Governance & GRC

The Compliance Stack: Law, Regulation, Professional Standard and Firm Policy — and What Happens When They Conflict

Most compliance failures are not failures of knowledge but of precedence. The four layers of obligation in UK and US financial services, and what to do when they point in different directions.

By Jonas Osman AbdelghafourPublished 4 August 2026

Most compliance failures in financial services are not failures of knowledge. The people involved knew the rule. They failed because they could not tell which of four competing obligations took precedence, and defaulted to the one with the loudest voice in the room — which is almost always firm policy, and almost never the one that governs.

Financial services obligations sit in four distinct layers with different sources, different enforcement mechanisms and different consequences for breach. Understanding the stack is not academic. It determines what you do when your employer's instruction and your professional standard point in different directions, which is a situation most technical professionals will face at least once.

*This article discusses regulatory and professional frameworks in general terms and is not legal advice.*

The Four Layers

Layer 1 — Statute and case law. Primary legislation, secondary legislation, and judicial decisions interpreting them. In the UK: the Financial Services and Markets Act framework, the Equality Act, UK GDPR, the Companies Act, and case law that reshapes obligations without any regulator lifting a pen — the Virgin Media v NTL Pension Trustees judgment being a recent example that created substantial uncertainty about historic pension scheme rule amendments, prompting the FRC to issue guidance for pension scheme actuaries on retrospective confirmations in January 2026, developed with input from the IFoA and the Association of Consulting Actuaries. In the US: federal banking statutes, securities law, state insurance codes, and the underlying authority provisions on which supervisory guidance rests.

Breach consequence: legal liability, criminal exposure in some cases, unenforceable arrangements.

Layer 2 — Regulatory rules and supervisory expectations. These are not one thing, and conflating them is a common error. A rule in the FCA Handbook is binding. A PRA supervisory statement is an expectation. SR 26-2 is, in the agencies' own framing, non-binding guidance resting on the underlying authority to act against unsafe or unsound practices. A NAIC model bulletin has no force at all until a state adopts it.

Breach consequence: enforcement action, fines, permission variation, individual sanction — but only where the instrument actually binds. For guidance, the consequence arrives indirectly, through supervisory judgement about whether practices were sound.

Layer 3 — Professional standards. TAS 100 and the Actuaries' Code in the UK; ASOPs and the Code of Professional Conduct in the US; equivalent codes for accountants, lawyers and chartered risk professionals. These bind the *individual*, through membership, regardless of what the employer wants.

Breach consequence: professional discipline, loss of designation, loss of the ability to practise.

Layer 4 — Firm policy. Internal frameworks, model risk policies, delegated authorities, approval matrices.

Breach consequence: employment consequence. Nothing more, in itself — though a policy breach frequently evidences a breach at a higher layer.

The Rule That Resolves Most Conflicts

The layers are not a simple hierarchy where higher always beats lower. The operative principle is different and simpler:

Each layer sets a floor, and the most demanding applicable floor governs.

Firm policy cannot authorise a breach of a professional standard. A professional standard cannot authorise a breach of a regulatory rule. A regulatory rule cannot authorise a breach of statute. But any layer can be *more* demanding than the one above it, and where it is, it governs the person or entity it binds.

This produces the situation that catches people out: a firm can be fully compliant with regulation while an individual within it breaches their professional standard. The firm's policy permitted it. The regulator's rules did not prohibit it. But the individual's professional obligation required something more.

This is not hypothetical. It arises routinely where a firm's model risk policy sets validation requirements below what a professional standard requires for the specific work, or where reporting timelines compress documentation below the standard of care the individual owes.

Four Live Conflict Points

Conflict 1 — Non-binding guidance versus binding professional standard. SR 26-2 is explicitly non-binding and has narrowed the definition of "model," meaning many spreadsheets and deterministic tools may fall outside formal model risk management scope. A US actuary using such a tool for reserving work is still subject to applicable ASOPs on data quality, assumption setting and documentation. The narrowing of the banking model definition does not narrow the professional obligation at all. Firms treating the SR 26-2 inventory reduction as a general reduction in rigour will create exactly this gap.

Conflict 2 — The reasonable steps problem under an unspecified standard. UK senior managers are assessed on reasonable steps. Where AI systems perform functions previously subject to human oversight, what constitutes reasonable steps has not been specified — the Treasury Committee's January 2026 report asked the FCA to publish guidance on precisely this by the end of 2026. Until it does, senior managers are constructing the standard through their own documentation. The safest position is to over-document the reasoning, because the absence of a specified standard means the assessment will be made retrospectively, with hindsight, against whatever practice becomes normal.

Conflict 3 — Speaking up when the layers diverge. Both the Actuaries' Code and the US Code of Professional Conduct contemplate circumstances in which a professional must escalate or, ultimately, decline to be associated with work. Firms have whistleblowing procedures; regulators have reporting channels; professional bodies have their own obligations. These do not automatically align, and the sequencing matters. The practical point is to understand the routes *before* needing them — including which communications attract protection and which do not.

Conflict 4 — Privilege, and where remediation work sits. This is the layer conflict that causes the most expensive surprises for cross-border groups. Legal professional privilege in the UK and attorney-client privilege and work product doctrine in the US are not coextensive, and the treatment of communications with in-house counsel differs materially, particularly in an EU context. A model validation or remediation review commissioned in a way that attracts privilege in one jurisdiction may be fully disclosable in another.

The practical consequence: decide the privilege position at the *commissioning* stage, with counsel, before the work starts. Deciding afterwards is not a decision — it is a discovery.

Where UK and US Structure Differs Most

Three structural differences change how the stack operates.

Individual versus institutional accountability. SM&CR pushes UK obligations down to named individuals with personal exposure. The US framework, in banking, locates accountability with the board and senior management collectively. This means the UK stack is experienced personally by more people, and the US stack is experienced institutionally — with the significant exception of the Appointed Actuary in US insurance, whose signed opinion is a genuinely individual exposure.

Federal versus unitary. A US insurer's Layer 2 obligations differ by state. It may face NAIC-derived AI governance expectations in some states, distinct frameworks in California, Colorado, New York and Texas, and nothing specific in others. UK Layer 2 is unitary. This is the single largest operational difference for compliance functions, and it is why US programme design tends toward building to the strictest state and applying it everywhere.

Independent versus profession-affiliated standard-setting. UK technical actuarial standards are set by the FRC, an independent regulator, and monitored through its Actuarial Monitoring Programme. US ASOPs are set by a profession-affiliated board. Layer 3 in the UK is therefore closer in character to Layer 2 than it is in the US.

A Practical Operating Discipline

Five things that materially reduce exposure across the stack.

Map obligations by layer for each material process. One page per process: statutory basis, regulatory instrument and its binding status, professional standards engaged, firm policy. Most firms have never distinguished binding rules from expectations in their own documentation, which means nobody knows which requirements are genuinely negotiable under time pressure.

State the binding status of every requirement you cite. "SR 26-2 expects" and "the Consumer Duty requires" are different sentences with different consequences. Precision here prevents both over-compliance with guidance and under-compliance with rules.

Write policy to acknowledge professional obligation explicitly. A clause stating that where an individual's professional standards require more than firm policy, the professional standard governs, costs nothing and pre-empts a whole class of conflict.

Decide privilege at commissioning. For any review that could surface findings — validation, remediation, incident investigation — establish the privilege position in writing before work begins, with jurisdiction-specific advice where the group operates cross-border.

Document judgement, not just conclusions. Across all four layers, the modern supervisory question is whether the judgement was reasonable. A file recording what was decided is weaker than a file recording what was considered, what was rejected, and why.

The Underlying Point

The stack exists because no single layer can do the whole job. Statute is too slow to keep pace. Regulation is too general to cover every technical judgement. Professional standards reach the individual but not the institution. Firm policy reaches the institution but has no external force.

Together they work reasonably well. The failures happen at the seams — and the seams are exactly where the interesting work is.

Key Takeaways

  • Financial services obligations sit in four layers — statute, regulation, professional standards, firm policy — with different sources and enforcement.
  • Each layer sets a floor; the most demanding applicable floor governs, so a firm can be regulation-compliant while an individual breaches a professional standard.
  • Binding status varies sharply within Layer 2: FCA rules bind, PRA supervisory statements are expectations, SR 26-2 is non-binding, NAIC bulletins bind only on state adoption.
  • SR 26-2's narrower model definition does not narrow actuarial professional obligations on the same work.
  • Legal privilege differs between UK and US regimes; the position must be established at commissioning, not after findings emerge.

Frequently Asked Questions

What takes precedence when firm policy conflicts with a professional standard? The professional standard governs the individual who is bound by it. Firm policy cannot authorise a breach of a professional obligation, though it can — and frequently should — require more than the professional minimum. Where the two diverge, the individual must meet the more demanding requirement.

Is non-binding regulatory guidance safe to depart from? Departing from guidance is not itself a breach, but it must be defensible. Supervisors retain authority to act where practices are unsafe or unsound, and examiners and auditors generally treat sound-practice guidance as the benchmark. A documented, reasoned departure is defensible; an undocumented one is very difficult to defend retrospectively.

How should cross-border firms handle differing UK and US requirements? Build one framework calibrated to the most demanding applicable standard across the footprint, with an annex mapping each jurisdiction's requirements against it. Running parallel frameworks reliably produces divergence, and divergence is difficult to explain to whichever supervisor finds it first.

Related reading

See also Governance, Risk and Compliance and Regulatory Compliance, or review qualifications.

About the author

Jonas Osman Abdelghafour is an actuary and risk expert advising insurers, banks and pension funds on model risk, regulatory compliance, financial crime and enterprise risk management across UK, EU and US regimes. He writes on where quantitative actuarial practice meets the governance, risk and compliance frameworks regulators expect boards to evidence. See qualifications and services, or get in touch to discuss an engagement.

Frequently asked questions

What should risk leaders know about the Four Layers?

**Layer 1 — Statute and case law.** Primary legislation, secondary legislation, and judicial decisions interpreting them. In the UK: the Financial Services and Markets Act framework, the Equality Act, UK GDPR, the Companies Act, and case law that reshapes obligations without any regulator lifting a pen — the Virgin Media v NTL Pension Trustees judgment being a recent example that created substantial uncertainty about historic pension scheme rule amendments, prompting the FRC to issue guidance...

What should risk leaders know about the Rule That Resolves Most Conflicts?

The layers are not a simple hierarchy where higher always beats lower. The operative principle is different and simpler:

What should risk leaders know about four Live Conflict Points?

**Conflict 1 — Non-binding guidance versus binding professional standard.** SR 26-2 is explicitly non-binding and has narrowed the definition of "model," meaning many spreadsheets and deterministic tools may fall outside formal model risk management scope. A US actuary using such a tool for reserving work is still subject to applicable ASOPs on data quality, assumption setting and documentation. The narrowing of the banking model definition does not narrow the professional obligation at all....

Where UK and US Structure Differs Most?

Three structural differences change how the stack operates.

What should risk leaders know about a Practical Operating Discipline?

Five things that materially reduce exposure across the stack.