The FCA Non-Financial Misconduct Proof of Compliance Template

The FCA's new rules take effect 1 September 2026, and a policy on paper is no longer enough. Firms must evidence that screening actually works. This free template shows you exactly what that proof looks like.

Complete the Form to Download

*Disclaimer: This template is a practical framework to support your compliance programme. It is not legal advice or a regulatory filing form. Firms remain responsible for their own compliance approach.

The FCA rules are changing. "We have a policy" won't be the answer.

The FCA's Policy Statement PS25/23 brings non-financial misconduct such as bullying, harassment, threats, and violence squarely inside the regulatory perimeter. From 1 September 2026, this conduct can count against an individual's fitness and propriety under the Code of Conduct (COCON) and Fit and Proper (FIT) sourcebooks, even when it happens online or outside the physical workplace.

Here's what's shifted: a completed policy or a training certificate is no longer sufficient. The FCA sets the outcome, not the method. That means the burden is on your firm to show a reasonable, risk-based programme is running and to act when credible information surfaces.

For compliance, HR, and talent acquisition teams, that raises one hard question: if the regulator asked tomorrow, could you evidence it?

A complementary, ready-to-use Proof of Compliance template

We built the template compliance and HR teams have been asking for. It's a structured record of a social media screening programme for non-financial misconduct, the kind of documented, defensible position the FCA now expects. It's a working framework, not a regulatory filing form. And, you can adapt every section to your firm.

What's inside?

Regulatory context, in plain English: what PS25/23 changes, who's in scope, and the legitimate-interest basis for processing data.

  • Screening scope: the behaviours mapped to the FCA's NFM perimeter (bullying and harassment, threats and violence, criminal activity), plus optional categories for firms that screen beyond the regulated minimum.
  • Capability evidence: training tracks for the people who run screening and the managers who act on it.
  • Screening results: a control-plan view of who was screened, what was found, and your flag rate.
  • Programme operations: screening cadence (pre-employment, annual re-screen, event-triggered) and how flagged cases are adjudicated.
  • Attestation and version control: sign-off structure for your Chief Compliance Officer (CCO).

What does "proof of compliance" actually mean under PS25/23?

The FCA's guidance is non-prescriptive by design. It tells you the outcome to reach a fair, consistent, proportionate, risk-based programme, but not the exact steps. That flexibility is also the challenge: your firm is responsible for producing the documentation and evidence.

In practice, a defensible programme can show four things:

  1. A documented, risk-based screening approach: clear scope, defined behaviours, and public-content-only screening.
  2. Evidence it's running: screening metrics that act as a control plan (who was screened, what was found, flag rate).
  3. Fair, consistent adjudication: every flag reviewed against a defined escalation path, with decisions recorded.
  4. A retained evidence trail: flag, source, context, adjudication note, and decision, available to the FCA or PRA on request.

The template gives you a structure for all four.

Built for the teams on the hook for 1 September 2026

This template was designed for the people who will be asked to evidence compliance, whether you run one office in London or hire across dozens of markets:

  • Chief Compliance Officers and SMF16 holders who need a defensible, board-ready record.
  • HR and People leaders balancing conduct risk with fair, documented process.
  • Talent acquisition and background screening teams building screening into hiring and re-screening.
  • Executive search firms and RPOs conducting due diligence on regulated-role candidates.

If your firm falls under the SMCR, whether a bank, asset manager, insurer, broker, wealth and payments firm, or one of the 37,000 non-bank firms newly in scope, this is for you.

Screening built for compliance, not guesswork

Fama is the innovator in social media screening. Our AI reviews public online content for workplace-relevant behaviour such as harassment and violence across 100 languages, while removing protected-class information to keep screening consistent and compliant.

  • Behaviour-first AI: that identifies the misconduct categories mapped to the FCA's NFM perimeter.
  • Compliance built in: SOC 2 Type 2 certified, EU-US Data Privacy Framework (and UK Extension) participant, and designed to meet GDPR, EEOC, and FCRA standards.
  • Public content only: no private accounts, no logins, no inferred protected characteristics.
  • Trusted at scale: 45M+ reports delivered to 3,600+ customers, with 99.5% data accuracy.

Get the template. Then make it yours.

Downloading the template is step one. Making it fit your firm, your roles, your risk appetite, and your cadence is where Fama comes in. Our team can help you turn the framework into a running programme before the deadline.

Non-financial misconduct compliance: quick answers

Q: What is FCA PS25/23? A: PS25/23 is the FCA's policy statement, "Tackling non-financial misconduct in financial services," published in December 2025. It confirms new rules and guidance clarifying that non-financial misconduct; such as bullying, harassment, and violence; can breach the Conduct Rules (COCON) and is relevant to the Fit and Proper (FIT) assessment. The changes come into force on 1 September 2026.

Q: What changes on 1 September 2026? A: From 1 September 2026, a new rule (COCON 1.1.7FR) extends the conduct rules to cover serious bullying, harassment, and violence in around 37,000 non-bank financial services firms, where there's a sufficient work-related link. Guidance also clarifies how misconduct in someone's private life, including online activity, can be relevant to their fitness and propriety.

Q: What is non-financial misconduct? A: Non-financial misconduct (NFM) is behaviour that isn't clearly financial in nature, for example bullying, harassment, discrimination, threats, and violence. Under PS25/23, serious NFM can amount to a conduct rule breach and can bear on whether someone is fit and proper for a regulated role.

Q: Is a policy or training certificate enough to prove compliance? A: No. The FCA expects firms to take a documented, defensible position and to act when credible information surfaces. Firms are responsible for producing evidence that a reasonable, risk-based programme is actually operating, not just that a policy exists.

Q: Is social media screening legal under GDPR? A: Screening public content for conduct risk in a regulated population can rest on legitimate interest, supported by the three-part test: a legitimate interest exists, the processing is necessary, and it's balanced against the individual's rights through proportionate, public-only screening. Fama screens public content only and removes protected-class information.

Q: Who is in scope for the FCA's non-financial misconduct rules? A: The conduct rule change applies broadly across SMCR firms, extending to around 37,000 non-bank firms in addition to banks, including asset managers, insurers, brokers, wealth managers, and payments firms.

Q: How can Fama help my firm prepare? A: Fama provides AI-powered social media screening that maps to the FCA's NFM behaviour categories, plus the documentation structure to evidence it. Download the template to start, then connect with Fama to customize it to your firm.

Don't wait for the first incident, or the first regulator request

1 September 2026 is a fixed date. The firms that will be ready are the ones documenting their programme now. Download the template today, and let Fama help you make it defensible.

For additional FCA resources, visit our FCA Non-Financial Misconduct Countdown Resource Center now.