✔ UK Insurance Resources ✔ Trusted UK Insurance Resource ✔ Free Insurance Guides

FCA Non-Financial Misconduct Rules and Insurance UK

What the FCA's new non-financial misconduct guidance, in force from 1 September 2026, means for UK insurers, brokers, their directors and senior managers, and how it connects to D&O and management liability insurance.

Quick Answer

From 1 September 2026, new FCA guidance on non-financial misconduct (NFM) comes into force, alongside a new rule, COCON 1.1.7FR, added to the Code of Conduct sourcebook. Set out in Policy Statement PS25/23, published 12 December 2025, the guidance clarifies that serious bullying, harassment or violence between colleagues, where it relates to an individual's role, can breach the FCA's Individual Conduct Rules, and explains how such conduct feeds into the Fit and Proper test (FIT) for Senior Managers and Certified staff. It applies to all firms with FCA Part 4A permission, including UK insurers, brokers and other insurance intermediaries, bringing non-bank firms' Conduct Rules scope much closer into line with banks. The rules don't create new employment law or make non-financial misconduct insurable in itself, but they do raise the practical stakes for individual directors and senior managers at regulated insurance firms, which is why reviewing D&O and management liability cover alongside compliance preparation is worth doing ahead of the September 2026 start date.

Key Takeaways

In force from 1 September 2026

New COCON rule and FCA guidance on non-financial misconduct start on this date.

Applies to all Part 4A firms

Includes UK insurers, brokers and other insurance intermediaries, not just banks.

Seriousness threshold applies

Only sufficiently serious bullying, harassment or violence is captured, not ordinary workplace friction.

Feeds into Fit and Proper assessments

Can affect whether a Senior Manager or Certified individual is judged fit and proper.

Regulatory references affected

Verified serious incidents must be disclosed when staff move between regulated firms.

Not new employment law

It's regulatory guidance on existing Conduct Rules, sitting alongside, not replacing, the Equality Act 2010.

About the Editor

Waqas Mehmood — Founder

Waqas Mehmood is the Founder of ShopTera and oversees its editorial standards. He is not an insurance professional or adviser. ShopTera publishes educational insurance information and does not give regulated advice.

About ShopTera

This guide has been researched and reviewed in line with our Editorial Policy and Fact-Checking Policy.

ShopTera provides educational insurance content for UK consumers and businesses. Our mission is to simplify insurance topics and help people make informed decisions.

Editorial Team · Editorial Policy · Fact-Checking Policy · Corrections Policy

Table of Contents

Introduction

On 1 September 2026, a change most UK consumers will never hear about takes effect deep inside the FCA's rulebook, but one that matters a great deal to anyone who runs, manages, or holds a senior role at an FCA-authorised insurer, broker or other insurance intermediary. New guidance on non-financial misconduct, and a new Code of Conduct rule, formalise how serious workplace bullying, harassment and violence are treated as a regulatory matter, not just an employment one. This guide explains what the FCA has actually changed, who it affects across the insurance sector, and where it connects to directors' and officers' insurance and management liability cover.

This guide complements our existing Directors' and Officers' Insurance UK and Management Liability Insurance UK guides, and our guide to Checking FCA Authorisation for an Insurer or Broker.

Key Terms Explained

Non-Financial Misconduct (NFM)
Workplace conduct such as bullying, harassment, discrimination, victimisation or violence, which the FCA's guidance clarifies can amount to a breach of its Conduct Rules when sufficiently serious.
COCON
The FCA's Code of Conduct sourcebook, setting out the Individual Conduct Rules that apply to most people working in FCA-regulated firms.
FIT
The Fit and Proper test for Employees and Senior Personnel sourcebook, used to assess whether someone is suitable to perform a Senior Management Function or Certification Function role.
Part 4A Permission
The core authorisation granted under the Financial Services and Markets Act 2000 allowing a firm to carry out regulated activities, including insurance underwriting and distribution.
Regulatory Reference
A structured reference certain FCA-regulated firms must provide about a departing employee's conduct history when they move to another regulated firm in specified roles.

Why This Matters

For insurance firms and their leadership, this matters because it changes non-financial misconduct from something handled purely as an internal HR and employment law issue into something with direct regulatory consequences, including the potential to affect an individual's Fit and Proper status, their career prospects at other regulated firms via regulatory references, and in serious cases, FCA enforcement action against the individual concerned. For anyone holding, or considering taking on, a Senior Management Function or Certified role at a UK insurer or broker, understanding where this new threshold sits, and how it interacts with the personal legal protection D&O insurance is designed to provide, is now a genuinely practical governance question, not an abstract compliance topic.

Background and Timeline

The road to this guidance began in September 2023, when the FCA published CP23/20, a consultation on a broader regulatory framework for diversity and inclusion in the financial sector, which included initial proposals touching on non-financial misconduct. In March 2025, the FCA announced it would not take that broader diversity and inclusion framework further, but would continue its specific work on non-financial misconduct. That work was set out in CP25/18, published in July 2025, which consulted on changing the Conduct Rules to better capture non-financial misconduct at non-bank firms and on whether further Handbook guidance was needed. The consultation closed in September 2025, and the FCA published its final Policy Statement, PS25/23, on 12 December 2025, confirming the guidance and the accompanying new rule, COCON 1.1.7FR, both of which come into force on 1 September 2026.

Expert Tip: The FCA has said this policy statement "brings our policy work on NFM to a close" for now, and that it will next focus on how firms are tackling non-financial misconduct in practice, meaning supervisory attention on how firms actually apply these rules is likely to follow the September 2026 start date, not stop there.

What the New Rule and Guidance Actually Change

It's worth being precise about what has and hasn't changed. The FCA is amending its Code of Conduct (COCON) sourcebook to add guidance explaining how non-financial misconduct can be a breach of the existing Individual Conduct Rules, principally Conduct Rule 1 (acting with integrity) and Conduct Rule 2 (acting with due skill, care and diligence). It is also explaining, through the Fit and Proper test (FIT) sourcebook, how non-financial misconduct should inform assessments of whether someone is fit and proper to hold a regulated role. The stated aim is to help firms interpret and apply the existing rules more consistently, and to help them make fair, decisive judgements when standards are breached.

What hasn't changed is the underlying legal framework for workplace conduct itself. The Equality Act 2010, and the wider law on harassment, discrimination and victimisation, continues to apply exactly as before. This is regulatory guidance operating alongside that law, giving the FCA an additional lever, tied to a firm's or individual's regulatory standing, rather than replacing employment tribunal routes or criminal law where relevant.

Who Is Affected in the Insurance Sector

According to the FCA's own publication, PS25/23 applies to all firms authorised under the Financial Services and Markets Act 2000 with Part 4A permission, and to staff in those firms who are subject to COCON or FIT. In practical terms for the insurance sector, this includes UK-authorised insurers, insurance intermediaries and brokers holding Part 4A permission, and by extension the individuals in those firms performing Senior Management Functions, Certification Functions, or otherwise subject to the Conduct Rules. Appointed Representatives operating under a principal firm's permission sit in a slightly different position, since Part 4A permission sits with the principal, but principals remain responsible for the conduct standards expected of their Appointed Representatives' relevant staff.

Warning: Don't assume this only affects large insurers or banks. The guidance is explicitly designed to bring non-bank firms, a category that includes the great majority of UK insurance intermediaries and many smaller insurers, into closer alignment with the Conduct Rules scope that has applied to banks for longer.

The Seriousness Threshold Explained

A central feature of the final guidance is that not every instance of poor workplace behaviour will breach the Conduct Rules. The FCA's guidance is clear that the conduct in question must be sufficiently serious, using language such as conduct that is "violating dignity", "degrading" or "humiliating". The Policy Statement sets out factors firms should weigh when assessing seriousness, including the pattern of behaviour (isolated incident versus repeated conduct), its duration, the impact on those affected, the seniority of those involved, and whether the conduct could amount to a criminal offence.

This matters for insurance firms designing or updating their internal investigation processes: a single sharp exchange in a stressful claims-handling period is not automatically non-financial misconduct in the FCA's sense, but a sustained pattern of degrading treatment by a senior manager toward a junior colleague plainly could be, particularly where it reflects on that manager's own integrity and fitness to hold a regulated role.

Banks vs Non-Banks: What's Changing

Before this guidance and rule change, the practical scope of Conduct Rules coverage for non-financial misconduct was narrower and less consistently applied at non-bank firms, including most insurers and brokers, than at banks, where a wider set of staff had long been subject to more developed expectations in this area. The changes taking effect on 1 September 2026 are widely reported as extending equivalent Conduct Rules scope to a further roughly 37,000 non-bank regulated firms, bringing insurers, asset managers and other non-bank firms much closer into line with the banking sector's existing approach.

AspectBefore 1 September 2026 (non-banks, incl. most insurers/brokers)From 1 September 2026
NFM and Conduct RulesLess developed, less consistently applied FCA guidance for non-banksExplicit Handbook guidance clarifying NFM can breach Individual Conduct Rules 1 and 2
Fit and Proper assessmentsNFM considered case-by-case, without dedicated FIT guidanceDedicated guidance on how NFM should inform Fit and Proper assessments
Alignment with banksNarrower Conduct Rules scope than banks in practiceScope brought much closer into line with the banking sector
Regulatory referencesExisting regulatory reference regime, less specific NFM focusVerified serious NFM incidents expected to be captured on staff moves

The Individual Conduct Rules in Practice

The FCA's Individual Conduct Rules already require, among other things, that a person subject to them acts with integrity (Conduct Rule 1) and acts with due skill, care and diligence (Conduct Rule 2). The new guidance explains, rather than replaces, how these existing rules can be breached by serious non-financial misconduct. In practice, this means an insurance firm investigating a serious bullying or harassment complaint involving a Certified or Senior Manager-level individual now needs to consider not just internal disciplinary and employment law consequences, but whether the conduct also amounts to a Conduct Rule breach requiring notification to the FCA and reflection in that person's fitness and propriety record.

The Fit and Proper Test and Senior Managers

The Fit and Proper test for Employees and Senior Personnel (FIT) is the framework firms and the FCA use to judge whether someone is suitable to perform a Senior Management Function or Certification Function role, assessing honesty, integrity and reputation, competence and capability, and financial soundness. The new guidance explains how evidence of serious non-financial misconduct should be factored into that assessment. This is significant for insurance firm boards and HR functions because it means a documented finding of serious non-financial misconduct is not simply a historical HR matter once resolved internally; it can become a live consideration in whether that individual remains fit and proper to continue in, or be approved for, a senior regulated role, potentially years later at the same or a different firm.

Which Insurance Roles Are Typically Certified Functions

Under the Certification Regime, firms themselves, rather than the FCA directly, are responsible for assessing and certifying that certain staff are fit and proper on an ongoing basis, at least annually. In insurance firms, roles that commonly fall within Certification Functions include those with significant management responsibility below Senior Manager level, staff dealing with clients in an advisory or discretionary capacity, and, depending on the firm's structure, some claims-handling and underwriting roles carrying material decision-making authority. Because the non-financial misconduct guidance feeds into Fit and Proper assessments, firms need to be clear internally about exactly which roles are Certified Functions, since it's the firm's own certification decision, not just an FCA one, that first has to grapple with how a serious non-financial misconduct finding affects an individual's certification.

Expert Tip: If you're unsure whether a role at your firm is a Certification Function, check your firm's own Senior Managers and Certification Regime mapping documentation, or ask your compliance function directly, rather than assuming customer-facing or supervisory seniority alone determines the answer.

Regulatory References: What Changes

UK financial services firms, including many insurers and larger brokers, already operate a regulatory reference regime requiring structured references to be given when certain staff move between regulated firms, covering matters relevant to fitness and propriety over a set look-back period. From September 2026, the expectation sharpens specifically around non-financial misconduct: verified, serious incidents are expected to be disclosed through these regulatory references, meaning a documented finding at one firm can genuinely follow an individual to their next role at another regulated firm, rather than remaining a purely internal matter.

Expert Tip: If your firm gives or receives regulatory references, review your process now for how findings of serious non-financial misconduct will be recorded, verified and disclosed, since getting this wrong, whether by over-disclosing unverified allegations or under-disclosing genuine findings, carries its own legal and regulatory risk.

Record-Keeping and Data Protection in NFM Investigations

Investigating and recording non-financial misconduct necessarily involves handling sensitive personal data, about both the person raising a concern and the person accused, and firms need to balance the FCA's expectation of proper record-keeping with their obligations under UK GDPR and the Data Protection Act 2018. Records need to be detailed enough to support a fair, defensible Conduct Rule assessment and, where relevant, an accurate regulatory reference, while being retained, secured and shared only in ways consistent with data minimisation and confidentiality principles. Firms should also be alert to how internal investigation findings are described, since inaccurate or unverified allegations recorded as though established could create separate legal risk, including potential defamation or data protection complaints from the individual concerned.

Our GDPR and Data Breach Insurance UK guide covers the wider data protection compliance landscape relevant to firms handling sensitive HR and investigation records.

How This Fits With the Wider SM&CR Review

This non-financial misconduct guidance sits alongside, and is best understood in the context of, the FCA's broader ongoing review of the Senior Managers and Certification Regime (SM&CR), the framework that underpins individual accountability across UK financial services, including insurance. While the SM&CR review itself covers a wider set of questions about how the regime operates in practice, the non-financial misconduct guidance is a concrete, near-term illustration of the direction of travel: greater individual accountability, more consistent application across banks and non-banks, and closer linkage between workplace conduct and regulatory standing.

Compliance Obligations for Insurance Firms

For insurers and brokers with Part 4A permission, practical compliance work ahead of 1 September 2026 typically involves reviewing HR, grievance and whistleblowing procedures to ensure they can identify conduct that may meet the FCA's seriousness threshold; training Senior Managers and Compliance functions on how to assess and record potential Conduct Rule breaches arising from non-financial misconduct; updating regulatory reference processes and templates; and ensuring board-level oversight of how the firm is applying the new guidance, since governance failures here can themselves raise separate Conduct Rule and Senior Manager accountability questions.

What This Means for Directors' and Officers' Insurance

Directors' and officers' (D&O) insurance exists to help protect individual directors and senior managers against the personal financial consequences of claims and investigations arising from how they've carried out their role, typically including legal defence costs. With non-financial misconduct now more clearly capable of triggering an FCA-facing Conduct Rule or Fit and Proper issue for a Senior Manager or Certified individual at an insurance firm, the practical relevance of D&O cover responding to the cost of properly defending a regulatory investigation, rather than covering any underlying fine or the misconduct itself, becomes more direct for this sector. Firms and individuals should check specific policy wording carefully, since D&O policies vary in how they define "claim", whether regulatory investigations are covered from an early stage or only once formal proceedings begin, and how any conduct-based exclusions are worded.

Our Directors' and Officers' Insurance UK guide covers how this cover works, what it typically includes, and its common exclusions in more detail.

Management Liability and Employment Practices Liability

Many smaller and mid-sized insurance intermediaries hold a management liability policy, which commonly bundles D&O cover with employment practices liability (EPL), covering claims such as unfair dismissal, discrimination and harassment brought by employees, typically through the employment tribunal system. It's important to understand these are related but distinct exposures: EPL responds primarily to employment law claims brought by the affected employee, while the FCA's non-financial misconduct guidance operates on a separate regulatory track, concerned with the firm's and individual's standing with the FCA rather than compensating the complainant. A firm facing a serious non-financial misconduct incident could realistically face both an employment tribunal claim and a Conduct Rule notification process running in parallel, which is a good reason to review both elements of a management liability policy together rather than assuming one substitutes for the other.

Our Management Liability Insurance UK guide explains how D&O and EPL cover typically combine within a single policy.

Professional Indemnity Considerations for Brokers

For insurance brokers specifically, professional indemnity (PI) insurance, required as a condition of FCA authorisation for most intermediaries, is designed around claims arising from advice and services provided to clients, not from a firm's own internal workplace conduct. Non-financial misconduct within a broking firm doesn't typically engage PI cover directly, but board and Compliance functions should be alert to the indirect risk: a firm distracted by a serious internal conduct investigation, or one facing reputational damage from how it's handled, can see knock-on effects on service quality and client-facing standards that do carry PI-relevant risk, reinforcing why swift, proper handling of these matters protects the business on more than one front.

Practical Steps for Insurance Firms

With the 1 September 2026 start date now confirmed, sensible practical steps include reading the FCA's published guidance on non-financial misconduct and PS25/23 in full, briefing the board and Senior Managers on the seriousness threshold and its implications for Fit and Proper assessments, reviewing and if necessary updating HR investigation, whistleblowing and regulatory reference processes, providing targeted training to those responsible for conducting workplace investigations, and reviewing D&O and management liability insurance cover alongside independent legal advice on the firm's specific risk profile, rather than assuming existing cover automatically responds to this new regulatory dimension.

What Insurance Doesn't Cover Under This Regime

It's important to be realistic about the limits of insurance here. No insurance policy can, or should, be expected to cover the underlying cost or consequences of proven serious misconduct itself, and D&O and management liability policies typically exclude cover for deliberate, dishonest or criminal conduct once established. FCA fines and penalties imposed on a firm or individual are generally uninsurable as a matter of public policy. What D&O and, to a more limited extent, management liability cover can potentially help with is the cost of properly and fairly defending a regulatory investigation or Fit and Proper challenge, which is a materially different thing from insuring against the consequences of genuine wrongdoing.

Warning: Don't treat D&O insurance as a substitute for getting workplace conduct right. Insurance can help with the cost of a fair defence process; it cannot and does not protect a director or senior manager whose serious misconduct is properly established.

Common Mistakes to Avoid

  • Assuming this guidance only affects banks, when it's specifically designed to bring non-bank firms, including most insurers and brokers, into closer alignment.
  • Treating every workplace complaint as automatically meeting the FCA's seriousness threshold, or conversely dismissing genuinely serious patterns as "just personality clashes".
  • Assuming existing D&O or management liability cover automatically responds to Conduct Rule investigations without checking policy wording.
  • Failing to update regulatory reference processes ahead of the September 2026 start date.
  • Confusing this FCA regulatory guidance with a change to underlying employment law, which continues to apply separately.
  • Under-training Senior Managers and HR staff on how to properly record and assess potential Conduct Rule breaches arising from workplace conduct.

Common Myths

  • Myth: This is a brand-new law against workplace bullying. It's FCA regulatory guidance clarifying how existing Conduct Rules and the Fit and Proper test apply to non-financial misconduct; the underlying employment law was already in place separately.
  • Myth: Only very senior directors are affected. The Conduct Rules and, where relevant, the Certification Regime apply to a wide range of staff at regulated firms, not only Senior Management Function holders.
  • Myth: D&O insurance will cover any consequences of a non-financial misconduct finding. D&O cover is generally aimed at defence costs for a fair investigation process, not at insuring proven serious misconduct, which is typically excluded once established.
  • Myth: Minor workplace disagreements will now trigger FCA involvement. The guidance is explicit that conduct must meet a genuine seriousness threshold, considering pattern, duration, impact, seniority and criminality.

Real-World Examples

Example: Reviewing D&O Cover Ahead of September 2026

A mid-sized insurance broker's board asked its insurance adviser to review the wording of its D&O policy specifically around how it defined "claim" and whether early-stage FCA regulatory enquiries were covered, ahead of the new non-financial misconduct guidance taking effect.

Example: Updating Whistleblowing Procedures

A regional insurer updated its whistleblowing and grievance procedures to explicitly reference the FCA's non-financial misconduct guidance and seriousness factors, and provided refresher training to its HR investigators before the 1 September 2026 start date.

Example: Regulatory Reference Process Review

An insurance intermediary reviewed its regulatory reference template and internal record-keeping with its compliance consultant, to ensure verified findings of serious non-financial misconduct could be properly and consistently disclosed when relevant staff moved to another regulated firm.

Frequently Asked Questions

When do the FCA's non-financial misconduct rules take effect?

The FCA's guidance on non-financial misconduct, published in Policy Statement PS25/23 on 12 December 2025, comes into force on 1 September 2026, at the same time as the new rule COCON 1.1.7FR is added to the Code of Conduct sourcebook.

Does this create a new law against bullying and harassment at work?

No. It is regulatory guidance clarifying how existing FCA Conduct Rules apply to serious non-financial misconduct, and how such conduct feeds into the Fit and Proper test for Senior Managers and Certified staff. Employment law protections against harassment and discrimination, such as the Equality Act 2010, already exist separately.

Which insurance firms does this affect?

It applies to all firms authorised under the Financial Services and Markets Act 2000 with Part 4A permission, and to staff in those firms subject to the Code of Conduct or the Fit and Proper test. This includes UK insurers, insurance intermediaries and brokers, and Appointed Representatives working under a principal firm's Part 4A permission.

Does every instance of workplace conflict count as non-financial misconduct under FCA rules?

No. The FCA's guidance stresses that conduct must be sufficiently serious, considering factors such as pattern, duration, impact, seniority of those involved, and whether the conduct is criminal. Ordinary workplace disagreements or one-off minor issues are not automatically captured.

Can a non-financial misconduct finding affect a director's ability to hold a senior role in insurance?

Yes, potentially. Non-financial misconduct forms part of the Fit and Proper test the FCA and firms apply to Senior Managers and Certified staff, so a serious finding could affect an individual's fitness and propriety assessment, and from September 2026 verified serious incidents must be disclosed through regulatory references when staff move between regulated firms.

Does D&O insurance cover FCA enforcement action for non-financial misconduct?

Directors' and officers' insurance is typically designed to help with defence costs where a director or senior manager faces a regulatory investigation or enforcement action, subject to policy terms and exclusions. It generally cannot cover fines or penalties imposed as a matter of public policy, and cover for deliberate or dishonest conduct is usually excluded.

What should insurance firms do to prepare for the new rules?

Review the FCA's published guidance on non-financial misconduct, check that HR, whistleblowing and investigation processes can identify and record conduct rule breaches, train Senior Managers on the seriousness threshold, review regulatory reference processes, and review D&O and management liability cover alongside legal advice on the firm's specific exposure.

References and Editorial Standards

This guide is reviewed regularly by the ShopTera Editorial Team and reflects the Financial Conduct Authority's Policy Statement PS25/23, "Tackling non-financial misconduct in financial services", published 12 December 2025, together with the FCA's related published guidance on non-financial misconduct in financial services and its Consultation Paper CP25/18. The guidance and accompanying rule change come into force on 1 September 2026; firms should always check the FCA's own published Handbook material and take independent legal or compliance advice for their specific circumstances, since this guide is intended for general educational purposes only and does not constitute legal or regulatory advice.

VersionDateChange
1.022 August 2026Initial publication

Conclusion

The FCA's non-financial misconduct guidance doesn't rewrite employment law, but it does mark a real shift in how seriously workplace conduct at UK insurance firms is treated from a regulatory standpoint, bringing non-bank firms much closer into line with the standards long expected of banks. For insurers, brokers and the individuals who lead them, understanding the seriousness threshold, the link to Fit and Proper assessments and regulatory references, and how this connects to, and is limited by, D&O and management liability insurance, puts firms and their Senior Managers in a far stronger position as the 1 September 2026 start date approaches.

Next Steps

  • Read the FCA's Policy Statement PS25/23 and its published non-financial misconduct guidance in full.
  • Brief your board and Senior Managers on the seriousness threshold and Fit and Proper implications.
  • Review HR, whistleblowing and regulatory reference processes ahead of 1 September 2026.
  • Review your D&O and management liability insurance cover with your broker or adviser.

Explore More UK Insurance Guides

Browse Insurance Guides