Featured image for BNPL is regulated. The checkout is still a shared responsibility

BNPL is regulated. The checkout is still a shared responsibility

BNPL regulation now applies to third-party Deferred Payment Credit lenders, while most merchant broking remains exempt. Merchants and brokers should still evidence lender checks, clear checkout journeys, complaint hand-offs and outcome monitoring.

Buy Now Pay Later has crossed a regulatory line. Since 15 July 2026, third-party lenders providing regulated Deferred Payment Credit must be authorised by the FCA or hold a temporary permission, and they must comply with the new consumer-credit rules.

For merchants and brokers, however, the perimeter is deliberately less tidy. The FCA confirms that broking Deferred Payment Credit agreements is exempt from regulation. Merchant own-credit arrangements also generally remain outside the new regime. That distinction matters, but it is not a permission slip to treat the checkout journey as somebody else's problem.

The practical question is no longer simply, "Are we the regulated lender?" It is, "What is our customer being shown, who is responsible for each decision, and can we evidence that the journey works as intended?"

What changed on 15 July

Deferred Payment Credit is the legal label applied to the interest-free form of Buy Now Pay Later brought into FCA regulation. Broadly, the new regime covers agreements where a third-party lender finances goods or services supplied through a merchant arrangement.

The FCA's rules require regulated DPC lenders to provide clear and timely information, lend responsibly and affordably, support customers in financial difficulty, and operate within the Consumer Duty. Consumers also gain access to the Financial Ombudsman Service for complaints about regulated agreements.

HM Treasury described the reform as giving BNPL users key protections available with other regulated credit products. The policy direction is clear: frictionless checkout cannot mean invisible borrowing.

There are important exclusions. The FCA states that DPC broking is exempt. Certain arrangements, including merchant own-credit and specified categories such as insurance-premium finance, may also sit outside the regulated DPC definition. Firms should not rely on a product label or a provider's marketing description. The legal structure and the activity actually carried on determine the perimeter.

Exempt broking does not remove operational responsibility

A merchant may not need credit-broking permission merely because it offers a third-party DPC option. That does not make the merchant's screens, sales incentives, complaints handling or provider selection irrelevant.

The checkout is where the customer encounters the credit proposition. Placement, prominence, default settings and wording can shape whether the customer understands that they are borrowing, what they will repay and what happens if they miss a payment. A lender may own the regulated affordability decision, but a merchant can still create confusion before the customer reaches it.

Other legal and commercial duties remain relevant too. Consumer protection and advertising rules do not disappear because an activity is exempt from FCA authorisation. Contractual arrangements with the lender may impose controls, training, audit and notification duties. Reputationally, customers are unlikely to draw a careful regulatory perimeter around a poor checkout experience; they will remember the retailer or platform whose name was at the top of the page.

For already regulated firms, the analysis needs further care. Exemption for one activity does not switch off wider obligations that apply to the firm, its products or its customer relationships. The perimeter should be documented, not assumed.

Five controls merchants and brokers should evidence

1. Map the legal and customer journey

Start with the actual flow, not the product brochure. Identify the lender, merchant, broker, platform and any technology provider. Record who makes the credit offer, who collects data, who presents pre-contract information, who makes the affordability decision and who handles complaints.

Then walk the journey on desktop and mobile. Look for screens that imply the credit is part of the merchant's own service, present it as a default, or place repayment information below more persuasive sales copy. The map should show both legal responsibility and what a reasonable customer is likely to understand.

2. Check the lender's status and product scope

The FCA says a DPC lender entering new regulated agreements must be authorised for the relevant activity or hold a DPC temporary permission. The temporary-permission registration window has closed.

Merchants should verify the provider's current status and understand which products are covered. Keep a dated record of the check and define what happens if the provider's status, permissions or product terms change. A logo in a payment settings panel is not due diligence.

3. Govern customer communications

Review every place the payment option appears: product pages, baskets, checkout, promotional banners, emails, social campaigns, scripts and affiliate content. Customers should understand that DPC is borrowing, who provides it, when payments fall due and that missed payments can have consequences.

Do not allow conversion copy to outrun the regulated disclosures. "Pay nothing today" may be literally true while giving an incomplete picture of the commitment. Test the combined journey rather than approving isolated fragments of wording.

4. Route complaints and customers in difficulty

A customer may complain to the merchant about a decision made by the lender, or contact the lender about goods supplied by the merchant. Front-line teams need a simple route that avoids bouncing the customer between organisations.

Agree ownership, hand-off times, data-sharing controls and escalation triggers. Train staff to recognise financial difficulty and vulnerability without asking customers to diagnose the regulatory category themselves. The new regime is meant to improve support; a perfectly drawn responsibility chart that leaves the customer stranded achieves the opposite.

5. Monitor outcomes after launch

Regulation day was a starting point, not a project-closure date. Track approval and decline patterns, checkout abandonment, failed payments, complaints, refunds, repeat use and customer-support contacts. Review whether particular products, channels or customer groups experience worse outcomes.

Merchants will not necessarily receive all lender data. That makes the data-sharing agreement important. Decide what information is necessary, proportionate and lawful, how often it is reviewed, and what evidence will trigger a change to the journey or provider relationship.

The board-level questions worth asking

  • Which BNPL or DPC products do we offer, and what is the legal basis for their regulatory treatment?
  • Have we verified every lender's current FCA status and relevant permission?
  • Can a customer tell that they are entering a credit agreement and identify the lender before committing?
  • Who approves checkout copy, promotional claims and material journey changes?
  • How are complaints, refunds, vulnerability and financial difficulty handed between the parties?
  • What outcome data do we receive, and who acts when it shows harm or confusion?
  • When will the perimeter assessment and provider due diligence be reviewed?

Do not confuse exemption with absence of risk

The new regime draws a deliberate boundary: regulated DPC lenders carry the central FCA obligations, while most broking by merchants is exempt. Firms should respect that boundary and avoid inventing duties that do not apply.

They should also avoid the opposite mistake. The customer experiences one journey. Poor provider selection, unclear presentation, weak hand-offs and unmonitored outcomes can create harm even where the merchant is outside the credit-broking perimeter.

Authorised Compliance's view is straightforward: document the perimeter, verify the lender, test the checkout, agree the hand-offs and monitor what happens after the sale. The best evidence will show not only why the firm believed an exemption applied, but why the resulting customer journey was still well controlled.

Source note

This article is based principally on the FCA's live guidance on regulating Buy Now Pay Later, FCA Policy Statement PS26/1, HM Treasury's 15 July 2026 announcement, and contemporary legal analysis of the merchant exemption and operational implications.

Led by real credit broking experience

I’m Will Hurst, and I bring 20+ years of hands-on experience across credit broking, AR/IAR oversight, lender relationships and regulated finance operations.

Learn more about my practical, FCA-focused approach
August 14, 2026