Cross-Sector Regulatory Topics/ Deep Dive 04

Templated compliance frameworks and regulatory risk

7 min readSmaller Asset Managers
Anchored to

the proportionality and organisational requirements in SYSC 4.1.1R; the FCA's asset management portfolio letter (26 February 2025) and its business-model review of smaller asset managers; and the supervisory pattern across the private market valuations review (March 2025) and the conflicts review.

SYSC 4.1.1R

A compliance template arrives describing a firm that does not exist: some average of the managers it was drafted for, with committees, roles and monitoring cycles that belong to none of them in particular. Buy it, adopt it across the firm, and you hold a written account of controls you may not run. The FCA has spent two years testing whether a firm’s governance matches its operations or only its paperwork. A template produces the document but not the operating records behind it. A polished template invites trust and hides how far it has drifted from actual operations.

A template is a reasonable place to begin. Left as the finished framework, it becomes a documented claim to controls the firm cannot show it runs, and under the FCA’s current supervisory stance that documented claim works against the firm.

SYSC 4.1.1R is the organisational rule underneath all of this. It requires a firm to maintain robust governance arrangements, effective processes to identify, manage, monitor and report the risks it faces, and internal control mechanisms — and it requires all of that to be appropriate to the nature, scale and complexity of the firm’s business. The last clause is the one a template cannot meet. A template is not built for any single firm’s nature, scale and complexity; it is built for the average of the firms it was written to cover. A single-strategy manager that adopts a framework drafted for a multi-strategy platform ends up describing committees it does not hold, roles it has not filled and processes it does not run. A fast-growing alternatives house still using its authorisation-stage template is describing a firm it has outgrown.

Proportionality cuts both ways: too little and too much are both failures. A framework too heavy for the firm is as much of a problem as one too light. Describe elaborate controls a small firm has no one to staff, and you have written a run of commitments the firm visibly fails to keep; a supervisor reading that against the real operation sees documents and reality that have drifted apart, which is the opposite of a well-run firm. SYSC rewards the framework that fits the firm, which is the one thing a template can’t do.

What makes this the live risk rather than a theoretical one is that the FCA’s recent reviews have repeatedly targeted this gap.

The regulator’s question has changed. The FCA no longer asks whether a firm has a policy. It asks the firm to show the policy running, with a dated, attributable record that the control operated. On the first question a templated framework is strong; on the second it has nothing, because a template records intent and not operation. A firm can pull its conflicts policy, its valuation policy and its market-abuse policy off the shelf in seconds and produce not one scrap of evidence that any of them runs as written, which the FCA reads as evidence the control isn’t operating.

The reviews bear it out. The private market valuations review of March 2025, covering firms that manage around £3 trillion between them, found that almost every firm had a valuation committee and a valuation policy on paper, while the records underneath (how a given valuation was reached, who challenged it, on what basis) were often missing. The conflicts review found the same pattern: policies in place, management absent. The asset management portfolio letter of 26 February 2025 pushed firms on whether their governance is effective in practice, not whether it is written down. And the review of smaller asset managers’ business models amounts to a check on whether what those firms do lines up with what they are authorised and documented to do. A templated framework tends to produce paperwork without the operating record behind it.

A templated framework becomes dangerous at three points in a firm’s life.

The first is the authorisation gateway. The FCA now expects an applicant to be ready and organised to operate its framework from day one, and an application built on a binder of templates, with no credible account of how any of it will run inside this particular firm, is the kind the tougher gateway now stalls or turns away. A template can slow authorisation rather than speed it.

Then there is ongoing supervision, where the show-me-it-works question arrives. A firm holding a templated framework answers a request for evidence with the policy plus whatever it can assemble after the fact, and that after-the-fact assembly is what the supervisor records, because it shows the control was never run as the template describes.

The third is a skilled-person review or an enforcement investigation, where the framework becomes evidence against the firm. A documented but un-operated control is evidence the firm knew the standard and didn’t meet it.

The exposure is structural because it runs through the whole framework at once. A firm that has templated its conflicts, valuation, financial-crime, operational-resilience and consumer-outcomes work has opened the identical gap in every one: generic description on one side, the specific firm on the other. A supervisor who finds it in a single area will reasonably assume it across the rest. Once one templated policy is shown not to match operations, a supervisor will doubt the rest.

This is also the cost paradox the industry keeps complaining about. Firms spend heavily on compliance documentation, buying more policies and more templates, which adds paper and nothing else. The spend that lowers risk turns a framework into something operated and evidenced, and it’s the one firms most often defer.

Growth makes it worse. The template risk grows as the firm grows, because the document/operations gap widens. A framework adopted at authorisation describes the firm as it stood then: one strategy, a few people, a short fund range. Three years and several funds on, the firm has picked up a credit sleeve, a co-investment programme, a Luxembourg vehicle and a dozen more staff, and the framework has not moved an inch, so a document that was generic on day one now misstates what the firm is. A supervisor comparing it with the current business sees a control environment set once and then left,

The drift shows up in concrete, checkable ways, and those are the first things an examiner reaches for. The framework names a committee the firm never convenes, or convenes without minutes. It states a monitoring frequency the firm does not keep. It names a role (a head of risk, a second line) the firm has never had. It routes escalation to people who have left, or into a structure that was never built. Each is a small factual mismatch between document and reality, and each falls to a single question: show me this committee’s last four sets of minutes; show me this check performed at this frequency; show me this role on your org chart. The template has no answer, because it was never written about this firm.

The alternative is a framework built around what the firm actually does, with four properties a template lacks.

It fits the firm. Each policy describes the controls this firm runs, at the scale and complexity it runs them, so the framework and the operation are one thing and not two documents drifting apart. A template can supply the starting structure; the structure then has to be rebuilt to fit rather than adopted as the answer.

Every control has an owner and an evidence trail. For each control the framework sets out, there is a named person who runs it and a defined record its operation throws off, so the control can be shown working instead of merely asserted. That single move is what turns a documented framework into an evidenced one.

The controls run on a schedule, and running them produces the evidence as a by-product, so the dated, attributable record is already sitting there before a supervisor asks, rather than being pieced together afterwards.

And the framework is kept current. It is revisited as the firm adds strategies, funds and people, so it tracks the firm instead of freezing it at the shape it had at authorisation. A framework that hasn’t kept pace with the firm becomes a misstatement over time.

What keeps those four properties going, rather than making them a heroic one-off rebuild, is an operating model that produces the evidence as a by-product of running the firm. In practice that comes down to four things: one authoritative compliance calendar listing every recurring obligation with its date and its owner; one control library in which each control is written once, with its owner and the record its operation has to produce; escalation routes that are written down; and management information that assembles itself from the controls as they run instead of being rebuilt each cycle. With those in place, the framework describes operations that are happening and leaving a trail behind them. In an operating model the framework is the business, and the evidence builds up whether or not an inspection is coming. Building it costs money, but it’s the compliance spend that actually lowers risk.

Exhibitwhat each property looks like as a bought template versus an operated framework.
PropertyTemplated (baseline)Operated (mature)
FitA high-quality template adopted across the firmEach policy rebuilt to describe the controls this firm runs
OwnershipPolicies existEvery control mapped to a named owner and the record its operation produces
OperationThe policy states that the control runsThe control runs on a schedule and leaves a dated, attributable trail
CurrencyThe framework was set at authorisationThe framework is revisited as the firm changes, and tracks it

This insight is provided for general informational purposes only and doesn’t constitute legal, investment, or regulatory advice.