Horizon Scanning and FCA Expectations: What UK Firms Must Demonstrate
In short
We found no FCA Handbook rule that names horizon scanning; the expectation is assembled from SYSC 6.1.1R, SYSC 4.1.1R, Principle 3 and Senior Manager Conduct Rule SC2. What supervisors can test is whether you can evidence what you saw, what you dismissed and who owned the next step, and the Citigroup Global Markets fine (GBP 12,553,800, for taking 18 months to assess a known rule change) shows what slow assessment costs.
We found no rule in the FCA Handbook that requires "horizon scanning" by name. As of 30 September 2026, the expectation is assembled from five Handbook locations: SYSC 6.1.1R (adequate policies and procedures to ensure compliance with "obligations under the regulatory system"), SYSC 4.1.1R (effective processes to identify, manage, monitor and report risks), SYSC 3.2.6R for insurers, Principle 3, and Senior Manager Conduct Rule SC2 (COCON 2.2.2R). If you are FCA-authorized, several of those bind you today.
To check that first sentence, we fetched 291 Handbook section pages across SYSC, PRIN, COCON, FIT, MIFIDPRU, SUP 15 and more than twenty other modules and searched them for the phrase. There were no hits for "horizon scanning." The Handbook's own search is a JavaScript application we could not query, so treat this as a scoped check and not a proof.
The absence of a named rule leaves your obligations intact and is a trap for firms that read the Handbook like a checklist. The test the FCA can apply is narrower than "do you scan." It is can you evidence what you saw, what you dismissed, and who owned what happened next. If your process cannot produce a dismissal log, it is closer to a newsletter subscription than to a process the FCA will find easy to accept. Below, each anchor is mapped to the evidence a supervisor can request, followed by a 17-row FCA-evidence checklist you can self-assess against this week and the enforcement record for firms that treated regulatory horizon scanning and change assessment as optional. For the discipline itself, start with what is regulatory horizon scanning; this piece is about what the FCA expects UK firms to demonstrate.
The FCA never wrote a horizon-scanning rule; it assembled one across five Handbook locations
The table below is the rule map. Wording comes from the live Handbook, read on 30 September 2026. The application column matters more than most commentary admits, so read it before quoting any of these at your board.
| Anchor | What it says (key wording) | Who it binds | As of |
|---|---|---|---|
| SYSC 6.1.1R | "establish, implement and maintain adequate policies and procedures sufficient to ensure compliance of the firm including its managers, employees and appointed representatives ... with its obligations under the regulatory system" | A rule for common platform firms, UCITS management companies and all "other" firms in SYSC 6 (for full-scope UK AIFMs it covers financial crime only; see SYSC 1 Annex 1) | In force 03/01/2018 |
| SYSC 6.1.2R and 6.1.2-AR | Policies "designed to detect any risk of failure by the firm to comply with its obligations." From 23 October 2025, common platform firms have SYSC 6.1.2-AR, tied to obligations under UK markets in financial instruments law | 6.1.2R is a rule for management companies and operators of electronic lending systems and guidance (6.1.2AG) for most other firms; 6.1.2-AR is a rule for common platform firms | 6.1.2R in force 01/01/2021; 6.1.2-AR from 23/10/2025 |
| SYSC 6.1.3R and 6.1.3-AR | A "permanent and effective compliance function which operates independently"; for common platform firms, reporting to the management body "at least on an annual basis" | Same application pattern: rule for management companies and P2P operators, guidance for other firms, SYSC 6.1.3-AR to -CR for common platform firms | 6.1.3R in force 09/12/2019; 6.1.3-AR from 23/10/2025 |
| SYSC 4.1.1R | "effective processes to identify, manage, monitor and report the risks it is or might be exposed to" | Broad application across authorized firms; insurers are under SYSC 3 instead | In force 03/01/2018 |
| SYSC 3.2.6R | "reasonable care to establish and maintain effective systems and controls for compliance with applicable requirements and standards under the regulatory system" | Insurers, managing agents and Lloyd's (who sit under SYSC 3, not SYSC 6) | In force 01/12/2001 |
| Principle 3, PRIN 2.1.1R | "take reasonable care to organise and control its affairs responsibly and effectively, with adequate risk management systems" | Effectively all authorized firms | Table version 31/07/2023 |
| Principle 11, PRIN 2.1.1R | "disclose to the FCA appropriately anything relating to the firm of which that regulator would reasonably expect notice" | Effectively all authorized firms | Same |
| SC2, COCON 2.2.2R | "You must take reasonable steps to ensure that the business of the firm for which you are responsible complies with the relevant requirements and standards of the regulatory system." | Every senior manager, personally, for their area | In force 07/03/2016 |
| PRIN 2A.8.3R to 2A.8.5R | The governing body reviews Consumer Duty outcomes and, under 2A.8.4R(3), assesses "whether the firm's future business strategy is consistent with its obligations under the Consumer Duty" | Firms in retail scope of the Consumer Duty | 2A.8.3R in force 31/07/2023; 2A.8.4R and 2A.8.5R reworded 26/06/2026 |
Read the middle column as one composite sentence and the expectation writes itself. You must maintain procedures sufficient to comply with a regulatory system that changes, detect risks of failing to comply with it (which logically includes rules that have been announced but not yet applied), identify and report those risks to your governing body, and have named senior managers taking "reasonable steps" over the whole thing. You cannot comply with obligations you have not noticed. Horizon scanning is the mechanism by which a firm can honestly claim its SYSC 6.1.1R procedures are "adequate" next year rather than last year.
Application varies by firm type, and parts of it are changing. Since 23 October 2025 the MiFID Organisational Regulation has no separate life: the FCA transferred its content into the Handbook (PS25/13), so common platform firms now find their policy and compliance-function duties in SYSC 6.1.2-AR and SYSC 6.1.3-AR to -CR, not in article 22 of that regulation. Insurers anchor in SYSC 3.2.6R, not SYSC 6. And the Consumer Duty reporting rules are moving: in CP26/23, which ran from 29 June to 18 September 2026, the FCA proposed that firms would not need a stand-alone Consumer Duty board report while proportionate reporting to the governing body continues at least annually, with final rules expected in the first quarter of 2027.
"Horizon scanning" is the FCA's own working vocabulary
If the Handbook is silent on the phrase, the FCA's supervisory material is not. Five primary sources, most recent first.
The regulator scans its own horizon and publishes the results. On 10 June 2026 the FCA released its first external Emerging Technology Horizon Scan, describing itself as wanting "to understand technological change to anticipate its outcomes and gain early insight on what it may mean for financial services and for us as a regulator." Be precise about what this document is: it describes the FCA's scanning, and it says it is "not a set of predictions or regulatory guidance." It does tell you the regulator considers the discipline core enough to institutionalize and publish.
Authorizations expects firms to speak for themselves. Sheree Howard, the FCA's executive director of Authorisations, told the APCC Spring Conference on 22 April 2026 (Getting firms fit to run, speech as drafted) that a firm's advisers are welcome in the room but the firm must be able to "speak for themselves" and "explain their business model and operations clearly, in their own words." Her pointed line for consultants: "When a firm sits down with us, it's their competence we're assessing. Not yours." The context was authorization interviews, not regulatory change, but the principle transfers. When the FCA asks how an incoming regime affects your firm, the answer has to come from your own impact work, not a forwarded law-firm briefing.
Supervision has already written the expectation down for operational resilience. The FCA's operational resilience insights page (28 May 2024) says it directly: "Horizon scanning to establish an understanding of new and emerging risks, and the proximity of impact, are key to ensuring testing is appropriate and that controls are in place to detect, respond and recover from operational disruptions, both current and in the future." The page is addressed to firms within the operational resilience rules, which include banks, building societies, insurers and enhanced-scope SM&CR firms, and it links scenario testing to new and emerging risks and their "proximity of impact."
Multi-firm reviews use the phrase as a marker of good and poor practice. In its review of sanctions systems and controls, the FCA wrote: "We consider this horizon scanning and scenario planning to be an important process for firms to adopt as part of their risk management procedures" (6 September 2023). In its March 2025 review of liquidity risk management in wholesale trading firms, it observed that "in their risk horizon scanning, firms were not considering emerging risks."
The newest FCA paper on evidence reads like a change-management checklist. The July 2026 outcomes monitoring paper describes good practice as "actions presented to senior governance forums included named owners, target dates and status updates," and for smaller firms proposes what amounts to a dismissal-and-action log: "straightforward records such as a log of issues, agreed actions and deadlines."
The FCA publishes much of the horizon for free, and it is the natural baseline for your source list
Nobody at the FCA expects a mid-size firm to run a global intelligence operation. What a supervisor can reasonably expect is that your source list includes the regulator's own forward-looking output, because it is free and addressed to you.
The centerpiece is the Regulatory Initiatives Grid. The 10th edition, published on 19 May 2026, lists 135 live initiatives on a 24-month forward view, a similar number to the previous edition, and joint initiatives make up 33% of them, which is why single-regulator feeds miss things. It is produced by the nine-member Financial Services Regulatory Initiatives Forum, which the FCA and the Bank of England/PRA co-chair, and the Grid is published twice a year. As of 1 October 2026 no 11th edition has been published or announced, so a board pack should cite the edition number and date it relies on. Around it sit the Handbook Notices, published roughly monthly (No. 144 came out on 25 September 2026), the nine annual Regulatory Priorities reports that replaced portfolio letters in February and March 2026, the annual work program, Dear CEO letters, and open consultations.
Here is the near-term UK horizon those sources currently show, the kind of key-dates table your own management information should contain (all rows as of 1 October 2026):
| Date | What changes | Primary source |
|---|---|---|
| 15 Jul 2026 (done) | Deferred payment credit (buy now, pay later) came under FCA regulation; broking of deferred payment credit agreements is exempt | FCA |
| 30 Sep 2026 (done) | Cryptoasset authorization gateway opened; the application period runs to 28 Feb 2027 | FCA |
| 1 Oct 2026 (done) | The Financial Promotion (Notification of Cryptoasset Approval) Instrument 2026 took effect, removing the requirement to notify the FCA of most cryptoasset promotion approvals | Handbook Notice 144 |
| Later in 2026 | Possible phase 2 consultation on broader SM&CR reforms, if HM Treasury's proposed changes proceed | PS26/6 |
| Q1 2027 | Final rules expected from CP26/23 on Consumer Duty scope and proportionality, including PRIN 2A.8 reporting | CP26/23 |
| 25 Oct 2027 | Cryptoasset regime comes into force: firms need authorization to operate in the UK | SI 2026/102 |
| Annually | Governing body reviews Consumer Duty outcomes | PRIN 2A.8 |
| Next edition | Regulatory Initiatives Grid (no date announced; the FCA says twice a year) | Grid page |
Crypto firms straddling the UK and EU perimeters are running two clocks at once; the EU side is mapped in our MiCA compliance checklist.
Volume rules out "read everything" as a methodology. In its 2023 Cost of Compliance report, Thomson Reuters Regulatory Intelligence put the 2022 global count at 61,228 regulatory events, an average of 234 alerts a day (2022 data; treat it as an order-of-magnitude anchor, and see how many regulatory changes happen per year for the fuller statistics). And even once a change is spotted, CUBE's Cost of Compliance Report 2025, a survey of more than 2,000 senior compliance, risk and legal leaders across 11 markets published on 4 November 2025, found that 74% of firms take more than a year to implement new regulations. The survey comes from a regulatory intelligence vendor, so weigh it accordingly.
The enforcement record prices the gap: GBP 12.55 million, GBP 48.65 million, and one personal fine
Three enforcement actions define the cost curve, and none of them required the FCA to cite a horizon-scanning rule.
Citigroup Global Markets, GBP 12,553,800: the cost of slow impact assessment. On 19 August 2022 the FCA fined CGML for failing to properly implement the Market Abuse Regulation's trade surveillance requirements. The key fact from the final notice is that MAR was a known, dated, published change, and CGML still took 18 months to identify and assess the specific market abuse risks its surveillance needed to cover: the notice records that the risk assessment "was not substantially complete until January 2018, more than 18 months after the MAR Effective Date." The breaches were MAR article 16(2) and Principle 2 (skill, care and diligence). The fine reflects a 30% settlement discount; it would otherwise have been GBP 17,934,030. The lesson is that the FCA measured the gap between a change taking effect and the firm's impact assessment, and priced it at eight figures. Your deadline register and impact assessments are the evidence that the gap does not exist at your firm.
TSB, GBP 48.65 million: the cost of ungoverned change. On 20 December 2022 the FCA and PRA fined TSB a combined GBP 48,650,000 (FCA GBP 29.75 million, PRA GBP 18.9 million, after a 30% discount from GBP 69.5 million) for operational risk management and governance failures in its 2018 IT migration. The FCA's findings were breaches of Principle 2, in managing the outsourcing of the migration, and Principle 3. This was a change program the firm itself initiated, not an external rule change, and it failed for want of the governance machinery (risk identification, board reporting, oversight of delegation) that Principle 3 and SYSC 4.1.1R describe. Externally imposed regulatory change runs through the same machinery.
Carlos Abarca, GBP 81,620: the accountability is personal. In April 2023 the PRA fined TSB's former Chief Information Officer GBP 81,620 (reduced by 30% from GBP 116,600 for settlement) for breaching PRA Senior Manager Conduct Rule 2, the PRA's equivalent of SC2. He failed to take reasonable steps to ensure that TSB adequately managed and supervised its outsourcing arrangement for the migration. The wording of that rule mirrors the SC2 text in the rule map above. "Reasonable steps" is the standard each of your senior managers must be able to evidence, personally, for regulatory changes landing in their area. The failing was outsourcing oversight, not a missed rule change, but the standard applied is the one your senior managers face.
Seventeen evidence items cover what a supervisor could ask for tomorrow
The checklist has seventeen evidence items in five sections, each mapped to the Handbook anchor a supervisor would recognize, the senior manager who owns it, the format it should live in, and its refresh cadence. Score yourself red, amber or green against each; anything red in sections B or D is where I would start, because those are the sections the enforcement record bites on.
| # | Evidence item | FCA anchor | What good looks like | Owner (SMF) | Format / artifact | Refresh |
|---|---|---|---|---|---|---|
| A. Coverage and methodology | ||||||
| 1 | Documented source universe: Handbook Notices, the Regulatory Initiatives Grid, Regulatory Priorities reports, Dear CEO letters, consultations, sector feeds | SYSC 6.1.1R | A maintained register with authority tiers and a review date, not a bookmarks folder | SMF16 | Source register | Annually and on each Grid edition |
| 2 | Written scanning methodology with a proportionality rationale (nature, scale, complexity of the business) | SYSC 6.1.1R; SYSC 4.1.1R | States cadence per source tier, who reads what, and why the scope fits the firm | SMF16 | Methodology document, committee-approved | Annually |
| 3 | Evidence the scan actually runs at the stated cadence | SYSC 4.1.1R | Timestamped run log or review sign-offs; no unexplained gaps | Compliance monitoring lead | Scanning log | Per stated cadence |
| B. Triage and impact assessment | ||||||
| 4 | Relevance decision log including items dismissed, with reasons | SYSC 6.1.2R (rule or guidance per firm type; SYSC 6.1.2-AR for common platform firms) | Every item carries an accept or dismiss decision and a one-line rationale; dismissals are the part examiners test | SMF16 | Triage log / regulatory change log | Per item |
| 5 | Impact assessment per accepted change, mapping it to affected business units, policies and controls | SYSC 4.1.1R | Completed within a defined SLA of acceptance; Citigroup's 18 months is the anti-pattern | Business-line SMF and compliance | Impact assessment record | Per accepted change |
| 6 | Deadline register: in-force dates plus internal milestones and owners | SYSC 6.1.1R | Every accepted change has a named owner and a completion date before the in-force date | SMF16 | Deadline register / obligations register | Per change and monthly review |
| C. Governance and management information | ||||||
| 7 | Regulatory change as a standing board or committee information item | SYSC 4.1.1R; PRIN 2A.8 (retail) | Shows pipeline, aging and overdue actions, not just counts of alerts read | Board and SMF16 | MI pack section | Monthly or quarterly |
| 8 | Compliance function's periodic report assessing the change process itself | SYSC 6.1.3R (management companies and P2P operators); SYSC 6.1.3-AR (common platform firms, at least annually); guidance for other firms | Assesses adequacy and effectiveness of the process, not merely lists changes handled | SMF16 | Compliance report | At least annually |
| 9 | Governing body reporting that assesses future business strategy against the Consumer Duty (retail firms) | PRIN 2A.8.3R to 2A.8.5R (watch CP26/23) | Actions carry owners and timescales, the gap the FCA's December 2024 review called out | Board and Duty champion | Annual board report or proportionate equivalent | Annually |
| 10 | Principle 11 notification log: what you told the FCA, when, and the decision trail | Principle 11 | Notifications traceable to the triage log; you can show why you did or did not notify | SMF16 / CEO (SMF1) | Notification log | Per event |
| D. Accountability | ||||||
| 11 | SMF16 statement of responsibilities explicitly covers regulatory change and horizon scanning | SM&CR; SUP 10C.11 | Names the scanning and triage process, not generic "compliance oversight" | SMF16 | Statement of responsibilities | On role or process change |
| 12 | Per-senior-manager "reasonable steps" evidence for changes landing in their area | SC2, COCON 2.2.2R | Each SMF can produce sign-offs, minutes and challenge, the standard the Abarca fine applied | Every SMF | Decision records, minutes | Per change |
| 13 | Delegation and oversight records where implementation is handed down or outsourced | COCON; SYSC 4.1.1R | Delegation documented with reporting lines and evidence of ongoing supervision | Delegating SMF | Delegation log | Annually and per change |
| E. Implementation and audit trail | ||||||
| 14 | End-to-end change log: identified, assessed, implemented, reviewed | SYSC 6.1.1R | One record traces a change from source publication to the control or policy it altered | SMF16 | Regulatory change log | Per change |
| 15 | Evidence retention: artifacts (policy diffs, training records, communications) attached to each change record | SYSC 4.1.1R | Retrievable in days, not weeks; survives staff turnover | Compliance operations | Evidence store | Per change |
| 16 | Operational resilience scenario refresh driven by scan output | FCA operational resilience insights | Severe-but-plausible scenarios reference named emerging risks and their "proximity of impact" | SMF24 (enhanced firms) or the operational resilience owner | Scenario testing pack | Annually and per material change |
| 17 | Post-implementation review confirming controls actually operate | Principle 2; Citigroup final notice lesson | Review completed within months of go-live, testing operation, not existence | Business-line SMF | Post-implementation review record | Per major change |
Two notes on using it honestly. First, row 4 is the highest-value, lowest-cost item on the table: a dismissal log converts informal awareness into examinable evidence immediately, and it is the row I would expect most firms to be missing. Second, the FCA's Consumer Duty board reports review (11 December 2024, covering the first annual reports of 180 firms, including 55 smaller firms) is the closest thing you have to a marking scheme for section C. It reported that some firms lacked the data quality to justify their conclusions and that some action plans came without timescales or action owners, and the July 2026 outcomes-monitoring paper repeats the point in positive form. Assume the same marking scheme applies to any regulatory-change information you put in front of a supervisor.
The worked row: the UK cryptoasset regime, traced through all seven columns
Take one live change from the key-dates table and run it through the checklist so the columns stop being abstract. The UK cryptoasset regime comes into force on 25 October 2027, and the FCA's authorization gateway opened on 30 September 2026, with an application period that closes on 28 February 2027 (check the FCA's direction and the commencement provisions for your own register before relying on this summary). As Sheree Howard put it in April: "from October 2027, crypto firms will need to be authorised to operate in the UK."
| Column | Entry |
|---|---|
| Evidence item | UK cryptoasset regime: activities that are unregulated today become FCA-regulated |
| FCA anchor | SI 2026/102; the FCA's gateway page and policy statements; SYSC 6.1.1R duty to maintain procedures adequate for the new obligation set |
| What good looks like | Triage decision dated within days of the FCA's gateway announcement. An impact assessment that answers: do we issue, trade, hold, promote or advise on cryptoassets for UK clients, including through an EU entity? If yes, an authorization plan with the application filed inside the window, or a documented decision not to apply. If no, a dismissal record saying exactly that |
| Owner (SMF) | SMF16 for the triage decision; the relevant business-line SMF for implementation, with SC2 evidence of their sign-off |
| Format / artifact | Change log entry, impact assessment, and a deadline register row with internal milestones back-scheduled from 28 February 2027 and 25 October 2027 |
| Refresh | Monthly until the application period closes; then a post-implementation review after commencement |
| Status | Open: set the row now |
A firm with no cryptoasset exposure still needs the row. "We assessed it on 1 October 2026 and dismissed it because we have no cryptoasset products; reviewed by SMF16" is thirty seconds of work and the artifact that distinguishes a scanning process from a subscription. The same exercise on a change that has already landed, deferred payment credit, which came under regulation on 15 July 2026, would end in a post-implementation review with a scoping answer that depends on your model: as the FCA's policy statement PS26/1 notes, merchants offering their own agreements directly, and the broking of deferred payment credit agreements, stay outside regulation.
Three fixes belong in front of the board before the next supervisory contact
With room to fix only three things at a UK firm this quarter, I would take them in this order:
- Start the dismissal log this week (row 4). Five columns: date seen, item, source, decision, one-line reasoning. It is the cheapest row on the checklist and the one that converts everything else you already do into evidence. Backfill nothing; start clean.
- Reconcile the deadline register against the current Grid edition (rows 1 and 6). Print the 10th edition's initiatives relevant to your portfolio, check that each has either a register entry or a dismissal record, and put the reconciliation date in your management information. Repeat when the next edition lands.
- Ask each senior manager for their SC2 file (row 12). Do not build one for them; ask them to produce what they would show a supervisor if a change in their area went the way TSB's migration did.
Where I sit: this checklist is the paper version of what we built RegWatch to produce as a by-product of normal operation. A Watchlist monitors your sources on the schedule you set, each Finding carries its source, dates and written reasoning, dismissing an alert requires a reason, accepted Alerts convert to Obligations with a named owner and deadline, and the audit log is tamper-evident. But the checklist works on spreadsheets and sharp discipline too, and a firm that runs it manually will demonstrate more to the FCA than a firm that bought software and skipped the governance rows.
The rules that let a supervisor ask for your dismissal log are already in force, and have been since 2001, 2016 and 2018. The only thing the FCA has not done is name the discipline in a rule. Sheree Howard's line generalizes better than any rule citation: when the FCA sits down with your firm, it is your competence being assessed, in your own words and from your own records.
Our financial services hub carries more UK financial-services coverage.
This article is general information, not legal advice.
Questions
Does the FCA actually require horizon scanning?
We found no Handbook rule that uses the phrase, after searching 291 Handbook section pages on 30 September 2026. The expectation is assembled from SYSC 6.1.1R (adequate policies and procedures to ensure compliance with obligations under the regulatory system), SYSC 4.1.1R (effective processes to identify, manage, monitor and report risks) and Principle 3. The FCA does use the term itself in supervisory material, including its operational resilience insights page and its own Emerging Technology Horizon Scan.
What evidence does the FCA expect firms to show for regulatory change?
Documented processes, decision records including dismissals, and board-level information with named owners and target dates. The FCA's December 2024 review of first annual Consumer Duty board reports found some firms' data too weak to justify their conclusions and some action plans without owners or timescales, and its July 2026 outcomes-monitoring paper describes good practice as actions with named owners, target dates and status updates.
What happens when a firm misses or under-implements a regulatory change?
Citigroup Global Markets was fined GBP 12,553,800 on 19 August 2022 after taking more than 18 months to identify and assess the market abuse risks created by the Market Abuse Regulation, in breach of Article 16(2) and Principle 2. TSB was fined GBP 48.65 million by the FCA and PRA on 20 December 2022 for governance failures in an IT migration and its outsourcing. Both figures include 30% settlement discounts.
What free FCA publications support horizon scanning?
The Regulatory Initiatives Grid (10th edition, 19 May 2026, with 135 live initiatives on a 24-month view), regular Handbook Notices, the nine Regulatory Priorities reports that replaced portfolio letters in early 2026, the annual work program, Dear CEO letters and open consultations. The FCA publishes them for firms in each sector, so they are the natural baseline for a documented source list.
Who is personally accountable for regulatory change under the SM&CR?
Every senior manager for their own area, through Senior Manager Conduct Rule SC2 (COCON 2.2.2R), plus the SMF16 compliance oversight holder. The precedent is personal: in April 2023 the PRA fined TSB's former chief information officer GBP 81,620 under the PRA's equivalent of SC2 for failing to take reasonable steps to ensure the bank adequately managed and supervised an outsourcing arrangement.
Terms in this guide
Sources
- FCA Handbook: SYSC 6.1 Compliance accessed 30 Sep 2026
- FCA Handbook: SYSC 1 Annex 1, detailed application of SYSC accessed 1 Oct 2026
- FCA Handbook: SYSC 4.1 General requirements accessed 30 Sep 2026
- FCA Handbook: SYSC 3.2 Areas covered by systems and controls accessed 30 Sep 2026
- FCA Handbook: PRIN 2.1 The Principles accessed 30 Sep 2026
- FCA Handbook: COCON 2.2 Senior manager conduct rules accessed 30 Sep 2026
- FCA Handbook: PRIN 2A.8 Governance and culture accessed 30 Sep 2026
- FCA Handbook: SUP 10C.11 Statements of responsibilities accessed 30 Sep 2026
- FCA: PS25/13, MiFID Organisational Regulation (transfer into the Handbook, 23 October 2025) accessed 30 Sep 2026
- FCA: CP26/23, Consumer Duty scope and proportionality (29 June to 18 September 2026) accessed 30 Sep 2026
- FCA: CP26/23 consultation paper, PDF (paragraphs 4.39 to 4.43 on board reporting) accessed 1 Oct 2026
- FCA: Handbook Notice 144 (25 September 2026), including the Financial Promotion (Notification of Cryptoasset Approval) Instrument 2026 accessed 1 Oct 2026
- FCA: Handbook Notice 142 (June 2026), including the PRIN 2A.8 amendments accessed 1 Oct 2026
- FCA: PS26/6, Senior Managers and Certification Regime review accessed 30 Sep 2026
- FCA: Regulatory Initiatives Grid, 10th edition (19 May 2026) accessed 30 Sep 2026
- Financial Services Regulatory Initiatives Forum: terms of reference accessed 30 Sep 2026
- FCA: Getting firms fit to run, speech by Sheree Howard at the APCC Spring Conference (22 April 2026, as drafted) accessed 30 Sep 2026
- FCA: Regulating Buy Now Pay Later, and PS26/1 on the regulation of deferred payment credit accessed 30 Sep 2026
- FCA: PS26/1, Regulation of Deferred Payment Credit (11 February 2026) accessed 1 Oct 2026
- FCA: How the cryptoasset authorisation gateway will operate accessed 30 Sep 2026
- The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, SI 2026/102 accessed 30 Sep 2026
- FCA: Emerging Technology Horizon Scan 2026 (10 June 2026) accessed 30 Sep 2026
- FCA: Emerging Technology Horizon Scan 2026, PDF accessed 1 Oct 2026
- FCA: Operational resilience, insights and observations (28 May 2024) accessed 30 Sep 2026
- FCA: Sanctions systems and controls, firms' response to increased sanctions due to Russia's invasion of Ukraine (6 September 2023) accessed 30 Sep 2026
- FCA: Multi-firm review of liquidity risk management in wholesale trading firms (10 March 2025) accessed 30 Sep 2026
- FCA: Consumer Duty board reports, good practice and areas for improvement (11 December 2024) accessed 30 Sep 2026
- FCA: Outcomes monitoring, good practice and areas for improvement (27 July 2026) accessed 30 Sep 2026
- FCA: Regulatory Priorities reports accessed 30 Sep 2026
- FCA: Final notice to Citigroup Global Markets Limited (19 August 2022) accessed 30 Sep 2026
- FCA: press release on the fine for failures to detect market abuse (19 August 2022) accessed 30 Sep 2026
- FCA: TSB fined GBP 48.65 million for operational resilience failings (20 December 2022) accessed 30 Sep 2026
- FCA: Final notice to TSB Bank plc (20 December 2022) accessed 1 Oct 2026
- Bank of England: PRA fines former CIO of TSB Bank plc for breach of PRA Senior Manager Conduct Rules (April 2023) accessed 30 Sep 2026
- CUBE: The Cost of Compliance Report 2025 (published 4 November 2025) accessed 30 Sep 2026
- Thomson Reuters Regulatory Intelligence: 2023 Cost of Compliance (PDF) accessed 30 Sep 2026
