← View all articles
When the Evidence Disappears, Oversight Disappears With It
Insights Compliance 4 min read By CommsPliant Editorial Team Published 6 September 2026

When the Evidence Disappears, Oversight Disappears With It

An adviser carries out regulated work they are not qualified or permitted to perform.

The firm responsible for oversight receives misleading information about that work.

The FCA also says client records were destroyed.

The problem is no longer limited to the original advice. It raises a wider question: what reliable evidence was available to support oversight and any later investigation?

What happened?

On 3 September 2026, the Financial Conduct Authority announced that it had decided to ban former financial adviser Daniel Thomas from working in financial services and fine him £742,700.

According to the FCA, Mr Thomas advised 53 clients on 63 transfers out of defined benefit pension schemes over five years, despite not holding the specialist qualification or permission required for that work. The FCA believes he earned more than £173,000 in fees from the transfer advice.

The FCA also states that he misled clients and pension providers about his qualifications, destroyed client records and failed to cooperate with its investigation.

His firm, DPT Financial Solutions Limited, operated as an appointed representative. This meant a principal firm was responsible for overseeing its regulated activities. According to the FCA, Mr Thomas also provided misleading information to the principal about his involvement in the pension transfer cases.

Mr Thomas has referred the Decision Notice to the Upper Tribunal. The findings are therefore provisional, and the FCA will take no action until the Tribunal has reached its decision. The FCA has also expressly stated that it made no findings against the principal firm in connection with this matter.

The operational failure behind the headline

The headline is about unauthorised pension transfer advice. The deeper operational issue is the separation between responsibility, visibility and evidence.

A principal may be responsible for oversight. But responsibility alone does not create visibility.

If oversight depends mainly on an individual accurately declaring what work they performed, the control is vulnerable to the very person it is meant to supervise. If supporting records can also be removed without leaving a reliable trace, the investigation begins with gaps instead of evidence.

This does not mean that a system can prevent every deliberate act of misconduct. It cannot. Nor can technology determine whether pension transfer advice was suitable or replace qualified supervision.

But operational controls can make clear:

Without those controls, oversight risks becoming a retrospective exercise: asking people what happened after the evidence has already become incomplete.

Record retention is not the same as record integrity

A firm may have a retention policy and still struggle to reconstruct what happened.

Keeping a document somewhere is not enough if the organisation cannot show whether it is complete, whether it changed, who controlled it or whether something else previously existed in its place.

Record integrity requires more than storage. It requires a reliable history around the record.

Storage is not control. A stored file does not, by itself, show which version was approved, who approved it, whether it later changed or whether another record previously existed in its place.

This is the role of CommsPliant's Evidence Vault: to connect a customer or communication reference with the approved version, approval and update history, rendering timestamp and a tamper-evident hash. This helps teams retrieve and reconstruct the evidence trail associated with a communication without treating storage alone as proof.

For regulated communications, that may include the approved wording, the version used, the people involved in the workflow, the relevant timestamps and evidence of any later change. Access and deletion controls should also prevent the same person from quietly removing the evidence of their own actions.

The purpose is not to retain everything without limit. It is to preserve the right evidence under a defined retention policy, with deletion itself governed and traceable.

Questions worth asking

This case raises practical questions for any regulated organisation that oversees advisers, appointed representatives, contractors or other distributed teams:

  1. Can we prove that a person was qualified and authorised for the activity they performed?
  2. Can the oversight team see relevant activity without relying entirely on self-reporting?
  3. Would the removal of an important record create a visible event or exception?
  4. Can we reconstruct which communication was approved and which version reached the customer?
  5. Are responsibility and system permissions aligned, or do they exist only in policy documents?

These are not simply questions for an investigation. They are questions to test while the process is operating normally.

Oversight must be demonstrable

The strongest oversight model is not one that assumes every participant will always provide a complete account.

It is one that creates independent evidence as work happens.

That means connecting permissions, review, approval, version history and record controls instead of leaving them across separate inboxes, spreadsheets, shared folders and individual accounts.

Oversight is not just knowing who was responsible.

It is being able to see what happened, restrict what should not happen and produce reliable evidence afterwards.

Register Interest

Book a Discovery Call

This article is for general information only and does not constitute legal or regulatory advice.

Sources