Background
The FCA regime for recording telephone conversations and electronic communications is set out in Senior Management Arrangements, Systems and Controls (SYSC)10A. The FCA noted that this work will be of interest to wholesale banks and other firms in scope of that regime.
The FCA surveyed eleven wholesale banks, both large and small requesting information on policy enhancements they had implemented and the management information they use for communications that are permitted by a firm yet take place outside of monitored and recorded channels and held follow up discussions with firms and industry panels.
Findings
The FCA found that most but not all firms in its sample continue to identify breaches of their internal policies, although the FCA noted that a breach of internal policy may not be a breach of FCA rules. However, according to the FCA, ongoing breaches demonstrate the importance of firms focussing on improvements in behaviour and not just in detecting off-channel communications.
That said, the FCA set out that all firms in the sample had improved their processes over the past two years. Actions firms had taken included:
- Frameworks: Updating policies to include new technology, streamlining processes for employees to submit self-disclosed off-channel messages, prohibiting the use of personal numbers in out of office replies and directories, and establishing helplines and training sessions on off-channel communications. Large firms had also adopted a single, global recording and monitoring policy across jurisdictions to ensure consistency.
- Surveillance: Updating surveillance lexicons to include non-text communications such as emojis and GIFs, integrating natural language processing to filter false alerts with AI, monitoring low levels of staff communication on on-channel applications, and providing corporate devices to client-facing staff.
- Third-party vendors (TPVs): Increase in third-party providers facilitating the monitoring and recording of different communication channels. However, firms reported challenges with TPV solutions such as service outages, data reconciliations and delays or missing recorded data from vendors. The FCA also reminded firms that regulatory responsibilities in relation to SYSC 10A cannot be transferred to third parties.
- Management Information (MI): For large firms this included detailed breach tracking, second line of defence findings, third party vendor KPIs, BYOD monitoring and detecting non-compliance via RAG thresholds. For smaller firms, the most comprehensive actions included breach data being reported at the group level, service level agreements for reviewing alerts using RAG thresholds, and enhancement programmes were tracked. Less comprehensive MI focussed solely on metrics without broader context about the underlying causes.
- Consequence Management: Training played a key role in reinforcing expectations where role-targeted, scenario-based sessions that incorporated real examples from surveillance made training more effective.
Next Steps
Overall, the FCA highlighted that firms may wish to consider whether staff understand their record-keeping responsibilities, barriers to compliance with policy frameworks, monitoring of third party-vendors, surveillance models, senior manager oversight and use of MI, and if leadership set a tone from the top to encourage compliance.
The FCA will continue to explore with firms their approach to off-channel communications and the outcomes being delivered, identifying trends on breach data and if further action may be required.

