FCA Publishes Findings on Asset Management and Alternative Firms’ Financial Crime Controls
The Financial Conduct Authority (FCA) has published its findings on the financial crime controls of asset management and alternative firms. The review is intended to help firms reflect on the financial crime risks of their business and the effectiveness of the systems and controls they have in place.
The FCA’s findings draw on the 2025/26 survey results from 242 asset management and alternative firms together with interviews with senior staff at a smaller subset of firms.
The FCA’s findings include practical examples of what it regards as good and poor practice and should be closely considered by firms benchmarking their own financial crime frameworks.
The FCA identified significant financial crime failings by asset management and alternative firms. Common failings included:
- Business-wide risk assessment: failure to undertake a business-wide risk assessment adequately or at all;
- Customer risk assessment: failure to operate a formal, documented risk assessment;
- Customer due diligence and enhanced due diligence: failure to maintain adequate oversight of outsourced due diligence and enhanced due diligence checks;
- Ongoing monitoring: failure to operate a formal transaction monitoring process or conduct systematic monitoring of customers following onboarding;
- Screening: failure to conduct repeat screening for PEPs and sanctions risk throughout the customer relationship;
- Governance: failure to invest appropriately in AML systems and controls, inadequate MLRO resource (including MLROs acting part-time or with shared responsibilities where inappropriate for the size and nature of the firm’s business) and inadequate board-level oversight of financial crime risk; and
- Training: failure to provide MLROs with training specific to their legal obligations, and to maintain staff awareness of legislative and industry guidance updates.
Asset management and alternative firms may see increased FCA enforcement activity in this area, particularly in respect of private markets funds where the FCA sees higher inherent financial crime risks as a result of complex ownership structures, politically exposed person (PEP) exposure and international transfers. Private markets funds have previously been a focus area for the FCA’s financial crime supervisory work (see FCA Dear CEO letter, 26 February 2025).
The report also lands against a backdrop of intensifying enforcement activity: the FCA’s recent arrest of four individuals as part of a coordinated fraud and money laundering investigation underscores its growing willingness to pursue both criminal and civil enforcement action.
Findings on systems and controls
The FCA found that most firms understood their legal and regulatory requirements and reflected this in their control framework. However, the FCA identified gaps where firms had underestimated their inherent risk, took a more “informal approach” to managing risks and failed to comply with obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (the MLRs).
The review assessed seven areas:
- Business-wide risk assessment
Firms are required to complete a business-wide risk assessment (BWRA) under the MLRs, which is seen by the FCA as the fundamental tool for assessing a firm’s inherent financial crime risk. The FCA found that:
- Just over a fifth of firms had either not undertaken a BWRA or had only completed it partially.
- 18% of firms active in private markets said their BWRA did not specifically cover private market risks.
- Some firms’ BWRAs did not adequately address financial crime risk or consider the risk factors prescribed under the MLRs.
The FCA warns that without a robust BWRA, firms could unknowingly facilitate financial crime. In addition, firms should refer to the 2025 National Risk Assessment of money laundering and terrorist financing and the 2021 National Risk Assessment of proliferation financing when carrying out the BWRA.
It is good practice for firms to regularly review their BWRA.
- Customer risk assessment
The FCA notes that some firms relied on frequent/close contact with a small customer base as a way of identifying profile changes in real time. However, the FCA notes that this is not an adequate substitute for a formal documented risk assessment.
Gaps identified include:
- 18% of firms had no formal customer risk assessment methodology at all.
- A small number of firms active in private markets had no formal process for verifying ultimate beneficial ownership in multi-layered or offshore structures.
- A small number of firms reported that they do not classify customers by risk.
- Customer due diligence and enhanced due diligence
Around 40% of firms outsource customer due diligence and enhanced due diligence checks, typically to compliance consultants or fund administrators. This is permissible under the MLRs, but firms remain fully responsible for compliance.
Of the roughly 40% of firms that outsource part of their financial crime compliance function, only 36% had full oversight of the third party’s anti-money laundering (AML) onboarding processes and 10% of firms did not verify the source of wealth of high-risk customers.
Some firms with limited oversight of outsourced work could not explain the due diligence processes being applied on their behalf or demonstrate that oversight was taking place and therefore were unable to demonstrate compliance with the MLRs.
- Ongoing monitoring
The FCA identified that 29% of firms reported no formal transaction monitoring process and 7% reported no systematic customer monitoring at all following onboarding (whether continuous, periodic or trigger-based).
Some firms rely on manual review by one or two individuals with no documented or defined triggers for identifying suspicious activity, raising concerns about consistency and effectiveness.
Ongoing monitoring of the business relationship, including scrutiny of transactions, is a mandatory requirement under the MLRs.
It is good practice for firms to review or audit internal suspicious activity reports to check submission quality.
- Screening
The FCA identified weaknesses in screening for PEPs and sanctions risk among a small number of firms, with 7% reporting they do not conduct repeat screening checks throughout the customer relationship.
Firms are under a legal obligation to identify PEP customers under the MLRs and to comply with UK sanctions requirements.
- Governance
The FCA identified several weaknesses in firms’ governance practices:
- Half of all firms reported no investment in remediation or system uplift of their AML systems and controls in the last 24 months.
- Only just over a third of firms discussed AML risk regularly at governance forums, with 36% doing so only annually or less.
- 18% of firms reported no formal quality assurance process over AML activity such as onboarding, alerts or reviews.
Staffing of the Money Laundering Reporting Officer (MLRO) role is a particular focus for the FCA. Over half of firms’ MLROs hold the role on a part-time or shared basis, often proportionate to the size of the business, but more than a quarter of larger firms (over £10bn in assets under management) also reported part-time or shared MLRO arrangements, despite typically having a wider customer base and more complex activities. The FCA expects such firms to consider whether their MLRO function is sufficient to ensure effective AML oversight and compliance.
It is good practice for firms to track and use management information on financial crime risks, including sanctions, PEP and adverse media alerts and key AML metrics.
- Training
The FCA identified that some MLROs had not received training specific to their legal obligations and responsibilities and noted that some firms generally lacked awareness of legislative and industry guidance updates on financial crime.
It is good practice for firms to provide staff with financial crime training relevant to their role. Tailoring content to cover (for example) financial crime detection and cybercrime, using case studies, and applying mandatory testing following training can all be good practice.
