top of page

FCA Financial Crime Compliance 2026: What Regulated Firms Need to Do

  • 6 days ago
  • 12 min read
FCA Financial Crime Compliance 2026: What Regulated Firms Need to Do

FCA financial crime compliance requires firms to understand how their business can be used for money laundering, terrorist financing, sanctions evasion, fraud, bribery, corruption and other criminal activity and to maintain controls proportionate to those risks. The exact legal framework depends on the type of firm because the Money Laundering Regulations, FCA Handbook provisions and sector-specific regimes do not apply identically to every regulated business. A strong framework therefore begins with an accurate regulatory perimeter and risk assessment rather than a generic AML manual.


Financial crime remains one of the FCA's four strategic priorities for 2026/27, and the regulator is increasingly using data and targeted sector reviews to identify weak controls. During 2026 the FCA published detailed findings on sanctions, insurance financial crime controls and financial crime frameworks in asset management, while its enforcement and supervisory work continues to focus heavily on crime prevention. Firms should therefore expect the regulator to test whether controls are effective in practice, not simply whether required policies exist.


FCA financial crime compliance at a glance

Area

What the FCA expects

Regulatory perimeter

Clear understanding of which MLR and FCA requirements apply to the firm

Business-wide risk assessment

Specific assessment of products, customers, geographies, channels and transactions

Customer risk assessment

Meaningful risk rating linked to due diligence and monitoring

CDD

Identification, verification, beneficial ownership and understanding the relationship

EDD

Additional measures responding to genuinely higher-risk relationships and situations

Ongoing monitoring

Customer information and activity kept under review throughout the relationship

Transaction monitoring

Risk-based scenarios, calibration, investigation and escalation

Sanctions

Customer, ownership, counterparty and transaction screening where relevant

Fraud

Prevention, detection, investigation and connection with AML controls

SARs

Effective internal escalation and external reporting where suspicion arises

Governance

Senior ownership, competent MLRO and meaningful management information

Training

Role-specific awareness and specialist competence

Compliance monitoring

Independent testing of design and operating effectiveness

Regulatory reporting

Accurate FCA financial crime returns where the firm is in scope


The FCA's Financial Crime Guide is an important source of good and poor practice, but firms should remember that it is guidance and not a substitute for the underlying law and applicable Handbook rules. Its application also varies by firm type, with payment and e-money institutions, for example, supervised for MLR compliance under a different statutory architecture from mainstream FSMA firms. Regulatory mapping should therefore be precise.


Start with the correct legal framework

The Money Laundering Regulations 2017 impose AML and CTF requirements on businesses within scope, including customer due diligence, risk assessment, policies and procedures, record keeping, training and suspicious activity governance. FCA-authorised firms can also be subject to SYSC financial crime systems-and-controls rules, Principles, sector rules and specific sanctions or fraud expectations. The exact combination depends on the activity and regulatory status.


This distinction matters because not every FCA-regulated business is an MLR relevant person for every activity. A pure mortgage broker, for example, is not automatically subject to the full MLR framework merely because it is FCA authorised, while lenders and other businesses can be in scope. Payment and e-money firms are supervised by the FCA for MLR obligations even though the application of certain Handbook financial crime rules differs.


A compliance framework should therefore identify the legal source of each control. This avoids both under-compliance and the opposite problem of imposing unnecessary procedures that obscure the risks that actually matter. Senior management should understand which obligations are mandatory and which measures are risk-based controls chosen by the firm.


The business-wide risk assessment should drive everything else

The business-wide risk assessment should identify how financial crime can arise from the firm's customers, products, services, jurisdictions, transactions and delivery channels. It should be specific enough to explain why one part of the business is higher risk than another and what controls respond to that risk. Generic statements that every financial institution faces money laundering risk provide little practical value.


The assessment should distinguish inherent risk from residual risk. A high-risk product does not become inherently low risk because strong controls exist, although those controls can reduce residual exposure. Maintaining that distinction helps management understand where the firm remains most vulnerable and where compliance resources should be concentrated.


The BWRA should also evolve when the business changes. New products, customer groups, jurisdictions, distribution channels, agents, acquisitions or material growth can change risk before the scheduled annual review. Change governance should therefore include a financial crime assessment and update the control framework where necessary.


Customer risk assessment should produce meaningful differentiation

Customer risk rating is useful only if it changes the level of due diligence and monitoring applied. Models should consider relevant factors such as customer type, ownership, geography, product use, delivery channel, source of funds and expected activity, with weightings that reflect the firm's actual experience and risk assessment. A system that rates almost every customer medium risk provides limited regulatory value.


Automation can improve consistency but needs governance. The firm should understand the model logic, how data quality affects outcomes and when manual override is permitted. Overrides should be documented and monitored because repeated changes may indicate a problem with the model or commercial pressure on the control environment.


Customer risk should also be dynamic. Transaction behaviour, ownership changes, adverse information or new jurisdictions can require reassessment before the normal review date. Transaction monitoring and ongoing due diligence should therefore feed back into the customer risk model.


CDD must establish who the firm is actually dealing with

Customer due diligence involves more than verifying an identity document or company number. Firms should identify and verify customers and relevant beneficial owners, understand the purpose and intended nature of the relationship and obtain enough information to assess risk. The depth of work should be proportionate to the relationship and regulatory requirements.


Corporate customers require particular care. Ownership chains, control, business activities, expected counterparties and source of funds can be materially more complex than individual retail onboarding. Automated company searches can support the process but do not replace the need to understand who ultimately owns or controls the relationship where the regulations require it.


CDD evidence should remain accessible and current. Where the firm cannot explain why a customer was accepted or what activity was expected, transaction monitoring becomes much less effective because there is no meaningful baseline against which to assess behaviour. Quality assurance should therefore test understanding as well as document completeness.


Enhanced due diligence should respond to the actual higher risk

EDD is required in specified circumstances and where the firm identifies a higher risk of money laundering or terrorist financing. The additional measures should address the risk presented rather than become a standard request for more documents. A complex corporate structure, high-risk jurisdiction, politically exposed person or unusual source of wealth can each require a different response.


Source of funds and source of wealth are often misunderstood. The firm should determine which information is relevant to the risk and obtain evidence sufficient to support its conclusion rather than collect large volumes of documents without analysis. Senior approval should be meaningful where required and should explain why the risk is acceptable.


Higher-risk customers should also receive enhanced ongoing monitoring. It is inconsistent to conduct detailed EDD at onboarding and then monitor the customer in exactly the same way as a low-risk relationship. Review frequency, transaction scrutiny and escalation should reflect the residual risk.


Ongoing monitoring keeps customer understanding current

A customer can change significantly after onboarding. Ownership can change, transaction behaviour can expand, adverse information can emerge or the customer can begin using products in ways not contemplated originally. Ongoing due diligence should therefore keep the firm's understanding of the relationship current.


Periodic review can form part of the process, but event-driven triggers are equally important. Unusual transactions, changes to directors or beneficial owners, sanctions exposure or material changes in business activity can require immediate reassessment. Systems should allow investigators to trigger a customer review rather than simply close an alert in isolation.


The FCA's 2026 sector reviews continue to emphasise the quality of ongoing monitoring. Firms should test whether customer files evolve with the relationship and whether recurring transaction concerns are reflected in risk ratings. Static onboarding records are unlikely to provide effective risk management for long-term relationships.


Transaction monitoring should be built from risk

Transaction monitoring should identify activity that is unusual or suspicious in the context of the customer and the firm's risk profile. There is no universal FCA scenario library that every business can adopt without modification. A bank, payment institution, insurer, investment firm and crypto business have different transaction patterns and therefore need different monitoring approaches.


Scenario design should connect to the BWRA and customer-risk model. Thresholds should be calibrated using real data and reviewed when activity changes, while backlogs should be treated as a control weakness rather than an ordinary operations metric. A system that generates alerts faster than investigators can assess them is not necessarily effective.


Data completeness is equally important. Missing payer, beneficiary, device, jurisdiction or product information can undermine the logic of a sophisticated monitoring tool. Independent testing should therefore assess data lineage, scenario performance, alert investigation and whether findings feed back into customer risk.


Sanctions compliance requires more than name screening

UK sanctions compliance can require firms to identify designated persons, ownership and control, counterparties, payment information and other risk factors depending on the business. The FCA's May 2026 sanctions systems and controls review highlighted governance, risk assessment, screening, list management, calibration and assurance as important areas. Firms should use current regulatory findings to test whether their controls work beyond onboarding.


Name screening needs current data and appropriately calibrated matching. Excessive tuning to reduce false positives can create missed matches, while poor data quality can make even a well-designed engine ineffective. Alert handling should be timely and investigators should understand the basis for clearing or escalating potential matches.


Ownership and control analysis is particularly important where the customer itself is not directly designated. Sanctions exposure can arise through corporate structures and counterparties, and firms should have processes for obtaining and assessing relevant information. Significant issues should be escalated through clear governance.


Fraud and financial crime controls should connect

Fraud can generate money laundering risk when proceeds enter or move through financial institutions, while AML monitoring can identify indicators of fraud. Firms should therefore avoid rigid organisational separation that prevents relevant intelligence moving between fraud and AML teams. Shared indicators, escalation and case information can improve detection and reduce duplication.


Mule accounts are a clear example. Device links, shared beneficiaries, rapid movement of funds and unusual transaction patterns can identify networks that individual customer reviews miss. Payment and banking firms should use appropriate data to identify relationships between accounts rather than assessing each customer only in isolation.


Customer treatment remains relevant when controls intervene. Account restrictions, payment delays and investigations should be governed so that legal obligations are met without unnecessary harm. Consumer Duty and financial crime can therefore interact directly in in-scope retail businesses.


Suspicious Activity Reports require judgement and evidence

Where the statutory suspicion threshold is met, relevant staff should know how to escalate internally and the nominated officer or MLRO should determine whether external reporting to the National Crime Agency is required. The process should be timely, confidential and supported by records explaining the decision. Defensive reporting should not become a substitute for meaningful investigation.


The quality of internal referrals matters. Staff need enough training to recognise indicators and provide relevant information without attempting to conduct the MLRO's full assessment themselves. Case management should preserve evidence and control access where tipping-off or confidentiality restrictions apply.


Management information can monitor volumes, themes and processing times without compromising case confidentiality. Significant changes in SAR activity can indicate changes in risk or control effectiveness and should be understood. Boards should receive enough information to oversee the framework without being exposed unnecessarily to sensitive case detail.


The MLRO needs authority, expertise and resources

A financial crime framework can fail even where policies and technology are strong if the MLRO lacks authority, capacity or access to senior management. The individual should understand the firm's business and risk profile and have enough resources to oversee due diligence, monitoring, sanctions, SARs and remediation effectively. A rapidly growing firm should reassess resourcing as volumes and complexity increase.


Management information should help the MLRO identify trends and capacity constraints. Higher-risk customers, EDD, alert backlogs, sanctions cases, fraud, SARs and overdue reviews are examples of useful indicators where relevant. Reporting should support decisions rather than overwhelm senior management with unfiltered operational data.


Board challenge is equally important. Financial crime should not be treated as a technical issue delegated entirely to the MLRO. Senior management should understand the material risks the firm accepts and the investment required to control them.

Training should be role-specific


All relevant staff need enough financial crime awareness to understand their responsibilities, but training should be adapted to the decisions they actually make. Customer-facing staff need practical escalation guidance, investigators need deeper technical competence and senior managers need enough understanding to challenge the control environment. One generic annual e-learning module is unlikely to meet all of those needs.


Training should reflect current risks and regulatory developments. Sanctions changes, new fraud typologies, products or jurisdictions can require targeted updates between annual cycles. Firms should also test understanding where roles are higher risk.


Competence should be evidenced through more than attendance records. Quality assurance, case reviews and supervisory feedback can reveal whether staff apply the rules correctly. Repeated operational errors may indicate a training or process design weakness even where completion rates are high.


Independent testing should assess operating effectiveness

Compliance monitoring, internal audit or another independent assurance function should test whether financial crime controls actually work. Reviewing whether policies exist and training was completed provides limited assurance about the effectiveness of CDD, EDD, transaction monitoring or sanctions screening. Testing should therefore use files, cases, system data and re-performance where appropriate.


Sampling should be risk-based. Higher-risk customers, overridden decisions, closed sanctions alerts and suspicious transaction cases can provide more insight than a sample composed entirely of straightforward low-risk files. Findings should determine whether weaknesses are isolated or systemic.


Remediation should be retested. A policy rewrite does not demonstrate that customer files, monitoring or investigations improved. Closure criteria should require evidence that the underlying control now operates effectively.


Financial crime is a major authorisation issue

The FCA assesses financial crime capability during authorisation and registration where relevant. A business-wide risk assessment, CDD framework, transaction monitoring, sanctions controls and governance should correspond with the business model and volumes described in the application. Generic policies can create significant questions where the FCA cannot see how the proposed controls would manage the stated risks.


Management competence is equally important. Senior individuals should be able to explain the firm's financial crime risks and how controls work rather than defer every question to an external consultant. The regulator is assessing whether the applicant itself can operate compliantly after authorisation.


Financial resources should also support the framework. A business projecting rapid growth needs enough compliance staff and technology to process due diligence and monitoring at the expected scale. Under-resourcing can therefore become both a financial crime and authorisation concern.


Financial crime should be included in regulatory change governance

New products, markets, technologies and distribution arrangements can change financial crime exposure materially. A change approval process should therefore include an assessment of customer risk, geography, transaction flows, sanctions, monitoring and staffing before launch. The BWRA and relevant controls should be updated where the change alters risk.


AI and new monitoring technology require equivalent governance. Firms should understand model limitations, data inputs, false positives and how changes affect detection. Vendor claims of improved accuracy do not replace validation in the firm's own environment.


Regulatory change also matters. FCA guidance, sanctions regimes and AML legislation continue to evolve, and firms should distinguish current requirements from proposals. Horizon scanning should result in owned implementation actions rather than a list of publications circulated to the compliance team.


A practical FCA financial crime review

A strong review begins with the regulatory perimeter and BWRA and then traces whether identified risks are reflected in customer risk, due diligence, transaction monitoring, sanctions, fraud and governance. The objective is to assess the framework as one connected system rather than review each policy separately. Gaps often become visible where different control components use inconsistent risk definitions.


Testing should then examine operational evidence. Customer files, EDD decisions, transaction alerts, sanctions cases, SAR governance, backlogs and management information can be sampled according to risk. The review should identify root causes, regulatory significance and whether the weakness affects a wider population.

The output should be prioritised. Critical weaknesses that can expose the firm to criminal misuse or regulatory breach need rapid action, while lower-risk documentation improvements can follow. Remediation plans should identify responsible owners, deadlines, evidence and retesting requirements.


How Buckingham Capital Consulting can help

Buckingham Capital Consulting provides specialist financial crime compliance support to regulated financial-services firms, with particular depth in payments, electronic money and cross-border financial businesses. We can conduct complete financial crime gap assessments covering the BWRA, customer-risk methodology, CDD, EDD, ongoing monitoring, transaction monitoring, sanctions, fraud, SAR governance, training, compliance monitoring and board oversight. Reviews are tailored to the firm's actual business model and legal obligations.


We also support remediation after FCA findings, internal audits or control failures. This can include redesigning risk assessments, strengthening monitoring and governance, improving policies and procedures, reviewing resourcing and preparing evidence for regulatory engagement. For new applicants, the financial crime framework can be developed as part of the wider authorisation project so that the regulatory business plan and controls remain consistent. To discuss an FCA financial crime audit, AML gap assessment, sanctions review or remediation programme, contact Buckingham Capital Consulting.


Frequently asked questions

What does FCA financial crime compliance include?

It can include AML and CTF risk assessment, CDD, EDD, ongoing monitoring, transaction monitoring, sanctions, fraud, SARs, governance, training and independent testing. The exact legal requirements depend on the firm's regulatory status and activities because the Money Laundering Regulations and FCA Handbook do not apply identically to every firm. A compliance review should therefore start with the regulatory perimeter.


What is a business-wide risk assessment?

The BWRA identifies and assesses the financial crime risks created by the firm's customers, products, services, jurisdictions, transactions and delivery channels. It should explain inherent risk, the controls in place and the residual exposure and should drive the design of due diligence and monitoring. It should be updated when material business changes alter the risk profile.


Does the FCA require transaction monitoring?

Firms subject to the relevant AML framework need ongoing monitoring and appropriate systems and controls capable of identifying suspicious activity, with the precise approach based on risk. Transaction monitoring should therefore reflect the business, customers and transaction flows rather than rely on generic scenarios. Data quality, calibration and investigation capacity are as important as the monitoring software itself.


How often should an AML compliance review be carried out?

There is no universal frequency that replaces ongoing monitoring and assurance. The firm should test controls according to risk and conduct additional review when products, jurisdictions, systems or regulatory expectations change materially. An annual independent review is common in many firms, but the appropriate scope and frequency should reflect the nature and scale of the business.


Can the FCA take action for weak financial crime controls even if no money laundering is proven?

Yes. FCA expectations focus on whether firms maintain adequate systems and controls, not only whether a specific criminal transaction is ultimately proven. Weak governance, risk assessment, due diligence, monitoring or sanctions controls can therefore create regulatory issues in their own right. Firms should remediate control weaknesses before they result in harm or enforcement.


#FCA Financial Crime Compliance 2026: What Regulated Firms Need to Do

 
 
bottom of page