How to Structure a Consumer Duty Board Report That Withstands FCA Scrutiny
This guide sets out how to build a Consumer Duty board report that demonstrates genuine oversight rather than compliance theatre. After reading, you will know what evidence to include, how to structure judgements, and where FCA scrutiny is most likely to bite.
The FCA has been explicit: annual Consumer Duty board reports are a window into whether firms are actually delivering good outcomes, or whether they are dressing up business as usual. Reports that read like marketing decks, or that lean on green RAG ratings without evidence, are the ones that attract follow-up questions, s.165 requests, and skilled person reviews. The bar is higher than most firms are meeting.
Key Executive Takeaways
- The report must show outcomes data, not activity data: what happened to customers, segmented by vulnerability and cohort, with honest commentary on what the numbers mean.
- Board challenge must be visible on the page. If minutes, questions, and resulting actions are not documented in the report itself, the FCA will assume oversight was passive.
- Every identified issue needs a named owner, a deadline, and a follow-through trail in the next report. Unresolved issues that quietly disappear are the single biggest credibility risk.
Start with the question the FCA is actually asking
The supervisor reading your report wants to answer one question: does this board understand whether its customers are getting good outcomes, and is it acting on what it sees? Structure the document to answer that directly. A useful test: if a supervisor read only the executive summary and the actions log, would they conclude the board is in control? If not, rewrite.
Build the report around the four outcomes, not your org chart
Too many reports are structured by business line or by function. That makes it hard for a reader to assess outcomes coherently. Structure by the four outcomes (products and services, price and value, consumer understanding, consumer support), and within each, present:
- The metrics you monitor and why they were chosen.
- Trend data across at least four quarters, not point-in-time snapshots.
- Segmented performance, particularly for vulnerable customers and distinct cohorts.
- Where the metric sits against your tolerance, and what the board concluded.
If a metric moved adversely and the commentary says "within appetite," explain why appetite is set where it is. Unexplained tolerance is a red flag.
Evidence, not assertion
The most common failure mode: assertions like "our products continue to deliver fair value" with no supporting evidence. Replace every such sentence with a specific data point, a customer research finding, or a file review result. Fair value assessments should reference the underlying analysis, including the assumptions and their sensitivities. If you have not stress-tested your fair value conclusions against a plausible downside, expect that question in writing.
Make vulnerability analysis specific
Aggregate vulnerability percentages tell the FCA nothing. What they want: how vulnerable customers experience your journeys differently, where drop-offs and complaints concentrate, and what you have changed as a result. If your report says vulnerability data is not yet available at the granularity needed, say so, and give the date it will be. Silence on data gaps reads as concealment.
Show the board doing its job
The report is evidence of oversight. Include:
- Specific challenges raised by non-executive directors, with names or roles attached.
- Instances where the board rejected or amended a management recommendation.
- Actions carried forward from the previous report, with status and honest commentary on delays.
A report that never records disagreement, delay, or bad news is not credible. Boards that only see good news are not overseeing anything.
Handle the difficult judgements openly
Every firm has areas where the answer is genuinely unclear: legacy products with imperfect data, distributor arrangements where end-customer outcomes are hard to see, price differentials between cohorts. Name these. Explain the current view, the uncertainty, and what work is planned. Firms that pretend certainty they do not have get caught out when the FCA tests the underlying analysis.
What good looks like
A strong report is roughly 30 to 50 pages, opens with a clear executive summary written in the board's voice, contains no marketing language, and includes a forward-looking section on emerging risks. Weak reports are either 10 pages of assertion or 200 pages of dashboards with no synthesis. The FCA is looking for judgement, not volume.
Your next decision
Before the next report cycle, run a red-team review: ask someone independent (internal audit, external counsel, or a specialist adviser) to read the draft as if they were a supervisor. If they cannot articulate your customer outcomes story in three sentences after reading it, the report is not yet fit to go to the board.
Frequently Asked Questions
How much detail on individual products should the report contain?
Enough to show the board understood the material risks. For most firms, that means a portfolio-level view plus focused deep analysis on products flagged as higher risk, whether by complaint volumes, fair value concerns, or vulnerability exposure. Do not attempt to cover every product equally.
Should we disclose issues we are still investigating?
Yes. Emerging concerns, with the analysis in progress and a date for resolution, are more credible than a report that only surfaces issues once they are neatly resolved. Suppressed problems that later surface through complaints or whistleblowing damage credibility far more.
How do we handle third-party distributor outcomes we cannot fully see?
Be explicit about the limits of your visibility, describe the information you do receive, and set out what you are doing to strengthen it. The FCA understands the challenge. What it does not accept is silence or vague assurances.
Who should draft the report?
Not the first line alone. The strongest reports are drafted by a small group including the Consumer Duty champion, risk, and someone with direct board exposure, with visible input from the second line. Reports written entirely by compliance tend to read defensively.
Frequently asked questions
How much detail on individual products should the report contain?
Enough to show the board understood the material risks. For most firms, that means a portfolio-level view plus focused deep analysis on products flagged as higher risk, whether by complaint volumes, fair value concerns, or vulnerability exposure. Do not attempt to cover every product equally.
Should we disclose issues we are still investigating?
Yes. Emerging concerns, with the analysis in progress and a date for resolution, are more credible than a report that only surfaces issues once they are neatly resolved. Suppressed problems that later surface through complaints or whistleblowing damage credibility far more.
How do we handle third-party distributor outcomes we cannot fully see?
Be explicit about the limits of your visibility, describe the information you do receive, and set out what you are doing to strengthen it. The FCA understands the challenge. What it does not accept is silence or vague assurances.
Who should draft the report?
Not the first line alone. The strongest reports are drafted by a small group including the Consumer Duty champion, risk, and someone with direct board exposure, with visible input from the second line. Reports written entirely by compliance tend to read defensively.
Related guides
How to Evidence Consumer Duty Outcomes to the Board and the FCA
A practical guide to building Consumer Duty evidence that withstands board challenge and FCA scrutiny. After reading, you will know what good evidence looks like, where most firms fall short, and how to structure your annual board report so it earns trust rather than questions.
Stakeholder Risk Management for FCA Regulated Firms: A Practical Guide
This guide sets out how senior leaders at FCA regulated firms should identify, assess, and manage stakeholder risk in a way that stands up to supervisory scrutiny. After reading it, you will know how to structure a stakeholder risk framework that aligns with Consumer Duty, SM&CR, and Threshold Conditions, and where firms typically fail.
What Makes a Decision Defensible to Regulators: A Practical Guide
This guide explains what regulators actually look for when they test a major decision after the fact, and how to build defensibility into the decision itself rather than reconstruct it later. You will finish with a clear view of what to document, who to involve, and where most firms leave themselves exposed.
How to Make a Defensible Board Decision
A practical guide to constructing board decisions that hold up under regulatory, legal, and shareholder scrutiny long after the vote. Readers will finish knowing what to document, how to structure the discussion, and where most boards leave themselves exposed.
How to Handle a Pre-Emptive Regulator Meeting After a Governance Failure
This guide covers how to prepare for and run a self-initiated regulator meeting when you have discovered a material governance failure inside your firm. After reading, you will know how to sequence the disclosure, frame the failure, and position remediation in a way that preserves credibility and controls the supervisory response.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity