Skip to main content
UK financial services · Public-content screening

Proportionate social-media screening for defined risk—not blanket monitoring

Review relevant publicly available content for defined roles or trigger events—with human verification, protected-data controls and an evidence trail for your decision.

  • Public content only
  • Human-reviewed
  • Decision support, not a decision

Screening should be necessary for an identified risk, transparent, fair and proportionate. See the ICO’s current draft vetting guidance.

Publicly available sources No request for private account access or passwords.
Protected-data controls Designed to reduce decision-maker exposure to irrelevant attributes.
Source-linked evidence Context, date and reviewer notes stay with the finding.
Human verification Identity and report findings reviewed before delivery.
Start with the use case

Use screening where the role or event justifies it

A good screening programme defines the reason, scope and decision standard before collecting public information.

Potentially appropriate

A defined, risk-based assessment

  • A sensitive appointment with a documented risk rationale
  • A credible conduct trigger requiring proportionate fact-finding
  • A fitness-and-propriety review tied to specific role standards
  • A consistent policy that is communicated to the person
  • A review with an appropriate response and correction process
Wrong starting point

Routine or curiosity-driven monitoring

  • Monitoring the entire workforce because the data is available
  • Looking for political, religious or other protected attributes
  • Using an automated score as the employment decision
  • Investigating information with no role or conduct relevance
  • Keeping reports without a defined retention purpose
What the report should prove

Evidence, context and controls—not a black-box score

A reviewer should be able to understand what was found, where it came from, what was withheld and what judgement still belongs to the firm.

  • Identity-matching confidence and human review status
  • Relevant public source, date and surrounding context
  • Applied review criterion and reviewer note
  • Recorded withholding of protected or irrelevant information
  • Clear separation between evidence and the firm’s decision
The workflow

A scoped review from policy question to evidence record

The final employment or regulatory decision remains with the authorised people in your firm.

01 · Define

Set the purpose

Document the role, trigger, lawful basis, review criteria and retention period.

02 · Match

Verify identity

Resolve public profiles carefully so information is not attributed to the wrong person.

03 · Review

Assess public content

Apply the defined criteria while retaining source context, date and evidential detail.

04 · Restrict

Limit exposure

Withhold protected or irrelevant information from the decision view where the process allows.

05 · Decide

Use human judgement

Review the evidence, invite context where appropriate and record the firm’s own rationale.

Privacy and fairness controls

Design the review to minimise irrelevant exposure

Technology can support a controlled process, but it does not replace lawful-basis, policy, transparency or human accountability.

Restricted decision view

Configure the process so reviewers do not receive unnecessary protected or irrelevant detail simply because it appears in a public source.

Documented criteria

Define the conduct and role criteria before review. Preserve which criterion was applied and why a finding reached the report.

Context and correction

Keep source context available and give the person an appropriate way to explain, challenge or correct material information.

Controlled retention

Retain the report and evidence only for a documented period aligned to your policy, legal obligations and the purpose of the assessment.

Ad hoc search versus controlled review

The method matters as much as the source

Public information does not become fair, relevant or reliable merely because a manager can find it in a browser.

Comparison of ad hoc searches and a controlled Ferretly workflow
ControlAd hoc manager searchConfigured review workflow
PurposeOften implicit or undocumentedDefined role, trigger and criteria
Protected informationVisible directly to the decision-makerDesigned to restrict irrelevant exposure
Identity and contextReviewer-dependentHuman verification and source context
ConsistencyVaries by manager and searchConfigured criteria and review record
Audit trailBrowser history or notesEvidence, source, date and rationale
Person’s contextMay be requested late or not at allResponse step built into the firm’s process
FCA non-financial misconduct

Use the rules to define the question—not to justify surveillance

PS25/23 changes how specified misconduct can engage COCON and informs FIT, but the FCA explicitly says firms need not monitor private lives or social media.

01

Define the regulatory relevance

Identify the COCON, FIT or people-risk question and the evidence needed to answer it.

02

Apply materiality and reliability

Do not treat an allegation, opinion or isolated signal as a conclusion without context.

03

Keep the firm accountable for the decision

The report supports analysis; it does not determine fitness, discipline or employment outcome.

Review the evidence format

See what the decision-maker should receive—and what they should not

Walk through the evidence, source context and protected-data controls that should support a proportionate review process.

Frequently asked questions

Social-media screening in UK financial services

Does the FCA require social-media screening?
No. The FCA explicitly says firms do not need to monitor employees’ private lives or social media. A proportionate public-content review may be appropriate where the firm has independently identified a lawful, role-specific or trigger-based need.
Is social-media vetting lawful in the UK?
Lawfulness depends on the purpose, necessity, proportionality, transparency and how information is used. The ICO’s current pre-employment vetting page is marked as draft guidance; obtain appropriate legal advice for your specific process.
Does Ferretly access private social-media accounts?
The proposed workflow is limited to publicly available content. It does not ask the person for account passwords or access to private content.
How are protected characteristics handled?
The process is designed to reduce exposure to protected or irrelevant information by restricting what reaches the decision view and recording withholding decisions. The exact configuration and verification should be reviewed during implementation.
Does the report make an employment or fitness-and-propriety decision?
No. The report organises public-source evidence and review context. The authorised decision-maker remains responsible for assessing relevance, fairness and outcome.
Can the person explain or correct information?
Your process should provide an appropriate route for context, correction or challenge before material information influences an adverse decision. Ferretly’s evidence record can support that conversation; it does not replace your policy.
What should we evaluate in the workflow review?
Check identity verification, source context, evidence dates, review criteria, protected-data handling, reviewer notes, retention controls and the separation between report findings and the firm’s final decision.