News
Print Article

8 KEY THEMES - FCA Asset Management & Alternative Firms' Financial Crime Controls Findings

28/07/2026

SCOPE AND METHODOLOGY

  • The asset management and alternatives sector comprises roughly 2,500 firms with widely varying business models.
  • The FCA's annual financial crime return (REP-CRIM) already captures data from approximately 2,100 of these.
  • In 2025/26, the FCA went further and engaged 242 firms directly — issuing a questionnaire (87% response rate) and following up with interviews at a smaller subset selected to span public/private asset strategies, different risk profiles, and firms both within and outside REP-CRIM scope.
  • Evaluation was against the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs 2017), the Financial Crime Guide (FCG), SYSC, JMLSG guidance and FATF guidance.
  • All percentages below are drawn from the 242-firm sample, not the full sector — the FCA is explicit that not every finding applies equally to every business model, and this is roughly a 10% sample of the wider population.
  • The review sits within the FCA's 2025–30 strategy and its supervisory priorities for the sector. The FCA states it will use the questionnaire data to target intervention where firms fall short.

THEME 1: INHERENT FINANCIAL CRIME RISK (ESPECIALLY PRIVATE MARKETS)

  • Private-markets firms face higher exposure via complex, often multi-jurisdictional, ownership structures, PEPs and cross-border flows.
    • Around a fifth of private-markets firms reported that over 30% of their customers use complex ownership structures; 85% of firms not active in private markets reported none.
    • 32% of private-markets firms reported PEPs in their customer base, versus 9% of non-private-markets firms.
    • 50% of all firms reported that over 60% of customers are domiciled overseas, with private-markets firms more likely to handle international fund transfers.
  • Regulatory references:
    • MLRs Reg 18/18A (business-wide risk assessment must account for these factors);
    • Reg 28 (CDD, including UBO identification);
    • SYSC 6.1.1R (requires firms to establish and maintain systems and controls to identify, assess, monitor and manage money laundering risk);
    • FCG; JMLSG.
  • Note:
    • The FCA's own findings document refers to SYSC generically rather than citing SYSC 6.1.1R by number.
    • The specific citation has been checked directly against the FCA Handbook and is accurate as the governing rule — it is added here for precision, not because the FCA findings document itself cites it.
  • Self-assessment questions
    • Does our BWRA explicitly quantify and risk-rate complex ownership, PEP exposure and international flows specific to our activity, or is it generic?
    • Have we tested whether UBO identification and verification actually works on the multi-layered/offshore structures in our book?
    • What proportion of our AUM or investor base carries elevated residual risk after controls, and is that reflected in risk appetite and resourcing?

THEME 2: BUSINESS-WIDE RISK ASSESSMENT (BWRA) — INCOMPLETE OR INADEQUATE

  • Just over a fifth of firms had either no BWRA or an incomplete one.
    • Some completed BWRAs failed to consider inherent risks arising from the firm's own activities.
    • 18% of private-markets firms stated their BWRA did not specifically cover private-markets risks.
  • Regulatory references:
    • MLRs Reg 18 and 18A (formal, up-to-date BWRA covering ML, TF and PF risk, taking account of National Risk Assessments); SYSC 6.1.1R.
  • Self-assessment questions
    • Is our BWRA current, board/senior-management approved, and does it systematically cover the risk factors in Reg 18/18A plus the 2025 ML/TF NRA and 2021 PF NRA?
    • Does it distinguish residual risk after controls and feed into CRA methodology, policy, monitoring and resourcing decisions?
    • When was it last independently challenged or updated for changes in business model, products or customer mix?

THEME 3: CUSTOMER RISK ASSESSMENT (CRA) AND CLASSIFICATION

  • 18% of firms had no formal CRA methodology. A small number of firms — mainly active in private markets — lacked formal UBO verification for multi-layered/offshore structures, and a small number did not classify customers by risk at all.
  • Regulatory references: MLRs Reg 28(12)–(13) (risk-based CDD measures).
  • Self-assessment questions
    • Do we have a documented, applied CRA methodology producing a risk rating before/at onboarding that drives the level of CDD/EDD?
    • Can we evidence that every customer, including those with complex structures, has been risk-rated and refreshed on a risk-based cycle or trigger?
    • How do we test that front-line staff actually apply the methodology rather than default to low risk?

THEME 4: CDD/EDD AND OUTSOURCING OVERSIGHT

  • Around 40% of firms outsource CDD/EDD, typically to compliance consultants or fund administrators.
  • Of those outsourcing part of the financial-crime compliance function, only 36% had full oversight of the third party's AML onboarding processes. 10% of firms did not verify the source of wealth for high-risk customers.
  • Regulatory references:
    • MLRs Reg 28 and 33 (CDD/EDD obligations remain with the firm regardless of outsourcing); SYSC 8 (general outsourcing requirements); FCG.
  • Note:
    • SYSC 13.9, sometimes cited for outsourcing, was checked and ruled out — it sits within SYSC 13 (Operational risk: systems and controls for insurers) and is scoped to insurers, not asset management or alternatives firms. SYSC 8 is the correct general outsourcing reference here.
  • Self-assessment questions
    • Where we outsource, can we demonstrate ongoing, risk-based oversight, testing and validation of the provider's processes and outputs — not just contractual reliance?
    • Do we retain sufficient knowledge and records to explain and defend CDD/EDD files to the FCA?
    • For high-risk/PEP/complex-structure customers, is source-of-wealth and source-of-funds verification actually performed and evidenced?

THEME 5: ONGOING MONITORING AND TRANSACTION MONITORING

  • The FCA's own framing here is more balanced than a bare gap list suggests:
    • Most firms have implemented controls to monitor customer relationships, and
    • Over half undertake periodic reviews (quarterly or annual refreshes).
    • Against that baseline, the gaps stand out:
      • 29% of responding firms had no formal transaction monitoring process; some rely on manual review by one or two people with no documented triggers.
      • 7% reported no systematic post-onboarding monitoring at all (continuous, periodic, or trigger-based).
      • 84% of firms reviewed or audited internal SARs to check submission quality (good practice — the FCA places this stat under Ongoing Monitoring, not Governance).
  • Regulatory references:
    • MLRs Reg 28(11) (mandatory ongoing monitoring, including scrutiny of transactions and the relationship).
  • Self-assessment questions
    • Do we have documented, risk-based transaction monitoring — automated or manual — with clear triggers, escalation and investigation procedures proportionate to volume and complexity?
    • How do we detect changes in customer behaviour, ownership or risk profile after onboarding?
    • Is the approach tested for effectiveness — false-negative/false-positive rates, coverage of typologies relevant to our book?

THEME 6: SCREENING (PEPS, SANCTIONS, ADVERSE MEDIA)

  • Among a small subset of firms, the FCA found weaknesses in ongoing screening. 7% of firms do not conduct repeat screening checks.
  • Regulatory references: MLRs Reg 35(1) (PEPs); UK sanctions regime; SYSC.
  • Self-assessment questions
    • Is screening performed at onboarding and repeated on a risk-based frequency (or continuously), covering the full ownership chain where relevant?
    • How do we calibrate, test and maintain screening lists and alert disposition quality?

THEME 7: GOVERNANCE, MLRO CAPACITY AND MI

  • Over half of MLROs worked part-time or had shared responsibilities — often appropriate for smaller firms.
  • However, more than a quarter of larger firms (over £10bn AUM) also reported part-time or shared MLRO arrangements — the FCA flags this specific finding as a concern given these firms' likely wider customer base and complexity.
    • This is the only finding the FCA ties directly to the £10bn+ AUM cohort.
    • the FCA does not state that larger firms show weaker controls generally, and
    • that broader claim should not be attributed to this report.
  • Only just over a third of firms discuss AML risk regularly at governance forums; 36% discuss it annually or less frequently.
  • 18% had no formal quality-assurance process for AML activity.
  • Half reported no investment in remediation or system uplift of AML systems/controls in the previous 24 months.
  • 88% tracked and used financial-crime management information (good practice).
  • Regulatory references:
    • SYSC 6.1.1R and SYSC 6.3 (MLRO responsibilities and adequate resources);
    • SM&CR (SMF17 accountability);
    • MLRs.
  • Self-assessment questions
    • Is the time, seniority, independence and support given to the MLRO (SMF17) commensurate with the firm's size, complexity, AUM and residual risk — particularly above £10bn AUM or with material private-markets exposure?
    • Does the board/relevant committee receive timely, decision-useful MI on financial-crime metrics, residual risk, control effectiveness and emerging issues, with challenge evidenced?
    • Is there an independent QA/testing programme covering onboarding, monitoring, screening and SAR quality?

THEME 8: TRAINING

  • Most firms provide some financial-crime training, generally on a regular or annual basis.
  • Gaps were noted in training tailored to MLROs' specific legal obligations, and in general staff awareness of legislative/industry updates.
  • Good practice included role-relevant, case-study-based training with testing.
  • Regulatory references:
    • MLRs (staff awareness and training obligations); SYSC.
  • Self-assessment questions
    • Is training role-specific, risk-based, current on typologies and guidance, and tested for effectiveness?
    • Does the MLRO, and senior management more broadly, receive targeted training on their personal and firm obligations?

Overall regulatory expectation and practical implication

    • The FCA expects firms to maintain adequate, proportionate policies, controls and procedures that identify, assess, monitor and manage financial-crime risk specific to their business model.
    • Outsourcing does not transfer responsibility.
    • Gaps in BWRA, CRA, outsourcing oversight, transaction monitoring and MLRO capacity are the areas the FCA has flagged as requiring review — and the regulator states it will use the underlying questionnaire data for targeted supervisory intervention.

Recommended immediate actions

  1. Map the findings to your current BWRA, CRA methodology, outsourcing arrangements, monitoring framework and MLRO capacity.
  2. Document the gap analysis, any residual-risk acceptance, and a remediation timeline.
  3. Escalate material gaps to the board/relevant SMF and retain evidence of challenge and decision.
  4. Re-test a sample of high-risk files — complex ownership, PEPs, outsourced CDD, high-risk source of wealth — against the standards above.

END

Primary source: FCA, "Asset management and alternative firms' financial crime controls: our findings" (Good and poor practice).

First published: 13 July 2026.  Last updated: 22 July 2026.

Full URL:

Verification note - figures below have been checked directly against the published FCA page. Where a citation goes beyond what the FCA document itself states, this is flagged rather than presented as an FCA finding.

This briefing is based on the FCA's published findings, verified directly against the source page. Firms should read the full FCA publication and apply the observations proportionately to their own risk profile. Any regulatory citation not attributable to the FCA text itself is flagged above and should be independently verified before use in client-facing material.

CDD EDD PEPs FATF MLRO SANCTIONS

The Team

Meet the team of industry experts behind Comsure

Find out more

Latest News

Keep up to date with the very latest news from Comsure

Find out more

Gallery

View our latest imagery from our news and work

Find out more

Contact

Think we can help you and your business? Chat to us today

Get In Touch

News Disclaimer

As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.