FCA review highlights gaps in financial crime controls

Scammer Fraud Awareness Concept, Businessman Receiving Suspicious Message from App, Cybercrime Risk, Online Fraud, Phishing, Data Theft, Financial Scam Alert,Cross-Border Cybersecurity, Digital Safety

The Financial Conduct Authority (“FCA”) has published the findings of its review into financial crime controls across the asset management and alternatives sector, drawing on engagement with 242 firms during 2025/26.

12.08.2026

The FCA’s latest review is a timely reminder that financial crime compliance cannot be treated as a box-ticking exercise. The findings reveal a sector where many firms have established robust controls, but where weaknesses remain, particularly among businesses operating in higher-risk markets and structures.

The review examined both firms' understanding of the financial crime risks inherent in their business models and the effectiveness of the controls used to identify, manage and mitigate those risks. 

Although the FCA noted that firms generally engaged constructively with the exercise, the regulator identified a number of weaknesses in key areas including risk assessments, customer due diligence, ongoing monitoring, governance and staff training.

The FCA’s concerns fall under the following broad themes:

- Weak understanding of financial crime risk

Good practice: Regularly reviewed and documented business-wide risk assessments that accurately reflected the firm's activities and risk profile. 

FCA concerns:

  • Just over a fifth of firms either had no business-wide risk assessment (BWRA) or had one that was incomplete.
  • Some firms failed to identify and assess the inherent financial crime risks arising from their business model.
  • 18% of firms active in private markets said their BWRA did not specifically address private market risks.
  • 18% of firms had no formal customer risk assessment methodology.
  • Some firms lacked effective procedures to identify ultimate beneficial owners in complex offshore or multi-layered structures. 

Key message: Some firms appeared to underestimate their exposure to financial crime risk, resulting in inadequate risk identification and assessment processes. 

- Poor oversight of due diligence and monitoring

Good practice: Robust review processes, quality assurance and active monitoring of suspicious activity reporting. 

FCA concerns:

  • Around 40% of firms outsourced elements of financial crime compliance, but only 36% of those firms reported having full oversight of third-party AML onboarding processes.
  • 10% of firms did not verify source of wealth for high-risk customers.
  • 29% of firms had no formal transaction monitoring process
  • 7% of firms reported no systematic monitoring of customer relationships after onboarding. 

Key message: The FCA was concerned that firms were relying on informal or manual processes that may not consistently identify suspicious activity or emerging risks. 

- Insufficient screening and controls

Good practice: Effective use of management information relating to sanctions, PEPs, adverse media and broader AML risks. 

FCA concerns:

  • Some firms had weaknesses in sanctions, PEP and adverse media screening.
  • 7% of firms did not carry out repeat screening checks during the customer relationship.
  • 18% of firms reported having no formal quality assurance process for AML activities such as onboarding, alerts and reviews. 

Key message: Controls that operate only at onboarding may fail to identify changing risk profiles, sanctions exposures or adverse developments during the life of a customer relationship. 

- Governance and culture shortcomings

Good practice: Active use of management information and governance structures that support informed decision-making on financial crime risks. 

FCA concerns:

  • Only just over a third of firms discussed AML risks regularly at governance forums.
  • 36% discussed AML risks annually or less frequently.
  • Half of firms reported no investment in AML remediation or systems improvements during the previous 24 months.
  • More than half of MLROs worked part-time or had significant shared responsibilities. 

Key message: The FCA's findings suggest that some firms still view financial crime compliance primarily as a compliance function issue, rather than a board-level governance and risk management responsibility.

- Training gaps

Good practice: Tailored financial crime training, role-specific learning, practical case studies and post-training testing. 

FCA concerns:

  • Some MLROs had not received training specific to their regulatory obligations and responsibilities.
  • Some firms lacked awareness of legislative changes and industry guidance updates relating to financial crime. 

Key message: Training was often provided, but not always sufficiently targeted or updated to address evolving financial crime risks.

What does this mean for firms?

The review is not limited to identifying weaknesses. It also contains examples of good practice, including regular review of risk assessments, quality assurance of suspicious activity reports, meaningful use of management information and tailored staff training programmes. 

However, the overall message is clear. Firms should not assume that a low-risk perception of their business model removes the need for rigorous financial crime controls. The FCA expects firms to understand their specific risk profile, maintain documented and effective risk assessments, oversee outsourced compliance activities, and ensure governance arrangements remain fit for purpose. 

For asset managers and alternative investment firms, now may be a sensible time to revisit existing frameworks, test whether controls operate effectively in practice and consider whether financial crime risks have evolved since their last review. As the FCA continues to use the results of this exercise in its supervisory work, firms that fail to address identified shortcomings may increasingly find themselves under closer regulatory scrutiny.

Key Takeaways

The FCA's examples of good practice are notable not because they are sophisticated or technologically advanced, but because they demonstrate disciplined risk assessment, effective oversight, meaningful governance and ongoing staff engagement. 

By contrast, the shortcomings identified by the regulator largely stem from firms failing to embed those fundamentals consistently across their financial crime frameworks.

 

 

 

Key Contacts

Related Articles

  • Fraud in the Digital Age: what the independent review means for victims of fraud
    Expert Comment
    Fraud in the Digital Age: what the independent review means for victims of fraud
    Fraud continues to evolve at a remarkable pace. As technology becomes increasingly embedded in everyday life, fraudsters are finding new ways to exploit businesses and individuals through online scams, cyber-enabled deception, investment fraud and sophisticated impersonation techniques.
  • Consumer Duty moves from supervision to enforcement
    Expert Comment
    Consumer Duty moves from supervision to enforcement
    New publication provides insight on Consumer Duty
  • FCA consultation on penalty decision-making: practical implications for firms
    Expert Comment
    FCA consultation on penalty decision-making: practical implications for firms
    On 15 June 2026, the Financial Conduct Authority (“FCA”) published a new consultation (“the Consultation”) proposing targeted reforms to how financial penalties are assessed and applied in enforcement cases when the FCA has concluded that its rules have been broken by regulated firms or individuals .

Recognised for excellence. Chosen for care.

  • Legal 500 Top Tier Firm UK 202
  • alt tzt
  • Sunday Times Best Places to Work 2025