FCA non-financial misconduct: the conduct risk firms cannot leave to HR

FCA non-financial misconduct rules take effect on 1 September 2026. Credit brokers and regulated firms should review conduct rules, FIT assessments, references and manager training now.

FCA non-financial misconduct: the conduct risk firms cannot leave to HR

There is a particular kind of regulatory change that looks deceptively tidy from a distance. It has a date, a rule reference and a neat label. It can be filed under culture, governance or conduct. Then, a few weeks before implementation, firms realise it touches employment policies, regulatory references, annual certification, breach reporting, manager training, investigation records and the judgement of senior people who thought this was mainly an HR matter.

The FCA non-financial misconduct changes fall squarely into that category.

From 1 September 2026, a new rule will extend the scope of the FCA conduct rules in non-banking firms so that bullying, harassment or violence against colleagues can fall within COCON where there is a sufficient work-related link. The FCA has also published guidance on how firms should think about the boundary between work and private life, how non-financial misconduct can affect fitness and propriety, and what managers may need to do when concerns arise.

This is not a sudden attempt to make regulators the office etiquette police. Nor is it an invitation for firms to start trawling through employees' private lives. The FCA says the rule is not retrospective, does not extend its remit beyond SMCR financial activities, and does not require firms to monitor private social media accounts or investigate trivial, implausible or irrelevant allegations.

That matters, because the sensible response is not panic. It is governance.

Why this matters for credit brokers and consumer credit firms

Many credit brokers, lenders and consumer credit firms will be tempted to treat FCA non-financial misconduct as a City issue, the sort of thing that belongs to banks, trading floors and large institutions with committees for committees. That would be a mistake.

The point of the change is consistency across financial services. Smaller regulated firms still have conduct rules staff. They still make fitness and propriety judgements. They still issue and receive regulatory references. They still depend on managers to identify when behaviour is more than a workplace nuisance and may be relevant to regulated activity.

For a credit broker, culture is not a soft side-topic. It shapes how leads are handled, how vulnerable customers are treated, how complaints are escalated, how incentives are understood and whether staff feel able to challenge poor practice. A firm that tolerates intimidation internally should not be surprised when weak challenge shows up externally in customer journeys, financial promotions, affordability handoffs or introducer oversight.

The FCA has spent years telling firms that conduct is not confined to narrow rule breaches. Consumer Duty, SMCR, operational resilience and financial promotions all push in the same direction: firms must be able to show that responsibility sits somewhere real, not somewhere decorative.

Non-financial misconduct is part of that same story. The regulator is drawing a line between personal behaviour and regulated trust. If serious misconduct goes unchecked, it can harm individuals, damage firms and weaken confidence in financial services. That is not an HR slogan. It is a supervisory concern.

The rule is narrower than the headlines, but wider than many policies

The FCA's own explainer is careful. The new COCON rule covers bullying, harassment or violence against colleagues where the behaviour relates to an individual's role and has a sufficient work-related link. It does not apply to every private argument, every unpleasant social interaction or every untested allegation.

That should reassure firms, but it should not lull them. The practical issue is that many firms' current processes are not built to make these distinctions well.

One policy may sit with HR. Another may sit with compliance. Certification may happen annually with a checklist. Regulatory references may be handled by operations or a senior manager with little visibility of historic investigations. Complaints about behaviour may be recorded in one place while conduct rule breach considerations sit somewhere else entirely.

That is the gap the September deadline exposes. A firm does not need to label every workplace concern as a conduct breach. It does need a defensible way to decide when the concern is relevant, who decides, what evidence is considered, how proportionality is applied and what record is kept.

FIT is the bigger sleeper issue

COCON will attract attention because it is new and rule-like. FIT may cause more practical difficulty.

The FCA says the Fit and Proper test already allows firms to consider any relevant misconduct, wherever it occurs, when assessing fitness and propriety. The new guidance clarifies how a broader range of non-financial misconduct can be relevant to those assessments, including issues involving private life, social media and unproven allegations.

That is uncomfortable territory because firms must balance regulatory judgement, employment law, privacy, fairness and evidence. Overreacting can be as dangerous as underreacting. A firm that treats every allegation as determinative risks unfairness. A firm that ignores credible, serious behaviour because it happened outside a narrow regulated task risks missing the point of FIT altogether.

The answer is not a crude policy that says all misconduct equals failure. The answer is a reasoned framework. What is the seriousness of the conduct? Is it substantiated? Is it relevant to the individual's role? Does it suggest dishonesty, lack of integrity, poor judgement, disregard for others or a risk to consumers or colleagues? Has the person shown insight? Are restrictions, supervision, training or role changes appropriate?

Those questions are not glamorous, but they are exactly where firms will be judged if decisions are later challenged.

Regulatory references need cleaning up before September

Regulatory references are where vague culture commitments become operational reality.

The FCA has said serious, substantiated cases of poor personal behaviour will need to be shared through regulatory references in the same way as financial misconduct. That means firms need to know what their records say, who owns them and how decisions are made when another firm asks for a reference.

For smaller firms, this is often where the machinery creaks. Historic notes may be incomplete. Settlement agreements may have been written without enough regulatory thought. Investigation outcomes may use employment language that does not map neatly onto conduct rules or FIT. A founder-led firm may remember what happened, but memory is not a governance system.

Before 1 September 2026, firms should test whether their reference process can answer four questions: what happened, was it substantiated, why was it relevant or not relevant to regulatory obligations, and what exactly should be disclosed?

If the answer depends on one person's recollection, the process is not ready.

Managers need more than a briefing note

The FCA guidance also points to reasonable steps for managers. This deserves attention because managers are often the first people to see the warning signs and the last people to describe them in regulatory language.

A line manager may see a pattern of intimidation, exclusion, aggressive messages or retaliatory behaviour. They may treat it as a personality clash, a performance issue or a private matter. Sometimes that is right. Sometimes it is a failure to recognise conduct risk.

Training should therefore be practical. Managers need to know when to escalate, what not to promise, how to avoid informal fixes that bury serious issues, and how to keep a record without turning every conversation into a courtroom transcript. They need to understand that the new rule does not make them investigators of private lives, but it does require judgement when behaviour has a work-related link.

For credit brokers, this matters because many firms run lean. The same person may supervise sales activity, approve financial promotions, handle complaints, review introducer conduct and deal with staff issues. If that person sees culture and compliance as separate worlds, September will expose the weakness.

What firms should do now

The most useful response is a short, disciplined readiness review.

Start with policies. Staff handbooks, disciplinary procedures, conduct rules training, SMCR documentation, certification processes and regulatory reference procedures should be checked against the FCA's latest guidance. The aim is not to paste FCA language into every document. It is to make sure the firm's process can produce sensible, evidenced decisions.

Then look at ownership. HR, compliance and senior management need a shared route for cases that may have regulatory significance. It should be clear who decides whether something may be a conduct rule breach, who assesses FIT implications, who approves reference wording and when legal advice is needed.

Next, check records. Firms do not need to reopen the past simply because the rules are changing. The FCA says they do not need retrospective analysis of past conduct rule decisions or past fitness and propriety assessments. But they do need to be ready for future cases from 1 September. If current record keeping would not support a future decision, fix it now.

Finally, train people in plain English. The message should be sober. Serious bullying, harassment or violence may now be relevant to FCA conduct rules in non-bank firms when linked to work. Fitness and propriety assessments may take account of relevant non-financial misconduct. Regulatory references may need to disclose serious substantiated matters. The firm will not monitor private life as a hobby, but it will not ignore conduct that calls regulatory trust into question.

The compliance lesson is bigger than misconduct

There is a broader lesson here for regulated firms. The FCA is increasingly unwilling to accept formal compliance that leaves real-world behaviour untouched. A policy exists, but nobody uses it. A manager is accountable, but nobody has trained them. A committee signs off culture, but uncomfortable evidence never reaches it. A firm can recite the conduct rules, but cannot explain what it would do if a senior producer behaved badly and generated revenue.

That is where FCA non-financial misconduct becomes a real test. It asks whether a firm can connect human behaviour to regulated responsibility.

For Authorised Compliance Ltd's clients and the firms watching this change, the practical work is not exotic. It is policy review, governance mapping, manager training, evidence standards, reference process design and board-level clarity. It is the kind of work that can be done calmly in advance or badly in a hurry after something has gone wrong.

September is close enough to matter and far enough away to act sensibly. Firms should use the window.

The lesson is simple: culture is not proved by saying the right things when everything is quiet. It is proved by how a regulated firm deals with the behaviour it would rather not have to discuss.

Source note: FCA Non-financial misconduct in financial services; FCA PS25/23; FCA PS26/6; FCA Handbook COCON guidance effective 1 September 2026; FCA Consumer Duty focus areas.

Led by real credit broking experience

I’m Will Hurst, and I bring 20+ years of hands-on experience across credit broking, AR/IAR oversight, lender relationships and regulated finance operations.

Learn more about my practical, FCA-focused approach
July 30, 2026