From 1 September 2026, the FCA’s non-financial misconduct rule (COCON 1.1.7FR) comes into force for around 37,000 non-bank firms.
The system of record for conduct & stress risk · FCA-regulated firms

When It’s Tested, Show What You Did to Stay Sighted, Don’t Argue It.

You have a policy and a survey, and nothing in between. EEmber turns a 60-second staff check-in into a weekly read on the conditions your people work under, a fix with a named owner, and a dated reasonable-steps trail that protects the senior manager personally, ready before 1 September 2026.

Aggregated, never the individual UK GDPR, UK hosted Supports reasonable-steps evidence
STEP 1
Over the last few days, how much has caseload pressure built up on you?
0123456
Staff check in
60 seconds, anonymous, no app
STEP 2
46AMBER
Top driver Demands · ▲ +6 · worsening
You see the driver
Know which team is straining this week
STEP 3
  • Caseload cap & reallocation
  • One logged escalation channel
  • Protected review blocks
You act on it
A proportionate step, owned and dated
STEP 4
  • Caseload cap · Demands
  • Escalation channel · Support
  • Review blocks · Control
You can prove it
Dated, mapped to the standard, retrievable
↓59%
lower average risk in one deployment
238
anonymous check-ins captured
1 page
the reasonable-steps file, ready when asked
From the people who ran it

The same weekly loop, in their words.

From EEmber’s first deployments in further education. The loop is identical in a regulated firm, a 60-second check-in, a named driver, an owned action, a dated record.

“EEmber gave us a simple weekly way to spot early pressure signals and act on them. It moved us from assumptions to clear decisions, daily stabilisers and visible changes, without becoming a tick-box wellbeing exercise. The main benefit was greater stability. It showed where change and workload pressures were building, and its daily controls helped protect ‘winnable days’ for staff.”
Carl D.
Carl D.
Department Lead, Bishop Auckland College
“I found the controls were simple and effective and did not add further stress to my days. The pilot helped me to spot operational drift early and put simple controls in place so days were easier to navigate, especially when tasks pile on top of each other unexpectedly.”
Nathan D.
Nathan D.
Management Course Leader, College of Esports
What the gap is already exposing you to

A policy on the intranet is not sight of your culture. When it’s tested, the gap is personal.

The annual survey tells you a number about last year. It never tells you what you did about it, or when. In a regulated firm that gap does not sit on the company, it sits on a named senior manager, and it is live now.

~37,000non-bank firms brought into non-financial-misconduct scope by COCON 1.1.7FR from 1 September 2026FCA
Personalthe Duty of Responsibility (FSMA s.66A) puts reasonable steps on the named SMF, not just the firmSM&CR
£80k+the PRA fined TSB’s former CIO personally in 2023 for failing to take reasonable steps in his areaPRA enforcement
Uncappedfrom January 2027 the cap on unfair-dismissal payouts is removed, and work-related stress can count as a disability with no formal diagnosisEmployment Rights Act
“Reasonable steps” is evidenced by contemporaneous records: what you saw, what you did, and when. With no dated trail, there is little to show you did anything at all.
Why now

A policy on the intranet is not oversight. The FCA has said it will look behind the wording.

Three deadlines turn conduct and stress risk from an HR topic into a personal-liability exposure with a named senior manager attached.

The non-financial misconduct rule lands

COCON 1.1.7FR brings bullying, harassment and violence into conduct-rule scope for around 37,000 non-bank firms. The FCA has rejected a tick-box approach and will look behind your policies at what happens on the ground. A dignity-at-work policy on its own is no longer the answer.

It is personal now

Under the Duty of Responsibility (FSMA s.66A) and Senior Manager Conduct Rule 2, a named senior manager is personally accountable for reasonable steps in their area. In 2023 the PRA fined TSB’s former CIO over £80,000 for failing to take them.

Payouts become uncapped

The Employment Rights Act removes the limit on unfair-dismissal payouts. Work-related stress can count as a disability with no formal diagnosis. One prevented senior exit is a five-to-six-figure event; an uncapped claim has no ceiling at all.

“Reasonable steps” is deliberately undefined, and it is evidenced by contemporaneous records: what you saw, what you did, and when. Underneath the FCA layer sits the employer duty itself, HSWA s.2 for mental health, MHSWR Reg 3 for a documented stress risk assessment, and in December 2025 the HSE served a formal notice on a major employer purely for failing to manage work-related stress. With no dated trail, there is little to show you did anything at all. FSMA s.66A · COCON · HSWA 1974 · MHSWR 1999 · HSE enforcement, December 2025
The dated reasonable-steps trail, mapped to the standard, retrievable on demand
The reasonable-steps trail · dated and mapped · retrievable in 60 seconds
The problem with the current playbook

The survey told you morale was fine. It never told you what you did about it, or when.

A policy signed at onboarding, a survey once a year, a score that lands and connects to nothing. When a grievance or a resignation surfaces the gap, your reasonable-steps answer is a folder, not a live record. A policy is not sight of your culture. When it’s tested, the dated proof you acted is.

Policy + annual survey
  • A number from last year, months stale before it is read
  • No driver named, so nobody acts on the real condition
  • No owner, no dated action, nothing between policy and incident
  • When it’s tested, the answer is “nobody told me”, not a record
A weekly system of record
  • A leading read, every week, on the conditions per team
  • The exact driver named: demands, control, support, relationships, role
  • A proportionate step with a named owner and a date
  • Every signal recorded next to the action taken, timestamped
Benefit 01 · you stop relying on being told

You stop finding out from the grievance.

The desk quietly running too hot, you see the conditions building weeks before they become a complaint or a senior exit, while there is still time to act and to be seen acting. No more relying on nobody having told you, when the duty to have known is yours personally.

The weekly conduct-and-stress view, one team flagged early
The weekly view · one team flagged early · sample data
Benefit 02 · the record defends you, it does not expose you

The record is a defence, not a weapon.

The fear is that documenting known pressure hands a claimant proof you knew. EEmber is built so that a signal is never recorded on its own, it is always logged next to the proportionate action, the named owner and the date. That is the exact shape of a reasonable-steps defence: not “we spotted a risk and sat on it”, but “we saw it, we acted, and here is when”. Invite your own counsel to read it, that is what it is built for.

Every signal shown next to the action taken, the owner and the date
Every signal, next to the action, owner and date · sample data
Benefit 03 · you show it, you do not argue it

When it’s tested, you show what you did, not what you meant to.

When the FCA, your board or a tribunal asks what you did to stay sighted, you do not reach for a policy and hope. You open one page and show what you saw, what you did, who owned it and when, dated, mapped to the standard, exportable in under fifteen minutes. You become the senior manager who was visibly watching, not the one relying on nobody having told them.

The reasonable-steps file, dated and mapped to the standard
The reasonable-steps file · exportable in under 15 minutes · sample data
Benefit 04 · a managed loop, not a tool you operate

Your compliance team builds nothing.

This is a managed loop we run, not a tool you operate. We run the check-ins, model the score, name the driver, assign the owners, chase completion and build the record. Your entire lift is one 45-minute setup call. You review one board-and-regulator-ready page; we run everything behind it, and it never becomes another thing on your plate.

The board-and-regulator-ready rollup you review, not operate
The board-and-regulator-ready page you review · sample data
Benefit 05 · nothing counts until it is proven

You can stand behind every Green, because a control on paper counts as zero.

Most systems let a tick mark stand as done. EEmber will not. A control on paper is not reasonable-steps; the dated proof it ran is. The board never shows Green until that proof exists, and the champion verifies the proof is real before anything reaches the log. So the Green you take to your board, or the FCA, is earned, not claimed.

A control on paper isn’t reasonable-steps. The dated proof it ran is.

And the same dated record answers every audience the senior manager is defended in front of. In a firm this size the SMF is the buyer, the owner and the liable person at once, one doorway, not three, so the one verified trail is read three ways: the regulator register, the board register, the staff register. The proof is verified before it reaches you, so you present it, you don’t assemble it.

The reasonable-steps file for the regulator
The regulator register
When the FCA asks what you did to stay sighted, you show it, dated and mapped.
The board-ready assurance page
The board register
Assurance that culture risk is watched and evidenced, not hoped away.
The weekly read that staff see acted on
The staff register
People answer honestly because they have seen the check-in lead to a real response.
How it works, end to end

Four steps to a dated record. You review one page; we run the other three.

No black box, no analysis on your side. Watch a 60-second check-in become a retrievable record you can put in front of the FCA, your board or a tribunal.

STEP 1
Over the last few days, how much has caseload pressure built up on you?
0123456
Staff check in
60 seconds, anonymous, no app
STEP 2
46AMBER
Top driver Demands · ▲ +6 · worsening
You see the driver
The band, the cause, the direction
STEP 3
  • Locked daily brief by 08:30
  • One change channel, logged
  • Protected cover for breaks
You act on it
A proportionate fix, owned and dated
STEP 4
  • Caseload cap · Demands
  • Escalation channel · Support
  • Review blocks · Control
You can prove it
Dated, mapped to the standard, retrievable
↓59%
lower average risk in one deployment
1 page
the dated record, ready when asked

And when a daily fix is not enough, the same driver recurring for a month escalates to a logged decision, with an owner and a review date, while every action is benchmarked against a 4-week baseline. So your best defence is never “we fixed everything”, it’s a dated record showing you saw a structural problem you couldn’t fix alone, raised it, and named an owner. The chronic issues can’t quietly slip; they’re logged and escalated, which is exactly what reasonable steps looks like.

60sanonymous, so people answer straight and you get honest signal
No appa link or QR, high take-up, nothing to maintain
Teamaggregated, never the individual, clear of the misconduct line
1 callto set up, then the loop runs off your plate
The proof it moves, not just measures

Two struggling teams. One deployment. The needle actually moved.

EEmber’s first deployments ran in further education; the loop is identical in a regulated firm. Two teams sat in a Yellow and Orange mix, the kind of sustained pressure that turns into grievances and senior exits if nothing changes.

↓59%drop in average risk score in one term (37.9 → 15.4)
↓65%drop in the peak risk spike (53.0 → 18.5)
238anonymous check-ins captured
48weekly governance packs delivered
The number that changed the conversation was not the risk score. Leadership assumed the pressure was workload. The read showed the top driver was lack of control. A headcount budget would have moved nothing. That is the difference between a survey that scores the problem and a loop that names the driver, and records the step you took.
From EEmber’s first deployments in further education; the loop is identical in a regulated firm. As a founding finance partner you shape the deployment, not inherit someone else’s. Results vary by setting.
Where EEmber sits

Not another survey that scores the problem. The weekly loop that names the driver and proves you acted.

Everything else tells you how staff felt months ago, or holds a policy on a shelf. Only one corner sees the driver early and leaves the dated reasonable-steps proof behind.

  EEmber Annual staff survey Policy + EAP Doing nothing
A leading read (sees it building)
Names the specific driver Score only
A proportionate action, owned and dated Static
Dated reasonable-steps proof, mapped to the standard On paper
Effort on you One 45-min call Admin every round Sits on a shelf None, until it is too late
Before you ask

The questions a senior manager asks first.

Doesn’t documenting known pressure just hand a claimant proof we knew?

It is built to do the opposite. A signal is never recorded on its own, it is always logged next to the proportionate action, the named owner and the date. That is the exact shape of a reasonable-steps defence: not “we saw a risk and sat on it”, but “we saw it, we acted, and here is when”. Invite your own counsel to read a sample, that is what it is built for. Check-in is aggregated and anonymous, held in the UK under UK GDPR, with a DPA signed before anything is collected.

We have a dignity-at-work policy and an EAP. Isn’t that enough for COCON?

The FCA has said it will look behind the policy at what actually happens, and rejected a tick-box approach. A policy on the intranet shows intent; it does not show you were sighted or that you acted. EEmber adds the layer both a survey and an EAP miss: a weekly leading read, a named step, and the dated trail that evidences reasonable steps. It sits on top of what you have, not in place of it.

What is the lift on our compliance team?

One 45-minute setup call. After that, staff tap a link for 60 seconds a day and we run everything, the check-ins, the modelling, the packs and the reasonable-steps log. This is a managed loop we run, not a GRC tool your team has to configure and feed. No platform to learn, no IT project, nothing to maintain.

Is EEmber investigating misconduct or making conduct findings?

No, and this line is deliberate. EEmber senses the conditions people work under and evidences that you acted on them. It does not investigate individuals, make conduct findings, or discharge your SM&CR or COCON duty, those remain yours. It is the sighting-and-evidence layer underneath your obligations, not a replacement for them.

Try it free for a month

Start with a private read on your exposure. Keep the standing layer only if it works.

Private, 7 days

The 7-Day Defensibility Audit

Free

A private read on where your reasonable-steps evidence would stand if the FCA asked tomorrow. Scoped to your firm, no obligation, no exposure to your staff.

  • Where your proof would stand today against COCON and the Duty of Responsibility
  • A self-assessment against the six psychosocial conditions
  • A self-demo check-in shown on the real tracker and reasonable-steps log
Get the audit
Your first month, on us

Your First Month, Free

£0 · fully managed · no card, no commitment

The full loop, run for you on the teams you choose. Four weekly governance packs, the reasonable-steps log built, the decision register live, at no cost for the first month.

  • Daily anonymous check-ins across your chosen desks
  • Four weekly governance packs with named owners and dated actions
  • Timestamped reasonable-steps log, mapped to the standard, exportable on demand
  • Board-and-regulator-ready pack at the end of the month
Start your free first month
No card, no commitment. If the first weekly pack is not governance-usable, walk away, the evidence you have built stays yours. We guarantee the record we deliver, never a change in the score, which depends on the actions you choose to run.
A culture consultant gives you one audit for £8,000–15,000 and walks away, stale the week they leave. The reasonable-steps log does that continuously, live, week after week. When your free month has proven it, you continue into the standing governance layer, fully managed, priced by the size of your firm, not per head, because a smaller firm is no less exposed than a larger one.
10–20 people
£3,000/mo
the full reasonable-steps loop
20–35 people
£5,000/mo
multi-desk, aggregated
35–50 people
£8,000+/mo
multi-function, board rollup
We onboard three new firms a month. Every pack is hand-delivered, assembled personally, not spun up by software, so we cap new starts to protect that standard. As a founding finance partner you shape the deployment; when the month’s three are taken, the next start is the following month.

One honest note. If you want a wellbeing badge for the intranet, EEmber is not it, and we will tell you so on the call. If you want the reasonable-steps record that stands up when the FCA, your board or a tribunal asks what you did, this is exactly it. Cancel any time; the evidence you have built stays yours.

See it. Act on it. Prove it.

The question is coming. Be the one who was watching, not the cautionary tale.

You have the policy and the survey and still could not show what you did to stay sighted, or when. COCON lands on 1 September 2026, the duty is personal, and whether a grievance or a claim surfaces is outside your control. The gap is not the policy. It is the dated proof, and it is the difference between showing what you did and relying on nobody having told you.

EEmber · eember.co.uk Twinio Ltd · Company No. 16701569 · VAT No. 503461328 EEmber’s welfare score is an operational decision-support index built on established burnout-inventory methodology and the six HSE Management Standards psychosocial conditions, combined through documented, calibrated weights. It is designed for governance decisions and management action, not clinical diagnosis. EEmber senses culture and conditions and supports a timestamped, reasonable-steps evidence record; it does not investigate individuals, make conduct findings, or by itself discharge any SM&CR or COCON duty or make any firm compliant with any rule. Deployment figures are from EEmber’s first deployments in further education; the loop is identical in a regulated firm and results vary by setting. Interface shown is illustrative with sample data.