant legal and commercial consequences.
These may include:
regulatory investigation and enforcement action;
financial penalties;
unenforceable credit agreements;
customer redress;
reputational damage;
restrictions on future authorisation; and
disruption to business growth and investment.
Understanding the regulatory perimeter before launching a product is therefore essential to avoiding unnecessary regulatory risk.
How Consumer Credit Permission Fits Within the UK Regulatory Framework
Consumer Credit Permission is one of several FCA authorisations that regulate financial services activities in the UK. It enables businesses to carry out regulated consumer credit activities, such as lending money, credit broking, consumer hire, and certain debt-related services. However, it does not permit firms to provide regulated payment services, issue electronic money, or access customers' payment account information unless they hold the appropriate additional permissions.
Many FinTechs begin with a focused consumer credit proposition before expanding into payment services, digital wallets, embedded finance, or Open Banking. As products evolve, additional FCA permissions may become necessary.
Selecting the appropriate regulatory model is therefore a strategic decision rather than simply a compliance exercise. Before applying, businesses should assess whether Consumer Credit Permission alone supports their long-term objectives or whether additional permissions, such as Payment Institution (PI), Electronic Money Institution (EMI), Account Information Service Provider (AISP), or Payment Initiation Service Provider (PISP) authorisation, may also be required.
Defining the regulatory perimeter early helps reduce implementation costs, avoid unnecessary regulatory change, and establish a scalable framework for future growth.
Do You Need FCA Authorisation?
Offering products or services involving consumer credit does not always mean applying directly for FCA authorisation. The most appropriate regulatory approach depends on your business model, the regulated activities you perform, and how your products and services are delivered to customers.
Before investing in an authorisation application, businesses should assess whether they need to become directly authorised or whether another regulatory model better supports their commercial strategy and long-term objectives.
Direct FCA Authorisation
Businesses carrying out regulated consumer credit activities in their own name will generally require FCA authorisation with the appropriate Consumer Credit Permission. Depending on the activities undertaken, this may involve either Limited Permission or Full Permission. Direct authorisation provides greater strategic independence but also requires robust governance, Consumer Duty compliance, risk management, operational resilience, financial crime controls, and ongoing regulatory oversight.
Appointed Representative
Some firms operate as an Appointed Representative (AR) of an authorised principal rather than becoming directly authorised themselves. Where appropriate, this can provide a faster route to market while allowing the principal firm to take responsibility for regulatory oversight, subject to the FCA's Appointed Representative regime and appropriate contractual arrangements.
Technology or Software Provider
Businesses that develop lending technology, credit decisioning platforms, affordability assessment tools, or software solutions without carrying out regulated consumer credit activities themselves may fall outside the FCA's regulatory perimeter. However, seemingly small changes to the operating model, customer journey, or contractual arrangements can significantly alter the regulatory position, making a regulatory perimeter assessment essential.
Outsourced Service Provider
Many organisations provide technology, operational support, cloud services, customer servicing, or specialist processing to authorised consumer credit firms without carrying out regulated activities themselves. Although FCA authorisation may not be required, these providers should still consider outsourcing requirements, operational resilience, cyber security, data protection, Consumer Duty implications, and contractual obligations, particularly where they support critical or important business services.
Why a Regulatory Perimeter Assessment Matters
Choosing the wrong regulatory model can lead to unnecessary costs, implementation delays, and future restructuring as the business evolves. A regulatory perimeter assessment helps businesses determine which activities are regulated, identify the most appropriate authorisation model, and design an operating model that supports both regulatory compliance and commercial growth.
Rather than asking,
"Do I need Consumer Credit Permission?"
businesses should first ask:
"What regulated activities will my business perform today, and how is my proposition likely to evolve over the coming years?"
Answering that question first provides a stronger foundation for selecting the most appropriate regulatory model, avoiding unnecessary regulatory change, and supporting sustainable business growth.
How Consumer Credit Business Models Typically Evolve
Many businesses do not begin by offering a comprehensive consumer credit proposition.
Instead, they launch with a focused product or service, such as retail finance, credit broking, or Buy Now Pay Later (BNPL), before expanding their capabilities as customer demand, commercial objectives, and product strategy evolve.
Understanding how your business may develop over time helps ensure that today's regulatory decisions continue to support tomorrow's growth.

Planning Beyond Your Initial Permission
Consumer Credit Permission should not be viewed as the final destination. As businesses introduce new products, enhance customer journeys, or expand into new markets, they often move beyond traditional consumer credit into additional regulated activities.
For example, businesses may choose to:
expand from Limited Permission to Full Permission as their range of regulated activities grows;
combine Consumer Credit Permission with Payment Institution (PI) authorisation to provide regulated payment services;
become an Electronic Money Institution (EMI) to offer payment accounts, digital wallets, or stored-value products;
introduce Open Banking capabilities through Account Information Service Provider (AISP) or Payment Initiation Service Provider (PISP) authorisation;
expand into embedded finance or integrated financial services that require additional FCA permissions.
Many successful FinTechs begin by solving a specific customer financing need before broadening their proposition to include payments, digital wallets, Open Banking, or other financial services. Planning for that evolution at an early stage helps businesses design a scalable operating model and avoid unnecessary regulatory restructuring as their proposition grows.
Considering these possibilities during the product design stage helps founders select the most appropriate regulatory strategy, minimise future variations of permission, and build a regulatory framework that supports sustainable long-term growth.
How Consumer Credit Permission Operates
Consumer Credit Permission enables businesses to carry out regulated consumer credit activities within a framework designed to protect consumers, promote fair outcomes, and ensure responsible lending. Although business models vary, most regulated consumer credit propositions follow a similar customer journey.
The typical customer journey follows five key stages.
Customer Application and Disclosure
The process begins when a customer applies for, or expresses an interest in, a credit product or service.
Before entering into a credit agreement, businesses must provide clear, fair and not misleading information, enabling customers to understand the product, associated costs, repayment obligations and any significant risks.
Depending on the business model, customers may:
apply directly with the lender;
be introduced through a credit broker or intermediary;
access finance at the point of sale; or
apply through an online or embedded finance platform.
Providing clear information at the outset supports informed customer decision-making and helps firms meet their regulatory obligations.
Credit Assessment and Decision Making
Once an application has been received, the business assesses whether the customer meets its lending criteria.
Depending on the product and business model, this may include:
affordability assessments;
creditworthiness checks;
identity verification;
fraud prevention controls;
financial information and supporting documentation; and
other risk-based lending assessments.
The objective is to ensure that lending decisions are responsible, proportionate and consistent with both regulatory requirements and the firm's risk appetite.
Product Delivery
If the application is approved, the customer enters into the relevant credit agreement and the product or service is provided.
Examples include:
personal loans;
Buy Now Pay Later (BNPL) products;
retail finance agreements;
motor finance;
consumer hire arrangements; and
other regulated consumer credit products.
Each business uses Consumer Credit Permission to support different customer propositions while operating within the same regulatory framework.
Ongoing Customer Management
Consumer credit obligations continue after the agreement has been established.
Businesses should maintain appropriate arrangements for:
customer communications;
payment collection;
complaints handling;
supporting customers experiencing financial difficulty;
regulatory reporting; and
ongoing compliance monitoring.
Strong customer servicing helps maintain regulatory compliance while delivering fair customer outcomes throughout the life of the credit agreement.
Ongoing Governance and Oversight
Operating under Consumer Credit Permission requires more than establishing compliant lending processes.
Businesses must maintain appropriate governance arrangements covering Consumer Duty, operational resilience, financial crime controls, complaints management, outsourcing oversight, data protection, risk management and ongoing regulatory compliance.
Strong governance not only supports regulatory compliance but also helps build customer trust, promote responsible lending practices and establish a resilient platform for sustainable long-term growth.
Become a authorised Consumer Credit firm with our expert help! From permission applications to ongoing risk and compliance support, we're here to support you. Discover Aevitium LTD Risk Management Services for FinTech and Payment firms.

Regulatory Framework and Compliance
Obtaining Consumer Credit Permission is only the first step in becoming an FCA-authorised consumer credit firm. Businesses must demonstrate that they can operate responsibly, deliver good customer outcomes, manage regulatory risks, and comply with the Financial Conduct Authority's (FCA) ongoing requirements throughout the life of the business.
Successful authorisation requires more than submitting an application. Firms should establish appropriate governance, Consumer Duty arrangements, operational resilience, financial crime controls, risk management, and compliance monitoring before commencing regulated activities.
FCA Authorisation
Businesses carrying out regulated consumer credit activities in the UK must obtain the appropriate FCA authorisation before providing those services.
The FCA assesses whether applicants have the governance, financial resources, systems, controls, and senior management arrangements necessary to operate safely and sustainably.
Successful applicants should demonstrate:
appropriate governance and organisational arrangements;
effective risk management and internal controls;
Consumer Duty implementation;
responsible lending and affordability assessment processes;
proportionate operational resilience and business continuity arrangements;
robust financial crime, fraud prevention and customer protection controls;
suitable oversight of outsourced or third-party service providers; and
sufficient financial and operational resources to support the proposed business model.
FCA authorisation is therefore as much an assessment of a firm's operating model as it is its regulatory documentation.
Consumer Duty and Customer Protection
Consumer protection sits at the heart of the UK's consumer credit regime.
Authorised firms are expected to deliver good customer outcomes throughout the customer journey by communicating clearly, designing products appropriately, supporting customers in vulnerable circumstances, and ensuring customers can make informed financial decisions.
Consumer Duty should therefore be embedded within governance arrangements, product design, customer communications, complaints handling, and ongoing monitoring rather than being treated as a standalone compliance exercise.
Responsible Lending and Credit Risk
Responsible lending is a fundamental principle of the UK's consumer credit framework.
Before entering into a regulated credit agreement, firms should carry out affordability and creditworthiness assessments that are proportionate to the products and services being offered.
Businesses should establish clear lending criteria, governance arrangements for credit decision-making, and effective monitoring processes to ensure lending practices remain responsible, consistent, and aligned with both regulatory expectations and the firm's risk appetite.
Operational Resilience and Outsourcing
Many consumer credit firms rely on third-party providers to support technology platforms, customer onboarding, payment processing, credit reference agencies, identity verification, cloud infrastructure, and customer servicing.
Businesses should establish appropriate arrangements for:
overseeing outsourced and third-party providers;
managing operational incidents and service disruptions;
maintaining business continuity and disaster recovery capabilities;
protecting customer information and critical business services; and
monitoring operational performance and resilience.
Building operational resilience from the outset helps firms deliver reliable services while meeting increasing regulatory expectations.
Financial Crime, Data Protection and Risk Management
Consumer credit firms should maintain governance and control frameworks proportionate to their business model.
This includes arrangements covering:
financial crime risk management;
fraud prevention and detection;
data protection and information security;
outsourcing oversight;
operational risk management;
regulatory reporting; and
ongoing compliance monitoring.
As businesses expand into additional regulated activities, these governance arrangements should evolve alongside the organisation.
Consumer Credit Permission and Other FCA Regulatory Models
One area that often causes confusion is when Consumer Credit Permission is required and how it differs from other FCA authorisations or regulatory models.
Businesses carrying out regulated consumer credit activities will generally require Consumer Credit Permission. However, firms that expand into payment services, electronic money, or Open Banking may require additional permissions depending on the products and services they offer.
The appropriate regulatory permission depends on the firm's business model, the regulated activities it performs, and how those activities are delivered to customers.
For example:
Businesses providing personal loans, retail finance, Buy Now Pay Later (BNPL), or other regulated lending activities typically require Consumer Credit Permission.
Firms introducing customers to lenders or arranging finance generally require Consumer Credit Permission as a credit broker.
Businesses providing regulated payment services may also require Payment Institution (PI) authorisation.
Firms issuing payment accounts, digital wallets, or stored-value products may require Electronic Money Institution (EMI) authorisation.
Businesses accessing customer payment account information through Open Banking may require Account Information Service Provider (AISP) authorisation, while those initiating payments directly from customers' bank accounts may require Payment Initiation Service Provider (PISP) authorisation.
Selecting the appropriate regulatory model at an early stage helps businesses avoid unnecessary regulatory change, reduce implementation costs, and establish a framework that supports long-term growth.
Direct FCA Authorisation or Appointed Representative?
Businesses looking to provide regulated consumer credit activities in the UK generally have two principal routes to market.
Direct FCA Authorisation
Direct authorisation provides the greatest level of independence and allows businesses to operate under their own FCA permission.
Benefits typically include:
full control over products, branding, and customer relationships;
flexibility to develop and expand the business model;
a direct regulatory relationship with the FCA; and
greater strategic independence.
However, firms are also responsible for maintaining appropriate governance, Consumer Duty compliance, operational resilience, financial crime controls, and ongoing regulatory compliance.
Becoming an Appointed Representative (AR)
Some businesses choose to operate as an Appointed Representative (AR) of an authorised principal rather than obtaining their own FCA permission.
This approach may provide:
a faster route to market;
lower initial regulatory costs;
access to an established compliance framework; and
ongoing regulatory oversight from the principal firm.
However, Appointed Representatives operate within the scope of the principal firm's permission and have less flexibility to develop their own regulatory strategy as their business evolves.
The Impact of Consumer Credit Permission on the Financial Services Ecosystem
Consumer Credit Permission plays an important role in supporting responsible lending, improving access to finance, and enabling innovation across the UK's financial services sector. By establishing a consistent regulatory framework, it helps businesses develop credit products that protect consumers while supporting economic growth and financial inclusion.
Expanding Access to Credit
Consumer credit enables individuals to spread the cost of significant purchases, manage short-term financial needs, and access products and services that might otherwise be unaffordable. For businesses, regulated credit products can improve customer choice, increase sales opportunities, and support long-term customer relationships.
Supporting Responsible Lending
The UK's regulatory framework promotes responsible lending by requiring firms to assess affordability, communicate clearly with customers, and deliver fair outcomes throughout the customer journey. This helps reduce the risk of unsustainable borrowing while encouraging better lending practices across the industry.
Driving Financial Innovation
Consumer Credit Permission provides the regulatory foundation for a wide range of modern financial services. Embedded finance, digital lending platforms, Buy Now Pay Later (BNPL) solutions, and technology-enabled credit assessment tools are transforming how consumers access finance while creating new opportunities for FinTech innovation.
Strengthening Consumer Protection
Consumer protection remains central to the UK's consumer credit regime. Regulatory requirements relating to Consumer Duty, governance, complaints handling, responsible lending, and financial resilience help build customer confidence while encouraging firms to develop products that deliver good outcomes.
Supporting a Connected Financial Ecosystem
Consumer credit increasingly operates alongside payment services, Open Banking, electronic money, and embedded finance. As financial products become more integrated, businesses are combining multiple FCA permissions to deliver seamless customer experiences while maintaining appropriate regulatory oversight.
Future Opportunities and Challenges for Consumer Credit Firms
The consumer credit market continues to evolve as customer expectations, technology, and regulatory requirements develop. Alongside significant commercial opportunities, firms will need to balance innovation with strong governance, responsible lending, and effective risk management.
Embedded Finance
Consumer credit is increasingly being integrated into digital platforms, retail journeys, and online marketplaces. As embedded finance becomes more common, businesses will need to ensure that credit products remain transparent, appropriate, and aligned with regulatory expectations regardless of where they are offered.
Artificial Intelligence and Digital Lending
Artificial intelligence and advanced analytics are transforming customer onboarding, affordability assessments, fraud detection, and credit decision-making. While these technologies can improve efficiency and customer experience, firms should ensure that automated decisions remain transparent, explainable, and subject to appropriate governance and human oversight.
Consumer Duty and Customer Trust
Maintaining customer trust will remain a key competitive differentiator. Firms that communicate clearly, design products around customer needs, and consistently deliver good outcomes are likely to build stronger customer relationships while meeting the FCA's increasing expectations under the Consumer Duty.
Operational Resilience
As digital lending platforms and embedded finance solutions become increasingly important, firms should ensure that critical business services remain resilient. Appropriate governance, business continuity arrangements, cyber resilience, incident management, and oversight of outsourced providers all contribute to maintaining reliable customer services.
Third-Party Dependencies
Many consumer credit firms rely on cloud providers, credit reference agencies, identity verification services, payment providers, technology platforms, and outsourced servicing partners. Effective supplier oversight, ongoing monitoring, and contingency planning are therefore essential to maintaining service quality and meeting regulatory expectations.
Evolving Regulatory Expectations
The consumer credit regulatory landscape continues to evolve in response to technological innovation, changing customer behaviour, and emerging risks. Firms should regularly review their governance arrangements, operating model, and compliance framework to ensure they remain aligned with evolving FCA expectations and industry best practice.
The Future of Consumer Credit
The future of consumer credit extends beyond traditional lending. As embedded finance, Open Banking, artificial intelligence, and digital identity become more closely integrated, businesses will increasingly deliver more personalised, data-driven, and seamless customer experiences.
Organisations that build scalable operating models, embed strong governance, and place customer outcomes at the centre of decision-making will be well positioned to respond to future regulatory developments while supporting sustainable long-term growth.
Scaling Beyond Regulation: What Makes a Consumer Credit Business Successful?
Obtaining Consumer Credit Permission allows a business to carry out regulated consumer credit activities, but long-term success depends on much more than regulatory compliance. The most successful firms combine responsible lending, strong governance, excellent customer outcomes, and sustainable commercial growth.
Founders should focus on four strategic pillars:
Delivering Meaningful Customer Outcomes
Customers seek consumer credit to achieve specific financial goals, whether purchasing a product, managing cash flow, or accessing short-term finance. Successful firms design products that are transparent, affordable, and aligned with customers' needs throughout the entire credit lifecycle.
Delivering clear value while ensuring responsible lending creates stronger customer relationships and supports long-term commercial success.
Building Trust Through Responsible Lending
Trust is one of the most valuable assets for any consumer credit business. Customers are more likely to engage with organisations that communicate clearly, lend responsibly, protect customer information, and provide appropriate support when financial circumstances change.
Responsible lending, fair treatment of customers, and a strong commitment to the Consumer Duty should be viewed not simply as regulatory obligations but as competitive advantages that strengthen reputation and customer confidence.
Designing for Scale and Operational Excellence
As businesses grow, they often expand into new products, customer segments, and distribution channels. Building a scalable operating model supported by effective governance, technology, operational resilience, and third-party oversight enables firms to introduce new products and respond to changing market conditions without compromising customer outcomes or regulatory compliance.
Planning Beyond Your Initial Permission
Many successful consumer credit businesses evolve beyond their original proposition. As products and services expand, firms may introduce embedded finance solutions, payment services, Open Banking capabilities, or digital wallets that require additional FCA permissions.
Considering this evolution early helps founders build an operating model and regulatory strategy that supports long-term growth rather than short-term compliance.
Conclusion
Consumer Credit Permission provides the regulatory foundation for businesses that lend money, arrange credit, or deliver other regulated consumer credit activities in the UK. It plays a vital role in protecting consumers, promoting responsible lending, and supporting innovation across the financial services sector.
However, obtaining FCA authorisation is only one part of the journey. The most successful firms begin by designing the right business model, understanding their regulatory perimeter, and establishing governance, risk, and compliance capabilities that evolve alongside their products and services.
Whether you are launching a consumer lending business, introducing Buy Now Pay Later (BNPL), expanding into embedded finance, or evaluating the most appropriate regulatory model, taking a strategic approach from the outset can reduce implementation costs, accelerate time to market, and provide a stronger foundation for sustainable long-term growth.
Planning a Consumer Credit Proposition?
Whether you are considering Consumer Credit Permission, evaluating an Appointed Representative model, or assessing whether additional FCA permissions better support your business, we help founders and leadership teams make informed strategic decisions before investing in FCA authorisation.
Our support extends beyond regulatory applications. We work with firms to define their regulatory strategy, design scalable operating models, establish governance, risk, and compliance frameworks, and build resilient foundations for long-term growth.
Explore our Risk Management Solutions for FinTech & Payment Firms or book a strategy call to discuss your business model, regulatory objectives, and growth plans.
FAQs: Consumer Credit Permission
1. Do I always need Consumer Credit Permission to offer finance?
Not necessarily. Whether Consumer Credit Permission is required depends on the activities your business performs and your role in the customer journey. Some firms require direct FCA authorisation, while others may operate as an Appointed Representative or fall outside the regulatory perimeter. A regulatory perimeter assessment should always be completed before launching a new product or service.
2. What is the difference between Limited Permission and Full Permission?
Limited Permission is generally available for businesses carrying out specific lower-risk consumer credit activities, such as certain retail finance arrangements. Full Permission is required for firms undertaking a broader range of regulated consumer credit activities, including consumer lending, credit broking, debt counselling, and debt collection. The appropriate permission depends on your business model and regulated activities.
3. Can a FinTech hold both Consumer Credit Permission and Payment Institution (PI) or Electronic Money Institution (EMI) authorisation?
Yes. Many FinTechs operate under multiple FCA permissions where their business model includes consumer credit alongside payment services, electronic money, or Open Banking. As firms expand their product offerings, additional regulatory permissions may become necessary.
4. Does Buy Now Pay Later (BNPL) always require Consumer Credit Permission?
Yes, for third-party lenders. Under the 15 July 2026 rules, interest-free BNPL is legally classified as Deferred Payment Credit (DPC). Your requirement depends strictly on your operational model:
Regulated (Full Permission): Third-party platforms or FinTechs financing purchases across external retail networks. Lenders must hold FCA permission or operate under the Temporary Permissions Regime.
Exempt: Short-term, interest-free credit offered directly by a merchant to its own customers without an outside financier.
5. Can a technology provider build lending software without Consumer Credit Permission?
Potentially. Businesses that develop software or technology platforms without carrying out regulated consumer credit activities themselves may not require FCA authorisation. However, relatively small changes to the operating model, customer journey, or contractual arrangements can bring a business within the FCA's regulatory perimeter.
6. How long does it take to obtain Consumer Credit Permission?
The timescale varies depending on the complexity of the business model, the quality of the application, and the FCA's assessment process. Firms should allow sufficient time not only for regulatory review but also for preparing governance arrangements, policies, financial forecasts, and operational controls before submitting an application.
7. Can overseas businesses obtain Consumer Credit Permission?
Yes, although the regulatory requirements will depend on the firm's structure, where regulated activities are carried out, and whether the business is targeting UK consumers. Overseas firms should obtain specialist advice to determine the most appropriate regulatory approach.
8. What happens if my business model changes after authorisation?
Businesses should regularly assess whether changes to their products, services, or operating model affect their regulatory permissions. Expanding into activities such as payment services, electronic money, or Open Banking may require additional FCA authorisation or a Variation of Permission (VoP).
9. How can businesses determine which FCA permission they need?
The starting point should always be a regulatory perimeter assessment. Rather than focusing on a specific permission, businesses should first define their products, customer journey, and operating model. This helps identify the most appropriate regulatory strategy and reduces the risk of selecting the wrong permission or requiring costly restructuring as the business grows.
.png)
