Compliance

FCA Handbook mapping

Every Bedrock capability mapped to the specific FCA Handbook rule it satisfies, with citations.

This page is the source of truth for “which Bedrock thing addresses which FCA rule.” It exists because compliance officers need to give the answer to that question without reading the engineering docs, and engineers need to give it without reading the FCA Handbook. Both groups should be able to point at the same row.

By rule

RuleNameBedrock features
PRIN 2A.2Products & services outcomeImpact assessments, Model registry
PRIN 2A.3Price & value outcomeBias monitoring
PRIN 2A.4Consumer understanding outcomeExplainability, Certificates
PRIN 2A.5Consumer support outcomeVulnerability routing, SLA enforcement, Bias monitoring, Drift detection, Model registry
PRIN 2A.6Cross-cutting obligationsVulnerability routing, Chain integrity
PRIN 6Customers' interestsSLA enforcement
PRIN 7Communications with clientsExplainability, Certificates
PRIN 11Relations with regulatorsIncident response
SYSC 6.1Compliance arrangementsChecklists, Incident response
SYSC 7.1Risk controlImpact assessments
SYSC 8OutsourcingModel registry, Drift detection
SYSC 9Record-keepingLedger, Chain integrity, Certificates
SUP 9Records available to the FCALedger, Certificates
COBS 9.2Suitability assessmentChecklists, Explainability
COBS 9.4Suitability reportsCertificates
DISP 1Complaints handlingIncident response
FG21/1Fair treatment of vulnerable customersVulnerability routing

Cross-cutting evidence

Two Bedrock capabilities act as evidence for almost every rule above: the ledger (because every other capability writes its evidence into it), and the certificate (because every signed certificate ties a specific decision to a specific reviewer with a verifiable timestamp). The other capabilities answer specific rules; these two answer the meta-question “can you prove it?” for any of them.

What this isn't

This mapping is not legal advice and is not a substitute for your own compliance function. It is a starting point for the conversation between your engineering and compliance teams about which controls satisfy which obligations. The marketing site's compliance page covers the wider context.