TL;DR
- A conduct risk taxonomy is a structured classification of the ways a firm’s behaviour can harm customers or damage market integrity, organised into categories and then into specific, named risk types.
- Mapping each category to a named FCA source, such as a Principle for Businesses or a Consumer Duty outcome, gives compliance teams a defensible link between what they monitor and what the regulator expects.
- Build it in four passes: draw categories from FCA sources, break each into observable risk types, write detection criteria for each type, then assign an owner and a review date.
- Keep it current by tracking FCA publications, running a fixed review cadence, and versioning every change so you can show when a category moved and why.
- The taxonomy earns its place when it feeds monitoring. In AI-assisted review, each risk type becomes a label a model is trained and evaluated against.
What is a conduct risk taxonomy?
A conduct risk taxonomy is a structured classification of the ways a firm’s behaviour can cause harm to customers or damage market integrity. It groups those risks into categories, then into specific risk types that staff and systems can recognise in day-to-day activity.
A single register listing dozens of risks in one column is hard to monitor and harder to report on. A taxonomy adds two things that flat list lacks. First, a hierarchy that rolls specific risks up into themes a board can review. Second, a shared vocabulary, so a complaint handler, a QA reviewer and a compliance officer all describe the same event the same way.
Typical top-level categories for a UK retail firm cover suitability of advice, clarity of communications, treatment of vulnerable customers, complaints handling, and price and value. Each one holds several named risk types underneath it.
How a conduct risk taxonomy maps to FCA principles
The FCA’s Principles for Businesses set the high-level obligations every category should trace back to. The Consumer Duty, in force since 31 July 2023, adds four outcomes that give conduct risk categories a sharper edge: products and services, price and value, consumer understanding, and consumer support.
Mapping each category to a specific reference is what makes the taxonomy defensible. When an auditor asks why a category exists, the answer is a rule number, not an opinion.
| Conduct risk category | Relevant FCA reference | What good looks like | Example risk type |
|---|---|---|---|
| Suitability of advice | Principle 9; Consumer Duty products and services outcome | Advice matches the customer’s circumstances and objectives | Recommendation sits outside the customer’s stated risk profile |
| Clarity of communications | Principle 7; Consumer Duty consumer understanding outcome | The customer understands the product before deciding | A material cost or risk is left out of an explanation |
| Treatment of vulnerable customers | FG21/1; Consumer Duty consumer support outcome | Vulnerable customers get outcomes as good as other customers | A disclosed vulnerability is recorded but not acted on |
| Complaints handling | DISP sourcebook; Principle 6 | Complaints are recognised and resolved fairly and on time | An expression of dissatisfaction is not logged as a complaint |
| Price and value | Consumer Duty price and value outcome | Price is reasonable relative to the benefit delivered | Fees are not justified by the service the customer receives |
Confirm the current rule references against the live FCA Handbook before you publish your own version, since the FCA amends principles and sourcebooks over time.
How to build a conduct risk taxonomy in four steps
1. Draw categories from FCA sources
Start with the obligations that create a duty to the customer. Work through PRIN, the four Consumer Duty outcomes, DISP, and the sector sourcebooks that apply to your permissions, such as COBS for investments, MCOB for mortgages, or ICOBS for insurance. Each obligation that protects a customer becomes a candidate category.
2. Break each category into observable risk types
A category such as clarity of communications is too broad to monitor. Split it into events someone could point to in a call recording or a letter: a cost not disclosed, a benefit overstated, jargon left unexplained. A risk type should describe a single thing that either happened or did not.
3. Write detection criteria for each risk type
For every risk type, write down the evidence that signals it. This is the step that turns the taxonomy from a document into something you can test against real cases. Detection criteria also settle disputes between reviewers, because two people scoring the same call now apply the same written test.
4. Assign an owner and a review date
Give every category a named owner and a date it is next reviewed. Unowned categories are the first to go stale, and a taxonomy nobody maintains stops matching the rulebook within a year.
How to keep a conduct risk taxonomy current with FCA guidance
The FCA publishes material that changes what firms must watch for. Track four sources in particular: policy statements and finalised guidance, Dear CEO and portfolio letters, and enforcement notices. Any one of these can add a risk type or redefine an existing one.
Run the review on a fixed cadence rather than in response to individual events. A short quarterly check confirms nothing has changed; a full annual review reworks definitions and retires risk types that no longer apply. Name who attends each review so the meeting actually happens.
Version every change. Record what changed, the FCA source that prompted it, the date, and who approved it. When a regulator or an internal auditor asks why a category reads the way it does, the version history answers in one line.
“A taxonomy is only useful if it tracks what the regulator cares about this quarter, not what it cared about two years ago. We tie every risk type back to a specific FCA source and re-check it on a fixed schedule, so when the guidance moves, the labels our models are trained on move with it.”
— Nicole Nisbett, Technical Product Manager, Models Team, Aveni
Where a conduct risk taxonomy fits in AI-assisted compliance monitoring
Detection criteria are what let a taxonomy drive automated review. Each risk type becomes a label. A model reads a call transcript or an advice document and flags the risk types it finds, applying the same written criteria a human reviewer would use.
This matters because manual sampling reaches a small proportion of cases. A model trained against the taxonomy can review a far higher share, and it applies the definitions consistently across every case. The taxonomy defines the risks; the model applies them at a scale manual review cannot match.
Aveni’s compliance monitoring product, Detect, works this way. Its risk models are built from gold-standard labels created by subject matter experts and refined with engineers, then evaluated against held-out cases before anything reaches production. See how Detect scores conduct risk and the Detect product page for where it sits in a monitoring workflow.
Common mistakes when building a conduct risk taxonomy
- Categories that mirror the org chart. A taxonomy built around departments misses risks that cross teams, such as a vulnerability flagged in a sales call and then overlooked at the complaint stage.
- Risk types too broad to detect. If you cannot write a detection criterion for something, treat it as a theme and break it down further until you can.
- No named owner. A category with no owner drifts out of line with the rulebook and nobody notices until an audit.
- Copying another firm’s taxonomy wholesale. FCA obligations apply to your permissions and products. A mortgage lender and a discretionary wealth manager carry different conduct risks, so a borrowed taxonomy will list risks you do not run and miss ones you do.
- Keeping it as a compliance document only. When the taxonomy stops matching the labels used in monitoring, the two drift apart and your reporting stops reconciling.
FAQ
What is the difference between a conduct risk taxonomy and a risk register?
A risk register lists risks, usually with a score and an owner. A conduct risk taxonomy adds structure on top: it groups risks into categories, defines each risk type precisely, and maps every one to an FCA source. A register tells you a risk exists; a taxonomy tells you how to recognise it and where the obligation comes from.
How many categories should a conduct risk taxonomy have?
Most UK retail firms land on five to ten top-level categories, each holding several risk types. Fewer than five usually means categories are too broad to monitor. More than ten often means themes have been split when they could sit together. Let the FCA obligations that apply to your permissions set the number.
Which FCA rules should a conduct risk taxonomy cover?
Start with the Principles for Businesses and the four Consumer Duty outcomes, then add the sourcebooks tied to your permissions, such as COBS, MCOB, ICOBS, and DISP for complaints. Firms serving vulnerable customers should also map to FG21/1.
How often should a conduct risk taxonomy be reviewed?
Run a short quarterly check to confirm nothing has changed, and a full annual review to rework definitions and retire outdated risk types. Review sooner if the FCA publishes a policy statement or Dear CEO letter that affects your permissions.
Can a conduct risk taxonomy be used to train AI models?
Yes. Each risk type with a written detection criterion becomes a label. Subject matter experts apply those labels to real cases to create a gold-standard dataset, which a model is then trained and evaluated against. This is the approach behind Detect.
Conclusion
A conduct risk taxonomy connects the FCA rulebook to the cases your team reviews every day. Build it from named FCA sources, write a detection criterion for every risk type, give each category an owner, and version every change. Once the definitions are firm, the same taxonomy can drive automated monitoring at a scale manual sampling cannot reach.
To see a defined taxonomy applied to live conduct monitoring, read how Detect scores conduct risk or book a walkthrough of Detect.