HandbookPERG

What Is PERG? FCA Perimeter Guidance

PERG is the FCA's Perimeter Guidance manual: what counts as a regulated activity, which exclusions apply, and where firms get the perimeter wrong.

By MEMA Regulatory Team·17 min read·

What It Is

The Perimeter Guidance manual (PERG) is the FCA's guide to the boundary between regulated and unregulated financial services activity. It helps firms, individuals, and their advisers determine whether a particular activity requires FCA authorisation, or whether it falls outside the regulatory perimeter through an exclusion, exemption, or because it does not constitute a regulated activity in the first place.

The perimeter is defined by the Financial Services and Markets Act 2000 (FSMA), the Regulated Activities Order 2001 (RAO), and various secondary legislation. PERG does not itself create rules: it provides the FCA's interpretation and guidance on how the statutory framework applies to common business models and activities. While not legally binding, PERG guidance carries significant weight: a firm that follows PERG guidance in good faith is in a stronger position than one that ignores it.

PERG covers a wide range of territory: general guidance on regulated activities (PERG 2), guidance on the communication of financial promotions (PERG 8), insurance distribution (PERG 5), payment services (PERG 15) and e-money (PERG 3A), and several other sector-specific chapters. The full map is set out below, because picking the wrong chapter is a common way to reach a confident but wrong answer. For any firm operating near the edge of the regulatory perimeter, PERG is essential reading.

Why the FCA Cares

The general prohibition is the foundation of the UK's financial regulatory framework. Section 19 of FSMA makes it a criminal offence to carry on a regulated activity in the UK without authorisation or an applicable exemption. The maximum penalty is two years' imprisonment and an unlimited fine. Agreements entered into in breach of the general prohibition may be unenforceable, meaning the firm cannot recover money owed under the contract.

The FCA actively monitors the perimeter. Its Unauthorised Business Department investigates firms and individuals that appear to be carrying on regulated activities without authorisation, and it publishes consumer warnings about unregulated entities. The FCA can seek injunctions, restitution orders, and criminal prosecution against those who breach the general prohibition.

Perimeter issues also matter for authorised firms. A firm that carries on regulated activities beyond the scope of its permissions is in breach of section 20 of FSMA. This can result in enforcement action, variation or cancellation of permissions, and, critically, the unenforceability of contracts made in breach. The FCA has taken action against firms that have expanded their business into new activities without obtaining the necessary permissions.

From the FCA's perspective, perimeter integrity protects consumers. Regulated firms are subject to conduct standards, capital requirements, complaints handling obligations, and the Financial Services Compensation Scheme. Consumers dealing with unregulated entities have none of these protections. Every firm that operates outside the perimeter without detection represents a gap in consumer protection.

Who It Affects

Perimeter questions affect three broad categories of firm. First, businesses that are not currently FCA-authorised but may be carrying on activities that require authorisation. This includes fintech companies, technology platforms, introducers, lead generators, and professional services firms whose activities may have strayed into regulated territory.

Second, FCA-authorised firms that are expanding into new business lines, launching new products, or changing their distribution model. A firm authorised to provide investment advice may inadvertently begin managing investments; a firm authorised to arrange insurance may begin effecting contracts. Each new activity must be assessed against the RAO to determine whether additional permissions are required.

Third, firms that rely on exemptions, particularly appointed representatives and firms relying on the professional or group exemptions. These exemptions have specific conditions, and if those conditions are not met, the firm is carrying on a regulated activity without authorisation.

Consumer credit firms are particularly affected. The consumer credit perimeter is complex, with detailed provisions governing lending, credit broking, debt collecting, debt adjusting, and ancillary activities. The expansion of the FCA's consumer credit remit in 2014 brought thousands of previously unregulated firms within scope, and perimeter questions in this sector remain frequent.

Payment services firms and e-money issuers operate under a separate but parallel regulatory framework, where the perimeter is defined by the Payment Services Regulations 2017 and the Electronic Money Regulations 2011. PERG 15 provides guidance on these regimes, including the scope of payment services, agent and distributor arrangements, and the application of exclusions.

What Firms Get Wrong

The most dangerous error is assumption. Firms assume that because their activity does not feel like financial services, or because similar businesses appear to operate without authorisation, their activity is not regulated. The perimeter does not depend on how the activity feels; it depends on whether the statutory definition is met. Introducing customers to lenders is credit broking. Helping someone complete an insurance application may be arranging. Managing a client's portfolio on a discretionary basis is managing investments. The labels firms use for their activities are irrelevant; the substance is what matters.

The second common error is misapplying exclusions. Exclusions in the RAO are narrowly drafted, and their application depends on precise factual circumstances. The "generic advice" exclusion, the "introducer" exclusion, and the "groups and joint enterprises" exclusion are all frequently misapplied. Firms read the exclusion broadly, assume it covers their activity, and do not seek legal advice. When the FCA investigates, the exclusion often does not apply, and the firm has been operating illegally.

Third, firms fail to reassess the perimeter when their business evolves. A firm that starts by providing information may, over time, begin providing advice. A firm that introduces clients to product providers may begin negotiating terms on the client's behalf. Each incremental change may cross a perimeter boundary, but because the change is gradual, the firm does not recognise the transition.

Fourth, firms confuse FCA registration with authorisation. Payment services firms, e-money issuers, and certain consumer credit firms may be registered rather than authorised, but registration still imposes regulatory obligations. Other firms assume that Companies House registration or professional body membership substitutes for FCA authorisation. It does not.

What Evidence the FCA Expects

When the FCA investigates a perimeter issue, it examines substance over form. The regulator will look at what the firm actually does, not what its website says, not what its contracts state, and not what the firm's directors believe. Customer communications, call recordings, email correspondence, and the firm's actual processes all form part of the evidential picture.

For firms relying on exclusions, the FCA expects contemporaneous evidence that the conditions of the exclusion are met. If a firm relies on the introducer exclusion, for example, the FCA will want to see evidence that introductions are made to authorised persons, that the firm does not advise, and that the firm's remuneration is disclosed.

For authorised firms, the FCA expects evidence that the firm monitors the scope of its permissions against its actual activities. This means a regular perimeter assessment, ideally annual, that maps the firm's business lines, products, and activities against its FCA permissions and identifies any gaps. The compliance function should own this assessment and escalate any issues to the board.

Where a firm has identified a perimeter issue and self-reported, the FCA will look at the firm's response: did it stop the unauthorised activity promptly, assess customer impact, consider whether redress is required, and take steps to prevent recurrence? Self-reporting and proactive remediation are significant mitigating factors.

Good Implementation

A firm with good perimeter governance maintains a permissions map, a document that links each of the firm's business activities to a specific FCA permission (or to a documented exclusion or exemption). This map is reviewed whenever the firm launches a new product, enters a new distribution channel, or changes its business model. It is owned by the compliance function and approved by the board.

Staff who are involved in client-facing activity understand the firm's permissions and the boundaries of what they can and cannot do. Training covers practical scenarios, not just regulatory abstractions. Front-line staff know that arranging a transaction is different from providing information, that recommending a product requires advice permissions, and that handling client money triggers CASS obligations.

The firm's contracts and terms of business accurately reflect the regulated activities it performs. Client agreements do not disclaim regulation when the firm is in fact carrying on regulated activities: such disclaimers have no legal effect and may actually make things worse by suggesting the firm is aware of the issue.

For firms operating near the perimeter, introducers, technology platforms, professional firms, legal advice is obtained before launching the business and periodically thereafter. The firm does not rely on informal guidance or competitor behaviour to justify its position.

The PERG Chapter Map

PERG is not one document. It is eighteen chapters, and the answer to a perimeter question usually lives in exactly one of them. Reading the wrong chapter is a reliable way to reach a confident answer that is wrong.

ChapterCovers
PERG 1Introduction to the Perimeter Guidance manual
PERG 2Authorisation and regulated activities — the general chapter
PERG 3AScope of the Electronic Money Regulations 2011
PERG 4Regulated activities connected with mortgages
PERG 5Insurance distribution activities
PERG 6Identification of contracts of insurance
PERG 7Periodical publications, news services and broadcasts
PERG 8Financial promotion and related activities
PERG 9Meaning of open-ended investment company
PERG 10Activities related to pension schemes
PERG 11Property investment clubs and land investment schemes
PERG 12Running or advising on personal pension schemes
PERG 13Investment services and activities, and investment firms
PERG 14Home reversion, home purchase and sale and rent back
PERG 15Scope of the Payment Services Regulations 2017
PERG 16Scope of the Alternative Investment Fund Managers regime
PERG 17Consumer credit debt counselling

Three things that catch people out. Consumer credit has no single chapter — PERG 17 covers debt counselling only, and the broader credit activities sit as specified activities in PERG 2.7 with their exclusions in PERG 2.9. Cryptoassets have no PERG chapter at all; the perimeter position sits outside PERG. Funeral plans were folded into PERG 2 rather than given a chapter of their own, with the business-element treatment at PERG 2.3.4B. PERG 3 was deleted and replaced by PERG 3A.

The FCA's Own Decision Sequence

PERG 2.2.3G sets out the order in which the FCA expects the question to be worked through, and reproduces it as a decision tree at PERG 2 Annex 1G. Using the regulator's own sequence is worth more than a bespoke one, because it produces a record that maps onto how the FCA will read it:

  1. Is the activity carried on by way of business? (PERG 2.3)
  2. Does it relate to a specified investment? (PERG 2.6)
  3. Is it a specified activity? (PERG 2.7)
  4. Is it carried on in the United Kingdom? (PERG 2.4)
  5. Does an exclusion apply? (PERG 2.8, PERG 2.9)
  6. Is the person exempt? (PERG 2.10)
  7. If authorisation is needed, what scope of Part 4A permission? (PERG 2 Annex 2G)

The order matters. A firm that starts at step 5 — hunting for an exclusion — has usually skipped the question of whether it needed one.

The "By Way of Business" Test

Section 22 FSMA requires an activity to be carried on "by way of business", but does not define the phrase. Two things fill the gap.

The first is the Carrying on Regulated Activities by Way of Business Order 2001 (SI 2001/1177), which varies the test by activity. Insurance distribution is only "by way of business" if taken up or pursued for remuneration. Securities and contractually-based investment activities use a narrower test than the ordinary one: the person must carry on the business of that activity in its own right, not merely do it incidentally. Deposit-taking turns on whether the person holds himself out as accepting deposits day to day.

The second is judgement. PERG 2.3.3G weighs the degree of continuity, the existence of a commercial element, the scale of the activity, and the proportion it bears to the person's other activities. None of these is decisive on its own, which is why "we only do it occasionally" is an argument rather than an answer.

There is a separate question that firms miss entirely: whose business is it? PERG 2.3.5G onwards deals with employees and agents. An employee carrying on a regulated activity for an employer is not in breach, because the business is the employer's. PERG 2.3.7G sets out the factors — control, integration, financial risk and reward, whether the person deals with customers in their own name, whether services go to more than one client. For anyone engaging self-employed introducers or consultants, that test decides who needs the permission.

The Exclusions That Matter Most

Exclusions in the Regulated Activities Order are narrowly drafted and turn on precise facts. These are the ones that come up most:

ExclusionRAO articleWhat it does
Trustees, nominees and personal representativesArticle 66Excludes a trustee or personal representative acting as such, provided they do not hold themselves out as providing the regulated service and take no remuneration beyond their trustee fee
Professions or businesses not involving regulated activitiesArticle 67Covers activity that is a necessary part of other professional services, and only where it is not separately remunerated
Groups and joint enterprisesArticle 69Excludes intra-group dealings and dealings within a joint enterprise for its commercial purposes
Sale of a body corporateArticle 70Excludes share transactions where 50% or more of the voting shares change hands, or where the object is acquiring day-to-day control
Employee share schemesArticle 71Excludes a company or scheme trustee operating a share scheme in its own securities. It does not extend to third-party administrators
Overseas personsArticle 72Excludes a person with no permanent UK place of business who deals through or with an authorised person, or acts on a legitimate approach

Separate from the RAO entirely, Part XX FSMA (sections 325 to 333) exempts members of designated professional bodies for activities incidental to their profession, provided they receive no undisclosed pecuniary reward and do not hold themselves out as conducting other regulated activities. Claiming that exemption falsely is itself an offence under section 333.

Where the Perimeter Applies Geographically

Section 19 requires authorisation for regulated activity carried on in the United Kingdom, and section 418 extends what that means considerably. An activity can be treated as carried on in the UK where day-to-day management of it is the responsibility of a UK establishment, or where it is carried on from a UK establishment even though its constituent steps happen abroad. PERG 2.4.3G gives the worked example: management in one country, assets held in a second, transactions in a third, but the decisions taken from a UK office — carried on in the UK.

The corollary is that an overseas firm without a UK place of business can still be caught, and its route out is usually the overseas persons exclusion at article 72 rather than an argument about geography.

Several regimes do not use the general test at all. Claims management has its own gateway confined to Great Britain. Home finance turns on the residency of the borrower or occupier. Funeral plans are regulated only where the contract is for a funeral in the United Kingdom.

What Happens If You Get It Wrong

Three consequences, and the second and third are the ones that hurt commercially.

The offence. Contravening the general prohibition in section 19 is a criminal offence under section 23 — up to two years' imprisonment and an unlimited fine on indictment. Section 23(3) provides a defence for a person who took all reasonable precautions and exercised all due diligence, which is the practical reason a documented perimeter analysis is worth keeping.

The contracts. Under section 26, an agreement made in the course of carrying on a regulated activity in breach of the general prohibition is unenforceable against the other party, who can recover money or property paid under it and be compensated for loss. Section 27 extends the same result to agreements made by an authorised firm where they result from something an unauthorised third party did — an unauthorised introducer can therefore make the authorised firm's contracts unenforceable.

The discretion. Unenforceability is not absolute. Section 28(3) lets the court allow the agreement to be enforced, or money paid under it to be retained, if satisfied that it is "just and equitable in the circumstances of the case". For section 26 cases, the court must have regard to whether the person carrying on the activity reasonably believed that he was not contravening the general prohibition. That is the point at which a contemporaneous perimeter analysis stops being a compliance document and becomes evidence. And a party recovering money under these provisions must return whatever they received themselves — the remedy is mutual restitution, not a windfall.

One caveat worth stating plainly: PERG is guidance issued under section 139A. It does not bind the courts. A perimeter memo built on it informs the "just and equitable" question; it does not decide it.

How Our Tool Helps

The MEMA perimeter assessment tool provides a structured framework for mapping your business activities against the FCA's regulated activities definitions. It walks you through each activity specified in the RAO, helps you identify which activities your firm performs, and flags where authorisation, additional permissions, or an exclusion analysis may be required.

The tool generates a documented permissions gap analysis that you can use as the basis for a board-level perimeter review. It highlights common risk areas for your sector and prompts you to consider activities that firms frequently overlook, such as financial promotions, arranging activities, and client money handling.

For firms that rely on exclusions, the tool includes a structured exclusion assessment that prompts you to document the factual basis for each exclusion relied upon, the conditions that must be met, and the monitoring you have in place to ensure those conditions continue to be satisfied.

How Our Service Helps

Our FCA authorisation service supports firms at every stage of the perimeter analysis and authorisation process. For firms that are unsure whether their activities are regulated, we conduct a detailed perimeter assessment, examining your business model, client interactions, revenue streams, and operational processes to determine whether FCA authorisation is required and, if so, which permissions you need.

For firms that need to apply for authorisation or vary their existing permissions, we manage the application process from start to finish. We prepare the regulatory business plan, draft the compliance monitoring programme, advise on capital adequacy, and coordinate with the FCA Gateway team throughout the assessment process.

For existing authorised firms, we provide periodic perimeter reviews to ensure that your permissions remain aligned with your business activities as they evolve. This is particularly valuable for firms undergoing growth, diversification, or changes in their distribution model.

Relevant Sectors

Consumer credit firms face some of the most complex perimeter questions in UK financial regulation. The distinction between credit broking, lending, debt administration, debt collecting, and ancillary credit activities is frequently misunderstood. Firms that believe they are simply introducing customers to lenders may in fact be carrying on credit broking. Buy-now-pay-later providers, salary advance firms, and peer-to-peer platforms all face nuanced perimeter questions.

Payment services firms must navigate the boundary between payment services (regulated under the PSRs) and other activities that may require FCA authorisation under FSMA. The interaction between e-money issuance, payment initiation services, and account information services creates perimeter complexity, particularly for fintech businesses with innovative business models.

Insurance brokers must distinguish between arranging insurance (a regulated activity requiring appropriate permissions), providing information about insurance products (which may fall within an exclusion), and advising on insurance (which requires specific advice permissions). The perimeter is further complicated by the distinction between insurance distribution (regulated under IDD) and activities that fall outside the distribution definition. Connected travel insurance, warranties, and group schemes all raise specific perimeter questions.

Frequently Asked Questions

Which PERG chapter covers my activity?

PERG 2 is the general chapter and the right starting point. From there: mortgages are PERG 4, insurance distribution PERG 5, what counts as a contract of insurance PERG 6, financial promotions PERG 8, pensions PERG 10 and 12, investment services and firms PERG 13, home reversion and sale and rent back PERG 14, payment services PERG 15, e-money PERG 3A, AIFM PERG 16, and consumer credit debt counselling PERG 17. Three things catch people out: consumer credit has no single chapter beyond debt counselling, cryptoassets have no PERG chapter at all, and funeral plans were folded into PERG 2 rather than given their own.

What does 'by way of business' actually mean?

Section 22 FSMA requires it but does not define it. The Carrying on Regulated Activities by Way of Business Order 2001 varies the test by activity, so insurance distribution is only caught if pursued for remuneration, and securities activities use a narrower test requiring the business to be carried on in its own right rather than incidentally. Beyond that it is a judgement weighing continuity, commercial element, scale, and the proportion the activity bears to everything else the person does.

If we get the perimeter wrong, are our contracts still valid?

Not necessarily. Under section 26 FSMA an agreement made in the course of carrying on a regulated activity in breach of the general prohibition is unenforceable against the other party, who can recover what they paid and claim compensation. Section 27 extends this to an authorised firm's agreements where they result from an unauthorised third party's involvement. Section 28 lets a court allow enforcement anyway where it is just and equitable, and for section 26 cases it must consider whether the firm reasonably believed it was not in breach - which is why a documented, contemporaneous analysis matters.

What is the general prohibition and what are the consequences of breaching it?

The general prohibition (section 19 of FSMA) makes it a criminal offence for a person to carry on a regulated activity in the UK unless they are authorised or exempt. Breach can result in up to two years' imprisonment and an unlimited fine. Agreements made in breach of the general prohibition may also be unenforceable against the customer, meaning the firm cannot recover money owed under the contract.

How does a firm determine whether its activities are regulated?

A regulated activity is an activity specified in the Financial Services and Markets Act 2000 (Regulated Activities) Order 2001 (RAO) that is carried on by way of business and relates to a specified investment or, in some cases, specified property. The analysis has three parts: is the activity specified, does it relate to a specified investment, and is it being carried on by way of business? All three must be satisfied. PERG provides detailed guidance on each element.

Can a firm rely on an exclusion without FCA authorisation?

Yes, but with great care. Exclusions in the RAO modify the scope of regulated activities: if an exclusion applies, the activity is not regulated and no authorisation is needed. However, exclusions are narrowly drafted and fact-specific. A firm that incorrectly relies on an exclusion is carrying on a regulated activity without authorisation, which is a criminal offence. The FCA recommends that firms take legal advice before relying on exclusions.

What is the difference between an exclusion and an exemption?

An exclusion removes the activity from the scope of regulation entirely: the activity is not a regulated activity if the exclusion applies. An exemption, by contrast, acknowledges that the activity is regulated but permits a specific category of person to carry it on without authorisation. The Appointed Representatives regime is a common example: the activity remains regulated, but the AR is exempt from the authorisation requirement because its principal takes regulatory responsibility.

PERGperimeter guidancegeneral prohibitionregulated activitiesexemptions

Need help implementing this?

Our regulatory consultants can help your firm meet FCA requirements with practical, evidence-based implementation support.

Book a Free Consultation