BlogAnalysis~14 min read

The FCA's 2024 AR Oversight Review: What Principal Firms Got Wrong, and What to Do About It

The FCA surveyed 251 principal firms in 2024 and rated only 43% of their annual reviews good quality. What it found, what it will test next, and what to do about it in the next ninety days.

In October 2024, the FCA published the findings of its first major review of how principal firms are handling their enhanced appointed representative oversight obligations. The regulator surveyed 251 principals and did deep-dive assessments on 23 of them.

The findings were not flattering. Most principals thought they were doing fine. The FCA largely disagreed.

If you run a principal firm, the review is required reading. Not because it introduces new rules, it does not, but because it is the clearest account the FCA has given of what it considers good oversight. It tells you what a supervisor will test on a visit, what attracts enforcement attention, and what will quietly get your principal permission looked at again once the new permissions regime arrives.

What follows is what the regulator found, what it means for principals now, and what to do about it, whether your oversight lives in spreadsheets or in software.

Table of contents

  1. Why the FCA ran this review
  2. The five headline findings
  3. Self-assessments, and the 48% that fell short
  4. Annual reviews, and the 43% that passed
  5. Onboarding and the over-automation problem
  6. Monitoring, where a third used no data at all
  7. Termination, the part everyone forgets
  8. What this means for 2026 and the principal permissions regime
  9. A practical action checklist for principals
  10. How Merrin addresses what the FCA found
  11. Further reading

1. Why the FCA ran this review

The enhanced AR regime took effect in December 2022 after years of concerns about consumer harm in AR networks. The FCA had data showing consumers engaging with ARs experienced worse outcomes than those dealing directly with authorised firms. Some of the enforcement cases that led to the reforms were serious.

The 2022 rules introduced three significant obligations for principals:

  • An annual self-assessment of the principal's own oversight arrangements, documented and signed off by the governing body
  • An annual review of each AR, covering fit and propriety of senior management, financial position, and adequacy of controls
  • Enhanced onboarding, monitoring, and termination obligations under SUP 12

Two years on, the FCA wanted to know whether firms were actually doing any of it properly. It surveyed 251 principals and then went through 23 of them in detail. The findings were published in October 2024.

The conclusion was blunt by the standards of a regulator. Some firms had taken a “bare minimum” approach, and the FCA recorded “overconfidence in how well firms are implementing the rules.”

Put less diplomatically: principals believe they are fine, and a good number of them are not.

2. The five headline findings

Five problem areas came out of the review. None of them will surprise anyone who has tried to run AR oversight across a spreadsheet, a SharePoint folder and a shared inbox. All of them are fixable.

The five areas:

  1. Self-assessments were often incomplete or weren't genuinely reviewed by the board
  2. Annual reviews of ARs were frequently superficial or reliant on self-declarations
  3. Onboarding over-relied on automated checks without human judgment
  4. Ongoing monitoring often used no real data or MI
  5. Termination went unplanned, and websites were rarely checked afterwards

Each one is a specific operational gap rather than a philosophical failing. Taking them in turn.

3. Self-assessments, and the 48% that fell short

Under SUP 12.6A, every principal must produce an annual self-assessment of its ability to oversee its ARs. The FCA found that of the 83% of principals that had completed a self-assessment, only 52% were good quality.

The common failures:

  • No formal record of the self-assessment being reviewed and signed off by the governing body
  • No consideration of whether existing controls and resources were actually adequate
  • No identification of material deficiencies and no action plan to fix them
  • Plenty of evidence that the review had been done, and none at all that it had been challenged

The regulator was particularly hard on self-assessments that had become tick-box exercises. A report showing an unbroken wall of green, or resting on a simple attestation, reads as unrealistic and points to a weak cultural approach to the Duty. No firm of any size is entirely green.

What good looks like

The FCA gave concrete examples of what good self-assessments contained:

  • Assessment of effectiveness of AR oversight arrangements and whether controls and resources are genuinely adequate
  • Use of broad management information: staff turnover, revenue changes, complaints rates, non-regulated activity
  • RAG-rated gap analysis with timelines and owners
  • Explicit consideration of consumer harm and market integrity risk
  • Board-level discussion with minuted challenge, not rubber-stamping

In short, show your working. A self-assessment that lists what you do says nothing about whether it works. The FCA wants to see that you know where your oversight is weak and what you are doing about it. Naming a gap yourself is a far better look than having a supervisor name it for you.

4. Annual reviews, and the 43% that passed

This is probably the most-quoted stat from the review. 82% of firms in the in-depth assessment had completed annual reviews of their ARs, but the FCA considered only 43% of these reviews to be of good quality.

Worth sitting with for a moment. More than half of the annual reviews the FCA examined, all of them from firms that had bothered to do the work, did not meet the quality bar. A further 18% had not done reviews at all.

The common failures were consistent:

  • Reviews that relied on the AR's own self-declarations without verification
  • Reviews conducted in a rush at year-end rather than built from a year of evidence
  • Reviews that ignored ongoing monitoring findings and started from a blank sheet
  • Reviews that never actually assessed fit and propriety, financial position or adequacy of controls, which are the three things SUP 12.6A asks for
  • No consideration of Consumer Duty implications in the AR's business activities

What good looks like

The FCA pointed to four characteristics of a good-quality annual review:

  • Strong understanding of the AR's business model, with actual analysis of their activity
  • Consumer Duty embedded into the review itself: fair value, distribution strategy, vulnerability
  • Bringing ongoing monitoring findings into scope, not treating the review as separate
  • Board-level discussion when material issues are identified

That last point matters more than it looks. A good review is not one where everything passes. It is one where something was found, escalated and dealt with. A file of flawless reviews is not reassuring. It is a flag.

“More than half of the annual reviews the FCA examined, all from firms that had bothered to do the work, did not meet the quality bar.”

5. Onboarding and the over-automation problem

This one is more nuanced than the rest, and software vendors ought to take it seriously. That includes us.

The FCA found firms relying solely on automated checks, with no human judgement applied, when running background searches on prospective ARs.

That is a shot squarely at one-click, AI-only onboarding tooling, and it is a fair one.

The regulator's position is not hard to follow. Automation is fine. Automation standing in for judgement is not. A credit check and a Companies House search are inputs to a decision, never the decision itself. Someone at the principal has to read the data, think about the business model, weigh the conflicts and put their name to a view.

Other onboarding failures the review flagged:

  • Failing to understand the mandatory contract terms required in SUP 12.5
  • Not considering the impact of appointing a new AR on the principal's own resources
  • Missing or outdated AR agreements

What good looks like

The FCA highlighted good onboarding practice as:

  • Clearly documented, maintained onboarding procedures
  • Initial and ongoing training for the AR on regulated activities and expectations
  • Enhanced due diligence that goes beyond the automated checks: financial accounts, linked individuals at Companies House, AML procedures and proper financial due diligence
  • Proper consideration of resource impact on the principal

The point running underneath all of it: onboarding is a structured human decision supported by data, not a checkbox exercise run by a tool.

6. Monitoring, where a third used no data at all

The most striking finding of the lot. A third of principals were not using data or management information to track whether their ARs were operating within the scope of their agreements.

A third of principals, the very firms the FCA holds legally responsible for their ARs' conduct, had no data-driven way of knowing what those ARs were doing. They were taking it on trust.

The typical failure pattern:

  • Oversight based on the AR's own self-reporting, without independent verification
  • No systematic monitoring of AR websites, promotions, or public activity
  • No integration between complaints data and AR-level risk assessment
  • No early-warning system for AR-level changes (permissions, directors, financials)

What good looks like

Monitoring that uses:

  • Broad MI including staff turnover, revenue changes, complaints rates, and non-regulated activity
  • Periodic reviews of the AR's public-facing material (website, social media, financial promotions)
  • Integration with the FCA Register for changes to permissions and individuals
  • Companies House monitoring for director changes and financial filings
  • Clear triggers for enhanced review when an AR's activity or risk profile changes

One theme runs through the whole review. Intent is not enough; evidence is. If you cannot show the data behind an oversight decision, a supervisor will assume you did not weigh it carefully. That is not unfair of them. It is what the record is for.

7. Termination, the part everyone forgets

Termination is where several principals came unstuck. The FCA found:

  • Firms not checking an AR's website after termination, leaving former ARs claiming permissions they no longer had
  • No clear mechanism for deciding when termination was the right answer
  • Inadequate planning for customer impact when an AR relationship ends
  • Principals failing to terminate ARs who weren't conducting regulated activity and were essentially using the principal's name as a “halo effect” for unregulated business

The last point deserves dwelling on. The FCA is worried about ARs sitting on the FS Register purely to lend regulatory respectability to unregulated business. A principal that keeps such a relationship alive out of inertia is not being neutral. It is lending its permission out.

What good looks like

  • A documented termination policy with clear conditions that trigger the process
  • Regular review of AR activity to identify dormant or off-scope relationships
  • Customer impact assessment as part of termination planning
  • Post-termination checks on the website, promotions, social media and the FS Register
  • Proper handover and communication plan for affected customers

8. What this means for 2026 and the principal permissions regime

The 2024 review isn't the end of the story. Two things are coming that will raise the stakes further.

First, the principal permissions regime. HM Treasury has confirmed that UK authorised firms wishing to act as principals will need to obtain a specific FCA permission to do so. The design is still being finalised, but the direction is clear: the FCA wants to be able to refuse or revoke permission to act as a principal, independent of the firm's other regulatory status.

If your oversight is weak when that regime lands, your principal permission is on the table. For any firm whose business model depends on running an AR network, that is a commercial threat rather than a compliance inconvenience.

Second, the shift towards impactful deterrence. The FCA has signalled a greater willingness to pursue smaller firms and bring lower-level enforcement actions in order to lift standards across the market. AR oversight failures are exactly the sort of thing that gets picked up in that net.

Taken together, quietly getting away with it has stopped being a strategy. Either your oversight is evidenced and can be produced on request, or the honest answer is that you should not be a principal.

9. A practical action checklist for principals

If you have recognised your own firm anywhere in the above, this is what to do in the next ninety days. None of it requires a budget round.

On your self-assessment

  • Dig out your last self-assessment and score it honestly against the FCA's good-practice examples
  • Establish whether it was genuinely challenged at board level, or simply noted
  • If it's stale, schedule the next one now with a genuine RAG-rated gap analysis
  • Set a standing board agenda item for AR oversight, not an annual dump

On annual reviews

  • Audit your last full cycle honestly. What proportion of those reviews would a supervisor call good quality?
  • Build a review template that covers fit and propriety, financial position, and adequacy of controls explicitly
  • Connect your ongoing monitoring to the review and stop starting from a blank sheet
  • Embed Consumer Duty considerations: fair value, distribution strategy, vulnerability

On onboarding

  • Document your onboarding procedure if you have not. A one-pager beats nothing
  • Ensure human sign-off is mandatory, not optional, at each stage
  • Upgrade your due diligence: Companies House, linked individuals, financial accounts, AML
  • Review every AR agreement against SUP 12.5 requirements

On monitoring

  • Identify the data sources you're already not using (FCA Register, Companies House, complaints, website checks)
  • Set up at minimum: quarterly register checks, monthly financial/director checks, complaints data by AR
  • Define your escalation triggers. What scale of change puts an AR into enhanced review?
  • Build management information that goes to the board, rather than into a folder

On termination

  • Write a termination policy if you don't have one
  • Run an audit of active ARs: which ones haven't conducted meaningful regulated activity in the last 12 months?
  • Check every former AR's website and promotions for lingering references
  • Plan customer impact for any AR relationship that's on shaky ground

None of this is a six-month programme. With the right tooling behind it, most of the list is a matter of weeks.

Free download

Get the FCA 2024 Review action checklist

We have turned the section above into a three-page PDF your compliance team can work through line by line. Free, and no sales call attached to it.

Download the checklist →

10. How Merrin addresses what the FCA found

This section is self-serving and you should read it that way. We built Merrin after watching principals struggle with precisely these problems, so it seems worth being explicit about how the product maps onto the findings above.

  • Self-assessments. A board-ready self-assessment structured around SUP 12.6A, with RAG ratings and a gap analysis built from your actual oversight data rather than from memory.
  • Annual reviews. Every review arrives pre-populated from twelve months of monitoring. You are not writing a review from a blank sheet. You are signing off on evidence that has been accruing all year.
  • Onboarding. Structured workflows for every check, and a named human approver on every decision. Automated data gathering, human judgement, exactly the split the FCA asked for.
  • Ongoing monitoring. Continuous FS Register sync, Companies House integration, warning list checks and per-AR watchlists, with an alert the day something moves.
  • Termination. A structured offboarding workflow with mandatory post-termination checks on the website and public material, and an audit trail behind the decision to end the relationship.

The whole product is built around the principle the FCA keeps repeating: evidence, not intent.

See how Merrin works →

11. Further reading

  • FCA, Principal firms embedding the new rules for effective appointed representative oversight: good practice and areas for improvement (October 2024)
  • FCA, Responsibilities and how to oversee your appointed representatives
  • HM Treasury, Consultation on the Appointed Representatives Regime
  • FCA Handbook, SUP 12, Appointed Representatives

Running AR oversight in spreadsheets?

Merrin was built for principal firms and nothing else. Give us twenty minutes and we will walk you through how it answers every finding above.

Book a 20-minute walkthrough →