Financial Services: CCO and Internal Audit

Know what regulators will find before they arrive

Conduct and culture risk monitoring for Chief Compliance Officers and Internal Audit. Regulators are reading public employee reviews. Are you?

The conduct intelligence gap

Regulators including the FCA, PRA, SEC, and Federal Reserve increasingly assess culture as a prudential risk, not just a compliance matter. Non-financial misconduct is now explicitly a fitness and propriety concern under SMCR.

But culture is measured through instruments the firm controls: engagement surveys, speak-up lines, HR reports. These channels capture what employees feel safe saying within organizational systems, not what they actually think.

FCA examiners interview junior staff and review public platforms to understand actual culture, not reported culture. The conditions they find, including harassment, bullying, pressure to mis-sell, and compliance shortcuts, are described publicly by employees months before any formal finding.

No existing compliance tool monitors public employee voice as a systematic conduct intelligence input.

For Chief Compliance Officers

Non-financial misconduct monitoring

The FCA has made clear that sexual harassment, bullying, and discrimination are fitness and propriety concerns under SMCR. Public employee reviews surface exactly these patterns, independently of HR-managed channels.

Regulatory examination readiness

Understand what examiners will find before they arrive. Surface management behavior patterns, compliance failures, and cultures of silence from public data, the same sources regulators increasingly use.

Independent culture intelligence

Triangulate internal speak-up data against external voice. Where internal channels show calm and public reviews show distress, there is a culture of silence, one of the highest-risk signals for regulatory scrutiny.

Consumer Duty evidence

Demonstrate that you understand the cultural and operational conditions affecting how your firm delivers for customers, with evidence from a source management cannot filter.

For Internal Audit

Independent data source

The three-lines model puts Internal Audit as the independent check on management. But audit teams still largely rely on management-provided information. Public employee voice is structurally independent. Staff post when there's no organizational filter and no fear of identification.

Management override risk detection

Management override is highest where culture is weakest. Where public reviews describe pressure to bypass controls, suppress reporting, or cut compliance corners, Internal Audit has a direct indicator of where to look.

Audit plan direction

Where operational failures and conduct patterns appear in public data consistently, control weaknesses are likely to exist. Use workforce intelligence to direct audit attention before formal findings.

Audit committee reporting

Provide the board and audit committee with independent assurance evidence from a source that management cannot prepare, curate, or brief against.

Regulatory drivers

United Kingdom

FCA Non-Financial Misconduct

CP23/20 and policy statement: harassment, bullying, and discrimination are fitness and propriety concerns under SMCR.

FCA Consumer Duty

Requires firms to understand the culture and operational conditions affecting customer outcomes.

Senior Managers and Certification Regime

Individual accountability for conduct. Culture failures now have named owners.

PRA Supervisory Expectations

Governance and culture as prudential risk factors, assessed through multiple data sources.

United States and International

SEC Whistleblower Program

Employees report externally when internal channels fail. Public reviews are an early indicator of what may be reported.

OCC and Federal Reserve Culture Guidance

Culture as a supervisory focus. Examiners assess whether firms understand their own cultural risk.

FINRA

Supervision and conduct standards increasingly focus on cultural conditions, not just transaction-level controls.

Basel Governance Principles and IIA Standards

International frameworks on governance and audit independence support external data as an assurance input.

See your firm the way regulators do

Request access to run an analysis on your own organization or a target firm.