Quentin CasaresData and AI leadership for regulated growth
Insights

2026-10-09 / 8 min

Management information now needs an audit trail

On 27 July 2026 the FCA published its review of Consumer Duty outcomes monitoring, drawn from a survey of 56 firms. Its finding is that holding management information is not evidence of good outcomes, and thresholds nobody can justify prove nothing.

In brief: on 27 July 2026 the Financial Conduct Authority published its review of how firms monitor consumer outcomes under the Consumer Duty, drawn from board reports, information request responses and a survey of 56 firms across every sector the Duty reaches. The repeated failure is not missing data but unexplained data: thresholds set at levels firms could not justify, management information nobody could trace to a decision, and remedies that were never tested to see whether they worked. The regulator now expects a clear audit trail from issue to action to outcome, which turns outcomes monitoring from a reporting pack into a data product with an owner.

A supervisor who asks what your management information changed is asking a data governance question wearing conduct clothing.

That is the shape of the FCA's 27 July 2026 review of outcomes monitoring. It introduces no new rules and sets no deadline, which is precisely why it deserves attention: it is a statement of what the next supervisory conversation will test. The review covers three areas, and only one of them is about data in the narrow sense. Strategy and framework asks whether a firm has defined what a good outcome is, by product and by journey stage. Data, management information and testing asks whether the firm can show that its indicators led anywhere. Governance, oversight and culture asks whether the board did anything with what it was shown.

Firms have spent three years building the second of those and comparatively little time on the first and third. The review reads as the bill arriving.

The finding is about explanation, not volume

The FCA's position is stated plainly enough to quote: a new tool or checklist, by itself, does not necessarily show that customer outcomes have improved. Several of the weaknesses it describes are familiar to anyone who has tried to evidence a regulatory submission from an estate that was never designed to produce one.

What the FCA foundThe underlying control gapWhat closes it
Many firms set thresholds without explaining how they indicated good or poor outcomes, and one could not consistently explain what its thresholds were based onThe threshold was inherited from a dashboard default or a vendor template, so no one owns the numberA documented basis for each threshold, set from the firm's own historic performance or a published benchmark, reviewed at least annually through governance
Firms collected management information but could not show how it led to decisions, challenge or improved outcomesReporting and decision records sit in different systems and are never reconciledAn audit trail from issue to action to outcome, recorded as the metric is produced rather than reconstructed for a review
Data inconsistencies or gaps limited firms' ability to evidence outcomesCustomer, product and complaint data were integrated for operations, not for measurementCritical Data Elements identified against each defined outcome, with lineage to source and a quality threshold that triggers action
Reliance on narrow, reactive and often lagging indicators, with few forward-looking measuresThe firm measures what its systems already emitIndicators chosen from the harm being monitored, with the data requirement derived afterwards
Vulnerability management information aggregated rather than split by driver such as health, financial resilience or life eventsVulnerability is held as a single flag because that is how it was first capturedSegmentation by driver, so differing outcomes between groups are visible rather than averaged away
Firms did not test whether remedies workedRemediation closes on delivery of the fix, not on movement in the measureA defined post-intervention measure, such as repeat contact or unresolved journeys, checked before the issue is closed

Read the middle column as the real finding. Each one is an ordinary data architecture decision taken years before the Duty existed, now being examined as a conduct control.

This is the third year of the same message

The pattern matters more than any single publication. The FCA has now said a version of this four times, and the language has tightened each time.

PublicationDateWhat it said about data
Review of first annual Consumer Duty board reports, covering 180 firms11 December 2024Some firms did not have sufficient data quality to justify their conclusions, and thresholds often lacked well-reasoned justifications
Year 2 board reports blog, Head of Consumer Policy16 April 2026A wider mix of quantitative and qualitative data, but some reports presented large volumes of it without explaining what it showed; boards should push beyond dashboards, and many did not document the challenge they gave
Products and services review, a qualitative survey of 38 firms10 July 2026The main gap is supply chain information sharing: some firms could explain their distributor due diligence but not how they knew those channels suited the target market
Outcomes monitoring review, covering 56 firms27 July 2026Management information exists; the audit trail from issue to action to outcome does not

A firm that has answered the same observation three times without changing its data model is not being slow. It is making a choice, and the choice is now documented in four places.

What the stronger firms did differently

The good practice examples are worth reading because they are small and specific rather than programmatic. One firm tested its rejected applicant data against its stated target market and ended two paid affiliate relationships when it found the applicants were unsuitable. Another used a financial vulnerability indicator and reviewed flagged customers individually rather than in aggregate. A smaller firm ran a management information tracker with defined triggers, such as complaint levels and missed vulnerability flags, that prompted escalation without waiting for a cycle. One firm improved its transaction categorisation and reported a 12.8 per cent uplift in accuracy, which is the least glamorous item in the review and the one that makes every downstream measure more defensible.

Two firms used AI inside the control rather than around it: one tested an AI tool for comprehension risk against its own human testing and reported a high average match rate, and another cut average first response times from 22 hours to under two minutes through in-app chat and routing. The FCA's framing is useful here. It suggests smaller firms could use AI as an added challenge to their own testing, with human oversight, which is a narrower and more defensible use case than most AI governance intakes receive.

Proportionality is explicit. Smaller firms may run a focused set of indicators provided they can show how those indicators identify and address customer harm. The test is the explanation, not the instrument count.

The distribution chain is the next data boundary

The outcomes question does not stop at a firm's own perimeter, and the rules on where it does stop are about to move. CP26/23 opened on 29 June 2026, closed on 18 September 2026, and the FCA expects a policy statement and any final rules in the first quarter of 2027. It proposes removing business with non-UK customers from the Duty's scope and clarifying when firms can reasonably rely on one another in a distribution chain, applying the Duty more proportionately according to a firm's role.

That is welcome relief on scope and a sharpening of the data question. If reliance between firms becomes clearer, the information passed along the chain becomes the control. The products and services review already states the boundary: firms are only responsible for ensuring compliance in respect of their own role and activities. A manufacturer that cannot evidence what target market and product characteristic data it sent, or what complaint and outcome data came back, has no defence that rests on reliance. The FCA and the ICO have published a joint statement on sharing vulnerability-related data across distribution chains, which removes the usual objection that data protection prevents it.

Under SM&CR this all resolves to a named person. Someone's statement of responsibilities already covers the annual board assessment, and the review's clear suggestion is that outcomes should reach the board through the year rather than once in it.

Five questions before the next board meeting

  1. For each outcome we claim to monitor, can we state what the threshold is based on, when it was last reviewed, and who approved it?
  2. Pick one issue from the last twelve months: can we produce the trail from the indicator that surfaced it, to the decision taken, to the measure that moved afterwards, without rebuilding it by hand?
  3. Which of our outcome measures are forward-looking, and which only tell us about harm that has already happened?
  4. Is our vulnerability data held as a single flag, or segmented by driver so we can see whether a group is being served worse than the average?
  5. For every product we manufacture or distribute, can we evidence the data we sent down the chain and the data we received back?

The regulator has stopped asking whether firms have the numbers and started asking what the numbers changed, and that is a question only an owned data product can answer.

Sources

Related service: Advisory

Executive Data Briefing

A low-volume note for data and AI decisions with consequence.

Consent-based and double opt-in. Governance patterns, board-level data trust, and decision infrastructure - not generic AI commentary.