On 6 August 2026 the Financial Conduct Authority (FCA) switched on an application programming interface (API) for its Handbook. Systems can now reach structured rulebook content directly. Alex Smith, the FCA's Head of Cross-cutting Policy & Strategy, put the purpose plainly in the announcement: "It enables systems to access structured Handbook content directly."

That reads like a technical footnote. It is not one. Until now, a regulator's rulebook was, to a machine, a pile of web pages. Anyone wanting to track rule changes automatically had to scrape and parse them, with every break that a layout change brings. The rule text is now a queryable data source. For anyone automating compliance processes or pointing agents at them, the foundation has shifted.

In brief

What: an application programming interface for the FCA Handbook, giving structured machine access to the rule text

Who: Financial Conduct Authority (FCA), announced by Alex Smith, Head of Cross-cutting Policy & Strategy

When: 6 August 2026

Scope: Handbook, Technical Standards and Glossary

Access: free after registering an account, governed by Terms & Conditions, with rate limiting per user and endpoint

Limit: no past versions; a back-dated call returns an error

What the FCA built the interface for

The announcement is unusually open about who it is meant for. It names firms with in-house technology teams, RegTech and technology providers, developers of compliance tools and, explicitly, developers of artificial intelligence applications. The stated benefits are mapping rules onto products, activities and customer journeys in near real time, and tracking and comparing rule changes as they happen.

The fourth justification is the striking one, because a supervisor would not have phrased it this way until recently. The FCA wants to supply "trusted, up-to-date data to support more useful, accurate and transparent AI tools". Here a regulator deliberately provides the data layer that other people's AI tools are meant to sit on. The logic holds up. A language model answering compliance questions is only as reliable as the rule text it can reach, and anyone sourcing that text second hand inherits every transcription error along the way.

Access costs nothing. A registered account is enough. Use falls under the Terms & Conditions, and protected endpoints carry a rate limit applied per authenticated user and endpoint path. The interface is not accessed through the website but through ordinary development tooling.

The limitation is absent from the announcement

The blog promotes the fact that the interface serves both the current and the forthcoming state of the rulebook. What it leaves out sits in the technical notice accompanying the launch, and it is the single most consequential sentence in the whole release: "The API does not provide past versions." A call carrying a date in the past returns an error.

This separates two kinds of compliance work cleanly. The forward-looking case is solved. Which rules apply today, which take effect when, what has changed since the last version: that is exactly what the interface is built for, and it does the job better than any scraping arrangement.

The backward-looking case is not. Audit, internal review, enforcement proceedings and the assessment of legacy contracts nearly always turn on the same question. Which rule applied on a given date, and in which version? Anyone who has to answer that question cannot get it from the interface, and will still need to version the rulebook themselves.

The interface answers which rule will apply tomorrow. It does not answer which rule applied yesterday. The second question is the one an audit asks. On the reach of the Handbook API

Machine-readable is not machine-executable

The second issue is what the FCA is actually claiming. What the FCA serves is structured rule text. It is not executable rule logic. The distinction matters a great deal, and the FCA understands it better than most, having spent a decade pursuing the second option.

The story starts in November 2016 with a TechSprint on digitising reporting instructions. A year later the Bank of England and the FCA ran a joint TechSprint titled "Model Driven Machine Executable Regulatory Reporting". The Digital Regulatory Reporting programme that followed ran two pilot phases. The first, from June to December 2018, tested whether reporting requirements could be expressed in executable form. The second, from February to October 2019, worked with domain-specific languages alongside a cost-benefit model. Seven institutions took part, listed as "Barclays, Credit Suisse, HSBC, Lloyds, Nationwide, NatWest and Santander".

The Viability Assessment of January 2020 sets out the scale involved. The FCA receives "500,000 scheduled regulatory reports" a year, and British firms spend an estimated "1.5 to 4 billion pounds a year" on regulatory compliance. A programme with that much leverage has not failed, yet it has not reached scale either. It was folded into the authority's data strategy, where a third phase now works on improving core data for supervisors and on the groundwork for technology-driven reporting.

Seen against that history, the Handbook API is less a breakthrough than a pragmatic intermediate step: not the executable rule, but the rule text in reliably structured form. That is the part of the problem which nine years have shown to be solvable.

Why European institutions should be watching

For firms without British business this looks at first like news from another jurisdiction. The comparison still pays off, because it brings the European position into sharper focus.

The European Banking Authority (EBA) runs an impressive counterpart in the Interactive Single Rulebook. It gathers level 1 texts, delegated and implementing acts, technical standards, guidelines, recommendations and the associated Q&As in one place. It also carries a disclaimer that goes to the heart of any automated use: "This Interactive Single Rulebook is meant purely as a documentation tool and has no legal effect." This is followed by "The EBA does not assume any liability for its contents." and a pointer to the Official Journal via EUR-Lex for the authentic text.

The EBA offers no interface to go with it. Access runs through a table of contents and a search box in the browser. Anyone in the EU wanting to build what British institutions can now simply call is still parsing web pages or the Official Journal.

This is not a league table but a description of two postures. The EBA takes care to protect itself on legal grounds and places its tool firmly alongside the binding text. The FCA supplies data and, in the same announcement, calls it "trusted". Anyone opening up the regulatory data space for agents and automated controls will find the second posture easier to work with.

What this means in practice

Four starting points for compliance, internal audit and everyone responsible for compliance architecture.

1. Automate the comparison, keep the evidence yourself

Immediate: Rule-change comparison can now hang off the source directly. Evidence cannot. Because the interface serves no past versions, an auditable in-house version history of the rulebook remains mandatory. Dismantling it in the course of automation removes precisely the capability an audit will call for.

2. Reshape change monitoring for UK entities

In planning: Firms with British entities or British clients can replace manual Handbook reviews with a call that also knows forthcoming versions. This changes the rhythm more than the tooling. Rule changes can be observed continuously rather than at fixed review dates, and the effort shifts from research to judgement.

3. In agentic compliance, keep the data source apart from the logic

Architecture: The interface gives an agent reliable rule text. It does not give it the interpretation, nor the application to a specific set of facts. Conflating the two produces a system that cites a correct source and still reaches the wrong conclusion. The rule holds: the agent researches and proposes; responsibility for the assessment stays with a person.

4. Carry the comparison into the European debate

Ongoing: That the EBA rules out any legal effect for its Single Rulebook and offers no interface is a defensible position, but also a limiting one. Institutions active in industry bodies and consultations now have a concrete reference case rather than an abstract demand. Every consultation on reporting and data standards is an opening to use it.

Timeline: nine years to a queryable rule text
From executable reporting to a structured data source
November 2016
First TechSprint on digital reporting instructions
The FCA tests whether reporting instructions can be digitised at all.
November 2017
Bank of England and FCA together
TechSprint on "Model Driven Machine Executable Regulatory Reporting".
2018 to 2019
Two pilot phases with seven institutions
Barclays, Credit Suisse, HSBC, Lloyds, Nationwide, NatWest and Santander test executable reporting requirements.
January 2020
Viability Assessment
500,000 scheduled reports a year, an estimated 1.5 to 4 billion pounds of compliance spend across the market.
6 August 2026
Handbook API goes live
Handbook, Technical Standards and Glossary available in structured form, free after registration.
open
Historic versions
Past states of the rulebook cannot be retrieved, and no timetable for them has been published.
Christian Schablitzki

Christian Schablitzki

Strategy & Management Consultant · Agentic AI expert for financial institutions

More than 20 years in investment banking and derivatives trading, followed by over 10 years advising financial institutions. Currently Partner at Infosys Consulting in Germany. Certified in Google AI, Generative AI Leader (Google Cloud) and IBM RAG and Agentic AI.

LinkedIn profile →
newsletter
the agentic banker

Keep reading – every 14 days in your inbox.

Capital markets insights, regulatory updates and AI trends. Concise, well-founded, free.

GDPR-compliant. Unsubscribe at any time.

← Back to overview