Background
In 2025/26, the FCA engaged with 242 firms. It wanted to gather the firms’ own assessments of the financial crime risks they face and understand their control frameworks.
The FCA evaluated firms’ controls against the:
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs 2017).
- Financial Crime Guide.
- Senior Management Arrangements, Systems and Controls (SYSC).
- Joint Money Laundering Steering Group guidance.
- Financial Action Task Force guidance.
The FCA’s findings centre on:
- How well firms understand their inherent financial crime risk.
- How well firms identify, mitigate and manage financial crime risk (control risks).
Findings
Key findings from the FCA’s engagement with firms include:
- Inherent risks: Around a fifth of firms active in private markets reported that over 30% of their customers use complex ownership structures. 85% of firms not active in private markets reported no customers using complex ownership structures. 32% of firms active in private markets reported politically exposed persons (PEPs) in their customer base, compared to 9% for firms not active in private markets. 50% of firms reported over 60% of their customer base was domiciled overseas, with firms active in private markets more likely to engage in international fund transfers.
- BWRA: Just over a fifth of all firms had either not undertaken a business wide risk assessment (BWRA) or that it was incomplete. Some firms had completed a BWRA, but it was inadequate. For example, some did not fully consider the inherent financial crime risk from the firm’s activities. An example of good practice included regular reviews of the BWRA. During the firm interviews, the FCA identified instances where firms had established review cycles for their BWRA to make sure they had an accurate risk assessment, and adequate policies, controls and procedures in place to mitigate the identified risks.
- CRA: Not all firms had a formal customer risk assessment (CRA), suggesting that some are not applying appropriate customer due diligence measures. Some firms active in private markets had not implemented effective controls for the identification of owners within multi-layered/offshore structures, highlighting weaknesses within their controls. An example of poor practice included that 18% of firms had no formal CRA methodology.
- CDD and EDD: Around 40% of firms told the FCA that they outsource customer due diligence (CDD) and enhanced due diligence (EDD) checks. Some firms had limited oversight of the work carried out by third parties and could not explain CDD/EDD processes or demonstrate that oversight of these activities was being conducted. An example of poor practice included that around 40% of all firms outsourced some part of their financial crime compliance function, yet only 36% of them had full oversight of the third party’s anti-money laundering (AML) onboarding processes.
- Ongoing monitoring: Most firms had implemented controls to monitor customer relationships, with over half undertaking periodic reviews, such as quarterly or annual refreshes, to support the effectiveness of ongoing due diligence. Over a quarter of firms indicated that they did not have a formal transaction monitoring process. An example of good practice included that 84% of firms reviewed or audited internal suspicious activities reports to check the quality of submissions.
- Screening: Among a small set of firms, the FCA found weaknesses in their approach to screening customers for PEPs, sanctions and adverse media. An example of poor practice included 7% of firms reporting that they do not conduct repeat screening checks for sanctions, PEPs, or adverse media.
- Governance: Over half of the firms’ money laundering reporting officers (MLROs) reported that they worked part-time or had shared responsibilities. The FCA found this was often commensurate with the size and nature of the business. An example of good practice included that 88% of firms tracked and used management information relating to financial crime risks, including sanctions, PEPs, adverse media alerts, and key AML metrics.
- Training: The majority of firms provided some level of financial crime training to staff. The level of training varied from tailored to more generalised financial crime training. Poor practice included some MLROs not receiving training specific to their legal obligations and responsibilities.
Reminders for firms
The FCA provides the following reminders:
- Systems and controls:
- Make sure financial crime systems and controls comply with the legal obligations under the MLRs 2017.
- Establish and maintain policies, controls and procedures to mitigate and manage the inherent financial crime risks that the firm faces.
- Risk assessments (BWRA and CRA):
- Identify and assess the risks of money laundering, terrorist financing and proliferation financing that the firm is exposed to and document this risk assessment under the MLRs 2017.
- Keep documented assessments of the risks posed by customers under the MLRs 2017.
- Due diligence, ongoing monitoring and screening
- Monitor any outsourced activities to ensure they comply with due diligence obligations under the MLRs 2017.
- Monitor business relationships on an ongoing basis, including transaction monitoring and know-your-customer reviews.
- Maintain effective, up-to-date screening systems appropriate to the nature, size and risk of the firm’s business.
- Governance and resourcing
- Use financial crime management information for effective governance and decision-making.
- Dedicate time and resource, commensurate with the size and business activities of the firm, to identify and address the financial crime risks it is exposed to.
- Training
- Make the firm’s employees aware of the law relating to money laundering, terrorist financing and proliferation financing, and train them regularly on how to recognise and deal with transactions, activities and situations which may be related to these areas of financial crime.
Next steps
The FCA encourages firms to consider its findings in the context of their own business model and activities and continue to address any gaps in their financial crime control frameworks.


