Objectives
To walk through the Code of Conduct regulations in order to understand the FCA’s requirements. Some test questions are set out towards the end of this post.
Outcomes
- To understand who falls in the scope of the regulations
- To know what the FCA’s expectations are in respect of embedding the Code of Conduct
- To be able to readily recall the component parts of the Code of Conduct
- To be aware of what constitutes a breach and the actions that must be taken
Session resources
Read the full transcript
Hi, my name’s Jeff Abbott. I’m Regulatory Services Director here at 2be Development Consultancy.
In this short video, I’m going to take a closer look at the code of conduct. The FCA code of conduct is the third element of the increased accountability regulations designed to introduce a culture of responsibility, individual accountability across the industry and throughout all firms.
The regulations are quite clear. They expect people to have an understanding of the rules of the code of conduct. That understanding should be developed by what is referred to as suitable training, which ensures that people have an understanding of the overall rules, as well as a deeper understanding of how those rules affect them on a day to day basis.
The individual conduct rules there are five of them. They’ve been in place in the banks and building societies since 2016. They will be extended to all FCA regulated firms by the end of by the 9th December 2020.
I wonder if you can remember what they are?
Here’s a little clue as regards the TV show catchphrase. Say what you see so you can see a man pointing to a Bible. A businessman walking across a tightrope which seems rather precarious. Another man that’s signalling us to be quiet. A couple of people sitting in what appears to be a customer waiting /area where one person clearly is more comfortable than the other. And then what appears to be a music conductor waving his baton over a fruit and veg stall.
So what does this all mean?
Well, these are the five conduct rules, so you must:
- Act with integrity
- Due care, skill & diligence
- Be honest and open with the regulator
- Treat customers fairly
- Follow appropriate standards of market conduct
On a more formal basis, this is what they look like. So the idea is that we have to make sure that we train the relevant audience on these conduct rules. That they understand those, as well as how they apply on a day to day basis to their role.
In addition, there is another layer appropriate to senior management functions, so as well as the five rules, there are additional rules as well.
The emboldened one at the bottom is a PRA derived rule. The other obviously applies to both FCA and PRA firms. So, ensuring that the business is controlled, making sure where you delegate things that you do it in an appropriate way, remembering you can’t delegate the accountability for something and that obviously your honest and open with the regulator.
The scope of these regulations is quite widespread. So, it goes not only from the senior management functions, the non-executive directors, the certification population. It also goes to all other employees, except those that are deemed to perform what they describe as an ancillary function. Whether it’s a receptionist, a security guard or a maintenance person. Broadly this is a person performing a role that would be similar in nature as if it was performed in a company outside financial services. Now some companies are actually choosing to include the staff as well.
So, we’re all in it together, which is not a bad idea.
The senior rules, as they would suggest applying to the senior management functions, as well as the certification PRA key function holders and for non-executive directors there is the requirement, to be honest, and open with the regulators. These conduct rules apply to both authorised and non-authorised financial services business. If people are working for a relevant authorized person, a bank or building society, these rules also extend to non-financial services business as well.
So, what are the issues?
So why do people struggle to remember if you were to walk into a bank or building society and ask people about the code of conduct, would they actually remember? Now it could be because the way in which it’s been introduced to them by a means of e-learning. A once a year event and there’s been no follow up or embedding action.
People get a bit confused as to how this code; a professional code introduced by the regulator relates to the company values that they’re asked to follow as well. So, there’s no connection between the two that are being made.
And finally, when it comes to introducing the regulations, the regulator tends to focus on negative behaviours as examples of how the code is breached. We tend to respond far more positively when there’s positive reinforcement as opposed to examples of negativity. So perhaps that’s something that’s being done as well.
Now let’s think about, you must act with integrity. What does that actually mean to you as an individual?
If you stop and think about it and write that down, I would virtually guarantee that your answer would be different to the person next to you or across the room. Therefore, that gives the company a bit of a challenge as to how it creates one common understanding of what integrity means.
I’ll give you another example is here is a situation where you’re out with your partner for a meal. The bill comes and you run a cursory eye over it, and you notice that the sweets haven’t been added to the bill, so you’re given a number of choices. So, if you read through the choices, which one do you choose? Because, at the end of the day no matter which one you wish to choose, it’s quite important that you would respond to how the company wishes you to respond.
So, if you all chose to answer ‘A’ for instance, what if the company expects you to answer, Answer ‘E’. So, there is some work by the company to define what each of these conduct statements means, and what they expect you to do in a given situation.
One of the ways to think about it is this anecdote of President Kennedy’s visit to the Cape Canaveral Space Centre. Here we have a scenario where he’s on a guided tour. He comes across various people. The first man he comes across is sweeping the floors. He asks him what’s he doing. And he says, well I’m earning a living. And then he meets the next man, who says well I’m cleaning away all the rubbish. And the third man says Well Mr. President I’m helping to put a man on the moon.
So, here’s a situation that says everybody has a part to play within their company. They should know how their individual contribution, the way in which they behave on a professional basis contributes to not only the company succeeding, but also delivering that code of conduct on behalf of the regulator as well.
Now that’s something to think about.
Here are examples of how you might define integrity.
On the left-hand side, you might want to keep it short and simple.
- By keeping promises
- Maintain confidentiality
- Be honest and open etc
Or you can have more descriptive standards, as per option B. This is where you are providing full, clear, accurate and relevant information to customers whether internal or external. The choice is yours.
You don’t have to do either of these ways but where you can progress with this is the concept of personal charters.
So, if you keep the whole thing simple enough and train and help people apply it. Think about creating personal charters where the individual lists the commitments that they are going to make to deliver their part of the code of conduct. Now as part of the Performance appraisals or performance reviews, you can review with them how they’ve actually delivered on their commitments. They might well be able to give you examples or evidence of how they’ve done that. And it’s yet a further reminder and an action to embed this within the firm, and you stand a much greater chance of actually succeeding in this regulatory requirement of ensuring that everybody understands how the code applies to them.
Now as well as the personal charters, you look towards embedding these practices where appropriate into your processes. The standards that you measure of a person’s competence and you measure in their performance. You need to make sure at the end of the day you reward them appropriately for behaving the way you expect.
There are of course requirements that should there be a breach of the code, action may be necessary. It really is a deliberate act that is quite meaningful that is recorded as a breach. That there are laid down procedures of what you expect but inevitably this would have led to some form of written warning that was in process. At the end of the sort of year, as far as a regulator is concerned. This is the end of August. During the month of October, you have to make a submission to them to record those code of conduct breaches.
So, it’s really quite important that you have that process in place from the outset of these regulations. In other words, the 9th of December, to take care of any breaches that come.
Another thing that might cause an issue for the regulator, as well, is if you decide not to issue a certificate and the root cause is a code of conduct breach. Not only is that something that has to be reported in the annual return. The regulator expects an immediate notification. And this is laid down within the rules themselves. So, from the 9th of December, you would have already had to have trained your senior managers and your certification population on the code, but be prepared from that day also, to deal with any potential breaches that arise.
Now I hope that covers a brief introduction to the challenges of the code of conduct and that if there are any questions, please do get in touch.
Test Questions
For a Core Firm when must initial training of the Code of Conduct be completed for all Certification Functions?
- By 09 December 2019
- By 09 December 2020
- Before you issue the Certificate evidencing the person is FIT and proper
- 31 December 2019
When will all staff who are in scope but not SMFs, NEDs or Certification Functions need to have been trained on the Code of Conduct?
- By 09 December 2019
- By 09 December 2020
- By 31 December 2020
- By 01 January 2020
Which one of the following roles is not deemed to be an ancillary role by the FCA?
- Receptionist
- Maintenance Worker
- Claims Administrator
- Security Guard
Which of the following is not a requirement of the Code of Conduct?
- You must act with integrity
- You must act with due care, skill and diligence
- You must ensure your customers are satisfied with your service
- You must observe proper standards of market conduct
Which of these elements of the Code of Conduct apply to NEDs?
- You must take reasonable steps to ensure that the business of the firm for which you are responsible is controlled effectively
- You must act with reasonable steps to ensure that the business for which you are responsible complies with the relevant requirements and standards of the regulatory system
- You must take reasonable steps to ensure that any delegation of your responsibilities is to an appropriate person and that you oversee the discharge of the delegated responsibilities effectively
- You must disclose appropriately any information of which the FCA or PRA would reasonably expect notice
In what circumstances is a Code of Conduct breach reported immediately to the FCA?
- When it is deemed serious enough to issue a written warning to the employee
- When a Certificate is declined due to a breach
- When the employee fails the annual assessment on the understanding of the code
- When the level of competence of the employee falls below the expected standards
Test Question Answers
For a Core Firm when must initial training of the Code of Conduct be completed for all Certification Functions?
- By 09 December 2019
- By 09 December 2020
- Before you issue the Certificate evidencing the person is FIT and proper
- 31 December 2019
When will all staff who are in scope but not SMFs, NEDs or Certification Functions need to have been trained on the Code of Conduct?
- By 09 December 2019
- By 09 December 2020
- By 31 December 2020
- By 01 January 2020
Which one of the following roles is not deemed to be an ancillary role by the FCA?
- Receptionist
- Maintenance Worker
- Claims Administrator
- Security Guard
Which of the following is not a requirement of the Code of Conduct?
- You must act with integrity
- You must act with due care, skill and diligence
- You must ensure your customers are satisfied with your service
- You must observe proper standards of market conduct
Which of these elements of the Code of Conduct apply to NEDs?
- You must take reasonable steps to ensure that the business of the firm for which you are responsible is controlled effectively
- You must act with reasonable steps to ensure that the business for which you are responsible complies with the relevant requirements and standards of the regulatory system
- You must take reasonable steps to ensure that any delegation of your responsibilities is to an appropriate person and that you oversee the discharge of the delegated responsibilities effectively
- You must disclose appropriately any information of which the FCA or PRA would reasonably expect notice
In what circumstances is a Code of Conduct breach reported immediately to the FCA?
- When it is deemed serious enough to issue a written warning to the employee
- When a Certificate is declined due to a breach
- When the employee fails the annual assessment on the understanding of the code
- When the level of competence of the employee falls below the expected standards





