When the Financial Conduct Authority reviews a firm's complaint logs, supervisors do not simply check whether an individual client received a settlement within eight weeks. Regulators look for the exact point where compliance leadership identified an isolated complaint as evidence of an underlying operational failure and what concrete remediations followed. For mid-sized investment managers, Compliance Consultant structures corrective action plans that address both the root cause analysis obligations in DISP App 3.4 and the proactive harm remediation requirements under PRIN 2A.10. By standardising reporting through an established governance framework, compliance officers can systematically turn recurring grievances into actionable operational changes that satisfy regulatory scrutiny. When determining resource allocation for these governance frameworks, firms often weigh internal builds against external models, as detailed in our guide to evaluating FCA compliance models for mid-sized UK investment firms.
The disconnect between resolving complaints and fixing systemic causes
Closing an individual grievance under DISP 1.4.1R by issuing an apology or a discretionary goodwill payment resolves the immediate customer dispute. It does nothing to satisfy the regulator that your operational risks are under control. The FCA increasingly views isolated payouts without aggregate trend analysis as a significant indicator of poor governance.
Supervisors expect mid-sized investment firms to separate the surface symptoms of a customer dispute from its underlying operational cause. A client complaining about unexpected portfolio drawdowns might appear to raise an investment performance dispute, which falls outside standard compensable grounds if the portfolio remained within agreed mandate parameters. If root cause analysis reveals that the initial onboarding workflow miscategorised the client's risk tolerance, the issue transforms immediately into a systemic suitability failure.
When compliance teams treat complaints solely as casework queues rather than risk indicators, recurring issues remain undetected. This creates acute exposure during regulatory supervisory visits, where firms must prove how customer feedback directly alters operational controls.

Investigating the root cause under DISP App 3.4
To construct an acceptable corrective action plan, an investment firm must map the issue against formal regulatory standards. Under DISP 1.3.3R, regulated firms must maintain management controls and take reasonable steps to identify and remedy any recurring or systemic problems in their sales practices and operational delivery.
The analytical baseline established in DISP App 3.4 Root cause analysis outlines six specific evidential factors that firms must assess during an investigation:
- The direct concerns raised by complainants at the point of sale and in subsequent interactions.
- The documented reasons behind rejected customer claims and complaints.
- The firm's formal, written sales practices and operational policies in effect at the time.
- The actual sales and execution practices carried out, verified through call recordings, suitability reports, and staff incentive schemes.
- Relevant regulatory findings, notices, and thematic reviews published by the FCA.
- Previous determinations and case summaries published by the Financial Ombudsman Service (FOS).
Reconciling stated policies with front-line execution
A common finding during regulatory audits is the variance between documented compliance policies and day-to-day employee conduct. Under DISP App 3.4.1(4), compliance teams must examine the evidentiary trail of actual practice.
For wealth managers and brokerages, this requires cross-referencing audio records of advisory calls against final suitability reports. If commercial advisers routinely use non-standard explanations to describe fee structures, liquidity horizons, or volatility bands, the policy document is irrelevant to the FCA's assessment of root cause. The operational failure exists in training, supervision, and front-line quality control.
Incorporating external regulatory signals
A robust investigation does not evaluate internal metrics in isolation. Compliance officers must incorporate broader industry trends into their internal causal analysis.
If the Financial Ombudsman Service or the FCA issues guidance detailing common failures in wealth transfer timelines or discretionary mandate disclosures, compliance functions must evaluate their historical files against those findings. Demonstrating that your compliance function updated its risk register in response to external ombudsman determinations shows supervisors that the firm operates an active, perceptive compliance program.
Evaluating foreseeable harm under PRIN 2A.10
The introduction of the Consumer Duty altered the regulatory threshold for complaint remediation. Under PRIN 2A.10, the FCA mandates that firms take proactive steps to identify and rectify foreseeable harm caused to retail customers, regardless of whether those customers have formally registered a dispute.
If an investment firm identifies that an administrative calculation error, a misleading disclosure, or an unsuitable distribution channel affected clients, compliance cannot wait for complaints to arrive. The firm must review historical records and initiate firm-led redress.
+---------------------------------------------------------------------------------------+
| FCA REDRESS TRIGGER MATRIX |
+--------------------------+------------------------------+-----------------------------+
| Identification Vector | Regulatory Obligation | Operational Mandate |
+--------------------------+------------------------------+-----------------------------+
| Single Inbound Complaint | DISP 1.4.1R | Diligent, prompt resolution |
| Systemic Process Defect | DISP 1.3.3R & DISP App 3.4 | Root cause rectification |
| Broader Customer Harm | PRIN 2A.10 & FG26/2 | Proactive cohort redress |
+--------------------------+------------------------------+-----------------------------+
As detailed in the FCA's FG26/2: Good and Poor Practice on identifying and rectifying harm, proactive exercises must define the affected cohort accurately. Regulators expect firms to examine adjacent product categories, past time horizons, and related client segments to determine whether identical systemic weaknesses created unvoiced customer detriment elsewhere.
For MiFID investment firms, specific provisions apply. When foreseeable harm is identified, DISP 1.1A.20R requires the firm to investigate the circumstances competently, diligently, and impartially, obtaining additional information where necessary. It demands an objective assessment of what remedial action or financial redress is appropriate, and whether another party in the distribution chain shares responsibility.

Structuring the corrective action plan
A corrective action plan must translate diagnostic findings into verifiable organisational change. At Compliance Consultant, we apply an established implementation methodology built around three distinct stages: engage, execute, embed.
- Engage: Establish regulatory requirements before infrastructure is built, securing executive alignment and mapping the necessary policy adjustments.
- Execute: Drive process and organisational change in parallel with technology development, updating controls and remediating affected clients.
- Embed: Integrate compliance into real-world operations through testing and scaling, confirming the updated controls prevent issue recurrence.
Stage 1: Engage through targeted diagnostic testing
The engage phase prevents firms from rolling out untested operational changes across the entire organisation at once. Compliance leadership selects a sample department, business line, or client portfolio to test revised workflows and draft disclosures.
During this stage, the team maps the exact regulatory deficiencies identified under DISP App 3.4 to specific operational bottlenecks. If suitability letters lacked clarity regarding compounding management charges, compliance works alongside the advisory desk to draft, evaluate, and calibrate revised reporting formats within a controlled test group.
Stage 2: Execute remediation and process overhauls
Execution requires two simultaneous workstreams: delivering restitution to affected clients and deploying updated operational workflows.
Restitution must follow clear actuarial or financial methodologies that return the customer to the financial position they would have occupied had the breach not occurred. Under FG26/2, customer communications must set out precisely what went wrong, what remediation is offered, and the steps the client should take if they contest the calculation.
In parallel, internal controls receive mandatory updates. Compliance managers revise the operational risk register, adjust procedural manuals, and roll out mandatory staff training designed to address the specific root causes uncovered during the investigation.
Stage 3: Embed controls across the enterprise
Embedding turns a temporary project into enduring business conduct. Once tested in the target department, the firm deploys the verified processes across all operating divisions.
During this final phase, the compliance monitoring plan incorporates targeted testing intervals, reviewing sample transactions at 30, 60, and 90 days post-implementation. This active monitoring confirms that staff have adopted the updated controls and verifies that complaint volumes related to the specific failure point have ceased.
Evidencing board oversight and MI reporting
Regulatory supervision focuses heavily on management information (MI). Under the FCA's update on Complaints and root cause analysis: good practice and areas for improvement, supervisors reiterated that boards must actively interrogate complaints data rather than passively receive high-level metrics.
A high-level dashboard indicating ten complaints received and eight resolved is considered inadequate by modern supervisory standards. The board pack must present granular data showing:
- Categorisation of complaints by product line, distribution channel, and specific operational failure.
- Trend analysis highlighting emerging themes across consecutive quarters.
- Outcomes for different customer groups, with dedicated tracking for clients with characteristics of vulnerability.
- Documented progress of active corrective action plans, including target remediation deadlines and post-implementation review findings.
- Clear audit trails showing board challenges, executive decisions, and remediation budgets.
The broader implications of these supervisory expectations are examined in our analysis of the state of mid-market FCA compliance in 2026.
+---------------------------------------------------------------------------------------+
| MANAGEMENT INFORMATION AUDIT |
+-----------------------+----------------------------------+----------------------------+
| Metric Category | Inadequate Board Reporting | FCA Good Practice Standard |
+-----------------------+----------------------------------+----------------------------+
| Volume & Aging | Total complaints received/closed | RCA categorisation by root |
| | within 8 weeks. | operational breakdown. |
+-----------------------+----------------------------------+----------------------------+
| Vulnerability Metrics | Binary flag of vulnerable | Specific outcome tracking |
| | status without outcome data. | across vulnerable cohorts. |
+-----------------------+----------------------------------+----------------------------+
| Remediation Tracking | Total financial settlement sums | Timelines, process fixes, |
| | paid out to complainants. | and second-line sign-offs. |
+-----------------------+----------------------------------+----------------------------+
Mid-sized firms often find their internal compliance managers, typically commanding a £60,000 base salary in the UK, stretched between daily advisory queries, transaction monitoring, and regulatory returns. They lack the dedicated capacity to build complex root cause analysis and MI reporting frameworks from scratch.

Our Silver retainer (£895 per month on quarterly billing, or £795 per month billed annually at £9,540 per year) directly resolves this capacity gap. It equips firms with our complete digital template suite, including the standalone Complaints RCA & MI Reporting Template (retailing individually at £149), alongside eight hours of monthly advisory support and documented quarterly reviews.
For firms requiring direct governance delivery, our Gold retainer (£1,495 per month quarterly, or £1,345 per month billed annually at £16,140 per year) delivers board-ready reporting drafted directly for your executive committee, an annual compliance monitoring programme, a 4-hour response guarantee, and direct mobile access to a dedicated senior consultant.
What most compliance teams get wrong
Even experienced compliance leaders make recurring errors when responding to complex complaint trends. Recognising these patterns helps firms avoid supervisory interventions and Section 166 skilled person reviews.
Confusing settlement with operational closure
The most frequent error in mid-market firms is treating individual complaint payouts as the conclusion of the compliance event. Under pressure to meet the eight-week response deadline set out in DISP, handlers calculate a settlement, draft a final response letter, and log the file as closed.
If that complaint was caused by an ambiguous fee schedule or a software calculation glitch, closing the case file leaves the firm exposed. Every day that passes without a corrective action plan expands the cohort of affected customers and increases potential financial liabilities under PRIN 2A.10.
Arbitrarily narrowing the redress boundary
When a firm uncovers a systemic operational defect, internal stakeholders often attempt to narrow the remediation boundary to minimise commercial costs. They might propose limiting the redress exercise strictly to customers who invested during a specific three-month window or those who purchased one precise share class.
The FCA's finalised guidance in FG26/2 explicitly cautions against artificial limitations. If the root cause analysis identifies that the core issue was a vague risk disclosure in a marketing template, that template may have been adapted across multiple product lines over several years. Regulators expect firms to test adjacent products, communication channels, and extended time periods to determine the true scope of consumer detriment.
Operationalising corrective action plans
Establishing an FCA-compliant complaint handling and root cause analysis architecture requires clear documentation, disciplined governance, and regular independent oversight. A compliant corrective action plan does not merely resolve an immediate grievance; it isolates the operational vulnerability, quantifies potential customer harm across the wider client base, and embeds lasting procedural fixes validated by the board.
If your firm is navigating an increase in customer disputes, upgrading its governance to satisfy the Consumer Duty, or seeking to replace fragile internal spreadsheets with an institutional reporting structure, expert support provides immediate certainty.
To evaluate your firm's current root cause analysis framework, book a free 30-minute discovery call with our advisory team. Visit Compliance Consultant or contact us directly at info@complianceconsultant.org to determine whether our Silver or Gold retainers fit your operational requirements.