On 1st September, the FCA’s new rules and guidance on non-financial misconduct came into force - intended to make it clearer about how firms should deal with serious workplace behaviour including bullying, harassment and violence.
At first glance, firms might reasonably ask what has actually changed. UK employment law already gives employers obligations around harassment and inappropriate workplace behaviour. The important difference is that the FCA is making serious misconduct a regulatory as well as a people and HR issue.
This is key because regulated financial institutions must now be able to establish what happened, demonstrate how they responded and, in serious and substantiated cases, potentially reflect that misconduct in regulatory references.
The trouble is we now live in a world where workplace conversations increasingly happen across channels such as WhatsApp and other messaging applications. If a serious allegation arises and the key part of a conversation between, say, a trader and risk manager has disappeared, the firm has a fundamental problem. Therefore, the biggest regulatory risk may therefore be an inability to demonstrate that appropriate controls were in place and that the firm acted properly when an allegation arose.
If a serious incident does happen across different communications channels and the firm cannot retrieve or reconstruct the relevant conversations, management can quickly find itself trying to answer a regulatory question without the evidence needed to support its answer. In financial markets, “we don’t know because we don’t have the records” is an increasingly awkward position to be in.
This is not to forget the people dimension too. Serious, substantiated misconduct can follow an individual through regulatory references rather than effectively disappearing when they change employer. Employees should therefore expect the boundary between workplace conduct and regulated conduct to become much clearer. A WhatsApp message does not stop being relevant simply because it was sent from a personal phone or outside the office.
That does not mean firms should start snooping on employees’ private lives. The FCA has been clear that firms are not expected to monitor private lives. But where communications are genuinely work related, the same standards of behaviour should apply whether the conversation happens face to face, over email or through a messaging app. Good records can also protect the accused as well as the complainant because investigations can be based on evidence rather than competing recollections.
While one should not expect a flood of fines immediately, the more intriguing period will come when the first serious cases test whether firms can actually evidence the controls and investigation processes they say they have in place. Financial institutions have spent decades improving their ability to capture trading and business communications. These rules create another reason why fragmented and off channel communications can become a regulatory liability. The firms that struggle will be those that discover after an incident that the evidence they need was sitting in a disappearing message or on a channel they could not access.


