Authorisation for investment, payment, e-money and crypto-asset firms.
Most of what we do is a first authorisation, or an extension of one. The application is the visible part. The work is making the firm the regulator reads on paper the same firm that will trade once it is authorised.
The applications we take
Investment firms
Brokerage, dealing, portfolio management and advice — MiFID firms in the EU and their UK equivalents, including variations of permission.
Payment institutions and e-money institutions
Authorised and small payment institutions, electronic money institutions, and the agents and distributors beneath them.
Crypto-asset service providers
MiCA authorisation in the EU, and authorisation under the UK's new crypto-asset regime.
Full permission for consumer credit
Lending, debt collection and administration, debt counselling and adjusting, and credit broking as a trade.
Change of control
The regulatory side of buying or selling a licensed firm: the controller's case and the change-in-control notification.
How an application runs with us
A conversation
What the firm does, what it needs permission for, who runs it and who owns it. Anything in its history the regulator will want explained comes out here rather than later. There is no charge for it.
Scope and fee, in writing
The permissions, the jurisdiction, the documents, the people who need approval, our fee and the regulator's own fee. Nothing starts until you have agreed it.
The application
The regulatory business plan, financial projections and capital calculations, policies and procedures, governance and systems-and-controls documents, and the approved-person applications — written for your firm, and reviewed by you before anything is filed.
Filing, and the questions that follow
The application goes in through the regulator's own portal, and the case officer's questions come to us to answer with you. Those questions are part of the engagement, not an extra.
After authorisation
A new firm's first year is when it is most exposed: first returns, first compliance monitoring, the first change the regulator has to be told about. We can stay on for it. See compliance and AML.
What we do not do
We do not act for banks: deposit-taking is a different regime with a different regulator relationship. We do not carry on regulated activities ourselves, and we are not a substitute for your own approved persons — the people who hold senior management functions must be yours.
And we do not promise outcomes or timetables. The decision on an application, and how long it takes, belong to the regulator. What we control is the quality of what it reads.