Regulated Industry Governance Best Practice: A Working Guide for Boards
This guide sets out what genuinely strong governance looks like in regulated financial services, from board composition through to escalation culture. After reading, senior leaders will know what to strengthen, what to test, and what regulators and other stakeholders actually expect to see.
Governance in regulated financial services is judged by whether it works under pressure, not by how it reads on paper. Boards that meet the bar have clear accountability, sharp information flows, and a culture that surfaces bad news early. This guide sets out the practices that separate credible governance from the kind that collapses under a Section 166, a supervisory visit, or a live incident.
Key Executive Takeaways
- Strong regulated governance rests on individual accountability, high-quality information, and a culture where challenge and escalation are expected, not tolerated.
- Most governance failures are not caused by missing frameworks; they are caused by boards receiving sanitised information and treating committee papers as assurance.
- The test of good governance is whether decisions, dissent, and follow-through are visible in the record, and whether the same standard applies when things are going wrong.
Start With Accountability That Names People
Under SMCR and equivalent regimes, accountability sits with named individuals. The governance question is whether those accountabilities are lived. Every material risk, control, and regulatory obligation should map to a single senior manager, with a documented handover when responsibilities move. Where two executives share responsibility for an outcome, neither owns it. Fix that before the regulator points it out.
What good looks like: responsibilities maps that match reality, statements of responsibility that are refreshed when structures change, and executives who can describe their accountabilities without reading from a document.
Build a Board That Can Actually Challenge
Composition is where most boards quietly underperform. The right mix is not just independence and diversity of background; it is genuine subject-matter depth in the areas that could sink the firm: credit, conduct, technology resilience, financial crime, capital and liquidity. If your board cannot interrogate a model validation report or a cyber incident timeline without relying on the executive, that is a gap to close.
Run a skills audit annually against the current risk profile, not the profile from three years ago. When a director is appointed, be explicit about what they are there to challenge.
Fix the Information Flow Before Anything Else
Boards fail because they are told what the executive wants them to hear. The remedy is structural:
- Set standing requirements for what board and committee papers must contain, including dissenting views, near misses, and unresolved audit findings.
- Give the chairs of Risk and Audit direct, unfiltered access to the CRO, Head of Internal Audit, and Head of Compliance, with regular private sessions.
- Require management to bring bad news early, and reward those who do. If the first the board hears of a problem is when it becomes a regulatory notification, the escalation culture is broken.
Good boards read the second and third order indicators: attrition in control functions, overdue audit actions, repeat findings, complaint themes, and the tone of internal whistleblowing.
Treat Regulatory Engagement as a Governance Discipline
Credible engagement with the FCA, PRA, or equivalent supervisors depends on preparation and honesty. That means: knowing your own weaknesses better than the supervisor does, remediating them on a timetable you can defend, and being straightforward when asked. Boards that try to manage the message rather than the substance almost always regret it.
When a supervisor raises a concern, the board's job is to test whether the executive response addresses the root cause or only the symptom. Ask what the equivalent issue looks like elsewhere in the firm. Ask what would have to be true for the fix to fail.
Make the Three Lines Work in Practice
The three lines model is only useful if the second and third lines have real authority, real budget, and real independence. Warning signs: CRO reporting lines that dilute independence, internal audit plans shaped too heavily by the executive, and compliance treated as a sign-off function rather than a control. The board, through its Risk and Audit Committees, owns the health of these functions. Review their effectiveness annually and act on what you find.
Test the Culture, Not Just the Framework
Culture is measurable. Look at speak-up data, exit interviews, control function turnover, and how disagreements are recorded in minutes. If minutes show unanimous decisions on every material item, the record is wrong or the challenge is missing. Either is a governance problem.
The Next Decision
Pick one area from this guide, information quality, escalation culture, or second line independence, and commission an honest assessment in the next quarter. Governance improves when boards test themselves against how they would perform in a crisis, before the crisis arrives.
Frequently Asked Questions
How often should a regulated board review its governance framework?
A full effectiveness review annually, with a deeper external review every three years, is the working standard. More importantly, review governance whenever the business model, risk profile, or regulatory perimeter changes materially.
What is the single most common governance weakness in regulated firms?
Information quality. Boards receive papers that describe activity rather than risk, omit dissent, and understate emerging issues. The fix is a paper standard enforced by the chair, not a new committee.
How should the board handle disagreement with the executive?
Record it. Minutes should show the challenge, the response, and the decision. A board that never disagrees on the record is either unusually aligned or not doing its job.
What signals to a regulator that governance is genuinely strong?
Consistency between what the board says, what the papers show, and what the executive does. Supervisors notice when senior managers can speak fluently to their responsibilities and when remediation happens on the timetable the firm committed to.
Should governance look different in smaller regulated firms?
Proportionate, not weaker. Smaller firms can run leaner committee structures, but the standards for accountability, information quality, and independent challenge are the same.
Frequently asked questions
How often should a regulated board review its governance framework?
A full effectiveness review annually, with a deeper external review every three years, is the working standard. More importantly, review governance whenever the business model, risk profile, or regulatory perimeter changes materially.
What is the single most common governance weakness in regulated firms?
Information quality. Boards receive papers that describe activity rather than risk, omit dissent, and understate emerging issues. The fix is a paper standard enforced by the chair, not a new committee.
How should the board handle disagreement with the executive?
Record it. Minutes should show the challenge, the response, and the decision. A board that never disagrees on the record is either unusually aligned or not doing its job.
What signals to a regulator that governance is genuinely strong?
Consistency between what the board says, what the papers show, and what the executive does. Supervisors notice when senior managers can speak fluently to their responsibilities and when remediation happens on the timetable the firm committed to.
Should governance look different in smaller regulated firms?
Proportionate, not weaker. Smaller firms can run leaner committee structures, but the standards for accountability, information quality, and independent challenge are the same.
Related guides
What Makes a Decision Defensible to Regulators: A Practical Guide
This guide explains what regulators actually look for when they test whether a decision was sound, and how to build that evidence before you need it. After reading, you will know how to structure, document, and stress-test decisions so they hold up under supervisory scrutiny or enforcement review.
How to Make a Defensible Board Decision
A practical guide to constructing board decisions that withstand regulatory scrutiny, shareholder challenge, and hindsight review. After reading, you will know how to structure the process, the record, and the reasoning so that the decision holds - even if the outcome doesn't.
How Boards Demonstrate Real Accountability in Regulated Industries
A practical guide to what board accountability actually looks like in regulated sectors, beyond charters and attestations. Readers will finish with a clearer view of where accountability breaks down, and what to change to make it stick.
Structuring a PRA Senior Manager Attestation on Risk Framework Effectiveness
This guide sets out how to structure a Senior Manager attestation on the effectiveness of a firm's risk framework in a way that meets PRA supervisory expectations and stands up to later challenge. Readers will finish with a clear method for scoping, evidencing, qualifying, and signing an attestation that reflects the true state of the framework.
Structuring an MLRO Annual Report That Satisfies SYSC 6 Without Triggering FCA Intervention
This guide sets out how to structure and write the MLRO annual report so it meets SYSC 6.3.9G expectations and gives the board a defensible record of financial crime oversight. After reading it, senior decision-makers will know what to include, what to leave out, and how to frame weaknesses without inviting supervisory follow-up.
Where internal consensus may be mistaken for validation
Polar Insight's Decision Rooms bring outside challenge to a live decision, so blind spots and untested assumptions surface before commitment, not after.
Explore Decision Rooms