FCA Financial Crime Controls Review: 10 Key Findings and 10 Priority Actions for Firms | Kroll

Regulatory Updates

July 30, 2026

FCA Financial Crime Controls Review: 10 Key Findings and 10 Priority Actions for Firms

The Financial Conduct Authority’s (FCA) recent review of financial crime controls across the asset management and alternatives sector serves as a timely reminder that firms must continually assess whether their frameworks are fit for purpose, proportionate to their risks and capable of withstanding regulatory scrutiny.

The review highlighted a number of recurring weaknesses across governance, risk assessments, customer due diligence, screening and monitoring arrangements, particularly among firms operating in private markets.

While many firms demonstrated robust practices and a good understanding of their obligations, the FCA identified several areas where firms appeared to have underestimated their inherent financial crime risks or failed to implement sufficiently effective controls.

The findings should not be viewed solely as regulatory observations; they represent a practical roadmap for firms seeking to strengthen their financial crime frameworks and reduce exposure to money laundering, terrorist financing, sanctions evasion and broader financial crime risks.

Against this backdrop, firms should take the opportunity to challenge their existing arrangements, assess any gaps and ensure that their control environment remains aligned with both regulatory expectations and evolving business models.

Ten Key Findings for Firms

  • Private Market Firms Face Elevated Financial Crime Risks

    Firms operating in private markets are exposed to greater inherent risk due to complex ownership structures, international fund flows, offshore vehicles and a higher prevalence of politically exposed persons (PEPs). These characteristics require enhanced scrutiny and stronger controls.
  •  
  • Understanding Risk is Fundamental

    The FCA expects firms to demonstrate a clear understanding of their inherent financial crime risks and document how those risks have been assessed and mitigated. Generic AML frameworks are unlikely to be sufficient.  
  • BWRA Remain a Concern

    More than one-fifth of firms either had no Business-Wide Risk Assessment (BWRA) or had produced one that was incomplete, highlighting a significant weakness in risk management frameworks. For firms with a BWRA, regular and documented reviews should take place even if the business model remains largely unchanged.
  •  
  • Risk Assessments Must Reflect the Actual Business Model

    Several firms maintained BWRAs that did not adequately consider the specific risks arising from their activities, particularly those associated with private markets and cross-border transactions.
  •  
  • CRAs Require Greater Rigor

    Customer Risk Assessments (CRAs) remain a key area of weakness, with a notable proportion of firms lacking a formal, documented methodology for assessing customer risk.

 

  • Beneficial Ownership Verification Remains Critical

    The FCA identified weaknesses in identifying and verifying ultimate beneficial owners (UBOs), particularly in relation to multilayered, offshore and complex corporate structures.
  •  
  • Outsourcing Does Not Remove Accountability

    Although many firms outsource elements of customer due diligence and enhanced due diligence, responsibility for compliance remains with the regulated firm. Effective oversight of third-party providers is essential.
  •  
  • Transaction Monitoring Frameworks Need Strengthening

    A significant proportion of firms reported having no formal transaction monitoring process, raising concerns regarding their ability to identify suspicious transactions, changes in ownership structures, evolving sanctions risks and shifts in customer behavior that could warrant enhanced scrutiny.
  •  
  • Screening Controls Require Ongoing Attention

    Weaknesses were identified in sanctions, PEP and adverse media screening processes, including instances in which firms failed to undertake ongoing screening throughout the customer lifecycle.

  •  
  • Governance and Training Are Key Enablers

    Effective financial crime frameworks depend on strong governance, meaningful management information, appropriately resourced MLRO functions and targeted financial crime training programs.

Ten Priority Actions for Firms

  • Conduct a Comprehensive BWRA Review

    Confirm that the BWRA is current, documented and accurately reflects the firm's business model, customer base, products, jurisdictions and distribution channels. It should also consider sanctions, terrorist financing and proliferation financing risks where relevant. Benchmark the assessment against FCA findings and the latest National Risk Assessments.
  •  
  • Validate Customer Risk Assessment Methodologies

    Ensure every customer is subject to a documented risk assessment and that risk ratings are consistently applied. Test whether customer risk classifications directly influence the level of CDD and EDD undertaken.

  •  
  • Review Ultimate Beneficial Ownership Controls

    Carry out a targeted review of UBO identification and verification procedures, particularly for offshore entities, trusts, nominee arrangements and layered ownership structures. Ensure evidential standards are robust and consistently applied.

  •  
  • Strengthen Oversight of Outsourced AML Activities

    Where AML activities are outsourced, ensure active oversight of third-party onboarding processes by considering the methodology applied by service providers and conducting periodic assurance reviews. Evidence of effective challenge and oversight should be maintained.

  •  
  • Review Enhanced Due Diligence Arrangements

    Assess whether EDD processes adequately address higher-risk customers, PEPs, higher-risk jurisdictions and complex ownership structures. Particular focus should be placed on source-of-funds and source-of-wealth verification.

 

  • Enhance Transaction Monitoring Controls

    Implement or strengthen documented, risk-based transaction monitoring processes. Ensure suspicious activity escalation routes are clearly defined and operate effectively among business areas, Compliance and the MLRO.
  •  
  • Test Screening Arrangements

    Review sanctions, PEP and adverse media screening controls to ensure they operate on an ongoing basis rather than solely at onboarding. Regularly test alert management, investigation and escalation procedures.
  •  
  • Improve Governance and Management Information

    Provide boards and risk committees with meaningful financial crime management information, including indicators covering customer onboarding, high-risk customer populations, sanctions alerts, suspicious activity reporting, training completion rates and overdue reviews.
  •  
  • Assess MLRO Capacity and Effectiveness

    Determine whether the MLRO function is appropriately resourced, sufficiently independent and equipped with the authority, expertise and time required to discharge its responsibilities effectively. Where the role is part time, firms should document the rationale and evidence of adequacy.
  •  
  • Refresh Financial Crime Training Programs

    Deliver targeted and role-specific training for boards, senior management, front-office staff, operations teams, Compliance and MLROs. Training should reflect current regulatory expectations and cover sanctions, proliferation financing, private-market risks and lessons emerging from the FCA review.

Conclusion

The FCA’s findings demonstrate that financial crime compliance is no longer simply about having policies and procedures in place. Regulators increasingly expect firms to provide clear evidence that their frameworks are risk-based, effective and embedded throughout the organization.

Firms should view this review as an opportunity to undertake a comprehensive health check of their financial crime control environment and challenge whether existing arrangements remain fit for purpose.

Boards, Risk Committees, MLROs and Senior Managers should ask themselves one simple question: If the FCA were to undertake a review of our firm tomorrow, could we clearly demonstrate that our risk assessments, due diligence processes, screening controls, transaction monitoring arrangements, governance framework and outsourced oversight activities are operating effectively and proportionately to our risk profile?

Those firms that cannot confidently answer "yes" should prioritize a structured gap analysis and remediation program now, before supervisory scrutiny identifies the weaknesses for them.

The FCA has clearly signaled where its expectations lie. Firms that take proactive steps today will be better positioned to demonstrate compliance, protect their business from financial crime risk and respond confidently to future regulatory engagement.

If you require any assistance with any of the items mentioned above or would like to learn more about how Kroll can support you, please reach out to your usual contact at Kroll or any of the contacts listed below.

Stay Ahead with Kroll

Financial Services Compliance and Regulation

In the ever-evolving financial services landscape, Kroll's award-winning team offers comprehensive regulatory and compliance services, guiding clients through registration, licensing, and compliance support to minimize risks and enhance efficiency globally.

UK Financial Services Compliance and Regulation Solutions

The UK regulatory landscape is constantly evolving, with new Financial Conduct Authority (FCA) initiatives introduced and working practices regularly updated at a European level.