Skip to content

Consumer Duty and Distribution Chains: What the FCA’s New Consultation Means for Your Business

The CP26/23 consultation paper from the FCA aims to bring clarity to applying rules across complex distribution chains. This could reshape how responsibilities are assessed, documented and monitored for payment and e-money firms operating away from the end customer.  

Where does Consumer Duty responsibility actually end for firms far down a distribution chain? 

The FCA has proposed an answer, a formal consultation setting out exactly where it considers the Duty should apply. In June 2026, the FCA published CP26/23, a consultation proposing targeted changes to how the Duty applies across distribution chains, particularly for firms whose role is indirect, or several steps removed from the end retail customer. The consultation runs until 18th September 2026, with a policy statement expected in Q1 2027.

The proposals go well beyond firms with direct customer relationships. Under the current rules, the Duty already extends to every firm in a distribution chain, including manufacturers, distributors, and anyone in between. This means any firm whose activities can determine or materially influence retail customers and the outcomes they receive. CP26/23 does not remove the principle, but tries to draw a clearer, more proportionate line around who is captured within it

Why is This Important?

Currently, the Duty applies across the full distribution chain, from product origination through to distribution and post-sale support. Any firm involved in manufacturing, providing, selling, or administering a product for a retail customer needs to consider whether it is in scope. This is judged by the impact a firm has on the retail end user, not by its position in the chain or what its contractual arrangements say. The consumer outcome is what determines this, not the contractual position underpinning it. 

From conversations that we at Thistle have had with firms, it is clear that a number have told the FCA that it is hard to apply the Duty consistently, especially where several parties contribute to one product or a firm's role is wholesale-facing and only indirectly connected to a retail outcome. Three changes in CP26/23 respond directly to this:

1. A Clearer Manufacturer Split

Where more than one firm contributes to building a product, the FCA is replacing “co-manufacturer” with a principal manufacturer and secondary manufacturer distinction. The principal manufacturer has substantive control over the product's design, operation, distribution strategy, or value proposition; secondary manufacturers get lighter-touch obligations focused on ensuring their contribution does not create material risk of harm, rather than the full set of products, price and value rules.

2. A Narrower Perimeter

Several activities are proposed for exclusion where they sit too far from the retail customer to meaningfully influence outcomes. Notably for payments and e-money firms, where a credit institution’s role is limited to safeguarding relevant funds for APIs, EMIs, or e-money-issuing Credit Unions, this is now framed as infrastructure behind the product and would fall outside the scope of Duty entirely, a real shift from FG22/5, which treated the safeguarding institution as a potential chain participant. This aligns with the FCA’s broader regulatory approach. Safeguarding is now subject to its own dedicated prudential regime under CASS 15, effective since 7th May 2026, which the FCA appears to regard as sufficient protection, removing the need for separate coverage under the Duty.

3. Proportionate Responsibility, Not Policing

CP26/23 proposes that firms are responsible for their own roles and activities only and need not oversee other firms’ compliance unless regulation or contract requires it. Firms can also reasonably rely on information from others in the chain, though not where there is a clear sign something is going wrong. CP26/23 illustrates this with a worked example: a firm that spots a problem through its monitoring of a distribution partner is expected to investigate whether the cause lies within its own control or the partners’, then act and feedback accordingly, rather than simply escalating it or stepping back. The same applies to customer support, a firm without its own support channels isn't responsible for that outcome directly but must still respond to a distribution partner’s requests promptly enough for that partner to support the customer. For EMI and API firms, this monitoring discipline runs alongside the operational resilience obligations covered below, including downtime against important business services and the quality of customer support.

A Distinction EMI and API Firms Need to Hold Onto

The monitoring discipline looks slightly different for firms in payments. Using safeguarding and money remittance as an example, outsourced providers contributing to the infrastructure behind the product are only caught by the Duty if something materially goes wrong, rather than by virtue of their role alone. For most remittance and FX EMIs and APIs, the firm is usually both manufacturer and distributor of its own product, with no separate “distributor” unless agents or white-label partners are involved. The safeguarding provider is being taken out of the distribution chain picture, and IT outsourcers were never really part of it. Neither is irrelevant to the Duty, though an outage or safeguarding disruption that stops a customer sending money or accessing funds is still a customer outcome problem, whatever regulatory category the provider sits in. FG22/5 makes this point with a payments example, citing a firm whose only support channel, an unresponsive chat function, had no fallback for a digital outage. A distribution chain map and an outsourcing or dependency map sit under different rulebooks (Consumer Duty on one side, SYSC 8 and SYSC 15A on the other), but a failure in either still lands on the same customer.

Preparatory Work Firms Should Consider Doing Now

1. Map the Firm's Actual Role in Each Distribution Chain, Product by Product:

For every product or service, work out whether the firm is the principal manufacturer, a secondary manufacturer, a distributor, or performing more than one of these roles at once, and check whether it might now fall under one of the proposed exclusions, such as the ‘safeguarding’ carve-out. The FCA judges this by what the firm actually does in practice, not by contractual labels, so this needs a genuine operational review involving the teams who run the product day to day, not a desk-based document exercise. The output should be a written record the firm can point to, since this is exactly what CP26/23 expects manufacturer agreements to reflect.

2. Review Manufacturer Agreements

Where a firm contributes to a product jointly with others, the principal manufacturer needs a written agreement covering each party’s role. Firms should start identifying which existing agreements will need revisiting once the rules are finalised. 

3. Reassess Board Reporting Proportionally

The FCA has acknowledged its rules have driven overly detailed reporting in some firms, and wants reporting scaled to a firm’s actual role rather than defaulting to full scope.

4. Revisit Due Diligence and Reliance Practices with Distributing Partners

CP26/23 confirms firms can take a proportionate approach to due diligence and reasonably rely on a partner's information, rather than re-verifying everything independently. That comfort has a limit: firms are still expected to investigate where their own monitoring, such as a pattern of complaints, points to a problem. In practice, this means checking that onboarding due diligence is proportionate rather than duplicative, and that ongoing monitoring can genuinely surface a trend before it becomes material harm.

5. Consider Responding to the Consultation

Especially for firms affected by the safeguarding exclusion or working across multiple manufacturers on one product. This is the window to help shape the final rules. 

6. For EMI and API Firms, Run a Parallel Exercise 

Build a dependency register listing the safeguarding provider, IT and cloud infrastructure, and payment rails, rated by how directly each failure would stop a customer sending or accessing funds. Set and test impact tolerances under Senior Management Arrangements Systems and Controls (SYSC) 15A, strengthen ongoing outsourcing oversight under SYSC 8, and prepare a tested customer communication plan for outages. Firms should also prepare for the new safeguarding rules under PS25/12, effective from 7 May 2026. 

7. Existing Duty Compliance Should Not Be Treated as Settled

Current PRIN 2A obligations remain in force while CP26/23 is under consultation. Firms should treat this period as preparation for prospective change rather than grounds to defer existing requirements.

How Thistle Initiatives Can Help

Thistle Initiatives supports firms assessing the impact of the Consumer Duty changes across the distribution chain, especially payments and e-money firms navigating safeguarding and agent arrangements, with practical, hands-on guidance. This covers advising on a firm’s actual role under the Duty, strengthening manufacturer agreements, and internal governance. Our team brings together FCA and compliance expertise to help clients navigate these developments as they take shape. Firms looking to review their distribution chains or prepare a consultation response are welcome to get in touch.


Meet the Expert

Vridhi Mathur - square 1920 (1)

Vridhi Mathur, Consultant  

Vridhi is a Payment Services and Compliance Consultant at Thistle Initiatives, specialising in UK regulatory compliance, FCA authorisations and safeguarding frameworks for payment institutions and e-money firms. With a background in financial law and regulatory change, she helps businesses achieve and maintain FCA compliance, streamline authorisation processes and embed effective governance structures.