FCA flags financial crime control weaknesses in UK asset management – here’s 7 focus areas for firms

Published: 01 Sep 2026

By Gaia Udage, Principal Consultant

At a glance

The Financial Conduct Authority (FCA)’s latest review of the UK asset management sector sends a clear message: financial crime controls remain firmly in the regulatory spotlight. While the FCA identified examples of strong anti-money laundering (AML) frameworks and effective governance, it also found recurring weaknesses in areas such as risk assessments, customer due diligence, ongoing monitoring, sanctions screening and oversight of outsourced providers. The findings serve as a timely reminder for asset managers to review their controls, address gaps and ensure their AML frameworks remain proportionate, well documented and capable of responding to evolving financial crime risks. In this article, we spotlight seven key areas requiring close attention.

Financial crime controls under the microscope: what the FCA’s findings mean for asset managers

In July 2026, the FCA published findings from its engagement with asset management and alternative investment firms, highlighting both good and poor practice in firms’ financial crime frameworks.

The FCA noted that certain business models and customer profiles – including private equity and hedge fund management – can expose firms to heightened financial crime risks. Risks include customers with complex ownership structures, politically exposed persons (PEPs), and facilitation of international fund flows.

Such features can increase the risk of money laundering, sanctions evasion and the concealment of beneficial ownership. As a result, firms operating in these areas are expected to maintain robust systems and controls capable of identifying, assessing and mitigating financial crime risks, including:

  • Business-wide risk assessments (BWRA)
  • Customer risk assessments (CRA)
  • Due diligence and outsourcing
  • Ongoing monitoring
  • Screening controls
  • Governance and resourcing
  • Training

Taking each of these systems and controls in turn, we’ll dive a little deeper into seven key points that UK asset managers should focus on to avoid falling foul of the FCA’s scrutiny.

1. Business-wide risk assessments should be conducted and reviewed regularly

A BWRA is a legal requirement under the Money Laundering Regulations (MLRs). The FCA found that firms demonstrating good practice had established regular review cycles to ensure their BWRAs remained current and accurately reflected the risks arising from their business activities. These reviews were supported by documented policies, controls and procedures designed to address identified risks.

However, the FCA also identified some firms with incomplete or non-existent BWRAs, as well as others that failed to assess risks associated with specific business activities such as private markets investing. In certain cases, firms had not considered the risk factors prescribed under the MLRs or had omitted wider financial crime risks altogether.

The FCA emphasised that even where a firm’s business model remains relatively unchanged, the BWRA should be reviewed periodically, and any review should be appropriately documented.

2. Customer risk assessments must be formal and documented

The review also identified weaknesses in customer risk assessment processes. Not all firms had established a formal CRA framework, raising concerns about whether customer due diligence measures were being applied consistently and proportionately.

The FCA reminded firms that close relationships with clients or frequent client interactions do not remove the requirement to conduct and document formal risk assessments. Informal knowledge of a client is not a substitute for a structured, risk-based approach.

Examples of poor practice included the absence of documented CRAs, lack of verification of ultimate beneficial owners (UBOs) and failure to classify customers according to risk. These shortcomings can make it difficult for firms to justify the level of due diligence applied and demonstrate compliance with regulatory obligations.

3. Due diligence and outsourcing require strong oversight

Customer due diligence (CDD) and enhanced due diligence (EDD) remain fundamental components of an effective AML framework. Although firms are permitted to outsource their due diligence processes, the FCA observed that some firms exercised limited oversight over third-party providers.

In a number of cases, firms were unable to explain how CDD and EDD checks were conducted or demonstrate how outsourced activities were monitored. The FCA reiterated that while outsourcing may be permitted, responsibility for compliance with the MLRs remains with the regulated firm.

The regulator also identified instances where high-risk customers’ sources of wealth had not been adequately verified. This is particularly concerning where firms deal with PEPs or clients operating in higher-risk jurisdictions.

4. Effective ongoing monitoring means periodic reviews, defined triggers and real-time surveillance

The FCA’s findings suggest that ongoing monitoring remains one of the weaker areas of AML compliance across some firms.

Good practice included the submission of high-quality internal suspicious activity reports (SARs), together with quality assurance reviews designed to improve reporting standards and identify areas for enhancement.

However, the FCA found that some firms failed to conduct systematic monitoring after customer onboarding. This included a lack of periodic reviews, trigger-based monitoring or real-time surveillance of customer activity.

In addition, some firms had no formal transaction monitoring arrangements and no documented criteria for identifying suspicious activity. Without effective ongoing monitoring, firms may fail to identify changes in customer behaviour, ownership structures or risk profiles that warrant additional scrutiny.

5. Screening controls must be maintained

Under the MLRs, firms must identify PEPs and comply with UK sanctions requirements. Screening is therefore a critical control within any financial crime framework.

The FCA observed instances where firms failed to conduct ongoing screening against sanctions lists, PEP databases or adverse media sources. Where screening is not refreshed regularly, firms risk missing material changes in customer circumstances and may fail to identify emerging sanctions or reputational risks.

6. Governance and resourcing matter

The FCA also highlighted governance and resourcing as critical components of an effective financial crime framework.

While it may be appropriate for smaller firms to have a part-time Money Laundering Reporting Officer (MLRO) or an individual performing multiple compliance functions, larger firms should ensure that AML resourcing remains proportionate to the scale and complexity of their operations.

Examples of good practice included the use of management information relating to sanctions alerts, PEP hits, adverse media findings and key AML metrics to support governance and decision-making.

In contrast, poor practice included limited investment in AML systems and remediation programmes, infrequent discussion of financial crime risks at governance forums and a lack of formal quality assurance of AML activities. These weaknesses can reduce senior management’s ability to effectively oversee financial crime risks.

7. Training must be relevant and up to date

The FCA observed that firms with stronger frameworks typically delivered role-specific financial crime training supported by mandatory testing. Training covered areas such as AML detection techniques, cyber-enabled financial crime risks and practical case studies relevant to employees’ responsibilities.

Conversely, some firms had gaps in MLRO training and demonstrated limited awareness of legislative developments and industry guidance. Given the evolving nature of financial crime risks, firms should ensure that both staff and senior management receive regular and relevant training.

Key takeaway

The FCA’s review provides a clear reminder that firms should regularly assess whether their financial crime controls remain effective and proportionate to their risk profile. Particular attention should be given to business-wide and customer risk assessments, oversight of outsourced due diligence activities, ongoing monitoring, screening arrangements, governance frameworks and staff training.

Firms should consider the FCA’s findings in the context of their own business model, identify any gaps in their existing arrangements and take steps to strengthen controls where necessary. A proactive approach to remediation can help reduce regulatory risk while enhancing the firm’s ability to identify and prevent financial crime.

How IQ-EQ can help

We support firms in developing and maintaining effective financial crime control frameworks, including gap analysis, independent process reviews, and e-learning modules and assessments. To find out more please click here or contact us to discuss how we can help.


About the author

Gaia Udage is a Principal Consultant in our UK compliance consultancy team, focused on providing compliance consulting advice, completing regulatory filings and applications, training, compliance monitoring and the drafting of policies and procedures to fit a range of client business types.

Working with IQ-EQ has been seamless – you and your team understand our business, advise us appropriately, and handle your side of our collective partnership so that we can focus on making good investment decisions. Evan Gibson SVP, Merchants Capital

Get in touch with us today

We’re ready to listen.

Make an enquiry

Interested in joining our team?

We are always on the lookout for passionate people that possess IQ and EQ to join our growing team.

View job vacancies