What Happened
The Upper Tribunal has upheld Crispin Odey's lifetime ban from the U.K. financial sector and confirmed a £1.5 million fine imposed by the Financial Conduct Authority. The FCA's enforcement director issued a warning that regulators will not tolerate a "slapdash" approach to ethics and non-financial misconduct. This signals a shift in regulatory priorities, placing conduct risk alongside traditional financial compliance.
Timeline
Although the source material doesn't provide a full chronology of the investigation and appeal, the enforcement action marks the culmination of regulatory scrutiny into conduct beyond conventional financial compliance violations. The tribunal's decision to reject the appeal reinforces the permanence of the sanction and validates the FCA's approach to non-financial misconduct cases.
Which Controls Failed or Were Missing
This case highlights three critical control gaps that persist across financial services firms:
Conduct surveillance mechanisms. Your organization likely has robust transaction monitoring, but do you apply the same rigor to behavioral red flags? Non-financial misconduct requires witness interviews, pattern analysis across complaints, and cultural assessment tools that many compliance functions lack.
Escalation protocols for non-quantifiable risk. When concerning behavior is reported that doesn't breach a specific rule, what happens? The failure here is procedural. Firms often lack clear pathways for escalating conduct concerns that don't fit existing categories in your risk register or incident management system.
Senior management accountability frameworks. The FCA's Senior Managers and Certification Regime (SM&CR) assigns specific conduct responsibilities to designated individuals. Yet many firms treat SM&CR as a documentation exercise rather than an accountability mechanism. If you can't map who owns non-financial misconduct oversight in your prescribed responsibilities statements, there's a control gap.
What the Relevant Standard Requires
The FCA's Conduct Rules establish baseline expectations, but they're principles-based. Individual Conduct Rule 1 requires you to "act with integrity," and Rule 2 demands you "act with due skill, care and diligence." These require judgment calls and cultural enforcement.
Under SM&CR, Senior Manager Conduct Rule 4 requires that you "disclose appropriately any information of which the FCA or PRA would reasonably expect notice." This creates a duty to surface non-financial misconduct, not just respond when it's reported.
The FCA's threshold conditions, which govern authorization, include Condition 2E: suitability. Your firm must conduct its business with integrity and demonstrate that those who manage it are fit and proper. A pattern of unaddressed non-financial misconduct undermines this requirement and can trigger enforcement action or license review.
Here's what compliance with these standards looks like in practice:
Documented conduct risk appetite. You need a board-approved statement defining what behaviors your firm won't tolerate, even if they're legal. This guides investigation thresholds and disciplinary decisions.
Behavioral indicators in your risk assessment. Your enterprise risk assessment should include specific non-financial misconduct scenarios with assigned likelihood and impact ratings. If "senior manager harassment" or "discrimination in client allocation" don't appear in your risk register, you're not complying with the spirit of the standard.
Evidence of supervisory challenge. The FCA expects senior managers to actively question and test conduct-related information they receive. Your compliance function should maintain records showing that designated SM&CR holders asked probing questions about conduct reports, requested follow-up investigations, or escalated concerns to the board.
Lessons and Action Items for Your Team
The FCA's warning about "slapdash" approaches indicates what not to do: don't treat non-financial misconduct as secondary, don't rely solely on annual training, and don't assume HR handles it.
Action 1: Audit your speak-up channels for non-financial issues. Review the past 12 months of reports to your whistleblowing line, HR hotline, and compliance inbox. How many concerned non-financial conduct? How were they categorized, investigated, and resolved? If you can't answer these questions with data, your tracking system isn't fit for purpose. Build a dedicated taxonomy for non-financial misconduct that includes harassment, bullying, discrimination, and integrity concerns as distinct categories.
Action 2: Map SM&CR accountability for conduct risk. Identify which Senior Manager Function holder owns oversight of non-financial misconduct in your prescribed responsibilities. If it's split between the Chief Risk Officer, Head of HR, and Head of Compliance, document the coordination mechanism. The FCA will want to see clear accountability, not shared responsibility that dilutes ownership.
Action 3: Implement behavioral risk indicators. Work with HR to identify leading indicators: exit interview themes, patterns in performance improvement plans, clustering of team transfers, or spikes in sick leave within specific departments. These metrics won't prove misconduct, but they'll help you spot cultural problems before they generate regulatory attention.
Action 4: Test your investigation protocols. Run a tabletop exercise simulating a non-financial misconduct allegation against a revenue-generating senior manager. Who leads the investigation? What's the standard of proof? How do you protect the complainant? Who makes the disciplinary decision? If your team debates these questions during the exercise, your protocols aren't clear enough.
Action 5: Review your disciplinary outcomes for consistency. Analyze whether your firm applies the same standards across seniority levels and business units. Inconsistent enforcement of conduct standards creates both legal risk and cultural damage. Your compliance function should receive anonymized data on all disciplinary actions to identify patterns that suggest bias or selective enforcement.
The Odey case demonstrates that non-financial misconduct carries financial consequences that match or exceed traditional compliance failures. A £1.5 million fine and lifetime ban aren't administrative penalties; they're career-ending sanctions that signal regulatory intent. Your compliance program needs equivalent seriousness in how it detects, investigates, and addresses conduct that falls outside conventional rule violations.





