Last updated: September 4, 2026
As of September 1, 2026, the FCA’s new COCON 1.1.7FR rule extends its Code of Conduct beyond banks to roughly 37,000 non-bank financial firms β insurers, asset managers, investment firms, and wealth managers. Serious bullying, harassment, or violence toward a colleague now counts as a Conduct Rules breach, can trigger a fitness-and-propriety review, and can be disclosed in regulatory references. The rule is not retroactive: it applies only to conduct occurring on or after September 1, 2026.
FCA Non-Financial Misconduct Rule 2026: What COCON 1.1.7FR Means for Bullying and Harassment Cases Outside Banking
The UK Financial Conduct Authority’s long-anticipated extension of its Code of Conduct sourcebook took legal effect on September 1, 2026. For the first time, non-bank financial firms face the same formal exposure that banks have carried for years: serious workplace bullying, harassment, or violence between colleagues can now be treated as a breach of the FCA’s Conduct Rules, not just an internal HR matter. This article explains what changed, who is affected, and what compliance, HR, and legal teams at insurers, asset managers, and investment firms need to do now that the deadline has passed.
Key Takeaways
What changed on September 1, 2026?
The FCA’s COCON 1.1.7FR rule came into force, extending Conduct Rules to serious non-financial misconduct at roughly 37,000 non-bank SMCR firms, including insurers, asset managers, and investment firms.
Who is now exposed to this rule?
Any firm’s “conduct rules staff” who bully, harass, or act violently toward a colleague in a work context, plus managers who knew about serious misconduct and failed to act on it.
What are the practical consequences of a breach?
A substantiated breach can trigger a Conduct Rules finding, a negative fitness-and-propriety determination, and disclosure in a future regulatory reference β affecting career mobility across the industry.
What Is the FCA Non-Financial Misconduct Rule and Who Does It Affect?
COCON 1.1.7FR is a new Financial Conduct Authority rule that extends its Conduct Rules to serious non-financial misconduct at non-bank Senior Managers and Certification Regime (SMCR) firms, effective September 1, 2026.
According to the FCA’s policy statement and confirmed by RWK Goodman, the rule captures workplace conduct toward a colleague that is either violent, or has the purpose or effect of “violating that person’s dignity” or creating “an intimidating, hostile, degrading, humiliating or offensive” environment β and this does not need to relate to a protected characteristic under discrimination law, a materially broader test than existing Equality Act claims.
Insurance Journal reports that approximately 37,000 non-bank financial firms across the UK now fall within scope, including asset managers, hedge funds, and insurers β firms that previously treated bullying complaints purely as an HR and employment-law issue must now build a regulatory reporting layer around the same allegations.
Which Firm Types Are Newly Covered by the Conduct Rules?
The rule newly applies to non-bank firms operating under the Senior Managers and Certification Regime, including investment firms, asset and fund managers, insurers, and wealth managers β firms that previously sat outside this specific conduct standard.
The following list covers the firm categories most directly affected by the September 1, 2026 extension, based on Freeths’ and White & Case’s analysis of the FCA’s final rules:
- Investment firms authorized under the SMCR
- Asset and fund managers
- Insurers (general and life)
- Wealth and private client managers
- Other FSMA-authorized firms holding Part 4A permission
Freeths notes that firms without Part 4A permission β payments and e-money firms, regulated investment exchanges, and credit ratings agencies β remain outside scope. Banks were already held to a comparable standard, so for them COCON 1.1.7FR mainly codifies existing expectations rather than introducing something new.
What Conduct Actually Counts as a Breach Under COCON 1.1.7FR?
Only serious, work-connected misconduct qualifies. A single sharp email or a one-off disagreement will not normally cross the threshold; the FCA is targeting a pattern of dignity-violating, hostile, or violent behavior connected to a person’s role.
White & Case’s analysis identifies a defined set of seriousness factors the FCA will weigh when assessing whether an incident is a Conduct Rules breach rather than an ordinary employee-relations matter. The following list covers the factors firms and investigators are expected to apply when grading an allegation:
- Repetition or duration of the behavior
- Impact on the person affected
- The seniority of the accused individual and any power imbalance
- Whether prior warnings had already been given
- Any criminal element to the conduct
- Whether the conduct alone would justify dismissal
Two Conduct Rules are most likely to be engaged: Conduct Rule 1 (acting with integrity) and Conduct Rule 2 (acting with due skill, care and diligence). White & Case’s analysis flags that Conduct Rule 2 can also be breached by a manager, not just the perpetrator β a manager who fails to intervene, ignores an internal policy, or does not maintain a safe working environment can be found in breach even without directly participating in the misconduct.
Managers carry independent regulatory exposure under this rule. Freeths’ analysis states that a manager who “knew, or ought reasonably to have known, about serious non-financial misconduct” and failed to take reasonable steps to prevent, escalate, investigate, or otherwise address it can face their own Conduct Rules breach β separate from any liability attaching to the person who committed the underlying misconduct.
How Does the Rule Change Fitness and Propriety Assessments?
Fitness and propriety assessments determine whether a person is suitable to hold a certified or senior management role at an FCA-regulated firm. Substantiated serious misconduct now weighs more heavily in that judgment.
Per the Freeths analysis, substantiated serious non-financial misconduct becomes “more likely to be treated as both a Conduct Rules issue and something relevant to whether the person remains fit and proper” β the same facts can now trigger two separate consequences: a Conduct Rules breach finding, and a fitness-and-propriety determination that can bar someone from a certified function altogether.
Law-firm guidance further notes that in some circumstances the FCA will look at conduct in an individual’s private life or on social media where it considers that conduct sufficiently relevant to fitness for the role β extending the honesty, integrity and reputation test beyond the physical workplace.
How Do Regulatory References Change Under the New Rule?
A regulatory reference is the mandatory disclosure a firm gives a new employer about a former employee’s conduct history when that person moves into another SMCR-regulated role.
According to White & Case, if misconduct is substantiated it becomes “more likely to appear in a regulatory reference because it may also be a Conduct Rules breach” β serious, substantiated bullying or harassment findings can now follow an individual across the industry, much like findings of dishonesty or market-abuse misconduct already do, materially affecting career mobility.
Because regulatory references now carry more weight, compliance teams should review their reference templates and sign-off process before the next reference request lands β retrofitting a rushed process under time pressure is where firms most often make defensible-but-embarrassing mistakes.
Why Is This Rule Change Happening Now?
The FCA moved to close a data gap it identified through its own supervisory work showing that bullying-related misconduct was rising and frequently going unreported to firms’ boards.
Insurance Journal reports a more than 70% increase in reported bullying misconduct across the three years through 2023, alongside findings that more than one-third of firms failed to escalate misconduct cases to their boards at all β this gap between what was happening and what reached senior oversight is the policy rationale the FCA cites for extending Conduct Rules beyond banking.
FCA Deputy Chief Executive Sarah Pritchard set out the regulator’s reasoning in its press release: “Behaviour like bullying or harassment going unchallenged is one of the reddest flags β a culture where this occurs can raise questions about a firm’s decision making and risk management.” That framing treats non-financial misconduct as a leading indicator of governance failure, a theme explored in Kurums’ analysis of the WorldCom scandal, where a permissive culture preceded a much larger corporate collapse.
What Should a Non-Bank Financial Firm Do Now That the Rule Is in Effect?
Firms that have not yet formalized their non-financial misconduct process face immediate exposure, since the rule is already live and any qualifying incident occurring today can be investigated and reported under it.
The following checklist covers the practical steps compliance, HR, and legal teams at newly-covered firms should complete as a matter of priority:
- Confirm which staff are “conduct rules staff” under your firm’s SMCR mapping, since only their conduct is directly captured
- Update whistleblowing, grievance, and disciplinary policies to reference COCON 1.1.7FR explicitly and to route qualifying cases to compliance, not HR alone
- Train people managers β not just HR β on the seriousness factors the FCA will apply, since managers now carry independent liability for failing to act
- Revisit your regulatory reference template and sign-off chain so substantiated findings are captured consistently and defensibly
- Brief the board on non-financial misconduct as a standing governance risk item, closing the escalation gap the FCA identified in its own data
- Avoid using the new rule as cover for expedited performance-based dismissals β several London employment lawyers have already flagged firms doing this, which creates its own legal risk
Firms building or refreshing formal oversight structures around this kind of conduct risk may also find it useful to review how board-level accountability is typically structured; see Kurums’ guide to board of directors structure for how executive and non-executive roles typically divide oversight responsibility.
Does the Rule Apply Retroactively?
No. The rule applies prospectively only, to conduct occurring on or after September 1, 2026, regardless of when an allegation later surfaces or is investigated.
This matters operationally: a complaint raised in 2027 about behavior from 2025 would not itself be a COCON 1.1.7FR breach, though it could still be relevant to a fitness-and-propriety judgment through other routes. Firms should record when conduct occurred, not only when it was reported, to classify cases correctly under the new regime.
Is This Only About Discrimination-Related Harassment?
No. The rule’s test is broader than the Equality Act’s protected-characteristic framework β conduct that is dignity-violating, hostile, or violent can breach COCON 1.1.7FR even where no protected characteristic is involved at all.
This is a consequential design choice. A “high-performing bully” scenario β a senior individual who mistreats colleagues generally rather than on discriminatory grounds β was previously easier for firms to treat as a performance or culture problem. KPMG employment lawyer David Cummings has noted that closing this exact gap, conduct overlooked because of an individual’s “rainmaker” status, was a specific aim of the FCA’s approach.
Frequently Asked Questions
What is COCON 1.1.7FR?
COCON 1.1.7FR is the FCA rule, effective September 1, 2026, that extends the Conduct Rules sourcebook to cover serious non-financial misconduct β bullying, harassment, and violence between colleagues β at non-bank SMCR-regulated firms.
Which firms are covered by the new FCA non-financial misconduct rule?
Roughly 37,000 non-bank firms authorized under FSMA with Part 4A permission, including investment firms, asset and fund managers, insurers, and wealth managers. Payments and e-money firms, regulated investment exchanges, and credit ratings agencies remain outside scope.
Does bullying now count as an FCA Conduct Rules breach?
Serious bullying, harassment, or violence connected to a person’s role can now breach Conduct Rule 1 (integrity) or Conduct Rule 2 (due skill, care and diligence), including for a manager who fails to act on a known incident.
Can non-financial misconduct affect a regulatory reference?
Yes. Substantiated serious misconduct is now more likely to be disclosed in a regulatory reference, since it may constitute both a fitness-and-propriety concern and a formal Conduct Rules breach.
Does the FCA rule apply to conduct that happened before September 2026?
No. COCON 1.1.7FR applies only prospectively, to conduct occurring on or after September 1, 2026, even if it is reported or investigated later.
Written by the Kurums Corporate Law & Compliance Editorial Team, based on FCA publications and law-firm regulatory analysis. This article is educational and not a substitute for advice from a qualified compliance or employment lawyer.
Discover more from Kurums | Business Intelligence
Subscribe to get the latest posts sent to your email.
