The FCA’s asset management review of financial crime controls
The Financial Conduct Authority has published the findings of its review of financial crime controls across the asset management and alternative investments sector. They show there is still much room for improvement.
In summary:
- The FCA’s review of financial crime controls assessed firms against requirements including the money laundering regulations (MLRs), the FCA's Financial Crime Guide, SYSC requirements, JMLSG guidance and FATF standards
- It found that firms operating in private markets were particularly likely to face elevated financial crime risks
- Many of the issues identified related to fundamental elements of the financial crime framework, including business-wide risk assessments, customer risk assessments, beneficial ownership verification and outsourced compliance activity oversight
- The review is timely reminder for firms to consider whether their existing frameworks remain proportionate to risks and aligned with regulatory expectations
The FCA review of financial crime controls provides a detailed assessment of how firms identify, assess and manage money laundering, terrorist financing and sanctions risks. Based on engagement with 242 firms, the review highlights examples of both good and poor practice, with particular focus on firms operating in private markets where Financial Crime risks tend to be more complex.
The FCA undertook the review as part of its broader supervisory focus on reducing financial crime and protecting the integrity of UK financial markets. The regulator noted that the asset management and alternatives sector comprises around 2,500 firms with a diverse range of business models, customer types and investment activities, resulting in significantly different risk profiles across the market.
To understand firms' exposure to financial crime risks and the effectiveness of their control frameworks, the FCA issued questionnaires to firms across the sector and conducted follow-up interviews with a selection representing a range of business models and risk profiles.
The review assessed firms against regulatory requirements, including the money laundering regulations (MLRs), the FCA's Financial Crime Guide, SYSC requirements, JMLSG guidance and FATF standards.
Private markets continue to present heightened risks
A key theme emerging from the FCA's findings is that firms operating in private markets are more likely to face elevated financial crime risks. According to the FCA, private market firms are more commonly exposed to:
- Complex ownership structures
- International fund flows
- Overseas investors
- Politically exposed persons (PEPs)
- Higher-risk transactions and counterparties
The review found that around one-fifth of private market firms reported that more than 30% of their customers had complex ownership structures. In contrast, 85% of firms not operating in private markets reported having no customers with such structures. The FCA also found that 32% of private market firms had PEPs within their customer base, compared with only 9% of other firms.
These characteristics can make it more difficult to identify beneficial ownership, understand the source of funds and wealth, and detect potential money laundering or sanctions risks. As a result, firms with higher inherent risk profiles are expected to maintain stronger and more sophisticated Financial Crime controls.
A key theme emerging from the FCA's findings is that firms operating in private markets are more likely to face elevated financial crime risks.
Weaknesses in business-wide risk assessments
One of the FCA's most significant concerns related to business-wide risk assessments (BWRAs), which form the foundation of a firm's anti-financial crime framework. The review found that just over one-fifth of firms had either not completed a BWRA or had only partially completed one. The FCA also identified cases where firms had documented assessments but failed to adequately consider the specific financial crime risks arising from their activities. Particularly concerning was the finding that 18% of private market firms stated that their BWRA did not specifically address private market risks, despite the elevated risks associated with this sector.
The FCA reminded firms that BWRAs are a legal requirement under the MLRs and should be regularly reviewed to ensure that financial crime risks remain accurately assessed and effectively mitigated. The regulator highlighted examples of good practice where firms conducted periodic reviews of their assessments even where their business model had not materially changed.
Customer risk assessment and due diligence remain areas of focus
The review also identified weaknesses in customer risk assessment processes and customer due diligence arrangements.
The FCA found that 18% of firms lacked a formal customer risk assessment (CRA) methodology, raising concerns that firms may not be consistently applying appropriate levels of due diligence. In some cases, firms relied on regular interaction with a relatively small customer base to understand risk levels. While ongoing engagement can help identify changes to a customer's profile, the FCA stressed that firms are still required to maintain formal, documented customer risk assessments.
The regulator also highlighted weaknesses in the identification and verification of ultimate beneficial owners (UBOs), particularly within complex and offshore ownership structures. A small number of firms active in private markets had no formal UBO verification process in place, which increases the risk of ownership structures being used to conceal illicit activity. Additionally, some firms reported that they did not classify customers according to risk at all, limiting their ability to apply a proportionate and risk-based approach to customer due diligence and ongoing monitoring.
Outsourcing does not transfer accountability
Many firms have chosen to outsource elements of their anti-money laundering programmes, particularly customer due diligence and enhanced due diligence activities. The FCA found that approximately 40% of firms outsourced some aspect of their financial crime compliance framework, typically to fund administrators or specialist compliance providers.
However, the review revealed that oversight of those outsourced arrangements was often inadequate. Among firms that outsourced AML onboarding activities, only 36% reported having full oversight of the third party's processes. The FCA noted that some firms could not adequately explain how customer due diligence was being performed or demonstrate that effective monitoring of the outsourced provider was taking place.
The review serves as an important reminder that outsourcing a function does not outsource regulatory accountability. Firms remain fully responsible for compliance with the MLRs and must be able to evidence appropriate oversight of third-party providers.
The review serves as an important reminder that outsourcing a function does not outsource regulatory accountability.
Our view: weaknesses in key controls
The FCA's findings reinforce a trend that we continue to observe across the asset management and alternatives sector. As firms expand into private markets, attract increasingly international investors and navigate more complex ownership structures, financial crime risks become more sophisticated and more difficult to manage.
What is particularly notable about the FCA's review is that many of the deficiencies identified relate to fundamental elements of a firm's financial crime framework. Business-wide risk assessments, customer risk assessments, beneficial ownership verification and oversight of outsourced compliance activities should form the bedrock of an effective control environment. Yet these were among the most common weaknesses identified by the regulator.
Importantly, firms should not view these findings as relevant only to higher-risk organisations. The FCA's observations demonstrate that weaknesses often arise not from a lack of policies, but from inadequate implementation, poor documentation, limited governance oversight or a failure to reassess risks as business models evolve.
Against a backdrop of increasing regulatory scrutiny, firms should use this publication as an opportunity to challenge whether their existing framework remains proportionate to the risks they face and aligned with current regulatory expectations.
The review is a timely reminder that effective financial crime controls are not simply a regulatory requirement but a critical component of good governance and risk management. While many firms demonstrated a strong understanding of their obligations, the findings show considerable room for improvement across the sector. Firms that take proactive steps now to reassess risks, strengthen controls and evidence effective oversight will be better positioned to meet regulatory expectations and respond to future supervisory scrutiny.
From compliance to competitive advantage
Responding directly to the FCA's findings or proactively reviewing existing arrangements, we can help.
We support asset managers, private equity firms, alternative investment managers and other regulated businesses assess and strengthen financial crime frameworks. We can help identify control gaps, prioritise remediation activity and strengthen your ability to demonstrate compliance.