How do I run a compliance gap analysis against FCA rules?
A compliance gap analysis takes every FCA rule that applies to your permissions and asks three questions of it: does a control exist, who owns it and what evidence proves it operated. Each answer is rated honestly and the gaps are fixed by date. The FCA's PS25/12, which made CASS 15 enforceable on 7 May 2026, is the current test case.
Three things this article will leave you able to do
Build an obligations register from the Handbook, not from a summary of it.
Rate each obligation on a four-point scale a skilled person would accept.
Walk PS25/12 → CASS 15 through the method, obligation by obligation.
Most firms discover the state of their compliance framework at the worst possible moment: when the FCA asks for evidence of it.
The request is rarely dramatic. A supervisory letter. A data request before a firm assessment. A skilled person appointed under section 166 of FSMA. In each case the question underneath is the same: show us the rule, the control you built for it and proof the control was working.
A gap analysis is how you answer that question before the regulator asks it. Done properly, it is not a document. It is a register that your firm keeps alive, with one row per obligation.
Who needs to run one and when
Every FCA-authorised firm carries this obligation implicitly. SYSC 6.1.1R requires a firm to "establish, implement and maintain adequate policies and procedures sufficient to ensure compliance of the firm... with its obligations under the regulatory system." You cannot know your policies are adequate against rules you have not listed.
In practice, a gap analysis gets triggered by five events:
A new policy statement lands. Payments and e-money firms ran one against PS25/12 when it was published on 7 August 2025, with the CASS 15 rules taking effect on 7 May 2026.
You apply for a new permission. The application asks how you will meet the rules that come with it.
You acquire, merge or restructure. Two firms' controls rarely map to one rulebook cleanly.
The FCA writes to your portfolio. Dear CEO letters usually say, in effect, "we expect you to have assessed yourself against this."
Nothing happened for a year. A register that has not been reviewed in twelve months is a historical record, not a control.
The method, step by step
1. Fix the perimeter
Start from your entry on the Financial Services Register: the actual permissions, not what the firm believes it does. Permissions determine which sourcebooks bite. A payments firm draws down CASS 15 and the Payment Services Regulations; an investment firm draws COBS and CASS 7; everyone authorised draws SYSC, PRIN and SM&CR. Scope creep in both directions is the first failure: firms assess rules that do not apply and miss ones that do.
2. Build the obligations register from the rules themselves
Open the Handbook, not a consultant's summary of it. Work through each applicable sourcebook and extract the provisions marked R (rules, which bind) separately from G (guidance, which is how the FCA reads its own rules). One row per obligation, in the rule's own words, with the reference. This is slow. It is also the entire point: every shortcut taken here surfaces later as a gap you did not know you had.
A 200-page policy statement typically reduces to somewhere between 30 and 60 discrete obligations. That number is what makes the rest of the exercise tractable.
3. Map each obligation to a control and an owner
For each row: which policy, procedure, system check or review meets this obligation and which named person owns it. Not a department. A person. Under SM&CR, prescribed responsibilities already sit with senior managers; the register should agree with your Statements of Responsibilities. Where it does not, you have found a different kind of gap.
4 · Rate the gap honestly
Four ratings, each with a recorded rationale:
Met. Control exists, operates and evidence exists.
Partial. Control exists but is incomplete, undocumented or not tested.
Gap. No control.
Not applicable. With the reason written down. "N/A" without a rationale is the single most common thing a skilled person reopens.
The distribution matters. A first-pass gap analysis that returns 95% "Met" has usually measured the firm's self-image rather than the firm. Reviewers know this, which is why an implausibly clean register invites more scrutiny, not less.
5. Attach evidence, not assertions
"We have a policy" is an assertion. The policy document, its version history, the board minute approving it, the reconciliation output and the training log are evidence. Each register row should point at the artefact that proves the control operated and the artefact should be dated. If the evidence for a control cannot be located inside a working day, treat the rating as Partial regardless of how good the control is.
6. Remediate with dates, owners and MI
Gaps become a remediation plan: action, owner, deadline and a route to the board or the relevant SMF. The FCA's supervisory teams read remediation plans the way auditors do; an undated action is a wish. Progress against the plan is management information. It belongs in the compliance report, not in a drawer.
7. Re-run when the rules move
A gap analysis is a snapshot of a moving target. PS25/12 changed the safeguarding register in August 2025. The June 2026 cryptoasset policy statements (PS26/9 to PS26/13) will change registers for firms entering that regime before it goes live. Horizon scanning is what tells you when to re-run; the register is what you re-run. Firms that connect the two spend days on each regulatory change. Firms that do not, start again from the perimeter each time.
What you must evidence
The table below shows the shape of a register using live CASS 15 obligations, the ones payments and e-money firms have been operating since 7 May 2026, plus the two horizontal obligations every firm carries.
Two things about this table. First, every evidence item is a dated artefact, not a description of intent. Second, none of it is produced for the regulator. It is the output of the controls operating, collected as it happens. Evidence assembled retrospectively for a review reads as exactly that.
Worked example: PS25/12 becomes 40 rows
The safeguarding reform is worth walking through because the dates are real and recent.
The FCA published PS25/12 on 7 August 2025. Firms had nine months to the 7 May 2026 effective date. A payments firm running the method above would have confirmed scope in August (an authorised payment institution or e-money institution holding relevant funds is in scope; agent-only is out), then extracted the CASS 15 obligations into the register through September: daily reconciliation, monthly returns, the audit, the resolution pack, third-party due diligence and insurance contingency plans, with any insurance-based cover renewed at least three months before policy expiry. Mapping those to existing safeguarding controls typically found that reconciliation existed but not daily, and that no resolution pack existed at all. The firm rated accordingly and spent Q1 2026 remediating, with the board tracking the plan monthly.
Firms that started in January 2026 instead compressed the same work into one quarter. The difference is visible now, in the quality of the first monthly returns and in which firms are comfortable when the first annual audit falls due.
The pattern generalises. Every policy statement is a countdown that starts on publication day and the gap analysis is the first item on it.
How firms handle this
Most firms still run the register in a spreadsheet. For a small firm with stable permissions that can work, until the Handbook moves and nobody owns the re-run. Larger firms bring in consultants for the trigger events, which buys expertise but produces a snapshot that starts ageing the day the engagement ends. Software closes the loop between the rule text, the register and the evidence; our Gap Analyzer does this against the FCA Handbook directly, keeping each obligation linked to its current rule text. Whichever route you take, the test is the same: when a rule changes, does your register know?
Primary sources
FCA, PS25/12: Changes to the safeguarding regime for payments and e-money firms. Published 7 August 2025; CASS 15 rules effective 7 May 2026.
FCA Handbook, SYSC 6.1 (Compliance). SYSC 6.1.1R.
FCA Handbook, CASS 15. Safeguarding requirements for payments and e-money firms.
FCA, PRIN 2A (the Consumer Duty). Outcome monitoring obligations.
FSMA 2000, section 166. Reports by skilled persons.
Volatile. Re-verify before each republish: first annual safeguarding audit timing for firms whose audit period ended mid-2026 · the CASS 15 sub-£100,000 audit exemption threshold · status of the interim vs end-state ("post-repeal") safeguarding regime · PS26/9–PS26/13 crypto regime go-live dates.
Related reading on Comply2Reg: Tokenisation vs digitisation. What actually changes in finance.