Share on Social Media
Compliance training in financial services: where HR holds the licence to operate
Financial services organisations operate under unprecedented regulatory pressure. The Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) in the UK, the Malta Financial Services Authority (MFSA), the European Banking Authority (EBA), ESMA, EIOPA, the ECB through the Single Supervisory Mechanism for significant banks, and now the Anti-Money Laundering Authority (AMLA) in Frankfurt are all increasing scrutiny, enforcement and expectations around internal controls and individual accountability.
This is no longer confined to compliance departments. The Senior Managers and Certification Regime (SMCR) in the UK and the MFSA's fit and proper framework in Malta put named individuals on the hook for the conduct of the people they supervise.
HR leaders are now directly accountable for making sure employees are trained, aware and capable of operating within regulatory frameworks at all times.
The real question is not whether compliance training exists. It is whether that training is effective enough to prevent failure and stand up under regulatory inspection.
Why financial services compliance training needs a different approach
Financial services organisations carry a unique combination of risk:
- Sensitive customer and transactional data
- High transaction volumes across multiple products and jurisdictions
- Cross-border operations with multiple regulators in scope at the same time
- Constant regulatory updates, with the EU framework still mid-overhaul
- Personal accountability for senior managers and certified individuals
In this environment, a single compliance failure can escalate quickly into regulatory action, financial penalties, individual fitness-and-propriety challenges and reputational damage that follows the firm and the individual for years.
Traditional training approaches (annual modules, generic theory, completion-rate KPIs) are no longer sufficient. Regulators now expect evidence of real understanding and behavioural application, not just a training log.
The compliance areas HR cannot leave to chance
1. Anti-money laundering, counter-terrorist financing and sanctions
AML, CTF and sanctions remain the most heavily enforced areas in financial services, with some of the largest regulatory fines globally landing in this space.
In the UK, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017), the Proceeds of Crime Act 2002 (POCA), the Terrorism Act 2000 and the Sanctions and Anti-Money Laundering Act 2018 all apply. The FCA supervises AML for the firms it authorises. OFSI (Office of Financial Sanctions Implementation) enforces financial sanctions, with significant penalty powers post-Russia sanctions expansion.
In Malta, the Prevention of Money Laundering Act (Chapter 373), the Prevention of Money Laundering and Funding of Terrorism Regulations (PMLFTR), and the FIAU Implementing Procedures Part I (subject persons) and Part II (sector-specific for banking, investment services, payments, insurance) apply, with the FIAU as supervisor and the MFSA as prudential regulator.
Across the EU, the new AML Regulation (Regulation (EU) 2024/1624) and the 6th AML Directive (Directive (EU) 2024/1640) set a single rulebook from 2027, with AMLA in Frankfurt directly supervising the highest-risk cross-border firms.
Employees should be trained on customer due diligence and enhanced due diligence, source of funds and source of wealth, PEP and sanctions screening, ongoing monitoring, suspicious activity reporting (SARs to the NCA in the UK, STRs to the FIAU in Malta), the failure-to-prevent offences, and the personal liability of the MLRO. The patterns track adjacent regulated sectors. Our guide on compliance training in iGaming covers parallel issues.
Failure here has led to some of the largest regulatory fines globally and to MLROs losing their personal approval to act.
2. Data protection, operational resilience and DORA
Financial institutions manage large volumes of highly sensitive personal and transactional data, and the regulatory framework treats both data and operational resilience as core prudential issues now.
In the UK, UK GDPR and the Data Protection Act 2018 apply, with the ICO as regulator. The FCA's operational resilience policy statement (PS21/3) and the joint Bank of England, PRA and FCA framework on critical third parties extend the operational resilience perimeter. The Network and Information Systems Regulations 2018 apply to operators of essential services in the relevant FMI space.
In Malta, the Data Protection Act (Chapter 586) sits alongside EU GDPR with the IDPC as regulator.
Across the EU, the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) has applied since 17 January 2025, requiring financial entities to implement ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk management and information sharing. NIS2 (Directive (EU) 2022/2555) is in force in Malta and applies to in-scope financial market infrastructures. The EU AI Act (Regulation (EU) 2024/1689) is staged in, with high-risk AI obligations relevant to credit-decisioning and insurance pricing landing through 2026.
Employees should be trained on secure data handling, access control, the 72-hour personal data breach notification timeline, the DORA major ICT incident reporting timelines, and the role of the second and third lines of defence. A data breach is no longer just a legal issue. It is a trust issue with the regulator, the client and the market.
3. Conduct risk, Consumer Duty and ethical behaviour
Misconduct continues to be a major regulatory concern, and the bar has risen significantly in the last three years.
In the UK, the Senior Managers and Certification Regime (SMCR) applies to FCA and PRA-authorised firms, with the Senior Managers Regime, Certification Regime and Conduct Rules (Individual Conduct Rules and Senior Manager Conduct Rules) sitting across the workforce. The FCA Consumer Duty (Principle 12), in force for new and existing products since 31 July 2023 and for closed products since 31 July 2024, requires firms to deliver good outcomes for retail customers across products and services, price and value, consumer understanding, and consumer support. The FCA Principles for Businesses (PRIN), Conduct of Business Sourcebook (COBS), MCOB, ICOBS, and SYSC all apply.
In Malta, the MFSA Conduct of Business Rulebook, the Investment Services Act (Chapter 370), the Banking Act (Chapter 371), the Insurance Business Act (Chapter 403) and the Insurance Distribution Act (Chapter 487) set the conduct framework, with the MFSA's fit and proper test running across senior individuals.
Across the EU, MiFID II / MiFIR, the Insurance Distribution Directive (IDD), Solvency II, CRR3/CRD VI for banks, the AIFMD and UCITS frameworks set product, conduct and prudential rules.
Training should address conflicts of interest, mis-selling risks, the Consumer Duty in practice (not just in policy), internal ethics, whistleblowing protections under the Public Interest Disclosure Act 1998 and the Maltese Whistleblower Act, the Conduct Rules for in-scope individuals, and the SMCR conduct rule breach notification process. Culture is now part of formal regulatory review under the FCA's culture framework and the MFSA supervisory work.
4. Market abuse, conflicts of interest and personal account dealing
For investment firms, banks with trading activities and asset managers, market abuse exposure is constant.
The UK Market Abuse Regulation (UK MAR) and the Criminal Justice Act 1993 (insider dealing) apply, supported by the FCA Code of Market Conduct. In Malta and across the EU, the Market Abuse Regulation (Regulation (EU) 596/2014) and CSMAD (Directive 2014/57/EU) apply, with the MFSA enforcing through its Conduct Supervision function.
Employees in scope should be trained on insider information identification, the disclosure framework, the disclosure of inside information by issuers, market manipulation indicators, personal account dealing rules, gifts and hospitality policies, and conflicts of interest management.
5. Financial crime awareness, fraud and APP fraud
Financial crime sits across multiple business lines, and the perimeter keeps widening.
Authorised Push Payment (APP) fraud reimbursement under the new PSR (Payment Systems Regulator) mandatory reimbursement rules came into effect on 7 October 2024, putting payment service providers in scope. The Failure to Prevent Fraud offence under the Economic Crime and Corporate Transparency Act 2023 is in force from 1 September 2025, requiring "reasonable fraud prevention procedures" for large organisations.
Across the EU, the proposed Payment Services Directive 3 (PSD3) and Payment Services Regulation (PSR) will extend fraud-related obligations further.
Employees across all departments, not just compliance, should recognise fraud indicators, understand transaction monitoring escalation, know the reporting obligations to the NCA, FIAU and internal Money Laundering Reporting Officer, and operate inside controls designed to evidence "reasonable procedures" under the Failure to Prevent Fraud offence.
The real cost of non-compliance
Fines make the headlines. The broader impact is what damages the franchise:
- FCA, PRA, MFSA, FIAU or ECB regulatory fines and enforcement notices
- Section 166 skilled person reviews in the UK that consume management time and money for months
- Loss of client confidence, particularly with corporate, institutional and high-net-worth clients
- Restrictions on operations, including variations of permission, capital add-ons and asset growth caps
- Increased regulatory oversight, including dedicated supervisors and intensive engagement
- Loss of correspondent banking relationships, which can stop the business
- Damage to employer brand, with knock-on effects on recruitment and retention
- Individual fitness-and-propriety challenges, conduct rule breach reports and management bans under SMCR or MFSA equivalents
- Criminal exposure for officers under the Bribery Act 2010, ECCTA 2023, sanctions law, and the failure-to-prevent offences
In a competitive market, trust is a core asset. Once lost, it is difficult and slow to rebuild.
What regulators expect today
Regulatory expectations have moved past "did the training happen?" to "did the training change behaviour?":
- Continuous training, refreshed against regulatory and product changes, not annual modules
- Role-specific learning aligned to risk exposure, with depth scaled to the conduct rule and certification population
- Evidence of understanding and behavioural change, not just attendance
- Clear audit trails of training effectiveness, including assessment performance and post-training behaviour metrics
- Senior management ownership, with named accountability under SMCR or MFSA fit and proper
This shifts compliance training from a tick-box exercise to a measurable business function with a regulator looking over its shoulder.
What HR leaders should do now
Move to role-based compliance training. Front office, middle office, operations, finance, technology, risk and support functions all carry different risk profiles. Training should be tailored to the SMCR / MFSA certified or approved population, the Conduct Rules staff population, the MLRO and deputies, the Senior Managers, and the wider workforce, with depth matched to risk.
Implement continuous learning frameworks. Compliance training should be embedded into the employee lifecycle: onboarding, ongoing development, certification cycles, annual fitness-and-propriety attestations and post-incident learning. Learning has to evolve alongside Consumer Duty, DORA, MiCA, the AML Regulation, the new ECCTA offences and other live changes.
Focus on real-world application. Scenario-based training is critical. Employees should be rehearsed on real situations: a SAR trigger, a Consumer Duty product-review challenge, an APP fraud claim, a conflict-of-interest disclosure, a market sounding, a sanctions breach near-miss, a DORA major ICT incident.
Measure effectiveness, not completion. HR should track assessment performance, behavioural indicators (SAR submission accuracy, conduct rule breach notification timeliness, complaint themes, audit findings, near-miss reporting volume), and reduction in compliance incidents. Completion rates tell you almost nothing the FCA or MFSA cares about.
Align compliance training with business performance. Compliance should sit inside performance management, risk appetite, the three lines of defence model, and organisational culture. Treat it as part of how the business runs, not an overhead the business tolerates.
Compliance as a competitive advantage
Forward-thinking financial institutions no longer view compliance as a cost. They use it as a differentiator with regulators, with institutional clients running their own due diligence, and with the talent market.
A well-trained workforce reduces risk, builds client trust, supports regulatory permissions, enhances operational resilience under DORA, strengthens correspondent and counterparty relationships, and improves the firm's standing in supervisory engagement.
HR as the driver of compliance culture
Compliance in financial services is no longer a departmental responsibility. It is an organisational capability driven by HR, senior management accountability under SMCR or MFSA fit and proper, and culture.
The organisations that succeed are those that move beyond basic training and focus on building real, measurable competence across the workforce that holds up under regulatory inspection and behind closed doors.
Try this for free
If your compliance training cannot demonstrate impact in reducing risk and improving decision-making, the organisation is already exposed.
Try our free course: https://www.aureninstitute.com/course/pay-transparency-in-the-eu-a-practical-guide-for-hr-leaders
Auren Institute. Compliance, Done Right.
