Compliance Training in the UK: FCA, HSE, and ICO: What Behaviour Change Actually Looks Like
Three UK regulators. Three enforcement frameworks. One consistent finding across all of them: training that produces a certificate does not prevent the violation that produces the fine. In 2026, the regulatory bar for what counts as adequate UK compliance training has moved. Completion records are no longer enough.
1. What UK Regulators Actually Cite and Why Training Records Don’t Stop It
UK regulators do not penalise organisations for low compliance awareness. They penalise them for the behaviour that violates the standard.
The HSE cites the unsafe act on the shop floor. The ICO cites the data breach caused by an employee clicking a phishing link. The FCA cites the adviser who did not disclose a conflict of interest. In every case, the organisation had a training record. The behaviour happened anyway.
£35.8M
HSE fines in a single financial year average court fine £150,000 per case
£17M
FCA fine to Metro Bank in November 2024 for AML monitoring failures
27%
of ICO data breaches caused by human error people who had, in most cases, completed data protection training
37,000
FCA-regulated firms now subject to non-financial misconduct rules from September 2026
Key Distinction
27% of ICO-reported data breaches are caused by human error. Most of those individuals completed data protection training. The training covered the rule. It did not practise the specific daily decision where the breach occurs. That is a design failure, not a coverage failure.
2. Three Regulators. Three Frameworks. One Workforce.
Most UK enterprises manage obligations across all three primary compliance regulators simultaneously. Each has different enforcement powers, different training expectations, and different consequences for getting it wrong.
HSE — Health and Safety Executive
Enforces the Health and Safety at Work Act 1974. Requires risk assessment, safe systems of work, documented training, and incident reporting. Can issue improvement notices, prohibition notices, and prosecution. Average court fine: £150,000. Sectors most exposed: manufacturing, construction, logistics, healthcare.
Annual refresh recommended · Role-specific risk training required
ICO — Information Commissioner’s Office
Enforces UK GDPR and the Data Protection Act 2018. Expects role-appropriate data protection training with documented evidence of completion. Can issue fines up to £17.5 million or 4% of global turnover for serious violations. Enforcement notices require remediation and evidence of sustained improvement. Human error remains the leading cause of breaches.
Annual refresher recommended · Role-based training expected · Documentation required for audit
FCA — Financial Conduct Authority
Regulates UK financial services firms. Requires AML training every 24 months, conduct training under SM&CR, and from September 2026, non-financial misconduct training (bullying, harassment, violence) as a COCON obligation for approximately 37,000 firms. Personal liability for senior managers under SM&CR means training failures can carry individual consequences — not just firm-level penalties.
AML: every 24 months · SM&CR conduct: ongoing · NFM: mandatory from September 2026
3. What Has Changed in 2026, and What UK Enterprises Must Act On Now
The UK compliance landscape has shifted materially in 2025–2026. Several changes carry direct training implications that most organisations have not yet fully addressed.
| Change | In Force | Training Implication |
|---|---|---|
| Failure to Prevent Fraud offence | September 2025 | Employees must be trained on fraud risks, reporting obligations, and personal exposure. Organisations without documented training face greater prosecution risk. |
| FCA non-financial misconduct — COCON 1.1.7FR | 1 September 2026 | Bullying, harassment, and violence are now FCA conduct breaches for ~37,000 firms. Awareness training is not sufficient — behaviour-based scenario training is required. |
| Crime and Policing Bill — expanded senior executive liability | Expected H1 2026 | Senior individuals can face criminal liability for offences they consented to, connived in, or negligently allowed. Governance and oversight training for senior managers becomes a personal risk issue. |
| ICO enforcement — third-party processor accountability | Active and increasing | Organisations are liable for breaches at sub-processors where due diligence was inadequate. Vendor management and data handling training must extend to procurement and contract roles. |
| UK Anti-Corruption Plan 2025 — more assertive enforcement | Active | Bribery Act and Failure to Prevent Tax Evasion offences being enforced more actively. Training documentation now matters at prosecution stage, not just audit stage. |
“From September 2026, harassment is a regulatory compliance issue under FCA rules not just an HR matter. The distinction between those two framings is significant. One requires a policy. The other requires evidenced training that changes behaviour. Many FCA-regulated firms have the first. Far fewer have the second.”
Qquench UK Compliance Training Practice · Regulated Enterprises · 25+ Years
Before your September 2026 FCA deadline, Qquench helps UK regulated firms build behaviour-based non-financial misconduct training that satisfies COCON requirements, not awareness sessions that regulators will look past.
4. What Behaviour-Based UK Compliance Training Looks Like
Behaviour-based compliance training starts from the specific situations where the violation occurs not from the regulatory text that describes what should not happen.
For HSE, that means scenario design built around the moments where workers make the unsafe choice: the shortcut when time is short, the PPE removed because it is uncomfortable, the maintenance task skipped because the production schedule is tight.
For ICO, it means scenarios built around the daily data handling decisions where breaches originate: clicking a link in a convincing phishing email, sharing a file with an unintended recipient, accessing patient or customer records beyond the minimum necessary.
For FCA, the design differs by population. AML training must practise the suspicious transaction recognition decisions that compliance officers and client-facing staff make under time pressure. Non-financial misconduct training must put managers in the specific interpersonal situations where harassment most commonly occurs and goes unreported.
- Start from incident data, not the regulatory text. Which specific behaviours are producing your current near-misses, complaints, and enforcement risk? Design starts there.
- Separate populations before separating topics. A warehouse operative’s HSE exposure is different from a line manager’s. An FCA-regulated adviser’s data obligations differ from a back-office analyst’s. Role-based design is what prevents the coverage gaps regulators find.
- Build scenarios around the decision moment, not the rule. The employee who causes the breach usually knows the rule. They made a situational decision that overrode it. Training must practise that specific decision — under the same pressures that produce it in real work.
- Reinforce at intervals, not annually. Research shows 80% of information is forgotten within 30 days without reinforcement. Annual compliance modules produce the decay curve that regulators find at the investigation stage.
- Document capability change, not just completion. Regulators are increasingly asking not just whether training occurred, but whether it produced a measurable change in the behaviour it was designed to address.
5. The Measurement Standard UK Regulators Are Moving Toward
The ICO, HSE, and FCA are each, in different ways, moving toward an expectation that training produces demonstrable change not just documented coverage.
The ICO’s guidance explicitly identifies staff training as a key safeguard and expects it to be “appropriate to job role” which implies assessment of whether the training is changing the specific data handling behaviours relevant to each population.
The HSE’s enforcement pattern shows consistent focus on the gap between training records and workplace behaviour particularly in industries with recurring violations in trained areas. Their improvement notices regularly require organisations to demonstrate what has changed in practice, not just what is now documented.
The FCA’s SM&CR framework already requires Training and Competence evidence for regulated individuals not just completion records, but evidence of ongoing competence in the specific conduct areas relevant to each role. The non-financial misconduct expansion from September 2026 extends that expectation to conduct around workplace behaviour.
What the measurement framework needs to cover
| Regulator | What to Measure | How to Demonstrate It |
|---|---|---|
| HSE | Incident rates in trained cohorts vs baseline | RIDDOR data, near-miss log, site inspection findings |
| ICO | Human-error breach rate by department vs baseline | Incident log, phishing simulation data, SAR handling accuracy |
| FCA | T&C competence evidence; conduct complaint rates | Assessment records, call QA data, COCON breach log |
None of these measurement frameworks can be built after the enforcement action. They must be designed before the training launches because the baseline data must exist before the intervention to make the comparison meaningful.
In Summary
UK compliance training in 2026 faces a higher standard from all three primary regulators. The FCA’s non-financial misconduct expansion, the Failure to Prevent Fraud offence, expanded senior executive personal liability, and ICO enforcement against third-party processor failures all require training designed around specific behaviours not awareness modules that cover the regulatory text.
The organisations that will demonstrate adequate compliance procedures when regulators look closely are not the ones with the most training records. They are the ones whose training was designed from the behaviour that produces violations, delivered to the specific populations where those violations occur, reinforced at intervals rather than annually, and measured against the incident and complaint data regulators actually examine.
Qquench · 25+ Years · Regulated Enterprises · UK · Global
Find out whether your UK compliance training is designed to prevent the violations that FCA, HSE, and ICO are citing, or to document the coverage that regulators are increasingly looking past.
Qquench’s UK compliance training audit starts from your current enforcement exposure, your incident and complaint data, and the 2026 regulatory changes — and identifies the design gaps before the next investigation does.
Frequently Asked Questions
Q1
What are the main compliance training requirements for UK enterprises in 2026?
HSE requires annual health and safety training with documented risk assessments; the ICO recommends annual UK GDPR refreshers with role-appropriate data protection training; FCA-regulated firms must deliver AML training every 24 months. From September 2026, FCA non-financial misconduct rules extend to approximately 37,000 firms, requiring formal training on bullying and harassment as regulatory compliance.
Q2
Why does UK compliance training fail to prevent enforcement action?
Because regulators cite the behaviour, not the training record. The HSE cites the unsafe act. The ICO cites the data breach. The FCA cites the conduct failure. Completion records demonstrate that training occurred — not that it changed what employees do. The 27% of ICO data breaches caused by human error represent people who had, in most cases, completed data protection training.
Q3
What does the FCA’s non-financial misconduct expansion mean for training in 2026?
From 1 September 2026, bullying, harassment, and violence fall within COCON for all FCA-regulated firms — not just banks. Approximately 37,000 firms are affected. Harassment is now a regulatory compliance issue with potential personal liability under SM&CR. Firms must upgrade from awareness training to behaviour-based training that addresses the specific conduct situations that produce COCON breaches.
Q4
How does the Failure to Prevent Fraud offence affect UK compliance training?
In force since September 2025, this offence means organisations can be prosecuted if an employee commits fraud for the organisation’s benefit and the organisation cannot demonstrate adequate fraud prevention procedures. Training is a core element of those procedures. Organisations that have not trained employees on fraud risks and reporting obligations are materially more vulnerable as enforcement gathers pace in 2026.
Q5
What is the right design approach for UK compliance training that satisfies HSE, ICO, and FCA simultaneously?
Role-based design that separates populations before separating topics. Each regulator’s expectations apply differently by role. Generic all-staff training produces the coverage gaps that enforcement actions consistently find. Role-specific, scenario-based training that documents completion and capability change is what regulators are increasingly expecting to see.
Q6
Has Qquench designed compliance training for UK enterprise clients?
Yes, with 25+ years and 1,256+ hours of eLearning delivered for regulated enterprises globally, including UK financial services, healthcare, and manufacturing clients, Qquench designs compliance training starting from the specific regulatory obligations and enforcement patterns relevant to each client’s sector. Programmes are designed to produce behaviour change in the specific situations where violations most commonly occur.
QS
Qquench Specialists
UK Compliance Training Practice · Qquench
Qquench Specialists is the collective voice of Qquench’s learning design and AI practice. With 25+ years delivering award-winning eLearning for regulated enterprises across the UK, Europe, and globally, we write from practice, not position papers.









