Firms face fresh scrutiny of vulnerability management as FCA changes complaints reporting rules

For financial services firms, complaints have long stood as both an important measure of customer experience – and a necessary part of regulatory reporting. From January 2027, however, they will serve a third purpose – providing the regulator with greater insight into how firms both identify and support customers in vulnerable circumstances.

Under changes set out in Policy Statement PS25/19, firms will be required to report two specific pieces of complaints data relating to customer vulnerability. The first is to capture complaints made by customers who have been identified as being in vulnerable circumstances, regardless of how that vulnerability was identified.

The second, and arguably more significant, is to capture complaints that relate to, or were by caused by, a firm’s failure to identify, consider or respond appropriately to a customer’s vulnerability.

Since there may be no correlation between the customer’s vulnerability and the reason for the complaint, it’s important that firms distinguish between complaints made by vulnerable customers and those where a failure to recognise or respond appropriately to vulnerability contributed to the complaint.

This is where the new reporting requirements become relevant to Consumer Duty, particularly as the regulation enters its next phase of maturity – moving from ‘implementation’ into ‘action with evidence’.

Three years on from being first implemented, Consumer Duty has pushed customer vulnerability forward from simply having the right processes in place. While still important, the focus is now on proving that those processes deliver good customer outcomes consistently – using robust data, rather than anecdotal feedback. The FCA’s recent intervention on outcomes monitoring is the clearest example of this.

Complaints data can provide an important part of that evidence.

After all, the existence of a process is not, in itself, evidence that the process is working. If a firm has invested in front-line training, introduced processes for identifying customers in need of additional support and developed policies for making adjustments, but complaints continue to arise because vulnerabilities were missed or not addressed, there is a question to answer.

The regulator is not expecting every firm to have a 100% success rate and zero complaints – that simply isn’t realistic. What it does want to see is that, where issues are identified, steps are taken to remedy, remediate and resolve both potential harms and poor outcomes for all customers – with evidence to prove this.

The FCA’s changes encourage firms to look at their complaints data differently. Rather than treating it as a regulatory return, firms should consider what it tells them about the effectiveness of their approach to customer vulnerability.

Do we know who our vulnerable customers are and what issues they face? Are we being proactive enough – for example not just reporting on characteristics that are visible or shared directly by the customer? Are we making the necessary adjustments to our products, service and communications, and are interventions actually helping customers achieve good outcomes? Crucially, can we evidence this?

Securing the answers to these questions requires that firms connect information held across disparate processes and functions – such as customer onboarding, claims, complaints, customer vulnerability management and outcomes monitoring – to create one cohesive view of the customer experience. With this approach, firms can then identify not only that a customer is vulnerable, but whether that vulnerability was relevant to the complaint.

With more robust complaints data, firms can have a greater understanding of where customers are encountering barriers, rather than a simplistic view of just how many complaints have been received. There is also the opportunity to identify patterns or recurring hotspots that may appear in areas such as communications, product design or accessibility. This can then inform changes and prevent similar problems from reoccurring.

The first reporting period will run from 1 January to 30 June 2027, with firms expected to make the necessary changes to their systems and processes ahead of this point.

That gives firms time to prepare and make sure their customer vulnerability management strategy is up to scratch. If not already, that strategy should be built around the right technology and processes to not just identify and classify, but monitor, support and report on customer vulnerabilities and outcomes in an objective, consistent and efficient way.

This will allow firms to answer that bigger question: what can complaints data tell us about the outcomes delivered for vulnerable customers? They should have the data and oversight in place to identify where customers are experiencing harm, understand why it’s happening and act on that insight to improve outcomes.

While enhanced complaints reporting may feel like an additional burden, this change in approach could provide a valuable feedback mechanism – and a clear competitive advantage – for firms willing to harness the data they gather.

Andrew Gething

Andrew is the founder and managing director of MorganAsh. Andrew, a recognised consumer vulnerability specialist and champion, is the driving force behind the award-winning consumer vulnerability management tool, MARS – adopted in the financial services, credit and utilities sectors.

Previous
Previous

Vulnerability and mortgage affordability: two sides of the same coin

Next
Next

Cybersecurity and customer vulnerability