FCA Compliance for UK Insurers 2026: Complete Guide
- 6 days ago
- 15 min read

FCA compliance for a UK insurer extends across the entire insurance lifecycle, from product design and pricing through distribution, customer communications, claims handling, complaints and post-sale support. The principal FCA framework includes the Principles for Businesses, Consumer Duty, the Insurance Conduct of Business Sourcebook, PROD product governance, SYSC systems and controls, the Senior Managers and Certification Regime, financial crime requirements, operational resilience, complaints and regulatory reporting. Most UK insurers are also prudentially regulated by the PRA, so an effective compliance framework must distinguish FCA conduct requirements from PRA capital, solvency and prudential obligations.
The FCA's 2026 Insurance Regulatory Priorities place particular emphasis on consumer understanding, claims handling and service quality, access to insurance, financial crime and the quality of firms' governance over outsourced arrangements. The regulator is also simplifying parts of the insurance rulebook, but simplification does not remove the obligation to deliver good customer outcomes or maintain effective systems and controls. Boards should therefore treat insurance compliance as an evidence-based operating framework rather than a collection of policies designed primarily for regulatory inspection.
UK insurance compliance requirements at a glance
Regulatory area | What it means for insurers |
FCA Principles | High-level obligations covering integrity, skill, management and control, customers and regulators |
Consumer Duty | Good outcomes for retail customers across products, value, understanding and support |
ICOBS | Insurance sales, disclosures, communications, claims and post-sale conduct |
PROD 4 | Product manufacture, target markets, distribution and product review |
SYSC | Governance, risk management, compliance, controls, outsourcing and record keeping |
SMCR, FIT and COCON | Senior accountability, fitness and propriety, certification and individual Conduct Rules |
Financial promotions | Fair, clear and not misleading marketing and customer communications |
Financial crime | AML where applicable, sanctions, fraud, bribery and corruption controls |
DISP | Complaints handling and Financial Ombudsman Service requirements |
Operational resilience | Important business services, impact tolerances and resilience for firms within scope |
SUP | FCA notifications, regulatory reporting and supervisory requirements |
PRA Rulebook and Solvency UK | Capital, solvency, governance and prudential requirements for PRA-regulated insurers |
The exact rule set depends on the insurer's business. Life insurers, general insurers, pure protection providers, wholesale insurers, Lloyd's businesses and firms operating through complex delegated distribution or claims chains can face materially different detailed requirements. Compliance should therefore begin with a map of permissions, products, customer types, distribution arrangements and the regulatory entities within the group.
ICOBS is the core insurance conduct sourcebook
The Insurance Conduct of Business Sourcebook is the central FCA conduct framework for non-investment insurance. It covers areas including communications, information about the firm and its services, customer demands and needs, product information, cancellation, claims and product-specific requirements. The rules apply differently depending on whether a firm is acting as insurer, intermediary or both, so firms should map the sourcebook to each stage of the customer journey rather than assuming every ICOBS provision applies identically.
Insurers should translate ICOBS into operational controls across quotations, policy documentation, renewals, endorsements, cancellation, claims and customer support. A policy that simply reproduces Handbook wording is not enough if the actual system, call script or delegated administrator works differently. Compliance monitoring should therefore test live journeys and customer files as well as the written framework.
The FCA has simplified some insurance requirements and continues to consult on further changes during 2026. Firms should distinguish changes already finalised from proposals that remain under consultation, because reducing unnecessary prescription does not change the continuing expectations under the Principles and Consumer Duty. Regulatory change governance should identify the effective date of each change and the operational owner responsible for implementing it.
Consumer Duty is now central to insurance compliance
Where it applies, Consumer Duty overlays detailed ICOBS rules with a requirement to deliver good outcomes for retail customers. Insurers need to consider the products and services, price and value, consumer understanding and consumer support outcomes, together with the cross-cutting rules requiring firms to act in good faith, avoid foreseeable harm and enable customers to pursue their financial objectives. The Duty therefore reaches product design, pricing, distribution, communications, claims and servicing rather than sitting in one standalone policy.
The FCA's 2026 Consumer Duty focus areas make clear that the regulator is relying on the Duty as a central supervisory tool and expects firms to evidence outcomes through data. For insurers, useful evidence can include claims acceptance rates, claims complaints, cancellation, renewal behaviour, support waiting times, vulnerable-customer outcomes, product value measures and differences between distribution channels. Boards should be able to explain what those measures show and what the firm changed when evidence indicated poor outcomes.
PROD 4 governs insurance product manufacture and distribution
PROD 4 imposes specific product governance requirements on insurance manufacturers and distributors. Manufacturers need an appropriate product approval process, a clearly identified target market, a distribution strategy consistent with that market and arrangements to review whether the product continues to meet customer needs. Significant adaptations to existing products should receive equivalent governance rather than being treated as ordinary commercial changes.
Product governance should connect underwriting, pricing, claims, distribution and customer-outcome information. If a product produces persistently low claims acceptance, unusually high complaints or adverse outcomes in a particular customer segment, the manufacturer should investigate rather than relying on the fact that the product was approved originally. Distributors also need enough product information to understand the target market and distribute the product appropriately.
The manufacturer and distributor responsibilities are therefore connected. Insurers should have processes for obtaining relevant information from distributors and for providing distributors with the information they need to meet their own obligations. Distribution agreements should support that information flow rather than treating regulatory outcome data as commercially sensitive information that cannot be shared.
Fair value must be evidenced, not asserted
Consumer Duty requires insurers within scope to assess whether products provide fair value. This does not require every insurer to charge the lowest price in the market, but the firm should be able to demonstrate a reasonable relationship between the total price paid and the benefits customers can reasonably expect to receive. Commissions, add-on products, fees, premium finance, exclusions and the expected claims experience can all affect the assessment.
The FCA publishes general insurance value-measures data including claims frequency, acceptance rates, average claims payouts and claims complaints. Firms should use appropriate internal and external information to identify whether their products or customer groups appear to receive weak value and whether action is required. A value assessment signed once each year without meaningful data or challenge is unlikely to provide strong evidence of compliance.
Where distribution chains contain substantial remuneration, manufacturers should understand how that remuneration affects the overall value received by the customer. Distributors should also consider the value of the services they provide rather than assuming that product manufacture sits entirely with the insurer. Governance should identify who is responsible for each assessment and how information is exchanged across the chain.
Home and motor pricing rules remain important
ICOBS 6B contains specific pricing requirements for home and motor insurance. In broad terms, the renewal price offered to an existing consumer cannot exceed the equivalent new business price calculated under the applicable methodology. The rule addresses the historic practice of charging longstanding customers more simply because they remained with the insurer.
Compliance requires more than changing the renewal letter. Pricing engines, channel differences, discounts, manual interventions and product versions need governance capable of determining the appropriate equivalent new business price consistently. The firm should also test whether data or algorithm changes can create unintended outcomes that breach the rule.
Consumer Duty continues to apply alongside the pricing rule. An insurer can comply with the equivalent new business price requirement and still need to assess whether the overall product provides fair value, whether customers understand the price and whether support arrangements create unreasonable barriers. Specific ICOBS compliance and broader outcomes testing should therefore be connected.
Claims handling is a major FCA priority in 2026
ICOBS 8 requires insurers to handle claims promptly and fairly, provide reasonable guidance, avoid unreasonable rejection and settle claims promptly once settlement terms are agreed. The FCA's 2026 Insurance Regulatory Priorities elevate claims handling and service quality as explicit supervisory concerns. This means claims data should be treated as core conduct risk information rather than simply an operational performance metric.
Insurers should monitor decline rates, partial settlements, complaints, repeat information requests, settlement times, outsourced adjuster performance and outcomes for vulnerable customers. Where claims are automated or supported by AI, management should understand how the model affects triage, fraud detection, valuation and rejection decisions. Responsibility remains with the regulated firm even where technology or third-party providers perform significant parts of the process.
The strongest compliance approach combines rule testing with outcome testing. A process may meet internal service-level targets but still create poor outcomes if customers are repeatedly asked for unnecessary evidence or cannot understand why a claim has been rejected. File reviews should therefore test the quality and fairness of decisions, not only whether each procedural step was completed.
Consumer understanding applies before and after sale
Insurance products can contain exclusions, excesses, conditions and limitations that materially affect the value of the cover. Consumer Duty requires firms to support customer understanding, which means important information should be presented at a time and in a form that helps customers make informed decisions. Technical disclosure is not enough where the overall communication creates a misleading or incomplete impression.
Firms should test whether customers understand the principal features and limitations of the product, particularly where the customer journey is digital or highly automated. Complaints, customer research, contact-centre questions, claims disputes and user testing can all provide evidence about where understanding is weak. Where misunderstanding is systematic, the insurer should improve the communication or product journey rather than treating every incident as an individual customer error.
The same principle applies after sale. Renewal notices, policy changes, claims communications and cancellation information should remain clear and actionable. Customers should not need specialist insurance knowledge to understand what they need to do to maintain cover or make a valid claim.
Financial promotions must be fair, clear and not misleading
Insurance marketing, websites, social media, comparison information and other customer communications must comply with applicable ICOBS requirements and the wider FCA Principles. Firms should assess the overall impression created by the communication, including headline pricing, key benefits and material exclusions, rather than assuming a small-print disclaimer cures an otherwise misleading message. Promotional governance should cover both centrally produced material and content created by distributors where the insurer is responsible for the outcome.
Approval controls should include version management and periodic review. Rates, product terms and promotional claims change, and old material can remain live on affiliate sites or archived customer journeys long after the underlying product has changed. Compliance monitoring should therefore include live-market sampling and not rely only on the marketing team's approval records.
Consumer Duty adds a further dimension by asking whether communications support understanding. The firm should consider the needs of the target market, including customers with characteristics of vulnerability, and adapt communications where necessary. Good financial promotion compliance is therefore both a legal review and an outcomes exercise.
Vulnerable customers require embedded support
Insurance firms frequently deal with customers at moments of acute vulnerability, including illness, bereavement, accident, unemployment or significant property loss. The FCA expects firms to understand the characteristics of vulnerability within their customer base and ensure products, communications and support can respond appropriately. The appropriate approach depends on the business, but staff should be able to recognise relevant indicators and adjust the service where necessary.
Vulnerability should not sit in a separate policy disconnected from claims, collections, renewals and complaints. Management information should show whether vulnerable customers experience materially worse outcomes and whether reasonable support is actually available when needed. Sensitive personal information should also be collected and used proportionately under data protection requirements.
Training needs to be role-specific. Claims staff, call-centre agents, underwriters and complaints handlers encounter different vulnerability scenarios and need practical guidance relevant to the decisions they make. Quality assurance should test whether staff apply that guidance consistently rather than merely confirming that annual training was completed.
SMCR makes senior management accountable
Most authorised insurers are subject to the Senior Managers and Certification Regime. Senior Managers must have clear responsibilities, satisfy fitness and propriety requirements and take reasonable steps to ensure the areas for which they are responsible are controlled effectively. Statements of Responsibilities and governance maps should reflect how the business operates in practice rather than becoming historical documents that no longer match reporting lines.
The Certification Regime requires firms to assess relevant individuals who can cause significant harm and certify their fitness and propriety at least annually. The assessment should use evidence such as competence, conduct, complaints, performance and regulatory concerns rather than operate as an automatic HR renewal. Changes to the SMCR framework made during 2026 should also be reflected in approval and governance processes where applicable.
COCON Conduct Rules apply directly to relevant individuals and include integrity, skill, care and diligence, cooperation with regulators and appropriate customer-outcome standards. Firms need role-specific Conduct Rules training and processes for identifying, investigating and reporting breaches where required. The regime therefore links personal accountability directly to the effectiveness of the firm's wider compliance framework.
SYSC requires effective governance and control
SYSC provides much of the organisational framework behind insurance compliance, including governance, compliance, risk management, outsourcing, internal controls and record keeping. The exact provisions depend on the firm's regulatory status, but the principle is consistent: the insurer should be able to demonstrate that responsibilities are clear and that its systems are adequate for the scale and complexity of the business.
Compliance monitoring should be risk-based. An insurer with material delegated underwriting, third-party claims administrators and multiple distribution channels should test those arrangements more intensively than a simple direct business with limited outsourcing. Findings should identify root causes and be tracked through remediation rather than closed when a policy has been rewritten.
Boards should receive management information that allows them to challenge the business. Product value, claims, complaints, customer support, operational incidents, financial crime and outsourced performance should be considered together where they reveal connected risks. Governance is strongest when compliance information helps management make decisions rather than merely recording that regulatory meetings occurred.
Outsourcing does not outsource regulatory responsibility
Insurers frequently use managing general agents, coverholders, third-party administrators, loss adjusters, cloud providers and specialist technology vendors. Outsourcing can be efficient and appropriate, but the insurer remains responsible for meeting the regulatory obligations that apply to it. Due diligence should therefore cover regulatory capability, resilience, data, security, financial stability and the provider's ability to support customer outcomes.
Ongoing oversight should examine actual performance. Service-level agreements alone do not show whether customers are treated fairly, claims are handled appropriately or vulnerable customers receive effective support. The FCA's 2026 insurance priorities specifically identify outsourced claims processes as an area of supervisory interest.
Exit planning also matters for material arrangements. The firm should understand how critical services could be transferred or brought back in-house if a provider fails or the relationship ends. Contracts should support regulatory access, audit, information rights and appropriate transition arrangements.
Operational resilience applies to insurers in scope
PRA-regulated insurers and relevant FCA firms are within the formal operational resilience framework and were required by 31 March 2025 to be able to remain within impact tolerances for important business services. The FCA's March 2026 operational resilience observations confirm that the focus is now on maintaining, testing and improving the framework rather than completing the original implementation exercise.
Insurers should identify important services from the customer or market perspective, map the people, processes, technology, facilities and third parties supporting them, and conduct severe but plausible scenario testing. Claims, policy servicing and payment of benefits can all become important business services depending on the insurer's model. Remediation should be prioritised where testing shows that an impact tolerance cannot be met reliably.
Operational resilience should connect with outsourcing, cyber security, business continuity and change management. A technology migration, acquisition or new claims platform can alter important dependencies materially, so the resilience map should be updated when the business changes. Board oversight should focus on whether vulnerabilities are understood and being reduced.
Financial crime controls must reflect the insurance business
Insurance firms are an important part of the UK's financial crime defence, and the FCA published a dedicated insurance financial crime controls review in June 2026. The review focused on the design of financial crime frameworks and reinforces the need for risk assessments, governance and controls that reflect the particular products, customers, jurisdictions and distribution channels of the insurer. Firms should not assume that generic banking AML controls can simply be transplanted into an insurance environment.
The exact Money Laundering Regulations scope depends on the firm's activities, with life business and certain other activities subject to different requirements from many general insurance products. Sanctions, fraud, bribery, corruption and other financial crime risks can still be relevant even where a particular product does not fall within the full MLR regime. The compliance framework should therefore map legal obligations and broader FCA systems-and-controls expectations separately.
Insurers should also consider claims fraud, intermediary fraud and sanctions exposure throughout the customer lifecycle. Screening at onboarding is not sufficient where beneficial ownership changes, claims counterparties emerge or payments create new exposure. Management information should help senior leadership understand where the firm's financial crime risks are increasing and whether controls remain effective.
Complaints and redress are part of the control framework
DISP requires firms to operate effective complaint-handling processes and provide eligible complainants with access to the Financial Ombudsman Service where applicable. Complaints can reveal recurring weaknesses in sales, policy wording, claims, pricing or customer support and should therefore feed into product governance and Consumer Duty monitoring. A complaints process that closes individual cases without analysing root causes misses a significant source of regulatory intelligence.
Firms should monitor complaint themes, uphold rates, repeat issues and outcomes across customer groups and distribution channels. Where redress is required, the methodology should be fair, consistently applied and supported by evidence. Material systemic issues may also create notification obligations or require broader customer remediation.
The FCA's increasing emphasis on identifying and rectifying harm means firms should not wait for customers to complain where internal evidence shows that a wider population may have been affected. Governance should determine whether proactive review or remediation is required and document the basis for the decision.
PRA compliance sits alongside FCA compliance
Most UK insurers are dual regulated, with the PRA responsible for prudential safety and soundness and the FCA responsible principally for conduct and market integrity. Solvency UK now provides the domestic prudential framework for relevant insurers, covering capital, technical provisions, governance, risk management and reporting. The firm's FCA and PRA frameworks should therefore be coordinated even though the regulators have distinct statutory objectives.
Insurers within Solvency UK maintain an Own Risk and Solvency Assessment and need appropriate systems of governance and financial resources. The PRA also focuses on areas such as funded reinsurance, liquidity, operational resilience and climate-related risk, while the precise obligations vary according to business model. Boards should avoid running conduct and prudential risk as entirely separate governance conversations where the same business decision affects both.
BCC's dedicated PRA compliance article in this series explains the wider prudential framework for banks and insurers. For an insurer, the practical objective is to maintain one coherent governance system capable of evidencing compliance with both FCA customer-outcome requirements and PRA prudential expectations.
Regulatory reporting and FCA notifications
Insurers are subject to regulatory reporting under FCA and PRA frameworks, with requirements depending on permissions, products and prudential status. Firms need data ownership, review and sign-off arrangements that ensure returns are complete, accurate and submitted on time. Differences between regulatory data and internal management information can indicate wider governance problems even where the return is eventually corrected.
SUP also creates event-driven notification requirements. Significant breaches, changes affecting threshold conditions, senior management matters and other specified events may need to be disclosed without waiting for the next periodic return. Compliance calendars should therefore distinguish scheduled reporting from issues that require judgement and escalation when they arise.
Regulatory reporting should be included within compliance monitoring and internal assurance. Firms should be able to trace material figures back to source systems and explain adjustments, methodologies and data ownership. The objective is not simply timely filing but reliable regulatory information.
A practical FCA compliance framework for an insurer
A strong framework begins with a regulatory obligations map based on the insurer's permissions, products, customers and distribution model. Each material obligation should then connect to a policy, operational process, control, responsible owner and source of evidence. This prevents compliance becoming a library of documents that cannot demonstrate how the business actually meets the rules.
The second layer is risk-based monitoring across sales, product governance, value, communications, claims, complaints, vulnerable customers, financial crime, outsourcing and operational resilience. Testing should examine both rule compliance and customer outcomes, with more intensive review where previous findings or data indicate higher risk. Findings should be prioritised, owned and retested after remediation.
The final layer is board oversight. Senior management should receive concise information that explains what is working, where customers or the firm are exposed and what decisions are required. A mature framework allows the insurer to identify and correct weaknesses before they become regulatory findings or customer remediation programmes.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting supports FCA-regulated firms with regulatory gap assessments, compliance audits, Consumer Duty, financial crime, governance, regulatory reporting and remediation. For insurers, we can assess the control framework against the firm's actual products, customer journeys and distribution arrangements, including ICOBS, PROD, Consumer Duty, SMCR, SYSC, claims, complaints, financial promotions, financial crime and operational resilience where applicable. The output can be structured as a prioritised remediation programme with clear regulatory rationale and evidence requirements.
We can also support firms preparing for FCA supervisory engagement or responding to identified compliance weaknesses. This can include reviewing policies and operational evidence, testing customer files and outcomes, strengthening board reporting and helping management demonstrate that remedial actions have addressed root causes. Where a matter also involves PRA prudential requirements, the regulatory workstream can be coordinated so that conduct and prudential obligations are treated consistently. To discuss an insurance compliance review, Consumer Duty assessment, regulatory remediation project or wider FCA compliance requirement, contact Buckingham Capital Consulting.
Frequently asked questions
What FCA rules apply to UK insurers?
The principal FCA framework can include the Principles for Businesses, Consumer Duty, ICOBS, PROD, SYSC, SMCR and COCON, financial promotions, DISP, SUP, financial crime requirements and operational resilience where the firm is in scope. The exact application depends on the insurer's products, customers and activities, so the framework should be mapped to the specific business. PRA-regulated insurers also need to comply with the PRA Rulebook and Solvency UK requirements.
Does Consumer Duty apply to insurance companies?
Yes, where the relevant product or service is within the Duty's scope. Insurers need to consider product design, target markets, fair value, customer understanding and support and should monitor whether customers actually receive good outcomes. The Duty operates alongside ICOBS and PROD rather than replacing those sourcebooks.
What does the FCA expect from insurance claims handling?
The FCA expects claims to be handled promptly and fairly, with reasonable guidance, fair decisions and timely settlement. In 2026, claims handling and service quality are explicit FCA supervisory priorities, including oversight of outsourced claims arrangements. Firms should therefore monitor both operational performance and the quality of customer outcomes.
Are insurers subject to SMCR?
Most authorised insurers are within the Senior Managers and Certification Regime, although the precise requirements depend on the firm's regulatory classification. Senior responsibilities, fitness and propriety, certification and Conduct Rules should be built into the governance framework and supported by evidence. The firm should also keep its arrangements aligned with 2026 changes to the regime where applicable.
Do UK insurers need both FCA and PRA compliance?
Most insurers carrying on regulated insurance business in the UK are dual regulated by the FCA and PRA. The FCA focuses principally on conduct, customer outcomes and market integrity, while the PRA focuses on prudential safety and soundness, including Solvency UK. A strong governance framework coordinates both sets of obligations without confusing their different purposes.
#FCA Compliance for UK Insurers 2026: Complete Guide

