The FCA has published findings from its engagement with asset management and alternative firms, setting out examples of good and poor practice across financial crime systems and controls. Thistle Initiatives Manager Elliott Day considers what has substantively changed, why it matters and where firms may wish to focus their attention.
The Financial Conduct Authority’s (FCA) findings provide a useful indication of how the regulator is currently assessing financial crime risk across the asset management and alternatives sector. The review covered 242 firms and focused on how well firms understand the financial crime risks inherent in their business models and whether their control frameworks are designed to identify, manage and mitigate those risks in practice. In simple terms, the FCA was testing whether firms could clearly explain where financial crime risk exists in their business and show evidence that their controls are designed to deal with it.
The findings give firms a clear view of the areas where the FCA continues to see weaknesses, particularly in relation to business-wide risk assessments, customer risk assessments, outsourced due diligence, transaction monitoring, screening, governance, money laundering reporting officer (MLRO) oversight and training.
For firms active in private markets or with exposure to complex ownership structures, higher-risk customers, international fund flows or outsourced anti-money laundering (AML) activity, the findings are particularly relevant.
The FCA’s publication also noted that firms active in private markets were more likely to exhibit higher-risk characteristics than firms undertaking other activities. These included complex ownership structures, overseas customer bases, politically exposed persons (PEPs), international fund transfers and activities involving higher-risk transactions. This does not mean all private market activity is inherently high risk. It does mean that where these features are present, firms are likely to be expected to demonstrate a more developed understanding of the related money laundering, terrorist financing, proliferation financing and sanctions risks.
The FCA found that over 20% of firms either had not undertaken a business-wide risk assessment (BWRA) or had one that was incomplete.
The regulator also identified examples where BWRAs existed but did not adequately consider the inherent financial crime risks arising from the firm’s activities. This is a notable finding because the BWRA remains the foundation of a firm’s financial crime control framework under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs). It is also continuously highlighted by the FCA as an area of importance, as well as an area in which the regulator consistently provides feedback on. If the BWRA does not properly identify the risks the firm faces, the rest of the framework is unlikely to be appropriately risk-based.
In practice, firms should utilise their BWRA to inform their framework across customer risk assessments, due diligence requirements, ongoing monitoring (transaction monitoring and screening) arrangements and training.
If the BWRA does not accurately reflect the risks faced by the business, weaknesses can flow through the wider AML programme.
In our experience, stronger firms treat the BWRA as a genuinely useful management tool rather than a compliance document. They review it regularly, use it to inform key AML decisions and ensure it reflects changes in customers, products, jurisdictions and delivery channels. Where firms are operating in higher-risk areas such as private markets or cross-border activity, we would generally expect those risks to flow clearly through the wider AML framework.
The FCA also identified gaps in customer risk assessments (CRAs), including firms with no formal CRA methodology and weaknesses in the way customers with complex ownership structures were assessed.
This is particularly relevant where firms deal with complex investors, customers or counterparties. Where ownership structures involve multiple layers, offshore entities or several beneficial owners, firms need to understand who ultimately owns or controls the customer and whether that creates a higher level of financial crime risk.
The FCA found that 18% of firms did not have a formal CRA methodology. It also identified examples where firms active in private markets had not implemented effective arrangements for assessing customers operating through multi-layered or offshore structures.
Without a documented and consistently applied approach to customer risk assessment, firms may find it more difficult to demonstrate why a customer has been assigned a particular risk rating and whether the level of due diligence applied is appropriate for the risks identified.
We are increasingly seeing firms strengthen their CRA methodologies by introducing clearer customer risk factors, more consistent risk scoring and stronger documentation of ownership structures.
Where customers operate through complex or offshore arrangements, firms should be able to demonstrate not only who ultimately owns the structure but how those factors influenced the overall customer risk assessment.
Around 40% of firms told the FCA that they outsource some customer due diligence (CDD) and enhanced due diligence (EDD) controls, commonly to compliance consultants or fund administrators. The FCA found examples where firms could not explain the outsourced CDD or EDD process or demonstrate sufficient oversight of the third party’s work.
The message is consistent with previous FCA communications: outsourcing is permitted, but accountability remains with the regulated firm. Several firms had delegated elements of customer due diligence to third parties but were unable to clearly explain how those checks were performed or how the quality of the work was assessed. Firms should be able to evidence oversight, challenge and quality assurance over outsourced activity.
Good practice is increasingly moving beyond contractual reliance on third parties. Firms are increasingly expected to perform sample testing, review management information, assess the quality of onboarding decisions and maintain sufficient understanding of the underlying process to challenge outcomes where necessary.
The FCA found that over 25% of responding firms did not have a formal transaction monitoring process. Some firms relied on manual reviews because of low transaction volumes but without clearly documented triggers for identifying suspicious activity. The FCA also identified weaknesses in repeat screening for sanctions, PEPs and adverse media. Where screening only takes place at onboarding, firms may miss changes in customer risk profile during the life of the relationship.
While transaction monitoring arrangements should remain proportionate to the nature and scale of the business, firms should be able to explain how suspicious activity would be identified in practice. Where manual monitoring is used, documented review processes, escalation criteria and management oversight can help demonstrate that the monitoring framework remains effective and consistent.
The FCA found that most firms collect financial crime management information but only around 35% discuss AML risk regularly at senior management or board meetings. For many firms, the question is no longer whether information is being collected. The FCA is increasingly interested in whether senior management is reviewing that information, identifying issues and making decisions based on it.
The regulator also highlighted that more than 25% of larger firms (those with over £10 billion in assets under management) reported having an MLRO who worked part-time or had shared responsibilities. Part-time or shared responsibilities may be proportionate for some firms. However, where firms are larger, more complex or exposed to higher-risk activity, the FCA is likely to expect firms to be able to demonstrate that MLRO capacity, expertise and oversight remain sufficient.
Across the sector, we continue to see stronger firms provide regular AML management information to senior management and boards, supported by clear discussion, challenge and documented actions. The FCA's findings suggest that collecting management information alone is unlikely to be sufficient if firms cannot demonstrate how that information informs decision-making and drives improvements where issues are identified.
The findings suggest that firms are likely to face increasing scrutiny not only on whether controls exist but whether they can demonstrate how those controls operate in practice. In several areas, the FCA's concern was not the absence of a policy or process. It was the absence of clear evidence showing that the process was understood, applied and subject to ongoing review.
For firms in the asset management and alternatives sector, this matters because financial crime risk can vary significantly by business model. A firm with a straightforward customer base and limited international exposure will not necessarily require the same control environment as a firm active in private markets, cross-border structures or higher-risk investment activity. However, both firms should be able to explain why their approach is proportionate.
The FCA’s findings also suggest that informal arrangements are unlikely to be sufficient where risk exposure is material. Close customer relationships, low transaction volumes or reliance on experienced staff may help firms manage risk in practice, but they do not remove the need for formal documented assessments, clear escalation triggers and evidence of oversight.
The review also fits with the FCA’s wider direction of travel towards more evidence-led supervision. Firms may increasingly be asked not only whether a control exists but how it operates, how often it is reviewed, what issues have been identified and how senior management has responded.
The impact of the FCA's findings will vary by firm, but several themes are likely to be relevant where financial crime exposure exists.
Where firms are active in private markets or deal with layered ownership structures, offshore vehicles or international fund flows, they may wish to revisit whether their BWRA, CRA and due diligence approach adequately capture those risks.
Where firms rely on manual transaction or customer monitoring because volumes are low, they may wish to consider whether the process is sufficiently documented, repeatable and auditable.
The key issue is whether the process can identify suspicious activity consistently and whether firms can demonstrate how decisions are made, reviewed and evidenced.
A manual process may be entirely appropriate for some firms, provided it is documented and operating consistently.
Where firms screen customers only at onboarding, they may wish to assess whether this remains appropriate given their customer base, jurisdictions, transaction activity and sanctions exposure.
Where AML management information is collected but not regularly discussed at governance forums, firms may wish to consider whether senior management is receiving the information needed to support challenge, decision-making and remediation.
With that in mind, firms may want to step back and consider whether they could confidently answer the following questions if asked by the FCA:
The FCA’s findings provide a clear indication of where supervisory attention is likely to remain across the asset management and alternatives sector.
The regulator is not suggesting that every firm should operate the same control framework.
A smaller firm with straightforward investors is unlikely to require the same arrangements as a firm dealing with complex ownership structures, offshore vehicles or significant international fund flows.
The more important point is that firms should be able to show that their framework is proportionate, risk-based and operating effectively in practice.
For firms with exposure to private markets, complex ownership structures, international fund flows or outsourced AML activity, the findings should be treated as a useful benchmark.
The key question is whether firms can evidence how financial crime risks are identified, assessed, managed and escalated in a way that reflects the nature of their business and the risks they face.
Thistle's financial crime team supports firms across the full compliance lifecycle, from independent assurance and s166 Skilled Person reviews through to remediation, transformation and ongoing managed services.
Whether firms are assessing the effectiveness of existing arrangements, responding to regulatory findings, implementing change or strengthening day-to-day compliance operations, we provide practical support tailored to the firm's risk profile, business model and regulatory obligations.
Our aim is simple: to help firms build and maintain financial crime frameworks that remain effective, proportionate and aligned to evolving regulatory expectations.
Elliott is a manager within Thistle’s Financial Crime team, supporting fintech and financial services clients to strengthen controls, uplift governance, and deliver regulatory remediation. His experience spans AML, sanctions, KYC/KYB, onboarding and risk assessment, with a focus on proportionate, risk-based frameworks and practical assurance.
Before joining Thistle, Elliott held financial crime and compliance roles across payments and fintech, enhancing policies, procedures and monitoring arrangements. Elliott has also contributed to industry publications, including editorials for The Company Lawyer.