Payment Institution Financial Crime Controls 2026: What the FCA Expects From AML and Transaction Monitoring
- Jul 9
- 22 min read

Payment Institution Financial Crime Controls 2026: What the FCA Expects From AML and Transaction Monitoring
Financial crime remains one of the FCA’s principal supervisory priorities for Payment Institutions and Electronic Money Institutions in 2026. Payment firms sit directly within the movement of money and can be exposed to money laundering, fraud, sanctions evasion, mule accounts, terrorist financing and other forms of criminal abuse, often at high transaction volumes and across multiple jurisdictions. The FCA therefore expects financial crime controls to reflect the actual risks created by the firm’s customers, products, payment flows and geographic exposure rather than relying on generic AML policies.
The regulatory standard has also become more evidence-driven. In its 2026 Payments Regulatory Priorities, the FCA confirmed that it will continue assessing firms’ governance, capability and financial crime systems and controls and will take action where firms consistently fail to meet expected standards. Separate FCA reviews published during 2026 have also highlighted weaknesses and good practice in customer due diligence, enhanced due diligence, ongoing monitoring and sanctions controls, giving payment firms a clearer indication of what effective implementation looks like in practice.
For PIs and EMIs, a strong financial crime framework therefore needs to connect the business-wide risk assessment, customer onboarding, transaction monitoring, sanctions screening, fraud controls, suspicious activity reporting, governance and compliance monitoring into one coherent system. A firm may have sophisticated technology in individual areas and still have a weak overall framework if those controls do not respond to the risks identified in its business model or if senior management cannot demonstrate that they understand whether the controls are effective.
FCA financial crime expectations for payment firms at a glance
Area | What the FCA expects |
Business-wide risk assessment | Specific assessment of customers, products, jurisdictions, delivery channels and transaction risks |
Customer due diligence | Risk-based identification, verification and understanding of the customer relationship |
Enhanced due diligence | Additional measures for genuinely higher-risk relationships and circumstances |
Ongoing monitoring | Customer information and transaction activity kept under review throughout the relationship |
Transaction monitoring | Risk-based scenarios, thresholds, investigation and escalation aligned with actual payment activity |
Sanctions controls | Appropriate customer, counterparty and payment screening, list management and escalation |
Fraud and mule risk | Controls proportionate to how the firm can be used to receive, move or dissipate criminal proceeds |
Governance | Clear board and senior management responsibility, competent MLRO and meaningful management information |
SARs | Effective internal escalation and external reporting to the NCA where suspicion arises |
Agents and third parties | Due diligence, oversight and monitoring proportionate to delegated financial crime risk |
Compliance monitoring | Independent testing of whether controls operate effectively rather than policy review alone |
Regulatory reporting | Accurate financial crime reporting where the firm falls within applicable FCA reporting requirements |
These components should operate as a connected control framework rather than a collection of separate compliance documents. The business-wide risk assessment should determine where enhanced controls are needed, transaction monitoring should respond to the risks identified through onboarding and ongoing due diligence, and management information should show whether those controls are actually producing appropriate outcomes. Where the different parts of the framework contradict each other, the FCA is likely to question whether the firm genuinely understands its financial crime exposure.
Financial crime is a specific FCA priority for payment and e-money firms
The FCA’s 2026 Payments Regulatory Priorities identify protecting financial system integrity as one of the regulator’s central priorities for the sector. The FCA expects firms to have effective governance, appropriate capability and systems and controls that enable them to identify, assess and mitigate financial crime risk, while supervisory work will continue to examine both financial crime and operational resilience.
This focus reflects the role payment firms play within the financial system. A PI or EMI may move customer funds rapidly across accounts, institutions and borders, meaning criminals can exploit weak onboarding or monitoring controls to place, move or disguise illicit funds before suspicious activity is detected. Digital onboarding and instant payment capability can increase convenience for legitimate customers while also allowing criminal activity to scale quickly where the control environment is inadequate.
The FCA has a range of supervisory and remediation tools where it identifies serious weaknesses. These can include requiring remediation, restricting higher-risk activities, imposing voluntary or formal requirements and using skilled person reviews where independent assessment is necessary. Firms should therefore treat financial crime effectiveness as a core business risk rather than an issue owned solely by the MLRO or compliance team.
Our FCA compliance services include financial crime framework reviews, AML gap assessments and remediation for Payment Institutions and Electronic Money Institutions.
The business-wide risk assessment should drive the entire framework
The business-wide risk assessment is the foundation of an effective AML and counter-terrorist financing framework. It should identify and assess the money laundering and terrorist financing risks arising from the firm’s customers, countries and geographic areas, products, services, transactions and delivery channels, then explain how those risks are mitigated.
A payment firm operating international remittance corridors should therefore have a materially different risk assessment from an EMI providing UK consumer wallets or a merchant acquirer onboarding online businesses. The assessment should reflect the actual business rather than using standard descriptions of generic risks copied from legislation, industry guidance or another firm.
The methodology should also distinguish inherent risk from residual risk. If a business serves customers in higher-risk jurisdictions, the inherent risk may remain elevated even where enhanced controls reduce the residual exposure. Simply changing a risk rating to “medium” because controls exist can obscure the true nature of the business and prevent senior management from understanding where the firm remains most vulnerable.
The risk assessment should be reviewed when the business changes as well as periodically. New products, customer types, payment corridors, agents, distribution channels, technology providers or material increases in transaction volume can all alter the firm’s exposure and should trigger an assessment of whether existing controls remain proportionate.
Generic risk assessments remain a major weakness
One of the clearest indicators of a weak financial crime framework is a risk assessment that could apply equally to almost any financial-services business. Statements that the firm faces “money laundering risk because it processes payments” provide little practical value unless they identify how that risk arises within the specific customer journey and transaction model.
A useful assessment explains, for example, whether customers can fund accounts using third-party payments, whether value can be moved immediately after onboarding, whether transactions cross higher-risk jurisdictions, whether merchants can process payments for underlying third parties or whether agents undertake customer-facing activity on the firm’s behalf. These characteristics determine how criminals could misuse the service and therefore what controls should exist.
The FCA’s Financial Crime Guide consistently emphasises risk-based systems and controls, and its 2026 supervisory work reinforces the importance of policies being aligned with the risks firms actually face. A business-wide risk assessment should therefore be a working governance document used to design controls and allocate resources, not a regulatory document updated once a year solely for compliance records.
Senior management should also challenge the assessment. Where commercial teams are entering a new market that increases risk materially, the board should understand what additional controls, staffing and monitoring will be required before approving the expansion.
Customer due diligence must establish who the firm is dealing with
Customer due diligence is more than collecting identity documents. The firm needs to identify and verify the customer appropriately, understand the purpose and intended nature of the relationship and obtain enough information to assess the risks presented by that customer.
For an individual consumer using a relatively simple payment product, the information needed may be straightforward. A corporate customer, merchant, money-service business or complex international company can require a much deeper understanding of ownership, business activity, source of funds, expected transaction behaviour and the individuals who ultimately control the entity.
The FCA’s April 2026 multi-firm review of CDD, EDD and ongoing monitoring highlighted the importance of clear policies, appropriately designed processes and meaningful compliance monitoring. Firms should use those findings as a benchmark for testing whether their procedures work in practice rather than relying on the fact that an automated onboarding platform completes identity verification successfully.
Identity verification confirms that a person or company exists; it does not by itself explain whether the relationship makes commercial sense or what financial crime risks it presents. Effective CDD combines verification with understanding of why the customer wants the service and how they are expected to use it.
Customer risk ratings need to be meaningful
Many firms use automated customer risk-rating models that assign customers as low, medium or high risk. Automation can improve consistency and scalability, but the quality of the output depends entirely on whether the factors and weightings reflect the real financial crime risks of the business.
A model should consider relevant factors such as customer type, ownership complexity, jurisdiction, product usage, delivery channel, source of funds and expected activity. The precise methodology will differ between a retail EMI serving UK consumers and an API processing high-value international B2B payments, because the factors that meaningfully change risk are different.
Firms should also understand how the model behaves. If almost every customer is rated medium risk regardless of geography, ownership or transaction profile, the system may provide the appearance of sophistication without producing meaningful differentiation. Similarly, an excessively sensitive model that classifies large numbers of ordinary customers as high risk can overwhelm EDD teams and reduce the attention available for genuinely higher-risk cases.
Overrides should be controlled and documented. Commercial pressure should not result in risk scores being lowered simply to allow onboarding, while compliance should be able to explain why an override was appropriate and whether recurring overrides indicate a weakness in the underlying model.
Enhanced due diligence should be genuinely enhanced
Enhanced due diligence is required where higher money laundering or terrorist financing risks are identified and in other circumstances specified by the Money Laundering Regulations. The measures taken should respond to the particular risk rather than becoming a standard exercise in collecting more documents.
A higher-risk corporate customer may require deeper analysis of ownership, source of wealth, source of funds, expected counterparties and the commercial rationale for the account. A customer operating in or connected with a higher-risk jurisdiction may require additional information about transaction routes, business relationships and the purpose of payments.
The decision to proceed should also be properly governed. Where the risk is materially elevated, senior management approval should represent a genuine assessment rather than an automatic electronic sign-off performed after all other onboarding steps are complete.
EDD also continues beyond onboarding. Higher-risk relationships should receive appropriately enhanced ongoing monitoring, with review frequency and transaction scrutiny proportionate to the risks identified.
Ongoing due diligence is as important as onboarding
A customer who appeared low risk when first onboarded can change materially over time. Ownership may change, transaction activity may expand into new jurisdictions, the nature of the customer’s business may evolve or adverse information may emerge that alters the risk assessment.
The firm should therefore keep customer information up to date and review the relationship according to risk. Periodic review cycles can form part of the framework, but firms should also have event-driven triggers where material changes require reassessment before the next scheduled review.
Transaction monitoring can provide an important source of these triggers. If activity becomes inconsistent with what the customer originally said it would do, the firm should not simply close individual transaction-monitoring alerts without considering whether the customer profile itself needs updating.
The FCA’s 2026 CDD review specifically examined ongoing due diligence alongside onboarding controls. Payment firms should therefore test whether customer files evolve with the relationship rather than remaining static snapshots of information collected several years earlier.
Transaction monitoring should reflect actual payment behaviour
Transaction monitoring is one of the most important financial crime controls for a PI or EMI because customers can move money rapidly after onboarding. Effective monitoring should identify activity that is unusual or potentially suspicious in the context of the customer, product and wider financial crime risks.
There is no single FCA-prescribed set of monitoring scenarios suitable for every payment business. A remittance provider may need to focus on corridor patterns, structuring, rapid changes in beneficiary behaviour and unusual transaction velocity, while a merchant acquirer may need to consider transaction laundering, unusual merchant activity, refund patterns and discrepancies between stated and actual business activity.
An EMI operating customer accounts or wallets may need to detect rapid movement of incoming funds, multiple accounts linked by common identifiers, unusual device or IP patterns, money mule behaviour and activity inconsistent with the stated purpose of the account. B2B payment providers may need to consider complex corporate ownership, third-party payments and transaction chains involving jurisdictions or counterparties that materially change risk.
The monitoring framework should therefore be derived from the business-wide risk assessment and customer-risk methodology. Buying an established transaction-monitoring platform does not solve the regulatory problem if the scenarios and thresholds have not been configured for the firm’s actual activity.
Transaction monitoring thresholds require calibration and testing
A scenario can be conceptually correct and still perform badly if its thresholds are poorly calibrated. Thresholds set too high can miss suspicious activity, while thresholds set too low can create excessive numbers of false positives that overwhelm investigators and weaken the quality of review.
Firms should therefore test how their rules perform using actual transaction data and adjust them where there is a documented risk-based rationale. Changes should be governed properly, with records showing why a threshold was altered and how the firm satisfied itself that the revised configuration remained effective.
Backlogs are a particularly important warning sign. A firm generating thousands of alerts that cannot be investigated within a reasonable timeframe does not have an effective control merely because the system technically identified the transactions. Resourcing, prioritisation and escalation need to ensure higher-risk alerts receive timely attention.
Independent testing should also assess whether the monitoring system identifies known typologies and whether data feeds are complete. If relevant transaction fields are missing, delayed or mapped incorrectly, sophisticated monitoring rules can still produce unreliable outcomes.
Customer and transaction monitoring should connect
A mature financial crime framework does not operate customer risk and transaction monitoring as entirely separate systems. Information learned during onboarding should influence how activity is monitored, while unusual transaction behaviour should feed back into the customer risk assessment.
For example, a customer expected to make occasional domestic business payments may begin receiving high volumes of third-party funds and immediately transferring them overseas. Closing each alert individually without reconsidering the customer’s profile can miss the broader risk presented by the relationship.
The same principle applies to corporate customers whose ownership changes or merchants whose transaction patterns no longer match their stated business. Monitoring should generate intelligence about the customer rather than functioning only as a queue of isolated alerts.
Firms should therefore design escalation procedures that allow investigators to trigger customer reviews, enhanced due diligence, restrictions or exit where transaction behaviour changes the risk materially. This creates a feedback loop between onboarding, monitoring and ongoing due diligence.
Money mule risk requires specific attention
Payment accounts, e-money wallets and fast payment services can be attractive to money mules because funds can be received and moved quickly before fraud is identified. Mule networks may use genuine identities, synthetic identities, compromised accounts or individuals recruited to receive and transfer criminal proceeds.
Firms should therefore consider mule risk during both onboarding and ongoing monitoring. Multiple accounts linked through shared devices, addresses, IP information, beneficiaries or transaction patterns can provide useful indicators, as can rapid receipt and onward movement of funds that is inconsistent with the customer’s expected profile.
The FCA has separately examined firms’ use of fraud databases and mule-detection tools, reinforcing the expectation that firms use available intelligence proportionately. External data can strengthen controls, but firms still need internal analysis capable of identifying patterns specific to their own customer population.
Fraud and AML teams should also share relevant information. A payment may begin as fraud against one customer and become a money laundering issue when the proceeds enter and move through another account, so rigid organisational separation can prevent the firm from seeing the complete picture.
APP fraud and AML controls increasingly overlap
Authorised Push Payment fraud remains a major source of consumer harm, and payment firms can appear at several points in the fraudulent payment chain. A firm may serve the victim sending money, the recipient account receiving criminal proceeds or another institution through which the funds are rapidly dispersed.
The FCA’s 2026 Payments Regulatory Priorities specifically identify slowing the growth of fraud, including APP fraud, alongside tackling money laundering. Firms should therefore consider how fraud intelligence informs their broader financial crime framework and how quickly they can respond where accounts appear to be receiving criminal proceeds.
The risk-based approach to payments introduced to support APP fraud prevention also means firms can delay certain outbound payments where there are reasonable grounds to suspect fraud and further investigation is required, subject to the statutory conditions. This creates additional expectations around investigation capability, customer communication and decision-making.
The objective should be to prevent harm where possible rather than relying entirely on post-event reimbursement or suspicious activity reporting. Strong payment monitoring can identify suspicious recipient behaviour before multiple victims are affected.
Sanctions controls must keep pace with a more complex environment
Sanctions compliance has become significantly more demanding as UK sanctions regimes have expanded in scope and complexity. The FCA’s May 2026 review of sanctions systems and controls identified good and poor practice across governance, management information, risk assessment, due diligence, screening, list management, calibration, alert handling and breach reporting.
Payment firms should assess sanctions exposure across customers, beneficial owners, counterparties and payments rather than relying solely on onboarding screening. A customer who is not designated may still create sanctions risk through ownership or control relationships, transaction counterparties, geographic exposure or attempts to evade restrictions.
Screening technology should therefore be configured and tested appropriately. Firms need reliable sanctions data feeds, effective matching logic, documented threshold decisions and enough trained staff to investigate alerts within appropriate timescales.
Governance is equally important because sanctions risk can change rapidly. Management should understand emerging exposures and ensure changes to sanctions regimes are translated into operational controls without unnecessary delay.
Sanctions screening should cover more than names
Name screening remains important, but sanctions controls cannot rely solely on matching customer names against a list of designated persons. Firms may need to consider ownership and control, payment information, counterparties, vessels, jurisdictions and other relevant data depending on their business model and exposure.
Payment screening should also be designed around the information actually available within the transaction. A cross-border payment message can contain ordering-party, beneficiary, bank and free-text information that may require screening, while incomplete data can create separate risks that need investigation.
False positives are inevitable in many screening systems, but firms should understand how their configuration balances detection and operational efficiency. Excessive tuning designed primarily to reduce alert volumes can create regulatory risk if potentially relevant matches are filtered out without an adequate rationale.
The FCA’s 2026 sanctions findings also emphasise calibration, configuration and assurance testing. Payment firms should therefore be able to evidence why their screening systems are designed as they are and how they know the controls continue to operate effectively.
The MLRO must have sufficient authority and resources
The Money Laundering Reporting Officer is central to the financial crime governance framework but cannot operate effectively without appropriate authority, access and resources. The FCA will consider whether the individual has sufficient experience and understanding of the business and whether senior management provides the support required to discharge the role properly.
A rapidly growing fintech can create particular challenges. Customer numbers and transaction volumes may increase far faster than compliance staffing, leaving the MLRO responsible for a control environment that has outgrown the resources originally designed for it.
The MLRO should have access to meaningful management information covering customer-risk distribution, higher-risk relationships, EDD, monitoring alerts, investigation backlogs, SARs, sanctions issues, fraud and material control failures. Reporting should identify trends and emerging concerns rather than simply present large volumes of operational data.
The board also needs to challenge the information it receives. Financial crime oversight is not effective where the MLRO delivers reports but senior management does not ask whether controls remain appropriate for the firm’s scale and risk exposure.
Suspicious Activity Reports are an outcome of investigation, not a substitute for controls
Where a firm knows or suspects, or has reasonable grounds to know or suspect, money laundering or terrorist financing, the relevant internal and external reporting obligations need to be considered. Staff should therefore understand how to make internal suspicious activity reports and the nominated officer or MLRO should have effective processes for assessing whether disclosure to the National Crime Agency is required.
The quality of the underlying investigation matters. A firm should not treat defensive or excessive SAR filing as a substitute for understanding its customers, investigating activity properly and taking appropriate decisions about whether the relationship should continue.
Records should explain the reasoning behind material decisions, including why a SAR was or was not submitted and whether additional action was required. Where statutory confidentiality and tipping-off restrictions apply, access and communication should also be controlled appropriately.
Management information can monitor SAR volumes and themes without compromising sensitive case information. Significant increases or decreases should be understood because they may reflect changes in risk, customer activity or the effectiveness of internal detection and escalation processes.
Agents and distributors can create additional financial crime risk
Payment Institutions and EMIs frequently use agents, distributors or other intermediaries to acquire customers or provide services. These arrangements can expand distribution quickly but also create additional financial crime exposure where customer-facing activity occurs outside the regulated firm’s direct operational environment.
The principal institution remains responsible for ensuring that regulated activities conducted through agents comply with applicable requirements. Due diligence before appointment should assess ownership, management, competence, financial crime risk, geographic exposure and the proposed activities rather than functioning as a simple commercial onboarding exercise.
Ongoing monitoring is equally important. The firm should understand transaction patterns generated through individual agents, complaints, unusual customer behaviour and whether any agent’s activity differs materially from what was expected.
Where agents perform elements of CDD, the institution should be confident that information and evidence are collected to the required standard and remain accessible. Delegating an operational step does not remove the regulated firm’s responsibility for the effectiveness of the control.
Merchant acquiring presents distinct financial crime risks
Merchant acquiring can expose payment institutions to different risks from consumer account or remittance businesses. The firm may process significant transaction volumes on behalf of merchants whose underlying business activities, customer base and transaction patterns can change after onboarding.
Merchant due diligence should therefore establish the genuine nature of the business, ownership, expected products or services, transaction values, geographic exposure and the websites or channels through which sales are generated. Higher-risk sectors may require additional analysis before the relationship is approved.
Ongoing monitoring should detect changes that could indicate transaction laundering, undisclosed business models or other suspicious activity. A merchant initially approved to sell low-risk consumer goods but later processing payments inconsistent with that business should trigger investigation rather than being treated merely as commercial growth.
Chargebacks, refunds, card-not-present patterns and abrupt changes in volume can also provide useful indicators when considered alongside broader financial crime information. The framework should reflect the specific risks of acquiring rather than applying a standard corporate CDD process to every merchant.
Cross-border payments require stronger geographic risk analysis
International payment firms need a structured approach to country and corridor risk because financial crime exposure does not depend solely on the customer’s country of residence. The jurisdictions through which money originates, transits and ultimately arrives can all affect the risk of the transaction.
Country risk models should consider relevant authoritative sources, sanctions exposure, FATF status, corruption, financial crime threats and the firm’s own experience. They should also recognise that no single external country list determines the complete risk assessment.
Corridor behaviour can be especially important for remittance businesses. A customer resident in a low-risk jurisdiction may still generate higher risk where funds are repeatedly routed to high-risk locations, unusual beneficiaries or regions inconsistent with the stated purpose of the relationship.
Risk appetite should explain which exposures the firm will accept, which require enhanced controls and which fall outside the business’s tolerance. Commercial teams should understand those boundaries before entering new markets rather than discovering them after products have launched.
Outsourced AML technology does not outsource regulatory responsibility
Payment firms increasingly rely on specialist vendors for identity verification, screening, transaction monitoring, fraud detection and case management. These tools can significantly improve control capability, but the regulated firm remains responsible for ensuring that the technology is appropriate and operates effectively.
Vendor selection should therefore include more than a feature comparison. The firm needs to understand data inputs, configuration, model limitations, update processes, service resilience and how quickly issues can be identified and corrected.
The same applies to managed compliance services. Outsourcing alert investigation or parts of customer due diligence can be legitimate, but the PI or EMI must retain oversight, access to information and enough internal expertise to challenge performance.
Contracts should support regulatory access, audit, data protection, business continuity and exit. A firm that cannot explain how its outsourced monitoring system works or how it validates the provider’s performance will struggle to demonstrate effective regulatory control.
AI can improve financial crime controls but requires governance
AI and machine-learning tools are increasingly used for transaction monitoring, fraud detection, adverse media and behavioural analysis. They can identify complex relationships and patterns that static rules may miss, particularly where payment volumes are high.
The regulatory question remains whether the firm understands and controls the system sufficiently. Models should be validated, monitored and governed, with clear processes for reviewing performance, handling false positives and identifying unintended blind spots.
Human judgement remains important in higher-risk decisions. Automated models can prioritise investigations or identify anomalies, but the firm should be cautious about allowing opaque systems to make material customer or suspicious-activity decisions without appropriate oversight.
Changes to a model should also be controlled. A vendor update that materially changes detection logic can alter the firm’s financial crime framework even if no internal policy has changed, so technology governance should connect directly with compliance oversight.
Compliance monitoring should test effectiveness, not simply policy completion
A financial crime compliance monitoring programme should assess whether controls work in practice. Reviewing whether a policy was updated on time or whether mandatory training was completed provides useful governance information but does not demonstrate that customer risk ratings, EDD or transaction monitoring are effective.
Testing should therefore include customer files, higher-risk relationships, transaction-monitoring alerts, sanctions cases, SAR processes and other areas based on risk. Samples should be selected intelligently so that the firm can identify systemic weaknesses rather than merely confirm that a small number of straightforward files were completed correctly.
The FCA’s April 2026 CDD review specifically considered compliance monitoring and audit, reinforcing the importance of independent challenge. Where testing identifies repeated weaknesses, management should investigate root causes and assess whether the problem extends beyond the sample reviewed.
Remediation should then be tracked to completion and retested. Closing an action because a procedure has been rewritten is insufficient where the underlying operational control has not been shown to improve.
Independent AML audits can provide valuable assurance
The Money Laundering Regulations require relevant persons, where appropriate to the size and nature of the business, to establish an independent audit function to examine and evaluate the adequacy and effectiveness of AML policies, controls and procedures. The appropriate structure depends on the firm, but independence from the activities being tested is essential to meaningful assurance.
For a PI or EMI, an AML audit can examine the business-wide risk assessment, customer-risk methodology, CDD and EDD, transaction monitoring, sanctions, SAR governance, training, agents and senior management oversight. The review should identify whether controls are both designed appropriately and operating effectively.
The value comes from challenge rather than producing a certificate that the firm is “compliant”. A well-designed review should identify weaknesses before the FCA does and give management a prioritised plan for remediation.
Boards should also ensure that significant findings receive appropriate oversight and follow-up. Repeated issues that remain unresolved across several reviews can be more concerning than an isolated control failure that is identified and corrected promptly.
Financial crime controls are critical during FCA authorisation
Financial crime is one of the most scrutinised areas in an API or EMI application. The FCA needs to understand the risks created by the proposed business and be satisfied that the applicant has the systems, people and governance required to manage those risks from the point authorisation is granted.
Applicants should therefore avoid generic AML documentation. The business-wide risk assessment, AML policy, customer-risk methodology, CDD and EDD procedures, transaction-monitoring framework, sanctions controls and governance arrangements should all correspond with the business model described in the regulatory business plan.
The framework should also be operationally credible. If the application projects hundreds of thousands of customers and high transaction volumes but relies on one junior compliance employee and largely manual monitoring, the FCA is likely to question whether resources are proportionate.
Senior management must understand the framework rather than delegating every regulatory question to an external adviser. The FCA assesses whether the people running the institution are capable of overseeing the regulated business once the application is approved.
Financial crime controls should evolve as the firm grows
A framework that was proportionate when a firm launched may become inadequate as customer numbers, transaction volumes and geographic exposure increase. Payment firms can scale quickly, particularly where technology allows new customers or markets to be added without equivalent growth in operational headcount.
Management should therefore monitor indicators that controls are reaching capacity. Rising alert backlogs, repeated manual overrides, delayed customer reviews, increasing EDD volumes or investigation quality issues can all indicate that the framework needs additional resources or redesign.
New products also change risk. Adding cards, merchant acquiring, stablecoin conversion, new payment corridors or additional agents can introduce financial crime typologies that existing monitoring rules were never designed to identify.
The business-wide risk assessment and control framework should therefore develop with the business. Regulatory compliance is not achieved permanently at authorisation; it requires continuous adjustment as the operating model changes.
What should boards and MLROs review in 2026?
Boards should begin by asking whether the financial crime risk assessment still describes the business accurately. If the firm has grown, entered new markets, added products or changed distribution channels since the assessment was last substantively revised, the control framework should be tested against those developments.
CDD, EDD and ongoing monitoring should then be reviewed using the FCA’s April 2026 findings as a practical benchmark. The firm should assess whether risk ratings genuinely differentiate customers, whether higher-risk relationships receive meaningful enhanced measures and whether customer information is updated when transaction behaviour or circumstances change.
Transaction monitoring and sanctions systems should be tested for data completeness, calibration, alert handling and investigation quality. This should include whether backlogs exist, whether repeated alerts generate broader customer review and whether sanctions list changes are implemented reliably.
Finally, the board should assess governance and assurance. The MLRO should have sufficient authority and resources, management information should identify meaningful trends, and independent testing should provide evidence that controls operate as intended rather than simply confirming that required policies exist.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting supports Payment Institutions, Electronic Money Institutions and fintech businesses with financial crime frameworks, FCA authorisation, compliance reviews and regulatory remediation. Our work focuses on aligning the AML and financial crime control environment with the actual business model, customer journey, payment flows and regulatory risk rather than applying generic documentation.
We can conduct a complete financial crime gap assessment covering the business-wide risk assessment, customer-risk methodology, CDD and EDD, ongoing monitoring, transaction monitoring, sanctions, fraud, SAR governance, agents, outsourcing, compliance monitoring and board oversight. The review identifies both regulatory gaps and operational weaknesses and provides a prioritised remediation plan based on the significance of each issue.
For firms preparing an API or EMI application, we develop the financial crime framework as part of the wider authorisation project, ensuring that the risk assessment, policies, transaction-monitoring approach and governance correspond with the regulatory business plan and financial forecasts. For existing regulated firms, we can independently review the effectiveness of current controls and support remediation where weaknesses have been identified through FCA supervision, internal assurance or other regulatory reviews.
We also support firms facing significant financial crime remediation, including governance improvements, risk-assessment redesign, monitoring-framework reviews and preparation for regulatory engagement. To discuss a financial crime audit, AML gap assessment, remediation project or FCA authorisation, contact Buckingham Capital Consulting.
Frequently asked questions
What AML controls does the FCA expect from a Payment Institution or EMI?
The FCA expects financial crime controls to be proportionate to the nature, scale and complexity of the business and the risks it actually faces. A robust framework normally includes a business-wide risk assessment, customer risk assessment, CDD and EDD, ongoing monitoring, transaction monitoring, sanctions controls, suspicious activity reporting, competent MLRO oversight and appropriate compliance monitoring. These components should operate together rather than as separate policies that are disconnected from the firm’s actual payment activity.
Does the FCA require transaction monitoring for payment firms?
Payment and e-money firms need systems and controls capable of identifying and managing money laundering and other financial crime risks, and ongoing monitoring under the Money Laundering Regulations includes scrutiny of transactions where applicable. The transaction-monitoring framework should reflect the firm’s customer types, products, jurisdictions and payment flows rather than relying on generic scenarios. Firms should also test data quality, thresholds, alert investigation and whether monitoring outcomes feed back into customer-risk assessments.
How often should an AML risk assessment be reviewed?
The business-wide risk assessment should be kept up to date and reviewed when material changes occur as well as through the firm’s normal periodic review process. New products, customer types, jurisdictions, agents, payment corridors or material growth can change financial crime exposure and should trigger reassessment where relevant. A review should be substantive and should consider whether existing controls remain appropriate rather than simply changing the document date.
What are the FCA’s main financial crime concerns for payment firms in 2026?
The FCA’s 2026 Payments Regulatory Priorities emphasise effective governance, capability and systems and controls to tackle money laundering and fraud, including APP fraud. Separate 2026 supervisory publications have focused on CDD, EDD, ongoing monitoring and sanctions controls, including governance, risk assessment, screening, calibration and compliance monitoring. Payment firms should use these publications to test whether their current framework provides evidence of effective implementation rather than relying primarily on written policies.
Can Buckingham Capital Consulting carry out an AML or financial crime review?
Yes. Buckingham Capital Consulting can conduct an independent financial crime gap assessment or compliance review for Payment Institutions, EMIs and fintech businesses, covering governance, AML risk assessments, CDD and EDD, transaction monitoring, sanctions, fraud, SAR processes and compliance monitoring. We can also develop and implement remediation plans where weaknesses are identified and support FCA authorisation applications or regulatory engagement where the review forms part of a wider regulatory project.


