FCA Conduct Risk: What It Is and How Small Firms Manage It
Conduct risk is one of those regulatory terms that sounds intuitive but is harder to pin down in practice. Regulators reference it constantly. Supervisors ask about it. Firms are expected to have frameworks for managing it. But small FCA-regulated firms — IFAs, mortgage brokers, insurance intermediaries — often lack a clear working definition, let alone a documented approach.
This guide explains how the FCA thinks about conduct risk, how it connects to your SMCR obligations, and what a practical conduct risk framework looks like for a small solo-regulated firm.
What is conduct risk?
The FCA does not publish a single, binding definition of conduct risk. Instead — as part of its 5 Conduct Questions Programme, which it launched in 2015 to engage firms on culture and conduct — the FCA's position was that "the first step in addressing conduct risk was for firms to develop their own working definition." The expectation is that each firm develops a definition relevant to its business and client base.
A widely-used working definition in the industry is:
The risk that firm or staff behaviour results in unfair outcomes for clients, market integrity failures, or regulatory censure.
At a small regulated firm, conduct risk tends to manifest in identifiable ways:
- An adviser recommending a product that is not suitable for the client's circumstances
- A manager creating an environment where staff feel unable to report concerns (the "speak up" risk)
- Undisclosed conflicts of interest influencing advice or transaction execution
- Inadequate record-keeping that prevents the firm from demonstrating how it acted in a client's best interests
Conduct risk is distinct from operational risk (systems failing) or credit risk (counterparty default). It is specifically about how people — individually and collectively — behave in ways that may cause harm.
How conduct risk connects to SMCR
SMCR does not use the phrase "conduct risk" prominently in the rules, but the entire regime is structured around managing it. The key connection points are:
The COCON individual conduct rules. The FCA's Code of Conduct sourcebook (COCON) sets out rules that apply to all staff at SMCR-regulated firms. The six individual conduct rules require staff to: act with integrity; act with due skill, care and diligence; be open and cooperative with the FCA; pay due regard to the interests of customers; observe proper standards of market conduct; and act to deliver good outcomes for retail customers under the Consumer Duty (this sixth rule — Individual Conduct Rule 6, added 31 July 2023 with the Consumer Duty — applies to all conduct-rules staff at firms whose activities fall within Consumer Duty scope, not only Senior Managers).
Conduct rule breaches are, in effect, the measurable outcome of conduct risk materialising. If a member of staff behaves in a way that causes harm to a client, the question the FCA will ask is: which conduct rule did this engage? And which Senior Manager was accountable for the activity in which it occurred?
Senior Manager accountability. Under SMCR, each significant activity at the firm must have a named Senior Manager who is accountable for it. If conduct risk materialises in an area — say, a systematic failure in suitability assessments — the FCA will trace accountability back to the Senior Manager responsible for that area. This makes conduct risk management a leadership responsibility, not just a compliance function.
Prescribed Responsibilities. One of the Prescribed Responsibilities (Responsibility (a)) requires a Senior Manager to take responsibility for the firm's culture and values. In the FCA's view, culture is the primary driver of conduct outcomes. A firm with a healthy culture — where staff understand what is expected of them, feel safe to raise concerns, and are rewarded for the right behaviours — is less likely to generate conduct risk events than a firm where short-term results dominate over how those results are achieved.
Fit and proper assessments. Your annual fit and proper assessment for certified staff and Senior Managers is, partly, a conduct risk assessment. You are asking: is this individual likely to behave in ways that create conduct risk for the firm? Prior conduct rule breaches, upheld complaints, or evidence of poor judgement are all conduct indicators that inform that assessment.
The FCA's four behavioural drivers
In its culture and governance guidance, the FCA identifies four drivers of firm behaviour that shape conduct risk:
| Driver | What the FCA looks for |
|---|---|
| Purpose | Does the firm have a clearly articulated purpose that goes beyond profit? Does it shape day-to-day decisions? |
| Leadership | Do Senior Managers model the behaviours they expect from staff? Is accountability real, not nominal? |
| Approach to rewarding and managing people | Does the firm recognise and reward good conduct, not just commercial results? Are poor conduct outcomes addressed? |
| Governance | Are there effective mechanisms for identifying and escalating conduct concerns before they cause harm? |
For a small firm, these translate into practical questions about how you run the business. Are there documented standards of conduct? Do staff know what they are expected to do and not do? When things go wrong, does the response focus on learning and improvement as well as on fixing the immediate problem?
What a conduct risk framework looks like for a small firm
Large banks run dedicated conduct risk teams with quantitative risk models. Small firms need something proportionate — documented enough to demonstrate that you take conduct risk seriously, practical enough to actually influence behaviour.
A basic conduct risk framework for a small solo-regulated firm typically covers:
1. Conduct risk identification
Map the specific ways conduct risk could materialise in your business. For an IFA, the most significant conduct risks might be: unsuitable advice, conflicts of interest, inadequate disclosure of fees, and failure to identify vulnerable customers. For a mortgage broker, similar concerns apply with additional focus on product suitability and lender panel selection.
This does not need to be a long document. A one-page risk register listing your firm's three to five highest-likelihood conduct risks, with an owner and a control for each, is proportionate and defensible.
2. Conduct standards and training
Staff need to understand what is expected of them. This means more than signing a copy of the conduct rules on joining. It means practical training on what the rules mean in the context of your firm's work — ideally worked examples of situations where the right and wrong choices are not obvious.
From 1 September 2026, PS25/23 extends COCON to cover non-financial misconduct — harassment, bullying, discrimination, and similar — for all non-bank FCA-authorised firms. Your conduct standards training will need to include this extended scope from that date. Staff who were previously trained only on financial conduct rules will need refreshed training that covers non-financial misconduct as a conduct rule breach.
3. Complaints and incident monitoring
Complaints are one of the most reliable early-warning signals for conduct risk. A pattern of complaints about a particular adviser, product type, or process points to a conduct issue before it becomes a regulatory one. Build in a regular review of complaints data against conduct risk categories.
Similarly, near-misses and internal incidents (cases that did not result in a formal complaint but flagged a concern) should be recorded and reviewed. The FCA expects firms to learn from incidents — the question supervisors ask is not only "what went wrong?" but "what did you do differently as a result?"
4. The speak-up environment
One of the most consistent findings from the FCA's conduct culture work is that firms with poor conduct outcomes typically also have environments where staff feel unable to raise concerns. People knew something was wrong but did not say so — because they feared the consequences, because previous concerns had been dismissed, or because the culture did not value challenge.
Creating a genuine speak-up environment at a small firm is partly structural (does your firm have a clear route for raising concerns without going through the line manager who may be the subject of the concern?) and partly cultural (how does leadership actually respond when concerns are raised?). The FCA will ask about this.
5. Annual conduct risk review
Conduct risk should be reviewed formally at least once a year — ideally linked to the annual fit and proper assessment cycle. The review should ask: have any conduct risk events occurred? Are the existing controls still appropriate? Have any changes to the business — new products, new staff, new client segments — created new conduct risks? Are there any external developments (new FCA guidance, market events at peer firms) that warrant updating the firm's approach?
Document the review. A two-page summary of what you reviewed, what you found, and what you changed or confirmed is proportionate for a small firm. The point is that it happened, you considered the evidence, and you made a deliberate decision about whether the existing approach remained adequate.
Connecting conduct risk to your SMCR documentation
Your conduct risk framework is not a standalone document — it connects to your wider SMCR documentation:
- Statements of Responsibilities: The Senior Manager responsible for culture and conduct should have that responsibility explicitly in their Statement of Responsibilities
- Management Responsibilities Map: Lines of accountability for conduct risk should be traceable through the MRM
- Fit and proper assessments: Conduct risk indicators (complaints, incident data, training completion) feed into the annual F&P cycle
- Regulatory references: Conduct rule breaches discovered through the conduct risk process become disclosable in regulatory references for departing staff
For the broader SMCR documentation framework, see our SMCR plain-English guide.
Why PS25/23 makes conduct risk management more important
The September 2026 deadline for PS25/23 is a significant milestone for conduct risk management. Before September 2026, conduct risk in most small firms centred on financial conduct — suitability, conflicts, disclosure. From September 2026, it explicitly includes non-financial misconduct.
This means your conduct risk identification exercise needs to consider: is harassment, bullying, or discrimination a realistic risk in your firm? For most small firms, the honest answer is yes — not because the firm has a particular problem, but because these risks exist wherever people work together, and a small team without clear HR structures is, if anything, more exposed to interpersonal conduct issues than a large firm with dedicated HR.
The PS25/23 extension to COCON also affects your regulatory reference obligations. If, after September 2026, you investigate a non-financial misconduct allegation and conclude it amounted to a conduct rule breach, that finding becomes disclosable in any future regulatory reference you give for that individual. The record you keep of how you handled the investigation — and what conclusion you reached — therefore has a long-term regulatory consequence.
This guide covers FCA conduct risk management for small solo-regulated firms under SMCR. It is intended as a practical overview, not legal advice. For complex conduct risk or non-financial misconduct situations, take specialist compliance or legal advice.
Sources: