As the FCA’s scrutiny over Annex 1 firms intensifies, the focus is shifting from proving that AML/CTF controls are in place to showing they work in practice. With deep-dive reviews and potential remediation requirements now forming part of the supervisory landscape, firms should take steps to assess their risk frameworks before regulatory gaps are identified.
The FCA’s supervisory programme for Annex 1 firms has moved into a more focused and intensive review programme. What began with the March 2024 Dear CEO letter has now evolved into a structured, multi‑phase review designed to test whether firms have genuinely strengthened their AML/CTF/CPF frameworks.
If you’re an Annex 1 firm, the question is no longer “Do we have controls?” but “Can we prove they work?”
Below, we break down what the FCA has done, what’s coming next, and, critically, what firms should be doing now to close gaps.
The FCA’s questionnaire required firms to evidence their approach to:
This was the FCA’s first test: Do firms understand their risks, and have these risks informed the control framework? In our experience, a number of firms use the business-wide risk assessment (BWRA) to ‘tick a box’, rather than actually use it to develop a proportionate framework.
Phase 2 is where the FCA has moved from self‑reported controls to proving operational effectiveness. Key milestones included:
The FCA did not select firms randomly. They focused on those with the highest inherent risk or the weakest controls, including:
Based on the FCA’s approach, Annex 1 firms should expect the regulator to scrutinise the following areas most intensely:
| Business-Wide Risk Assessments (BWRA) | Business-Wide Risk Assessments (BWRA) | Business-Wide Risk Assessments (BWRA) |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
| Governance & MI Quality | Governance & MI Quality | Governance & MI Quality |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
| CDD & EDD Quality | CDD & EDD Quality | CDD & EDD Quality |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
| Transaction Monitoring Effectiveness | Transaction Monitoring Effectiveness | Transaction Monitoring Effectiveness |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
| Transaction Monitoring Effectiveness | Transaction Monitoring Effectiveness | Transaction Monitoring Effectiveness |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
| Independent Review & Assurance | Independent Review & Assurance | Independent Review & Assurance |
| What the FCA look for | Common gaps | How to close the gap |
|
|
|
This is the foundation of the FCA’s risk‑based approach. The FCA identified numerous firms whose BWRAs were either incomplete, overly generic, or disconnected from the firm's actual activities and customer base. In many cases, firms had risk assessments that existed purely as compliance documents rather than tools used to inform day-to-day controls.
If it’s not documented, the FCA will assume it didn’t happen. One of the consistent themes from FCA reviews has been weak governance oversight and poor evidence of challenge from senior management. The regulator expects boards, directors and MLROs to actively oversee financial crime risk rather than treating AML as a compliance function operating in isolation.
Focus on beneficial ownership, EDD, and ongoing monitoring. CDD file testing has been a core component of FCA deep-dive reviews. The regulator's concern is not simply whether identification documents are present, but whether firms have properly assessed and documented customer risk throughout the relationship.
Ensure rules match your risk profile—and document tuning. Many firms operate transaction monitoring systems that were implemented years ago and no longer align with their business model, customer base or risk assessment. The FCA expects monitoring scenarios to be derived from the BWRA and customer risks identified by the firm.
Zero SARs = high regulatory concern. The FCA has become increasingly sceptical of firms that report no Suspicious Activity Reports (SARs), particularly where firms operate in higher-risk sectors or have significant customer and transaction volumes. A very low SAR volume may indicate ineffective monitoring, inadequate staff training or weak escalation procedures rather than an absence of suspicious activity.
Thistle has supported a significant number of Annex 1 firms, including: the creation of regulatory-ready frameworks, remediation when issues are identified, and independent audits. We can help you:
James has worked in financial crime compliance across a range of sectors and firms for over 20 years.
As a certified fraud investigator, James has experience in all three lines of defence: conducting investigations, designing and delivering fraud controls and risk assessments, as well as creating and reviewing policies and procedures.