Sponsored

For most of its life, the Financial Conduct Authority’s Code of Conduct did a narrow job. It set out how the people who work in regulated firms must handle client money, treat customers, manage conflicts and deal straight with the regulator. From 1 September 2026 it does something the industry has spent a year bracing for: it also governs how you treat the person at the next desk.

The change arrives through a single new rule, COCON 1.1.7FR, confirmed in the FCA’s policy statement PS25/23, published on 12 December 2025. It makes explicit that serious bullying, harassment and violence toward a colleague are a matter of regulatory concern at every firm inside the Senior Managers and Certification Regime, not only the banks that were already covered. For the large population of non-bank SM&CR firms, from asset managers and insurers to advisers, brokers and payment businesses, that is a genuine expansion of the perimeter rather than a restatement of existing duties.

From employment law to personal accountability

The temptation is to read this as the regulator wading into workplace culture, and much of the early commentary has framed it that way. That misses what actually moved. Bullying and harassment were already unlawful under employment and equality law, enforced through tribunals and internal grievance procedures. What PS25/23 does is pull that conduct into a prudential-style accountability framework built for a different purpose.

Under the new rule, serious non-financial misconduct can now engage the FCA Conduct Rules directly, feed the fitness and propriety assessment that decides whether an individual can hold a regulated role, trigger conduct-breach reporting to the regulator, and surface in the regulatory reference that follows a person from firm to firm. A tribunal deals with an employer and an employee. The SM&CR machinery deals with an individual’s standing to work in financial services at all, and it is portable across the industry.

That is the structural story. A financial regulator has annexed territory that used to sit squarely in employment law and wired it into the same personal-accountability plumbing it uses for mis-selling and market abuse. The question of whether someone is “fit and proper” now has a behavioural dimension that a poor reference can carry from one employer to the next.

Where the line sits, and where it blurs

The scope is not unlimited, and the boundaries are where the practical difficulty lives. The rule bites where there is a sufficient connection to the person’s work, and, for non-banks, where either the individual accused or the individual affected works in the part of the business that deals with financial services. It captures serious bullying, harassment and violence toward colleagues. It does not, for non-banks, sweep in the full range of Equality Act conduct such as discrimination or victimisation in the way the regime already does for banks, leaving a deliberate asymmetry between the two populations.

Two words carry a lot of weight: “sufficient” and “serious”. A regulator that used to draw bright lines around client-asset segregation is now asking firms, and ultimately itself, to decide where ordinary workplace friction ends and reportable misconduct begins. The FCA has published guidance alongside the rule precisely because that judgment is hard, and the industry asked for it: of the small pool of respondents to the consultation, an overwhelming majority wanted more detail before the switch flipped. Firms that get the threshold wrong risk two opposite failures, over-reporting minor disputes into someone’s permanent regulatory record, or under-reporting conduct that later resurfaces in an enforcement case.

What firms have to build

The compliance task is not a new poster in the staff kitchen. It is a set of connected processes that most non-bank firms have never had to run for this kind of conduct. They need a way to decide when a workplace incident crosses into a Conduct Rule breach, a route to report certified and senior staff breaches to the FCA, a fitness and propriety process that can weigh non-financial matters without collapsing into either leniency or overreach, and reference-writing practices that capture the new ground truthfully without inviting defamation claims.

For firms that already operate to the banking standard, the marginal change is modest. For the far larger group of solo-regulated firms that have treated conduct rules as a client-facing discipline, this is a cultural and operational shift landing at the same time as a stack of other 2026 obligations. It also raises a governance question for boards: senior managers carry personal responsibility for the areas they run, and a persistent failure to deal with bullying in a team is now something a supervisor can ask a named individual to account for.

The perimeter question

The broader significance is about direction of travel. The FCA has spent recent years pushing personal accountability deeper into the firms it oversees, from the Senior Managers regime to the Consumer Duty’s demand that outcomes, not processes, be evidenced. Extending conduct rules to how staff treat each other is of a piece with that. It treats internal culture as a supervisory signal rather than a private employment matter, on the theory that firms which tolerate abusive behaviour internally are likelier to cut corners with customers and markets.

Whether that theory holds will not be visible for some time. There is no published data yet on how many non-financial-misconduct breaches the wider population will report, how consistently firms will apply the “serious” threshold, or how often the new ground will actually change a fitness decision. What is already clear is that a line has moved. From this month, the conduct that can cost a financial-services professional their ability to work in the industry is no longer only about the money. It is also about the people they work alongside.

Finance & Markets Correspondent
Covers: Finance, capital markets, technology investing

David Whitmore covers the intersection of capital and code — the funding rounds, market structures and policy moves that shape how money flows through the technology economy.