
Most firms assume the risk in their Part 4A permission is being out of scope. In the firms we have reviewed it rarely is. The permission is usually right. What is missing is the dated, minuted record of anyone deciding it was right — and that is the gap external examination finds first.
The problem: three drifts, not one
A Part 4A permission is a public claim about what your firm does. It is published on the Financial Services Register, relied on by consumers, counterparties, banks and acquirers, and treated by the FCA as a statement you stand behind. The business changes constantly. The claim does not. That gap is permission creep, and it opens in three directions.
- Outward drift. The firm does something the permission does not cleanly cover once the limitations are read properly. A new customer segment. A different remuneration model. A service that began as a favour and became a revenue line.
- Inward drift. The firm holds permissions for activities it stopped performing years ago. Nobody removed them, because removing them felt like closing a door.
- Evidential drift. The firm is genuinely within scope but cannot produce the decision that establishes it. No dated assessment, no named owner, no board minute connecting the service to the permission covering it.
The first two are scope problems and are comparatively rare. The third is a governance problem, it is common, and it is the one that fails when someone outside the firm asks a direct question.
Why firms get it wrong
Authorisation is treated as a completed project. Enormous effort goes into the application; once granted, the permission is filed. The firm that emerges three years later differs materially from the one described, and nobody has revisited the description.
The mapping is done, but not as a governed act. Somebody competent does check — in a spreadsheet, an email thread, or a conversation. It is real work that leaves no institutional trace. When that person leaves, the reasoning leaves too.
The wrong review trigger. Review gets attached to the annual cycle. The events that create drift — a new service, a new appointed representative, a new jurisdiction, a change in how the firm is paid — do not wait for it.
The regulatory basis
None of this rests on a single rule. It sits at the intersection of four.
The business model threshold condition. COND 2.7 requires a firm’s business model to be suitable for the regulated activities it carries on. The test is present tense. It applies to the business you run now, not the one described in your application.
Notification. Principle 11 and SUP 15.3 require a firm to tell the FCA about matters the regulator would reasonably expect notice of, including material change to the nature or scale of its activities. Concluding internally that a change is not material is itself a decision — and an undocumented decision is difficult to defend later.
Variation of permission. SUP 6.3 sets out the route for adding activities, removing them, or varying their description and limitations. It also carries a point firms overlook: where a firm varies its permission to add categories of regulated activity, it should be mindful of the requirement to commence those activities within 12 months. Adding permissions speculatively is not cost-free.
Firm details. SUP 16.10 requires firms within scope to check the accuracy of their firm details within 60 business days of their accounting reference date and confirm or correct them. The FCA states that where a firm does not confirm within that window it will receive a late return notification and an administrative fee, and that the Financial Services Register and Firm Checker will display a non-compliant banner (Keeping your firm’s information up to date).
That banner is the point most boards have not absorbed. It is public. Your clients, your bank and anyone running due diligence on you can see it.
The enforcement picture should be read carefully rather than dramatically. In 2025/26 the FCA’s Threshold Conditions team cancelled 1,255 firm authorisations and issued 586 Final Notices, against 1,456 and 863 the previous year. Those cases turn on fees, returns, attestations and unused permissions. The FCA has also said that, having completed the initial wave of “use it or lose it” work, it expects volumes to fall from January 2026 (FCA Enforcement data 2025/26). On unused permissions specifically, the FCA’s published approach is to give a firm two warnings and then cancel or vary the permission 28 days after the first warning if the firm has not acted (FCA press release, May 2022).
The honest framing is not that enforcement is coming. It is that the administrative machinery is precise, automated, public, and indifferent to your intentions.
The permission alignment file
This is the method. It takes two people about two hours in a small firm, and it is written so you can run it without engaging anyone. You need your Part 4A permission in full, twelve months of revenue data, and somewhere to record decisions that is not a personal inbox.
- Extract the permission verbatim. From the Financial Services Register. Every regulated activity, every specified investment, every customer type, and every limitation and requirement. Not a summary. Scope lives in the limitations, and the limitations are the lines people skip.
- List what the firm actually does. Work from revenue lines, not job titles or the website. Every service that produced income in the last twelve months, including anything an appointed representative or introducer performs in your name.
- Map one to the other. Complete the table below, one row per revenue line. Three outcomes only: covered, not covered, unclear. “Probably” is not an outcome.
- Deal with the dead entries. Any permitted activity with no revenue for twelve months goes on a separate list. For each, decide: reactivate, or apply to vary the permission to remove it.
- Date the decision and minute it. Each row gets a named owner, a date, two or three sentences of reasoning, and a board or committee minute recording that it was considered. The record is the deliverable. The spreadsheet is working paper.
- Set a trigger, not a diary date. Bind the remap to events: new service, new customer type, new jurisdiction, new AR or introducer, change in remuneration. Any of those triggers a mapping before launch.
The mapping table
| Revenue line | Regulated activity relied on | Investment / customer type | Limitations tested | Outcome | Owner and date | Minute reference |
|---|---|---|---|---|---|---|
| Advised mortgage sales | Advising on regulated mortgage contracts | Regulated mortgage contracts / retail | Client-type and product limitations checked | Covered | A. Owner, 14/09/2026 | Board 2026-09, item 4 |
| New commercial introductions | To be determined | Commercial borrowers | Not yet tested | Unclear | A. Owner, 14/09/2026 | Board 2026-09, item 5 |
The test that tells you whether it worked. Hand a stranger your permission wording and your last twelve months of invoices. Could they reach the same conclusion you reached, using only what is written down? If not, you do not have a scope position. You have an opinion.
The same discipline applies on the financial crime side. Where permissions or registration define the scope of a firm’s AML and financial crime obligations, the mapping must reconcile with the business-wide risk assessment. Two documents describing different firms is a finding waiting to happen.
An illustrative case
The following is illustrative. Margaret Okonkwo is a composite drawn from patterns we see, not a real person or firm.
Margaret is compliance director at a general insurance intermediary. In 2023 the firm began arranging cover for a new class of commercial client at an introducer’s request. It grew into roughly a tenth of turnover. The activity was within permission; Margaret had checked it at the time, against the limitations, and had been right.
In 2026 the firm entered discussions with a consolidator. The due diligence pack asked for the governance record behind each material service line introduced in the previous three years.
For the 2023 line there was no record. The email thread had gone with a departed colleague’s mailbox. Margaret spent three weeks reconstructing an assessment that originally took an afternoon, and the firm paid for an external opinion confirming what it had always believed. The introducer relationship then attracted the same scrutiny, because once one mapping is undocumented a buyer assumes the rest are too.
No rule was breached. Nothing was notifiable. The FCA was never involved. The cost was entirely commercial, and entirely avoidable.
What to do next
Run steps one to three this week. They are the steps that find things.
If the mapping produces a “not covered” or a stubborn “unclear”, the sequence matters: establish the position first, document it, and only then decide whether a variation of permission or a notification is warranted. Firms that reverse that order end up notifying a problem they have not yet understood.
If it produces dead permissions, treat the decision as a board decision rather than an administrative one. Holding an unused permission is a choice with consequences, and it should be minuted as such.
Where the exercise raises questions you cannot settle internally, that is the point at which a structured compliance audit or review earns its fee — and where the wider governance, risk and SMCR framework needs to absorb the trigger points so this does not recur.
Want a second pair of eyes on what your mapping finds?
Thirty minutes, no charge, no obligation. We will walk through your permission, your revenue lines and the gaps between them.
Book a discovery call | UK 0800 689 0190 | Int’l 020 8243 8620
Making Compliance Work
Frequently asked questions
What is permission creep?
The widening gap between what a firm actually does and what its FCA permission says it may do. It runs in three directions: doing things the permission does not cleanly cover, holding activities no longer performed, and being in scope without any record proving it.
How often should we review our Part 4A permission?
An annual review is the minimum, but calendar-based review is the wrong primary control. Tie the review to events — a new service, a new customer type, a new appointed representative, a new jurisdiction, or a change in how the firm is paid.
Do we need to tell the FCA about a new service that is already within our permission?
Possibly. Principle 11 and SUP 15.3 require notification of matters the FCA would reasonably expect notice of, including material change to the nature or scale of a firm’s activities. Materiality is a judgement, and the judgement should be recorded.
What happens if we hold permissions we do not use?
The FCA’s published “use it or lose it” approach is to issue two warnings, then cancel or vary the permission 28 days after the first warning where the firm has not acted. Applying voluntarily to remove an unused permission is the better-controlled route.
Is a variation of permission always needed when the business changes?
No. Many changes sit within an existing permission once the limitations are read properly. The alignment file establishes which situation you are in, on the record, before you decide.
Compliance Consultant is a trading style of UK Compliance Consultant Limited (Companies House 14805896). We are an independent regulatory compliance consultancy and are not authorised or regulated by the Financial Conduct Authority. This article is general information, not regulatory or legal advice, and should not be relied upon in place of advice specific to your firm’s circumstances.