Skip to main content
How to Build NFM Compliance Into Your FrameworkEthics Culture & Standards
6 min readFor Compliance Training Managers

How to Build NFM Compliance Into Your Framework

As of September 1, 2026, approximately 37,000 non-bank regulated firms must address serious bullying, harassment, and violence as potential breaches of the FCA's Standards of Business Conduct (COCON). The new COCON 1.1.7FR provision clarifies that non-financial misconduct falls within regulatory scope, closing a gap that left non-banks uncertain.

This isn't about creating a surveillance state or turning every workplace disagreement into a compliance incident. It's about building a framework that identifies serious misconduct, assesses its regulatory relevance, and responds proportionately. Here's how you and your team can do that work.

What You Need Before Starting

Policy and process inventory. Gather your current versions of:

  • Employee Standards of Business Conduct and standards of business conduct
  • Anti-harassment and bullying policies
  • Speak-up program documentation
  • Investigation procedures
  • Fitness and propriety assessment templates
  • Regulatory reference forms and procedures
  • Manager accountability frameworks

Cross-functional working group. Bring together people from Compliance, HR, Legal, and Learning & Development. Non-financial misconduct sits at the intersection of employment law, regulatory compliance, and workplace culture. No single function can handle this alone.

Baseline understanding of COCON scope. Ensure your team understands Individual Conduct Rule 1 (integrity) and Individual Conduct Rule 2 (due skill, care, and diligence). The framework doesn't create new conduct rules; it clarifies when serious non-financial misconduct can breach existing ones.

Documentation of your current state. Before making changes, document how you currently handle harassment complaints, bullying allegations, and fitness assessments. This will help identify gaps and measure progress.

Step-by-Step Implementation

Step 1: Update your Conduct Rules breach reporting process

Your existing COCON breach reporting workflow likely focuses on financial misconduct, conflicts of interest, and market conduct. Add a decision tree for non-financial misconduct:

  • Is the alleged conduct serious bullying, harassment, violence, or offensive behavior?
  • Is there a sufficient work-related connection? (Conduct at the office, while working remotely, or during work-related activities typically qualifies. Purely private conduct generally doesn't.)
  • Does the conduct meet the regulatory threshold for a potential Conduct Rules breach?

The FCA's guidance lists factors to weigh: impact on the victim, whether it's part of a pattern, duration, seniority of those involved, and power imbalances. A single serious incident can be enough. Build this assessment into your case intake form. When HR receives a complaint, they need a clear path to escalate potential regulatory issues to Compliance.

Step 2: Revise fitness and propriety assessment procedures

Your FIT assessment template should now explicitly address non-financial misconduct. Add prompts that ask:

  • Has the individual been involved in substantiated serious misconduct, whether at work or in their private life?
  • If the conduct occurred outside work, does it demonstrate a material risk that the individual will breach regulatory standards in their role?

The FCA warns against assuming private behavior will automatically repeat at work. You're looking for material risk, not remote speculation. But dishonesty, serious violence, sexual misconduct, abuse of trust, or conduct showing willingness to disregard legal obligations can all be relevant, even when they occur outside the workplace.

Document your reasoning. If you conclude that substantiated private misconduct doesn't affect fitness and propriety, explain why the risk isn't material. If you conclude it does, explain the connection to regulatory standards.

Step 3: Update regulatory reference procedures

Serious, substantiated non-financial misconduct may need to appear in regulatory references. This prevents individuals from avoiding consequences by moving between firms.

Add a section to your regulatory reference template that asks about substantiated serious misconduct. Be specific: you're asking about conduct serious enough to potentially breach COCON or affect fitness and propriety, not every HR policy violation.

Train the people who prepare and review references. They need to distinguish between an employment matter (someone was late three times) and a regulatory matter (someone engaged in sustained harassment of a colleague).

Step 4: Define manager responsibilities

The FCA expects managers to take reasonable steps to prevent and address serious misconduct in their areas. Potential failures include ignoring known issues, mishandling complaints, failing to operate controls effectively, and failing to create a safe environment for raising concerns.

Create a manager accountability checklist:

  • Do you know how to recognize serious misconduct?
  • Do you know how to escalate concerns to HR and Compliance?
  • Do you understand your responsibility to act when you become aware of potential issues?
  • Do you know the difference between taking reasonable steps and guaranteeing zero misconduct?

Proportionality matters. Managers aren't expected to prevent every incident. They're expected to act reasonably based on what they knew or should have known, the authority they had, and the actions available to them.

Step 5: Build training for three audiences

All employees: What counts as serious misconduct under the new framework? What's the work-related boundary? How do you raise concerns? Make it clear that controversial opinions aren't automatically regulatory issues, but threats, violence, and sustained harassment are.

Managers: Everything employees learn, plus their specific responsibilities. Use scenarios that show the difference between intervening appropriately and overreaching. Practice escalation decisions.

HR and Compliance: Deep dive into the regulatory threshold. When does an HR complaint become a potential COCON breach? When does private conduct affect FIT? How do you document decisions? What goes in a regulatory reference?

Validation: How to Verify It Works

Test your escalation pathway. Create three realistic scenarios (a serious harassment complaint, a bullying allegation involving a senior manager, and a report of private conduct that may affect fitness). Walk them through your process from intake to resolution. Time how long it takes to reach Compliance. Identify any gaps or delays.

Review a sample of recent cases. Pull five harassment or bullying complaints from the past six months. Apply your new framework retrospectively. Would any have required different handling? If yes, what would have changed?

Audit your regulatory references. Review the last ten references your firm provided. Would any need to include non-financial misconduct information under the new standard? If you're missing substantiated serious misconduct, your process has a gap.

Survey managers. Ask them: Do you understand your responsibilities regarding non-financial misconduct? Do you know how to escalate? Do you feel equipped to handle these situations? If more than 20% answer no to any question, you need more training.

Maintenance and Ongoing Tasks

Quarterly cross-functional review. HR and Compliance should meet every quarter to review non-financial misconduct cases. Are you seeing patterns? Are escalations happening appropriately? Are investigations thorough and documented?

Annual policy review. As case law develops and FCA guidance evolves, your policies need to keep pace. Schedule an annual review of your framework, ideally tied to your broader COCON and FIT policy review cycle.

Manager refresher training. Manager turnover and role changes mean your trained population erodes over time. Build responsibilities into onboarding for new managers and offer annual refresher sessions.

Track metrics that matter. Monitor:

  • Time from complaint to Compliance notification (target: same day for serious allegations)
  • Percentage of cases with documented regulatory assessment
  • Manager confidence scores from training surveys
  • Regulatory reference accuracy (are you catching substantiated serious cases?)

The FCA didn't create these rules to expand regulatory reach for its own sake. It created them because serious misconduct undermines culture, silences speak-up programs, and erodes trust. Your framework should do more than check a compliance box. It should make your workplace safer and your regulatory standing stronger.

You Might Also Like