The FCA introduces non-financial misconduct rules: Here's what companies need to prepare by September 2026

Share this article
Contents
Example H2
Example H3
Example H4

The Financial Conduct Authority’s Policy Statement PS25/23, Tackling Non-Financial Misconduct in Financial Services, confirms a clear direction of travel for regulated firms. Serious behaviour such as bullying, harassment, discrimination, violence and sexual misconduct can no longer be treated only as internal HR issues. It may affect whether a person is fit and proper to perform a regulated role.

The new requirements come into force on 1 September 2026. Firms still have time to prepare, but the practical work should start now.

For many organisations, that means reviewing how they assess conduct risk before hiring, during certification and throughout employment. It also means asking a harder question: would employees feel safe enough to report misconduct before it becomes a regulatory, legal or reputational issue?

What is the FCA changing?

For several years, the FCA has emphasised the importance of healthy workplace cultures and the role culture plays in reducing harm to consumers and markets. PS25/23 essentially reinforces this position by providing greater clarity on how companies should consider non-financial misconduct when applying the Conduct Rules and assessing whether individuals are fit and proper to perform regulated roles.

With the new rules and guidance taking effect on 1 September 2026, companies have a limited window to review their recruitment, certification and Fitness & Propriety (F&P) assessment processes to ensure they remain fit for purpose in an evolving regulatory environment.

The FCA’s message is direct. Misconduct towards colleagues or others may be relevant when assessing an individual’s suitability to work in financial services.

That creates a broader compliance challenge. Firms need policies that define unacceptable behaviour, screening processes that support informed decisions, and internal reporting channels that allow concerns to surface early.

What does non-financial misconduct (NFM) mean in the context of financial services?

Non-financial misconduct (NFM) includes behaviour that is not of a clearly financial nature such as bullying, harassment and violence. Where NFM is serious and goes unchecked, it can harm individuals, firms and confidence in financial services.

Examples of misconduct highlighted by the FCA include:

  • Bullying
  • Harassment
  • Sexual misconduct
  • Violence
  • Discrimination
  • Serious abusive or intimidating behaviour

Where this behaviour goes unchecked, it can damage individuals, weaken trust inside the organisation and raise questions about management oversight.

The key shift is that firms should no longer see these issues only through an employment lens. Serious conduct concerns can also affect regulatory risk, certification decisions and Fitness and Propriety assessments.

Whistleblowing channels will become more important for financially regulated companies

Screening and due diligence help firms assess risk before someone joins the business. They do not solve the whole problem.

Many conduct issues emerge during employment. Some are visible to colleagues long before they appear in formal complaints, investigation records or management reports. Without a trusted whistleblowing process, those concerns may stay hidden until the harm is greater.

A clear whistleblowing process helps firms limit exposure to non-financial misconduct by giving employees and other stakeholders a safe route to report concerns. It also gives the organisation a better chance to identify patterns, investigate fairly and act before misconduct becomes embedded.

This matters for FCA-regulated firms because culture is rarely measured by policy documents alone. Regulators will look at whether firms have systems that work in practice. A speak-up process that employees trust is one of the strongest indicators that the organisation takes conduct seriously.

What makes a whistleblowing process effective?

A whistleblowing policy is useful only if people believe it will protect them.

An effective process should make it clear what can be reported, who can report, how reports are handled and what protections apply. It should also support confidential or anonymous reporting where appropriate.

Anonymity is especially important in cases involving bullying, harassment or abuse of power. Employees may fear retaliation, career damage or being dismissed as difficult. If the reporting process feels informal, exposed or dependent on a single manager, many people will stay silent.

That silence creates risk. Firms cannot manage misconduct they never hear about.

Veremark’s whistleblowing platform gives organisations a secure channel for receiving and managing whistleblowing reports and workplace complaints. It is designed to support confidential reporting, with end-to-end encryption and security controls that help strengthen trust in anonymity. For regulated firms preparing for the FCA’s new expectations, this can form part of a wider conduct risk framework.

How companies should prepare for September 2026

The implementation date may seem some distance away, but firms that begin reviewing their processes now will be better placed to respond.

The FCA’s guidance signals an expectation that firms actively assess conduct, integrity and culture when making recruitment, certification and Fitness and Propriety decisions. For many organisations, this means reviewing whether existing processes provide enough visibility of conduct-related risks.

Questions firms should consider include:

  • Do current screening and due diligence processes provide enough insight into potential conduct concerns?
  • Do Fitness and Propriety assessments properly consider integrity, honesty and reputation?
  • Are there clear procedures for escalating and assessing allegations of serious misconduct?
  • Is there a trusted whistleblowing process for employees to raise concerns safely?
  • Are conduct issues recorded and reviewed consistently across the employee lifecycle?

Addressing these questions now can help firms prepare for implementation while showing a proactive approach to regulatory expectations.

Implications for Recruitment and Fitness & Propriety Assessments

The changes are likely to influence how companies approach hiring decisions, certification reviews and ongoing assessments of staff conduct.

Many organisations are already reviewing their existing frameworks to determine whether they have sufficient processes in place to identify conduct-related risks before and during employment.

Questions companies may wish to consider include:

  • Are current screening and due diligence processes providing sufficient insight into potential conduct concerns?
  • Do Fitness & Propriety assessments adequately consider indicators of integrity, honesty and reputation?
  • Are there clear procedures for escalating and assessing allegations of serious misconduct?
  • Is there consistency in how conduct issues are recorded and reviewed across the employee lifecycle?

Addressing these questions now can help companies prepare for implementation while demonstrating a proactive approach to regulatory expectations.

Enhanced Due Diligence: A Growing Area of Focus

While the FCA has not prescribed specific screening requirements, some regulated companies are exploring whether additional due diligence measures could provide valuable context when assessing conduct, integrity and reputational risk.

Examples include:

Adverse Media Searches Media screening can help identify publicly reported allegations, investigations or incidents that may warrant further review as part of a wider assessment process.

Risk-Based Social Media Screening Where conducted lawfully and proportionately, social media screening may provide additional insight into behaviours that could present conduct or reputational risks.

Civil Litigation Searches Civil court records may reveal disputes or findings that could be relevant when assessing integrity, judgement or patterns of behaviour.

It is important to note that these measures are not mandated by the FCA. Rather, they are being considered by some organisations as supplementary tools to support existing recruitment and F&P frameworks.

The Importance of Proportionality

Any enhanced screening programme should be carefully designed to ensure it is proportionate, risk-based and compliant with applicable employment, privacy and data protection laws.

Companies should avoid adopting a "one size fits all" approach and instead consider factors such as:

  • The nature and seniority of the role
  • Regulatory responsibilities attached to the position
  • The level of potential conduct risk
  • Legal and data protection obligations
  • Transparency and fairness within the recruitment process

A balanced approach enables organisations to strengthen risk management while maintaining compliance and supporting positive candidate experiences.

How Veremark Can Help

As firms prepare for the FCA’s new requirements, many are reviewing whether their current screening, due diligence and internal reporting processes provide enough visibility of conduct, integrity and reputational risks.

Veremark supports regulated organisations with screening solutions that complement recruitment, certification and Fitness and Propriety frameworks. These include adverse media searches, risk-based social media screening, civil litigation checks and financial regulation checks, helping firms obtain additional context when making hiring and risk management decisions.

Veremark also provides a whistleblowing solution for organisations that need a secure, confidential process for receiving and managing reports. For firms concerned about exposure to non-financial misconduct, this helps close a critical gap: the gap between having a conduct policy and giving people a trusted way to report when that policy is breached.

With 1 September 2026 approaching, now is the time to review your current approach and identify where improvements are needed.

To discuss how your organisation can prepare for the FCA’s non-financial misconduct requirements, contact Veremark to learn how we can support your screening, compliance and whistleblowing processes.

Share this article

Popular Packages

FAQs

What background check do I need?

This depends on the industry and type of role you are recruiting for. To determine whether you need reference checks, identity checks, bankruptcy checks, civil background checks, credit checks for employment or any of the other background checks we offer, chat to our team of dedicated account managers.

Why should employers check the background of potential employees?

Many industries have compliance-related employment check requirements. And even if your industry doesn’t, remember that your staff have access to assets and data that must be protected. When you employ a new staff member you need to be certain that they have the best interests of your business at heart. Carrying out comprehensive background checking helps mitigate risk and ensures a safer hiring decision.

How long do background checks take?

Again, this depends on the type of checks you need. Simple identity checks can be carried out in as little as a few hours but a worldwide criminal background check for instance might take several weeks. A simple pre-employment check package takes around a week. Our account managers are specialists and can provide detailed information into which checks you need and how long they will take.

Can you do a background check online?

All Veremark checks are carried out online and digitally. This eliminates the need to collect, store and manage paper documents and information making the process faster, more efficient and ensures complete safety of candidate data and documents.

What are the benefits of a background check?

In a competitive marketplace, making the right hiring decisions is key to the success of your company. Employment background checks enables you to understand more about your candidates before making crucial decisions which can have either beneficial or catastrophic effects on your business.

What does a background check show?

Background checks not only provide useful insights into a candidate’s work history, skills and education, but they can also offer richer detail into someone’s personality and character traits. This gives you a huge advantage when considering who to hire. Background checking also ensures that candidates are legally allowed to carry out certain roles, failed criminal and credit checks could prevent them from working with vulnerable people or in a financial function.

Transform your hiring process

Request a discovery session with one of our background screening experts today.

Background screening in finance companies - 8 ways to stay compliant

In a tightly-regulated industry like finance, how easy is it to hire the right people and remain compliant?

In this guide we look at the problems facing banks and fintech companies as they struggle to acquire talent in a competitive labour market - while doing it in accordance to strict industry regulations.

And with around 70% of candidates admitting to fabricating details on their CV, we look at the essential checks required to ensure you get all the insights you need on a candidate in order to make an informed hiring decision.

Make sure your financial organisation is doing hiring right, every time, and keeping your workplace safe, happy and compliant.

Get your own copy!