What the FCA's non-financial misconduct rules mean for communications compliance
A shorter version of this piece originally appeared in Financial Reporter
This week the FCA's new rules on non-financial misconduct came into force, bringing roughly 37,000 additional non-bank firms under the Senior Managers and Certification Regime's conduct rules for the first time. Bullying, harassment and violence at work, where connected to someone's role, are now captured by COCON 1.1.7FR, alongside updated Fit and Proper guidance that lets firms weigh this conduct when assessing whether someone is suitable to hold a regulated role.
On paper, this looks like an HR and culture story. In practice, it's a records story too, and that's the part getting less attention.
This was already unlawful. So, what's changed?
UK employment law has barred harassment and inappropriate workplace behaviour for a long time. What's new is that the FCA has made serious misconduct a regulatory matter as well as a people one. Regulated firms now need to be able to establish what happened, show how they responded, and, in the most serious cases, reflect that in regulatory references when someone moves firms.
That's a significantly higher bar than a well-run HR process. And it lands at an awkward moment: we now live in a world where workplace conversations increasingly happen across WhatsApp, Signal, Teams and personal mobile devices, not just email and the office floor. If the material part of a conversation between a trader and a risk manager, or between any two colleagues, has disappeared, there's a fundamental problem before an investigation even starts.
The risk isn't the misconduct. It's not being able to evidence the response.
The biggest exposure here isn't simply that misconduct happens - it's a firm being unable to demonstrate it had appropriate controls and acted properly once an allegation was raised. If a serious incident plays out across channels a firm can't retrieve or reconstruct, management can find itself trying to answer a regulatory question without the evidence to support the answer. In financial markets, "we don't know because we don't have the records" is an increasingly awkward position to be in.
There's a people dimension too. Serious, substantiated misconduct can follow an individual through regulatory references, rather than quietly disappearing when they change employer. That raises the stakes on getting the investigation, and the evidence behind it, right the first time.
Where the FCA has drawn the line
It's worth being precise about scope, because it’s not necessarily about monitoring more. The FCA has been explicit that this does not mean firms should start snooping on employees' private lives, and firms aren't expected to monitor personal social media or investigate conduct that's genuinely unconnected to work. Firms should expect the boundary between workplace conduct and regulated conduct to become much clearer. A work-related WhatsApp message doesn't stop being in scope just because it was sent from a personal phone or outside the office.
That's actually a useful clarity for employees, not just firms. Good records protect the accused as well as the complainant, because investigations can run on evidence rather than competing recollections, which is a far better outcome for everyone involved than a he-said-she-said standoff.
Where do firms start?
None of this is solved by policy updates alone. In practice, closing the gap comes down to four things:
1) Firms first need to know where the gaps actually are - mapping which work-related conversations happen on channels that aren't currently captured (WhatsApp and other messaging apps being the obvious starting point) before deciding what to do about them. There's no point tuning detection on top of a capture regime that's missing half the conversation.
2) Once the channels are covered, surveillance itself needs to widen. Most firms' existing lexicons and monitoring were built for market abuse and financial crime - insider dealing, market manipulation, that kind of language. NFM calls for a different layer on top: language and sentiment analysis tuned to harassment, bullying and exclusionary behaviour, flagging patterns for a person to review rather than triggering anything automatically. The FCA's line on proportionality applies here as much as anywhere - this is about surfacing what's already in scope, not casting a wider net over people's private lives.
3) The two teams that need to work from the same evidence are compliance/surveillance and HR, and today they often don't. A flagged conversation is only useful if it reaches the right team, with the right confidentiality, in time to act on it, which means an actual escalation path between the two functions, not an assumption that someone will notice.
4) And finally, capture on its own isn't enough, a firm also needs to be able to retrieve the right conversation quickly enough to support an investigation, and in a form that stands up when it feeds into a Fit and Proper assessment or a regulatory reference. Records that exist but take weeks to reconstruct don't help much when an allegation lands.
What happens next?
While there’s unlikely to be an immediate flood of enforcement action, the test will come when the first serious cases surface and firms have to show, in practice, that the controls and investigation processes they say they have actually work. Early on, expect some firms to be cautious while legal teams work out exactly where the boundaries sit. The FCA's own statement that it doesn't expect blanket surveillance should keep that caution from tipping into overreach.
But there's a bigger structural point underneath this. Financial institutions have spent the better part of two decades improving how they capture trading and business communications, largely driven by market abuse and best execution requirements. Non-financial misconduct gives firms another reason, a distinct one, rooted in conduct and culture rather than market integrity, why fragmented, off-channel communications are a regulatory liability rather than just an operational inconvenience. The firms that struggle will be the ones that discover, after an incident, that the evidence they needed was sitting in a disappearing message or on a channel they never had access to in the first place.
And that’s a gap VoxSmart can help close - not by watching more of what people say, but by making sure the work-related conversations that firms are already obliged to capture are actually there, searchable and defensible, when a regulator or an investigation asks for them.
If you're working through what this rule means for your firm's communications surveillance and evidence gaps, get in touch for a conversation.
%20(1).png)

