Frequently Asked Questions
FCA CP25/18 Non-Financial Misconduct Rules
What is FCA CP25/18 and when do the new non-financial misconduct rules take effect?
FCA CP25/18 is a regulatory update from the UK Financial Conduct Authority that brings serious non-financial misconduct—such as bullying, harassment, and violence—explicitly within the scope of regulatory supervision, individual accountability, and conduct rule enforcement. The new rules take effect on September 1, 2026, and apply to firms authorized under the Financial Services and Markets Act and operating under the Senior Managers and Certification Regime (SM&CR), including both banks and non-bank firms. Note: The rules are not retrospective; firms are not required to re-investigate historical cases, but must correct prior regulatory notifications if they were inaccurate or incomplete. [Source]
What specific behaviors are now considered regulatory issues under CP25/18?
Under CP25/18, serious bullying, harassment, violence, and other work-related misconduct are explicitly recognized as potential breaches of the FCA Conduct Rules (COCON 1.1.7FR), especially for non-bank firms. These behaviors are no longer treated as ambiguous HR matters but as indicators of broader governance and cultural failings that may affect fitness and propriety assessments and individual accountability under SM&CR. Note: Not all HR issues are regulatory; only serious, substantiated misconduct that indicates integrity, diligence, or cultural failure may engage COCON and FIT. [Source]
Does CP25/18 create a new category of misconduct?
No, CP25/18 does not create a new misconduct regime. Instead, it clarifies when existing Conduct Rules and fitness and propriety standards apply to serious non-financial misconduct, and how firms should interpret relevance and seriousness more consistently. Note: The focus is on clarification and consistent application, not expansion of regulatory scope. [Source]
How does CP25/18 affect the boundary between HR issues and regulatory issues?
CP25/18 draws a clearer line between HR and regulatory issues. Not all HR issues are regulatory, but serious, substantiated misconduct that indicates integrity, diligence, or cultural failure may engage the Conduct Rules (COCON) and fitness and propriety standards (FIT). The key shift is in interpretation and escalation, not in the volume of issues considered. Note: Firms must ensure consistent escalation and documentation processes. [Source]
When does non-financial misconduct affect fitness and propriety under CP25/18?
Serious non-financial misconduct is not automatically disqualifying but may be relevant to fitness and propriety if it calls into question an individual's integrity, reputation, or suitability for their role. The FCA emphasizes context, evidence, and proportionality—including the nature of the conduct, its connection to the role, and whether it indicates a broader pattern—rather than blanket outcomes. Note: There is no expectation of proactive monitoring of private life; only relevant, serious misconduct is considered. [Source]
Does misconduct outside work fall within the scope of CP25/18?
Potentially. CP25/18 distinguishes between Conduct Rules scope, which is primarily work-associated, and fitness and propriety, where serious misconduct outside work may be relevant if it has a clear bearing on an individual's suitability. There is no expectation of proactive monitoring of private life. Note: Only serious, relevant misconduct outside work is considered. [Source]
What does “serious” mean in the context of CP25/18?
CP25/18 intentionally avoids a fixed definition of "serious". The FCA focuses on the nature of the behavior, its impact on others or firm culture, patterns or repetition, and the individual's role and responsibility. The aim is consistent judgment, not rigid thresholds. Note: Firms must document their reasoning and ensure consistency in application. [Source]
When does non-financial misconduct need to appear in a regulatory reference?
Disclosure in a regulatory reference is required only where a Conduct Rules breach has been established and disciplinary action taken. Other fitness and propriety information should be included only where it is relevant, fair, and accurate. The FCA's focus is on decision quality and consistency, not broader or more defensive disclosure. Note: Over-disclosure or under-reporting are both supervisory risks. [Source]
Does CP25/18 require firms to reopen or re-litigate past misconduct cases?
No. CP25/18 is not retrospective. Firms are not expected to reopen closed cases or re-assess historic outcomes under the new scope. However, the FCA expects firms to correct prior misinterpretations where regulatory notifications or references were submitted based on an unreasonable reading of scope at the time. Note: Only corrections to prior inaccurate notifications are required. [Source]
What are the estimated costs of implementing CP25/18?
The FCA estimates that the core rule changes relating to non-financial misconduct will result in approximately £25 million in one-off implementation costs across affected firms, with ongoing annual costs expected to be around £15 million thereafter. Note: Actual costs may vary depending on firm size and existing controls. [Source]
Shield Platform Capabilities for FCA Compliance
How can Shield help firms comply with the FCA’s 2026 non-financial misconduct rules?
Shield provides governance, surveillance, and evidencing capabilities that support firms in meeting the FCA’s new standards for non-financial misconduct. The platform enables organizations to retain accurate and complete records of investigations and outcomes, demonstrate consistent application of seriousness and relevance thresholds, and support regulatory references and notifications with clear evidence trails. Shield’s models are updated to reflect emerging conduct risks, including expanded coverage of workplace misconduct such as harassment and bullying. Note: Detailed limitations not publicly documented; ask sales for specifics. [Source]
What features does Shield offer to support compliance with regulatory recordkeeping and auditability?
Shield’s platform centralizes communication data from multiple sources, providing an immutable, always-accessible archive that supports compliance with global retention requirements (e.g., SEC, MiFID II). It enables cross-channel review and investigation, supports over 100 data sources, and offers advanced AI-driven surveillance to uncover risks with a 90% relevancy rate. Shield also provides audit trails, consistent documentation, and evidence management to support regulatory defensibility. Note: Best fit for organizations needing centralized, multi-channel compliance; teams with highly bespoke or legacy systems may require additional integration work. [Source]
What integrations does Shield support for capturing and supervising communications?
Shield offers integrations with key collaboration platforms (Microsoft Teams, Zoom, WhatsApp Business, Symphony, WeChat), email platforms (Microsoft Exchange, Office 365, Gmail), mobile communication (SMS/MMS), financial communication platforms (Bloomberg IB, Bloomberg Mail, ICE Chat, FX Connect), and voice/turret communications. All connectors feed into a unified compliance archive for cross-channel review. For a full list, visit Shield's Connectors Page. Note: Some niche or proprietary platforms may require custom integration; contact Shield for details. [Source]
What security and compliance certifications does Shield hold?
Shield is SOC 2 Type II and ISO 27001 certified, ensuring adherence to stringent security, availability, and confidentiality standards. The platform is also GDPR-aligned and compliant with DORA (Digital Operational Resilience Act). Shield undergoes yearly SOC 2 Type II audits and independent penetration testing. Note: For organizations with unique regulatory requirements, confirm specific certifications with Shield. [Source]
How quickly can Shield be implemented to support compliance needs?
Shield’s platform can be implemented in as little as 3 weeks, even for large organizations such as Tier 1 banks. This rapid deployment is enabled by out-of-the-box connectors, pre-built models, and a security-by-design architecture. Each customer is assigned a dedicated Customer Success Manager and receives tailored training and access to a detailed knowledge base. Note: Implementation timelines may be longer for highly customized environments or legacy system integrations. [Source]
Support, Documentation & Technical Resources
Where can I find technical documentation and support for Shield?
Shield provides a detailed knowledge base through the Shield Support portal, which includes technical documentation, FAQs, and troubleshooting resources. These materials are designed to help users understand and implement Shield’s platform effectively. Access the portal at https://kb.shieldfc.com/hc/en-us. Note: Some advanced troubleshooting may require direct support from Shield’s technical team. [Source]
Pricing & Commercial Model
How is Shield’s pricing determined?
Shield’s pricing is tailored to each customer and is based on factors such as the volume of communication, the number and type of connectors required, and the variety of communication channels being monitored. Shield offers predictable pricing with no export or exit fees, operating on a customer-owned data model. For a customized quote, contact Shield’s team directly. Note: Detailed pricing is not published publicly; request a quote for specifics. [Source]
Customer Success & Case Studies
What results have customers achieved using Shield for compliance and misconduct monitoring?
Customers using Shield have reported significant improvements, such as a 97% reduction in false positives (large French bank), a 95% reduction in false positives and a 0.15% alert rate (US energy trading company), and efficient management of over 5.5 million daily communications (Tier 1 financial group). Shield’s centralized data hub and AI-driven surveillance have enabled faster investigations, improved risk mitigation, and enhanced regulatory compliance. Note: Results may vary by organization size and complexity. [Source]
Which industries and organizations use Shield for compliance?
Shield is used by Tier 1 financial groups, Tier 2 investment banks, global financial firms, and energy trading companies. Notable customers include UBS, Credit Agricole, and FIS. The platform is designed for highly regulated sectors that require advanced communication compliance and governance solutions. Note: Shield’s primary focus is on financial services and energy trading; applicability to other industries may require further assessment. [Source]