I spent years building and running an FCA-regulated financial services business. We scaled it to £8 million and eventually completed a successful exit. Throughout that process, the single most important thing I learned about compliance had nothing to do with policies, procedures, or regulatory submissions. It was about culture.
The gap between documentation and behaviour
Every regulated firm has a compliance manual. Most have policies covering the key regulatory requirements — anti-money laundering, treating customers fairly, data protection, conflicts of interest. The question that actually matters is whether anyone follows them. Not when the compliance officer is watching, not when an audit is scheduled, but in the ordinary course of daily business.
In the early days of building the business, I made the mistake of thinking that good documentation was the same as good compliance. It isn't. A policy that sits in a shared drive and gets reviewed once a year is not a compliance control — it's a liability. The FCA has made this point repeatedly: they assess culture, not just documentation. The SM&CR regime is explicitly designed to make individuals accountable for the culture within their areas of responsibility.
What actually builds compliance culture
Compliance culture is built through three things: leadership behaviour, practical training, and consequences. If the senior team treats compliance as a cost centre or an obstacle to commercial activity, that attitude permeates the entire organisation. If training consists of annual tick-box e-learning modules that nobody takes seriously, it achieves nothing. And if non-compliance has no consequences — or if commercial performance is rewarded regardless of how it was achieved — then the message is clear, whatever the policy document says.
In our business, the most effective compliance measure we ever implemented was not a policy or a system. It was a standing agenda item in every management meeting where we discussed compliance issues openly, including mistakes. Making compliance a normal part of operational conversation, rather than something that only surfaces during annual reviews or when something goes wrong, changed how people thought about it.
The lesson for consultants and advisors
Now that I work as an independent compliance consultant, I bring this perspective to every engagement. When an organisation asks me to review their compliance framework, the first thing I look at is not the documentation — it's the culture. How does the senior team talk about compliance? What happens when someone raises a concern? Is there a genuine commitment to doing things properly, or is compliance treated as a necessary evil?
The documentation matters, of course. You need policies, procedures, monitoring programmes, and evidence of oversight. But if the culture isn't right, all of that documentation is just an expensive fiction. Building genuine compliance culture is harder than writing a policy, but it's the only thing that actually protects an organisation when it matters.