Compliance Monitoring Programme Document

The words compliance, rules and regulation written on a digital banner

FCA Compliance Monitoring Requirements

At the time a firm applies for FCA authorisation, and during the authorised period, they must maintain a Compliance Monitoring Programme Document. The requirement to complete this document is noted on the application form and in the supporting notes. The regulator expects every firm to document the checks undertaken to ensure compliance with the FCA Handbook rules. Below we look at the best format, criteria and regulatory requirements for FCA compliance monitoring.

Template for a Compliance Monitoring Programme

The FCA compliance authorisation application guide includes a summary of the monitoring programme requirements. However, they don’t provide a working template for use with the monitoring requirements. What they do offer is a basic layout of what a completed document could look like. This also includes the mandatory criteria for adequate records. The FCA expect you to document each regulatory requirement applicable to your business. You will then need to record: –

Policy checklist clipboard
  • What checks, actions or testing will take place?
  • How often will the checks take place?
  • Who will be responsible for the checks?
  • What records will be kept to evidence the checks?

How to Complete a Compliance Monitoring Programme (CMP)

The is one of the most searched questions for those applying for FCA authorisation! Many firms fall short during their application by submitting a CMP that is incomplete or not adequate. It can be confusing to document the actions you take to monitor compliance when you are not sure where to start. So, lets take a look at what you need to do to ensure your compliance monitoring programme document is compliant and effective.

FCA Expectations

SYSC 6 of the FCA handbook relates to compliance, internal audits and financial crime. It states that “a firm must establish, implement and maintain adequate policies and procedures sufficient to ensure compliance of the firm with its obligations under the regulatory system.”  In addition, firms must also monitor and assess the adequacy and effectiveness of their measures and procedures to ensure compliance.

The ‘adequate policies and procedures’ are the documents you implement that explain what you must comply with, why you must comply and how you intend to do it. You do not need to submit these documents with your application, but they must be readily available if requested. The Compliance Monitoring Programme Document is not about simply listing your policies and procedures. It requires you to document how you ensure that your compliance procedures are suitable and effective.

This results in establishing, maintaining and carrying out a programme of actions to check that you comply with both the regulatory requirements and your own compliance procedures.

Business Risks and Regulatory Requirements

Clipart showing man with speech bubble and targetWhere to start! You can’t write compliance policies and procedures and then monitor them for effectiveness until you know what you are complying with. Start by reviewing your regulatory activities and business type. The FCA’s Perimeter Guidance manual is the place to visit if you want to review your activities and find out whether you need authorisation or registration.

Once you know which FCA handbook modules and sourcebooks apply to your business type, you will be able to start documenting which rules apply to your firm. Some of the modules apply to all firms (think PRIN, COND, GEN, SYSC and FC!) However, you may need to comply with additional modules or sourcebooks for areas such as insurance, mortgages, consumer credit or debt collection.

It doesn’t matter which format you choose to document the application regulatory rules and guidance. What’s important is that you know what they are and have them readily accessible. From this point you can develop and implement compliance policies, procedures and controls to comply with the relevant FCA requirements.

Compliance Monitoring Checks

Okay, so you have all your FCA regulatory requirements documented in a compliance monitoring programme document. You now need to start adding your actions, checks and testing functions for each requirement.

This is not something that can be supplied on a template as it is bespoke to each firm. However, once you have your regulatory requirements and business risks documented, you will be well on your way towards a compliant monitoring programme.

An example of our ready to use compliance monitoring programme document is over on the right for your reference.

Compliance Monitoring Programme Document Sample

Frequency, Responsibility & Records

You will now have a document containing your regulatory requirements and the actions you take to monitor compliance. You now need to record how often you carry out each check (frequency), who has overall responsibility and what records you maintain of the checks.

The FCA expects firms to document the checks and tests you take to monitor compliance. These should be in the form of audit records which can be noted on your CMP. You do not need to attach the actual record to your document, just note the type of record you have completed and will maintain. You can also hyperlink to the record to make finding and evidencing the check easier.

Compliance Monitoring Programme Examples

EXAMPLE 1:

Regulatory requirement: Status disclosed on all stationery relating to regulated business. 

Action taken by firm to check compliance: Review status disclosure procedures to ensure they align with GEN 4 statutory status disclosure requirements. Audit existing stationery to check for correct disclosures.

Frequency: Annual 

Responsibility: Admin Manager

Compliance Record: Compliance audit form completed and reviewed stationery samples recorded.

EXAMPLE 2:

Regulatory requirement: Conflict of interest records kept. 

Action taken by firm to check compliance: Review conflict of interest policy and procedures to ensure they align with SYSC 10 requirements. Review conflict of interest register and compare it to reported conflicts.

Frequency: Monthly 

Responsibility: Compliance Officer

Compliance Record: Compliance audit form completed with entries from conflict of interest register.