FCA Annex 1 Questionnaires & Deep Dive Reviews: What Firms Should Look Out For – And How to Close the Gaps
As the FCA’s scrutiny over Annex 1 firms intensifies, the focus is shifting from proving that AML/CTF controls are in place to showing they work in practice. With deep-dive reviews and potential remediation requirements now forming part of the supervisory landscape, firms should take steps to assess their risk frameworks before regulatory gaps are identified.
The FCA’s supervisory programme for Annex 1 firms has moved into a more focused and intensive review programme. What began with the March 2024 Dear CEO letter has now evolved into a structured, multi‑phase review designed to test whether firms have genuinely strengthened their AML/CTF/CPF frameworks.
If you’re an Annex 1 firm, the question is no longer “Do we have controls?” but “Can we prove they work?”
Below, we break down what the FCA has done, what’s coming next, and, critically, what firms should be doing now to close gaps.
The FCA's Timeline
Phase 1 - Annex 1 Firms' Questionnaires (Oct-Dec 2025)
The FCA’s questionnaire required firms to evidence their approach to:
- Inherent financial crime risk identification
- AML/CTF/CPF controls
- Governance and SMF accountability
- CDD and EDD
- Transaction and activity monitoring
- SARs processes
- Independent review arrangements
This was the FCA’s first test: Do firms understand their risks, and have these risks informed the control framework? In our experience, a number of firms use the business-wide risk assessment (BWRA) to ‘tick a box’, rather than actually use it to develop a proportionate framework.
Phase 2 - Evidence-Based Deep Dives (Late 2025-2026)
Phase 2 is where the FCA has moved from self‑reported controls to proving operational effectiveness. Key milestones included:
- Late 2025–Early 2026: Firm selection and initial evidence requests
- Q1 2026: Deep dives, interviews, walkthroughs, file testing
- Q2 2026: Feedback letters and mandatory remediation plans
Who the FCA Targeted - And Why It Matters
The FCA did not select firms randomly. They focused on those with the highest inherent risk or the weakest controls, including:
- High‑risk customers or jurisdictions
- Rudimentary or manual monitoring
- Weak governance or unclear SMF17 accountability
- Zero or unusually low SAR submissions
- Missing BWRA or outdated risk assessments
- Inconsistent CDD files
- Historic supervisory issues
What Annex 1 Forms Should Look Out for Now
Based on the FCA’s approach, Annex 1 firms should expect the regulator to scrutinise the following areas most intensely:
Business-Wide Risk Assessments (BWRA)
| Business-Wide Risk Assessments (BWRA) | Business-Wide Risk Assessments (BWRA) | Business-Wide Risk Assessments (BWRA) |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
Governance & MI Quality
| Governance & MI Quality | Governance & MI Quality | Governance & MI Quality |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
CDD & EDD Quality
| CDD & EDD Quality | CDD & EDD Quality | CDD & EDD Quality |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
Transaction Monitoring Effectiveness
| Transaction Monitoring Effectiveness | Transaction Monitoring Effectiveness | Transaction Monitoring Effectiveness |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
SARs Quality & Escalation
| Transaction Monitoring Effectiveness | Transaction Monitoring Effectiveness | Transaction Monitoring Effectiveness |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
Independent Review and Assurance
| Independent Review & Assurance | Independent Review & Assurance | Independent Review & Assurance |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
What Firms Should Do Now
Priority 1: Validate your BWRA and Customer Risk Scoring
This is the foundation of the FCA’s risk‑based approach. The FCA identified numerous firms whose BWRAs were either incomplete, overly generic, or disconnected from the firm's actual activities and customer base. In many cases, firms had risk assessments that existed purely as compliance documents rather than tools used to inform day-to-day controls.
Priority 2: Evidence your Governance
If it’s not documented, the FCA will assume it didn’t happen. One of the consistent themes from FCA reviews has been weak governance oversight and poor evidence of challenge from senior management. The regulator expects boards, directors and MLROs to actively oversee financial crime risk rather than treating AML as a compliance function operating in isolation.
Priority 3: Conduct a CDD File Quality Review
Focus on beneficial ownership, EDD, and ongoing monitoring. CDD file testing has been a core component of FCA deep-dive reviews. The regulator's concern is not simply whether identification documents are present, but whether firms have properly assessed and documented customer risk throughout the relationship.
Priority 4: Review Transaction Monitoring Rules and Alert Handling
Ensure rules match your risk profile—and document tuning. Many firms operate transaction monitoring systems that were implemented years ago and no longer align with their business model, customer base or risk assessment. The FCA expects monitoring scenarios to be derived from the BWRA and customer risks identified by the firm.
Priority 5: Strengthen SARs Processes
Zero SARs = high regulatory concern. The FCA has become increasingly sceptical of firms that report no Suspicious Activity Reports (SARs), particularly where firms operate in higher-risk sectors or have significant customer and transaction volumes. A very low SAR volume may indicate ineffective monitoring, inadequate staff training or weak escalation procedures rather than an absence of suspicious activity.
Priority 6: Commission Independent AML Assurance
This is now expected, not optional. Whether this is done through an internal audit function (3LOD) or by an external audit, the regulator is looking for that independent assurance that the firm’s AML framework and financial crime controls are robust, proportionate and effective.
How Thistle Initiatives Can Help
Thistle has supported a significant number of Annex 1 firms, including: the creation of regulatory-ready frameworks, remediation when issues are identified, and independent audits. We can help you:
- Provide independent AML assurance
- Rebuild your BWRA and customer risk scoring
- Review and uplift CDD/EDD files
- Assess transaction monitoring effectiveness
- Deliver training to staff and senior management
- With ongoing retainer support for complex queries
- Strengthen SARs processes and QA
- Prepare for FCA interviews, deep dives, and evidence requests
Meet the expert
James Dodsworth, Senior Manager
James has worked in financial crime compliance across a range of sectors and firms for over 20 years.
As a certified fraud investigator, James has experience in all three lines of defence: conducting investigations, designing and delivering fraud controls and risk assessments, as well as creating and reviewing policies and procedures.