Journey

Start a fintech business

Launch a financial technology business requiring FCA authorisation

Technology & Digital Professional & Financial Services Starting a Business Updated 15 September 2026
references 14 guides

Launching a fintech business in the UK requires navigating a complex regulatory landscape. If your business involves payment services, e-money, cryptoassets, or other regulated financial activities, you'll need Financial Conduct Authority (FCA) authorisation before you can operate.

This journey guides you through the regulatory pathway specific to fintech, from understanding if you need authorisation through to compliance obligations once you're live.

Understand FCA authorisation requirements

Determine if your fintech activities require full FCA authorisation under FSMA 2000. Covers payment services, e-money, investment platforms, P2P lending, and security/e-money tokens.

Cryptoasset business regulation

If your business involves cryptoassets, understand the two-tier regulatory system. Security/e-money tokens require full FCA authorisation; exchange/utility tokens need MLR registration only.

Choose your business structure

Almost all FCA-authorised fintech businesses operate as limited companies. This structure provides liability protection, meets FCA capital adequacy requirements, and enables you to raise investment through SEIS/EIS schemes.

Limited company vs sole trader

Understand why limited company structure is essential for FCA-regulated fintech businesses. Required for meeting threshold conditions and attracting investors.

Protect your software intellectual property

Secure automatic copyright protection for your fintech platform code, assess patent eligibility for technical innovations, and register trademarks for your brand.

Data protection compliance

All fintech businesses process significant personal and financial data. UK GDPR compliance is mandatory from day one, with stringent requirements for security, consent, and data subject rights.

ico.org.uk

Register with the ICO (opens in a new tab)

Register your fintech business with the ICO and pay your annual data protection fee. Required before you start processing customer data.

UK GDPR compliance for tech businesses

Implement privacy by design, establish data breach procedures, create compliant privacy policies, and respond to data subject access requests within required timeframes.

Corporation Tax and specialist taxes

Once your fintech company starts trading, you'll pay Corporation Tax on profits. Very large digital platforms may also be subject to Digital Services Tax if they exceed revenue thresholds.

Corporation Tax basics

Register for Corporation Tax when you start trading. Understand the 19% small profits rate (up to £50k) and 25% main rate (over £250k), with marginal relief between.

Digital Services Tax (DST) compliance

Only applies to very large fintech platforms with £500m+ worldwide revenues AND £25m+ UK revenues from in-scope services (online marketplaces, search engines, social media).

Cybersecurity requirements

FCA-regulated firms must demonstrate robust cybersecurity controls. Cyber Essentials certification is required for many government and enterprise fintech contracts.

Cyber Essentials certification

Government-backed scheme proving you've implemented five essential cybersecurity controls. Required for government contracts and demanded by many enterprise clients.

Network and Information Systems (NIS) Regulations

Applies to medium/large fintech digital service providers (50+ employees or €10m+ turnover). Requires security measures, incident procedures, and breach reporting to ICO.

Privacy and Electronic Communications Regulations (PECR)

Fintech platforms must comply with PECR for cookie consent, email marketing, and electronic communications. Separate from UK GDPR but equally enforced by ICO.

Cross-cutting tech compliance

Beyond FCA regulation, fintech businesses must comply with broader tech sector requirements including software licensing, e-commerce regulations, and AI governance frameworks.

Software licensing compliance

Understand open source licensing obligations, commercial license agreements, and SaaS terms that comply with Consumer Rights Act and UK GDPR.

E-commerce regulations for online selling

If your fintech platform sells services online, comply with pre-contract information requirements, 14-day cancellation rights, and clear order button labeling.

AI regulation framework

For fintech platforms using AI/ML for credit decisions, algorithmic trading, or fraud detection, follow UK's principles-based AI framework and sector-specific FCA/PRA rules.

Export control for dual-use technology

Check if your fintech software or technology requires export licensing. Particularly relevant for cryptography, surveillance, and advanced computing.

Next steps

Once you've completed FCA authorisation (or MLR registration for cryptoassets), implemented UK GDPR compliance, and established cybersecurity controls, you're ready to launch your fintech business.

Remember: FCA authorisation typically takes 6 months for FSMA firms and 3 months for payment/e-money firms. Start your application early and engage with the FCA Innovation Hub if you're building an innovative fintech product.

For ongoing compliance, maintain your Consumer Duty obligations, file annual FCA returns, and keep your data protection and cybersecurity measures under continuous review.