Skip to main content

How to Structure a Threshold Conditions Self-Assessment That Pre-empts FCA Withdrawal Risk

This guide sets out how boards and senior managers should structure a Threshold Conditions self-assessment that identifies authorisation withdrawal risk before the FCA does. After reading, you will know how to sequence the assessment, where the real judgement calls sit, and what evidence a supervisor expects to see.

If the FCA is asking questions about your Threshold Conditions, you are already behind. A credible self-assessment is not a compliance artefact. It is a board-owned document that demonstrates, in the supervisor's own framework, that the firm continues to satisfy the minimum conditions for authorisation, and that where risks exist, they are named, sized, and being fixed on a timetable the regulator would accept.

Key Executive Takeaways

  • Structure the assessment around each Threshold Condition in COND 2, with a clear pass/watch/fail judgement supported by evidence, not assurance language.
  • The highest-risk conditions in practice are Effective Supervision (2.3), Appropriate Resources (2.4), and Suitability (2.5); most withdrawal cases sit here, not in Location or Business Model.
  • Sequence remediation commitments before the FCA imposes them; a voluntary requirement (VREQ) offered early is materially less damaging than one imposed under OIREQ.

Start with the trigger, not the template

Before drafting, be honest about why the assessment is being done. A pre-emptive review triggered by a board risk appetite breach, a Skilled Person report, a Dear CEO letter, or a supervisory meeting each demands a different tone and depth. If the FCA has already raised concerns, the self-assessment must directly address those concerns in the language used by the case officer. If the review is genuinely proactive, the tone can be more analytical.

What most firms get wrong: they produce a generic Threshold Conditions map that reads like a policy inventory. Supervisors discount this immediately. They are looking for evidence of self-critical judgement.

Structure the document around COND 2, condition by condition

Use the FCA's own framework. For each of the five conditions applicable to your permission (Legal Status, Location, Effective Supervision, Appropriate Resources, Suitability, and Business Model where relevant), produce a section with four parts:

  1. The condition, in plain terms, referenced to COND 2.X.
  2. Current position, with specific evidence: financial resources actuals versus TCR, governance structure, SMF coverage, control testing outcomes, customer outcome metrics.
  3. A judgement: pass, watch, or fail. Do not hedge. If a condition is under strain, say so.
  4. Actions and timetable, with named SMF owners and board-approved deadlines.

Where the real risk sits

Withdrawal cases rarely hinge on Legal Status or Location. They cluster around three conditions:

Effective Supervision (COND 2.3): group structures that obscure accountability, offshore booking models, or opaque outsourcing arrangements. If your legal entity chart requires a footnote, expect challenge.

Appropriate Resources (COND 2.4): this is not only capital and liquidity. It covers people, systems, and non-financial resources. Persistent control failures, high turnover in second line, or unresolved audit findings all sit here.

Suitability (COND 2.5): the fitness and propriety of the firm as a whole. Historic misconduct, unresolved redress, or a pattern of supervisory concerns will be read as a Suitability issue even if you frame it as an isolated incident.

Be direct about which conditions are under pressure. A self-assessment that grades every condition green is not credible and tells the supervisor you lack insight.

Get the evidence architecture right

Every judgement should link to a specific artefact: board minutes, MI packs, capital planning outputs, internal audit reports, control testing results. Maintain a source annex. If a supervisor asks for the underlying document, you should be able to produce it within a working day.

Where evidence is thin, say so and commit to producing it. Silence is read as concealment.

Sequence the board's role deliberately

The assessment should be drafted by the second line, challenged by internal audit or an external adviser, and formally adopted by the board. The board minute matters: it should record specific challenges raised and how they were resolved. A rubber-stamp approval undermines the entire document.

Offer remediation before it is demanded

If a condition is under strain, propose a voluntary requirement or an attestation before the FCA asks. This changes the supervisory posture from enforcement to remediation. Firms that wait to be told almost always end up with harsher terms.

The decision point

Before submission or filing, ask one question: if this document were disclosed in a Section 166 or an enforcement referral, would it read as the work of a board in control of its risks? If the answer is uncertain, the document is not ready.

Frequently Asked Questions

Should the self-assessment be shared with the FCA proactively?

Only if there is a supervisory reason to do so, such as a live concern, a permission variation, or a Dear CEO response. Unsolicited disclosure of a critical self-assessment can create issues it was designed to manage. Keep it board-owned and available on request.

How often should this be done?

Annually as a minimum, with an interim refresh whenever there is a material change: senior management turnover, a significant control failure, a change in group structure, or supervisory contact that raises Threshold Conditions concerns.

Who should own the assessment at SMF level?

The Chief Executive (SMF1) is ultimately accountable, but the drafting is typically coordinated by the Chief Compliance Officer (SMF16) or Chief Risk Officer (SMF4). The Chair should ensure board challenge is genuine and recorded.

What is the biggest mistake firms make?

Treating the assessment as a compliance deliverable rather than a governance document. If the board has not debated the judgement calls, the document will not survive supervisory scrutiny.

Does this apply to firms not currently under supervisory pressure?

Yes. The purpose is pre-emption. Firms that only produce a Threshold Conditions assessment when asked are already in a weaker position than those who can show a track record of self-critical review.

Frequently asked questions

Should the self-assessment be shared with the FCA proactively?

Only if there is a supervisory reason to do so, such as a live concern, a permission variation, or a Dear CEO response. Unsolicited disclosure of a critical self-assessment can create issues it was designed to manage. Keep it board-owned and available on request.

How often should this be done?

Annually as a minimum, with an interim refresh whenever there is a material change: senior management turnover, a significant control failure, a change in group structure, or supervisory contact that raises Threshold Conditions concerns.

Who should own the assessment at SMF level?

The Chief Executive (SMF1) is ultimately accountable, but the drafting is typically coordinated by the Chief Compliance Officer (SMF16) or Chief Risk Officer (SMF4). The Chair should ensure board challenge is genuine and recorded.

What is the biggest mistake firms make?

Treating the assessment as a compliance deliverable rather than a governance document. If the board has not debated the judgement calls, the document will not survive supervisory scrutiny.

Does this apply to firms not currently under supervisory pressure?

Yes. The purpose is pre-emption. Firms that only produce a Threshold Conditions assessment when asked are already in a weaker position than those who can show a track record of self-critical review.

Related guides

Regulation & Regulatory Change

How to Structure an Operational Resilience Self-Assessment That Withstands Regulator Challenge

This guide sets out how to build an operational resilience self-assessment that holds up to FCA and PRA impact tolerance scrutiny. After reading, senior leaders will know how to sequence evidence, frame judgements, and pre-empt the challenges supervisors are most likely to raise.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

How to Structure a Reverse Stress Testing Narrative for PRA Board Attestation

This guide sets out how to build a Reverse Stress Testing (RST) narrative that credibly supports board attestation under PRA expectations. After reading, you will know how to sequence the analysis, frame the point of non-viability, and present findings in a way that survives supervisory challenge.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Section 165 Response That Limits Scope Creep

This guide sets out how to respond to an FCA Section 165 information request in a way that satisfies the statutory duty without widening the supervisory perimeter. After reading, you will know how to scope, sequence, and caveat your response to close down inference-driven follow-ups.

Regulatory submissionRegulatorsRegulatory uncertainty
4 min read · Step by stepRead guide →
Regulation & Regulatory Change

How to Structure a Pillar 2 Liquidity Narrative That Anticipates PRA ILAAP Challenge

This guide sets out how to build an ILAAP liquidity narrative that pre-empts the specific challenges PRA supervisors raise on Pillar 2 risks. After reading, senior leaders will know how to sequence the document, where to concentrate evidence, and how to defend judgement calls under supervisory pressure.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Solvency II ORSA Narrative That Pre-empts PRA Capital Challenge

This guide sets out how to build an ORSA narrative that anticipates PRA scrutiny on capital adequacy, risk quantification, and management action credibility. After reading it, senior insurance leaders will know how to sequence the document, evidence key judgements, and close the gaps supervisors most often probe.

Regulatory submissionRegulatorsBoards
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity