FCA Compliance UK 2026: A Practical Guide for Regulated Firms
- 7 days ago
- 10 min read

For a CEO or founder, FCA compliance should answer one question: can you show that the business is operating within its permissions, controlling its material risks and treating customers as the rules require? If the answer depends on a compliance manual nobody uses, the framework is not working.
The best regulated firms do not treat compliance as a separate department that reviews documents after decisions have been made. Compliance is built into product launches, customer onboarding, financial promotions, complaints, outsourcing, financial crime, board reporting and regulatory change. The result is not more bureaucracy. It is fewer surprises, better evidence and faster decisions when the FCA asks a question.
There is no single FCA compliance checklist that applies to every firm. A payment institution, investment firm, mortgage broker, consumer credit business and insurance intermediary have different detailed rules. This guide focuses on the practical controls that senior management should expect to see across most FCA-regulated firms, with sector-specific requirements added where relevant.
What does FCA compliance mean in practice?
At a minimum, an FCA-regulated firm should know its permissions, the rules that apply to its activities, who owns each material obligation, what control is used to meet it and what evidence proves the control operated. That sounds simple, but it is the difference between a live compliance framework and a library of policies.
The FCA's systems and controls rules require firms within scope to establish, implement and maintain adequate policies and procedures to ensure compliance and counter financial crime risk. The appropriate framework should reflect the nature, scale and complexity of the business rather than copying the structure of a much larger institution.
The CEO view: what should be in place?
A current map of the firm's regulatory permissions and material obligations.
Clear senior management ownership for compliance, financial crime and key regulated risks.
A risk-based compliance monitoring programme.
A current business-wide financial crime risk assessment.
Customer due diligence, sanctions and transaction monitoring controls where relevant.
Consumer Duty governance for firms and activities within scope.
Complaints handling and root-cause analysis.
Controlled financial promotions and customer communications.
Regulatory reporting and notification processes.
Prudential monitoring where capital or liquidity rules apply.
Outsourcing and third-party oversight.
Operational resilience and incident management.
A breach and remediation process with clear ownership and deadlines.
Board management information that explains risk rather than just activity.
1. Start with permissions and the regulatory perimeter
One of the most expensive compliance failures is discovering that the firm is carrying on an activity outside its permission. Products evolve, new revenue lines appear, partnerships change and companies expand overseas. Each material change should therefore include a regulatory perimeter check before launch.
Compliance should ask whether the new activity is already within the firm's permission, whether a variation is required, whether another regulated entity is performing the activity and whether any notification is needed. This should sit inside product and change governance, not be an ad hoc legal question raised after contracts have been signed.
2. Make responsibility obvious
Senior management should be able to explain who owns each material regulatory risk. Where the Senior Managers and Certification Regime applies, there are formal accountability requirements. Even outside that regime, unclear ownership is a common source of control failure.
The board should not receive a list of regulatory obligations without knowing who is responsible for them. Every material compliance issue should have an owner, a decision route and an escalation point. If three executives assume someone else owns a control, nobody owns it.
3. Build a compliance monitoring programme that tests the real risks
A compliance monitoring programme should not be a calendar of policy review dates. It should test whether important controls actually work. Higher-risk activities should receive deeper or more frequent testing, while low-risk areas can be reviewed proportionately.
A useful review sets out the requirement, sample, testing method, findings, severity, root cause, action owner and deadline. Issues should be closed only when there is evidence that the remedial action has been implemented. Management promises are not closure evidence.
4. Treat financial crime as an operating system
For firms exposed to money laundering, terrorist financing, sanctions, fraud or other financial crime, the business-wide risk assessment should drive the control framework. It should identify the risks created by products, customers, countries, distribution channels and transaction behaviour and then show how those risks are mitigated.
The operating controls can include KYC and KYB, beneficial ownership, customer risk scoring, enhanced due diligence, sanctions screening, transaction monitoring, suspicious activity escalation, record keeping, staff training and management information. The important point is that customer files and operational evidence should show the policy working in practice.
5. Consumer Duty needs evidence, not slogans
For firms and activities within scope of the Consumer Duty, the FCA expects firms to deliver good outcomes across products and services, price and value, consumer understanding and consumer support. By 2026, the question is no longer whether a firm has completed its implementation project. It is whether management can evidence customer outcomes and act when they deteriorate.
Useful management information might include complaints, cancellations, failed transactions, support response times, product usage, vulnerable customer outcomes, fee data and customer testing. The board should be able to see what the information means, where customers may be experiencing harm and what the firm is doing about it.
6. Complaints are compliance intelligence
A complaints process should do more than produce final response letters within the required timetable. Complaints can identify weaknesses in products, communications, customer support, affordability, payment execution and other controls. The firm should therefore analyse themes and root causes as well as individual outcomes.
Senior management should see trends, upheld rates, repeat issues, vulnerable customer themes, Financial Ombudsman outcomes where relevant and the status of remediation. If the same complaint appears every quarter, the problem is no longer the individual complaint. It is the underlying process.
7. Financial promotions and customer communications
Websites, advertising, social media, onboarding journeys, sales material and customer notices can all create regulatory risk. The approval process should make sure communications are fair, clear and appropriate for the target audience and comply with the sector-specific rules that apply to the product.
For a fast-moving business, the process should also be practical. Marketing needs a clear route to approval, version control and a standard for when a change is material enough to require fresh review. Compliance should not become a bottleneck, but neither should regulated claims go live because nobody owns the approval process.
8. Regulatory reporting should reconcile
Regulatory returns should be prepared from controlled source data and reviewed before submission. The numbers should reconcile with the firm's underlying books, customer data or regulatory calculations. A firm that discovers inconsistencies only when the FCA asks a question has weak reporting governance.
There should also be a process for event-driven notifications. Material breaches, financial difficulties, changes in control, significant incidents, senior management changes and other events can trigger regulatory notification requirements depending on the firm's regime. Staff need to know when to escalate an issue for regulatory assessment.
9. Outsourcing does not outsource responsibility
Most regulated firms rely on third parties for cloud infrastructure, payment processing, screening, customer support, compliance systems and other important services. The FCA does not treat outsourcing as a transfer of responsibility. The regulated firm remains accountable for the service it provides to customers.
Material providers should be subject to proportionate due diligence, contracts, service monitoring, incident escalation and exit planning. The board should know which third parties create the greatest operational or regulatory dependency. A vendor list is not an outsourcing framework.
10. Operational resilience must be tested
For firms within scope of the FCA operational resilience rules, the March 2025 implementation milestone has passed. In 2026, firms should be able to show that important business services have been identified, impact tolerances have been set where required, testing is taking place and lessons from disruption lead to improvements.
For other firms, business continuity and incident management remain essential even where the detailed operational resilience framework does not apply in the same way. Cyber events, outages, loss of a critical provider or inability to access customer records can rapidly become regulatory issues.
11. Prudential requirements need forward-looking monitoring
If the firm has regulatory capital, liquidity or own-funds requirements, management should know the current level, headroom and forecast position. Monitoring only at the point a regulatory return is due is too late. A strong framework sets warning thresholds so management can act before a breach occurs.
The calculation is sector-specific. Payment institutions, investment firms, mortgage and insurance businesses do not all use the same prudential rules. The compliance plan should therefore reflect the firm's actual permissions and sourcebook.
12. Payment and e-money firms: CASS 15 is now live
For payment and e-money firms, safeguarding is one of the most important 2026 compliance developments. The FCA's CASS 15 supplementary safeguarding regime came into force on 7 May 2026. It applies to safeguarding institutions that receive or hold relevant funds, including authorised payment institutions and electronic money institutions, and to SPIs that elect to safeguard.
The framework strengthens governance, third-party due diligence, books and records, safeguarding reconciliations, treatment of discrepancies and unidentified funds, resolution information, reporting and assurance. For affected firms, the board should be asking a direct question: can we prove every day how much we should be safeguarding, where the money is and whether any shortfall exists?
13. Keep policies aligned with the business
Policies should describe the business that exists today. When products, systems, suppliers or regulations change, the relevant policies and procedures need to change as well. A policy that says the firm performs a control one way when the operations team performs it another way creates false evidence and unnecessary regulatory risk.
This is why policy review should be linked to business change and incidents, not only an annual calendar. A material payment flow change, new onboarding provider or new country can require immediate updates to multiple policies and controls.
14. Make the board compliance report useful
A good board report should answer: what changed, what failed, what is getting worse, what customer harm may exist, what is overdue and what decision does management need to make? It should not be a twenty-page description of regulatory news.
For many firms, the core dashboard will cover compliance monitoring findings, breaches, complaints, Consumer Duty outcomes, financial crime, regulatory reporting, prudential headroom, safeguarding where relevant, outsourcing, incidents and overdue remediation. Trend and exception reporting is more useful than large amounts of static data.
15. Manage regulatory change without chasing every consultation
Regulatory change needs a disciplined process. The firm should identify changes that actually affect its permissions and products, assess the impact, assign an owner and track implementation. It does not need to turn every FCA publication into a project.
The FCA's 2026/27 work programme and the Regulatory Initiatives Grid provide useful forward visibility, but firms should filter the pipeline according to relevance. The objective is to avoid both extremes: missing a material change and overwhelming the business with regulatory developments that do not apply.
A practical FCA compliance calendar
Monthly
Review breaches, incidents and complaints trends.
Check overdue compliance actions and remediation.
Review financial crime and sanctions management information where relevant.
Confirm regulatory reporting deadlines for the next period.
Review prudential or safeguarding position where applicable.
Escalate material changes in products, ownership, outsourcing or financial position.
Quarterly
Complete planned compliance monitoring reviews.
Review high-risk outsourcing and third-party issues.
Refresh board compliance management information.
Review Consumer Duty outcomes where applicable.
Assess material regulatory changes and implementation status.
Annually
Refresh the compliance risk assessment and monitoring plan.
Review the business-wide financial crime risk assessment where applicable.
Review core policies against the current operating model.
Complete required fitness, propriety, training or certification processes.
Review regulatory permissions against current products and future plans.
Assess whether compliance resources remain proportionate to the size and complexity of the business.
When should you use an external FCA compliance consultant?
External support is most valuable where the firm needs specialist expertise, independent testing or more senior regulatory judgement than it can justify employing full-time. Typical uses include authorisation, compliance monitoring, regulatory reviews, remediation, Consumer Duty, financial crime, safeguarding, change-in-control work and support during FCA engagement.
Outsourcing the work does not outsource responsibility. Senior management should understand the advice, approve material decisions and retain ownership of the regulated business. The best model is often a small capable internal team supported by specialist external expertise where the risk or complexity justifies it.
Common FCA compliance failures
The firm owns policies but cannot evidence the controls operating.
Products are launched without checking whether they fit the firm's permissions.
The board receives data but no clear assessment of risk or customer outcomes.
Compliance monitoring findings stay open for months without effective escalation.
Financial crime controls do not change as the business expands into new markets.
Regulatory returns do not reconcile with source data.
Complaints are handled individually but root causes are ignored.
Critical suppliers are not subject to meaningful ongoing oversight.
Capital or safeguarding problems are identified only at reporting time.
Regulatory change is either ignored or turned into unnecessary work without prioritisation.
Frequently asked questions
Does every FCA-regulated firm need the same compliance framework?
No. The detailed requirements depend on the firm's permissions, sector, products, customers and size. A proportionate framework should focus on the material obligations and risks that actually apply to the business.
Do I need a full-time compliance officer?
Not every firm needs the same staffing model. The FCA expects adequate resources and clear responsibility for compliance. Smaller firms can use proportionate internal and outsourced arrangements, but senior management remains responsible and the people performing compliance work need sufficient competence, authority and time.
What is a compliance monitoring programme?
It is the structured process used to test whether regulatory controls are working. A good programme is risk-based, documents the testing performed, records findings and tracks remediation to evidence-based closure. It should test live operations rather than only reviewing whether policies exist.
How often should FCA compliance be reviewed?
There is no single frequency for every obligation. Some controls operate daily or monthly, while others can be reviewed quarterly or annually. The monitoring plan should reflect risk, regulatory requirements, business change and previous findings.
What should be reported to the board?
The board should receive material breaches, compliance monitoring findings, complaints and customer outcomes, financial crime information, regulatory reporting issues, prudential or safeguarding risks, outsourcing and operational incidents, regulatory change and overdue remediation. The report should highlight decisions and exceptions, not simply list activity.
Can FCA compliance be outsourced?
Yes, many compliance activities can be supported or performed by external specialists, subject to the requirements applicable to the firm. Responsibility remains with the regulated firm and its senior management. The external arrangement therefore needs clear scope, oversight and escalation.
What are the main FCA compliance priorities in 2026?
The answer varies by sector, but material themes include Consumer Duty evidence, financial crime, operational resilience, regulatory reporting, governance and accountability, and for payment and e-money firms the new CASS 15 safeguarding regime. Firms should prioritise according to their own risk assessment rather than copying a generic market list.
What happens if we identify an FCA breach?
The firm should assess the issue promptly, stop or contain continuing harm, determine the cause and impact, record the decision, implement remediation and consider whether notification to the FCA or another authority is required. The response should be proportionate but documented.
How do I know whether our compliance framework is good enough?
A useful test is whether an independent reviewer can select a material obligation and trace it from the rule to the responsible person, operating control, evidence, monitoring and remediation. If that chain breaks, the framework is likely relying too heavily on policy rather than demonstrable control.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting has advised FCA-regulated and payments businesses since 2013. We support firms with ongoing regulatory advice, compliance monitoring, governance, financial crime frameworks, Consumer Duty, regulatory reporting, safeguarding, regulatory reviews and remediation, as well as FCA authorisation and change projects.
Our approach is practical: identify the obligations that matter, turn them into operating controls, test whether those controls work and give senior management clear evidence of where risk sits. Firms can use us for an ongoing compliance function or for targeted projects where specialist regulatory expertise is required. See our FCA Reviews and Remediation service or contact Buckingham Capital Consulting to discuss ongoing FCA compliance support.

