← View all articles
Senior FCA Official Urges Financial Firms to Use ECCTA Information-Sharing Powers
UK Compliance 4 min read By CommsPliant Editorial Team Published 17 August 2026 Updated 31 August 2026

Senior FCA Official Urges Financial Firms to Use ECCTA Information-Sharing Powers

Listen to the audio briefing

A short audio version of this article for busy compliance, operations and product teams.

As firms are encouraged to share more financial-crime intelligence, government guidance also puts audit trails, decision records and secure handling firmly in the operational picture.

A senior Financial Conduct Authority official is urging financial services firms to make greater use of the information-sharing powers introduced under the Economic Crime and Corporate Transparency Act (ECCTA), arguing that individual institutions typically see only a fragment of the wider financial-crime picture.

Beth Harris, an FCA Head of Department, set out the regulator's position in a LinkedIn article published on 12 August 2026, later reported by AML Intelligence on 13 August. Harris said the ECCTA's information-sharing provisions are supported by the FCA because they give firms a clearer route to share intelligence that helps prevent, detect and investigate financial crime. Her message to firms was direct: "Responsible information sharing is not just a regulatory opportunity. It is a necessity."

What ECCTA allows firms to do

ECCTA gives AML-regulated firms legal protection from confidentiality and civil-liability claims when they share customer information with one another for the purpose of preventing, detecting or investigating economic crime, either directly, firm to firm, or indirectly through a third-party intermediary.

Firms can rely on this protection under two conditions: a "warning condition", where a firm has taken, or would have taken, safeguarding action against a customer over economic-crime concerns, or a "request condition", where a firm believes another regulated firm holds relevant information about a customer.

Importantly, the protection doesn't extend to UK GDPR. Firms sharing personal data still need a lawful basis for doing so, and the measures don't override existing data protection obligations.

p class="isSelectedEnd">The regulator's encouragement lands against a backdrop of patchy but improving take-up.

In a call for evidence published in March 2026, the Home Office reported anecdotal feedback that use of the direct sharing power, particularly the warning condition, is increasing as firms become more familiar with the legislation. Use of the indirect sharing power, by contrast, remains low.

Where firms are sharing information, the government's feedback points to something more interesting than a simple adoption gap: firms are taking different approaches to how shared data is formatted and standardised, and to which mechanisms they use to exchange it.

The result, according to the Home Office, is an inconsistent approach across industry, with firms using different formats, standards and mechanisms to exchange information.

The operational question: can the decision be reconstructed later?

A legal gateway answers whether information may be shared in particular circumstances. It doesn't remove the operational work that sits around that decision.

For each sharing event, a firm may still need to be able to establish: what information was shared; why the warning or request condition applied; who made or reviewed the decision; what handling restrictions were attached; when the information moved; and what record remains afterwards.

This isn't a hypothetical concern.

The government's own guidance on the ECCTA measures already encourages both sending and receiving firms to keep an audit trail of everything shared and to record key decision points, partly to support assurance work and partly to help firms handle any complaints or redress that follow.

More sharing does not mean less control

The direction of travel from regulators is becoming clearer: financial-crime intelligence is more useful when firms can connect information across organisational boundaries, and the FCA's latest intervention adds weight to that push.

But as information-sharing becomes more routine, the operational controls around those exchanges matter more, not less.

For firms, the practical challenge may increasingly sit not only in determining whether information can be shared under the ECCTA framework, but in whether the organisation can later demonstrate what was shared, under what process, and how the decision was governed.


What happened: FCA Head of Department Beth Harris urged financial services firms to make greater use of ECCTA's information-sharing powers.

When: Harris's LinkedIn article was published 12 August 2026; AML Intelligence reported it on 13 August 2026.

Who is affected: AML-regulated firms using, or considering using, ECCTA's direct or indirect information-sharing provisions.

Why it matters: Government feedback from March 2026 suggests direct sharing is increasing, but firms differ in how they format, standardise and route shared information. Official guidance already encourages firms to keep audit trails and record key decision points as adoption grows.

Operational control matters beyond the regulation itself.

If version control, approvals and audit evidence for regulated customer communications are gaps in your current process, see how CommsPliant brings them into one governed workflow.

Book a discovery call

This article is for general information only and does not constitute legal or regulatory advice.

Sources