What happened

Rules that let the Financial Conduct Authority take action over bullying, harassment and acts of violence at work came into effect on 1 September 2026 and now cover around 37,000 additional UK financial services firms, extending well beyond banks. The change is meant to counter poor workplace culture and inconsistent treatment across the sector.

The mechanism is a new conduct rule, COCON 1.1.7FR, which extends the conduct rules in non-banking firms to cover bullying, harassment or violence against colleagues where there is a sufficient work related link. It does not apply retrospectively and it does not widen the FCA's remit beyond Senior Managers and Certification Regime financial activities. Serious, substantiated cases of poor personal behaviour will also need to be shared through regulatory references, in the same way financial misconduct already is.

Alongside the rule, the FCA published guidance covering the boundary between work and private life, how non-financial misconduct can breach the conduct rules, the reasonable steps expected of managers, and fitness and propriety assessments that take in private life, social media and unproven allegations.

Why this is a GRC story

This is a regulator treating culture as a risk control. The FCA's own framing is that behaviour like bullying going unchallenged is a red flag about a firm's decision making and risk management. That is a claim about control effectiveness, not about human resources policy, and it is the reason the rule lands in the conduct rulebook rather than in employment guidance.

The reporting line between HR and compliance has to change. What was previously handled as an internal people matter can now create a regulatory reporting obligation and a regulatory reference entry. Firms whose HR and compliance functions do not share a view of the same incident will produce inconsistent outcomes, and the inconsistency itself is the exposure.

Regulatory references raise the stakes for individuals. Serious substantiated findings follow a person between firms, which is precisely the intent: it removes the option of leaving the consequence behind when changing employer. That also means the accuracy of the reference becomes a governance issue in its own right.

Scope is narrower than it looks. The rule applies to FSMA firms with a Part 4A permission. Payments and e-money firms, regulated investment exchanges and credit rating agencies sit outside it, because the senior managers regime does not reach them.

What to watch

Watch whether supervisory scrutiny follows the rules. The FCA has said its policy work on this topic is complete and its attention is shifting to how firms apply the regime in practice, which usually shows up as thematic reviews and targeted information requests. Firms should expect questions about conduct breach reporting volumes, how fitness and propriety assessments handle private life evidence, and what managers actually did when an issue was raised. The practical work now is making sure staff policies, breach reporting and reference processes describe the same standard.

Attribution: Analysis based on Compliance Week's reporting and the FCA's published rules and guidance on non-financial misconduct. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News