ENTRY № 10 · STATUTORY READING · FCA PRIN 2A
PUBLISHED 2026-05-09 · ~14-MIN READ · WARRANT COMPLIANCE

FCA Consumer Duty Principle 12, line by line.

Principle 12 binds every UK retail-facing firm to deliver good outcomes; PRIN 2A breaks the principle into operative duties. Three cross-cutting obligations, four outcomes; one Handbook chapter. Read against an AI agent making customer-facing decisions, the four outcomes (products and services, price and value, consumer understanding, consumer support) become evidence-of-record obligations.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant.

CLAUSE
PRIN 2A· 2A.1–2A.11 · 4 outcomes
FCA Handbook PRIN 2A, inserted by instrument FCA 2022/31. Effective 31 July 2023 for products and services open to sale or renewal.
IN FORCE
2023-07-31· closed 2024-07-31
Binds every FCA-authorised firm in the chain that delivers the retail outcome. Governing-body review and approval of the outcomes report at least annually — PRIN 2A.8.4R.
PENALTY EXPOSURE
unlimited· FSMA § 206
FSMA 2000 s.206 sets no cap: a penalty "of such amount as it considers appropriate". Personal accountability runs through the individual Conduct Rules (COCON 2.1.6R) and senior-manager allocation — instrument FCA 2022/31 created no Duty-specific prescribed responsibility.
01 · § 1 · THE PRINCIPLE IN ONE SENTENCE

The load-bearing claim.

A firm must act to deliver good outcomes for retail customers. FCA Handbook · PRIN 2.1.1R · in force 2023-07-31

Eleven words. The whole of PRIN 2A descends from that one rule. The original eleven Principles for Businesses had Principle 6, treating customers fairly, which the supervisor read as a process standard. Principle 12 is the outcome standard. Act to deliver is operative. Good outcomes is the test. The firm bears the evidential burden, and a process diagram does not satisfy it.

The placement of the rule matters, though not in the way it is often described: Principle 12 does not override the product-specific sourcebooks. It raises the standard above them. PRIN 2A.1.17G(1) puts it directly — Principle 12 "imposes a higher and more exacting standard of conduct in relation to a firm's retail market business relative to what Principles 6 or 7 would have otherwise required", with "a broader application", and it reaches retail customers who "do not stand in a client relationship with that firm in the distribution chain". PRIN 2A.1.17G(4) adds that acting in line with existing Principle 6 and 7 guidance "should not be relied on alone" in considering how to comply. So the duty sits over mortgage origination under MCOB, consumer-credit decisions under CONC, insurance pricing under ICOBS, investment advice under COBS and retail banking under BCOBS — and over a retail product class with no sourcebook chapter of its own yet. An AI agent operating across product lines is exactly the case where a firm cannot answer by pointing at one sourcebook.

An AI agent making any retail-facing decision is squarely in scope. A model that classifies a credit application, that prices an insurance renewal, that suggests a savings product, that triages a complaint, or that authors the response a contact-centre agent reads to a customer is, in every case, acting in the chain that produces the retail outcome. PRIN 2.1.1R reaches the firm; the firm reaches the chain; the chain reaches the agent. The firm cannot disclaim the duty by pointing at the model vendor.

"Eleven words at the head of PRIN 2A bind the firm to the outcome. Everything else in the chapter is the supervisor explaining what counts as evidence."Warrant Compliance · 2026-05-09
02 · PRIN 2A.3–2A.6 · THE FOUR OUTCOMES

What good outcomes look like.

The four outcomes operationalise PRIN 2.1.1R. They are not aspirational; each is drafted as a rule the firm must satisfy, and each generates a distinct evidence shape. An AI agent participating in any of the four chains inherits the supervisor's expectation of a per-decision record.

For each product that is not a closed product, a manufacturer's product approval procedures must: … (4) ensure that the design of the product: (i) meets the needs, characteristics and objectives of the target market; … FCA Handbook · PRIN 2A.3.4R(4)(i) · products and services outcome · made by FCA 2022/31

Read against a recommendation agent, that rule needs a per-decision record showing the agent considered the customer's identified target-market segment and that the recommendation falls inside the manufacturer's intended distribution strategy — PRIN 2A.3.4R(5) requires the approval procedures to ensure that strategy is appropriate for the target market. A target-market check that exists only as a one-time approval at product-launch time does not satisfy a duty that applies to every retail interaction. The check has to live inside the agent's per-action envelope.

For the purposes of this outcome: … (2) a product provides fair value where the amount paid for the product is reasonable relative to the benefits of the product. FCA Handbook · PRIN 2A.4.1R(2) · price and value outcome · made by FCA 2022/31

Price and value is the outcome that lands hardest on AI pricing engines. The assessment runs at product level, but PRIN 2A.4.1R(2) frames fair value around "the amount paid for the product" — a figure that, for an AI-determined price, exists per customer. For an AI-determined price, the per-decision record must capture the inputs to the price (including any inferred attributes), the cohort placement, and the residual customer-outcome risk. Reasonable relative to the benefits is a cohort-level test that has to survive a per-customer audit.

A firm must support retail customer understanding so that its communications: (a) meet the information needs of retail customers; (b) are likely to be understood by retail customers; and (c) equip retail customers to make decisions that are effective, timely and properly informed. FCA Handbook · PRIN 2A.5.3R(1) · consumer understanding outcome · made by FCA 2022/31

Consumer understanding governs every output an AI agent produces that ends up in front of a retail customer. A chatbot answer, a generated email, a personalised product summary, a quote document, an in-app explanation of a declined application: all of it is a communication subject to PRIN 2A.5. The evidence shape is a per-output communication-clarity record (reading-level estimate, key-information presence, prominence of fees and material risks, accessibility of the channel) that the firm can retrieve and tie to the specific customer who received it.

A firm must design and deliver support to retail customers such that it: (1) meets the needs of retail customers, including those with characteristics of vulnerability; … FCA Handbook · PRIN 2A.6.2R(1) · consumer support outcome · made by FCA 2022/31

Support is where the AI agent itself most often sits. The outcome attaches whether the agent is the support channel, mediates the support channel, or replaces a human in the support channel. The evidence shape includes the escalation path the agent followed, the human-in-the-loop trigger conditions that fired or should have fired, and the resolution outcome the customer experienced. PRIN 2A.6 is also the outcome with the most explicit vulnerable-customer overlay: where a customer characteristic suggests vulnerability, the support quality is judged against that customer's needs, not against the average.

03 · PRIN 2A.2 · CROSS-CUTTING RULES

The three cross-cutting obligations.

PRIN 2A.2, headed "Cross-cutting obligations", carries three rules that apply in addition to the four outcomes, not in substitution. They are what remains binding on conduct that does not fall neatly inside any one outcome.

2A.2.1R
A firm must act in good faith towards retail customers. SCOPE · PRIN 2A.2.2R defines the standard: honesty, fair and open dealing, and acting consistently with the reasonable expectations of retail customers. The definition is in the rule, not left to industry practice.
2A.2.8R
A firm must avoid causing foreseeable harm to retail customers. SCOPE · PRIN 2A.2.9R: foreseeable harm may be caused by both act and omission. PRIN 2A.2.5R adds a positive duty to take appropriate action, including redress where appropriate, once the firm identifies harm suffered.
2A.2.14R
A firm must enable and support retail customers to pursue their financial objectives. SCOPE · positive duty — enable and support, not merely refrain from harm. PRIN 2A.2.15G governs what conclusions a firm can properly reach about a customer's financial objectives.

The cross-cutting rule that lands hardest on AI is the second. Foreseeable harm reaches a model recommendation the firm cannot fully explain. The argument runs: a model whose decision boundary the firm cannot interrogate produces decisions whose harm the firm cannot foresee in the supervisor's sense; a firm that deploys such a model into retail channels has, by deployment alone, accepted a class of harm it cannot foresee. Explainability is the input to foreseeability, and foreseeability is the test under PRIN 2A.2.8R.

That reading is Warrant's, not the FCA's: no FCA instrument or published guidance states an AI-explainability obligation under PRIN 2A.2.8R in those terms. What the enacted text does carry is the rule itself, unqualified — "A firm must avoid causing foreseeable harm to retail customers" (PRIN 2A.2.8R, made by FCA 2022/31) — and PRIN 2A.3.4R(4)(iii), which requires a manufacturer's product approval procedures to ensure the design of the product "avoids causing foreseeable harm in the target market". Neither carves out harm the firm cannot explain. Where the firm's own evidence cannot show what a model did and why, the firm has no material with which to answer a foreseeability question.

The good-faith rule under PRIN 2A.2.1R has its own AI overlay. A model trained on data that systematically disadvantages a protected characteristic, even where the firm did not intend the disadvantage, is hard to reconcile with the reasonable expectation a retail customer brings to the interaction — PRIN 2A.2.2R characterises acting in good faith as "a standard of conduct characterised by honesty, fair and open dealing and acting consistently with the reasonable expectations of retail customers", and PRIN 2A.2.3G(a) gives "failing to take account of retail customers' interests, for example in the way it designs a product or presents information" as an example of a firm not acting in good faith. On Warrant's reading the practical consequence is evidential: the firm that cannot show how the data, the design, and the operation of the agent were oriented toward the customer's interests has nothing to put in front of a supervisor asking.

The enabling rule under PRIN 2A.2.14R is the rule most often missed. It is a positive duty. An AI agent that defaults to the firm's preferred product, that hides the cheaper alternative behind a click, or that fatigues the customer into a decision that does not match the customer's stated objective is not enabling the customer's pursuit of that objective. The evidence shape is the per-action record that the agent considered the alternatives that mattered to the customer.

04 · PRIN 2A.8 + COCON 2.1.6R · THE SMCR OVERLAY

The senior manager signs the chain.

PRIN 2A.8 puts Consumer Duty on the governing body, not in the compliance function. Two distinct mechanisms sit behind that, and they are routinely conflated. The first is the Consumer Duty champion — an expectation in guidance, not a rule. FG22/5 paragraph 10.10 states: "We expect firms to have a champion at board (or equivalent governing body) level who, along with the Chair and the CEO, ensures that the Duty is being discussed regularly and raised in all relevant discussions. The champion should be an Independent Non-Executive Director (NED), where possible." That is an expectation of an iNED champion, not a mandated senior-manager owner. The codified obligation sits beside it in PRIN 2A.8.3R and PRIN 2A.8.4R. The second mechanism is SMCR. Personal accountability does not come from a Duty-specific designation; instrument FCA 2022/31 created no such designation. It comes from the individual Conduct Rules — the same instrument inserted COCON 2.1.6R, "Rule 6: You must act to deliver good outcomes for retail customers" — and from senior-manager allocation, with Duty outcomes generally read into existing prescribed responsibilities rather than a new one. A senior manager holding an affected prescribed responsibility carries the duty of responsibility under FSMA section 66A.

The duty is personal, not corporate. Where consumer harm follows an AI-driven decision and the firm cannot evidence the chain (rationale, oversight, alternatives considered), the SMF holder is exposed to personal fines, prohibition orders, or industry exclusion. The firm-level civil penalty is recoverable from the firm's balance sheet; the personal sanction is not. A record mapped to the specific obligation is the trail.

Read the two rules precisely, because the copy in circulation tends to blur them. PRIN 2A.8.3R puts the drafting on the firm: "A firm must prepare a report for its governing body setting out the results of its monitoring under PRIN 2A.9 and any actions required as a result of the monitoring." PRIN 2A.8.4R puts the cadence and the sign-off on the governing body: "At least annually, the governing body of a firm must: (1) review and approve the firm's report on the outcomes being received by retail customers; (2) confirm whether it is satisfied that the firm is complying with its obligations under Principle 12 and PRIN 2A; and (3) assess whether the firm's future business strategy is consistent with its obligations under Principle 12 and PRIN 2A." Annual is the floor in the rule. Many firms run the pack quarterly so the annual approval rests on evidence already validated; that is practice, not obligation, and this post does not attribute it to the FCA.

Rule 6
COCON 2.1.6R
Individual Conduct Rule 6, inserted by FCA 2022/31: "You must act to deliver good outcomes for retail customers." Duty outcomes are generally read into existing prescribed responsibilities; the instrument created no new one.
66A
DUTY OF RESPONSIBILITY
FSMA 2000 section 66A. The reasonable steps are the senior manager's — exposure arises where the senior manager did not take the steps a person in that position could reasonably be expected to take. As read 2026-08-06.
1/yr
GOVERNING-BODY APPROVAL
PRIN 2A.8.4R: at least annually the governing body reviews and approves the outcomes report the firm prepares under PRIN 2A.8.3R. Annual is the floor in the rule.
10y
LOOK-BACK, OBSERVED
FCA Final Notice against TSB Bank plc, dated 9 October 2024: relevant period 25 June 2014 to 1 March 2020. A decade between the earliest conduct and the notice.

What does the senior manager actually need before the governing body approves the report? Three things. First, a per-cohort outcomes pack for every retail product line: target-market alignment under PRIN 2A.3, fair value evidence under PRIN 2A.4, communication-clarity evidence under PRIN 2A.5, support-quality evidence under PRIN 2A.6. Second, a per-decision retrieval capability so that when the supervisor pulls a specific customer case the SMF can stand behind the answer in the same minute. Third, a record that the SMF reviewed the outcomes, signed off, and named the residual risk carried into the next period. For an AI-driven product, the per-decision retrieval is the load-bearing piece, and a 90-day-rolling Datadog dashboard does not produce it.

That is why AI-decision logging is not optional for the SMF. The duty of responsibility under FSMA section 66A is a personal exposure that survives the SMF's tenure at the firm. An SMF who attests on evidence the firm cannot reproduce a year later, and on which the supervisor later finds harm, has attested a personal liability into existence. The structural answer is to make the per-decision evidence retrievable, independently verifiable without contacting Warrant, and external to any single observability tool the firm operates.

05 · PRIN 2A.9 · DATA AND OUTCOMES MONITORING

Regular monitoring is per cohort, per decision.

A firm must regularly monitor the outcomes retail customers receive from: (1) the products the firm manufactures or distributes; (2) the communications the firm has with retail customers; and (3) the customer support the firm provides to retail customers. FCA Handbook · PRIN 2A.9.8R · monitoring of consumer outcomes · made by FCA 2022/31

For an AI-driven product the operative question is what counts as regular. The rule does not define it, and no FCA instrument or published guidance sets a numeric cadence — Warrant is aware of none, and this post asserts none on the FCA's behalf. What PRIN 2A.9.9R does fix is the standard the monitoring must reach: it "must enable [the firm] to determine at least" whether customers were sold products designed to meet their needs, whether the products purchased provide fair value with appropriate action taken where they do not, and whether customers were equipped with the right information to make effective, timely and properly informed decisions. A cadence that cannot answer those questions for the product in front of it is not regular in the sense the rule requires. Warrant's own reading is that the interval has to track the harm horizon of the product: short-cycle lending needs a tighter loop than a 25-year life policy. That is a reading, not a supervisory expectation.

Monitoring at the cohort level is necessary; it is not sufficient. PRIN 2A.9.9R is framed around what the firm can determine, and a determination about a specific customer needs the specific customer's record. Where the per-cohort monitoring runs on observability data that rotates at 30 to 90 days, and the customer case is older than 90 days, the answer is that the monitoring would not have surfaced the harm. PRIN 2A.9 is a per-cohort monitoring rule that depends on a per-decision evidence trail.

What the Warrant evidence package actually carries, named off the published v0.2 package schema rather than described loosely: a classification envelope (domain, jurisdictions, regimes, risk_tier, risk_tier_justification); an actions array in which each row carries action_id, actor, action and subject; an authorizations array keyed to the same action_id, carrying within_purpose, preconditions_met, human_oversight_appropriate, reversible and a written justification; and an obligations map, again keyed by action_id, whose rows name a corpus clause id with a compliance status of satisfied, gap, uncertain or unvalidated. Two limits are worth stating plainly. The action rows carry no separate input, output or timestamp fields — the package timestamp lives once, in trace_metadata.timestamp. And there is no bespoke per-outcome field: the binding to a PRIN 2A clause is generic, through the obligation row's clause id.

The architecture answer matters. A monitoring system that reads observability data and produces a dashboard answers a different question than the one PRIN 2A.9 asks. The Handbook asks: were the outcomes monitored, and is the firm acting on them. The Warrant evidence of record answers that question per decision and per cohort, and produces an evidence record, independently verifiable without contacting Warrant, that the SMF can hand the supervisor without negotiating retention.

06 · PS22/9 § 1.34 · THE CLOSED-PRODUCTS CLOCK

Closed products fell into scope on 2024-07-31.

PS22/9 paragraph 1.34 sets both dates in one sentence: "Firms will need to apply the Duty to new and existing products and services that are open to sale (or renewal) from 31 July 2023. We have given firms longer, until 31 July 2024, to apply the Duty to products and services held in closed books." Both deadlines have passed. The pinpoint is worth getting right: § 12.11 sets out the FCA's own implementation-support and monitoring work, not the deadline.

The perimeter is not a matter of interpretation. PRIN 2A.3.26R provides that "a closed product not already subject to PROD must follow the closed product rules set out in PRIN 2A.3.5R to 2A.3.6R and PRIN 2A.3.21R to 2A.3.23G", and PRIN 2A.3.21R addresses products with existing contracts entered into before 31 July 2023. So legacy mortgage portfolios originated before the duty, closed insurance products on which the firm still takes premium, and investment products no longer marketed but still on existing customers' books are inside PRIN 2A by rule. What Warrant does not assert, because no FCA instrument or published guidance we can cite says it, is any particular supervisory expectation about historical-decision review on those books.

For AI agents that adjudicate closed-product issues the implication is direct. A model that handles arrears on a legacy lending portfolio, a model that prices renewal on a closed insurance book, a model that triages complaints on a discontinued investment product, all sit inside the closed-products perimeter and therefore inside PRIN 2A. Nothing in PRIN 2A.3.26R or PRIN 2A.9 makes the evidential standard lighter because the book is closed. An AI agent that cannot retrieve the per-decision record for a closed-product case from 2024 cannot defend the case in 2026.

07 · ANNEX 1 · WHAT GOOD EVIDENCE LOOKS LIKE

The shape of a defensible evidence record.

PRIN 2A's value-assessment framing carries through to the broader evidence shape. No FCA instrument prescribes a record format, so what follows is Warrant's reading of what a record has to contain to answer the questions PRIN 2A.9.9R makes the firm able to determine: per cohort and per decision, which outcome or cross-cutting obligation the action engaged, what mitigating control was applied, and what residual customer-outcome risk the firm accepted. Per cohort because the outcomes operate at the cohort level; per decision because the specific case is what an examination reaches for.

On that reading a defensible record has six fields. First, the identification of the retail customer cohort and the specific customer where data protection allows. Second, the identification of the AI action and the actor (model identity, version, prompt template, deployment scope). Third, the inputs the agent considered, including any inferred attributes that fed the decision. Fourth, the output the agent produced and the rationale it can defend. Fifth, the human oversight trigger conditions that fired or should have fired, with the reviewer identity if the trigger fired. Sixth, the binding to the specific Handbook clauses engaged.

Warrant package_id 7de85ceaeac42a47 is a worked example of that shape, and it is worth being exact about what it is and what it is not. It was generated from a German consumer-lending underwriting trace — agent loan_underwriter_eu_v1, classified jurisdictions DE and EU — and the regimes it evaluates are EU AI Act Article 12 (six obligations) and Article 13 (three obligations), across four warranted actions. It binds no PRIN 2A clause and makes no Consumer Duty finding. The corpus regime fca_consumer_duty_ai applies to the UK, and a package classified DE/EU does not reach it. It is reproduced here as a specimen from a different regime, because the package shape is the point rather than the regime: where a clause is bound, it is bound in the obligations map — keyed by action_id, each row naming a corpus clause id and a compliance status — and a PRIN 2A binding would occupy exactly those rows, against the fca_consumer_duty clause ids listed in § 09. The schema has no field named regulatory_obligations. The PDF is retrievable and independently verifiable without contacting Warrant, which is the property that makes an evidence record answerable to a supervisor at all, whichever regime the record binds.

W
Specimen package · DE/EU lending trace · EU AI Act Article 12 + Article 13 · binds no PRIN 2A clauseSHOWN FOR SHAPE · INDEPENDENTLY VERIFIABLE WITHOUT CONTACTING WARRANT
→ /v/7de85ceaeac42a47
08 · FSMA 2000 § 206 · THE PENALTY REGIME

Unlimited civil penalty, personal SMCR exposure.

The financial penalty regime sits in the Financial Services and Markets Act 2000, section 206. The provision empowers the FCA to impose a financial penalty on an authorised person of such amount as it considers appropriate, where the firm has contravened a relevant requirement. The statute does not cap the amount. In practice the FCA's penalty-setting policy runs through DEPP 6 (the Decision Procedure and Penalties manual), but the statutory ceiling is unlimited.

The 15-million figure that circulates in industry conversation is a comparison anchor from another regime, not a UK statutory limit, and it is denominated in euro: EU AI Act Article 99(4) sets a ceiling of EUR 15,000,000 or, if the offender is an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

For scale on the UK side, the closest instrument on the public record is the FCA Final Notice against TSB Bank plc, dated 9 October 2024. It imposed a financial penalty of £10,910,500 under section 206 — the same power discussed above — after TSB breached Principles 3 and 6 in its handling of retail customers in arrears or financial difficulty between 25 June 2014 and 1 March 2020. The notice records 232,849 customers identified as having suffered or been at risk of loss, and £99.9m paid in redress. Note what that notice is not: the relevant period closed in March 2020, more than three years before Principle 12 applied, so it is a Principles 3 and 6 case, not a Consumer Duty case. Warrant has not identified any FCA Final Notice citing Principle 12, and this page does not claim one exists in either direction — the absence has not been verified, only the failure to find.

The personal SMCR exposure is the lever that creates a stronger evidence-discipline incentive than the firm-level penalty. A firm-level fine is a balance-sheet event the firm can accommodate in the next reporting cycle. A personal sanction against an SMF holder, including prohibition orders that exclude the individual from authorised-firm employment, is career-ending. The SMF holder who signs a quarterly attestation on evidence the firm cannot reproduce is, in effect, signing a personal liability into existence. The structural answer for the firm is to make the per-decision evidence retrievable for the duration of the SMF's exposure, not for the duration of the firm's standard observability cycle.

What the enacted text supports about entry points is narrower than a supervisory-priorities claim, and it is worth saying so. PRIN 2A.9.9R makes the firm able to determine outcomes for retail customers, and PRIN 2A.6.2R(1) attaches support quality to customers "including those with characteristics of vulnerability". A firm whose evidence answers at the cohort level and fails on the individual vulnerable case has not met the standard the rules set, whoever asks first. Warrant does not attribute a 2026 casework priority to the FCA here; no instrument or published guidance we can cite states one.

09 · WHERE WARRANT MAPS PRIN 2A

The clause-to-field map.

The table below names the Handbook clause, the evidence the AI agent must produce per action, and the identifier under which Warrant's corpus binds that clause. One point of precision, because loose versions of this table circulate: the package schema carries no bespoke per-outcome field. There is no fair_value_assessment, no target_market_check, no communication_clarity_score. Every clause binds through the same generic path — an obligations row keyed by action_id, naming a corpus clause id with a compliance status — with the regime-level roll-up in coverage_by_regime["fca_consumer_duty_ai"]. The third column below is therefore the corpus clause id, not a field name.

PRIN 2A clause What AI must evidence Corpus clause id (bound in obligations)
PRIN 2.1.1R · Principle 12 · good outcomes Every retail-facing decision, with the authorisation judgement written out. fca_consumer_duty.prin_12
2A.3 · products and services Target-market alignment per recommendation. fca_consumer_duty.outcome_products_and_services
2A.4 · price and value Price-vs-benefit assessment per offer. fca_consumer_duty.outcome_price_and_value
2A.5 · consumer understanding Communication-clarity audit per output. fca_consumer_duty.outcome_consumer_understanding
2A.6 · consumer support Escalation path and human-oversight judgement. fca_consumer_duty.outcome_consumer_support
2A.9 · monitoring Outcomes-review trail per cohort. no corpus clause — binds only at regime level, coverage_by_regime
2A.2.1R · good faith Customer-interest orientation per decision. fca_consumer_duty.prin_2a_cross_cutting_good_faith
2A.2.8R · foreseeable harm Harm-avoidance assessment per action. fca_consumer_duty.prin_2a_cross_cutting_avoid_harm
2A.2.14R · enable objectives Alternatives considered per recommendation. fca_consumer_duty.prin_2a_cross_cutting_objectives
FG22/5 § 10.10 + 2A.8.3R + COCON Governing-body report and individual conduct. fca_consumer_duty.smcr_accountability

The mapping is reversible. Given a supervisor's question on a specific clause, the firm filters the obligation rows on that clause id and gets the actions that engaged it. Given a specific customer case, the firm reads the action's obligation rows and gets the bound clauses. Either direction is one query against the evidence package. The 2A.9 row is the honest gap: outcomes monitoring binds at regime level only, so a per-decision claim against PRIN 2A.9 is not something a current package can carry.

10 · THE DISCLOSURE CLOCK

How far back an examination reaches.

Start with what this section does not say. There is no single Handbook rule setting a Consumer Duty evidence-retention floor, and DEPP 6.5.4G is not one: DEPP 6.5.4G concerns the apportionment of a financial penalty between separate and distinct areas of misconduct. Earlier copy on this page attributed a six-year retention obligation to it. That attribution was wrong and is withdrawn. Retention for Consumer Duty evidence is set by the sectoral record-keeping rules that apply to the firm's own business, which differ by sourcebook, and Warrant does not name a pinpoint here that it has not read.

What can be stated from the public record is the horizon an examination actually reaches, and it is long. The FCA Final Notice against TSB Bank plc, dated 9 October 2024, ran on conduct beginning 25 June 2014: a decade from the earliest conduct in the relevant period to the notice, on a matter the firm had already remediated. Set that against a product lifetime and the arithmetic is the point. A 30-year mortgage, a 25-year life policy, a workplace pension with a 40-year accumulation and a 30-year decumulation phase — each has decisions inside it that a later examination may reach, and the look-back does not restart because the firm changed observability vendors. An AI agent that adjudicates pricing, communications, or support on any of these books needs an evidence record that survives the product, not the log-retention setting.

Standard observability does not survive that horizon. Application logs rotate at 30 to 90 days. Cloud-provider audit trails rotate at 1 to 3 years on default settings. Even long-retention archive tiers run on the order of 7 to 10 years. None of these match the lifetime of a long-cycle retail product. The structural gap is real and growing.

The Warrant evidence package closes the gap by making retrievability a mathematical property rather than an infrastructure property. The package is independently verifiable without contacting Warrant: the retention of the underlying file is the firm's choice, but the verification of the file is independent of any retention decision the firm makes. Across a thirty-year product the firm's standard observability stack will rotate dozens of times; the verifiable package will not.

That is the line the regulator-grade evidence stack draws. PRIN 2A.9.8R requires the firm to monitor outcomes regularly, and PRIN 2A.9.9R requires the monitoring to let the firm determine, at minimum, whether customers got products designed for their needs, fair value, and the information to decide. Neither obligation is satisfied by data that has rotated. The answer does not depend on finding a retention rule with a number in it: an evidence record the firm controls, and that a supervisor can verify independently without contacting Warrant, outlives the retention decision either way. The artefact is the answer to the disclosure clock.

11 · FAQ

Questions a CCO and an SMF holder ask first.

Does PRIN 2A apply to me if i am not UK-domiciled?

PRIN 2A binds every firm authorised by the FCA, irrespective of group domicile. A non-UK parent operating through a UK-authorised subsidiary, branch, or appointed representative is in scope through that authorised entity. PRIN 2A.1.14G addresses obligations on firms in a product's distribution chain, but the duty attaches to the authorised firm: an unauthorised group entity does not itself become bound by participating.

Does an AI agent making a recommendation count as "consumer support"?

It depends which chain the agent sits in. PRIN 2A.6.2R(1) requires the firm to design and deliver support that meets the needs of retail customers, including those with characteristics of vulnerability — so an agent that is, mediates, or replaces the support channel is inside PRIN 2A.6. An agent that makes a recommendation may instead engage the products-and-services outcome (PRIN 2A.3) and consumer understanding (PRIN 2A.5). Either way the firm cannot offload the duty to the model vendor; it travels with the FCA-authorised firm that operates the channel.

What is the difference between PRIN 2A and the original eleven Principles for Businesses?

Principle 12 raises the standard above Principle 6 (treating customers fairly). PRIN 2A is the Handbook chapter that operationalises Principle 12 into four outcomes, three cross-cutting rules, and a continuous outcomes-monitoring obligation. The shift is from process compliance to outcomes compliance. A firm that satisfied Principle 6 by following a documented process can fail PRIN 2A by producing the wrong outcome.

How long must i retain Consumer Duty evidence?

PRIN 2A sets no retention period, and no single Handbook rule sets a Consumer Duty retention floor — the applicable period comes from the record-keeping rules of the sourcebook governing the firm's own business, so it differs by firm. Warrant does not name a pinpoint it has not read. What is on the public record is how far an examination reaches: the FCA Final Notice against TSB Bank plc of 9 October 2024 ran on conduct from 25 June 2014, a decade earlier. For a 30-year mortgage book, evidence that rotates at 90 days answers nothing.

Does the SMF have personal liability for an AI's decision?

There is no "Senior Manager assigned Consumer Duty" — instrument FCA 2022/31 created no Duty-specific prescribed responsibility. Exposure runs two ways instead. The individual Conduct Rules bind the senior manager directly: COCON 2.1.6R, inserted by the same instrument, reads "Rule 6: You must act to deliver good outcomes for retail customers." And a senior manager holding an affected prescribed responsibility carries the duty of responsibility under FSMA 2000 section 66A, where the reasonable steps in question are the senior manager's own. Where harm follows an AI-driven decision and the firm cannot evidence the chain, there is nothing to answer with.

What does "fair value" mean for an AI-determined price?

PRIN 2A.4.1R(2) defines it: a product provides fair value where the amount paid is reasonable relative to the benefits of the product. PRIN 2A.4.2R then requires a manufacturer to ensure its products provide fair value to retail customers. For an AI-determined price the firm must evidence a fair value assessment that captures the inputs to the price, the customer benefit considered, and the residual customer-outcome risk. The assessment is per cohort, per product, and reviewable per decision; a one-time assessment at product-launch time does not satisfy the ongoing duty.

Can a Datadog dashboard satisfy the monitoring obligation?

No. Operational dashboards measure system uptime and latency, not retail outcomes. PRIN 2A.9.8R requires the firm to regularly monitor the outcomes retail customers receive from its products, its communications and its customer support, and PRIN 2A.9.9R requires the monitoring to let the firm determine, at minimum, whether customers were sold products designed for their needs, whether those products provide fair value, and whether customers were equipped to decide. Standard observability rotates at 30 to 90 days; the Consumer Duty horizon runs in years. The monitoring obligation depends on a per-decision evidence trail the firm can retrieve long after the underlying observability data has rotated.

What is the connection between PRIN 2A and the EU AI Act?

Both regimes reach the same AI agent through different doors. The EU AI Act binds the high-risk AI system through Article 12 logging and Article 13 transparency. PRIN 2A binds the FCA-authorised firm through outcomes evidence per retail decision. A single Warrant evidence package can satisfy both regimes for a cross-border deployment, because the per-action shape that satisfies Article 12 is the per-action shape that satisfies PRIN 2A.

12 · READ THE SOURCE

Read the source directly.

Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. Every quotation of PRIN, COCON and DEPP on this page was read on 2026-08-06 against instrument FCA 2022/31 (the Consumer Duty Instrument 2022, 68 pp), which inserted PRIN 2A and COCON Rule 6; the PS22/9 and FG22/5 quotations were read against those documents as published. Where a quotation is shortened, an ellipsis marks it. Where this page states a reading rather than a rule, it says so. Rule text is quoted as made by FCA 2022/31 and has not been re-checked for later amendment beyond the Handbook's current-version dates recorded on 2026-08-06.