Hong Kong CPD/RME HK
Book an intro

Non-financial misconduct and SMCR Phase 2: your questions answered

The FCA’s expanded Code of Conduct rules on non-financial misconduct took effect on 1 September 2026, bringing serious bullying, harassment and violence into regulatory scope wherever there’s a sufficient connection to a person’s work, even outside the office. At the same time, SMCR Phase 2 is working its way through Parliament, aiming to cut the regime’s administrative burden by around 50 per cent without reducing individual accountability. Together, these changes mean companies will need to get better at distinguishing serious regulatory risk from ordinary workplace conduct, while preparing for an accountability framework that’s less prescriptive but no less demanding.

Understandably, you have a lot of questions about what these changes mean and how to prepare for them. We answer them below. 

Non-financial misconduct and COCON

What actually changed on 1 September 2026?
The FCA expanded its Code of Conduct (COCON) so that serious bullying, harassment and violence towards colleagues can become a regulatory matter where there is a sufficient connection to the person’s work. This brings non-bank firms much closer to the position that has already applied to banks.

Does this mean every rude comment is now a regulatory issue?
No. The threshold is “serious” behaviour, not every bad-tempered exchange. The FCA’s guidance points to factors like repetition, impact, power imbalance and aggravating circumstances. A single incident can be serious, particularly where it involves violence or very serious harassment, but context always matters. Plenty of behaviour will still sit in the space between “acceptable” and “regulatory misconduct”, warranting an internal HR response without triggering a Conduct Rules breach.

When does behaviour have a “sufficient connection” with work?
There’s no simple time or location cut-off. Behaviour at the office, while working remotely, travelling for work, or at a company Christmas party is clearly work-related. Six colleagues meeting privately at the weekend, with no company involvement, is much less likely to fall within scope. The test throughout is whether a sufficient connection with work remains.

What about the party that spills over into a second venue?
This is where judgement is needed. If a later event is effectively a continuation of an official work event, or if problematic behaviour began at the original event and carried on afterwards, the connection with work can still apply. Relevant factors include who organised the second venue, how many of the same people attended, whether senior staff and their direct reports were present, and how much time passed. Calling something “private” doesn’t automatically make it so, especially if junior staff felt they were expected to attend.

Do firms need to monitor employees’ private lives?
No. The FCA has been explicit that firms are not expected to monitor employees’ private lives. If something private does come to a firm’s attention, it’s only relevant if it points to a real, material risk that the person will breach regulatory standards, not a remote or speculative one. Sometimes the right response is no investigation at all, and sometimes the right body to investigate is the police rather than the employer.

Does private conduct ever matter for regulatory purposes?
Yes, in limited circumstances. Serious private conduct can raise genuine questions about someone’s fitness and propriety, particularly if it suggests a willingness to ignore the law, abuse a position of trust, or take advantage of vulnerable people. The FCA cites a prison sentence, including a suspended sentence, as an example likely to be serious enough to matter, though firms still need to weigh the circumstances, time elapsed and evidence of rehabilitation.

Do firms need to monitor employees’ social media?
No, there is no general requirement to monitor employees’ private social media activity, and doing so raises its own data protection concerns. The question is only whether something that comes to the firm’s attention indicates a real risk, such as a threat of violence, evidence of criminal activity, or conduct suggesting a genuine harassment risk. A lawful, if controversial, opinion does not by itself put someone’s fitness and propriety in question. The Court of Appeal’s decision in Higgs v Farmor’s School sets clear limits on how far employers can go in policing lawful views expressed outside work.

How should firms decide whether something is worth investigating?
Start with the actual risk. Is there credible evidence, is it connected to the person’s role, and could it affect customers, colleagues, the firm’s reputation or the individual’s fitness and propriety? If the answer is no, there may be nothing further to do. If yes, investigate the relevant facts without turning it into a broader inquiry into someone’s private life. The threshold for “let’s look into this” is deliberately lower than the threshold for “we’ve established misconduct.” Managers are expected to escalate a concern, not diagnose it themselves.

Why does documentation matter, even when a firm decides not to investigate?
Deciding not to investigate is itself a decision. Firms should be able to show they weighed an allegation against a consistent framework, considered the evidence, and reached a reasoned conclusion. This protects the firm if the decision is later questioned and avoids the trap of over-reporting “just in case” as a substitute for proper judgement.

Does reporting more complaints mean a firm has a worse culture?
Not necessarily, and this is one of the FCA’s key points. A firm with more reported incidents may have a healthier speak-up culture, while very low numbers can simply mean people don’t feel safe raising concerns. Firms should look for patterns across whistleblowing reports, complaints, disciplinary cases, exit interviews and surveys, rather than treating a falling complaint count as a target.

How does this interact with sexual harassment and the Employment Rights Act?
From 30 October 2026, employers have a new duty to take all reasonable steps to prevent sexual harassment, alongside new third-party harassment provisions. A sexual harassment allegation can carry employment-law implications, regulatory implications, or both, so firms need a triage process that identifies every relevant obligation up front rather than treating it purely as an HR matter.

What is the relevance of the Crime and Policing Act 2026?
It expands corporate criminal liability for senior managers whose conduct affects the business, covering all offences rather than just economic crime. If a senior manager harasses staff or commits any other offence in the course of their employment and the firm fails to act, the business itself could be exposed to liability.

What should senior management be able to demonstrate?
That the system actually works in practice, not just on paper. This means showing how risks were assessed, how concerns were handled, and that managers understood what was expected of them. A policy alone is not a control; training is what demonstrates that people understood and used it.

SMCR reform

What’s the difference between SMCR Phase 1 and Phase 2?
Phase 1 is already happening, introduced through FCA and PRA rulemaking rather than new legislation. Changes took effect on 24 April 2026 (regulatory references, criminal record checks, the 12-week SMF cover rule, statements of responsibilities), 10 July 2026 (certification functions, enhanced regime thresholds), and 1 September 2026 (non-financial misconduct, covered above). Phase 2 is the larger legislative reform, which still needs to complete its passage through Parliament before regulators can build the detailed replacement rules.

What is Phase 2 actually trying to achieve?
The government and regulators share an ambition to reduce the administrative burden of SMCR by around 50 per cent, while maintaining individual accountability.

Is the Certification Regime being abolished?
Partly true, but easy to overstate. The government intends to remove the statutory framework, including the annual recertification requirement, from primary legislation. That doesn’t mean firms stop assessing whether key staff are fit and proper. Regulators are expected to consult on a more proportionate, risk-based replacement.

What’s changing for Senior Management Function approvals?
The reforms could reduce the number of SMFs requiring advance regulatory approval. For some roles, firms may assess fitness and propriety themselves and notify the regulator, rather than waiting for prior approval, though regulators retain the ability to require pre-approval where appropriate. This shifts more weight onto firms’ own internal assessments.

Are Conduct Rules being scrapped?
No. The government intends to remove some of the detailed statutory requirements around notifying regulators of Conduct Rules breaches and mandatory training, so the FCA and PRA can set the detail through their own rules instead. Current requirements continue to apply until they actually change, so firms should not cancel existing Conduct Rules training in anticipation.

What is the Financial Services and Markets Bill, and how does it relate to SMCR?
This is the formal name of the legislation introduced into Parliament on 19 May 2026 (previously referred to by its working title, the Enhancing Financial Services Bill). It completed committee stage in the House of Lords and entered report stage on 7 September 2026. SMCR Phase 2 sits within this Bill, which is broader still: it also contains provisions paving the way for the FCA to become the AML supervisor for legal, accountancy and trust and company service providers, with the government confirming the underlying Money Laundering Regulations obligations remain unchanged.

What should firms do now, ahead of the final Phase 2 rules?
Build an SMCR Phase 2 change register rather than pre-empting the legislation. Map current processes around certification, fitness and propriety assessments, Senior Manager approvals, Statements of Responsibilities, Conduct Rules reporting and training, and identify where the biggest administrative burdens sit. This puts firms in a position to act quickly once formal consultations begin.

How should HR and compliance work together on a misconduct allegation?
Non-financial misconduct is no longer purely an HR issue. HR typically leads the employment process, while compliance needs visibility of any regulatory implications, such as a potential COCON breach or fitness and propriety concern. The most effective approach is to agree to the process before an allegation arises. This involves a joint protocol setting out who investigates, who makes the employment decision and who assesses regulatory risk, so nothing is only discovered after the fact.

Read our guide: Non-financial misconduct and SMCR phase 2

Download it here →