Skip to main content
Compliance

How Financial Advisers Should Document Suitability and Risk

The assessment and the record of it are different things, and files usually fail on the second. A practical approach to capturing objectives, risk, capacity for loss and rationale defensibly.

TakeNote Team12 min read

Last reviewed: August 2026

Why documenting suitability matters

An unrecorded suitability assessment is, for regulatory purposes, an assessment that did not happen. The file is the only evidence available to a reviewer years later, so documentation quality determines whether sound advice can be shown to have been sound.

This is the uncomfortable asymmetry of advice files. An adviser can conduct a thorough, well-reasoned suitability assessment and still be unable to demonstrate it. When a complaint arrives three years later, the adviser's recollection carries little weight against a thin file, and the Financial Ombudsman Service will generally decide on the evidence available.

The practical objective is therefore narrower than “good documentation”. It is reconstructability: could someone who was not present rebuild the reasoning from the file alone? Everything below serves that test.

Documenting client objectives

Objectives must be specific enough to test a recommendation against. Record the purpose, the amount, the time horizon and any competing calls on the money — not a product category or a one-word goal.

Compare two entries for the same client. “Client seeks growth over the medium term” cannot be assessed: growth of what, from what, by when, and at what cost to liquidity? Against that, “client wishes to build a fund of approximately £250,000 by age 60 to support partial retirement, while retaining £40,000 accessible within two years for a planned extension” can be tested directly against any recommendation.

The second version also does something the first cannot: it surfaces a constraint. The accessible £40,000 has implications for asset allocation and product selection that would otherwise be invisible in the file, and a reviewer can see the adviser accounted for it.

Documenting financial circumstances

Circumstances must be recorded as at the date of the advice. This sounds obvious and is routinely missed, because circumstances are typically captured in a fact-find at onboarding and then referenced rather than refreshed. A recommendation assessed against three-year-old income, expenditure and liability figures has not been assessed against the client's actual position.

Where circumstances have not changed, record that they were checked and confirmed unchanged. That single line converts an apparent omission into evidence of diligence, and it costs nothing.

Documenting knowledge and experience

The record should be specific to the product being recommended rather than general. That a client has “20 years of investment experience” says nothing about their familiarity with, for example, a structured product with conditional capital protection. Note what was explained about the specific mechanics and what the client demonstrated back.

Knowledge is also not static in the direction firms assume. It can decline, and the FCA's guidance on the fair treatment of vulnerable customers expects firms to be alert to that.

Documenting attitude to risk

Record the conversation that established the client's risk attitude, not only the questionnaire score. Where the adviser's conclusion departs from the tool output, the reasoning for that departure is the most valuable item in the file.

A profiling questionnaire produces an input. The assessment is the adviser's reasoned conclusion, informed by that input and by the conversation. A file containing only “ATR: 6/10 (Balanced)” records the input and omits the assessment entirely.

Departures from the score are common and legitimate — a client may answer a questionnaire optimistically, or their answers may conflict with how they describe reacting to past market falls. Recording “questionnaire indicated 7; adviser assessed 5 following discussion of the client's response to 2022, when they described considering moving to cash” demonstrates judgement. Silently overriding the score demonstrates nothing and looks arbitrary on review.

Documenting capacity for loss

Capacity for loss is objective and must be evidenced separately from attitude to risk, with the financial inputs behind the conclusion. The question is whether the client could absorb a loss without material effect on their standard of living.

Conflating capacity for loss with attitude to risk is the most consequential documentation failure in advice files, and it differs in kind from the others. Most documentation weaknesses are evidential — the advice was fine, the record was thin. This one tends to produce genuinely unsuitable outcomes, because a client with high risk appetite and low capacity who is placed on appetite alone is exposed to a loss they cannot absorb.

The record should show the inputs: essential expenditure, secure income, liquid reserves, time to recovery, and what would happen if the invested capital fell by a material percentage. A conclusion without inputs is an assertion. The FCA suitability requirements guide sets out how the FCA has treated this distinction in file reviews.

Documenting recommendation rationale

The rationale must explain why the recommendation suits this client specifically. If it would read identically for any client with the same risk score, it evidences a segmentation decision rather than a suitability assessment.

This is the single most useful test to apply to a draft file. Remove the client's name and personal details. If the rationale remains entirely intact and could be sent to a different client unchanged, it is a product description.

A rationale that passes the test connects specific client facts to specific features of the recommendation — the two-year liquidity requirement to the cash allocation, the limited capacity for loss to the reduced equity weighting, the stated intention to phase retirement to the drawdown structure.

Alternatives considered

Recording what was considered and set aside is among the strongest available signals that a real comparative judgement occurred. It also pre-empts the most common complaint framing — that an obvious alternative was never contemplated. Two or three lines are usually sufficient: what was considered, and the reason it was not recommended.

Client vulnerabilities where relevant

Where vulnerability indicators are present, the file should record what was observed and how the advice process was adjusted in response. Where none are present, record that the question was considered. Silence is ambiguous, and ambiguity is resolved against the firm.

Evidence captured during client meetings

The meeting is where nearly all of the material above originates, and the interval between the meeting and the write-up is where most of it is lost. Detail degrades quickly: the exact phrasing a client used about their retirement intentions, the concern they raised and then moved past, the moment they said they had not understood something.

Contemporaneous records also carry greater evidential weight than later reconstructions. A suitability note demonstrably written months after the meeting, following a complaint, invites precisely the scrutiny a firm wants to avoid — even where its contents are accurate.

Maintaining a defensible audit trail

A defensible trail shows who recorded what, when, and in what sequence, and cannot be retrospectively altered by the people whose actions it records. Those three properties — attribution, timestamping, immutability — are what allow a file to be shown as contemporaneous rather than merely dated.

Retention matters here too, and it is not a single period: suitability records for insurance-based investment products must be kept for at least the duration of the client relationship, which will often exceed the five-year minimum applying to MiFID business. The FCA record-keeping requirements guide sets out the periods and their Handbook sources.

Common documentation weaknesses

The same handful of weaknesses recur across firms of every size:

  • Risk recorded as a score with no supporting conversation.
  • Capacity for loss absent, or collapsed into attitude to risk.
  • Objectives too vague to test a recommendation against.
  • Circumstances carried forward from onboarding without refresh.
  • Rationale that would suit any client in the same risk band.
  • No record of alternatives considered.
  • No record that vulnerability was considered either way.
  • Summary retained but the underlying meeting evidence deleted.
  • Write-up completed long enough after the meeting that detail is plainly reconstructed.

Each is a variance problem rather than a knowledge problem. Advisers know these elements belong in the file; they are omitted under time pressure, inconsistently, by different people. That is why structural fixes outperform further training.

Practical checklist

A working checklist for an advice file. It is a documentation aid, not a statement of regulatory requirements — firms should map it to their own permissions and to COBS 9A requirements or COBS 9 as applicable.

  • Objectives recorded specifically enough to test a recommendation against — purpose, amount, time horizon
  • Financial circumstances as at the date of advice, not as at onboarding
  • Attitude to risk recorded with the conversation that established it, not only a score
  • Capacity for loss assessed separately, with the inputs behind the conclusion
  • Any departure from a profiling tool score, with the adviser’s reasoning
  • Knowledge and experience relevant to the specific product recommended
  • Recommendation rationale explaining why this client, not this risk category
  • Alternatives considered and the reason each was set aside
  • What was explained about risk, and what the client demonstrated they understood
  • Vulnerability indicators considered, including a positive record where none were found
  • Date and time advice was given, and the version of any report issued
  • The underlying meeting evidence retained alongside the structured summary

Supporting consistency in practice

Where each required element has a defined place in the record, omissions become visible when the record is created rather than at a file review two years later. Retaining the meeting evidence alongside the structured summary keeps the two functions distinct: the summary is the record, and the meeting evidence is what supports it.

The limits should be explicit. Structured capture improves consistency and surfaces gaps; it does not make the suitability judgement, which remains the adviser's, and it does not guarantee regulatory compliance. Adviser and compliance review remains essential to every record. See how TakeNote supports FCA compliance processes for where the platform assists and where human review is required.

Frequently asked questions

What is the difference between attitude to risk and capacity for loss?
Attitude to risk is the client’s subjective willingness to accept variability in returns. Capacity for loss is an objective assessment of whether they could absorb a loss without material effect on their standard of living. They are independent: a client can be comfortable with risk while having little capacity to bear it, and both must be documented separately.
How much detail should a suitability rationale contain?
Enough that a reviewer with no prior knowledge of the client could understand why this recommendation suited this client. If the rationale would read identically for any client with the same risk score, it is too generic to evidence an assessment.
Do alternatives considered need to be recorded?
Recording alternatives considered and why they were set aside materially strengthens a file. It demonstrates that a comparative judgement was made rather than a default applied, and it is one of the clearest indicators that a genuine suitability assessment took place.
Should the file record that no vulnerability was identified?
Yes. A positive record that vulnerability indicators were considered and none identified is materially stronger than silence, which is ambiguous between "considered and absent" and "never considered".
Is a risk profiling questionnaire enough to evidence attitude to risk?
No. The questionnaire output is an input to the assessment, not the assessment. Where the adviser’s conclusion differs from the score, the reasoning for that difference is the most important item in the file.
How soon after a meeting should the record be written?
As close to the meeting as practicable. Detail degrades quickly, and the gap between meeting and write-up is where most documentation weakness originates. Contemporaneous records also carry more evidential weight than reconstructions produced after a complaint.