Compliance

FCA Regulatory Change Management in 2026: A Practical Framework for Regulated Firms

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 11 min read

On this page

Regulatory change management should give an FCA-regulated firm enough time to identify a relevant change, decide what it means for the business, implement it properly and prove that the new control works. It is not the same as forwarding regulatory newsletters to senior management or maintaining a long spreadsheet of consultations that never become actions.

The challenge in 2026 is not simply the volume of change. Firms need to distinguish between different types of regulatory information and act at the right stage. A consultation paper may require impact analysis and planning but does not create final rules. A policy statement can fix the direction and implementation date. A Handbook instrument can change the legal requirement. FCA supervisory publications, speeches and Regulatory Priorities can affect the firm's risk assessment without necessarily changing the rulebook at all.

The FCA has also changed how it communicates supervisory priorities. In 2026 it introduced nine annual Regulatory Priorities reports to replace portfolio letters, while the Regulatory Initiatives Grid continues to provide a forward view of planned regulatory initiatives across the financial services system. A mature change framework should use both, but it should not treat either as a substitute for monitoring the actual Handbook, legislation and formal regulatory publications relevant to the firm.

Separate regulatory sources by status before assessing impact

The first control is classification. A firm should be able to tell whether a new item is law, a final FCA rule, guidance, a consultation, supervisory feedback, an enforcement or thematic publication, or an early policy signal. That status determines what the firm needs to do next.

A consultation paper normally creates an implementation risk rather than an immediate rule change. The firm may need to analyse likely impact, respond to the consultation, reserve technology capacity or alert the board, but it should avoid describing the proposal internally as a binding requirement before the FCA has made final rules.

A policy statement usually gives much greater certainty. It can confirm the final rules, implementation dates, transitional arrangements and changes made following consultation. The change record should then move from horizon item to controlled implementation.

Handbook changes and statutory instruments require precise rule mapping. The firm should identify which legal entity, permission, product, customer population or process is affected. A broad statement that "the FCA has changed the rules" is not enough for an implementation team to know what must change.

Supervisory publications need a different analysis. A multi-firm review may not change the legal text, but it can show how the FCA interprets current expectations and which controls it is likely to test. The firm should therefore consider whether the findings reveal a weakness in its own framework even where there is no new implementation date.

Horizon scanning should be systematic but proportionate

The FCA does not prescribe one universal horizon-scanning frequency for every regulated firm. The appropriate process should reflect the firm's size, permissions, products, jurisdictions and rate of regulatory change.

A small single-sector firm may be able to operate an effective process using a defined set of primary sources and clear internal ownership. A diversified group operating across insurance, mortgages, payments and investments will need broader coverage, more sophisticated filtering and stronger coordination between legal, compliance, product and business teams.

Primary sources should sit at the centre of the process. These can include FCA consultations, policy statements, Handbook notices, Regulatory Priorities, enforcement and supervisory publications, HM Treasury material, legislation and other relevant UK regulators. Trade bodies, law firms and compliance publications can be useful for interpretation and early warning, but they should not replace verification against the underlying source.

The firm should also monitor changes that do not arrive as a new FCA rule. Court judgments, Government legislation, Financial Ombudsman developments and changes from other regulators can alter the way a regulated activity needs to be operated.

The result should be a manageable pipeline rather than a news archive. Items with no plausible impact on the firm should be screened out, while potentially material changes should move into formal assessment.

Applicability should be decided at entity, activity and product level

Regulatory change often fails at the applicability stage. A headline may appear relevant to the sector but apply only to a particular permission, customer type, product or class of firm.

The assessment should therefore identify which legal entities are affected, which regulated activities are in scope and whether the change applies to retail or wholesale business, manufacturers or distributors, lenders or brokers, principals or ARs, or another specific population.

Group structures require additional care. One change may affect a UK regulated entity but not an overseas affiliate, while another may create different obligations for several entities in the same group. A group-wide policy update can be misleading if the legal requirements are not identical.

The applicability record should also explain why a seemingly relevant change is not being implemented. A documented non-applicability conclusion is useful governance evidence where the reasoning is sound.

Compliance should challenge assumptions based on commercial labels. Terms such as fintech, MGA, lender or wealth manager do not by themselves determine rule scope. The legal activity and regulatory status do.

Materiality should determine the implementation response

Not every regulatory change warrants a major project. The firm should assess materiality based on factors such as customer impact, regulatory breach risk, financial exposure, operational complexity, technology change, number of products or entities affected and the amount of management attention required.

A minor reporting-definition change may require a controlled data amendment and testing. A new product-governance regime may require policy, systems, contracts, training, governance and customer-remediation analysis across several business areas.

Materiality should influence escalation. Senior management does not need to approve every technical Handbook amendment, but it should have visibility of changes capable of affecting strategy, risk appetite, customer outcomes or significant operational resources.

The assessment should also identify dependencies. A rule change may appear straightforward until the firm discovers that a core supplier, distributor or technology platform needs to change first. Those dependencies should be identified early enough to manage implementation risk.

A useful materiality assessment therefore answers what changes, who is affected, what could go wrong and what level of governance is appropriate.

The regulatory change register should record decisions, not just publications

A regulatory change register should function as a control record. It should show the source, regulatory status, applicability, materiality, owner, implementation date, affected obligations, actions, governance and closure evidence.

The register should not become a dumping ground containing hundreds of links with no conclusion. Each material entry should have a clear next step, while screened-out items should contain enough reasoning to demonstrate why no action was required.

Ownership needs to be specific. "Compliance" is often too broad where implementation depends on product, technology, operations, finance or legal. The business owner responsible for changing the process should be identifiable, with compliance providing interpretation and challenge as appropriate.

Status should also be meaningful. Labels such as "in progress" can conceal substantial delay. Firms should distinguish impact assessment, design, implementation, testing and closure so management can see where the change is actually blocked.

Where a deadline moves or a consultation becomes a final policy statement, the register should be updated without losing the historical decision trail.

Impact assessment should map regulation to the operating model

A strong impact assessment translates regulatory text into concrete business consequences. It should identify the rules or expectations that change and then trace where those requirements sit in the firm's operating model.

That can involve policies, procedures, product terms, customer communications, systems, regulatory returns, contracts, governance, training, monitoring and outsourced arrangements. A change is rarely complete because the compliance manual has been updated.

The assessment should identify control owners and affected data. If a new rule changes a regulatory return, the firm may need to change system fields months before the first submission. If a product-governance rule changes information-sharing expectations, distribution contracts and MI may need to be revised.

Customer impact should be considered separately. Some changes affect only future business, while others require treatment of existing customers or remediation of historic arrangements. The implementation plan should make that distinction explicit.

The firm should also identify interactions with other regulatory projects. Two changes affecting the same customer journey should be coordinated rather than implemented through conflicting programmes.

Governance should match the significance of the change

There is no universal FCA rule that one specific Senior Management Function must personally own every regulatory change framework. Responsibility should follow the firm's governance, SMCR allocation where applicable and the nature of the change.

Compliance will often maintain the framework and provide regulatory interpretation, but business ownership is important. A technology change cannot be implemented effectively by compliance alone, and a product change should normally have accountable product or business leadership.

Material changes should have appropriate senior oversight. This can include a regulatory change committee, executive risk committee, board committee or governing body depending on the firm's size and the significance of the programme.

The governance record should capture challenge. A committee pack stating that all actions are green provides limited assurance if delivery dependencies or interpretation uncertainties are not visible.

Where the firm operates under SMCR, Statements of Responsibilities and wider responsibility mapping should be consistent with the governance actually used. The objective is clear accountability, not assigning every regulatory initiative to the same senior manager by default.

Implementation should cover policies, systems, contracts and people

Regulatory change is often weakened by treating documentation as the implementation itself. A new policy may explain the required control, but the underlying system, customer journey or commercial arrangement may still operate under the old framework.

The implementation plan should therefore identify every affected control type. Systems may require new fields, rules or permissions. Customer communications may need new disclosures. Supplier or distribution contracts may need new information rights. Procedures and scripts may need to change. Staff may need targeted training.

Training should be role specific. A short awareness session can be suitable for staff who only need to understand the existence of a change, while employees making regulatory decisions may require detailed practical instruction and competence assessment.

Third parties should be included where the firm's compliance depends on them. Outsourcing does not remove the need to ensure that relevant providers implement the change on time.

The project should also control transition. The firm may need to distinguish applications started before an implementation date from business written after it, or maintain separate treatment for existing and new customers.

Pre-implementation testing should challenge whether the control will work

Before a material change goes live, the firm should test the implementation rather than rely on project completion status. The test should reflect the type of control.

For a digital customer journey, this can mean end-to-end testing across desktop and mobile. For regulatory reporting, it can mean sample data extraction, reconciliation and dry-run submissions. For product governance, it can involve testing whether the required information is actually available to decision-makers.

Testing should include exceptions and edge cases where risk warrants it. A system can work perfectly for the standard journey while failing for vulnerable customers, manual overrides or products with unusual features.

Issues identified before implementation should be tracked to closure. Where a known defect is accepted for launch, management should understand the risk, interim control and remediation deadline.

This is particularly important where regulatory deadlines are fixed. A project marked complete because the implementation date has arrived can create false assurance if material defects remain open.

Post-implementation review should confirm the intended outcome

A regulatory change programme should not close automatically on the effective date. Material changes deserve a period of post-implementation assurance to confirm that the new process works and that unexpected consequences have been identified.

The evidence can include file reviews, system exceptions, complaints, customer outcomes, regulatory reporting data and feedback from operational staff. The right measures depend on the change.

Post-implementation review is also where the firm can identify control drift. Staff may create workarounds because the new process is impractical, or a technology solution may produce a different result from the design specification.

Where problems emerge, the firm should decide whether the issue is a defect in implementation, a misunderstanding of the rule or a wider product and customer-outcome problem.

Closure should therefore require evidence that the obligation has been embedded, not merely evidence that the project team delivered its actions.

Regulatory Priorities and the Grid should inform the pipeline differently

The 2026 Regulatory Priorities reports are sector-specific supervisory publications. They set out where the FCA expects firms in each market to focus and which areas of work the regulator plans to pursue. Boards and senior management should consider the report relevant to their business model and any other reports that cover material business lines.

The Regulatory Initiatives Grid serves a different purpose. The May 2026 edition provides a forward view of planned regulatory initiatives across the next 24 months. It is useful for resource planning and identifying dependencies across several regulators.

Neither source replaces formal rule monitoring. A Regulatory Priority can be significant without changing a rule, while a Handbook instrument can create an obligation even if it did not feature prominently in a priority report.

A good framework therefore uses the Priorities to shape risk and assurance, the Grid to support forward planning and primary legal and FCA sources to determine the binding change that must be implemented.

What should senior management see?

Senior management should receive a concise view of material regulatory change rather than the complete scanning log. The report should identify important upcoming deadlines, implementation risk, significant dependencies, overdue actions and any change capable of affecting strategy or customer outcomes.

The board should also understand where uncertainty remains. A consultation with a potentially material impact should be visible as an emerging risk without being presented as final law.

Management information should distinguish between identification, impact assessment, implementation and assurance. This allows leaders to see whether the firm's problem is interpretation, resources, technology or delayed remediation.

The practical objective is confidence that no material change is falling between functions and that the firm can demonstrate how it moved from regulatory source to operating control.

How Regulatory Counsel can support

Regulatory Counsel supports FCA-regulated firms with regulatory change frameworks, horizon scanning, impact assessments, rule mapping, implementation governance, policy and control updates and post-implementation assurance.

We can design the complete framework or support a specific material regulatory change programme.

Speak to Regulatory Counsel to discuss regulatory change management support.

Frequently Asked Questions

The FCA does not prescribe one universal scanning frequency for every firm. The process should be proportionate to the firm's activities, regulatory exposure and rate of change, with material developments identified early enough for effective implementation.

No. Consultation papers contain proposals, not final rules. Firms should assess likely impact and plan where appropriate, then update the programme when final rules and implementation dates are confirmed.

The Grid provides a forward view of planned regulatory initiatives across the financial services system. The May 2026 edition covers the next 24 months and can support firms' planning and resource allocation.

The FCA introduced nine annual Regulatory Priorities reports to replace portfolio letters. Firms should review the report relevant to their sector and consider other reports where they operate across several business lines.

Yes. We can design the source inventory, screening methodology, change register, impact assessment, governance, implementation and assurance process for FCA-regulated firms.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert