Skip to content

FCA Non-Financial Misconduct: What Small Firms Must Do Now

Since 1 September 2026, small FCA-regulated firms have had to be able to handle non-financial misconduct allegations under the expanded COCON conduct rules. The new rule covers bullying, harassment (including sexual harassment) or violence against colleagues where it relates to the individual's role; discrimination and victimisation were not brought into COCON's scope by it, but can still breach the existing conduct rules on the ordinary tests. Either way, if a staff member is accused, you need a documented process for investigating, assessing, and recording the outcome. (For a step-by-step walkthrough specific to harassment allegations — including the dual employment / regulatory tracks — see our guide on handling a harassment allegation.)

This guide explains exactly what your firm needs to do — step by step — to comply with the rule and the PS25/23 guidance now that both are live. For the key dates and how the regime was phased in, see our PS25/23 deadline guide.

What is non-financial misconduct under PS25/23?

The FCA's own definition is deliberately short. Its non-financial misconduct page says: "Non-financial misconduct includes behaviour that is not of a clearly financial nature such as bullying, harassment and violence." PS25/23 uses the same narrow meaning throughout its COCON chapter — at paragraph 2.3, "'NFM' refers to the types of serious misconduct described in the new rule at COCON 1.1.7FR. Broadly, these are bullying, harassment and violence, unless otherwise stated."

The FCA deliberately declined to publish a longer list. Asked by respondents exactly what the new rule catches, it answered at paragraph 2.20 that it "is not possible to list all types of misconduct that might amount to a breach of COCON (or of fitness standards in FIT), as each case requires individual judgement based on its specific circumstances."

What the rule does define is the kind of behaviour in scope. COCON 1.1.7FR(4) reaches unwanted conduct that has the purpose or effect of "violating B's dignity" or "creating an intimidating, hostile, degrading, humiliating or offensive environment for B", and conduct "that is violent to B" — where B is a colleague, someone performing a function for the firm or its group, or someone providing services to it.

Two things small firms commonly get wrong:

  • There is no protected-characteristic test. The FCA consulted on one and then dropped it. PS25/23 paragraph 2.30: "we have withdrawn the proposed factor relating to 'specific characteristics or vulnerabilities.'" Harassment with no discrimination angle at all is squarely in scope — a firm that screens allegations for a protected characteristic will miss real breaches.
  • Sexual harassment is in; discrimination and victimisation are not. Paragraph 2.20 again: the rule "covers sexual harassment but does not expand the scope of COCON in non-banks to cover other forms of conduct prohibited by the Equality Act, such as discrimination and victimisation." Discrimination can still breach the existing conduct rules on the ordinary tests — it is simply not what the new rule brought in.

For COCON purposes the misconduct must be work-related and directed at a colleague: PS25/23 confirms at paragraph 2.23 that "the new NFM rule relates only to work-related misconduct against a colleague," and that the test is whether the conduct relates "to the performance […] of qualifying functions" under section 64A(4) FSMA. That can extend beyond the office — work events, work communications including messaging apps, business travel, and third-party events a person attends because of their job — but private life as such sits outside the FCA's power to make conduct rules at all.

Fitness and propriety is a different and wider question, and the narrow definition above does not govern it. See how the FIT test differs below.

What PS25/23 actually requires

PS25/23 does not create an entirely new regulatory obligation. It clarifies how existing COCON conduct rules apply to non-financial misconduct. The key changes:

1. A new handbook rule (COCON 1.1.7FR) — the rule itself was confirmed by the FCA in July 2025 (CP25/18), not by PS25/23. Since 1 September 2026 it extends COCON at non-bank firms to serious non-financial misconduct against colleagues. Previously the scope for non-banks was limited to conduct connected to regulated activities.

2. Guidance on how NFM can breach conduct rules — The FCA has explained which conduct rules are most likely to be engaged:

Conduct rule How NFM can breach it
Rule 1 — Act with integrity Bullying, harassment, or violence against a colleague can demonstrate a lack of integrity
Rule 2 — Act with due skill, care, and diligence A manager who ignores or mishandles an NFM allegation may breach Rule 2
SC1 — Ensure effective control of the business A senior manager who fails to establish NFM processes breaches SC1
SC2 — Ensure compliance with regulatory requirements A senior manager who fails to ensure the firm can handle NFM allegations breaches SC2

3. F&P assessment guidance — the fitness and propriety criteria for honesty, integrity and reputation sit at FIT 2.1, not FIT 2.2 (which is competence and capability). The FCA has added two new matters at FIT 2.1.3G(14) and (15): "whether the person has been found by a tribunal or court to have been engaged in harassment, victimisation or discrimination" and "whether the person has been found to have carried out harassment, bullying, victimisation or discrimination following an internal disciplinary process."

Note how much wider that is than the COCON rule. PS25/23 paragraph 3.2 is explicit: "In this chapter, the meaning of the term 'NFM' is not limited to the same types of misconduct discussed in Chapter 2… Conduct both inside and outside the workplace may be relevant to fitness and propriety." The FCA puts it more plainly still on its NFM page: "FIT allows firms to consider any relevant misconduct, wherever it occurs, when assessing fitness and propriety." So discrimination and victimisation — outside the new COCON rule — are expressly named in the FIT criteria.

4. Existing reporting requirements apply — NFM-related conduct rule breaches must be reported using the same mechanisms: annual REP008 for non-SMF staff, within 7 business days for SMF breaches.

What PS25/23 does NOT require

The FCA has been specific about what firms do not need to do. This matters because some compliance consultancies are overstating the requirements:

  • No retrospective review of past conduct or past F&P assessments
  • No social media monitoring or surveillance of employees' private lives
  • No investigation of trivial disagreements — the threshold is serious misconduct, not workplace friction
  • No conflict with employment law — firms should not take actions that breach data protection or employment rights
  • No mandatory software purchase — you can comply using paper records and the FCA's published flow diagrams in PS25/23 Appendix 1

Step-by-step: what your firm needs in place

Step 1: Establish an NFM policy

Write a short policy (2–3 pages is sufficient for a small firm) covering:

  • What behaviour constitutes non-financial misconduct
  • How staff should report NFM concerns (including anonymously)
  • Who is responsible for handling allegations (typically the compliance officer or principal)
  • How investigations will be conducted
  • How outcomes are recorded and reported to the FCA

This does not need to be a separate document. Many small firms will add an NFM section to their existing compliance procedures manual. The reporting channel itself often engages the SYSC 18 whistleblowing regime — see our guide on whistleblowing vs non-financial misconduct for how the two run in parallel.

Step 2: Build an investigation process

This is the critical gap for most small firms. When an allegation arrives, you need a clear process:

  1. Receive and log the allegation — Record who reported it, what is alleged, who is involved, and when it allegedly occurred. Accept anonymous reports.
  2. Assess severity — Is this serious enough to engage the conduct rules? Trivial disagreements are excluded. Bullying, harassment (including sexual harassment) and violence against a colleague are in the new rule's scope; discrimination and victimisation sit outside it, and are assessed against the existing conduct rules on the ordinary tests.
  3. Investigate — Gather evidence: interview the complainant, the accused, and witnesses. Collect relevant documents and communications. Maintain a timeline.
  4. Assess against COCON rules — Map the findings to specific conduct rules. Which rules were breached? Was the breach deliberate? Was there harm?
  5. Determine F&P impact — Does this finding affect the individual's fitness and propriety? Use the FIT 2.1 honesty, integrity and reputation criteria, and remember FIT is wider than COCON. Our F&P assessment guide covers each of the FIT 2 considerations and how NFM findings feed into the annual certification process.
  6. Record the outcome — Document the investigation findings, COCON assessment, F&P determination, and any disciplinary or remedial action.
  7. Report — If a conduct rule breach is confirmed, report via REP008 (non-SMF) or within 7 business days (SMF).

Use our free NFM Investigation Checklist to walk through this process step by step.

Step 3: Update your F&P assessment process

Your annual certification process for certification function holders should now include:

  • A question about whether any NFM allegations have been made against the individual
  • A step to check whether any NFM findings affect their F&P status
  • Documentation of the assessment and outcome

For initial applications (new hires into certification roles), include NFM in your due diligence checks.

Step 4: Train your staff

Staff need to understand three things:

  1. Non-financial misconduct can now have regulatory consequences — not just HR consequences
  2. How to report NFM concerns at your firm
  3. What happens when an allegation is received (so they cooperate with investigations)

Training does not need to be elaborate. A 30-minute briefing covering the policy, the reporting process, and practical examples is sufficient for most small firms.

Step 5: Brief your senior managers

Senior managers holding SMFs face personal accountability under SC1 (effective control) and SC2 (regulatory compliance). They need to understand:

  • They are personally responsible for ensuring the firm can handle NFM allegations
  • They must oversee the investigation process, not delegate it without oversight
  • Failure to act on a credible allegation is itself a potential conduct rule breach

Step 6: Test your process

Run a tabletop exercise. Create a realistic (but hypothetical) NFM scenario and walk through your investigation process end to end:

  • Can you log the allegation properly?
  • Can you conduct a structured investigation?
  • Can you map findings to specific COCON rules?
  • Can you assess F&P impact?
  • Can you produce an audit-ready record?

If any step fails, you know where to strengthen your process. Our free COCON Conduct Rules Self-Assessment can help you test individual scenarios.

Common questions

Does this apply to my firm? If your firm has Part 4A permission from the FCA and is not a bank, building society, or credit union, then yes — the rule and the PS25/23 guidance have applied since 1 September 2026. This covers IFAs, mortgage brokers, insurance brokers, wealth managers, and other small regulated firms.

What if we only have 3 staff? Firm size does not affect the obligation. A 3-person IFA needs the same process as a 50-person wealth manager. The process can be simpler and shorter for a smaller firm, but it must exist and be documented.

What if we already have an HR process for handling complaints? Your HR process is a starting point, but it is not sufficient on its own. The regulatory assessment — mapping to COCON rules, assessing F&P impact, and reporting to the FCA — sits on top of whatever HR process you use.

Can we outsource investigations? You can use an external investigator or compliance consultant. However, the senior manager with oversight responsibility must still review and approve the investigation outcome. You cannot outsource accountability.

Sources

This guide is for general information only and does not constitute legal or regulatory advice. Last reviewed: 3 September 2026.

Ready to manage conduct rule compliance properly?

ConductLog gives small FCA firms a structured investigation workflow with built-in COCON rule mapping. Join the waitlist for early access.

No spam. Unsubscribe any time. Privacy policy.