FCA — High-growth firms: good and poor practice

Tag: S-2026-08-10-fca-high-growth-firms-good-poor-practice Type: report (good and poor practice review) Author(s): Financial Conduct Authority (FCA) Date of source: 2026-08-10 (publication date) Date ingested: 2026-08-14 Authority weight: high — the FCA’s own published good/poor-practice review, retrieved in full via direct WebFetch of the publication and its accompanying press release. Raw file: S-2026-08-10-fca-high-growth-firms-good-poor-practice.md. Source URLs: fca.org.uk/publications/good-and-poor-practice/high-growth-firms and fca.org.uk/news/press-releases/fca-boosts-support-innovative-firms-scale-grow, both 10 August 2026.

What it claims

On 10 August 2026 the FCA published “High-growth firms: good and poor practice”, a review of good practice and areas for improvement identified through its Early and High Growth Oversight pilot. Between July 2025 and March 2026 the FCA engaged directly with 15 firms across asset management, wealth management and payments, using a data-led approach (revenue, expenditure, staff growth, changes in permissions or control) to identify rapidly growing firms earlier and to assess whether each firm’s governance, risk management and control frameworks were keeping pace with its growth.

The central message: rapid growth can benefit consumers and markets, “but if firms prioritise expansion ahead of developing governance, risk management and control frameworks, this can increase the risk of harm.” The publication is aimed at Boards, senior management function holders, and those responsible for risk, compliance and operational oversight — and, while drawn from a sample, its themes are presented as relevant to firms of different sizes and business models undergoing growth or operational change.

Findings are organised across six areas, each with good practice and areas for improvement:

  1. Governance and senior management oversightGood: frameworks that kept pace with growth; clear Board/Committee structures with defined roles, regular oversight of risk and compliance, high-quality MI, well-documented decisions/challenge, and strengthened governing bodies with the right mix of skills and independent/non-executive challenge (notably in payments firms). Improve: governance not keeping pace; ineffective Board/Committee scope, frequency and format; insufficient independent challenge with responsibilities concentrated in a few individuals; weak governance record-keeping (incomplete/missing minutes; poor documentation of attendance, quorum, conflicts, decisions and follow-up).
  2. Risk management frameworksGood: more mature risk approaches, risk-focused committees reviewing enterprise-wide risks and escalating to the Board, clear risk appetites and key risk indicators, reduced single-individual dependency through cross-training. Improve: heavy reliance on key individuals with limited contingency/succession/knowledge transfer; failure to check whether risk-management resources remain appropriate to scale and complexity — “particularly where third-party relationships were becoming deeper or more numerous, or where firms were making greater use of new technologies such as AI”; policies/procedures/controls (e.g. suitability frameworks) not updated as business models or customer populations evolved.
  3. Resourcing, capability and scalabilityGood: investment in staff capability and scalable technology; strengthened compliance functions (resourcing, updated financial-crime frameworks, enhanced transaction monitoring); forward-looking regulatory judgement (preparing early for upcoming requirements such as safeguarding; using the Regulatory Initiatives Grid); delaying expansion into new regulated activities until existing controls were robust. Improve: capability/control frameworks lagging changes in business model or customer population.
  4. Systems, controls and management information (MI)Good: proactive cyber and operational-resilience arrangements (recognised security standards, penetration testing, third-party oversight, and “structured governance over the use of emerging technologies such as AI”); strong conflicts-of-interest identification and escalation; controls improved following cyber incidents. Improve: insufficient conflicts arrangements; outdated MI (references to superseded documents/meetings) undermining oversight; need to strengthen “evidence of change control, data governance, cyber testing, third-party oversight and operational resilience planning, particularly where firms were introducing new technology, automation, platform changes or AI”.
  5. Financial resilienceGood: proactive monitoring of liquidity and counterparty exposures; stress testing of the cost base. Improve: wind-down plans not always current, practical or proportionate; firms reminded of notification obligations such as SUP 15.
  6. Consumer and market outcomesGood: active product/service oversight, benchmarking, transparent client reporting, provider/platform due diligence and client-feedback loops delivering Consumer Duty outcomes (fair value, appropriate propositions). Improve: greater emphasis needed on assessing customer outcomes and fair value.

Next steps: the FCA gave individual feedback to all 15 pilot firms and “encourage[s] firms experiencing growth to reflect on these findings and assess whether their own arrangements remain appropriate for their size, scale and complexity”, addressing any gaps “in a timely and proportionate way”. The FCA will use the insights to inform its supervisory approach and its data-led identification of emerging risks. The accompanying press release also announced that five solo-regulated firms (ClearScore, Modulr, Teya, Urban Jungle, Zilch) joined the FCA’s Scale-up Unit.

Notable quotes

“But if firms prioritise expansion ahead of developing governance, risk management and control frameworks, this can increase the risk of harm.” — FCA, High-growth firms: good and poor practice, 10 August 2026 (introduction)

“We assessed whether their governance, risk management and control frameworks were developing in line with their growth.” — FCA, 10 August 2026 (What we looked at)

“[Areas for improvement on cyber included] strengthening evidence of change control, data governance, cyber testing, third-party oversight and operational resilience planning, particularly where firms were introducing new technology, automation, platform changes or AI.” — FCA, 10 August 2026 (§3.4 Systems, controls and MI)

“Early investment in governance, risk management and controls helps firms manage the opportunities and challenges of growth, as well as scale sustainably.” — FCA press release, 10 August 2026

What’s speculative vs. asserted

  • Asserted (primary FCA publication): the 10 August 2026 publication; the pilot scope (15 firms in asset management, wealth management, payments; July 2025–March 2026); the six finding areas and their good/poor-practice examples; the data-led firm-identification method; and the “self-assess and close gaps proportionately” next steps.
  • Asserted (primary — accompanying press release): five named solo-regulated firms joining the Scale-up Unit; applications for solo-regulated firms opened in May and closed 22 June 2026; six FCA/PRA jointly-regulated firms formed the first cohort in February 2026.
  • Framing, not new rules: the publication is a good/poor-practice review — illustrative supervisory expectation-setting, explicitly not a new rule or requirement. The AI references appear as examples within cyber/systems-and-controls and risk-management findings, not as an AI-specific control framework.
  • Not this document: this is distinct from the FCA’s still-pending AI “good and poor practice” publication (the AI Lab output flagged for later in 2026 on FCA approach to AI). Do not conflate the two.

Topics this feeds

  • FCA — Financial Conduct Authority — a material FCA good/poor-practice review setting supervisory expectations that governance, risk and control frameworks must scale with business growth.
  • FCA approach to AI — secondary AI hook: the review names AI/new technology as an emerging-tech area needing structured governance, data-governance, change-control and cyber-resilience controls.
  • Operational Resilience and Third Party Risk — cyber, third-party oversight and operational-resilience planning feature in the systems-and-controls findings.
  • Suggested future Concept/Topic page: Governance scaling with firm growth / high-growth firm oversight — promote if a second source arrives (e.g. the FCA’s supervisory follow-through or a related thematic review).

Open questions raised

  • Will the FCA’s data-led identification of high-growth firms and this good/poor-practice benchmark translate into more intensive supervisory engagement or thematic follow-up for growing firms?
  • How should a growing firm evidence that its governance/risk/control frameworks are “keeping pace” — what artefacts (Board effectiveness reviews, risk-appetite refresh, MI quality checks, wind-down plan reviews) would satisfy the FCA’s implicit benchmark? (Direct assurance hook.)
  • How does the AI/new-technology governance expectation here relate to the forthcoming AI good/poor-practice publication and the Mills Review’s end-2026 guidance recommendations?