Written by a human
Non-Financial Misconduct in Financial Services
In brief:
- What it is: workplace behavior such as bullying, harassment, discrimination, and violence is treated by the FCA as a conduct issue, not just an HR matter.
- What’s changing: a new FCA Conduct Rule, COCON 1.1.7FR, extends the rules on serious non-financial misconduct to non-bank firms.
- When: 1 September 2026 (applies only to conduct on or after that date; no retrospective effect).
- Who’s affected: around 37,000 non-bank firms authorized under FSMA, plus their in-scope staff.
- Why it matters: exposure now spans Conduct Rule breaches, fitness-and-propriety assessments, and regulatory references.
What it is · Why regulators care · How we got here · Types · How common it is · How it’s regulated · What changes in September 2026 · Detection and prevention · How to prepare · FAQ
What is non-financial misconduct?
Non-financial misconduct (NFM) is workplace behavior, such as bullying, harassment, sexual harassment, discrimination, violence, and intimidation that harms colleagues or undermines a firm’s culture, as distinct from misconduct involving money, markets, or client assets. In financial services, the Financial Conduct Authority (FCA) treats serious non-financial misconduct as a matter of regulatory concern, not just an internal HR issue, because it goes to an individual’s fitness to work in the industry and to the health of a firm’s culture.
There is no single statutory definition of non-financial misconduct. It is an umbrella term the FCA uses to capture personal misconduct that is not, on its face, about financial wrongdoing but that can still breach conduct standards and call an individual’s fitness and propriety into question. The bottom line for regulated firms: behavior that damages people and culture is now squarely inside the regulatory perimeter. Firms are expected to identify it, act on it, and in serious cases, report it.
This guide explains what non-financial misconduct covers, why regulators care, how it is regulated in the UK, what changes on 1 September 2026, and what firms should be doing to prepare.
Why does non-financial misconduct matter to regulators?
The FCA’s position is that non-financial misconduct is misconduct, plain and simple. Conduct is the regulator’s core mandate, and behavior that violates a colleague’s dignity or creates a hostile working environment is treated as inconsistent with the FCA’s statutory objectives, protecting consumers, protecting market integrity, and promoting effective competition.
If people don’t feel safe calling out a bullying or harassment problem, are they likely to call out a risky trade?
The reasoning connects culture to risk in three ways:
- Misconduct is caught first by colleagues, not regulators. In a firm where people feel safe to speak up, problems surface early. In a firm that tolerates harassment or bullying, the same culture of silence that suppresses a harassment complaint can suppress a warning about a bad trade, a mis-selling problem, or a control failure.
- Homogeneity breeds blind spots. Discrimination and exclusionary behavior keep diverse perspectives out of the room, and groupthink is a recognized risk factor for poor decision-making.
- Bad behavior clusters. Firms with high levels of non-financial misconduct often have weaker financial conduct records, and there is a documented link between abusive communication and other misconduct such as market abuse.
The FCA therefore sees non-financial misconduct as a leading indicator of wider conduct and governance weakness. For firms, it now carries regulatory exposure on three fronts at once: a possible breach of the Conduct Rules, a mark against an individual’s fitness and propriety, and an obligation that can surface in regulatory references when that person moves firms.
How did the rules get here?
- 2018: The FCA sets out that non-financial misconduct is “misconduct, plain and simple.” After it spoke out, the regulator received its highest-ever number of whistleblower disclosures, roughly triple the previous year.
- September 2023: The FCA publishes CP23/20, proposing a framework on diversity, inclusion, and non-financial misconduct.
- March 2025: The FCA confirms it will not pursue the broader diversity and inclusion proposals, but will proceed with the non-financial misconduct work.
- July 2025: The FCA issues CP25/18, finalizing the new Conduct Rule for non-banks and consulting on supporting guidance.
- 12 December 2025: The FCA publishes Policy Statement PS25/23, settling the final Handbook guidance in COCON and FIT and bringing its policy work on non-financial misconduct to a close.
- 1 September 2026: The new rule and guidance come into force.
The FCA has said its focus now shifts from policy-making to how firms tackle non-financial misconduct in practice, in other words, supervisory scrutiny.
What are the main types of non-financial misconduct?
Non-financial misconduct is a category, not a single behavior. The most commonly recognized forms include:
- Bullying and harassment: the most frequently reported category, covering intimidating, hostile, or degrading treatment of colleagues.
- Sexual harassment: unwanted conduct of a sexual nature, reinforced by a proactive employer duty under the Worker Protection Act 2023.
- Discrimination: less favorable treatment connected to a protected characteristic such as age, race, sex, disability, religion, or sexual orientation.
- Violence and intimidation: physical aggression or threats, treated as among the most serious forms.
- Victimization and retaliation: punishing someone for raising a concern, which can itself be a conduct breach.
- Other personal misconduct: a broad residual category firms report as including alcohol or substance misuse in a work context, and inappropriate or offensive language in communications, whether spoken or electronic.
The new Conduct Rule (below) focuses specifically on bullying, harassment, and violence; the wider list above describes non-financial misconduct as a category. The breadth of the “other” group is telling: a large share of incidents do not fit a named box, which is part of why consistent identification is so hard and why the behavior surfaces across so many channels, from meetings to messaging apps.
How common is non-financial misconduct?
The most authoritative data comes from the FCA’s own culture and non-financial misconduct survey, published in October 2024, the first comprehensive data-gathering exercise of its kind. The FCA compelled responses from 1,028 wholesale firms (investment banks, brokers, and wholesale insurers), covering 2021 to 2023 across a combined workforce of roughly 326,000 employees.
The headline findings:
- Reported incidents rose across the three-year period, both in absolute terms and per 1,000 employees.
- Bullying and harassment (26%) and discrimination (23%) were the most reported categories, with a large “other” group (41%) underlining how hard personal misconduct is to categorize.
- Firms detected incidents mainly through formal grievance processes (50%) and whistleblowing, alongside firm-led detection methods including surveillance.
- Disciplinary or other action was taken in 43% of cases; violence, intimidation, and sexual harassment were more likely to result in dismissal.
- 62% of reported discrimination incidents and 47% of bullying and harassment incidents were not upheld, and only around 1% of incidents were not investigated at all, pointing to how difficult these cases are to substantiate.
- The overwhelming majority of firms said they would include non-financial misconduct in a regulatory reference.
The FCA noted the data can be read more than one way, as a high number of complaints can signal a healthy speak-up culture rather than a worse workplace, but described the survey as a baseline, implying further data collection to come. Most respondents also asked the FCA for further guidance, which is why the finalized COCON and FIT guidance is as detailed as it is.
How is non-financial misconduct regulated?
In the UK, non-financial misconduct is governed through the FCA’s conduct framework rather than a single dedicated rule. Three components matter most.
The Senior Managers and Certification Regime (SM&CR) is the accountability framework underneath all of this. For a full explanation, see our guide to the Senior Managers and Certification Regime.
The Code of Conduct sourcebook (COCON) contains the Conduct Rules that apply to staff. Two individual rules do the work for non-financial misconduct: Conduct Rule 1 (act with integrity) and Conduct Rule 2 (act with due skill, care, and diligence). Serious harassment, bullying, or violence toward a colleague can breach these rules.
The Fit and Proper test (FIT) governs whether an individual is suitable to hold their role. Non-financial misconduct can be relevant to a fitness and propriety assessment, in some circumstances even when it occurs outside work, and can affect certification, approvals, and what a firm must disclose in a regulatory reference.
Until now there has been an important asymmetry between banks and non-banks. In banks, COCON has applied broadly. In non-banks, it has applied more narrowly, mainly to conduct connected to regulated activities, meaning fewer non-financial misconduct incidents fell within scope. That gap is what the 2026 change closes.
What’s changing on 1 September 2026?
On 1 September 2026, a new rule, COCON 1.1.7FR, comes into force, extending the Conduct Rules so that serious non-financial misconduct is explicitly captured for non-bank firms, bringing them into line with banks. The rule reaches all FCA-authorized firms with a Part 4A permission under the Financial Services and Markets Act 2000 (FSMA) and their staff subject to the Conduct Rules — on the FCA’s estimate, around 37,000 non-bank SM&CR firms.
The essentials of the new rule and finalized guidance:
- What it captures. Unwanted conduct toward a colleague that is either violent, or has the purpose or effect of violating that person’s dignity or creating an intimidating, hostile, degrading, humiliating, or offensive environment.
- Who counts as a colleague. Fellow employees, employees of group companies, and contractors’ staff, not only direct employees.
- Purpose or effect. A breach can arise from the effect of the conduct on the recipient or from its purpose, so intent to harass can count even where an abusive message is intercepted or deleted before it is seen.
- Extended scope for non-banks. Previously the Conduct Rules for non-banks generally applied only to regulated activities. The rule expands this to bullying, harassment, and violence toward any colleague where there is a sufficient work-related link.
- Seriousness threshold. Only serious misconduct is in scope. The FCA declined to give an exhaustive definition, so firms must exercise judgment and document how they reached it. Relevant factors include the purpose of the conduct, the seniority of those involved, and whether there is a pattern of behavior.
- Protected characteristics are not required. The FCA deliberately did not limit the rule to conduct linked to a protected characteristic, so it reaches a wider range of behavior than the employment-law harassment test. Where conduct does relate to one, that increases its seriousness.
- Managerial accountability. A manager can breach Conduct Rule 2 if they fail to take reasonable steps to prevent harassment, or fail to take complaints seriously.
- Regulatory references. Serious, substantiated cases must be included in regulatory references, stopping individuals leaving one firm under a cloud and joining another with a clean record.
- No retrospective effect. The rule applies only to misconduct occurring on or after 1 September 2026.
- Clients versus colleagues. The new rule focuses on conduct toward colleagues; work-related misconduct toward clients was already within the existing rules.
For ongoing analysis, see our coverage of the FCA’s broader non-financial misconduct rules and the FCA’s final NFM guidance.
Where’s the line between work and private life?
This is the question firms find hardest, and the FCA’s finalized guidance is designed to draw a workable boundary.
For the Conduct Rules (COCON), purely private-life conduct is out of scope. The rule is about workplace behavior toward colleagues and conduct connected to the firm’s activities. Context matters at the edges: conduct at a firm-organized or client event may still count as work-related, particularly where attendance felt obligatory, while genuinely personal, off-duty behavior generally does not. To help firms apply this, the FCA added a scenario table to its guidance (COCON 1.3.7G):
| In scope (COCON applies) | Out of scope (private life) |
| Misconduct on firm premises, such as at a workplace Christmas party | Misconduct involving family members at home |
| Remote-working interactions on Zoom or Slack | Private social events, such as a wedding, not organized by the firm |
| Offsite training, award ceremonies, or client events | Commuting on public transport, unless with a colleague |
| Social media posts using work-issued devices | Personal social media use, unless it results in workplace bullying |
For fitness and propriety (FIT), the boundary is different. Private conduct can be relevant, but only where it is serious enough to suggest a material risk of future regulatory breach, or where it would undermine confidence in the individual’s suitability. The FCA has been explicit about the limits: firms are not expected to monitor employees’ private lives or private social media, and are not required to investigate trivial or implausible allegations.
Consider a senior manager who, in a personal capacity, participates in an anonymous online forum that harasses people based on protected characteristics, but where the police find insufficient evidence for a prosecution. The firm can face a governance deadlock, an approved individual in a regulated role while under a cloud with no criminal finding to lean on. The FCA has stressed that it expects firms to have effective systems in place to identify and mitigate risks of all kinds. Regulatory conclusions are also independent of employment and criminal outcomes: a firm can reach a view even where an employment claim settles or no conviction follows.
There is a legitimate concern on the other side, that firms could be pushed toward policing employees’ private lives. The guidance tries to hold the line by keeping COCON focused on work. For more on getting that balance right, see our analysis of surveillance and employee privacy.
How does non-financial misconduct affect fitness and propriety, and regulatory references?
Even where a piece of conduct does not breach the Conduct Rules, it can still matter for fitness and propriety. The FIT framework asks whether an individual has the honesty, integrity, and reputation to perform their role, and non-financial misconduct can weigh directly on that judgment. This is also the route by which serious private conduct can become relevant, not because the regulator polices private lives, but because it can indicate a real risk that the person will fall short of regulatory standards.
This is where a finding follows someone from firm to firm, the reference obligation becomes portable. When a certified or approved person moves firms, the outgoing firm must provide a regulatory reference, and serious, substantiated non-financial misconduct findings can fall within what must be disclosed. In the FCA’s survey, the overwhelming majority of firms said they would include it. The effect is that a finding does not simply disappear when someone changes employer.
How can firms detect and prevent non-financial misconduct?
Effective firms treat detection and prevention as a layered system rather than a single control.
- Culture and tone from the top. A culture where the behavior is genuinely not tolerated and where senior managers model it. Regulators look at whether standards are reflected in real decisions, including remuneration and promotion.
- Speak-up and whistleblowing channels. Safe, trusted routes to raise concerns, backed by anti-retaliation measures. Retaliation can itself be a conduct breach.
- Governance and management information. Boards and senior committees need regular reporting on conduct and culture, including non-financial misconduct and whistleblowing trends. The survey exposed how many firms lacked this.
- Bridging HR and compliance. Historically, surveillance sat with compliance and non-financial misconduct with HR. Keeping them siloed is now a risk. Build a unified escalation workflow that routes behavioral alerts to both, with access controls that let HR review alerts without unnecessarily exposing sensitive financial data.
- Clear policy boundaries. Because conduct can breach the rules even where the recipient never saw the message, update acceptable-use policies to address intent-based misconduct, and use metadata to help triage whether an alert is genuinely work-related. WORM-compliant logging provides a defensible audit trail for deleted or edited communications.
Detection in business communications. A large share of non-financial misconduct such as, offensive, abusive, or intimidating language happens in the channels firms already capture. The FCA’s survey recognized firm-led detection, including communications surveillance, as one route by which incidents come to light. Surveillance will not fix culture on its own and is no substitute for a healthy speak-up environment, but keyword matching struggles with hostile-environment cases, for example, a senior manager repeatedly using dismissive or intimidating language toward a junior colleague across Slack. Context-aware monitoring that detects patterns of power imbalance or exclusionary language gives firms a proactive way to surface behavior that never reaches a formal grievance.
The goal across every layer is proportionate, defensible, and documented: catching serious behavior without overreaching into people’s private lives.
How should firms prepare before September 2026?
With the rule applying only to conduct from 1 September 2026, firms have a clear runway.
- Review and update policies so non-financial misconduct is explicitly embedded in Conduct Rules and fitness-and-propriety frameworks.
- Align with employment law, checking disciplinary policies, the definition of gross misconduct, and grievance procedures work alongside the regulatory rules.
- Refresh training for all Conduct Rules staff on scope, the seriousness threshold, and the work/private-life boundary.
- Bridge HR and compliance with a unified escalation workflow and appropriate access controls.
- Strengthen governance so boards receive regular conduct-and-culture reporting.
- Reinforce speak-up channels and anti-retaliation protections.
- Build proportionate detection and escalation, including communications monitoring calibrated to flag potentially abusive content for review, without monitoring private lives.
- Document judgment. Because the rule hinges on what counts as ‘serious’, and that’s a judgment call, the most valuable thing a firm can build right now is a clear, well-documented decision trail.
Firms that treat this as a culture program rather than a compliance checkbox will be best placed when supervisory scrutiny intensifies.
Frequently asked questions
Is non-financial misconduct a criminal offense?
No. It is a regulatory and conduct concept, not a criminal one, although some underlying behavior (such as assault) may also be a crime. A regulatory finding can be reached independently of any criminal outcome.
Does the new rule apply to banks or non-banks?
Both are in scope of the standards, but the 1 September 2026 change specifically extends the Conduct Rules for non-banks so their position aligns with banks, where serious non-financial misconduct was already broadly captured.
Can something in my private life count as non-financial misconduct?
Not under the Conduct Rules, which focus on workplace conduct. Private conduct can be relevant to a fitness and propriety assessment where it is serious enough to suggest a real risk to regulatory standards or public confidence. Firms are not expected to monitor employees’ private lives.
Does non-financial misconduct have to relate to a protected characteristic?
No. The FCA deliberately did not limit the rule to conduct linked to a protected characteristic, so it reaches a broader range of behavior than the employment-law harassment test. Where one is involved, it is treated as increasing seriousness.
Do firms have to monitor employees’ communications for non-financial misconduct?
There is no rule requiring communications monitoring specifically for this purpose, and firms must not monitor private lives. Many firms already capture and supervise business communications for market-conduct reasons, and that same monitoring can surface offensive or abusive language for proportionate human review.
What is the difference between non-financial misconduct and financial misconduct?
Financial misconduct involves money, markets, or client assets, for example fraud, market abuse, or mis-selling. Non-financial misconduct involves interpersonal and cultural behavior such as bullying, harassment, and discrimination. Both can breach conduct standards and affect fitness and propriety.
When do the new non-financial misconduct rules take effect?
The new Conduct Rule for non-banks (COCON 1.1.7FR) and the accompanying FCA guidance come into force on 1 September 2026 and apply only to conduct occurring on or after that date.
How Global Relay helps
Ready to strengthen your non-financial misconduct detection?
The FCA now expects firms to detect and act on serious non-financial misconduct — including abusive or harassing language in business communications. Global Relay Surveillance uses AI-enabled, context-aware monitoring across email, chat, collaboration tools, and voice to identify genuine conduct risk while filtering out noise — helping compliance and HR teams flag and escalate the warning signs before they become a regulatory matter. Learn more about Global Relay’s communications monitoring.
Related reading: