Compliance
Vulnerable customers: applying FCA guidance in commercial broking
Ask a commercial broker whether vulnerable customer rules apply to them and a fair number will say no. Their clients are limited companies, sole traders and property investors, not consumers buying a mortgage on their home. That reading is too narrow, and it leaves firms exposed.
The FCA's guidance on the fair treatment of vulnerable customers, FG21/1, was written with retail financial services in mind, but the regulator has been consistent that firms dealing with small business owners, sole traders and personal guarantors need to think about the same drivers of harm. A sole trader arranging asset finance is, for regulatory purposes, closer to a retail customer than a plc treasury team. A director signing a personal guarantee is exposed personally, whatever the borrowing entity looks like on paper.
Why vulnerability matters in a B2B-looking market
Commercial broking sits in an odd middle ground. The borrowing entity is usually a company, but the person you deal with, the director, the sole trader, the guarantor, is a human being who can be under just as much pressure as any retail customer. Bridging finance clients are frequently dealing with a chain collapse, a tax bill or a divorce settlement. Development finance clients can be managing a cash flow crisis that puts their home at risk through a guarantee. None of that shows up if you only look at the company.
The FCA's four drivers of vulnerability, health, life events, resilience and capability, apply whether the customer is buying a sofa on credit or trying to refinance a portfolio in six weeks before a lender pulls funding. A client under acute financial pressure, recently bereaved, or dealing with a health crisis is more likely to misunderstand terms, make rushed decisions, or fail to disclose facts that matter to your due diligence.
Where this sits alongside Consumer Duty
Vulnerable customer guidance and Consumer Duty are not the same thing, but they pull in the same direction. Consumer Duty applies where firms deal with retail customers, and the FCA has been clear that some commercial lending activity, particularly regulated bridging and some personal guarantee arrangements, falls inside its scope. We've written separately about what good Consumer Duty evidence looks like and the four outcomes in more detail. The vulnerability piece is one strand of the consumer understanding and fair value outcomes, not a separate regime you can ignore because the deal is 'commercial'.
Even where Consumer Duty doesn't technically bite because the customer is genuinely a corporate entity with no natural person exposure, treating customers fairly remains a Principle for Businesses and good practice regardless of authorisation status.
Spotting the signs without turning it into an interrogation
Nobody wants a broker who treats every enquiry call like a screening interview. The practical approach is to build vulnerability awareness into conversations you're already having, rather than adding a new one.
- Health: a client mentions a diagnosis, hospital appointments, or a carer's role that affects their availability or concentration.
- Life events: bereavement, divorce, redundancy, a recent business failure, or a sudden change in family circumstances.
- Resilience: thin cash reserves, reliance on a single facility, or a business that cannot absorb a rate change or delay.
- Capability: limited experience of financial products, language barriers, or difficulty engaging with digital processes.
None of these should trigger a refusal to deal with the client. They should trigger adjustment: more time, plainer language, a written summary instead of a rushed call, or a second point of contact if a decision-maker is under pressure.
Recording it properly
The FCA's own review work on vulnerability has repeatedly found that firms identify vulnerability inconsistently, and record it worse. Verbal awareness in the head of the account manager who took the call is not evidence; a note that a file was 'handled sensitively' is not evidence either. If a complaint or a file review comes six months later, you need a contemporaneous, specific record of what was identified, when, and what was done differently as a result.
That's a workflow and data problem as much as a training problem. A CRM that lets you flag a vulnerability indicator against a client record, timestamp it, and link it to the actions taken, an extra call, a paused deadline, a plain-English summary sent alongside the standard documents, gives you something you can actually produce. Doing this in email threads and personal notebooks doesn't survive contact with an FCA request for management information.
The firms that struggle with vulnerability reviews are rarely the ones that treated clients badly. They are the ones that treated clients well and can't prove it.
Building it into onboarding, not bolting it on
The best time to pick up vulnerability indicators is at the start of the relationship, during client onboarding, when you're already gathering fact-find information, running due diligence and asking about circumstances. We cover the wider onboarding sequence in our step-by-step guide to the client onboarding process. Vulnerability screening should be one deliberate step within it, not an afterthought triggered only when something goes wrong.
A short, standard set of prompts within your onboarding checklist, nothing intrusive, just space for the adviser to note anything relevant and a light-touch question about how the client prefers to receive information, does most of the work. The important part is that it happens every time, for every client, so the record exists whether or not anything was flagged.
Training that reflects your actual client base
Generic vulnerable customer training modules are usually written with retail lending in mind: payday loans, overdrafts, mortgage arrears. They translate poorly to a room of commercial finance advisers who will, rightly, switch off if the examples don't match their world. Better to build a handful of scenarios from your own pipeline: a sole trader refinancing after a supplier collapse, a director guaranteeing a facility during a marital separation, an ageing landlord managing a portfolio with declining cognitive capacity. Real scenarios, anonymised, land better than a stock e-learning course.
What good evidence looks like at review time
When the FCA or your own compliance function asks for evidence, you want to be able to show, across a sample of files, how vulnerability was considered at onboarding, what was identified in specific cases, what adjustments were made, and how those adjustments were tracked through to completion. That means the same record needs to be visible to whoever handles the file next, not locked in one adviser's head. A shared workflow system that surfaces flags to anyone who picks up the case does this automatically; a personal spreadsheet does not.
Firms are also expected to review the effectiveness of their approach, not just have a policy sitting on a shelf. The FCA's guidance expects monitoring: are staff actually identifying vulnerability, are outcomes for vulnerable customers as good as for everyone else, and is anything being done with the data collected. That last point is where most small and mid-sized brokerages fall down. They collect the flag and never look at it again.
This is also worth raising with your trade body. Both NACFB and FIBA publish member guidance and run sessions on regulatory topics that are worth attending even if your firm isn't directly authorised, since good practice here tends to set the tone lenders and introducers expect from the whole panel.
The cost of getting this wrong
The financial and reputational cost of poor vulnerability handling rarely shows up immediately. It surfaces later, as a complaint that escalates to the Financial Ombudsman, a lender relationship that sours because a guarantor felt misled, or a regulatory file review that finds a pattern across several cases rather than one. None of these risks are unique to retail lending. They apply equally to a broker who arranged a bridging loan for a sole trader who, in hindsight, was not in a fit state to understand the exit risk they were taking on.
There's also a quieter cost. Firms that don't think about vulnerability tend to lose good clients unnecessarily. A director going through a difficult patch who feels rushed or unheard by their broker is less likely to come back for the next deal, and less likely to refer colleagues. Treating people well when they're under pressure isn't only a compliance obligation. It's how repeat business and referrals actually happen in a relationship-driven industry.
Keeping it proportionate
None of this requires turning a commercial brokerage into a retail bank's vulnerability unit. It requires a short, honest process: ask, listen, note it down, adjust where needed, and be able to show your workings later. Most brokers already do the human part well. The gap is almost always in the record, not the relationship, and that's the part a decent system fixes without adding much friction to a broker's day.
