Wholesale banking sits within one of the most densely regulated areas of UK financial services. Firms are subject to prudential supervision by the Prudential Regulation Authority and conduct supervision by the Financial Conduct Authority, alongside directly applicable requirements covering market abuse, transaction reporting, financial crime, operational resilience and individual accountability.
This article sets out the regulatory framework applying to wholesale banks in the UK, the FCA's current supervisory priorities, the areas in which the regulator has identified recurring weakness, and the practical components of a compliance framework capable of withstanding supervisory scrutiny.
What is a wholesale bank for FCA purposes?
The FCA does not define wholesale banking as a discrete regulated activity. The term describes firms whose business is conducted with institutional counterparties, corporates, governments and other market participants rather than with retail consumers.
In practice, the population supervised by the FCA's wholesale banks department includes UK-incorporated banks conducting wholesale business, UK branches of overseas banks, and investment firms undertaking dealing, arranging and related activities in wholesale markets. Business lines typically include debt and equity capital markets, sales and trading across rates, credit, foreign exchange, equities and commodities, prime services, structured products, and corporate lending and advisory.
The regulatory perimeter matters because obligations attach to activities and permissions rather than to a firm's self-description. A firm conducting wholesale business alongside any retail-facing activity carries the full weight of both regimes for the relevant business lines.
The regulatory architecture
Dual regulation
Banks accepting deposits are dual-regulated. The PRA is responsible for prudential regulation - capital adequacy, liquidity, risk management, recovery and resolution planning. The FCA is responsible for conduct regulation, market integrity, and, in respect of matters not reserved to the PRA, systems and controls.
Investment firms that are not deposit-takers are solo-regulated by the FCA, with prudential requirements set under the Investment Firms Prudential Regime rather than the banking framework.
The practical consequence is that governance, systems and controls sit within both regulators' interests, and firms must be able to evidence a coherent framework to each without inconsistency between them.
The principal sources of obligation
SYSC. The Senior Management Arrangements, Systems and Controls sourcebook sets the framework requirements for governance, risk management, compliance, internal audit, outsourcing, records and, under SYSC 10A, recording of telephone conversations and electronic communications.
SM&CR. The Senior Managers and Certification Regime allocates individual accountability through Senior Management Functions, Prescribed Responsibilities, Statements of Responsibilities and the Management Responsibilities Map, and extends conduct rules across the firm.
MAR and the market abuse framework. The UK Market Abuse Regulation prohibits insider dealing, unlawful disclosure and market manipulation, and requires firms to detect and report suspicious orders and transactions.
Transaction reporting. UK MiFIR requires reporting of transactions in scope instruments, with content and format prescribed by technical standards.
Financial crime. The Money Laundering Regulations 2017, the FCA's Financial Crime Guide, the Proceeds of Crime Act 2002 and the UK sanctions regime.
Conduct of business. COBS applies to designated investment business, with client categorisation determining the extent of protections owed.
Operational resilience. Firms must identify important business services, set impact tolerances, and remain within those tolerances in severe but plausible scenarios.
Client assets. Where a firm holds client money or safe custody assets, CASS 6 and CASS 7 apply.
The FCA's supervisory priorities for wholesale markets
In March 2026 the FCA published its inaugural Regulatory Priorities report for Wholesale Markets, replacing the portfolio letters previously issued to supervised populations. The change in format is itself significant: the report is directed at senior management and sets out both supervisory expectations and the regulator's own planned activity across a defined period.
Five themes are relevant to wholesale banks.
Financial crime and market abuse
The FCA has identified weaknesses in anti-money laundering and market abuse frameworks across the supervised population. Specific findings include weak business-wide risk assessments, over-reliance on third-party due diligence, and underestimation of money laundering risk.
On market abuse, the regulator has identified gaps in surveillance arrangements: incomplete or inaccurate data feeds into surveillance systems, ineffective alert calibration producing either excessive false positives or missed activity, and weak testing and governance of surveillance models.
The last point is the one firms most often underestimate. A surveillance system that has not been tested against known scenarios, whose calibration has not been reviewed, and whose model governance is undocumented, is difficult to defend regardless of how sophisticated the underlying technology is.
Conflicts of interest and conduct oversight
The FCA expects firms to identify and manage conflicts of interest and to strengthen conduct oversight and accountability. A consultation on conflicts of interest and the application of Consumer Duty to firms primarily engaged in wholesale activity was signalled for the first half of 2026.
Conflicts management in wholesale banking is structurally demanding: the same institution may act as lender, adviser, market maker and principal in related transactions. The regulator's interest is in whether the firm's conflicts framework reflects how the business actually operates rather than how it is described in policy.
Operational resilience
The FCA has indicated that it will review a subset of wholesale banks' operational resilience self-assessments, and will undertake threat-led penetration testing under the CBEST framework across wholesale banks and trading venues.
Self-assessments are the document through which a firm demonstrates that it has identified its important business services, set impact tolerances on a defensible basis, mapped the resources supporting each service, and tested its ability to remain within tolerance. Where the self-assessment is a compliance artefact rather than a working document, that becomes apparent under review.
Data quality and transaction reporting
Transaction reporting data quality has been a persistent supervisory theme. The FCA has continued engagement with industry on improving the UK transaction reporting regime, with a policy statement expected during 2026.
Transaction reporting errors are among the most common causes of enforcement action against wholesale firms, and they are cumulative: a systematic misreporting issue affects every transaction of the relevant type until identified, which can produce very large populations of incorrect reports.
Individual accountability
The FCA, HM Treasury and the PRA are reviewing SM&CR with the stated aim of reducing the regime's regulatory burden. PS26/6 has been published as the first phase of these reforms.
Firms should note that reform is directed at proportionality and administrative burden rather than at the principle of individual accountability. The Senior Manager who holds a Prescribed Responsibility retains it.
The compliance function in wholesale banks
The FCA conducted a multi-firm review of the compliance function in wholesale banks, issuing a questionnaire containing 27 questions to a sample of 22 firms ranging from large global banks operating across multiple business lines to firms with a limited UK footprint.
The exercise reflects a supervisory interest not only in whether firms comply, but in whether the compliance function is positioned, resourced and empowered to make compliance likely.
Several themes are consistently relevant when assessing a wholesale compliance function.
Positioning and independence. Whether compliance reports through a route that preserves its ability to challenge revenue-generating business, and whether it has direct access to the board and the relevant Senior Managers.
Resourcing against business complexity. Whether headcount and expertise are proportionate to the firm's product range, trading activity and jurisdictional footprint. Firms that have grown business lines without corresponding investment in compliance capability are visible.
The first line and second line boundary. Whether responsibility for controls is clearly allocated, and whether the first line genuinely owns its controls or defaults to compliance for tasks that are properly business responsibilities.
Technology. Whether surveillance, monitoring and reporting systems are fit for the firm's activity, and whether the compliance function has the capability to operate and challenge them rather than relying on vendor assurance.
Monitoring. Whether the compliance monitoring programme is risk-based, whether it tests controls rather than confirming their existence, and whether findings are tracked to closure.
Recordkeeping and off-channel communications
SYSC 10A requires firms to record telephone conversations and electronic communications relating to certain regulated activities, and to retain those records.
The FCA reviewed 11 firms' arrangements for managing off-channel communications - those taking place outside monitored and recorded channels approved by the firm. The review found that all firms in the sample had made improvements over the preceding two years, but that breaches of internal policy continued to occur across all staff grades, with 41% involving individuals at director grade or above.
The seniority distribution is the finding that matters. Policy breaches concentrated among junior staff suggest a training issue. Breaches concentrated among senior staff suggest a culture issue, and culture issues are considerably harder to remediate and considerably more interesting to a supervisor.
The FCA also observed examples of non-compliance with policies on the use of personal mobile devices on dealing floors.
Firms should be able to demonstrate not only that a policy exists but that it is enforced, that breaches are detected rather than self-reported, that consequence management applies consistently across grades, and that the arrangements have been tested rather than assumed.
Building a defensible compliance framework
The components below are those a supervisor is most likely to examine and those where deficiencies most commonly appear.
Governance and accountability. A Management Responsibilities Map that reflects the actual allocation of responsibility. Statements of Responsibilities that are current. Prescribed Responsibilities allocated to individuals with the authority and information to discharge them. Committee terms of reference that align with how decisions are actually taken.
Risk assessment. A business-wide financial crime risk assessment that reflects the firm's client base, products, jurisdictions and delivery channels, updated when those change rather than annually by default. A conflicts of interest register that reflects the firm's actual business model.
Compliance monitoring. A risk-based monitoring programme testing the operation of controls, with findings, owners, deadlines and evidence of closure. Monitoring that confirms controls exist rather than testing whether they work will not satisfy a supervisor.
Surveillance. Market abuse surveillance covering the firm's traded products and communication channels, with documented alert calibration, periodic model testing, and governance over changes to scenarios and thresholds. Complete and accurate data feeds, with reconciliation between source systems and the surveillance platform.
Transaction reporting. Controls over completeness and accuracy, including reconciliation of reportable transactions against reports submitted, error identification and correction, and back-reporting where errors are historic.
Recordkeeping. Communications capture across all approved channels, retention meeting the applicable period, and arrangements to detect and address use of unapproved channels.
Operational resilience. Important business services identified, impact tolerances set and justified, resource mapping completed, scenario testing conducted, and a self-assessment maintained as a live document.
Training and competence. Role-appropriate training with completion tracked, and evidence that training is tailored to the firm's activities rather than generic.
Regulatory change. A horizon-scanning process, impact assessment against the firm's business, implementation tracking and board reporting.
Where firms most often have difficulty
Framework and practice diverge. The policy describes a control that operates differently in practice, or not at all. This is the most common source of supervisory finding and it arises from documentation that is not reviewed against operational reality.
Monitoring confirms rather than tests. A compliance monitoring programme that establishes that a control exists, rather than sampling its operation and reporting failures.
Surveillance is unexamined. Alerts are generated and closed, but calibration has not been reviewed, the model has not been tested, and no one can evidence that the system would detect the behaviours it is intended to detect.
Risk assessment is periodic rather than responsive. A business-wide risk assessment updated annually while the business has entered new markets, onboarded different client types or launched new products in the interim.
Findings are raised but not closed. Issues identified by compliance monitoring, internal audit or the regulator that remain open beyond their target date without escalation or revised plan.
Overseas branches and subsidiaries are under-supervised. The FCA has indicated it will review wholesale brokers' monitoring of overseas branches and subsidiaries, following identification of poor oversight and failure to remediate identified problems. The point applies more widely: group structures where UK oversight of overseas operations is nominal present a recognised supervisory risk.
Regulatory developments to track
Firms should maintain visibility of the following, each of which has been signalled by the FCA or is in train.
SM&CR reform, with PS26/6 published as the first phase and further work during 2026 aimed at reducing the regime's burden.
A consultation on conflicts of interest and the application of Consumer Duty to firms primarily engaged in wholesale activity, signalled for the first half of 2026.
A policy statement on improving the UK transaction reporting regime.
Commodity derivatives framework reforms set out in PS25/1, with implementation during 2026.
The consolidated tape for bonds and equities, with final rules and operator procurement in train.
A post-implementation review of the Investment Firms Prudential Regime, beginning with a call for input and followed by consultation.
A consultation on market risk capital requirements for investment firms.
Policy on ESG ratings providers, with rules taking effect at a later date.
Continued FCA and Bank of England survey work on the use of artificial intelligence and machine learning in UK financial services.
Dates and scope may change. Firms should confirm the current position against FCA publications rather than relying on secondary summaries.
About Regulatory Counsel
Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.
Our work with wholesale banking clients covers compliance framework design and review, regulatory gap analysis, compliance monitoring programme development, market abuse surveillance assessment, transaction reporting review, SM&CR implementation and Management Responsibilities Map development, financial crime frameworks and business-wide risk assessment, operational resilience self-assessment, remediation programme design, and preparation for supervisory engagement and thematic review.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA and PRA publications and take advice on their specific circumstances.
Frequently Asked Questions
Banks accepting deposits are dual-regulated. The PRA is responsible for prudential regulation including capital, liquidity and risk management. The FCA is responsible for conduct regulation, market integrity and systems and controls. Investment firms that are not deposit-takers are solo-regulated by the FCA under the Investment Firms Prudential Regime.
The FCA's Regulatory Priorities report for Wholesale Markets, published in March 2026, identifies financial crime and market abuse, conflicts of interest and conduct oversight, operational resilience, data quality including transaction reporting, and market effectiveness reforms. The report replaces the portfolio letter model previously used to communicate supervisory focus.
SYSC 10A requires firms to record telephone conversations and electronic communications relating to specified regulated activities, and to retain those recordings. In practice this requires firms to identify approved channels, capture communications on those channels, and take steps to prevent and detect use of channels that are not monitored.
The FCA reviewed 11 firms' arrangements and found continued breaches of internal policy across all staff grades, with 41% involving individuals at director grade or above. Firms are expected to demonstrate that policies are enforced and breaches detected, rather than that policies exist.
Incomplete or inaccurate data feeds into surveillance systems, ineffective alert calibration, and weak testing and governance of surveillance models. Firms should be able to evidence that surveillance covers the products and channels in scope, that calibration has been reviewed, and that the model has been tested.
Yes. The FCA, HM Treasury and the PRA are reviewing the regime with the aim of reducing its regulatory burden, and PS26/6 has been published as the first phase of reform. The reforms are directed at proportionality and administrative burden rather than at the principle of individual accountability.
A risk-based programme that tests the operation of controls rather than confirming their existence, covering the firm's principal regulatory risks, with findings recorded, owners assigned, deadlines set and closure evidenced. Coverage should reflect the firm's business model, product range and jurisdictional footprint.
Supervisory interest extends beyond outcomes to whether the function is positioned to be effective: its independence and reporting lines, resourcing relative to business complexity, the clarity of the boundary between first and second line responsibilities, the adequacy of its technology, and the rigour of its monitoring. The FCA's multi-firm review of the compliance function in wholesale banks examined these themes across a sample of 22 firms.