- Spotlight
- Sep 15, 2026
UK BNPL Authorisation: Your Retention Setting Is Your Defenсe
In this piece, Ronke Jegede, Founder and CEO of Cardinal AI Systems, looks at the gap between how long a BNPL lender can be challenged on a decision and how long it can actually prove one, and what to do about it before January 2027.

If you lend through buy now, pay later (BNPL) in the UK, July 15 changed your job. Deferred payment credit became a regulated activity that day. Klarna, Clearpay, Zilch, and everyone smaller either registered for temporary permission or already held consumer credit permissions, and either way, the same test now applies: under CONC 5.2A, you must be able to demonstrate that you assessed whether a customer could afford the repayments – not that you assessed, but that you can show it.
Which turns a technical question into the one that matters. How long does your system keep the record of a single lending decision?
A complaint from 2032
It is spring 2032. A customer who took out a £600 deferred payment agreement on Thursday, September 3, 2026, has complained to the Financial Ombudsman Service. She says the credit was unaffordable. She had three other BNPL arrangements running at the time, her current account showed a pattern of short-term borrowing, and her limit was raised twice without her asking.
She is on time. The Ombudsman can look back six years from the event, or three years from the point she knew or ought reasonably to have known she had cause to complain, whichever ends later. And it does not ask whether the firm was authorised. That is settled. It asks something narrower and much harder: what did you know about this customer at 14:22 on that Thursday, and how did what you knew produce this outcome?
By 2032, the decision engine has been retrained a dozen times. The device intelligence vendor has been replaced. Two thresholds moved in a release recorded as a performance fix rather than a policy change. And the decision-level logs, the ones holding which signals fired, which rules applied, which model version returned what score, rolled off on a ninety-day cycle in December 2026.
The firm can prove it had permission to lend. It cannot prove it made an assessment. That gap is the real regulatory event of 2026, and almost nobody is counting the clock on it.
What actually happened on July 15
The July milestone was widely reported as BNPL becoming regulated, and in places as firms entering full authorisation. Neither is quite right, and the imprecision matters, because it obscures the date that actually binds.
On July 15, deferred payment credit became a regulated activity. Firms that registered in time received temporary permission, which is permission to keep trading while they apply, and six months from Regulation Day in which to submit a full authorisation application. That puts the deadline at January 15, 2027. Lenders that already held consumer credit permissions never entered the regime, but they meet the same evidence test through variation of permission and through supervision. Temporary permission is a bridge. Authorisation is the exam, and it has not been sat.
Four things changed in July, and all four are evidence obligations wearing different clothes.
Creditworthiness. CONC 5.2A now bites, and it reaches even the smallest agreements. A firm must not enter into the agreement unless it can demonstrate that it carried out a reasonable assessment of the customer's ability to make the repayments without significant adverse impact. That construction allocates a burden. Having assessed isn't the standard. What counts is demonstrating that you assessed, judged on the information you were aware of at the time rather than on what the file looks like when the complaint arrives. A risk model tuned for loss rates and an affordability assessment are distinct artefacts serving different beneficiaries, and the record has to make that difference legible.
The Consumer Duty. Foreseeable harm, outcomes monitoring, an annual board-level assessment. The Duty is enforced by evidence that outcomes were monitored and that someone acted when they drifted, not by statements of intent.
Ombudsman jurisdiction. Individual decisions become individually contestable on the six- and three-year clocks above. This is the change that converts portfolio-level risk into file-level risk.
Connected lender liability. Section 75 of the Consumer Credit Act applies to regulated deferred payment credit, but only where the cash price of the item exceeds £100, so it will not apply to much of the BNPL basket at all. Where it does, it pulls merchant conduct into the lender’s file and keeps that file live for years.
Every one of those converts a product decision into something that must be reconstructible long after the team that built it has moved on.
The gateway is an evidence test
The threshold conditions ask whether a firm holds appropriate resources, explicitly including non-financial ones such as systems, controls, and people, whether its business model is suitable, and whether it can be effectively supervised.
Case officers want to see artefacts. The affordability policy and its version history. The monitoring MI, and the meeting at which somebody actually looked at it. A sample of real decisions with the reasoning still attached. The minute in which a threshold change was proposed, challenged, and approved.
Firms fail here on controls that exist in practice but were never written down. The team knows exactly why the threshold moved in November, and nobody recorded it at the time. Write it down afterward, and you've produced a reconstruction, which any competent case officer distinguishes from a record within a page.
The asymmetry is in the Handbook, not in Brussels
CONC requires a record of the creditworthiness assessment sufficient to demonstrate that the assessment was reasonable. It doesn't say how long to keep it. The retention question falls through to SYSC 9.1, whose standard is that records be kept for as long as is relevant to the purposes for which they were made. You can't configure a system against that.
So the number gets set somewhere else entirely: in a vendor's default configuration, by an engineer at integration, against no standard at all.
Your exposure to challenge on an individual decision runs to six years, and longer where the three-year limb applies. Your evidence, on a common ninety-day vendor default, runs to a quarter. The ratio between the window in which you can be asked and the window in which you can answer is roughly twenty-four to one. A generous six-month retention still leaves it at twelve to one.
Calculate that ratio for your own stack. It's the single number that predicts whether you can defend a decision, and most firms have never computed it, because retention gets configured system by system by whoever stood each system up. The method for calculating it, including default liability horizons to keep the number comparable across firms, is published in the Cardinal Decision Evidence Assessment.
What Brussels is and is not asking
One EU obligation already applies: since August 2, 2026, Article 50(1) of the AI Act requires that a customer interacting with an AI system be told so, which applies to the chat agent handling a limit increase request. It is a real duty, and a narrow one, and it says nothing about what you must be able to prove afterward.
The bigger obligations are further out. Under the Digital Omnibus, the application date for Annex III high-risk obligations moved to December 2, 2027. The creditworthiness assessment of natural persons is set out in Annex III. Until that date, those systems are not classified as high risk, and the logging, record-keeping, and explanation duties that attach to high-risk classification are asking nothing of your 2026 decision records.
If you were looking for a reason to defer, that is it, and it is a real one. It is also beside the point, for two reasons.
The first is the section above. The obligation to evidence a creditworthiness assessment is a UK one; it is in force, and it applies to the decision your engine makes this afternoon.
The second is Article 111(2), which almost nobody in this market is reading. Systems placed on the market before the Annex III application date, December 2, 2027, fall outside the high-risk regime unless they are subject to significant changes in their design thereafter. A BNPL decision engine is retrained. Thresholds move. Vendors are swapped. Features are added on a sprint cadence.
Whether a given change is significant turns on whether it was anticipated in the system's original design and documentation. So your scope position in 2028 rests on an artefact you're generating now: your model and policy version history, and what it shows about what was planned versus what was introduced. Firms with disciplined change records can demonstrate they stayed inside their envelope. Firms without them will be arguing from memory about a retraining run that took place two years earlier.
The deferral doesn't remove the record-keeping problem. It gives you 15 months during which the records that will determine your classification are being generated and either kept or discarded.
The record begins at onboarding
This is where it stops being a compliance problem and becomes a verification one.
The decision record is created at the moment of the decision, and for BNPL that moment is onboarding: the identity check, the device signal, the bureau pull, the fraud score, the limit assignment. If it is not captured there, it exists nowhere.
A defensible record should capture the full context of every decision. This includes a decision identifier and timestamp, as well as immutable version identifiers for the model, policy, and ruleset in force at that moment. It should preserve the inputs as received, including full vendor response payloads, rather than only the pass-or-fail verdict layered on top of them. Each signal should also carry its vintage – when the bureau, device, or behavioural data was captured, distinct from when it was used. The record should document the reason codes and thresholds applied, along with any human involvement: who reviewed the case, what they were shown, what they changed, and why. Finally, it should record the outcome and the explanation given to the customer.
Two procurement questions decide whether any of this is achievable, and both belong in the contract rather than in the implementation. What is your log retention period, and can it be set to ours rather than yours? And on termination, what is exported, in what format, and how long do we have to take it? A vendor’s ninety-day default becomes your evidentiary ceiling, silently, on the day you integrate.
Set retention to the longest applicable challenge window. Not to the shortest configurable floor.
The clock
Model quality isn't what the threshold conditions test, nor is it what an Ombudsman asks about. The firms that clear the gateway will be the ones who can sit down in 2032 and reconstruct precisely what happened at 14:22 on a Thursday in September 2026.
Applications are due January 15, 2027. The evidence you'll be judged on is being kept, or quietly not kept, right now.
Relevant articles
- spotlight
- Jul 9, 2026

- spotlight
- Aug 5, 2026
In this article, Simon Jones, CEO at Sumvin, discusses the problem of identity as the missing layer of the internet.

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


