Regulatory Assurance

FCA Regulatory Health Checks and Thematic Review Preparation

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 10 min read

Key Takeaways

  • A regulatory health check is an independent assessment of a firm's compliance framework against current FCA requirements and supervisory expectations, conducted before the regulator does it.
  • The FCA's shift from portfolio letters to annual Regulatory Priorities reports has made supervisory focus more visible and more specific, which raises the standard expected of firms in identifying their own gaps.
  • Thematic and multi-firm reviews are a principal supervisory tool. Firms selected are given limited notice and are assessed on evidence rather than intent.
  • The most common finding across supervisory work is not absence of control but absence of evidence that the control operated.
  • A skilled person review under section 166 of FSMA is commissioned by the FCA and paid for by the firm. Preparation reduces both the cost and the findings.
Independent reviewer examining compliance framework documentation and control testing files in a City of London office, illustrating an FCA regulatory health check

Supervisory engagement is no longer principally a periodic event. The FCA gathers data continuously, publishes its priorities annually, and conducts multi-firm reviews across defined populations. A firm's first indication that it has a problem should not be a request for information from its supervisor.

A regulatory health check is an independent assessment conducted on the firm's own terms, against the same standard the regulator would apply. This article sets out what such a review covers, how thematic reviews operate, and how firms prepare.

[IMAGE]

Why firms commission a health check

Ahead of supervisory engagement. Where a firm expects a visit, a thematic review or a period of closer supervision, and wants to identify gaps while it still controls the timetable.

Following a change. New permissions, a new product line, entry to a new market, an acquisition, or growth that has outpaced the compliance function.

In response to a regulatory publication. A Regulatory Priorities report, a Dear CEO letter, a multi-firm review or an enforcement notice that identifies risks the firm may share.

On a change of senior management. An incoming Senior Manager taking on a Prescribed Responsibility will want an independent view of what they are accepting.

Before or after an authorisation event. Ahead of a variation of permission, or following authorisation where the framework built for the application must now operate.

As periodic assurance. Some firms commission an independent review on a defined cycle as part of their assurance framework, distinct from internal compliance monitoring.

What a health check covers

Scope should be defined by risk rather than by rulebook coverage. A review that attempts to assess every applicable rule at equal depth will be shallow across all of them.

Typical components include the following.

Governance and accountability. Whether the Management Responsibilities Map reflects the actual allocation of responsibility, whether Statements of Responsibilities are current, whether Prescribed Responsibilities sit with individuals who have the authority and information to discharge them, and whether committee arrangements match how decisions are taken.

Framework against practice. Whether policies and procedures describe what the firm actually does. Divergence between documented framework and operational reality is the most common source of supervisory finding.

Compliance monitoring. Whether the programme is risk-based, whether it tests the operation of controls rather than confirming their existence, and whether findings are tracked to closure.

Regulatory reporting. Whether returns are produced from operational records, reviewed before submission, and consistent with the underlying data.

Financial crime. Business-wide risk assessment, due diligence, transaction monitoring, sanctions and governance. Addressed in detail in our guide to FCA financial crime compliance.

Conduct and Consumer Duty. Where retail customers are involved, whether outcomes are monitored and evidenced rather than assumed.

Sector-specific obligations. Safeguarding, client assets, market abuse surveillance, appointed representative oversight, delegated authority, or whatever the firm's permissions require.

Findings and remediation. Whether issues previously identified by compliance, internal audit or the regulator have been closed, and whether closure was evidenced.

Methodology

An independent review that produces useful output follows a consistent method.

Document review against the applicable requirements, identifying where the framework is silent, out of date or inconsistent.

Sample testing of the controls that matter, examining what actually happened rather than what the procedure says should happen. This is the element most often omitted, and the element that produces the findings a supervisor would find.

Interviews with the individuals who operate the controls, testing whether practice matches documentation and whether staff understand why a control exists.

Data analysis where volume permits: monitoring outputs, complaints, breaches, reporting, and any operational data that indicates whether controls are working.

Findings report with each issue rated by risk, root cause identified, and a recommendation that is specific enough to act on.

Remediation plan with owners, deadlines and defined evidence of completion.

A review that produces a list of observations without prioritisation, root cause or a route to closure has moved the problem rather than addressed it.

Thematic and multi-firm reviews

The FCA conducts reviews across defined populations to assess practice against a specific requirement or risk. Recent examples across sectors include reviews of the compliance function in wholesale banks, off-channel communications, second charge mortgage affordability, and claims handling in general insurance.

Selected firms are typically asked to provide information within a defined period, and may be interviewed or visited. Findings are published in aggregate, and individual firms may receive specific feedback.

Two characteristics matter for preparation.

Notice is short. Firms are generally not given time to build a framework. Assessment is against what exists.

Assessment is evidential. The question is not whether the firm has a control but whether it can demonstrate that the control operated across the period examined.

Firms in a population that has been identified as a supervisory priority should assume they may be selected and prepare accordingly.

Section 166 skilled person reviews

Where the FCA requires an independent assessment, it may commission a skilled person review under section 166 of the Financial Services and Markets Act 2000. The firm pays.

Reviews may be commissioned across governance, systems and controls, financial crime, client assets, conduct, or any area within the FCA's remit. The scope is set by the regulator, the skilled person reports to the FCA, and the findings inform supervisory action.

Preparation does not avoid a section 166 review, but it materially affects the outcome. A firm whose records are complete, whose framework matches practice, and whose known issues are already in remediation faces a shorter, cheaper review with fewer findings than one where the skilled person is establishing the position from scratch.

Findings that recur across sectors

The framework and practice diverge. The policy describes a control that operates differently, or has been superseded, or was never implemented as written.

Monitoring confirms rather than tests. A programme that establishes controls exist without sampling whether they work.

Evidence is assembled rather than retained. The control operated and the record demonstrating it was created afterwards, under time pressure, from recollection.

Risk assessment is generic. A template describing sector-level risk rather than the firm's own exposure.

Findings remain open. Issues identified and recorded, deadlines passed, no escalation and no revised plan.

Management information does not enable challenge. Volumes and activity reported without outcomes, trends or exceptions, so governance has nothing to act on.

Growth has outpaced control. New products, markets or volumes absorbed without corresponding investment in compliance capability.

Where a review identifies deficiencies, our guide to FCA policy and compliance monitoring remediation addresses how remediation programmes are structured and evidenced.

About Regulatory Counsel

Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.

Our assurance work covers independent regulatory health checks and framework reviews, thematic review preparation, section 166 skilled person support, compliance monitoring programme design and assessment, governance and SM&CR review, control testing and file review, findings reporting with prioritised remediation planning, and support through supervisory engagement.

Contact our regulatory team at info@regulatorycounsel.co.uk.

This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.

Frequently Asked Questions

An independent assessment of a firm's compliance framework against current regulatory requirements and supervisory expectations, testing whether controls operate as documented and identifying gaps before the regulator does.

Compliance monitoring is the firm's own ongoing testing of its controls. A health check is an independent assessment of the framework as a whole, including whether the monitoring programme itself is adequate.

A supervisory exercise in which the FCA assesses practice across a defined population against a specific requirement or risk. Firms are typically given limited notice, and assessment is based on the evidence the firm holds.

A review by an independent skilled person, commissioned by the FCA under section 166 of FSMA and paid for by the firm. The scope is set by the regulator and the skilled person reports to the FCA.

Scope determines duration. A review focused on a single area may take two to four weeks; a full framework review across a firm with multiple permissions considerably longer. Scope should be set by risk rather than by attempting uniform coverage.

Absence of evidence rather than absence of control. In most cases the firm performed the activity and cannot demonstrate, from records created at the time, that it did.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert