34 training duties across 20 instruments binding Financial Services, plus 10 that bind you whatever your sector — statute, rulebook, statutory guidance and licence conditions. Every one traced to its clause, its date and its published source, and each one labelled with what makes it a training duty.
Financial services carries more mandatory training duties than any other sector in this series, and they do not behave alike.
A handful are specified in hours or months and are generally well managed — three separate annual CPD figures for three different populations, and a certificate that lasts a maximum of twelve months.
The rest are not. They are drafted as duties to ensure competence, to assess it at defined moments, and to be able to produce a record of what was done. Several sit outside the FCA Handbook entirely — in primary legislation, in statutory instruments, and in the authorisation conditions the firm holds its permission under.
Each clause carries a label saying why it is a training duty. Where the instrument does not use the word, we cite the guidance or the case that makes training the way you discharge it. Where we cannot cite anyone, it is not listed as a training duty at all.
| Clause | Who must be trained or assessed | What is required | Interval | Evidence required |
|---|---|---|---|---|
| Senior Management Arrangements, Systems and Controls (SYSC), Chapter 5.1 | ||||
| SYSC 5.1.1R competence | named role — quoted: "personnel with the skills, knowledge and expertise necessary for the discharge of the responsibilities allocated to them" | The firm must employ personnel who have the skills, knowledge and expertise needed for the responsibilities they are given. It is a competence duty on the firm, not a duty to run a course. | none specified | none specified in this rule |
| SYSC 5.1.5ABR competence | defined population — individuals who make personal recommendations or give information about financial instruments or structured deposits | The firm must ensure those individuals possess the necessary knowledge and competence to meet its obligations under SYSC, COBS and PROD. | none specified | none specified in this rule |
| Training and Competence sourcebook (TC), Chapter 2.1 | ||||
| TC 2.1.12R competence | defined population — employees carrying on activities listed in TC Appendix 1 | The firm must review the competence of each such employee on a regular and frequent basis and take appropriate action to ensure competence is maintained. | "regular and frequent" — no interval stated | none specified in this rule; see TC 2.1.24R |
| TC 2.1.15R says train | named role — retail investment advisers | A minimum of 35 hours of appropriate continuing professional development in each 12-month period, of which a minimum of 21 hours should be structured CPD (TC 2.1.16G). | 35 hours per 12-month period | Records of CPD completed — TC 2.1.24R |
| TC 2.1.23AR says train | named role — pension transfer specialists | A minimum of 15 hours of CPD per 12-month period, including at least 9 hours of structured activity, of which at least 5 hours must be from external independent providers. Pro-rated in the year of assessment. | 15 hours per 12-month period | Records of CPD completed — TC 2.1.24R |
| TC 2.1.27R and TC 2.1.28R says train | named role — retail investment advisers | The firm must obtain independent verification from an accredited body that the adviser has attained the appropriate qualification, has complied with the 35-hour CPD rule, and has made the annual declaration. Verification must be obtained within 60 days of the competence date and annually thereafter. TC 2.1.29G indicates this takes the form of a statement of professional standing. | within 60 days of the competence date, and annually thereafter | Independent verification by an accredited body — a statement of professional standing |
| TC 2.1.5BR and TC 2.1.5CR says train | defined population — employees carrying on MCD credit activities (regulated activities 23A to 23E) | Employees must possess appropriate knowledge across nine named areas: MCD credit agreements and ancillary services; consumer protection law relating to such agreements; the property purchasing process; security valuation; the organisation and functioning of land registers; the market; business ethics standards; creditworthiness assessment; and financial and economic competency. A firm MUST NOT assess knowledge and competence based solely on relevant professional experience — the assessment must also include qualifications, diplomas, degrees, training or competency tests. | none specified | The assessment, which cannot rest on experience alone |
| TC 2.1.5HR competence | named role — employees advising on P2P agreements (regulated activity 9A) | A firm must not assess an employee advising on P2P agreements as competent until the employee has attained each module of an appropriate qualification for giving personal recommendations on retail investment products to retail clients. | none specified — a precondition to being assessed as competent | Attainment of each module of the qualification |
| Money Laundering Regulations 2017 | ||||
| Regulation 24 (Training) says train | defined population — quoted: "relevant employees" and "any agents it uses for the purposes of its business whose work is of a kind mentioned in paragraph (2)" | The relevant person must take appropriate measures to ensure that relevant employees and agents are made aware of the law relating to money laundering, terrorist financing and proliferation financing and to data protection, and are regularly given training in how to recognise and deal with transactions and other activities which may be related to money laundering, terrorist financing or proliferation financing. | "regularly" — no interval stated | The relevant person must maintain a record in writing of the measures taken, including the training given to relevant employees and to any agents. |
| Regulation 21 (Internal controls) competence | defined population — relevant employees appointed by the relevant person | The relevant person must carry out screening of relevant employees appointed by it, both BEFORE the appointment is made and DURING the course of the appointment. Screening means assessing the skills, knowledge and expertise of the individual to carry out their functions effectively, and the conduct and integrity of the individual. | before appointment and during the course of the appointment — no interval stated for the ongoing limb | none specified in this regulation |
| SYSC 27 (Senior managers and certification regime: Certification regime) | ||||
| SYSC 27.2.3G competence | named population — employees performing an FCA certification function | A firm must take reasonable care to ensure that no employee performs an FCA certification function unless the employee has a valid certificate issued by that firm to perform the function. | none in this provision; certificate validity capped at 12 months by SYSC 27.2.10G | A valid certificate issued by the firm |
| SYSC 27.2.4G and SYSC 27.2.5G says train | named population — candidates for an FCA certification function | A firm may issue a certificate only if satisfied the person is fit and proper to perform the function. In assessing that, the firm must have regard to whether the person has obtained a qualification, undergone training, possesses the required level of competence, or has the required personal characteristics. | none specified | The assessment underpinning the certificate |
| SYSC 27.2.10G, with SYSC 27.2.20G competence | named population — certification staff | A certificate is valid for a maximum of 12 months. A firm may set a shorter period but cannot exceed 12 months. SYSC 27.2.20G states the FCA would expect annual re-certification on expiry to be done in a proportionate and streamlined manner. | maximum 12 months — annual re-certification | A current, in-date certificate per person per function |
| SYSC 27.2.15G says train | named population — certification employees changing role | Where a certification employee's role changes so as to involve a new FCA certification function with different personal characteristics, competence, qualification or training requirements, the firm must assess fitness for the new function BEFORE the employee starts it — expressly not at the annual reassessment point. | trigger-based — before the employee starts the new function | An assessment dated before the role change took effect |
| FIT (The Fit and Proper test for Employees and Senior Personnel), Chapter 1.3 | ||||
| FIT 1.3.1B, FIT 1.3.2A and FIT 1.3.4B competence | named population — candidates and holders of certification functions | The most important considerations are honesty, integrity and reputation; competence and capability; and financial soundness (FIT 1.3.1B). The firm must consider the nature, scale and complexity of its business and whether the candidate has the knowledge, skills and experience to perform the specific role (FIT 1.3.2A). Assessors require an up-to-date job description (FIT 1.3.4B). | none specified | An up-to-date job description is expressly required for a proper assessment (FIT 1.3.4B) |
| Financial Services and Markets Act 2000 | ||||
| Section 64B (Rules of conduct: responsibilities of authorised persons) says train | defined population, drawn very wide — relevant persons, comprising persons approved under s.59 on the firm's application, EMPLOYEES of the authorised person, and DIRECTORS of the authorised person | Every authorised person must notify all relevant persons of the conduct rules that apply to them, and take all reasonable steps to secure that those persons understand how those rules apply to them. The statute states that the steps to be taken to comply with the second limb include, in particular, THE PROVISION OF SUITABLE TRAINING. | none specified | none specified in the section |
| Section 63E (Certification of employees by relevant authorised persons), with section 63F competence | named population — employees performing a specified significant-harm function | An authorised person must take reasonable care to ensure that no employee performs a specified function unless the employee has a valid certificate issued by the firm under section 63F. Specified functions are significant-harm functions — those involving aspects of the business that present a risk of material harm to the firm or its customers. | certificate validity is addressed by s.63F and capped at 12 months in SYSC 27.2.10G | A valid certificate per employee per function |
| Section 63F (Issuing of certificates) competence | named population — candidates for a significant-harm function | An authorised person may issue a certificate only if satisfied that the person is a fit and proper person to perform the function to which the certificate relates. The certificate must state that the firm is so satisfied, and set out the aspects of the firm's affairs in which the person will be involved. A certificate is valid for a period of 12 months beginning with the day on which it is issued. | 12 months — STATUTORY, not merely Handbook guidance | The certificate itself, stating the satisfaction and the scope of involvement |
| SYSC 18.3 (Whistleblowing) | ||||
| SYSC 18.3.1R(2)(g), with SYSC 18.3.4G says train | three distinct populations — UK-based employees; managers of UK-based employees wherever the manager is located; and employees who operate the firm's internal whistleblowing arrangements | The firm's internal arrangements must include appropriate training for each of the three populations. SYSC 18.3.4G sets out different content for each: UK-based employees need the firm's statement that it takes reportable concerns seriously, the reporting routes, examples of events that would prompt a concern, examples of action taken afterwards, and sources of external support. Managers additionally need to recognise a disclosure, protect confidentiality, give feedback, treat an accused person fairly, and know where to get advice. Those operating the arrangements need training on protecting confidentiality, assessing the significance of a disclosure, and assisting the whistleblowers' champion. | none specified | none specified in this provision |
| SYSC 28 (Insurance distribution: training and competence) | ||||
| SYSC 28.2.1R(1) competence | defined population — the firm itself and all non-investment insurance personnel and all long-term insurance personnel | The firm must ensure that it and all relevant insurance personnel possess appropriate knowledge and ability in order to complete their tasks and perform their duties adequately. | none specified in this sub-paragraph | Records — SYSC 28.4.1R |
| SYSC 28.2.1R(3), with SYSC 28.2.1R(2) and SYSC 28.2.1R(4) says train | named role — each long-term insurance employee or person | Each long-term insurance employee must complete a minimum of 15 hours of professional training or development in each 12 month period. The firm must comply with continued professional training and development requirements to maintain adequate performance, and in assessing personnel must take account of the role and activity carried out, and the type of distribution and nature of the products. | 15 hours per 12-month period | An up-to-date record per person per 12-month period — SYSC 28.4.2R |
| SYSC 6.3 (Financial crime) | ||||
| SYSC 6.3.7(1) says train | all staff — employees | A firm's systems and controls should include appropriate training for its employees in relation to money laundering. | none specified | none specified |
| COND 2.5 (Threshold conditions: Suitability) | ||||
| COND 2.5.1A(1)(e), with guidance at COND 2.5.6(10), (12), (15) and (18) competence | defined population — those who manage the firm's affairs; the governing body; persons performing controlled functions; and, for insurance distribution, relevant staff | Those who manage the firm's affairs must have adequate skills and experience and act with probity. The guidance adds that the governing body should comprise individuals with an appropriate range of skills and experience to understand, operate and manage the firm's regulated activities; that persons performing controlled functions should act with due skill, care and diligence; that for insurance distribution relevant staff must demonstrate appropriate knowledge and ability to complete their tasks and perform their duties adequately; and that the firm should have HR policies ensuring it employs only individuals who are honest and committed to high standards of integrity. | continuous — the threshold conditions must be satisfied at all times | none specified |
| FIT 2.2 (Competence and capability) | ||||
| FIT 2.2.1 and FIT 2.2.1A says train | named population — candidates for senior management and certification functions | In determining competence and capability, regard is had to whether the person satisfies the relevant FCA training and competence requirements, and whether the person has demonstrated BY EXPERIENCE AND TRAINING that they are suitable to perform the function. FIT 2.2.1A applies the same considerations to firms assessing candidates for FCA designated senior management or certification functions. | none specified | Evidence of experience and training sufficient to demonstrate suitability |
| Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) | ||||
| Article 13(6) says train | all staff — quoted: "applicable to all employees and to senior management staff", and where appropriate ICT third-party service providers | Financial entities shall develop ICT security awareness programmes and digital operational resilience training AS COMPULSORY MODULES in their staff training schemes. Those programmes and training shall be applicable to all employees and to senior management staff, and shall have a level of complexity commensurate to the remit of their functions. Where appropriate, financial entities shall also include ICT third-party service providers in their relevant training schemes in accordance with Article 30(2), point (i). | none stated — but the modules are compulsory within the staff training scheme | none specified in this Article |
| Article 5(4) says train | named population — members of the management body, personally | Members of the management body of the financial entity shall actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk and its impact on the operations of the financial entity, INCLUDING BY FOLLOWING SPECIFIC TRAINING ON A REGULAR BASIS, commensurate to the ICT risk being managed. | "on a regular basis" — no interval stated | none specified in this Article |
| Article 30(2), point (i), read with Article 13(6) says train | ICT third-party service providers' personnel, via contract | The contractual arrangement between the financial entity and an ICT third-party service provider must set out the conditions for the participation of the provider in the financial entity's ICT security awareness programmes and digital operational resilience training in accordance with Article 13(6). | none specified | The contractual arrangement itself |
| COCON (Code of Conduct), Chapter 2 | ||||
| COCON 2.1 (individual conduct rules) and COCON 2.2 (senior manager conduct rules), with FSMA s.64B says train | defined population — conduct rules staff, and separately senior managers | Six individual conduct rules apply to conduct rules staff: act with integrity; act with due skill, care and diligence; be open and cooperative with the FCA, PRA and other regulators; pay due regard to the interests of customers and treat them fairly; observe proper standards of market conduct; and act to deliver good outcomes for retail customers. Four senior manager conduct rules apply in addition. Under FSMA section 64B the firm must notify all affected staff of the rules that apply to them and ensure they understand how those rules apply, through suitable training — providing both broad awareness and a deeper understanding of the rules relevant to a person's specific role. | none specified | none specified in COCON itself; the s.64B duty is an outcome duty |
| Directive 2014/65/EU on markets in financial instruments (MiFID II) | ||||
| Article 25(1) competence | defined population — natural persons giving investment advice or information about financial instruments, investment services or ancillary services to clients on behalf of the firm | Member States shall require investment firms to ensure AND DEMONSTRATE to competent authorities on request that such natural persons possess the necessary knowledge and competence to fulfil their obligations under Article 24 and Article 25. Member States shall publish the criteria to be used for assessing such knowledge and competence. | none specified | The firm must be able to DEMONSTRATE knowledge and competence to the competent authority on request |
| Financial Crime Guide: A firm's guide to countering financial crime risks (FCG) | ||||
| FCG 2.2.6 says train | all staff, differentiated by role and risk — with new customer-facing staff and higher-risk roles called out specifically | The self-assessment questions ask what approach the firm takes to vetting staff and whether vetting reflects the financial crime risks of the role; how it ensures employees are aware of financial crime risks and their obligations; whether staff can access training on an appropriate range of financial crime risks; how training quality and currency are maintained; whether training is tailored to particular roles; and how the firm assesses training effectiveness. Good practice: tailored training keeping staff knowledge adequate and up to date; new customer-facing staff receiving role-tailored financial crime training; higher-risk roles subject to more thorough vetting; training with a strong practical dimension such as case studies, and some form of testing. | none specified — but currency of material and of vetting are both tested | Evidence of training effectiveness assessment; vetting records proportionate to role risk |
| The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as explained by HMRC's Economic Crime Supervision Handbook | ||||
| Regulation 24(3), per HMRC ECSH33220 says train | "relevant employees" and agents whose work is relevant to compliance, can contribute to identifying or mitigating risk, or can prevent or detect money laundering, terrorist financing or proliferation financing | Regulation 24 is not prescriptive about timing. Regulation 24(3) requires the business itself to DETERMINE the frequency of training by reference to the nature of its business, its size, and the nature and extent of the risks it is subject to. Content must adequately address the 2017 Regulations, Part 7 of the Proceeds of Crime Act 2002 and relevant sections of the Terrorism Act 2000; how to recognise and deal with relevant transactions or activity; red-flag indicators and sector-specific risks; the procedure when suspicion arises; data protection; and risks specific to the business. A written record of the training provided must be maintained. | determined by the firm from its own size and risk profile — the DUTY IS TO SET THE FREQUENCY, not to meet a stated one | A written record of the training provided, and the reasoning behind the frequency chosen |
| JMLSG Guidance for the UK Financial Sector, Part I, Chapter 7 (Staff awareness, training and alertness) | ||||
| Part I, paragraphs 7.1-7.3, 7.8-7.11, 7.16-7.21, and the chapter summary says train | "relevant employees" — defined at 7.9 as those whose work is relevant to the firm's compliance with the ML Regulations, or otherwise capable of contributing to the identification or mitigation of money laundering and terrorist financing risk. Separately and expressly: SENIOR MANAGEMENT, the MLRO and the nominated officer. | Firms must implement a clear and well-articulated policy ensuring relevant employees are aware of their obligations and are trained in identifying suspicious activity (7.3). AWARENESS AND TRAINING ARE SEPARATE REQUIREMENTS addressed separately by the ML Regulations (7.11). Screening of relevant employees means assessing both the skills, knowledge and expertise to carry out their functions effectively AND the conduct and integrity of the individual (7.8). Firms should take reasonable steps to ensure relevant employees are aware of their responsibilities under the firm's arrangements, and of the identity and responsibilities of the nominated officer and the MLRO (7.21). Awareness and training arrangements specifically for senior management, the MLRO and the nominated officer should also be considered (7.18). The chapter summary states: staff training should be given AT REGULAR INTERVALS, AND DETAILS RECORDED; the MLRO is responsible for oversight of the firm's compliance with its requirements in respect of staff training; and the relevant director or senior manager has overall responsibility for the establishment and maintenance of effective training arrangements. | "at regular intervals" — no interval stated | Details of training recorded. Named accountability: MLRO oversight, and a director or senior manager with overall responsibility for training arrangements. |
| APER (Statements of Principle and Code of Practice for Approved Persons), Chapter 4 | ||||
| APER 4.2.13, with APER 4.2.2AG competence | named population — approved persons performing a controlled function at an appointed representative | Quoted: "Continuing to perform a controlled function despite having failed to meet the standards of knowledge and skill set out in the Training and Competence sourcebook (TC) for that controlled function" does not comply with Statement of Principle 2 (due skill, care and diligence). The Statements of Principle are rules made under section 64A(1)(a) FSMA; APER 4 is the Code of Practice guidance on them. | none specified | none specified in this provision |
| APER 4.5.13A, with APER 4.5.8G, APER 4.5.9G(1) and APER 4.5.14G competence | named role — the approved person performing an accountable higher management function, in respect of each individual member of staff in their area | APER 4.5.13A: the approved person performing an accountable higher management function "should take reasonable steps to satisfy themselves, on reasonable grounds, that each area of the business for which they are responsible has in place appropriate policies and procedures for reviewing the competence, knowledge, skills and performance of each individual member of staff". APER 4.5.9G(1) makes "failing to review the competence, knowledge, skills and performance of staff to assess their suitability to fulfil their duties, despite evidence that their performance is unacceptable" a breach. APER 4.5.14G requires the approved person to review carefully whether to allow an individual to continue in position where performance is unsatisfactory. | none specified — the trigger is evidence of unacceptable performance | Policies and procedures for reviewing competence, knowledge, skills and performance, per area of business |
10 further obligations sit outside Financial Services regulation and bind you as an employer or as a deployer of AI. They are the ones a sector-by-sector review misses, because nobody who reads only their own rulebook ever reaches them.
| Clause | Who must be trained or assessed | What is required | Interval | Evidence required |
|---|---|---|---|---|
| EU AI Act (Reg (EU) 2024/1689) | ||||
| Article 4 (AI literacy) says train | defined population — quoted from the pre-amendment text: "their staff and other persons dealing with the operation and use of AI systems on their behalf" | AS ENACTED: providers and deployers were to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, education and training, the context of use, and the persons on whom the systems are used. AS AMENDED from 2026-07-27 by the Digital Omnibus on AI: AI literacy remains an obligation on providers and deployers, but no specific or 'sufficient' level is mandated; the Commission and Member States take a stronger role in promoting AI literacy. The obligation on deployers of HIGH-RISK AI systems to ensure staff are trained for human oversight remains in place. | none specified | none specified |
| Article 26(2) says train | named population — the natural persons assigned to exercise human oversight | Quoted: "Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support." | none specified | none specified in this paragraph |
| Employment Rights Act 2025 | ||||
| Whole Act — training provisions at s.65 and related says train | named role — trade union equality representatives, not the general workforce | The Act's training provisions concern whether a trade union equality representative has undergone sufficient training to carry on those activities, with notice requirements on the union and reference to a relevant ACAS or Secretary of State Code of Practice. It is not a mandatory workforce training duty of the kind the rest of this map records. | none specified | Written notice from the trade union to the employer |
| Equality Act 2010 | ||||
| Section 109(4), with section 109(1) case law Allay (UK) Ltd v Gehlen [2021] UKEAT/0031/20 — stale or inadequate training defeats the s.109(4) 'all reasonable steps' defence, making training the operative discharge. | all staff — the defence turns on steps taken to prevent employees doing discriminatory acts | An employer is liable for anything done by a person in the course of their employment. Quoted from 109(4): "In proceedings against A's employer (B) in respect of anything alleged to have been done by A in the course of A's employment it is a defence for B to show that B took all reasonable steps to prevent A—(a) from doing that thing, or (b) from doing anything of that description." | none specified | The employer must SHOW the steps taken. The burden sits with the employer. |
| UK GDPR | ||||
| Article 24, read with Article 5(2) guidance UK GDPR Article 39(1)(b) — read at source 2026-08-12 — names staff training as an element of compliance with the Regulation: the data protection officer must "monitor compliance with this Regulation... including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits". LIMIT OF THIS CITATION, stated plainly: Article 39 applies only where Article 37 requires a DPO to be appointed, so it does not by itself establish a training duty for every controller. It establishes that the Regulation treats staff training as part of compliance. The unconditional citation would be the ICO Accountability Framework, which has NOT been read — see not_yet_searched. | not specified — training is not expressly named in Article 24 | Quoted: "the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation." Those measures must be reviewed and updated where necessary, and are to include appropriate data protection policies where proportionate to the processing activities. Article 5(2) supplies the accountability principle itself: "The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1" — that is, with all six data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality. | measures to be reviewed and updated where necessary — no interval | The controller must be able to DEMONSTRATE compliance. This is the accountability limb. |
| The Regulatory Reform (Fire Safety) Order 2005 | ||||
| Article 21, with articles 3 and 6 says train | all staff — quoted: "his employees" | Quoted, 21(1): the responsible person "must ensure that his employees are provided with adequate safety training (a) at the time when they are first employed; and (b) on their being exposed to new or increased risks because of" transfer or change of responsibilities, new or changed work equipment, new technology, or a new or changed system of work. 21(2): that training must "(a) include suitable and sufficient instruction and training on the appropriate precautions and actions to be taken by the employee in order to safeguard himself and other relevant persons on the premises; (b) be repeated periodically where appropriate; (c) be adapted to take account of any new or changed risks; (d) be provided in a manner appropriate to the risk identified by the risk assessment; and (e) TAKE PLACE DURING WORKING HOURS." | Trigger-based, not periodic: on first employment AND on each of four listed changes. "Repeated periodically where appropriate" — no interval stated. | none specified in the article |
| The Management of Health and Safety at Work Regulations 1999 | ||||
| Regulation 13(2), with 13(1) and 13(3) says train | all staff — every employee, on recruitment and again on each triggering change | Quoted, 13(2): "Every employer shall ensure that his employees are provided with adequate health and safety training— (a) on their being recruited into the employer's undertaking; and (b) on their being exposed to new or increased risks because of— (i) their being transferred or given a change of responsibilities within the employer's undertaking, (ii) the introduction of new work equipment into or a change respecting work equipment already in use within the employer's undertaking, (iii) the introduction of new technology into the employer's undertaking, or (iv) the introduction of a new system of work into or a change respecting a system of work already in use within the employer's undertaking." 13(1) separately requires the employer, "in entrusting tasks to his employees, [to] take into account their capabilities as regards health and safety." | No fixed interval. The duty is TRIGGER-BASED — on recruitment, and on each of the four changes listed in 13(2)(b). | Not specified in the regulation itself. |
| Health and Safety at Work etc. Act 1974 | ||||
| Section 2(2)(c), with section 2(1) says train | all staff — scoped by what is 'necessary to ensure' their health and safety | Quoted, s.2(2)(c): the employer's general duty extends in particular to "the provision of such information, instruction, training and supervision as is necessary to ensure, so far as is reasonably practicable, the health and safety at work of his employees." This is the primary-legislation parent of the MHSWR reg 13 duty. Note the double qualifier: training is owed only so far as it is BOTH 'necessary to ensure' health and safety AND 'reasonably practicable'. | None. The measure is necessity, not interval. | Not specified in the section. |
| Council Directive 89/391/EEC (the Framework Directive) on the introduction of measures to encourage improvements in the safety and health of workers at work | ||||
| Article 12(1) and 12(4) says train | all staff — 'each worker' | Quoted, 12(1): "The employer shall ensure that each worker receives adequate safety and health training, in particular in the form of information and instructions specific to his workstation or job: — on recruitment, — in the event of a transfer or a change of job, — in the event of the introduction of new work equipment or a change in equipment, — in the event of the introduction of any new technology. The training shall be: — adapted to take account of new or changed risks, and — repeated periodically if necessary." Quoted, 12(4): "The training referred to in paragraphs 1 and 3 MAY NOT BE AT THE WORKERS' EXPENSE... The training referred to in paragraph 1 MUST TAKE PLACE DURING WORKING HOURS." | No fixed interval. Trigger-based on four named events, PLUS two standing qualities the UK implementation does not spell out as clearly: adapted to new or changed risks, and "repeated periodically if necessary". | Not specified in Article 12. |
| Article 12(2) says train | named population — workers from OUTSIDE undertakings and/or establishments engaged in work in your undertaking. Contractors, agency staff, visiting engineers, maintenance crews. | Quoted in full: "The employer shall ensure that workers from outside undertakings and/or establishments engaged in work in his undertaking and/or establishment HAVE IN FACT RECEIVED appropriate instructions regarding health and safety risks during their activities in his undertaking and/or establishment." | None — triggered by the outside workers being engaged in work in your undertaking. | Not specified, but note the wording: the employer must ensure they "have in fact received" the instructions. That is a verification duty, not a provision duty — it is not discharged by having issued something. |
7 provisions that sit alongside the duties above without themselves requiring training. They are here because they are the ones most often mistaken for training duties, or most often missed when scoping them. We separate them rather than pad the count.
| Clause | Who it concerns | What is required | Interval | Evidence required |
|---|---|---|---|---|
| Training and Competence sourcebook (TC), Chapter 2.1 | ||||
| TC 2.1.24R related Record itself declares this is not a training duty. | n/a — this is a record-keeping duty, not a training duty | The firm must make and retain records of the CPD completed by each retail investment adviser and pension transfer specialist, and of the dates of and reasons for any suspension of the CPD requirement. | none specified | Records of CPD completed, and of suspensions and their reasons. Retention period not stated in the rule text. TC 2.1.24AG indicates the records should enable FCA monitoring of continued professional training under SYSC 9.1.1R. |
| SYSC 27 (Senior managers and certification regime: Certification regime) | ||||
| SYSC 27.2.13G related Record itself declares this is not a training duty. | n/a — record-keeping duty | A firm must maintain a record of every employee who has a valid certificate issued by it. | none specified | A maintained record of all certificated employees |
| SYSC 18.3 (Whistleblowing) | ||||
| SYSC 18.3.7R related Duty is to INFORM of a right, not to train. The express whistleblowing training duty is SYSC 18.3.1R(2)(g), held separately in this map as express_training. | defined population — UK-based employees of the firm's appointed representatives and tied agents | The firm must take reasonable steps to ensure that its appointed representatives and tied agents inform their UK-based employees who are workers of their right to make a protected disclosure to the FCA. | none specified | none specified |
| SYSC 28 (Insurance distribution: training and competence) | ||||
| SYSC 28.4.2R, with SYSC 28.4.1R related Record itself declares this is not a training duty. | n/a — record-keeping duty | The firm must keep an up-to-date record of the continued professional training and development completed by each long-term insurance employee in each 12 month period, and must establish, maintain and keep appropriate records to demonstrate compliance with the chapter. It must provide any version of the record to the FCA on request, and give the FCA the name of the person responsible for the records on request. | per 12-month period | Retained for a minimum of 3 years after the person stops carrying on the activity |
| SYSC 28.4.3R and SYSC 28.4.4R related Record itself declares this is not a training duty. | n/a — access duty | The firm must not prevent a non-investment insurance employee, or a long-term insurance employee, from obtaining access to their own training records maintained under SYSC 28.4.1R, SYSC 28.4.2R, SYSC 3.2.20R or SYSC 9.1.1R. | none specified | n/a |
| SYSC 22.2 (Regulatory references) | ||||
| SYSC 22.2.1R, SYSC 22.2.2R and SYSC 22.2.4R related Record itself declares this is not a training duty. | n/a — an evidence and disclosure duty supporting the fitness assessment | A firm must obtain a reference from the candidate's current employer and from anyone who employed them within the past 6 years, requesting the prescribed information and the SMCR questions in the Annex 1 template. A firm asked for a reference must disclose all information it is aware of that it reasonably considers relevant to the fitness and propriety assessment, covering the 6 years before the request, plus matters arising between request and reference, plus serious misconduct at any time. A firm must revise a reference it has already given if it becomes aware of matters that would have changed it — for up to 6 years after the person ceased employment. | 6-year look-back; revision duty runs for 6 years after the person leaves | The reference itself, in the prescribed form |
| FIT (The Fit and Proper test), Chapters 2.1 and 2.3 | ||||
| FIT 2.1.1G and FIT 2.1.3G; FIT 2.3.1G and FIT 2.3.2G related Record itself declares this is not a training duty. | n/a — assessment criteria rather than a training duty | Honesty, integrity and reputation (FIT 2.1): the FCA will have regard to all relevant matters, including thirteen categories at FIT 2.1.3G — criminal convictions including spent convictions, adverse civil findings, regulatory investigations and disciplinary proceedings, contraventions of regulatory or professional standards, complaints, association with refused or de-registered entities, insolvency involvement, dismissal or requested resignation from positions of trust, director disqualification, and candour in dealings with regulators. Financial soundness (FIT 2.3): outstanding judgment debts, arrangements with creditors, bankruptcy and bankruptcy restrictions. FIT 2.3.2G states the FCA will not normally require a statement of assets or liabilities and that limited means alone does not affect suitability. | none specified | The assessment against these criteria |
The most demanding training duty in UK financial services is not in the Handbook at all. Section 64B of the Financial Services and Markets Act 2000 requires every authorised person to notify relevant persons of the conduct rules and to take all reasonable steps to secure that they understand how those rules apply to them — and the statute names the provision of suitable training as the particular step expected.
The standard is comprehension, not delivery. And since the conduct rules were extended, the population is very close to the whole firm.
A training matrix assembled from the Handbook alone will not contain it.
SYSC 27.2.15G is the sharpest instance. Where a certification employee moves into a function with different competence, qualification or training requirements, fitness must be assessed before they start it — and the provision says expressly that this is not done at the annual reassessment point.
So a firm running a clean, well-evidenced annual re-certification cycle can still be in breach for every internal move made between cycles. The provision carries a 24 April 2026 date stamp: it is among the newest text in this map.
Regulation 21 of the 2017 Regulations has the same shape from the other direction — screening of relevant employees is required both before the appointment is made and during the course of the appointment. The continuing limb has no interval and, in most firms, no owner.
Three separate annual CPD figures apply to three overlapping populations. Retail investment advisers: 35 hours. Pension transfer specialists: 15 hours, with at least 5 from external independent providers. Long-term insurance personnel: 15 hours, under a different chapter with a different record-retention rule.
Standardise on one figure across advisory and insurance staff and you will satisfy some of these and breach others — and the breach is invisible on an aggregate completion report.
Two duties leave the payroll altogether. Regulation 24 covers any agents used for the purposes of the business. SYSC 18.3.7R requires the firm to ensure its appointed representatives and tied agents inform their own employees of the right to make a protected disclosure.
Three separate duties here require a record that survives the employment relationship.
SYSC 28.4.2R — the CPD record for long-term insurance employees, retained a minimum of three years after the person stops the activity. SYSC 22.2.4R — the duty to revise a regulatory reference already given, for up to six years after the person left. And TC 2.1.27R, which goes furthest of anything here: the firm's own record is expressly not enough, and an accredited body must independently verify qualification, CPD compliance and the annual declaration.
A learning system that deprovisions leavers breaches the first silently, because the record that would evidence the gap is the one that was deleted.
This map states what it did not check as well as what it did. A map that quietly omits its own gaps is worth less than one that marks them.
34 obligations across 20 instruments, each read directly from the published source on 2026-08-10.
Recorded because “we searched and found nothing” is a different fact from “we did not search”.
Their absence is not evidence that they contain no training duty.
Ten minutes on where your obligations actually sit. Fifteen watching a module built live from your own source documents. Five on whether there is a next step. Nothing to prepare and nothing to send beforehand.