Vulnerability Data: The Compliance Risk Firms Cannot Ignore
10/2/20262 min read
Identifying customer vulnerability is firmly embedded within Consumer Duty.
But there is another question firms need to answer just as carefully:
What are we doing with the information once we have it?
In March 2026, the FCA and ICO issued a joint statement on firms’ use of vulnerability-related data, making the point clear: firms need to support customers in vulnerable circumstances while also using personal information lawfully, fairly and responsibly.
That creates a very real compliance challenge.
Recording vulnerability is not the end of the process
Many firms have improved how they identify vulnerability.
Staff are trained to listen for indicators. Systems may contain flags. Customer journeys increasingly include prompts around additional support.
But simply capturing information does not demonstrate good outcomes.
Compliance teams should be asking:
· What information are we recording?
· Why do we need it?
· Who can access it?
· How long are we retaining it?
· Does it actually change how the customer is supported?
· Are customers in vulnerable circumstances receiving comparable outcomes?
The FCA’s latest review of payments firms found positive examples, but also identified room for improvement in how firms identify vulnerability, monitor outcomes and provide appropriate support.
More data is not necessarily better data
There can be a temptation to collect as much information as possible “just in case”.
That creates its own risk.
A firm does not necessarily need a detailed medical history to understand that a customer requires additional time, an alternative communication method or support from a third party.
The compliance question should therefore move from:
“Can we record this?”
to:
“What information do we genuinely need in order to deliver the right outcome?”
That distinction matters.
The real issue is whether the information changes the outcome
A vulnerability flag that sits on a system but changes nothing in the customer journey has limited value.
If a customer discloses a vulnerability, the business should understand what happens next.
Does the information follow the customer through different channels?
Can frontline staff see what support is required without forcing the customer to repeat themselves?
Are vulnerable customers abandoning journeys more frequently?
Are they experiencing longer resolution times, higher complaint rates or poorer service outcomes?
Those are Consumer Duty questions as much as they are operational ones.
The FCA continues to emphasise that firms should understand customers’ actual experiences and use outcomes monitoring to identify emerging harm.
Compliance needs to join the dots
This is not purely a Conduct Risk issue.
It cuts across:
Consumer Duty. Data Protection. Vulnerable Customers. Operational Processes. Training. Systems. MI.
That is why vulnerability frameworks should not be designed in isolation.
Compliance, Data Protection, Operations and Customer Service need to understand how information moves through the business — from disclosure through to support, monitoring and eventual deletion.
The strongest framework is not the one that records the most vulnerability data.
It is the one that can demonstrate:
we identified the customer’s needs, recorded only what was necessary, used the information appropriately and delivered a better outcome as a result.
That is the standard firms should be working towards.
Building the future, building success
Eazycrest Recruitment is a trading name of EAZ Career Ltd.
EAZ Career Ltd is registered in England and Wales under company number 14394668.
VAT Registration No. 425 6499 69.
© 2026 EAZ Career Ltd. All rights reserved.
GET IN TOUCH
QUICK LINKS
The Eazycrest Way


45 Albemarle Street
Mayfair
London
W1S 4JL
