Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚑ TL;DR
From September 1, 2026, the UK Financial Conduct Authority’s new rule β€” COCON 1.1.7FR β€” brings serious bullying, harassment, and violence between colleagues inside its formal Code of Conduct for roughly 37,000 firms, not just banks. Firms must now investigate and record these incidents as regulatory conduct matters, not purely as internal HR issues. Non-UK companies with UK-regulated entities or UK staff are in scope.

The FCA non-financial misconduct rule β€” formally COCON 1.1.7FR β€” takes effect on September 1, 2026, and extends the Financial Conduct Authority’s Code of Conduct to serious bullying, harassment, and violence at roughly 37,000 UK-regulated firms. Until now, non-financial misconduct sat in a grey zone between HR policy and regulatory risk; from this date, it is a defined conduct issue that examiners can test firms against directly.

What is the FCA’s new non-financial misconduct rule?

COCON 1.1.7FR is a Financial Conduct Authority rule that pulls serious bullying, harassment, and violence toward colleagues into the formal Code of Conduct (COCON), applying it to all Senior Managers and Certification Regime (SMCR) firms rather than only banks. The rule follows Policy Statement PS25/23, published on December 12, 2025, which set out how the FCA would treat non-financial misconduct as a matter of regulatory concern.

Before this change, COCON’s conduct rules focused almost entirely on financial wrongdoing β€” market abuse, mis-selling, failures of due skill and diligence. Bullying and harassment were handled, if at all, through internal grievance procedures and employment law, with no direct line to a firm’s regulatory standing. The new rule closes that gap by requiring “a sufficient work-related link” between the conduct and the individual’s role, after which the incident falls within the regulator’s remit.

Which firms does COCON 1.1.7FR apply to?

The rule applies to the roughly 37,000 firms already subject to the Senior Managers and Certification Regime, including asset managers, insurers, brokers, payment institutions, and consumer credit firms β€” not just deposit-taking banks. This is the key expansion: earlier non-financial misconduct guidance was widely understood to bite hardest at large banks with heavy regulatory scrutiny.

Group structures matter here. A multinational with a UK subsidiary that holds FCA permissions β€” even a small payments or advisory arm β€” brings that entity’s staff and reporting lines inside scope. Global HR and compliance teams that assumed this was “a UK banking problem” should re-check which of their legal entities actually hold FCA authorisation.

Why is workplace misconduct rising even as reporting improves?

Reported workplace misconduct reached 55% of employees in 2025, up from 41% in 2024 β€” a near seven-year high β€” even as investigation and resolution rates hit record levels. This is the uncomfortable backdrop against which the FCA rule lands: better reporting culture is surfacing more problems, not fewer.

Industry survey data breaks the most common violation types into favoritism or nepotism (37%), bullying or intimidation (36%), conduct code and policy violations (27%), corruption, age or gender discrimination and sexual harassment (22% combined), and retaliation (21%). Nearly four in ten employees (38%) reported encountering multiple incidents, either repeated within one case or across separate events β€” evidence that today’s HR investigations are more complex than a single-incident model can handle.

On the response side, 78% of employees who witnessed misconduct reported it, and 75% of reported cases were investigated and resolved β€” up 16 percentage points on 2024, with 90% of employees saying the outcome felt fair. The gap that remains is visibility: only 56% of employees know an anonymous reporting channel exists, even though awareness of anonymous reporting roughly doubles the rate at which people actually use it. Remote employees also reported issues far more often (86%) than in-office staff experiencing the same problems (76%), a gap that firms building COCON-compliant processes cannot ignore.

What must firms actually do to comply before September 1, 2026?

Firms must be able to make and defend a documented judgment on what happened in each case, not simply point to an anti-harassment policy on file. The FCA’s guidance is explicit that a written policy alone does not satisfy the rule; the test is whether the firm investigated properly and reached a defensible conclusion.

Four practical steps stand out for firms with a September 1 deadline:

  • Map which legal entities hold FCA permissions and confirm which employees, contractors, and senior managers fall under COCON as a result.
  • Audit existing HR investigation records against the “sufficient work-related link” test β€” off-site conduct at work social events or on messaging platforms used for work purposes is very likely in scope.
  • Raise awareness of anonymous reporting channels, given the direct correlation between awareness and reporting rates found in 2025 survey data.
  • Brief senior managers on individual accountability, since SMCR already places personal responsibility on senior managers for the conduct environment they oversee.
πŸ’‘ Pro Tip: Treat this as a joint HR-and-compliance project, not an HR-only update. Compliance teams need visibility into misconduct investigations to assess regulatory exposure, and HR needs compliance input to know which cases carry a “sufficient work-related link.”

How does this rule interact with existing HR investigation processes?

COCON 1.1.7FR does not replace employment law grievance procedures; it adds a parallel regulatory reporting and record-keeping obligation on top of them. A firm can run its normal HR investigation and still fail the compliance test if the process, evidence, and conclusion are not documented in a way that would satisfy an FCA review.

Firms that already use structured HR analytics to track case volume, resolution time, and outcome consistency are better placed to demonstrate this. Coupling case-management data with the kind of measurement approach described in kurums.com’s guide to agentic people analytics gives compliance teams a defensible audit trail rather than a folder of disconnected emails.

What are the compliance risks of getting this wrong?

Firms that fail to properly investigate in-scope misconduct risk both a Code of Conduct breach against the firm and personal accountability findings against the senior manager responsible for oversight. Because COCON sits inside SMCR, a poor response to a bullying or harassment complaint can now surface in a senior manager’s fitness-and-propriety record, not just in an internal disciplinary file.

There is also a market-integrity dimension. Firms operating in the same 2026 environment as tightening AI governance expectations β€” covered in kurums.com’s guide to boardroom AI governance readiness β€” are already under pressure to show directors can evidence sound judgment on culture and risk, not only financial controls. Non-financial misconduct failures increasingly feed into that same board-level scrutiny.

⚠️ Warning: Do not assume conduct on personal social media or outside working hours is automatically out of scope. The “sufficient work-related link” test can capture conduct connected to a person’s role even when it occurs off-site or after hours, particularly at work-organized events.

How should global companies with UK operations respond?

Multinational firms should treat COCON 1.1.7FR as the leading edge of a broader global trend toward regulating workplace culture, not an isolated UK requirement. Embedding conduct-risk reporting into existing strategic operating rhythms β€” the same discipline behind frameworks like the one described in kurums.com’s OKR methodology guide for strategic alignment β€” helps ensure conduct metrics get board-level visibility rather than sitting solely inside HR.

Given that 2025 misconduct-survey data already shows record reporting volumes globally, firms outside the UK should expect similar expectations to spread through other regulators over the next 12–24 months, following the same pattern seen with SMCR’s original rollout from banks to the wider financial sector.

Are other regulators moving in the same direction as the FCA?

Yes β€” the FCA’s move follows a broader international pattern of regulators treating workplace culture as a supervised risk category rather than an internal HR matter, mirroring how conduct-risk frameworks expanded across banking after the 2008 financial crisis. The UK’s SMCR itself began as a bank-only regime in 2016 before widening to insurers and then, in 2019, to virtually all FCA-authorised firms β€” the same expansion path COCON 1.1.7FR is now following for non-financial misconduct specifically.

Other markets are watching closely. Financial regulators in the EU and parts of Asia-Pacific have signalled interest in similar non-financial misconduct disclosure requirements, and several global banks have already begun applying UK-style conduct-risk documentation to non-UK entities voluntarily, anticipating that group-wide consistency will be cheaper than retrofitting compliance market-by-market later. For multinational HR and compliance leaders, the practical read is that COCON 1.1.7FR is a preview of where global expectations are heading, not an isolated UK compliance cost.

What should a compliant investigation file actually contain?

A defensible investigation file needs a documented complaint intake, an evidence-gathering record, a reasoned conclusion tied to the “sufficient work-related link” test, and a record of the remedial action taken. The FCA’s emphasis on firms being able to “make and defend a judgment” means the reasoning matters as much as the outcome.

In practice, this means moving away from informal notes and verbal sign-offs toward a structured case file for every qualifying report: who was involved, what evidence was reviewed, why the firm reached its conclusion, and what happened next. Firms that already run structured, data-backed HR case management β€” rather than ad hoc email threads β€” will find it far easier to produce this file on demand during an FCA review, which is precisely why compliance teams are increasingly pulling HR analytics infrastructure into their audit-readiness planning rather than treating it as a separate department’s tool.

Frequently Asked Questions

Does COCON 1.1.7FR apply to firms outside the UK?
It applies to any legal entity holding FCA authorisation under SMCR, including UK subsidiaries of foreign parent companies. Staff and senior managers within that authorised entity are in scope even if the wider group is headquartered elsewhere.

What counts as a “sufficient work-related link”?
The FCA has not published an exhaustive list, but guidance indicates conduct connected to an employee’s role, colleagues, or work-organized settings β€” including after-hours events and work-related messaging platforms β€” can qualify, even if it happens away from the office.

Is this the same as the individual conduct rules under SMCR?
No. SMCR’s individual conduct rules already applied to personal accountability. COCON 1.1.7FR specifically extends the firm-level Code of Conduct to cover bullying, harassment, and violence as a distinct category of regulatory concern.

What happens if a firm has an anti-harassment policy but does not investigate properly?
Having a policy is not sufficient on its own. The FCA’s expectation is that the firm can demonstrate a documented, defensible investigation and judgment for each qualifying incident.

Does the rule cover remote employees?
Yes. The work-related link test applies regardless of work location, and 2025 data shows remote employees already report misconduct at a higher rate (86%) than in-office staff (76%), making remote-specific reporting channels a practical priority.

Son GΓΌncelleme / Last Updated: September 10, 2026


Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading