FCA Compliance Monitoring Plan: A Guide and Template for Small Firms
Every FCA-regulated firm has to be able to show that it monitors its own compliance — not just that it has policies, but that it actively checks whether those policies are being followed. The document that structures this is the compliance monitoring plan (sometimes called a compliance monitoring programme). For a small firm, it is one of the first things a supervisor or a skilled-person review will ask to see.
The problem is that most guidance on compliance monitoring plans is written for large firms with dedicated second-line teams. A five-person IFA does not need a forty-page programme — but it does need a real, risk-based plan that covers its actual regulated activities. This guide explains what the FCA requires, what a proportionate plan looks like for a small firm, and how to structure your own.
What is a compliance monitoring plan?
A compliance monitoring plan is a scheduled programme of checks a firm carries out on itself to confirm it is meeting its regulatory obligations. It answers three questions:
- What are we going to check? (the regulatory areas and controls)
- How often? (the frequency, driven by risk)
- Who does it, and what happens when we find something? (ownership and remediation)
It is the operational expression of the firm's compliance function. Where the compliance manual says what the rules are, the monitoring plan says how we confirm we are following them.
Why small firms need one — the SYSC basis
The requirement flows from the FCA's Senior Management Arrangements, Systems and Controls sourcebook (SYSC). The general obligation in SYSC 6.1.1R is that "a firm must establish, implement and maintain adequate policies and procedures sufficient to ensure compliance of the firm ... with its obligations under the regulatory system and for countering the risk that the firm might be used to further financial crime."
Where a firm has a compliance function, its job — in the words of SYSC 6.1.3R — is "to monitor and, on a regular basis, to assess the adequacy and effectiveness of the measures and procedures put in place ... and to advise and assist the relevant persons responsible for carrying out regulated activities to comply with the firm's obligations under the regulatory system."
The application of SYSC 6.1 varies by firm type. The compliance-function rule (SYSC 6.1.3R) binds a firm that is a management company (or an operator of an electronic system in relation to lending) as a hard rule; common platform firms are subject to an equivalent compliance-function requirement under the MiFID Org Regulation rather than under 6.1.3R itself. The FCA is also explicit that other firms should take account of it as guidance: SYSC 6.1.3AG says other firms "should take account of the compliance function rule (SYSC 6.1.3 R) as if it were guidance." Separately, SYSC 6.1.4AR requires a firm that is not a common platform firm or management company but carries on designated investment business with retail or professional clients to "allocate to a director or senior manager the function of ... having responsibility for oversight of the firm's compliance."
So while a five-person firm is unlikely to be a common platform firm subject to the fullest version of the rules, the underlying expectation is consistent across the regime: the firm must allocate compliance oversight to a named senior person and be able to demonstrate that it monitors its compliance on a systematic, risk-based basis. A compliance monitoring plan is how a small firm evidences that.
Responsibility for this typically sits with the SMF16 Compliance Oversight function holder under the Senior Managers and Certification Regime. If your firm is still mapping who holds what, the SMCR plain-English guide covers how the senior management functions fit together, including where compliance oversight sits.
What goes in a compliance monitoring plan?
A proportionate plan for a small firm covers the regulated activities the firm actually performs. For a typical small advisory or intermediary firm, the areas to monitor include:
| Monitoring area | What you check | Typical frequency |
|---|---|---|
| Financial promotions | Approvals, fair-clear-not-misleading standard, records | Quarterly / on issue |
| Suitability of advice | File reviews against suitability requirements | Ongoing sample |
| Client money / assets (CASS) | Reconciliations, segregation (if applicable) | Monthly / as CASS rules require |
| Complaints handling | DISP timescales, root-cause analysis, reporting | Quarterly |
| Training and competence | Competence assessments, CPD records | Annual / on trigger |
| SMCR obligations | F&P assessments, conduct breach register, Directory accuracy | Annual + on change |
| Financial crime / AML | Customer due diligence, SARs, MLRO oversight | Ongoing / risk-based |
| Consumer Duty | Outcomes monitoring, fair value, board report | Ongoing / annual report |
The plan should record, for each area: the obligation being tested, the check performed, who performs it, the frequency, and where the results are recorded. This last point matters — a monitoring plan with no record of the checks actually happening is not evidence of monitoring.
Make it risk-based, not exhaustive
The FCA does not expect a small firm to check everything with equal intensity. The plan should weight effort toward the areas of highest risk to customers and to the firm — for a mortgage intermediary that is suitability and financial promotions; for a firm holding client money that is CASS. A risk-based plan is both more defensible and more useful than a box-ticking checklist that treats every obligation identically.
A template structure you can build from
You do not need software to run a compliance monitoring plan — a well-structured spreadsheet works for most small firms. A workable template has these columns:
- Regulatory area — e.g. "Financial promotions"
- Obligation / rule reference — the specific requirement being tested
- Monitoring activity — what the check actually involves
- Frequency — quarterly, annual, on-trigger
- Owner — who performs the check (often the SMF16 holder or a delegate)
- Last completed — date the check was last done
- Next due — date the check is next due
- Findings — what the check found
- Action / remediation — what was done about any issue, and by when
Reviewed quarterly, this gives the Compliance Oversight function a live picture of what has been checked, what is overdue, and what issues are open. It also produces exactly the kind of audit trail a supervisor or skilled person expects to see.
The plan itself should be reviewed at least annually and updated whenever the firm's activities change, a new rule takes effect, or a monitoring finding reveals a gap. A static plan that was written once and never revisited is a red flag.
How the monitoring plan connects to the rest of your compliance
A compliance monitoring plan does not sit in isolation. It draws on and feeds into the firm's other SMCR and conduct arrangements:
- Conduct rule breaches surfaced by monitoring feed the breach register and any REP008 reporting. Our conduct rule breach reporting guide covers that obligation.
- Training and competence gaps identified in monitoring feed the T&C scheme.
- SMCR housekeeping — F&P assessments, Directory accuracy, Statements of Responsibilities — is itself a monitoring area, especially with the PS25/23 non-financial misconduct rules taking effect on 1 September 2026.
- Consumer Duty monitoring (outcomes testing, fair value) is increasingly the area supervisors focus on.
A good monitoring plan is the spine that connects all of these into a coherent, evidenced compliance picture.
Common mistakes
1. Copying a large-firm programme wholesale. A forty-page plan built for a network is unusable at a five-person firm and signals that the plan is not genuinely the firm's own.
2. No record of checks actually happening. The plan lists what should be checked but there is no evidence the checks occurred. Monitoring you cannot evidence is monitoring the FCA will treat as absent.
3. Never updating it. A plan written at authorisation and never revisited does not reflect the firm's current activities or the current rules.
4. No remediation loop. Findings are recorded but nothing tracks whether the issue was actually fixed. The "action / remediation" column closes this loop.
Summary
- A compliance monitoring plan is a scheduled, risk-based programme of checks a firm runs on its own compliance.
- The expectation flows from SYSC — a firm must be able to demonstrate systematic monitoring, typically owned by the SMF16 Compliance Oversight holder.
- Keep it proportionate and risk-weighted: cover the firm's actual regulated activities, not a generic checklist.
- A simple spreadsheet with area, obligation, activity, frequency, owner, dates, findings and remediation works for most small firms.
- Review the plan at least annually and record every check — monitoring you cannot evidence does not count.
Last reviewed: 11 August 2026. This guide explains the FCA's compliance monitoring expectations for small regulated firms. It is general information, not regulatory or legal advice, and it does not describe a ConductLog product feature — ConductLog is validating demand for a tool that helps small FCA-regulated firms handle conduct and misconduct processes. For your firm's specific obligations, check the FCA Handbook and consider professional advice.