Skip to main content

What Makes a Decision Defensible to Regulators: A Practical Guide

This guide explains what regulators actually look for when they test whether a decision was sound, and how senior leaders should structure and document decisions so they hold up under later scrutiny. After reading, you will know what to build into your decision process now to withstand a supervisory review, enforcement inquiry, or section 166 later.

A decision is defensible to regulators when a reasonable person, reading the file months or years later with the benefit of hindsight, can see that the right people asked the right questions, weighed the right evidence, understood the risks to customers and markets, and reached a conclusion that a competent firm could reasonably reach. Defensibility is not about the outcome being correct. It is about the reasoning being sound, the process being intact, and the record being honest. Regulators rarely punish good decisions that turned out badly. They punish decisions that were poorly reasoned, poorly evidenced, or poorly recorded.

Key Executive Takeaways

  • Defensibility rests on process integrity and contemporaneous evidence, not on the decision being proven right after the fact.
  • The single most common failure is a decision record that reconstructs the rationale after the outcome is known, rather than capturing the reasoning as it happened.
  • Regulators test whether the firm genuinely engaged with the hard questions, particularly customer harm, conflicts, and dissenting views, not whether the paperwork looks tidy.

What regulators actually test

When a supervisor, skilled person, or enforcement team reviews a decision, they work backwards from the outcome to the reasoning. They are looking for four things: whether the decision-maker had authority and competence, whether the information base was adequate, whether foreseeable risks were identified and weighed, and whether the chosen course was within the range of reasonable options open to the firm at the time.

They are not looking for perfection. They are looking for evidence that the firm took its obligations seriously. That distinction matters, because it changes what you need to build into the decision itself.

The components of a defensible decision

A clear question, framed honestly

The decision paper should state what is being decided, what the alternatives are, and what the firm is giving up by choosing this path. Papers that only present the preferred option, with alternatives strawmanned or omitted, are the fastest way to lose credibility in a later review.

An adequate evidence base

This means data, analysis, and expert input proportionate to the significance of the decision. For a pricing change affecting vulnerable customers, that includes distributional analysis and outcome testing. For a new product, target market analysis and stress scenarios. If the evidence base is thin, say so, and record what compensating controls or review points you have put in place.

Explicit consideration of customer and market impact

Under the Consumer Duty, SM&CR, and equivalent regimes, the record must show that foreseeable harm was actively considered, not assumed away. Vague assertions that customers will benefit are worse than useless. Specifics, with numbers where possible, are what stands up.

Genuine challenge, captured on the record

Defensible decisions show dissent. If the risk function, legal, or a non-executive raised concerns, those concerns should appear in the minutes along with how they were addressed. A unanimous board with no recorded debate on a contested issue reads as either groupthink or a sanitised record. Neither is comfortable to defend.

The right decision-maker

Check that the person or committee making the call has the delegated authority and the competence to do so. Decisions taken at the wrong level, or by people without the requisite understanding, are structurally weak regardless of how good the reasoning was.

Contemporaneous documentation

The record must be created at the time, not reconstructed. Version control, dated minutes, and preserved drafts matter. Post-hoc tidying of the file is one of the most damaging things a firm can do when a matter becomes contentious.

What good looks like in practice

A well-run decision has a paper that a new board member could read cold and understand: what was proposed, what was considered, who challenged what, what the risks were, why the chosen path was preferred, and what will be monitored to test whether the decision holds up. It names the accountable individual. It sets review triggers. It acknowledges what could go wrong and what the firm will do if it does.

What most firms get wrong

The common failures are predictable. Papers written to secure approval rather than to inform debate. Risk sections that list risks without weighing them. Customer impact assessments that conclude every option is beneficial. Minutes that record outcomes but not reasoning. Delegated authority frameworks that no one has looked at in three years. Each of these is fixable, but only if the firm treats the decision process itself as a supervised activity, not a formality.

Your next step

Pick a significant decision your firm made in the last twelve months. Read the file as if you were a skilled person reviewing it. Ask whether the reasoning is visible, whether the challenge is on the record, and whether a competent outsider could see why the decision was reasonable at the time. If the answer is no, the fix is not better writing. It is a better process, applied consistently, starting with the next decision on your agenda.

Frequently Asked Questions

Does defensibility mean the decision has to be right?

No. Regulators accept that firms make judgement calls under uncertainty. What they expect is that the judgement was informed, the risks were weighed, and the reasoning is on the record. A decision that turned out badly can still be fully defensible.

How much documentation is enough?

Proportionate to the significance and reversibility of the decision. A routine operational choice needs a light record. A decision affecting customer outcomes, capital, or market conduct needs a substantive paper with evidence, options analysis, and recorded challenge.

What is the biggest single weakness in most decision files?

Absence of recorded challenge. Files that show only the case for the chosen option, with no visible debate, look constructed rather than deliberated. Capturing dissent, and how it was addressed, is the single highest-value improvement most firms can make.

Should legal privilege be relied on to protect decision records?

Relying on privilege as a shield is a poor strategy. Regulators can compel production in many circumstances, and firms that appear to have hidden reasoning behind privilege damage their credibility. Assume the record will be read, and write it accordingly.

Who owns defensibility inside the firm?

The accountable senior manager owns the specific decision. But the underlying process, the templates, the challenge culture, the documentation standards, is a governance responsibility that sits with the board and the chief risk officer collectively.

Frequently asked questions

Does defensibility mean the decision has to be right?

No. Regulators accept that firms make judgement calls under uncertainty. What they expect is that the judgement was informed, the risks were weighed, and the reasoning is on the record. A decision that turned out badly can still be fully defensible.

How much documentation is enough?

Proportionate to the significance and reversibility of the decision. A routine operational choice needs a light record. A decision affecting customer outcomes, capital, or market conduct needs a substantive paper with evidence, options analysis, and recorded challenge.

What is the biggest single weakness in most decision files?

Absence of recorded challenge. Files that show only the case for the chosen option, with no visible debate, look constructed rather than deliberated. Capturing dissent, and how it was addressed, is the single highest-value improvement most firms can make.

Should legal privilege be relied on to protect decision records?

Relying on privilege as a shield is a poor strategy. Regulators can compel production in many circumstances, and firms that appear to have hidden reasoning behind privilege damage their credibility. Assume the record will be read, and write it accordingly.

Who owns defensibility inside the firm?

The accountable senior manager owns the specific decision. But the underlying process, the templates, the challenge culture, the documentation standards, is a governance responsibility that sits with the board and the chief risk officer collectively.

Related guides

Boards, Governance & Defensibility

Structuring an MLRO Annual Report That Satisfies SYSC 6 Without Triggering FCA Intervention

This guide sets out how to structure and write the MLRO annual report so it meets SYSC 6.3.9G expectations and gives the board a defensible record of financial crime oversight. After reading it, senior decision-makers will know what to include, what to leave out, and how to frame weaknesses without inviting supervisory follow-up.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Handle a Pre-Emptive Regulator Meeting After a Governance Failure

This guide covers how to prepare for and run a self-initiated regulator meeting when you have discovered a material governance failure inside your firm. After reading, you will know how to sequence the disclosure, frame the failure, and position remediation in a way that preserves credibility and controls the supervisory response.

Regulatory submissionRegulatorsBoards
3 min readRead guide →
Boards, Governance & Defensibility

How to Structure a Section 166 Response That Preserves Board Credibility

A practical guide to responding to a Skilled Person review in a way that protects the board's standing with the regulator. Covers how to sequence the engagement, where boards typically damage their own credibility, and how to convert findings into a credible remediation posture.

Regulatory submissionBoardsRegulators
3 min readRead guide →
Regulation & Regulatory Change

What Regulators Look For in a Submission: A Practical Guide

This guide explains what regulators actually assess when reviewing a formal submission, from authorisation applications to Section 166 responses and thematic returns. After reading it, you will know how to structure a submission that reflects genuine control, sound judgement and credible governance.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

How to Prepare a Bank Board for a Consumer Duty Annual Assessment Sign-Off

This guide sets out how to prepare a bank board to sign off the Consumer Duty annual assessment with genuine confidence rather than procedural comfort. You will finish knowing what evidence to demand, what challenge to expect, and how to sequence the work so the board can meet its accountability with clarity.

Regulatory submissionBoardsRegulators
4 min readRead guide →

Where internal consensus may be mistaken for validation

Polar Insight's Decision Rooms bring outside challenge to a live decision, so blind spots and untested assumptions surface before commitment, not after.

Explore Decision Rooms