Ongoing vulnerability monitoring: logs, triggers and reassessment
Vulnerability is not a one-time check. Once a signal is logged, the record needs to stay live — a reassessment cadence, an evidence trail, and board visibility.
What the FCA says about ongoing monitoring
The duty to act for vulnerable customers is not discharged at the point of sale — it continues for as long as the client is served. The FCA's Consumer Duty pages frame this as part of the firm's monitoring of outcomes: the assessment is revisited, the record is kept live, and the results feed the firm's view of whether customers are getting good outcomes.
The recurring lesson in the FCA's Enforcement Watch series is the snapshot problem: a signal noticed once, logged nowhere, and by the next review the trail has gone cold. Monitoring is the record that keeps the client's situation current.
The monitoring loop
Log the signal
The indicator, the date, and the source are recorded the moment it is noticed — not reconstructed later.
Set a reassessment cadence
When the signal is logged, the next review date is set. Circumstances change; the record should track them.
Keep the evidence trail
Each reassessment adds to the file: outcome, reasoning, adjustments. The trail is what makes the monitoring evidence.
Board visibility
Vulnerability counts and outcomes feed the board report, so vulnerability monitoring is part of outcomes monitoring — not separate.
The triggers that keep the record live
Monitoring does not wait for the annual review. The record is updated whenever a trigger appears: a change of job, a bereavement, a complaint about debt, a request to access pension funds early in retirement, a missed payment, or a change in health. Each trigger prompts a re-check of the four drivers and a dated note of what changed.
Worked example: a signal logged and followed
One client, two outcomes for the same signal. Anonymised and illustrative.
Before
A bereavement was mentioned in a call. Nothing was logged. At the annual review months later there is no trace, no reassessment, and no record that the firm knew about the change at all.
After
The signal was logged the next day — date, source, driver (life events). A reassessment was set for three months. At that review the outcome was recorded (income gap identified), adjustments were made (timeline extended, fees spread), and the board summary picked up the vulnerability count.
Common mistakes in ongoing monitoring
- The noticed-but-not-logged signal. The firm knew; the file does not — which is the same as not knowing.
- Logged with no next review date. A record without a reassessment point stops being monitoring.
- Reassessment without a record. The review happened in a meeting and never reached the file; the trail has a gap at exactly the point that matters.
- Vulnerability kept out of management reporting. If vulnerability counts and outcomes never reach the board summary, monitoring is invisible to the firm's own oversight.
The monitoring record at a glance
| Field | What to record | Why it matters |
|---|---|---|
| Signal | The indicator, date, and source. | Time-stamped evidence, not reconstruction. |
| Reassessment date | The next review point, set at log time. | Keeps the record live and the follow-up scheduled. |
| Outcome | What the reassessment found, with reasoning. | The trail of consideration, not just a label. |
| Board visibility | Counts and outcomes in management reporting. | Makes monitoring part of outcomes monitoring. |
Related reads
Ongoing monitoring is the follow-through on the vulnerable customers hub. Use the per-file adjustment checklist for what changes when a signal is logged, and the one-paragraph documentation wording to keep each reassessment evidenced.
Frequently asked questions
When should a signal be logged?
The moment it is noticed. A signal reconstructed weeks later is weaker evidence and easily lost; a record made at the time carries the date, the source, and the context that make it credible.
How often should we reassess?
There is no fixed cadence — the reassessment date is set when the signal is logged, based on the client's circumstances. The record shows the date set and the follow-up that happened.
Does vulnerability monitoring feed the board report?
Yes. Vulnerability counts and outcomes are part of outcomes monitoring, not a separate exercise — the board report carries them alongside review results so the loop is visible.
Your next step
Pick one client with an open vulnerability signal and run it through the loop: log, date, reassess, record, escalate to the summary. Start a free trial or see pricing.