fs banner

FCA's findings on Customer Due Diligence processes and controls: Good and poor practices

TLT picks out the key points you shouldn't miss...

What’s this about?

The FCA has published its findings from its multi-firm review of Customer Due Diligence (CDD), Enhanced Due Diligence (EDD) and ongoing controls, highlighting the good and poor practices it observed. The findings revolve around firms’ approaches to their policies and procedures, CDD and EDD processes, as well as compliance monitoring and audit.

The review focuses on how firms design, implement and oversee their CDD and EDD frameworks, including policies and procedures, operational execution, senior management oversight, and compliance monitoring and audit arrangements.

Our Head of Risk and Financial Crime, Ben Cooper says...  

“We encourage clients to consider the FCA’s findings inlight of their own policies and procedures. Monitoring customer due diligence is an increasing area of supervisory focus for regulators, and firms should take the opportunity to use these findings to identify where their own customer due diligence processes can be improved.”

The points not to miss...

Good practice in policies and procedures

Policies clearly distinguishing CDD from EDD measures and comprehensive, detailed control frameworks for identifying politically exposed persons (PEPs) were indicators of good practice. Firms were also able to demonstrate that policies were actively embedded in day‑to‑day onboarding and review processes, rather than operating as static or purely theoretical documents.

Poor practice in policies and procedures

Poor practice included: (i) inadequate detail (i.e. no clear explanation of what additional measures are required in EDD); (ii) insufficient information regarding when periodic reviews should be undertaken and next steps; (iii) lack of alternative methods for checking and verifying customer identity; and (iv) firms failing to follow their own policies. In some cases, deficiencies in documentation created challenges in evidencing compliance to supervisors, even where firms believed risks were being managed operationally.

Good practice in CDD processes

CDD processes that functioned well contained clear guidance for EDD measures and were tailored for the specific financial crime risks posed by individual customers. Documenting each stage of a firm’s EDD process was also a strong factor. This included maintaining clear audit trails to demonstrate why particular risk assessments were reached and how enhanced measures were applied in practice.

Poor practice in CDD processes

Poor practice in CDD processes was indicated by a clear lack of information and relevant documentation, such as evidence of the specific EDD steps taken or details on the purpose of the business relationship. There were also concerns regarding effective governance and oversight, with requirements for senior management approval not specified. The FCA noted that weaknesses in governance arrangements increased the risk of inconsistent decision‑making and insufficient challenge for higher‑risk relationships.

Good practice in compliance monitoring and audit

Firms which demonstrated good practice in terms of compliance conducted thematic reviews of their CDD processes through external audit. They also carried out regular audits of their CDD systems and controls. These firms were better able to identify systemic issues and drive continuous improvement across their control frameworks.

Poor practice in compliance monitoring and audit

Firms exhibiting poor practice in this area included: lacking detail regarding how they were conducting quality control checks, having no independent reviews of CDD/EDD in place, and having no version control over their documentation. Inadequate version control and review evidence also increased the risk of outdated or inconsistent standards being applied across the business.

How TLT can help

We have extensive experience in helping firms with their financial crime compliance, including undertaking assurance reviews and GAP-style analyses, as well as supporting them with developing and implementing enhanced policies and procedures.

We regularly support firms in responding to FCA reviews and supervisory interventions, including remediation planning, governance enhancements and preparation of management information.

If you would like to discuss your firm’s current approach, please get in touch.

At a glance...

Publication link Firms' customer due diligence processes and controls: out findings (FCA)
Published date 8 April 2026
Who has published it? FCA
Publication type Regulatory report
Any key dates? N/A
What's it relevant to? CDD, EDD

Authors: Hannah Yeager and Hannah Stanley

This publication is intended for general guidance and represents our understanding of the relevant law and practice as at April 2026. Specific advice should be sought for specific cases. For more information see our terms & conditions.

No items found.

No items found.
Date published
24 Apr 2026

Abstract overlapping curved shapes in varying shades of violet and purple on a solid violet background.

Legal insights & events

Keep up to date on the issues that matter.

Abstract yellow background with overlapping translucent olive green curved shapes.

Follow us

Find us on social media

No items found.
No items found.