management
Written by

Alan Gurung
Co-Founder & CEO
Sharing links



Last updated •
Summarize with AI
TL;DR: Principal firms carry full regulatory liability for their Appointed Representatives' permitted activities under FCA SUP 12 rules. With Consumer Duty and the 2026 HM Treasury reform proposals shifting expectations from passive monitoring to continuous active oversight, manual file sampling is no longer a defensible compliance strategy. This playbook covers the core SUP 12 and Consumer Duty obligations, the 2026 SM&CR extension proposals, and how Evie, Emma, Colin, and Atlas can standardise documentation across your AR network without adding compliance headcount. Operations Directors should evaluate whether their current AR oversight model can evidence continuous, pre-delivery compliance checking. If the answer is no, the FCA's 2026 proposed reforms will expose that gap.
Under FCA SUP 12 and Section 39 of FSMA 2000, when an Appointed Representative writes a non-compliant suitability report, the regulator does not fine the AR. It fines you. Consumer Duty under PRIN 2A extends that liability further: principals must now evidence good outcomes across all four areas for every client their ARs advise. Growing an AR network is a documentation play. If you cannot standardise and audit files continuously, your regulatory exposure grows with every AR you add.
Defining the Appointed Representative Regulatory Scope
Definition of an Appointed Representative
Section 39 of FSMA 2000 provides that ARs are exempt persons who do not need direct FCA authorisation to carry out regulated activities. Instead, they operate under the regulatory umbrella of a directly authorised principal firm. The AR operates within a scope of activities defined in a written agreement between the AR and the principal, and the principal accepts responsibility in writing for those activities.
This written agreement defines the exact scope of permissions the AR operates within and establishes the boundaries of the principal's liability. Recent case law has clarified that firms are generally not liable for AR activities falling entirely outside the permitted scope. However, under FSMA s39(3) and (4) and FCA guidance in PERG and SUP 12, limitations that govern only the manner in which permitted activities are carried out, rather than excluding those activities from scope entirely, do not carry the same protective effect. The principal's liability to consumers for those activities may remain even where the AR has breached a conduct restriction in the written agreement.
AR-Side Obligations Under the Regime
The AR regime places obligations on the AR as well as the principal. ARs must operate strictly within the scope of regulated activities defined in their written agreement with the principal. Carrying out activities outside that permitted scope does not transfer liability to the principal, but it does expose the AR to direct FCA enforcement as an unauthorised firm conducting regulated business.
ARs are also contractually required to notify their principal promptly when trigger events occur: changes to the business model, senior management turnover, appointment of an additional principal, or a material increase in client complaints. These notification obligations exist because SUP 12 requires the principal to reassess the AR relationship when circumstances change. An AR that delays or withholds notification undermines the principal's ability to meet its own regulatory obligations and risks termination of the appointment.
ARs must cooperate fully with the principal's oversight processes, including providing access to client files, fact-finds, suitability reports, and meeting records on request. Where the principal mandates pre-delivery compliance checks or standardised documentation templates, the AR operates within those requirements as a condition of the appointment.
The 2026 HM Treasury reform proposals extend SM&CR conduct rules directly to all relevant individuals within AR firms. Named individuals at AR level will be subject to the same individual accountability standards as certified staff at directly authorised firms. ARs that have not yet mapped individual accountability to specific regulated functions should treat this as an immediate governance gap, not a future consideration.
Managing AR Compliance and Oversight
The FCA's regulatory position under SUP 12 is unambiguous: appointing an AR is not a delegation of regulatory responsibility. It is an extension of the principal firm's own permissions, one that must be actively controlled, monitored, and evidenced. The regulator holds the principal firm accountable for AR compliance failures.
The forthcoming 2026 SM&CR extension, outlined in HM Treasury's consultation on AR regime reform, proposes three primary reforms: requiring FCA permission to act as a principal before a firm can appoint ARs, extending the FOS compulsory jurisdiction to certain AR complaints, and applying SM&CR conduct rules directly to all relevant individuals within AR firms. The FCA may also introduce a dedicated senior management function for AR oversight at the principal level, though this is framed in the consultation as a potential measure rather than a confirmed requirement. These are not distant proposals. They are the direction the FCA has been signalling since its targeted AR supervision programme saw principals terminate more than 1,300 AR relationships from July 2022 to August 2023.
Expanding Operations via the AR Model
Principal firms use the AR model to extend their distribution footprint without requiring every adviser to hold direct FCA authorisation. The compliance arithmetic only works if the oversight infrastructure scales proportionally. As the AdvisoryAI whitepaper on operational efficiency demonstrates, suitability report preparation alone consumes between one and seven hours per report across 71.9% of UK advice firms. Multiply that across ten or twenty AR relationships and the compliance team cannot sample files fast enough to catch problems before they reach clients.
Key Compliance Tasks for Principal Firms
Principal Firm Oversight Obligations
SUP 12.4 sets specific tasks that principals must fulfil before and during every AR appointment.
Before appointment:
Assess the AR's fitness and propriety, financial stability, and suitability for regulated business
Notify the FCA at least 30 days before the appointment takes effect
Ongoing annual obligations:
Review fitness and propriety of all AR senior management
Assess the AR's financial position and stability
Evaluate the adequacy of controls and oversight resources
Trigger events requiring immediate reassessment:
Business model changes at the AR
Changes in senior management
Appointment of an additional principal
A material increase in complaints
The FCA's good-and-poor-practice publication on AR oversight confirms that principals must embed these triggers in contractual arrangements and require ARs to provide prompt notification when they occur.
Principal Obligations for Consumer Duty
Consumer Duty under PRIN 2A requires principal firms to oversee their ARs' actions and to check that those ARs comply with the Duty across four outcomes. The table below maps practical AR oversight activities to relevant Consumer Duty outcomes and the operational evidence firms should consider maintaining.
AR Oversight Activity | Relevant Consumer Duty Outcome | Operational Evidence to Consider |
|---|---|---|
Pre-delivery file checking | Products and Services / Price and Value | Documented suitability justification for recommendations |
Vulnerability tracking | Consumer Support | Clear flags in back-office systems with recorded actions |
Suitability report auditing | Consumer Understanding | Checks ensuring clear, non-jargon executive summaries |
Annual review tracking | Consumer Support | Records of annual review meetings and follow-up actions |
How Principals Manage AR Liabilities
Principal firms can face significant penalties and compensation orders for AR misconduct. PI insurance premiums rise sharply after enforcement action, and a public FCA censure affects recruitment, client retention, and firm valuation simultaneously.
The 2026 reforms propose that the FCA may introduce a dedicated senior management function for AR oversight, which would hold a named individual at the principal firm directly accountable for oversight failures. The consultation also proposes extending FOS compulsory jurisdiction to certain AR complaints, widening the financial exposure principal firms carry for AR conduct. A manual sampling process will not be a sufficient defence once these reforms are in place.
Managing AR Obligations Under FCA Guidelines
Mandatory AR Documentation Protocols
Every new AR appointment requires a structured due-diligence and onboarding process from day one.
Entity due diligence: Assess fitness and propriety of key individuals and the AR's financial standing.
Business model analysis: Assess the AR's business model and advice propositions to confirm permitted scope alignment.
Systems integration: Consider connecting AR client data to the principal's back-office systems (such as Intelliflo, Plannr, Curo, and Xplan).
Template alignment: Configure the AR's suitability report templates within Emma to match the firm's established document structure, advice style, and tonality. Emma supports both the firm's own templates and fully customisable off-the-shelf templates, so principals can standardise compliance across the AR network without requiring ARs to abandon their existing formats.
Accountability mapping: Assign a certified Senior Manager to the AR relationship under the proposed 2026 AR Senior Management Function.
Ensuring FCA Suitability Compliance
COBS 9 requires that advice provided meets documented suitability standards. The challenge for principal firms is enforcing that standard consistently across AR firms that may have been writing suitability reports their own way for years.
The Emma suitability report generator works directly from the firm's or the AR's established templates, which means ARs do not face pressure to abandon document structures they have built compliance confidence around. Emma generates reports from fact-finds, LOA pack summaries, ceding information, cashflow modelling, risk profiles, and meeting notes, citing every statement back to its source document and producing a draft the adviser reviews and approves rather than writing from scratch.
The model was built by ex-financial advisers and paraplanners and trained on thousands of sample reports, so it understands the regulatory requirements and practitioner workflows that drive UK suitability documentation. Jigsaw Tree Research data, cited in the same AdvisoryAI whitepaper, shows a 65.48% reduction in suitability letter preparation time when using automation, from four hours forty-five minutes to one hour thirty-eight minutes per report. For a principal firm managing twenty ARs, that compression directly reduces the volume of incomplete or delayed reports that compliance teams must chase.
You can see Emma generating a suitability report from firm templates in the Emma product walkthrough.
Principal Firm Governance Protocols
The shift from passive monitoring to active oversight is an operational redesign as much as a technology decision. The following three-step framework reflects the FCA's expectations under SUP 12 and the Consumer Duty's requirement to evidence outcomes continuously:
Establish regular back-office data feeds: Replace quarterly spreadsheet submissions with regular back-office syncing, connecting AR client data directly to Intelliflo or Plannr so compliance teams can query current file status without waiting for adviser submissions.
Implement pre-delivery compliance checks: Require all AR suitability reports to pass automated checks before they are delivered to clients. Colin runs 42 automated checks per suitability report and flags specific gaps with remediation guidance before the document leaves the adviser's desk.
Track AR compliance centrally: Colin's percentage compliance scores and remediation records give your team the structured data to prioritise review time on the highest-risk files, logged and tracked in your firm's own management information framework.
Do your compliance teams review AR files before or after they are sent to clients? If the answer is after, your oversight model is retrospective and does not satisfy the FCA's expectation of proactive, preventive monitoring.
Standardising Firm Meeting Note Logs
Inconsistent meeting notes are the earliest point at which AR compliance failures originate. Evie records and transcribes client meetings via Microsoft Teams, Zoom, or Google Meet, then produces structured notes covering objectives, circumstances, recommendations, next steps, and actions. Evie captures not just what clients say but how they respond: tone, reactions, anxieties, and family dynamics that signal vulnerability or capacity concerns.
These notes populate specific fields in the fact-find section of the connected back-office system (personal information, investment details, risk assessments), so the paraplanner has access to complete structured data immediately rather than waiting for the adviser to submit notes manually. The Evie meeting notes tool is demonstrated in this FCA-compliant notes walkthrough, and its impact at Timothy James and Partners included a 50% reduction in post-meeting documentation time, with support teams able to access structured notes significantly faster than under the previous manual process.
How Does the Principal Monitor AR Compliance?
Validating Documentation for Compliance
The operational problem in any multi-AR network is variance. Different AR offices develop different documentation habits, different levels of detail in fact-finds, and different approaches to evidencing suitability. Over time, an AR that submits clean files during the annual audit may revert to vague meeting notes the rest of the year, accumulating regulatory risk invisibly.
Colin addresses this directly. Colin runs 42 automated checks on every suitability report and multi-category checks on fact-finds, covering:
AML documentation completeness
Client profiling (identity verification, financial literacy assessment, health details, foreseeable life changes)
Risk assessment adequacy (behavioural bias identification, capacity for loss)
Recommendation suitability (justification for transfers vs retaining existing arrangements)
Report quality (executive summary presence, recommendation clarity)
Checks produce a colour-coded pass/fail score, for example 95.24% compliant (40 of 42 checks passed), with specific remediation guidance for each failed item such as "Add AML check documentation" or "Include executive summary with key recommendations." You can see how Colin works in practice in this compliance checker walkthrough.
A critical differentiator for multi-AR principal firms is that Colin is system-agnostic: it checks any suitability report or file note, regardless of whether it was produced in AdvisoryAI, a legacy system, or written manually by an AR that has not yet adopted the platform. You do not need to mandate a full platform migration to begin auditing AR files consistently.
Consumer Duty Compliance Monitoring
The value of a percentage-score compliance report is that it converts a subjective file review into an objective, auditable record. A compliance officer reviewing AR files manually can realistically sample only a fraction of total files submitted within any given period. Colin covers 100% of files submitted to it, produces a pass/fail record and percentage score for each check, and flags specific remediation actions so the adviser corrects gaps before client delivery rather than after an FCA review. This is the documentary foundation that the Duty's evidencing requirements demand.
Principal Firm Monitoring and Liability Framework
FCA Oversight Team Requirements
The internal compliance burden on a principal firm's oversight team grows with every AR added to the network, unless the file-checking process is automated. The FCA's good-and-poor-practice publication on AR oversight makes clear that principals need integrated MI and record-keeping frameworks that enable early risk identification and informed intervention, rather than end-of-year reporting. That means maintaining a structured record of AR activities, advice files, and client communications rather than relying on periodic emails and quarterly spreadsheets. The Satis UK deployment of Evie and Emma produced a clearer audit trail on every compliance file and richer evidence captured per meeting, reducing team explanation time during external file reviews.
Managing AR Compliance Documentation
Operations Directors managing AR networks face a data fragmentation problem: compliance information sits across multiple AR back-office systems, file servers, and email chains, making firm-wide queries impossible without manual collation. Atlas solves this by connecting meeting transcripts, suitability reports, client documents, and back-office data in a single plain-English interface.
Atlas remembers context across sessions, so a compliance officer can ask follow-up questions days later without re-explaining the situation or re-querying the same client records. A compliance officer can ask: "Which ARs have not completed annual reviews for vulnerable clients this month?" Atlas queries the firm's real data and returns cited answers from the connected Intelliflo or Plannr records.
The May 2026 Adaptive Thinking update to Atlas addresses the most common objection compliance officers raise about AI: that they cannot trust an output they cannot audit. Atlas now displays each step as it processes a query, from analysing the request to searching for a client to loading their profile, and every response includes a collapsible thinking block showing the full reasoning trail. Reasoning persists across sessions, so older queries remain auditable and a compliance officer can return to a query days later and review exactly how Atlas reached its answer. The input field locks during processing to prevent duplicate queries. You can watch AdvisoryAI CEO Alan Gurung discuss AI oversight and how AdvisoryAI differs from black-box tools.
AR Oversight Obligations and Liability
The mandatory documentation set that principal firms must be able to review and evidence for every AR client relationship includes:
Fact-finds and client information records
Attitude to risk (ATR) questionnaires and capacity-for-loss assessments
Suitability reports and suitability letters
Structured meeting notes
Records of annual review meetings and follow-up actions
Vulnerability flags and recorded actions in the back-office system
For multi-principal AR arrangements, an AR can normally only have one principal firm for the same type of regulated activity under FCA rules. A multi-principal agreement requires formal written contracts with each principal and FCA registration. The AdvisoryAI compliance checker page details the specific check categories Colin applies to each document type, and risk-based scheduling determines how frequently each AR's files should be formally audited alongside continuous automated monitoring, with frequency reflecting the risk profile of each AR relationship rather than a uniform calendar-based approach.
Principal firms that standardise documentation at the AR desk, rather than auditing failures after the fact, convert compliance from a cost centre into a capacity advantage. With HM Treasury consulting on proposals that would require FCA permission to act as a principal, extend FOS compulsory jurisdiction to certain AR complaints, and apply SM&CR conduct rules to AR individuals, building defensible oversight infrastructure is no longer optional.
Start a 14-day free trial. No credit card required. Request a demo to see how Colin and Atlas work with your existing back-office systems. Monthly rolling agreement, 30-day money-back guarantee, and annual plans with a 10% discount are available.
FAQs
Can an AR Have More Than One Principal Firm?
An AR can normally only have one principal firm for the same type of regulated activity under FCA rules. A multi-principal arrangement is permitted where a specific written agreement is formally executed and registered with the FCA, and the terms must clearly define which regulated activities each principal is responsible for overseeing. Where an AR has multiple principals, formal written contracts must be in place with each principal, and complaints procedures establish which principal acts as the lead contact point.
How Often Must a Principal Firm Audit an AR's Client Files?
The FCA does not set a fixed audit frequency, but SUP 12 requires principals to review all relevant information about their ARs' activities and business at least every 12 months. Additional reviews are required when trigger events occur, such as business model changes, senior management turnover, or a material increase in complaints.
What Is the Penalty for a Principal Firm's Failure to Oversee an AR?
The FCA can impose significant financial penalties and order direct compensation payments to affected clients. Principal firms may also face authorisation restrictions and increased regulatory scrutiny. Public FCA censure affects recruitment, client retention, and firm valuation.
What Does the SM&CR Extension Mean for AR Networks?
The 2026 HM Treasury consultation proposes three primary reforms: requiring FCA permission to act as a principal before a firm can appoint ARs, extending FOS compulsory jurisdiction to certain AR complaints, and applying SM&CR conduct rules directly to all relevant individuals within AR firms. The FCA may also introduce a dedicated senior management function for AR oversight at the principal level, framed in the consultation as a potential measure rather than a confirmed requirement. Principal firms should treat these proposals as a clear signal of regulatory direction.
Can Colin Check Suitability Reports Produced Outside AdvisoryAI?
Yes. Colin is system-agnostic and checks any suitability report, fact-find, or file note regardless of where it was produced. Principal firms can run Colin's 42 automated compliance checks on documents submitted by ARs using legacy systems or manual processes without requiring a full platform migration across the AR network.
What Triggers a Mid-Cycle AR Reassessment Under SUP 12?
Trigger events requiring reassessment outside the annual review typically include shifts in the AR's business model, changes in senior management, the appointment of an additional principal, and a material increase in complaints. Principal firms should embed these triggers in the AR contractual agreement with notification obligations on the AR side.
Key Terms Glossary
Appointed Representative (AR): A firm or individual carrying out regulated activities under a principal firm's authorisation, without holding their own FCA permission. They operate within the scope of a written agreement defining permitted activities and principal liability. In multi-principal arrangements, complaint procedures establish which principal acts as the lead contact point for client enquiries.
Principal Firm: An FCA-authorised firm that appoints ARs and accepts full regulatory and financial liability for their regulated activities within the scope of the written agreement. Principals must conduct annual reviews and maintain continuous oversight under SUP 12.
SUP 12: The FCA Supervision Manual section governing Appointed Representative rules, including pre-appointment due diligence, annual review obligations, and trigger-event reassessment requirements. Principals must notify the FCA 30 days before any AR appointment.
Consumer Duty: The July 2023 FCA standard requiring firms to deliver and evidence good outcomes across four areas: products and services, price and value, consumer understanding, and consumer support. Principals must prove active monitoring of Consumer Duty outcomes across their entire AR network.
SM&CR: The Senior Managers and Certification Regime assigning individual accountability for regulated activities to named senior managers. The 2026 reform proposals extend SM&CR conduct rules to AR firm individuals, and may introduce a dedicated senior management function for AR oversight within principal firms.
COBS 9: The conduct of business sourcebook section governing suitability requirements, requiring that every piece of advice meets a documented suitability standard for the individual client's circumstances.

Subscribe to our newsletter
Get an AI summary of AdvisoryAI
For questions or partnerships,
contact us at team@advisoryai.com
For product support, help, contact us at support@advisoryai.com
Solutions
Compare












