Understanding the regulatory perimeter is crucial for UK businesses embedding finance features—such as payments, lending, and wallets—into their digital platforms. A clear grasp of the Financial Conduct Authority (FCA) perimeter helps prevent inadvertent breaches, enforcement risk, and reputational harm. This regulatory perimeter checklist provides practical, actionable guidance for SMEs and finance teams navigating the UK’s evolving rules around embedded finance.
Clarifying the Regulatory Perimeter in Embedded Finance
The first step in perimeter analysis is to determine whether your embedded finance activities qualify as regulated under the Financial Services and Markets Act 2000 (FSMA) and related FCA rules. The answer hinges on your product’s structure, the parties involved, and how financial features interact with your core offerings. Recent FCA thematic reviews have emphasised that even ancillary financial services can bring a business within the regulatory perimeter if they meet specified criteria.
- Are you facilitating customer payments (e.g., enabling checkout with stored cards or direct bank transfers) directly or via partners?
- Are lending options (such as Buy Now Pay Later, point-of-sale loans, or invoice finance) offered at the point of sale or as ongoing features?
- Do you provide digital wallet functionality—such as storing e-money balances or facilitating peer-to-peer transfers—within your app or platform?
- Is your business acting as principal, agent, or introducer, and are these roles clearly documented in contracts and customer journeys?
- Could your activities be interpreted as payment services, consumer credit, or electronic money issuance under FCA definitions?
Mapping your business model against FCA perimeter guidance is essential. For example, a marketplace platform handling seller payments may need payment institution authorisation, while an e-commerce brand embedding BNPL could trigger consumer credit licensing. If your model falls into a grey area, seek specialist legal or compliance advice to ensure your regulatory perimeter checklist is robust and up-to-date.
Key Regulatory Touchpoints: Payments, Lending, and Wallets
Embedded finance spans a range of regulated activities, each with distinct compliance requirements. Below, we explore the main regulatory touchpoints through practical, real-world examples:
- Payments: Does your system initiate payments (e.g., open banking APIs for account-to-account transfers) or collect/disburse funds on behalf of others (e.g., gig economy platforms)? These activities may fall under the Payment Services Regulations 2017, requiring FCA registration as a Payment Institution or Small Payment Institution. For example, a SaaS platform enabling invoice payments between businesses could be captured by these rules.
- Lending: Are you offering credit directly (such as point-of-sale finance) or brokering third-party loans? Consumer credit activity, including many BNPL models, is regulated under the Consumer Credit Act 1974. A digital marketplace offering short-term instalment plans must assess whether its structure triggers FCA authorisation, especially given recent FCA focus on BNPL and high-cost credit providers.
- Wallets: If your app allows users to hold stored value or make P2P payments, you may be issuing e-money under the Electronic Money Regulations 2011. For instance, a loyalty app enabling users to top up balances and spend with partner retailers could require an FCA e-money licence or partnership with an authorised e-money institution.
- Are you relying on exemptions (such as the limited network or commercial agent exemptions)? These are narrowly defined, and the FCA has increased scrutiny on firms using them. For example, a retailer’s closed-loop gift card may be exempt, but expansion into broader payment options could remove this protection.
- Does your model necessitate direct FCA authorisation, or can you operate under an appointed representative arrangement? Many fintechs launch under the umbrella of an authorised principal before seeking their own permissions.
Each regulated activity involves specific obligations—such as customer due diligence, safeguarding client funds, and ongoing reporting. Regularly reviewing your regulatory perimeter checklist and maintaining clear documentation is key for compliance and audit readiness.
Governance, Accountability, and Corporate Structure
Strong governance and accountability are explicit FCA expectations, especially for firms approaching or within the regulatory perimeter. This includes:
- Clearly defined roles and responsibilities for regulatory compliance across senior management and operational teams, ideally documented in a formal governance framework.
- Board and leadership awareness of regulatory perimeter risks, especially under the Senior Managers and Certification Regime (SM&CR), which places personal accountability on key decision-makers.
- Regular compliance reviews at board or committee level, with clear escalation processes for regulatory issues and perimeter changes.
As your business evolves—through new financial features, partnerships, or re-structuring—review whether your company structure, governance, and statutory records remain fit for purpose. Where adjustments are needed, corporate company secretarial services can assist with governance reviews, Companies House filings, and the maintenance of statutory registers to ensure regulatory alignment.
Operational Controls and Regulatory Compliance
Robust operational controls underpin effective regulatory perimeter management. Practical steps include:
- Tailoring customer onboarding and Know Your Customer (KYC) processes to the regulated activities you undertake or facilitate—including enhanced due diligence for higher-risk products.
- Implementing proportionate anti-money laundering (AML) and financial crime controls, including transaction monitoring and suspicious activity reporting.
- Ensuring your complaints process is compliant with FCA DISP rules and is accessible and transparent for all customers, including vulnerable users.
- Reviewing technology and data protection controls to ensure customer funds and personal information are securely managed, particularly for digital wallets and payment systems.
Regular operational reviews against FCA sourcebooks (SYSC, COBS, DISP) and a well-documented compliance framework will help demonstrate regulatory readiness and support your regulatory perimeter checklist for ongoing operations.
Tax, Reporting, and Record-Keeping Considerations
Regulatory perimeter assessments should be integrated with your broader financial governance. For example, your regulatory status may affect VAT treatment of financial services or require specific FCA returns. A proactive approach—such as implementing a tax risk register framework—will help identify, track, and mitigate both direct and indirect tax exposures as your business model evolves.
Keep comprehensive records of your perimeter analysis, regulatory rationale, and key compliance decisions. This documentation is vital in the event of an FCA review or audit and should be regularly updated as your business or the regulatory environment changes.
When to Seek Specialist Support
Given the complexity and pace of change in FCA regulation—especially around embedded finance—obtaining external expertise can be invaluable. Specialist advisers can interpret FCA guidance, structure compliant models, and support with authorisation or notification processes. For comprehensive legal, governance, and compliance resources, consult the legal and compliance guidance hub.
Conclusion
For SMEs and growth companies embedding payments, lending, or wallet features, a proactive regulatory perimeter checklist is fundamental to sustainable, compliant growth. Use this guide to structure your perimeter review, close compliance gaps, and document your regulatory position. Ongoing governance, timely operational controls, and regular reviews are essential as the embedded finance landscape and FCA expectations continue to evolve.

