Ben Parker, CEO, eflow
The FCA’s new non-financial misconduct (NFM) rules have just come into effect. From 1st September onwards, any instances of NFM and any failures to report it from that point on will mean individuals and firms could be subject to regulatory action. As the FCA defines, NFM is “behaviour that is not of a clearly financial nature such as bullying, harassment and violence”.
Currently, the scope of rules for non-banking firms relates to certain conduct that is tied to their financial services activity or transactions. But the expanded scope as part of a new Code of Conduct (COCON) rule – COCON 1.1.7FR – means that any form of NFM will come under the regulations “if there is a sufficient work-related link”. The rules also include updated guidance for NFM with regards to the Fit and Proper test.
When new rules come into force, it can be easy for organisations to put off taking action until they are required to report on any relevant cases. But this is a high-risk strategy, one that will leave them immediately exposed to enforcement while also playing catch-up with getting their compliance systems up to speed.
Taking action on the changes, however, is not without its challenges too. Firms need to update their internal policies and operational infrastructure to ensure they have both the process and system capability to meet these updated regulatory expectations.
The dangers of not taking action – and why a reactive strategy is risky
Research has revealed that the vast majority of firms (77%) believe the new rules will have a limited impact on the business. But this mindset could catch them out.
Until now, for non-banking firms, employee misconduct of a non-financial nature would be treated as an HR issue. This might provide the impression that any cases of NFM can simply be reported on by compliance teams as an extension of any HR investigations that take place. Yet these investigations can be complex and sensitive, requiring more time and resources to adequately identify, document and then escalate any instances of NFM.
Simple tweaks to policies and processes are unlikely to meet the necessary reporting threshold the new rules are bringing in. Compliance teams are also unlikely to have extensive experience in dealing with incidents of NFM, meaning a lack of preparation could impact how they evidence and report cases to the FCA while also eating into their wider capacity. And with a reactive reporting strategy, many cases might get missed altogether.
These unresolved situations can continue to impact internal culture and affected individuals and escalate into far more serious instances of NFM, resulting in greater reputational damage and regulatory punishment. That’s why prevention and investigations need to become joint compliance and HR activities to help proactively mitigate NFM as well as improve the processing and reporting of cases.
How to identify and overcome the conduct gap
Two key challenges non-banking firms face in order to meet the new rules is having the ability to identify NFM and then gather evidence of it. As they haven’t had to report on this type of misconduct before, it’s possible that many will still have a conduct gap between what these new regulatory expectations say they should be assessing and their operational capability to do so. Therefore, it’s imperative that firms evaluate their capability to perform both of these steps to see how much of a conduct gap they may or may not have.
For example, many of these organisations will have systems that are able to monitor financial transactions and certain internal communications channels. While the former won’t generally be applicable for the new rules, internal comms can provide key indicators of NFM – but as this is a new type of regulatory misconduct, these systems won’t be calibrated to detect it effectively.
However, what these teams might not be aware of is that the latest eComms surveillance technology can provide them with the ability to automatically monitor and review comms data in real time for examples of NFM. Not only does this enable them to proactively identify NFM, but any message sent on a firm’s digital communication channels is archived, building a detailed bank of evidence that can be easily audited by regulators. Compliance teams can also search through this data to support oversight and escalation requirements.
A lesson for trade surveillance
The arrival of the new rules also provides a lesson for trade surveillance and the need to build adaptable infrastructure. Regulations are constantly changing in line with emerging trends or threats, so systems need to be adaptable and have the ability to be recalibrated for aspects such as new market typologies or asset classes. But the NFM rules show how wider elements that have traditionally sat outside of ‘financial activity’ can suddenly come under regulatory scrutiny.
So, the more interoperable infrastructure is, the better connections can be made between different datasets. The NFM changes are an apt example of having systems that can monitor eComms as well as trade data, capabilities that have become essential for effectively monitoring for market abuse. This interconnectivity is also paramount for internal collaboration too.
Compliance traverses many departments. With the new NFM rules, HR and compliance will need to work closely to ensure that systems are correctly flagging NFM and that any investigations are being documented and reported properly. Reactive investigations are still necessary for compliance. But if they form the sole strategy for a firm, it will be on the back foot when it comes to reporting NFM in a timely manner – and may even miss signs completely. This could result in unanticipated regulatory action arriving at their door.


