Written by a human
How to meet expanded non-financial misconduct rules: A practical guide
Download Global Relay’s practical non-financial misconduct guide for non-bank firms. Explore the FCA’s expanded rules, key compliance obligations, and how communications capture, surveillance, archiving, and investigation tools can help your firm build a defensible NFM control framework.
Since September 1, 2026, the Financial Conduct Authority’s (FCA) expanded non-financial misconduct rules have applied to approximately 37,000 non-bank firms subject to the Senior Managers and Certification Regime (SMCR).
Serious bullying, harassment, violence, and other forms of misconduct can now breach the FCA’s Conduct Rules (COCON), where there is a sufficient connection to work. This makes non-financial misconduct more than an employment or HR issue: it’s a regulatory, compliance, and business risk.
Download this practical guide to understand how the rules have evolved, what the FCA expects from firms, and how communications data can help you identify, investigate, and evidence potential non-financial misconduct.
Moving from policies to evidence
Many firms have updated their policies, introduced seriousness frameworks, and trained employees on the new requirements. However, the FCA has made clear that its attention is turning to how firms address non-financial misconduct in practice.
This creates an important question for compliance teams: can your firm demonstrate that its controls are working?
Doing so requires more than written policies. Firms need access to complete, reliable, and searchable communications data across the channels employees use for business. Without this evidence, it may be difficult to identify patterns of behavior, assess the seriousness of an allegation, or demonstrate that appropriate action was taken.
What does the non-financial misconduct guide cover?
The guide explores five key obligations created by the expanded rules:
- Capture relevant business communications: Gain oversight of the channels where work-related conduct may occur, including email, mobile messaging, collaboration platforms, voice, video, and social media.
- Document seriousness assessments: Use historical evidence and cross-channel context to understand whether an incident forms part of a wider pattern of behaviour.
- Demonstrate management accountability: Show that managers took reasonable steps to identify, prevent, and respond to non-financial misconduct.
- Support fitness and propriety assessments: Ensure relevant disciplinary outcomes and conduct concerns can feed into annual FIT reviews.
- Report serious misconduct: Maintain a defensible record of notification decisions, including the evidence used when deciding whether to report an incident to the FCA.
Building a defensible non-financial misconduct framework
This non-financial misconduct guide also explains how Global Relay can help firms capture communications, detect potential risks, preserve evidence, and conduct defensible investigations within a single platform.
With comprehensive channel capture, contextual communications surveillance, tamper-proof archiving, identity-aware search, legal holds, and complete audit trails, firms can create a clearer and more defensible record of how potential misconduct was handled.
Role-based access controls and ring-fenced workspaces also allow compliance, legal, and HR teams to work from a consistent source of information while maintaining appropriate separation and data protection controls.
Download the guide to learn how your firm can turn its non-financial misconduct policies into practical, evidence-based controls and how Global Relay can help you meet non-financial misconduct rules.