Most firms understand in broad terms which regimes apply to them. The harder question is what the FCA is actually scrutinising right now — which gaps are attracting supervisory attention, which rule changes require immediate action, and where enforcement risk is concentrated. This article cuts across the full regulatory landscape to give a current, practical view.
It is not a comprehensive listing of every regime in force — that would run to hundreds of pages and is better found in the FCA Handbook directly. The focus here is on where the regulatory risk is live and where firms are most commonly falling short.
Transaction reporting — the FCA's highest-volume enforcement area
Transaction reporting under UK MiFIR is the FCA's most actively enforced reporting obligation and has generated more financial penalties for investment firms than any other regime over the past five years. The FCA receives approximately 20 billion transaction reports annually and uses sophisticated data analytics to identify accuracy failures, completeness gaps and late submissions. A firm that believes its reporting is broadly compliant based on no negative feedback from the FCA is taking an unjustified comfort — the FCA often identifies issues years after the fact.
The regime requires investment firms to report details of transactions in financial instruments admitted to trading on UK venues to the FCA via an Approved Reporting Mechanism (ARM) by the end of the following business day (T+1). The fields required — instrument identification, counterparty details, quantity, price, timestamps, trader identifiers — are highly technical and error-prone. Field-level accuracy, not just submission volume, is what the FCA assesses.
Recent enforcement — transaction reporting
The FCA has issued numerous Final Notices for transaction reporting failures across a range of firm types — from global banks to mid-sized investment firms. Penalties in the range of £1–40m have been imposed for failures including: late reporting at scale, systematic field inaccuracies (wrong LEIs, instrument identifiers, counterparty classifications), and failure to report certain transaction types at all.
Market Watch 75 (2023) and subsequent editions have highlighted ongoing issues with: UTI (Unique Transaction Identifier) generation inconsistencies; incorrect population of the trading capacity field (principal vs agent); wrong or absent DEA client identifiers; and failure to report post-trade modifications and cancellations.
The FCA expects firms to conduct regular self-assessments of their reporting completeness and accuracy — not to wait for regulatory feedback. Firms that identify issues and self-report are treated more favourably than those where the FCA identifies the problem first.
Completeness reconciliation: Run monthly checks comparing your internal trade blotter against ARM submission confirmations. Every executed transaction in a reportable instrument must appear in the reports. Unexplained gaps are a regulatory risk.
Field accuracy: The most common field errors are: trading capacity (principal/agent/matched principal), buyer/seller LEIs for OTC transactions, instrument ISIN for off-venue transactions, and quantity/price field conventions. Check these specifically rather than relying on a general sense that reporting is working.
Surveillance of your own reports: Appoint someone responsible for monitoring ARM rejection rates and rejection reasons daily. Rejections not investigated and resolved promptly become completeness failures.
UK EMIR Refit — derivatives transaction reporting
UK EMIR Refit went live in September 2024 with significantly upgraded technical standards — 203 reportable fields (up from 129), mandatory ISO 20022 XML format, UTI waterfall, UPI requirements, and pairing and matching obligations at trade repository level. This is a materially more demanding regime than its predecessor. The FCA monitors matching rates; sub-80% rates attract supervisory attention. One year on, many firms continue to carry legacy inaccuracies from the pre-go-live period.
Common failure points — UK EMIR Refit
UTI generation and sharing failures — the UTI waterfall requires coordination between counterparties. Where both counterparties report the same trade with different UTIs, the report fails matching. Firms often do not have clear internal processes for UTI generation vs receipt.
UPI (Unique Product Identifier) population — many firms are still populating UPIs incorrectly or defaulting to legacy product identifiers. The UPI replaces the previous product classification approach and requires subscription to the ANNA-DSB service.
Back-reporting remediation — pre-go-live trades that were reported under the old standards should have been re-reported under the new standards. Many firms have not completed this exercise, leaving a legacy population of incorrectly formatted reports in the trade repository.
Matching rate monitoring: Pull your matching rate data from your trade repository regularly. Understand what is failing to match and why — UTI mismatches, counterparty LEI errors and valuation field mismatches are the most common causes.
Back-reporting remediation: If your firm has not completed a review of pre-Refit reports that require re-submission under the new standards, this should be prioritised. The FCA has been clear that historic accuracy is part of its assessment.
Delegation arrangements: If a counterparty reports on your behalf, you remain responsible for the accuracy and completeness of those reports. Obtain confirmation of matching rates and review the delegation agreement to ensure it includes appropriate data quality obligations.
MiFID / UK MiFIR — conduct, market structure and organisational obligations
MiFID II was onshored into UK law at Brexit and continues to apply as UK MiFID. The FCA's supervisory focus has shifted from initial implementation to ongoing standards — in particular, whether firms have maintained and evolved their MiFID frameworks as their businesses have changed, rather than building them once and leaving them static.
FCA supervisory themes — MiFID firms
Best execution: The FCA's multi-firm review of best execution (2023–2024) found that many firms had best execution policies that were not operationally implemented — policies existed but monitoring was inadequate, venue analysis was not conducted, and order routing decisions were not evidenced. The FCA expects firms to demonstrate, not just assert, best execution.
Conflicts of interest: The FCA continues to scrutinise conflicts frameworks — particularly at smaller firms where conflicts between the firm's own trading and client activity may not be adequately identified or managed. Soft commission arrangements, principal trading against client flow, and PA dealing policies are active areas.
Algorithmic trading (RTS 6): The FCA has made clear in Market Watch and bilateral supervisory engagement that RTS 6 obligations are not being taken seriously enough at smaller algo-trading firms. Annual self-assessments, algorithm approval processes, kill-switch documentation, and DEA provider controls are frequently deficient. Market Watch 74 and 76 cover algorithmic trading governance in detail.
Best execution: Review whether your best execution policy matches how you actually route and execute orders. Conduct quarterly venue analysis. Document the rationale for venue selection. If you have changed your execution arrangements, update the policy — stale policies are themselves a compliance failure.
RTS 6 — algo trading: Complete the annual RTS 6 self-assessment and ensure it reflects your current algorithms and controls. The self-assessment must document the governance process for approving new algorithms and changes to existing ones. Kill-switch and throttle controls must be documented and tested.
Product governance: If you manufacture or distribute financial instruments, your product governance framework (PROD) must be current. Target market definitions, distribution strategies and manufacturer/distributor agreements require ongoing maintenance — not a one-time build.
Market abuse and surveillance
Market abuse remains a priority enforcement area for the FCA. Recent Final Notices have covered insider dealing, market manipulation, and failures of firms' systems and controls to detect and prevent abuse. The SYSC 10A surveillance obligation — requiring firms to have systems and controls proportionate to the nature, scale and complexity of their business — is increasingly being tested through thematic reviews and enforcement investigations.
Recent enforcement themes — market abuse
The FCA issued Final Notices in 2024–2025 for market manipulation by trading firms involving spoofing and layering strategies — entering orders with no intention of execution to create a false impression of supply or demand. These cases involved both individual traders and firms held accountable for inadequate controls.
Insider dealing enforcement has continued with both criminal prosecutions and regulatory action. The FCA has signalled that it will pursue cases involving professional traders and advisers, not just individuals — the firm's failure to maintain insider lists and wall-crossing controls creates institutional exposure.
STORs (Suspicious Transaction and Order Reports) are monitored by the FCA. Firms that have low or zero STOR filings relative to their trading activity attract scrutiny — the FCA views this as a potential indicator of inadequate surveillance rather than a clean bill of health.
Surveillance calibration: Alert libraries must be calibrated to your specific strategies and instruments — not left on default thresholds from vendor implementation. The FCA expects to see evidence that thresholds have been reviewed and adjusted. Generic alerts that fire on everything (and are routinely dismissed) are worse than targeted alerts that generate fewer but higher-quality alerts.
Communications surveillance: Coverage must match your actual communication channels. WhatsApp, Teams, Slack and other messaging platforms used for business purposes must be in scope. The failure to capture and surveil off-channel communications is both a MAR issue and a regulatory records failure.
STOR governance: Maintain a STOR decision log — a record of all alerts escalated for potential STOR filing, the outcome of the investigation, and the decision on whether to file. No-file decisions must be documented. The FCA may request this log in a supervisory visit.
Insider lists: Active insider lists must be maintained for all projects involving material non-public information. Briefing external parties (prime brokers, administrators, advisers) on confidential matters without adding them to an insider list is a common and avoidable failure.
MiFIDPRU — prudential requirements
MiFIDPRU replaced the old IFPRU and BIPRU prudential frameworks in January 2022. Most firms have now completed their initial classification and submitted their first ICARA, but ongoing compliance is where standards slip. The FCA has been clear that ICARA is a living process — it must be updated when business model, strategy or risk profile changes materially, not just refreshed annually on a schedule.
ICARA quality: The FCA's review of ICARA submissions has found that many are formulaic and do not genuinely reflect the firm's risks. Wind-down scenarios are often unrealistic; stress tests are not calibrated to actual risk exposures. The ICARA must tell a credible story about how the firm would wind down in an orderly manner.
SNI threshold monitoring: Track AUM, on- and off-balance-sheet assets daily. Reclassification from SNI to non-SNI has significant capital and reporting consequences and must be notified to the FCA promptly.
RegData submissions: FCA090 (capital adequacy), FCA091 (liquidity), FCA092 (ICARA outcomes) — ensure these are submitted on time and accurately. Late or materially inaccurate submissions are an enforcement risk independent of the underlying capital position.
AIFMD — investment fund managers
UK AIFMD applies to managers of alternative investment funds — any collective investment undertaking that raises capital from investors to invest in accordance with a defined investment policy. The definition is intentionally broad. A manager that operates a pooled co-investment vehicle alongside SMAs may be operating an AIF without realising it. Below the AIFMD thresholds (£100m leveraged / £500m unleveraged), a lighter regulatory regime applies — in most cases this still requires Part 4A authorisation (not merely registration), but with lighter obligations than the full-scope AIFMD regime: reduced reporting, no mandatory depositary, and a streamlined governance framework. Above the thresholds, full-scope AIFMD applies with mandatory depositary, AIFMD remuneration code, Annex IV reporting and annual AIF report obligations.
Common failure points — AIFMD
Failure to obtain the required authorisation as a sub-threshold AIFM when managing a collective investment scheme — often where founders co-invest alongside external investors in what was intended to be an SMA structure. The FCA takes a wide view of what constitutes an AIF, and the sub-threshold lighter regime does not mean no obligations apply.
Annex IV reporting failures — incorrect leverage calculations, incomplete exposures data, late submissions. The FCA uses Annex IV data in its systemic risk monitoring; inaccurate or absent submissions are noticed.
AIFMD 2 (EU, April 2026): UK firms with EU-domiciled AIFs or EU AIFM delegation arrangements are affected by AIFMD 2's enhanced substance and liquidity management tool requirements. UK AIFMD has not yet been updated but firms with EU structures need to act now.
Perimeter check: If any pooled vehicle — however informally structured — raises capital from more than one investor and invests according to a defined policy, take legal advice on whether it constitutes an AIF requiring AIFM registration or authorisation.
Threshold monitoring: AUM must be calculated and monitored regularly against the AIFMD thresholds. Breaching the threshold triggers a 30-day window to apply for full authorisation — missing this is an enforcement risk.
Annex IV reporting: Ensure your Annex IV submissions are accurate and filed on time. If you use a third-party reporting agent, you remain responsible for the accuracy of the data submitted on your behalf.
SMCR — where ongoing standards slip
SMCR Phase 1 reforms are now in force (FCA PS26/6, 22 April 2026). Most changes took effect on 24 April 2026, with further changes on 10 July and 1 September 2026. The direction is simplification — but the core obligation of individual accountability is unchanged. The FCA's supervisory review found that many firms treat SMCR as a one-time exercise rather than a live governance framework.
Phase 1 changes now live: The 12-week SMF replacement rule has changed (firms now have 12 weeks to submit, not obtain approval). Criminal records check validity extended to 6 months; no longer required for intra-firm or intra-group SMF moves. Statements of Responsibilities and MRMs can be batch-submitted every 6 months. Update your procedures now.
Annual Certification: Certified persons must be formally assessed as fit and proper each year — documented and evidenced. Not a rubber-stamp. Certification records are among the first documents requested in an FCA supervisory visit to an investment firm.
Non-financial misconduct (from 1 September 2026): Conduct Rule breach reporting for individuals performing SMF functions must be reported as soon as reasonably practicable, not on an annual basis. Review your escalation and reporting procedures before September.
Phase 2 — watch: The FCA expects to consult on Phase 2 later in 2026. The most significant proposal is removal of the Certification Regime from FSMA — a structural change. Not yet law, but firms should monitor and avoid building processes that assume Certification continues unchanged.
Operational resilience and third-party risk
The FCA's operational resilience framework (PS21/3) applies to all FCA-authorised firms, but the requirements are explicitly proportionate to the nature, scale and complexity of the business. A new investment manager is not expected to have the same resilience infrastructure as a systemically important bank — but it is expected to have identified its important business services, set realistic impact tolerances, and tested them. The self-assessment deadline passed in March 2025. The FCA is now in active supervisory mode — asking firms to evidence their self-assessments, not just confirm they have done them. Third-party ICT risk is the area most commonly found to be inadequate, particularly among smaller firms that rely heavily on cloud infrastructure and third-party platforms without formal resilience assessments of those dependencies.
Self-assessment quality: The FCA expects your self-assessment to demonstrate genuine testing — not a theoretical analysis. Scenario testing results, remediation actions taken, and updated tolerance levels must be documented. If your self-assessment is a Word document that has not been updated since 2022, it is not compliant.
Third-party ICT register: Maintain a register of all material third-party ICT providers — cloud infrastructure, market data, trading platforms, surveillance vendors, ARMs. Assess concentration risk. DORA (EU, live January 2025) requires this explicitly for EU-connected firms; the FCA is moving in the same direction for UK firms.
Incident reporting: Material operational incidents must be reported to the FCA under SYSC. Review your incident reporting triggers and thresholds — underreporting is a compliance failure in its own right.
Is your firm keeping pace
with the FCA's current focus?
If any of the above has identified gaps in your current framework, a 30-minute conversation with James Lane will give you a clear picture of what needs attention and in what order. Transaction reporting, surveillance and SMCR gaps are the most common starting points.
Get in touch →