The Model Office Blog

Remote working and Governance, Risk and Compliance

[fa icon="calendar'] Oct 23, 2020 10:40:48 AM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting, resilience, cyberrisk

[fa icon="comment"] 0 Comments

Enforcing regulatory compliance can be enough of a challenge when your workforce is in the office. When they are dispersed, how can you be sure that your marketing and communications collateral adheres to FCA rules?

1. Have and communicate clear processes

The first step in managing compliance, whether locally or remotely, is to have clear processes that everyone understands. This means ensuring the compliance team are on the same understanding, systems and controls are managed tightly and SMF’s responsibilities are understood and aligned.  

2. Make sure everyone understands the relevant rules

Training and Competence is crucial here is everyone in your business aligned with the rules relevant to their roles? Are they up to date with their SPS and CPD requirements? With Senior Managers and Certification Regime ‘honeymoon period’ ending March ’21 and ESG, Vulnerable clients, Treating Customers Fairly, Know Your Customer, MiFID II, advice suitability to name a few are all highly relevant to showcasing professional practice, you need to evidence your team know the relevant rules and how they work in practice in their roles and responsibilities.

3. Improve collaboration even when youre not in the same place

Collaborating effectively on marketing projects improves efficiency, reduces unnecessary admin and duplication, and helps you stay aligned as a team and ensure consistency of compliance practice and client service.

4. Consider security

Remote workers are the weakest link when it comes to cyber-resilience. Cyber risk is one of the top business risks facing organisations. Despite this, the majority are not adequately prepared for a cyber incident. You will need to address key issues and employ Cyber strategy aligned to the FCA requirements.

Do you mandate the use of secure work emails? Are there rules about encryption of sensitive material? Are GDPR requirements met? All these issues are potentially exacerbated when teams are dispersed. Read our Cyber-crime blog here 

5. Review technology and automation help?

Our Remote working and FinTech handbook covers plenty of quality technology providers across a range of business strategies that can help during these challenging times. RegTech in particular will help ensure you have the evidence that you have addressed specific issues and have a holistic approach where all the relevant stakeholders are on the same understanding. Download Model Office’s RegTech infographics here.

Your compliance Joke:

'Why do people take an instant dislike to compliance officers? To save time later....'

If you're interested in finding out more you can book a demo of our software please click below to see MO® in action. 

Read More [fa icon="long-arrow-right"]

More Compliance Chat

[fa icon="calendar'] Sep 18, 2020 10:24:23 AM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting, resilience, cyberrisk

[fa icon="comment"] 0 Comments

Dear CEO, there you go that made you tremble didn't it? Well the FCA have been as active as ever this week and produced directives that are indicative of the direction in which UK regulation is likely to move forward over the next few years. (Your compliance joke's at the bottom of this blog)

Firstly we have the latest instalment in The FCA's gripping '5 Conduct Risks'series. seriously this is really good stuff and although focused on the banks, applies to all retail investment firms too. This is very important considering the need to ensure your Senior Managers and Certification Regime (SM&CR) certification process and staff conduct training is on track. 

The key messages are:

  • Despite significant improvement, there remains a lack of awareness, in-depth understanding and the ability to identify day-to-day conduct risks
  • Some firms have taken insufficient steps in ensuring the contribution of personal conduct and behaviour to achieve conduct objectives
  • Although most firms have clear escalation and whistleblowing channels, in practice they are largely unused and followed in only the most serious cases
  • Participants were often unclear on their firm's corporate purpose statements and how their role and responsibilities contribute

The Second issue is symbolic of the work done by regulators around digitisation, in both FinTech and RegTech. This will become even more of a priority for them in the changed world created by COVID-19, remote audits spring to mind.

The FCA's digital sandbox for example, goes form strength to strength and the latest pilotwill enable innovative firms to test and develop proofs of concept in a digital testing environment around three use cases related to coronavirus, including:

  • detecting and preventing fraud and scams
  • supporting the financial resilience of vulnerable consumers
  • improving access to finance for small and medium-sized enterprises.

The FCA Dear CEO letter to professional Insurance Intermediaries shows the FCA believes the general insurance sector carries significant risks of potential customer harm, with the most significant risk within the intermediary portfolio being that of customers purchasing unsuitable or poor-value products. This is attributed to inappropriate sales tactics and insufficient or unclear information at the point of sale.

The letter highlights the importance of robust governance and controls, and the need to embed healthy cultures and behaviours within firms. The FCA will focus on these themes and the letter sets out some of the key related issues, such as bonus and incentive arrangements.

Finally, but not least, the FCA are sending out yet another Financial resilience questionnaire to advice firms (they're clearly concerned) at Model Office-MO® we have made our Financial Resilience Diagnostic free of charge so firms gain heat mapped dashboards and assess the strengths of their firm’s financial ratios and cashflow. You can sign up and download it for free here.

Your compliance Joke:

“How many compliance officers does it take to change a light bulb?”

“Three. One to change it, one to check it and one to check it again and file a report.”

If you're interested in finding out more you can book a demo of our software please click below to see MO® in action. 

Read More [fa icon="long-arrow-right"]

Cyber-crime: an IT or Regulatory Challenge?

[fa icon="calendar'] Aug 13, 2020 3:27:34 PM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting, resilience, cyberrisk

[fa icon="comment"] 0 Comments

As we have seen with the COVID-19 pandemic, resilience is a key strategy and concern for the FCA. There are two key areas here: financial and operational resilience. What is often overlooked where operational resilience is concerned is Cyber-crime.

 

In their recent paper Cyber-security – industry insights, The FCA are clearly keen to ensure retail investment advice firms (RIAs) engage in good governance practice in this area.

The paper covers some important strategy that can easily be employed across:

 

  • Governance and risk management: Taking a top-down approach and using enterprise risk management approach to assess and monitor cyber-risks across the business operations, technologies, client service strategy
  • Keeping it simple: Move away from management speak and keep language and communications clear and concise
  • Cyber culture champions: appoint influential and experience staff members to take responsibility for addressing cyber-risk
  • Think strategically: Identify who can attack the business, where and how. Identify vulnerable data management practice and understand the extent of cyber-crime networks across the UK and internationally
  • Link risk and controls: Creating metrics and indicators for critical controls is imperative
  • Use existing standards. Standards provide valuable frameworks devised from good practice; consider the NIST Cybersecurity Framework, ISO27001/2, SANS CIS, NCSC’s 10 Steps to Cyber Security or NCSC’s NIS Directive Cyber Assessment Framework, Cyber Essentials

 

It is important to identify what you need to protect so here the FCA provide some simple yet effective techniques that can easily be applied:

 

  • Consider what you know: The GDPR provides great guidance on data security, so leverage this and re-assess your systems and controls plus identify what you don’t know and find solutions fast
  • Take a holistic approach: Too many businesses employ checklist and tick-box strategy which can create a silo approach, firms now need to think vertically and horizontally across all business activities this can then aid change management records, vulnerability scans, anti-virus management and other sources
  • Know who does what: Identifying roles and responsibilities is a key requirement of the Senior Managers and Certification Regime (SM&CR) so here we need to ensure that we know what staff are responsible for, map it out and also re-assess how personal data for staff and client’s alike is processed in line with the SM&CR and the ICO’s GDPR.
  • Watch out for outsourcing: Identifying and managing stakeholders can be difficult so again along with the SM&CR and GDPR, any outsourced suppliers need to be managed carefully particularly when it comes to processing personal data and related cyber-risks

 

So what can be done to ensure data is protected?

 

Effective cyber-risk strategy requires careful planning and use of the right tools and techniques:

  1. Invest in training: Ensure all staff are aware of cyber-risk on an ongoing basis. We conduct plenty of Anti-Money Laundering training, but as some of this activity has shifted online, there are no excuses as to ensuring cyber-crime is not a mandatory annual training standard within your business
  2. Be aware of vulnerabilities: knowing weaknesses and your digital footprint is essential to good research and due diligence in your cyber-risk strategy. Also understanding the digital reach of your business is essential
  3. Cyber-security integrated with change management strategies: Resilience is an essential compliance and business strategy, this can be undermined very quickly via a cyber-attack, so including cyber-security within change management strategy can build a resilient structure
  4. Employ detection tools: As with the GDPR, run a systems check and keep a register so you are able to detect any attempted attacks on systems and business services. This involves:
    1. Mapping roles and responsibilities (similar to SM&CR) and identifying those with privileged access to data e.g. data controllers plus monitor systems behaviour and apply the SM&CR Conduct rules to user behaviour
    2. Design logs to assess your firms data and generate relevant alert systems
    3. Apply string access controls to audit database logs to prevent cybercriminals removing any traces
  5. Respond and Recover: Be aware of emerging threats by participate in industry conferences, forums and learn from others. As with any resilience focus firms will need to:
    1. Test and retest scenarios and your defences
    2. Define business tolerance for recovery of systems
    3. Learn lessons from any failures
  6. Use Technology: identifying and applying technology can aid thwarting and a swift response to any cyber-attacks.
    1. Use encryption, this could involve e-mail encryption services such as Origo’s Unipass Mailock
    2. Back up regularly
    3. Update your services
    4. Create strong passwords
    5. Audit using RegTech systems so you are aware of where all the issues may lie prior to your manual audit process

With Cyber-crime on the up in this pandemic, if you apply strategy, tools and techniques we have discussed then you will ensure your business is cyber-resilient.  

Read More [fa icon="long-arrow-right"]

Remote working and managing compliance risk

[fa icon="calendar'] Aug 7, 2020 11:53:38 AM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting, resilience

[fa icon="comment"] 0 Comments

One of the biggest concerns the FCA are banging on about is business resilience through the pandemic we face. It is clear that the regulator expects firms to take full accountability for their own governance, risk and compliance (GRC) affairs and align this with building systems and controls that will identify monitor, manage operational and financial resilience.

 

The pandemic has now brought a new way of working and with it the application of existing and new technologies that can streamline business management practices. With remote working the new norm, we also have challenges in ensuring our staff are aligned, engaged and also are happy, mental health is also a concern when we have to isolate and remove ourselves from the social interaction a workplace brings.

 

Enforcing regulatory compliance can be challenging enough when your workforce is in the office, but when dispersed this is a huge challenge.

 

So what can we do to ensure we keep our finger on the GRC pulse, encourage a resilient and positive working practice and culture?

 

  1. Communicate, communicate, communicate: Employing clear processes, systems and controls that engages all stakeholders is essential. This means everyone knows the risks and challenges faced but most importantly, how they are managed and the part they and others play. The Senior Managers and Certification Regime (SM&CR) is a huge help here, firms should already have their roles, responsibilities and delegation strategy mapped so everyone knows who does what, when and how
  2. The art of collaboration: The has never been a more important time to ensure your C-suite, compliance, operations, teams are working together around GRC. By streamlining working practices around remote working challenges and opportunities, this can enable effective and efficient identification of risks that can impact business resilience. We can also reduce admin and duplication and get the messages we need across quicker to staff and clients alike.
  3. Be security minded: Cyber-risks are on the up during the pandemic, so we have to ensure that operational systems and controls are in place to protect our business practices across, client communications, asset and document management and data security. Remote workers could be the ‘weakest link’ here, as they are working with new systems and technologies, so mandating specific cyber-risk proofed platforms such as back office, e-mail encryption and document protection will be crucial.
  4. Get onboard the same train: All staff need to be of the same understanding when it comes to compliance, resilience and risk management. So ensure you’re up-to-date with your training and competence programme, again the SM&CR and conduct rules training will help here
  5. Automate and streamline: Technology isn’t magic, but built and implemented well it’s a great enabler platform for your business to work more effectively around GRC, keeping staff engaged and happy and your business resilient across constant operational and financial risks.
Read More [fa icon="long-arrow-right"]

The FCA and Your Financial Resilience

[fa icon="calendar'] Jul 31, 2020 10:30:17 AM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting, resilience

[fa icon="comment"] 0 Comments

The FCA’s Final Guidance assessing adequate financial resources places a specific spotlight on retail investment adviser firm’s (RIA’s) financial resilience. The minimum standards the regulator uses to protect consumers, reduce market disruption and minimise harm and assess firm’s sustainability are called threshold conditions.   

 

Threshold conditions and Financial resilience

The assessment of appropriate resources under threshold conditions considers:

  • the nature and scale of a firm’s business model
  • the risks to the continuity of the services provided
  • the impact of other members of the firm's group on the adequacy of its resources
  • To assess if a firm has adequate financial resources, we consider if a firm:
  • has the ability to meet its debts when they fall due
  • For firms, other than those with limited consumer credit permissions, we also consider if a firm has:
  • taken reasonable steps to identify and measure its risks
  • appropriate systems and controls and human resources to measure risks prudently at all times
  • access to adequate capital to support the business, and that client money and custody assets are
  • not placed at risk
  • resources which are commensurate with the likely risks it faces

With a pandemic to manage through, the FCA are obviously concerned at firm’s who sit outside formal prudential standards for adequate financial resources, for instance Internal Capital Adequacy Assessment Process (ICAAP) requires banks boards to regularly assess and mitigate risks and ensure adequate financial capital is retained to manage these risks.

 

So, we now have a framework that requires RIAs to implement and evidence Governance, Risk and Compliance (GRC) strategy to assess and manage across:

 

Systems, controls, governance and culture:  Here the FCA are interested in conduct i.e. behaviours that drive good outcomes across the firm’s purpose, competent leadership, staff competence and incentives. Plus, employ sound risk management across systems and controls such as whistle blowing or complaints handling. What drives all this is individuals accountability and responsibility, something RIAs should have addressed under the Senior Managers and Certification Regime (SM&CR)

 

RIAs are also now expected to employ a system to identify, monitor and manage risks and employ a quantified risk appetite strategy which is communicated, understood and followed across the firm. Policy and procedures are then required to ensure the risk function is resourced, has appropriate controls, manage conflict of interests and outsourcing risks.

 

Identify and assess the impact of harm: Here RIAs should place a specific focus on conduct and competence, ensuring the right people are in the right place with the right skills and responsibilities. Firm’s need to ensure they can compensate consumers for losses and thus the issue of the Financial Services Compensation Scheme (FSCS) and ability to fund applies here. It’s worth noting that the majority of payments made by the FSCS is against solo regulated firms are those firms not subject to detailed prudential standards discussed above.

 

Continuity of service is also a key area and thus RIAs need to evidence investment in people, processes, systems and controls. Advice suitability is front and centre here, particularly around pension transfers for example.

 

Monitor and manage the potential depletion of financial resources: As I have written extensively on the need for RIAs to balance their charging strategy and move away from the industry wide reliance on ad-valorem charging to client paid fees, the issues we have witnessed during adverse market conditions such as the financial crises and current Covid19 means that there is a risk of depletion of income that can adversely affect the firm’s financial stability. Firm’s need to keep clients close, box clever and shift a percentage of fees to direct charging. This can stabilise cashflow in the short and long term.

 

Business model strategy and sustainability: Whenever I speak at public events, I tend to ask the question how many firms have a bonafide 10-year busines plan. Very few put their hands up! Just as it is so important for clients to have a long-term financial plan, RIAs need to employ a strategic plan that can ensure strengths, weaknesses, opportunities and threats are covered, stress testing is in place and all staff are aligned to this company strategy. This will ensure the FCA have confidence is RIA ability to manage financial resilience across the business and their client needs.  

 

Wind down planning:  Preparing for worst case scenarios is crucial, after all, it is those adviser firms who ensure their clients have adequate life insurance who are providing a holistic service, so RIAs also need to ensure that their business strategy incorporates their own demise if this is an unavoidable outcome of the pandemic.

 

How can firms deal with all this?

 

We need to avoid overwhelm and ensure firms continue to conduct the good work they are doing, so here we would argue that risk diagnostic assessments can help to ensure GRC strategy incorporating operation and financial resilience activities.

 

So, employing technology is a good start, this can ensure RIA’s gain specific management information and data to ensure their business resilience strategies are aligned to their rules and also to their clients and stakeholder needs. At Model Office for example, we have made our Financial Resilience Diagnostic free of charge so firms gain heat mapped dashboards and assess the strengths of their firm’s financial ratios and cashflow. You can sign up and download it for free here.

 

We have also developed an Action Tracker, Compliance Diary system that allows firms to automate audit actions and provides alerts to ensure stuff gets done and identify, manage and monitor risks.

Read More [fa icon="long-arrow-right"]

Appropriate Advice, Culture, Competence and Conduct

[fa icon="calendar'] Jul 10, 2020 10:30:41 AM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting

[fa icon="comment"] 0 Comments

  1. Examine your firm’s culture. At Model Office we benchmark your firm’s culture, conduct and competence against the rules and your peers so you know that you are meeting the FCA’s standards on suitability which essentially is all about culture. And although a recent piece of research from the regulator suggests that measuring your corporate culture may not be the magic solution many businesses hope for, implementing actions that move you towards a more compliant culture can only have positive effects.
  2. Part of this cultural overhaul may involve making compliance procedures more central to your processes. This might mean giving everyone accountability for compliance.
  3. Encourage greater collaboration between Marketing and Compliance. Often, people are tempted to shortcut the correct processes due to a desire to speed materials to market or avoid labour-intensive manual edits. Closer working between your Compliance team and Marketing – or other – teams producing promotional materials can help to create a clearer understanding of what’s acceptable and will be approved without the need for time-consuming revisions.
  4. Re-familiarise yourself with the FCA’s 6 consumer outcomes – many of which centre around suitability and fairness. Work towards meeting these and more suitable advice should be a natural result.
  5. Ensure your marketing and communications materials are a fair and accurate reflection of your products. For regulated firms, robust and consistent Compliance team reviews are central to this. 
    Mandating approvals before financial promotions are published will reduce the changes of non-compliant materials reaching the market. 
    Some firms have found that introducing an element of 
    automation can help here, making the Compliance approval process non-negotiable as well as simpler, faster and more robust.
  6. Keep control of your financial promotions. Sign-off is essential, but when it comes to having rigour around your marketing activity, it’s not the whole story. If a ‘rogue’ advert or promotion is issued by mistake, are your processes geared up to respond?

Please click the below icon link to MO®'s #RegTech platform and learn more about MO® today..

Read More [fa icon="long-arrow-right"]

The FCA's focus for the remainder of 2020

[fa icon="calendar'] Jun 26, 2020 9:50:31 AM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting

[fa icon="comment"] 0 Comments

In their latest 2020/21 business plan the FCA outlines 5 key areas of concern and risk:

Read More [fa icon="long-arrow-right"]

RegTech, Karate, Resilience, Persistence and Patience

[fa icon="calendar'] May 29, 2020 9:55:13 AM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting, karate

[fa icon="comment"] 0 Comments

Maybe one for Facebook, our founder and director Chris Davies said, but achieving Shodan first degree blackbelt last weekend with his local karate club Tiska St Albans is testament to the ‘two P’s’ we apply to our business; persistence and patience.

Read More [fa icon="long-arrow-right"]

Model Office, RegTech and The Endowment Effect

[fa icon="calendar'] Jan 28, 2020 11:13:49 AM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting, HRD, Endowment-theory

[fa icon="comment"] 0 Comments

If we worked together in the same office and I offered to make  you a cup of coffee and presented you your own cup you have brought in from home or a clean office cup, which one would you choose? It’s pretty obvious you would choose your own cup, why? Because you own it off course, it’s yours! But it's just a coffee cup..

Read More [fa icon="long-arrow-right"]

Dear CEO

[fa icon="calendar'] Jan 22, 2020 2:46:41 PM / by Chris Davies posted in Financial regulation, Financial business development, fintech, regtech, Risk management, practice management, FCA, advice, HMT, suitability, FAWG, FAMR, MiFIDII, SMCR, Data, GDPR, Chatbot, Culture, Enforcement, supervision, audit, Conduct, AI, Risk,, Accountability, Platforms, PROD, Product governance, digital,, Regulatory, Reporting, HRD, PII

[fa icon="comment"] 0 Comments

So, the FCA start the new decade with a bang by writing to all Retail Investment Adviser firms with their latest directives surrounding regulatory concerns and risks…

Read More [fa icon="long-arrow-right"]

Subscribe to Email Updates

Recent Posts