Ashurst Governance & Compliance Update – Issue 87
The Financial Conduct Authority has published Primary Market Bulletin 66 which includes its observations, following discussions with issuers and advisers, on issuer disclosure obligations, particularly under the UK Market Abuse Regulation (MAR), which may arise in the context of a cyber incident. Headline observations include:
Not every cyber incident will be inside information but the FCA suggests that it may be prudent to begin from the assumption that information relating to an incident could be inside information and then undertake an assessment relative to the scale and nature of the incident, its reputational impact, and any immediate or anticipated disruption to the issuer's operation or financial position.
The FCA also reminds issuers that, before making a disclosure under MAR, they are afforded a short period of time if it is necessary to clarify the situation, for example the nature, scale and immediate impact of the incident.
In addition, if the incident affects an issuer’s ability to interact with its customers or clients and it makes proactive or reactive communications in response, it should also consider its disclosure obligations. Indeed, it may need to issue a holding announcement, if it believes there is a danger of inside information leaking before the facts and their impact can be confirmed.
The FCA observes that the ability to delay disclosure may be particularly relevant if an issuer is negotiating with attackers and the outcome of those negotiations would be jeopardized by immediate disclosure.
Vulnerabilities in cyber security systems may, in themselves and even without an active incident, constitute inside information, immediate disclosure of which could make an attack more likely and therefore be prejudicial to an issuer's legitimate interests.
The ability to delay the disclosure of inside information relies on the ability of the issuer to keep it confidential. On the basis that it is likely that an attacker is also in possession of that same information, an issuer will need to continually assess whether it remains confidential.
An issuer should carefully and continuously monitor whether changes in its circumstances mean it becomes obliged to make an announcement under MAR.
If the incident is ongoing and new information comes to light, then inside information may arise. This might concern the ongoing impact on the issuer’s operations, the likely duration of the incident, and reputational issues that may damage customer or investor confidence.
Even when an incident is fully resolved, inside information may arise where there is a material impact on the issuer’s financial position. This could include: the costs and impact of remediation, increased cyber protection costs, and the need for the issuer to revise its previously stated outlook or financial targets.
The FCA reminds issuers that justifying non-disclosure of information by offsetting negative and positive news is not acceptable.
The FCA acknowledges that issuers may be required, requested, or choose to share knowledge of impending or actual cyber incidents with government departments, law enforcement, regulatory or crime agencies in jurisdictions relevant to them. In doing so, an issuer sharing details of a cyber incident which amount to inside information will need to consider whether this is lawful under MAR – that is where the disclosure is necessary and the person disclosing the information is acting in the normal exercise of their employment, profession or duties.
Further guidance is included on when this may be permissible and the issues to be considered when doing so. In addition, the FCA encourages issuers to inform recipients that the information they are about to receive is or could be inside information, and that they should keep it confidential and be aware of their own obligations under MAR. It may also be prudent to document the information that has been disclosed, whether the issuer considers it inside information, and their justification for disclosing it.
The Bulletin also covers various other issues including a consultation on a Technical Note (803.1) which focuses on the FCA's expectations as regards comply or explain in the context of its new sustainability disclosure requirements. This consultation dovetails with the FCA's publication of its Policy Statement (PS26/19) on which further details can be found in Item 6 below.
The London Stock Exchange has published its Dividend Procedure Timetable for 2027, which it expects issuers, both on the Main Market and AIM, to follow when declaring dividends. By way of reminder, where a dividend timetable does not follow the Timetable, it must be approved by the LSE's Corporate Actions team in advance of the announcement of the dividend. The Timetable also prescribes the content of such announcements.
From 11 October 2027, the UK will move to a T+1 settlement cycle. The Timetable notes that, while Record dates will remain unchanged, from that date associated Ex Dividend dates and the Record date will fall on the same business day. As a transitional measure, securities will not be marked Ex Dividend during the period from 4 October to 18 October 2027, to allow the market to move to the new settlement cycle. The first Ex Dividend date on a T+1 basis will be 22 October 2027.
For further details on the move to a T+1 settlement cycle, see AGC Update, Issue 75 – Item 5.
Glass Lewis has published its 2026 review of the UK Proxy Season.
Key trends identified include:
For a reminder of Glass Lewis' proxy voting policy guidelines for 2026, see AGC Update, Issue 76 – Item 5.
By way of reminder, Glass Lewis has announced that it will retire its Benchmark Policy voting guidelines from September 2027, adopting instead a new framework based on multiple research perspectives enabling customised voting approaches.
Georgeson has also published its 2026 European AGM Season Review which includes an overview of UK AGMs in the FTSE 100.
The Financial Reporting Council has published its Annual Review of Corporate Reporting for 2025/2026. As in past years, the report provides information that is particularly relevant to preparers and auditors of financial statements, as well as investors.
Example disclosures which represent good quality application of reporting requirements that companies should consider when preparing their annual reports and accounts are included. The 'Highlights' section also provides an overview of the FRC's activities and findings in 2025/26, the FRC's expectations for reports next year and key reporting developments. The review concludes with a helpful reminder of the scope of the FRC's Corporate Reporting Review (CRR) Team's work and how companies should interact with them.
The review found that the quality of corporate reporting by FTSE 350 companies has been maintained, while the gap in quality between larger listed companies and other companies is narrowing. The proportion of FRC reviews leading to substantive enquiry letters also fell for the second consecutive year, reflecting a positive trend in reporting quality across the FRC’s risk-based sample.
The review identifies cash flow statements, financial instruments, impairment of assets, fair value measurement and revenue as the most common areas where substantive questions were raised during the year.
Looking ahead, the FRC highlights the need for companies to prepare for significant forthcoming reporting developments, including implementation of IFRS 18, revisions to FRS 102 and the introduction of Provision 29 of the UK Corporate Governance Code 2024.
The number of restatements prompted by the review work of the FRC's CRR team fell for the second year in a row, consistent with the number of reviews which resulted in substantive queries. However, four restatements affected profit (2025: one), with the majority of restatements continuing to arise in companies outside of the FTSE 350.
In more detail:
The FRC has historically reported on the 'top ten' issues raised in the CRR's review work. Following feedback, it has limited this year's review to the top five in order to enable it to also highlight useful insights in selected other areas including:
The review also sets out the FRC's key expectations for companies when preparing their next annual reports and accounts. Companies should ensure that:
For a reminder of the FRC's review for 2024/2025, see AGC Update, Issue 71 – Item 8.
Three directors have become the first to be fined for failing to verify their identity at Companies House. The convictions were secured by the Insolvency Service during proceedings brought at the City of London Magistrates' Court.
By way of reminder, it is now an offence for an individual to act as a director of a UK incorporated company or as a member of a UK Limited Liability Partnership if they have not verified their identity within the stipulated timeframe.
Newly appointed directors have been required to verify their identity with Companies House before acting as a director from 18 November 2025. Existing directors are required to verify during a 12-month transition period, when filing the company’s next confirmation statement.
The sanctions imposed were as follows:
For a reminder of identity verification requirements for directors, LLP members and persons with significant control, see AGC Update, Issue 73 – Item 1.
The successful prosecutions underscore the fact that the identity verification requirements are a cornerstone of the reforms being introduced under the Economic Crime and Corporate Transparency Act, seeking to ensure that those setting up, running and controlling companies are who they claim to be. They also demonstrate that directors have responsibilities not only for their own compliance but also for ensuring that unverified individuals do not continue acting as directors on behalf of a company.
The UK Financial Conduct Authority (FCA) has published Policy Statement PS26/19 containing its rules requiring listed issuers to make climate and sustainability disclosures against the UK Sustainability Reporting Standards (UK SRS) on a 'comply or explain' basis. The new rules replace existing climate-related financial disclosures and apply to accounting periods starting on or after 1 January 2027, with first reporting in 2028.
The rules follow the FCA's January 2026 consultation on amending the UK Listing Rules (UKLR) to align listed issuers’ sustainability disclosures with the UK SRS.
Most of the requirements proposed in the consultation have been adopted. A key change is that all categories of disclosures will be subject to a 'comply or explain' approach, whereas the consultation had proposed that climate disclosures (other than in relation to Scope 3 emissions) would be mandatory.
Transitional reliefs are available, including in relation to Scope 3 emissions and non-climate related sustainability (S1) disclosures.
As noted in Primary Market Bulletin 66 | FCA, the FCA is also consulting on a technical note to help issuers apply the 'comply or explain' approach.
We will issue a detailed overview of the Policy Statement and the consultation as soon as possible.
Delegated Regulation (EU) 2026/1563 (Simplified ESRS Regulation), which seeks to simplify the original EU Sustainability Reporting Standards (ESRS), was published in the EU Official Journal on 21 September 2026. This follows its July 2026 adoption by the EU Commission and the two-month scrutiny period by the EU Parliament and Council. The Simplified ESRS Regulation includes minor amendments and corrections from the version adopted by the Commission. The Simplified ESRS Regulation enters into force on 10 November 2026 and applies to financial years beginning on or after 1 January 2027.
For financial years beginning between 1 January and 31 December 2026, the Simplified ESRS Regulation allows reporting entities to choose whether to use:
Importantly, reporting entities must specify which version of the ESRS is used. From financial years starting from 1 January 2027, use of the Simplified ESRS is mandatory.
Delegated Regulation (EU) 2026/1560 (Voluntary Standards Regulation) has also been published in the Official Journal. It introduces voluntary reporting standards for entities with 1,000 employees or less in the preceding financial year (protected undertakings) that are not in-scope of the Corporate Sustainability Reporting Directive (CSRD) but which may face information requests from larger business partners that are in-scope of the reporting requirements. The Voluntary Standards Regulation enters into force three days after publication in the Official Journal and applies from financial years beginning on or after 1 January 2027. EFRAG has updated its non-mandatory guidance on the Voluntary Standard and plans to update its digital template in November 2026 to reflect changes in the Voluntary Standard.
For background information on the ESRS simplification process, the changes made to simplify the original ESRS and the concept of the value chain cap, which was introduced as part of the Omnibus 1 package to prevent trickle down of the burden of reporting obligations to smaller business partners, see EU adopts simplified ESRS and sustainability reporting standard for voluntary use.
The EU Commission has published a package of documents to enhance energy efficiency and sustainability of EU data centres. The package includes (i) a call for evidence on a proposed regulation to establish minimum performance standards (MPS) to reduce the energy consumption and environmental footprint of data centres; and (ii) a delegated regulation establishing a rating scheme and sustainability label for data centres with a capacity above 500kW.
The call for evidence seeks views on (i) the need for, and feasibility of, MPS for EU data centres and on the most appropriate way to establish them; (ii) which indicators should have MPS; and (iii) the thresholds that should be set. Responses should be submitted on or before 14 December 2026. The Commission is expected to adopt a proposal for an MPS Regulation under the Energy Efficiency Directive ((EU) 2023/1791) covering the energy efficiency, water use, waste heat reuse, and other selected sustainability criteria for data centres, in Q2 2027.
The rating scheme delegated regulation, which complements the reporting scheme for data centres introduced in 2024, is now subject to a two-month scrutiny by the EU Parliament and Council before entering into force. The first sustainability labels for data centres are expected to be displayed in 2027.
Apart from being of interest to data centre owners and operators and cloud service providers, the data centre rating scheme and MPS call for evidence will also be of interest to companies that wish to understand the sustainability footprint associated with their data centre use including for reporting under the CSRD and to support procurement decisions.
Authors: Will Chalk, Partner; Shan Shori, Expertise Counsel; Becky Clissmann, Sustainability Counsel and Marianna Kennedy, Senior Associate.
If you would like to receive future Ashurst Governance & Compliance updates, please click here.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.