Authorisation

FCA Permissions Review: Aligning Authorisation to Actual Business Activity

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 9 min read

Key Takeaways

  • A firm's permissions must cover every regulated activity it carries on. Activity outside the scope of permission is a perimeter breach regardless of intent.
  • Permissions carry requirements and limitations that can restrict business in ways firms forget over time.
  • The FCA has removed permissions from firms that are not using them, on the basis that unused permissions create a misleading impression of a firm's regulated status.
  • Variation of permission is assessed against the Threshold Conditions as though the firm were applying afresh for the activity concerned.
  • Permission review should be triggered by business change, not conducted on a calendar.
Regulatory permissions schedule and scope of activity documents under review on a desk in a professional office, illustrating an FCA permissions review

Permissions are granted at authorisation and then, in many firms, not examined again. The business changes, products are added, markets are entered, models evolve, and the permission set remains as granted.

The consequences run in both directions. A firm carrying on activity outside its permission commits a perimeter breach. A firm holding permissions it does not use presents a misleading picture of its regulated status and may have them removed.

This article sets out when a permissions review is warranted, what it covers, and how variation applications are approached.

[IMAGE]

When to review permissions

On business change. New products, new customer types, new distribution models, entry to a new market segment, or a change in how an existing service is delivered.

On corporate change. Acquisition, disposal, group restructuring, or a change in the entity through which activity is conducted.

Where activity has grown into a different category. Most obviously where a small payment institution or small electronic money institution approaches or exceeds its threshold and requires full authorisation.

Where permissions are unused. Activities in the permission set that the firm does not carry on and does not intend to.

Where requirements or limitations constrain the business. Restrictions imposed at authorisation that no longer reflect the firm's capability or circumstances.

Ahead of supervisory engagement. A permission set that does not match the business is among the first things a supervisor will notice.

Where a new regime brings existing activity into scope. Firms carrying on activity that becomes regulated, such as those within the UK cryptoasset regime, require authorisation or a variation.

What a permissions review covers

Activity mapping. What the firm actually does, described by reference to the regulated activities in the Regulated Activities Order or the relevant regime, rather than by commercial description. The analysis turns on substance.

Permission comparison. Each activity mapped against the firm's Part 4A permission or registration, identifying activity not covered and permissions not used.

Investment types and customer types. Permissions are granted by reference to specified investments and customer categories. A firm permitted to advise retail clients on one investment type and dealing in another should confirm the boundaries are observed.

Requirements and limitations. Any restriction attached to the permission, whether imposed at authorisation or subsequently. These are frequently forgotten, particularly where the individuals who negotiated them have left.

Group structure. Which entity carries on which activity, and whether activity is being conducted by an entity that does not hold the relevant permission.

Appointed representatives. Whether AR activity falls within the principal's permissions, since the principal cannot authorise an AR to do more than the principal itself may do. See our guide to principal self-assessment and appointed representative oversight.

Ancillary and exempt activity. Whether activity treated as outside the perimeter genuinely is, including reliance on exclusions and exemptions.

Variation of permission

An application to vary permission is assessed against the Threshold Conditions in relation to the activity concerned, as though the firm were applying afresh.

The FCA will examine the business model for the new activity, the adequacy of resources including capital and staffing, the systems and controls supporting the activity, governance and the allocation of responsibility, and whether the firm's existing arrangements scale to the addition.

Applications are commonly delayed for reasons that are avoidable: a business model description that does not explain how the activity will work in practice, financial projections inconsistent with the model, systems and controls described in aspiration rather than as implemented, and governance arrangements that do not identify who will be responsible.

The FCA will assess the application against what exists at the time of assessment, not against what the firm intends to build afterwards.

Cancellation and removal

Where a firm no longer carries on a regulated activity, it should apply to cancel or vary the permission accordingly.

The FCA has taken action to remove permissions from firms not using them, on the basis that a firm listed on the register as holding permissions it does not exercise creates a misleading impression for consumers and counterparties. Firms should not assume that dormant permissions are cost-free.

Cancellation of Part 4A permission entirely requires the firm to have wound down its regulated business and dealt with outstanding obligations to customers, and the FCA will assess whether it has.

About Regulatory Counsel

Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.

Our authorisation work covers regulatory perimeter analysis, permissions review against actual business activity, variation of permission applications, new authorisation and registration applications, change in control notifications, requirements and limitations review and removal applications, cancellation and wind-down, and support through the FCA's assessment process including responses to case officer queries.

Contact our regulatory team at info@regulatorycounsel.co.uk.

This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.

Frequently Asked Questions

An assessment of whether a firm's FCA permissions cover the regulated activities it actually carries on, and whether it holds permissions it does not use. The analysis maps activity to the regulated activity definitions rather than to commercial descriptions.

It is a breach of the general prohibition, which is a criminal offence and may render agreements unenforceable. The FCA may take supervisory or enforcement action, and the firm should notify and seek to regularise its position.

Against the Threshold Conditions in relation to the activity concerned, as though the firm were applying afresh. The FCA examines business model, resources, systems and controls, and governance, and assesses what exists rather than what is planned.

Yes. The FCA has acted to remove unused permissions on the basis that they present a misleading impression of a firm's regulated status.

Restrictions attached to a permission, whether imposed at authorisation or subsequently, constraining what the firm may do. They are binding and are frequently overlooked, particularly where time has passed since they were imposed.

On business change, corporate change, growth into a different regulatory category, where permissions are unused, where requirements constrain the business, ahead of supervisory engagement, and where a new regime brings existing activity into scope.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert