What Makes a Decision Defensible to Regulators: A Practical Guide
This guide explains what regulators actually look for when they test a major decision after the fact, and how to build defensibility into the decision itself rather than reconstruct it later. You will finish with a clear view of what to document, who to involve, and where most firms leave themselves exposed.
A decision is defensible to regulators when the record shows that the right people asked the right questions, considered the relevant risks and stakeholders, weighed credible alternatives, and reached a reasoned conclusion consistent with the firm's obligations. Defensibility is not about being proved right by outcomes. It is about being able to demonstrate, months or years later, that the decision was made with appropriate rigour on the information reasonably available at the time.
Key Executive Takeaways
- Regulators judge process quality and evidence of challenge, not the outcome: a poor result from a well-run decision is usually defensible, while a good result from a sloppy one often is not.
- The single most powerful defensibility artefact is a contemporaneous record showing what alternatives were considered, what customer and market impacts were tested, and why the chosen option was preferred.
- Most firms fail defensibility tests not because they made bad decisions, but because they cannot reconstruct the reasoning, the dissent, or the stakeholder analysis when asked.
What regulators are actually testing
When a supervisor or enforcement team reviews a decision, they are running four tests, usually in this order.
First, was the decision taken by people with the authority and competence to take it? Governance failures show up fast: unclear delegated authorities, committees operating outside their terms of reference, or material decisions made informally between meetings.
Second, did the decision-makers have the right information? This includes management information that was accurate and timely, risk and compliance input that was genuinely independent, and, increasingly, evidence that customer outcomes and vulnerable customer impacts were specifically considered.
Third, was there real challenge? Regulators are practised at spotting rubber-stamp minutes. They look for recorded dissent, alternatives that were considered and rejected with reasons, and evidence that inconvenient data was engaged with rather than explained away.
Fourth, was the reasoning proportionate to the stakes? A pricing change affecting two million customers requires a different depth of analysis than a routine operational tweak. Firms get into trouble when the process is either too light for the risk or, less commonly, so bureaucratic that the actual reasoning is buried.
What to build into the decision itself
Defensibility is cheap to build in and expensive to retrofit. Six things belong in the decision record every time:
- A clear statement of the decision being taken and the authority under which it is being taken.
- The options considered, including the option of doing nothing, with the reasons for rejecting the alternatives.
- The customer, market, and conduct impacts assessed, with named owners for each area of analysis.
- The risks identified, the mitigations agreed, and the residual risk accepted.
- The dissenting views expressed and how they were addressed, not just noted.
- The review trigger: what would cause the firm to revisit this decision, and when.
If your board or executive committee papers do not routinely contain these six elements, your defensibility is weaker than you think.
Where firms get it wrong
The most common failure is confusing volume with quality. Hundred-page board packs with no clear articulation of the judgement being made are worse than a tight ten-page paper that names the trade-off explicitly.
The second is treating challenge as a formality. If your risk function's comments always appear as a paragraph at the end saying "Risk is comfortable," you have a problem. Regulators will ask what risk was uncomfortable about, and what changed.
The third is poor handling of external intelligence. When a decision depends on assumptions about customer behaviour, competitor response, or stakeholder reaction, the source and reliability of that intelligence should be on the record. "Management view" is not evidence.
The fourth is silence on stakeholders who were not consulted. If you did not talk to a group whose interests were affected, say why. Regulators are more forgiving of a reasoned choice than of an apparent oversight.
The test to apply before you sign off
Before approving any material decision, ask: if a supervisor asked me in two years to explain this, would the papers alone tell the story, or would I need to fill in the gaps from memory? If the answer is the latter, the decision is not yet defensible. Fix the record before you take the decision, not after.
Frequently Asked Questions
How much documentation is enough?
Enough to allow someone unfamiliar with the decision to understand what was decided, why, what was considered and rejected, and who was accountable. For material decisions, that usually means a standalone paper plus minutes that capture the substance of the discussion, not just the conclusion.
Does defensibility change under the Consumer Duty or SM&CR?
Yes. Both raise the bar on evidence of customer outcome consideration and individual accountability. Under the Duty in particular, decisions affecting retail customers need explicit analysis of foreseeable harm, including to customers with characteristics of vulnerability. Under SM&CR, the senior manager taking the decision should be identifiable from the record.
What if the decision has to be taken quickly?
Speed is not a defence, but proportionality is. Document the time constraint, what information was available, what was not, and the review commitment to revisit once fuller information exists. A fast decision with a clear reconsideration trigger is defensible. A fast decision with no follow-up is not.
How should dissent be recorded?
Name the concern, name (or role-identify) who raised it, and record how it was addressed. Do not sanitise minutes to remove disagreement. Regulators read redrafts of minutes as a red flag, and clean minutes from a contested meeting invite scrutiny rather than deflect it.
Who owns defensibility?
The chair of the decision-making body owns the quality of the process. The senior manager accountable for the outcome owns the substance. Company secretariat owns the record. When any of these three is unclear, defensibility erodes.
Frequently asked questions
How much documentation is enough?
Enough to allow someone unfamiliar with the decision to understand what was decided, why, what was considered and rejected, and who was accountable. For material decisions, that usually means a standalone paper plus minutes that capture the substance of the discussion, not just the conclusion.
Does defensibility change under the Consumer Duty or SM&CR?
Yes. Both raise the bar on evidence of customer outcome consideration and individual accountability. Under the Duty in particular, decisions affecting retail customers need explicit analysis of foreseeable harm, including to customers with characteristics of vulnerability. Under SM&CR, the senior manager taking the decision should be identifiable from the record.
What if the decision has to be taken quickly?
Speed is not a defence, but proportionality is. Document the time constraint, what information was available, what was not, and the review commitment to revisit once fuller information exists. A fast decision with a clear reconsideration trigger is defensible. A fast decision with no follow-up is not.
How should dissent be recorded?
Name the concern, name (or role-identify) who raised it, and record how it was addressed. Do not sanitise minutes to remove disagreement. Regulators read redrafts of minutes as a red flag, and clean minutes from a contested meeting invite scrutiny rather than deflect it.
Who owns defensibility?
The chair of the decision-making body owns the quality of the process. The senior manager accountable for the outcome owns the substance. Company secretariat owns the record. When any of these three is unclear, defensibility erodes.
Related guides
How to Handle a Pre-Emptive Regulator Meeting After a Governance Failure
This guide covers how to prepare for and run a self-initiated regulator meeting when you have discovered a material governance failure inside your firm. After reading, you will know how to sequence the disclosure, frame the failure, and position remediation in a way that preserves credibility and controls the supervisory response.
How to Structure a Section 166 Response That Preserves Board Credibility
A practical guide to responding to a Skilled Person review in a way that protects the board's standing with the regulator. Covers how to sequence the engagement, where boards typically damage their own credibility, and how to convert findings into a credible remediation posture.
How to Make a Defensible Board Decision
A practical guide to constructing board decisions that hold up under regulatory, legal, and shareholder scrutiny long after the vote. Readers will finish knowing what to document, how to structure the discussion, and where most boards leave themselves exposed.
Positioning a Consumer Duty Review for Board and Regulator Audiences
This guide sets out how to structure a Consumer Duty implementation review so it works for both your board and the FCA without compromising either audience. You will finish with a clear approach to framing, evidence, and sequencing that avoids the common trap of producing two conflicting narratives.
How to Prepare Your Board for an SMCR Accountability Challenge
This guide sets out how to ready your board and Senior Managers for a regulator-led accountability challenge under SMCR, including where the evidentiary weaknesses usually sit. After reading, you will know what to test, what to document, and how to sequence the internal work before the FCA or PRA comes knocking.
Where internal consensus may be mistaken for validation
Polar Insight's Decision Rooms bring outside challenge to a live decision, so blind spots and untested assumptions surface before commitment, not after.
Explore Decision Rooms