
FCA puts asset managers on notice: financial crime controls falling short
TLT picks out the key points you shouldn't miss...
What's this about?
The FCA has published the findings of a sector-wide review of financial crime controls across 242 asset management and alternative investment firms. While the review highlights examples of good practice, the headline message is clear: the FCA has identified significant weaknesses in core AML controls across the sector, including business-wide risk assessments, customer due diligence, transaction monitoring, governance and oversight of outsourced compliance activities. The FCA has also confirmed that it will use the findings as part of its ongoing supervisory work and will intervene where firms fall short. Firms should therefore view the publication as more than a thematic review; it is a clear indication of the FCA's current supervisory priorities and expectations.
Ben Cooper, Partner in Risk and Financial Crime, says...
"Many of the shortcomings identified by the FCA are not new. They relate to fundamental AML controls that firms have been expected to have in place for years. The significance of this review lies not in the findings themselves, but in the FCA's clear indication that it intends to use them to drive future supervisory activity. Firms should assume that the regulator will expect them to have assessed whether similar weaknesses exist in their own frameworks and, where they do, to have taken steps to address them before the FCA asks the question. This publication feels less like a retrospective review and more like a roadmap for future FCA supervision."
The points not to miss...
Just over a fifth of firms either had no business-wide risk assessment (BWRA) or had one that was incomplete. Others had undertaken a BWRA but failed to properly assess the financial crime risks arising from their activities. Given that the BWRA should underpin a firm's entire financial crime framework, shortcomings in this area often drive weaknesses elsewhere in the financial crime framework.
Firms active in private markets are exposed to increased risk due to complex ownership structures, higher-risk customers and international fund flows. Around a fifth reported that more than 30% of their customers use complex ownership structures, while 32% reported politically exposed persons (PEPs) within their customer base, compared with just 9% of firms not active in private markets. These findings underline the heightened risk profile of the sector.
18% of firms had no formal customer risk assessment methodology, while a small number of private markets firms lacked a formal process for verifying ultimate beneficial owners in multi-layered or offshore structures. Without a robust approach to assessing customer risk at onboarding, firms are unlikely to be able to apply appropriate due diligence measures consistently.
Around 40% of firms outsource customer due diligence (CDD) and enhanced due diligence (EDD), typically to compliance consultants or fund administrators. However, some firms were unable to explain how those checks were performed or demonstrate effective oversight of the outsourced activities. Notably, only 36% of firms that outsource elements of their AML function reported having full oversight of onboarding processes.
29% of firms reported having no formal transaction monitoring process, while 7% carried out no systematic customer monitoring after onboarding. These controls are a core part of any effective financial crime framework and, without them, firms increase the risk of suspicious activity going undetected.
7% of firms reported that they do not conduct ongoing screening for sanctions, PEP or adverse media risks. Failure to carry out repeat screening increases the likelihood that emerging risk factors are missed after a customer relationship has been established.
More than half of MLROs reported working part-time or combining the role with other responsibilities. In addition, 36% of firms discussed AML risk only annually, or less frequently, and 18% had no formal quality assurance process covering AML onboarding, alerts and reviews. Together, these findings suggest that many firms are not giving financial crime risk the level of governance focus the FCA expects.
Half of firms reported making no investment in AML remediation or system enhancements during the previous 24 months. While most firms collect management information on financial crime risks, only a little over a third regularly discuss AML risk at governance forums. This suggests that many firms are not using available data effectively to assess control effectiveness or inform management decision-making.
The FCA identified MLROs who had not received training specific to their responsibilities, as well as firms that lacked awareness of legislative and industry developments. Regular training remains essential if firms are to keep pace with evolving risks, regulatory expectations and emerging financial crime typologies.
So what should firms be doing now?
The FCA has made clear that it will use the findings from this review as part of its ongoing supervisory activity. Firms should therefore assess whether their own financial crime frameworks would withstand regulatory scrutiny and take steps to address any gaps before the FCA identifies them.
In particular, firms should consider:
- Refreshing their business-wide risk assessment to ensure it properly reflects their activities, customer base, distribution channels, geographic exposure and emerging risks.
- Testing whether customer risk assessment methodologies remain fit for purpose, particularly where complex ownership structures, offshore entities, PEPs or higher-risk jurisdictions are involved.
- Reviewing oversight arrangements for outsourced AML activities and ensuring they can evidence meaningful monitoring, challenge and quality assurance.
- Assessing the adequacy of transaction monitoring, periodic review and ongoing screening processes.
- Evaluating whether boards and governance forums receive sufficient management information on financial crime risk and are providing effective oversight and challenge.
- Considering whether AML systems, resourcing and training programmes remain appropriate for the scale and complexity of the business.
The key message from this review is that the FCA no longer views these issues as technical compliance shortcomings. They are governance and risk management failings that may result in supervisory intervention, remediation programmes or enforcement action. Asset managers should use this publication as an opportunity to identify and remediate weaknesses before the FCA identifies them first. Firms that take proactive steps now are likely to be better placed when faced with future supervisory engagement.
How can TLT help?
TLT regularly supports asset managers, wealth managers and alternative investment firms in assessing and enhancing their financial crime frameworks. We help firms respond to regulatory scrutiny, identify and remediate control weaknesses, and deliver practical, risk-based solutions that are proportionate to their business model and risk profile.
Our support includes:
- Independent reviews of business-wide risk assessments, customer risk assessment methodologies and AML governance frameworks.
- Gap analyses and remediation programmes following FCA reviews, thematic findings or supervisory engagement.
- Reviews of outsourced AML operating models, including oversight and governance arrangements.
- Sanctions, AML and financial crime compliance audits and health checks.
- Financial crime training for boards, senior managers, MLROs and compliance teams.
- Support with FCA supervisory engagement, skilled person reviews and enforcement investigations.
With the FCA signalling that financial crime controls remain a supervisory priority, firms should take the opportunity to assess whether their frameworks would withstand regulatory scrutiny and address any weaknesses before they become supervisory issues.
At a glance...
This publication is intended for general guidance and represents our understanding of the relevant law and practice as at August 2026. For more information see our terms & conditions.
Get in touch
Get in touch
Insights & events

FCA puts asset managers on notice: financial crime controls falling short

Tipping off under POCA: the first Court of Appeal authority arrives

FCA raises the bar on Consumer Duty outcomes monitoring: what your firm needs to do now

Inside the minds of money mules: what new Home Office research means for your anti-financial crime framework

FCA updates complaints and root cause analysis good practice guidance – what firms need to know

FCA product governance review: what firms must do now to get product design right under Consumer Duty

Payroll providers and HMRC AML supervision: why registration is the easy part

Consumer Duty enforcement is here – 11 investigations and counting

FCA publishes landmark Mills Review into AI and retail financial services: what firms need to know

Consumer Duty: Distribution chains, manufacturer obligations and board reporting – what firms need to know

What the first three OFSI Settlements tell us about UK sanctions enforcement

FCA flags financial crime control gaps across insurance sector in new multi-firm review

Government announces once-in-a-generation overhaul of the home buying and selling system

FCA sets out research agenda that will shape regulation for the next five years

UK anti-money laundering rules overhauled: what financial services firms must do now

FCA consults on targeted mortgage rule reforms to support first-time buyers and underserved consumers




%20%C3%94%C3%87%C3%B4%20790px%20X%20451px%2072ppi21.jpg)


%20%C3%94%C3%87%C3%B4%20790px%20X%20451px%2072ppi2.jpg)


%20%E2%80%93%20790px%20X%20451px%2072ppi%20LONDON9.jpg)




