TL:DR: The FCA’s PS25/23 brings serious non-financial misconduct firmly within the regulatory perimeter, making workplace behaviour, culture and integrity matters for conduct rules and fit and proper assessments. For asset and wealth managers, this means embedding culture risk into governance, HR, compliance, remuneration, certification and risk frameworks. The UK is taking a more explicit approach than other major regions, but global regulators are moving in the same direction.
Whether conduct outside work is relevant to fitness and propriety will depend on whether the conduct is sufficiently serious that it may be relevant to the individual’s integrity and reputation.
The UK Financial Conduct Authority’s (FCA) Policy Statement PS25/23 marks a significant evolution in how regulators treat conduct risk. Previous frameworks focused primarily on financial misconduct, PS25/23 firmly establishes that non-financial misconduct (NFM), including bullying, harassment, and discrimination, is a regulatory issue as well as an HR concern. This shift has material implications for asset managers and wealth managers alike and reflects a broader global trend toward embedding culture and behaviour within prudential and conduct supervision.
PS25/23 finalises guidance on how firms should interpret and apply existing rules under the FCA Handbook, specifically the Code of Conduct (COCON) and the Fit and Proper Test (FIT). There are four key elements.
Non-Financial Misconduct (NFM) is now explicitly within regulatory scope
The FCA has clarified that serious workplace misconduct can breach individual conduct rules and undermine fitness and propriety assessments. Importantly, this applies across both banks and non-banks, removing historical inconsistencies.
Scope expansion beyond “financial activity”
The rules now cover behaviour in the following scenarios:
This reflects a deliberate move to treat culture as a driver of financial risk.
Private life is relevant, but only if material
The FCA draws a boundary. Conduct outside work is only relevant where it creates a “material risk” of regulatory breach.
This avoids overreach while still capturing serious integrity concerns.
Managers are accountable
Senior managers must take “reasonable steps” to prevent misconduct, but accountability depends on what they knew (or should have known) and their authority.
Implementation timeline has been set and changes become effective from 1 September 2026, firms are expected to embed changes into HR, compliance, and SM&CR frameworks.
This policy is easy to underestimate as it’s framed as guidance. However, in practice it accomplishes three critical steps:
The regulator has made clear that misconduct is not solely about: “Does this harm clients or markets?”. Regulators are showing more intent and focus upon: “Does this behaviour indicate a lack of integrity or risk to the system?”
We now see the FCA explicitly linking workplace behaviour, governance quality and market trust. This aligns with its broader strategy to strengthen confidence and reputation in financial services.
Firms must now treat HR investigations, whistleblowing, and cultural issues as regulatory processes, not internal matters.
For asset managers, PS25/23 is less about immediate rule breaches and more about systemic changes to governance and risk frameworks.
Conduct risk becomes a front-office issue
Portfolio managers, traders, and analysts are now directly exposed to conduct rule breaches for behavioural issues and subject to increased scrutiny under FIT assessments.
This changes how firms assess:
Increased regulatory scrutiny of “star performers”
Historically, high-performing individuals could be insulated from scrutiny. That model is no longer viable. Repeated behavioural issues can now:
Integration with investment risk frameworks
Firms will need to connect culture indicators, conduct breaches, investment decision-making risk. This is particularly relevant in high-pressure trading environments and private markets with less transparency
Third-party and delegated model risk
Asset managers relying on delegated portfolio managers or external advisers must consider whether cultural failures in third parties create regulatory exposure.
Wealth managers face a different, but equally important set of challenges.
Client-facing conduct risk expands
Advisers are now assessed on suitability and advice quality as well as behaviour toward colleagues and ethical standards. This matters because client trust is directly linked to perceived integrity.
Heightened suitability and reputation risk
Misconduct (even internal) can undermine client confidence and trigger complaints or reputational damage.
Greater pressure on smaller firms
Wealth managers often lack formal HR infrastructure and mature compliance frameworks. PS25/23 forces them to formalise processes, document decisions and evidence consistency
Social media and personal conduct
Advisers’ personal behaviour may now matter if it signals a risk of breaching regulatory standards. This is particularly relevant in relationship-driven business models.
The EU has taken a more indirect approach. Here the key focus areas relate to governance, risk culture and “fit and proper” assessments. We see the regulators like the European Central Bank emphasise board suitability and risk culture frameworks.
However, they do not explicitly codify workplace misconduct in the same way as the FCA.
The key difference is that the UK has explicit rules on behaviour and is more prescriptive, whereas the EU’s approach focused upon principles-based governance.
APAC Region:
In the APAC region, regulators are more conservative but appear to be converging on similar focal points. For example, Monetary Authority of Singapore (MAS) has a strong focus on individual accountability and culture, and we see the Hong Kong Monetary Authority (HKMA) emphasising manager accountability and governance.
However NFM is generally addressed through fitness and propriety and conduct expectations.
The APAC region appears to have in implicit linkage (eg culture means risk) whereas the UK has a more explicit regulatory trigger. Misconduct could be a breach according to its materiality.
N America Approach:
The US approach is more enforcement-driven rather than framework-driven. Regulators such as the Securities and Exchange Commission (SEC) or Financial Industry Regulatory Authority (FINRA) focus on misconduct affecting clients or markets, disclosure failures and ethical breaches tied to securities laws. Workplace misconduct is usually only relevant if it impacts clients or signals fraud or dishonesty.
In this way, the US approach is tied to investor harm, whereas in the UK, conduct is tied to integrity and culture.
The UK is leading on “culture as regulation”. PS25/23 is one of the clearest examples globally of turning culture into enforceable supervision.
We should expect convergence. Other regions are moving in the same direction, but more slowly and less prescriptively.
Firms need to rethink operating models. Firms must integrate HR, Compliance, Risk, Governance into a single conduct framework.
PS25/23 fundamentally changes the question firms must ask. The old mindset of asking: “Did this behaviour break a rule?” must be replaced with: “Does this behaviour indicate a risk to integrity, culture, or trust?”
For asset and wealth managers, the challenge is about proving that culture is controlled, measurable, and governable.
If firms embed it into their risk frameworks, they'll be ahead of where regulation is going.
Ruleguard can help firms turn PS25/23 expectations into practical, evidence-based controls. By connecting regulatory obligations, policies, attestations, workflows, issue management and assurance activity in one platform, Ruleguard enables asset and wealth managers to evidence how culture risk, conduct risk and individual accountability are identified, managed and governed.
This gives compliance, risk, HR and senior managers a clearer view of whether non-financial misconduct risks are being controlled consistently across the business.
Learn more about Ruleguard's Accountability Solution.
Ready to turn GRC into a board-level advantage?
Book a tailored discovery call with Ruleguard to see how leading firms unify risk and compliance, surface the insights executives care about, and stay audit-ready, without the spreadsheet sprawl.