Agiliton
Sector obligation map

Mandatory training obligations in financial services

34 training duties across 20 instruments binding Financial Services, plus 10 that bind you whatever your sector — statute, rulebook, statutory guidance and licence conditions. Every one traced to its clause, its date and its published source, and each one labelled with what makes it a training duty.

JurisdictionUnited Kingdom
Built2026-08-10
Training duties44
Instruments28
Verified44 of 44
Every entry traced to a published clause

Financial services carries more mandatory training duties than any other sector in this series, and they do not behave alike.

A handful are specified in hours or months and are generally well managed — three separate annual CPD figures for three different populations, and a certificate that lasts a maximum of twelve months.

The rest are not. They are drafted as duties to ensure competence, to assess it at defined moments, and to be able to produce a record of what was done. Several sit outside the FCA Handbook entirely — in primary legislation, in statutory instruments, and in the authorisation conditions the firm holds its permission under.

The obligations

Each clause carries a label saying why it is a training duty. Where the instrument does not use the word, we cite the guidance or the case that makes training the way you discharge it. Where we cannot cite anyone, it is not listed as a training duty at all.

says trainThe instrument itself requires training, instruction or CPD.
competenceThe instrument requires competence, qualification or knowledge. Training is the usual means; the instrument does not name it.
guidanceThe binding duty is an outcome. Official guidance under the instrument names training as how it is discharged.
case lawThe binding duty is an outcome. Case law makes training the operative discharge.
ClauseWho must be trained or assessedWhat is requiredIntervalEvidence required
Senior Management Arrangements, Systems and Controls (SYSC), Chapter 5.1
SYSC 5.1.1R
competence
named role — quoted: "personnel with the skills, knowledge and expertise necessary for the discharge of the responsibilities allocated to them"The firm must employ personnel who have the skills, knowledge and expertise needed for the responsibilities they are given. It is a competence duty on the firm, not a duty to run a course.none specifiednone specified in this rule
SYSC 5.1.5ABR
competence
defined population — individuals who make personal recommendations or give information about financial instruments or structured depositsThe firm must ensure those individuals possess the necessary knowledge and competence to meet its obligations under SYSC, COBS and PROD.none specifiednone specified in this rule
Training and Competence sourcebook (TC), Chapter 2.1
TC 2.1.12R
competence
defined population — employees carrying on activities listed in TC Appendix 1The firm must review the competence of each such employee on a regular and frequent basis and take appropriate action to ensure competence is maintained."regular and frequent" — no interval statednone specified in this rule; see TC 2.1.24R
TC 2.1.15R
says train
named role — retail investment advisersA minimum of 35 hours of appropriate continuing professional development in each 12-month period, of which a minimum of 21 hours should be structured CPD (TC 2.1.16G).35 hours per 12-month periodRecords of CPD completed — TC 2.1.24R
TC 2.1.23AR
says train
named role — pension transfer specialistsA minimum of 15 hours of CPD per 12-month period, including at least 9 hours of structured activity, of which at least 5 hours must be from external independent providers. Pro-rated in the year of assessment.15 hours per 12-month periodRecords of CPD completed — TC 2.1.24R
TC 2.1.27R and TC 2.1.28R
says train
named role — retail investment advisersThe firm must obtain independent verification from an accredited body that the adviser has attained the appropriate qualification, has complied with the 35-hour CPD rule, and has made the annual declaration. Verification must be obtained within 60 days of the competence date and annually thereafter. TC 2.1.29G indicates this takes the form of a statement of professional standing.within 60 days of the competence date, and annually thereafterIndependent verification by an accredited body — a statement of professional standing
TC 2.1.5BR and TC 2.1.5CR
says train
defined population — employees carrying on MCD credit activities (regulated activities 23A to 23E)Employees must possess appropriate knowledge across nine named areas: MCD credit agreements and ancillary services; consumer protection law relating to such agreements; the property purchasing process; security valuation; the organisation and functioning of land registers; the market; business ethics standards; creditworthiness assessment; and financial and economic competency. A firm MUST NOT assess knowledge and competence based solely on relevant professional experience — the assessment must also include qualifications, diplomas, degrees, training or competency tests.none specifiedThe assessment, which cannot rest on experience alone
TC 2.1.5HR
competence
named role — employees advising on P2P agreements (regulated activity 9A)A firm must not assess an employee advising on P2P agreements as competent until the employee has attained each module of an appropriate qualification for giving personal recommendations on retail investment products to retail clients.none specified — a precondition to being assessed as competentAttainment of each module of the qualification
Money Laundering Regulations 2017
Regulation 24 (Training)
says train
defined population — quoted: "relevant employees" and "any agents it uses for the purposes of its business whose work is of a kind mentioned in paragraph (2)"The relevant person must take appropriate measures to ensure that relevant employees and agents are made aware of the law relating to money laundering, terrorist financing and proliferation financing and to data protection, and are regularly given training in how to recognise and deal with transactions and other activities which may be related to money laundering, terrorist financing or proliferation financing."regularly" — no interval statedThe relevant person must maintain a record in writing of the measures taken, including the training given to relevant employees and to any agents.
Regulation 21 (Internal controls)
competence
defined population — relevant employees appointed by the relevant personThe relevant person must carry out screening of relevant employees appointed by it, both BEFORE the appointment is made and DURING the course of the appointment. Screening means assessing the skills, knowledge and expertise of the individual to carry out their functions effectively, and the conduct and integrity of the individual.before appointment and during the course of the appointment — no interval stated for the ongoing limbnone specified in this regulation
SYSC 27 (Senior managers and certification regime: Certification regime)
SYSC 27.2.3G
competence
named population — employees performing an FCA certification functionA firm must take reasonable care to ensure that no employee performs an FCA certification function unless the employee has a valid certificate issued by that firm to perform the function.none in this provision; certificate validity capped at 12 months by SYSC 27.2.10GA valid certificate issued by the firm
SYSC 27.2.4G and SYSC 27.2.5G
says train
named population — candidates for an FCA certification functionA firm may issue a certificate only if satisfied the person is fit and proper to perform the function. In assessing that, the firm must have regard to whether the person has obtained a qualification, undergone training, possesses the required level of competence, or has the required personal characteristics.none specifiedThe assessment underpinning the certificate
SYSC 27.2.10G, with SYSC 27.2.20G
competence
named population — certification staffA certificate is valid for a maximum of 12 months. A firm may set a shorter period but cannot exceed 12 months. SYSC 27.2.20G states the FCA would expect annual re-certification on expiry to be done in a proportionate and streamlined manner.maximum 12 months — annual re-certificationA current, in-date certificate per person per function
SYSC 27.2.15G
says train
named population — certification employees changing roleWhere a certification employee's role changes so as to involve a new FCA certification function with different personal characteristics, competence, qualification or training requirements, the firm must assess fitness for the new function BEFORE the employee starts it — expressly not at the annual reassessment point.trigger-based — before the employee starts the new functionAn assessment dated before the role change took effect
FIT (The Fit and Proper test for Employees and Senior Personnel), Chapter 1.3
FIT 1.3.1B, FIT 1.3.2A and FIT 1.3.4B
competence
named population — candidates and holders of certification functionsThe most important considerations are honesty, integrity and reputation; competence and capability; and financial soundness (FIT 1.3.1B). The firm must consider the nature, scale and complexity of its business and whether the candidate has the knowledge, skills and experience to perform the specific role (FIT 1.3.2A). Assessors require an up-to-date job description (FIT 1.3.4B).none specifiedAn up-to-date job description is expressly required for a proper assessment (FIT 1.3.4B)
Financial Services and Markets Act 2000
Section 64B (Rules of conduct: responsibilities of authorised persons)
says train
defined population, drawn very wide — relevant persons, comprising persons approved under s.59 on the firm's application, EMPLOYEES of the authorised person, and DIRECTORS of the authorised personEvery authorised person must notify all relevant persons of the conduct rules that apply to them, and take all reasonable steps to secure that those persons understand how those rules apply to them. The statute states that the steps to be taken to comply with the second limb include, in particular, THE PROVISION OF SUITABLE TRAINING.none specifiednone specified in the section
Section 63E (Certification of employees by relevant authorised persons), with section 63F
competence
named population — employees performing a specified significant-harm functionAn authorised person must take reasonable care to ensure that no employee performs a specified function unless the employee has a valid certificate issued by the firm under section 63F. Specified functions are significant-harm functions — those involving aspects of the business that present a risk of material harm to the firm or its customers.certificate validity is addressed by s.63F and capped at 12 months in SYSC 27.2.10GA valid certificate per employee per function
Section 63F (Issuing of certificates)
competence
named population — candidates for a significant-harm functionAn authorised person may issue a certificate only if satisfied that the person is a fit and proper person to perform the function to which the certificate relates. The certificate must state that the firm is so satisfied, and set out the aspects of the firm's affairs in which the person will be involved. A certificate is valid for a period of 12 months beginning with the day on which it is issued.12 months — STATUTORY, not merely Handbook guidanceThe certificate itself, stating the satisfaction and the scope of involvement
SYSC 18.3 (Whistleblowing)
SYSC 18.3.1R(2)(g), with SYSC 18.3.4G
says train
three distinct populations — UK-based employees; managers of UK-based employees wherever the manager is located; and employees who operate the firm's internal whistleblowing arrangementsThe firm's internal arrangements must include appropriate training for each of the three populations. SYSC 18.3.4G sets out different content for each: UK-based employees need the firm's statement that it takes reportable concerns seriously, the reporting routes, examples of events that would prompt a concern, examples of action taken afterwards, and sources of external support. Managers additionally need to recognise a disclosure, protect confidentiality, give feedback, treat an accused person fairly, and know where to get advice. Those operating the arrangements need training on protecting confidentiality, assessing the significance of a disclosure, and assisting the whistleblowers' champion.none specifiednone specified in this provision
SYSC 28 (Insurance distribution: training and competence)
SYSC 28.2.1R(1)
competence
defined population — the firm itself and all non-investment insurance personnel and all long-term insurance personnelThe firm must ensure that it and all relevant insurance personnel possess appropriate knowledge and ability in order to complete their tasks and perform their duties adequately.none specified in this sub-paragraphRecords — SYSC 28.4.1R
SYSC 28.2.1R(3), with SYSC 28.2.1R(2) and SYSC 28.2.1R(4)
says train
named role — each long-term insurance employee or personEach long-term insurance employee must complete a minimum of 15 hours of professional training or development in each 12 month period. The firm must comply with continued professional training and development requirements to maintain adequate performance, and in assessing personnel must take account of the role and activity carried out, and the type of distribution and nature of the products.15 hours per 12-month periodAn up-to-date record per person per 12-month period — SYSC 28.4.2R
SYSC 6.3 (Financial crime)
SYSC 6.3.7(1)
says train
all staff — employeesA firm's systems and controls should include appropriate training for its employees in relation to money laundering.none specifiednone specified
COND 2.5 (Threshold conditions: Suitability)
COND 2.5.1A(1)(e), with guidance at COND 2.5.6(10), (12), (15) and (18)
competence
defined population — those who manage the firm's affairs; the governing body; persons performing controlled functions; and, for insurance distribution, relevant staffThose who manage the firm's affairs must have adequate skills and experience and act with probity. The guidance adds that the governing body should comprise individuals with an appropriate range of skills and experience to understand, operate and manage the firm's regulated activities; that persons performing controlled functions should act with due skill, care and diligence; that for insurance distribution relevant staff must demonstrate appropriate knowledge and ability to complete their tasks and perform their duties adequately; and that the firm should have HR policies ensuring it employs only individuals who are honest and committed to high standards of integrity.continuous — the threshold conditions must be satisfied at all timesnone specified
FIT 2.2 (Competence and capability)
FIT 2.2.1 and FIT 2.2.1A
says train
named population — candidates for senior management and certification functionsIn determining competence and capability, regard is had to whether the person satisfies the relevant FCA training and competence requirements, and whether the person has demonstrated BY EXPERIENCE AND TRAINING that they are suitable to perform the function. FIT 2.2.1A applies the same considerations to firms assessing candidates for FCA designated senior management or certification functions.none specifiedEvidence of experience and training sufficient to demonstrate suitability
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
Article 13(6)
says train
all staff — quoted: "applicable to all employees and to senior management staff", and where appropriate ICT third-party service providersFinancial entities shall develop ICT security awareness programmes and digital operational resilience training AS COMPULSORY MODULES in their staff training schemes. Those programmes and training shall be applicable to all employees and to senior management staff, and shall have a level of complexity commensurate to the remit of their functions. Where appropriate, financial entities shall also include ICT third-party service providers in their relevant training schemes in accordance with Article 30(2), point (i).none stated — but the modules are compulsory within the staff training schemenone specified in this Article
Article 5(4)
says train
named population — members of the management body, personallyMembers of the management body of the financial entity shall actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk and its impact on the operations of the financial entity, INCLUDING BY FOLLOWING SPECIFIC TRAINING ON A REGULAR BASIS, commensurate to the ICT risk being managed."on a regular basis" — no interval statednone specified in this Article
Article 30(2), point (i), read with Article 13(6)
says train
ICT third-party service providers' personnel, via contractThe contractual arrangement between the financial entity and an ICT third-party service provider must set out the conditions for the participation of the provider in the financial entity's ICT security awareness programmes and digital operational resilience training in accordance with Article 13(6).none specifiedThe contractual arrangement itself
COCON (Code of Conduct), Chapter 2
COCON 2.1 (individual conduct rules) and COCON 2.2 (senior manager conduct rules), with FSMA s.64B
says train
defined population — conduct rules staff, and separately senior managersSix individual conduct rules apply to conduct rules staff: act with integrity; act with due skill, care and diligence; be open and cooperative with the FCA, PRA and other regulators; pay due regard to the interests of customers and treat them fairly; observe proper standards of market conduct; and act to deliver good outcomes for retail customers. Four senior manager conduct rules apply in addition. Under FSMA section 64B the firm must notify all affected staff of the rules that apply to them and ensure they understand how those rules apply, through suitable training — providing both broad awareness and a deeper understanding of the rules relevant to a person's specific role.none specifiednone specified in COCON itself; the s.64B duty is an outcome duty
Directive 2014/65/EU on markets in financial instruments (MiFID II)
Article 25(1)
competence
defined population — natural persons giving investment advice or information about financial instruments, investment services or ancillary services to clients on behalf of the firmMember States shall require investment firms to ensure AND DEMONSTRATE to competent authorities on request that such natural persons possess the necessary knowledge and competence to fulfil their obligations under Article 24 and Article 25. Member States shall publish the criteria to be used for assessing such knowledge and competence.none specifiedThe firm must be able to DEMONSTRATE knowledge and competence to the competent authority on request
Financial Crime Guide: A firm's guide to countering financial crime risks (FCG)
FCG 2.2.6
says train
all staff, differentiated by role and risk — with new customer-facing staff and higher-risk roles called out specificallyThe self-assessment questions ask what approach the firm takes to vetting staff and whether vetting reflects the financial crime risks of the role; how it ensures employees are aware of financial crime risks and their obligations; whether staff can access training on an appropriate range of financial crime risks; how training quality and currency are maintained; whether training is tailored to particular roles; and how the firm assesses training effectiveness. Good practice: tailored training keeping staff knowledge adequate and up to date; new customer-facing staff receiving role-tailored financial crime training; higher-risk roles subject to more thorough vetting; training with a strong practical dimension such as case studies, and some form of testing.none specified — but currency of material and of vetting are both testedEvidence of training effectiveness assessment; vetting records proportionate to role risk
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as explained by HMRC's Economic Crime Supervision Handbook
Regulation 24(3), per HMRC ECSH33220
says train
"relevant employees" and agents whose work is relevant to compliance, can contribute to identifying or mitigating risk, or can prevent or detect money laundering, terrorist financing or proliferation financingRegulation 24 is not prescriptive about timing. Regulation 24(3) requires the business itself to DETERMINE the frequency of training by reference to the nature of its business, its size, and the nature and extent of the risks it is subject to. Content must adequately address the 2017 Regulations, Part 7 of the Proceeds of Crime Act 2002 and relevant sections of the Terrorism Act 2000; how to recognise and deal with relevant transactions or activity; red-flag indicators and sector-specific risks; the procedure when suspicion arises; data protection; and risks specific to the business. A written record of the training provided must be maintained.determined by the firm from its own size and risk profile — the DUTY IS TO SET THE FREQUENCY, not to meet a stated oneA written record of the training provided, and the reasoning behind the frequency chosen
JMLSG Guidance for the UK Financial Sector, Part I, Chapter 7 (Staff awareness, training and alertness)
Part I, paragraphs 7.1-7.3, 7.8-7.11, 7.16-7.21, and the chapter summary
says train
"relevant employees" — defined at 7.9 as those whose work is relevant to the firm's compliance with the ML Regulations, or otherwise capable of contributing to the identification or mitigation of money laundering and terrorist financing risk. Separately and expressly: SENIOR MANAGEMENT, the MLRO and the nominated officer.Firms must implement a clear and well-articulated policy ensuring relevant employees are aware of their obligations and are trained in identifying suspicious activity (7.3). AWARENESS AND TRAINING ARE SEPARATE REQUIREMENTS addressed separately by the ML Regulations (7.11). Screening of relevant employees means assessing both the skills, knowledge and expertise to carry out their functions effectively AND the conduct and integrity of the individual (7.8). Firms should take reasonable steps to ensure relevant employees are aware of their responsibilities under the firm's arrangements, and of the identity and responsibilities of the nominated officer and the MLRO (7.21). Awareness and training arrangements specifically for senior management, the MLRO and the nominated officer should also be considered (7.18). The chapter summary states: staff training should be given AT REGULAR INTERVALS, AND DETAILS RECORDED; the MLRO is responsible for oversight of the firm's compliance with its requirements in respect of staff training; and the relevant director or senior manager has overall responsibility for the establishment and maintenance of effective training arrangements."at regular intervals" — no interval statedDetails of training recorded. Named accountability: MLRO oversight, and a director or senior manager with overall responsibility for training arrangements.
APER (Statements of Principle and Code of Practice for Approved Persons), Chapter 4
APER 4.2.13, with APER 4.2.2AG
competence
named population — approved persons performing a controlled function at an appointed representativeQuoted: "Continuing to perform a controlled function despite having failed to meet the standards of knowledge and skill set out in the Training and Competence sourcebook (TC) for that controlled function" does not comply with Statement of Principle 2 (due skill, care and diligence). The Statements of Principle are rules made under section 64A(1)(a) FSMA; APER 4 is the Code of Practice guidance on them.none specifiednone specified in this provision
APER 4.5.13A, with APER 4.5.8G, APER 4.5.9G(1) and APER 4.5.14G
competence
named role — the approved person performing an accountable higher management function, in respect of each individual member of staff in their areaAPER 4.5.13A: the approved person performing an accountable higher management function "should take reasonable steps to satisfy themselves, on reasonable grounds, that each area of the business for which they are responsible has in place appropriate policies and procedures for reviewing the competence, knowledge, skills and performance of each individual member of staff". APER 4.5.9G(1) makes "failing to review the competence, knowledge, skills and performance of staff to assess their suitability to fulfil their duties, despite evidence that their performance is unacceptable" a breach. APER 4.5.14G requires the approved person to review carefully whether to allow an individual to continue in position where performance is unsatisfactory.none specified — the trigger is evidence of unacceptable performancePolicies and procedures for reviewing competence, knowledge, skills and performance, per area of business

Binds you whatever your sector

10 further obligations sit outside Financial Services regulation and bind you as an employer or as a deployer of AI. They are the ones a sector-by-sector review misses, because nobody who reads only their own rulebook ever reaches them.

ClauseWho must be trained or assessedWhat is requiredIntervalEvidence required
EU AI Act (Reg (EU) 2024/1689)
Article 4 (AI literacy)
says train
defined population — quoted from the pre-amendment text: "their staff and other persons dealing with the operation and use of AI systems on their behalf"AS ENACTED: providers and deployers were to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, education and training, the context of use, and the persons on whom the systems are used. AS AMENDED from 2026-07-27 by the Digital Omnibus on AI: AI literacy remains an obligation on providers and deployers, but no specific or 'sufficient' level is mandated; the Commission and Member States take a stronger role in promoting AI literacy. The obligation on deployers of HIGH-RISK AI systems to ensure staff are trained for human oversight remains in place.none specifiednone specified
Article 26(2)
says train
named population — the natural persons assigned to exercise human oversightQuoted: "Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support."none specifiednone specified in this paragraph
Employment Rights Act 2025
Whole Act — training provisions at s.65 and related
says train
named role — trade union equality representatives, not the general workforceThe Act's training provisions concern whether a trade union equality representative has undergone sufficient training to carry on those activities, with notice requirements on the union and reference to a relevant ACAS or Secretary of State Code of Practice. It is not a mandatory workforce training duty of the kind the rest of this map records.none specifiedWritten notice from the trade union to the employer
Equality Act 2010
Section 109(4), with section 109(1)
case law
Allay (UK) Ltd v Gehlen [2021] UKEAT/0031/20 — stale or inadequate training defeats the s.109(4) 'all reasonable steps' defence, making training the operative discharge.
all staff — the defence turns on steps taken to prevent employees doing discriminatory actsAn employer is liable for anything done by a person in the course of their employment. Quoted from 109(4): "In proceedings against A's employer (B) in respect of anything alleged to have been done by A in the course of A's employment it is a defence for B to show that B took all reasonable steps to prevent A—(a) from doing that thing, or (b) from doing anything of that description."none specifiedThe employer must SHOW the steps taken. The burden sits with the employer.
UK GDPR
Article 24, read with Article 5(2)
guidance
UK GDPR Article 39(1)(b) — read at source 2026-08-12 — names staff training as an element of compliance with the Regulation: the data protection officer must "monitor compliance with this Regulation... including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits". LIMIT OF THIS CITATION, stated plainly: Article 39 applies only where Article 37 requires a DPO to be appointed, so it does not by itself establish a training duty for every controller. It establishes that the Regulation treats staff training as part of compliance. The unconditional citation would be the ICO Accountability Framework, which has NOT been read — see not_yet_searched.
not specified — training is not expressly named in Article 24Quoted: "the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation." Those measures must be reviewed and updated where necessary, and are to include appropriate data protection policies where proportionate to the processing activities. Article 5(2) supplies the accountability principle itself: "The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1" — that is, with all six data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality.measures to be reviewed and updated where necessary — no intervalThe controller must be able to DEMONSTRATE compliance. This is the accountability limb.
The Regulatory Reform (Fire Safety) Order 2005
Article 21, with articles 3 and 6
says train
all staff — quoted: "his employees"Quoted, 21(1): the responsible person "must ensure that his employees are provided with adequate safety training (a) at the time when they are first employed; and (b) on their being exposed to new or increased risks because of" transfer or change of responsibilities, new or changed work equipment, new technology, or a new or changed system of work. 21(2): that training must "(a) include suitable and sufficient instruction and training on the appropriate precautions and actions to be taken by the employee in order to safeguard himself and other relevant persons on the premises; (b) be repeated periodically where appropriate; (c) be adapted to take account of any new or changed risks; (d) be provided in a manner appropriate to the risk identified by the risk assessment; and (e) TAKE PLACE DURING WORKING HOURS."Trigger-based, not periodic: on first employment AND on each of four listed changes. "Repeated periodically where appropriate" — no interval stated.none specified in the article
The Management of Health and Safety at Work Regulations 1999
Regulation 13(2), with 13(1) and 13(3)
says train
all staff — every employee, on recruitment and again on each triggering changeQuoted, 13(2): "Every employer shall ensure that his employees are provided with adequate health and safety training— (a) on their being recruited into the employer's undertaking; and (b) on their being exposed to new or increased risks because of— (i) their being transferred or given a change of responsibilities within the employer's undertaking, (ii) the introduction of new work equipment into or a change respecting work equipment already in use within the employer's undertaking, (iii) the introduction of new technology into the employer's undertaking, or (iv) the introduction of a new system of work into or a change respecting a system of work already in use within the employer's undertaking." 13(1) separately requires the employer, "in entrusting tasks to his employees, [to] take into account their capabilities as regards health and safety."No fixed interval. The duty is TRIGGER-BASED — on recruitment, and on each of the four changes listed in 13(2)(b).Not specified in the regulation itself.
Health and Safety at Work etc. Act 1974
Section 2(2)(c), with section 2(1)
says train
all staff — scoped by what is 'necessary to ensure' their health and safetyQuoted, s.2(2)(c): the employer's general duty extends in particular to "the provision of such information, instruction, training and supervision as is necessary to ensure, so far as is reasonably practicable, the health and safety at work of his employees." This is the primary-legislation parent of the MHSWR reg 13 duty. Note the double qualifier: training is owed only so far as it is BOTH 'necessary to ensure' health and safety AND 'reasonably practicable'.None. The measure is necessity, not interval.Not specified in the section.
Council Directive 89/391/EEC (the Framework Directive) on the introduction of measures to encourage improvements in the safety and health of workers at work
Article 12(1) and 12(4)
says train
all staff — 'each worker'Quoted, 12(1): "The employer shall ensure that each worker receives adequate safety and health training, in particular in the form of information and instructions specific to his workstation or job: — on recruitment, — in the event of a transfer or a change of job, — in the event of the introduction of new work equipment or a change in equipment, — in the event of the introduction of any new technology. The training shall be: — adapted to take account of new or changed risks, and — repeated periodically if necessary." Quoted, 12(4): "The training referred to in paragraphs 1 and 3 MAY NOT BE AT THE WORKERS' EXPENSE... The training referred to in paragraph 1 MUST TAKE PLACE DURING WORKING HOURS."No fixed interval. Trigger-based on four named events, PLUS two standing qualities the UK implementation does not spell out as clearly: adapted to new or changed risks, and "repeated periodically if necessary".Not specified in Article 12.
Article 12(2)
says train
named population — workers from OUTSIDE undertakings and/or establishments engaged in work in your undertaking. Contractors, agency staff, visiting engineers, maintenance crews.Quoted in full: "The employer shall ensure that workers from outside undertakings and/or establishments engaged in work in his undertaking and/or establishment HAVE IN FACT RECEIVED appropriate instructions regarding health and safety risks during their activities in his undertaking and/or establishment."None — triggered by the outside workers being engaged in work in your undertaking.Not specified, but note the wording: the employer must ensure they "have in fact received" the instructions. That is a verification duty, not a provision duty — it is not discharged by having issued something.

Related duties — not training obligations

7 provisions that sit alongside the duties above without themselves requiring training. They are here because they are the ones most often mistaken for training duties, or most often missed when scoping them. We separate them rather than pad the count.

ClauseWho it concernsWhat is requiredIntervalEvidence required
Training and Competence sourcebook (TC), Chapter 2.1
TC 2.1.24R
related
Record itself declares this is not a training duty.
n/a — this is a record-keeping duty, not a training dutyThe firm must make and retain records of the CPD completed by each retail investment adviser and pension transfer specialist, and of the dates of and reasons for any suspension of the CPD requirement.none specifiedRecords of CPD completed, and of suspensions and their reasons. Retention period not stated in the rule text. TC 2.1.24AG indicates the records should enable FCA monitoring of continued professional training under SYSC 9.1.1R.
SYSC 27 (Senior managers and certification regime: Certification regime)
SYSC 27.2.13G
related
Record itself declares this is not a training duty.
n/a — record-keeping dutyA firm must maintain a record of every employee who has a valid certificate issued by it.none specifiedA maintained record of all certificated employees
SYSC 18.3 (Whistleblowing)
SYSC 18.3.7R
related
Duty is to INFORM of a right, not to train. The express whistleblowing training duty is SYSC 18.3.1R(2)(g), held separately in this map as express_training.
defined population — UK-based employees of the firm's appointed representatives and tied agentsThe firm must take reasonable steps to ensure that its appointed representatives and tied agents inform their UK-based employees who are workers of their right to make a protected disclosure to the FCA.none specifiednone specified
SYSC 28 (Insurance distribution: training and competence)
SYSC 28.4.2R, with SYSC 28.4.1R
related
Record itself declares this is not a training duty.
n/a — record-keeping dutyThe firm must keep an up-to-date record of the continued professional training and development completed by each long-term insurance employee in each 12 month period, and must establish, maintain and keep appropriate records to demonstrate compliance with the chapter. It must provide any version of the record to the FCA on request, and give the FCA the name of the person responsible for the records on request.per 12-month periodRetained for a minimum of 3 years after the person stops carrying on the activity
SYSC 28.4.3R and SYSC 28.4.4R
related
Record itself declares this is not a training duty.
n/a — access dutyThe firm must not prevent a non-investment insurance employee, or a long-term insurance employee, from obtaining access to their own training records maintained under SYSC 28.4.1R, SYSC 28.4.2R, SYSC 3.2.20R or SYSC 9.1.1R.none specifiedn/a
SYSC 22.2 (Regulatory references)
SYSC 22.2.1R, SYSC 22.2.2R and SYSC 22.2.4R
related
Record itself declares this is not a training duty.
n/a — an evidence and disclosure duty supporting the fitness assessmentA firm must obtain a reference from the candidate's current employer and from anyone who employed them within the past 6 years, requesting the prescribed information and the SMCR questions in the Annex 1 template. A firm asked for a reference must disclose all information it is aware of that it reasonably considers relevant to the fitness and propriety assessment, covering the 6 years before the request, plus matters arising between request and reference, plus serious misconduct at any time. A firm must revise a reference it has already given if it becomes aware of matters that would have changed it — for up to 6 years after the person ceased employment.6-year look-back; revision duty runs for 6 years after the person leavesThe reference itself, in the prescribed form
FIT (The Fit and Proper test), Chapters 2.1 and 2.3
FIT 2.1.1G and FIT 2.1.3G; FIT 2.3.1G and FIT 2.3.2G
related
Record itself declares this is not a training duty.
n/a — assessment criteria rather than a training dutyHonesty, integrity and reputation (FIT 2.1): the FCA will have regard to all relevant matters, including thirteen categories at FIT 2.1.3G — criminal convictions including spent convictions, adverse civil findings, regulatory investigations and disciplinary proceedings, contraventions of regulatory or professional standards, complaints, association with refused or de-registered entities, insolvency involvement, dismissal or requested resignation from positions of trust, director disqualification, and candour in dealings with regulators. Financial soundness (FIT 2.3): outstanding judgment debts, arrangements with creditors, bankruptcy and bankruptcy restrictions. FIT 2.3.2G states the FCA will not normally require a statement of assets or liabilities and that limited means alone does not affect suitability.none specifiedThe assessment against these criteria

Where gaps commonly sit

The duty is in the Act, not the rulebook

The most demanding training duty in UK financial services is not in the Handbook at all. Section 64B of the Financial Services and Markets Act 2000 requires every authorised person to notify relevant persons of the conduct rules and to take all reasonable steps to secure that they understand how those rules apply to them — and the statute names the provision of suitable training as the particular step expected.

The standard is comprehension, not delivery. And since the conduct rules were extended, the population is very close to the whole firm.

A training matrix assembled from the Handbook alone will not contain it.

An annual cycle can conceal the duty

SYSC 27.2.15G is the sharpest instance. Where a certification employee moves into a function with different competence, qualification or training requirements, fitness must be assessed before they start it — and the provision says expressly that this is not done at the annual reassessment point.

So a firm running a clean, well-evidenced annual re-certification cycle can still be in breach for every internal move made between cycles. The provision carries a 24 April 2026 date stamp: it is among the newest text in this map.

Regulation 21 of the 2017 Regulations has the same shape from the other direction — screening of relevant employees is required both before the appointment is made and during the course of the appointment. The continuing limb has no interval and, in most firms, no owner.

Defined populations, and the numbers differ inside them

Three separate annual CPD figures apply to three overlapping populations. Retail investment advisers: 35 hours. Pension transfer specialists: 15 hours, with at least 5 from external independent providers. Long-term insurance personnel: 15 hours, under a different chapter with a different record-retention rule.

Standardise on one figure across advisory and insurance staff and you will satisfy some of these and breach others — and the breach is invisible on an aggregate completion report.

Two duties leave the payroll altogether. Regulation 24 covers any agents used for the purposes of the business. SYSC 18.3.7R requires the firm to ensure its appointed representatives and tied agents inform their own employees of the right to make a protected disclosure.

The record is the obligation, and it outlives the person

Three separate duties here require a record that survives the employment relationship.

SYSC 28.4.2R — the CPD record for long-term insurance employees, retained a minimum of three years after the person stops the activity. SYSC 22.2.4R — the duty to revise a regulatory reference already given, for up to six years after the person left. And TC 2.1.27R, which goes furthest of anything here: the firm's own record is expressly not enough, and an accredited body must independently verify qualification, CPD compliance and the annual declaration.

A learning system that deprovisions leavers breaches the first silently, because the record that would evidence the gap is the one that was deleted.

Coverage

This map states what it did not check as well as what it did. A map that quietly omits its own gaps is worth less than one that marks them.

Searched and found

34 obligations across 20 instruments, each read directly from the published source on 2026-08-10.

Searched and found nothing

Recorded because “we searched and found nothing” is a different fact from “we did not search”.

  • FCA Handbook PRIN 2A.1 and PRIN 2A.2 (Consumer Duty — application/purpose and cross-cutting obligations) — NO provisions relating to staff competence, training, culture, or ensuring staff act to deliver good outcomes were found in either section.
  • The Money Laundering — Training is NOT expressly named among the required policies, controls and procedures in regulation 19.
  • FCA Handbook — APER (Statements of Principle and Code of Practice for Approved Persons) — APER 2.1 is marked DELETED. The page carries a last-updated date of 31/03/2013 and no substantive principle text.
  • FCA Handbook — SYSC 15A (Operational resilience) — NO provisions imposing staff training or awareness obligations. The chapter covers important business services, impact tolerances, mapping, scenario testing, documentation, governance and communications. SYSC 15A.7.1R (31/03/2022) requires the governing body to approve and regularly review the written records, but mandates no training.
  • FCA Handbook — SYSC 27.2 — SYSC 27.2 contains NO Rules. Every provision examined is Guidance (G). The binding obligation sits in FSMA sections 63E(1) and 63F.
Not searched

Their absence is not evidence that they contain no training duty.

  • FCA finalised guidance on the Consumer Duty — the likely home of the staff-capability expectation
  • Regulation 24(3) of MLR 2017 read directly at legislation.gov.uk rather than via HMRC's manual
  • ESMA guidelines on knowledge and competence under MiFID II Article 25(1)
  • EU AMLD national transpositions for the non-UK pool
  • JMLSG Part I paragraphs 7.22-7.45 — training methods, delivery and monitoring (7.1-7.21 read)

Sources

All read 2026-08-10. Primary sources only — no summaries, no commentary.
Senior Management Arrangements, Systems and Controls (SYSC), Chapter 5.1
Training and Competence sourcebook (TC), Chapter 2.1
Money Laundering Regulations 2017
SYSC 27 (Senior managers and certification regime: Certification regime)
FIT (The Fit and Proper test for Employees and Senior Personnel), Chapter 1.3
Financial Services and Markets Act 2000
SYSC 18.3 (Whistleblowing)
SYSC 28 (Insurance distribution: training and competence)
SYSC 6.3 (Financial crime)
Money Laundering Regulations 2017
COND 2.5 (Threshold conditions: Suitability)
FIT 2.2 (Competence and capability)
SYSC 22.2 (Regulatory references)
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
COCON (Code of Conduct), Chapter 2
Directive 2014/65/EU on markets in financial instruments (MiFID II)
Financial Services and Markets Act 2000
Financial Services and Markets Act 2000
FIT (The Fit and Proper test), Chapters 2.1 and 2.3
Financial Crime Guide: A firm's guide to countering financial crime risks (FCG)
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as explained by HMRC's Economic Crime Supervision Handbook
JMLSG Guidance for the UK Financial Sector, Part I, Chapter 7 (Staff awareness, training and alertness)
APER (Statements of Principle and Code of Practice for Approved Persons), Chapter 4
EU AI Act (Reg (EU) 2024/1689)
Employment Rights Act 2025
Equality Act 2010
UK GDPR
EU AI Act (Reg (EU) 2024/1689)
The Regulatory Reform (Fire Safety) Order 2005
The Management of Health and Safety at Work Regulations 1999
Health and Safety at Work etc. Act 1974
Council Directive 89/391/EEC (the Framework Directive) on the introduction of measures to encourage improvements in the safety and health of workers at work

Thirty minutes, on your own material

Ten minutes on where your obligations actually sit. Fifteen watching a module built live from your own source documents. Five on whether there is a next step. Nothing to prepare and nothing to send beforehand.

Book a briefing