To secure FCA authorisation, financial firms must demonstrate to the regulator that they are “ready, willing, and organised” before submitting their application through the FCA Connect portal. This guide by Compliance Consultant breaks down exactly how to evidence the five Threshold Conditions, structure a credible Regulatory Business Plan (RBP), and build operational policies that pass regulatory scrutiny. For mid-sized investment firms and consumer credit providers, the most effective approach in 2026 is resolving strategic governance and prudential questions before drafting a single application form.
Resolving the strategy before filling out forms
Firms frequently rush to complete application forms before resolving foundational business architecture questions. The Financial Conduct Authority (FCA) expects applicants to demonstrate structural readiness before they submit their data. Attempting to fit an incomplete business model into standard application forms is a primary driver of extended delays. To prevent this, our UK regulatory compliance firm applies a defined implementation philosophy: engage: establish regulatory requirements before infrastructure is built; execute: drive process and organisational change in parallel with technology development; embed: integrate compliance into real-world operations through testing and scaling.
Every firm seeking permission must meet the five non-negotiable Threshold Conditions enshrined in Schedule 6 of the Financial Services and Markets Act 2000 (FSMA) and detailed in the FCA COND sourcebook. These conditions represent the bare minimum standards required for entry and must be maintained indefinitely.
These five conditions are:
- Location of offices: The head office and main management must be physically in the UK if incorporated here.
- Adequate supervision: The firm’s structure must not prevent the regulator from supervising it effectively, meaning group structures must be clear and transparent.
- Appropriate resources: The firm must possess sufficient financial, human, and systems capacity.
- Suitability: The management must act with integrity, competence, and prudence.
- Business model: The commercial plan must be sustainable and safe for consumers.
Before drafted policies can be written, founders must resolve how they will fund the initial capital requirements and where they will source qualified senior personnel. If you are moving from an indirect structure, you can review our analysis on Direct FCA authorisation vs Appointed Representative: A 2026 comparison to determine if your scale justifies the direct regulatory burden. Resolving these operational decisions early ensures that your submission is built on a concrete commercial foundation rather than vague promises.
Proving staff suitability and mapping ownership
The FCA’s Authorisation and registration applications – good practice and areas for improvement publication identifies staff capability as a primary target for case officer scrutiny. A frequent point of failure in financial services compliance consulting is submitting CVs without explaining how the individuals possess the specific skills to manage a regulated firm. Case officers do not merely check qualifications; they measure the capacity of your team to run the business compliantly on day one.
Assessing Approved Persons and Key Individuals
A major sign of readiness is providing your own suitability assessments for individuals applying for Senior Management Functions (SMFs) under the Senior Managers and Certification Regime (SMCR). Rather than expecting the regulator to perform the evaluation, you must document your own fit and proper checks. This means presenting a skills gap analysis and a training plan that details how you will upskill existing personnel or recruit specialized staff within a defined period after approval. If a director holds multiple responsibilities, you must show exactly how they will balance these roles without creating conflicts of interest or exceeding their operational capacity.
Presenting clear ownership structures
Applications often stall because the controller structure is muddy or difficult to trace. The regulator requires a clear ownership structure chart that identifies the ultimate beneficial owners and any intermediate holding companies. For any controller of the firm, you must supply complete financial histories, evidence of the source of wealth, and proof of their suitability to influence the business. Presenting this information in a clean, visual format prevents the back-and-forth queries that frequently drag out the initial review phase.
Building operational policies that demonstrate active compliance
The regulator is highly critical of what they term “boilerplate policies.” These are templated documents that simply copy and paste the FCA Handbook rules without translating those rules into practical day-to-day work. Within Compliance Consultant’s advisory practice in London, we see case officers reject applications where the applicant cannot explain how their written policies function in real-world scenarios.

Translating rules into daily processes
A compliant policy does not merely state that the firm will comply with senior management arrangements. It must explain who performs the check, what system they use, how they log the output, and where those logs are stored. For example, if your policy mentions risk registers, you must document how often the registry is updated, who is responsible for the heat mapping, and how escalating risks reach the board. If you do not have these processes documented, the regulator will assume you are unprepared to operate.
Embedding fair value and Consumer Duty
Since the implementation of the Consumer Duty, the regulator expects applicants to place customer outcomes at the center of their business model. Your policies must show how you measure and prove fair value for your target customers. This requires detailing your pricing structures, identifying vulnerable customer triggers, and establishing clear management information (MI) reporting lines. If your business model involves retail clients, the application must include your completed Fair Value Assessment Framework and show how your staff incentives avoid driving high sales volume at the expense of consumer outcomes.
Coordinating the Regulatory Business Plan (RBP) with financial projections
The Regulatory Business Plan (RBP) is the foundation of your submission. It is not a pitch deck for investors; it is a technical document that proves to the regulator that you understand the rules of your sector. When relying on a regulatory compliance specialist, you must ensure that your RBP is customized to your exact operational model and matches your numerical submissions.

Reconciling narrative with numbers
A common mistake is submitting financial spreadsheets that do not match the story told in the RBP. If your business plan states you will hire three compliance staff in year two, but your financial projections show zero recruitment costs, the case officer will halt the process. Every revenue line, capital adequacy reserve, and wind-down projection must directly correspond to the text in your RBP. The FCA expects to see realistic cash flow forecasts under both normal and stressed conditions to ensure you meet the appropriate financial resources condition.
The official statutory target for the regulator to determine a completed application is six months (or 12 months for an incomplete submission). However, real-world processing times in 2026 typically range between six and nine months depending on the quality of the initial file. To help firms work through this timeline efficiently, we structure our tiered compliance retainers to provide both the physical templates and the professional advisory hours required to keep applications on track.
The table below outlines our retainer structures, which deliver the tools and compliance resources needed to build your application and maintain post-authorisation standards.
| Retainer Tier | Annual Total | Stated Value | Stated Inclusions & Service SLA | Included Digital Templates |
| :— | :— | :— | :— | :— |
| Bronze | From £5,340/yr | Not documented | Lite tools, base tracker access | Lite Risk Register, Lite Horizon Scanner |
| Silver | £9,540/yr (or £895/mo quarterly billing) | £3,969/month | 8 hours advisory support, 1 business day response SLA, monthly briefing, quarterly review meeting | Full Compliance Risk Register, Regulatory Horizon Scanning Tracker, SMCR Responsibilities Mapping Playbook, Complaints RCA Template, Compliance Monitoring Programme Builder, Consumer Duty Toolkit |
| Gold | £16,140/yr (or £1,495/mo quarterly billing) | £10,956/month | 16 hours advisory support, 4-hour response guarantee SLA, monthly strategic call, dedicated consultant, board reports, 10% project discount | All Silver templates PLUS: Fair Value Assessment Framework, Conduct Rules Breach Toolkit, Section 166 Prep Toolkit, SMCR Handover Docs, PEP EDD Workbook, AR Oversight Policy, Third-Party Oversight Toolkit, FCA Query Response Pack |
Firms can find detailed instructions on managing the complete application timeline in our resource, The complete project management playbook for FCA authorisation in 2026.
What most people get wrong
Many applicants view the FCA application process as an administrative exercise. They believe that buying a generic set of policies online and filling out the Connect portal forms will secure their license. This perspective regularly leads to rejected applications or forced withdrawals.
The boilerplate policy trap
When a case officer opens an application and reads a compliance manual that still contains bracketed placeholders like “[Insert Firm Name Here]” or references services the firm does not offer, the review is effectively over. The FCA notes that this demonstrates a complete lack of proprietary ownership. A firm cannot be “ready” or “organised” if it does not understand its own policies. Every document must reflect your actual, everyday workflow.
Cross-referencing failures and timeline delays
When policies do not correspond with each other, delays quickly accumulate. For instance, if your anti money laundering (AML) policy refers to an automated screening tool, but your IT policy and budget make no mention of that software, the regulator will flag the discrepancy. Resolving these issues after submission is incredibly slow. Each round of questions from a case officer can add weeks or months to the timeline.
Unlike conventional institutional consultancies that charge high hourly rates to answer questions once the application process starts, Compliance Consultant provides a full Q&A service with no extra charge during the preparation phase. This process ensures that all cross-referencing errors are caught and corrected before your file is submitted to the regulator, protecting your launch timeline.
You can read more about managing the ongoing compliance obligations once your application is approved in our guide to Managing the FCA compliance lifecycle: authorisation, supervision, and variation of permission.
To discuss your specific authorisation requirements and find the correct path forward, book a free 30-minute discovery call by emailing info@complianceconsultant.org with the subject “Retainer Discovery Call” or by calling 0800 689 0190. You can also view our full suite of professional services on the Compliance Consultant website.