FCA puts asset managers on notice: financial crime controls falling short

TLT picks out the key points you shouldn't miss...

What's this about?

The FCA has published the findings of a sector-wide review of financial crime controls across 242 asset management and alternative investment firms. While the review highlights examples of good practice, the headline message is clear: the FCA has identified significant weaknesses in core AML controls across the sector, including business-wide risk assessments, customer due diligence, transaction monitoring, governance and oversight of outsourced compliance activities. The FCA has also confirmed that it will use the findings as part of its ongoing supervisory work and will intervene where firms fall short. Firms should therefore view the publication as more than a thematic review; it is a clear indication of the FCA's current supervisory priorities and expectations.

Ben Cooper, Partner in Risk and Financial Crime, says...

"Many of the shortcomings identified by the FCA are not new. They relate to fundamental AML controls that firms have been expected to have in place for years. The significance of this review lies not in the findings themselves, but in the FCA's clear indication that it intends to use them to drive future supervisory activity. Firms should assume that the regulator will expect them to have assessed whether similar weaknesses exist in their own frameworks and, where they do, to have taken steps to address them before the FCA asks the question. This publication feels less like a retrospective review and more like a roadmap for future FCA supervision."

The points not to miss...

Business-wide risk assessments remain a fundamental weakness across the sector

Just over a fifth of firms either had no business-wide risk assessment (BWRA) or had one that was incomplete. Others had undertaken a BWRA but failed to properly assess the financial crime risks arising from their activities. Given that the BWRA should underpin a firm's entire financial crime framework, shortcomings in this area often drive weaknesses elsewhere in the financial crime framework.

Private markets firms face materially heightened financial crime risks

Firms active in private markets are exposed to increased risk due to complex ownership structures, higher-risk customers and international fund flows. Around a fifth reported that more than 30% of their customers use complex ownership structures, while 32% reported politically exposed persons (PEPs) within their customer base, compared with just 9% of firms not active in private markets. These findings underline the heightened risk profile of the sector.

Customer risk assessments are missing or ineffective at a significant number of firms

18% of firms had no formal customer risk assessment methodology, while a small number of private markets firms lacked a formal process for verifying ultimate beneficial owners in multi-layered or offshore structures. Without a robust approach to assessing customer risk at onboarding, firms are unlikely to be able to apply appropriate due diligence measures consistently.

Outsourcing AML activities does not outsource regulatory responsibility

Around 40% of firms outsource customer due diligence (CDD) and enhanced due diligence (EDD), typically to compliance consultants or fund administrators. However, some firms were unable to explain how those checks were performed or demonstrate effective oversight of the outsourced activities. Notably, only 36% of firms that outsource elements of their AML function reported having full oversight of onboarding processes.

Transaction monitoring and ongoing customer screening have critical gaps

29% of firms reported having no formal transaction monitoring process, while 7% carried out no systematic customer monitoring after onboarding. These controls are a core part of any effective financial crime framework and, without them, firms increase the risk of suspicious activity going undetected.

Ongoing screening for sanctions, PEPs and adverse media remains inconsistent

7% of firms reported that they do not conduct ongoing screening for sanctions, PEP or adverse media risks. Failure to carry out repeat screening increases the likelihood that emerging risk factors are missed after a customer relationship has been established.

Governance arrangements are weaker than the FCA expects

More than half of MLROs reported working part-time or combining the role with other responsibilities. In addition, 36% of firms discussed AML risk only annually, or less frequently, and 18% had no formal quality assurance process covering AML onboarding, alerts and reviews. Together, these findings suggest that many firms are not giving financial crime risk the level of governance focus the FCA expects.

Investment in AML systems and controls appears to have stalled

Half of firms reported making no investment in AML remediation or system enhancements during the previous 24 months. While most firms collect management information on financial crime risks, only a little over a third regularly discuss AML risk at governance forums. This suggests that many firms are not using available data effectively to assess control effectiveness or inform management decision-making.

Training gaps persist, including at MLRO level

The FCA identified MLROs who had not received training specific to their responsibilities, as well as firms that lacked awareness of legislative and industry developments. Regular training remains essential if firms are to keep pace with evolving risks, regulatory expectations and emerging financial crime typologies.

So what should firms be doing now?

The FCA has made clear that it will use the findings from this review as part of its ongoing supervisory activity. Firms should therefore assess whether their own financial crime frameworks would withstand regulatory scrutiny and take steps to address any gaps before the FCA identifies them.

In particular, firms should consider:

  • Refreshing their business-wide risk assessment to ensure it properly reflects their activities, customer base, distribution channels, geographic exposure and emerging risks.
  • Testing whether customer risk assessment methodologies remain fit for purpose, particularly where complex ownership structures, offshore entities, PEPs or higher-risk jurisdictions are involved.
  • Reviewing oversight arrangements for outsourced AML activities and ensuring they can evidence meaningful monitoring, challenge and quality assurance.
  • Assessing the adequacy of transaction monitoring, periodic review and ongoing screening processes.
  • Evaluating whether boards and governance forums receive sufficient management information on financial crime risk and are providing effective oversight and challenge.
  • Considering whether AML systems, resourcing and training programmes remain appropriate for the scale and complexity of the business.

The key message from this review is that the FCA no longer views these issues as technical compliance shortcomings. They are governance and risk management failings that may result in supervisory intervention, remediation programmes or enforcement action. Asset managers should use this publication as an opportunity to identify and remediate weaknesses before the FCA identifies them first. Firms that take proactive steps now are likely to be better placed when faced with future supervisory engagement.

How can TLT help?

TLT regularly supports asset managers, wealth managers and alternative investment firms in assessing and enhancing their financial crime frameworks. We help firms respond to regulatory scrutiny, identify and remediate control weaknesses, and deliver practical, risk-based solutions that are proportionate to their business model and risk profile.

Our support includes:

  • Independent reviews of business-wide risk assessments, customer risk assessment methodologies and AML governance frameworks.
  • Gap analyses and remediation programmes following FCA reviews, thematic findings or supervisory engagement.
  • Reviews of outsourced AML operating models, including oversight and governance arrangements.
  • Sanctions, AML and financial crime compliance audits and health checks.
  • Financial crime training for boards, senior managers, MLROs and compliance teams.
  • Support with FCA supervisory engagement, skilled person reviews and enforcement investigations.

With the FCA signalling that financial crime controls remain a supervisory priority, firms should take the opportunity to assess whether their frameworks would withstand regulatory scrutiny and address any weaknesses before they become supervisory issues.

At a glance...

Publication link Asset management and alternative firms' financial crime controls: our findings — FCA, 22 July 2026
Publication date 22 July 2026
Who has published it? Financial Conduct Authority (FCA)
Publication type Good and poor practice findings
Any key dates? No consultation deadline. The FCA will use the questionnaire data as part of ongoing supervisory activity and will intervene where firms fall short.
What's it relevant to? Asset management; alternative investment firms; financial crime; anti-money laundering (AML); money laundering regulations (MLRs); know your customer (KYC); customer due diligence (CDD); enhanced due diligence (EDD); politically exposed persons (PEPs); sanctions; business-wide risk assessment (BWRA); MLRO; governance; compliance; private markets; proliferation financing; terrorist financing

This publication is intended for general guidance and represents our understanding of the relevant law and practice as at August 2026.  For more information see our terms & conditions.

No items found.

Date published
06 Aug 2026

Abstract overlapping curved shapes in varying shades of violet and purple on a solid violet background.

Legal insights & events

Keep up to date on the issues that matter.

Abstract yellow background with overlapping translucent olive green curved shapes.

Follow us

Find us on social media

No items found.