What 5 evidence gaps does the FCA keep finding in files?
Five FCA evidence gaps in small-firm files: undocumented vulnerability, template reasoning, missing alternatives, thin monitoring, unproven ongoing value.
Why does the FCA care about evidence, not just good advice?
The FCA stopped asking whether a firm has implemented the Consumer Duty. Since 31 July 2023 the question has moved to outcomes, and outcomes are only visible in records — so the FCA's focus areas for 2025/26 put supervision where the records live: individual advice files.
Proven Duty scores suitability reports across 11 check areas, and the failures cluster: the advice is defensible, the record is not. Regarding evidence gaps, the same five show up firm after firm, and none of them is an advice error. A reviewer reads the file cold, so whatever is missing from the record never happened.
Supervision tests records, not intentions. (Source: FCA focus areas 2025/26)
Was vulnerability considered — and can you prove it?
FG21/1 expects vulnerability consideration to be documented: the characteristics checked, the outcome reached, and the reasoning. The FCA's March 2025 multi-firm review kept finding consideration that happened in the adviser's head and nowhere in the file.
Regarding vulnerability, the typical file contains one line — "no vulnerability identified" — with nothing behind it. The paraplanner considered it; the reviewer cannot see that. The fix costs one standard paragraph: the characteristics considered, the checks made, the outcome, and the reasoning. The vulnerable customers under Consumer Duty guide carries the full checklist. Regarding evidence gaps, this is the most common one — and the cheapest to close.
The documentation test has four parts: characteristics, checks, outcome, reasoning. (Source: FCA FG21/1)
Is the suitability reasoning about this client, or anyone's?
COBS 9.2.1R requires suitability reasoning specific to the client's circumstances and objectives. Template text — "your attitude to risk has been taken into account" — satisfies neither the rule nor a reviewer, because the same sentence would fit any client in any file.
Regarding suitability reasoning, the swap test catches generic text in seconds: replace the client's name and read the paragraph again. Generic reasoning passes the swap unchanged; client-specific reasoning references the client's actual objectives, figures, and circumstances, and stops making sense when they change.
The cousin failure: attitude to risk recorded where capacity for loss was required — distinct COBS elements that templates merge under one heading.
The swap test is the whole review: change the name and see whether the reasoning notices. (Source: FCA COBS 9.2.1R)
Does the file show alternatives, or just the winner?
PRIN 2A.4, the price and value outcome, lands at file level as two checks: charges shown, and realistic alternatives named with the rejection explained for this client. Files routinely show the cost and assert the comparison — "representing better value than the alternatives" — without naming one.
Regarding price and value, the assertion fails where the comparison passes. A file that names two or three realistic alternatives, sets comparable figures against them, and explains why this client should not hold them produces evidence. A file that repeats the word "value" produces a claim. The comparison need not be long — only specific enough that a reviewer could reconstruct the decision from the record.
"Better value than the alternatives" invites one question: which ones? PRIN 2A.4 wants the answer in the file. (Source: FCA PRIN 2A.4)
Is monitoring structured, or a stack of sampling logs?
The November 2025 requirements review expects monitoring to be structured, repeated, and evidenced. A folder of sampling logs with pass marks records activity, not monitoring — no fixed rubric, no grading standard, no trend line, no fixes tracked to closure.
Regarding monitoring, the distinction is the system, not the effort. Monitoring means a fixed set of check areas applied the same way every cycle, graded outcomes, gaps logged with fixes, and a summary the board can read. Sampling is an input to that system; on its own it is a to-do list with ticks. The FCA's own good-practice material shares the shape: standard applied, result recorded, exception actioned.
A sampling log records that someone looked. Monitoring records what was looked for, against what standard, and what changed. (Source: FCA requirements review, November 2025)
Can you show value for the ongoing fee?
PRIN 2A.6 expects clients to receive the service they were promised, and TR24/1 para 1.40 shows the FCA testing that promise against the charge. The gap in files: the annual fee is collected, the review meeting happens, and the record shows neither the service nor its value.
Regarding ongoing service, the per-client log is the whole defence — service delivered, when, its value against the fee, and the next review date. Fee-for-no-service exposure builds in exactly the files where the fee renews and the record does not.
The fee and the file must tell the same story year on year. (Source: FCA TR24/1 para 1.40)
How do you close the gaps before the FCA asks?
Regarding evidence gaps, the fix is structural rather than heroic: a fixed pre-send checklist, a standard vulnerability paragraph, named alternatives with reasons, a graded monitoring log, and a per-client service record.
| Gap | Rule behind it | Evidence that closes it |
|---|---|---|
| Undocumented vulnerability | FG21/1 | Characteristics, checks, outcome, reasoning |
| Template reasoning | COBS 9.2.1R | Client-specific objectives, figures, circumstances |
| Alternatives asserted, not named | PRIN 2A.4 | Named alternatives + rejection reasons |
| Sampling without monitoring | Requirements review (Nov 2025) | Fixed rubric, graded log, tracked fixes |
| Fee without recorded value | PRIN 2A.6; TR24/1 | Per-client service and value log |
Table: The five gaps, the rules behind them, and the record that closes each one.
The Consumer Duty file reviews guide maps the 12-point pre-send check to the same areas. Closing the gaps before an FCA information request, a FOS case, or a PI renewal is the entire point — after the ask, the same five gaps cost explanations instead of paragraphs.
Consumer Duty evidence is the record that good advice happened. The record is the only part a reviewer will ever see.
About the Author: Nick Thorp is the founder of Proven Duty, which automates Consumer Duty file reviews and outcomes monitoring for 1-5 adviser firms. He writes about what the Duty means at file level. Connect on LinkedIn.
Frequently asked questions
Why does the FCA care about evidence, not just good advice?
Since 31 July 2023 the FCA tests outcomes, and outcomes are only visible in records. The September 2025 focus areas and the November 2025 requirements review moved supervision from policy documents to individual files, so the record is what gets inspected.
Was vulnerability considered — and can you prove it?
FG21/1 expects documented consideration: the characteristics checked, the outcome, and the reasoning. The March 2025 multi-firm review kept finding consideration that happened but was never recorded. An unrecorded judgement is invisible to a reviewer.
Is the suitability reasoning about this client, or anyone's?
COBS 9.2.1R requires reasoning specific to the client's circumstances. Template text fits any client in any file. The swap test catches it: change the client's name and see whether the paragraph notices.
Does the file show alternatives, or just the winner?
PRIN 2A.4 lands at file level as two checks: charges shown, and realistic alternatives named with the rejection explained. Files routinely show the cost and assert the comparison without naming a single alternative.
Is monitoring structured, or a stack of sampling logs?
The November 2025 requirements review expects monitoring to be structured, repeated, and evidenced. Sampling logs with pass marks record activity, not monitoring — no rubric, no grading standard, no trend, no fixes tracked.
Can you show value for the ongoing fee?
PRIN 2A.6 expects clients to receive the service they were promised, and TR24/1 para 1.40 shows the FCA testing exactly that. The file needs the service delivered, when, its value against the fee, and the next review.
How do you close the gaps before the FCA asks?
The five gaps share one root: good work that leaves no record. The fix is structural — a fixed checklist, a standard vulnerability paragraph, named alternatives, a graded monitoring log, and a per-client service record.
Consumer Duty guides
See what your files are missing
Run one suitability report through the AI file review and get a Pass / Amber / Fail score against Consumer Duty checks.
Try the free file review