Consumer Duty
Customers in Vulnerable Circumstances: Moving Beyond Policy to Evidence of Good Outcomes
A vulnerability policy establishes intent. Firms also need to know whether customers are identified appropriately, staff can respond, support is effective and management can evidence and improve the outcomes being delivered.
Key takeaways
- Design the approach around the firm’s business model, customer base, products, services and likely vulnerability profile—not a generic template.
- Give customer-facing teams practical guidance, escalation routes and the authority to apply appropriate support or adjustments.
- Use management information and outcome testing to understand whether arrangements work in practice, not merely whether a policy exists.
- A low recorded identification rate is not proof of failure or a target to increase; it is a reason to test whether detection arrangements are effective.
Payments and e-money firms often have a vulnerability policy, training module and a field in the customer record. Those elements matter, but they do not by themselves demonstrate that customers in vulnerable circumstances receive appropriate support or achieve outcomes as good as those of other customers.
The FCA’s good and poor practice for payments firms does not create new requirements or prescribe one operating model. It shows the importance of understanding customer needs, providing suitable support and being able to evidence outcomes. The practical design should reflect the firm’s business model, customer base, products and services, channels and vulnerability profile.
Why policy alone is not enough
A policy usually describes principles, indicators, responsibilities and available support. The customer experience depends on whether those expectations are translated into prompts, scripts, system fields, permissions, hand-offs and quality checks that work under normal operational pressure.
A useful framework connects four things: how potential vulnerability is identified, how relevant information is recorded, what support follows, and how the firm tests whether that support produced a good outcome. A break in any part of that chain can leave management with reassuring process data but limited insight into customer experience.
Identification and recording
Customers may disclose a circumstance directly, show signs through conversation or behaviour, or encounter a temporary event that changes what support they need. Firms should decide which indicators are relevant to their channels and train staff to explore sensitively without making assumptions or diagnoses.
Records should be accurate, proportionate and useful. They need to give the next colleague enough information to avoid repeated disclosure and provide agreed support, while respecting privacy, access controls and retention requirements. Vague labels can be as unhelpful as excessive notes; recording should focus on relevant needs and actions.
Digital journeys also deserve attention. Failed verification, repeated abandoned transactions, unusual navigation or repeated contact may justify further analysis, but automated indicators should not become unsupported conclusions. Firms should understand what their data can and cannot show.
Customer-facing staff capability and guidance
Broad awareness training is only a starting point. Staff need role-specific guidance on recognising cues, asking appropriate questions, recording needs, offering available support, escalating concerns and handling situations where financial crime, fraud or safeguarding controls also apply.
Capability is shaped by the operating environment. Quality measures, call targets, approval limits and rigid scripts can discourage the time or judgement needed to respond well. Managers should test whether staff know what they can do and can obtain timely help where a need falls outside standard options.
Appropriate support and adjustments
Support should respond to the customer’s needs and the service being provided. It might involve changing the communication channel or pace, providing information in another format, enabling a trusted representative through appropriate controls, allowing more time, or using a specialist escalation route.
No single adjustment will suit every circumstance, and vulnerability does not mean a customer lacks capacity or should automatically be prevented from transacting. The firm should understand the need, explain available options and record what was agreed. It should also consider where third-party providers or banking partners constrain the support it can offer and how those dependencies are managed.
Governance and management information
Boards and senior management need information that connects activity to outcomes. Counts of disclosures or training completion can support oversight, but they are not sufficient on their own. Useful management information may examine:
- where and how needs are identified across products and channels;
- the support or adjustments provided and whether requests are completed;
- wait times, repeat contact, failed journeys, complaints and escalations;
- outcomes for relevant customer groups compared with the wider customer base;
- quality-assurance findings and whether staff follow guidance; and
- remediation actions, accountable owners, deadlines and evidence of effectiveness.
The right set will vary by firm. Measures should be interpreted in context, with definitions and limitations clear enough for management to challenge what the data appears to show.
Monitoring actual customer outcomes
Outcome testing asks what happened to the customer, not only whether staff completed required steps. A file may contain a vulnerability marker and still show repeated transfers between teams, an unsuitable communication method or an unresolved access barrier.
Testing can combine file review, journey analysis, call listening, complaint themes, customer research, quality assurance and targeted data analysis. Sampling should cover the circumstances, products and channels most relevant to the firm rather than relying only on cases already labelled as vulnerable.
Interpreting low identification rates
A low recorded rate of vulnerability is not, by itself, evidence of poor practice and firms should not set an arbitrary target for the number of customers identified. Customer populations and products differ, and some customers will not disclose a circumstance.
It can nevertheless be a useful prompt. Management can compare channels, review contact and complaint themes, listen to interactions, test staff understanding and assess whether system design creates barriers to recording. The purpose is to test effectiveness, not to manufacture a higher number.
Continuous improvement and remediation
Findings should lead to timely action proportionate to customer risk. That may include improving guidance, changing a journey, expanding adjustment options, correcting records, revisiting affected cases or strengthening oversight of a service provider.
Remediation should have clear ownership and completion evidence. Where a change addresses a symptom rather than the underlying design, outcome testing should continue until management can see that the position has improved in practice.
A practical vulnerable-customer review checklist
- Define the vulnerability characteristics and support needs relevant to the firm’s customers, products and channels.
- Map how customers can disclose needs and how staff or systems may identify relevant cues.
- Review whether records are proportionate, accessible to the right people and useful at the next interaction.
- Test role-specific guidance, training, supervision, escalation and staff authority to provide support.
- Assess whether available adjustments address the needs likely to arise across each customer journey.
- Examine partner and outsourced-service dependencies that can affect customer support.
- Build management information that links identification and support activity to customer outcomes.
- Sample journeys and cases, including customers not already marked as vulnerable, to test effectiveness.
- Treat low identification rates as a prompt for investigation rather than a quota.
- Track improvements through accountable owners, deadlines and follow-up testing.
A mature framework does not assume every difficulty can be eliminated. It gives the firm a disciplined way to recognise needs, respond appropriately, learn from outcomes and improve where evidence shows the approach is not working.
Sources and further reading
Important: This article is general information only and does not constitute legal advice. Regulatory requirements depend on a firm’s specific model and circumstances.
Start a conversation