The FCA Regulatory Sandbox can help a firm test a genuinely innovative proposition with defined customers and safeguards, but it is not a queue that ends automatically in full authorisation. A durable authorised business still needs the correct permissions, capable management, adequate financial resources, operational controls, customer protection and a model that works outside a small test. The founder’s job is to use the sandbox to answer a narrow uncertainty while building the full company in parallel.
- OverviewThe FCA Regulatory Sandbox can help a firm test a genuinely innovative proposition with defined customers and safeguards, but it is not a queue that ends automatically in full authorisation.
- The sandbox answers a bounded questionThe FCA assesses applicants against five criteria: scope, genuine innovation, consumer benefit, readiness and a need for support.
- Restricted permission is still permission with limitsIf a firm must carry on regulated activity during its test, it needs the relevant authorisation or registration unless an exemption applies.
- Full operation requires a business-ready applicationThe sandbox test and the full authorisation case overlap, but they answer different questions.
- Three public journeys show why outcomes differThe FCA’s public material provides useful examples, although it is not a substitute for current register checks and company interviews.
The FCA Regulatory Sandbox can help a firm test a genuinely innovative proposition with defined customers and safeguards, but it is not a queue that ends automatically in full authorisation. A durable authorised business still needs the correct permissions, capable management, adequate financial resources, operational controls, customer protection and a model that works outside a small test. The founder’s job is to use the sandbox to answer a narrow uncertainty while building the full company in parallel.
The route is therefore test, evidence, decision and authorisation work, not acceptance, publicity and launch. Some participants are already authorised firms testing a new product. Some technology suppliers do not conduct regulated activity themselves. Others require restricted permission to run the agreed test. Those starting points lead to different outcomes and should never be collapsed into a single sandbox success rate.
The Regulatory Sandbox is a UK-wide FCA service, not a London programme. A London base may make some meetings or adviser relationships easier, but neither eligibility nor authorisation depends on a London postcode. This article remains in the London collection because of its relevance to the city’s fintech market, not because the regulatory route is geographically distinct.
The sandbox answers a bounded question
The FCA assesses applicants against five criteria: scope, genuine innovation, consumer benefit, readiness and a need for support. Its current eligibility guidance expects a developed testing plan, clear objectives and safeguards, relevant partners and readiness to apply for authorisation where necessary. A conventional product with no distinct testing need is unlikely to qualify merely because its founder wants regulatory reassurance.
A credible test begins with a decision the company cannot settle through desk research or ordinary user testing. That might concern how a disclosure performs with a particular customer group, whether a new risk control works in a live journey, or how an innovative model fits existing rules. The plan should state the test population, duration, success and stop criteria, data to collect, customer communications, redress arrangements and what happens when the test ends.
That discipline has commercial value even before acceptance. It forces the founder to separate the core uncertainty from everything else that must be true for the business to work. A six-month test cannot prove long-term retention, profitability or resilience under rapid growth unless the design and data genuinely address those questions.
Restricted permission is still permission with limits
If a firm must carry on regulated activity during its test, it needs the relevant authorisation or registration unless an exemption applies. The FCA’s application guidance explains that any permission granted for a sandbox test is restricted to the agreed plan. The firm may be limited by customer type, number of customers, transaction value, product scope or time.
The restriction protects consumers and keeps the test proportionate. It also means the company must control its acquisition and product systems so that it cannot accidentally operate outside the permission. Marketing should explain the product accurately and must not present sandbox acceptance as FCA endorsement.
Founders should map every intended activity before applying. Holding client money, issuing electronic money, providing payment services, arranging investments, advising, lending and supplying unregulated software can involve different regimes. The legal entity, partners and flow of funds matter as much as the interface. A vague plan to become “FCA approved” is not an authorisation strategy.
Full operation requires a business-ready application
The sandbox test and the full authorisation case overlap, but they answer different questions. Testing can produce evidence about customer behaviour, controls and product benefit. Authorisation asks whether the firm is fit and ready to conduct the requested regulated activities on an ongoing basis.
The FCA says applicants should be able to explain their regulatory obligations and submit a complete, tailored application. Depending on the model, that can include a regulatory business plan, financial forecasts, governance arrangements, senior-manager responsibilities, capital and liquidity, safeguarding, wind-down planning, complaints, financial-crime controls, outsourcing, technology risk and Consumer Duty evidence. A consultant may help, but management remains accountable for the application.
The transition plan should start before the live test. Assign an owner to every control, build an evidence register and record what the test changes. If customers will continue after restrictions are removed, design migration, communications and support before the test closes. If the result is negative, the company also needs a safe exit and a clear treatment of customer data and obligations.
Three public journeys show why outcomes differ
The FCA’s public material provides useful examples, although it is not a substitute for current register checks and company interviews.
Amplified Global, described as Amplifi in the FCA’s 2025 innovation report, first engaged with innovation services in 2019, joined the Digital Sandbox in 2020 to 2021, participated in the Regulatory Sandbox in 2022 to 2023 and was accepted again in 2026 to test layered disclosures. The FCA reports that the company used engagement to refine its proposition and raised about £2.7 million for development and scale. That is an outcome involving learning and finance, not public proof of unrestricted authorisation. The exact legal and trading names must still be matched to current Companies House and regulatory records before publication.
The same FCA report names another case as Bourn AI, which tested a flexible trade-account proposition using open-banking data and artificial intelligence for small-business finance. It says sandbox work focused on credit assessment, operational processes and regulatory compliance and supported a transition towards live operations. “Towards” matters: the public description does not establish the exact permission, customer volume or durable revenue position. This draft does not assume that “Bourn Technologies” is the relevant legal entity; that identity must be confirmed before publication.
Revolut entered the FCA’s 2026 stablecoin cohort as an established regulated group exploring a sterling-denominated stablecoin. The cohort page states that firms are testing under permissions and registrations they already hold, while the proposed future regime continues to develop. This is not a startup moving from unregulated idea to first authorisation. It shows that an existing firm may use a sandbox to investigate a new product at the regulatory frontier.
Together, the cases show three different results: iterative proposition development, progress towards live operation and a regulated incumbent testing an additional activity. None supports the claim that entry itself equals authorisation or commercial success.
The final report should drive a go, change or stop decision
The FCA normally expects a sandbox test to follow the agreed safeguards and end with a report on its aims and results. A founder should use that point as an investment committee would. Did the product deliver the stated consumer benefit? Which risks appeared? Did customers understand it? Could operations remain within limits? What would change at ten or one hundred times the test volume?
A positive result may support an application to remove restrictions or obtain the permissions needed for the full proposition. It may also justify another bounded test. A mixed result can require redesign, a different partner or a narrower target market. A negative result should be allowed to stop the product. Treating every test as a marketing success destroys the value of testing.
Once authorised, the work continues. The firm must meet ongoing reporting, capital, systems, conduct and governance obligations. It must monitor complaints, customer outcomes, incidents, financial crime and third parties. Authorisation is permission to operate under continuing supervision, not a certificate that the business model is durable.
Limits of the public evidence
The FCA’s accepted-firms list records participation, not a standardised result. The Financial Services Register shows regulatory status and permissions, but not revenue, customer retention or profitability. Companies House filings may be delayed, abridged or silent on product-level outcomes. Similar company names can also cause serious attribution errors.
Before publication, the three journeys need fresh entity-specific Register and Companies House checks, confirmation of each legal and trading name, direct company confirmation and interviews with participants that completed, changed or stopped a test. This draft explains the route accurately at a process level, but it does not claim that the named firms have identical permissions or that sandbox participation caused their later outcomes.
Reporting by Shoreditch Talk




