FCA Non-Financial Misconduct Rules 2026: The Governance Test for Boards

Sep 02, 2026

TL;DR: The FCA’s non-financial misconduct rules are now in force. For boards, this is more than a question of regulatory scope. It tests whether the organisation can turn a concern into reliable information, an accountable decision and credible assurance. Illume sees that as a test of two connected capabilities: Governance Maturity and Leadership Performance.

Professionals discussing organisational governance

From 1 September 2026, the FCA’s Conduct Rules expressly capture serious, work-related bullying, harassment and violence across non-banking SM&CR firms. The accompanying guidance also clarifies how non-financial misconduct may affect Conduct Rule and Fit and Proper assessments.

Firms need to understand those regulatory boundaries. But for boards, the more consequential question is how the organisation responds when a concern emerges.

Can it identify the correct decision route? Is ownership clear across HR, Compliance, Legal, Risk and business leadership? Does relevant information reach the right level? Are comparable cases treated consistently? And can the board obtain credible assurance that the system works?

The FCA change therefore tests the organisation’s cultural governance. It shows whether behavioural expectations are connected to authority, escalation, decision-making and accountability, or remain statements of intent.

What do the FCA’s non-financial misconduct rules establish?

The regulatory position can be summarised in five points:

  • The new COCON rule applies specifically to non-banking SM&CR firms. Banks already operated under a broader application of the Conduct Rules.
  • Serious bullying, harassment or violence towards a colleague can fall within COCON where there is a sufficient connection to the individual’s role and the other scope conditions are met.
  • Private conduct remains outside COCON, although relevant private conduct may inform a separate Fit and Proper assessment.
  • Not every instance of inappropriate behaviour automatically becomes a Conduct Rule breach. Seriousness, context and the work-related connection matter.
  • The changes are not retrospective. Conduct before 1 September 2026 should be assessed under the Handbook provisions in force at the time.

The FCA does not expect firms to reopen historic COCON decisions, revise historic FIT assessments or monitor employees’ private lives. Its guidance on non-financial misconduct should be read alongside the relevant Handbook provisions and firms’ wider legal obligations.

Why are the FCA rules a cultural governance test?

The rules are a cultural governance test because their effectiveness depends on what happens after a concern is raised: who takes ownership, how information moves, which decisions follow and what assurance reaches the board.

An FCA survey of around 1,000 wholesale financial firms recorded 2,347 allegations of non-financial misconduct in 2023. The volume matters, but a board cannot judge the quality of cultural governance from case numbers alone.

It needs to understand how concerns are detected, where they go, which judgements are applied, how outcomes differ and whether those differences can be explained.

The value of an escalation and reporting process ultimately depends on the quality of oversight it informs.

Our view is that the regime exposes two connected organisational capabilities within Illume’s Cultural Governance Framework and Index:

  • Governance Maturity: whether authority, escalation, management information and assurance are developed sufficiently for cultural risk to be governed rather than merely recorded.
  • Leadership Performance: whether leaders exercise judgement and accountability consistently when behavioural concerns involve status, commercial pressure, reputation or contested facts.

Together, these controls form a connected governance system. Ownership determines who is accountable. Escalation determines how information moves. Management information determines what leaders can see. Decision consistency shows how standards operate under pressure. Assurance tests whether the system works beyond its stated design.

Illume cultural governance pathway connecting employee voice, escalation, management information, accountable decisions and board assurance

The FCA rule increases the consequences of weaknesses anywhere in this pathway.

What patterns does Illume observe in practice?

Across Illume’s work with organisations, the recurring constraint is rarely a complete absence of evidence, activity or intent. More often, the weakness lies in the governance mechanisms connecting that evidence to ownership, decisions and assurance.

In one review, multiple sources of colleague and leadership insight were consolidated into a single evidence base, identifying where executive ownership and accountability needed to be strengthened. In another engagement, formal accountability mechanisms, defined governance responsibilities and impact reporting were built into the organisation’s operating model. Elsewhere, a board used structured consultation, scenario development and legal input to reach a collective position on a sensitive issue carrying organisational and reputational risk.

These were not FCA non-financial misconduct engagements. Together, they illustrate a recurring governance pattern. Voice, values and policies provide inputs; Governance Maturity determines how that evidence is consolidated, where responsibility sits, how decisions are reached and how the organisation assures itself that those decisions are applied in practice.

Why is Governance Maturity more than policy ownership?

The board should not manage individual employee-relations cases as a matter of course. Its role is to govern the system in which those cases are identified, assessed and resolved.

Mature governance extends beyond assigning non-financial misconduct to HR or Compliance. It depends on clarity about where authority sits, how functions work together and which decisions require challenge or oversight. That includes:

  • an accountable executive owner;
  • defined responsibilities across HR, Compliance, Legal, Risk and the business;
  • escalation thresholds distinguishing employee relations, COCON, FIT, notification and regulatory-reference considerations;
  • proportionate board or committee reporting;
  • a method for testing consistency across business units and levels of seniority; and
  • assurance that reporting routes, investigations and anti-retaliation controls operate in practice.

These recommendations describe cultural governance above the FCA’s regulatory floor rather than requirements imposed by COCON 1.1.7FR.

Accountability often appears clear on an organisation chart while becoming diffuse in a live case. HR may own the employment process, Compliance the Conduct Rules assessment, the business the commercial relationship and a senior manager the final judgement. Unless the interfaces are designed, every function can perform its own task while the organisation as a whole fails to make a coherent decision.

Why is Leadership Performance tested in difficult cases?

Leadership Performance is tested when leaders must apply agreed standards in the face of seniority, commercial pressure, reputational risk or contested facts.

The FCA’s guidance on Conduct Rule 2 does not make every manager responsible for every act of misconduct. It applies to managers subject to COCON, and the assessment of reasonable steps depends on factors including their authority, knowledge and the constraints under which they operated.

For boards, this creates a leadership question as well as a regulatory one. Has the firm made authority clear enough for a manager to act? Do leaders know when a concern must move beyond a local response? Are they expected to challenge a commercially important individual with the same discipline applied elsewhere? Can they evidence what they knew, decided and did?

Training may establish awareness, but Leadership Performance becomes visible in the quality and consistency of the decisions leaders make under pressure.

Promotion, succession, deployment and reward decisions should therefore form part of the oversight. Behavioural standards lose authority when formal case outcomes are inconsistent with subsequent people decisions.

What five questions should boards test now?

Together, these questions test how the regime operates as a governance system. They trace the route from ownership and escalation to decision-making and assurance.

Five cultural governance questions covering ownership, escalation, board information, decision consistency and assurance

1. Who owns the system?

Who has executive accountability for non-financial misconduct oversight? Where do HR, Compliance, Legal, Risk and business leadership responsibilities begin and end? Which committee receives assurance, and who resolves disagreement between functions?

The board must also establish whether the named owner has the authority, information and cross-functional support to govern the whole system.

2. What triggers escalation?

What determines when a concern moves from an employee-relations process into COCON, FIT, regulatory notification or regulatory-reference consideration? Are thresholds documented and understood? Can the firm explain why apparently similar cases followed different routes?

The organisation needs a defensible process for determining and recording when escalation is required.

3. What information reaches the board?

Does the board receive decision-useful information or simply a count of cases? Proportionate reporting might include themes, recurrence, time to resolution, reporting channels, seniority, business area, outcomes, appeals, retaliation concerns and interaction with exits or promotions.

Boards should be alert to confidentiality, small populations and false precision. Reporting should give them visibility of patterns while preserving confidentiality and operational independence.

4. Are decisions consistent under pressure?

How does the firm test whether comparable concerns are investigated, assessed and resolved consistently across business units, geographies and levels of seniority? Where outcomes differ, is the rationale explicit and reviewable?

Consistent governance allows outcomes to differ where relevant facts justify the difference and makes that rationale reviewable.

5. What assurance does the board receive?

How does the board know that reporting routes are trusted, retaliation is identified and addressed, managers escalate appropriately and policy operates as designed? Which evidence is independent of the function that owns the process?

Assurance should establish whether formal controls operate effectively in practice.

How should firms implement the rules as one governance system?

The FCA identifies four areas for firms to address: staff policies, Conduct Rule breach reporting, FIT assessments and regulatory references. Firms also need to ensure that staff and managers understand how the rules and guidance apply to them. These elements should operate coherently rather than as separate compliance tasks.

Boards should require an integrated governance view:

  • Map the decision route. Follow a concern from first report through triage, investigation, COCON, FIT, notification, employment outcome and regulatory reference. Identify where ownership changes and information can be lost.
  • Set governance thresholds. Agree which patterns, risks and exceptions reach executives, committees or the board while preserving confidentiality and operational independence.
  • Test management information. Determine whether reporting explains exposure and decision quality, not merely activity.
  • Calibrate decisions. Review a proportionate sample of concluded matters across business areas and seniority to test whether comparable facts receive comparable treatment.
  • Assure the system. Use independent evidence to test whether people trust reporting routes, managers act when concerns arise and retaliation controls operate.

The work should remain proportionate. The FCA expressly says firms do not need to reopen past Conduct Rule determinations, revise historic FIT assessments, monitor employees’ private lives or social media, investigate trivial or implausible private-life allegations, or act contrary to privacy, employment or other law.

How should firms distinguish COCON, FIT, SC4 and employment law?

These are related judgements, not a single test. Treating them as one vague category of “culture risk” weakens ownership, confuses escalation and makes consistent decisions harder.

  • COCON asks whether conduct within its scope breached an individual or senior manager Conduct Rule. For non-banking SM&CR firms, serious bullying, harassment or violence towards a colleague may now fall within scope where the required work-related connection and other conditions are met.
  • FIT asks whether an individual remains fit and proper for the relevant role. Its evidential scope can be wider than COCON and may include relevant private conduct.
  • SC4 requires senior conduct rules staff to disclose appropriately information of which the FCA or PRA would reasonably expect notice.
  • Employment law imposes separate duties and processes. It should not be collapsed into the regulatory analysis.

The distinction is operational as well as legal. Firms need a defensible method for deciding which test applies, who owns each judgement, when information moves between functions and how the rationale is recorded.

How does the Employment Rights Act 2025 fit alongside the FCA change?

This is a related but distinct development. From 30 October 2026, the Government’s implementation timetable says employers will be required to take all reasonable steps to prevent sexual harassment, strengthening the existing preventative duty. The Act also introduces a separate obligation concerning harassment by third parties.

Firms should now examine how the FCA regime interacts operationally with the employment-law changes taking effect on 30 October. Coordinating implementation may be sensible, but the employment-law duty, COCON, FIT and SC4 have different legal foundations, scope and decision tests and should not be treated as interchangeable.

The board test is whether the system works

The FCA’s non-financial misconduct rules provide a clearer regulatory position. The larger organisational question is whether the firm can identify a concern, move it to the right decision-maker, apply the correct tests and explain why the outcome was consistent and fair.

The regulation establishes a clearer floor, while responsibility for the cultural governance system above it remains with boards and executives.

If implementation has exposed uncertainty about ownership, escalation, management information, decision consistency or assurance, contact Illume. Illume works with boards and executive teams to assess cultural governance, clarify accountability and strengthen the systems through which cultural risk is identified, escalated and governed.

Explore selected examples of Illume’s work or subscribe to The Culture Economy for monthly analysis of cultural governance, leadership accountability and organisational performance.

This article is provided for general information only and does not constitute legal or regulatory advice. Firms should take advice on the application of the FCA Handbook, employment law and other obligations to their circumstances.

Key primary sources

Continue the Thinking

If you found this perspective valuable, subscribe to receive The Culture Economy's monthly intelligence briefing, plus updates on new research and executive briefings.