
The FCA's non-financial misconduct rules are no longer a future implementation project. They took effect on 1 September 2026, and the question for non-bank firms has changed. It is no longer simply, "Have we updated the policy?" It is, "Could we make a fair, consistent and evidenced decision if a concern arrived today?"
That distinction matters. A polished staff handbook cannot decide whether conduct has a sufficient work-related link, whether it is serious enough to engage COCON, whether it indicates a lack of integrity or due skill, care and diligence, or whether behaviour outside work is relevant to fitness and propriety. Those decisions need governance, facts and records.
The FCA updated its non-financial misconduct page on 1 September 2026 to confirm that the rules and guidance are now in force. This is a genuine change from the position covered in our earlier pre-implementation guide to FCA non-financial misconduct. Firms have moved from readiness to operation.
For non-banking SMCR firms, the new rule at COCON 1.1.7FR extends the conduct-rules framework so that serious bullying, harassment or violence against colleagues can fall within COCON where the necessary work-related connection exists.
The FCA has also introduced detailed guidance on how the conduct rules apply, including the boundary between work and private life, the seriousness of behaviour, the effect and purpose of conduct, the position of witnesses, single incidents and managers' responsibilities. Separate guidance in FIT 1.3 explains when non-financial misconduct may be relevant to fitness and propriety, including some conduct in private life.
This is not a general workplace-behaviour code enforced by the FCA. It is a regulatory framework with defined questions about who is covered, what conduct is in scope, where it occurred, how serious it was and which rule may have been breached.
The change is relevant to firms with a Part 4A permission and to people who are subject to COCON or FIT. Firms without a Part 4A permission, including payment and e-money firms that fall outside SMCR, are not brought into scope by this rule simply because they are FCA-regulated. Principals and appointed representatives should map the position carefully rather than assume that every employee across every entity is covered in the same way.
Every decision should begin with scope. Is the individual a member of conduct rules staff? Does the conduct relate to the firm's activities? For a non-bank, does the new harassment rule apply because the person responsible or the subject of the conduct works in the financial-services part of the business? Do the territorial rules apply?
The answer cannot be reduced to where an incident happened. Conduct on firm premises or during work is relevant, but no single factor is conclusive. A social event may be connected to work; an exchange between colleagues may be private. Mixed financial and non-financial businesses create additional questions about which part of the organisation the people and activity relate to.
Firms should record the scope analysis before jumping to the breach question. A short decision template covering the individual, role, business activity, people involved, context and territorial link will usually be more useful than a policy that simply repeats the word "harassment".
The FCA's COCON 4.3 guidance makes clear that the new rule is concerned with serious conduct. Relevant factors include repetition, duration, impact, seniority, power over another person's career, previous warnings, aggravating or mitigating circumstances, criminality and whether the behaviour could justify dismissal.
A single incident can be enough. Equally, a breach of an internal policy does not automatically establish a conduct-rule breach. Firms need to consider the facts and then ask whether the behaviour involves a lack of integrity under Individual Conduct Rule 1 or a failure to act with due skill, care and diligence under Individual Conduct Rule 2.
Case triage should therefore avoid two shortcuts: treating every grievance as a regulatory breach, and dismissing an issue because it is described as a personality conflict. The useful question is whether the evidence satisfies the relevant regulatory tests.
The live guidance raises the stakes for managers without pretending that every manager controls every system. The FCA says a manager should try to prevent harassment and related misconduct that breaches COCON. Possible failures include not intervening where appropriate, not operating relevant policies and controls, not taking complaints seriously, and not providing a safe environment for concerns to be raised.
Accountability is still relative to the facts. Knowledge, reasonable steps, authority and constraints all matter. A manager may reasonably rely on HR to run an investigation, but allocating responsibility to HR or a central function does not automatically remove the manager's own regulatory responsibilities.
Training should use realistic decision scenarios. Managers should know when to preserve evidence, whom to notify, what confidentiality can and cannot be promised, and when a matter needs HR, compliance, legal or senior-management involvement. The record should show the information available at the time, not a tidier story written after the event.
COCON and FIT are connected, but they are not interchangeable. COCON is restricted by its application rules and does not generally cover private or personal life. FIT can consider a broader range of behaviour where it is relevant to whether an individual is fit and proper.
Private conduct may be relevant to FIT if, for example, it shows a material risk that the person will breach regulatory standards, demonstrates dishonesty or lack of integrity, involves an abuse of trust or exploitation of vulnerability, or is sufficiently serious to affect confidence in the regulatory system. A remote or speculative risk is not enough.
The FCA does not require firms to monitor employees' private lives or social-media accounts. It also does not expect firms to investigate trivial, implausible or irrelevant allegations. Where there is a good reason to look further, the response should remain proportionate, lawful and fair, with the reasoning recorded.
A sound case file should therefore contain distinct conclusions: whether COCON applies, whether a conduct rule was breached, whether the matter is relevant to FIT, what evidence supports each conclusion, and what review or mitigation is appropriate.
Serious, substantiated personal misconduct may need to flow into conduct-breach reporting and regulatory references. Firms also have an existing duty to notify conduct rules staff about the rules and take reasonable steps to ensure they understand how those rules apply.
The practical risk is fragmentation. HR may hold the investigation, compliance the COCON decision, a certification owner the FIT assessment and operations the reference request. If those records cannot be reconciled, the firm may reach inconsistent conclusions or miss a regulatory consequence.
Test the full path using a hypothetical case. Can the firm move from allegation to triage, investigation, COCON decision, FIT assessment, notification consideration, certification decision and regulatory reference without losing the rationale? Can it explain who approved each step and which version of the facts they relied on?
Proportionate implementation includes knowing what not to do. The FCA says firms do not need to reopen historic conduct-rule decisions or revise past fitness and propriety assessments merely because the new framework has commenced. The new COCON rule is not retrospective.
Firms do not need to monitor private lives, patrol private social media or investigate trivial and implausible allegations. They should not act contrary to privacy, employment or other applicable law. Regulatory confidence is not improved by disproportionate surveillance or weak process.
Smaller credit firms often combine responsibilities. The same senior person may oversee sales, complaints, financial promotions, certification and staff management. That can make escalation quick, but it can also concentrate judgement in one person and leave little independent challenge.
Principals should consider how relevant concerns involving approved persons at appointed representatives reach the right decision-makers. Directly authorised credit brokers should check that people responsible for certification, regulatory reporting and references receive the outcome of relevant investigations. Every firm should distinguish its employment process from its regulatory assessment while ensuring the two can exchange necessary facts lawfully.
This is also an evidence question. Our guide to preparing for an FCA compliance audit explains why a control is only as useful as the records showing how it operates. Non-financial misconduct is now another area where policy, practice and evidence must agree.
By the end of the first month, a firm should be able to produce a compact evidence pack containing:
The FCA's final policy statement, PS25/23, repeatedly emphasises judgement. That is not permission to be vague. It means firms need a process that helps competent people exercise judgement consistently and explain it later.
The first week of a new rule rarely produces a dramatic regulatory event. The more revealing question is whether the firm's next real case will be handled better than the last one.
Authorised Compliance helps credit brokers, principals and other regulated firms translate FCA changes into workable policies, decision frameworks, training and monitoring. For support with an implementation review of the non-financial misconduct rules, contact support@authorisedcompliance.com.
The rule is now live. The standard to aim for is not perfect foresight; it is proportionate action, clear ownership and evidence that shows how the firm reached its decision.

I’m Will Hurst, and I bring 20+ years of hands-on experience across credit broking, AR/IAR oversight, lender relationships and regulated finance operations.
Learn more about my practical, FCA-focused approach