Financial Services Compliance Blog - Thistle Initiatives

FCA Annex 1 Questionnaires & Deep Dive Reviews: What Firms Should Look Out For – And How to Close the Gaps

Written by James Dodsworth | Aug 4, 2026, 3:50:18 PM

As the FCA’s scrutiny over Annex 1 firms intensifies, the focus is shifting from proving that AML/CTF controls are in place to showing they work in practice. With deep-dive reviews and potential remediation requirements now forming part of the supervisory landscape, firms should take steps to assess their risk frameworks before regulatory gaps are identified.

The FCA’s supervisory programme for Annex 1 firms has moved into a more focused and intensive review programme. What began with the March 2024 Dear CEO letter has now evolved into a structured, multi‑phase review designed to test whether firms have genuinely strengthened their AML/CTF/CPF frameworks.

If you’re an Annex 1 firm, the question is no longer “Do we have controls?” but “Can we prove they work?”

Below, we break down what the FCA has done, what’s coming next, and, critically, what firms should be doing now to close gaps. 

The FCA's Timeline

Phase 1 - Annex 1 Firms' Questionnaires (Oct-Dec 2025)

The FCA’s questionnaire required firms to evidence their approach to: 

  • Inherent financial crime risk identification
  • AML/CTF/CPF controls
  • Governance and SMF accountability
  • CDD and EDD
  • Transaction and activity monitoring
  • SARs processes
  • Independent review arrangements

This was the FCA’s first test: Do firms understand their risks, and have these risks informed the control framework? In our experience, a number of firms use the business-wide risk assessment (BWRA) to ‘tick a box’, rather than actually use it to develop a proportionate framework.  

Phase 2 - Evidence-Based Deep Dives (Late 2025-2026)

Phase 2 is where the FCA has moved from selfreported controls to proving operational effectiveness. Key milestones included: 

  • Late 2025–Early 2026: Firm selection and initial evidence requests
  • Q1 2026: Deep dives, interviews, walkthroughs, file testing
  • Q2 2026: Feedback letters and mandatory remediation plans
Q3–Q4 2026: Ongoing monitoring, potential Section 166s, attestations

Who the FCA Targeted - And Why It Matters

The FCA did not select firms randomly. They focused on those with the highest inherent risk or the weakest controls, including: 

  • High‑risk customers or jurisdictions
  • Rudimentary or manual monitoring
  • Weak governance or unclear SMF17 accountability
  • Zero or unusually low SAR submissions
  • Missing BWRA or outdated risk assessments
  • Inconsistent CDD files
  • Historic supervisory issues 

What Annex 1 Forms Should Look Out for Now

Based on the FCA’s approach, Annex 1 firms should expect the regulator to scrutinise the following areas most intensely: 

Business-Wide Risk Assessments (BWRA)

Business-Wide Risk Assessments (BWRA) Business-Wide Risk Assessments (BWRA) Business-Wide Risk Assessments (BWRA)
What the FCA look for Common gaps How to close the gap
  • A current, documented BWRA aligned to the firm’s actual business model
  • Clear methodology linking inherent risks → controls → residual risk
  • Evidence of annual review or event-driven updates
  • Generic templates not tailored to the firm
  • No link between risk scoring and monitoring thresholds
  • BWRA not updated after product changes or growth
  • Rebuild the BWRA using FCA risk factors
  • Ensure customer risk scoring aligns with monitoring rules
  • Document review cycles and Board approval

 

Governance & MI Quality

Governance & MI Quality Governance & MI Quality Governance & MI Quality
What the FCA look for Common gaps How to close the gap
  • Active Board oversight and challenge
  • SMF17 accountability clearly documented
  • MI that highlights risk, not just activity
  • Board minutes with no AML discussion
  • MI packs that report volumes, not risk
  • MLROs without sufficient authority or resource
  • Lack of 2LOD monitoring and testing
  • Introduce AML as a standing Board agenda item
  • Enhance senior management training to include their role in providing challenge and oversight to financial crime compliance
  • Redesign MI to include risk trends, SAR themes, high‑risk exposures
  • Conduct an SMF17 effectiveness review
  • Creation of a risk-based Financial Crime Compliance Monitoring Programme

 

CDD & EDD Quality 

CDD & EDD Quality CDD & EDD Quality CDD & EDD Quality
What the FCA look for Common gaps How to close the gap
  • Consistent onboarding files
  • Clear EDD triggers and rationale
  • Ongoing monitoring evidence
  • Missing beneficial ownership documentation
  • EDD applied inconsistently
  • No evidence of periodic refresh
  • Introduce QC function, and risk-based 2LOD QA through monitoring and testing
  • Document EDD decision-making
  • Implement risk‑based refresh cycles

 

Transaction Monitoring Effectiveness

Transaction Monitoring Effectiveness Transaction Monitoring Effectiveness Transaction Monitoring Effectiveness
What the FCA look for Common gaps How to close the gap
  • Rules aligned to risk
  • Evidence of alert investigation
  • Calibration and tuning logs
  • Manual monitoring for high‑risk businesses
  • No typology mapping
  • Alerts closed without rationale
  • Map monitoring rules to customer/product risks
  • Introduce QA on alert handling
  • Document tuning decisions and rule changes

 

SARs Quality & Escalation

Transaction Monitoring Effectiveness Transaction Monitoring Effectiveness Transaction Monitoring Effectiveness
What the FCA look for Common gaps How to close the gap
  • Clear internal escalation
  • QA on SARs prior to submission to the NCA.
  • Evidence of training
  • Zero SAR submissions (a major red flag)
  • High volume Transaction Monitoring alerts not filtering into suspicious activity, meaning Transaction Monitoring rules may not be appropriate
  • No internal SAR log
  • Poor narrative quality
  • Introduce SAR QA and peer review
  • Train staff on red flags and reporting obligations
  • Lessons learned are incorporated back into monitoring rules, training and risk assessments

 

Independent Review and Assurance

Independent Review & Assurance Independent Review & Assurance Independent Review & Assurance
What the FCA look for Common gaps How to close the gap
  • Internal audit or external AML assurance
  • Evidence of remediation
  • Board oversight of findings
  • No independent testing
  • Findings not tracked
  • Remediation not evidenced
  • Commission an external AML audit
  • Build a remediation tracker
  • Report progress to the Board quarterly

 

What Firms Should Do Now

Priority 1: Validate your BWRA and Customer Risk Scoring

This is the foundation of the FCA’s risk‑based approach. The FCA identified numerous firms whose BWRAs were either incomplete, overly generic, or disconnected from the firm's actual activities and customer base. In many cases, firms had risk assessments that existed purely as compliance documents rather than tools used to inform day-to-day controls. 

Priority 2: Evidence your Governance

If it’s not documented, the FCA will assume it didn’t happen. One of the consistent themes from FCA reviews has been weak governance oversight and poor evidence of challenge from senior management. The regulator expects boards, directors and MLROs to actively oversee financial crime risk rather than treating AML as a compliance function operating in isolation. 

Priority 3: Conduct a CDD File Quality Review

Focus on beneficial ownership, EDD, and ongoing monitoring. CDD file testing has been a core component of FCA deep-dive reviews. The regulator's concern is not simply whether identification documents are present, but whether firms have properly assessed and documented customer risk throughout the relationship. 

Priority 4: Review Transaction Monitoring Rules and Alert Handling

Ensure rules match your risk profile—and document tuning. Many firms operate transaction monitoring systems that were implemented years ago and no longer align with their business model, customer base or risk assessment. The FCA expects monitoring scenarios to be derived from the BWRA and customer risks identified by the firm. 

Priority 5: Strengthen SARs Processes

Zero SARs = high regulatory concern. The FCA has become increasingly sceptical of firms that report no Suspicious Activity Reports (SARs), particularly where firms operate in higher-risk sectors or have significant customer and transaction volumes. A very low SAR volume may indicate ineffective monitoring, inadequate staff training or weak escalation procedures rather than an absence of suspicious activity.

Priority 6: Commission Independent AML Assurance

This is now expected, not optional. Whether this is done through an internal audit function (3LOD) or by an external audit, the regulator is looking for that independent assurance that the firm’s AML framework and financial crime controls are robust, proportionate and effective.  

How Thistle Initiatives Can Help

Thistle has supported a significant number of Annex 1 firms, including: the creation of regulatory-ready frameworks, remediation when issues are identified, and independent audits. We can help you:

  • Provide independent AML assurance
  • Rebuild your BWRA and customer risk scoring
  • Review and uplift CDD/EDD files
  • Assess transaction monitoring effectiveness
  • Deliver training to staff and senior management
  • With ongoing retainer support for complex queries
  • Strengthen SARs processes and QA
  • Prepare for FCA interviews, deep dives, and evidence requests

Meet the expert

James Dodsworth, Senior Manager  

James has worked in financial crime compliance across a range of sectors and firms for over 20 years.

As a certified fraud investigator, James has experience in all three lines of defence: conducting investigations, designing and delivering fraud controls and risk assessments, as well as creating and reviewing policies and procedures.