Three years into a legal duty to identify vulnerable customers, the FCA found payments firms with 'very few, or in some cases no' such customers. It will not say how many it checked, or when it will look again.
Estimated reading time: 6 minutes
In short. On 17 September 2026 the Financial Conduct Authority published its findings on how payments firms treat customers in vulnerable circumstances under the Consumer Duty [1]. Some firms, it found, "identified very few, or in some cases no customers in vulnerable circumstances, despite having customer bases where characteristics of vulnerability may reasonably be expected" [1], five years after the FCA's own guidance told firms to stop treating this kind of monitoring "as a one-off exercise" [2] and more than two years after the Duty made it a binding rule, not just guidance [3]. The review names no firm, gives no sample size, and sets no date to check again. Three documented mistakes: four stars.
The Consumer Duty came into force for open products and services on 31 July 2023, and for closed products a year later, on 31 July 2024, under the FCA's own policy statement PS22-9 [3]. On the regulator's own description, it "sets a high standard for retail consumer protection" [1]. A central plank of that standard is identifying which customers are vulnerable and adjusting service accordingly, something the FCA had already told firms to do, in detail, two and a half years before the Duty existed at all.
Guidance from 2021, still not landing in 2026
In February 2021 the FCA published finalised guidance setting out four drivers of vulnerability, health, life events, resilience and capability, and told firms exactly how to act on them [2]. Chapter 5 of that guidance was explicit that identifying vulnerable customers is not a task to be done once: "firms should not monitor MI as a one-off exercise", because "consumer needs and circumstances can change" and firms that fail to keep collecting and analysing management information "risk being unable to ensure they are delivering the right outcomes for vulnerable consumers" (para 5.11) [2].
Five and a half years, and more than two years of the Duty being legally binding, later, the FCA's September 2026 review of payments firms found exactly the failure mode that 2021 guidance warned against. Under "Areas for improvement", it recorded that some firms "relied heavily on staff judgement with limited supporting processes to promote consistent identification of vulnerability" and "could not consistently evidence how vulnerability information was recorded and shared across the customer journey" [1]. That is the ad hoc approach the 2021 guidance was written to replace, still present in a sector now bound by a Duty that turned identifying vulnerability from advisory best practice into a rule firms "must" meet [3].
The starkest finding goes further than uneven practice. The FCA reported that some firms "identified very few, or in some cases no customers in vulnerable circumstances, despite having customer bases where characteristics of vulnerability may reasonably be expected" [1]. Given the FCA's own 2021 estimate that a substantial share of UK adults show characteristics of vulnerability at any one time [2], a payments firm recording none is not a clean bill of health. It is a sign the firm is not looking.
A review that will not count itself
The FCA's own words describe the exercise loosely: "We reviewed a sample of payments firms to assess how they are supporting consumers in vulnerable circumstances" [1]. No number of firms is given anywhere in the publication, and no firm is named; every example is introduced as "one payments provider" or "a money remitter" [1].
That is not how the FCA always publishes this kind of review. Its own outcomes-monitoring review, in the same "good and poor practice" series and published two months earlier on 27 July 2026, states plainly under "Our review": "We also conducted a survey of 56 firms, covering their" approach to monitoring customer outcomes [4]. Whatever the reasons for the difference, a reader comparing the two documents has no way of knowing whether the payments findings rest on five firms or fifty, or what share of the market they represent. A finding that some firms record zero vulnerable customers is only as strong as the sample it comes from, and the FCA has chosen not to say.
The publication closes under "Next steps" with a single supervisory promise: "We'll continue to engage with firms in this area. Where we find firms are not meeting expectations, we'll intervene using our full range of supervisory tools" [1]. No date attaches to that continued engagement, and no commitment to publish a follow-up review, named or anonymised, at any point.
The claims, tested
| The document's own words | What the evidence actually shows | Verdict |
|---|---|---|
| "This publication does not introduce new requirements or prescribe a particular way to meet our expectations" [1] | The expectations it restates, structured identification of vulnerability and ongoing monitoring, were set out in detail in the FCA's own February 2021 guidance, chapter 5, five and a half years earlier [2] | Correct on its own terms; the standard is old, only the compliance gap is news |
| Firms "should not monitor MI as a one-off exercise" (FG21/1, para 5.11) [2] | The 2026 review found firms that "relied heavily on staff judgement with limited supporting processes" instead of the ongoing, structured monitoring the guidance called for [1] | The one-off approach the FCA warned against in 2021 persists under a binding Duty in 2026 |
| "We reviewed a sample of payments firms" [1] | Its own sibling review, published 27 July 2026, discloses "a survey of 56 firms" for a comparable exercise [4]; the payments review gives no equivalent figure | The regulator can disclose a sample size when it chooses to, and chose not to here |
| "Where we find firms are not meeting expectations, we'll intervene using our full range of supervisory tools" [1] | No firm is named, no date is set for a follow-up review, and no mechanism is described for a reader to learn whether intervention ever happens | An open-ended promise with no way to check it |
The mistakes, counted
A five-year-old failure mode, still current (1). The FCA's own 2021 guidance told firms plainly not to treat vulnerability identification "as a one-off exercise" [2]. More than five years later, and over two years into a legally binding Duty built on that same expectation [3], its own review found firms relying on ad hoc staff judgement and identifying "very few, or in some cases no" vulnerable customers at all [1].
No sample size, where a comparable review gave one (2). The payments review describes checking only "a sample of payments firms", with no number attached anywhere in the document [1]. Its own July 2026 sibling review in the same series names an exact figure, a survey of 56 firms [4], showing the omission in the payments review is a choice, not a house style.
No firm named, no date to check again (3). Every example in the review is anonymised, and the "Next steps" section commits only to continued engagement and possible future intervention, with no date and no promise of a further published check [1]. A reader cannot hold the FCA to a timetable that does not exist.
Credit where due
The review itself is not thin on substance: it sets out concrete good practice, tailored onboarding for customers with limited IT skills, multilingual support from money remitters, board-level reporting on vulnerability metrics, and equally concrete areas for improvement, in language firms can act on without needing a lawyer to translate it [1]. The FCA is also transparent that the document creates no new legal obligations, so no firm can claim to have been blindsided by a hidden standard. And its own guidance and policy statements, the ones this review measures firms against, have been public and specific since 2021 and 2022 respectively [2] [3]; the underlying rules are not the problem here.
Verdict
Four stars, from three documented mistakes. The Financial Conduct Authority has been telling firms since 2021 how to identify vulnerable customers, and has had the legal power to require it since 2023. Its own review of payments firms in September 2026 found the basic habit, structured, ongoing identification rather than staff guesswork, still missing in places, with some firms recording next to no vulnerable customers in a market where the regulator's own evidence says that is not plausible. The FCA then published that finding without the one number that would let a reader judge how widespread the problem is, without naming a single firm, and without committing to look again by any particular date. A regulator that can say "56 firms" in July can say a number in September. This time, it chose not to.
Sources
- Payments firms: delivering good outcomes for consumers in vulnerable circumstances, Financial Conduct Authority, published 17 September 2026
- FG21/1: Guidance for firms on the fair treatment of vulnerable customers, Financial Conduct Authority, published February 2021
- PS22-9: A new Consumer Duty, Financial Conduct Authority
- Outcomes monitoring: good practice and areas for improvement, Financial Conduct Authority, published 27 July 2026