When HR becomes a regulatory matter: the FCA’s new guidance on non-financial misconduct

From 1 September 2026, new FCA guidance makes explicit what many in financial services have long suspected: how people behave towards one another is no longer solely an HR issue, but a regulatory one. In this video briefing, Tom Walker and Hester Jewitt examine what is changing, and what firms need to do before September arrives.

What is actually new here?

It might be assumed that this is nothing firms have not already had to deal with. To an extent, that is correct: a regulated individual convicted of a serious crime has always been a fitness and propriety concern, regardless of whether the offence was financial in nature. What has changed is the clarity.

Until now, the FCA’s Code of Conduct (COCON) and its fitness and propriety rules (FIT) were built around examples of financial misconduct, such as insider dealing or market abuse. Firms, particularly those outside banking, were often left uncertain as to whether bullying, harassment or violence towards a colleague would breach the rules, because COCON traditionally required misconduct to connect back to a firm’s regulated activities. In practice, this meant financial wrongdoing was covered, while most other conduct fell into a grey area.

The new guidance closes that gap and gives the FCA’s rulebook a specific, detailed definition of serious harassment, bullying, and violence towards colleagues.

The origins of this change are worth noting. Much of the impetus traces back to a letter from the FCA to the chair of the Commons Women and Equalities Committee, written in response to the #MeToo movement, which warned that a culture tolerating sexual harassment is one that discourages people from speaking up, with consequences for talent retention and the quality of a firm’s decision-making.

However, the rules that have emerged are not limited to sexual harassment. They are aimed at any bullying conduct towards colleagues. ‘Colleagues’ is defined more broadly than many firms might expect – it covers not only direct employees, but also contractors and other service providers.

Defining the conduct: harassment, bullying, and where the line sits

The new definition borrows directly from the Equality Act: unwanted conduct that has the purpose or effect of violating someone’s dignity, or of creating an intimidating, hostile, degrading, humiliating or offensive environment.

Two points are worth noting. First, unlike harassment under the Equality Act, the FCA’s version does not require any link to a ‘protected characteristic’ – eg it is not limited to conduct connected to sex or race, and captures bullying more broadly. Second, violent conduct is also expressly included.

How is it determined whether particular conduct meets that definition? The assessment combines subjective and objective factors. Where conduct was intended to violate someone’s dignity, that is generally sufficient. Where it was not, the focus shifts to effect: how the conduct was perceived, and whether it was reasonable for it to have had that impact. If the person on the receiving end did not feel harassed, the test is not met; equally, an unreasonably sensitive reading of ordinary behaviour will not meet it either.

The office is not the only place this applies

One of the more practically significant aspects of the new guidance concerns scope. COCON applies only to conduct that is work-related; private life, by contrast, is a matter for FIT, not COCON. However, ‘work-related’ extends further than many firms may assume.

Consider a common scenario: colleagues in a pub after work. Where this is effectively a continuation of a work event, or a manager is present, or a direct report feels obliged to attend because their manager invited them, that pressure can be sufficient to bring the conduct within scope, even though it occurred outside the office and outside working hours.

Meeting the definition is only the first stage. The conduct must also be sufficiently serious to constitute a breach. The FCA has set out a multi-factor test for assessing this: whether the conduct was repeated, its duration, its impact on the person affected, any imbalance of seniority or power, whether there were previous warnings, and whether the conduct was criminal or serious enough to justify dismissal in its own right.

It is not only the harasser who is exposed

Perhaps the most significant point for firms to absorb is that COCON liability does not stop with the person responsible for the misconduct. A manager who fails to act can breach COCON 2, the rule requiring due care, skill and diligence, in their own right. That liability arises where a manager had the authority to intervene and did not, where they knew or reasonably should have known what was happening and failed to act.

It also arises where their firm’s policies and controls were not operating effectively, or where complaints were not dealt with appropriately. In practice, this means an investigation into a single incident may need to consider two individuals: the person accused of the misconduct, and the manager who was aware of it and did nothing.

Where this leaves fitness and propriety

A COCON breach will usually trigger a fitness and propriety assessment, but the two tests are not the same, and not every COCON breach will mean an individual is no longer fit and proper. The FIT assessment weighs the seriousness of the conduct – particularly where it involves dishonesty, breach of trust, or violence – alongside the vulnerability of the victim and whether the behaviour was a one-off or part of a pattern. Importantly, genuine remorse and insight, and steps taken to address the behaviour, are recognised as mitigating factors.

Conduct that falls outside COCON’s scope entirely, because it occurred in an individual’s private life, can still be relevant to a FIT assessment, provided it points to a material risk that the individual might breach regulatory requirements in their professional role. The threshold is important here – a remote or speculative risk is not sufficient. However, the FCA’s own guidance gives examples of where the line sits – violent or sexually inappropriate conduct, for instance, may indicate a material risk of similar conduct towards customers or colleagues in future.

What organisations should be doing before September 2026

The practical guidance from this episode is clear and actionable.

  1. Training should be refreshed now, with particular focus on line managers, and it makes sense to align this with training on the new duty to prevent sexual harassment under the Employment Rights Act, given the overlap between the two obligations.
  2. HR and compliance teams need clear guidance on how to investigate and apply the new rules. Policies should be current and properly understood, not only by those who might raise a complaint, but by those responsible for handling complaints and intervening when they observe an issue.

A point that bears repeating: a live regulatory concern does not permit a firm to bypass its usual employment process. Natural justice remains important to the FCA. The appropriate response to a reported incident is an objective, evidence-based investigation, conducted jointly between HR and compliance, rather than a rush to discipline because the underlying facts appear clear-cut. Decisions should be reasoned and evidence-based, both to justify a firm’s position to the regulator and to withstand any employment claim that follows. Any confirmed COCON or FIT breach must also be reflected accurately in that individual’s regulatory reference.

For further information, or to discuss how these changes affect your organisation, please contact Tom Walker or Hester Jewitt.

Related expertise