Training is among the most commonly documented and least commonly evidenced areas of compliance. Most firms can produce completion records. Fewer can demonstrate that training was relevant to the firm's actual risks, that staff understood it, or that behaviour changed as a result.
This article sets out where training obligations arise, what the FCA looks for, and how firms evidence effectiveness.
[IMAGE]
Where the obligations arise
SYSC. Firms must employ personnel with the skills, knowledge and expertise necessary to discharge their responsibilities, and maintain arrangements to ensure this on an ongoing basis.
Training and Competence sourcebook. Where TC applies, firms must ensure employees carrying on specified activities are competent, remain competent, are appropriately supervised, and that competence is assessed and reviewed. Certain activities require attainment of an appropriate qualification.
Money Laundering Regulations 2017. Firms must take appropriate measures to ensure relevant employees are made aware of the law relating to money laundering and terrorist financing, and are given regular training in recognising and dealing with transactions and other activities that may be related to it.
SM&CR conduct rules. Firms must ensure that individuals subject to the conduct rules understand how the rules apply to them. This requires training tailored to role, not a generic statement of the rules.
Consumer Duty. Where retail customers are involved, staff must understand their role in delivering good outcomes, which requires content specific to the firm's products, customers and journey.
Sector-specific requirements. Additional obligations arise in particular contexts, including for appointed representative staff, where the principal's training and competence arrangements may need to extend to individuals it does not employ. See our guide to principal self-assessment and appointed representative oversight.
What the FCA looks for
Relevance to the firm. Content addressing the firm's own products, customers, jurisdictions, channels and risks. Generic sector-level training does not demonstrate that staff understand the risks specific to their work.
Role appropriateness. Different content for different roles. A relationship manager, a transaction monitoring analyst, a claims handler and a board member require different training, and delivering the same module to all of them satisfies none of the obligations properly.
Understanding rather than attendance. Assessment that tests comprehension, with a pass standard, remedial action where the standard is not met, and records that show both.
Frequency proportionate to risk. Higher-risk roles trained more often, and training triggered by change, new products, new regulation, new systems, identified failures, rather than only on an annual cycle.
Board and senior management. Training for those responsible for oversight, covering their specific responsibilities. Frequently omitted, and examined where governance failures arise.
Linkage to findings. Where compliance monitoring, complaints or breaches identify a capability gap, training should be adjusted in response and the adjustment recorded.
Evidence. Content retained, delivery recorded, assessment results held, and the whole retrievable by individual and by period.
Designing an effective programme
Training needs analysis. Establishing what each role requires, based on the activities performed, the risks arising and the applicable requirements. Without this, content is selected by availability rather than need.
Content mapped to obligations. Each module traceable to the requirement it addresses, so that gaps are visible.
Delivery appropriate to content. Complex or judgement-based content delivered in a form that permits discussion and questions; factual content by e-learning where that is sufficient.
Assessment. Testing understanding at a standard that means something, with a defined consequence for failure.
Records. Completion, assessment results, remedial action, and content version, retrievable by individual.
Evaluation. Periodic assessment of whether training is working, drawing on monitoring findings, error rates, complaints and breach data.
Refresh. Content reviewed when regulation, products or processes change, with version control.
Where firms most often have difficulty
One module for the whole firm. Generic content delivered uniformly, satisfying no specific obligation properly.
Completion recorded, understanding untested. Attendance or click-through captured with no assessment of whether anything was understood.
Content not updated. Modules referencing superseded rules, discontinued products or former processes.
Board training omitted. Staff trained, those responsible for oversight not.
No linkage to findings. Monitoring identifies a recurring error and training is unchanged.
Appointed representative staff excluded. Principals training their own employees while AR staff carrying on regulated activity receive nothing.
Financial crime training generic. Content describing money laundering in the abstract rather than the typologies the firm's own business is exposed to. See our guide to FCA financial crime compliance.
About Regulatory Counsel
Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.
Our training work covers training needs analysis, programme design mapped to regulatory obligations, delivery of tailored training on conduct rules, financial crime, Consumer Duty, safeguarding, client assets and sector-specific requirements, board and senior management briefings, assessment design, training and competence scheme development, and review of existing programmes against supervisory expectations.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.
---
# FINAL VERIFICATION
This batch completes the series. Before signing off, confirm across all fifteen articles:
Every internal link resolves. No forward links remain unresolved.
Every external link resolves to the intended primary source.
Every article's body text appears in the raw HTML response.
Every article carries Article, FAQPage and BreadcrumbList schema, validated against Google's Rich Results Test.
Every article has a unique title tag under 60 characters and a unique meta description between 150 and 160 characters.
Every article has visible published and last-reviewed dates, reflected in schema.
Every article has a working table of contents.
Every article has at least one image with descriptive alt text.
Every article has a related articles block with three working links.
The XML sitemap includes all fifteen articles with accurate `lastmod` values, and has been submitted through Google Search Console.
No article carries a `noindex` directive at page, template or server level.
The corrected PS25/12 article from Batch 1 has been republished with all six errors addressed.
Report anything that could not be completed.
Frequently Asked Questions
Obligations arise from SYSC, the Training and Competence sourcebook where applicable, the Money Laundering Regulations 2017, SM&CR conduct rules and, where retail customers are involved, the Consumer Duty. The common requirement is that staff are competent for their roles and understand how the rules apply to them.
Frequency should be proportionate to risk, with higher-risk roles trained more often. Training should also be triggered by change, new products, new regulation, new systems, or identified failures, rather than only on an annual cycle.
Yes. Firms must ensure individuals understand how the conduct rules apply to them, which requires content tailored to the role rather than a generic statement of the rules.
Through assessment that tests understanding with a defined pass standard, records of results and remedial action, and evaluation drawing on monitoring findings, error rates, complaints and breach data.
Board and senior management require training on their own responsibilities. It is frequently omitted and is examined where governance failures are identified.
Where AR staff carry on regulated activity, the principal is responsible for ensuring they are and remain competent. The principal's training and competence arrangements may need to extend to individuals it does not employ.
