FSMA is a central UK financial-services statute covering regulated activities, authorization, permissions, markets, enforcement, and consumer mechanisms.
The Financial Services and Markets Act 2000 (FSMA) is a central statute in the United Kingdom’s financial-regulation framework. As amended, it governs matters including regulated activities, authorization and permissions, financial promotions, official listing and markets, regulator powers, enforcement, complaints, and compensation arrangements.
FSMA does not mean that every financial product or business is regulated in the same way. Scope depends on the legal entity, activity, investment or property, business context, customer, territorial connection, exemption, and permission in force.
Before FSMA’s main regime, UK investment business operated under the Financial Services Act 1986, while banking, insurance, and building societies also had separate statutory arrangements.
The Securities and Investments Board changed its name to the Financial Services Authority (FSA) in 1997. FSMA did not originate that company name change; it gave the integrated FSA regime its broad statutory foundation. The main provisions came into force on 1 December 2001, replacing several prior regimes.
After the global financial crisis, the Financial Services Act 2012 amended FSMA and reorganized supervision. From 1 April 2013:
FSMA should therefore be read as an amended framework, not as a frozen description of the original FSA model.
Section 19 provides that no person may carry on a regulated activity in the UK, or purport to do so, unless the person is authorized or exempt. Determining whether the prohibition applies requires a perimeter analysis rather than a job-title test.
Examples can include accepting deposits, effecting or carrying out insurance contracts, dealing in investments, arranging transactions, managing investments, giving specified investment advice, operating certain schemes, or providing other activities designated by legislation.
An activity is not regulated in the abstract. The relevant shares, debt instruments, fund units, insurance contracts, deposits, mortgages, or other specified property must fall within the applicable definition.
Many regulated activities must be carried on “by way of business.” The UK connection must also be analyzed. Cross-border websites, overseas firms, branches, agents, and remote services can require specific treatment.
The statutory framework contains exclusions and exemptions. Their wording and conditions matter; a broad commercial description such as “technology provider” or “professional adviser” does not settle the issue.
An authorized person needs permission for the activities it performs. Under the current framework, a Part 4A permission records the scope and may include limitations or requirements.
| Check | Question | Evidence |
|---|---|---|
| Legal entity | Is this the exact company or individual providing the service? | Registered name and company details |
| Status | Is the person authorized, exempt, an appointed representative, or outside scope? | Statute, FCA Register, or official order |
| Activity | Does the permission cover advice, arranging, dealing, managing, custody, deposits, or insurance? | Permission details and limitations |
| Product | Is the specific investment or service within scope? | Contract, product terms, and statutory definition |
| Customer | Do retail, professional, eligible-counterparty, or other classifications change the rule? | Client classification and applicable rule |
| Date | Was the status and permission effective when the activity occurred? | Effective dates and historical records |
The FCA’s Financial Services Register can help verify status and permissions. It should be matched to the exact legal entity and service. A genuine authorized firm can also be impersonated by a clone, and an authorized firm’s unregulated activity may not receive the same protections as its regulated business.
Section 21 establishes a separate restriction on communicating invitations or inducements to engage in investment activity in the course of business unless the communication is made or approved by an authorized person or an exemption applies.
Authorization to conduct one activity does not automatically permit every promotion. The communicator, audience, medium, product, approval route, and exemption conditions all matter. FCA rules can add requirements concerning whether communications are fair, clear, and not misleading for firms within scope.
The Financial Conduct Authority authorizes or registers many firms, maintains the Financial Services Register, makes rules, supervises conduct, regulates markets within its remit, and can use statutory enforcement powers. Its current objectives and powers come mainly from FSMA as amended.
The Prudential Regulation Authority is part of the Bank of England. It prudentially regulates specified deposit takers, insurers, and major investment firms. PRA-authorized firms can also be regulated by the FCA for conduct, so dual regulation does not mean duplicate roles.
The Bank of England has financial-stability, resolution, payment-system, and market-infrastructure responsibilities under FSMA and related statutes. HM Treasury, courts, the Financial Ombudsman Service, the Financial Services Compensation Scheme, and other authorities also perform distinct functions.
No single body resolves every FSMA question.
Assume a UK company launches an online platform that asks users about their goals, recommends one of several investment funds, arranges the purchase, and receives a distribution fee.
The company cannot settle its position by calling itself a “software marketplace.” A perimeter review would ask:
If the firm is permitted only to arrange investments, adding personalized recommendations may cross into an activity outside its permission. The correct response is to verify and, if necessary, vary permission before launching the feature, not to rely on a broad “FCA authorized” label.
FSMA supplies powers and mechanisms that can include investigation, public notices, financial penalties, injunctions, restitution, variation or cancellation of permission, and criminal consequences for specified conduct. Procedure, burden, appeal rights, and available remedies depend on the provision and facts.
The framework also supports:
These mechanisms have jurisdiction, eligibility, time, product, and compensation limits. They do not reimburse every loss or convert a risky investment into a guaranteed one.
Saying FSMA applies identically to all financial-service providers. The perimeter is based on defined activities and other statutory conditions.
Claiming FSMA created the FCA and PRA in 2000. The 2013 architecture followed the Financial Services Act 2012 amendments.
Treating “authorized” as an unlimited licence. Permission scope and limitations are central.
Assuming the FCA Register guarantees safety. The register helps establish regulatory status; it does not endorse a product or guarantee recovery, liquidity, or returns.
Using guidance without checking legislation. Perimeter guidance aids interpretation but does not replace the Act, orders, rules, or case law.
Assuming all losses qualify for compensation. Eligibility depends on the claimant, firm, activity, product, failure, timing, and scheme rules.
This article is general education, not legal, regulatory, compliance, tax, or investment advice. FSMA is frequently amended, and a current conclusion requires the specific facts, instruments, permissions, and effective dates.