Proven Duty

Ongoing vulnerability monitoring: logs, triggers and reassessment

Vulnerability is not a one-time check. Once a signal is logged, the record needs to stay live — a reassessment cadence, an evidence trail, and board visibility.

What the FCA says about ongoing monitoring

The duty to act for vulnerable customers is not discharged at the point of sale — it continues for as long as the client is served. The FCA's Consumer Duty pages frame this as part of the firm's monitoring of outcomes: the assessment is revisited, the record is kept live, and the results feed the firm's view of whether customers are getting good outcomes.

The recurring lesson in the FCA's Enforcement Watch series is the snapshot problem: a signal noticed once, logged nowhere, and by the next review the trail has gone cold. Monitoring is the record that keeps the client's situation current.

The monitoring loop

The triggers that keep the record live

Monitoring does not wait for the annual review. The record is updated whenever a trigger appears: a change of job, a bereavement, a complaint about debt, a request to access pension funds early in retirement, a missed payment, or a change in health. Each trigger prompts a re-check of the four drivers and a dated note of what changed.

Worked example: a signal logged and followed

One client, two outcomes for the same signal. Anonymised and illustrative.

Before

A bereavement was mentioned in a call. Nothing was logged. At the annual review months later there is no trace, no reassessment, and no record that the firm knew about the change at all.

After

The signal was logged the next day — date, source, driver (life events). A reassessment was set for three months. At that review the outcome was recorded (income gap identified), adjustments were made (timeline extended, fees spread), and the board summary picked up the vulnerability count.

Common mistakes in ongoing monitoring

The monitoring record at a glance

FieldWhat to recordWhy it matters
SignalThe indicator, date, and source.Time-stamped evidence, not reconstruction.
Reassessment dateThe next review point, set at log time.Keeps the record live and the follow-up scheduled.
OutcomeWhat the reassessment found, with reasoning.The trail of consideration, not just a label.
Board visibilityCounts and outcomes in management reporting.Makes monitoring part of outcomes monitoring.

Related reads

Ongoing monitoring is the follow-through on the vulnerable customers hub. Use the per-file adjustment checklist for what changes when a signal is logged, and the one-paragraph documentation wording to keep each reassessment evidenced.

Frequently asked questions

When should a signal be logged?

The moment it is noticed. A signal reconstructed weeks later is weaker evidence and easily lost; a record made at the time carries the date, the source, and the context that make it credible.

How often should we reassess?

There is no fixed cadence — the reassessment date is set when the signal is logged, based on the client's circumstances. The record shows the date set and the follow-up that happened.

Does vulnerability monitoring feed the board report?

Yes. Vulnerability counts and outcomes are part of outcomes monitoring, not a separate exercise — the board report carries them alongside review results so the loop is visible.

Your next step

Pick one client with an open vulnerability signal and run it through the loop: log, date, reassess, record, escalate to the summary. Start a free trial or see pricing.