FCA focuses on governance and outsourcing in review of asset managers’ and alternative firms’ financial crime controls

FCA focuses on governance and outsourcing in review of asset managers’ and alternative firms’ financial crime controls

On 22 July 2026, the Financial Conduct Authority (FCA) published its latest multi-firm review, Asset Management and Alternative Firms’ Financial Crime Controls: Our Findings (the Findings).

The Findings are particularly significant because they go beyond technical AML compliance and place renewed emphasis on governance, senior management oversight, and the quality of firms’ control over outsourced financial crime processes.

The FCA engaged with 242 firms, obtaining questionnaire responses from 87% of them and conducting follow-up interviews with senior personnel at selected firms. The review assessed firms against the Money Laundering Regulations 2017 (MLRs), the FCA’s Financial Crime Guide (FCG), SYSC requirements, JMLSG guidance, and FATF standards.

The Findings are directed at asset managers and alternative investment firms, including private markets participants. Their purpose is to help firms assess whether their financial crime frameworks adequately identify, manage and mitigate the risks inherent in their business models. The FCA makes clear that exposure to financial crime risks is not uniform across the sector. In particular, firms operating in private markets often face heightened risks arising from complex ownership structures, international fund flows and higher-risk customer profiles.

Many of the themes will be familiar to compliance and financial crime professionals. In April 2026, the FCA published its review of firms’ customer due diligence (CDD), enhanced due diligence (EDD) and ongoing monitoring controls (see our earlier article here).1 The April 2026 findings identified weaknesses in policies and procedures, customer risk assessments, governance arrangements and compliance assurance.

While there are common themes across the two publications, the Findings are notable in two respects.

  1. They place greater emphasis on financial crime governance, including board oversight, management information and the resourcing of MLRO functions.

  2. They contain some of the FCA’s clearest commentary to date on outsourcing financial crime controls, particularly CDD and EDD activities. In both areas, the FCA’s view is unequivocal: firms may outsource financial crime activities, but those activities must be understood and monitored. Responsibility cannot be outsourced.
       

Key Findings

Inherent Financial Crime Risks in Private Markets

The FCA's data suggests that firms active in private markets face materially greater inherent financial crime risks than other asset managers. Around a fifth of private markets firms reported that more than 30% of their customers utilised complex ownership structures, whereas 85% of firms outside private markets reported no customers with such structures. Similarly, 32% of private markets firms reported politically exposed persons (PEPs) within their customer base compared with only 9% of other firms.

The FCA also found that half of all firms reported that more than 60% of their customers were domiciled overseas, with private markets firms more likely to facilitate international transfers and cross-border fund flows.
   

Weaknesses in Business-Wide Risk Assessments

Just over one-fifth of firms had either failed to conduct a business-wide risk assessment (BWRA) or had only completed one partially. The FCA also found examples where BWRAs existed but did not adequately consider the firm's actual financial crime risks. Particularly striking was the finding that 18% of firms active in private markets stated that their BWRA did not specifically address private markets risks.
  

Customer Risk Assessment Failings

The FCA identified shortcomings in formal customer risk assessment methodologies. Eighteen per cent of firms lacked a documented customer risk assessment framework altogether. Some firms operating in private markets had no robust process for identifying and verifying beneficial owners within complex offshore or multi-layered structures. A small number did not classify customers according to risk.
  

Ongoing Monitoring and Screening

Although many firms operated periodic review processes, 29% reported having no formal transaction monitoring process. The FCA encountered firms relying on informal manual reviews conducted by a small number of individuals without documented escalation criteria or triggers. It also found that 7% of firms did not conduct repeat sanctions, PEP or adverse media screening.
 

Training

While most firms offered some financial crime training, the FCA identified MLROs who had not received role-specific training and firms with limited awareness of legislative, regulatory and industry guidance developments. The FCA emphasised that regular training not only improves awareness of developments and risks, but also “reinforces staff accountability for detecting and reporting financial crime concerns”.
  

Financial Crime Governance

Governance is one of the most significant aspects of the Findings.

The FCA's findings suggest that many firms view AML controls principally as a compliance function issue and do not place sufficient emphasis on the governance aspects of financial crime control. Financial crime risk management clearly depends on effective oversight from senior management and boards.

One notable finding was that only slightly more than one-third (36%) of firms regularly discussed AML risks at governance forums. This may give rise to concerns that boards and senior management lack sufficient visibility of emerging financial crime risks, the effectiveness of controls, and areas requiring remediation.

Management information was another focal point. Although 88% of firms collected financial crime management information, the more important question is whether they are using that information effectively to support challenge, decision-making and resource allocation. Collecting data is not enough; firms must actively use the data to identify trends, assess vulnerabilities and drive improvements.

The FCA was also concerned about resourcing. More than half of MLROs worked part-time or held other responsibilities. While this may be proportionate in smaller businesses, the FCA highlighted that more than a quarter of firms with assets under management exceeding £10 billion operated with part-time or shared MLRO arrangements.
 

Outsourcing of Financial Crime Controls – CDD and EDD

The other particularly significant aspect of the Findings is the FCA’s data and commentary on financial crime outsourcing.

Approximately 40% of firms reported outsourcing elements of their CDD and EDD processes to fund administrators, compliance consultancies or other service providers. Outsourcing is commonplace within the asset management industry, particularly in private funds, where administrators frequently perform investor onboarding and verification functions.

The FCA expressly acknowledges that outsourcing is permissible. However, it emphasises that firms remain fully responsible for compliance with the MLRs regardless of any delegation arrangements. Notably, the FCA asserts that this goes to the heart of compliance with the MLRs, observing that: “Without adequate oversight and monitoring of outsourced CDD and EDD processes, firms won’t be able to demonstrate that they’re meeting obligations under Regulation 28 and 33 of the MLRs.”

The FCA found that only 36% of firms outsourcing AML onboarding activities maintained what it considered “full oversight” of those processes. Some firms were unable to explain the CDD/EDD methodologies used by outsourced providers or demonstrate that oversight of these activities was being conducted. Ten per cent of firms did not verify high-risk customers’ source of wealth.

These findings should resonate with firms operating outsourced compliance models. Regulatory expectations increasingly focus on outcomes and how they are achieved, including through the design and operation of outsourcing arrangements and related contractual controls. Firms must be capable of demonstrating ongoing oversight through appropriate governance, quality assurance testing, service-level monitoring, escalation procedures and periodic reviews.

From a supervisory perspective, outsourcing appears likely to become an area of increasing focus, particularly in higher-risk sectors such as private markets and alternative investments.
   

Analysis – Implications for Firms

Across both the April 2026 review and the Findings, the regulator's focus extends beyond whether firms possess the required AML policies and procedures. It is examining whether firms understand their own risk profile; whether senior management is actively engaged with financial crime issues; and whether control frameworks operate effectively in practice rather than merely on paper.

Where the FCA regards weaknesses in financial crime controls as evidence of broader governance failings, deficiencies that might once have been treated primarily as supervisory concerns can become the subject of intrusive supervision, interventions, or potential enforcement action.

The FCA's findings suggest that firms will face increasing scrutiny regarding how financial crime risks are identified, assessed, and escalated. In particular, the reviews highlight instances where firms appeared to underestimate or misunderstand the level of financial crime risk inherent in their business activities or failed to demonstrate a sufficiently rigorous approach to documenting and evidencing risk-based decisions. As always, meeting regulatory expectations is not simply a matter of reaching the correct outcome; firms must also be able to explain and justify the process through which that outcome was reached.

The publications also contain an important warning for firms that rely heavily on outsourced third-party providers. The finding that only 36% of firms maintained full oversight of outsourced AML onboarding activities is particularly striking. Almost two-thirds of firms may therefore be falling short of the FCA’s expectations for oversight of outsourced AML arrangements. The takeaway for most firms is clear: financial crime outsourcing arrangements should be reviewed as a matter of priority.

In an enforcement environment where financial crime has become the FCA's clear priority (see our earlier article here), that observation may take on greater significance.2 Firms may need to be able to demonstrate not only that third-party providers have been appointed following appropriate due diligence, but that their processes are well understood and their outputs are subject to ongoing review, challenge and testing. Outsourcing arrangements that reduce visibility over key financial crime controls may attract increasing regulatory attention.

The governance implications of the Findings are equally important. The Findings point towards an expectation that boards and senior management should receive meaningful information about financial crime risks, including control deficiencies and remediation activity, and should act upon that information. The FCA also highlights concerns in relation to resourcing, including examples involving insufficient financial crime expertise and inadequate support for key control functions. Financial crime frameworks that are perceived as under-resourced or insufficiently embedded within decision-making structures may therefore become an area of regulatory focus.

In emphasising the importance of financial crime governance, the FCA is also seeking to focus the attention of those with the authority to drive change within firms on the areas of weakness identified in the Findings.

The practical message is that firms should not wait for supervisory engagement before testing whether their arrangements would withstand regulatory scrutiny. In higher-risk business models, particularly where key controls are outsourced, firms should be able to evidence not only that policies exist, but that governance, oversight and challenge operate effectively in practice.

Against that backdrop, firms may wish to revisit the following practical questions:

  • Does the firm's financial crime risk assessment accurately reflect the current reality of its customers, products, services, delivery channels, and geographic exposure?

  • Can senior management demonstrate active oversight of financial crime risk and evidence how significant decisions are escalated and challenged?

  • Are outsourced due diligence, screening and monitoring activities understood and subject to meaningful assurance and testing?

  • Is there a sufficiently clear audit trail explaining why higher-risk customers, transactions or relationships were accepted, who approved those decisions, and how they were reviewed?

  • Are control functions adequately resourced to keep pace with the firm's risk profile and growth strategy?

Taken together, the enforcement data and the FCA's recent supervisory findings suggest that financial crime is becoming one of the principal ways in which the regulator assesses whether firms are being run effectively.

Firms should therefore view financial crime controls not as a siloed compliance obligation, but as an increasingly important component of governance, risk management and operational resilience. Those that can demonstrate effective oversight, clear accountability and robust control frameworks are likely to be better placed if supervisory scrutiny develops into FCA intervention or enforcement action.

Alan Ward is a Partner in the Regulation and Investigations practice group at Stephenson Harwood LLP
 

1 Key practical takeaways from the FCA’s latest review of CDD and EDD, Alan Ward
2 FCA – Financial Crime Agency?, Alan Ward

Share Article

Related Expertise