Asset Management Financial Crime Controls: A Practical Guide to the FCA's Findings
- Andrew Arginovski

- 5 days ago
- 8 min read

On 22 July 2026, the Financial Conduct Authority (FCA) published its findings on financial crime controls across asset management and alternative firms. The publication introduces no new rules and sets no deadline. It reports what the FCA found when it examined how firms identify, manage and mitigate financial crime risk, measured against obligations already in force, principally the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (the MLRs). Its central message is that some firms have underestimated the risk inherent in their business models and are managing it informally rather than through the documented framework the law requires.
The findings apply to asset management and alternative firms, a population of around 2,500 firms, and the FCA is explicit that exposure is not uniform and that not all findings apply to all firms, though its data point clearly at private markets. The reason to act is supervisory rather than legal: the FCA has said it will use the underlying questionnaire data as it supervises the sector, will intervene where firms fall short, and will continue to monitor firms through its supervisory work. That makes a documented review of a firm's own arrangements a sensible response for boards and money laundering reporting officers (MLROs) alike, and the publication also merits attention from asset management firms applying for FCA authorisation, since a firm's financial crime framework forms part of the systems and controls assessed at application.
What Did the FCA Find on Financial Crime Controls?
The FCA engaged with 242 firms during 2025/26, issuing a questionnaire to which 87% responded and interviewing senior staff at a smaller subset spanning public and private markets. Controls were evaluated against the MLRs, the Financial Crime Guide (FCG), the Senior Management Arrangements, Systems and Controls sourcebook (SYSC), Joint Money Laundering Steering Group (JMLSG) guidance and Financial Action Task Force (FATF) guidance. All percentages are calculated from that sample of 242 firms, not from the sector as a whole
The findings cover how well firms understand their inherent financial crime risk and how well they control it. The FCA states plainly that in some instances the findings were concerning and will require firms to review their frameworks.
Inherent Risk Is Concentrated, But Not Confined, to Private Markets
Three features drive higher inherent risk: complex ownership structures crossing jurisdictions, high-risk customers, and international fund flows. The FCA's data show these clustering in private markets. Around a fifth of firms active in private markets reported that over 30% of their customers use complex ownership structures, while 85% of firms not active in private markets reported no such customers at all. Politically exposed persons (PEPs) featured in the customer base of 32% of private markets firms, against 9% elsewhere. Half of all firms reported that over 60% of their customer base is domiciled overseas.
Inherent risk should drive the design of the framework. A firm with a largely UK institutional client base is not expected to operate the controls of a firm onboarding multi-layered offshore vehicles, but it is expected to have documented which of the two it is.
Business-Wide Risk Assessments: A Legal Requirement Some Firms Have Not Met
The most significant finding is that just over a fifth of all firms either had not undertaken a business-wide risk assessment (BWRA) or had one that was only partially complete. Among private markets firms, 18% said their BWRA did not specifically cover private markets risks. The FCA also found assessments that were complete but inadequate, for example because they did not consider the inherent risk arising from the firm's own activities or the risk factors prescribed in Regulations 18 and 18A of the MLRs.
This is law rather than best practice, and the BWRA is what allows a firm to judge whether its controls are proportionate to its risks. The good practice identified was simply documented review cycles, including at one firm whose business model was static but which still reviewed and recorded its BWRA regularly. Firms are also directed to the National Risk Assessment of Money Laundering and Terrorist Financing (July 2025).
Customer Risk Assessments and Beneficial Ownership
The FCA found that 18% of firms had no formal customer risk assessment (CRA) methodology, a small number do not classify customers by risk at all, and a small number of private markets firms had no formal process for verifying the ultimate beneficial owner behind multi-layered or offshore structures.
Several firms explained that close relationships and small customer bases let them pick up changes in real time. The FCA accepted this can support event-driven review but was clear it does not remove the requirement for formal documented assessments, without which a firm may be unable to comply with Regulation 28(12) and (13) of the MLRs.
Outsourced Due Diligence Without Adequate Oversight
Around 40% of firms outsource customer due diligence (CDD) and enhanced due diligence (EDD), generally to compliance consultants and fund administrators. Of those, only 36% reported full oversight of the third party's anti-money laundering (AML) onboarding processes, and the FCA found firms that could not explain the processes applied on their behalf. Separately, 10% did not verify the source of wealth of high-risk customers. Outsourcing is permitted, but firms remain fully responsible for compliance with the MLRs and must demonstrate they meet Regulations 28 and 33.
This is the finding most firms will underestimate, because delegation feels like risk transfer when it is nothing of the sort. Oversight needs its own controls: defined service standards, periodic sample testing of files, management information on volumes and exceptions, and a documented annual assessment of the provider.
Ongoing Monitoring and Screening
Most firms monitor customer relationships, with over half undertaking periodic refreshes. Against that, 29% reported no formal transaction monitoring process and 7% no systematic monitoring at all after onboarding. Some rely on manual review because volumes are low, with one or two individuals performing it without documented triggers for identifying suspicious activity. Monitoring the business relationship, including scrutiny of transactions, is mandatory under Regulation 28(11). On screening, 7% do not repeat checks for sanctions, PEPs or adverse media during the relationship, despite the obligation under Regulation 35(1).
Manual monitoring is not the problem here; undocumented monitoring is. A firm with genuinely low volumes can run a proportionate manual process, provided the triggers, frequency, responsible individual and outcomes are written down and capable of being evidenced.
Governance, MLRO Resourcing and Training
Over half of MLROs work part-time or hold shared responsibilities, which the FCA found was often commensurate with the size of the business. Its concern is narrower: more than a quarter of firms with over £10bn in assets under management also reported a part-time or shared MLRO despite wider customer bases and more complex activities, and should consider whether that supports effective AML oversight.
The governance finding is more striking. While 88% of firms track and use management information on financial crime risks, only just over a third discuss AML risk regularly at governance forums and 36% do so annually or less. Half reported no investment in remediation or system uplift in the last 24 months, and 18% had no formal quality assurance process for AML activity. Nearly all firms provide role-relevant training, but some MLROs may not have received training specific to their own legal obligations.
Data gathered but not discussed does not support decision-making, and this gap can be closed at limited cost by a standing agenda item.
Key Themes From the FCA's Findings
Four themes are worth drawing out for boards and senior managers:
Formality is the dividing line. Firms were often doing sensible things without documenting them, and an undocumented risk assessment does not satisfy the MLRs at all.
Inherent risk drives everything else. Where a firm's self-assessment sits below its actual exposure, every downstream control is calibrated too low.
Responsibility cannot be outsourced. Oversight of delegated due diligence is itself a control the FCA expects to see operating.
Governance is where the gap is widest. Management information is being produced but not used.
These points are consistent with the FCA's wider work, including its Asset Management and Alternatives portfolio letter of February 2025 and its commitment to fighting financial crime under the 2025 to 2030 strategy.
What Should Firms Do Now
No firm needs to overhaul its framework because of this publication. What is sensible is a documented review, scaled to inherent risk, that a supervisor could later be shown:
Confirming in writing whether the firm displays the risk features identified: complex or offshore ownership, PEPs, and significant overseas domicile or international fund flows.
Testing the BWRA against Regulations 18 and 18A, including coverage of private markets activity, and setting a recorded review cycle even where the business model is static.
Confirming the CRA methodology is formal and documented, with a defined process for verifying ultimate beneficial ownership in layered structures.
Mapping outsourced CDD and EDD, and adding sample testing, management information and a documented periodic assessment of the provider.
Documenting monitoring arrangements, including manual ones, and confirming screening is repeated during the relationship rather than only at onboarding.
Making AML risk a standing governance item, and assessing whether MLRO capacity and training remain adequate.
Proportionality matters throughout. A small firm should not be building the framework of a global private markets manager, but it should be able to show why its framework is the right one for its risk, which is the evidence the FCA found missing.
Frequently Asked Questions
Does the FCA's July 2026 publication introduce new rules for asset managers?
No. It is categorised as "Good and poor practice" and reports findings from engagement with 242 firms during 2025/26. It creates no new obligations and sets no implementation date. The requirements it refers to, principally in the Money Laundering Regulations 2017, are already in force.
Which firms do the FCA's financial crime findings apply to?
They apply to asset management and alternative firms, a sector of around 2,500 firms, though the FCA notes not all findings apply to all firms. Private markets firms are the primary focus, because they are more likely to have complex ownership structures, PEPs and significant international fund flows.
What is a business-wide risk assessment and is it mandatory?
It is a firm's documented assessment of the money laundering, terrorist financing and proliferation financing risks arising from its business model, customers, products and jurisdictions. It is a legal requirement under Regulations 18 and 18A of the MLRs. The FCA found just over a fifth of firms had none or only a partial one.
Can a firm outsource customer due diligence to a fund administrator or compliance consultant?
Yes, and around 40% of firms in the FCA's sample do. Responsibility does not transfer with the work: the firm remains fully responsible under the MLRs and must demonstrate oversight of the outsourced process. Only 36% of firms that outsource reported full oversight of their provider's AML onboarding.
What happens next after the FCA's findings?
The FCA will use the questionnaire data as it supervises the sector and will intervene where firms fall short. No further consultation or guidance has been announced, so firms should treat the findings as a supervisory benchmark and address gaps in their own frameworks.
How Compliance Angle Can Help
Compliance Angle supports FCA-regulated firms and firms seeking authorisation with financial crime frameworks proportionate to the business model rather than copied from a template. In relation to these findings, we most often help with:
Building business-wide and customer risk assessments into a firm's FCA compliance frameworks and policies, including methodology, documentation and review cycles that meet Regulations 18, 18A and 28 of the MLRs.
Strengthening FCA risk management and governance, including financial crime reporting to boards and committees and management information that supports a decision.
Providing ongoing compliance support and monitoring, including monitoring plans that test AML controls and the arrangements needed to evidence oversight of outsourced due diligence.
Reviewing MLRO capacity and SM&CR responsibilities, including whether a part-time or shared arrangement remains appropriate as a firm grows.
Delivering financial crime training for staff, and role-specific training for MLROs on their own legal obligations.
Supporting applicant firms through FCA authorisation and application support, where a credible financial crime framework must be evidenced at the point of submission.
Support is scaled to a firm's business model, permissions, size and regulatory risk. For a smaller firm broadly in good shape, that may mean a focused gap analysis and a refreshed BWRA. For a private markets firm, it is likely to mean deeper work on beneficial ownership verification and oversight of outsourced due diligence.
If you would like to discuss how these findings apply to your firm, please contact us at info@complianceangle.co.uk.
Source: Financial Conduct Authority, "Asset management and alternative firms' financial crime controls: our findings", published 22 July 2026.


