
Buy Now Pay Later has crossed a regulatory line. Since 15 July 2026, third-party lenders providing regulated Deferred Payment Credit must be authorised by the FCA or hold a temporary permission, and they must comply with the new consumer-credit rules.
For merchants and brokers, however, the perimeter is deliberately less tidy. The FCA confirms that broking Deferred Payment Credit agreements is exempt from regulation. Merchant own-credit arrangements also generally remain outside the new regime. That distinction matters, but it is not a permission slip to treat the checkout journey as somebody else's problem.
The practical question is no longer simply, "Are we the regulated lender?" It is, "What is our customer being shown, who is responsible for each decision, and can we evidence that the journey works as intended?"
Deferred Payment Credit is the legal label applied to the interest-free form of Buy Now Pay Later brought into FCA regulation. Broadly, the new regime covers agreements where a third-party lender finances goods or services supplied through a merchant arrangement.
The FCA's rules require regulated DPC lenders to provide clear and timely information, lend responsibly and affordably, support customers in financial difficulty, and operate within the Consumer Duty. Consumers also gain access to the Financial Ombudsman Service for complaints about regulated agreements.
HM Treasury described the reform as giving BNPL users key protections available with other regulated credit products. The policy direction is clear: frictionless checkout cannot mean invisible borrowing.
There are important exclusions. The FCA states that DPC broking is exempt. Certain arrangements, including merchant own-credit and specified categories such as insurance-premium finance, may also sit outside the regulated DPC definition. Firms should not rely on a product label or a provider's marketing description. The legal structure and the activity actually carried on determine the perimeter.
A merchant may not need credit-broking permission merely because it offers a third-party DPC option. That does not make the merchant's screens, sales incentives, complaints handling or provider selection irrelevant.
The checkout is where the customer encounters the credit proposition. Placement, prominence, default settings and wording can shape whether the customer understands that they are borrowing, what they will repay and what happens if they miss a payment. A lender may own the regulated affordability decision, but a merchant can still create confusion before the customer reaches it.
Other legal and commercial duties remain relevant too. Consumer protection and advertising rules do not disappear because an activity is exempt from FCA authorisation. Contractual arrangements with the lender may impose controls, training, audit and notification duties. Reputationally, customers are unlikely to draw a careful regulatory perimeter around a poor checkout experience; they will remember the retailer or platform whose name was at the top of the page.
For already regulated firms, the analysis needs further care. Exemption for one activity does not switch off wider obligations that apply to the firm, its products or its customer relationships. The perimeter should be documented, not assumed.
Start with the actual flow, not the product brochure. Identify the lender, merchant, broker, platform and any technology provider. Record who makes the credit offer, who collects data, who presents pre-contract information, who makes the affordability decision and who handles complaints.
Then walk the journey on desktop and mobile. Look for screens that imply the credit is part of the merchant's own service, present it as a default, or place repayment information below more persuasive sales copy. The map should show both legal responsibility and what a reasonable customer is likely to understand.
The FCA says a DPC lender entering new regulated agreements must be authorised for the relevant activity or hold a DPC temporary permission. The temporary-permission registration window has closed.
Merchants should verify the provider's current status and understand which products are covered. Keep a dated record of the check and define what happens if the provider's status, permissions or product terms change. A logo in a payment settings panel is not due diligence.
Review every place the payment option appears: product pages, baskets, checkout, promotional banners, emails, social campaigns, scripts and affiliate content. Customers should understand that DPC is borrowing, who provides it, when payments fall due and that missed payments can have consequences.
Do not allow conversion copy to outrun the regulated disclosures. "Pay nothing today" may be literally true while giving an incomplete picture of the commitment. Test the combined journey rather than approving isolated fragments of wording.
A customer may complain to the merchant about a decision made by the lender, or contact the lender about goods supplied by the merchant. Front-line teams need a simple route that avoids bouncing the customer between organisations.
Agree ownership, hand-off times, data-sharing controls and escalation triggers. Train staff to recognise financial difficulty and vulnerability without asking customers to diagnose the regulatory category themselves. The new regime is meant to improve support; a perfectly drawn responsibility chart that leaves the customer stranded achieves the opposite.
Regulation day was a starting point, not a project-closure date. Track approval and decline patterns, checkout abandonment, failed payments, complaints, refunds, repeat use and customer-support contacts. Review whether particular products, channels or customer groups experience worse outcomes.
Merchants will not necessarily receive all lender data. That makes the data-sharing agreement important. Decide what information is necessary, proportionate and lawful, how often it is reviewed, and what evidence will trigger a change to the journey or provider relationship.
The new regime draws a deliberate boundary: regulated DPC lenders carry the central FCA obligations, while most broking by merchants is exempt. Firms should respect that boundary and avoid inventing duties that do not apply.
They should also avoid the opposite mistake. The customer experiences one journey. Poor provider selection, unclear presentation, weak hand-offs and unmonitored outcomes can create harm even where the merchant is outside the credit-broking perimeter.
Authorised Compliance's view is straightforward: document the perimeter, verify the lender, test the checkout, agree the hand-offs and monitor what happens after the sale. The best evidence will show not only why the firm believed an exemption applied, but why the resulting customer journey was still well controlled.
This article is based principally on the FCA's live guidance on regulating Buy Now Pay Later, FCA Policy Statement PS26/1, HM Treasury's 15 July 2026 announcement, and contemporary legal analysis of the merchant exemption and operational implications.

I’m Will Hurst, and I bring 20+ years of hands-on experience across credit broking, AR/IAR oversight, lender relationships and regulated finance operations.
Learn more about my practical, FCA-focused approach