Welcome to the UKGI weekly regulation update service for Aviva ABC brokers
We hope you find the Updates useful. If you are
interested in subscribing to our affordable
ABC compliance support package, please
email us at ABC@ukgigroup.com or
call UKGI on our dedicated ABC
contact line 01925 765777.
UKGI has teamed up with Aviva to provide ABC brokers with access to our weekly regulation update free of charge! The service provides a round-up of compliance-related issues to give you an overview of what’s on the regulatory horizon.
This will help you stay up to date with what regulatory changes may be coming up, so you can plan ahead.
You can also access previous ABC weekly regulation updates by clicking on the archive tab at the top of the page.
UKGI is working with Aviva to provide ABC brokers with access at preferential rates to our market-leading, online compliance manual and its library of over 200 template documents!
To watch a short introductory video showcasing the manual, click here, and to see for yourself just how useful the manual could be for your business, book an interactive demonstration.
| Link(s): | Motor finance scheme: legal challenge documents | FCA VW reply to the FCA response Mercedes-Benz reply to the FCA response CAAF reply to the FCA response Consumer Voice reply to the FCA response |
Context
The FCA has updated its Motor legal finance scheme legal challenge documents web page, and has published four industry responses to its motor finance redress scheme Grounds of Response, which the FCA served on 6 July 2026. The responses are from Volkswagen Financial Services, Mercedes-Benz Financial Services, CA Auto Finance UK, and Consumer Voice Limited.
Key points to note and next actions
- All of the Applicants remain in favour of regulatory intervention to ensure an orderly resolution of complaints and claims pertaining to motor finance commissions, but stress that both firms and consumers are entitled to expect that proper time and care is given to the design and execution of the Schemes to ensure that they are legally robust and operationally fit for purpose.
- The responses raise a number of challenges, not least in relation to the whether the FCA’s exercise of its discretion in this regard is within Statutory (FSMA) boundaries.
- Challenges include the presumption of ‘unfair relationship’, redress, the legality of the scheme, causation of loss, market integrity, compensatory interest, and standing/candour.
Context
The FCA has updated its Scale-up Unit: supporting fast-growing, innovative firms web page to confirm that the Unit is open to expressions of interest for a second cohort.
Key points to note and next actions
- From 1 September to 30 September 2026, the Unit is open to expressions of interest for firms wishing to be part of the second cohort.
- Find further details, including eligibility criteria, on the PRA website.
Context
The FCA has updated its Non-financial misconduct in financial services web page to remind firms that the new rules and guidance have come into effect.
Key points to note and next actions
- Non-financial misconduct includes behaviour that is not of a clearly financial nature such as bullying, harassment and violence.
- Where NFM is serious and goes unchecked, it can harm individuals, firms and confidence in financial services.
- The new rules and guidance to help tackle NFM came into effect on 1 September 2026. Firms should ensure that they know about the changes and how to implement them within their firms.
Context
The FCA has published its insights for firms on how frontier AI may affect cyber resilience, governance and vulnerability management. We’re making these insights widely available so that firms (particularly small to medium-sized firms) can learn from others, consider the insights in the adoption of AI models, and prepare for AI-enabled cyber threats.
Key points to note and next actions
Although frontier AI models can help firms identify and analyse their cyber vulnerabilities quicker, if used maliciously they can amplify cyber threats to firms’ safety and soundness, customers, market integrity, and financial stability.
The FCA has previously commented that these models represent a step-change in capability, with significant implications for cybersecurity and operational resilience. It has therefore been engaging with firms to understand how they were using, testing and preparing for frontier AI models with cyber capabilities, to learn more.
The main themes reported by firms were: vulnerability discovery is accelerating faster than firms’ ability to respond; frontier AI is becoming a test of organisational resilience, not just a tool; the value of frontier AI depends on the firm’s operating environment; frontier AI is making foundational cyber and operational resilience more important; and effective governance and human judgement remain critical.
The findings in the publication are covered under the following titles:
- Harness engineering (the environment, controls and processes around an AI model that make its outputs useful, safe and reliable);
- Preparing for a vulnerability wave; and
- Effective cyber and operational resilience foundations
Context
The FSCP has published its response to the FCA in about the FCA Consultation Paper CP26/22: Simplifying the insurance rules. Broadly, the Panel supports the FCA’s ambition of reducing consumer confusion and information overload by removing mandatory disclosures that do not help consumers choose policies whilst enabling and supporting the improvement of consumer confidence, understanding and capability.
Key points to note and next actions
The Panel recognises:
- most retail general insurance products are now purchased online, and supports greater personalisation of digital communications; and
- removing the overlapping definitions of advice in the retail general insurance market and clarifying the boundary between a true personal recommendation and a simple non-advised sale is helpful.
The Panel believes that AI adoption, and indeed Consumer Duty outcome requirements, should require firms to proactively signpost to other service providers where they are unable to meet a consumer need and/or a support/service requirement.
The Panel urges the FCA to:
- be mindful that, whilst the majority of consumer retail general insurance policies are today purchased online and on a non-advised basis, this is not the case in relation to pure protection insurance where the majority of sales made result from engagement with an adviser and the provision of a personalised recommendation; and
- continue to stress to financial services firms that, irrespective of the type of sales and product, firms must pay due regard to the information and support needs of their client, particularly where they are digitally excluded, vulnerable and/or requiring reasonable adjustment.
Context
The FSCP has published its response to the FCA in about the FCA Consultation Paper CP26/23 Consumer Duty – scope and proportionality. The Panel has opted to respond to some of the questions posed in the Consultation, even though the proposals within it are centred on firms and seek to refine the application of the Consumer Duty.
Key points to note and next actions
The Panel:
- stresses that consumer protections and the foundational customer understanding, fair value, good service and support outcomes of Consumer Duty must be preserved.;
- welcomes clearer accountability for consumer outcomes across multi-firm distribution chains;
- asks that the operational cost savings released as a consequence of this CP’s proposals should be recycled to improve consumer value and benefits; and
- recommends greater clarity, in relation to the allocation of risk between firms in the distribution and/or manufacturing chain, on who the consumer complains to and how would they be able to determine this. The Panel asks how the consumer avoid being passed between, for example, the primary and secondary manufacturers.
In relation to the specific questions in the Consultation, the Panel comments specifically on two issues:
- The Panel suggest that both Pure Protection and Health Insurances are brought within scope of the FCA’s proposal as the protection was purchased when the consumer was resident in the UK (response to Q. 5).
- The Panel welcomes the FCA providing clarified guidance to firms to reflect that they may act differently to support customers in vulnerable circumstances depending on their role within the distribution chain with firms closer to the customer having more direct responsibility for identifying and responding appropriately to vulnerable customers’ needs (response to Q. 21).
| Link(s): | CBNA_London_Public_Penalty_Notice.pdf Financial sanctions enforcement: decisions and monetary penalties imposed – GOV.UK |
Context
OFSI has imposed a £4,732,830.58 monetary penalty on Citibank, N.A., London Branch (CBNA London) for breaches of the Russia (Sanctions) (EU Exit) Regulations 2019 and the Global Anti-Corruption Sanctions Regulations 2021.
Key points to note and next actions
- The case involved £19.7 million worth of transactions (970 in total), which were processed between 2022 and 2025. The majority of the breaches occurred between February and November 2022 following Russia’s illegal invasion of Ukraine and arose across the bank’s operations.
- CBNA London voluntarily disclosed the majority of the breaches, co-operated with OFSI’s investigation and undertook remediation. A 20% voluntary disclosure and co-operation discount and a 20% settlement discount were applied, which resulted in a final penalty of £4,732,830.58 being levied.
Context
With venues being booked, suppliers being secured and deposits being paid months, or even years, before the big day, couples are being urged by the Financial Ombudsman Service to make checking their insurance part of their wedding planning.
Key points to note and next actions
Over the past six years, the FOS has investigated more than 600 wedding insurance complaints, with claim declines, delays and valuations being among the most complained about issues. Cases have included:
- venues becoming unusable following fires or flooding
- venues or suppliers going out of business
- photographers, caterers and other suppliers failing to provide the expected service
- illness affecting the couple or close family members
- cancelled travel disrupting overseas weddings
The FOS has shared tips for couples, to help them avoid insurance pitfalls and also provides a couple of case studies in the article itself.
Firms that sell Wedding Insurance should review the article and ensure they support customers to understand the potential issues that could arise and help them decide on the most appropriate cover.
Context
The NCSC has seen increased targeting of operational technology systems (OT) across multiple sectors globally, including the UK. This has been carried out by a range of threat actors and resulted in some limited real-world disruption.
Key points to note and next actions
- Any organisation with internet-exposed OT could be affected, and firms should not assume that their OT is inaccessible from the internet without verifying it. Misconfigurations, legacy connections or unmanaged assets can all lead to unintended exposures.
- The NCSC recommends that firms should –
- Build a definitive view of their OT assets and ensure OT devices are not directly accessible from the public internet
- Replace default credentials and strengthen access controls for OT systems
- Control access to OT networks and maintain secure, supported boundary devices
- Adopt secure industrial and management protocols where possible
- Ensure all connectivity to and within OT networks is logged and monitored
- Ensure OT devices are operated in a state that prevents remote programming during normal operations
- Separate OT, management and business networks to limit the impact of incidents
- Maintain tested backups and recovery procedures for critical OT systems
The NCSC recommends all organisations should register for its free Early Warning service to help identify publicly exposed vulnerabilities and other potential security issues affecting internet-facing systems, supporting efforts to detect and address risks before they are exploited.
