Read our review of good practice and areas for improvement identified through our Early and High Growth Oversight pilot with high-growth firms.
Firms that grow rapidly can benefit consumers and markets by increasing choice and access, improving services and supporting innovation. High growth firms can also contribute to economic growth through job creation and investment in infrastructure and technology.
But if firms prioritise expansion ahead of developing governance, risk management and control frameworks, this can increase the risk of harm.
Between July 2025 and March 2026, we engaged with 15 firms across asset management, wealth management and payments as part of a high-growth pilot. This was to identify rapidly growing firms earlier and support them as they establish and evolve their business. We assessed whether their governance, risk management and control frameworks were developing in line with their growth.
Below, we set out examples of good and poor practice we identified.
Firms experiencing growth should consider these findings and assess whether their arrangements remain appropriate for their size, scale, complexity and risk profile. If they find gaps, firms should take timely and appropriate action.
1. Who this applies to
This is relevant to authorised firms that are:
- newly established
- experiencing rapid growth
- undergoing significant change
It is particularly relevant to firms in the asset management, wealth management and payments sectors.
It will be of most interest to:
- Boards
- individuals in senior management functions
- those responsible for risk, compliance, and operational oversight
These individuals are key in making sure firms have the right governance arrangements, risk management frameworks, and focus on delivering good outcomes for consumers and markets.
Although the examples here are drawn from our engagement with a sample of firms, the themes may be relevant to firms of different sizes, business models and sectors, particularly when considering whether their own arrangements are adequate for growth or operational change.
2. What we looked at
Through the pilot, we sought to better understand:
- how firms grow
- the characteristics of sustainable growth
- the point at which risks begin to emerge
We also considered how data can help identify high-growth firms at an earlier stage, enabling more timely supervisory engagement. Our data-led approach identified firms exhibiting signs of growth, such as revenue, expenditure, staff growth and changes in permissions or control.
We engaged directly with each firm to assess whether its governance, risk management and control arrangements were keeping pace with its growth.
3. Key findings
3.1. Governance and senior management oversight
Good practice
Firms with stronger arrangements ensured governance, risk management and control frameworks kept pace with business growth.
They had clear Board and Committee structures, with defined roles and responsibilities, regular oversight of risk and compliance matters, and high-quality management information for better decision-making.
Decisions, actions and challenge were properly documented, for transparency and accountability.
Firms also strengthened their governing bodies as they evolved. Boards had the right mix of skills, knowledge and experience, with independent or non-executive members to challenge them. This was particularly evident in payments firms where Boards drew on a mix of payments, fintech and senior governance experience.
Areas for improvement
In some firms, governance arrangements had not kept pace with business growth. Board and Committee structures including the scope, frequency and format of meetings, were not always effective.
Some firms lacked sufficient independent challenge, with responsibilities concentrated among a small number of individuals. We also saw weaknesses in governance record-keeping, including:
- incomplete, insufficiently detailed or missing meeting minutes
- poor documentation of attendance, quorum, conflicts, decisions and follow-up actions
Growing firms may benefit from revisiting governance and oversight arrangements to ensure they remain effective.
Firms with strong governance, risk management and oversight arrangements are often better equipped to manage the challenges associated with rapid growth. This can improve the sustainability of growth and reduce the risk of consumer harm as the firm scales.
3.2. Risk management frameworks
Examples of good practice
Stronger firms had more mature risk management approaches. Some used risk-focused committees to review enterprise-wide risks and escalate issues to the Board, supported by clear risk appetites and key risk indicators. Some firms reduced their dependency on single individuals through cross-training and wider knowledge sharing.
Areas for improvement
Some firms relied heavily on key individuals, with limited contingency, succession planning, or broader knowledge transfer arrangements.
Some failed to sufficiently consider whether their risk management resources remained appropriate for the scale and complexity of the business. This was particularly relevant where third-party relationships were becoming deeper or more numerous, or where firms were making greater use of new technologies such as AI.
We also observed weaknesses where business models or customer populations had evolved but policies, procedures and control frameworks had not. For example, some firms’ target market had changed and they would have benefited from reviewing their suitability frameworks more regularly to keep pace.
3.3. Resourcing, capability and scalability
Examples of good practice
As their business evolved, stronger firms invested in capability by recruiting and training staff, and in scalability through improved technology. They strengthened their compliance functions through:
- additional resourcing
- updated financial crime frameworks to reflect market developments
- enhanced transaction monitoring through partner tools, manual review and real-time controls
Stronger firms also demonstrated forward-looking regulatory judgement, preparing early for upcoming policy changes and legal requirements. For example, some prepared early for upcoming safeguarding requirements.
In some cases, firms showed sound regulatory judgement by delaying expansion into new regulated activities until their controls for existing business were more robust.
Using tools such as the Regulatory Initiatives Grid[2] to anticipate future developments could be helpful.
Areas for improvement
We identified some weaknesses in firms’ capability and control frameworks where business models or customer populations had evolved but internal policies and procedures had not. For example, some firms would benefit from reviewing suitability frameworks more regularly in light of changes to their target market.
Firms should ensure that their resourcing, policies and oversight arrangements continue to evolve alongside the business so that they remain appropriate and effective.
3.4. Systems, controls and management information (MI)
Examples of good practice
Stronger firms had proactive cyber and operational resilience arrangements. This included using recognised security standards, penetration testing, third-party oversight and structured governance over the use of emerging technologies such as AI.
Stronger examples of conflict management included firms identifying conflicts arising from:
- group relationships
- co-manufacturing arrangements
- shared resources
- combined senior management responsibilities
Such firms were able to explain how conflicts were escalated, challenged and monitored through governance forums.
Some firms had also improved their controls following cyber incidents, demonstrating they had learnt from events and strengthened resilience. Regularly testing and reviewing cyber controls helps firms identify vulnerabilities early and respond to emerging threats.
Firms of all sizes should consider how they would respond to and recover from cyber incidents and other operational disruptions, including those affecting their third-party suppliers as well as their own systems. Ensuring staff understand their role in identifying and responding to cyber risks will also help.
Areas for improvement
Weaknesses included insufficient conflict of interest arrangements and management information that had not been updated.
Outdated MI, including references to superseded documents or meetings, reduced the quality of oversight and undermined firms’ ability to identify conflict issues promptly.
Similarly, weak conflict management arrangements can impair firms’ ability to identify, manage and mitigate potential detriment to customers.
Areas for improvement on cyber included strengthening evidence of change control, data governance, cyber testing, third-party oversight and operational resilience planning, particularly where firms were introducing new technology, automation, platform changes or AI.
3.5. Financial resilience
Examples of good practice
Stronger firms proactively monitored key financial risks, including liquidity and counterparty exposures.
Some firms used stress testing to check that their cost base was resilient, and that they could remain viable during periods of stress while continuing to meet regulatory capital requirements. These arrangements helped firms understand their financial resilience and prepare for adverse scenarios.
Areas for improvement
Some firms needed to strengthen their financial resilience planning. In particular, wind-down plans were not always current, practical or proportionate to the business.
Effective planning can help prevent a firm’s failure, but if it does fail it also helps it wind down in an orderly way and reduces the potential for consumer harm. Firms should supplement their wind-down plans with an understanding of relevant notification obligations such as SUP 15.
3.6. Consumer and market outcomes
Examples of good practice
Stronger firms had active oversight of their products and services, including:
- regular product or portfolio reviews
- benchmarking exercises
- transparent client reporting
Some firms also carried out due diligence on providers and platforms with customer outcomes in mind, including identifying more cost-effective or more flexible solutions where appropriate. Others used client feedback and satisfaction reviews to inform their business decisions, including those about growth.
These practices helped firms deliver the outcomes expected under the Consumer Duty[3], such as assessing fair value, maintaining appropriate propositions and monitoring whether customers were receiving suitable outcomes.
Areas for improvement
Some firms needed to put greater emphasis on assessing customer outcomes, including fair value.
Without active monitoring, firms may be less able to check if their products and services continue to meet customer needs, represent fair value, or remain appropriate for the intended target market. This increases the risk of causing foreseeable harm to consumers. Firms should have effective processes in place to monitor outcomes and act where they identify problems.
4. Next steps
We have provided individual feedback to all firms involved in the pilot, highlighting areas where they need to improve to ensure governance, risk management and control frameworks keep pace with growth.
We encourage firms experiencing growth to reflect on these findings and assess whether their own arrangements remain appropriate for their size, scale and complexity. Where gaps are identified, firms should address them in a timely and proportionate way.
We will use insights from this work to inform our supervisory approach and how we engage with firms experiencing high growth. We will also consider how data-led approaches can support earlier identification of emerging risks and more targeted supervisory interventions, where appropriate.