FCA NFM Guidance: Considerations for Social Media Screening
The FCA's non-financial misconduct rules are in effect. This legal white paper by Seyfarth Shaw's Senior Counsel, International Employment Law, Yana Komsitsky, shares insights about Social Media Screening that every global Financial Services firm needs to know.
Complete the form to download the white paper
* By downloading, you agree to Fama contacting you about this and related resources. This publication is for general information only and is not legal advice.
*Disclaimer: This is not legal advice. Contact your general counsel for questions and concerns.
The rules on conduct in financial services are widening. From 1 September 2026, non-financial misconduct against colleagues comes within scope of the FCA's Code of Conduct (COCON) for Senior Managers and Certification Regime (SMCR) firms when it relates to a person's role. New FCA Handbook guidance also takes effect the same day, reinforcing a simple point: trust in financial services depends on misconduct not going unchecked.
For firms, this raises a practical question. If conduct and people risk now reach beyond traditional financial or regulatory misconduct, where does that risk show up? And how do you assess it fairly and consistently?
Increasingly, it shows up online. Many people now catalogue their interactions across social media, and public activity can reveal behaviour relevant to fitness and propriety. The FCA is clear that firms do not need to proactively monitor employees' social media. But it is equally clear that personal social media activity and private-life behaviour can be relevant to a person's fitness and propriety where it indicates a material risk of a regulatory breach; for example, threats of violence, clear involvement in criminal activity, or conduct showing a material risk of bullying or harassment at work.
What's inside the white paper
This legal white paper unpacks that distinction and the considerations that follow. Use it as a practical, legally grounded guide for FSMA firms with a Part 4A permission. Inside:
- What changes under COCON 1.1.7FR on 1 September 2026, and what doesn't
- How COCON and FIT differ, and why that shapes your approach
- The FCA's stated examples of when personal social media activity becomes relevant
- A data protection checklist for lawful, proportionate review
- Seven areas to evaluate in any technology-assisted screening process
- Governance, escalation, training, and maintenance considerations
Complete the form to download the free guide and a full analysis, including the factors firms may weigh when deciding whether, and how, public social media information fits a broader compliance programme.
*For additional resources on the FCA, visit our FCA Non-Financial Misconduct Resource Centre here.
Author

Yana Komsitsky
Senior Counsel, International Employment Law and Data Law
Seyfarth Shaw LLP
* Licensed in California, England, and Wales, and a Certified Information Privacy Professional/Europe since 2014.
About the FCA’s new NFM regulations
What is non-financial misconduct (NFM)?
Non-financial misconduct is behaviour that is not clearly financial in nature, such as bullying, harassment, and violence. Left unchecked, this behaviour can harm individuals, firms, and public confidence in financial services.
What's changing on 1 September 2026?
FIT has always allowed firms to consider relevant misconduct, wherever it occurs, when assessing fitness and propriety. What's new is the clarified, broader view of conduct and organisational risk, and updated guidance on how firms can take a wider range of NFM into account.
From 1 September 2026, a new rule, COCON 1.1.7FR, extends the conduct rules in non-banking SMCR firms to cover bullying, harassment, or violence against colleagues where it relates to a person's role. It applies where there is a sufficient work-related link, and is no longer restricted to conduct that forms part of, or supports, financial services activities.
In practice, this means work-related NFM in non-banks falls within COCON if either the person responsible or the person affected works in the part of the business carrying out SMCR financial activities.
Where does social media come in?
Conduct outside the workplace can still be closely enough connected to work to fall within the rules. The FCA's own analogies include misconduct at a client-organised training event, an award ceremony, or a workshop. On social media, that could include people engaging with one another about work, or developing professional relationships online.
Personal social media activity can be relevant to fitness and propriety if it indicates a material risk that the person will breach regulatory standards. The FCA's examples include threats of violence, clear involvement in criminal activity, and conduct showing a material risk of bullying or harassment at work.
Conventional background checks and references still matter, but they have limits. A targeted review of public social media can add another source of insight when assessing continued suitability for senior manager, certification, and other higher-risk roles, particularly where conduct risk is heightened.
Does the FCA require firms to screen social media?
Legally, no. Effectively, yes.
The guidance expressly states that firms do not need to proactively monitor their employees' social media accounts. However, the guidance does recognise that public social media information may be relevant to fitness and propriety, and firms need to take and document appropriate measures to mitigate this risk.
It’s important to know that a screening process or product does not, by itself, demonstrate compliance with COCON, FIT, or any annual assessment obligation. Using a compliant social media screening provider can provide process and documentation guidance beyond screenings alone.
In short: screening is a considered, proportionate option, not a regulatory mandate on its own.
What about data protection?
Public availability does not remove UK data protection obligations. Any firm considering social media screening should assess the UK GDPR, the Data Protection Act 2018, applicable ICO guidance, and relevant employment law, addressing purpose, necessity, proportionality, transparency, data minimisation, accuracy, retention, security, individual rights, and the treatment of special category or criminal offense data.
A few principles the white paper draws out:
- Justify it. ICO guidance indicates a firm should be able to explain why reviewing public social media information is necessary and proportionate to an identified purpose and risk, and should limit the scope and method accordingly.
- Stay on public information. Accessing private profiles is not recommended.
- An FCA purpose is not enough on its own. The FCA materials may inform a firm's assessment of regulatory purpose and risk. But a firm must separately assess whether screening is necessary, proportionate, and lawful in its particular circumstances.
Can technology help? And where are its limits?
Social media screening tools can support parts of a screening workflow. Alone, however, a tool does not remove a firm's responsibility to design, document, validate, and oversee its own process. Vendor features should be evaluated against the firm's identified purposes, legal requirements, risk assessment, policies, and governance controls.
Best practices to consider when looking for a solution partner include:
- Data protection notice management: consistent, timely notices and record-keeping to support transparency, while the firm remains responsible for content, timing, and legal sufficiency.
- Data minimisation: role-related criteria, defined sources and time periods, exclusions, access controls, and human review, so broad review doesn't surface irrelevant or sensitive information.
- Lawful basis and necessity: documenting purpose and lawful basis, assessing less intrusive alternatives, and any required balancing test or impact assessment.
- Data retention: periods tied to a documented purpose and legal requirements, with an enforced deletion process.
- Escalation and response: governance for review, validation, escalation, correction, documentation, and periodic assessment.
- Training: for everyone who uses screening results, plus Senior Managers' own reasonable-steps obligations.
- Maintenance: periodic reassessment of legal basis, necessity, proportionality, scope, vendor controls, and accuracy, at points that fit the firm and the role.
How Fama’s social media screening technology supports an FCA-compliant approach
Fama’s social media screening solution helps FCA-compliant employers identify candidate or employee behaviours on social media that create regulatory risk. The solution analyses text, images, and video across a person's social media and online presence to surface relevant behaviour risk signals, and can be configured to match your firm's code of conduct.
Fama is built to support human judgement, not replace it. Fama does not score individuals, rank candidates, or make employment decisions. It aligns with the UK GDPR, the Data Protection Act 2018, applicable ICO guidance, and other applicable laws, and removes protected-class information so firms can apply insights responsibly and consistently.
Beyond the technology, firms can rely on Fama to help operationalise a targeted, documented, and proportionate review, the kind of consistently applied process that helps a firm explain the design and operation of what it does.