What are the Consumer Duty cross-cutting rules?
The Consumer Duty cross-cutting rules are three FCA Principle 12 standards that every regulated firm must evidence: act in good faith, avoid foreseeable harm, and enable customers to pursue their financial objectives.
Set out in the FCA Handbook at PRIN 2A.2, they sit under the Consumer Principle and shape how you treat retail customers at every stage. In the FCA's order, they are:
- Act in good faith toward retail customers, with honest, fair and transparent treatment across the product lifecycle.
- Avoid causing foreseeable harm to retail customers, anticipating and preventing detriment before it occurs.
- Enable and support retail customers to pursue their financial objectives, removing practical barriers to access, support, switching, cancelling and claiming.
Consumer Duty itself is the wider framework; this guide covers the rules underneath it. For what Consumer Duty is and how the four outcomes map to operational controls, see our Consumer Duty pillar.
The rules apply across every product, service and interaction. There's no carve-out for the files you didn't get round to reviewing, which is why they're less a definition exercise than an evidence one. That's where most firms feel the pressure. For a quick reference, see how many cross-cutting rules there are. <!-- TODO: resolves when sibling publishes -->
Why the cross-cutting rules are really an evidence test
In April 2026, when the FCA set out its Year-2 observations on how firms were embedding the Consumer Duty, one failure mode kept recurring across board reports: weak evidence for the cross-cutting rules. Firms could describe what they did. Far fewer could prove it held across every customer. That gap is the story: the rules aren't the hard part to understand, they're the hard part to evidence.
Read closely, all three rules ask one question: can you prove you knew before it broke? They want evidence that risks were spotted before customers were harmed, not a description of good intentions after the fact.
That's where most operating models buckle. The honest version, as one compliance leader put it to us, is structural:
"Most networks currently check low-teen percentages of files. They know it's not enough. Regulators know it too. Networks are forced into sampling, which means risk is statistical, not managed."
When risk is statistical rather than managed, the foreseeable-harm rule has nothing to bite on. You can't anticipate detriment in files you never opened.
The FCA's FG22/5 guidance is explicit that good outcomes must be demonstrated, not asserted, and its April 2026 Year-2 observations named weak cross-cutting-rules evidence as a recurring board-report failure. The point isn't that firms are acting badly. It's that they can't show, file by file, that they aren't.
So the lens shifts. Under Consumer Duty the FCA isn't auditing your speed, it's auditing whether your evidence holds. That runs through all three rules, and it changes what each one asks you to keep.
Rule 1: Act in good faith
Good faith sounds like a value. Under the cross-cutting rules it's a demonstrable standard, something you show rather than assert in a policy.
The FCA's PRIN 2A.2 frames good faith as honesty, fair dealing and consistency with customers' reasonable expectations across the lifecycle. Law firms such as Browne Jacobson have drilled into the same standard, and the common thread is that good faith has to be visible in how decisions are actually made, not just declared.
That makes evidence-of-decision the heart of it: for every flagged file, you want the reasoning behind the call, not just the outcome. It's where reasoning transparency earns its place. Curvestone records why a check fired, with citations to the document pages and an audit trail behind each decision, so the rationale is recoverable later, which is exactly what a regulator asks to see.
Good faith also has to be consistent firm-wide. A standard that lives in one reviewer's head, or in a checklist last updated two years ago, becomes an evidence weakness the moment that person is on leave. Consistency across reviewers and files is itself part of the proof.
A compliance officer at a UK directly-authorised mortgage brokerage described the gap plainly: vulnerable-customer data sits in the CRM but never reaches the audit-ready report. Good faith intended isn't good faith evidenced.
Rule 2: Avoid foreseeable harm
This is the load-bearing rule. Avoiding foreseeable harm means anticipating and preventing detriment before it occurs, which calls for forward-looking detection rather than retrospective spot-checks.
The economics are what make that hard. Manual file review takes 50 to 90 minutes per case in UK mortgage networks, and at typical broker volumes that cost forces single-digit-to-low-teens sampling, leaving every out-of-sample file unevidenced against the rules. A compliance lead at a wealth-advice firm told us their manual checks reach only 20 to 30% of the business. The rest goes unchecked, and they know it.
You can't anticipate harm in files you never see. Here's the part nobody wants to say out loud:
Sampling 2% of files satisfies a 2010 quality-assurance mindset. It does not satisfy Consumer Duty. The cross-cutting rules require evidence that risks were identified before widespread harm, and a 98% blind-spot is not evidence.
Forward-looking detection closes the gap. Curvestone processes roughly a quarter of UK mortgage-network compliance checks at 99% accuracy with a per-case audit trail, which is the detection record this rule needs. The file-review check runs on every case, not a sample, and the vulnerability assessment reads the actual comms, calls and emails rather than waiting for someone to tick a box.
The FCA expects risk caught before it crystallises into harm. A model that inspects one file in fifty can't make that claim, however well it documents the one it saw.
Rule 3: Enable customers to pursue their financial objectives
The third rule is about removing practical barriers, to access, to support, to switching, cancelling and claiming, and then proving you removed them for each kind of customer.
Different customers carry different objectives, so the evidence has to be specific. A vulnerable customer, a buy-to-let landlord, a bridging borrower and a debt-consolidation case don't face the same barriers, and a single generic check won't show you cleared the right ones. The proof is per segment, not blanket.
That's why configurability is evidence, not just convenience. Curvestone runs checks tuned per product and customer type, so a vulnerable-customer file is assessed against the support that customer needed, and a bridging file against its own risks. Each segment generates its own evidence trail. Case files ingest straight from origination systems including OMS, so the assessment runs on the real record, not a re-keyed summary.
A compliance director at a UK mortgage broker handling 50 to 60 cases a month described the throughput ceiling precisely: chasing brokers and solicitors for missing documents is what caps the business; they want gaps flagged before submission, not after. That's rule 3 in operational terms: enabling a customer's objective starts with not letting their file stall on a preventable gap.
The FCA's consumer-support good and poor practice sets the bar: support that is as easy to use as the sale was, evidenced in how customers are actually treated.
What evidencing the rules looks like in practice
Picture a directly-authorised broker or network running 50 to 300 cases a month. Evidencing the rules isn't a quarterly report; it has to be true of every case as it moves.
In practice, each file carries its own chain: a dated good-faith decision record showing the call and its reasoning; a foreseeable-harm detection pass run before submission, not sampled after; an objective-enablement check matched to that customer's segment; and an override log, so any human change to an automated flag is recorded with a reason and a timestamp.
Strung together, that chain answers the regulator's question. For any customer you can name, you can show what was checked, what was found, what was done and when.
The obvious objection is that reviewing every file isn't operationally feasible. It is. Walker Morris cut compliance review time on service agreements from four hours to fifteen minutes per file using Curvestone's automated checking, a 93% reduction, and the same approach scales the cross-cutting rules across every file rather than a 2% sample.
That's a regulated-sector reference where full coverage already runs. The constraint was never the law; it was the 50 to 90 minutes a manual review used to cost. For the wider programme, see how to prepare for an FCA Consumer Duty audit. <!-- TODO: resolves when sibling publishes -->
Operator checklist: evidencing the cross-cutting rules
If you're pressure-testing your own evidence, start here.
- Map each rule to a dated, per-case evidence artefact, not a policy document. A statement of intent is not proof that intent was carried out.
- Replace sampling with monitoring at scale. Set your coverage target at every file, not a percentage you can defend in a meeting but not to a regulator.
- Capture the decision and its reasoning per file, not just the outcome. Good faith lives in the why, and the why is what gets audited.
- Tag vulnerability from the actual interaction record, the calls, comms and emails, rather than a CRM field nobody updates.
- Keep a remediation trail linking each identified risk to the action taken and the date it was taken. An open risk with no closing entry reads as a risk you missed.
Run that list against a real month of files, and the gaps tend to show up fast.
Frequently asked questions
How many Consumer Duty cross-cutting rules are there?
What are the three Consumer Duty cross-cutting rules?
How does the FCA expect firms to evidence the cross-cutting rules?
Are the cross-cutting rules different from the four Consumer Duty outcomes?
Why is sampling-based file review insufficient under Consumer Duty?
Consumer Duty: why evidencing good outcomes never stops being the job
The Consumer Duty is a Financial Conduct Authority standard, in force since 31 July 2023, requiring UK financial services firms to act to deliver good outcomes for retail customers. It is not a finished 2023 project: it is a permanent obligation to evidence good outcomes on every case, which most firms cannot yet prove.
DefinitionHow many Consumer Duty cross-cutting rules are there?
There are three Consumer Duty cross-cutting rules: act in good faith toward retail customers, avoid causing foreseeable harm to retail customers, and enable retail customers to pursue their financial objectives. The rules are set out in PRIN 2A.2 of the FCA Handbook and apply under Principle 12.
How toHow to prepare for an FCA Consumer Duty audit
An FCA Consumer Duty audit is the annual board-attestation cycle in which UK regulated firms must evidence good customer outcomes against the four outcomes and three cross-cutting rules of the Duty. The next Year-2 board report is due 31 July 2026, and the FCA's April 2026 observations require substantive evidence across all four outcomes.
DefinitionConsumer Duty board reports: the 12-cell evidence grid
A Consumer Duty board report is the assessment a firm's board must review and approve at least annually, evidencing the outcomes retail customers received across the four outcomes and three cross-cutting rules. The FCA's 2026 observations show most reports evidence too few of the twelve outcome-by-rule cells the Duty requires.

Dawid Kotur
CEO and co-founder, Curvestone
Dawid co-founded Curvestone in 2024 after a decade working at the intersection of financial services and applied machine learning. He writes about the strategic direction of regulated-industry AI, the FCA's evolving approach to model risk, and the operational changes UK lenders are making in response to Consumer Duty. He sits on the FCA Smart Data Accelerator advisory cohort.
LinkedIn