FCA credit broking: does your business need permission?

FCA credit broking permission depends on what your business actually does in the customer journey. Use this practical activity map to identify perimeter, permission and control questions before you launch or change a model.

FCA credit broking is not defined by what a business calls itself. It is shaped by what the business actually does between a customer deciding they may need finance and a lender or broker receiving, assessing or acting on that opportunity.

That sounds obvious. In practice, it is where many permission problems begin. A retailer may describe finance as an add-on. A software platform may say it only routes enquiries. A lead generator may believe it is simply selling marketing data. A commercial broker may assume business finance sits outside consumer credit regulation. Those descriptions may be commercially convenient, but the regulatory analysis follows the activity, the customer and the agreement.

The useful question is therefore not simply, “Are we a credit broker?” It is: what regulated activity could each step of our customer journey amount to, and under whose permission is it carried on?

What does FCA credit broking cover?

Credit broking is broader than recommending a particular loan. The FCA’s perimeter guidance describes a range of activities that can fall within credit broking, including introducing a person who wants credit or hire to a lender or owner, introducing them to another credit broker, and taking steps to bring about a regulated credit or consumer hire agreement.

The word “introducing” matters. A business does not need to negotiate an agreement, handle money or make the lending decision before the perimeter becomes relevant. Passing a qualified lead, providing a route to an application, collecting information for a finance partner or arranging the hand-off may all need analysis.

There are exclusions and important limits, and the treatment of an activity depends on the facts. That is why a permission review should start with the journey rather than a generic label.

Start with the customer and the agreement

Before debating permissions, identify who the customer is and what type of finance or hire agreement is involved. Consumer credit rules can apply beyond an ordinary retail consumer. For example, certain sole traders, small partnerships and unincorporated bodies can fall within the relevant definition of an individual.

A firm that only serves limited companies may therefore have a different perimeter analysis from one serving sole traders. A platform offering several finance routes may have different answers for different products. The fact that part of the business is unregulated does not automatically take the whole journey outside the FCA perimeter.

Build a simple matrix for every route:

  • customer type and legal status;
  • product or agreement type;
  • who provides the credit or hire;
  • who introduces whom;
  • what information is collected and passed;
  • who controls the application journey;
  • who communicates the promotion;
  • how commission or fees arise; and
  • which firm accepts regulatory responsibility at each stage.

If the matrix cannot be completed clearly, the business model is not ready for a confident permissions decision.

Six activities that should trigger a permission check

1. Sending a customer to a lender or another broker

A link, button or warm transfer can be more than advertising when it is designed to introduce a particular customer to a finance provider or broker. The detail matters: what the customer has been told, what data is passed, whether the destination is selected, and whether the business receives payment for the introduction.

Do not treat the technology as the legal answer. An API can make an introduction just as effectively as a telephone call.

2. Collecting information before the hand-off

Gathering contact details, finance needs, trading history, income information or vehicle details may make the business more involved in the credit journey. The key question is what happens with that information. Is it merely used to display general information, or is it used to match, qualify, rank, route or prepare an application?

The more the business shapes the route to credit, the less convincing it becomes to describe the activity as passive marketing.

3. Matching customers with products or providers

Comparison tables, eligibility tools and lead-routing systems can influence customer decisions even when no human gives a recommendation. Firms should understand the criteria used, the lenders included, any commercial preference, and how results are presented.

Where a business describes itself as independent, FCA rules also place weight on whether it can access a representative range of products and whether commercial arrangements constrain that access.

4. Helping a customer refinance or settle existing borrowing

A credit broker may cross into additional regulated activities when helping a customer consolidate, repay or otherwise end existing finance. The FCA’s material for primary credit brokers highlights debt counselling and debt adjusting as permissions that may be relevant alongside credit broking.

This is a common place for a seemingly simple introduction model to become more complex. Staff scripts, website copy and operational processes should not drift beyond the permissions the firm actually holds.

5. Promoting finance through affiliates, retailers or introducers

A customer journey may involve an unauthorised website, an affiliate, a retailer, an appointed representative or an introducer appointed representative. Those statuses are not interchangeable. Nor does approval of a financial promotion automatically authorise every regulated activity that follows from it.

Map who communicates each promotion, who approved it where approval is required, whose name appears, and whether the customer can understand if they are dealing with a broker rather than a lender. CONC 3 requires a credit broker that is not a lender to state prominently that it is a credit broker and not a lender.

6. Changing the journey after authorisation

Permissions analysis is not only an application-stage exercise. Adding a new customer type, lender panel, product, affiliate channel, comparison feature, debt-consolidation journey or automated matching tool can change the regulatory position.

A firm can remain authorised and still act outside the scope of its permission. Change control should therefore include a regulatory impact assessment before the new route goes live.

Limited Permission or Full Permission?

The FCA distinguishes between Limited Permission and Full Permission consumer credit firms. Limited Permission is available only for specified activities and circumstances. For example, it may apply where credit broking is secondary to selling the firm’s own goods or supplying its own services, subject to the relevant conditions, or in certain consumer hire and hire purchase introductions.

If credit broking is a main business activity, Full Permission is generally the starting point. A primary credit broker that introduces customers to third-party finance providers will usually need Full Permission Credit Broking unless a specific Limited Permission route applies.

Limited Permission is not a lighter label a firm can choose because the business is small. It follows the activity and the conditions. The FCA’s application page lists common misunderstandings, including primary broking businesses incorrectly applying for Limited Permission and firms overlooking debt adjusting or debt counselling activity.

Existing permissions elsewhere in the group or business also need careful review. The legal entity carrying on the activity must have the right permission or operate within a valid representative arrangement. A permission held by a sister company is not a group-wide umbrella.

Direct authorisation, AR or IAR?

Once the activity is understood, a firm can consider the regulatory route. Direct authorisation gives the firm its own permissions and direct accountability to the FCA. Appointed Representative status places regulated activity within a principal firm’s oversight and permission framework. Introducer Appointed Representative status is narrower and is generally intended for limited introducing and financial-promotion activity.

The route should fit the real operating model. An IAR arrangement should not be used to dress up a business that controls a broader credit journey. An AR arrangement is not outsourcing in the ordinary commercial sense: the principal must have the capability and resources to oversee the representative properly.

Whichever route is chosen, document the activity analysis, the permitted scope and the operational boundaries. Staff and systems need to know what the firm may do, not merely which badge appears in the footer.

Permissions are only the first control

Holding the correct permission does not make the journey compliant by itself. The FCA expects credit brokers to deliver good outcomes, communicate clearly, manage fees and commissions, protect customer information, handle complaints and keep appropriate records.

For primary credit brokers, the FCA expects an application to explain the end-to-end customer journey, lender or broker relationships, credit or hire products, fees, commission, risks to consumers and controls. That is a useful standard even for an established firm reviewing its permissions.

Test whether the business can evidence:

  • a current permissions map tied to the live journey;
  • clear broker-not-lender disclosure;
  • promotion approval and version control;
  • lender-panel and commercial-arrangement governance;
  • customer-understanding testing;
  • complaints and outcome monitoring;
  • oversight of affiliates, ARs or IARs;
  • change control for new products and channels; and
  • management information that can identify activity outside scope.

A practical FCA credit broking review

A useful review does not begin by reading the permission name on the Financial Services Register and declaring the job finished. It begins with evidence from the live business.

  1. Walk the journey. Use the website, forms, calls, scripts, APIs and hand-offs as a customer would.
  2. Mark every regulatory verb. Introduce, match, recommend, arrange, assist, promote, advise, adjust, collect and communicate.
  3. Match each activity to an entity and permission. Record who performs it and under what authority.
  4. Test the boundaries. Check whether staff, affiliates or automated systems do more than the documented model permits.
  5. Fix the model or the permission. Change the journey, narrow the activity, vary permissions or choose an appropriate representative route before relying on optimistic wording.

The perimeter is rarely solved by adding a disclaimer after the commercial model has been built. Good FCA credit broking compliance starts earlier, with a business model that is clear about who does what, for whom, and under whose responsibility.

Where Authorised Compliance can help

Authorised Compliance helps credit brokers, lead generators, retailers, lenders, principals and representative firms turn a customer journey into a practical permissions and controls map. That can include perimeter analysis, direct-authorisation support, AR or IAR route design, financial-promotion review, monitoring and change-control work.

If your model has changed, your traffic comes from several partners, or the boundary between marketing and broking is no longer obvious, review it before the next campaign or integration goes live. The cost of a careful map is usually lower than discovering later that the business has been operating outside its intended scope.

Sources

Led by real credit broking experience

I’m Will Hurst, and I bring 20+ years of hands-on experience across credit broking, AR/IAR oversight, lender relationships and regulated finance operations.

Learn more about my practical, FCA-focused approach
August 17, 2026