Ok
logo_outline-1

Where Your Financial Crime Controls Will Fail Next

Author: Priscilla Gaudoin
shutterstock_2725431707
CheckCircle

Author: Priscilla Gaudoin, Head of Risk & Compliance, published August 2026

CheckCircle

Topics: AI, Alternatives Sector, Asset Management, Due Diligence, Governance, Money Laundering, SM&CR

CheckCircle

Regions and Regulators: UK - FCA

ICA_R_BAD_CPD_19769

Time to read: 4 minutes


TL:DR:
The FCA's July 2026 review of 242 asset management and alternatives firms found that nearly a third have no formal transaction monitoring, a fifth have no adequate business-wide risk assessment, and half haven't invested in AML system upgrades in two years. Under the Senior Managers regime, these are personal accountability gaps. This is a practical guide to closing them, including where AI genuinely helps and where it doesn't.


Financial Crime & Accountability

On 22 July 2026, the FCA published its findings from engagement with 242 asset management and alternative firms, covering business models, inherent risk and control frameworks. This is a mirror, held up to a sector of roughly 2,500 firms, showing precisely where financial crime controls hold up under scrutiny and where they don't.

Effective financial crime controls are not measured by the number of policies on the intranet, but by whether firms can prove those controls work when the regulator asks.

 

Senior management should read these numbers 

The FCA's findings are more specific, and more uncomfortable, than most thematic reviews. A sample of what firms told the regulator about themselves:

  • 29% of firms reported having no formal transaction monitoring process at all
  • Just over a fifth had either no business-wide risk assessment or an incomplete one
  • Half reported no investment in remediation or system upgrades for AML controls in the previous 24 months
  • 36% discussed AML risk at governance forums annually or less often
  • 18% had no formal quality assurance process covering onboarding, alerts or reviews
  • Around 40% outsource client due diligence (CDD) or enhanced due diligence (EDD) checks, while just over a third of those firms had full oversight of the third party's AML onboarding process.

This can be found in the FCA's own publication, and it's the first thing a supervisor will bring to the table in your next review meeting.

Why this happened to a sector that thought it was low-risk

Asset managers have long been viewed as carrying lower money laundering risk than banks. That assumption has been eroding for years, and the FCA's data explains why. Firms active in private markets are far more likely to have customers with complex cross-jurisdictional ownership structures, politically exposed persons in their customer base, and a majority of clients domiciled overseas. Roughly half of all firms in the review reported that over 60% of their customer base sits outside the UK.

Global investment structures have grown more complex, private markets have expanded, and sanctions obligations have widened significantly. The FCA has correspondingly increased its supervisory focus on firms that may previously have attracted less attention. This review demonstrates how the regulator expects firms to apply existing requirements under the Money Laundering Regulations and Senior Management Arrangements, Systems and Controls (SYSC) in practice. The underlying principle hasn't changed: compliance should be driven by risk, not by templates. 

Where the FCA found the real gaps 

Business-wide risk assessments need to be real, not generic

This is the clearest theme in the review. Too many firms are relying on generic risk assessments that don't reflect their actual business. A business-wide risk assessment should explain how risk arises from a firm's specific investor base, products, distribution channels, jurisdictions and intermediaries. Where firms had built detailed, regularly reviewed assessments, the FCA found every other control such as CDD, monitoring, governance to be stronger as a result. The risk assessment isn't merely paperwork, it should be the foundation for everything else.

Customer due diligence: documentation isn't due diligence

Most firms had documented CDD procedures. The FCA's concern was how consistently they were actually applied, particularly around beneficial ownership in multi-layered or offshore structures, and oversight of outsourced CDD/EDD work. Collecting documents is not the same as understanding a client, identifying elevated risk, and being able to explain the judgment behind a decision.

Governance is the line that separates strong and weak frameworks

The firms with the strongest financial crime frameworks shared one trait: engaged senior management and active board oversight. The FCA found that more than a third of firms discuss AML risk at governance forums only annually or less and, notably, more than a quarter of firms with over £10bn in assets under management have an MLRO working part-time or with shared responsibilities. Financial crime accountability sits with senior management under SM&CR, not with the compliance team alone, and the data suggests that message hasn't fully landed.

Sanctions and screening controls need testing, not just software

Given the pace of geopolitical change, sanctions compliance remains a top supervisory priority. The FCA's message is unambiguous: screening software is not a substitute for understanding how the system works, testing its effectiveness, ensuring data quality, and considering whether sanctions risk extends beyond direct customers to investors, counterparties and beneficial owners. This matters most for firms operating internationally or across multiple jurisdictions which is most of the sector.

Where AI genuinely helps 

AI is not part of the FCA's July 2026 findings, but it sits directly behind several of the gaps identified in the review, and it's increasingly part of how firms close them.

Specialist transaction-monitoring engines and sanctions or Politically Exposed Persons (PEP) screening tools already use AI and machine learning to catch patterns manual review misses, and beneficial ownership investigation increasingly draws on AI-assisted entity resolution. Those are important developments, but they sit within specialist screening and monitoring vendors. Firms need a different category of solution to close the governance and evidencing gaps this review is actually raising. This is where a continuous assurance platform's AI adds distinct value is in the layer above those tools. Firms are turning the evidence they and the rest of the control environment produce into something a firm can actually stand behind.

Risk assessment gap analysis: AI can compare a firm's documented risk assessment against its live business data (customer base, jurisdictions, products, distribution channels) and flag where the two have drifted apart. This is the answer to the FCA's single biggest finding: a fifth of firms had no adequate business-wide risk assessment, often because it hadn't kept pace with the business.

Evidence assembly and audit trail: AI can assemble the evidence trail across policies, control testing, attestations and monitoring outputs into a coherent, on-demand response. No need to scramble through emails and the shared drive to collate the evidence.

Board and management reporting: AI can convert control and incident data into board-ready MI, and flag when money laundering risk hasn't reached governance forums as often as it should. This closes the gap given that over a third of firms in the review discussed AML risk annually or less.

Regulatory horizon-scanning: AI can track incoming changes to the Money Laundering Regulations, and FCA guidance, and flag which existing policies or controls they touch. This ensures that a firm’s risk assessment and framework remain current between formal reviews, rather than static until the next one.

None of this replaces a screening engine or a transaction-monitoring system, firms still need those and should judge them on their own merits. What it does is make sure the governance layer sitting above them is as strong as the controls themselves. 

The FCA's broader stance on AI in financial services is consistent with the governance theme running through this review: AI does not reduce senior management's accountability for financial crime outcomes, instead it raises the bar on demonstrating oversight of the tools making the decisions. Firms that adopt AI in financial crime controls without extending the same governance, testing and challenge they apply elsewhere are simply replacing a manual process to an automated one. And not reducing their risk. 

Where does your firm actually sit?

Every firm in this review believed, going in, that its controls were reasonably sound. Half turned out not to have invested in system upgrades in two years. A fifth had no adequate risk assessment. The uncomfortable question for senior management is whether they apply to you, and whether you'd know before a supervisor tells you.

Five questions worth putting to your next executive or board meeting:

  • Does our business-wide risk assessment reflect our business today, or a template from three years ago?
  • Could we explain, with evidence, why our CDD is proportionate to the risks we actually carry?
  • How often does AML risk actually reach board-level discussion, and is that frequency defensible?
  • Are our sanctions controls tested for effectiveness, or just switched on?
  • If the FCA arrived tomorrow, could we evidence that our controls work, not just that they exist?
If any answer is uncertain, that uncertainty is the finding. The FCA has told the market what it's checking. The only real choice left is whether you close the gap on your own timeline or theirs.

How Ruleguard can help


Ruleguard turns these questions into an evidence-based framework rather than a set of intentions. By centralising risk assessments, linking it to compliance monitoring activity, board reporting and assurance testing in one auditable system, Ruleguard gives senior management what the FCA is actually asking for: proof that controls are risk-based, proportionate, and operating effectively and available on demand, not assembled under pressure.

For firms that want a clearer picture of where they stand, we've built a short self-assessment checklist mapped directly to the FCA's July 2026 findings, the same six areas covered in this article, including AI oversight. It takes ten minutes and tells you exactly where to start.

Learn more about Ruleguard's Operational Risk Management Solution

For firms that want a clearer picture of where they stand, we've built a short self-assessment checklist mapped directly to the FCA's July 2026 findings, the same six areas covered in this article, including AI oversight. It takes ten minutes and tells you exactly where to start.

Book a tailored discovery call 

Ready to turn GRC into a board-level advantage?
Book a tailored discovery call with Ruleguard to see how leading firms unify risk and compliance, surface the insights executives care about, and stay audit-ready, without the spreadsheet sprawl. 

Lets chat!-2

 

About the Author

In a career spanning 30 years, Priscilla has worked as a consultant, CCO and MLRO providing regulatory oversight and advice to firms across the financial services industry. She is responsible for our thought leadership programme, writing regular articles and white papers, and hosting webinars on a variety of regulatory matters.
 
She is a Fellow of the International Compliance Association, a certified GRC practitioner, and a member of the Institute of Risk Management.
 
Contact Priscilla
Priscilla Gaudoin