Compliance for financial and advisory websites

What regulated financial and advisory firms must consider on their websites: permissions, communication rules, record keeping and the line around advice.

4 minread 832words last updated

The short answer

A website belonging to a regulated financial or advisory firm is a regulated communication, not just marketing. Four things follow. Identification: the legal entity, licence or registration number, supervisory authority and the public register where clients can verify you, alongside the ordinary company details and a complaints and dispute resolution route. Communication standards: promotional material must be fair, clear and not misleading, with product-specific requirements about risk warnings, past performance, comparisons and target markets. The advice boundary: content that presents something as suitable for a particular person or situation can constitute advice, which may require permissions you do not hold, and calculators, comparison tools and personalised content are where general information drifts across the line. And record keeping: communications and their approvals must generally be retained, which makes versioning and an approval trail part of the website’s design rather than an afterthought. The practical consequence is that compliance belongs in the publishing workflow, not in a review at the end.

What shapes a regulated firm’s website

AreaRequirementWhere it bites
IdentificationEntity, licence number, supervisor, public register, complaints and dispute routesFooter, about and contact pages
Fair, clear, not misleadingBalanced presentation, risks alongside benefits, no cherry-picked outcomesProduct and service pages
Product-specific rulesRisk warnings, past performance statements, target market, cost disclosureAnything product-related
Advice boundaryGeneral information versus personal recommendationCalculators, comparison tools, personalised content, chat
Testimonials and case studiesOften restricted; substantiation requiredMarketing pages
Record keepingCommunications and approvals retained for a defined periodPublishing workflow and versioning
Client dataUsual data protection plus sector confidentialityForms, portals, communication
Security and continuitySector expectations and, for some, operational resilience rulesHosting, monitoring, incident procedures
AccessibilityConsumer-facing services may fall within the Accessibility ActForms, portals, documents

Building it properly

  1. Involve compliance at the brief, not at the review, so structure and features are agreed early.
  2. Publish identification and regulatory details exactly as your supervisor requires, verified against the register.
  3. Write product pages with balance: risks with benefits, no selective outcomes, substantiated claims.
  4. Treat calculators and comparison tools as high-risk features; get the advice boundary assessed before building.
  5. Build approval into publishing: a documented sign-off per change, recorded with the version.
  6. Keep the site in version control, so you can show what was published when.
  7. Apply retention to communications and approvals per your obligations.
  8. Handle client data with sector confidentiality as well as data protection.
  9. Meet accessibility where consumer services bring you within scope.
  10. Review the site periodically as products and rules change, with compliance sign-off recorded.

Working with a web partner

A regulated firm’s web partner needs to understand that content changes are controlled communications: they go through approval, they are versioned, and the record matters. That changes the workflow from publish quickly to publish with a trail, and it is straightforward when designed in, using a repository, previews and a recorded sign-off per change. A partner who treats the site as ordinary marketing will produce a site that is fast to change and impossible to evidence, which is the wrong trade for a regulated firm.

What this means for you

A regulated firm’s website must carry identification and supervisory details, present products fairly and clearly with required warnings, stay on the right side of the advice boundary, and keep records of communications and approvals with versions. Involve compliance at the brief, treat calculators and personalised features as high-risk, build approval and versioning into publishing, and review as products and rules change. This is general information rather than legal or compliance advice; your supervisor’s rules and your compliance function govern your position.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

What must a regulated firm show on its website?

Identification and regulatory details: the legal entity, the registration or licence number, the supervisory authority, and often the register where clients can verify it, alongside the ordinary company details. Complaints procedures and dispute resolution routes are usually required too. The specifics come from your national supervisor and the rules for your permissions, so confirm them rather than copying another firm's footer.

When does website content become advice?

The boundary depends on the regime and the product, and it typically turns on whether the content is presented as suitable for a particular person or situation rather than as general information. Calculators, comparison tools and personalised content are where general information most often drifts towards advice. Because the consequences include needing permissions you may not hold, this is precisely the question to put to your compliance function before building such a feature.

Do we have to keep records of what the website said?

Regulated firms generally have record-keeping obligations covering communications with clients and promotional material, including approval records and versions. Websites are communications. Keeping the site in version control, with an approval record per change, makes the obligation straightforward instead of archaeological, and it is the argument for treating website content the same way as any other regulated communication.

Sources

  1. AFM: Licence registers (accessed 2026-09-14)
  2. European Securities and Markets Authority (accessed 2026-09-12)