Governance, risk and compliance for FCA-regulated firms: SM&CR, financial crime, Consumer Duty.

Running the compliance function including monitoring plans, policy and record management, regulatory change and training and competence.

A practical guide to building a policy management framework for UK regulated firms, covering the policy lifecycle, ownership, approval and rule mapping.
7 min read
How to build an FCA-compliant training and competence scheme, from the competent employees rule in SYSC to TC qualifications, supervision and CPD.
7 min read
How UK firms track FCA rule changes through CPs, PSs and Handbook Notices, use the Regulatory Initiatives Grid, and meet their SYSC compliance duties.
7 min read
A practical guide to FCA record-keeping requirements under SYSC 9, plus the retention periods set by COBS, DISP and the Money Laundering Regulations 2017.
8 min read
How UK MAR defines insider dealing, unlawful disclosure and market manipulation, what inside information is, and when a firm must submit a STOR to the FCA.
9 min read
Design a CMP that supports testing, evidence capture, and governance reporting.
16 min read
Common safeguarding breaks and how to evidence reconciliations.
14 min readConsumer Duty and conduct obligations including fair value, vulnerable customers, complaints handling and financial promotions.

How the FCA defines vulnerable customers, the four drivers of vulnerability, key Financial Lives figures and what FG21/1 and the Consumer Duty require.
7 min read
A source-checked guide to financial promotions compliance: the section 21 restriction, the fair, clear and not misleading rule and the approver gateway.
9 min read
How to run a fair value assessment under Consumer Duty. PRIN 2A.4 rules, FG22/5 guidance, manufacturer and distributor duties, and how to evidence value.
9 min read
What the annual Consumer Duty board report must contain, what the governing body must approve, and the FCA's good and poor practice from its review.
7 min read
How complaints handling works under the FCA DISP sourcebook: what a complaint is, the 8 week and 3 business day deadlines, and ombudsman referrals.
8 min read
Complete guide to FCA Consumer Duty implementation for payment institutions, EMIs, and fintechs including outcomes monitoring, fair value, and governance requirements.
16 min read
Track Consumer Duty outcomes with MI, governance, and fair value evidence.
15 min read
Build a compliant promotion workflow with approvals, versioning, and evidence.
15 min readAnti-money-laundering and financial crime controls including CDD, EDD, PEP screening, SARs, sanctions, transaction monitoring and source of funds.

How UK firms build sanctions screening controls that meet OFSI and FCA expectations, covering lists, name matching, reporting and penalties.
10 min read
A practical UK guide to writing and filing a suspicious activity report: the legal duty, the SAR Portal, DAML consent, tipping off and a good SAR.
8 min read
A UK guide to writing a business-wide financial crime risk assessment under MLR 2017 reg 18, the FCA Financial Crime Guide, SYSC 6.3 and JMLSG.
9 min read
Build a compliant AML framework under the Money Laundering Regulations 2017: risk assessment, CDD, the MLRO, SAR reporting, training and audit.
8 min read
How transaction monitoring meets the Money Laundering Regulations, what the FCA expects on tuning and alerts, and the link to suspicious activity reports.
8 min read
Understand the difference between source of funds and source of wealth, when UK firms must establish each under the MLRs, and how to evidence both.
8 min read
How to run PEP screening under the UK Money Laundering Regulations 2017 and FCA guidance: definitions, senior sign-off, source of wealth and monitoring.
8 min read
How to run KYC and customer due diligence onboarding under the Money Laundering Regulations 2017: when CDD applies, the three levels and monitoring.
7 min read
When enhanced due diligence is required under the Money Laundering Regulations 2017, the measures it involves, and how it differs from standard CDD.
8 min read
Build a compliant AML risk assessment framework for payment institutions and EMIs that satisfies FCA and JMLSG requirements.
15 min readSenior managers and certification regime, board governance, statements of responsibilities, fitness and propriety, conduct rules and whistleblowing.

How FCA firms build whistleblowing arrangements under SYSC 18: the whistleblowers' champion, internal arrangements, employee comms and settlement rules.
9 min read
A practical UK guide to writing a Statement of Responsibilities under the FCA Senior Managers Regime, covering SUP 10C.11 and common errors.
7 min read
SM&CR explained for UK solo-regulated firms: the three pillars, Core, Enhanced and Limited Scope tiers, SMFs, responsibilities and conduct rules.
9 min read
Run fitness and propriety assessments under the FCA's SM&CR: the three FIT factors, who to assess, annual reviews, references and criminal checks.
7 min read
How to deliver Conduct Rules training, capture attestations and meet FCA notification duties under COCON, from who is covered to REP008 reporting.
8 min read
How FCA-regulated firms meet board governance expectations under SYSC 4, including the management body, board committees, and links to the SM&CR.
8 min read
Why Excel-based SM&CR solutions create risk and how purpose-built software delivers better outcomes for FCA-regulated firms.
12 min read
How to build responsibilities maps that meet FCA expectations and support accountability.
14 min readOperational resilience, third-party and outsourcing risk, cyber security, the ICARA process and UK GDPR data protection.

How UK GDPR applies to financial firms: the six principles, lawful bases, individual rights, the 72-hour breach rule and the data protection fee.
10 min read
How UK firms should manage outsourcing risk under FCA SYSC 8, FG16/5 cloud guidance and the critical third parties regime, from due diligence to exit.
9 min read
A practical guide to the ICARA process under the FCA's IFPR: the overall financial adequacy rule, threshold requirements, wind-down planning and MIF007.
8 min read
How FCA firms should manage cyber risk: operational resilience, SYSC governance, reporting material incidents, the ICO 72-hour rule and NCSC controls.
8 min read
Meet FCA operational resilience requirements with practical guidance on important business services, impact tolerances, scenario testing, and self-assessment.
14 min readFCA reporting and notification duties including RegData, REP-CRIM, the RMAR, the MLRO annual report and Principle 11 breach reporting.

How FCA regulatory reporting works: what RegData is, how returns are scheduled, who must submit REP-CRIM under SUP 16.23, common returns and deadlines.
7 min read
A practical guide to the RMAR return: which firms submit it, what sections A to K cover, how often you report and the 30 working day deadline in RegData.
7 min read
How Principle 11 and SUP 15 shape what you must tell the FCA, which events require notification, the timing, and how to submit a breach report.
8 min read
What to put in your MLRO annual report under SYSC 6.3.9R, the FCA Financial Crime Guide and JMLSG guidance: systems and controls, SARs, training and more.
9 min readEnterprise risk management including risk assessments, risk appetite statements and key risk indicators.

A UK guide to the enterprise-wide risk assessment under SYSC 4 and SYSC 7: risk categories, appetite, inherent vs residual risk and the three lines.
10 min read
A practical UK guide to writing a risk appetite statement, with the SYSC 7 and FSB definitions of appetite, capacity, tolerance and limits.
7 min read
What a key risk indicator is, how KRIs differ from KPIs and KCIs, and how to set thresholds, escalation and board MI under FCA SYSC 7 and Basel guidance.
10 min read