# Protecting the customer: conduct and fair treatment
In 2023, a UK bank refunded thousands of customers after charging them fees for a "packaged account" (a current account bundled with insurance and perks) they never used or could not benefit from. The trigger was not a lawsuit. It was a regulator asking a simple question: was this fair? That question, applied at scale, now shapes what banks can charge, how they must disclose it, and when they must pay money back.
This lesson covers the rules that police bank conduct: the FCA's Consumer Duty in the UK, Regulation E in the US, and the deposit insurance schemes (FDIC and FSCS) that protect balances when a bank fails. These are not abstract. They dictate refunds, disclosures, and penalties in daily banking operations.
Prudential regulation asks: is the bank safe? Conduct regulation asks a different question: is the bank treating customers fairly? A bank can be perfectly solvent and still harm customers by mis-selling products, hiding fees, or dragging its feet on fraud refunds.
The classic cautionary tale is the UK's Payment Protection Insurance (PPI) scandal. Banks sold insurance alongside loans, often to people who could never claim on it. The eventual redress bill across the industry exceeded 38 billion pounds (widely cited estimate, paid out over roughly a decade). That single episode reshaped how UK regulators think about product design and sales.
The Financial Conduct Authority (FCA) is the UK's conduct regulator. In July 2023 it introduced the Consumer Duty, a set of rules requiring firms to deliver "good outcomes" for retail customers.
The Duty is built on one overarching principle: a firm must act to deliver good outcomes for retail customers. Underneath sit four outcomes:
The shift is subtle but powerful. Old rules asked "did you disclose it?" The Duty asks "did the customer actually understand, and was the outcome fair?"
Concrete example. A savings account paying a low rate while the bank pushes new customers to a higher rate account can now fail the "price and value" and "consumer understanding" tests. Under Duty, firms must review whether loyal customers are being quietly disadvantaged.
You can read the FCA's own plain summary here: FCA Consumer Duty overview.
Banks must now evidence outcomes, not just process. Compliance teams run "fair value assessments" on products, test whether disclosures are understood, and track complaint resolution times. A product that generates high fees and low usage (like an unused packaged account) is a red flag the Duty forces firms to catch themselves.
The US splits conduct rules across several bodies. The Consumer Financial Protection Bureau (CFPB) and the Federal Reserve oversee key consumer protections. The most operationally important for everyday banking is Regulation E, which implements the Electronic Fund Transfer Act (EFTA).
Reg E governs electronic transactions: debit card payments, ATM withdrawals, direct deposits, and transfers. Its core promise is limiting consumer liability for unauthorized transactions.
The liability tiers (as of 2026, long-standing thresholds):
Worked example. A customer's debit card is stolen. A thief spends 1,200 dollars. If the customer reports within 2 business days, the bank can hold them liable for at most 50 dollars and must refund the rest. If they wait 10 days, the cap rises to 500 dollars. The timing directly drives the refund the bank owes.
Reg E covers *unauthorized* transactions. But what if a customer is tricked into authorizing a payment themselves (an "authorized push payment" scam)? Historically these fell outside Reg E, because the customer technically approved the transfer. This is a live regulatory and political fight in both the US and UK.
The UK has moved faster. Since October 2024, the Payment Systems Regulator (PSR) requires banks to reimburse most victims of authorized push payment (APP) fraud, split between the sending and receiving bank, up to a set cap. This is a major expansion of who pays when a customer is deceived.
🎬 [VIDEO: "How the CFPB Protects Consumers" - youtube.com - a short overview of the US Consumer Financial Protection Bureau's role and enforcement tools]
Conduct rules protect customers during normal operations. Deposit insurance protects them when the bank itself fails.
United States: FDIC. The Federal Deposit Insurance Corporation insures deposits up to 250,000 dollars per depositor, per insured bank, per ownership category (as of 2026). When Silicon Valley Bank failed in March 2023, this cap became front-page news: many startups held far more than 250,000 dollars in a single account. Regulators ultimately invoked a systemic risk exception to protect uninsured deposits, but that was an emergency measure, not the standard rule.
United Kingdom: FSCS. The Financial Services Compensation Scheme protects deposits up to 85,000 pounds per person, per authorised firm (as of 2026). For joint accounts, the protection doubles to 170,000 pounds.
Worked example. A UK customer holds 120,000 pounds at a single bank that fails. The FSCS covers 85,000 pounds. The remaining 35,000 pounds is at risk (they become a creditor in the insolvency and may recover some, or none). The practical lesson banks must communicate: spread large balances across separately authorised institutions.
A subtle trap: two "brands" can share a single banking licence, meaning the 85,000 pound limit applies across both combined, not per brand. Banks are required to disclose which brands share a licence.
You can check protection details at the FSCS official site.
Vérification des acquis
1. What fundamental question distinguishes conduct regulation from prudential regulation?
2. A bank is fully solvent and meets all its capital requirements, yet it bundles unusable insurance into accounts and charges customers who can never benefit. Which type of regulatory concern does this scenario primarily raise?
3. Under the FCA's 'price and value' outcome, what does 'fair value' actually require?
4. Select ALL correct answers about what the Consumer Duty's outcomes are designed to achieve.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers describing why the PPI scandal reshaped UK conduct regulation.
Sélectionnez toutes les réponses correctes.
Mis-selling means selling a product that is unsuitable, misrepresented, or not in the customer's interest. Regulators have escalating tools:
Real enforcement pattern. The CFPB has repeatedly ordered US banks to refund "junk fees" such as surprise overdraft charges (fees triggered when a balance looked positive but a later posting pushed it negative) and multiple non-sufficient-funds fees on the same transaction. These orders combine refunds to customers with civil penalties.
The direction of travel in both jurisdictions is clear: disclosure alone is no longer a defence. If the outcome was unfair, the bank pays.
Think of three protective layers around a retail customer:
1. Before the sale: product design and fair value rules (Consumer Duty) stop unsuitable products reaching the customer.
2. During use: transaction protections (Reg E, APP reimbursement) cap losses from fraud and errors.
3. If the bank fails: deposit insurance (FDIC, FSCS) protects the balance itself.
A professional in banking needs to know which layer a given problem sits in, because the responsible regulator, the required action, and the timeline all differ.