Financial Services Office Move: FCA Compliance & Audit Trail Requirements

By Riley Cross

Moving office is never simple. For a regulated financial services firm, it’s a compliance event – full stop.

Every other business worries about downtime and removal costs. You worry about those too, but you also carry obligations that don’t pause for a van loading bay. The FCA expects continuous service delivery. The Senior Managers and Certification Regime assigns personal accountability for operational failures. PRA Supervisory Statement SS1/21 requires you to stay within impact tolerances for your important business services – even on moving day.

Get it wrong and you’re not just dealing with a disrupted office. You’re dealing with a potential regulatory breach, a supervisory notification, and a senior manager with their name on the accountability map.

This guide is written for compliance officers, COOs, and senior managers at UK financial services firms who are planning a move and need to understand exactly what the regulatory framework demands – and how to build an audit trail that proves you met it.

If you want to talk through your specific situation before reading on, speak to our team at any point.

Why Financial Services Moves Are Different

Most businesses treat an office move as a project management challenge. You do too – but layered on top of that is a regulatory compliance challenge that most project managers have never encountered.

Regulatory Obligations That Don’t Pause for a Move

The FCA’s expectations of authorised firms are continuous. There is no grace period for a relocation. Your obligations under the FCA Handbook – record-keeping, client data security, system availability, conduct standards – apply at 9am on moving day exactly as they did the week before.

That means a move must be designed around your regulatory obligations, not the other way around. If your trading systems need to be live by market open, the move schedule bends to that requirement. If your client files must remain in a secure, auditable chain of custody throughout transit, the removal methodology is built around that constraint.

This is the fundamental difference between a financial services office move and a standard commercial relocation. The regulatory framework is not a box to tick at the end – it shapes every decision from the moment you sign the new lease.

FCA Operational Resilience Rules and What They Mean for a Physical Move

FCA PS21/3 – the policy statement on building operational resilience – came into full effect on 31 March 2025. By that date, all in-scope firms were required to have identified their important business services, mapped the people, processes, technology, facilities, and information that underpin them, set impact tolerances, and tested their ability to remain within those tolerances under severe but plausible disruption scenarios.

A physical office move is exactly the kind of scenario PS21/3 was designed to stress-test. It involves:

  • Temporary loss of or disruption to facilities – the single biggest operational resilience risk in a relocation.

  • Changes to third-party dependencies – new building management, new IT infrastructure providers, new physical security arrangements.

  • Potential gaps in system availability – particularly during IT cutovers and network migrations.

  • Staff displacement – temporary remote working, unfamiliar environments, reduced oversight.

The FCA does not prescribe how you manage a move. It prescribes the outcome: your important business services must remain within their impact tolerances throughout. How you achieve that is your problem to solve – and your compliance team’s problem to document.

SM&CR Accountability – Who Owns the Move?

Under the Senior Managers and Certification Regime, every material operational risk must sit within a named senior manager’s Statement of Responsibilities. An office relocation is a material operational event. That means someone’s name is on it.

In most firms, the COO (SMF24) is the natural owner of a relocation programme. In some structures it falls to the CEO (SMF1) or the Chief Risk Officer (SMF4). The specific function matters less than the clarity of ownership. If the move causes a service disruption and the FCA asks who was accountable, the answer must be immediate and unambiguous.

We’ll cover SM&CR accountability in detail later. The point here is simple: before you do anything else, name the senior manager who owns this move and document it.

The FCA Audit Trail: What You Must Document

An audit trail for a financial services office move is not a nice-to-have. It’s the evidence pack that demonstrates – to the FCA, to the PRA, and to your own board – that the move was managed to a regulated standard.

Pre-Move Regulatory Notification Requirements

The FCA Handbook (SUP 15) requires firms to give reasonable advance notice of a change to their principal place of business in the UK. In practice, this means submitting a notification through the FCA’s Connect portal before the move date, not after it.

The notification must include:

  • The new address.

  • The effective date of the change.

  • Any consequential changes to the firm’s regulatory permissions or operational arrangements.

For dual-regulated firms – those supervised by both the FCA and the PRA – the notification obligation runs to both regulators. The PRA Rulebook mirrors the SUP 15 requirement. Don’t assume that notifying one regulator satisfies the other.

If the move involves a change to your registered office address (as distinct from your principal place of business), that’s a Companies House notification too – separate process, separate deadline.

Document everything. Keep a copy of the Connect submission, the submission date, any acknowledgement from the FCA, and the date the change appeared on the FCA Register. That’s the foundation of your pre-move audit trail.

Chain of Custody for Physical Records and Client Files

Physical client records – KYC files, complaint files, account documentation, documents under legal hold – are regulated assets. They carry data protection obligations under UK GDPR and record-keeping obligations under the FCA Handbook (SYSC 9). Moving them is not the same as moving furniture.

A compliant chain of custody for physical records during a move looks like this:

  • Pre-move inventory. Every file, box, and archive container is catalogued before anything leaves the premises. Each item receives a unique identifier – a barcode, a sealed container number, a reference that can be tracked individually.

  • Signed handoff at origin. The person responsible for the records signs off at the point of collection. The removal team signs to confirm receipt. Both signatures are timestamped.

  • Secure transit. Records travel in locked, access-controlled vehicles. Tamper-evident seals are applied to containers. No records are left unattended in transit.

  • Signed receipt at destination. Records are received and signed for at the new premises. The receiving party confirms the seal integrity of each container.

  • Reconciliation. The arrival manifest is checked against the origin manifest. Every item is accounted for before boxes are opened.

  • Post-move sign-off. The chain-of-custody log – covering origin, transit, and destination – is filed as part of the move audit pack.

Any break in that chain is a potential data breach notification under UK GDPR Article 33. It’s also a potential FCA record-keeping breach. Neither is a comfortable conversation to have with a regulator.

IT and Data Continuity Documentation

Your IT relocation is arguably the highest-risk element of the entire move. The documentation requirements are correspondingly demanding.

Before the move, your IT continuity documentation should cover:

  • A complete asset register of all hardware being relocated, with serial numbers and current locations.

  • Network architecture diagrams showing the current and target states.

  • System availability requirements for each important business service – which systems must be live at all times, which can tolerate a planned outage window, and what that window is.

  • Rollback procedures for each system, in case the cutover fails.

  • A communications plan for staff and, where relevant, clients.

During the move, you need a real-time log of:

  • Each system taken offline, with timestamp and responsible technician.

  • Each system brought online at the new premises, with timestamp and sign-off.

  • Any deviations from the planned cutover schedule, with the reason and the impact assessment.

After the move, the IT continuity documentation forms part of your post-move audit pack. It demonstrates that you managed the transition in a controlled, documented way – and that any disruption was within your pre-agreed impact tolerances.

For firms moving a data centre relocation alongside the main office move, the documentation requirements are even more granular. Treat the data centre migration as a separate workstream with its own audit trail.

Post-Move Sign-Off and Evidence Pack

The audit trail doesn’t end when the last box is unpacked. A compliant post-move evidence pack should include:

  • Confirmation that the FCA Register has been updated with the new address.

  • Confirmation that the PRA has been notified (for dual-regulated firms).

  • The completed chain-of-custody log for all physical records.

  • The IT continuity log, including any incidents and their resolution.

  • An updated business continuity plan reflecting the new premises.

  • Updated SM&CR Statements of Responsibilities if the move changed any senior manager’s operational scope.

  • Sign-off from the accountable senior manager confirming that the move was completed within the firm’s impact tolerances.

This pack should be retained for at least five years – the standard FCA record-keeping period under SYSC 9 – and made available for regulatory inspection on request.

Our post-move support service is specifically designed to help financial services firms close out the compliance documentation after a move. If you’d like to understand what that looks like in practice, speak to our team.

PRA and FCA Operational Resilience During a Move

Operational resilience is not a concept that applies only to cyber incidents or system failures. It applies to any event that could cause a firm to exceed its impact tolerances for an important business service. A physical office move qualifies.

Business Continuity Planning Obligations

Your Business Continuity Plan (BCP) must be updated before the move begins – not after. The move itself is a planned disruption scenario, and your BCP should address it explicitly.

At a minimum, the pre-move BCP update should cover:

  • The period of maximum risk – typically the 24–72 hours around the physical move date.

  • The specific important business services that could be affected and the controls in place to protect them.

  • Fallback arrangements if the move encounters unexpected delays – for example, if IT systems cannot be brought online at the new premises within the planned window.

  • Remote working protocols for staff who cannot access either the old or new premises during the transition.

  • Communication protocols for clients and counterparties if service is affected.

The BCP update should be approved by the board – or by the appropriate board committee – before the move date. That approval is itself a piece of audit trail evidence.

Important Business Services Mapping

Under PS21/3 and SS1/21, firms must maintain current mapping of the people, processes, technology, facilities, and information that underpin each important business service. A move changes the facilities component of that mapping – and potentially the technology and third-party components too.

Before the move, review your IBS mapping and identify every service where the physical premises is a dependency. For each one, ask:

  • What happens to this service if the move is delayed by 24 hours? By 48 hours? By a week?

  • What is the impact tolerance for this service? Is it measured in hours or days?

  • Do the fallback arrangements in the BCP keep the service within tolerance?

If the answer to the last question is no, you have a problem to solve before the move date – not on it.

After the move, update the IBS mapping to reflect the new premises, new third-party arrangements, and any changes to the technology or process dependencies.

Tolerances for Disruption – What the FCA Expects

The FCA’s position on impact tolerances is clear: by 31 March 2025, firms should have been able to demonstrate that they can remain within tolerance for each important business service under severe but plausible scenarios. An office move is not a severe scenario – it’s a planned one. The expectation is correspondingly higher.

In practice, that means:

  • Trading and order execution services at an investment firm should have zero planned downtime during market hours. The move schedule must be designed around market hours, not the other way around.

  • Payment processing services at a bank or payment institution should have a tested fallback that can be activated if the primary system is unavailable during the move.

  • Client-facing services – online portals, telephone support, claims processing – should have a tested continuity arrangement covering the move window.

The FCA will not accept “we were moving office” as a justification for exceeding an impact tolerance. The move was planned. The disruption was foreseeable. The expectation is that you planned around it.

SM&CR – Assigning Accountability for the Move

The Senior Managers and Certification Regime is built on a simple principle: for every material risk and operational function, there is a named individual who is personally accountable. An office relocation is a material operational event. It needs a named owner.

Senior Manager Function Ownership

The most common ownership structure for a financial services office move is:

  • SMF24 (Chief Operations) – owns the overall relocation programme, including logistics, IT migration, and operational continuity.

  • SMF16 (Compliance Oversight) – owns the regulatory compliance workstream, including FCA notifications, audit trail, and post-move sign-off.

  • SMF17 (Money Laundering Reporting Officer) – owns the chain of custody for AML-relevant records and any changes to the firm’s physical AML controls.

In smaller firms where these functions are combined, one senior manager may own all three workstreams. What matters is that the ownership is documented in the relevant Statements of Responsibilities before the move begins.

If the move changes the scope of any senior manager’s responsibilities – for example, if the new premises introduces new third-party arrangements that fall within an SMF’s accountability – the Statement of Responsibilities must be updated and submitted to the FCA via Connect.

Vendor Oversight Obligations Under SM&CR

Under SM&CR, a firm cannot outsource its accountability. If you engage a relocation vendor, the senior manager responsible for the move remains personally accountable for the vendor’s compliance with the firm’s regulatory requirements.

That means:

  • Due diligence on the vendor before appointment – including their data handling procedures, chain-of-custody protocols, and confidentiality arrangements.

  • A written contract that specifies the firm’s compliance requirements and the vendor’s obligations.

  • Ongoing oversight during the move – not a hands-off delegation.

  • Post-move review of the vendor’s performance against the agreed standards.

This is not bureaucracy for its own sake. It’s the SM&CR framework operating as intended. The senior manager who appointed the vendor is the person who answers to the FCA if something goes wrong.

Our approach to financial services relocations is built around this accountability structure. We provide the documentation, the chain-of-custody protocols, and the compliance-aware methodology that allows the accountable senior manager to demonstrate genuine oversight – not just a signed contract. Speak to our team to understand how we support SM&CR compliance throughout the move.

What Happens When Things Go Wrong

If the move causes a service disruption that exceeds an impact tolerance, or if a data breach occurs during transit, the SM&CR accountability chain becomes immediately relevant.

The accountable senior manager must:

  1. Assess the impact – does the disruption trigger a regulatory notification obligation?

  2. Notify the FCA – under SUP 15, firms must notify the FCA of a significant operational incident without undue delay. If the disruption affects an important business service, that notification is likely required.

  3. Notify the ICO – if the disruption involves a personal data breach, UK GDPR Article 33 requires notification to the Information Commissioner’s Office within 72 hours of becoming aware of the breach.

  4. Document the incident – the incident log, the impact assessment, the remediation steps, and the lessons learned all form part of the post-move audit pack.

  5. Update the BCP – if the incident revealed a gap in the business continuity arrangements, that gap must be addressed before the firm’s next operational resilience self-assessment.

The firms that handle incidents well are the ones that had the documentation in place before anything went wrong. The audit trail is not just about demonstrating compliance – it’s about being able to respond quickly and credibly when the FCA asks questions.

Physical Logistics That Carry Regulatory Risk

The compliance obligations of a financial services office move are not abstract. They attach to very specific physical activities – the things that happen on the day.

Trading Floor Continuity

For investment firms, banks, and brokers with active trading operations, the trading floor is the highest-risk element of the physical move. A trading floor cannot simply be taken offline for a weekend.

The standard approach is a phased migration – moving desks and workstations in tranches, maintaining a live trading capability throughout. This requires:

  • A detailed seat-by-seat migration plan, sequenced to maintain minimum viable trading capacity at all times.

  • Pre-tested connectivity at the new premises before any trading infrastructure is moved.

  • A tested rollback plan in case connectivity at the new premises fails.

  • Real-time monitoring of trading system availability throughout the migration.

For a headquarters relocation that includes a trading floor, the planning complexity is significant. We’ve managed this type of move before – the methodology is available to discuss with our team.

Secure Handling of Physical Client Records and Confidential Documents

We covered chain of custody in the audit trail section. The physical logistics deserve equal attention.

Every box of client records should be:

  • Packed by authorised personnel only – not by general removal staff.

  • Sealed with tamper-evident tape before it leaves the packing area.

  • Labelled with a unique identifier that corresponds to the chain-of-custody log.

  • Loaded into a dedicated, locked vehicle – not mixed with general office furniture.

  • Transported directly to the new premises – no intermediate stops, no overnight storage in an unsecured location.

If the move requires temporary storage of client records – for example, because the new premises isn’t ready to receive them – that storage must be in a secure, access-controlled facility, with the chain of custody maintained throughout.

For firms with particularly sensitive records – trading records, client portfolios, complaint files under regulatory review – consider a specialist secure document transfer service rather than integrating records into the general move.

CCTV, Access Control, and Physical Security During Transit

The FCA’s expectations around physical security are not codified in a single rule, but they flow from the general obligation to maintain appropriate controls over client data and firm assets. During a move, those controls are at their most vulnerable.

Before the move:

  • Confirm that CCTV coverage at the new premises is operational before any assets arrive.

  • Confirm that access control systems at the new premises are configured and tested.

  • Brief all removal staff on the firm’s security protocols – including the prohibition on photographing or recording in areas where client data is visible.

During the move:

  • Maintain a log of everyone who enters and exits both premises throughout the move.

  • Ensure that no client data is left unattended or visible in common areas, loading bays, or vehicles.

  • Confirm that the old premises is fully cleared and access-controlled before handing back keys.

After the move:

  • Confirm that CCTV footage from the move day is retained for the firm’s standard retention period.

  • Confirm that access control logs from both premises are retained as part of the move audit pack.

Temporary Workspace and Remote Working Obligations

For moves that span multiple days, or where staff cannot access either premises during the transition, temporary workspace and remote working arrangements carry their own compliance obligations.

Remote working arrangements for regulated staff must comply with the firm’s existing remote working policy – including requirements around secure network access, screen privacy, and the prohibition on processing client data on personal devices.

If the move requires staff to work from temporary premises – a serviced office, a co-working space, or a hotel meeting room – the firm must satisfy itself that those premises meet its physical security and data protection standards. A co-working space with open-plan seating is not an appropriate environment for processing confidential client data.

Document the temporary arrangements, the controls applied, and the duration. That documentation is part of the move audit pack.

Step-by-Step Regulatory Compliance Timeline for a Financial Services Move

The following timeline assumes a 12-week lead time – the minimum we’d recommend for a financial services firm of any significant size. Larger firms or those with complex trading operations should plan for 16–20 weeks.

For a more detailed look at the overall planning process, our office relocation planning timeline guide covers the full project lifecycle.

12-Week Pre-Move Checklist

Weeks 12–10: Governance and Regulatory Preparation

  • Identify and document the accountable senior manager (SMF) for the move.

  • Update the relevant Statement(s) of Responsibilities if required.

  • Conduct an IBS mapping review – identify all important business services with a physical premises dependency.

  • Review impact tolerances for each affected IBS.

  • Appoint a relocation vendor – conduct SM&CR-compliant due diligence (see Section 8).

  • Submit the FCA Connect notification of change of principal place of business.

  • Notify the PRA (if dual-regulated).

  • Notify Companies House of registered office change (if applicable).

Weeks 9–7: Business Continuity and IT Planning

  • Update the BCP to cover the move period explicitly.

  • Obtain board (or board committee) approval of the updated BCP.

  • Commission IT infrastructure assessment at the new premises.

  • Develop the IT cutover plan, including system-by-system availability requirements and rollback procedures.

  • Identify any systems that require a planned outage window and confirm that window is within impact tolerances.

  • Brief the IT team on the chain-of-custody requirements for hardware.

Weeks 6–4: Physical Logistics and Records Management

  • Conduct a full inventory of physical client records and confidential documents.

  • Assign unique identifiers to all records containers.

  • Confirm secure transit arrangements with the relocation vendor.

  • Confirm temporary storage arrangements (if required) and their security credentials.

  • Brief all staff on the move-day protocols, including the prohibition on personal photography in data-visible areas.

  • Confirm CCTV and access control readiness at the new premises.

Weeks 3–1: Final Checks and Dry Runs

  • Conduct a connectivity test at the new premises for all critical systems.

  • Run a tabletop exercise simulating a move-day IT failure – confirm that rollback procedures work.

  • Confirm that the FCA Register update is scheduled for the move date.

  • Confirm that all vendor contracts include the firm’s compliance requirements.

  • Distribute the move-day protocol to all staff and the relocation vendor.

Move-Day Protocol

On the day itself, the compliance focus is on execution against the plan – and documentation of any deviations.

  • Designated compliance observer present throughout the move, with authority to pause operations if a compliance breach is identified.

  • Real-time chain-of-custody log maintained for all physical records movements.

  • IT cutover log maintained in real-time, with timestamps for each system going offline and coming online.

  • Incident log open and ready – any deviation from the plan is recorded immediately, with the impact assessment and the response.

  • Senior manager available – the accountable SMF should be contactable throughout the move day, even if not physically present.

Post-Move Audit Pack and Sign-Off

Within five business days of the move:

  • Reconcile the chain-of-custody log against the origin and destination manifests.

  • Confirm that the FCA Register reflects the new address.

  • Confirm that all IT systems are operating within their normal parameters.

  • Compile the post-move audit pack (see Section 3 for the full list of contents).

  • Obtain sign-off from the accountable senior manager.

  • File the audit pack in the firm’s regulatory records system.

Within 30 days of the move:

  • Update the IBS mapping to reflect the new premises.

  • Update the BCP to reflect the new premises as the primary site.

  • Conduct a post-move lessons-learned review and document the findings.

  • Update the firm’s operational resilience self-assessment.

Our post-move support team can manage the 30-day close-out process on your behalf, ensuring that the compliance documentation is complete and filed correctly.

Choosing a Relocation Partner That Understands Regulation

Not every removal company is equipped to work in a regulated environment. Most aren’t. The gap between a standard commercial removal and a compliant financial services relocation is significant – and the consequences of choosing the wrong vendor fall on the accountable senior manager, not the vendor.

For a broader look at what to look for when selecting a removal partner, our how to choose the right office relocation vendor guide covers the key criteria in detail.

What to Look for in a Vendor

When evaluating a relocation vendor for a financial services move, the compliance-relevant criteria are:

Chain-of-custody capability. Can the vendor demonstrate a documented, auditable chain-of-custody process for physical records? Do they use unique identifiers, tamper-evident seals, and signed handoff logs? If they can’t show you the process in writing, they don’t have one.

Data protection compliance. Does the vendor have a current Data Processing Agreement? Are their staff trained on UK GDPR obligations? Do they have a documented procedure for reporting a data breach during a move?

Physical security standards. Do their vehicles have GPS tracking and access controls? Do they use dedicated vehicles for sensitive records, or do they mix client records with general office furniture?

Confidentiality protocols. Do they require staff to sign confidentiality agreements? Do they have a policy on personal devices and photography in client-data environments?

Regulatory awareness. Do they understand the FCA’s operational resilience framework? Have they worked with regulated financial services firms before? Can they provide references?

Documentation capability. Can they provide a move-day log, a chain-of-custody report, and a post-move reconciliation report as standard deliverables?

SM&CR compatibility. Can they work within the firm’s SM&CR accountability structure – providing the documentation and oversight evidence that the accountable senior manager needs?

Why Continuum Green

Continuum Green specialises in managed relocations for regulated and complex environments. We’ve worked with financial services firms, NHS trusts, government bodies, and research institutions – environments where the compliance stakes are high and the margin for error is low.

Our financial services office move methodology is built around the FCA’s operational resilience framework and the SM&CR accountability structure. We don’t just move furniture. We provide:

  • A documented chain-of-custody process for all physical records, from pre-move inventory to post-move reconciliation.

  • Real-time move-day logging, with a compliance observer embedded in the move team.

  • IT relocation support that integrates with your IT cutover plan and maintains the system availability documentation your audit trail requires.

  • Post-move documentation – the chain-of-custody report, the IT continuity log, and the compliance sign-off pack – delivered within five business days.

  • A named account manager who understands the regulatory context and can support the accountable senior manager throughout the process.

We also offer commercial relocation, laboratory relocation, NHS relocation, and executive relocation services – all delivered to the same standard of documentation and accountability.

No hand-offs. No confusion. One team, one audit trail, one point of accountability.

If you’re planning a financial services office move and want to understand how we can support your FCA compliance obligations, get a quote today.

For a detailed breakdown of what a managed financial services relocation costs, our true cost of an office move guide is a useful starting point.

And if you want a deeper dive into the compliance framework specifically, our financial services relocation compliance guide covers the regulatory landscape in full.

FAQ – Financial Services Office Move Compliance

Do I need to notify the FCA before moving office?

Yes. Under SUP 15 of the FCA Handbook, firms must give reasonable advance notice of a change to their principal place of business in the UK. The notification is submitted through the FCA’s Connect portal and must include the new address and the effective date of the change. For dual-regulated firms, the PRA must also be notified separately. Notifying one regulator does not satisfy the obligation to the other. Failure to notify before the move – rather than after – is itself a breach of the Handbook.

What records must I keep for an FCA audit trail during a move?

The audit trail should cover four areas: pre-move regulatory notifications (Connect submission, acknowledgement, FCA Register update); chain of custody for all physical client records and confidential documents (pre-move inventory, signed handoff logs, tamper-evident seals, arrival reconciliation); IT and data continuity documentation (asset register, cutover log, incident log, rollback records); and post-move sign-off (updated BCP, updated IBS mapping, senior manager sign-off). The complete audit pack should be retained for at least five years under SYSC 9.

Who is responsible under SM&CR for an office relocation?

The accountable senior manager is typically the Chief Operations function (SMF24), though in some firms it falls to the CEO (SMF1) or another SMF depending on the firm’s governance structure. The key requirement is that ownership is documented in the relevant Statement of Responsibilities before the move begins. If the move changes the scope of any senior manager’s responsibilities – for example, by introducing new third-party arrangements – the Statement of Responsibilities must be updated and submitted to the FCA. SM&CR accountability cannot be delegated to a vendor: the named senior manager remains personally accountable for the vendor’s compliance with the firm’s regulatory requirements.

How do I maintain operational resilience during a physical move?

Start by reviewing your IBS mapping and identifying every important business service with a physical premises dependency. For each one, confirm that your impact tolerance can be maintained throughout the move window – including any planned outage periods for IT systems. Update your BCP to cover the move period explicitly, and obtain board approval of the updated plan before the move date. For services that cannot tolerate any planned downtime – trading operations, payment processing – design the move schedule around the service requirements, not the other way around. Run a tabletop exercise simulating a move-day failure before the move date, and confirm that your rollback procedures work.

Can a financial services firm use a standard removals company?

Technically, there is no FCA rule that prohibits it. In practice, it creates significant compliance risk. A standard removals company will not have a documented chain-of-custody process for physical records, will not have staff trained on UK GDPR obligations in a financial services context, and will not be able to provide the compliance documentation that the accountable senior manager needs for the audit trail. Under SM&CR, the senior manager who appoints the vendor remains personally accountable for the vendor’s compliance with the firm’s regulatory requirements. Appointing a vendor without the capability to meet those requirements is a governance failure – regardless of what the contract says.

What happens if our move causes a service disruption?

If the disruption exceeds an impact tolerance for an important business service, the firm must assess whether it triggers a regulatory notification obligation under SUP 15. If it does, the FCA must be notified without undue delay. If the disruption involves a personal data breach, the ICO must be notified within 72 hours under UK GDPR Article 33. In both cases, the quality of the firm’s documentation – the incident log, the impact assessment, the remediation steps – will significantly affect how the regulator responds. Firms with a complete audit trail and a clear chain of accountability are in a materially better position than those without one.

Plan the Move. Protect the Firm.

A financial services office move is one of the most complex operational events a regulated firm can undertake. The regulatory framework – FCA PS21/3, SM&CR, SUP 15, UK GDPR – doesn’t pause for a removal van. Every obligation continues. Every accountability remains. The audit trail starts the moment you sign the new lease.

The firms that get this right are the ones that treat the move as a compliance programme from day one – not a logistics project with a compliance checklist bolted on at the end. They name the accountable senior manager early. They notify the FCA before the move, not after. They build the chain of custody into the removal methodology. They update the BCP and get board sign-off before moving day. And they choose a relocation partner who understands the regulatory environment they’re operating in.

That’s exactly what we do at Continuum Green. Our managed financial services relocation service is built around the FCA’s operational resilience framework and the SM&CR accountability structure. We provide the documentation, the chain-of-custody protocols, the IT continuity support, and the post-move audit pack that your compliance team needs – and that the FCA expects.

No surprises. No gaps. No excuses.

If you’re planning a financial services office move and want a relocation partner who understands what FCA compliance actually requires, get a quote from our team today. We’ll walk you through our methodology, answer your compliance questions, and give you a clear picture of what a fully managed, audit-trail-ready relocation looks like in practice.

Useful Sources

SHARE POST