This note explains the current position, particularly in light of the Senior Managers and Certification Regime (the SMCR), the Rehabilitation of Offenders Act 1974 (the ROA or the Act), and the Disclosure and Barring Service (DBS) filtering rules.
When are convictions considered spent?
The ROA supports the reintegration of individuals with criminal records into employment. Under the Act, cautions and convictions become “spent” after specified rehabilitation periods, which vary depending on the offence or circumstances. The offender is then regarded as rehabilitated.
For most purposes, the Act treats a rehabilitated individual as if they had never committed, been charged with, prosecuted for, convicted of, or sentenced for the offence. As a result, the individual is not required to declare their spent caution(s) or conviction(s) when applying for most roles.
However:
- Some sentences can never become spent, including sentences of imprisonment for life and certain public protection sentences for certain sexual and violent offences. These are referred to as listed offences.
- Certain roles are exempt from the ROA as a result of the RAO (Exceptions) Order 1975 (the RAO Exceptions Order). For these roles, individuals must disclose both spent and unspent convictions (subject to filtering rules discussed below).
DBS filtering and “protected” offences
Filtering determines which criminal records are disclosed on Standard or Enhanced DBS certificates.
A conviction or caution may be “protected” (and therefore not disclosed on a DBS certificate) if criteria are met:
For adults (18+ at time of offence):
- Cautions: protected 6 years after the offender accepted it (or protected 2 years after the offender accepted it if the individual was under 18 at the time).
- Convictions: protected after 11 years, provided:
- it did not result in a custodial sentence, and
- it is the individual’s only conviction.
If the individual was under 18 at the time of the conviction, it will be protected after 5 years and 6 months.
Exceptions
A conviction or caution will never be protected if it relates to a listed offence, as referred above and which includes serious violent and sexual offences.
What must be disclosed to the FCA?
The FCA expects regulated individuals and those working in regulated firms to be open and transparent with them and they assess criminal matters as part of the “fit and proper” test, particularly under the honesty, integrity and reputation limb. They expect employers to do the same, to the extent required by law.
In practice:
- Relevant individuals who are being assessed by the regulators as ‘fit and proper’ to perform a regulatory role and seek FCA approval must disclose:
- Unspent convictions and cautions; and
- Spent convictions and cautions where legally required (i.e. where the individual’s role is exempt under the ROA Exceptions Order); and
- Convictions and cautions for listed offences.
Protected convictions and cautions do not need to be disclosed.
The FCA will take into account factors including:
- seriousness and relevance of the offence;
- recency;
- pattern of behaviour; and
- evidence of rehabilitation.
Firms may rely on the FCA exemption in relation to the ROA Exceptions Order to require disclosure of spent convictions and cautions of senior managers to their organisation, subject to the restriction around protected offences.
For those individuals who will be certified by their employer (i.e. certification staff) and assessed as ‘fit and proper’ as part of that regime, but who are not senior managers, no FCA approval is required.
Importantly, for these roles:
- Criminal record checks are not mandatory, but firms may conduct them where legally permitted.
- Firms will not automatically be able to rely on the ROA Exceptions Order as these roles are mostly not senior enough to fall under that regime.
- As a result, firms are generally not entitled to ask about spent convictions for most certification roles.
This creates a key practical distinction under SMCR:
- For senior manager roles there must be full disclosure (subject to filtering) and mandatory checks.
- For certification roles there is more limited disclosure and constrained employer enquiries.
What criminal records checks can employers request?
Firms must ensure that any criminal records checks comply with the ROA, the RAO Exceptions Order and DBS eligibility criteria.
The types of DBS checks available are:
- Basic check: shows unspent convictions only (available broadly).
- Standard / Enhanced checks: include spent (non‑protected) convictions and cautions, but are only available for eligible roles (i.e. where an individual is engaged in an activity listed under the RAO Exceptions Order).
Eligibility
A Standard or Enhanced DBS check can only be requested where:
- the role falls within the ROA Exceptions Order; and
- (for Enhanced checks) the role is also listed in regulations under the Police Act 1997.
In financial services, eligibility will typically cover:
- Senior FCA‑approved roles (SMFs);
- certain regulated professional roles (e.g. actuaries, some accountants); and
- roles where the FCA itself is entitled to ask exempted questions.
For most certification and other staff, firms will be limited to:
- Basic checks; and
- lawful pre‑employment vetting that does not involve questions about spent convictions.
Data protection considerations
Criminal records data (criminal convictions and offences data) is subject to additional protections under Article 10 UK GDPR and the Data Protection Act 2018.
Firms need to have a clear lawful basis for processing and therefore must:
- ensure that Article 10 UK GDPR requirements are met. Firms will need to be clear on why they are allowed to process criminal offence data. This will either be because they are processing the data as they are under the control of an official authority or the processing is authorised under law (usually this means satisfying a condition in Schedule 1 of the Data Protection Act 2018);
- ensure proportionality (only request what is necessary);
- implement appropriate safeguards; and
- comply with documentation (firms should consider if they need to carry out a data protection impact assessment), retention and confidentiality requirements.
For firms and individuals, some practical takeaways include:
- Always distinguish between senior manager and certification roles.
- Apply current DBS filtering rules.
- Do not assume entitlement to ask about spent convictions unless the role is clearly exempt.
- Align recruitment, vetting, and certification processes with both SMCR obligations and employment law constraints.
- Do not forget to consider any relevant data protection requirements.
Doyle Clayton’s combination of leading employment lawyers and regulatory expertise means we are well placed to support our clients. Please contact Benedicte Perowne or your usual Doyle Clayton contact to discuss how we can help you in this area.