Remediation follows identification. A health check, an internal audit, a thematic review, a section 166 report or a supervisory letter identifies that something is wrong, and the firm must put it right and demonstrate that it has.
The difficulty is rarely knowing what to fix. It is designing remediation that addresses cause rather than symptom, evidencing that the change took effect, and doing so within a timetable the regulator regards as reasonable.
This article sets out how policy frameworks and compliance monitoring programmes are remediated, and what the FCA looks for in assessing whether remediation has worked.
[IMAGE]
Policy framework remediation
A policy framework fails for identifiable reasons, and the reason determines the remedy.
The framework describes controls that do not operate as written. The most common failure. The policy was drafted at authorisation, or by a predecessor, or copied from a template, and operational practice has diverged. The remedy is not to rewrite the policy to match practice without asking whether practice is adequate, nor to force practice into a policy designed for a different business. It is to establish what the requirement demands, what the business does, and to close the gap in whichever direction is correct.
The framework is internally inconsistent. Amendments made over time to individual documents without reference to the whole, producing conflicting statements across policies, procedures and process notes. The remedy is a mapped review across the framework rather than document-by-document amendment.
The framework is silent. An obligation exists and no document addresses it. Common where a firm has added permissions, products or markets without revisiting its framework.
The framework is not owned. No named owner, no review cycle, no trigger for update on change. Documents drift because nobody is responsible for them.
The framework is not read. Policies exist, are technically accurate, and are not used by the people operating the controls. Remediation here is a training and process issue rather than a drafting one.
An effective policy framework has a defined hierarchy, policy, procedure, work instruction, with each document owned, dated, versioned, subject to review, and traceable to the obligation it addresses.
Compliance monitoring remediation
The most frequent finding on compliance monitoring programmes is that they confirm rather than test.
A programme that establishes a control exists, that a policy is in place, or that a process is documented, tells the firm nothing about whether the control works. Supervisory expectation is that monitoring samples the operation of controls and reports failure.
Remediating a monitoring programme involves the following.
Risk-based planning. Coverage determined by the firm's principal regulatory risks, informed by the business-wide risk assessment, previous findings, complaints, breaches and regulatory focus. Not a rolling schedule that gives equal attention to every requirement.
Defined testing methodology. For each review: what is being tested, what evidence will be examined, what sample size and selection basis, and what constitutes a pass or fail.
Sampling that reflects risk. Selection weighted toward higher-risk activity, customers or individuals rather than random or convenience sampling.
Findings with root cause. Each finding recorded with the underlying cause, not only the symptom. A file that fails a review because a document was missing may indicate a process gap, a training gap, a system limitation or a capacity problem, and the remedy differs in each case.
Owners and deadlines. Every finding assigned to an individual with authority to fix it, with a date.
Evidence of closure. Closure supported by evidence that the change took effect, not by confirmation that action was taken.
Escalation. A defined route where findings are not closed by their deadline, and evidence that escalation occurs.
Reporting. Output to governance in a form that enables challenge: findings by risk, trend over time, overdue items, and repeat findings.
Root cause analysis
Root cause is the element most often missing and the one that determines whether remediation holds.
Symptoms are what monitoring finds. Cause is why it happened. Remediation directed at symptoms produces recurrence, and recurrence is what a supervisor notices.
Categories of cause that recur:
Process. The process does not require the control, or requires it at the wrong point, or permits it to be bypassed.
System. The system does not enforce the control, permits inconsistent data entry, or does not capture the evidence.
Capacity. The control is designed correctly and there are insufficient people to operate it at the required standard.
Capability. Staff do not understand the requirement or how to apply it.
Culture and incentive. The control conflicts with how performance is measured or rewarded.
Governance. Nobody owns the outcome, or the information reaching those who own it does not show the problem.
Remediation that addresses process where the cause is capacity will fail. So will training where the cause is system design.
Demonstrating remediation to the FCA
Where remediation follows regulatory intervention, the standard is evidence.
A plan the regulator can follow. Each finding, the cause, the action, the owner, the deadline, and the evidence that will demonstrate closure. Defined before work begins rather than assembled afterwards.
Progress reporting against the plan. Regular, honest about slippage, with revised dates and reasons where deadlines move.
Evidence of operation, not implementation. Implementing a control is not the same as demonstrating it operates. Closure evidence should show the control working across a period.
Independent validation. For material remediation, independent assessment that the remediation achieved what it intended. Self-certified closure carries less weight.
Governance oversight. Board or committee tracking of the programme, with evidence of challenge rather than receipt.
Customer outcomes where relevant. Where the deficiency affected customers, redress considered and the basis for the decision documented.
Where remediation programmes fail
The plan addresses findings, not causes. Each finding closed individually while the underlying condition persists, producing recurrence at the next review.
Deadlines are set without capacity. A programme committing to dates the firm cannot meet, producing slippage that itself becomes a supervisory concern.
Closure is asserted. Actions marked complete without evidence that the change took effect.
The programme runs parallel to the business. Remediation treated as a project separate from operations, so changes do not embed.
Governance receives status, not substance. Percentage complete reported without findings, causes or risks.
No validation. Nobody independently checks that remediation worked.
Where the underlying framework requires reassessment before remediation can be scoped, our guide to FCA regulatory health checks addresses independent review. Where deficiencies concern financial crime specifically, see our guide to FCA financial crime compliance.
About Regulatory Counsel
Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.
Our remediation work covers policy and procedure framework review and redesign, compliance monitoring programme development, root cause analysis, remediation plan design and delivery, findings tracking and closure evidencing, independent validation of completed remediation, governance reporting design, and support through regulatory engagement on remediation progress.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.
Frequently Asked Questions
Redesigning the monitoring programme so that it tests the operation of controls rather than confirming their existence: risk-based planning, defined testing methodology, risk-weighted sampling, findings with root cause, assigned owners and deadlines, evidenced closure and escalation.
Most commonly because they describe controls that operate differently in practice. Other causes include internal inconsistency following piecemeal amendment, silence on obligations the firm has acquired, absence of ownership and review cycles, and frameworks that are technically accurate but not used.
Establishing why a control failed rather than recording that it failed. Causes typically fall within process design, system limitation, capacity, capability, incentive, or governance, and the remedy differs in each case.
On evidence that the control now operates, across a period, rather than on confirmation that action was taken. For material remediation, independent validation carries more weight than self-certified closure.
For material remediation, yes. Independent assessment that the remediation achieved what it intended is more persuasive than self-certification, particularly where the deficiency was identified by the regulator.
Substance rather than status: findings by risk, root causes, actions and owners, evidence of closure, overdue items, and residual risk. Percentage-complete reporting does not enable challenge.
