The short version
- In a bank, the floor plan is a compliance document. Information barriers have to exist physically, not just in policy.
- Front office and back office need different booking rules, different neighbourhoods and different levels of oversight.
- Visitor control must produce an audit trail: who came in, who signed them in, which floors they could reach, when they left.
- RTO mandates fail quietly when nobody measures attendance. HybridHero benchmarks put average utilisation at 54% against a 60 to 70% target.
- One platform for desks, rooms, visitors and parking beats four disconnected systems every time an auditor asks a question.
Running a financial services workplace is not like running any other office. The facilities lead at a software company worries about desk supply and coffee. You worry about whether an M&A analyst can see the equity research team’s screens, whether a visitor badge would survive an FCA visit, and whether the COO’s attendance mandate is actually happening on the floors you manage. I have sat in enough of those Monday meetings to know the difference.
The short answer to how banks and financial firms should run their offices: treat space as a controlled asset, the same way you treat data. That means information barriers drawn onto the floor plan and enforced by the booking system, separate rules for front office and back office teams, visitor workflows that leave an evidence trail, and attendance data solid enough to defend an RTO policy. A purpose-built platform for the financial services workplace handles all four in one place. The rest of this guide covers how each piece works in practice.
The floor plan is a compliance document
Every regulated firm has information barriers on paper. Fewer have them on the floor. Policy says corporate finance and research must be separated. Then hybrid working arrives, desks become bookable, and an analyst working on a live deal books a hot desk two seats from the sector research team. Nobody did anything wrong. The system just did not know the rule existed.
The fix is to encode the barrier into the booking layer. Zone the floor plan by team and by wall-crossing status. Restrict who can book into each zone. Make exceptions require approval rather than a quiet swap. When compliance asks who sat where during a deal window, the booking history answers in minutes instead of a week of badge-log archaeology.
The same logic applies to the trading floor. Traders need fixed or semi-fixed positions, recorded lines and no casual drop-ins from other functions. That is not a culture preference. It is a supervision requirement, and your workplace system should treat the trading floor as a restricted zone with its own booking rules, not just another neighbourhood.
Front office and back office are different problems
Front office space is client-facing, expensive and political. Back office space is where the real utilisation gains live. Treating them identically wastes money on one side and creates risk on the other.
Front office teams tend to resist hot desking, and sometimes they are right to. A banker who hosts clients three days a week has a fair claim to a consistent setting. Back office and operations teams, on the other hand, are usually the best candidates for shared neighbourhoods, because their attendance patterns are steadier and their desk kit is standard. A clean desk policy matters in both, but for different reasons: client impressions at the front, data protection at the back.
| Zone | Booking approach | Compliance considerations |
|---|
| Trading floor | Fixed or team-assigned positions, restricted booking | Supervision, recorded communications, no cross-function drop-ins |
| Deal and advisory teams | Zoned desks with approval for exceptions | Information barriers, wall-crossing status, booking audit trail |
| Front office client floors | Priority or reserved desks, bookable meeting suites | Client confidentiality, clean desk standards, visitor escort rules |
| Back office and operations | Shared neighbourhoods, team days, flexible ratios | Data protection, clear desk discipline, attendance evidence |
| Visitor and reception areas | Pre-registration tied to a named host | Sign-in records, badge control, retention and deletion of visitor data |
Visitor control that survives an audit
A paper sign-in book at reception is a liability twice over. It leaks names to anyone who glances at it, and it produces no usable record when you need one. In a regulated firm, visitor management has to answer four questions on demand: who was in the building, who authorised them, where they were allowed to go, and when they left.
Pre-registration is the piece most firms skip. When a host registers a visitor in advance, security knows who is expected, reception is faster, and the compliance record starts before the visitor reaches the door. Tie every visitor to a named employee host, print or issue a badge that shows access scope, and set retention rules so visitor data is deleted on schedule rather than kept forever by default. That last point matters as much as the first three. Holding visitor records indefinitely is its own data protection failure.
Test it before the regulator does. Pick a date from three months ago and ask your current system who visited, who hosted them and when they left. If the answer takes more than five minutes, fix the process now, on your own schedule, rather than during an audit on someone else’s.
Making the RTO mandate real
Most large financial firms now have an attendance mandate. Three days is common, four or five on some desks. What I see repeatedly is a gap between the policy and the floor. Leadership announces the mandate, the middle of the week fills up, and Fridays stay empty. HybridHero benchmarks, drawn from more than 1,500 workplace teams, show midweek attendance peaking near 60% while Fridays sit in the mid 30s.
Attendance and utilisation benchmarks in hybrid offices
Midweek attendance peak60%
Friday attendance35%
Meeting room no-shows (upper end)35%
Source: HybridHero Workplace Visibility Report benchmarks.
An unmeasured mandate is a suggestion. The teams that make attendance policies stick do three things. They anchor each team to set office days so people arrive to colleagues rather than an empty bank of desks. They give managers visibility of their own team’s pattern instead of a firm-wide average that hides everything useful. And they smooth the midweek crush by shifting some team days to Monday and Friday, which fixes both the Tuesday desk shortage and the Friday ghost town at once.
Measure it or watch it drift
Every decision above depends on data you can trust. HybridHero benchmarks put average desk space utilisation at 54% against a typical target of 60 to 70%, and meeting room no-shows at 25 to 35%. In a financial firm those numbers carry real money. City and Wall Street floor space is among the most expensive real estate a business can hold, and a floor running at half capacity is a line item the CFO will eventually find.
Pull booking, attendance, visitor and room data into one reporting view, and review it monthly with the people who own the property budget. That is what reporting and analytics built into the workplace platform gives you: utilisation by floor and team, mandate compliance by division, no-show rates by room, and the evidence base for the next lease decision. Firms like HooYu and Coface run this way today, and their stories below show what the shift looks like from the inside.
One last point on the platform itself. If a system holds your floor plans, attendance records and visitor logs, it is holding regulated-adjacent data. Ask the same questions of it that your vendor risk team asks of any supplier. HybridHero covers desks, rooms, visitors and parking in one platform, operates across roughly 40 countries, and is ISO 27001 and GDPR ready, which tends to shorten that conversation considerably.
The financial services control map
The easiest way to make a financial services workplace safer is to map each workplace workflow to the control it supports. That stops workplace software being seen as a booking tool and starts positioning it as operational control infrastructure.
| Workflow | Control objective | What to capture | What to review monthly |
|---|
| Restricted desk zones | Protect information barriers and supervisory requirements | Who booked, team, zone, date, exception approver | Cross-zone exceptions and wall-crossed staff movement |
| Trading floor access | Keep controlled teams in controlled areas | Eligible users, fixed positions, access rules | Unauthorised booking attempts and manual overrides |
| Client and vendor visits | Prove who entered, who hosted them and where they were allowed | Host, visitor, company, NDA/policy acceptance, check-in and check-out | Unclosed visits, missing host details and retention compliance |
| Attendance mandates | Turn RTO policy into observable practice | Booking, check-in, team, office, day of week | Mandate gaps by division, not just firm-wide average |
| Meeting room booking | Protect client rooms and reduce no-show waste | Booking owner, attendees, check-in, release time | No-show rate, recurring ghost bookings and peak-day shortages |
This is the same discipline operational resilience teams use elsewhere: identify the important service, define the tolerance, collect evidence and review exceptions. The workplace is no different. If the office is where controlled activity happens, the office needs controls that produce evidence.
What to ask before you buy or renew a workplace system
- Can we restrict booking by team, role or zone? If not, the system cannot enforce information barriers.
- Can we prove who visited and who hosted them? Visitor data should be private, searchable, exportable and governed by retention rules.
- Can managers see their own team pattern? Firm-wide averages hide mandate drift. Division-level data is where action happens.
- Can we join desks, rooms, visitors and parking? Separate tools create separate audit trails, which is exactly what makes evidence hard to produce.
- Can vendor risk review the platform quickly? Security, access control, data retention and support processes should be ready before procurement asks.
Do the five-minute audit test. Pick a sensitive week from last quarter and ask: who was on the restricted floor, who visited, which rooms were used and which bookings were overridden? If the answer requires four exports and a spreadsheet, the control is too fragile.
Sources and further reading
- The HybridHero Workplace Visibility Report
- Return to office statistics 2026
- Glossary: information barriers
- Glossary: front office and back office
- Glossary: trading floor
- Glossary: visitor management
- Client story: HooYu
- Client story: Coface
- Information Commissioner’s Office, for guidance on handling visitor and employee data
- Operational resilience (Financial Conduct Authority). The FCA defines operational resilience as a firm’s ability to prevent, adapt, respond to, recover and learn from disruption, with firms in scope required to operate important business services within impact tolerances by 31 March 2025.
- JPMorgan Chase joins the 5-days-a-week RTO wave (Banking Dive). JPMorgan Chase required its roughly 310,000 employees to return to the office five days a week from March 2025, joining Goldman Sachs in full-time office mandates, with more than half of staff already working in-office full time.
- JPMorgan RTO and headquarters plans highlight financial services firms' prioritization of the office (Facilities Dive (citing JLL research)). JLL research found 70% of financial services firms rank workforce expansion as a top-three expectation and 66% expect to increase office utilization, with the sector moving toward firmer and stricter attendance mandates in 2025.
- PS25/23: Tackling non-financial misconduct in financial services (Financial Conduct Authority). The FCA's PS25/23 (December 2025) sets out guidance, effective 1 September 2026, on how non-financial misconduct such as bullying and harassment can breach the Conduct Rules and factor into fit-and-proper assessments, extending coverage beyond banks to non-bank financial services firms.