How the FCA’s New Conduct Rule Affects eComms Surveillance

Workplace Conduct Is Becoming a Regulatory Compliance Issue

On 1 September 2026, a new FCA rule, Code of Conduct (COCON) Sourcebook 1.1.7FR, brings serious bullying, harassment, and violence toward colleagues within the Code of Conduct for roughly 37,000 firms, including asset managers, insurers, and is expanding to non-banks.

Now, non-financial misconduct becomes both a Conduct Rules breach and a fitness and propriety consideration. For compliance and surveillance teams, it also creates a new challenge: electronic communications surveillance.

Why This Is More Than Another Policy Update

Many firms may initially approach this as a routine FCA Handbook update: read the policy statement, update the staff handbook, and provide non-financial misconduct training for relevant teams. The implications, however, extend much further. Here’s why:

First, the scope. The FCA’s final policy statement, PS25/23, confirms that non-bank SM&CR firms are being brought into much closer alignment with banks, where comparable non-financial misconduct standards have applied for years. For many of these firms, this is not a refinement of an existing framework; it’s the first time these firms will treat this behaviour as regulatory conduct rather than an internal disciplinary matter.

Second, the standard. Unlike harassment under the Equality Act 2010, conduct covered by the new COCON rule does not need to relate to a protected characteristic. As a result, the scope of what could constitute non-financial misconduct is broader than existing discrimination law and captures a wider range of behaviour than many firms are accustomed to considering when they think about what “counts”. As a rule of thumb, behaviour that involves violating a person’s dignity, degrading or humiliating them is likely to fall within scope.

Third, and perhaps most practically, non-financial misconduct often leaves a trace in electronic communications. The FCA has been explicit that it is not asking firms to police employees’ private lives or monitor personal social media activity. Instead, it is raising expectations around workplace conduct, and many of those interactions now take place through email, chat, and collaboration platforms.

As regulators broaden their view of what constitutes serious misconduct, scrutiny will increasingly focus on the channels where that behaviour is most visible. For firms, the challenge is not only detecting potential misconduct but also showing how it was assessed and addressed. Electronic communications surveillance can play a critical role in both, helping firms identify potential risk, support investigations, and demonstrate the rationale behind misconduct determinations when questioned by regulators.

This Isn’t Hypothetical: Enforcement Is Already Happening

This is no longer a theoretical regulatory risk. Enforcement is already underway. 

One of the most prominent recent examples is the FCA’s enforcement action against the founder and majority owner of a UK asset management firm. In March 2025, the FCA issued a Decision Notice proposing a £1.8 million fine and a ban from the UK financial services industry. Importantly, the FCA did not make findings on the underlying sexual harassment allegations themselves. Rather, although an internal investigation had identified numerous allegations of sexual harassment spanning many years, the FCA’s case focused on the individual’s alleged efforts to frustrate and obstruct the firm’s disciplinary process.  

That gap between “the harassment happened” and “we can actually take regulatory action on it” is precisely what the new September 2026 rule is intended to address. In announcing the case, the FCA stated that a culture in which misconduct allegations are not dealt with effectively can put consumers and markets at risk because it discourages reporting and weakens firm governance.

Important note: the matter remains subject to legal proceedings. The individual referred the FCA’s Decision Notice to the Upper Tribunal, meaning the FCA’s findings are currently provisional pending the Tribunal’s determination. 

In the United States, the SEC does not regulate workplace conduct directly. Instead, it has focused on whether firms have adequate disclosure controls and procedures. In February 2023, a major public company agreed to pay $35 million to settle SEC charges that it failed to maintain disclosure controls designed to collect and analyse employee complaints of workplace misconduct across its business units. According to the SEC, management lacked sufficient information about the volume and substance of those complaints to assess whether any material issues required disclosure to investors. 

Separately, the settlement also addressed alleged violations of the SEC’s whistleblower protection rule. The SEC found that certain separation agreements required former employees to notify the company if they received requests for information from SEC staff, language the regulator concluded could impede direct communications with the Commission.  

The significance of the case is that the SEC’s enforcement action was not based on findings regarding the underlying workplace misconduct itself. Rather, it focused on whether the company had appropriate controls to ensure potentially material information reached those responsible for public disclosures and whether its agreements complied with whistleblower protection requirements. 

The broader implication is clear: a firm that can’t see its conduct issues in aggregate can’t effectively manage, disclose, or defend them during a regulatory examination. This is as much a surveillance and data problem as it is an HR issue. 

The Challenge for Compliance: Managing Noise in a Broadening Risk Landscape

Instances of discrimination, harassment, workplace intimidation, and inappropriate language are complex, multifaceted challenges for firms to navigate and remediate. They can violate Code of Ethics and Personal Conduct policies, damage relationships internally and externally, and cause lasting reputational harm with downstream consequences for investment opportunities and outcomes. Under the new COCON rule, they now fall squarely within a firm’s regulatory conduct assessment.

The instinct, understandably, is to reach for a lexicon-based policy: build a list of terms, phrases, and patterns known to correlate with harassment or abuse, and let it flag hits for review. Lexicon policies work, and they will remain part of any credible surveillance programme. But they carry two structural weaknesses that this new regulatory environment will expose.

1. Noise

Lexicon-based policies built to catch harassment and abusive language are prone to false positives, and a significant share of that noise comes from inbound communications, including language a firm’s own employee didn’t write but received, quoted, or was copied on. A policy tuned to catch a term shows up equally when an employee is the target, the reporter, or an innocent bystander, and reviewers bear the burden of that ambiguity with every alert.

2. Evolution

Language describing discrimination and harassment doesn’t hold still. The underlying sentiment is constant, but the vocabulary carrying it evolves constantly, and it evolves differently across markets. English in London and English in New York diverge enough in idiom and register that a lexicon tuned on one can miss meaningful signal in the other. This is not a limitation of the model itself, but a reflection of the linguistic differences it must interpret. A global surveillance programme is really running several dialects of the same risk simultaneously, and a static term list can’t keep up without constant, resource-intensive re-tuning.

How ACA Can Help: Effective Surveillance Today and Adaptive Detection Tomorrow

ACA helps firms meet these evolving surveillance expectations by combining our ComplianceAlpha® eComms solution with experienced subject matter experts who conduct electronic communications reviews across a global client base. That combination of technology, policy expertise, and experienced reviewers helps firms build a practical, scalable approach to monitoring harassment and discrimination risk.

Tools Available Today

  • Noise reduction: ComplianceAlpha eComms includes noise detection capabilities designed to reduce the false positives commonly generated by harassment and discrimination policies. By filtering out irrelevant alerts, firms can spend less time reviewing noise and more time focusing on communications that may present genuine conduct risks.
  • HR-focused policies and risk insights: For alerts that pass noise reduction and lexicon screening, ComplianceAlpha eComms provides additional context to help reviewers assess risk more quickly and consistently.

Looking Ahead: AI-Powered Detection

AI-based policies are currently in active development. Harassment and discrimination do not always use the same words, but the underlying behaviour and sentiment often remain consistent. ACA is developing AI-based policies that can help identify these patterns, even as language evolves across regions, cultures, and communication channels.

While traditional lexicon policies remain an important foundation, AI has the potential to make detection more flexible, helping firms keep pace with how employees actually communicate. As the market continues to mature, firms that begin building these capabilities now will be better positioned for the future.

What This Means Before September

The FCA has been clear that only serious misconduct triggers a Conduct Rules breach, and whether conduct is considered serious depends on the facts and circumstances. Frequency, severity, seniority, and impact all factor in.

Surveillance technology may help surface communications for human review, but firms remain responsible for assessing the conduct and its regulatory significance. Firms that get this right between now and September will be the ones that treat detection technology, policy design, and human review as one connected system, rather than improving one component in isolation.

The deadline is fixed. The relevant conduct and the language used to express it may continue to change over time. Firms should not rely solely on the length of their surveillance lexicons when preparing for 1 September. They will be the firms whose surveillance programmes can continue learning as quickly as the language evolves.

See Conduct Risk More Clearly

Preparing for September 2026 starts with understanding where conduct risk appears and how it can be identified effectively. As regulatory expectations around non-financial misconduct continue to evolve, firms need surveillance programmes that can identify meaningful risk, reduce review noise, and provide the context reviewers need to make informed decisions.

Schedule a demo today to learn how ComplianceAlpha eComms solution helps firms strengthen electronic communications surveillance and build a more effective approach to conduct risk monitoring.

For firms looking to complement their technology investment, ACA’s non-financial misconduct training and regulatory compliance advisory services can help teams interpret evolving expectations, apply consistent judgement, and embed practical, sustainable conduct-risk practices. 

Frequently Asked Questions

The rule takes effect on 1 September 2026.

No. The COCON rule addresses serious bullying, harassment, and violence against colleagues where there is a sufficient work-related connection and the relevant Conduct Rules requirements are met.

No. The FCA states that firms do not need to monitor employees’ private lives or social media accounts.

Potentially. FIT operates separately from COCON and may permit firms to consider relevant misconduct more broadly when assessing fitness and propriety.