The Financial Conduct Authority has given the City four weeks to finish a job most of banking took years to embed. From 1 September 2026, non-financial misconduct, meaning bullying, harassment and violence against colleagues, becomes a formal Conduct Rule breach across roughly 37,000 non-bank financial services firms, from asset managers and brokers to insurers, payment firms and financial advisers. It is the biggest extension of the FCA’s conduct regime beyond the banks since the Senior Managers and Certification Regime was rolled out to solo-regulated firms in 2019.
The change rests on a single new rule. COCON 1.1.7FR, added by the FCA’s Non-Financial Misconduct (No 2) Instrument 2025, extends the Code of Conduct in non-banking firms so that serious bullying, harassment or violence towards a colleague is treated as a breach where there is a sufficient work-related link. Banks and building societies were already caught by the FCA’s earlier interpretation of the conduct rules. The 1 September change closes the gap for everyone else the regulator supervises under COCON, and it does so on a fixed date rather than a transitional runway.
What actually changes on 1 September
Until now, a manager who bullied a subordinate at a solo-regulated firm might have faced an HR process, but the behaviour did not automatically engage the FCA’s individual conduct rules. From next month it does. A substantiated case can amount to a Conduct Rule breach in its own right, sitting alongside the familiar requirements to act with integrity and due care. That matters because Conduct Rule breaches feed into the regulatory machinery: they can trigger notification obligations to the FCA, shape a firm’s assessment of whether an individual remains fit and proper, and follow a person between employers.
The regulator has been careful about scope. The rule bites on conduct towards colleagues where it relates to the individual’s role, not on every dispute or off-duty disagreement. The FCA’s own framing turns on a “sufficient work-related link”, a phrase that will do a great deal of work in borderline cases and which the accompanying guidance is designed to help firms interpret.
The guidance that firms have had since December
The rule does not arrive cold. On 12 December 2025 the FCA published Policy Statement PS25/23, “Tackling non-financial misconduct in financial services”, which finalised the guidance that comes into force alongside COCON 1.1.7FR. That guidance is where the harder questions live.
Three points have drawn most of the attention from City employment lawyers. The first is the boundary between work and private life. The FCA has confirmed that conduct in someone’s personal life, including behaviour on social media, can be relevant to their fitness and propriety where it has a bearing on their role in financial services, while stopping short of turning the regulator into an arbiter of private morality. The second is the treatment of unproven allegations: firms are expected to handle these with care rather than treat an accusation as a finding, a distinction that will matter in fitness assessments. The third is the “reasonable steps” expectation on managers, which frames what senior individuals are expected to do to prevent and address misconduct within their remit.
For compliance and HR teams the practical consequence is that fit-and-proper assessments, the FIT sourcebook that sits beneath the certification regime, now have to account explicitly for non-financial misconduct. The guidance finalised in December was written to reduce firms’ reliance on external legal advice. Whether it does that, or simply raises the number of judgement calls a firm has to document, is the open question of the next month.
Regulatory references, and the memory that follows people
One of the more consequential mechanics sits in the reference regime. Firms will be obliged to disclose serious, substantiated cases of personal misconduct in the regulatory references they provide when an individual moves to another regulated employer. The intent is to stop the pattern, familiar from earlier scandals, of a person leaving under a cloud and resurfacing elsewhere with a clean-looking record. In practice it hands firms a disclosure judgement that carries legal risk in both directions: say too little and you may fall short of the reference rules, say too much about an unproven matter and you invite a dispute with the departing employee.
Four weeks, and an uneven state of readiness
The timing is the story for early August. Larger asset managers and insurers, many of which run group-wide conduct frameworks, have been preparing since the December policy statement and treat 1 September as a compliance checkpoint rather than a cliff edge. The concern sits further down the scale. Among the tens of thousands of smaller solo-regulated firms, the appointed representatives, boutique advisers and smaller payment and consumer-credit businesses, the regime is a genuinely new obligation, and the FCA has not offered a soft landing on the in-force date.
The near-term to-do list is not exotic: confirm that conduct policies and disciplinary procedures map onto COCON, brief managers on the reasonable-steps expectation, update the fit-and-proper assessment process to capture non-financial misconduct, and settle an internal position on what goes into a regulatory reference. None of that is difficult in isolation. The difficulty is doing it across 37,000 firms of wildly different sophistication in the weeks that remain.
The wider point is cultural, and the FCA has been explicit about it. The regulator has spent the better part of a decade arguing that how a firm treats its own people is a legitimate supervisory concern, not a matter it should leave to employment tribunals. On 1 September that argument stops being a matter of interpretation and becomes a rule with a date attached. For most of the sector, the substance is familiar. The novelty is that, from next month, getting it wrong is a breach.
Discussion
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.