Financial crime compliance is the area in which the FCA has taken the largest number of enforcement actions against regulated firms, and the area in which supervisory findings recur most consistently across sectors. The obligations are not sector-specific in their structure: the same framework of risk assessment, due diligence, monitoring, reporting and governance applies whether a firm is a wholesale bank, a payment institution, an insurance intermediary or a cryptoasset business.
What differs is the risk profile the framework must address, and it is the mismatch between generic frameworks and specific risk that produces most findings.
This article sets out the sources of obligation, the components of a financial crime framework, the deficiencies the FCA has identified, and the areas where firms most often have difficulty.
Sources of obligation
| Source | What it requires |
|---|---|
| Money Laundering Regulations 2017 | Risk assessment, policies and controls, customer due diligence, enhanced due diligence, record keeping, training, and the appointment of a nominated officer |
| Proceeds of Crime Act 2002 | Suspicious activity reporting, and the principal money laundering offences |
| Terrorism Act 2000 | Terrorist financing offences and reporting |
| Sanctions and Anti-Money Laundering Act 2018 and UK sanctions regulations | Asset freezing, prohibitions on dealing, and reporting to the Office of Financial Sanctions Implementation |
| SYSC 3 and SYSC 6 | Systems and controls, including the obligation to counter the risk of being used to further financial crime |
| The FCA's Financial Crime Guide | Non-binding guidance setting out the FCA's expectations across each element of the framework |
The Financial Crime Guide is not a rulebook, but supervisory assessment is conducted substantially against it. Firms that have not mapped their framework against the Guide should expect to be asked why.
The business-wide risk assessment
The business-wide risk assessment is the document on which the entire framework rests. Every subsequent control should be traceable to a risk identified in it.
The Regulations require firms to identify and assess the risks of money laundering and terrorist financing to which the business is subject, taking account of the firm's customers, the countries or geographic areas in which it operates, its products and services, its transactions, and its delivery channels.
The FCA has identified weak business-wide risk assessments as a recurring deficiency, alongside over-reliance on third-party due diligence and underestimation of money laundering risk.
The characteristics of an assessment that will withstand scrutiny are consistent.
It reflects the firm's actual business. Customer types the firm actually onboards, jurisdictions it actually touches, products it actually offers, channels it actually uses. An assessment drawn from a sector template describes the sector, not the firm.
It is granular where risk concentrates. Where a firm has a small number of high-risk relationships, corridors or products, those should be addressed specifically rather than absorbed into a category average.
It drives control design. Each identified risk should be linked to the control mitigating it, and the residual risk after control should be stated.
It is updated on change, not on schedule. A new product, a new corridor, a new customer segment, a new distribution channel or a material change in volume should trigger reassessment. An assessment refreshed annually while the business has changed materially in the interim is out of date the moment the change occurred.
It is approved at the right level. Senior management approval, with evidence that the assessment was considered rather than noted.
Customer due diligence
Due diligence obligations scale with risk.
Standard due diligence requires identification and verification of the customer, identification of beneficial owners where the customer is a legal person, and information on the purpose and intended nature of the relationship.
Simplified due diligence may be applied where the firm has determined that the relationship presents a lower degree of risk, but the determination must be documented and monitoring continues.
Enhanced due diligence is required in specified circumstances including high-risk third countries, politically exposed persons, correspondent relationships, and any situation the firm has assessed as presenting higher risk. It requires additional information on the customer and beneficial owner, on the source of funds and source of wealth where relevant, and senior management approval.
Ongoing monitoring requires scrutiny of transactions to ensure consistency with the firm's knowledge of the customer, and keeping documents and information up to date.
Two points recur in supervisory findings.
The first is reliance. Where a firm relies on a third party to conduct due diligence, the firm remains liable for compliance. The FCA has identified over-reliance on third-party due diligence as a specific weakness. Reliance arrangements require a written agreement, immediate access to the underlying information, and the firm's own assessment of the third party's standards.
The second is the trigger for review. Periodic review on a fixed cycle by risk rating is common, but risk is dynamic. Trigger-based review, on a change in behaviour, in ownership, in jurisdiction or in product usage, is what supervisory expectation increasingly reflects.
Transaction monitoring
Transaction monitoring is assessed on effectiveness rather than existence.
Data completeness. The monitoring system must receive complete and accurate data from every relevant source. Incomplete feeds are among the most common and most serious deficiencies, because the firm cannot know what it has not seen. Reconciliation between source systems and the monitoring platform should be documented.
Rule calibration. Thresholds and scenarios should reflect the risks identified in the business-wide risk assessment and the firm's actual transaction profile. Calibration should be reviewed periodically and after material changes to the business.
Tuning and testing. The firm should be able to evidence that the rules detect the behaviours they are intended to detect. Above-the-line and below-the-line testing, and periodic model validation where the system is model-driven.
Alert handling. Alerts investigated to a documented standard, with quality assurance over closure decisions and evidence that closures are not driven by volume pressure.
Governance. Changes to rules, thresholds and scenarios approved and recorded, with an audit trail of what changed, when and why.
Sanctions
Sanctions obligations are strict liability. A breach occurs whether or not the firm intended it and whether or not the firm's controls were reasonable.
The framework requires screening of customers and, where relevant, of transactions and counterparties, against the UK sanctions list and any other applicable regime. Screening should occur at onboarding, on list updates, and on a periodic basis.
Screening alone does not discharge the obligation. Firms should also address ownership and control, where an entity not itself designated may nonetheless be caught because a designated person owns or controls it; evasion typologies, including the use of intermediaries and complex ownership structures; and reporting to the Office of Financial Sanctions Implementation where a designated person is identified or a breach occurs.
Firms operating internationally should assess which regimes apply to their activity. UK, EU, US and UN regimes differ in scope and in designation.
Governance and the MLRO
The Regulations require the appointment of a nominated officer to receive internal suspicion reports and make external reports to the National Crime Agency. The FCA additionally requires a Money Laundering Reporting Officer with responsibility for the firm's anti-money laundering systems and controls.
Where SM&CR applies, financial crime responsibility is allocated as a Prescribed Responsibility.
The characteristics the FCA looks for are the same as in any control function: sufficient seniority and authority to challenge business decisions, adequate resource, direct access to senior management and the board, and information sufficient to identify emerging risk.
Board and senior management engagement is assessed on evidence of challenge rather than on the existence of a reporting line. Management information should be sufficient to allow challenge: alert volumes and outcomes, due diligence backlogs, high-risk relationship numbers, sanctions screening performance, training completion, and open findings.
Suspicious activity reporting
Internal reporting to the nominated officer, and external reporting to the National Crime Agency where knowledge or suspicion arises.
Areas of supervisory interest include the timeliness of internal reporting and the time taken to reach a decision; whether defence against money laundering consent is sought where required, and whether transactions proceed before consent is received; the quality of report content; the tipping-off risk and how staff are trained on it; and whether reporting volumes are consistent with the firm's risk profile, since both under-reporting and defensive over-reporting attract attention.
Training
Training must be relevant to the role and to the firm's actual risks. Generic annual e-learning completed by all staff regardless of function does not meet the standard where the firm has identifiable, specific risks.
The FCA looks for role-appropriate content, evidence of completion, testing of understanding rather than attendance, and additional training for higher-risk roles including onboarding, transaction monitoring and relationship management.
Building a defensible framework
Risk assessment reflecting the firm's actual business, granular where risk concentrates, driving control design, and updated on change.
Policies and procedures that describe what the firm actually does, reviewed when practice changes, and traceable to the risks identified.
Customer due diligence proportionate to risk, with documented rationale for risk ratings and for the application of simplified or enhanced measures.
Transaction monitoring with complete data, calibrated rules, evidenced testing and quality-assured alert handling.
Sanctions screening at onboarding, on list update and periodically, addressing ownership and control and evasion typologies.
Reporting with defined internal escalation, timely external reporting, and quality control over report content.
Governance with an empowered MLRO, board information sufficient for challenge, and clear allocation of responsibility.
Assurance through compliance monitoring that tests the operation of controls, and periodic independent review.
Training that is role-appropriate and tested.
Where firms most often have difficulty
The risk assessment describes the sector rather than the firm. A template populated with generic risk categories, with no analysis of the firm's own customers, corridors, products and channels.
Controls are not traceable to risk. The framework exists but no line runs from an identified risk to the control mitigating it, so the firm cannot demonstrate that its controls address its risks.
Transaction monitoring data is incomplete. Feeds missing, delayed or partial, with no reconciliation between source systems and the monitoring platform.
Rules have never been tuned. Thresholds set at implementation and unchanged since, generating either unmanageable alert volumes or implausibly few.
Alert closure is volume-driven. Investigation quality degrades under backlog, with no quality assurance sampling to detect it.
Reliance is undocumented. Third-party due diligence relied upon without a written agreement, without access to underlying records, and without assessment of the third party's standards.
Sanctions screening ignores ownership and control. Names screened against the list without assessment of whether a designated person owns or controls the entity.
Management information does not enable challenge. Volumes reported without outcomes, trends or exceptions, so the board has nothing to challenge.
Findings remain open. Issues identified by compliance monitoring, internal audit or the regulator that pass their target date without escalation.
Firms preparing for supervisory engagement or an s166 review may find our note on FCA regulatory health checks and thematic review preparation relevant. Where deficiencies have been identified, our guide to FCA policy and compliance monitoring remediation addresses how remediation programmes are structured.
Sector-specific considerations
Payment institutions and electronic money institutions. Agent and distributor networks, corridor risk, transaction monitoring across the payment chain, and the completeness of data where the firm does not originate every leg. See our guides to payment institutions and electronic money institutions.
Wholesale banks. Correspondent banking relationships, trade finance, complex ownership structures, and the interaction between financial crime and market abuse surveillance. See our guide to wholesale banking compliance.
Insurance. Ghost broking, application fraud, and claims fraud, with particular exposure in digital distribution channels. See our guide to FCA compliance for insurers.
Mortgage firms. Application fraud, identity risk and misuse of consumer data. See our guide to FCA compliance for mortgage providers.
Cryptoasset firms. Source of funds, blockchain analytics, exposure to mixers and high-risk exchanges, and the travel rule. See our guide to FCA compliance for cryptoasset firms.
About Regulatory Counsel
Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.
Our financial crime work covers business-wide risk assessment design and review, customer due diligence framework and risk rating methodology, transaction monitoring calibration and effectiveness review, sanctions screening assessment, suspicious activity reporting process review, MLRO and governance framework design, financial crime policy and procedure drafting, independent AML audit under Regulation 21, remediation programme design and delivery, s166 skilled person support, and preparation for supervisory engagement and thematic review.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA and Government publications and take advice on their specific circumstances.
Frequently Asked Questions
An assessment of the money laundering and terrorist financing risks to which a firm is subject, taking account of its customers, the countries and geographic areas in which it operates, its products and services, its transactions and its delivery channels. It is required by the Money Laundering Regulations 2017 and forms the foundation of the firm's control framework.
On material change rather than on a fixed schedule. A new product, corridor, customer segment or distribution channel, or a material change in volume, should trigger reassessment. Annual refresh alone is insufficient where the business has changed in the interim.
Yes, subject to conditions, but the firm remains liable for compliance. Reliance requires a written agreement, immediate access to the underlying information, and the firm's own assessment of the third party's standards. The FCA has identified over-reliance on third-party due diligence as a recurring deficiency.
Complete and accurate data from every relevant source, rules calibrated to the risks identified in the business-wide risk assessment and to the firm's actual transaction profile, evidence that the rules detect what they are intended to detect, alert investigation to a documented standard with quality assurance, and governance over changes to rules and thresholds.
No. Screening is necessary but not sufficient. Firms must also address ownership and control, where an entity not itself designated may be caught because a designated person owns or controls it, and evasion typologies including the use of intermediaries and complex structures. Sanctions obligations are strict liability.
The Money Laundering Regulations require a nominated officer to receive internal suspicion reports and make external reports. The FCA additionally requires an MLRO with responsibility for anti-money laundering systems and controls. Where SM&CR applies, financial crime responsibility is allocated as a Prescribed Responsibility.
Information sufficient to enable challenge: alert volumes and outcomes, due diligence backlogs, high-risk relationship numbers, sanctions screening performance, suspicious activity reporting volumes and timeliness, training completion, and open findings with owners and deadlines.
Non-binding guidance setting out the FCA's expectations across each element of a financial crime framework. It is not a rulebook, but supervisory assessment is conducted substantially against it, and firms should map their framework to it.
