
Compliance Audit & Reviews in 2026: Your Compliance Monitoring Programme Is Now Your Only Defence โ So Why Does It Only Measure Activity?
Making Compliance Work | Compliance Consultant
The short answer
A compliance audit is an independent test of whether your controls actually work; compliance monitoring is the routine, risk-based testing that runs between audits. In 2026 the FCA has shifted decisively to a supervision-led model โ intervening earlier through voluntary requirements and skilled person reviews rather than waiting to build an enforcement case. That makes your own monitoring evidence the first thing a supervisor asks for and the last thing standing between a routine query and a section 166. The problem: most programmes in small and mid-sized firms record that work was done, not what it found. Activity is no longer evidence.
1. Four different things, routinely confused
Firms use “audit”, “review” and “monitoring” interchangeably, then discover under supervisory pressure that they have three of the four and none of the one that mattered. The ladder looks like this:
| Activity | Who does it | What it answers | Frequency |
|---|---|---|---|
| Compliance monitoring | Second line (internal or outsourced) | Are our controls operating as designed, right now? | Continuous, risk-based |
| File review | Second line or specialist | Did this specific customer outcome meet the standard? | Sampled, monthly or quarterly |
| Compliance audit | Independent of the compliance function | Is the compliance framework itself adequate and effective? | Annual, or on material change |
| Skilled person review (s166) | FCA-appointed, firm-funded | Whatever the FCA has decided it needs to know | When you have already lost control of the narrative |
The distinction that matters most is between review and test. Reading a policy and confirming it exists is a review. Pulling twenty files and checking whether the policy was followed โ and what happened to the customer when it wasn’t โ is a test. Almost every weak programme we assess is built entirely from the former.
2. Why 2026 raised the stakes
Three shifts, all pointing the same way.
The FCA’s revised supervisory model rewards evidence and punishes opacity. Firms that can consistently demonstrate good outcomes can expect lighter-touch supervision; where the regulator identifies harm it intends to intervene more quickly and decisively. “Demonstrate” is the operative word โ the firm carries the evidential burden.
Earlier, quieter intervention is now routine. Voluntary requirements rose from 104 in 2023/24 to 119 in 2024/25 โ no longer exceptional but a standard supervisory tool, and recorded on the Financial Services Register for your clients, lenders and PI insurers to see. Regulatory risk has migrated forward in the cycle, away from headline fines and into binding requirements imposed during ordinary engagement.
Skilled person reviews have surged. Deployment jumped from 47 to 83 reviews year-on-year, and a new FCA skilled person panel framework took effect on 1 April 2026 running to 31 March 2030. Controls and risk management frameworks account for the majority of mandates. A s166 costs a small firm a six-figure sum it did not budget for, consumes the senior team for months, and produces a report the FCA reads before you have finished arguing with it.
The uncomfortable arithmetic: the cheapest independent review of your controls is the one you commission yourself.
Related reading: our companion piece on the Money Laundering Regulations 2026 changes explains why AML frameworks in particular now depend on documented judgement rather than prescriptive triggers.
3. The failure mode: programmes that count activity
The FCA’s own review of Consumer Duty board reports found persistent weaknesses, and independent analysis of board reporting has reached the same conclusion โ too many boards rely on aggregated MI and narrative assurance that documents oversight without demonstrating impact.
That is the whole problem in one sentence, and it applies far beyond the Duty.
Here is what a weak monitoring output looks like:
“Q2 monitoring completed. 15 mortgage files reviewed. 2 minor documentation issues identified. Training reminder issued. RAG status: Green.”
And here is what the same quarter looks like when the programme is actually working:
“15 files sampled from the two advisers with the highest BTL volumes (risk-based selection rationale attached). 2 files showed affordability evidence obtained after the recommendation was made โ a sequencing failure, not a documentation failure. Root cause: the CRM allows the suitability report to be generated before the income verification field is completed. 3 of 3 files subsequently pulled from the same adviser showed the same pattern, so this is systemic, not isolated. System control change requested (owner: Ops Director, due 31 July). Prior-period customer impact assessment scoped: 41 cases. Re-test scheduled Q4. RAG status: Amber pending system fix.”
The first paragraph is worthless under scrutiny. The second is a defence โ because it demonstrates detection, root cause analysis, ownership, customer impact consideration and verification. Those five elements are what a supervisor, a skilled person or an FCA authorisation caseworker is looking for, and their absence is what turns a small finding into a serious one.
4. What a 2026-grade Compliance Monitoring Programme contains
If your CMP is a spreadsheet of tasks with dates, it is a diary, not a programme. A defensible CMP has seven components:
- Risk-based scope, documented. Every item on the plan traces to a risk on your risk register, and every material risk has monitoring coverage. Where a risk is not monitored, the rationale is recorded. Unexplained gaps are the finding.
- Sampling methodology. How many, chosen how, and why that is sufficient. Random sampling looks impartial and often is not risk-based; targeted sampling is stronger provided the targeting logic is written down.
- Testing standards. For each check: what “pass” means, in objective terms, before you start looking. Retro-fitted standards are not standards.
- Root cause analysis. Not “adviser error” โ that is a symptom. Systems, incentives, capacity, training design and process sequencing are causes.
- Named ownership and deadlines for remediation. Compliance identifies; the business fixes. A finding without a named business owner will still be open next year.
- Closure verification. The re-test. This is the single most commonly missing element and the one that most clearly separates a real programme from a performative one.
- MI and escalation to the board. Trends, not snapshots. Repeat findings flagged as repeat findings. Overdue actions ageing visibly. Minuted board challenge โ the FCA expects boards to interrogate the report, not receive it.
5. Your 2026 audit plan: eight areas that will be tested
Build the year’s plan around where supervisory attention is actually pointing.
1. Consumer Duty outcomes โ evidence, not framework. The FCA published six good-practice and areas-for-improvement papers within the first ten weeks of 2026. The question has moved from “do you have a framework” to “can you show outcomes insight is changing decisions”. Test the annual board report against the underlying data, not against last year’s report.
2. Customers in vulnerable circumstances. Test the journey, not the policy. Sample cases where vulnerability was disclosed and trace what changed as a result. If nothing changed, that is your finding.
3. AML and financial crime post-30 June 2026. The amended Money Laundering Regulations narrowed prescriptive triggers, which means your Business-Wide Risk Assessment now carries the judgement. Audit whether the BWRA is live, whether customer risk ratings are applied rather than merely defined, and whether monitoring is calibrated to the risks you identified.
4. Complaints and root cause analysis. Complaint handling remains a core supervisory focus, with expectations around proper identification, recording, analysis and genuine root cause work. Test whether root cause findings ever produce a change to a product, process or script. If the RCA log has no downstream actions, the process is decorative.
5. Operational resilience and third-party oversight. This is the most consistent cross-sector obligation, with new operational incident and material third-party reporting requirements landing. Test dependency mapping and whether scenario testing has ever produced a remediation action.
6. SMCR certification and reasonable steps. SMCR reform is in train with the stated aim of halving the regulatory burden โ but simplification of process does not dilute individual accountability. Audit the certification evidence base and whether Senior Managers can each produce the paper trail supporting their reasonable steps.
7. Appointed representatives, introducers and outsourced functions. Your regulatory responsibility does not stop at your own front door. Test the actual oversight performed, not the oversight agreement signed.
8. Regulatory reporting data quality. The FCA increasingly identifies firms through data anomalies before any human forms a view. Test whether your returns reconcile to your source systems. Being selected for scrutiny because of a reporting error is an avoidable and expensive way to meet your supervisor.
6. Why firms cannot credibly audit themselves
Three structural reasons, none of which reflect on the competence or integrity of the people involved:
- The compliance function cannot independently assess the compliance framework it built. That is not scepticism; it is the definition of independence. In a firm of fifteen people, the person who wrote the procedure is the person testing it.
- Familiarity suppresses findings. After six months, the person doing the sampling has stopped seeing the pattern that a fresh reviewer spots in the first three files.
- Escalation is career-shaped. An employed compliance officer raising a systemic finding about a director’s book of business is doing something an external reviewer does without hesitation.
An annual independent review does not replace internal monitoring โ it validates it. And when the FCA asks who has independently assessed your framework, “we did it ourselves” and “an independent firm reviewed it in March, here is the report and the closed action log” are answers with very different consequences.
7. A twelve-month cycle you can actually run
Month 1 โ Plan. Refresh the risk register. Map monitoring coverage to it. Set the year’s sampling volumes and testing standards. Board approves the plan, minuted.
Months 2โ11 โ Execute in quarterly blocks. Each quarter: one thematic deep-dive (from the eight areas above), a rolling file review sample, and a follow-up test of the previous quarter’s remediation. Report to the board quarterly with trend MI, not raw counts.
Month 6 โ Independent review. External assessment of the highest-risk theme, or of the monitoring programme itself. Timed mid-year so findings can be remediated within the same cycle rather than landing on the year-end pile.
Month 12 โ Effectiveness assessment. One paper answering three questions: what did monitoring find this year, what changed as a result, and what does that tell us about next year’s plan? That document is the single most useful artefact you can hand to a supervisor, a skilled person, an acquirer in due diligence, or a PI insurer.
Frequently asked questions
What is the difference between a compliance audit and compliance monitoring?
Monitoring is continuous, risk-based testing of whether controls operate as designed, carried out by the second line. A compliance audit is a periodic, independent assessment of whether the compliance framework itself is adequate and effective โ including whether the monitoring is any good. Firms need both.
How often should a firm carry out a compliance audit?
Annually as a baseline, and additionally on material change: new permissions, a new product line, a significant acquisition, rapid growth, a change of Senior Manager, or a new regulatory regime affecting your business. Growth in particular is a trigger โ several major enforcement cases turned on controls that failed to scale with volumes.
Does a small firm really need a Compliance Monitoring Programme?
Yes. The FCA’s expectations are proportionate to size and complexity, not waived by them. A two-adviser firm needs a shorter programme, not the absence of one โ and SYSC obligations and the SMCR reasonable steps expectation apply regardless of headcount.
What triggers an FCA section 166 skilled person review?
There is no published list, but recurring triggers include data anomalies in regulatory returns, complaints patterns, safeguarding concerns in payments firms, governance and AML control weaknesses, unclear SMCR responsibility mapping, and whistleblowing or incident reports. A credible internal monitoring record, with closed actions, is the most effective protection.
What should a compliance monitoring report contain?
Scope and sampling rationale, testing standard applied, findings, root cause, customer impact assessment where relevant, named remediation owner, deadline, re-test date and outcome, plus trend data against prior periods. If your report lacks root cause and re-test, it is a checklist rather than a monitoring report.
How Compliance Consultant helps
We have spent 25 years building and testing compliance frameworks for FCA-regulated firms in mortgage broking, payment services, investment management, claims management, fintech and cryptoasset businesses.
- Independent Compliance Audits โ an external assessment of your framework, with a prioritised, costed remediation plan rather than a list of observations.
- Compliance Monitoring Programme templates โ practical, risk-mapped CMPs for FSMA and PSR firms, ready to adapt to your permissions.
- File Reviews โ including residential, buy-to-let, second charge, equity release and bridging mortgage file review frameworks, and DB pension transfer pre-submission checks.
- AML & Governance Reviews โ BWRA, CDD, monitoring and MLRO function testing against the 2026 Regulations, with an Annual MLRO Report template.
- SMCR support โ annual certification attestation and reasonable steps evidencing.
- FCA Authorisation โ where the governance and monitoring arrangements you describe in the application actually have to exist on day one.
Book a Discovery Call: https://bit.ly/CCDiscovr
Prefer to answer a few preliminary questions first? Use our voice agents:
Sources and further reading
- FCA, Consumer Finance and sector Regulatory Priorities reports, 2026
- FCA, review of Consumer Duty board reports; good practice and areas for improvement publications, 2026
- FCA Handbook: SYSC (systems and controls), PRIN 2A (Consumer Duty), SUP (supervision)
- Financial Services and Markets Act 2000, section 166 โ skilled person reports; FCA Skilled Person Panel framework, 1 April 2026 to 31 March 2030
- FCA Annual Report and enforcement data 2024/25 โ voluntary requirements and supervisory interventions
- The Money Laundering and Terrorist Financing (Amendment) Regulations 2026, SI 2026/621
- FCA/HM Treasury/PRA review of the Senior Managers and Certification Regime, 2026
Follow us:
Facebook | Twitter | Instagram | LinkedIn | Pinterest
Compliance Consultant | https://complianceconsultant.org | UK 0800 689 0190 | Int’l 020 8243 8620 | Discovery call: https://bit.ly/CCDiscovr
Compliance Consultant and Compliance Doctor are trading styles of UK Compliance Consultant Limited, Companies House number 14805896.
This article is general guidance current at the date of publication and does not constitute legal or regulatory advice for any specific firm.



