Consumer Duty audits are catching brokers out, what a defensible file actually looks like

 

A broker can walk into a file review feeling confident and still walk out with a list of findings. That has been happening more often since the Financial Conduct Authority told mortgage intermediaries, in a portfolio letter sent to chief executives in January 2025, that embedding the Consumer Duty properly would be its main supervisory focus for the following two years. Eighteen months on, the regulator has published enough findings across enough sectors to make one thing clear. A file that looks compliant and a file that is defensible are not always the same document.

The gap between the two is where most of the trouble sits. A file can have every box ticked, every disclosure attached, every signature in place, and still fail to explain itself when someone outside the firm actually reads it. That is the standard now being applied, and it is worth understanding exactly what it involves before it gets applied to yours.

What the regulator has actually been finding

The January 2025 letter to mortgage intermediaries set out four priority areas, and they still hold. Quality of advice and suitability, with particular attention to customers facing financial difficulty or characteristics of vulnerability. Conflicts of interest, including whether incentive structures reward advisers for volume over quality. Fair value, meaning firms need to be able to justify their fees rather than simply state them. And financial promotions, where the risks of a product have to sit as prominently as the benefits.

What has changed since then is how precisely the FCA is defining evidence. In April 2026, its review of second year Consumer Duty board reports found that many firms were presenting large amounts of data without explaining what it actually showed about customer outcomes, and that monitoring of outcomes delivered through distribution chains and third parties remained weak. That finding matters directly to brokers, because a broker sits inside a lender's or a network's distribution chain, and is exactly the kind of third party the FCA is now asking firms to monitor more closely.

In July 2026, a thematic review covering product governance surveyed thirty eight firms and found a related pattern. Firms could show that a customer had been flagged as vulnerable, but struggled to show what had actually changed about the advice, the communication, or the product because of that flag. Identifying vulnerability and adapting to it were being treated as the same step, when the regulator expects the second to be visible on its own.

And in March 2026, a review into consumer understanding found that sales figures and the absence of complaints were being used as evidence that customers understood what they had bought. The FCA was direct about this. Neither one proves anything of the kind.

None of this is unique to mortgages. But it is worth being specific about the parts that are. The FCA's own review of second charge lending flagged affordability checks, debt consolidation advice and fee transparency as areas where practice was inconsistent, particularly for customers showing more than one characteristic of vulnerability at once. That is a narrower market than the mortgage sector as a whole, but the pattern it describes, vulnerability being under served precisely where the file suggests it was handled, is the same one showing up everywhere else.

What a defensible file actually looks like

Taken together, these findings point to a fairly specific set of things a file needs, beyond the standard disclosures. Vulnerability recorded as an adaptation, not a flag. The file should not just show that a characteristic of vulnerability was identified. It should show what changed, in the advice process, the communication method, or the timescale, because of it.

A suitability rationale written for that client, not lifted from the last one. A reviewer reading the wording alone should be able to tell that the recommendation was built around this person's income, circumstances and objectives, rather than assembled from a template with the details swapped in. A fair value note that says more than this reflects our standard fee. Something that connects the charge to the complexity of the case and the work actually carried out for that particular client. Interpretation, not just activity. A log of calls, emails and uploaded documents proves that something happened. It does not prove that anyone drew a conclusion from it. The file needs a note connecting what was found to what was done about it, however briefly.

Evidence of understanding that goes beyond silence. No complaint is not proof that a client understood their mortgage. A short record of how understanding was actually checked carries far more weight than an unbroken run of quiet cases. A version that survives being read by a stranger. Every point above should be legible to someone who was not in the room, reading the file eighteen months later with nothing to go on except what was written down at the time.

Where files usually fall down in practice

Most of the gaps are not dramatic. They come from time pressure rather than carelessness. A suitability letter gets built from the last similar case because the client's circumstances genuinely were similar, and the paragraph that made it specific to them gets forgotten in the rush to submit. A vulnerability characteristic gets noted at the fact find stage and never mentioned again, even though the case runs for another six weeks. A fee gets justified once, in the firm's own pricing document, and never again in the individual file. None of these look like failures on the day. They look like failures eighteen months later, when someone who was not there has to work out what happened from the page in front of them.

Building the evidence as the case moves, not after it closes

The hardest part of any file review is reconstruction, going back through a closed case to explain decisions that were never written down as decisions in the first place. The alternative is building that evidence while the case is still open, so there is nothing to reconstruct later. This is closer to what a structured fact find and a properly built suitability letter are for. Not to produce a document that looks thorough, but to force the specific details of a case into the file at the point they are known, rather than leaving them to memory. Automated Consumer Duty file scoring works the same way, flagging a case that is missing a vulnerability adaptation or a fair value rationale while the file is still active, not after it has already been pulled for review.

The standard is not going to loosen

The FCA has said a consultation on how the Duty applies across distribution chains is coming in the first half of 2026, which means the scrutiny on intermediaries specifically is not a passing phase. Defensible is not a state a file reaches once and keeps. It is something that has to be provable, for every case, to someone who was never part of the conversation. That is a higher bar than compliant, and it is the one that is now actually being applied.

Discover more at Mortgage Magic™

Comments

Popular posts from this blog

The Loaded Premium Scandal: How a Quarter of the UK Protection Market Is Silently Overcharging Customers

7 things to look for in a Mortgage SaaS Platform

How to use automation to convert more mortgage leads