
Becoming a mortgage adviser is about more than mastering product knowledge and passing your CeMAP exams—it’s about operating within a robust regulatory framework that protects consumers and upholds professional standards. From securing the correct FCA authorisation to maintaining airtight data-protection protocols, each step ensures you can practise legally and ethically.
This guide walks you through the essential registrations, permissions, and ongoing obligations you need to build a compliant, trusted mortgage advice business in the UK.

FCA Authorisation: Appointed Representative vs Direct Authorisation
Securing FCA authorisation is your first critical step. You have two main routes: joining a network as an Appointed Representative (AR) or applying for Direct Authorisation (DA) yourself. Each has unique advantages, costs, and responsibilities.
Appointed Representative (AR)
Joining a mortgage network as an AR lets you “piggyback” on their FCA permissions. The network takes on the lion’s share of compliance oversight, allowing you to focus on client service.
- How it works: The network holds the FCA permissions, and you operate under their umbrella.
- Support provided: Compliance manuals, audit assistance, PI insurance cover, and training.
- Timeframe & costs: Typically one to two weeks for onboarding; fees range from £200–£500 setup plus monthly subscriptions and commission splits of 15–25%.
- Key obligation: You must still meet personal Conduct Rules and complete annual SM&CR certifications.
Direct Authorisation (DA)
If you crave full control—over your branding, lender panel, and fee structures—DA is the route. You apply directly to the FCA via the My FCA portal and take on all compliance responsibilities.
- Application process: Submit a detailed business plan, senior-manager Statements of Responsibilities, and systems & controls documentation.
- SM&CR implications: You must assign and document Senior Manager Functions (SMFs) and ensure Certification Regime standards for advisers.
- Costs & timeline: FCA application fee £1,200+) and compliance software costs. Approval can take 8–12 weeks.
SM&CR (Senior Managers & Certification Regime)
The Senior Managers & Certification Regime replaced the old Approved Persons regime to increase accountability within financial services firms. Even as a sole practitioner, you fall under SM&CR.
- Senior Managers: If you plan to hire staff or take on certain functions (e.g., Head of Advice), you become a Senior Manager, with a published Statement of Responsibilities.
- Certified Persons: Every adviser providing regulated mortgage advice must be certified annually as fit and proper.
- Conduct Rules: Seven fundamental standards (e.g., act with integrity, due skill and care) that apply to all certified and senior managers.
- Ongoing assessments: Annual performance reviews and fitness-and-propriety checks keep everyone up to date.
Embedding SM&CR practices ensures clarity of roles, reduces operational risk, and demonstrates to the FCA that your firm is well-governed.
Professional Indemnity (PI) Insurance
Professional Indemnity insurance is mandatory under FCA rules. It protects both your clients and your business in the event of an error, omission, or negligent advice.
- Minimum coverage: The FCA requires a minimum PI limit of £100,000 per claim, though many advisers choose higher limits (often £250,000–£500,000).
- Premium drivers: Factors include annual turnover, claim history, the complexity of advice, and whether you operate as AR or DA.
- Choosing a policy: Look for broad cover (including PI, civil liability, and defence costs), retroactive cover for past advice, and a reputable insurer with a clear claims process.
Maintaining continuous PI cover is non-negotiable—lapses can lead to FCA disciplinary action and loss of authorisation.
Anti-Money Laundering (AML) & CASS Obligations
AML Requirements
The UK’s AML regime is rigorous, reflecting the seriousness of preventing financial crime. As a mortgage adviser, you must implement robust AML procedures.
- Risk assessment: Conduct a firm-wide AML risk assessment to identify vulnerabilities.
- KYC and due diligence: Obtain and verify identity documents (e.g., passport, utility bills), source-of-fund information, and ongoing monitoring for high-risk clients.
- Suspicious Activity Reports (SARs): Train staff to spot and report unusual transactions to the National Crime Agency.
- Record retention: Keep AML records for at least five years after the end of a client relationship.
Client Money & Custody (CASS)
If you ever handle client money—perhaps collecting fees or holding deposits—you must comply with the FCA’s Client Assets Sourcebook (CASS) rules.
- Segregation: Hold client funds in separate bank accounts labeled “Client Money Account.”
- Reconciliation: Perform weekly reconciliations to ensure client ledger balances match bank statements.
- Exemptions: Commission-only advisers not holding client money are typically exempt, but you must document and evidence this status.
Data Protection & GDPR
Handling personal data responsibly is both a legal requirement under GDPR and a cornerstone of client trust. Non-compliance risks hefty fines and reputational damage.
- Lawful bases: Identify your lawful basis for processing client data (typically “performance of a contract” or “legitimate interests”).
- Privacy notices: Provide clear, concise privacy notices detailing how you collect, use, and store personal data.
- Client consent: Obtain explicit consent for any marketing communications, with easy opt-out mechanisms.
- Subject-access requests (SARs): Be prepared to supply clients with their data within one calendar month.
- Security measures: Encrypt data at rest, use strong access controls, and have an incident-response plan for data breaches.
Embedding GDPR best practices not only avoids fines but also strengthens client confidence in how you handle their sensitive information
Record-Keeping & Reporting
Accurate, accessible records underpin every compliance regime—from FCA supervision to CPD audits. A robust system protects you and demonstrates professional integrity.
- Record types: Keep fact-find documents, suitability reports, financial promotions, AML checks, and marketing approvals.
- Retention periods: Typically retain client records for six years post-relationship (longer if regulated mortgages are still in force).
- Digital vs paper: Cloud-based document management systems with version control and secure backups are now best practice.
- FCA returns: As a DA, you must file annual regulatory returns via RegData; ARs rely on their network to submit aggregated data.
A well-organised record-keeping system reduces audit time, aids with client queries, and ensures you can evidence compliance at any time.
Ongoing Obligations: CPD, Fees & Renewals
Compliance doesn’t end once you’re authorised—it’s an ongoing journey requiring diligence and planning.
- FCA fees & renewals: Pay your annual FSCS levy and regulatory fees on time via the My FCA portal to avoid penalties.
- LIBF CPD: Complete at least 35 hours of CPD annually (5 hours must cover ethics and regulation) and log your activities for inspection.
- SM&CR refreshers: Certify your advisers annually under SM&CR and schedule regular training on Conduct Rules.
- Policy reviews: Update your AML risk assessment and compliance manuals at least yearly or when regulations change.
Staying on top of these recurring tasks ensures uninterrupted authorisation and demonstrates your commitment to professional excellence.
Conclusion
Launching and maintaining a mortgage advice business in the UK means navigating a complex web of registrations, permissions, and legal requirements. From FCA authorisation and SM&CR to AML, GDPR, and PI insurance, each piece of the puzzle plays a vital role in protecting consumers and upholding industry standards. By following this roadmap—securing the right permissions, embedding robust controls, and committing to ongoing compliance—you’ll build a practice that is fully authorised, trusted, and resilient in a dynamic regulatory environment.
Ready to advance your mortgage expertise? Explore our CeMAP mortgage modules and gain the confidence to advise clients on tracker mortgages and beyond.