top of page

Non-financial misconduct: the 10 checks a board should be able to evidence

Writer: Sarah Fearon
Sarah Fearon
Aug 8
8 min read

Updated: Sep 2

Since 1 September 2026, serious bullying, harassment or violence towards a colleague can be a breach of the FCA's Individual Conduct Rules. COCON 1.1.7FR brings that conduct within the scope of the conduct rules in non-banking firms. Under COCON 4.3.3G it breaches Individual Conduct Rule 1 or Rule 2 where it also involves a lack of integrity, or a failure to act with due skill, care and diligence. Banks were already covered. In the FCA's own words, on 1 September 2026 "the same rules will be extended to around 37,000 other regulated firms, increasing consistency across financial services". Below are the ten checks a board should be able to evidence, and what the evidence looks like for each.


What changed on 1 September


The FCA confirmed the rules on 2 July 2025, publishing CP25/18 on the supporting guidance the same day, and finalised that guidance in PS25/23 on 12 December 2025. Conduct before 1 September is judged under the previous scope; conduct after it is a conduct-rule matter, not an HR matter. From the same date, non-financial misconduct forms part of fitness and propriety assessments. The reference rules did not change on 1 September: firms have had to disclose conduct rule breaches in regulatory references since SYSC 22 came into force on 7 March 2017. What changed is what counts as a breach, so findings that would once have stayed in the HR file now travel. Under SYSC 22.2.1R the next regulated employer must take reasonable steps to obtain references from anyone who has employed the individual in the past six years, and under SYSC 22.2.2R(3) the reference covers matters from the six years before the request. Serious misconduct sits outside that window rather than extending it: SYSC 22.2.2R(3)(c) requires disclosure "(in the case of serious misconduct) at any time". The full analysis is in the cornerstone piece; this is the working checklist.


The 10 checks


1. Do your conduct policies now name non-financial misconduct?

The conduct-rules map and the training materials that sit under it should reference serious bullying, harassment and violence towards colleagues as well as market conduct. Evidence: an updated conduct-rules map, and a compliance officer who can produce it on request.


2. Does your definition match the rule, or your discrimination policy?

COCON 1.1.7FR(4) borrows the Equality Act's language almost word for word. It applies to "unwanted conduct" that has the "purpose or effect" of "violating B's dignity" or "creating an intimidating, hostile, degrading, humiliating or offensive environment for B", which is section 26(1) of the Equality Act 2010 with one limb removed: the rule has no counterpart to the Act's "related to a relevant protected characteristic". In that one respect it is wider, and a definition recycled from the discrimination policy is too narrow because it starts from protected characteristics. In other respects the rule is narrower, being confined to the relationships listed at COCON 1.1.7FR(3), carved back by (5), and subject to a seriousness threshold the Act does not impose. The FCA describes the rule as covering "bullying, harassment or violence against colleagues, where it relates to an individual's role", and says it "applies where there is a sufficient work-related link". Evidence: policy wording checked against COCON 1.1.7FR itself, not against the discrimination policy it was copied from.


3. Can your board show it sees the data?

In February 2024 the FCA surveyed 1,028 regulated wholesale financial services firms (London market insurers and intermediaries, wholesale banks and wholesale brokers) about incidents recorded in 2021, 2022 and 2023. 984 responded. Of those, 38% "stated that a board or a board level committee did not receive management information (MI) about non-financial misconduct". No case numbers, no trends, no speak-up data reaching the top as routine reporting. Evidence: non-financial misconduct reporting on a board or committee agenda, with minutes that prove it was discussed.


4. Is there a formal route that decides outcomes?

In the same survey, 33% "stated that they have no formal governance structure or committee that decides the outcomes and disciplinary actions for those involved in non-financial misconduct cases". Ad hoc decisions produce inconsistent outcomes, and inconsistency is what scrutiny finds. Evidence: a named committee or role with terms of reference and a decision log.


5. Do you detect misconduct any way other than grievances?

Firms told the FCA that grievances or "other formal escalation processes" were the main ways they had identified non-financial misconduct. A firm that relies on formal complaints learns about conduct last. Evidence: speak-up data, exit-interview themes and manager escalations, logged and reviewed.


6. Do your managers know what to do with what they see?

The people who witness conduct first are the managers between the board and the floor. If they cannot describe the escalation route without looking it up, the route does not exist in practice. Evidence: escalations that actually arrive through managers as well as through HR.


7. Does that layer have the capacity to carry the rule?

82% of managers who enter management positions have had no formal management and leadership training (CMI, 2023), and manager engagement fell to 22% worldwide in 2025, from 27% the year before (Gallup, State of the Global Workplace 2026). A rule that lands on a layer with no training and no slack lands nowhere. Evidence: management-capability training for the layer (supervising people, handling conflict, as well as conduct-rule awareness), and supervision loads and spans of control that have been examined rather than assumed.



The handler's record

The implementation gap in checks five, six and seven carries a second exposure, and it belongs to the managers themselves. COCON 4.1.8-B G gives a "non-exhaustive list of examples of conduct by a manager in relation to misconduct referred to in COCON 4.1.8-AG that would breach rule 2". They include failing to take reasonable steps to protect staff against misconduct of that kind, failing to take seriously or to deal appropriately with complaints of it, and failing to take reasonable steps to provide a safe environment for people to raise concerns about such treatment.

The counterweight sits one provision earlier. COCON 4.1.8-A G opens by saying a manager "should try to prevent harassment and other kinds of misconduct referred to in COCON 4.3.1G (Purpose) that breaches COCON", and then sets the limit: "What a manager should do in a particular situation will depend on the exact facts. A manager will not be in breach of rule 2 if they have acted reasonably. There will often be a number of different reasonable courses of action that can be taken in a particular case."

Where a firm takes disciplinary action against a manager and that action relates to a conduct rule breach, it must be disclosed in that manager's own regulatory reference, with the basis for it and its outcome. "Disciplinary action" is narrowly defined, and SYSC 22 Annex 1R adopts the definition at s.64C(2) FSMA: the issuing of a formal written warning; the suspension or dismissal of the person; the reduction or recovery of any of the person's remuneration. An informal warning, a file note or performance management does not trigger it. A manager is accountable to the extent of their knowledge and their authority, and acting reasonably is a defence. But mishandling someone else's misconduct can now become a finding on the handler's own record. If checks five, six and seven fail, this is where the failure lands.


8. Would your case outcomes survive scrutiny?

In the FCA's survey, 47% of reported bullying and harassment incidents between 2021 and 2023 were not upheld, and disciplinary or other actions were taken in 43% of cases. A single not-upheld finding tells you nothing. A pattern of them, varying by business area, tells you something, and a pattern only surfaces if someone is looking for it. Tracking that nobody audits is a filing system. A control is something that gets tested. Evidence: outcome tracking by conduct type and business area, a periodic audit of those outcomes that tests for patterns and checks the process is working as designed, and anything the audit finds flagged to a named person with responsibility for acting on it.


9. Do your fitness assessments and regulatory references now capture non-financial misconduct?

Since 1 September, non-financial misconduct forms part of the fitness and propriety assessment. The reference rules are unchanged, but what they capture is not: where a firm has taken disciplinary action relating to a conduct rule breach, it must disclose that in the regulatory references it gives for Senior Managers, Certification staff and non-executive directors, and a reference already given must be updated if new information comes to light. Evidence: FIT assessment templates and reference processes updated before the first case tests them.


One further change belongs in this check, and it has been in force since 24 April 2026. FCA guidance at SYSC 22.5.2G(4) states that "the fact that the employee leaves before the investigation into the suspected misconduct is complete does not necessarily mean that the firm should omit the suspected misconduct" from a regulatory reference (FCA PS26/6, April 2026). Disclosure is not automatic. The same provision says a firm "should not include information about suspected misconduct unless the firm has taken sufficient steps to verify the information", and the guidance directs firms to weigh how material the misconduct would be if proven, the strength of their grounds for believing it occurred, fairness to the individual, and what privacy and employment law permit. But resignation no longer closes the file. Your reference process needs a documented position on how those four factors are weighed, and by whom, before the first mid-investigation departure tests it.


10. Could each senior manager put their hand on their reasonable-steps evidence today?

The Duty of Responsibility under s.66A(5) FSMA is personal to the SMF holder, and the adequacy of the structure they relied on is the evidence in that assessment. A reasonable-steps defence is only as strong as the capacity of the layer it delegated to. Evidence: a per-SMF record of delegation, oversight, the management information received and the action taken on it.


Where the exposure actually sits


Most implementation plans stopped at policy and training. The checks that fail in practice are five, six and seven: detection, escalation and capacity, all of which live in the manager layer. That is where conduct is witnessed first, absorbed first, and either surfaced or buried. A firm can pass checks one to four on paper and still be exposed, because the layer the rule depends on was never examined.


Frequently asked questions


What should a board be able to show?

That it receives management information on non-financial misconduct, that a formal governance route decides case outcomes, and that its senior managers can each evidence the reasonable steps taken in their areas. Those three cover the failures the FCA's own survey found most often.


Does conduct before 1 September count under the new rule?

No. Conduct before that date is judged under the previous scope. Conduct from 1 September falls within the scope of COCON, by virtue of COCON 1.1.7FR.


Who is assessed on reasonable steps, the firm or the individual?

The individual. The Duty of Responsibility sits with each SMF holder personally. The structure they relied on is evidence in that assessment; it does not discharge the duty.


Read your own firm next

The Manager-Layer Fracture Check is six checks and ten minutes. It scores whether the layer absorbing your firm's conflict has any structure holding it. Get the Fracture Check.

When you want the layer examined properly, the Keystone Briefing is 90 minutes with the person who owns the risk, and the Fracture Point Readout lands within 48 hours.


This checklist is what to evidence. The Non-Financial Misconduct Briefing is where firms are getting it wrong: five mistakes, one email a day for five days.


One email a day for five days, then occasional briefings from Fearon Advisory. Unsubscribe any time.

The structural picture behind the checks: manager layer burnout.


This article is general information about the FCA's non-financial misconduct rules (COCON 1.1.7FR, CP25/18 and PS25/23). It is not legal advice. Sarah Fearon is a former barrister, and Fearon Advisory provides structural and organisational advisory, not legal services.

 
 

ABOUT THE AUTHOR

Sarah Fearon is a former family-law barrister and co-founder of Crown Chambers, ranked a Leading Junior in The Legal 500 from 2020 to 2026. She has built and run a professional-services partnership from the inside, not just advised one. At Fearon Advisory she diagnoses where burnout and conflict are structurally produced in the manager layer, and redesigns it so pressure stops collecting on one layer, drawing on the Bar and an MA in International Politics. Structure, not wellness.

bottom of page