An investment firm's compliance monitoring programme should provide evidence that its regulatory controls work in the business that exists today. It should not be a fixed annual calendar copied from the previous year or a checklist designed mainly to prove that policies have been reviewed.
For firms within the relevant SYSC 6.1 framework, the compliance function must conduct a compliance risk assessment and establish a risk-based monitoring programme. The FCA's 2026 Consumer Investments Regulatory Priorities then provides a current sector lens: suitable products and services, fair value, strong governance, financial crime controls, effective AR oversight, operational resilience and good customer outcomes.
The exact programme depends on the firm. A discretionary wealth manager, financial adviser, platform, SIPP operator and CFD provider do not have the same risk universe. The monitoring plan should therefore begin with permissions, products, customers and distribution rather than a generic investment-firm template.
Build the programme from the compliance risk assessment
SYSC 6.1 expects relevant firms to base their monitoring programme on an assessment of compliance risk. That assessment should identify the regulatory obligations most capable of causing customer harm, market harm or a significant breach if the controls fail.
The risk assessment should reflect current business. Growth through acquisition, a new MPS proposition, increased use of ARs, entry into private markets, adoption of AI or a change in client profile can all alter the monitoring priorities even where the firm's permissions remain unchanged.
Risk should also respond to evidence. Complaints, file review findings, regulatory returns, incidents, audit reports and FCA publications can each reveal that an area deserves more attention than the annual plan originally assumed.
A risk-based programme therefore needs a mechanism for change. If the plan remains identical after a material business change or repeated adverse findings, the firm should challenge whether it is genuinely risk based.
Suitability and advice quality should be tested through files and decisions
For advice and discretionary firms, suitability is a central conduct risk. Monitoring should test whether the firm's COBS 9 or COBS 9A framework is operating in practice, including the quality of client information, risk assessment, capacity for loss, recommendation reasoning and records where relevant.
The sample should include higher-risk cases rather than depend only on random selection. Complex investments, replacement business, vulnerable clients, large withdrawals, unusual charges, concentrated portfolios and advisers with previous findings can each justify targeted testing.
Discretionary firms should also test mandate compliance and portfolio suitability. A robust onboarding assessment provides limited assurance if later portfolio changes move clients outside agreed risk, liquidity or investment restrictions.
Monitoring should distinguish administrative defects from substantive suitability failures. A missing document date and a recommendation that exposes a client to an unsuitable level of risk should not receive the same regulatory weight.
Consumer Duty should be monitored through investment-specific evidence
Consumer Duty monitoring should use evidence generated by the investment relationship. The products and services outcome can connect with proposition design and target markets, while price and value can involve advice fees, discretionary fees, platform charges and other customer costs.
Consumer understanding can be tested through suitability reports, cost communication, product literature and digital journeys. Consumer support can include transfer times, access to advisers, bereavement processes and vulnerable customer support.
The FCA's 2026 Consumer Investments priorities specifically expects firms to monitor outcomes and demonstrate fair value. The compliance programme should therefore assess both the quality of the outcome data and whether management acts on it.
A board report containing four green ratings should not be accepted as evidence if the underlying data shows one adviser population, portfolio size or customer group receiving weaker results.
Ongoing advice service delivery deserves a specific test
Financial advisers charging ongoing fees should have monitoring that verifies whether the contracted service is delivered. The FCA's 2025 ongoing advice review makes this a distinct current control issue rather than an administrative service-level question.
Testing should compare client agreements, scheduled review activity, evidence of completed work, disengaged-client processes and fee outcomes. Where the promised service was not delivered, the firm should understand whether fees continued and whether remediation is required.
The compliance team should also distinguish contractual service delivery from any periodic suitability requirement applying under the relevant COBS regime. The two can overlap, but they are not necessarily identical.
Repeated missed reviews can indicate a capacity or adviser-book problem. Monitoring should therefore consider whether adviser workloads and business growth make the proposition operationally deliverable.
Financial crime should be tailored to the firm's actual investment risks
The FCA's July 2026 findings on asset management and alternative firms reinforce the importance of business-specific financial crime controls. Firms should understand the risks inherent in their clients, products, jurisdictions, ownership structures and transaction patterns rather than import a generic AML framework from another sector.
Monitoring can test the business-wide risk assessment, customer due diligence, enhanced due diligence, sanctions screening, transaction monitoring, suspicious activity escalation and oversight of outsourced controls where applicable.
Private markets can require a different risk analysis from listed retail portfolios because ownership structures, cross-border flows and transaction visibility can be more complex. The monitoring plan should reflect the firm's actual exposure rather than assume all asset management has the same risk profile.
The FCA's 2026 Consumer Investments priorities also links financial crime with AR oversight and online scams. Principal firms should therefore consider whether AR financial crime risk is visible within the programme rather than assessed only at the directly authorised entity level.
AR oversight should be visible as a separate principal-firm workstream
A principal firm should not rely on the same monitoring plan for its own direct business and its Appointed Representatives. SUP 12 requires a distinct oversight framework, and the FCA's Consumer Investments priorities expects effective AR oversight.
Monitoring should examine onboarding, scope, risk ratings, financial promotions, advice quality, complaints, Consumer Duty outcomes, financial crime and annual AR review processes. The principal should be able to identify variation between ARs rather than rely on one network average.
The FCA's March 2026 report states that 29 percent of principal firms in its recent work had not conducted financial crime risk assessments for their ARs. That is a useful prompt for investment principals to test whether financial crime has been integrated into AR governance rather than assumed to sit solely with the AR.
Inactive ARs also require oversight. The FCA's April 2026 review makes clear that a lack of reported regulated activity can itself require challenge and should not cause the principal to stop monitoring the relationship.
Financial promotions and digital acquisition need live testing
Investment firms increasingly acquire customers through websites, social media, affiliates and online content. Monitoring should therefore test live promotions and customer journeys rather than only the version originally approved.
The 2026 Consumer Investments priorities notes the role of social media, finfluencers and scams. Firms should be able to distinguish legitimate financial promotion activity from content that is inaccurate, unclear or capable of exposing customers to foreseeable harm.
Where ARs or affiliates create content, the principal or regulated firm should understand the approval route and monitor drift after approval. Screenshots, archived pages and customer complaints can provide evidence of what was actually live.
Consumer understanding should form part of the test. A promotion can avoid an obvious rules breach while still creating a misleading impression through design or omission.
CASS and IFPR should be included where they actually apply
Investment firms should avoid two opposite mistakes: omitting client asset or prudential monitoring where those regimes are material, or applying CASS and IFPR as generic tests to firms outside their relevant scope.
Where CASS applies, monitoring can include client money and custody controls, reconciliations, acknowledgement arrangements, breach handling and governance. The depth should reflect the firm's CASS footprint and the risks in the relevant chapter.
Where MIFIDPRU and IFPR apply, the programme can test own funds, liquid assets, ICARA processes, concentration, regulatory reporting and wind-down planning as relevant to the firm. Regulatory Counsel already has separate IFPR guidance, so this article should not duplicate the detailed prudential regime.
The compliance risk assessment should identify which prudential and client-asset obligations are material to the legal entity and build monitoring accordingly.
Operational resilience and third parties should reflect the service model
The FCA's Consumer Investments priorities identifies operational resilience and material third parties as areas of focus. Investment platforms and other firms can expose customers to significant harm if systems fail, transfers stop or client data becomes unavailable.
Monitoring should test the obligations actually applying to the firm, including important business services and impact tolerance arrangements where relevant. It should also consider whether critical third parties are identified, governed and capable of supporting recovery.
The FCA's new operational incident and material third-party reporting rules take effect in March 2027. Firms within scope should build implementation into regulatory change management during 2026 rather than describe the future reporting regime as already live.
Technology risk should also include responsible use of AI where material. Compliance does not need to reproduce a separate AI audit in every programme, but should understand where automated tools can affect regulated decisions or customer communications.
Sampling should combine baseline assurance with thematic depth
Random file samples can help establish broad performance, but they should not be the only monitoring method. A risk-based programme should deliberately target areas more likely to reveal harm or control weakness.
Thematic reviews can be useful where several data sources point to the same issue. A rise in transfer complaints, for example, may justify an end-to-end service review rather than additional random advice files.
The programme should explain what each sample can demonstrate. A targeted sample of high-risk cases should not be presented as a statistically representative pass rate for the whole population.
Reviewer calibration also matters. If two compliance reviewers reach materially different conclusions from the same evidence, management cannot rely confidently on the aggregate results.
Findings should move through root cause, remediation and retesting
A compliance monitoring finding should identify the regulatory issue, customer impact, root cause, owner and action required. Repeated findings should not be closed through repeated training if the actual cause sits in a system, proposition or incentive.
Material customer impact may require review beyond the sample. The firm should consider whether other clients could have been affected and whether redress or proactive remediation is appropriate.
Closure should require evidence. A revised procedure proves that documentation changed, not that the control now works. Material findings should be retested after implementation.
The programme should then learn from its own results. An area producing repeated high-risk findings should receive more attention until evidence shows that the control has stabilised.
Senior management should see the risk story, not the testing volume
Management information should show the most significant findings, customer impact, trends, repeat issues, overdue actions and areas where assurance remains weak. The number of reviews completed is useful but should not dominate.
For firms within the relevant SYSC 6.1 framework, the compliance function needs sufficient authority, resources and access to perform its role objectively. Escalation should therefore allow significant compliance risk to reach the management body without being diluted through business ownership.
The board or governing body should be able to answer which investment compliance risks are currently highest, what evidence supports that assessment and whether remediation is working.
That is the purpose of the monitoring programme: to convert regulatory risk into evidence and management action.
How Regulatory Counsel can support
Regulatory Counsel supports investment advisers, wealth managers, platforms and principal firms with compliance risk assessments, monitoring programme design, thematic reviews, suitability QA, Consumer Duty, AR oversight and remediation.
We can review the existing programme or operate individual independent monitoring workstreams alongside the firm's compliance function.
Monitoring programmes are frequently built alongside our compliance support and compliance audit work, with dedicated testing of financial crime controls where the firm's risk assessment requires it.
Speak to Regulatory Counsel to discuss an investment firm compliance monitoring programme.
Frequently Asked Questions
No. The programme should be risk based and reflect the firm's activities, permissions, products, customers and regulatory obligations.
Not necessarily. A risk-based programme should prioritise material risks and change as business and regulatory evidence changes, subject to any specific review obligations applying to the firm.
For advice and discretionary firms, suitability testing is an important source of assurance. The sample and depth should reflect the firm's risk and the applicable COBS framework.
No. Those regimes should be included where they apply to the particular firm. The compliance risk assessment should identify the relevant prudential and client-asset obligations.
Yes. We can undertake individual themes, risk-based file reviews or a wider assessment of the firm's compliance monitoring framework.