Skip to content
Demo · Day 1

Day 1 — The Section 166 Notice

HSBC Holdings plc logo

HSBC Holdings plc · Identity & Access Management Overhaul

Section 1 of 5 · Scene Setup

~15 min left

Scene Setup

Your Monday morning starts at 7:48 AM with a Teams meeting invite marked URGENT — CONFIDENTIAL from Colin Bell's executive assistant. Subject line: 'IAM Programme — Regulatory Mandate Briefing.' You're dialling in from your home office in Surrey, laptop open on a standing desk, a second monitor showing your empty calendar for a project you were formally assigned to on Friday afternoon. The handover from your predecessor — who left HSBC for Barclays after 11 weeks — consisted of a 3-page PDF and a Slack message that read: 'Good luck. You'll need it.'

By 8:15 AM, you're looking at a Teams grid of faces. Colin Bell, Group Chief Compliance Officer, is in his study at home in Buckinghamshire, bookshelves lined with regulatory textbooks behind him. Greg Maybury, Group CISO, is joining from HSBC's Singapore office — it's 3:15 PM there, and he's clearly been in meetings all day. Eleanor Wright, Head of Regulatory Affairs, is in what appears to be a hotel room in Edinburgh, fresh from an FCA supervisory meeting that ran until Friday evening.

Colin opens without pleasantries. 'Thank you for joining at short notice. What I'm about to share is classified as Restricted under our information governance framework. On September 15th, the FCA issued HSBC a Section 166 notice — a Skilled Person review — focused on our identity and access management controls. The notice specifically cites three findings from their 2024 thematic review: 234,000 orphaned accounts across our Active Directory estate, 17 disconnected AD forests with no centralised governance, and the complete absence of a Privileged Access Management solution in our trading systems environment. The FCA has given us 18 months to demonstrate material remediation. That clock started 6 weeks ago.'

Eleanor Wright unmutes. 'I should add context. This didn't come out of nowhere. The FCA's thematic review on operational resilience flagged IAM as a systemic weakness across Tier 1 UK banks. We were the worst performer. And the timing is sensitive — the DOJ consent order from the 2012 sanctions case requires us to demonstrate "adequate systems and controls" by March next year. Our US counsel believes a failed IAM remediation could be cited as a consent order violation. We're not just talking about an FCA fine. We're talking about potential restrictions on our US dollar clearing operations.'