The GRC Navigator
Your Bi-Weekly GRC Intelligence Briefing
Executive Summary
On 14 September 2026 the Upper Tribunal released Odey v FCA [2026] UKUT 00351 (TCC), upholding the FCA's prohibition of Crispin Odey and setting his penalty at £1,529,374, down from the £1,835,200 the FCA had decided on. The Tribunal held that the conduct rules, and with them the s.66 penalty power, reach a controller who is also a certified employee when he uses his ownership powers on the firm's governance, because COCON turns on the function the conduct relates to. It removed the FCA's 20% uplift for aggravating factors as double counting and kept a deterrence multiple of two, justified partly by the firm's average assets of about £2.925bn. The decision came two weeks after COCON 1.1.7FR took effect on 1 September, extending the conduct rules at non-bank firms to serious bullying, harassment and violence towards colleagues.
An FCA research note on 3 September gave the first market-wide picture of UK alternative investment funds from AIFMD returns. CP26/32, published on 4 September, proposes weekly reporting for UK and overseas money market funds from Q3 2027 and 12 more months for CCIs closed to new business. FS26/1 and a call for input on tokenised gold (14 September) set out the FCA's current reading of the fund perimeter for asset-backed tokens. The PRA published no policy in the period. In enforcement, the FCA decided to fine and ban Daniel Thomas over defined benefit transfer advice outside his appointed representative permissions, a decision he has referred to the Tribunal, and banned Nurul Miah on the strength of SRA findings.
Upper Tribunal upholds Odey ban and sets the fine at £1.53m, holding that ownership powers used on governance fall within COCON
HIGH RISK · Sectors: Asset Management, Hedge Funds, All Regulated Firms
On 14 September 2026 the Upper Tribunal released its decision in Robin Crispin Odey v The Financial Conduct Authority [2026] UKUT 00351 (TCC), dismissing Mr Odey's reference against the FCA's Decision Notice of 3 March 2025. The Tribunal (Mr Justice Thompsell, Judge Rupert Jones and tribunal member Catherine Farquharson) upheld the prohibition order under s.56 FSMA and determined that the appropriate penalty under s.66 is £1,529,374, against the £1,835,200 the FCA had decided on (FCA press release). A reference is a full rehearing, so the findings are now the Tribunal's own.
The Tribunal described the primary focus of the case as Mr Odey's lack of integrity in corporate governance (para 11). He founded and was the ultimate majority owner of Odey Asset Management LLP (OAM), an AIFM, and was certified by it as a fund manager. In February 2021 OAM's executive committee (ExCo) issued him a final written warning after finding, with his acceptance at the time, that he had behaved inappropriately towards female employees. When a second disciplinary hearing was scheduled on alleged breaches of that warning, he used his ownership powers on 24 December 2021 to remove the ExCo, appointed himself its sole member and postponed the hearing indefinitely. He removed a second ExCo on 31 March 2022. The Tribunal found all five of the FCA's allegations proved, among them deliberate frustration of the disciplinary process to avoid accountability, reckless disregard for OAM's governance, and a lack of candour with OAM, its clients, investors and the FCA.
Mr Odey's main legal argument was that he removed the ExCos as a controller, a status governed by Part 12 FSMA, which gives the FCA no power to fine, and not as a certification employee, so neither COCON nor s.66 applied. The Tribunal rejected it. Under s.64A FSMA and COCON 1.1.7R (rule) the conduct rules apply to an employee's conduct in relation to functions relating to the carrying on of activities by the employer, whether or not regulated. For a non-bank, COCON 1.1.7AR (rule) narrows that to conduct forming part of, or for the purpose of, the firm's SMCR financial activities. Those include activities carried on in connection with a regulated activity, and the Tribunal held that "in connection with" needs only a factual link (para 1332). In the Tribunal's words, "it is the function to which the conduct relates that defines and limits the applicability of the COCON rules rather than the capacity in which the conduct was carried out" (para 1324). Deciding who sits on the governing body and running a disciplinary process about a regulated employee are both such functions (para 1335). Alternatively, his own vote as an LLP member made the meeting quorate, and a member counts as an employee under s.64A(6) (paras 1345 to 1347).
The FCA did not allege dishonesty, and the Tribunal made no finding of it (para 68). It applied the test in Seiler v FCA [2023] UKUT 133 (TCC): integrity is an essentially objective standard, and knowingly taking a risk that is unreasonable in the circumstances is enough. Removing the ExCos put OAM in breach of three requirements for a total of 112 days: SYSC 4.2.1R; SYSC 4.2.2R, under which a full-scope UK AIFM must be managed by at least two people; and FUND 3.7.2R, which requires risk management to be functionally and hierarchically separate from portfolio management, something that could not be achieved while a fund manager was the governing body's only member. The Tribunal accepted that not every deliberate breach shows a lack of integrity: a board that was itself engaged in market abuse, misappropriation or major fraud might, exceptionally, justify removal without notice (para 1398). Nothing of that kind arose here, and a third ExCo's later decision not to dismiss him did not justify the removals (para 10).
The penalty follows DEPP 6.5B (guidance), with one change to the FCA's figures:
- Step 1: nil, as there was no direct financial benefit.
- Step 2: level 4, 30% of relevant income of £2,548,957, giving £764,687. Mr Odey argued for level 3 (£509,791); the Tribunal found the breach deliberate and reckless.
- Step 3: the FCA had added 20% because he removed the second ExCo after being told of its concerns (DEPP 6.5B.3G(2)(f)), reaching £917,624. The Tribunal removed the uplift, holding that his cooperation in reporting the breaches and reconstituting the ExCo offset it and that it overlapped with factors already used to set level 4 (paras 1380 to 1383).
- Step 4: a multiple of two for deterrence under DEPP 6.5B.4G, upheld by reference to OAM's average assets under management of about £2.925bn (the Step 3 figure was below 0.03% of that), funds he managed of up to £1.351bn and his own investment of about £304m in OAM funds (para 1388).
- Step 5: no settlement discount.
The Tribunal said this was not a case about whether sexualised misconduct is, by itself, within the FCA's jurisdiction (para 13), and it declined to decide the FCA's wider submission that integrity requires "a willingness to submit to these governance structures" (para 1397). Any appeal would lie to the Court of Appeal on a point of law, with permission. The conduct also predates COCON 1.1.7FR, which since 1 September 2026 has brought serious harassment of colleagues at non-bank firms within COCON (see Regulatory Updates); the FCA has said that rule is not retrospective. For conduct after that date, both the underlying behaviour, if it meets the rule's seriousness threshold, and an owner's use of control to stop a process about it can be conduct rule breaches.
The consequence falls on owner-managed firms whose LLP agreement or articles let the majority owner reconstitute the governing body by written resolution. The governing body of such a firm should adopt a protocol for disciplinary matters involving a controller or senior manager that names who convenes and who decides, when the compliance function and the FCA are told, and how the firm keeps two people directing the business under SYSC 4.2.2R if the panel is removed, with a chair who is not the controller named in the minute that adopts it.
In my view paragraph 1324 is the one founders should read twice. It's tempting, in an owner-managed firm, to treat the shareholder register and the regulated role as separate compartments; the Tribunal has said they aren't, at least where an owner who is also an employee uses ownership powers on the governing body or on a process about a regulated employee. The penalty reasoning shows the cost. The deterrence multiple was justified by the firm's assets and by his own investment in its funds, so a senior individual's exposure isn't capped by salary.
After Odey, a founder cannot use the shareholder register to step outside the conduct rules when the target is the firm's own governance.Asad Bukhory
Regulatory Updates
Non-financial misconduct rules take effect: COCON 1.1.7FR brings serious harassment at non-bank firms inside the conduct rules
HIGH RISK · Sectors: All Regulated Firms, Asset Management, Wealth Management
The FCA's rule on non-financial misconduct at non-bank firms, COCON 1.1.7FR, came into force on 1 September 2026, together with the guidance in the Non-Financial Misconduct (No 2) Instrument 2025 (FCA 2025/60), published with PS25/23 on 12 December 2025. The FCA confirmed the rule on 2 July 2025 in CP25/18, which also consulted on the guidance; the original proposals were in CP23/20.
COCON 1.1.7FR is a rule. For SMCR firms other than banks it extends the conduct rules to unwanted conduct towards colleagues, people who perform functions for or provide services to the firm or its group, and their staff, where the conduct has the purpose or effect of violating the person's dignity or creating an intimidating, hostile, degrading, humiliating or offensive environment, or is violent. Conduct relating only to a part of the business with no SMCR financial activities stays outside (COCON 1.1.7FR(5)); PS25/23 explains that conduct is in scope if either the person responsible or the person affected deals with the financial services business. Banks already had the wider scope, and the new COCON 4.3 guidance applies to them too (COCON 4.3.5G).
The conduct must be serious (COCON 4.3.7G), judged on factors that include repetition, duration, impact, the seniority gap and whether the individual controls the other person's career, and whether the individual had been warned or had undertaken not to repeat the behaviour (COCON 4.3.8G). A single incident can qualify (COCON 4.3.17G), and so can the effect on a witness (COCON 4.3.16G). Individual Conduct Rule 1 is breached only where there is intention, recklessness or turning a blind eye (COCON 4.3.19G), although an unreasonable belief that the conduct was justified can itself show a lack of integrity (COCON 4.3.21G); conduct short of that may breach Rule 2 (COCON 4.3.23G).
Between CP25/18 and the final guidance the FCA made several changes, most in firms' favour:
- it withdrew a proposed seriousness factor about the "specific characteristics or vulnerabilities" of the person affected;
- it limited managers' accountability to what they knew or should reasonably have known and had authority to act on (COCON 4.1.8-BG);
- it deleted a sentence implying that unproven allegations should be reported to the FCA, keeping only the cross-reference to SUP 10C.14.18R;
- it told firms they need not investigate trivial or implausible allegations about private life (FIT 1.3.20G) or apply the FCA's statutory objectives as a self-standing fitness test (FIT 1.3.12G(3)).
The rule is not retrospective. Conduct before 1 September 2026 is judged under the rules then in force, and the FCA does not expect a back-book review, though a firm that finds it wrongly determined a past breach should correct its SUP 15 notification. The rule covers sexual harassment but does not bring discrimination or victimisation within COCON at non-banks. Territorial scope is unchanged, so COCON 1.1.10R still limits how the rules reach UK firms' staff overseas. And the FCA's statement that it will treat a firm's reasonable judgement on seriousness as compliant sits in the policy statement, not in a Handbook provision.
By now a non-bank should have a disciplinary policy that maps outcomes to COCON 1.1.7FR, conduct rules training under s.64B that covers the new rule, and a SYSC 22 regulatory reference process that records substantiated cases. What it cannot yet settle is when a case must be reported: only formal disciplinary action (a written warning, suspension or dismissal, or a reduction or recovery of pay) triggers notification under s.64C FSMA, and the breach-reporting thresholds consulted on in CP25/21 are still under consideration.
FCA's first market-wide AIF data study puts UK AIFMs at £1.8tn and shows the data gaps FRAME is meant to close
INFO · Sectors: Asset Management, Private Credit, Hedge Funds, Private Equity
A research note published by the FCA's Economics Department on 3 September 2026, The UK alternative investment fund market: evidence from regulatory reporting, is the first FCA publication to present market-wide statistics on the sector from AIFMD returns. Research notes carry a disclaimer that they may not represent the FCA's position, but this one says it informed the calibration of CP26/28 on the UK AIFM regime and sets a baseline to help evaluate the reforms. We covered CP26/26, CP26/27 and CP26/28 in Issue 25.
The headline figures, at year-end 2025:
- AIFs available to UK investors had a combined NAV of £5.1tn, up 30% since 2021; UK AIFMs managed £1.8tn, up from £1.5tn. Managers marketing under the National Private Placement Regime accounted for 65% of NAV.
- Private credit NAV rose from £147bn to £335bn and the number of funds from 381 to 786. UK-managed private credit was £25.5bn across 111 funds.
- Excluding hedge funds, aggregate adjusted leverage stayed between 99% and 114% of NAV from 2016 to 2025. Among UK-managed funds, around 12% of private credit funds have run above three times NAV since 2020, the threshold the note aligns with AIFMD "significant leverage".
- Retail investors held 20% of UK-managed NAV (£366.9bn), concentrated in funds of funds and the "other" category, which includes most investment trusts.
The note also records the weaknesses in the data. AIF002 does not say whether a fund is open-ended or closed-ended, so the FCA inferred structure from the redemption fields. Legal Entity Identifiers are neither mandatory for all funds nor used consistently, which limits master-feeder matching. The gross and commitment leverage figures were inconsistent enough that the FCA built its own adjusted measure. About 3,000 funds, 25% of NAV, sit in the "other" category, and private credit funds had to be identified using name and strategy rules, manual review, machine learning and large language models. On liquidity the note finds no aggregate mismatch but a concentration in real estate, where 10% of NAV can be redeemed within 30 days against 7% of assets that can be sold in that time, and it warns that the measure relies on managers' own assessment of asset liquidity, "which may be overoptimistic".
These are the gaps CP26/26 (FRAME) is meant to close. CP26/26 and the main CP26/28 chapters now close on 22 October 2026, after extensions announced in late August; the non-prudential CP26/28 discussion chapters close on 18 September.
I read this note as a statement of what the FCA can already see. It has its own leverage measure and a way of finding private credit funds that don't label themselves as such, and it has written down that managers' own liquidity assessments may be overoptimistic. If a manager's AIF002 liquidity buckets don't match its dealing terms and its own stress results, I'd correct that now, before FRAME collects the same information more consistently.
FCA frontier AI review: firms say models now find vulnerabilities faster than they can fix them
LOW RISK · Sectors: All Regulated Firms, Asset Management, Investment Firms
The FCA's multi-firm review Frontier AI and cyber resilience, published on 2 September 2026, reports how firms are using, testing and preparing for frontier AI models with cyber capabilities. It summarises what firms told the FCA and states that it "does not introduce new rules, guidance or regulatory expectations". It follows the joint statement by the FCA, the Bank of England and HM Treasury in May 2026, which described these models as a step-change in capability and also disclaimed new expectations.
Firms reported that models find vulnerabilities faster than they can be validated and fixed, so the constraint moves to triage, engineering capacity, patch testing and change control. Models can also chain several low-rated flaws into a route to compromise, which undermines remediation queues ordered by severity rating alone, and firms described moving to prioritisation by exploitability and by the effect on important business services. They said a model's value depends on the environment built around it (the "harness") and on human review, and that supplier preparedness and software supply chain dependencies are becoming more prominent. Some firms are using targeted deployments to test whether their triage and remediation processes can cope before scaling up, and the review suggests risk committees and senior leaders may need clearer visibility of how the models affect vulnerability registers, remediation and supplier dependencies.
The review changes no obligation, and which obligations apply depends on the firm. SYSC 15A (operational resilience) applies to enhanced scope SMCR firms, banks, designated investment firms, building societies, Solvency II firms and payment and e-money firms, among others (SYSC 15A.1.1R). Those firms must identify their important business services (SYSC 15A.2.1R), set impact tolerances (SYSC 15A.2.5R) and be able to remain within them in a severe but plausible disruption (SYSC 15A.2.9R). A core SMCR asset manager is outside SYSC 15A; its cyber obligations run through the general governance requirement in SYSC 4.1.1R and, for a common platform firm, the outsourcing rules in SYSC 8.1.1R. The review says it is written particularly for small and medium-sized firms, many of which are core SMCR firms in the second group.
For those firms the review's own questions make a fair test of the vulnerability register: which open findings affect a service clients rely on, how long each has been open, which depend on a supplier's fix, and who has authority to accept the risk. A register organised around severity ratings and patch dates cannot answer them unless it also records the business service and supplier behind each finding.
CP26/32 proposes weekly money market fund reporting from Q3 2027, overseas funds included, and 12 more months for closed CCI books
MEDIUM RISK · Sectors: Asset Management, Wholesale Markets, Retail Distribution
The FCA published CP26/32, its 53rd quarterly consultation, on 4 September 2026, with comments on chapters 2 to 8 due by 12 October 2026. Two chapters matter to fund managers: chapter 7 on money market fund (MMF) reporting and chapter 8 on the Consumer Composite Investments (CCI) disclosure rules.
UK MMFs currently report fund details and holdings quarterly under the UK Money Market Funds Regulation and NAV information daily under Article 29(5). Overseas MMFs marketed in the UK are subject to the same reporting in law, but the FCA says it has chosen not to enforce it. Chapter 7 changes both:
- quarterly reporting would move into the FRAME framework proposed in CP26/26, using selected FRAME modules plus the MMF type, due 30 days after the period end;
- daily NAV reporting would give way to a weekly report, with daily values for some metrics, including NAV, liquidity buffers and, for LVNAV and public debt CNAV funds, NAV per unit and constant NAV per unit, and end-of-week figures for others, including maturity measures, the liquidity profile, the share held by the five largest investors and net flows;
- both would apply to managers of UK MMFs and of overseas MMFs marketed into the UK.
The FCA intends to make its wider MMF rules, in a new MMFS sourcebook, by the end of 2026 and bring them into force in Q3 2027, when the UK MMFR would be revoked and weekly reporting would begin. Until FRAME is fully implemented, which the FCA aims for in 2028, UK MMFs would file interim quarterly returns under draft MMFS 8 in an almost unchanged format, still in euros, without the stress-testing data. The Bank of England will also use the data. No cost benefit analysis was prepared, under the exemption in s.138L(3) FSMA.
Chapter 8 corrects the CCI rules made in PS25/20. The DISC rules have applied since 6 April 2026 under a transitional period that ends on 7 June 2027 (DISC TP 2.1R). Beyond typographical fixes, the chapter proposes three changes of substance:
- CCIs closed to new business but still taking top-ups from existing investors would have until 8 June 2028, 12 months longer; products closed to both remain outside the regime;
- Enterprise Investment Scheme funds would be excluded from the past-performance line graph in DISC 7.2, because a single graph for a cohort-based umbrella fund would not match any investor's experience;
- the past-performance periods for financial promotions in COBS 4.6.2R and COBS 4.5A.10R would move from five years to ten, to match DISC 7.1.1R.
The FCA also confirms that funds in the temporary marketing permissions regime, which HM Treasury plans to extend beyond 2026 for MMFs, need not produce a product summary until June 2027.
The overseas change is the one I'd flag to any EU manager distributing an MMF into the UK. An obligation the FCA has chosen not to enforce would become a weekly filing with daily values from Q3 2027, so the build work, and the question of who signs off the figures, starts well before then.
FS26/1 and the tokenised gold call for input set out the FCA's reading of the CIS and AIF perimeter for asset-backed tokens
LOW RISK · Sectors: Asset Management, Wholesale Markets, Digital Assets
On 14 September 2026 the FCA published FS26/1, its feedback statement on the joint FCA and Bank of England call for input of May 2026 on tokenisation in wholesale markets, and a separate call for input on tokenised gold, which closes on 23 October 2026. Neither changes any rule. FS26/1 reports 123 responses and commits the FCA and the Bank to a Tokenisation Roadmap with target dates "later this year".
For asset managers the feedback is mostly about collateral. Respondents named it as by far the most frequent use case, and buy-side firms raised tokenised money market funds repeatedly, because a tokenised MMF unit could be posted as collateral without being redeemed. The authorities accept that collateral mobility is the near-term benefit, and the Bank will consult later this year on a supervisory statement and a discussion paper on tokenised collateral at central counterparties. On custody of relevant specified investment cryptoassets (tokenised securities), most respondents preferred the CASS 6 custody rules, with overlays for risks such as private key management, to the crypto safeguarding chapter, CASS 17, which comes into force on 25 October 2027; the FCA will consult in the first half of 2027. It restated two positions: every regulated activity needs an identifiable, accountable regulated person, and for traditional investments it "cannot accept solutions where customers have no recourse when assets are lost or stolen".
The gold paper is narrower and goes further into the law. It asks when tokens backed by physical gold are collective investment schemes or AIFs. The FCA's view is that a token giving direct, allocated ownership of a commercially tradeable bar, with no pooling or management, is more likely to fall outside both definitions, while fractional interests in a bar that is managed or disposed of collectively indicate pooling, in which case the CIS and AIF framework may be the right home. A UCITS cannot be dedicated to gold, so a gold CIS may be an unregulated scheme with restricted marketing. Industry has argued that co-ownership in undivided shares of goods keeps fractional tokens outside the perimeter; the FCA asks to hear why such structures would not still meet every element of the definitions. Its options run from guidance to a targeted exemption made with HM Treasury, which would come with 12 conditions covering, among other things, custody and reconciliation, independent audit, governance, dealing, disclosure and wind-down. The paper notes that the Treasury's July 2026 consultation proposes to clarify the legislative definition of an AIF.
The FCA says the lessons may inform its thinking on other tokenised commodities. In my reading the chapter 5 analysis reaches further, to any token backed by real assets, because it turns on a question every such structure has to answer: does the holder own an identified asset, or a share of a managed pool?
Bank of England & PRA
Bank of England frontier AI note puts data access and proximity to production at the centre of harness design
INFO · Sectors: Banking, Insurance, All Regulated Firms
The Bank of England's Frontier AI Information Sharing Forum published Frontier AI: Harness engineering on 2 September 2026, a note on the tools, workflows and controls firms build around a frontier model used for cyber defence. The Bank presents it as a summary of discussion themes that sets no supervisory expectations or policy and gives no guidance. The PRA itself published no consultation paper, policy statement or supervisory statement between 1 and 15 September.
Firms can build harnesses in-house, take them from the model vendor, use managed services or assemble open-source components, and the Bank reports that no single approach is yet complete. Vendor harnesses fit their own model closely but give less context and less control over validation; internal and open-source tools give flexibility at the cost of engineering, documentation and assurance. An orchestration layer that routes work between several tools and models reduces early dependence on one supplier. The Bank treats data access as a central risk management question: the model is more useful with source code, asset inventories and architecture material, and each addition increases the exposure if the model or harness is compromised. Direct deployment into production networks is "generally regarded as higher risk", so firms are working in sandboxed or production-like environments and building controls into the harness itself, such as use-case restrictions, network isolation, approval workflows and rules of engagement.
For PRA-regulated firms the existing frame remains SS1/21 on impact tolerances for important business services and SS2/21 on outsourcing and third party risk management; the note adds nothing to either. It is most useful as a checklist for the approval paper a risk committee should see before a frontier model is pointed at the firm's estate: which repositories and environments are in scope and which are excluded, where the model runs, which actions need human approval, and who owns findings the remediation teams cannot absorb. The Bank also notes that smaller suppliers may lack the engineering capacity to fix what AI-assisted testing finds in their products, which puts supplier remediation capacity into due diligence.
Fund Launches & Capital Raises
Four VCTs open 2026/27 offers for up to £80m, paying their managers promoter fees of up to 5.5%
INFO · Sectors: Asset Management, Retail Distribution
Four venture capital trusts published prospectuses for new share offers between 1 and 15 September 2026: Triple Point Venture VCT on 1 September (£10m, or £20m if oversubscribed), Blackfinch Spring VCT on 8 September (up to £20m plus a £20m over-allotment), Pembroke VCT on 14 September (up to £40m of B shares plus £20m) and Guinness VCT on 15 September (up to £10m plus £5m). Molten Ventures VCT announced on 10 September an intended offer of up to £30m, with an offer document due in early October.
Each manager, or a company in its group, is promoter and is paid by the VCT: up to 5.5% of the money raised at Triple Point and Blackfinch, and at Guinness and Pembroke 3% for advised investors against 5.5% (Guinness) or 5.0% (Pembroke) for direct or non-advised investors. All four announcements treat the agreement as a related party transaction and follow the procedure described for Albion's offers in Issue 27 (UKLR 11.5.4R and UKLR 8.2.1R): approval by the directors without a conflict, a sponsor's written confirmation that the terms are fair and reasonable, and an announcement.
The sponsor's test in UKLR 8.2.1R(3) is fairness to the company's existing security holders. At Guinness the fee is applied to each application through the offer's pricing formula, which puts the cost on the incoming subscriber, so an adviser recommending the offer still has to judge that cost for the new investor.
Kelso, a geared 10-stock investment vehicle listed as a commercial company, raises £3m at NAV and offers up to £1m to retail investors
INFO · Sectors: Asset Management, Listed Companies, Retail Distribution
Kelso Group Holdings plc announced on 10 September 2026 a placing and subscription to raise £3.0m at 3.3p a share, its NAV per share and a 5.7% discount to the previous day's closing mid-price, plus a retail offer of up to £1.0m at the same price through RetailBook, due to close on 16 September. Certain existing shareholders have committed up to £3.0m to cover any shortfall; admission is expected on 21 September. Kelso calls itself a Main Market listed investment vehicle holding about ten UK-listed small and mid-cap companies; its 2 September update reported NAV per share up about 43% in the eight months to 31 August 2026 and 33% gearing, with gross investments of about £23.0m on net assets of £15.2m.
The new shares are to be admitted to the equity shares (commercial companies) category. UKLR 11 applies only to closed-ended investment funds listed in the closed-ended investment funds category (UKLR 11.1.1R), so the requirement to publish and keep an investment policy covering asset allocation, risk diversification and gearing, with maximum exposures (UKLR 11.2.8R and UKLR 11.4.4R), does not attach to Kelso. Kelso says the fundraise needs no prospectus: the placing is limited to qualified investors under the Public Offers and Admissions to Trading Regulations 2024, and the retail offer runs on a financial promotion approved under s.21 FSMA by RetailBook Limited. Gearing is the first comparison for a retail investor weighing Kelso against a listed investment trust: a listed fund must publish its maximum, and Kelso, geared at 33%, has no listing-rule duty to publish one.
Enforcement Watch
FCA decides to fine Daniel Thomas £742,700 and ban him over DB transfer advice his appointed representative agreement did not permit
MEDIUM RISK · Sectors: Wealth Management, Retail Distribution
The FCA has decided to fine Daniel Thomas £742,700 under s.66 FSMA and to prohibit him under s.56, in a Decision Notice published on 3 September 2026. Mr Thomas has referred the notice to the Upper Tribunal, so its findings are provisional and reflect the FCA's view of what happened; the action has no effect until the Tribunal decides (press release).
Mr Thomas was the only person approved for the CF1 Director (AR) function at DPT Financial Solutions Limited, an appointed representative of Quilter (formerly Intrinsic), and held CF30 at the principal. His AR agreement allowed defined benefit (DB) transfer advice only for advisers holding the G60 or AF3 qualification who had attended a workshop, passed a test and submitted each case for compliance pre-approval. He had attended the workshop and passed the test, but held neither qualification and submitted no DB case for pre-approval. The FCA's case is that between April 2014 and April 2019 he advised 53 clients on 63 DB transfers, four of them British Steel Pension Scheme members, and received £173,732.57; that letters to scheme administrators claimed he held the Article 53E permission; that he told Quilter he referred DB cases elsewhere; and that he destroyed the client files. The FCA has made no findings against Quilter.
Because the relevant period (8 April 2014 to 20 September 2019) predates the SMCR's extension to solo-regulated firms, the breaches are of the Statements of Principle for approved persons (APER 2.1A.3): Principle 1 (integrity, on a recklessness basis), Principle 2 (due skill, care and diligence, for destroying the records, relying on COBS 9.5.2R) and Principle 4 (cooperation with the FCA). The notice makes no finding of dishonesty, although it describes the representations to administrators as knowingly false. The requirement that DB transfer advice be given or checked by a pension transfer specialist is now in COBS 19.1.1AR.
The FCA built the penalty in five steps under DEPP 6.5B:
- Step 1: £202,114, the £173,732 in fees plus £28,382 interest;
- Step 2: level 5, 40% of relevant income of £1,126,345 from DPT, giving £450,538;
- Step 3: a 20% uplift for failing to answer information requests and compelled requirements (DEPP 6.5B.3G(2)(b)), giving £540,645;
- Steps 4 and 5: no deterrence adjustment and no settlement discount.
The total is Step 1 plus Step 5, rounded down. In Odey the Tribunal struck out a 20% uplift that overlapped with factors already used to set the seriousness level, so a Step 3 uplift is an obvious target on any reference. This one rests on non-cooperation during the investigation, which none of the Step 2 factors cover, and I think the double-counting objection has much less to work with.
According to the notice, Quilter's compliance systems could not see that the fees came from DB transfer business because Mr Thomas coded them as "Fund Initial Charges" or "personal pension" when he logged the payments, while the pension provider's own records showed transfers out of DB schemes with him as adviser. A principal that reconciles provider commission data, including the provider's record of the transfer type, against the adviser's own coding before paying out would have seen the mismatch. As the notice explains, a principal is responsible for its AR only within the scope it has accepted, and SUP 12.6.6R (rule) requires it to take reasonable steps to ensure its ARs do not carry on regulated activities in breach of the general prohibition.
FCA bans Nurul Miah and withdraws his SMF3 approval two years after an SRA finding that he took £28m of client money
MEDIUM RISK · Sectors: Wealth Management, All Regulated Firms
On 15 September 2026 the FCA issued a Final Notice to Nurul Miah (also known as Neil Mia and Neil Miah), withdrawing his approval to perform SMF3 (Executive Director) at Oracle Consultants Ltd, now in liquidation, under s.63 FSMA and prohibiting him from any function in relation to regulated activity under s.56 (press release). He did not refer the Decision Notice of 3 August 2026 to the Tribunal, so the findings are final. There is no penalty: this is a fitness decision.
The basis is another regulator's findings. On 11 September 2024 an SRA Adjudication Panel found that, as sole owner of Kingly Solicitors Limited, Mr Miah dishonestly caused or allowed over £28m of client money to be withdrawn without authority between 9 April 2019 and 23 July 2020, leaving a shortfall of more than £10m that he used for his own benefit. The SRA fined him £3,984,440, ordered £41,670 in costs and disqualified him under s.99 of the Legal Services Act 2007. The FCA relied on those findings and on FIT 1.3.1BG (honesty, integrity and reputation as the most important criteria), and the notice says expressly that the misconduct "did not occur through this approved role".
A prohibition under s.56 needs no link between the misconduct and the regulated role, because fitness is assessed on everything relevant. That is the contrast with Odey, where the s.66 penalty depended on showing that COCON reached the conduct. The FIT guidance in force since 1 September 2026 says as much: breaches of other regulators' requirements are relevant (FIT 1.3.14G), and firms may rely on a regulator's findings about conduct outside the firm (FIT 1.3.20G(4)(c)).
The timing is harder to read. Mr Miah held CF1 at Oracle from 2 December 2016 and SMF3 from 9 December 2019, "a position he continues to hold to date", and the SRA decision was made two years before this notice. The notice does not say when the FCA or Oracle learned of it, and no inference about either should be drawn.
For a firm the control sits in its own records. SUP 10C.14.18R (rule) requires a firm that becomes aware of information reasonably material to an SMF manager's fitness to tell the FCA, a duty that depends on the firm knowing what its senior managers do elsewhere. An outside business interests register that lists any other regulated or licensed business an SMF manager owns or runs, with a trigger to reassess fitness when that business's regulator acts, would supply that knowledge; so would a written question in each periodic fitness assessment about investigations or findings against such businesses.
Also in enforcement: a guilty plea over a fake takeover approach, a refused revocation and three cancellations
LOW RISK · Sectors: Listed Companies, Financial Crime, All Regulated Firms
Fake takeover approach. On 10 September 2026 Christopher Woolcott pleaded guilty at Westminster Magistrates' Court to fraud by false representation (ss.1 and 2 Fraud Act 2006) and three counts of making a false instrument (ss.1 and 6 Forgery and Counterfeiting Act 1981) (FCA press release). He created a fictitious takeover approach for Touchstone Exploration Inc, which is listed on AIM and the Toronto Stock Exchange, using false identities and forged documents, while holding shares that would have gained from any rise in price had the approach been announced. The FCA opened its criminal investigation in March 2025; Touchstone is not under investigation, and sentencing will follow. The charges are fraud and forgery offences, and on the FCA's account the approach was never announced to the market. AIM companies and their nominated advisers can guard against the same trick by verifying a bidder and its advisers through independently sourced contacts before treating an approach as real.
Revocation refused. A Decision Notice dated 15 July 2026 and published on 1 September refuses Anthony George's application under s.56(7) FSMA to revoke the prohibition order made in September 2021, which rested on self-assessment returns understating his income and false information given in a compelled FCA interview. Under ENFG 5.5.4G the FCA will not generally revoke an order unless it is satisfied both that the risk will not recur and that the individual is fit and proper. It was satisfied of neither, citing the limited self-reflection Mr George had shown about his misconduct and the insufficiency of the steps he had taken since 2021 to address its concerns about his dishonesty. He has referred the notice to the Upper Tribunal.
Cancellations. Final notices dated 11 September 2026 cancel the Part 4A permissions of O B Payments Ltd, for unpaid fees and levies, and Professional Liability Network, which stopped answering FCA correspondence and did not keep its contact details up to date, both under s.55J on threshold condition grounds. A notice of decision of 7 September cancels HR Bank Limited's registration as an Annex 1 financial institution under regulation 60(3)(b) of the Money Laundering Regulations 2017, after it failed to answer two regulation 66 information notices sent in December 2025. HR Bank had been registered since 22 April 2015 and had not responded to any of the FCA's attempts to contact it between July 2024 and August 2025. None of these notices carries a penalty. In each, an unanswered request from the FCA became the ground for removal.
Market Developments
Wilkins says the Bank's systemic stablecoin rules will be final by the end of 2026, with tighter reserve and liquidity terms
INFO · Sectors: Payments, Digital Assets, Asset Management
On 15 September 2026 Carolyn Wilkins, a member of the Financial Policy Committee, gave a speech at Queen's University Belfast on stablecoins and the international role of the US dollar. She said the views were her own rather than the FPC's.
On timing, she said the Bank's framework for systemic sterling-denominated stablecoins, published as a policy statement and draft rules in June 2026, "will be finalised at the end of this year". On calibration, she described it as more restrictive on reserve assets than the US framework she discussed and as giving more weight to liquidity contingency planning, payment-system access and arrangements for failure, while allowing for central bank liquidity under appropriate conditions; an overseas issuer of a systemic sterling stablecoin would have to establish a UK entity and keep key safeguarding arrangements in the UK. She also compared the way redemptions force issuers to sell reserve assets with the 2022 LDI episode in gilts, and said the sector is not currently large enough to pose a material financial stability risk in the UK.
She also addressed where stablecoin money comes from. If investors move from a government money market fund into a stablecoin whose issuer buys the same bills, net demand for safe assets barely changes; if the money comes from bank deposits, bank funding and credit can be affected. She put stablecoins in the same category as deposits and money market fund units: demandable claims that holders can redeem quickly.
FS26/1, published the day before, is the companion piece. The authorities have confirmed that stablecoins can be used as settlement assets in the Digital Securities Sandbox, subject to conditions, and they're working on tokenised collateral, which respondents said should include tokenised MMF units. If both develop, sterling treasury cash could sit in two instruments doing a similar job under two different sets of liquidity rules. I think managers of short-dated sterling funds should follow the Bank's final stablecoin rules as closely as the FCA's MMF proposals.
Pill argues for a 4% Bank Rate before the 17 September decision and warns that markets are pricing two different paths
INFO · Sectors: Asset Management, Private Credit, Banking
Huw Pill, a member of the Monetary Policy Committee, set out his case for a higher Bank Rate in remarks to an Edinburgh Chamber of Commerce roundtable, published by the Bank on 3 September 2026. They are one member's views, not the Committee's. The MPC has held Bank Rate at 3.75% since March; Mr Pill has voted to raise it to 4% at recent meetings, and the remarks explain why ahead of the next decision on 17 September. As he describes it, the majority has judged 3.75%, together with tighter broader financial conditions including an upward-sloping money market curve, sufficient to contain the inflation risk from higher energy prices.
He describes the energy shock from the Gulf conflict as something closer to Knightian uncertainty, which will not resolve meeting by meeting, so waiting for clarity risks a bias towards the status quo. Relying on that curve to do the tightening carries what he calls "wrong-way risk": the market may ease conditions just when the MPC needs them tighter. He cites staff analysis showing that the three scenarios in the April Monetary Policy Report implied a two-peaked distribution for Bank Rate a year ahead, one near 3.75% and the other towards around 5%, while the July scenarios produced a single peak with a higher mean. He sees no de-anchoring of longer-term inflation expectations; his concern is "catch-up" dynamics as firms, households and government respond to the relative price shock. A prompt rise, he says, "need not be the start of a prolonged and aggressive series of increases".
For leveraged funds the remarks bear on stress-test design. Managers with floating-rate borrowers or fund-level facilities should record in their liquidity and valuation papers which rate path they assume, and why. A real estate or private credit fund whose rate stress stops at 4% covers Mr Pill's preferred path and leaves out the upper peak of the April distribution.
Regulatory Calendar
September 2026
- 16 Sep FCA CP26/27, remuneration reform for solo-regulated firms, closes.
- 17 Sep MPC Summary and minutes (Bank Rate decision).
- 18 Sep FCA CP26/28 discussion chapters other than prudential close; FCA CP26/23, Consumer Duty scope and proportionality, closes; PRA CP9/26, Basel 3.1 internal model approach for market risk, closes.
- 30 Sep FCA cryptoasset authorisation application window opens (closes 28 February 2027).
October 2026
- 6 Oct FCA Annual Public Meeting, Assembly Rooms, Edinburgh, and online.
- 12 Oct FCA CP26/32 (MMF reporting, CCI corrections and other quarterly items) closes.
- 14 Oct PRA CP10/26, ring-fenced bodies, closes; PRA CP11/26 and FCA CP26/29 on captive insurance close.
- 16 Oct FCA CP26/30, equity market transparency and market structure, closes.
- 22 Oct FCA CP26/26 (FRAME) and CP26/28 (UK AIFM regime: consultation chapters and prudential discussion chapter) close, both extended in August.
- 23 Oct FCA call for input on tokenised gold closes.
November and December 2026
- 5 Nov MPC Summary and November Monetary Policy Report.
- 17 Dec MPC Summary and minutes.
- End-2026 FCA to make its MMF rules in a new MMFS sourcebook (CP26/32); Bank to finalise its systemic sterling stablecoin framework (Wilkins speech, 15 September).
- Later in 2026 FCA and Bank Tokenisation Roadmap with target dates; Bank consultation on tokenised collateral at CCPs (FS26/1); further FRAME prototype forms.
Key dates in 2027 and beyond
- 1 Jan 2027 PRA rules for the Overseas Prudential Requirements Regime (PS16/26) take effect alongside Basel 3.1.
- H1 2027 FCA policy statement on FRAME; FCA consultation on custody of relevant specified investment cryptoassets.
- 7 Jun 2027 CCI transitional period ends (DISC TP 2); full DISC regime applies from 8 June.
- Q3 2027 Proposed start of the new MMF rules and weekly MMF reporting (CP26/32).
- 25 Oct 2027 Cryptoasset regime and CASS 17 safeguarding rules take effect.
- 2028 Envisaged implementation of the UK AIFM regime and FRAME; proposed 8 June 2028 deadline for CCIs closed to new business.
If your firm's founder or controlling owner became the subject of a disciplinary process tomorrow, who would convene the panel, who could remove its members, and would the firm still have two people directing the business and a risk function separate from portfolio management the following morning? Which board-approved document answers each of those questions, and when did the board last test it against the partnership agreement or articles?
We’d welcome your perspective. The best responses may feature in a future edition.
Insight
Individual accountability moved twice this fortnight. On 1 September the conduct rules at non-bank firms widened to cover serious harassment of colleagues. On 14 September the Upper Tribunal confirmed that a founder who used his ownership to remove the body holding him to account was acting within COCON and could be fined for it, and it went through the FCA's penalty arithmetic line by line, cutting what it saw as double counting and keeping a deterrence multiple justified in part by the firm's assets. Taken together, they make it much harder for an owner-managed firm to treat conduct at the top as a private matter between partners.
The same fortnight shows the FCA building its data capability ahead of a lighter AIFM rulebook. The research note, the FRAME consultation that now runs to 22 October and the weekly MMF proposals point one way: fewer prescriptive rules for smaller managers and better, more comparable data on all of them. I think that's a sensible trade, but it moves compliance effort. Returns that used to be filed and forgotten will be read and compared across peers, and the FCA has already written that some self-reported liquidity figures may be overoptimistic.
For an owner-managed firm the autumn list is short. Check that the constitution cannot leave the firm with one director overnight, map the disciplinary policy to COCON 1.1.7FR, and test the AIF002 return against the fund documents and the risk function's own stress results. Principals with appointed representatives can add one item from the Thomas notice: reconcile provider commission data against advisers' own coding before paying out. Each item needs a named senior owner and leaves a record the board can ask to see.