The FCA regulatory strategy for 2025 to 2030 rests on a deceptively simple idea: effective regulation should manage risk, not attempt to remove it altogether.
That distinction runs through the FCA’s Annual Report and Accounts 2025/26. The regulator wants to intervene earlier, make decisions faster and direct its resources towards the most serious harms. It is simplifying reporting requirements and digitising its own processes while expanding its use of data and artificial intelligence.
None of this amounts to softer regulation. Taken together, the report’s simplification and enforcement measures suggest a regulator seeking to spend less time on low-value administration and more on material harm.
For financial services firms, this changes the practical meaning of good compliance. A process cannot be considered robust simply because it is cautious, exhaustive or slow. Firms should be prepared to explain how they reach proportionate decisions, preserve evidence and apply their standards consistently.
That has consequences well beyond the compliance function. Marketing is likely to be one of the first places where the difference becomes visible.
The FCA regulatory strategy is an operating model, not a slogan
The first year of the FCA’s five-year strategy has concentrated on four priorities: helping consumers, becoming a smarter regulator, supporting growth and fighting financial crime.
The interesting part is how the FCA believes these priorities fit together. Consumer protection and economic growth are not presented as opposite ends of a regulatory seesaw. The regulator’s stated aim is to support both by making more deliberate choices about risk.
FCA Chair Ashley Alder argues in the report that treating zero risk as the benchmark will eventually suppress the activity that competitive markets need. The result can be reduced access, less choice and a financial system that serves consumers poorly, despite being designed to protect them.
This is an unusually direct acknowledgement of the cost of excessive caution. It also creates a higher standard for regulatory judgement. Once zero risk is no longer the default answer, decisions require a clearer account of which risks are acceptable, who carries them and what safeguards are proportionate.
The same logic applies inside regulated firms.
Blanket restrictions are relatively easy to administer. So are policies that send every decision through the same lengthy approval route. They may feel safe, but they can obscure the difference between a routine customer communication and a genuinely high-risk proposition.
A risk-based model is harder to design. It depends on reliable information, clear decision rights and people who understand the context in which a rule should be applied. When it works, it gives specialists more time for the decisions that genuinely require their attention.
Less regulatory administration does not mean a lower bar
The FCA has offered firms some tangible evidence that simplification is more than an aspiration.
During 2025/26, it fully decommissioned eight regulatory returns and moved another five from quarterly to annual submission. The changes affected more than 90 per cent of regulated firms and are expected to save them £16 million a year.
The regulator has also automated parts of its own supervisory work. Processing time for less complex cases fell from as much as four hours to an average of six minutes. In the final quarter of the reporting year, 97.6 per cent of authorisation applications were determined within the FCA’s voluntary or existing targets.
Further proposed changes to transaction reporting could save businesses an estimated £87 million annually.
These numbers matter because regulatory cost is not confined to fees or headcount. It includes the time spent searching for information, repeating checks, reconciling different interpretations and waiting for approval. A poorly designed review process can consume substantial resources without improving the eventual decision.
Yet the other side of the report is just as important. The FCA had 11 open enforcement cases relating to the Consumer Duty at 31 March 2026, compared with one a year earlier. Open cases are not findings of a breach, but the increase demonstrates greater enforcement activity in this area. The FCA also took down more than 190 scam websites and used data analysis to identify suspected unregistered crypto brokers and approximately £30 million in unregistered activity.
The direction is clear. Lower-value administration may decrease, while scrutiny of outcomes, conduct and serious harm becomes more focused.
Firms that interpret simplification as permission to weaken their controls will have missed the point. The opportunity is to remove activity that produces little assurance and strengthen the systems that show how decisions are made.
Marketing will reveal whether risk-based regulation works
Marketing sits at an awkward but valuable intersection of commercial ambition, customer understanding and regulatory responsibility.
It is where a product promise becomes public. It is also where internal complexity can become a consumer problem.
The FCA’s report places considerable weight on the quality of information provided to customers. Its work during the year included new rules for consumer composite investments, forthcoming protections for interest-free Buy Now Pay Later products and continued scrutiny of how firms support vulnerable consumers.
Consumer Duty compliance is therefore not simply a matter of checking whether a promotion contains the required wording. Firms must consider whether the customer is likely to understand the communication, whether the presentation is fair and whether the wider journey supports a good outcome.
This requires judgement. A phrase may be technically accurate but misleading in context. A disclosure may be present but effectively invisible. A campaign may pass a conventional approval checklist while leaving the intended audience with the wrong impression.
Where marketing compliance still depends on email chains, generic policies, disconnected folders and the recollection of a small number of experienced reviewers, the process can favour document control over contextual judgement. Feedback may arrive after the creative direction and media plan have already been settled.
That model can delay marketing without demonstrating that the additional time has improved the customer outcome. It may also make consistency difficult. Similar claims can receive different treatment depending on the reviewer, the deadline or how much background information happened to accompany the request.
If the FCA expects firms to be faster and more deliberate about risk, marketing approval needs to become equally deliberate. Low-risk work should move through an efficient route. Novel products, material claims and communications aimed at vulnerable audiences should receive deeper scrutiny. The reasons for each decision should remain visible after the campaign has gone live.
Faster decisions depend on better institutional knowledge
The FCA describes itself as becoming a more data-led regulator. It is embedding AI in parts of the authorisation process and exploring its use as a first responder to suspected abuse in wholesale markets.
It is also encouraging experimentation across the industry. The first AI Supercharged Sandbox cohort, run with NVIDIA, received 132 applications and supported 23 firms. Applications to the FCA’s wider innovation services rose by 89 per cent during the year.
The significance for marketing and compliance is not that every firm now needs an AI project. It is that the regulator itself is treating technology as a way to direct human expertise towards higher-risk work.
That is a more useful model than applying a general-purpose AI assistant to individual tasks and hoping for consistent results.
A general-purpose AI tool used without access to the firm’s approved regulatory interpretations, product history, previous decisions, risk appetite and approval responsibilities will lack important context. Without that context, speed can come at the expense of reliability.
For regulated workflows, a useful design objective is to make approved institutional knowledge easier to retrieve and apply. Any compliance automation used for this purpose should help reviewers identify relevant requirements and comparable decisions, while preserving an intelligible record of what was reviewed, what changed and who remained accountable for the final judgement.
The aim should be to reduce avoidable retrieval and repetition while keeping responsibility with the accountable reviewer.
What marketing and compliance leaders should change
The FCA’s approach suggests four practical priorities for regulated organisations.
Define where judgement is required
Not every asset needs the same review. Firms should distinguish between repeatable, lower-risk communications and work involving new propositions, significant financial claims or vulnerable audiences.
The criteria should be explicit enough to guide teams before a piece of content reaches compliance. If everything is labelled high risk, the classification has ceased to be useful.
Make previous decisions reusable
Many organisations possess considerable regulatory knowledge but store it poorly. Policies sit in one system, approved wording in another and the reasons behind past decisions in individual inboxes.
A usable knowledge base should connect the rule, the firm’s interpretation and examples of how that interpretation has been applied. Otherwise, each new campaign begins with unnecessary archaeology.
Measure the quality of the review process
Turnaround time matters, but it should not become the only measure. Leaders should also examine how often work is returned for avoidable reasons, where reviews become stuck and whether similar decisions are producing consistent outcomes.
Those measures can expose whether the problem lies in marketing briefs, unclear policies, limited capacity or the design of the workflow itself.
Use automation to improve the handover between teams
The most valuable systems will not belong exclusively to marketing or compliance. They will help both functions work from the same requirements and evidence.
That might mean checking routine content against approved guidance before submission, highlighting claims that need specialist attention or assembling the information a reviewer needs. The technology should improve the conversation between teams, not attempt to eliminate it.
Compliance must now make a case for how it operates
The FCA estimates that rules introduced over the past decade delivered £5.6 billion in benefits to consumers and the economy during 2025/26. It also expects interventions including stronger Buy Now Pay Later protections and improved outcomes for pension savers to generate more than £1 billion in annual benefits over the next decade.
Those figures show that regulation can create substantial public value. They also reinforce the need to distinguish the controls that improve outcomes from the activity that merely makes an organisation appear busy.
The FCA is attempting to make that distinction in its own operations. Firms should expect to do the same.
For marketing and compliance leaders, the central challenge is no longer how to add another check. It is how to build an operating model that applies the right scrutiny, preserves evidence and allows routine work to proceed without needless delay.
That calls for better systems, but also for confidence in human judgement. Any digital teammate used in this process should be configured around approved sources, defined controls and clear routes for human review. Accountability, interpretation and commercial judgement remain with the people who understand the business.
Rebalancing risk is not the easy alternative to caution. Done properly, it is more demanding. It asks organisations to know why a decision is safe enough, not merely to prove that a process was followed.
What teams need to know
What are the FCA’s priorities for 2025 to 2030?
The FCA has four strategic priorities: helping consumers, becoming a smarter regulator, supporting economic growth and fighting financial crime. Its stated vision is to deepen trust, rebalance risk, support growth and improve lives.
Does the FCA’s focus on growth mean less consumer protection?
No. The FCA presents growth and consumer protection as mutually dependent. It is reducing unnecessary regulatory burden while directing greater attention towards serious consumer harm, financial crime and poor market conduct.
What does the FCA Annual Report 2025/26 mean for marketing teams?
Marketing teams should expect continued scrutiny of customer understanding, fair presentation and Consumer Duty outcomes. Firms will need approval processes that can distinguish routine communications from work requiring deeper regulatory judgement.
How can AI support financial services compliance?
When configured with approved sources and appropriate controls, AI may assist with retrieving guidance, flagging content for review and maintaining records. The accountable reviewer should still determine the regulatory outcome.
What is risk-based regulation?
Risk-based regulation directs attention and resources according to the likelihood and potential severity of harm. For firms, this means applying proportionate controls while being able to explain and evidence the reasoning behind each decision.