Compliance Training in the UK: FCA, HSE, and ICO: What Behaviour Change Actually Looks Like

Three UK regulators. Three enforcement frameworks. One consistent finding across all of them: training that produces a certificate does not prevent the violation that produces the fine. In 2026, the regulatory bar for what counts as adequate UK compliance training has moved. Completion records are no longer enough.


1. What UK Regulators Actually Cite and Why Training Records Don’t Stop It

UK regulators do not penalise organisations for low compliance awareness. They penalise them for the behaviour that violates the standard.

The HSE cites the unsafe act on the shop floor. The ICO cites the data breach caused by an employee clicking a phishing link. The FCA cites the adviser who did not disclose a conflict of interest. In every case, the organisation had a training record. The behaviour happened anyway.

HSE fines in a single financial year average court fine £150,000 per case

FCA fine to Metro Bank in November 2024 for AML monitoring failures

of ICO data breaches caused by human error people who had, in most cases, completed data protection training

FCA-regulated firms now subject to non-financial misconduct rules from September 2026

Key Distinction

27% of ICO-reported data breaches are caused by human error. Most of those individuals completed data protection training. The training covered the rule. It did not practise the specific daily decision where the breach occurs. That is a design failure, not a coverage failure.


2. Three Regulators. Three Frameworks. One Workforce.

Most UK enterprises manage obligations across all three primary compliance regulators simultaneously. Each has different enforcement powers, different training expectations, and different consequences for getting it wrong.

HSE — Health and Safety Executive

Enforces the Health and Safety at Work Act 1974. Requires risk assessment, safe systems of work, documented training, and incident reporting. Can issue improvement notices, prohibition notices, and prosecution. Average court fine: £150,000. Sectors most exposed: manufacturing, construction, logistics, healthcare.

Annual refresh recommended · Role-specific risk training required

ICO — Information Commissioner’s Office

Enforces UK GDPR and the Data Protection Act 2018. Expects role-appropriate data protection training with documented evidence of completion. Can issue fines up to £17.5 million or 4% of global turnover for serious violations. Enforcement notices require remediation and evidence of sustained improvement. Human error remains the leading cause of breaches.

Annual refresher recommended · Role-based training expected · Documentation required for audit

FCA — Financial Conduct Authority

Regulates UK financial services firms. Requires AML training every 24 months, conduct training under SM&CR, and from September 2026, non-financial misconduct training (bullying, harassment, violence) as a COCON obligation for approximately 37,000 firms. Personal liability for senior managers under SM&CR means training failures can carry individual consequences — not just firm-level penalties.

AML: every 24 months · SM&CR conduct: ongoing · NFM: mandatory from September 2026


3. What Has Changed in 2026, and What UK Enterprises Must Act On Now

The UK compliance landscape has shifted materially in 2025–2026. Several changes carry direct training implications that most organisations have not yet fully addressed.

ChangeIn ForceTraining Implication
Failure to Prevent Fraud offenceSeptember 2025Employees must be trained on fraud risks, reporting obligations, and personal exposure. Organisations without documented training face greater prosecution risk.
FCA non-financial misconduct — COCON 1.1.7FR1 September 2026Bullying, harassment, and violence are now FCA conduct breaches for ~37,000 firms. Awareness training is not sufficient — behaviour-based scenario training is required.
Crime and Policing Bill — expanded senior executive liabilityExpected H1 2026Senior individuals can face criminal liability for offences they consented to, connived in, or negligently allowed. Governance and oversight training for senior managers becomes a personal risk issue.
ICO enforcement — third-party processor accountabilityActive and increasingOrganisations are liable for breaches at sub-processors where due diligence was inadequate. Vendor management and data handling training must extend to procurement and contract roles.
UK Anti-Corruption Plan 2025 — more assertive enforcementActive
Bribery Act and Failure to Prevent Tax Evasion offences being enforced more actively. Training documentation now matters at prosecution stage, not just audit stage.

“From September 2026, harassment is a regulatory compliance issue under FCA rules not just an HR matter. The distinction between those two framings is significant. One requires a policy. The other requires evidenced training that changes behaviour. Many FCA-regulated firms have the first. Far fewer have the second.”


4. What Behaviour-Based UK Compliance Training Looks Like

Behaviour-based compliance training starts from the specific situations where the violation occurs not from the regulatory text that describes what should not happen.

For HSE, that means scenario design built around the moments where workers make the unsafe choice: the shortcut when time is short, the PPE removed because it is uncomfortable, the maintenance task skipped because the production schedule is tight.

For ICO, it means scenarios built around the daily data handling decisions where breaches originate: clicking a link in a convincing phishing email, sharing a file with an unintended recipient, accessing patient or customer records beyond the minimum necessary.

For FCA, the design differs by population. AML training must practise the suspicious transaction recognition decisions that compliance officers and client-facing staff make under time pressure. Non-financial misconduct training must put managers in the specific interpersonal situations where harassment most commonly occurs and goes unreported.

  1. Start from incident data, not the regulatory text. Which specific behaviours are producing your current near-misses, complaints, and enforcement risk? Design starts there.
  2. Separate populations before separating topics. A warehouse operative’s HSE exposure is different from a line manager’s. An FCA-regulated adviser’s data obligations differ from a back-office analyst’s. Role-based design is what prevents the coverage gaps regulators find.
  3. Build scenarios around the decision moment, not the rule. The employee who causes the breach usually knows the rule. They made a situational decision that overrode it. Training must practise that specific decision — under the same pressures that produce it in real work.
  4. Reinforce at intervals, not annually. Research shows 80% of information is forgotten within 30 days without reinforcement. Annual compliance modules produce the decay curve that regulators find at the investigation stage.
  5. Document capability change, not just completion. Regulators are increasingly asking not just whether training occurred, but whether it produced a measurable change in the behaviour it was designed to address.

5. The Measurement Standard UK Regulators Are Moving Toward

The ICO, HSE, and FCA are each, in different ways, moving toward an expectation that training produces demonstrable change not just documented coverage.

The ICO’s guidance explicitly identifies staff training as a key safeguard and expects it to be “appropriate to job role” which implies assessment of whether the training is changing the specific data handling behaviours relevant to each population.

The HSE’s enforcement pattern shows consistent focus on the gap between training records and workplace behaviour particularly in industries with recurring violations in trained areas. Their improvement notices regularly require organisations to demonstrate what has changed in practice, not just what is now documented.

The FCA’s SM&CR framework already requires Training and Competence evidence for regulated individuals not just completion records, but evidence of ongoing competence in the specific conduct areas relevant to each role. The non-financial misconduct expansion from September 2026 extends that expectation to conduct around workplace behaviour.

What the measurement framework needs to cover

RegulatorWhat to MeasureHow to Demonstrate It
HSEIncident rates in trained cohorts vs baselineRIDDOR data, near-miss log, site inspection findings
ICOHuman-error breach rate by department vs baselineIncident log, phishing simulation data, SAR handling accuracy
FCAT&C competence evidence; conduct complaint ratesAssessment records, call QA data, COCON breach log

None of these measurement frameworks can be built after the enforcement action. They must be designed before the training launches because the baseline data must exist before the intervention to make the comparison meaningful.


In Summary

UK compliance training in 2026 faces a higher standard from all three primary regulators. The FCA’s non-financial misconduct expansion, the Failure to Prevent Fraud offence, expanded senior executive personal liability, and ICO enforcement against third-party processor failures all require training designed around specific behaviours not awareness modules that cover the regulatory text.

The organisations that will demonstrate adequate compliance procedures when regulators look closely are not the ones with the most training records. They are the ones whose training was designed from the behaviour that produces violations, delivered to the specific populations where those violations occur, reinforced at intervals rather than annually, and measured against the incident and complaint data regulators actually examine.


Frequently Asked Questions

Q1

What are the main compliance training requirements for UK enterprises in 2026?

HSE requires annual health and safety training with documented risk assessments; the ICO recommends annual UK GDPR refreshers with role-appropriate data protection training; FCA-regulated firms must deliver AML training every 24 months. From September 2026, FCA non-financial misconduct rules extend to approximately 37,000 firms, requiring formal training on bullying and harassment as regulatory compliance.


Q2

Why does UK compliance training fail to prevent enforcement action?

Because regulators cite the behaviour, not the training record. The HSE cites the unsafe act. The ICO cites the data breach. The FCA cites the conduct failure. Completion records demonstrate that training occurred — not that it changed what employees do. The 27% of ICO data breaches caused by human error represent people who had, in most cases, completed data protection training.


Q3

What does the FCA’s non-financial misconduct expansion mean for training in 2026?

From 1 September 2026, bullying, harassment, and violence fall within COCON for all FCA-regulated firms — not just banks. Approximately 37,000 firms are affected. Harassment is now a regulatory compliance issue with potential personal liability under SM&CR. Firms must upgrade from awareness training to behaviour-based training that addresses the specific conduct situations that produce COCON breaches.


Q4

How does the Failure to Prevent Fraud offence affect UK compliance training?

In force since September 2025, this offence means organisations can be prosecuted if an employee commits fraud for the organisation’s benefit and the organisation cannot demonstrate adequate fraud prevention procedures. Training is a core element of those procedures. Organisations that have not trained employees on fraud risks and reporting obligations are materially more vulnerable as enforcement gathers pace in 2026.


Q5

What is the right design approach for UK compliance training that satisfies HSE, ICO, and FCA simultaneously?

Role-based design that separates populations before separating topics. Each regulator’s expectations apply differently by role. Generic all-staff training produces the coverage gaps that enforcement actions consistently find. Role-specific, scenario-based training that documents completion and capability change is what regulators are increasingly expecting to see.


Q6

Has Qquench designed compliance training for UK enterprise clients?

Yes, with 25+ years and 1,256+ hours of eLearning delivered for regulated enterprises globally, including UK financial services, healthcare, and manufacturing clients, Qquench designs compliance training starting from the specific regulatory obligations and enforcement patterns relevant to each client’s sector. Programmes are designed to produce behaviour change in the specific situations where violations most commonly occur.


Qquench Specialists

Qquench Specialists is the collective voice of Qquench’s learning design and AI practice. With 25+ years delivering award-winning eLearning for regulated enterprises across the UK, Europe, and globally, we write from practice, not position papers.