All Insights
Remediation

When the FCA puts a requirement on your permission

VREQs and OIREQs are how the regulator contains a problem while you fix it. They're increasingly common, usually public, and the window to shape one is short.

24 June 2026 · 5 min read


Between an information request and a full enforcement investigation sits a set of supervisory tools that most firms only learn about when one arrives. A requirement placed on your permission is the most consequential of them. It can be voluntary — a VREQ, where the firm applies to vary its own permission to include the requirement — or imposed by the regulator using its own-initiative powers, an OIREQ. Either way the practical effect is similar: a clear, enforceable boundary on what the firm can do while a concern is contained and fixed. Typical triggers are concerns about systems and controls, financial crime, client assets, conduct, or governance and management.

The scale is worth understanding. The FCA has been reviewing and updating the requirements, directions and limitations applied to over 9,000 firms, and its use of these tools has grown markedly over recent years as supervision has taken on work that once went to enforcement. Requirements are typically published on the Financial Services Register — a point on which the Financial Regulators' Complaints Commissioner has criticised the FCA for not making the position clear enough to firms — so for many firms the reputational consequence arrives alongside the operational one. Sponsor banks, counterparties and prospective clients all read the Register.

Non-engagement doesn't avoid the requirement; it removes your influence over its terms.

The most important thing to understand is that the voluntary route is a negotiation and the imposed route largely isn't. A VREQ can be discussed: firms can make representations that a requirement isn't necessary, propose alternative internal changes, or offer undertakings addressing the specific concern. Decline to engage and a voluntary requirement can simply become an imposed one — and once an own-initiative requirement is issued via a supervisory notice, the route of challenge is the Upper Tribunal, which has yet to overturn one. Non-engagement doesn't avoid the requirement; it removes your influence over its terms.

The second most important thing: a requirement is not the end of the story, it's the start of a clock. It exists so a problem is contained while you fix it, and it comes off when the FCA is satisfied that you have. Many are deliberately shaped so a firm can keep servicing existing clients while restricting new business, precisely so it can trade through the fix. Firms that treat one as an administrative inconvenience — rather than resourcing the remediation that would lift it — end up living with it far longer than necessary. And firms have been fined for breaching requirements they agreed to themselves, which converts a supervisory matter into an enforcement one in a single step.

What firms should do

  • Escalate immediately and get the right people around it. This is a board-level matter, not a compliance inbox item.
  • Engage on the wording while you still can — scope, carve-outs for existing clients, and the conditions for removal are all legitimately discussable.
  • Assume it will be public, and prepare what you'll say to clients, banking partners and counterparties before they read it on the Register.
  • Build the remediation plan that lifts the requirement, with owners, evidence and a realistic timeline. The exit criteria are the whole point.
  • Comply precisely and document that you have. Breaching a requirement is the fastest route from supervision to enforcement.

Sources: FCA news, "Updates to requirements, limitations and directions" (review covering over 9,000 firms); FSMA own-initiative requirement and variation of permission powers; FCA Enforcement Guide; Office of the Financial Regulators' Complaints Commissioner findings on publication of requirements; Hickman & Rose, Norton Rose Fulbright, Richardson Lissack and IQ-EQ commentary (January–May 2026).

Need help applying this?

ComplyPath works with investment and payments firms on financial crime, CASS and safeguarding, Consumer Duty, regulatory remediation and authorisations.

Get in touch

Related Insights