1 Obligations under the regulations
UK firms do not have a single “error log” rule in the same form as Ireland’s CPC, but you are still required to detect, fix and evidence things that go wrong.
Insurers must take reasonable care to establish and maintain systems and controls appropriate to their business (SYSC 3.1.1R). Consumer Duty requires you to act in good faith, avoid foreseeable harm, and enable customers to pursue their financial objectives (PRIN 2A). Principle 11 and SUP 15.3 require you to tell the FCA about matters of which it would reasonably expect notice, including significant rule breaches and significant failures in financial-crime systems and controls.
From 18 March 2027, operational incidents that reasonably pose a risk of intolerable consumer harm, of harm to the firm’s safety and soundness, or of harm to market integrity must be reported under the FCA’s operational incident framework (SUP 15.18 / FG26/3), normally within 24 hours of deciding a threshold is met. Dual-regulated insurers should also consider the PRA’s policyholder-protection threshold.
If personal data is involved, UK GDPR Article 33 still requires a breach notification to the ICO without undue delay and, where feasible, within 72 hours. If a customer complains about the error, DISP time limits apply as well.
2 What do I need to do
Use one intake, then split the clocks. A pricing error, a platform outage and a data leak may share a register but they do not share a regulator.
1. Capture the event on the day it is found
Date discovered, products, customers, first description, and who raised it. Do not wait for a perfect root cause before the event exists on a register. Regzact can assist: record the event on the Errors register immediately.
2. Triage against every applicable clock
Is it a Consumer Duty harm issue? A SUP 15 / operational-incident notification? An ICO breach? A DISP complaint? Assign a severity and an owner. Regzact can assist: categorise the entry, generate tasks, and alert the right people.
3. Contain, remediate, and treat affected customers fairly
Stop the failure, identify everyone affected, put them back in the position they should have been in, and keep evidence of contact. If it becomes a complaint, follow DISP. Regzact can assist: track actions, send emails, and chase owners with reminders.
4. Record root cause and report trends
SYSC and Consumer Duty both expect you to learn. Board MI should show volumes, harm, repeat causes and whether controls actually changed. Regzact can assist: capture root cause, attach evidence, and run management reporting and risk analysis.
3 What records do I need to keep
If the FCA asks how you spotted, fixed and learned from an error, you need a file — not a reconstruction from chat history.
- Description, discovery date, period of occurrence, and how it was found
- Customers affected, financial impact, and remediation paid
- Root cause, control gaps, and the actions taken to prevent recurrence
- Customer communications and any DISP complaint file
- Internal escalation (including to SMF holders / the board) and the rationale
- Copies of FCA, PRA or ICO notifications and the assessment of why they were or were not required
- Trend reporting that shows whether the same cause is repeating
4 Using AI to streamline the process
The judgement calls (is this notifiable? is the harm intolerable?) stay with the firm. AI can still take the grind out of triage and learning:
- Draft a category and a first root-cause note from the incident description
- Cluster similar events so board MI is more than a count of tickets
- Flag language that suggests a data breach, a consumer-harm threshold, or a DISP complaint
- Help draft customer communications for a human to approve
Do not let a model decide a SUP 15 or ICO notification. Use it to prepare the file; keep the decision with compliance.
5 How Regzact can help
The Errors register gives you a single place to record operational events, work them through, and evidence the outcome.
- Structured capture, triage and task generation
- Emails, reminders and alerts so owners do not miss a notification window
- Root-cause fields, evidence attachments and an audit trail
- Management reporting and risk analysis across errors and related registers
Staff SM&CR records, partner profiles and sanctions checks sit alongside the incident file. Regzact can assist with each step of this process.
This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.