How to Structure a Threshold Conditions Self-Assessment That Pre-empts FCA Withdrawal Risk
This guide sets out how boards and senior managers should structure a Threshold Conditions self-assessment that identifies authorisation withdrawal risk before the FCA does. After reading, you will know how to sequence the assessment, where the real judgement calls sit, and what evidence a supervisor expects to see.
If the FCA is asking questions about your Threshold Conditions, you are already behind. A credible self-assessment is not a compliance artefact. It is a board-owned document that demonstrates, in the supervisor's own framework, that the firm continues to satisfy the minimum conditions for authorisation, and that where risks exist, they are named, sized, and being fixed on a timetable the regulator would accept.
Key Executive Takeaways
- Structure the assessment around each Threshold Condition in COND 2, with a clear pass/watch/fail judgement supported by evidence, not assurance language.
- The highest-risk conditions in practice are Effective Supervision (2.3), Appropriate Resources (2.4), and Suitability (2.5); most withdrawal cases sit here, not in Location or Business Model.
- Sequence remediation commitments before the FCA imposes them; a voluntary requirement (VREQ) offered early is materially less damaging than one imposed under OIREQ.
Start with the trigger, not the template
Before drafting, be honest about why the assessment is being done. A pre-emptive review triggered by a board risk appetite breach, a Skilled Person report, a Dear CEO letter, or a supervisory meeting each demands a different tone and depth. If the FCA has already raised concerns, the self-assessment must directly address those concerns in the language used by the case officer. If the review is genuinely proactive, the tone can be more analytical.
What most firms get wrong: they produce a generic Threshold Conditions map that reads like a policy inventory. Supervisors discount this immediately. They are looking for evidence of self-critical judgement.
Structure the document around COND 2, condition by condition
Use the FCA's own framework. For each of the five conditions applicable to your permission (Legal Status, Location, Effective Supervision, Appropriate Resources, Suitability, and Business Model where relevant), produce a section with four parts:
- The condition, in plain terms, referenced to COND 2.X.
- Current position, with specific evidence: financial resources actuals versus TCR, governance structure, SMF coverage, control testing outcomes, customer outcome metrics.
- A judgement: pass, watch, or fail. Do not hedge. If a condition is under strain, say so.
- Actions and timetable, with named SMF owners and board-approved deadlines.
Where the real risk sits
Withdrawal cases rarely hinge on Legal Status or Location. They cluster around three conditions:
Effective Supervision (COND 2.3): group structures that obscure accountability, offshore booking models, or opaque outsourcing arrangements. If your legal entity chart requires a footnote, expect challenge.
Appropriate Resources (COND 2.4): this is not only capital and liquidity. It covers people, systems, and non-financial resources. Persistent control failures, high turnover in second line, or unresolved audit findings all sit here.
Suitability (COND 2.5): the fitness and propriety of the firm as a whole. Historic misconduct, unresolved redress, or a pattern of supervisory concerns will be read as a Suitability issue even if you frame it as an isolated incident.
Be direct about which conditions are under pressure. A self-assessment that grades every condition green is not credible and tells the supervisor you lack insight.
Get the evidence architecture right
Every judgement should link to a specific artefact: board minutes, MI packs, capital planning outputs, internal audit reports, control testing results. Maintain a source annex. If a supervisor asks for the underlying document, you should be able to produce it within a working day.
Where evidence is thin, say so and commit to producing it. Silence is read as concealment.
Sequence the board's role deliberately
The assessment should be drafted by the second line, challenged by internal audit or an external adviser, and formally adopted by the board. The board minute matters: it should record specific challenges raised and how they were resolved. A rubber-stamp approval undermines the entire document.
Offer remediation before it is demanded
If a condition is under strain, propose a voluntary requirement or an attestation before the FCA asks. This changes the supervisory posture from enforcement to remediation. Firms that wait to be told almost always end up with harsher terms.
The decision point
Before submission or filing, ask one question: if this document were disclosed in a Section 166 or an enforcement referral, would it read as the work of a board in control of its risks? If the answer is uncertain, the document is not ready.
Frequently Asked Questions
Should the self-assessment be shared with the FCA proactively?
Only if there is a supervisory reason to do so, such as a live concern, a permission variation, or a Dear CEO response. Unsolicited disclosure of a critical self-assessment can create issues it was designed to manage. Keep it board-owned and available on request.
How often should this be done?
Annually as a minimum, with an interim refresh whenever there is a material change: senior management turnover, a significant control failure, a change in group structure, or supervisory contact that raises Threshold Conditions concerns.
Who should own the assessment at SMF level?
The Chief Executive (SMF1) is ultimately accountable, but the drafting is typically coordinated by the Chief Compliance Officer (SMF16) or Chief Risk Officer (SMF4). The Chair should ensure board challenge is genuine and recorded.
What is the biggest mistake firms make?
Treating the assessment as a compliance deliverable rather than a governance document. If the board has not debated the judgement calls, the document will not survive supervisory scrutiny.
Does this apply to firms not currently under supervisory pressure?
Yes. The purpose is pre-emption. Firms that only produce a Threshold Conditions assessment when asked are already in a weaker position than those who can show a track record of self-critical review.
Frequently asked questions
Should the self-assessment be shared with the FCA proactively?
Only if there is a supervisory reason to do so, such as a live concern, a permission variation, or a Dear CEO response. Unsolicited disclosure of a critical self-assessment can create issues it was designed to manage. Keep it board-owned and available on request.
How often should this be done?
Annually as a minimum, with an interim refresh whenever there is a material change: senior management turnover, a significant control failure, a change in group structure, or supervisory contact that raises Threshold Conditions concerns.
Who should own the assessment at SMF level?
The Chief Executive (SMF1) is ultimately accountable, but the drafting is typically coordinated by the Chief Compliance Officer (SMF16) or Chief Risk Officer (SMF4). The Chair should ensure board challenge is genuine and recorded.
What is the biggest mistake firms make?
Treating the assessment as a compliance deliverable rather than a governance document. If the board has not debated the judgement calls, the document will not survive supervisory scrutiny.
Does this apply to firms not currently under supervisory pressure?
Yes. The purpose is pre-emption. Firms that only produce a Threshold Conditions assessment when asked are already in a weaker position than those who can show a track record of self-critical review.
Related guides
How to Design a Board-Level Risk Appetite Statement Regulators Will Accept
This guide sets out how to build a risk appetite statement that functions as a genuine governance tool, not a compliance artefact. After reading, you will know how to structure, calibrate, and operationalise a statement that boards can use and supervisors will credit.
How to Build a Credible ICAAP Narrative That Withstands Supervisory Scrutiny
This guide explains how to construct an ICAAP document that reads as a genuine articulation of risk, capital adequacy and board ownership rather than a compliance artefact. After reading, you will know what supervisors actually test for, where most narratives fall apart, and how to sequence the work so the story holds together under challenge.
How to Brief a Board Ahead of a Section 166 Skilled Person Review
This guide explains how to prepare your board for a Section 166 review so directors understand the scope, their obligations, and what credible engagement looks like. After reading, you will know how to structure the briefing, what to put in front of the board, and which judgement calls to surface early.
How to Prepare for a Regulator Meeting When Rules Are Open to Interpretation
A practical guide for senior leaders preparing to meet a regulator on matters where the published rules leave genuine room for judgement. Covers how to build a defensible interpretation, sequence the conversation, and demonstrate the quality of your reasoning, not just your conclusion.
What Regulators Look For in a Submission: A Practical Guide
This guide explains what regulators actually assess when reviewing a formal submission, from authorisation applications to Section 166 responses and thematic returns. After reading it, you will know how to structure a submission that reflects genuine control, sound judgement and credible governance.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity