Desk audit TBR-A-2026-004

Pepperstone

Independent desk audit of a retail broker, from public sources. Published 2 October 2026.

Current. Valid to 2 October 2027.

TBR DESK AUDIT · DESK AUDIT · A 75/100

Strong

Uncommissioned desk audit. TBR carried out this audit on its own initiative, using public sources only. Pepperstone did not commission or pay for it. No accounts were opened or tested, so Execution & Pricing and Operational Resilience were not assessed and do not count towards the grade. Pepperstone may respond, and any response is published in full. How desk audits are scored.

Summary

Pepperstone holds licences from seven regulators, including the FCA, ASIC, CySEC and BaFin, and no enforcement action was found in the sources reviewed. It also operates an offshore entity in the Bahamas, and as a private group it publishes less than its listed peers.

Grade
A
Score
75/100
Fieldwork
1 Oct 2026 to 2 Oct 2026
Findings
2 medium1 strength

Scorecard

PillarWeightScoreGrade
Regulation & Licensing19%80AA
Corporate Structure & Ownership14%70A
Client Money & Payouts19%78A
Execution & Pricingn/aNot assessed: requires live testing
Conduct & Disclosure14%88AA
Operational Resiliencen/aNot assessed: requires live testing
People & Community5%15C
Overall71%75A

The overall score is the weighted average of the assessed pillars, with their weights scaled back up to 100.

Findings

Licences verified

Each licence was checked directly against the regulator's public register on the date shown.

EntityRegulatorLicenceCheckedResult
Pepperstone EU LimitedCySEC388/202 Oct 2026ConfirmedAuthorised 3 August 2020; approved website pepperstone.com.

Notes and sources

Evidence and scope

Scope

Desk audit of the group’s client-facing entities, using public sources only: regulator registers and announcements, court and stock-exchange filings, and the firm’s own published documents, as available on 2 October 2026. No accounts were opened, nothing was tested live, and the firm was not asked for evidence.

Limitations

Absence of a public enforcement record is not evidence of good conduct. FCA and ASIC licence details are taken from the firm’s disclosures; the FCA and ASIC registers could not be queried directly for this audit and should be checked before publication.

Evidence reviewed

  • CySEC register entry, Pepperstone EU Limited
  • Pepperstone regulatory disclosures
  • Pepperstone legal documents

Version history

  1. Report published.
  2. Methodology update: enforcement older than eight years is recorded but no longer scored, applied to all audits.
  3. Methodology update: People & Community pillar added (workplace certification and community contribution, from public sources), applied to all audits.

Request a re-audit

Staff of Pepperstone can ask us to reopen this audit, for example after correcting a finding or completing remediation. Requests must come from a company email address, and you can attach evidence.

Request a re-audit

Badge and verification

Pepperstone may display this badge while the audit is current. It always links back to this report, and it updates itself: when the audit expires or is withdrawn, the badge says so. Anyone can check a badge by its reference in the audit registry.

Pepperstone audit badge