About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

FCA Misconduct Rules Put Surveillance Evidence and HR–Compliance Workflows to the Test

Subscribe to our newsletter

The Financial Conduct Authority’s expanded non-financial misconduct rules took effect on 1 September, bringing around 37,000 non-bank firms within a broader conduct regime. Firms now need to show how complaints, communications evidence and employment investigations inform regulatory decisions.

New rule COCON 1.1.7FR covers serious work-related bullying, harassment and violence towards colleagues. It brings non-bank firms closer to the position already applying to banks and applies only to conduct occurring from 1 September 2026.

A policy update will satisfy only part of the requirement. When an allegation arises, the firm must establish what happened, assess its seriousness and decide whether it affects the individual’s conduct record or fitness and propriety. That process may involve human resources, Legal, Compliance, Surveillance and senior management.

Surveillance has a supporting role

The rules do not require firms to monitor communications specifically for non-financial misconduct. The FCA also does not expect them to monitor employees’ private lives. Many firms already capture email, voice and collaboration messages for market-conduct purposes, however, and those records may provide evidence when a complaint involves workplace communications.

The FCA’s 2024 survey showed how limited that contribution has been. Monitoring and surveillance detected only about 1% of reported incidents among London market insurers and intermediaries. Wholesale banks and brokers used surveillance more frequently, partly because they already monitored communications for market abuse. The FCA encouraged firms to combine several detection methods rather than depend on one channel.

Existing systems may also struggle with the nature of the behaviour. Market-surveillance tools look for recognisable terms, trading patterns and financial relationships. Bullying or intimidation may emerge through tone, repetition, exclusion or a manager’s treatment of a junior employee over several months.

Paul Cottee, director of regulatory compliance at NICE Actimize, writes that “traditional lexicons and phrase libraries were not built to detect cultural misconduct.” He argues that firms will need more contextual analysis and the ability to identify patterns across communications.

Artificial intelligence can group related messages and prioritise material for review. It cannot reliably decide whether conduct was unwanted, whether it had a sufficient connection to work or whether it crossed the FCA’s seriousness threshold. Those decisions require investigation and documented human judgement.

HR findings need a regulatory assessment

Many firms hold employee complaints and disciplinary findings inside HR systems. Compliance may see the outcome only when a case is escalated informally. That division becomes harder to defend when the same conduct may trigger a COCON breach, a fitness-and-propriety reassessment or an entry in a regulatory reference.

Comply Technologies identifies the missing control as a structured route from the HR investigation to a Compliance-owned regulatory assessment. Compliance needs enough information to decide whether the conduct rules apply and must record the reasoning behind that decision. Aggregated information can also reveal repeated allegations involving the same manager, desk or business unit.

A workable process should preserve the original complaint or surveillance alert, relevant communications and the investigation record. It should then document the factual findings, seriousness assessment, COCON and FIT conclusions, reporting decision and approvals.

Where AI contributed to an alert, the record should identify the model or rule used, its version and the reason the communication was selected. Reviewers also need the surrounding conversation. An isolated message may misrepresent the exchange or omit evidence relevant to intent and impact.

Slaughter and May says findings should address context, hierarchy, knowledge and the way concerns were escalated. The reasoning must be capable of withstanding regulatory and tribunal scrutiny.

More monitoring creates other risks

The boundary between work and private life remains important. COCON addresses workplace conduct and conduct with a sufficient work-related link. Serious private behaviour may still affect a FIT assessment, but firms are not expected to investigate trivial allegations or supervise personal communications.

Monitoring must therefore be proportionate and tied to a stated purpose. Firms need to control access to sensitive messages, protect whistleblowers and decide how long to retain unsubstantiated alerts. Employment rights, data protection and legal privilege continue to apply.

The first supervisory tests will examine the joins between existing controls. Firms will need to retrieve the evidence, show who considered it and explain why similar cases produced consistent outcomes.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Managing Off-Channel Communications Compliance

The compliance challenge around off-channel communications has moved beyond the familiar narrative of WhatsApp messages on personal phones. Today, the real issue confronting firms has become communication sprawl: conversations occurring across messaging apps, collaboration platforms, social media direct messages, personal email, and even messaging tools embedded within trading and workflow applications. Regulators’ expectations focus on...

BLOG

Holistic Conduct & Surveillance: Unifying Trade, Voice, and eComms Data with AI

Holistic surveillance is moving beyond data integration towards an operating model that can surface cross-channel evidence, assign escalation ownership, govern approved channels, organise analysts around risk and keep AI-supported triage accountable to experienced human review. That was the central message of A-Team Insight’s recent webinar, Holistic Conduct & Surveillance: Unifying Trade, Voice, and eComms Data...

EVENT

Eagle Alpha Alternative Data Conference, London, hosted by A-Team Group

Now in its 8th year, the Eagle Alpha Alternative Data Conference managed by A-Team Group, is the premier content forum and networking event for investment firms and hedge funds.

GUIDE

Regulatory Data Handbook – Third Edition

Need to know all the essentials about the regulations impacting data management? Welcome to the third edition of our A-Team Regulatory Data Handbook which provides all the essentials about regulations impacting data management. A-Team’s series of Regulatory Data Handbooks are a great way to see at-a-glance: All the regulations that are impacting data management today...