Written by a human

Non-Financial Misconduct in Financial Services

Global Relay Compliant business communications archiving, messaging, supervision, and eDiscovery
17 mins read 14 August 2026

In brief:

  • What it is: workplace behavior such as bullying, harassment, discrimination, and violence is treated by the FCA as a conduct issue, not just an HR matter.
  • What’s changing: a new FCA Conduct Rule, COCON 1.1.7FR, extends the rules on serious non-financial misconduct to non-bank firms.
  • When: 1 September 2026 (applies only to conduct on or after that date; no retrospective effect).
  • Who’s affected: around 37,000 non-bank firms authorized under FSMA, plus their in-scope staff.
  • Why it matters: exposure now spans Conduct Rule breaches, fitness-and-propriety assessments, and regulatory references.

What it is · Why regulators care · How we got here · Types · How common it is · How it’s regulated · What changes in September 2026 · Detection and prevention · How to prepare · FAQ

Non-financial misconduct (NFM) is workplace behavior, such as bullying, harassment, sexual harassment, discrimination, violence, and intimidation that harms colleagues or undermines a firm’s culture, as distinct from misconduct involving money, markets, or client assets. In financial services, the Financial Conduct Authority (FCA) treats serious non-financial misconduct as a matter of regulatory concern, not just an internal HR issue, because it goes to an individual’s fitness to work in the industry and to the health of a firm’s culture.

There is no single statutory definition of non-financial misconduct. It is an umbrella term the FCA uses to capture personal misconduct that is not, on its face, about financial wrongdoing but that can still breach conduct standards and call an individual’s fitness and propriety into question. The bottom line for regulated firms: behavior that damages people and culture is now squarely inside the regulatory perimeter. Firms are expected to identify it, act on it, and in serious cases, report it.

Why does non-financial misconduct matter to regulators?

The FCA’s position is that non-financial misconduct is misconduct, plain and simple. Conduct is the regulator’s core mandate, and behavior that violates a colleague’s dignity or creates a hostile working environment is treated as inconsistent with the FCA’s statutory objectives, protecting consumers, protecting market integrity, and promoting effective competition.

If people don’t feel safe calling out a bullying or harassment problem, are they likely to call out a risky trade?

The reasoning connects culture to risk in three ways:

  • Misconduct is caught first by colleagues, not regulators. In a firm where people feel safe to speak up, problems surface early. In a firm that tolerates harassment or bullying, the same culture of silence that suppresses a harassment complaint can suppress a warning about a bad trade, a mis-selling problem, or a control failure.
  • Homogeneity breeds blind spots. Discrimination and exclusionary behavior keep diverse perspectives out of the room, and groupthink is a recognized risk factor for poor decision-making.
  • Bad behavior clusters. Firms with high levels of non-financial misconduct often have weaker financial conduct records, and there is a documented link between abusive communication and other misconduct such as market abuse.

How did the rules get here?

  • 2018: The FCA sets out that non-financial misconduct is “misconduct, plain and simple.” After it spoke out, the regulator received its highest-ever number of whistleblower disclosures, roughly triple the previous year.
  • September 2023: The FCA publishes CP23/20, proposing a framework on diversity, inclusion, and non-financial misconduct.
  • March 2025: The FCA confirms it will not pursue the broader diversity and inclusion proposals, but will proceed with the non-financial misconduct work.
  • July 2025: The FCA issues CP25/18, finalizing the new Conduct Rule for non-banks and consulting on supporting guidance.
  • 12 December 2025: The FCA publishes Policy Statement PS25/23, settling the final Handbook guidance in COCON and FIT and bringing its policy work on non-financial misconduct to a close.
  • 1 September 2026: The new rule and guidance come into force.

What are the main types of non-financial misconduct?

Non-financial misconduct is a category, not a single behavior. The most commonly recognized forms include:

  • Bullying and harassment: the most frequently reported category, covering intimidating, hostile, or degrading treatment of colleagues.
  • Sexual harassment: unwanted conduct of a sexual nature, reinforced by a proactive employer duty under the Worker Protection Act 2023.
  • Discrimination: less favorable treatment connected to a protected characteristic such as age, race, sex, disability, religion, or sexual orientation.
  • Violence and intimidation: physical aggression or threats, treated as among the most serious forms.
  • Victimization and retaliation: punishing someone for raising a concern, which can itself be a conduct breach.
  • Other personal misconduct: a broad residual category firms report as including alcohol or substance misuse in a work context, and inappropriate or offensive language in communications, whether spoken or electronic.

How common is non-financial misconduct?

The most authoritative data comes from the FCA’s own culture and non-financial misconduct survey, published in October 2024, the first comprehensive data-gathering exercise of its kind. The FCA compelled responses from 1,028 wholesale firms (investment banks, brokers, and wholesale insurers), covering 2021 to 2023 across a combined workforce of roughly 326,000 employees.

The headline findings:

  • Reported incidents rose across the three-year period, both in absolute terms and per 1,000 employees.
  • Bullying and harassment (26%) and discrimination (23%) were the most reported categories, with a large “other” group (41%) underlining how hard personal misconduct is to categorize.
  • Firms detected incidents mainly through formal grievance processes (50%) and whistleblowing, alongside firm-led detection methods including surveillance.
  • Disciplinary or other action was taken in 43% of cases; violence, intimidation, and sexual harassment were more likely to result in dismissal.
  • 62% of reported discrimination incidents and 47% of bullying and harassment incidents were not upheld, and only around 1% of incidents were not investigated at all, pointing to how difficult these cases are to substantiate.
  • The overwhelming majority of firms said they would include non-financial misconduct in a regulatory reference.

How is non-financial misconduct regulated?

In the UK, non-financial misconduct is governed through the FCA’s conduct framework rather than a single dedicated rule. Three components matter most.

The Senior Managers and Certification Regime (SM&CR) is the accountability framework underneath all of this. For a full explanation, see our guide to the Senior Managers and Certification Regime.

The Code of Conduct sourcebook (COCON) contains the Conduct Rules that apply to staff. Two individual rules do the work for non-financial misconduct: Conduct Rule 1 (act with integrity) and Conduct Rule 2 (act with due skill, care, and diligence). Serious harassment, bullying, or violence toward a colleague can breach these rules.

The Fit and Proper test (FIT) governs whether an individual is suitable to hold their role. Non-financial misconduct can be relevant to a fitness and propriety assessment, in some circumstances even when it occurs outside work, and can affect certification, approvals, and what a firm must disclose in a regulatory reference.

What’s changing on 1 September 2026?

On 1 September 2026, a new rule, COCON 1.1.7FR, comes into force, extending the Conduct Rules so that serious non-financial misconduct is explicitly captured for non-bank firms, bringing them into line with banks. The rule reaches all FCA-authorized firms with a Part 4A permission under the Financial Services and Markets Act 2000 (FSMA) and their staff subject to the Conduct Rules — on the FCA’s estimate, around 37,000 non-bank SM&CR firms.

The essentials of the new rule and finalized guidance:

  • What it captures. Unwanted conduct toward a colleague that is either violent, or has the purpose or effect of violating that person’s dignity or creating an intimidating, hostile, degrading, humiliating, or offensive environment.
  • Who counts as a colleague. Fellow employees, employees of group companies, and contractors’ staff, not only direct employees.
  • Purpose or effect. A breach can arise from the effect of the conduct on the recipient or from its purpose, so intent to harass can count even where an abusive message is intercepted or deleted before it is seen.
  • Extended scope for non-banks. Previously the Conduct Rules for non-banks generally applied only to regulated activities. The rule expands this to bullying, harassment, and violence toward any colleague where there is a sufficient work-related link.
  • Seriousness threshold. Only serious misconduct is in scope. The FCA declined to give an exhaustive definition, so firms must exercise judgment and document how they reached it. Relevant factors include the purpose of the conduct, the seniority of those involved, and whether there is a pattern of behavior.
  • Protected characteristics are not required. The FCA deliberately did not limit the rule to conduct linked to a protected characteristic, so it reaches a wider range of behavior than the employment-law harassment test. Where conduct does relate to one, that increases its seriousness.
  • Managerial accountability. A manager can breach Conduct Rule 2 if they fail to take reasonable steps to prevent harassment, or fail to take complaints seriously.
  • Regulatory references. Serious, substantiated cases must be included in regulatory references, stopping individuals leaving one firm under a cloud and joining another with a clean record.
  • No retrospective effect. The rule applies only to misconduct occurring on or after 1 September 2026.
  • Clients versus colleagues. The new rule focuses on conduct toward colleagues; work-related misconduct toward clients was already within the existing rules.

Where’s the line between work and private life?

This is the question firms find hardest, and the FCA’s finalized guidance is designed to draw a workable boundary.

For the Conduct Rules (COCON), purely private-life conduct is out of scope. The rule is about workplace behavior toward colleagues and conduct connected to the firm’s activities. Context matters at the edges: conduct at a firm-organized or client event may still count as work-related, particularly where attendance felt obligatory, while genuinely personal, off-duty behavior generally does not. To help firms apply this, the FCA added a scenario table to its guidance (COCON 1.3.7G):

In scope (COCON applies)Out of scope (private life)
Misconduct on firm premises, such as at a workplace Christmas partyMisconduct involving family members at home
Remote-working interactions on Zoom or SlackPrivate social events, such as a wedding, not organized by the firm
Offsite training, award ceremonies, or client eventsCommuting on public transport, unless with a colleague
Social media posts using work-issued devicesPersonal social media use, unless it results in workplace bullying

For fitness and propriety (FIT), the boundary is different. Private conduct can be relevant, but only where it is serious enough to suggest a material risk of future regulatory breach, or where it would undermine confidence in the individual’s suitability. The FCA has been explicit about the limits: firms are not expected to monitor employees’ private lives or private social media, and are not required to investigate trivial or implausible allegations.

Consider a senior manager who, in a personal capacity, participates in an anonymous online forum that harasses people based on protected characteristics, but where the police find insufficient evidence for a prosecution. The firm can face a governance deadlock, an approved individual in a regulated role while under a cloud with no criminal finding to lean on. The FCA has stressed that it expects firms to have effective systems in place to identify and mitigate risks of all kinds. Regulatory conclusions are also independent of employment and criminal outcomes: a firm can reach a view even where an employment claim settles or no conviction follows.

How does non-financial misconduct affect fitness and propriety, and regulatory references?

Even where a piece of conduct does not breach the Conduct Rules, it can still matter for fitness and propriety. The FIT framework asks whether an individual has the honesty, integrity, and reputation to perform their role, and non-financial misconduct can weigh directly on that judgment. This is also the route by which serious private conduct can become relevant, not because the regulator polices private lives, but because it can indicate a real risk that the person will fall short of regulatory standards.

How can firms detect and prevent non-financial misconduct?

Effective firms treat detection and prevention as a layered system rather than a single control.

  • Culture and tone from the top. A culture where the behavior is genuinely not tolerated and where senior managers model it. Regulators look at whether standards are reflected in real decisions, including remuneration and promotion.
  • Speak-up and whistleblowing channels. Safe, trusted routes to raise concerns, backed by anti-retaliation measures. Retaliation can itself be a conduct breach.
  • Governance and management information. Boards and senior committees need regular reporting on conduct and culture, including non-financial misconduct and whistleblowing trends. The survey exposed how many firms lacked this.
  • Bridging HR and compliance. Historically, surveillance sat with compliance and non-financial misconduct with HR. Keeping them siloed is now a risk. Build a unified escalation workflow that routes behavioral alerts to both, with access controls that let HR review alerts without unnecessarily exposing sensitive financial data.
  • Clear policy boundaries. Because conduct can breach the rules even where the recipient never saw the message, update acceptable-use policies to address intent-based misconduct, and use metadata to help triage whether an alert is genuinely work-related. WORM-compliant logging provides a defensible audit trail for deleted or edited communications.

Detection in business communications. A large share of non-financial misconduct such as, offensive, abusive, or intimidating language happens in the channels firms already capture. The FCA’s survey recognized firm-led detection, including communications surveillance, as one route by which incidents come to light. Surveillance will not fix culture on its own and is no substitute for a healthy speak-up environment, but keyword matching struggles with hostile-environment cases, for example, a senior manager repeatedly using dismissive or intimidating language toward a junior colleague across Slack. Context-aware monitoring that detects patterns of power imbalance or exclusionary language gives firms a proactive way to surface behavior that never reaches a formal grievance.

How should firms prepare before September 2026?

With the rule applying only to conduct from 1 September 2026, firms have a clear runway.

  1. Review and update policies so non-financial misconduct is explicitly embedded in Conduct Rules and fitness-and-propriety frameworks.
  2. Align with employment law, checking disciplinary policies, the definition of gross misconduct, and grievance procedures work alongside the regulatory rules.
  3. Refresh training for all Conduct Rules staff on scope, the seriousness threshold, and the work/private-life boundary.
  4. Bridge HR and compliance with a unified escalation workflow and appropriate access controls.
  5. Strengthen governance so boards receive regular conduct-and-culture reporting.
  6. Reinforce speak-up channels and anti-retaliation protections.
  7. Build proportionate detection and escalation, including communications monitoring calibrated to flag potentially abusive content for review, without monitoring private lives.
  8. Document judgment. Because the rule hinges on what counts as ‘serious’, and that’s a judgment call, the most valuable thing a firm can build right now is a clear, well-documented decision trail.

Frequently asked questions

Is non-financial misconduct a criminal offense?

No. It is a regulatory and conduct concept, not a criminal one, although some underlying behavior (such as assault) may also be a crime. A regulatory finding can be reached independently of any criminal outcome.

Does the new rule apply to banks or non-banks?

Both are in scope of the standards, but the 1 September 2026 change specifically extends the Conduct Rules for non-banks so their position aligns with banks, where serious non-financial misconduct was already broadly captured.

Can something in my private life count as non-financial misconduct?

Not under the Conduct Rules, which focus on workplace conduct. Private conduct can be relevant to a fitness and propriety assessment where it is serious enough to suggest a real risk to regulatory standards or public confidence. Firms are not expected to monitor employees’ private lives.

Does non-financial misconduct have to relate to a protected characteristic?

No. The FCA deliberately did not limit the rule to conduct linked to a protected characteristic, so it reaches a broader range of behavior than the employment-law harassment test. Where one is involved, it is treated as increasing seriousness.

Do firms have to monitor employees’ communications for non-financial misconduct?

There is no rule requiring communications monitoring specifically for this purpose, and firms must not monitor private lives. Many firms already capture and supervise business communications for market-conduct reasons, and that same monitoring can surface offensive or abusive language for proportionate human review.

What is the difference between non-financial misconduct and financial misconduct?

Financial misconduct involves money, markets, or client assets, for example fraud, market abuse, or mis-selling. Non-financial misconduct involves interpersonal and cultural behavior such as bullying, harassment, and discrimination. Both can breach conduct standards and affect fitness and propriety.

When do the new non-financial misconduct rules take effect?

The new Conduct Rule for non-banks (COCON 1.1.7FR) and the accompanying FCA guidance come into force on 1 September 2026 and apply only to conduct occurring on or after that date.

How Global Relay helps

Ready to strengthen your non-financial misconduct detection? 

The FCA now expects firms to detect and act on serious non-financial misconduct — including abusive or harassing language in business communications. Global Relay Surveillance uses AI-enabled, context-aware monitoring across email, chat, collaboration tools, and voice to identify genuine conduct risk while filtering out noise — helping compliance and HR teams flag and escalate the warning signs before they become a regulatory matter. Learn more about Global Relay’s communications monitoring.

Related reading:

Global Relay Compliant business communications archiving, messaging, supervision, and eDiscovery
17 mins read 14 August 2026