2026 is the year regulatory standards stop being written and start being tested. For three years, regulated firms have built the frameworks and written the policies; now regulatory supervisors are asking whether people can apply them under pressure, and whether it can be evidenced. The capability you build before year-end is what answers that question.
The build phase is over. The examination has started.
For three years, regulated firms have been building. Frameworks written, policies approved, board packs assembled. By 2026 that work is largely done, and the regulatory question has changed with it. Regulatory supervisors are no longer asking whether a framework exists. They are asking whether your people can apply it under pressure, and whether you can show that they did. Regulatory exposure rarely comes from a missing policy. It comes from how standards hold up under uncertainty, time pressure and competing commercial priorities, and that is written into the calendar of four regimes at once.
Operational resilience is the clearest case. The UK transitional period closed in March 2025, so firms must now stay within their impact tolerances for important business services in severe but plausible scenarios, and evidence it. DORA reached full application in January 2025, which makes 2026 the first complete regulatory supervisory cycle for its testing, incident-reporting and ICT third-party requirements. The registers and tolerances are filed. The open question is whether they hold when something breaks.
Consumer Duty has moved along the same path. Implementation is behind firms; outcomes are in front of them. The FCA wants evidence of good outcomes in the annual board report, in price and value assessments, in the removal of sludge, not a description of the processes meant to produce them. AI sits earlier on the curve but is moving fast: the EU AI Act’s high-risk obligations take effect in August 2026, UK regulators are pressing on who is accountable when an automated system makes a decision, and AI-enabled fraud is already a live operational threat, not a forecast.
The sharpest change is the one firms least expect to be a regulatory matter. Since October 2024 the Worker Protection Act has placed an anticipatory duty on employers to take reasonable steps to prevent sexual harassment, before it occurs and not only after a complaint. The FCA has gone further, bringing serious non-financial misconduct within the conduct rules, so bullying and harassment now bear on fitness and propriety. In the high-pressure, historically male-dominated environment of a trading floor, culture is no longer an HR concern running alongside compliance. It is compliance. ZISHI examines this directly in a recent Financial Currents podcast episode with an employment law specialist and tracks the wider landscape in Advice Matters, its accredited CPD publication.
Across all four, the common thread is not a gap in documentation. It is whether people make sound decisions, escalate with discipline and leave a defensible record when the standard is tested in real conditions. That is a capability question, and capability is built, not bought. More can be delivered before year-end than most teams assume: practitioner-led interventions on the themes already on your risk register, configured to your operating model rather than built from scratch, led by people who have sat on the other side of regulatory supervisory engagement.
Want capability your people can use, and you can evidence, before the budget year closes?
Contact us on info@thezishi.com to arrange a scoping conversation about Regulation & Compliance programmes deployable before year-end.
The 2026 Capability Questions Boards Will Ask
The following ten questions are designed to help assess whether your organisation is prepared for that conversation.