FCA conduct rules increase rescreening risk

FCA conduct rules increase rescreening risk

Financial services employers face sharper scrutiny over workforce conduct controls. New FCA misconduct rules increase pressure on rescreening programmes.


First Advantage has warned that financial services employers could face workforce and regulatory risk if they do not review employee rescreening programmes before new Financial Conduct Authority rules on non-financial misconduct take effect.

The FCA’s updated rules come into force on 1 September 2026 and broaden how misconduct is considered within regulated financial services. Behaviour including bullying, harassment, and violence can affect conduct assessments, fit and proper reviews, and the way organisations manage risk throughout the employment lifecycle.

First Advantage said input from a recent webinar suggested that many organisations still face barriers to effective rescreening. Employee experience and privacy concerns were cited by 38% of survey respondents, followed by operational complexity and resource constraints at 35%. Cost and budget pressures were identified by 27%.

The findings point to a practical governance challenge. Background screening has traditionally been concentrated at the point of hire. The new regulatory environment places greater emphasis on whether organisations continue to understand workforce risk after employees have joined, changed roles, gained access to sensitive systems, or moved into positions with higher conduct exposure.

The FCA’s policy statement on non-financial misconduct updated the Handbook to include guidance for companies applying its rules. The change forms part of a broader regulatory push to link workplace behaviour, culture, governance, and customer protection more closely.

Charlie Cove, customer success director at First Advantage, said: “While Financial Services firms are not suddenly being asked to evaluate entirely new types of risk, the regulatory lens they are scrutinised under is changing. Non-financial misconduct, employee behaviour, online conduct, and potential conflicts of interest can all affect workforce integrity, regulatory compliance, and trust.

“The challenge for businesses is that rescreening can feel sensitive when introduced without context. Employees need to understand why checks are being carried out, what they involve, and how the information will be used. Businesses that approach rescreening as a transparent, trust-building exercise and an ongoing part of governance will be better placed to protect their people, customers, and reputation.

“With the FCA’s new rules coming into force in September, now is the time for Financial Services businesses to move beyond a tick-box approach to screening and build rescreening programmes that are clear, fair, defensible, and aligned to the risk profile of the role.”

The warning arrives as regulated employers are already dealing with expanding obligations across conduct, operational resilience, consumer duty, technology risk, and senior manager accountability. HR, compliance, legal, and risk teams increasingly need a shared view of workforce integrity rather than treating employee behaviour as solely an employment relations issue.

Workplace enforcement is widening in other areas too, with the Fair Work Agency expanding holiday pay focus. Although the FCA rules apply to a different regulatory setting, both developments reflect closer scrutiny of how employers manage obligations during employment, not only when a contract is signed.

Rescreening is sensitive because it touches privacy, trust, proportionality, and employee relations. A poorly communicated programme can be perceived as surveillance or suspicion. A well-designed programme should define which roles require checks, what those checks cover, how often they occur, how data is handled, and what rights employees have.

Proportionality will be central. A senior manager, trader, adviser, complaints handler, payments employee, or worker with access to sensitive customer data may justify a different level of ongoing review from a lower-risk role. Organisations will need to connect screening frequency and scope to actual risk rather than applying a blanket approach without explanation.

The operational burden should not be underestimated. Rescreening can require policy updates, consent processes, data protection assessments, supplier management, escalation routes, HR training, and clear links to disciplinary and regulatory reporting procedures. Financial services employers operating across borders face additional complexity because local privacy and employment laws differ.

The regulatory direction is clear. Non-financial misconduct is no longer peripheral to financial services governance. Conduct outside direct financial activity can affect culture, trust, judgement, and customer outcomes. Employers that rely on pre-employment checks alone may find that their controls no longer match the level of scrutiny applied by regulators.