Regulatory Compliance · Article
Securing a conduct licence is a project with a clear end. Running the programme behind it is not. New Zealand’s CoFI regime has shown how easily the handover from build to business as usual can be underestimated.
|
Disclaimer This article is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding’s own and do not represent any employer or client organisation. |
Most organisations spend the visible effort on a major conduct regime before the licence is granted. The programme is designed, documented, tested against the regulator’s expectations and submitted. A team is assembled, a deadline is set, and the work takes the shape every project takes: a beginning, a middle and an end.
The licence is that end. And it is the point at which the actual work begins.
New Zealand’s Conduct of Financial Institutions regime has taken the whole sector through this. Banks, insurers and non-bank deposit takers have had to build fair conduct programmes, secure their licences, and operate them for as long as they remain in business. The build had an end date. The operation does not.
Between those two phases sits a step that rarely gets the attention it deserves: the handover. The programme has to pass from the people who built it to the people who will run it, and then be monitored for the rest of its life. This article is about that handover and the monitoring that follows. It uses CoFI as the worked example because it shows the transition from build to business as usual clearly, but the pattern is not specific to New Zealand or to conduct. It applies wherever an organisation builds something to satisfy a regulator and then has to live with it.
CoFI in one paragraph
The Conduct of Financial Institutions regime was introduced by the Financial Markets (Conduct of Institutions) Amendment Act 2022, which inserted a new Subpart 6A into Part 6 of the Financial Markets Conduct Act 2013. At its centre is the fair conduct principle: a financial institution must treat consumers fairly. Subpart 6A places a duty on every financial institution to establish, implement and maintain an effective fair conduct programme, with section 446J of the Act setting out the programme’s minimum requirements. That programme consists of policies, processes, systems and controls designed to ensure compliance with the fair conduct principle. The Financial Markets Authority licenses, monitors and enforces the regime.
Why the handover is the weak point
A conduct programme is built by a project team. That team is, by design, temporary. It is assembled for the build, funded for the build, and, once the licence is secured, disbanded, with its people returned to their previous roles or moved to the next priority. This is normal and not a criticism. It is how organisations resource major pieces of work.
But it means the programme has to change hands. The people who designed it are not the people who will operate it. And the moment of transfer is rarely treated as the significant event it is. It is treated as administrative: the documents are moved to a repository, the owner field is updated in the system, a closure report is signed, and the project is declared complete.
What that treatment misses is that a programme is not only its documents. It is also the understanding behind them. The build team knows why a particular control was designed the way it was, which risk a particular process was meant to address, what was considered and rejected, where the known weak spots are, and which parts of the programme are robust and which are held together with goodwill. None of that is in the policy document. All of it matters to whoever now has to run the programme.
When the handover is treated as administrative, that understanding is not transferred. It leaves with the project team. What the operational owners inherit is a set of artefacts whose internal logic they cannot fully reconstruct. They can follow the programme. They cannot readily improve it, adapt it, or judge when a proposed change would quietly break it. The programme becomes harder to maintain on the day it is handed over, and nobody notices because it still works on that day.
What a real handover involves
Treating the handover as a genuine piece of work, rather than a closing formality, requires a small number of deliberate actions.
An overlap period. In practice, the operational owners should be running the programme while the build team is still available to answer questions. Not a briefing session, but a period of weeks during which the people who will own the programme operate it and can turn to those who built it when something is unclear. A handover that happens on a single day is not a handover. It is a document transfer.
The reasoning is written down, not just the programme. The artefacts record what the programme is. The handover also needs to record why. Why each significant control exists, what it is meant to catch, what was considered and not done, and where the build team knows the programme is weaker than anyone would like. This is uncomfortable to write because it commits the known weaknesses to paper. It is also the single most useful thing the build team can leave behind.
Named owners who can be asked. Every significant part of the programme needs an operational owner who could be asked today what it is for and whether it is working, and who could answer without assembling a working group. Ownership that sits with a committee or a function in the abstract is ownership that no individual actually holds. A programme owned by everyone is monitored by no one.
The monitoring mechanism is already running before the build team leaves. The way the programme will be checked on an ongoing basis should be operational and have produced its first results by the time the build team is still in place. If the first real test of the programme happens months after the people who built it have gone, the organisation has lost the only group that could quickly diagnose and fix what that test finds.
The monitoring that has to follow
A conduct programme cannot be set running and left. Not because regulators say so, though they do, but because the organisation around the programme does not stand still. Products are launched and withdrawn. Distribution channels change. Fee structures are revised. Teams are restructured. Systems are replaced. Each of these changes is managed by people focused on the change itself, not on the conduct programme, and each one moves the business a small distance away from the programme that was written to describe it.
Monitoring is what catches that drift. And useful monitoring has a particular quality: it is built into the programme’s ordinary operation, not bolted on as a periodic exercise.
There is a real difference between the two. A programme monitored by a special annual review produces a verdict once a year, at a moment chosen by the calendar rather than for any operational reason. It is assembled by people pulling information together specifically to answer the question. A programme monitored continually produces evidence of how it is working as a by-product of running. Complaint data is already telling a story. Breach identification and the speed of response are already being tracked. The programme’s own assurance findings already exist. When someone asks whether the programme is working, the answer is assembled from data the organisation was already capturing.
The second kind of monitoring is more honest, because it is harder to stage. An annual review can be prepared. A continual signal is what it is. It is also more useful, because it surfaces problems close to when they arise, while they are still small and while the people who can fix them are still in post.
The questions worth asking of a conduct programme are not complicated. When the business last changed something material, was the programme revisited, or did it simply fall a little further out of date? When a pattern in complaints suggested something was wrong, did it change anything, or was it logged? When the programme’s own assurance found a gap, was the gap closed, or was the finding recorded and the programme left as it was? These are not framework questions. They are the questions that reveal whether a programme is being monitored or merely being kept.
Supervision asks a different question from licensing
Licensing and supervision are not the same activity, and they do not ask the same question. Licensing asks whether the programme is credible: whether it is well designed, complete and plausible. Supervision, which is where a regulator’s attention goes once a sector is licensed, asks whether the programme is working: whether it is shaping decisions, catching problems and keeping pace with the business.
An organisation that has answered the first question well does not automatically have an answer to the second. The programme that satisfied the licensing assessment was, reasonably enough, built to satisfy that assessment. Unless it was deliberately handed over and is being genuinely monitored, the honest answer to the supervisory question may be that nobody quite knows whether it is working, because nobody has been positioned to tell.
An organisation that treats the handover as real and builds monitoring into ordinary operations should find the supervisory conversation more straightforward. Not because it has prepared for that conversation, but because the evidence a supervisor wants is the evidence the programme generates anyway. That is the practical pay-off of doing the unglamorous part well.
The cost, and where it sits
A proper handover and a real monitoring mechanism cost something. An overlap period means the build team is retained a little longer. Writing down the reasoning takes time. Establishing monitoring before the build team leaves brings forward work that is easy to defer. It is genuinely tempting, on the day a licence is granted, to declare the project complete, release the team and bank the saving.
But the cost of doing the handover well is a small cost set against the cost of the build, and very small set against the cost of discovering, two or three years later, that the programme has drifted, that nobody can explain why it was built as it was, and that the organisation has to reconstruct an understanding it once had and gave away. The expensive path is not the overlap period. The expensive path is the silent reconstruction project that a poor handover makes inevitable.
Final thought
Securing a conduct licence is a real achievement and hard work. But it is the visible part, the part with a deadline and a team and a moment of completion. The part that determines whether the programme actually protects customers is the part with no deadline at all: the handover into operational ownership and the steady, unglamorous monitoring that has to follow for as long as the organisation holds the licence.
CoFI has put this in front of an entire sector at once. The institutions that come through it well will not necessarily be the ones that built the most polished programme. They will be the ones that treated the day after the licence as part of the licence work, not the day after it ended.