FCA UK highlights gaps in financial crime oversight

FCA Financial Crime Oversight

FCA, UK Financial Authority, highlights gaps in financial crime oversight and weaknesses in BWRA and CRA

The UK Financial Conduct Authority has reported material weaknesses in financial crime oversight, focusing on corporate finance firms, and separate failings in business-wide risk assessments and customer risk assessments across selected sectors. Firms should review risk frameworks, evidence governance, and address control gaps promptly.

Key findings on corporate finance firms

An FCA survey indicates many corporate finance firms that are not required to submit financial crime returns may be falling short of money laundering requirements. Highlights include:

  • 11% reported no documented business-wide risk assessment (BWRA).
  • 10% said they did not retain documented customer due diligence (CDD) evidence.
  • 29% of principal firms did not conduct financial crime risk assessments for appointed representatives.
  • 6% of principal firms did not monitor appointed representatives’ compliance or conduct on-site checks.

FCA review of risk assessment processes and controls

A separate multi-firm review, covering building societies, platforms, custody and fund services, e-money/payments and wealth managers, found:

  • Most firms have a BWRA, yet many do not tailor risks to their business model.
  • Limited linkage between risk assessments, decision-making, and monitoring.
  • Few documented actions arising from assessments.
  • Fraud risk awareness tends to be stronger than other financial crime risks.

Context: Recent enforcement and public actions show the FCA’s continued focus on economic crime controls.

What firms should do now

Use the FCA’s findings to test your framework and prepare evidence for supervisory queries: FCA

  • Refresh your BWRA: map products, delivery channels, geographies, customer types, and financial crime typologies, then evidence rationale and scoring.
  • Tighten CRA rules: link customer risk factors to CDD levels, ongoing monitoring, and trigger events.
  • Close governance gaps: record actions from each assessment, assign owners and deadlines, and track completion.
  • Evidence oversight of ARs: risk assess appointed representatives, perform on-site reviews, and keep an audit trail.
  • Join up MI and decisions: show how risk metrics inform approvals, product changes, and resource plans.
  • Train senior management: broaden beyond fraud to include sanctions, bribery and corruption, and market abuse interfaces.
  • Document everything: store versions of BWRAs, CRAs, methodology notes, scenarios, and board minutes.

How Cascade can help

While specific features vary by deployment, AML/KYC platforms like Cascade can typically support: guided CRA workflows, document capture and retention, adverse media and PEP/sanctions screening, ownership mapping, automated monitoring, and review reminders. Discuss your requirements to shape an implementation that meets sector needs.

FAQs

What is a BWRA and why does it matter?

A BWRA (business-wide risk assessment) is the firm-level assessment of inherent and residual financial crime risks. It drives control design, staffing, and monitoring priorities.

How should CRAs connect to CDD and monitoring?

Your CRA (Customer Risk Assessment) should determine CDD depth, screening thresholds, periodic review cadence, and alert treatment, with clear rationale recorded.

What will the FCA expect to see?

A tailored, documented BWRA and CRA, clear links to decisions and MI, evidence of AR oversight where relevant, and completed action logs.

Does this apply beyond corporate finance firms?

Yes, the thematic findings on risk assessment quality apply across several regulated sectors, not just corporate finance.

Get started with AML tools
Speak with our team about an implementation that aligns with your UK risk profile and FCA expectations.

Ready to Get Started?

Empower your compliance with the leading end-to-end AML KYC platform Cascade