
The Financial Conduct Authority’s expanded non-financial misconduct rules took effect on 1 September, bringing around 37,000 non-bank firms within a broader conduct regime. Firms now need to show how complaints, communications evidence and employment investigations inform regulatory decisions.
New rule COCON 1.1.7FR covers serious work-related bullying, harassment and violence towards colleagues. It brings non-bank firms closer to the position already applying to banks and applies only to conduct occurring from 1 September 2026.
A policy update will satisfy only part of the requirement. When an allegation arises, the firm must establish what happened, assess its seriousness and decide whether it affects the individual’s conduct record or fitness and propriety. That process may involve human resources, Legal, Compliance, Surveillance and senior management.Surveillance has a supporting role
The rules do not require firms to monitor communications specifically for non-financial misconduct. The FCA also does not expect them to monitor employees’ private lives. Many firms already capture email, voice and collaboration messages for market-conduct purposes, however, and those records may provide evidence when a complaint involves workplace communications.
The FCA’s 2024 survey showed how limited that contribution has been. Monitoring and surveillance detected only about 1% of reported incidents among London market insurers and intermediaries. Wholesale banks and brokers used surveillance more frequently, partly because they already monitored communications for market abuse. The FCA encouraged firms to combine several detection methods rather than depend on one channel.Existing systems may also struggle with the nature of the behaviour. Market-surveillance tools look for recognisable terms, trading patterns and financial relationships. Bullying or intimidation may emerge through tone, repetition, exclusion or a manager’s treatment of a junior employee over several months.
Paul Cottee, director of regulatory compliance at NICE Actimize, writes that “traditional lexicons and phrase libraries were not built to detect cultural misconduct.” He argues that firms will need more contextual analysis and the ability to identify patterns across communications.
Artificial intelligence can group related messages and prioritise material for review. It cannot reliably decide whether conduct was unwanted, whether it had a sufficient connection to work or whether it crossed the FCA’s seriousness threshold. Those decisions require investigation and documented human judgement.
HR findings need a regulatory assessment
Many firms hold employee complaints and disciplinary findings inside HR systems. Compliance may see the outcome only when a case is escalated informally. That division becomes harder to defend when the same conduct may trigger a COCON breach, a fitness-and-propriety reassessment or an entry in a regulatory reference.
Comply Technologies identifies the missing control as a structured route from the HR investigation to a Compliance-owned regulatory assessment. Compliance needs enough information to decide whether the conduct rules apply and must record the reasoning behind that decision. Aggregated information can also reveal repeated allegations involving the same manager, desk or business unit.
A workable process should preserve the original complaint or surveillance alert, relevant communications and the investigation record. It should then document the factual findings, seriousness assessment, COCON and FIT conclusions, reporting decision and approvals.
Where AI contributed to an alert, the record should identify the model or rule used, its version and the reason the communication was selected. Reviewers also need the surrounding conversation. An isolated message may misrepresent the exchange or omit evidence relevant to intent and impact.
Slaughter and May says findings should address context, hierarchy, knowledge and the way concerns were escalated. The reasoning must be capable of withstanding regulatory and tribunal scrutiny.
More monitoring creates other risks
The boundary between work and private life remains important. COCON addresses workplace conduct and conduct with a sufficient work-related link. Serious private behaviour may still affect a FIT assessment, but firms are not expected to investigate trivial allegations or supervise personal communications.
Monitoring must therefore be proportionate and tied to a stated purpose. Firms need to control access to sensitive messages, protect whistleblowers and decide how long to retain unsubstantiated alerts. Employment rights, data protection and legal privilege continue to apply.
The first supervisory tests will examine the joins between existing controls. Firms will need to retrieve the evidence, show who considered it and explain why similar cases produced consistent outcomes.
Subscribe to our newsletter


