The Consumer Duty file-review checklist: 12 checks every suitability report should clear
Before a suitability report leaves your desk, it should clear these twelve checks. This is the short version of the rubric used for file review.
Each check maps to an FCA rule and to a check area in the Consumer Duty default rubric. The rule citations below are the ones carried in the rubric's guidance fields.
The 12 checks at a glance
| Check | What to look for | FCA rule |
|---|---|---|
| Objectives | The rationale draws on the client's objectives, not a generic template. | COBS 9.2.1R / COBS 9A.3.3R(1)(b) |
| Vulnerability | Vulnerability consideration is on the file, including the conclusion that no indicators were identified. | FG21/1 |
| Charges | Initial and ongoing charges, with the impact on returns, in terms the client can follow. | PRIN 2A.4 / COBS 9.4.7R(2) |
| Services | The ongoing service is stated, including what it covers and the ongoing charge for it. | PRIN 2A.6 / COBS 9A.3.3R(2) |
| Risks | Key risks are explained for this client in plain language, not generic warnings. | COBS 9.4.7R(2) / Principle 7 |
| Cancellation rights | The client can cancel the ongoing service, and the route is stated in terms they can follow. | PRIN 2A.6 / COBS 9A.3.3R(2) |
| Value for money | The recommendation is justified against the cost, in the context of this client — not just that it fits. | PRIN 2A.4 / COBS 9.4.7R(2) |
| Alternatives | Named alternatives, with the reason they were not recommended — not a bare statement that they were considered. | COBS 9.4.7R(2) / FG12/16 |
| Attitude to risk | The recorded risk profile matches the recommendation and is consistent through the file. | COBS 9.2.2R / COBS 9A.3.3R(1)(b)(iii) |
| Capacity for loss | The client's ability to bear losses is addressed against their stated circumstances, with the impact of a loss shown. | COBS 9.2.2R / COBS 9A.3.3R(1)(b)(iii) |
| Knowledge and experience | The recommendation is grounded in what the client actually understands and has experience of, not a standard assumption. | COBS 9.2.1R / COBS 9A.3.3R(1)(b) |
| Ongoing service | The report states whether the arrangement is likely to require periodic review and what happens next. | PRIN 2A.6 / COBS 9A.3.3R(2) |
| Check | Result | What the reviewer sees |
|---|---|---|
| ObjectivesReport §2 | PASS | Rationale quotes the client's objective in their own words |
| VulnerabilityReport §4 | PASS | Considered and documented; no indicators identified, reason given |
| ChargesReport §6, p.3 | AMBER | Ongoing charge stated, but impact on returns not shown |
| AlternativesReport §7 | FAIL | Alternatives named without the reason they were discounted |
| Capacity for lossReport §5 | PASS | Loss impact addressed against stated circumstances |
| Ongoing serviceReport §9 | AMBER | Review promised, but no next review date |
What the FCA says: why the checklist exists
The checklist exists because the Consumer Duty and the COBS 9 and COBS 9A rules ask a report to carry more than a recommendation. The report must explain why the recommendation is suitable (COBS 9.4.7R(2)), set out possible disadvantages (COBS 9.4.7R(3)), and be based on the client's actual needs and circumstances, including attitude to risk and capacity for loss (COBS 9.2.1R and COBS 9.2.2R). The FCA's Consumer Duty pages set these expectations out in full.
The FCA reviews files the way a reviewer reads them cold: if the evidence is not in the file, it does not exist. The Consumer Duty publications library holds the firm-level guidance and the good- and poor-practice examples that show the standard. The twelve checks are that standard, split into items a file can be scored against.
The FCA's enforcement lessons keep returning to the same gap, set out in its Enforcement Watch series: firms that could not show what a recommendation was based on because the report never carried the evidence. This checklist is the pre-send answer to that failure — run before the report leaves the desk, not after a request arrives.
Objectives
Rubric: client_circumstances
The client's stated goals appear in the rationale, in the client's own words where possible.
The rationale draws on the client's objectives, not a generic template.
FCA reference: COBS 9.2.1R / COBS 9A.3.3R(1)(b)
Vulnerability
Rubric: vulnerability_assessment
Considered and documented — or explicitly ruled out, with why.
Vulnerability consideration is on the file, including the conclusion that no indicators were identified.
FCA reference: FG21/1
Charges
Rubric: cost_disclosure
Full disclosure, including ongoing.
Initial and ongoing charges, with the impact on returns, in terms the client can follow.
FCA reference: PRIN 2A.4 / COBS 9.4.7R(2)
Services
Rubric: ongoing_service_commitment
What the client gets, especially ongoing.
The ongoing service is stated, including what it covers and the ongoing charge for it.
FCA reference: PRIN 2A.6 / COBS 9A.3.3R(2)
Risks
Rubric: risk_disclosure
Specific to this recommendation, not boilerplate.
Key risks are explained for this client in plain language, not generic warnings.
FCA reference: COBS 9.4.7R(2) / Principle 7
Cancellation rights
Rubric: ongoing_service_commitment
Present, correct, plain English.
The client can cancel the ongoing service, and the route is stated in terms they can follow.
FCA reference: PRIN 2A.6 / COBS 9A.3.3R(2)
Value for money
Rubric: cost_disclosure
Why this product, at this cost, for this client.
The recommendation is justified against the cost, in the context of this client — not just that it fits.
FCA reference: PRIN 2A.4 / COBS 9.4.7R(2)
Alternatives
Rubric: product_alternatives
What else was considered, and why discounted.
Named alternatives, with the reason they were not recommended — not a bare statement that they were considered.
FCA reference: COBS 9.4.7R(2) / FG12/16
Attitude to risk
Rubric: capacity_loss
Documented, consistent with the recommendation.
The recorded risk profile matches the recommendation and is consistent through the file.
FCA reference: COBS 9.2.2R / COBS 9A.3.3R(1)(b)(iii)
Capacity for loss
Rubric: capacity_loss
Tied to actual circumstances.
The client's ability to bear losses is addressed against their stated circumstances, with the impact of a loss shown.
FCA reference: COBS 9.2.2R / COBS 9A.3.3R(1)(b)(iii)
Knowledge and experience
Rubric: client_circumstances
Relevant, not generic.
The recommendation is grounded in what the client actually understands and has experience of, not a standard assumption.
FCA reference: COBS 9.2.1R / COBS 9A.3.3R(1)(b)
Ongoing service
Rubric: ongoing_service_commitment
What happens next, and when.
The report states whether the arrangement is likely to require periodic review and what happens next.
FCA reference: PRIN 2A.6 / COBS 9A.3.3R(2)
Vulnerability is the one most likely to be missed — and the one the FCA's FG21/1 guidance is built around. If a file does not show that vulnerability was considered, a reviewer reading it cold cannot tell whether it was.
Worked example: the same report, checked and unchecked
The same recommendation, two ways. Anonymised and illustrative.
Before
“Recommended a growth portfolio to meet your objectives. The ongoing charge is 0.75%.” — no objectives in the client's own words, no attitude to risk, no capacity for loss, no alternatives, no disadvantages, no review date.
After
The same recommendation carrying all twelve: objectives restated in the client's words, vulnerability considered and ruled out with why, charges shown with their impact on returns, alternatives named and discounted, risks specific to the recommendation, the ongoing service and next review date stated, and a value-for-money paragraph tying the cost to this client's circumstances.
The after version also carries its dates — the report date, the review date, and the next review date — so the timing of the follow-up is part of the evidence, not an afterthought.
The checks that fail most often
- Vulnerability (FG21/1). The most common single miss. Consideration and its outcome need a line in the file, even when nothing is found.
- Alternatives. Alternatives are named or skipped entirely; the file must say what else was considered and why this recommendation won for this client.
- Capacity for loss. Attitude to risk is recorded and capacity for loss is inferred or missing. Both are distinct check areas; the ATR-versus-capacity distinction matters because a client can be willing to take risk and unable to bear the loss.
- Ongoing service. The service and its next review date are left vague, which leaves the value of an ongoing charge undocumented.
How to run the twelve in one pass
The twelve are quickest run as four phases rather than twelve separate reads:
- Assemble. Pull the report, the fact find, the risk questionnaire, and the service record into one view.
- Score. Score each check Pass or Amber against the summary and what-to-check lines above, noting the file reference for each.
- Fix. Return the Ambers to the adviser with the specific gap, and re-score once fixed.
- Second read. Read the final report cold — as a reviewer would — before it ships.
The scored output of that pass is itself evidence: it shows a review happened, what it found, and what changed. The methodology evidence guide explains how to keep that record defensible.
Reading the scores: pass, amber, fail
The twelve are scored in three tiers, and a reviewer reads each tier the same way every time:
Pass
The evidence is present, specific, and reasoned for this client. The check area is answered and the file supports it.
Amber
Something is there but it is thin — vulnerability considered without the characteristics listed, charges shown without their impact, alternatives named without a reason. Amber is fix-before- ship; if a file ships amber, the reason is recorded alongside it.
Fail
The item is missing entirely — no vulnerability line, no alternatives, no review date. A fail does not ship; the report returns to the adviser with the specific gap.
The tier, the reason, and the fix are recorded for every check. That scored record is what an outcomes-monitoring review or an information request asks to see — it shows the review ran, what it found, and what changed as a result.
Related reads
This checklist is the pre-send gate for the file review and suitability hub. Read the eleven-rule mapping for where each check comes from, and the 12-section report anatomy for where each check lands in the report.
Frequently asked questions
Do all twelve checks apply to every report?
The twelve are the fixed set the rubric scores, but how each is evidenced scales with the recommendation. A simple product needs a shorter rationale than a complex one; the check that it is present and reasoned does not change.
Can I run the checklist in my own system?
Yes. The twelve checks are a scoring grid, not a tool requirement — a spreadsheet with one row per check and a Pass/Amber/Fail per file reproduces it. What matters is that the same checks run on every file and the results are kept.
What happens if a check fails?
The report does not go out until the check is fixed or the amber is explained and recorded. A file with a documented amber and a reason reads differently from one with the item missing entirely.
Does the checklist replace a compliance review?
No. The checklist is the pre-send gate that turns a draft into a reviewable file. A compliance consultant or reviewer signs off on the judgement; the checklist makes sure the evidence is in front of them.
Your next step
Run one report through the twelve before it goes out next time, and keep the scored result on file. Proven Duty scores files against a fixed version of this rubric and returns the per-check output, so the evidence trail builds itself. Start a free trial or see pricing.
Sources
- COBS 9.2 (FCA Handbook)
- COBS 9.4 (FCA Handbook)
- COBS 9A.3 (FCA Handbook)
- PRIN 2A.4 — The price and value outcome (FCA Handbook)
- PRIN 2A.6 — The consumer support outcome (FCA Handbook)
- FG21/1 — Guidance for firms on the fair treatment of vulnerable customers (FCA)
- FG12/16 — Assessing suitability: replacement business and centralised investment propositions (FCA)