The FCA’s non-financial misconduct rules come into force on 1 September 2026. For regulated firms, this is not just another policy update. It changes how firms are expected to identify, assess and evidence conduct risk across the employee lifecycle.
The FCA has made clear that serious non-financial misconduct , including bullying, harassment and violence can be relevant to the Code of Conduct (COCON) and Fitness and Propriety (FIT) assessments.
That matters for screening.
Many firms still rely on traditional background checks: identity, employment history, criminal record checks, credit checks and regulatory references. These remain essential. But on their own, they do not always provide visibility of behavioural, reputational or digital conduct risk.
That is the gap now facing financial services firms.
If a firm’s screening model only looks at historic, formal records, it may miss the types of conduct indicators the FCA now expects firms to consider when assessing whether someone is fit and proper for a regulated role. This could be described as “behavioural gap” between legacy checks and modern conduct risk expectations.
The question is no longer whether screening is required.
The question is whether the screening framework is still fit for purpose.
Where things stand today
Under existing screening frameworks, most firms already assess candidates and employees against core financial services requirements.
That typically includes:
- identity verification
- right to work checks
- employment history verification
- qualification checks
- credit and financial probity checks
- criminal record checks where appropriate
- regulatory reference checks
- sanctions and adverse media checks for higher-risk roles
These checks remain an important part of regulated onboarding and workforce assurance.
But the FCA’s direction of travel is clear. Fitness and propriety is not limited to technical competence, qualifications or financial integrity. Behaviour, conduct and judgement all matter. The FCA states that FIT already allows firms to consider relevant misconduct wherever it occurs when assessing fitness and propriety, while new guidance clarifies how broader non-financial misconduct may be taken into account.
That creates a practical challenge.
Traditional checks are often designed to confirm whether something has been formally recorded. Non-financial misconduct may not always appear in a criminal record, credit report or employment reference. It may emerge through adverse media, social media, internal conduct processes, complaints, whistleblowing, or later employee lifecycle events.
That means screening can no longer be treated as a single onboarding step.
It needs to become part of an ongoing conduct risk framework to identify behaviours like bullying and harassment, threats or harmful conduct and Indicators of criminal or unethical behaviour.
What the FCA changes actually mean
The FCA has introduced new rules and guidance to help firms tackle non-financial misconduct more consistently. COCON 1.1.7FR will extend the scope of conduct rules in non-banking firms to cover bullying, harassment or violence against colleagues where the conduct relates to an individual’s role and has a sufficient work-related link.
The FCA has also confirmed that COCON and FIT operate separately. COCON focuses on certain work-related misconduct. FIT can take a broader view of whether an individual remains fit and proper, including relevant private-life conduct, social media issues and unproven allegations where these are material and relevant.
This does not mean firms are expected to monitor every employee’s private life or carry out blanket social media surveillance. The FCA is explicit that firms do not need to monitor employees’ private lives or social media accounts, investigate trivial or implausible allegations, or act contrary to privacy, employment or other relevant law.
But it does mean firms need a clear, proportionate and defensible process for dealing with relevant conduct information when it arises.
That is where screening frameworks need to evolve.
The screening gap
The biggest risk for firms is not that they have no screening process.
Most regulated firms do.
The risk is that their screening process is too narrow for the new regulatory environment.
A firm may be able to evidence that an individual passed a criminal record check, credit check and employment history check. But can it evidence that the same individual was assessed appropriately for conduct, integrity and reputational risk?
Can the firm show:
If not, there may be a gap between the firm’s policy position and its operational evidence.
What best practice screening now looks like
The firms best placed for September 2026 will be those that move from static onboarding checks to a risk-based, lifecycle screening model.
That does not mean screening everyone in the same way.
It means applying the right level of screening to the right roles, with a clear rationale and audit trail.
1. Risk-based screening by role
Not every role carries the same level of regulatory, reputational or conduct risk.
A proportionate framework should consider:
Higher-risk roles may justify enhanced due diligence, including adverse media screening, social media screening and civil litigation checks, where lawful and proportionate. The FCA has not mandated a specific screening checklist, but it does expect firms to apply judgement and make fair, consistent decisions.
2. Adverse media and reputational screening
Adverse media screening can help firms identify publicly available information that may be relevant to conduct, integrity or reputational risk.
This may include credible reporting relating to:
The key is proportionality. Adverse media should not be used as a blunt instrument. Findings need to be reviewed in context, assessed fairly and escalated through an agreed decision framework.
3. Social media screening where proportionate
Social media is one of the most sensitive areas of the new landscape.
The FCA has confirmed that private social media activity may be relevant to fitness and propriety where it indicates a material risk that the individual could breach regulatory standards.
That distinction is important.
Best practice is not blanket monitoring.
Best practice is a proportionate screening model that is:
For regulated or higher-risk roles, social media screening may be considered as part of a wider conduct risk assessment. This may include reviewing publicly available content for serious indicators such as harassment, threats, discrimination, violence or other behaviours that could call fitness and propriety into question.
4. Annual and event-driven re-screening
The biggest practical change is the move from one-time screening to ongoing assurance.
Fitness and propriety is not a one-off onboarding decision. Firms need confidence that individuals remain suitable throughout employment, particularly where responsibilities change or new information comes to light. The FCA specifically tells firms to review whether they need to update their approach to fit and proper assessments, conduct breach reporting and regulatory references before September 2026.
Best practice screening programmes are likely to include:
For Senior Management Functions, Material Risk Takers, Certified Persons and other high-risk groups, annual screening can support a more consistent and evidence-led approach to F&P.
5. Clear escalation and audit trails
A screening framework is only as strong as the decision-making process behind it.
Firms need clear answers to practical questions:
The FCA’s guidance is designed to support fair and consistent decision-making, but firms still need to exercise judgement in each case.
That makes auditability critical.
If a decision is ever challenged, the firm needs to show what information was available, how it was assessed, who reviewed it, what conclusion was reached and why.
What regulated firms should be doing now
September 2026 may feel some distance away, but the operational work should not be underestimated.
Firms should start with five practical actions.
1. Map roles by conduct risk
Identify which roles require enhanced screening, annual re-screening, or event-driven checks, like promotions.
2. Review current screening packages
Assess whether existing checks provide enough visibility of conduct, behavioural and reputational risk.
3. Define where social media screening may be appropriate
Agree where social media screening is proportionate, what risk indicators are relevant, and how findings will be reviewed.
4. Connect screening to F&P
Ensure screening outputs feed directly into F&P assessments, certification decisions and conduct risk reviews.
5. Build the evidence trail
Document workflows, escalation routes, decision criteria and review outcomes so the firm can evidence a consistent and defensible process.
How Giant Screening can support
Giant Screening works with regulated organisations to design and deliver screening frameworks that are practical, proportionate and audit-ready.
Through our technology and screening expertise, we support firms with:
Our iCHEX platform helps organisations apply checks consistently, manage workflows, capture decision points and maintain the evidence needed for internal governance and regulatory scrutiny.
The aim is not to create unnecessary friction.
The aim is to help firms move from point-in-time compliance to ongoing workforce assurance.
The FCA’s non-financial misconduct rules change the role of screening in financial services.
Screening is no longer just about verifying what a candidate has done before they join. It is becoming part of how firms identify, evidence and manage conduct risk throughout employment.
The firms that act now will be better placed to show that their approach is:
The firms that wait may find that their policies have moved on, but their screening processes have not.
And that is where the real compliance gap will sit.
