July 17, 2026 by Stefan Jovanovic

FCA Compliance: What Financial Firms Need to Know About Recordkeeping, Audits and Enforcement

Key Takeaways

  • The Financial Conduct Authority (FCA) regulates around 42,000 firms in the UK and issued more than £186 million in fines during the 2024/25 enforcement year
  • FCA compliance rests on six pillars: conduct rules, Consumer Duty, recordkeeping, anti-money laundering, financial promotions and regulatory reporting
  • Recordkeeping failures and gaps in communications oversight are among the most common triggers for FCA investigations and enforcement action
  • Audit readiness depends on maintaining searchable, tamper-proof communication archives across every channel your firm uses
  • Automation through archiving and AI-powered supervision reduces compliance risk, cuts audit response times and helps you stay ahead of regulatory changes

Introduction

Between April 2024 and March 2025, the FCA imposed £186 million in financial penalties across 29 enforcement actions, a 337% increase from the year before (FCA Enforcement Data, 2024/25). Most of those failures trace back to gaps in recordkeeping, weak internal controls and poor communications oversight. If your firm operates under FCA regulation, you need defensible records, active supervision and the ability to respond to regulators quickly.

In this article, we’ll cover:

  • What the FCA is and which firms it regulates;
  • The six core compliance requirements every regulated firm must address;
  • What happens when firms fail FCA compliance, including real enforcement examples;
  • How to prepare for an FCA compliance audit;
  • How to automate FCA compliance using archiving and AI-powered supervision; and
  • How FCA obligations overlap with other regulatory frameworks like FINRA, SEC and MiFID II.

What is the Financial Conduct Authority (FCA)?

The Financial Conduct Authority is the UK’s independent financial regulatory body. It was established in 2013 when it replaced the Financial Services Authority (FSA) under the Financial Services Act 2012.

The FCA regulates the conduct of around 42,000 financial services firms across banking, insurance, wealth management, payments and fintech. Its three statutory objectives are protecting consumers, enhancing market integrity and promoting effective competition.

The FCA operates independently of the UK government and is funded entirely by fees from regulated firms. It works alongside the Prudential Regulation Authority (PRA), which supervises the financial health of banks, insurers and major investment firms.

The PRA handles balance sheet risk. The FCA handles conduct, consumer protection and market behavior.

For firms outside the UK, the FCA still matters. If you offer financial products or services to UK customers, operate a UK subsidiary or manage UK client assets, you’re likely subject to FCA regulation. Many organizations that already invest in data archiving for financial services find that FCA requirements overlap with obligations they already manage.

Core FCA Compliance Requirements

FCA compliance covers six main areas. Each one carries enforcement risk, and together they form the regulatory framework that every regulated firm must address.

Conduct rules and the Senior Managers and Certification Regime (SM&CR)

The Senior Managers and Certification Regime assigns personal accountability to senior leaders within regulated firms. Under the Senior Managers Regime, individuals in key roles must be pre-approved by the FCA and take direct responsibility for their areas of oversight.

Conduct Rules apply to nearly all employees, not just senior management. These rules require integrity, due skill and care, cooperation with regulators and fair treatment of customers. When something goes wrong, the FCA can hold individual managers accountable, not just the firm.

This personal accountability model means your firm’s compliance program must include clear documentation of who is responsible for what. If you can’t demonstrate that accountability structure during an investigation, you’re already behind.

Consumer Duty

The FCA’s Consumer Duty took effect in July 2023. It requires firms to deliver good outcomes for retail customers across four areas: products and services, price and value, consumer understanding and consumer support.

Consumer Duty goes beyond having policies on paper. Firms must prove they’re actively monitoring outcomes and taking corrective action when customers aren’t getting fair results. The FCA has made it clear that passive compliance won’t satisfy this standard.

For compliance teams, this means capturing and analyzing communications that relate to customer interactions. You need evidence that your firm identified issues, escalated them and acted on them.

Recordkeeping and communications archiving

FCA recordkeeping requirements, outlined primarily in SYSC (Senior Management Arrangements, Systems and Controls) 9 of the FCA Handbook, require firms to retain records that evidence decisions, customer interactions and governance activities.

These requirements extend well beyond email. The FCA expects firms to capture and retain digital communications across every channel in active use: email, chat platforms like Microsoft Teams and Slack, messaging apps including WhatsApp and iMessage, SMS, social media and voice recordings. Organizations already practicing email archiving in financial services need to extend that approach to cover all channels.

Off-channel messaging is a growing enforcement target. When employees use personal devices or unapproved platforms to conduct business, those communications fall outside your compliance perimeter. The FCA considers that a recordkeeping failure.

Retention periods vary by record type, but the standard expectation is a minimum of five years for most transaction records and client communications. Firms must apply consistent retention policies and ensure archived data is searchable, retrievable and tamper-proof. Understanding data retention requirements in the UK is a good starting point.

Your compliance archiving strategy should capture communications from every channel, apply automated retention rules and make records available for search and export within hours, not weeks.

Anti-money laundering (AML) and financial crime

AML compliance requires firms to implement risk-based controls: customer due diligence (CDD), enhanced due diligence for higher-risk clients, transaction monitoring and suspicious activity reporting.

The FCA opened 965 financial crime supervision cases in 2024/25, a 164% increase from 2021 (FCA Annual Report, 2024/25). AML failures have driven some of the largest fines in FCA history. In 2025 alone, Nationwide Building Society was fined £44.1 million, Barclays Bank was fined £39.3 million and Monzo Bank was fined £21.1 million, all for weaknesses in systems and controls related to financial crime prevention (FCA Final Notices, 2025).

Financial promotions

Every financial promotion your firm produces, whether it’s an advertisement, email campaign, social media post or website page, must be fair, clear and not misleading. Retail-facing content requires sign-off by a qualified individual before publication.

The FCA intervened on 19,766, up 97.5% from 10,008 in 2023 (FCA Annual Report, 2024/25). If your marketing and compliance teams aren’t coordinating on promotional content, you’re exposed.

Regulatory reporting

Firms must submit accurate regulatory returns through RegData (the FCA’s online regulatory reporting portal) and other FCA reporting channels on time and without errors. Late or inaccurate filings can trigger supervisory action, including formal investigations.

Regulatory reporting failures often signal deeper problems with a firm’s data infrastructure. If your internal systems can’t produce accurate reports on demand, that’s a compliance gap that extends beyond reporting.

These FCA regulatory compliance rules form the foundation of every firm’s compliance program and should be reflected in documented policies, procedures and ongoing monitoring.

What Happens When Firms Fail FCA Compliance

The FCA’s enforcement toolkit is broad. It includes formal investigations, warning notices, decision notices, financial penalties, public censure, prohibition orders that ban individuals from the industry and criminal prosecution.

Recent enforcement trends

In the 2024/25 enforcement year, the FCA issued 37 Final Notices, imposed £186.4 million in financial penalties, secured five criminal convictions, canceled the authorization of 1,456 firms and achieved 135 outcomes using formal intervention tools (FCA Enforcement Data, 2024/25).

The regulator has also shifted its approach. The FCA is now pursuing fewer investigations but closing them faster.

Open enforcement operations dropped from 188 in March 2024 to 130 in March 2025 (FCA Enforcement Data, 2024/25). Five recent enforcement operations reached a public outcome in under 16 months, compared to a historical average of 42 months (FCA Enforcement Data, 2024/25).

Real enforcement examples

Nationwide Building Society (December 2025): £44.1 million fine. The largest FCA fine of 2025 targeted Nationwide for inadequate anti-financial crime systems and controls between October 2016 and July 2021. The FCA found that Nationwide could not effectively identify, assess, monitor or manage money laundering risks among its personal current account customers, and that it took too long to fix weaknesses it already knew about. The penalty included a 30% discount for early settlement; without it, the fine would have been £62.97 million (FCA Final Notice, December 2025).

Barclays Bank (July 2025): £39.3 million fine. Barclays was fined for a breach of Principle 2 (skill, care and diligence) over its failure to adequately manage money laundering risks associated with its client Stunt & Co. In just over a year, Stunt & Co received £46.8 million from Fowler Oldfield, a multimillion-pound money laundering operation, and Barclays failed to reassess the relationship even after receiving intelligence from law enforcement and learning that police had raided both firms. The fine was reduced from £56.1 million following early settlement, and a separate £3.1 million penalty was imposed on Barclays Bank UK in the same month for due diligence failures relating to WealthTek (FCA Final Notices, July 2025).

Monzo Bank (July 2025): £21.1 million fine. The FCA fined Monzo for inadequate financial crime controls between 2018 and 2020, including onboarding customers with obviously implausible details, and for onboarding over 34,000 high-risk customers between 2020 and 2022 in breach of a specific FCA restriction. The case echoes the £29 million fine Starling Bank received in 2024: in both, rapid customer growth outpaced the compliance infrastructure behind it. Growth doesn’t reduce regulatory expectations.

Common triggers

The patterns across FCA enforcement cases are consistent. The most frequent triggers include:

  • Recordkeeping failures and missing communications data;
  • Off-channel messaging that falls outside your archiving perimeter;
  • Misleading financial promotions;
  • AML control gaps, particularly around customer due diligence;
  • Governance failures under the SM&CR framework; and
  • Treating customers unfairly under Consumer Duty standards.

Reputational damage from an FCA enforcement action often exceeds the financial penalty. Investigations can take years and consume significant internal resources, even when they don’t result in a fine.

The FCA publishes enforcement notices, including Warning Notices, Decision Notices and Final Notices, to communicate regulatory actions against firms and individuals.

How to Prepare for an FCA Compliance Audit

Audit readiness isn’t something you build overnight. It requires a structured approach that touches every part of your compliance infrastructure.

Step one: Map your regulatory obligations. Know which FCA rules apply to your specific business activities. This includes identifying all applicable provisions under the FCA Handbook, including SYSC (Senior Management Arrangements, Systems and Controls), COBS (Conduct of Business Sourcebook) and SUP (Supervision).

Step two: Audit your data. Confirm that all regulated communications are being captured, stored and indexed across every channel your firm uses. This means email, chat, messaging apps, social media, SMS and voice. If you can’t prove a communication happened, the FCA will treat it as if it didn’t.

Step three: Test retrieval. Run mock data requests to measure response time and completeness. The FCA expects you to produce records quickly and accurately. If a regulator’s request takes your team weeks to fulfill, your archiving infrastructure needs work.

Step four: Review policies and training. Ensure your compliance policies are current, reflect the latest FCA guidance (including Consumer Duty requirements) and are documented. Verify that staff training is up to date and that you can prove when training occurred and who completed it.

Step five: Conduct a gap analysis. Compare your current capabilities against FCA expectations, with particular attention to newer requirements like Consumer Duty and off-channel messaging capture. Identify gaps before the regulator does.

Step six: Document everything. The FCA assesses not just what you do but whether you can prove it. Every policy decision, risk assessment, training session and compliance review should be recorded and retrievable. Audit trails matter as much as outcomes.

How to Automate FCA Compliance

Manual compliance processes break down at scale. The volume of regulated communications across a typical financial firm, combined with the speed of regulatory change and the risk of human error, makes manual oversight impractical.

Why manual processes fail

A mid-sized financial firm generates thousands of communications per day across email, Teams, Slack, WhatsApp and other channels. Reviewing that volume manually for conduct risk, recordkeeping compliance and potential regulatory issues requires staff time that most compliance teams don’t have.

Manual processes also create gaps. An employee switches to a personal device to message a client on WhatsApp. A compliance officer misses a flagged communication during a periodic review.

A retention policy gets applied inconsistently because it depends on individual judgment. Each of these gaps is a potential enforcement trigger.

Four automation priorities

1. Automated capture and archiving across all channels. Every communication channel your firm uses, whether approved or not, needs to feed into a centralized archive. This includes email, chat platforms, SMS, WhatsApp archiving, iMessage, social media and voice recordings. Automated archiving eliminates the risk of missing records.

2. AI-powered supervision and keyword monitoring. Rather than reviewing communications after the fact, AI-driven supervision flags conduct risk in near-real time. Policy-based keyword monitoring, sentiment analysis and pattern detection catch problems before they become enforcement issues.

3. Policy-based retention with automated enforcement. Retention rules should be applied automatically based on record type, regulation and jurisdiction. This removes manual deletion decisions and inconsistent application. Automated retention ensures your records are both defensible and complete.

4. Instant search and export for audit responses and ediscovery. When the FCA requests records, you need to produce them fast. Your archiving platform should support full-text search across all channels, filtered exports and audit-ready output that you can deliver within hours. Purpose-built Data Connectors make it possible to capture from 25+ sources into a single searchable archive.

The business case for automation

RegTech adoption is accelerating among FCA-regulated firms. Automated compliance monitoring can reduce audit response times from weeks to hours.

It lowers the risk of human error in surveillance reviews and creates the continuous monitoring capability that the FCA now expects, replacing periodic reviews with real-time oversight.

Gartner projects that by 2029, 30% of enterprises will shift to proactive employee digital communications governance, up from less than 10% in 2025. Firms that automate now position themselves ahead of that curve.

An effective FCA compliance monitoring plan combines automated archiving, AI-powered supervision, periodic reviews and documented escalation procedures.

FCA Compliance Across Borders

Many financial firms don’t operate under a single regulator. If your firm has operations in both the UK and the US, you’re likely subject to FCA requirements alongside FINRA and Securities and Exchange Commission (SEC) rules. Each regulator has its own recordkeeping standards, retention periods and enforcement approach.

MiFID II (Markets in Financial Instruments Directive II) requirements overlap with FCA recordkeeping rules for investment firms, creating additional retention obligations for transaction records and client communications. General Data Protection Regulation (GDPR) and UK data protection laws add constraints on how you store and process personal data within your compliance archive. Firms managing Sarbanes-Oxley Act (SOX) compliance alongside FCA face similar documentation and audit trail requirements.

The practical solution is a unified archiving strategy that meets multiple regulatory requirements through a single system. Rather than building separate compliance workflows for FCA, FINRA, SEC and GDPR, you centralize capture, retention and search in one platform that maps to each regulator’s expectations.

Cross-border compliance is one of the strongest arguments for investing in purpose-built archiving technology. When a single archive supports FCA, FINRA, SEC, SOX and MiFID II requirements, you reduce duplication, lower compliance costs and respond to any regulator from the same source of truth.

If your firm needs a faster path to FCA compliance, Jatheon’s cloud archiving platform captures and archives communications across 25+ channels, supports automated retention and AI-powered supervision and helps compliance teams respond to regulatory requests in hours instead of weeks. Book a Demo to see how it works.

 

FAQ

What is FCA compliance and what are the FCA regulatory compliance rules?

FCA compliance means operating within the rules the UK’s Financial Conduct Authority sets for authorized firms, from how you treat customers and market your products to how you record decisions and report to the regulator. In practice, it comes down to two things: running your business according to the FCA Handbook and being able to prove that you did.

What are the penalties for FCA non-compliance?

The FCA can impose unlimited financial penalties, issue public censures, ban individuals from working in financial services, cancel a firm’s authorization entirely and bring criminal prosecutions. Individual fines regularly reach into the tens of millions of pounds, and the reputational and remediation costs that follow an enforcement action frequently outweigh the fine itself.

How long must FCA-regulated firms retain records?

Five years is the baseline for most transaction records and client communications, and some record types carry longer obligations under MiFID II-derived rules. The retention period is only half the requirement, though. Records must also remain complete, tamper-proof and retrievable throughout, which is why the FCA treats a record you can’t produce as a record you don’t have.

What communication channels does the FCA expect firms to archive?

Any channel used to conduct regulated business, whether or not your firm officially approved it. That covers corporate email and collaboration tools as well as text messages, consumer messaging apps and voice calls on personal devices. If an employee discusses client business on an unapproved app, the FCA still expects that conversation to be captured and produced on request.

How can archiving software help with FCA compliance?

A cloud archiving platform automates the three things regulators test most: capture, retention and retrieval. It ingests communications from every business channel as they happen, applies your retention policies without manual intervention and lets you search and export records in response to a regulatory request in hours. AI-powered supervision adds a proactive layer by flagging risky communications before they turn into enforcement issues.

Read Next:

WORM Compliance Requirements for SEC-Regulated Firms

Communication Surveillance: What It Is and How to Build a Compliant Program

Data Governance Risk and Compliance: What It Is, How It Works and Why Archiving Matters

About the Author
Stefan Jovanovic
Stefan Jovanovic is a PR and SEO Manager at Jatheon who specializes in B2B SaaS marketing and outreach strategies that drive engagement, generate leads, and support business growth. Outside of work, he enjoys photography, social media, and writing.

See how data archiving can simplify compliance and ediscovery for your organization

Book a short demo to see all the key features in action and get more information.

Get a Demo

Share via
Copy link