Go Back

New FCA Non-Financial Misconduct Rules: What Changed on September 1, 2026 and What Firms Must Evidence

A conference screen displays six panelists for Conduct Risk 2.0: Culture, Conflicts and the Changing Expectations at XLoD Global London, with their names, companies, and photos shown on a blue background.

At XLoD Global London in June 2026, there was a fascinating discussion about the next evolution of conduct risk.

The panel, Conduct Risk 2.0: Culture, Conflicts and the Changing Expectations, brought together senior leaders from across risk, controls and conduct to ask an important question: After nearly two decades of strengthening conduct frameworks, where does the industry go next?

One observation captured the challenge: “The frameworks are quite well set up. However, the outcome will always be shaped by how the humans within that framework actually behave.”

On September 1, 2026, that question became even more relevant. The FCA’s expanded rules and guidance on non-financial misconduct come into force, bringing serious work-related bullying, harassment, and violence more clearly within the Conduct Rules for non-bank firms.

There are immediate implications for policies, conduct-breach reporting, fit-and-proper assessments, and regulatory references.

But September 1 raises a bigger question:If regulation is increasingly focused on human behavior, how good are firms at seeing behavioral risk?

From Conduct 1.0 to Conduct 2.0

Financial services have come a long way since the global financial crisis. Governance has matured. SM&CR strengthened individual accountability. Conduct and culture moved firmly onto the board agenda. Firms invested heavily in policies, controls, and processes.

As one XLoD panelist put it: “The frameworks… have matured. I think they are now quite robust.”

But another observation got to the next challenge: “What we have not spent enough time thinking about… is really the human side of the behavior.”

The panel described an industry moving beyond the foundational elements of conduct risk toward greater use of behavioral science and the ability to “connect the dots.”

That’s an important distinction:Conduct 1.0 built the framework. Conduct 2.0 needs to understand what people do inside it.

Behavior Firmly in Focus

From September 1, the FCA’s new COCON 1.1.7FR extends the Conduct Rules in non-bank firms to certain serious unwanted conduct toward colleagues where there is a sufficient work-related connection. The accompanying guidance provides greater clarity around non-financial misconduct and fitness and propriety, managers’ responsibilities, regulatory references and the boundary between work and private life.

There are important limits. The FCA isn’t asking firms to monitor employees’ private lives or social-media accounts, and the new COCON rule isn’t retrospective. Instead, the change makes clearer when serious workplace behavior becomes a regulatory conduct issue. 

Having the right policy is therefore only part of the equation.The harder challenge is recognizing risk in practice.

What If We See the Problem Too Late?

One comment at XLoD particularly stood out: “There might be things happening now that we won’t see the end product of until five, ten years.”

Conduct risk has an inherent visibility problem. A complaint arrives. A whistleblower raises a concern. An investigation starts. Communications are reconstructed. Eventually, patterns that weren’t obvious at the time become obvious in hindsight.

But what happened before the incident became a case? What weak signals already existed? What behavioral changes could have been visible?

This is where the industry needs to shift its thinking. The objective should be to become better at identifying meaningful risk signals within the communications firms legitimately govern, and giving compliance professionals the context to determine what those signals mean.

Conduct Is a Pattern of Behavior Understood in Context

Was something an isolated interaction or part of a pattern? Who was communicating with whom? What was their relationship? Was there a difference in seniority or influence? Did behavior change over time? Are multiple seemingly insignificant signals more meaningful when viewed together?

A keyword can’t answer those questions. That’s why communications surveillance is moving toward something closer to behavioral intelligence.

AI can help connect signals across conversations, channels, participants, languages, and time, bringing together context that would be extraordinarily difficult for investigators to reconstruct manually.

But that doesn’t mean asking AI to decide whether somebody committed misconduct. Non-financial misconduct demonstrates exactly why human judgment, explainability, and governance must remain central. 

AI can surface evidence, connect signals and reduce noise. Humans remain accountable for judgment.

Can Technology Help Preserve Institutional Judgment?

Experienced risk professionals don’t just know the rules; they recognize patterns. They connect weak signals and understand how seemingly minor behaviors can develop into something more significant.

As that institutional memory changes, could technology help firms augment and scale some of that pattern recognition? It helps them see more of what matters, not replace them. This is one of the most interesting opportunities for AI in surveillance.

Behavioral Risk Lives in Your Communications Data: DCGA Is How You Govern It

Non-financial misconduct doesn’t show up as a single message; it shows up as a pattern across email, chat, voice, and collaboration channels over time. Spotting that pattern before it becomes a case depends on firms having their communications data governed and retained consistently in the first place, not scattered across systems and reconstructed only after a complaint lands.

That’s what Digital Communications Governance and Archiving (DCGA) provides: a single, well-governed source of truth for communications data that makes it possible to see context — relationships, seniority dynamics, behavioral change over time — rather than just keywords.

As the FCA’s expanded conduct rules push firms toward earlier identification of behavioral risk, DCGA is the foundation that makes that identification possible.

Growth, Incentives, and the Conduct Equation

The panel also placed conduct risk within today’s wider growth and efficiency agenda. One participant warned: “Performance management incentive is always going to be a component of human behavior driving.”

That means mature conduct programs need to look beyond the rules themselves and understand the environment in which decisions are being made. At the same time, compliance teams face their own economic reality: more communications, more channels, more data, and increasingly complex risks, without unlimited resources.

As one panelist said: “We will need to… look to some of the emerging technologies, ways that can aid us in doing the jobs we do today and do them even better, but in a more cost-efficient way.”

That’s the AI opportunity: expanding intelligence without compromising control. 

September 1, 2026 has Passed. The Bigger Shift Is Behavioral

For affected firms, September 1 requires practical action around policies, training, conduct-breach reporting, fit-and-proper assessments, regulatory references and manager responsibilities. But stopping there would miss the bigger shift.

For nearly two decades, financial institutions have focused on building stronger conduct frameworks. The next challenge is making those frameworks better at understanding the human behavior happening inside them.

That means moving from isolated communications toward context, from keywords toward patterns, and from retrospective investigation toward earlier risk identification. And from relying solely on individual experience toward using technology to augment human judgment, while keeping governance, explainability, and accountability firmly in place.

September 1 brings the issue into sharper regulatory focus, but Conduct Risk 2.0 is much bigger than one FCA deadline. It’s about whether the industry’s ability to understand behavioral risk is evolving as quickly as the behaviors it is expected to govern.

Ready for the new requirements?

We’ve created a practical guide to help firms understand what the FCA’s expanded approach to non-financial misconduct means for COCON, FIT, senior management, surveillance, documentation, and auditability.

FAQ: Understanding the FCA's Non-Financial Misconduct Rules and Common Questions

What changed with the FCA’s non-financial misconduct rules on September 1, 2026?

The FCA’s expanded COCON 1.1.7FR now extends the Conduct Rules in non-bank firms to certain serious unwanted conduct toward colleagues, where there’s a sufficient work-related connection. Accompanying guidance clarifies fitness and propriety assessments, managers’ responsibilities, and regulatory references. The rule isn’t retrospective, and firms aren’t required to monitor employees’ private lives or personal social media.

Does this mean firms now have to monitor employees’ personal lives or social media?

No. The FCA guidance is explicit that it doesn’t ask firms to monitor employees’ private lives or social media accounts. The rule is focused on serious workplace conduct with a genuine work-related connection, not personal conduct outside that context.

Why is conduct risk considered hard to see before it becomes a formal case?

Conduct risk typically becomes visible only after a complaint, whistleblower report, or investigation begins — at which point communications get reconstructed and patterns become obvious in hindsight. The harder challenge is spotting the weak signals that existed before the incident, which requires understanding context (relationships, seniority dynamics, behavioral change over time) rather than just scanning for keywords. Shield’s Surveillance platform is built to put alerts in that kind of context rather than flagging isolated keyword hits.

What’s the difference between keyword-based surveillance and “behavioral intelligence”?

Keyword-based tools flag isolated words or phrases without understanding whether a message is part of a pattern, who’s involved, or how a relationship or behavior has changed over time. Behavioral intelligence connects signals across conversations, channels, participants, languages, and time to surface meaningful context. Shield’s Proactive Surveillance capability applies this kind of multi-layered AI analysis — looking at context, sentiment, and intent rather than just words.

Is AI being used to determine whether someone committed misconduct?

No. AI’s role is to surface evidence, connect signals across communications, and reduce noise so compliance teams can focus on what matters — not to make judgment calls about misconduct itself. Human judgment, explainability, and governance remain central, particularly for non-financial misconduct cases. Shield’s Supervision tools are designed to route the right alerts to the right supervisors while keeping that judgment with people.

What should firms actually do now that September 1 2026 has passed?

Practical steps include reviewing policies, training, conduct-breach reporting processes, fit-and-proper assessments, regulatory references, and manager responsibilities against the new guidance. Beyond that immediate checklist, firms should also look at whether their surveillance approach can identify behavioral patterns early rather than relying solely on retrospective investigation. Shield has published a practical FCA guide covering what the FCA’s expanded approach means for COCON, FIT, senior management, surveillance, documentation, and auditability.

How does a DCGA solution like Shield support the FCA’s non-financial misconduct requirements?

A DCGA solution like Shield captures, retains, and governs communications data across channels in one consistent source of truth, then applies AI-driven surveillance to put that data in context — connecting signals across conversations, participants, and time rather than flagging isolated keywords. Since the FCA’s expanded rules focus on serious workplace conduct patterns rather than single incidents, that combination of governed data and contextual analysis is what makes earlier, more accurate identification of behavioral risk possible, while keeping judgment on misconduct itself with human compliance teams.

Subscribe

Follow Us

Subscribe to our newsletter

Gain access to exclusive insights, industry influencers, and thought leaders in

Digital Communications Governance and Archiving (DCGA).