Teaming up with... AVIVA

Welcome to the UKGI weekly regulation update service for Aviva ABC brokers

We hope you find the Updates useful. If you are
interested in subscribing to our affordable
ABC compliance support package, please
email us at ABC@ukgigroup.com or
call UKGI on our dedicated ABC
contact line 01925 765777.

UKGI has teamed up with Aviva to provide ABC brokers with access to our weekly regulation update free of charge! The service provides a round-up of compliance-related issues to give you an overview of what’s on the regulatory horizon.

This will help you stay up to date with what regulatory changes may be coming up, so you can plan ahead.

You can also access previous ABC weekly regulation updates by clicking on the archive tab at the top of the page.

UKGI is working with Aviva to provide ABC brokers with access at preferential rates to our market-leading, online compliance manual and its library of over 200 template documents!

To watch a short introductory video showcasing the manual, click here, and to see for yourself just how useful the manual could be for your business, book an interactive demonstration.

Link(s):  FCA RegData: Resources
COM001 – Complaints Reporting – Data Definition.xlsx

Context

The FCA has updated the Data Reference Guides section of RegData to include (on the third page) a link to an Excel spreadsheet of the questions and data requirements for the new COM001 Complaints Return.

Key points to note and next actions

The spreadsheet includes several tabs, including version control, ‘start page’, nil returns and sectors, and sector-specific table including ‘GI and Pure Protection’ and ‘Consumer Credit’.

  • On the GI and Pure Protection tab, row 31 confirms that the required data items set out at 309A to 313A (which appear under ‘Alloy wheel insurance’ as an example) will need to be repeated for each of the product types that the firm has received complaints about in the reporting period.
  • Similarly, row 59 confirms that the required data items set out at 322A to 325D (which appear under ‘Alloy wheel insurance’ as an example) will also need to be repeated for each of the product types that the firm has received complaints about in the reporting period.
  • On the Consumer Credit tab, the data item in row 7 (question 701A) asks for the ‘categories’ that firms have had complaints about.  There are only three options to pick from, one of which is ‘other consumer credit services’.  For most insurance intermediaries, this will be the only category that they are likely to receive ‘consumer credit’ complaints about.
  • The data item in row 8 (question 702A) includes a list of product / service types, and one of the options under ‘Other consumer credit services’ is ‘credit broking’.  This may be the only category that insurance intermediaries need to select.

The next UKGI Bulletin will be in relation to the new complaints reporting.

Link(s):  FCA secures bankruptcy order against Arthur Temlett | FCA
Financial Conduct Authority places restrictions on Arthur Temlett | FCA

Context

The FCA has asked the Court to make Arthur Temlett, trading as Abacus Insurance Consultants (‘Abacus’), bankrupt. This is known as sequestration in Scotland. The Sheriff granted the FCA’s application on 27 August 2026.

Key points to note and next actions

  • In January 2025 the FCA said it was concerned that the firm may have been selling motor or home insurance products without passing the premiums to the insurance provider.
  • Consequently the FCA placed restrictions on the firm with it being unable to carry out any regulated activities.
  • The FCA stated that Mr Temlett is awaiting trial on embezzlement charges following an investigation by Police Scotland.
  • The FCA also applied to the court to make the broker bankrupt, with the application being granted on 27 August 2026. Aver Chartered Accountants have been appointed as Trustee, to review Mr Temlett’s financial affairs and return any recovered funds to creditors.
  • The FSCS has opened for claims from Mr Temlett’s customers, and has confirmed they are working with Police Scotland to gather relevant information.
Link(s):  Handbook Notice 144
CP26/17: Quarterly consultation paper No. 52

Context

The FCA has published its latest Handbook Notice covering certain changes to the Supervision sourcebook in relation to the Baseline Financial Resilience return (FIN073).

Key points to note and next actions

  • The FCA Board has made changes to the Handbook section SUP 16 Annex 54G, which are the guidance notes for completion of the FIN073 return.
  • The amendments in question were part of Quarterly Consultation CP26/17. The return is now on an annual basis.
  • The changes came into force on 1 October 2026.
Link(s):  Operational resilience | FCA
operational-resilience-questionnaire.docx

Context

The FCA has published the questionnaire it uses to help firms assess their operational resilience.

Key points to note and next actions

  • The FCA’s work to ensure firms are operationally resilient continues and they have recently published the questionnaire they ask firms to complete when they make a Variation of Permission application.
  • It is a document that firms must complete and submit to the regulator where they may be applying for a Variation of Permission (VoP) or as part of a new authorisation.
  • Firms may find it useful to consider the question set and the responses they may provide, should the regulator approach them to ask about the steps they have taken to ensure they are resilient.
Link(s):  Frontier AI and the question of governance | Bank of England – the UK’s central bank

Context

Andrew Bailey, Governor of the Bank of England, has argued that the key challenge posed by frontier AI is ensuring society retains the ability to oversee, test and intervene in increasingly powerful systems. While highlighting AI’s potential to drive innovation and economic growth, he warned that governance and understanding should come before regulation.

Key points to note and next actions

  • Frontier AI can learn from its own outputs, creating self-reinforcing systems that may become harder to oversee.
  • Human intervention and the ability to set boundaries should remain central to AI governance.
  • Rigorous testing before and after deployment should be the starting point for managing AI risks.
  • The UK AI Security Institute is helping to develop standards and assurance mechanisms for AI.
  • AI could increase cyber threats and create new financial stability risks for banks, markets and payment systems.
  • The goal must be not to limit AI adoption, but to ensure increasingly capable systems remain subject to effective human governance.
Link(s):  The PRA held a captive insurance industry roundtable | Bank of England – the UK’s central bank
Minutes: CP11/26 Captives Industry Roundtable
CP11/26 – A tailored regime for captive insurance | Bank of England – the UK’s central bank

Context

The Prudential Regulation Authority (PRA) held a roundtable with the Financial Conduct Authority (FCA) and HM Treasury to discuss the proposal for a tailored UK regime for captive insurers, CP11/26.

Key points to note and next actions

Discussion centred on the proposed scope of the regime, authorisation processes, supervision, governance and capital requirements. The PRA reiterated its aim of authorising complete applications within four to six weeks, emphasised a proportionate supervisory approach, and confirmed that captive boards would remain accountable even where activities are outsourced. Participants were broadly supportive of the proposed capital framework, while the PRA confirmed that pension risks would remain outside the initial scope of the regime.

Also discussed was the potential future introduction of protected cell companies (PCCs), group captives and association captives. HM Treasury noted that PCCs would require legislative change before implementation and confirmed that no special tax incentives are currently planned, with captives expected to be taxed in the same way as other insurance undertakings.

For firms that wish to respond to the consultation on the proposed captive insurance regime, they must do so before the consultation closes on 14 October 2026.

Link(s):  Using software to file your company’s information – GOV.UK
Change the details of a UK establishment of an overseas company (OS CH01) – GOV.UK
Company authentication codes for online filing – GOV.UK
Overseas companies in the UK: registration and filing – GOV.UK
Filing your Companies House accounts – GOV.UK
Companies House fees – GOV.UK

Context

Companies House has updated a number of its web pages which may be relevant to firms.

Key points to note and next actions

Companies House has:

  • Outlined how firms can send information to them using commercial software,
  • Provided information on how a UK establishment of an overseas company can submit a return for any changes in details,
  • Outlined how firms can request and manage the company authentication code they will need to file information online at Companies House,
  • Provided guidance on the rules for filing accounts each year for UK registered companies; and
  • Issued guidance on all the fees Companies House charges and how those fees are determined.
Link(s):  D&O Insurance – why it can make the difference

Context

Edwin Coe has published an article for insolvency practitioners, on the position where a firm becomes insolvent, and not to overlook whether D&O cover is in place. The article suggests D&O cover should be considered as an asset.

Key points to note and next actions

  • Whilst the article is aimed at insolvency practitioners, it draws attention to any D&O cover which may be in place and how it could assist should the firm become insolvent.
  • For insurance intermediaries it offers useful background and insight when firms may be discussing this type of cover with clients. D&O cover offers protection and the article comments on the various reasons why it should be considered.
  • Intermediaries themselves could look to set up their own D&O cover to provide some protection in the event of insolvency.
Link(s):  2nd Special Report – Financial Inclusion Strategy
Financial Inclusion Strategy: Government response

Context

The Treasury Committee has warned that financial exclusion in the home contents insurance market may cause certain consumer harm and has called for action to ensure vulnerable households are not left without adequate protection.

Key points to note and next actions

The warning is part of the Committee’s response to the Government’s Financial Inclusion strategy, originally published in November 2025, which identifies insurance as a key area for improving financial inclusion, particularly those on lower incomes.

  • For households without savings to fall back on, losing essential possessions through fire, theft or flooding can create significant financial pressures.
  • The Committee’s report called on HM Treasury and the FCA to develop better inclusion measures, focusing on larger providers and markets where exclusion from insurance could cause particular harm.
  • In its September 2026 response, the Government agreed that monitoring outcomes where financial exclusion is prevalent is important, and the FCA noted that a number of factors needed to be considered to improve outcomes, such as considering the complexity of factors affecting exclusion, affordability, product availability and the risk profile of customers.
  • The Committee’s warning suggests that contents insurance should be firmly amongst those financial services markets where the consequences of exclusion require closer scrutiny and possibly stronger intervention to ensure the right outcomes are achieved.
Link(s):        OFSI General licence INT/2025/7363752 – GOV.UK
General trade licence: services necessary for the continued operation of the Shah Deniz project – GOV.UK
General Trade Licence: Services Necessary for the Continued Operation of the Shah Deniz Gas Field – GOV.UK

Context

OFSI has published two licences in connection with the Shah Deniz project.

Key points to note and next actions

The licences allow a person, or relevant UK institution, to undertake any necessary activity for the continued operation of the Shah Deniz Project, including the provision of goods, services, financing or other support, provided that –

  • No direct payment is made to the Naftiran Intertrade Company (NICO) or any other designated person
  • Any payments due to NICO are managed via an offset mechanism, special purpose vehicle, or other arrangement such that no funds or economic resources are made available directly to NICO.
Link(s):  IUA gives qualified welcome to Consumer Duty rule changes – IUA
CP26/23: Consumer Duty – scope and proportionality

Context

For several years the insurance industry has argued that the FCA’s rules should not apply to non-UK business and a proposal from the FCA to limit the international scope of the Consumer Duty regulations is seen as a positive development by the IUA.

Key points to note and next actions

The IUA said the reforms would enable insurers to apply local regulatory rules where products are distributed, rather than having to comply with both FCA and local requirements.

The IUA also welcomed FCA efforts to clarify how Consumer Duty should be applied proportionately. However, it expressed concern that insurers may not fully benefit from the reforms because equivalent changes have not been proposed for insurance-specific product governance rules. The association argues that firms such as brokers and managing general agents are often best placed to conduct fair value assessments, and that accountability should be allocated according to each party’s role in the distribution chain.

It further challenged FCA proposals to remove certain remuneration disclosure requirements, warning that reduced transparency could disadvantage customers and increase the risk of undisclosed commission or fee arrangements. The IUA has called for continued disclosure obligations to help ensure customer transparency and maintain confidence in insurance distribution practices.

Link(s):  Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway | National Cyber Security Centre

Context

The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway.

Key points to note and next actions

NCSC highlights a security bulletin published by Citrix, which details eight vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. Two of these, CVE-2026-88771 and CVE-2026-88772, have been confirmed as being actively exploited.  The NCSC is working to understand the impact of these vulnerabilities on UK organisations. The vulnerabilities identified are:

  • CVE-2026-88771: Improper input validation allowing an unauthenticated remote attacker to execute arbitrary commands.
  • CVE-2026-88772: Improper restriction of operations within the bounds of a memory buffer, leading to remote code execution or denial of service.
  • CVE-2026-88773: Inconsistent interpretation of HTTP requests (HTTP request/response smuggling), which may allow an attacker to manipulate or bypass security controls.
  • CVE-2026-88774: Improper HTTP URL-based expression usage leading to a feature policy bypass.
  • CVE-2026-88775: Memory overflow vulnerability that may result in unpredictable or erroneous behaviour, or denial of service.
  • CVE-2026-88776: Memory overflow vulnerability that may result in unpredictable or erroneous behaviour, or denial of service.
  • CVE-2026-88777: Memory overflow vulnerability that may result in unpredictable or erroneous behaviour, or denial of service.
  • CVE-2026-88778: Predictable exact value vulnerability that may allow an attacker to influence integrity or availability.

Organisations using Citrix NetScaler ADC or Citrix NetScaler Gateway are affected, with the following supported versions of customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway being affected by the vulnerabilities:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.23
  • Citrix NetScaler ADC FIPS before 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.279

The notice provides information and highlights actions to follow in order to mitigate vulnerabilities.