Supervisory engagement is no longer principally a periodic event. The FCA gathers data continuously, publishes its priorities annually, and conducts multi-firm reviews across defined populations. A firm's first indication that it has a problem should not be a request for information from its supervisor.
A regulatory health check is an independent assessment conducted on the firm's own terms, against the same standard the regulator would apply. This article sets out what such a review covers, how thematic reviews operate, and how firms prepare.
[IMAGE]
Why firms commission a health check
Ahead of supervisory engagement. Where a firm expects a visit, a thematic review or a period of closer supervision, and wants to identify gaps while it still controls the timetable.
Following a change. New permissions, a new product line, entry to a new market, an acquisition, or growth that has outpaced the compliance function.
In response to a regulatory publication. A Regulatory Priorities report, a Dear CEO letter, a multi-firm review or an enforcement notice that identifies risks the firm may share.
On a change of senior management. An incoming Senior Manager taking on a Prescribed Responsibility will want an independent view of what they are accepting.
Before or after an authorisation event. Ahead of a variation of permission, or following authorisation where the framework built for the application must now operate.
As periodic assurance. Some firms commission an independent review on a defined cycle as part of their assurance framework, distinct from internal compliance monitoring.
What a health check covers
Scope should be defined by risk rather than by rulebook coverage. A review that attempts to assess every applicable rule at equal depth will be shallow across all of them.
Typical components include the following.
Governance and accountability. Whether the Management Responsibilities Map reflects the actual allocation of responsibility, whether Statements of Responsibilities are current, whether Prescribed Responsibilities sit with individuals who have the authority and information to discharge them, and whether committee arrangements match how decisions are taken.
Framework against practice. Whether policies and procedures describe what the firm actually does. Divergence between documented framework and operational reality is the most common source of supervisory finding.
Compliance monitoring. Whether the programme is risk-based, whether it tests the operation of controls rather than confirming their existence, and whether findings are tracked to closure.
Regulatory reporting. Whether returns are produced from operational records, reviewed before submission, and consistent with the underlying data.
Financial crime. Business-wide risk assessment, due diligence, transaction monitoring, sanctions and governance. Addressed in detail in our guide to FCA financial crime compliance.
Conduct and Consumer Duty. Where retail customers are involved, whether outcomes are monitored and evidenced rather than assumed.
Sector-specific obligations. Safeguarding, client assets, market abuse surveillance, appointed representative oversight, delegated authority, or whatever the firm's permissions require.
Findings and remediation. Whether issues previously identified by compliance, internal audit or the regulator have been closed, and whether closure was evidenced.
Methodology
An independent review that produces useful output follows a consistent method.
Document review against the applicable requirements, identifying where the framework is silent, out of date or inconsistent.
Sample testing of the controls that matter, examining what actually happened rather than what the procedure says should happen. This is the element most often omitted, and the element that produces the findings a supervisor would find.
Interviews with the individuals who operate the controls, testing whether practice matches documentation and whether staff understand why a control exists.
Data analysis where volume permits: monitoring outputs, complaints, breaches, reporting, and any operational data that indicates whether controls are working.
Findings report with each issue rated by risk, root cause identified, and a recommendation that is specific enough to act on.
Remediation plan with owners, deadlines and defined evidence of completion.
A review that produces a list of observations without prioritisation, root cause or a route to closure has moved the problem rather than addressed it.
Thematic and multi-firm reviews
The FCA conducts reviews across defined populations to assess practice against a specific requirement or risk. Recent examples across sectors include reviews of the compliance function in wholesale banks, off-channel communications, second charge mortgage affordability, and claims handling in general insurance.
Selected firms are typically asked to provide information within a defined period, and may be interviewed or visited. Findings are published in aggregate, and individual firms may receive specific feedback.
Two characteristics matter for preparation.
Notice is short. Firms are generally not given time to build a framework. Assessment is against what exists.
Assessment is evidential. The question is not whether the firm has a control but whether it can demonstrate that the control operated across the period examined.
Firms in a population that has been identified as a supervisory priority should assume they may be selected and prepare accordingly.
Section 166 skilled person reviews
Where the FCA requires an independent assessment, it may commission a skilled person review under section 166 of the Financial Services and Markets Act 2000. The firm pays.
Reviews may be commissioned across governance, systems and controls, financial crime, client assets, conduct, or any area within the FCA's remit. The scope is set by the regulator, the skilled person reports to the FCA, and the findings inform supervisory action.
Preparation does not avoid a section 166 review, but it materially affects the outcome. A firm whose records are complete, whose framework matches practice, and whose known issues are already in remediation faces a shorter, cheaper review with fewer findings than one where the skilled person is establishing the position from scratch.
Findings that recur across sectors
The framework and practice diverge. The policy describes a control that operates differently, or has been superseded, or was never implemented as written.
Monitoring confirms rather than tests. A programme that establishes controls exist without sampling whether they work.
Evidence is assembled rather than retained. The control operated and the record demonstrating it was created afterwards, under time pressure, from recollection.
Risk assessment is generic. A template describing sector-level risk rather than the firm's own exposure.
Findings remain open. Issues identified and recorded, deadlines passed, no escalation and no revised plan.
Management information does not enable challenge. Volumes and activity reported without outcomes, trends or exceptions, so governance has nothing to act on.
Growth has outpaced control. New products, markets or volumes absorbed without corresponding investment in compliance capability.
Where a review identifies deficiencies, our guide to FCA policy and compliance monitoring remediation addresses how remediation programmes are structured and evidenced.
About Regulatory Counsel
Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.
Our assurance work covers independent regulatory health checks and framework reviews, thematic review preparation, section 166 skilled person support, compliance monitoring programme design and assessment, governance and SM&CR review, control testing and file review, findings reporting with prioritised remediation planning, and support through supervisory engagement.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.
Frequently Asked Questions
An independent assessment of a firm's compliance framework against current regulatory requirements and supervisory expectations, testing whether controls operate as documented and identifying gaps before the regulator does.
Compliance monitoring is the firm's own ongoing testing of its controls. A health check is an independent assessment of the framework as a whole, including whether the monitoring programme itself is adequate.
A supervisory exercise in which the FCA assesses practice across a defined population against a specific requirement or risk. Firms are typically given limited notice, and assessment is based on the evidence the firm holds.
A review by an independent skilled person, commissioned by the FCA under section 166 of FSMA and paid for by the firm. The scope is set by the regulator and the skilled person reports to the FCA.
Scope determines duration. A review focused on a single area may take two to four weeks; a full framework review across a firm with multiple permissions considerably longer. Scope should be set by risk rather than by attempting uniform coverage.
Absence of evidence rather than absence of control. In most cases the firm performed the activity and cannot demonstrate, from records created at the time, that it did.
