{"site":{"name":"Koji","description":"AI-native customer research platform that helps teams conduct, analyze, and synthesize customer interviews at scale.","url":"https://www.koji.so","contentTypes":["blog","documentation"],"lastUpdated":"2026-08-03T04:07:09.726Z"},"content":[{"type":"documentation","id":"5468597f-7c3a-457b-8bc0-b35a30b13980","slug":"vulnerable-customer-research","title":"Vulnerable Customer Research: How to Evidence Good Outcomes Under FCA Rules","url":"https://www.koji.so/docs/vulnerable-customer-research","summary":"FG21/1, the FCA guidance on the fair treatment of vulnerable customers, is issued under the Principles and sets expectations in four areas: understanding the needs of vulnerable customers, staff skills and capability, responding through product design, customer service and communications, and monitoring and assessing outcomes. It frames vulnerability through four drivers: health, life events, resilience and capability. These are situational states rather than permanent traits, so annual point-in-time research cannot monitor them. The FCA published its review of firms treatment of customers in vulnerable circumstances on 7 March 2025, updated December 2025, based on interviews with 29 firms across 12 markets, a survey of 725 firms, commissioned consumer research with around 1,500 participants, and analysis of the 2020, 2022 and 2024 Financial Lives waves. It found that consumers in vulnerable circumstances continue to report poorer outcomes than other consumers, with the widest gap for those with multiple characteristics, and that firm-level progress has not yet appeared in UK-wide data. Firms asked for sector-specific case studies, better guidance on outcome monitoring methods, approaches for customers who do not disclose, and recognition of the intersection with Equality Act protected characteristics; the FCA published good practice case studies rather than revising the guidance. The central methodological problem is non-disclosure: disclosed vulnerability flags are a biased sample, so research should measure the drivers rather than the label using multiple_choice circumstance questions, behavioural scale questions on confidence and comprehension, and open_ended AI follow-ups on low scores. Outcomes should be monitored per Consumer Duty outcome, triggered by life events rather than by calendar, and always reported split by driver and by number of characteristics rather than in aggregate. Research methods themselves must not exclude low-capability customers: asynchronous participation, voice as a first-class option, short resumable sessions, plain language, no app install and deliberate recruiting for characteristics.","content":"If you rely on your vulnerability flags to evidence outcomes for customers in vulnerable circumstances, **your evidence is drawn from a biased sample and your monitoring is measuring the wrong population.** Most customers in vulnerable circumstances never disclose. The FCA has explicitly named both problems — how to monitor outcomes, and how to reach customers who do not tell you — and neither is solved by better reporting on the flags you already hold. They are solved by primary research designed to find vulnerability rather than waiting for it to be declared.\n\nThis guide is about that research programme. It sits alongside the [Consumer Duty guide](/docs/consumer-duty-customer-research), which covers comprehension testing for the consumer understanding outcome; here the subject is vulnerability as a **sampling and monitoring** problem across all four Duty outcomes.\n\n## What the FCA actually expects\n\nFG21/1, *Guidance for firms on the fair treatment of vulnerable customers*, is issued under the Principles rather than as Handbook rules — which is why firms so often under-invest in it and then find it applied firmly at supervision. It sets expectations in four areas:\n\n1. Understanding the needs of vulnerable customers in your target market and customer base\n2. Making sure staff have the skills and capability to recognise and respond to those needs\n3. Responding to those needs through product and service design, flexible customer service and communications\n4. Monitoring and assessing whether you are meeting and responding to those needs\n\nAreas 1 and 4 are research obligations in everything but name. Area 3 cannot be evidenced without them.\n\nThe guidance frames vulnerability through **four drivers**, and the practical value of the model is that it is situational — most of these are states people move through, not permanent traits.\n\n| Driver | What it covers | Typical research implication |\n|---|---|---|\n| Health | Physical or mental health conditions, cognitive impairment | Journey length, memory load, ability to complete in one sitting |\n| Life events | Bereavement, job loss, relationship breakdown, caring responsibilities | Timing-sensitive research; consent and duty of care |\n| Resilience | Irregular income, over-indebtedness, low savings | Financial stress changes decision-making under any communication |\n| Capability | Low literacy or numeracy, limited digital skills, low financial knowledge | Method itself can exclude the population you need |\n\nBecause vulnerability is situational, **a single annual study is structurally incapable of monitoring it.** Someone bereaved in March is a different research subject in September.\n\n## The 2025 review verdict, and what it means for your research\n\nThe FCA published its review of firms' treatment of customers in vulnerable circumstances on **7 March 2025**, updated in December 2025. It was substantial work: interviews with 29 firms across 12 markets, a survey of 725 firms, commissioned quantitative and qualitative consumer research with around 1,500 participants, and analysis of the 2020, 2022 and 2024 Financial Lives waves.\n\nThe verdict was uncomfortable. Consumers in vulnerable circumstances **continue to report poorer outcomes than other consumers**, and the gap is widest for people with multiple vulnerability characteristics. The Consumer Duty has visibly renewed firms' focus, but the progress seen in firm-level assessments has not yet shown up in the UK-wide data.\n\nFirms themselves asked the FCA for four things: more sector-specific case studies, better guidance on **outcome monitoring methods**, approaches for **customers who do not disclose vulnerability**, and recognition of how vulnerability intersects with Equality Act protected characteristics. The FCA chose not to rewrite FG21/1, publishing good-practice case studies instead — which means the expectation is unchanged and the burden of designing the monitoring sits with you.\n\nThree things follow directly for a research programme:\n\n- **Aggregate outcome metrics are not enough.** A firm-level satisfaction or complaints number cannot show a gap it is not split by.\n- **Disclosed flags are the wrong denominator.** They measure who told you, which is a different question from who is affected.\n- **Multiple characteristics need to be visible.** If your analysis treats vulnerability as one binary, you cannot see the group with the worst outcomes.\n\n## Problem one: the customers who never tell you\n\nNon-disclosure is the central methodological problem. People do not disclose because they do not recognise the label, because they fear consequences for credit or access, because the channel gave them no natural opening, or because they were in a hurry and the disclosure question sat behind a menu.\n\nThe fix is not to ask harder. It is to **measure the drivers rather than the label**:\n\n- Ask about circumstances, not categories. \"In the last twelve months, have you experienced any of the following?\" with a `multiple_choice` list of concrete life events outperforms any question containing the word vulnerable.\n- Capture capability behaviourally. A `scale` question on how confident someone felt completing the last step of a journey tells you more than a self-declared digital skills rating.\n- Probe the ones that matter. In Koji, an `open_ended` follow-up fires automatically when a confidence score is low — \"you said you were not sure what would happen next; what did you do at that point?\" — which is where the actual failure story lives.\n- Let people answer by voice. Typing is itself a capability filter, and a spoken answer from someone with low literacy carries detail no form field would have captured.\n\nRun this in the research instrument, and you get a vulnerability signal for **every participant**, not only the ones already flagged. That is the denominator the FCA is asking about, and it lets you do the analysis that matters: comparing outcomes between customers you had flagged, customers you had not flagged but who show characteristics, and customers who show none.\n\nAlmost every firm that runs this comparison for the first time finds the same thing — the undisclosed group looks materially worse than the flagged group, because the flagged group has been receiving support.\n\n## Problem two: monitoring outcomes rather than reporting activity\n\nOutcomes monitoring fails in a predictable way: firms report what they did (calls handled, flags recorded, training completed) instead of what happened to customers. Activity is easy to count and proves nothing.\n\nA workable monitoring design measures each Duty outcome, split by vulnerability characteristic:\n\n| Outcome | What to measure with customers | Method |\n|---|---|---|\n| Products and services | Did the product still fit after circumstances changed? | Triggered study after a life-event signal |\n| Price and value | Did the customer understand what they were paying and why? | Comprehension test plus `scale` value perception |\n| Consumer understanding | Can the customer correctly state what happens next? | Recall test with pre-set pass criteria |\n| Consumer support | Could the customer get help, first time, through their channel of choice? | Post-interaction study across channels |\n\nTwo design rules carry most of the weight. First, **trigger studies on events rather than a calendar** — a bereavement notification, a missed payment, a power of attorney registration, a complaint about a communication. Vulnerability is situational and your evidence should be too. Second, **always report split, never only aggregate.** An 84% satisfaction figure that hides 61% among customers with three or more characteristics is worse than no figure, because it creates false assurance — exactly the pattern the FCA criticised when it said reliance on sales data or an absence of complaints provides no reliable assurance.\n\n## Problem three: your research method is probably excluding them\n\nThis is the failure that quietly invalidates everything above. Standard research methods select against precisely the customers you need:\n\n- Scheduled video interviews exclude shift workers, carers and anyone without reliable connectivity or a quiet room.\n- Panel recruitment over-represents confident, digitally fluent, repeat participants.\n- Long written surveys select for literacy and stamina.\n- App downloads and account creation exclude low-capability users at the first step.\n- Incentives paid only by digital transfer exclude the unbanked and underbanked.\n\nAn inclusive design does the opposite. Make participation **asynchronous** so it fits around caring responsibilities and irregular shifts. Offer **voice as a first-class option**, not a fallback — for someone with low literacy or a visual impairment, speaking is not an accommodation, it is the usable path. Keep sessions short and allow them to be resumed. Write at a genuinely plain reading level. Offer the study in the languages your customer base actually speaks. And recruit deliberately for the characteristics rather than hoping a general panel contains them.\n\nThis is the strongest structural argument for AI-moderated research in this domain: **a study that runs by voice or text, asynchronously, in any language, with no moderator to schedule and no software to install, removes most of the access barriers that make vulnerable customers hard to research at all.** Koji runs exactly that shape of study, and because the AI probes automatically, a short session still reaches the depth a moderator would have needed a booked hour for.\n\n## Building the evidence pack\n\nWhat a board or supervisor needs to see, in order:\n\n1. **Who you researched, and how you found them** — including how you identified characteristics beyond disclosed flags.\n2. **Outcome results split by driver and by number of characteristics**, with the comparison against the non-vulnerable group stated explicitly.\n3. **Verbatim evidence** of where the journey failed, quoted, with the transcript retained.\n4. **What changed as a result**, with dates and owners — the decision trail, not just the finding.\n5. **Re-test results after the change**, which is what converts a finding into evidence of improvement.\n6. **Residual gaps**, named, with dates. Boards get more credit for a known gap with an owner than for an unblemished dashboard.\n7. **Method and data lineage** — how participants were sampled, what was asked, where transcripts and exports live.\n\nAdd the intersection the FCA called out: report where vulnerability characteristics overlap with Equality Act protected characteristics, because that is where both regulatory and reputational risk concentrate.\n\n## Common mistakes\n\n- Treating vulnerability as a permanent customer attribute rather than a situational state.\n- Monitoring only customers who disclosed, then reporting the result as coverage of vulnerable customers.\n- Collapsing all vulnerability into one binary flag, which hides the multiple-characteristic group with the worst outcomes.\n- Reporting activity metrics as outcome evidence.\n- Running the research with methods that structurally exclude low-capability customers, and never noticing.\n- Testing once a year, when the drivers are events that occur continuously.\n- Collecting health and financial hardship data without a lawful basis, a retention limit and a deletion route — vulnerability data is often special category data and deserves a data protection impact assessment.\n\n## Frequently asked questions\n\n**Does the FCA require firms to do research with vulnerable customers?**\nFG21/1 does not name research as an activity, but it requires firms to understand the needs of vulnerable customers in their customer base and to monitor whether those needs are being met. Neither can be evidenced from internal activity metrics alone, and the FCA's March 2025 review found that firms themselves asked for better guidance on outcome monitoring methods. Primary research is how those two expectations get satisfied in practice.\n\n**How do we research customers who never disclose their vulnerability?**\nStop asking for the label and measure the drivers instead. Ask about concrete circumstances in the last twelve months with a multiple_choice list, capture confidence and comprehension behaviourally with scale questions, and probe low scores with open_ended follow-ups. That produces a vulnerability signal for every participant, letting you compare outcomes across flagged customers, unflagged customers with characteristics, and everyone else.\n\n**What are the four drivers of vulnerability in FG21/1?**\nHealth, life events, resilience and capability. Health covers physical and mental health conditions; life events covers bereavement, job loss, relationship breakdown and caring responsibilities; resilience covers irregular income, over-indebtedness and low savings; capability covers low literacy, numeracy, digital skills or financial knowledge. Most are situational states rather than permanent traits, which is why point-in-time annual research cannot monitor them.\n\n**How often should we research vulnerable customer outcomes?**\nContinuously, triggered by events rather than by the calendar — bereavement notifications, missed payments, power of attorney registrations, complaints about communications — plus before and after any material change to a product, journey or communication. An annual study leaves the evidence stale for most of the year and cannot capture a situational driver.\n\n**How do we stop our research method from excluding the customers we need?**\nMake it asynchronous so it fits around shifts and caring responsibilities, offer voice as a first-class option rather than a fallback, keep sessions short and resumable, write at a genuinely plain reading level, offer the languages your customer base speaks, avoid app installs and account creation, and recruit deliberately for the characteristics instead of relying on a general panel. Then check the achieved sample against your customer base and report the gap honestly.\n\n**What should we report to the board on vulnerable customer outcomes?**\nOutcome results split by driver and by number of characteristics with an explicit comparison to non-vulnerable customers, how the sample was identified beyond disclosed flags, verbatim evidence of journey failures, the decision trail for what changed, re-test results after those changes, named residual gaps with owners and dates, and the intersection with Equality Act protected characteristics. Aggregate satisfaction figures without splits create false assurance rather than evidence.\n\n## Related resources\n\n- [Structured Questions Guide](/docs/structured-questions-guide) — the six question types behind driver measurement and comprehension tests\n- [FCA Consumer Duty Customer Research](/docs/consumer-duty-customer-research) — comprehension testing for the consumer understanding outcome\n- [Accessibility Research Guide](/docs/accessibility-research-guide) — including users with disabilities in your studies\n- [AI Customer Research for Banking & Financial Services](/docs/ai-research-for-banking) — the sector view\n- [AI-Powered Customer Research for Insurance Companies](/docs/ai-research-for-insurance) — insurance-specific outcome monitoring\n- [DPIA for User Research](/docs/dpia-user-research) — assessing risk before you collect health and hardship data\n- [Research Data Retention and Deletion](/docs/research-data-retention-deletion) — retention limits for special category data","category":"Research Operations","lastModified":"2026-08-03T03:24:07.668023+00:00","metaTitle":"Vulnerable Customer Research: Evidencing Outcomes Under FCA Rules","metaDescription":"How to design research that evidences good outcomes for customers in vulnerable circumstances: measuring the four FG21/1 drivers, reaching customers who never disclose, and monitoring outcomes by characteristic.","keywords":["vulnerable customer research","FCA vulnerable customers","FG21/1 guidance","characteristics of vulnerability","vulnerable customer outcomes monitoring","financial vulnerability research","inclusive customer research","Consumer Duty vulnerability"],"aiSummary":"FG21/1, the FCA guidance on the fair treatment of vulnerable customers, is issued under the Principles and sets expectations in four areas: understanding the needs of vulnerable customers, staff skills and capability, responding through product design, customer service and communications, and monitoring and assessing outcomes. It frames vulnerability through four drivers: health, life events, resilience and capability. These are situational states rather than permanent traits, so annual point-in-time research cannot monitor them. The FCA published its review of firms treatment of customers in vulnerable circumstances on 7 March 2025, updated December 2025, based on interviews with 29 firms across 12 markets, a survey of 725 firms, commissioned consumer research with around 1,500 participants, and analysis of the 2020, 2022 and 2024 Financial Lives waves. It found that consumers in vulnerable circumstances continue to report poorer outcomes than other consumers, with the widest gap for those with multiple characteristics, and that firm-level progress has not yet appeared in UK-wide data. Firms asked for sector-specific case studies, better guidance on outcome monitoring methods, approaches for customers who do not disclose, and recognition of the intersection with Equality Act protected characteristics; the FCA published good practice case studies rather than revising the guidance. The central methodological problem is non-disclosure: disclosed vulnerability flags are a biased sample, so research should measure the drivers rather than the label using multiple_choice circumstance questions, behavioural scale questions on confidence and comprehension, and open_ended AI follow-ups on low scores. Outcomes should be monitored per Consumer Duty outcome, triggered by life events rather than by calendar, and always reported split by driver and by number of characteristics rather than in aggregate. Research methods themselves must not exclude low-capability customers: asynchronous participation, voice as a first-class option, short resumable sessions, plain language, no app install and deliberate recruiting for characteristics.","aiPrerequisites":["A UK FCA-regulated firm subject to FG21/1 and the Consumer Duty","Access to customer records or journeys where vulnerability characteristics may be present","A lawful basis and DPIA for collecting health and financial hardship data"],"aiLearningOutcomes":["Map the four FG21/1 drivers of vulnerability to concrete research questions","Measure vulnerability characteristics without asking customers to self-label","Compare outcomes across flagged, unflagged-with-characteristics and non-vulnerable customers","Design event-triggered outcome monitoring instead of annual studies","Remove the method-level barriers that exclude low-capability customers from research","Assemble a board evidence pack that reports outcomes split by characteristic"],"aiDifficulty":"advanced","aiEstimatedTime":"13 min read"}],"pagination":{"total":1,"returned":1,"offset":0}}