Welcome to the UKGI weekly regulation update service for Aviva ABC brokers
We hope you find the Updates useful. If you are
interested in subscribing to our affordable
ABC compliance support package, please
email us at ABC@ukgigroup.com or
call UKGI on our dedicated ABC
contact line 01925 765777.
UKGI has teamed up with Aviva to provide ABC brokers with access to our weekly regulation update free of charge! The service provides a round-up of compliance-related issues to give you an overview of what’s on the regulatory horizon.
This will help you stay up to date with what regulatory changes may be coming up, so you can plan ahead.
You can also access previous ABC weekly regulation updates by clicking on the archive tab at the top of the page.
UKGI is working with Aviva to provide ABC brokers with access at preferential rates to our market-leading, online compliance manual and its library of over 200 template documents!
To watch a short introductory video showcasing the manual, click here, and to see for yourself just how useful the manual could be for your business, book an interactive demonstration.
| Link(s): | Outcomes monitoring: why understanding the consumer experience matters and where firms should focus… |
Context
The FCA’s Director of cross-cutting policy and strategy, Charlotte Clark explains what good practice looks like for outcomes monitoring under the Consumer Duty. The article explains that outcomes monitoring is central to the Consumer Duty, because it helps firms understand customers’ experiences, identify potential harm, and take action to improve outcomes.
Key points to note and next actions
- Strong firms use structured, evidence-based monitoring frameworks linked to the customer journey.
- Effective monitoring is not just about collecting data; firms should use information to identify risks, review performance, and drive improvements.
- Good practice includes defining what good outcomes look like, using measurable indicators, and showing a clear link between data, decisions, and actions.
- Some firms need to improve by making monitoring more proactive, outcomes-focused, and better evidenced.
- Firms should use management information to spot emerging harm, test interventions, and explain why metrics and tolerances were chosen.
- Third-party and distribution-chain oversight is important because customers experience products and services as a whole.
- Boards and senior leaders should show clear evidence of challenge, scrutiny, accountability, and decision-making.
- The strongest firms focus on what changed for customers, not just what activity was monitored.
In summary, firms should not simply monitor activity; they should use outcomes monitoring to identify harm early, take effective action, and prove that customer outcomes have improved.
| Link(s): | Strengthening resilience across an increasingly interconnected financial system | FCA Critical Third Parties: Strengthening UK Financial Services | FCA |
Context
In an article written by the FCA director of specialists Mark Francis and Simon Dixon, director of supervisory risk specialists at the Prudential Regulation Authority (PRA), it
highlights that as firms increasingly rely on common third-party service providers, delivering operational resilience is no longer just about your own individual organisation. It’s about strengthening resilience across the wider network that supports the UK financial system. It explains the UK’s new Critical Third Parties (CTP)oversight regime is designed to strengthen the operational resilience of financial services by directly overseeing key technology, data and service providers that many firms depend on.
Key points to note and next actions
- Financial services increasingly rely on a small number of common third-party providers, such as cloud, technology and data firms.
- Disruption at one provider can affect many firms and consumers at the same time, as shown by incidents like the CrowdStrike outage and major cyber disruptions.
- The Bank of England, PRA and FCA will jointly oversee designated CTPs to manage system-level risks and improve coordination during incidents.
- The regime does not replace firms’ own responsibility for managing resilience or outsourcing risks.
- CTPs will be expected to identify risks, test resilience, share information and engage openly with regulators and firms.
- The overall aim is to make critical financial services more resilient, reduce the spread of disruption and support confidence, innovation and growth in the UK financial system.
Context
The FCA has launched a national advertising campaign to remind millions of car finance customers, who may be owed compensation, they can get help making a complaint for free.
Key points to note and next actions
- Research by the FCA found that 27% of car finance customers lack confidence to make a complaint without using a claims management company (CMC) or law firm, despite free tools from the FCA being available.
- 59% of car finance customers have made or are considering a claim but a significant group (23%) say they are unsure of their options.
- Sheree Howard, executive director at the FCA, said: “Many people who may be owed compensation aren’t sure where to start or don’t realise they don’t have to pay someone to make a complaint. Our free tools are there to help people feel claim confident – so they can get any money owed back without it costing them a penny.”
- The campaign – running across TV, radio, print, billboards and social media until 6 September – directs people to a free template complaint letter on the FCA website. More than 80% of those surveyed said this would make them more confident about complaining directly to their lender.
Context
The FCA has decided to make an order prohibiting Dharmendra Devji Solanki (“Mr Solanki”) from performing any function in relation to any regulated activity carried on by an authorised person, exempt person or exempt professional firm, pursuant to section 56 of the Act.
Key points to note and next actions
- Mr Solanki was previously approved to act as an SMF17 Money Laundering Reporting Officer at several authorised firms until July 2022. In October 2023, he pleaded guilty to carrying on regulated activity without authorisation and to money laundering, offences committed while he was an approved person.
- He was later sentenced to a suspended prison term, community work and unpaid work, and was ordered to pay £169,941.89 following a confiscation hearing.
- The FCA considered that these offences show a serious lack of integrity and that Mr Solanki is not fit and proper to perform regulated activities, so it proposed a prohibition order to protect consumers and maintain confidence in the UK financial system
Context
The FCA has commissioned independent research exploring how UK financial services hubs relate to regional growth, productivity and SME access to finance. Two independent research papers examine how financial services hubs contribute to UK economic growth, including whether regional hubs deliver distinct benefits compared with London, and how financial activity affects firm performance, access to capital, and productivity.
Key points to note and next actions
- Financial services are linked to higher productivity, incomes and regional growth, but the benefits are uneven and concentrated around major centres like London.
- The distribution and type of financial activity appear to matter more than the overall size of the financial sector. Growth outcomes seem to depend on where finance is available and which financial services are accessible to firms and regions.
- Access to finance for SMEs appears especially important, while geography, networks and centralised decision-making still shape financial outcomes despite digitalisation.
- These patterns may contribute to regional differences in economic performance in the UK, although the relationship between finance and growth is complex and not causally identified.
The FCA notes the following themes as relevant to its objectives and will consider them alongside other evidence:
- access to finance and market functioning in SME lending, including the role of market structure, information and potential intermediation frictions, and
- whether a more explicit spatial lens may be useful in market analysis.
- It also stresses that the findings are indicative rather than causal, have methodological limitations, and should not be treated as FCA endorsement of the authors’ conclusions or policy recommendations.
| Link(s): | HM Treasury and Financial Conduct Authority Regulatory Perimeter Meeting – April 2026 – GOV.UK |
Context
The Financial Conduct Authority (FCA) regularly updates its Perimeter Report setting out its views on the financial services regulatory perimeter, which defines the financial services activities that require firms to be authorised by the FCA. On 30 April 2026 the Economic Secretary to the Treasury (EST), Lucy Rigby, and the Chief Executive (CEO) of the FCA, Nikhil Rathi, met to discuss the March 2026 update to the FCA’s Perimeter Report.
Key points to note and next actions
The CEO discussed Deferred Payment Credit (Buy Now Pay Later), which will be under FCA oversight on 15 July 2026, and thanked the EST for the Government’s support with this. The CEO also raised the following areas for consideration:
- Artificial Intelligence (AI): The CEO raised the impact of fast-paced technological change and AI adoption, noting the importance of responding to these issues quickly and the benefits of an outcomes-based approach to regulation, which provides greater flexibility. The EST agreed that the Treasury and FCA should work together to understand the impact of AI on the regulatory perimeter.
- Prediction Markets: The CEO noted the points raised within the report about prediction market products (PMPs) and explained the FCA’s view is currently that they only provide binary options and therefore remain subject to the FCA’s permanent ban on the sale of binary options to retail consumers. Following the FCA’s Discussion Paper on Consumer Access to Investments, it is considering if further work is required on access to these products and/ or clarifying the perimeter.
- Investment Consultants: The CEO noted the recommendation in the perimeter report that these activities be brought into the perimeter.
- Senior Managers & Certification Regime: The CEO raised that not all types of firms are subject to the Senior Managers & Certification Regime (SM&CR) and suggested that the government should consider extending it to other types of firms.
- Financial Influencers: The CEO raised the issue of fraudulent online ‘finfluencers’ (financial influencers) and highlighted that the FCA is taking action where it can, but the FCA cannot force social media platforms to remove content under current legislation. The CEO also suggested the Government could go further to allow information sharing between different regulators. The EST agreed that this is an important issue to consider.
Context
The ABI has issued Travel insurance advice for wildfires in France and Spain. As they continue to spread, the ABI is urging holidaymakers to pay close attention to local advice and updates from the Foreign, Commonwealth and Development Office (FCDO), as travelling against this is likely to invalidate your insurance, and to check travel insurance policies. Insurers are ready to support customers and as the fire continues to spread the ABI is sharing travel insurance advice.
Key points to note and next actions
- If you’re being forced to leave your accommodation, it’s vital you follow the advice of emergency services and any local health advice.
- If your travel insurance policy includes trip disruption or natural disaster cover, you should be covered if you have to cut short or cancel your holiday.
- Your travel insurance will apply in the usual way if you need emergency medical treatment.
- If you have lost or had to abandon your possessions, these will likely be covered by standard travel insurance policies.
- Policies can vary, so speak to your insurer and they can advise on available support.
- Refunds for cancelled flights or accommodation should be sought from the airline, tour operator or accommodation provider in the first instance. Any bookings made through a credit card may also have recoverable costs.
- If you want to book another flight back to the UK or need alternative accommodation, speak to your insurer first to check what is covered and they can advise on next steps.
- If you’ve not yet set off on holiday, contact your insurer before you decide to cancel flights or book any new accommodation. They can advise on what your policy covers.
Context
Search warrants have been executed across the UK as the ICO cracks down on suspected nuisance marketing linked to car finance mis-selling claims as part of the joint regulatory taskforce.
The searches have been carried out across Bolton, Burnley, Liverpool, London and Swansea in a new action from joint regulatory taskforce with FCA, ASA and SRA, which follows 12 million complaints being made about car finance nuisance marketing.
Key points to note and next actions
More than 12 million complaints about nuisance marketing text messages have been submitted by the public since September 2025, with up to 100,000 received per day.
The warrants, carried out on Wednesday 29 July, targeted a mix of residential and business premises linked to five companies across Bolton, Burnley, Liverpool, London and Swansea. The companies are subject to ongoing investigations and are believed to be responsible for sending a combined 170 million text messages to members of the public between September 2025 and May 2026.
Andy Curry, Head of Investigations at the ICO, said “People are fed up with being bombarded by unwanted calls, texts and emails about car finance claims, and we’re taking action. This week’s searches send a clear message to the claims management sector: comply with the law or expect to hear from us. We are working closely with our taskforce partners to make sure people are properly informed and protected and we will not hesitate to take further action where we find evidence of wrongdoing.”
The ICO is urging all companies operating in the claims management sector, including lead generators and law firms responsible for instigating direct marketing, to ensure they are complying with the Privacy and Electronic Communications Regulations (PECR).
For guidance, refer to the ICO website. Guidance includes a Direct Marketing Advice Generator to help organisations understand their obligations.
The data protection regulator has the power to apply to court for a warrant to search premises as part of investigations under PECR, where evidence may be seized such as mobile phones, laptops or even sim farms.
Context
William Malcolm, the ICO’s Executive Director Regulatory Risk and Innovation, has published a blog discussing the ICO’s Regulatory Sandbox and how it is evolving to meet the challenges and demands of new technology, including AI.
Key points to note and next actions
- For more than eight years the ICO’s Regulatory Sandbox has been a place for organisations to test new ideas, explore data protection risks and build privacy into new products and services by design.
- Sandboxes have proved an important part of the regulatory toolkit for responding to fast moving technology deployment and deployment cycles, but more can be done to ensure that these regulatory tools are meeting the moment.
- The ICO is committed to ensuring that its investment in innovation services and regulatory sandboxes has the largest possible impact.
- It is one of four regulators supporting government’s new Advisory AI Growth Lab (AIGL) for legal services and it is working closely with the FCA, helping firms develop, test and evaluate AI through the FCA’s AI Lab. It has also been involved in piloting an AI and digital hub, which is a multi-agency service for projects that need advice from all four regulators: the CMA, FCA, Ofcom and ICO.
- Here is a snapshot of the findings from the ‘ICO Statutory Regulatory Sandbox: final report’:
- A data protection SRS is feasible but government and the ICO would need to address important challenges, including protecting the ICO’s independence and ensuring that individual rights are transparently protected through alternative but equivalent accountability and governance mechanisms;Public trust must be at the heart of the SRS with innovations delivering clear public benefit. People are willing to see new and novel data use in cases that deliver better services and outcomes for everyone; and
- Demand for an SRS is niche, but the potential impact is significant if we can unlock key economic opportunities and societal benefits faster.
- The ICO is committed to improving its existing sandbox offering to make it run faster, with clearer outputs and conclusions for those who participate. However, it is urging organisations to commit to bringing the hard problems and to accept that co-creation is also about accepting limits on tech deployment where privacy, safety and individual rights are at play.
- Any SRS would require changes to data protection legislation, so it will be for government to decide next steps.
Context
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign.
Key points to note and next actions
- Russian state-supported actors have developed a new technique to target Western email platforms and gain persistent access to compromised networks. They have targeted Western organisations with a malicious campaign which uses a zero-click exploit coined “beehive” (or “Ulej”) to steal emails, the UK has warned.
- The NCSC, alongside cyber security agencies in 15 countries, has exposed activities of LAUNDRY BEAR, an advanced persistent threat group who specialise in the covert acquisition of email data. Since July 2025, LAUNDRY BEAR has successfully targeted and stolen sensitive email information from organisations using Zimbra Collaboration Suite (ZCS) software.
- In a joint advisory, the NCSC and partners warn LAUNDRY BEAR’s ongoing campaign is indicative of espionage and almost certainly carried out with Russian state support. Unlike traditional phishing campaigns, “beehive” allows the threat actors to gain extensive and sustained access to emails without a user’s input. Instead of clicking a link or opening a file, the user only has to view a malicious email within a vulnerable version of the ZCS webmail service to be compromised.
- Organisations that use ZCS are urged to follow the mitigation advice, including to immediately patch vulnerabilities and improve network monitoring capabilities.
Context
New guidance provides a framework for response and recovery when cyber attacks happen. As technology evolves and cyber threats continue to grow in scale and sophistication, more organisations are having to prepare for the possibility of serious disruption.
Key points to note and next actions
- The NCSC’s new response and recovery guidance guides you through a highly disruptive cyber incident. It shows that organisations can and do recover from even the most severe attacks and provides a framework to understand what has happened, deal with the impacts, and move forward to full recovery. The guidance is split into 3 sections, to enable focus on the key aspects for the challenges faced as recovery proceeds:
- The first hours matter: as you’re working out what’s happened, what the impact is and trying to coordinate your actions. It emphasises the importance of swift defensive actions, establishing governance and getting control of communications.
- Building your recovery programme: The second stage is focused on building and implementing your recovery programme. This is key to getting your organisation back up and running, to minimum viable operations (MVO)
- Beyond recovery: Rebuilding stronger. This is a distinct shift from the recovery stage and focuses on getting the organisation back to business as usual or stronger than before. It includes ensuring the issues that contributed to the incident occurring in the first place are addressed and taking the opportunity to rebuild in a more secure and resilient way.
It is best to prepare and practice for these types of incident in advance. Organisations that act early are often better placed to respond effectively, maintain critical operations and recover more quickly. The guidance will help develop plans and test response arrangements before an incident occurs.
