When preparing an application for direct authorisation, firms must submit a Regulatory Business Plan (RBP) that satisfies strict regulatory standards rather than investor expectations. Compliance Consultant helps financial services firms structure their RBPs to survive rigorous case officer scrutiny during the FCA Connect submission process in 2026. This guide outlines how to construct an RBP that demonstrates full compliance with the statutory Threshold Conditions and embeds the Consumer Duty framework natively. Rather than focusing on aggressive revenue projections, successful applicants reverse-engineer their plans starting with governance and risk mitigation.
Shifting from a commercial pitch to a regulatory roadmap
At Compliance Consultant, our regulatory compliance team routinely reviews business plans written for venture capitalists rather than regulators. An investor deck sells optimism, rapid scaling, and market disruption. The Financial Conduct Authority (FCA), by contrast, evaluates risk, operational resilience, and consumer protection.
The primary reason applications stall is because the business plan fails to translate commercial ambitions into a structured compliance narrative. When writing your RBP, you must demonstrate a granular understanding of the regulatory perimeter you are entering. You must prove that your business model is sustainable, managed by fit and proper persons, and designed to protect market integrity.
Target customer base and distribution channels
Your RBP must define your target customer base with high precision. The FCA will not accept vague definitions like “the general public” or “high net worth individuals” without objective criteria. You need to specify demographic boundaries, financial literacy expectations, and wealth thresholds.
The distribution channels must be documented step by step. If you use third-party platforms, brokers, or digital marketing funnels, you must show how you control the onboarding journey. The case officer will look for potential mis-selling risks or signs that products are being distributed to consumers for whom they are unsuitable.
Identification of key regulatory risks and mitigation strategies
You must include a dedicated risk matrix that matches every business activity to its corresponding regulatory risk. If your firm provides investment management, you must address market risk, liquidity risk, and portfolio concentration. If you operate in payment services, transaction fraud and safeguarding failures must be addressed.
Each risk requires a detailed, active mitigation plan. Do not rely on passive statements like “the firm will monitor transactions.” Explain the systems you use, the triggers for manual intervention, and the exact compliance policies that govern those processes.
Compliance monitoring arrangements
Your RBP must show how you will test your own compliance on an ongoing basis. This requires a formal Compliance Monitoring Programme (CMP) that details what will be reviewed, who will perform the review, and how often.
A generic statement promising annual reviews is a major red flag for case officers. Your plan should detail weekly, monthly, and quarterly testing schedules for high-risk areas. This includes financial promotions reviews, customer suitability file checks, and transaction monitoring audits.

Structuring the RBP around the five Threshold Conditions
Every applicant must satisfy the five statutory Threshold Conditions detailed in the FCA COND Sourcebook. These are the non-negotiable minimum standards that your firm must meet at the point of authorisation and maintain continuously.
- Location of offices: The firm must be directed and managed from the UK if incorporated here.
- Adequate supervision: The regulator must be able to supervise the firm effectively, without obstruction from opaque group structures.
- Appropriate resources: Adequate financial, human, and IT resources must be demonstrably in place.
- Suitability: Owners and senior managers must be fit and proper, possessing the requisite expertise and integrity.
- Business model: The business model must be sustainable, coherent, and must not pose undue risks to consumers or market integrity.
Location of offices and effective supervision
To satisfy the location of offices condition, your firm’s mind and management must reside in the UK. This means your board meetings, key commercial decisions, and compliance oversight must happen within the jurisdiction.
Adequate supervision requires a clear, uncomplicated corporate structure. If your firm has parent companies, overseas subsidiaries, or ultimate beneficial owners in offshore jurisdictions, you must provide a detailed ownership chart. The case officer must be able to trace the flow of control and capital back to the individual controllers without hitting regulatory blind spots.
Appropriate resources (financial, human, IT)
The FCA expects you to prove you have the resources to run your business safely. This extends beyond basic capital adequacy requirements. You must document your non-financial resources, including your IT infrastructure, cloud service providers, and operational personnel.
A common pitfall is failing to show that your staff has the capacity to execute their roles. If a single individual holds multiple major responsibilities, the FCA will challenge their capacity to perform those duties effectively. You must explicitly show how key compliance and operational tasks are divided to prevent a single point of failure.
Suitability and business model coherence
The suitability condition focuses on the fitness and propriety of your senior team. This requires robust background checks, regulatory references, and qualification records. Your RBP must align individual skills with the specific regulated activities you want to perform.
Furthermore, the business model must show coherence. The FCA will cross-examine your financial projections against your operational plan. If you project rapid client acquisition but plan to operate with a skeleton staff and basic IT systems, the case officer will conclude that your business model is unsustainable and poses an active threat to consumer outcomes.
Embedding Consumer Duty throughout the business plan
For any firm operating in retail financial markets, the RBP must show how the firm places customer outcomes at the heart of its operations. The FCA expects the Duty to be woven naturally into every section of your plan, from product design to post-sale support.
┌──────────────────────────────────────────────────────────┐
│ CONSUMER DUTY RBP INTEGRATION │
├─────────────────────────────┬────────────────────────────┤
│ 1. Product Design & Governance│ Avoid target market mismatch│
├─────────────────────────────┼────────────────────────────┤
│ 2. Price and Value │ Clear fair value assessments│
├─────────────────────────────┼────────────────────────────┤
│ 3. Consumer Understanding │ Jargon-free communications │
├─────────────────────────────┼────────────────────────────┤
│ 4. Consumer Support │ Post-sale service friction │
└─────────────────────────────┴────────────────────────────┘
For firms in scope of the Duty
If your firm falls within the scope of the Consumer Duty, you must document how your products are designed for a specific target market. You must prove that the pricing structure provides fair value, supported by a formal fair value assessment.
Your RBP must outline how you will test customer understanding of your communications and marketing materials. Additionally, your post-sale support structures must be as accessible as your sales processes, ensuring customers do not face artificial barriers when trying to exit a product or make a complaint. For more details on showing this compliance, see the 2026 Consumer Duty board report guidelines.
For firms out of scope (Principles 6 and 7)
If your firm is strictly institutional and falls outside the scope of the Duty, you cannot simply ignore the topic. The FCA’s sample business plan states that you must explicitly explain why your business is out of scope.
Furthermore, you must demonstrate how you will comply with Principle 6 (treating customers fairly) and Principle 7 (communications) of the FCA Handbook, which continue to apply to firms not subject to the Consumer Duty. This means you must still show how you ensure clear, fair, and non-misleading information flows to your institutional clients.

Mapping the narrative to your active compliance framework
A successful RBP is not a standalone narrative. It must act as the index for your entire compliance framework. The FCA expects your business plan to match the policies, procedures, and governance arrangements you submit alongside it.
Policies, procedures, and cross-referencing
The FCA cross-references the business plan against every other document in your application pack. If your RBP states that you have a low risk of financial crime, but your anti-money laundering policies contain generic, un-tailored procedures, the case officer will flag the inconsistency.
Ensure your business plan directly references the exact sections of your core policies, including:
- Your Anti-Money Laundering and Counter-Terrorist Financing (AML/CTF) Policy
- Your Conflicts of Interest Policy and conflict register
- Your Complaints Handling Procedure, aligned to the DISP sourcebook
While the official FCA target for processing complete applications is six months, real-world turnaround times frequently run longer. Case officers handle high volumes, and any data mismatch between your RBP, financial projections, and FCA Connect forms will immediately pause the application clock while queries are raised.
Governance and management structures
Your business plan must detail the governance structures that will oversee your operations. This includes providing a clear, transparent ownership chart that identifies all Controllers. Under the Senior Managers and Certification Regime (SMCR), you must map specific senior management functions to individuals with the correct level of seniority and experience.
The FCA good practice guidelines recommend that firms perform and submit their own internal suitability assessments of key individuals. This proves to the regulator that you have vetted your own team before asking the FCA to approve them. For more information on dividing these duties, you can read about SMCR accountability and conduct risk training.
| Retainer Tier | Primary Application Use Case | Included Asset Benefits | Pricing (Quarterly / Annual Billing) |
| :— | :— | :— | :— |
| Bronze | Pre-authorisation preparation and basic horizon scanning | Lite Risk Register, Horizon Scanning Tracker | From £5,340/yr |
| Silver | Proactive compliance management with advisory support | Full compliance template suite, 8 hours monthly advisory | £895/mo (Quarterly) / £795/mo (Annual) |
| Gold | Strategic board-level support and complete outsourcing | Full template access, 16 hours monthly advisory, board pack drafting | £1,495/mo (Quarterly) / £1,345/mo (Annual) |
Securing specialist support for your application
Drafting a regulatory business plan is an operational exercise that requires specialized knowledge of the regulator’s expectations. Attempting to use generic, off-the-shelf templates will lead to immediate rejection, as case officers easily identify un-tailored documentation.
Compliance Consultant provides the specialized templates, advisory hours, and board-level expertise needed to build a fully compliant, consistent application. Whether you need structured risk templates or expert feedback on your governance mapping, our team helps you navigate the authorization process with confidence.
Learn more at the Compliance Consultant homepage. To discuss your specific FCA authorization needs, book a free 30-minute discovery call by emailing info@complianceconsultant.org with the subject line “Retainer Discovery Call,” or call our UK Freephone number at 0800 689 0190. For international inquiries, contact our team at 0208 243 8620.