Hatch resource banner image for How to manage and report on regulatory compliance

How to manage and report on regulatory compliance

Effective regulatory reporting ensures your business stays legal and operational by keeping the FCA informed of your financial health and conduct.

The most critical aspect of managing regulatory compliance is establishing a strict reporting calendar and using the FCA’s RegData system to submit your returns on time. Failure to submit reports, even if you have had no business activity, can lead to significant fines and the eventual withdrawal of your authorisation.

Understanding RegData

Once your firm is authorised by the Financial Conduct Authority (FCA), you will be granted access to RegData. This is the online portal where UK financial firms submit their regulatory data. Your specific reporting requirements are determined by the 'permissions' your business holds. Even if you are a small startup, you will likely have a set of mandatory reports that must be filed monthly, quarterly, or annually.

Create a Compliance Calendar

To avoid missing deadlines, you should build a compliance calendar that maps out every recurring requirement. Common reports include:

  • Financial Returns: These provide the FCA with a snapshot of your balance sheet, profit and loss, and capital adequacy.
  • Complaints Returns: Even if you have received zero complaints, you must often submit a "nil return" to confirm this.
  • Product Sales Data: If you sell specific financial products, you may need to report on the volume and type of sales made.

Handling Ad-hoc Notifications

Compliance isn't just about scheduled reports; it is also about transparency regarding significant changes. You are legally required to notify the FCA via the Connect portal if certain events occur within your business. These are often referred to as 'SUP 15' notifications in the FCA handbook. Examples include:

  • A change in your business address or legal name.
  • The appointment or resignation of a Director or a Senior Manager.
  • Significant fraud or a major cybersecurity breach.
  • Any legal action taken against the firm.

Best Practices for Ongoing Monitoring

Regulatory compliance should be a daily habit, not a year-end panic. Following these best practices will keep your relationship with the regulator healthy:

ActionFrequencyPurpose
Internal AuditQuarterlyCheck that your internal processes still match your written policies.
RegData CheckMonthlyLog in to ensure no new reporting requirements have been added to your schedule.
Horizon ScanningOngoingStay updated on FCA news and 'Dear CEO' letters that might signal changes in rules.
Tip: Always document your decision-making process. If you decide a specific incident doesn't need to be reported to the FCA, keep a written record of why you came to that conclusion. The regulator values a clear audit trail.

Managing Reporting Failures

If you realise you have missed a deadline or submitted incorrect data, the best approach is proactive disclosure. Contact the FCA as soon as the error is identified. They are generally more lenient with firms that self-report mistakes and provide a clear plan to rectify them than those who wait for the regulator to find the error during an inspection.

Created by hatch. • Updated on April 28, 2026