This piece is not a repeat of what this series has covered in depth over the past twelve weeks. It is an action list — specific checks across financial promotions, Consumer Duty, and GDPR that every firm should be able to confirm before the window opens. Each item links to the relevant piece in this series for the full analysis.
Work through each one not by asking whether your policy addresses it, but by asking whether your systems and records demonstrate that it is operational.
Financial Promotions
Risk warning prominence. Pull your last five promotional sends across every format — email, social media, video, mobile, push notification. Does the mandated risk warning appear prominently in each? Not present somewhere in the communication — prominent, in the right wording, visible before the main promotional content. → The five things the FCA found wrong
Cooling-off period. Walk through your first-time investor journey end to end. Is the 24-hour cooling-off period enforced by the system — not just referenced in policy — before a direct offer financial promotion reaches a first-time investor? → The five things the FCA found wrong
Incentive prohibition. Check every active promotion and every affiliate channel for anything that could constitute an investment-linked reward — referral bonuses, sign-up incentives, tiered rewards. The prohibition is absolute and applies across all channels. → The five things the FCA found wrong
Section 21 approver status. If your firm relies on a section 21 approver, confirm today that the approver holds the gateway permission introduced in 2024. Check the FCA register. If they do not hold it, you do not have a lawful approval route. → Section 21 approvals: what’s changed
Affiliate and partner channels. When did you last audit what your affiliates are actually publishing? Not what the contract requires — what is on their social media pages, websites, and embedded integrations, right now. → Affiliate marketing and crypto promotions
Consumer Duty
Annual board report. Does your board report evidence outcomes or describe actions? The FCA expects evidenced data on whether customers are receiving good outcomes across the four areas of the Duty — not a narrative of what the firm has done. → Consumer Duty in 2026: can you prove it’s working?
Vulnerable customer identification. Can you describe, specifically, how a customer interacting with your platform today would be identified as potentially vulnerable — beyond what your policy says? Is there a documented process and a monitoring mechanism? → Consumer Duty and vulnerable customers
Fair value assessments. When were your fair value assessments last reviewed? If the answer is “when we first implemented Consumer Duty,” they are not current documents. → Consumer Duty in 2026: can you prove it’s working?
Outcome monitoring. Does your outcome monitoring framework measure actual customer outcomes — or process metrics that proxy for them? Is there data segmented by customer type, including for potentially vulnerable customers? → Consumer Duty and vulnerable customers
GDPR
Consent records. For every individual on your marketing list, can you produce a timestamped consent record showing when they consented, what they were shown, and what they agreed to? A consent flag in your CRM is not a consent record. → GDPR and direct marketing
Legacy consent. Are there customers on your marketing list whose consent was obtained more than two years ago without a subsequent re-engagement or refresh? If so, the consent basis for those sends should be reviewed before the next campaign. → GDPR and direct marketing
KYC lawful basis. Is the lawful basis documented for KYC and AML processing legal obligation — not consent? If your privacy notice describes consent as the basis for KYC data collection, it needs to be corrected. → GDPR and crypto onboarding
Retention schedule. Is there a documented retention schedule covering every category of data collected at onboarding, with the applicable retention period, legal basis, and deletion trigger for each? → GDPR and crypto onboarding
The Integrated Check
Pre-send review process. For your next promotional send — whatever it is — can you confirm compliance across all three regimes before it goes out? Audience list reviewed against GDPR consent status and vulnerability flags. Content reviewed against financial promotions requirements and Consumer Duty consumer understanding standard. Approval documented across all three dimensions. → One promotion, three problems
Where FCA Enforcement Attention Lands Next
The checklist above is about what firms should be addressing now. The question that follows: what does the FCA focus on after September? – will be addressed in full in next week’s piece.
The short version: the opening of the authorisation window does not reduce enforcement activity. It intensifies it. The FCA’s supervisory resource shifts from identifying firms operating without authorisation to reviewing how authorised and registered firms are performing against their ongoing obligations. Firms that treated the September deadline as the goal line will find that the FCA’s attention arrives sooner than they expected.
The firms best placed going into autumn 2026 are those that have addressed the checklist above – not because September required it, but because the FCA’s ongoing supervisory framework demands it.
Find out how our crypto authorisation readiness audit can help.
If you have outstanding gaps and want to address them before September closes, speak to our team.
Book a free consultation
We help crypto firms close compliance gaps quickly across financial promotions, Consumer Duty and GDPR — before and after the September authorisation window.
Email: info@lhiconsult.com | Phone: +44 203 319 5147 | Web: lhiconsult.com