Hatch resource banner image for How to create a vulnerable customers policy

How to create a vulnerable customers policy

Ensure your business treats every client fairly by establishing a clear framework to identify and support those in vulnerable circumstances.

To create an effective Vulnerable Customers policy, you must establish a clear framework for identifying clients who may be at risk of harm and document the specific actions your business will take to ensure they receive a fair outcome. This policy is not just a "box-ticking" exercise; it is a live document that guides how you interact with people during some of their most difficult moments, ensuring your service remains accessible and supportive to everyone.

Why this policy is essential

In the UK, particularly within financial services, the Financial Conduct Authority (FCA) expects firms to prioritise the needs of vulnerable customers. A person is considered "vulnerable" if, due to their personal circumstances, they are especially susceptible to harm—particularly when a firm is not acting with appropriate levels of care. Having a formal policy ensures that your business provides a consistent, empathetic, and legally compliant service to all.

Step 1: Define the drivers of vulnerability

Your policy should start by defining what vulnerability looks like. The FCA identifies four key "drivers" that can increase the risk of vulnerability. Including these in your policy helps you and your staff know what to look out for:

Driver Examples
Health Physical disabilities, chronic illness, or mental health conditions.
Life Events Bereavement, relationship breakdown, or caring responsibilities.
Resilience Low or erratic income, high debt, or lack of financial "buffer."
Capability Low literacy/numeracy skills or lack of digital savvy.

Step 2: Outline the identification process

Explain how your business will proactively identify these customers. This usually involves "active listening" during conversations. Your policy should encourage staff to look for "red flags," such as a customer mentioning a recent hospital stay, sounding confused, or requesting information in a different format.

Step 3: Detail the support and "reasonable adjustments"

This is the core of your policy. What will you actually do when a vulnerable customer is identified? Examples include:

  • Allowing more time for meetings or phone calls.
  • Providing documents in large print or plain English.
  • Allowing a friend or family member to be present during discussions.
  • Offering a "breathing space" period before a customer has to make a significant decision.

Step 4: Address data protection and consent

Recording that a customer is "vulnerable" involves handling sensitive personal data. Your policy must state that you will ask for explicit consent before recording any health-related information on your systems. You must also explain how this data is stored securely, in line with UK GDPR requirements.

Tip: Use the "TEXAS" model for handling disclosures: Thank the customer, Explain how the info will be used, eXplicit consent, Ask questions, Signpost to help.

Step 5: Training and review

Finally, state how often you will train yourself (and any staff) on these procedures and how often the policy will be reviewed. At a minimum, you should review the policy annually to ensure it still meets the latest regulatory standards and reflects the actual needs of your client base.

Created by hatch. • Updated on May 14, 2026