How to Respond to a Dear CEO Letter Without Self-Incriminating
This guide sets out how to structure a response to an FCA Dear CEO letter that credibly engages with thematic findings while protecting the firm from admissions of specific control failures. It equips senior leaders to calibrate tone, sequencing, and evidence so the response advances remediation without creating supervisory or enforcement exposure.
A Dear CEO letter is not a compliance exercise. It is a supervisory instrument designed to shift the burden of proof onto the firm, and the response you file will be read years later by enforcement lawyers, skilled persons, and potentially claimants. The task is to demonstrate that the board has genuinely absorbed the FCA's thematic concerns and is acting on them, without conceding that the specific failures identified across the sector exist in your firm in the form described.
Key Executive Takeaways
- Treat the response as a supervisory artefact that will be quoted back to you: every sentence should survive being read in an enforcement context.
- Separate thematic acknowledgement from firm-specific attestation. You can accept the FCA's concerns are legitimate without accepting they crystallise in your firm.
- Anchor the response in a gap analysis you commissioned and controlled, not one the FCA can later characterise as reactive or incomplete.
Start with the reading audience, not the letter
Before drafting, map who will read the response and when. The immediate reader is your supervisor, but the durable readers are enforcement, the skilled person if one is later appointed, and internal audit. That means the response must be internally consistent with your board minutes, MI packs, and prior attestations. Pull those documents first. If your Consumer Duty board report said outcomes testing was mature, do not now describe it as nascent.
Structure the response in four blocks
A credible response has four distinct sections, in this order:
- Acknowledgement of the thematic issue. State that the board has considered the letter, understands the concerns, and agrees they are material for the sector. This is not an admission about your firm.
- Firm-specific assessment methodology. Describe how you tested whether the thematic issues manifest in your firm: who led the review, what population was sampled, what standard was applied, and when it concluded. This is where you earn the right to make firm-specific claims later.
- Findings, calibrated. Report what you found in language that is precise. Distinguish between areas where controls operate as designed, areas where design is sound but execution needs strengthening, and areas where you have identified genuine gaps. Do not use the FCA's own characterisation verbatim unless it fits.
- Actions, owners, dates. Commit only to what you will deliver. Every action should have a named executive owner and a date the board has approved.
The language calibration that matters
The difference between "we have identified opportunities to strengthen" and "we have identified control weaknesses" is the difference between a routine supervisory exchange and a s.166 trigger. Use the language of continuous improvement for areas where controls work but could be sharpened. Reserve the language of gaps and remediation for issues you have already decided to disclose and fix. Never use hedged language to describe something that is actually a failure: supervisors read through it, and it damages credibility for the issues where your calibration is genuine.
What most firms get wrong
Three errors recur. First, over-attestation: signing off that the firm is fully compliant across every dimension of the thematic finding, which supervisors instantly discount and which becomes a hostage document if a failure later emerges. Second, defensive minimisation: dismissing the FCA's concerns as not applicable, which almost always invites a follow-up request or a visit. Third, action inflation: committing to 30 remediation actions to look thorough, then missing dates. Five well-chosen, delivered commitments beat 30 slipped ones.
Governance the letter itself
The response should be approved by the board or a delegated committee with a minuted discussion, not just signed by the CEO. The minute matters: it evidences that the board applied challenge. Ensure the paper to the board includes the alternative drafting choices you rejected and why. If enforcement ever asks whether the board understood what it was attesting to, the minute is your answer.
Next decision point
Before you draft, decide who owns the pen: general counsel, the CRO, or compliance. That single choice determines whether the response reads as a legal document, a risk document, or a regulatory document. For most Dear CEO responses, general counsel should own the final draft with the CRO owning the findings section. Make that call now, before drafting begins.
Frequently Asked Questions
Should we disclose issues the FCA has not specifically asked about?
Only if they are within the thematic scope of the letter and you would struggle to justify their omission if later discovered. Volunteering unrelated issues sets a precedent for disclosure you may regret.
How detailed should the remediation plan be?
Detailed enough that a supervisor can see governance, ownership, and milestones, but not so granular that every internal slippage becomes a reportable breach of your own commitments. Commit at outcome level, manage delivery at task level.
Can we push back on the FCA's characterisation of the thematic issue?
Yes, but rarely in the response itself. If you disagree materially, raise it in a supervisory meeting first and reflect the agreed position in the written response. Written disagreement without prior dialogue reads as defensive.
Who should sign the response?
The CEO, with clear evidence that the board or relevant committee approved it. A response signed by compliance or the CRO alone signals the board has not engaged.
How long should the response be?
Long enough to be credible, short enough to be read. For most thematic letters, 8 to 15 pages plus appendices covering methodology and action plans is the right range.
Frequently asked questions
Should we disclose issues the FCA has not specifically asked about?
Only if they are within the thematic scope of the letter and you would struggle to justify their omission if later discovered. Volunteering unrelated issues sets a precedent for disclosure you may regret.
How detailed should the remediation plan be?
Detailed enough that a supervisor can see governance, ownership, and milestones, but not so granular that every internal slippage becomes a reportable breach of your own commitments. Commit at outcome level, manage delivery at task level.
Can we push back on the FCA's characterisation of the thematic issue?
Yes, but rarely in the response itself. If you disagree materially, raise it in a supervisory meeting first and reflect the agreed position in the written response. Written disagreement without prior dialogue reads as defensive.
Who should sign the response?
The CEO, with clear evidence that the board or relevant committee approved it. A response signed by compliance or the CRO alone signals the board has not engaged.
How long should the response be?
Long enough to be credible, short enough to be read. For most thematic letters, 8 to 15 pages plus appendices covering methodology and action plans is the right range.
Related guides
How to Challenge a PRA Pillar 2A Add-On Without Damaging the Relationship
This guide sets out how to structure a technically robust challenge to a PRA Pillar 2A capital add-on while protecting your supervisory standing. After reading, you will know how to sequence the challenge, frame the evidence, and manage the supervisory dynamic to secure a meaningful reduction.
How to Structure a Recovery Plan Playbook That Passes PRA Credibility Tests
This guide sets out how to build a Recovery Plan playbook that meets the PRA's credibility, usability and timeliness expectations without creating documents that could damage confidence if they surface externally. After reading, you will know how to sequence indicators, options and governance triggers so the plan works as a live management tool rather than a compliance artefact.
How to Structure an Operational Resilience Self-Assessment That Withstands Regulator Challenge
This guide sets out how to build an operational resilience self-assessment that holds up to FCA and PRA impact tolerance scrutiny. After reading, senior leaders will know how to sequence evidence, frame judgements, and pre-empt the challenges supervisors are most likely to raise.
How to Structure a Pillar 2 Liquidity Narrative That Anticipates PRA ILAAP Challenge
This guide sets out how to build an ILAAP liquidity narrative that pre-empts the specific challenges PRA supervisors raise on Pillar 2 risks. After reading, senior leaders will know how to sequence the document, where to concentrate evidence, and how to defend judgement calls under supervisory pressure.
How to Structure a Solvency II ORSA Narrative That Pre-empts PRA Capital Challenge
This guide sets out how to build an ORSA narrative that anticipates PRA scrutiny on capital adequacy, risk quantification, and management action credibility. After reading it, senior insurance leaders will know how to sequence the document, evidence key judgements, and close the gaps supervisors most often probe.
Where a specific question needs an outside answer, quickly
Polar Insight's Expert Network connects leadership teams with practitioners who can speak to a precise regulatory, commercial, or stakeholder question before a decision is finalised.
Explore Expert Network