Non-financial misconduct is now a conduct rule, not an HR matter.

Updated: Aug 25
From 1 September 2026, serious bullying, harassment or violence towards a colleague is a breach of the FCA’s conduct rules, not a matter that stays inside HR. The rule reaches around 37,000 firms that were not fully in scope before. This piece sets out what the rule actually says, what it means in practice, and where a regulated firm’s real exposure sits, which is earlier than the allegation and lower in the building than most implementation plans reach.
What the rule actually says
For years, non-financial misconduct in a non-bank firm was only in scope if it formed part of the firm’s regulated financial activity. That changes. In Policy Statement PS25/23 (December 2025), following consultation in CP25/18 (July 2025), the FCA confirmed a new conduct rule and supporting guidance that come into force on 1 September 2026. Serious bullying, harassment and violence towards colleagues now breach the Individual Conduct Rules, and the scope in around 37,000 non-bank firms is brought into line with the scope that already applied to banks (FCA, PS25/23).
Conduct that was an employment-relations problem is now, in a regulated firm, also a regulatory one. It goes on the record, it feeds the fitness and propriety test, and it can follow the individual between firms. The rule is not retrospective: conduct before 1 September 2026 is judged under the old scope. But from that date, the question on every serious people-problem is no longer only “how do we resolve this”, it is “is this a conduct breach, is it reportable, and what does it mean for this person’s certification”.
What now counts as non-financial misconduct
The test echoes the harassment language of the Equality Act, but it is deliberately wider. Conduct is capable of being in scope where it is serious and either has the purpose or the effect of violating a colleague’s dignity, or creates an intimidating, hostile, degrading, humiliating or offensive environment, or is violent towards them. Unlike harassment under the Equality Act, the conduct does not have to relate to a protected characteristic, so the range of behaviour that can count is potentially wider than discrimination law.
Two details carry more weight than they first appear. Purpose counts as much as effect: the FCA’s guidance gives the example of a hostile message intercepted before it reaches its target, where no one was harmed and the conduct is still capable of being a breach. And there must be a work-related link: purely private conduct sits outside the conduct rules, but it does not sit outside fitness and propriety. Behaviour in someone’s private life, including on social media, can still bear on whether they are fit and proper to hold their role. The two tests operate separately, and the second net is the wider one.
What it means in practice
Four things move from good practice to evidenced control:
Fitness and propriety. Assessments, at hire and at annual certification, can and should take relevant non-financial misconduct into account wherever it occurred, including private life and social media, with care over unproven allegations (FCA, PS25/23).
Regulatory references. A conduct breach for bullying or harassment goes on the record and follows the individual, which changes the weight of every disciplinary decision your panels make.
The manager's duty. Managers must take reasonable steps to prevent misconduct and to respond when it surfaces. The FCA has been precise: a manager is not responsible for conduct they could not reasonably have known about or lacked the authority to act on. That places the exposure exactly where knowledge and authority sit, so document both.
Breach reporting. Breach reporting, disciplinary process and regulatory notification now have to speak to each other.
None of this is unfamiliar. It is the same disciplinary decision your panels already make, now with a regulator reading over their shoulder.
The FCA also drew the boundaries deliberately. Firms are not expected to reopen past conduct decisions, revisit old assessments, monitor employees’ private lives, investigate trivial or implausible allegations, or cut across privacy and employment law. The duty is to manage the risk properly from here, not to police everything retrospectively.
Where your real exposure actually sits
Everything above treats misconduct at the point it surfaces: the allegation, the investigation, the panel. That is necessary, and it is late. A conduct breach does not begin as a compliance event. It begins as friction: a pattern in one team, a grievance that settles nothing, a conflict everyone can see and nobody owns. Workplace conflict already costs UK employers around £28.5bn a year (Acas, on 2018/19 data). From September, in a regulated firm, the same unresolved conflict carries a second price: reportable breaches, marked references, and the regulator’s stated interest in how you handled it.
That friction does not sit evenly across the firm. It finds one door first, and it is usually the same door: the manager or team head expected to stay composed and sort it, who was trained for the technical job and never trained to carry any of this. Manager engagement fell to 22% worldwide in 2025, the steepest drop of any layer (Gallup, State of the Global Workplace 2026), and 82% of UK managers entered the role with no formal management training (CMI, 2023). So the layer now expected to spot misconduct early, take reasonable steps, and evidence that it did, is the layer given the least structure to do it. For the new rule, that is not a culture observation. It is where your exposure concentrates, and where most implementation plans are not looking.
The reasonable steps to take before 1 September
Six weeks is enough if the work starts now, and the same discipline continues every year after.
A gap analysis. Map your current policies against the new rule and guidance: staff handbook, code of conduct, speak-up guidelines, disciplinary procedures. The seriousness threshold and the work-versus-private boundary are the two places most policies are silent.
Update the documents that have to move. Staff policies, conduct breach reporting, fitness and propriety frameworks, and regulatory reference procedures.
Train the people who will hold the rule. Not a firm-wide e-learning module, but targeted work for the groups who carry the risk: managers on their reasonable-steps duty, investigators and conduct committees on the new tests, and certification staff on what now counts.
Stress-test before it is live. Run one realistic scenario end to end: an allegation against a senior manager, a complaint about conduct at a firm event, a screenshot from a personal account. Fix what stalls in August, not in a live case.
After 1 September the rhythm is annual (assessments and certification weighing misconduct, training refreshed), quarterly (management information to the board on grievance themes, speak-up volumes and outcomes by team), and continuous (breach determinations and references kept consistent, enforcement outcomes fed back). The firms that will find this rule easy are the ones that resolve conflict while it is still conflict. Early identification and resolution just became a compliance control. The granular version of the work to do before the date, the 10 checks a board should be able to evidence and what the evidence looks like for each, is set out separately: the 10 checks to run before 1 September.
A note on scope
This is a financial-services regime. It applies to FSMA firms with the relevant permissions and the staff subject to the conduct rules. For law firms and other employers outside financial services, the parallel duty is the Health and Safety Executive’s: work-related stress and psychosocial risk managed so far as is reasonably practicable, and evidenced. The direction of travel is the same across both regulators, but the language is not interchangeable. If you are outside financial services, the HSE duty is the one to evidence, and I have set that out separately in the reasonable-steps piece.
The structural point
I spent 25 years as a barrister, ranked a Leading Junior in The Legal 500, and I co-founded a set of chambers. I carried other people’s highest-stakes conflict for a living, and I helped run the professional-services partnership that had to hold the people doing it. Conflict is structural before it is personal. The new rule will land hardest on firms that treat it as a policy problem, and easiest on those that fix where conflict is produced, in the manager layer, before it becomes a breach.
You survey the building every year. Nobody inspects the stone where the pressures meet.
If you run a regulated firm and you could not, today, put your hand on the evidence that your manager layer can spot and manage misconduct early, that is the gap worth closing before 1 September. If you want to test that in the next hour rather than the next quarter, run the readiness checklist first. Book a call.
This article is general information about the FCA’s non-financial misconduct rules (COCON 1.1.7FR, CP25/18 and PS25/23). It is not legal advice. Sarah Fearon is a former barrister, and Fearon Advisory provides structural and organisational advisory, not legal services.
Frequently asked questions
When do the FCA’s non-financial misconduct rules come into force?
On 1 September 2026. The FCA confirmed the new conduct rule and guidance in Policy Statement PS25/23 (December 2025), following consultation in CP25/18. Conduct before that date is judged under the previous scope.
Which firms does the rule apply to?
It extends the conduct-rules scope to around 37,000 non-bank FCA-regulated firms, bringing them into line with the scope that already applied to banks. It covers staff subject to the conduct rules in FSMA firms with the relevant permissions.
What counts as non-financial misconduct under the rule?
Serious bullying, harassment or violence towards a colleague. The test borrows the Equality Act’s language of purpose or effect, violating dignity or creating an intimidating, hostile, degrading, humiliating or offensive environment, but it is wider: unlike Equality Act harassment, the conduct does not have to relate to a protected characteristic.
Is this the same as the HSE’s duty on work-related stress?
No. This is a financial-services regime. For law firms and other non-FS employers, the relevant duty is the HSE’s requirement to manage psychosocial risk so far as is reasonably practicable. Two regulators, moving the same direction, but the tests are separate.
Read your own firm next
The Manager-Layer Fracture Check is six checks and ten minutes. It scores whether the layer absorbing your firm's conflict has any structure holding it. Get the Fracture Check.
When you want the layer examined properly, the Keystone Briefing is 90 minutes with the person who owns the risk, and the Fracture Point Readout lands within 48 hours. Book a consultation.
For everyone outside the FCA's reach: work-related stress is already your legal duty.
The structural picture behind the rule: manager layer burnout.
The rule at length, across six short emails: the September Readiness Briefing.

