The FCA deliberately declined to tell firms how to investigate non-financial misconduct, calling it an area requiring careful judgement. The implication is not that any investigation process will do. The implication is that firms will be judged on the quality of the process they chose, after the fact. For People and Legal leaders in FCA-authorised firms, the question between now and 1 September 2026 is whether the investigation framework holds up under that kind of scrutiny.
This post pulls together the pattern we have seen running cleanly across sectors already operating under equivalent regimes — multi-country ER programmes, healthcare governance under the CQC, and the EU Whistleblowing Directive. The components are the same. What matters is whether they are stitched together or sitting in different systems.
Why the FCA left the investigation framework undefined
Policy Statement PS25/23 is explicit on this point. The FCA considered prescribing an investigation standard and chose not to. The reasoning: non-financial misconduct spans too wide a range — bullying, harassment, sexual misconduct, violence, inconclusive outcomes, outside-work conduct — for one framework to serve every case. Firms, as the FCA put it, are best placed to assess seriousness in individual cases.
The absence of prescriptive guidance is not the absence of expectation. The guidance anchors firmly on dignity and environment under the Equality Act test, and anchors Senior Manager personal liability on whether a manager could reasonably have known and had authority to act. Both anchors imply an investigation process capable of surfacing the misconduct, substantiating it or dismissing it with reason, and producing the record that proves the firm met its Conduct Rule 2 duty.
For the full regulatory context, see our pillar guide: the FCA non-financial misconduct rules.
The pattern that works, assembled from the sectors already running it
Three sectors have been running equivalent frameworks for several years and the pattern across them is remarkably consistent.
Multi-country employee relations. The large multi-country programmes we have seen — mining services, global technology, international hospitality — all run the same spine: case intake with severity classification, independent routing when the allegation touches the line, documented investigation, substantiation or dismissal with reasons, action tracking, and a learning loop back into training. The pattern survives because it is defensible when a regulator or a plaintiff asks what the firm did.
Healthcare under the CQC's Single Assessment Framework. Registered healthcare providers run a near-identical pattern under the "Safe" and "Well-led" key questions. The vocabulary differs — incidents, duty of candour, Reg 20 instead of COCON 1.1.7FR — but the components are the same. The CQC inspects the quality of the loop, and that is instructive for how the FCA will likely approach it.
EU Whistleblowing Directive and Sapin II. EU operations have had to run a documented investigation framework for serious concerns since 2021 (Directive) and 2017 (Sapin II). Firms with operations across the UK, EU and US already run the pattern, since one channel typically has to satisfy multiple regimes at once.
From those three, the pattern looks like this:
1. Intake and severity classification
A single intake surface for every type of serious concern — named channel, anonymous channel, email, hotline. Every case classified at intake using a severity scheme the firm has published. The dignity-and-environment test is the one anchor PS25/23 leaves specific, so it belongs here.
2. Independent routing when the line is implicated
If the allegation touches the reporter's line manager, the case must route independently. Firms that have been inside a tribunal know what happens when it does not. The route needs to be in the policy and visible in the system log, not in someone's head.
3. Investigation documented at step level
Not just an outcome report. The steps taken, the people spoken to (with role, not necessarily name), the documents reviewed, the chronology from intake to decision. A Senior Manager invoking the Conduct Rule 2 defence — "could not reasonably have known" — relies on an audit trail they can point to.
4. Substantiation or dismissal with reasons
Three outcome categories, not two. Substantiated, dismissed with reason, and inconclusive-with-reason. The FCA called inconclusive outcomes an area requiring careful judgement. The careful judgement has to be documented, not inferred.
5. Action tied to the outcome
Substantiated cases produce an action with an owner and a deadline. The action can be disciplinary, developmental, structural (a training change, a policy change, a reporting-line change), or a combination. The closed loop is what gives the firm something to show in a quarterly culture review and in a regulatory inspection.
6. Learning fed back
Patterns across cases feed back into training content, policy language, channel copy and the severity classification scheme itself. This is the component that distinguishes a mature framework from a procedural one.
Three places this pattern breaks when it is run in separate systems
The pattern described above is not controversial. What breaks it is almost always the same thing: the components live in different systems and the thread between them is manual.
In the readiness audits we have seen running this year, three breaks recur:
- Intake in a form or inbox, investigation in a Word doc, action in a spreadsheet. The audit trail is reconstructable but not retrievable; a Senior Manager cannot produce it on a day's notice. This is where "due skill, care and diligence" is hardest to defend.
- Learning that does not reach training. Patterns are visible to the investigator and the HRBP, invisible to the person who writes the manager training. The training content ages faster than the signal.
- Inconclusive outcomes with no documented reasoning. The hardest cases close with "insufficient evidence" and nothing further. When a regulatory reference is later requested, the firm cannot answer the FCA's standard: what judgement did we exercise and why.
What to look at between now and September 2026
Three questions to put to the current framework:
- Can every Senior Manager produce a chronological record of every substantiated case in their area, with intake date, investigation steps, decision reason and verified closure, in a day?
- Does the inconclusive-outcome handling in the framework produce documented reasoning the firm would be comfortable attaching to a regulatory reference?
- Does learning from substantiated cases reliably reach the training content, the channel copy and the severity classification scheme — or does it stop at the investigator's final report?
If any of those answers is "not reliably", that is where to spend the next eleven months.
How Safe Workplace fits
Safe Workplace runs the investigation framework described above as one connected workflow — intake with severity classification, independent routing when the line is touched, step-level documentation of the investigation, three-outcome decisioning, action tracking tied to policy and training, and pattern feedback across cases. If the Conduct Rule 2 defence in your firm currently relies on reconstructing an audit trail from three systems, we would be happy to show you what the one-click version looks like. Book a demo.

