Deals for wealth managers, insurance brokers, payment firms, consumer credit businesses and advisory practices all share one feature: the buyer cannot simply complete when the lawyers are ready. The regulator has to agree first, and the data room has to serve both conversations.
Change in control usually sets the timetable
Under Part 12 of the Financial Services and Markets Act 2000, anyone who decides to acquire or increase control of an authorised firm must notify the regulator and obtain approval before completing. For most firms the first threshold is 10% of shares or voting power, with further thresholds above that. The FCA’s change in control guidance sets out the forms and process. For firms regulated by both the FCA and the PRA, such as banks and insurers, the PRA leads.
The FCA's change in control clock
Before the clock
The clock only starts once the FCA treats the notice as complete. Gaps found at this point cost time before day 1.
Up to 60 working days
The FCA can approve, approve with conditions or object within the assessment period.
Clock stopped
A request for further information can pause the clock until it is answered. Day 25 is illustrative.
A complete notice and fast answers are what keep the deal inside the assessment period.
datarooms.ukClock stop illustrative
The FCA has up to 60 working days to assess a complete notice and can pause the clock to ask for more information. Most delays come before or during that pause: missing documents on the buyer’s ownership chain, funding or business plan. Completing without approval can be a criminal offence, so build the long-stop date in the sale agreement around this period, not around diligence.
Two readers, one document set
| Document | What the buyer wants to know | What the regulator wants to know |
|---|---|---|
| Business plan after completion | Will revenue and margins hold? | Will the firm stay solvent and treat customers fairly? |
| Group structure and ownership chain | Who is the counterparty? | Who will control the firm, directly and indirectly? |
| Source of funds | Can the buyer pay? | Is the money clean and is the firm adequately capitalised? |
| Complaints and breach registers | What liabilities are hidden? | Are there unresolved conduct issues? |
The buyer usually prepares the change in control notice, but much of what it needs comes from the target. A dedicated folder, opened to the buyer’s regulatory counsel, avoids the same documents being requested twice under different names.
Regulated records that need care
Buyers will read the target’s own compliance evidence closely. Expect requests for:
- Compliance monitoring reports and the board’s responses
- Complaints data, root cause analysis and Financial Ombudsman Service decisions
- Client money and assets audit reports, if the firm holds client money
- The board’s annual Consumer Duty report and outcome monitoring
- Statements of responsibilities and the management responsibilities map under the Senior Managers and Certification Regime
- Correspondence with the FCA, including any skilled person reviews or voluntary requirements
Many of these name individual clients or staff. Summaries and anonymised samples are usually enough at first; complete files can be opened later to a small, named group. If new senior managers will join after completion, their approval applications also need time, and their supporting documents should sit in a separate restricted folder.
Mistakes in regulated deals
The commonest error is treating approval as a formality and signing a timetable that assumes it. Others include uploading full client files when a summary would do, letting the buyer’s operational staff see complaint details before exclusivity, and failing to keep the Q&A log complete. The regulator can ask what the buyer knew and when, and the room’s audit trail and Q&A export are the best evidence of it.
Budget
Regulated deals often stay open longer than a comparable unregulated sale, because the approval period follows signing. Choose pricing that does not penalise a few extra months, and check what an archive copy costs at the end. A small advisory practice will rarely need an enterprise room; a payments or insurance group sold by an investment bank often will. See our cost guide and the security details on the providers page.
Questions people ask
How long does FCA change in control approval take?
The FCA has up to 60 working days from the point it treats a notice as complete, and the clock can stop while it waits for further information. Allow for preparation time before submission as well.
Can the buyer see client files during diligence?
Only what it needs, when it needs it. Start with anonymised data and summaries, then open specific files to named reviewers after exclusivity, keeping UK GDPR and client confidentiality obligations in mind.
Does the FCA look at the data room?
Not directly. It reads the change in control notice and supporting documents, but those are usually drawn from the room, and the Q&A record shows what the buyer was told.
Should the data room provider be ISO 27001 certified for a regulated deal?
It is not a legal requirement, but many regulated buyers ask for ISO 27001 or SOC 2 reports as part of their own vendor risk checks. Ask early so the room is not questioned midway through.
