IntegrityAI

Insights

Vulnerable customers

Vulnerable clients, the distribution chain, and what a file actually needs to prove

The FCA has not rewritten its guidance on vulnerable customers. It has done something that changes more for a file checker: it has told firms, in a quiet July 2026 update to FG21/1, to stop reading it as a standalone document and start reading it through the Consumer Duty instead. Combined with a joint statement from the FCA and the Information Commissioner on what vulnerability data firms should hold, and a live consultation on who owns the response across a distribution chain, the practical question a file review needs to answer has moved.

FG21/1 was last updated on 22 July 2026 with a short note: the guidance contains references to historical publications that pre-date the Consumer Duty, and firms should look to the FCA’s Consumer Duty material for its current expectations on management information and good outcomes. The guidance itself has not changed. What has changed is the frame it sits inside. Vulnerability is no longer a compliance topic that happens to interact with the Duty. It is a Consumer Duty topic that FG21/1 supplies the vocabulary for.

Two documents that matter more than the headline

Two other 2026 publications do more work than that reframing alone.

The first is the joint FCA and ICO statement, published 27 March 2026 and updated in July, on vulnerability-related data. It sits at a genuine tension point: the Consumer Duty expects firms to identify and respond to vulnerability, which usually means recording something about it, while data protection law expects firms to record only what is necessary and proportionate. The statement does not resolve that tension with a formula. It tells firms to decide, deliberately, what they need to record to meet their Duty obligations, and to be able to explain that decision, rather than defaulting to recording everything a client discloses or, in the other direction, recording nothing for fear of getting data handling wrong. It also says something that reaches beyond any one firm’s own file: manufacturers and distributors are expected to share vulnerability-relevant information across a distribution chain where doing so is necessary to deliver good outcomes, and that a firm’s own compliance does not stop at the point a client’s information passes to another firm in the chain.

The second is CP26/23, the FCA’s consultation on scope and proportionality under the Consumer Duty, published 29 June 2026 and running to 18 September 2026. Buried inside a much broader consultation on wholesale scope and territorial reach is a specific proposal on vulnerability: new guidance to make clear that a firm’s responsibility for identifying and responding to vulnerability depends on its role in the chain, its activities, and the risk of harm involved. In plain terms, the FCA is proposing to say explicitly that an adviser at the point of sale, a platform provider, and a product manufacturer do not carry identical obligations for the same client, and that firms have been asking for that clarity because the current position leaves the allocation ambiguous.

For an advice firm, that is good news in outline and a live problem in the file. If responsibility genuinely varies by role, a file review needs to be able to show what this firm did with what it knew, and separately, what it received from or passed to anyone else in the chain, rather than treating vulnerability as a single tick answered once at the fact-find stage.

The gap the FCA keeps finding

Running underneath both publications is a finding the regulator has repeated through 2026: firms have the frameworks, but outcomes for vulnerable customers are not closing the gap the frameworks are meant to close. Industry research published mid-2026 put a number on the disconnect that will be familiar to anyone who has sat through a Consumer Duty board meeting: strong majorities of firms reporting confident leadership buy-in and embedded governance, against a much smaller minority of consumers who actually believe their provider acts in their best interests. The FCA’s own July 2026 review of outcomes monitoring makes the same point in supervisory language: firms with well-documented vulnerability frameworks were still producing materially worse outcomes for vulnerable customers than for everyone else, and a generic assurance that “vulnerable customers receive extra care” is treated as evidence of a policy, not evidence of an outcome.

That is exactly the distinction a file check is built to test, and exactly where most file checks currently stop short. A fact-find that flags a vulnerability characteristic and a suitability report that makes no visible adjustment to pace, format, or content is a file that has recorded a policy input and produced no outcome evidence at all. It will pass a check that only asks “was vulnerability considered”, and it should not pass one that asks what changed as a result.

What this does not solve

Recording the right things does not, by itself, close the outcomes gap the FCA keeps describing, and no file review, human or AI-assisted, can manufacture a good outcome that the advice process itself did not produce. What a file review can do is exactly what it already does well: check, consistently and at volume, whether the adjustment the FCA is looking for is visible on the page, and point the reviewer straight at the place where it either is or is not. That is a narrower claim than “identifies vulnerable customers”, and it is the honest one. The judgement about whether an adjustment was adequate, and what proportionate data retention looks like for a given client, stays with a person who can weigh the whole file, not with a grading model reading a fact-find in isolation.

There is also a distribution chain point that a single firm’s file review cannot answer on its own. If your firm sits downstream of a platform or product manufacturer, the question CP26/23 is trying to settle, what did they know and pass to you, sits outside any file your firm holds. Where that matters, it belongs in the firm’s wider Consumer Duty governance, not in a file-by-file check.

Where this leaves a firm

Four questions worth putting to a back book, and to new business, before the CP26/23 consultation closes on 18 September 2026:

  1. When a vulnerability characteristic is recorded, does the file show what changed in the advice process as a result?
  2. Can the firm explain, for the data it holds on vulnerability, why it holds that much and no more?
  3. Where the firm sits in a distribution chain, does it know what it is expected to receive from, or pass to, the other firms in it?
  4. If a supervisor asked for outcome evidence rather than policy evidence, could the file review produce it?

A firm that can answer all four is describing an advice process that closes the gap the FCA keeps finding. A firm that can only answer the first two has a governance framework and not yet the outcome evidence to go with it.

A note on this piece

This is commentary, not regulatory advice, and it does not constitute compliance sign-off for any firm or file. Descriptions of FG21/1, the joint FCA/ICO statement and CP26/23 are our reading of what has been published; firms should refer to the FCA’s and ICO’s own materials and take their own advice before acting. If you would like to talk about how vulnerability findings show up inside Frank’s file review output, we are happy to have that conversation.