FCA Compliance Monitoring Programme
Also called a compliance monitoring plan, this is how a regulated firm evidences that its policies and procedures are genuinely working, not just that they exist. We design and run risk-based compliance monitoring programmes that give your board real assurance and stand up to FCA scrutiny.
What Is an FCA Compliance Monitoring Programme?
How it differs from a one-off compliance audit or a policy pack
A Continuous Cycle, Not a Snapshot
An FCA compliance monitoring programme is the ongoing, structured cycle a firm runs to test whether its controls are actually working in practice, rather than whether they exist on paper. It is easy to confuse this with two things it is not. A one-off compliance audit is a point-in-time health check, useful before an FCA visit, after an incident, or ahead of a funding round, but it produces a single snapshot rather than continuous assurance. A policy pack is a static set of documents describing how the business should operate. Neither, by itself, tells the board whether the firm's controls are actually delivering the right outcomes on an ongoing basis.
A genuine monitoring programme sets out what will be tested, how often, using what method, and who reviews the results. It produces management information the compliance function and the board can act on, and it creates a documented trail showing that issues, once identified, are tracked through to closure. That combination, continuous testing plus a closed feedback loop, is what separates a working monitoring programme from a policy document sitting in a folder.
One-off Audit
A point-in-time review, useful for a specific trigger such as authorisation or an incident, but it does not tell you whether controls are still working six months later.
Policy Pack
A set of documents describing how the business should operate. Necessary, but it says nothing about whether staff are following the policy or whether it produces the right outcome.
Monitoring Programme
A continuous, risk-based cycle of testing, reporting and closure that gives the board ongoing, evidenced assurance rather than a one-off statement.
Why the FCA Expects a Monitoring Programme
SYSC 6.1.1R requires a firm to establish, implement and maintain adequate policies and procedures designed to detect the risk of failure to comply with its regulatory obligations, and to put in place adequate measures and procedures to minimise that risk. Having a policy does not, by itself, satisfy this rule. The FCA reads "adequate" as including some mechanism for checking that policies are being followed and are actually effective, which is exactly the gap a compliance monitoring programme is designed to close.
For firms operating under the Senior Managers and Certification Regime, responsibility for compliance monitoring typically sits with whoever holds the compliance oversight function, SMF16. That individual needs a genuine monitoring programme behind them to discharge the role credibly. Without one, they have no evidence base for the assurance they give the rest of the board, and no defensible answer if the FCA asks how they know the firm's controls are working.
More broadly, Principle 3 of PRIN requires firms to organise and control their affairs responsibly and effectively, with adequate risk management systems. Monitoring is how a firm demonstrates, rather than simply asserts, that its risk management systems are adequate. In supervisory engagement, the FCA generally draws a clear distinction between firms that can produce monitoring evidence, testing results, an issue log and board papers, and firms that can only produce a policy document.
What a Compliance Monitoring Programme Should Contain
The core components the FCA expects to see behind a credible monitoring plan
Risk-Based Scope
The plan should cover every regulated activity and Handbook obligation the firm is subject to, weighted towards the areas of greatest regulatory and customer risk rather than spread evenly.
Frequency and Sampling
Higher-risk areas are tested more often and in greater depth. Sample sizes should be large enough, and selected in a defensible way, to support a genuine conclusion.
Testing Methodology
A clear, documented method for each test: file reviews, MI analysis, control walkthroughs or observation, so results are repeatable and comparable over time.
Reporting Lines and MI
Findings flow to the right people quickly, with management information that shows trends over time rather than a single test result in isolation.
Issue Tracking and Closure
Every finding has a named owner, a deadline and a defined severity, logged centrally so nothing is resolved informally and then forgotten.
Board and Committee Reporting
Monitoring results feed a regular report to the board or a delegated committee, in terms non-specialists can act on, not just a compliance-team summary.
How to Build a Risk-Based Monitoring Plan
A monitoring plan built by copying a template rarely survives contact with a real supervisory visit. The method below is how a proportionate, defensible plan is actually constructed, starting from what the firm is permitted to do and working through to how issues get closed.
1. Identify regulated activities and permissions
Start with a precise map of what the firm is actually authorised and required to do. Pull the exact regulated activities from the FCA register, including any variations obtained through a Variation of Permissions, and note where the firm's activities sit close to the regulatory perimeter. Newly authorised firms building their first monitoring plan, and firms that have recently completed an FCA authorisation application, should treat this step as the foundation the rest of the plan is built on.
2. Map obligations to each activity
For each regulated activity, list the specific Handbook obligations, legislation and supervisory expectations that apply: conduct rules under the relevant sourcebook, complaints handling under DISP, financial crime controls where the firm carries transaction risk, and Consumer Duty outcomes across the customer journey. This mapping step is where generic, templated monitoring plans usually fail, because they test the same handful of topics regardless of what the firm actually does.
3. Risk-rate each obligation
Score each obligation for likelihood and impact: how likely is a control failure, and how serious would the consequence be for customers, the firm and the FCA relationship. This is a judgement exercise, not a mechanical one, and it should draw on real inputs such as complaints data, past findings, incident history and front-line staff feedback, not just a generic risk matrix copied from a template.
4. Set frequency and depth
Translate the risk rating into a testing cadence. High-risk areas might be tested quarterly with deep file sampling; lower-risk areas might be tested annually with a lighter-touch review. The plan should say explicitly why each area sits where it does, so the rationale can be defended to the FCA rather than simply asserted.
5. Define the testing method
Decide, for each area, whether the right method is file sampling against defined criteria, quantitative MI analysis, control walkthroughs, staff interviews, or a combination. File sampling in particular needs a genuine, unbiased selection method and a large enough sample to support a real conclusion; a handful of hand-picked files reviewed once a year does not constitute monitoring.
6. Define escalation and reporting
Decide in advance who sees findings, at what severity a finding gets escalated immediately rather than waiting for the next report, and how issues are tracked to closure with re-testing to confirm the fix worked. Without this step, monitoring produces findings that go nowhere, which is one of the most common gaps in practice.
Common Failures the FCA Finds
Patterns that recur often enough in supervisory work to be worth naming plainly
Testing Existence, Not Outcomes
Monitoring that confirms a policy exists and was signed off, without ever testing whether it produced the right result for a real customer. A policy can be perfect on paper and still fail in practice.
No Sampling of Real Customer Files
Monitoring built entirely from dashboards, MI and self-reported statistics, with no one opening an actual customer file to see what really happened. Aggregated data can look healthy while individual outcomes are not.
Findings With No Owner or Deadline
Issues logged in a spreadsheet with no named owner and no closure date, so they drift indefinitely. A finding without accountability is not one the firm can evidence it acted on.
No Re-testing of Remediated Issues
An issue marked closed as soon as a fix is implemented, without any follow-up testing to confirm the fix actually worked and has not quietly regressed.
Monitoring Under Consumer Duty
Consumer Duty has sharpened what monitoring needs to mean for many firms. It is no longer enough to confirm that a process was followed; firms are expected to monitor the outcomes customers actually receive across the four outcomes: products and services, price and value, consumer understanding, and consumer support. A compliance monitoring plan built before Consumer Duty came into force may need materially more outcomes-focused testing than it currently has: complaints themes, cancellation and switching patterns, vulnerable customer treatment, and value assessment data feeding back into product review.
The Consumer Duty board report requirement sits naturally on top of a working monitoring programme rather than as a separate exercise. Firms are expected to produce an annual report to the board assessing the outcomes customers are receiving, drawing on management information and testing evidence. A monitoring plan that already tracks outcomes data, complaints root causes and file-level findings makes that board report an exercise in synthesis. A firm without that underlying monitoring evidence is left trying to construct a credible outcomes narrative from very little.
How MEMA Helps
Programme design, ongoing testing and board reporting
As part of our wider work as FCA compliance consultants, MEMA designs, and where needed runs, compliance monitoring programmes for firms across the sectors we support. That includes principal firms with responsibility for overseeing an appointed representative estate, where monitoring the AR network is a specific FCA expectation in its own right, not an optional extra layered onto ordinary compliance monitoring.
Programme Design
Building a risk-based monitoring plan from your specific permissions, obligations and risk profile, not a generic template.
Annual Monitoring Calendar
A working calendar setting out what gets tested, how often, and by when, so monitoring actually happens rather than sitting as an intention.
File Testing
Structured sampling of real customer files against defined criteria, producing evidence the board and the FCA can rely on.
Thematic Reviews
Deeper reviews of specific risk areas, such as vulnerable customer outcomes or complaints handling, where a full annual review is not proportionate.
Board Reporting
Turning testing results into a board or committee report that is clear, evidenced and genuinely useful for governance.
Remediation Support
Helping design and track the fix once an issue is found, including the re-testing needed to confirm it actually worked.
If your monitoring programme was built for authorisation and has not been revisited since, or you are building one for the first time, book a consultation and we will assess what a proportionate compliance monitoring plan looks like for your firm.
Ex-FCA Judgement Behind Every Plan
MEMA is a London-based FCA compliance consultancy, founded by former regulators, at Office 1810a, 60 Tottenham Court Road, Fitzrovia.
Frequently Asked Questions
Common questions about FCA compliance monitoring programmes
What is the difference between a compliance monitoring programme and a compliance audit?
How often should a compliance monitoring programme be reviewed or updated?
Who is responsible for compliance monitoring under SMCR?
Does a small firm really need a formal monitoring programme?
What does the FCA look for in a compliance monitoring plan?
Ready to Build a Compliance Monitoring Programme?
Contact our compliance monitoring specialists to discuss a risk-based plan for your firm
📞 Phone: 0330 133 0811
📧 Email: contact@memaconsultants.com