Consumer credit regulatory reporting is becoming a core part of the FCA's supervisory model. The regulator is increasingly using granular activity and performance data to understand how firms operate, identify outliers and target intervention. For consumer credit firms, that means reporting quality can influence supervision rather than simply satisfy an administrative deadline.
Two reporting developments are particularly important in 2026. CCR009 is now live for relevant ancillary credit firms, while consumer credit Product Sales Data gives the FCA agreement-level sales and performance information for in-scope lenders. The two datasets serve different purposes and apply to different firms, so they should not be treated as interchangeable.
The first control is therefore scope. A firm should know exactly which returns appear on its RegData schedule, why they apply and what underlying systems support each material field.
CCR009 applies to specified ancillary credit activities
CCR009 collects data from firms with permission to carry on credit broking, debt adjusting, debt counselling or providing credit information services. The return came into effect in May 2025 and replaced CCR004 and CCR005, while also changing parts of the wider consumer credit reporting architecture.
The return is activity based. Depending on the firm's business model, it can collect information about permissions, business model, marketing, revenue, staff and other tailored data relevant to the activities performed.
Most in-scope firms report CCR009 once a year. Firms with annual revenue of £5 million or more from credit-related regulated activities report every six months. The data is based on the calendar year rather than the firm's accounting reference date.
For 2026 data onwards, the FCA says the annual reporting window opens in January. Firms should still use their live RegData schedule for the actual task and deadline because first-period mechanics and individual schedules can differ.
The important point is that CCR009 should be built into the firm's reporting calendar and data architecture rather than assembled manually when the task appears.
AR data needs to be consolidated where the rules require it
Current SUP 16 reporting instructions for CCR009 require firms with Appointed Representatives to provide consolidated data that includes relevant activity of the principal and its ARs unless the data item states otherwise.
This makes AR data quality a principal-firm control. The principal should know whether it can obtain reliable volumes, revenue and other relevant information from the network and whether the definitions are applied consistently.
A network can therefore have an AR oversight problem disguised as a reporting problem. If the principal cannot explain activity across the AR population, it may lack the information needed both for the return and for risk-based supervision.
The reporting process should identify which ARs contribute to each field and preserve enough working papers to reconcile material numbers with internal MI.
Outliers should be investigated before submission. A rapid increase in one AR's activity may be legitimate, but it can also indicate a scope change or risk that should have been visible through the oversight framework.
Product Sales Data applies to in-scope lenders, not every credit firm
Consumer credit Product Sales Data has a different scope. The FCA requires firms with consumer credit lending permission that reported annual total values of £2 million or more in outstanding consumer credit balances and/or new advances in CCR003 to submit PSD008 sales data and PSD009 performance data for relevant regulated credit agreements.
When a lender first comes into scope, it also submits a one-off PSD008a back-book report covering relevant agreements that will appear in the first PSD009 performance return but were not included in the first PSD008 sales return.
Relevant regulated credit agreements exclude overdrafts and regulated credit agreements secured on land for these reports. Firms should apply the current SUP 16 definitions rather than assume every consumer credit product is reportable.
High-cost short-term credit and home credit can have PSD006 requirements even where the firm is below the £2 million threshold for PSD008 and PSD009.
This scope analysis should be documented because errors in CCR003 can themselves cause PSD reports to appear incorrectly on a firm's RegData schedule.
PSD reporting is quarterly with different submission windows
Consumer credit PSD collections are calendar-quarterly. PSD006 and PSD008 are due within 20 working days of quarter end, while PSD009 is due within 30 working days. PSD008a is due within 30 working days of the end of the firm's first PSD009 reporting period.
The timing means data production needs to be routine. A lender cannot wait until the deadline to determine whether agreement-level data is complete, particularly where information comes from several servicing or origination systems.
The reporting architecture should identify which fields are captured at sale and which depend on subsequent performance. Changes to product systems should therefore include regulatory reporting impact analysis before deployment.
A new data field that is optional operationally can still be mandatory for regulatory reporting. Product and technology teams should know which fields support PSD so that a system redesign does not accidentally remove data the firm needs to submit.
Where the firm is first entering the regime, the lead time before the first reporting period should be used for data mapping, testing and reconciliation rather than treated as spare time.
Data lineage should make every material field explainable
Good reporting governance means another competent reviewer can trace a field from the submitted return back to the underlying source. That is particularly important for CCR009, where business-model data may come from several systems, and PSD, where the FCA receives granular agreement-level records.
The firm should document source systems, transformations, manual adjustments and ownership. Where a spreadsheet bridges two systems, that spreadsheet is part of the regulatory control environment and should be version controlled.
Definitions need equal attention. Internal terms such as "lead", "introduction", "agreement", "active customer" or "revenue" may not map automatically to the regulatory definition. The reporting team should use the relevant Handbook and FCA completion notes rather than rely on management-report labels.
Manual corrections should have evidence and review. A recurring adjustment can indicate that the source system or mapping needs to change rather than become a permanent manual workaround.
The standard is reproducibility. If the FCA questions an outlier six months later, the firm should be able to explain the number without depending on the memory of the person who filed the return.
Reconciliation should focus on logical consistency, not forced equality
Regulatory data often needs to reconcile with management information, accounts or other returns, but the figures may not be identical because definitions and periods differ. The control should therefore identify expected relationships and explain material differences rather than force numbers to match.
CCR009 revenue, for example, should be understandable in the context of financial accounts and internal revenue reporting. PSD agreement counts should make sense against origination systems. AR data should align with the principal's own network MI.
Cross-return checks can also reveal errors. A substantial change in CCR003 lending that brings the firm into PSD scope should be expected by compliance before new reports appear on the schedule.
The firm should document reconciliation thresholds and the review process for anomalies. A number can be correct and still deserve investigation if it is inconsistent with the rest of the business story.
FCA data-quality checks should be treated as supervisory feedback
The FCA says it performs PSD quality checks after submission, including completeness, consistency between sales or back-book and performance data, and outliers. It can contact firms where potential issues are identified.
That interaction should not be treated as a purely technical query. Repeated reporting errors can indicate weak systems, governance or understanding of the business.
The firm should track FCA data-quality queries, identify root cause and determine whether the same issue affects other periods or returns. Correcting one file without fixing the underlying mapping can allow the error to recur.
Management should also consider what the FCA may infer from the data even when it is technically correct. High arrears, unusual pricing, rapid growth or concentrated AR activity can attract supervisory attention.
This is the broader purpose of the regime: the FCA is using better data to supervise more precisely.
Reporting should feed Consumer Duty and compliance monitoring
Regulatory reporting can provide useful internal evidence. PSD009 performance information can help lenders understand arrears and customer outcomes, while CCR009 can reveal business-model and AR trends that should already be visible to management.
The firm should therefore avoid a reporting process that sends data to the FCA without asking what the same data says internally. An outlier identified by the regulator should ideally already have been considered through the firm's own monitoring.
Consumer Duty makes this especially relevant. Granular product and performance data can help firms understand whether customers receive materially different outcomes across products or segments.
The same data can inform compliance monitoring, fair value, financial difficulty and AR oversight. Regulatory reporting should therefore connect with governance rather than sit as a specialist back-office task.
Errors should be corrected and root cause understood
Where a reporting error is identified, the firm should establish the correct position and follow the current FCA process for correction or resubmission. It should also assess whether the error affects another return, internal MI or a regulatory calculation.
Root cause should distinguish transcription, definition, mapping, system and governance failures. The remediation required for each is different.
Material or repeated errors can also raise wider notification questions depending on the circumstances. The firm should consider Principle 11 and SUP 15 where appropriate rather than assume that resubmission always resolves the regulatory issue.
Senior management should be informed of significant reporting weaknesses because data quality is increasingly part of how the FCA assesses firms.
How Regulatory Counsel can support
Regulatory Counsel supports consumer credit firms with CCR009, PSD reporting, reporting inventories, data mapping, regulatory interpretation, quality assurance and remediation.
We can review a specific return or assess the firm's wider regulatory reporting framework and controls.
Speak to Regulatory Counsel to discuss consumer credit regulatory reporting.
Frequently Asked Questions
CCR009 applies to firms with specified permissions for credit broking, debt adjusting, debt counselling or providing credit information services, subject to the detailed reporting rules.
Most firms submit annually, while firms with £5 million or more annual revenue from credit-related regulated activities report every six months. Firms should confirm the current RegData schedule.
In-scope consumer credit lenders that meet the FCA's £2 million CCR003 threshold for outstanding balances and/or new advances submit PSD008 sales and PSD009 performance reports for relevant regulated credit agreements.
The consumer credit PSD collections are calendar-quarterly. PSD006 and PSD008 are due within 20 working days of quarter end, and PSD009 within 30 working days. PSD008a has its own first-reporting deadline.
Yes. We can review scope, definitions, source data, mappings, reconciliations, governance and material reporting judgements.