Regulation & Compliance

The Compliance Stack: How Rules, Standards, Codes and Guidance Actually Bind

By Jonas Osman Abdelghafour · August 2026

As at August 2026. General commentary, not legal advice. The binding status of specific instruments should be confirmed with counsel for the matter at hand.

Financial services compliance framework layers are routinely flattened in practice: firms speak of "the rules" as if statute, regulatory rulebooks, professional standards and supervisory guidance were one substance. They are not, and the differences - in who enforces them, what discharge looks like, and what happens when they conflict - decide real cases. A working model has four layers, and the interesting compliance failures almost all happen between them.

The four layers

Layer one: statute and retained law. Acts of Parliament, US federal and state statutes, and directly applicable retained rules. Breach is unlawfulness; interpretation belongs ultimately to courts. Statute is sparse but sovereign - and when a court reads it unexpectedly, everything below reorganises. The recent UK pensions experience is the clean example: litigation over section 37 confirmation requirements for scheme amendments - the Virgin Media line of cases - held that historical amendments lacking the required actuarial confirmation could be void, throwing decades of scheme practice into doubt until legislative-and-regulatory follow-up, including 2026 guidance on retrospective confirmation, restored a workable position. A statutory formality outranked years of accepted professional practice, exactly as the layer model predicts.

Layer two: regulator rules and supervisory instruments. FCA and PRA handbooks and supervisory statements; in the US, agency regulations, and below them supervisory letters and bulletins. This layer contains its own gradient: handbook rules bind; supervisory statements set expectations whose breach invites supervisory consequence rather than automatic unlawfulness; US interagency guidance - including the model risk guidance I compare across jurisdictions elsewhere - formally disclaims the force of law while functioning, through examination, as near-mandatory. Treating "binding" as binary misreads this layer; the operative question is what enforcement path attaches.

Layer three: professional standards. FRC technical actuarial standards, the Actuaries' Code, US Actuarial Standards of Practice and Qualification Standards, audit standards. These bind persons rather than firms: enforcement runs through professional discipline and, indirectly, through regulators' reliance on professional sign-off. Their reach is defined by the work, not the employer - which is why they catch activity that firm-level rulebooks miss, a point developed in my article on actuarial regulation UK vs USA.

Layer four: guidance, codes and expectations. Regulator "Dear CEO" letters, thematic review findings, industry codes, Q&A material. Formally non-binding; practically the layer supervisors quote back to you. Its force is evidential - it defines what "reasonable steps" and "good practice" mean when layers one to three are applied to your facts.

The failure modes between layers

Assuming bindingness flows downward intact. Firms build controls to guidance while missing a statutory formality - the Virgin Media pattern. Layer four diligence does not cure a layer one defect.

Assuming safety flows upward. Complying with statute while ignoring guidance leaves you lawful and still supervisorily exposed: "not unlawful" has never closed an FCA or examiner finding.

Conflict between layers. A professional standard may demand disclosure a client resists; a US actuary's ASOP obligations may exceed what state filing law requires; a UK senior manager's reasonable-steps defence may require more than handbook minimum. The professional's answer is generally that the stricter obligation governs their signature - and firms that plan for this, rather than discovering it in the room, keep their professionals and their filings aligned.

Jurisdictional interleaving. The stack composes differently across borders. One example with teeth: legal professional privilege. Internal compliance investigations conducted under legal advice sit differently in UK and US law - who counts as the "client," what preparatory material is protected, and what regulators can compel differ enough that a document freely created in one jurisdiction becomes discoverable leverage in the other. Cross-border investigation protocols are a compliance-stack question, not just a legal one.

Running the stack deliberately

Three disciplines make the model operational. Classify obligations at intake: every requirement entering the compliance inventory tagged by layer, enforcement path and the persons or entities it binds - an afternoon's metadata that changes how conflicts surface. Trace each material control upward: which layer does this control discharge, and is anything above it undischarged? Controls that exist only to satisfy layer four deserve to know that about themselves. Rehearse the conflicts: the professional-versus-commercial collision, the guidance-versus-statute gap, the cross-border privilege question - each has a better answer at policy time than at incident time.

The compliance stack is not a bureaucratic taxonomy; it is a prediction machine. It tells you which instrument wins when they collide, which failures are survivable and which are void-from-the-beginning, and where the next Virgin Media-shaped surprise can come from: always from a high layer everyone had stopped reading, because the lower layers felt like the whole of the law.

Key Takeaways

Frequently Asked Questions

What is the difference between rules and guidance in financial services? Rules - statutes and regulator rulebook provisions - create enforceable obligations whose breach is unlawful or directly actionable. Guidance and supervisory statements set expectations: formally non-binding, but supervisors use them to judge whether conduct was reasonable, so ignoring them creates supervisory risk even where conduct remains lawful.

Are supervisory statements legally binding? Not in the strict sense: instruments such as PRA supervisory statements and US interagency guidance typically disclaim the force of law. In practice they define supervisory expectations, and departures invite findings, remediation demands and consequences for individual accountability assessments - a distinct enforcement path from statutory breach.

Why did the Virgin Media pension case matter for compliance frameworks? Because it demonstrated a statutory formality overriding decades of professional practice: scheme amendments made without the required actuarial confirmation could be void regardless of how carefully lower-layer processes were followed. It is the clearest recent illustration that diligence at the guidance layer cannot cure a defect at the statutory layer.

Related reading

About the author

Jonas Osman Abdelghafour is a UK-based actuary and financial engineer specialising in quantitative risk management, reinsurance pricing, catastrophe bond structuring and stochastic modelling. Learn more about Jonas or get in touch.