About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

FCA Misconduct Rules Put Surveillance Evidence and HR–Compliance Workflows to the Test

Subscribe to our newsletter

The Financial Conduct Authority’s expanded non-financial misconduct rules took effect on 1 September, bringing around 37,000 non-bank firms within a broader conduct regime. Firms now need to show how complaints, communications evidence and employment investigations inform regulatory decisions.

New rule COCON 1.1.7FR covers serious work-related bullying, harassment and violence towards colleagues. It brings non-bank firms closer to the position already applying to banks and applies only to conduct occurring from 1 September 2026.

A policy update will satisfy only part of the requirement. When an allegation arises, the firm must establish what happened, assess its seriousness and decide whether it affects the individual’s conduct record or fitness and propriety. That process may involve human resources, Legal, Compliance, Surveillance and senior management.

Surveillance has a supporting role

The rules do not require firms to monitor communications specifically for non-financial misconduct. The FCA also does not expect them to monitor employees’ private lives. Many firms already capture email, voice and collaboration messages for market-conduct purposes, however, and those records may provide evidence when a complaint involves workplace communications.

The FCA’s 2024 survey showed how limited that contribution has been. Monitoring and surveillance detected only about 1% of reported incidents among London market insurers and intermediaries. Wholesale banks and brokers used surveillance more frequently, partly because they already monitored communications for market abuse. The FCA encouraged firms to combine several detection methods rather than depend on one channel.

Existing systems may also struggle with the nature of the behaviour. Market-surveillance tools look for recognisable terms, trading patterns and financial relationships. Bullying or intimidation may emerge through tone, repetition, exclusion or a manager’s treatment of a junior employee over several months.

Paul Cottee, director of regulatory compliance at NICE Actimize, writes that “traditional lexicons and phrase libraries were not built to detect cultural misconduct.” He argues that firms will need more contextual analysis and the ability to identify patterns across communications.

Artificial intelligence can group related messages and prioritise material for review. It cannot reliably decide whether conduct was unwanted, whether it had a sufficient connection to work or whether it crossed the FCA’s seriousness threshold. Those decisions require investigation and documented human judgement.

HR findings need a regulatory assessment

Many firms hold employee complaints and disciplinary findings inside HR systems. Compliance may see the outcome only when a case is escalated informally. That division becomes harder to defend when the same conduct may trigger a COCON breach, a fitness-and-propriety reassessment or an entry in a regulatory reference.

Comply Technologies identifies the missing control as a structured route from the HR investigation to a Compliance-owned regulatory assessment. Compliance needs enough information to decide whether the conduct rules apply and must record the reasoning behind that decision. Aggregated information can also reveal repeated allegations involving the same manager, desk or business unit.

A workable process should preserve the original complaint or surveillance alert, relevant communications and the investigation record. It should then document the factual findings, seriousness assessment, COCON and FIT conclusions, reporting decision and approvals.

Where AI contributed to an alert, the record should identify the model or rule used, its version and the reason the communication was selected. Reviewers also need the surrounding conversation. An isolated message may misrepresent the exchange or omit evidence relevant to intent and impact.

Slaughter and May says findings should address context, hierarchy, knowledge and the way concerns were escalated. The reasoning must be capable of withstanding regulatory and tribunal scrutiny.

More monitoring creates other risks

The boundary between work and private life remains important. COCON addresses workplace conduct and conduct with a sufficient work-related link. Serious private behaviour may still affect a FIT assessment, but firms are not expected to investigate trivial allegations or supervise personal communications.

Monitoring must therefore be proportionate and tied to a stated purpose. Firms need to control access to sensitive messages, protect whistleblowers and decide how long to retain unsubstantiated alerts. Employment rights, data protection and legal privilege continue to apply.

The first supervisory tests will examine the joins between existing controls. Firms will need to retrieve the evidence, show who considered it and explain why similar cases produced consistent outcomes.

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: The Next Compliance Frontier: Monitoring GenAI and Unstructured Comms Data

Date: 16 September 2026 Time: 10:00am ET / 3:00pm London / 4:00pm CET Duration: 50 minutes Generative AI is rapidly transforming how employees create, share, and interpret information. From internal copilots drafting client messages to AI tools summarising trading conversations or generating research notes, large language models are increasingly embedded in daily workflows across capital...

BLOG

From Regulatory Noise to Defensible Action: Where RegTech Must Deliver Next

A compliance system delivers value when it helps a firm decide what to do next. That remains difficult when the evidence sits across internal policies, siloed data and external intelligence. AI can handle the volume and diversity, but faster analysis does not guarantee a better compliance decision. Firms still need to establish why an alert...

EVENT

Eagle Alpha Alternative Data Conference, Fall, New York, hosted by A-Team Group

Now in its 8th year, the Eagle Alpha Alternative Data Conference managed by A-Team Group, is the premier content forum and networking event for investment firms and hedge funds.

GUIDE

Hosted/Managed Services

The on-site data management model is broken. Resources have been squeezed to breaking point. The industry needs a new operating model if it is truly to do more with less. Can hosted/managed services provide the answer? Can the marketplace really create and maintain a utility-based approach to reference data management? And if so, how can...