If your firm is FCA-regulated, most of your website is not "content", it is a financial promotion, and the rules that applied when compliance approved it keep applying every single day it stays live. That is the trap: approval happens once, but the website keeps changing, and a promotion that was compliant at sign-off can be non-compliant by Friday because someone tightened the copy, moved a risk warning below the fold, or A/B tested the disclaimer away.
This guide is for the finance and compliance teams responsible for that gap: what the rules actually require on a website, the specific ways pages drift out of compliance, and how to keep watch across every page without manually re-reading the site each month. The usual caveat applies: practical guidance, not legal advice.
What the rules expect from a web page
The core standard is deceptively simple: financial promotions must be fair, clear and not misleading. On a real website that translates into specifics:
- Risk warnings that are actually prominent. "Capital at risk", "past performance is not a guide to future performance", investment-specific warnings: present, legible, and not buried beneath the fold or in grey-on-grey small print.
- Balance. Benefits cannot shout while risks whisper. A page that lists ten advantages and links to the risks is not balanced.
- Representative examples where trigger terms appear. Credit promotions that mention rates or incentives generally need the representative APR and example, correct and current.
- Approval and attribution. Promotions communicated by unauthorised persons need approval under section 21, and the approving firm is on the hook for the content, including the version that is live today, not the version they approved.
- Consumer Duty on top. Since 2023 the question is not only "is this technically accurate" but "does this support good customer outcomes and understanding", which pulls clarity and audience-appropriateness into scope.
- Sector specifics. High-risk investments carry mandated warning formats and friction; cryptoasset promotions now sit inside the regime with prescribed risk warnings. If it applies to you, you know the detail; the website is where it must hold true continuously.
How compliant pages become non-compliant
Almost never through a decision. Through drift:
- The conversion edit. Marketing shortens a page, and the risk warning is what got shortened. Click-through improves; compliance does not.
- The A/B test. Variant B, the one without the cluttered disclaimer, wins the test and quietly becomes the page.
- The stale example. Rates changed at the product level; the representative example on a landing page from last year did not.
- The forgotten page. Old campaign URLs stay live and indexed, promoting terms that no longer exist. Regulators do not care that nobody links to it any more.
- The template change. A redesign moves risk warnings into a collapsed accordion or below an expanded hero. Same words, no longer prominent.
- The third-party widget. An embedded calculator or rate table updates its output; the surrounding approved copy no longer matches what it shows.
Every one of these is invisible to the people who caused it, and expensive when found by the wrong audience first. The FCA's supervisory work on financial promotions has repeatedly ordered firms to amend or withdraw thousands of live promotions, and "we did not know the page had changed" is not a defence, the obligation is continuous.
Continuous compliance, without continuous re-reading
The practical answer is the same pattern legal teams use for claims monitoring, tuned for promotions:
- Inventory the promotional pages. Product pages, landing pages, rate tables, campaign URLs, including the old ones. The forgotten-page problem dies here.
- Encode the mandatory wording as must-contain rules. Each risk warning, representative example and required disclosure becomes a per-page rule: if the exact required text stops appearing, you get an alert the same day. This is content monitoring doing compliance work.
- Set the banned list. "Guaranteed returns", "risk-free", "no-brainer": wording your policy prohibits becomes a must-not-contain rule across every page.
- Let policy checks judge the grey areas. Beyond exact strings, TLDTrack's compliance checks read pages against your uploaded policy documents, your promotions standards, your balance requirements, your tone rules, and flag content that contradicts them. The reworded benefit paragraph that now overpromises gets caught even though no banned phrase appears.
- Alert on any change to approved pages. An edit to an approved promotion is precisely the event your process says requires re-approval. Now it is also an automatic notification instead of an honesty system.
- Keep the log as your compliance record. Checks run, changes detected, findings resolved: a continuous monitoring record is exactly the kind of systems-and-controls evidence the FCA expects, and it turns the annual promotions review from an excavation into a confirmation.
The finance-team payoff
The teams that adopt this stop being the department that says no. Approval gets faster, because compliance knows nothing moves post-approval without an alert. Marketing gets more freedom, because the guardrails are automated rather than procedural. And the compliance file writes itself: every page, every rule, every change, timestamped.
The underlying discipline is the one that runs through everything we write here: websites drift, silently, and the failures that cost most are the quiet ones. For promotions, the quiet failure is a missing risk warning found by a regulator. Cheaper to be the one who finds it first.
