The consumer duty, which came into effect for open products and services in July 2023, established a high standard of care for retail customers. It requires firms to act in good faith, avoid causing foreseeable harm, and enable and support retail customers to pursue their financial objectives.
For payment services and e-money firms, as for other providers within scope, this has required a sharper and more deliberate focus on consumer outcomes. Firms need to understand what a good outcome should look like for their customers, how their products and services may affect those outcomes, and how they will evidence that their arrangements are working in practice.
Earlier this month, the FCA published its findings on good and poor practice in supporting consumers in vulnerable circumstances. The review does not introduce new requirements or prescribe a single approach. Rather, it gives firms a practical basis against which to challenge the effectiveness of their own arrangements, taking account of their business model, customer base and risk profile.
On one level, the publication is a review of the vulnerability arrangements adopted by payments firms. On another, it highlights a much broader challenge as the consumer duty continues to mature. The firms demonstrating the strongest outcomes were not simply those able to point to policies, governance structures or sophisticated management information. They were those able to show that their arrangements were working and delivering good outcomes in practice.
That distinction is becoming increasingly important as regulatory attention moves beyond framework design towards operational effectiveness, customer outcomes and the evidence firms can produce to support their conclusions.
The assurance gap hiding in plain sight
At its heart, the FCA's review highlights a challenge that exists across many regulatory programmes. Most firms can demonstrate that customer vulnerability has been considered within policies, procedures, governance forums and training programmes. Many can also produce management information showing how those arrangements are monitored.
However, demonstrating that customers in vulnerable circumstances consistently receive appropriate support throughout their relationship with the firm is far more demanding. It requires firms to move beyond showing that controls exist and instead understand whether customers are achieving the intended outcomes and, in turn, whether controls are operating effectively enough to support those outcomes.
This is particularly relevant in the context of the consumer duty. The question is no longer simply whether a firm has a vulnerability framework. Increasingly, firms need to evidence that the framework is working, identify where outcomes may be falling short and demonstrate that appropriate action is taken when potential risks of harm emerge.
The FCA's findings illustrate the point. Some firms had policies and training in place but identified very few, or in some cases no, customers in vulnerable circumstances, despite serving customer bases where vulnerability might reasonably be expected. The FCA also identified opportunities to strengthen monitoring, testing, recording practices and the sharing of information across the customer journey. These findings do not necessarily indicate a lack of commitment. They demonstrate how difficult it can be to evidence that arrangements are working consistently in practice.
Beyond box-checking: what effective testing looks like
This is why testing and assurance matter. Effective assurance moves beyond confirming that a process exists. It examines whether arrangements are appropriately designed, operate consistently and produce the outcomes they were intended to achieve.
In practical terms, firms should consider whether indicators of vulnerability are recognised consistently, whether relevant information is accurately recorded and shared, whether appropriate support is triggered, and whether the customer's experience is materially improved as a result. Testing should therefore look beyond process completion to customer experience and outcomes.
There is no single prescribed methodology. A proportionate approach may combine customer journey testing, case and call reviews, thematic analysis, customer cohort comparisons, complaint correlation, vulnerability deep dives and retrospective assessment of customer decisions and interventions. The purpose is not to create more testing for its own sake. It is to understand where harm may be occurring, why it is occurring and whether the firm's response is effective.
Why fixing the issue once is not enough
Recent support activity illustrates the point. A customer vulnerability review at one firm identified a concerning increase in complaints linked to the communication and application of forbearance options within a consumer finance operation. Despite established policies and processes, the trend indicated that customers in vulnerable circumstances were not consistently receiving the outcomes the firm intended.
Importantly, the issue was not identified through a policy review or governance reporting alone. It became visible through deeper analysis of complaints, customer interactions and outcomes. The framework existed, management information was being produced and training had been completed. Yet poor outcomes were still occurring. Targeted assurance exposed the gap between design and operational reality.
The firm responded with a comprehensive remediation and uplift programme, including stronger governance, revised customer journeys, enhanced quality assurance, more targeted management information and extensive training for customer-facing employees and agents. Colleagues were required to reach and maintain a higher level of accreditation before handling relevant customer interactions independently.
The programme delivered positive results. Quality scores improved and better customer outcomes followed. However, over the next year, those gains began to erode as performance declined and some agents reverted to previous behaviours and decision-making patterns.
The experience is a powerful reminder that improving outcomes for customers in vulnerable circumstances is not a once-and-done exercise. Sustainable improvement requires more than process redesign and training. It requires an enduring cultural shift, reinforced by dynamic controls, ongoing monitoring, continuous coaching and active management intervention. Higher standards must become the way the organisation operates, not a temporary response to a particular issue.
Identification is not the destination
A common mistake is to treat vulnerability identification as the objective in its own right. In reality, identification is only the beginning. The more important question is what happens next. Does the information lead to meaningful support? Is that support applied consistently across channels, products and teams? Does it reduce friction, remove barriers or mitigate foreseeable harm?
Customer outcomes are determined by the quality and consistency of the firm's response, not by the act of recording a characteristic of vulnerability. The strongest approaches therefore assess outcomes across the customer journey rather than evaluating individual controls in isolation.
The objective is not necessarily to achieve identical outcomes for every customer. It is to ensure that customers in vulnerable circumstances do not experience avoidable barriers, foreseeable harm or materially poorer outcomes because of their circumstances.
What firms discover when they look harder
Robust testing and assurance often uncover weaknesses that are not visible through policy reviews or headline management information. Vulnerability information may be captured in one part of the customer journey but fail to follow the customer elsewhere. Different teams may identify and record support needs at materially different rates. Needs may be recorded without triggering meaningful support, while digital journeys may create unintended barriers for customers requiring additional assistance.
One recurring challenge is that firms measure what is easy to count rather than what is important to understand. Volumes, completion rates, training statistics and identification levels can all be useful indicators, but they do not by themselves demonstrate whether customers experienced better outcomes. Aggregated board reporting can also appear reassuring while masking poorer experiences within particular customer groups.
These are often not failures of intent. More commonly, they reveal gaps between framework design, operational delivery and the evidence available on customer outcomes.
From management information to genuine assurance
Policies remain essential because they establish the firm's intended approach. Management information is also important because it can identify trends, emerging risks and areas requiring attention. However, neither provides assurance in isolation.
Assurance bridges the gap between policy and practice by helping firms understand whether customers are achieving the intended outcomes and whether controls are operating effectively enough to support them. Quality assurance may form part of that picture through file reviews, call monitoring and process testing, but genuine assurance is broader. It brings together evidence from across the customer journey and subjects management's conclusions to informed challenge.
Many firms organise assurance activity across the first, second and third lines of defence, with each providing a different perspective and degree of challenge. The objective should not be to repeat the same review activity several times. It should be to build a complementary view of control design, operational effectiveness and customer outcomes.
A mature approach will often combine journey testing, case reviews, outcomes analysis, root-cause investigation, independent challenge and validation of remediation. Crucially, assurance should not be viewed as an occasional retrospective exercise. The strongest approaches embed it within a wider system of dynamic controls, monitoring and challenge that continually tests whether outcomes remain aligned with the firm's expectations.
The real risk is complacency
Poor outcomes do not always arrive with obvious warning signs. Most firms do not set out to create customer harm. The greater risk is assuming that arrangements are working because there is no clear evidence to suggest otherwise.
Good governance is therefore not about confirming success. It is about actively looking for evidence, identifying weaknesses and addressing emerging issues before they result in customer harm, complaints, costly remediation or regulatory scrutiny.
Viewed through that lens, the FCA's review is more than a collection of examples of stronger and weaker practice. It gives firms a practical framework for challenging their own arrangements and asking whether they genuinely understand the outcomes being experienced by customers in vulnerable circumstances.
What boards need to know
The consumer duty has moved the conversation beyond framework design and compliance activity towards outcomes and evidence. The question is not simply whether the firm has the right policies, governance structures and controls. It is whether the board can demonstrate, through evidence and ongoing assurance, that those arrangements are delivering good outcomes in practice.
For many firms, the next stage of consumer duty maturity will not be defined by creating more frameworks. It will be defined by their ability to evidence, with confidence, that existing arrangements are operating effectively and delivering the outcomes they were intended to achieve. The firms that succeed will be those that embed continuous testing, challenge and improvement into the way they operate. Those that do not may find that the gap between policy and customer experience is wider than they realised.