As part of its ongoing focus on tackling financial crime, the Financial Conduct Authority (FCA) has published its findings with examples of what it considers to be good and poor practice for financial crime controls among asset management and alternatives firms.
The review, which was informed by surveying asset management and alternatives firms alongside interviews with senior staff at selected firms, identified weaknesses in some companies’ financial crime control frameworks and approaches to financial crime risks, notably around risk assessments, governance and outsourcing of control processes.
The FCA highlighted business-wide risk assessments which, despite being a legal requirement, more than a fifth of those surveyed had either not carried out or not fully completed, with the regulator stressing the importance of considering inherent financial crime risks from a firm’s activities in preparing these.
It also looked at customer risk assessments (CRA) in its report, noting that not all firms had a formal CRA and, in particular, identifying weaknesses in controls for firms participating in private markets.
Sébastien Ferrière, a financial services regulation expert with Pinsent Masons, explained that the regulator’s review had emphasised how certain business models could be at heightened risk of financial crime.
“For firms with private markets business, the FCA’s findings highlight the need for effective due diligence processes for customer risk assessment, especially for customers with complex, layered and/or off-shore structures,” he said.
“In particular, the FCA has reminded firms of the need to establish the ultimate beneficial owner in such structures.”
Private markets are investments outside public stock exchanges. They are seen as a growth area by the regulator and were included among its supervisory priorities for asset management and alternatives firms in its February 2025 portfolio letter (5-page / 124KB PDF).
“With its latest findings, the FCA is reminding firms that proportionate and risk-based customer due diligence and ongoing monitoring must be effective and reflective of their relevant business model,” Ferrière added.
“All firms, in particular those with private markets activity, should look to address any gaps and weaknesses in their financial crime control framework around customer due diligence, as well as assessing if other pointers in the FCA’s review also could apply to their business.”
The FCA reported that around 40% of the firms it engaged with outsource some part of their financial crime compliance function but only 36% of them had full oversight of the third party’s anti-money laundering (AML) onboarding processes. The FCA reminded firms that they remain fully responsible for their own compliance with the AML regulatory regime, and effective oversight and monitoring of outsourced arrangements plays an important role in meeting these obligations.
Additionally, more than a quarter of responding firms appeared to have no formal transaction monitoring process. The report underlines the FCA's expectation that firms maintain consistent and effective ongoing monitoring arrangements, with documented and defined triggers for identifying suspicious activity.
The FCA’s review also found that more than half of the money laundering reporting officers (MLRO) reported they were either part time or had shared duties. The FCA expects larger firms in particular, which it foresees as likely to have wider customer bases and potentially more complex activities, to consider if their MLRO function is sufficient to ensure effective AML oversight and compliance.
David Heffron, a financial services regulation expert with Pinsent Masons, said the findings put asset management and alternatives firms on notice of the potential for increased regulatory activity around financial crime control issues.
“One of the regulator’s poor practice findings was that oversight of AML risk by senior management at some firms was limited, with the FCA reporting that just over a third of firms discussed AML risk annually or less frequently at governance forums”.
“With the FCA specifically reminding firms to use financial crime management information for effective governance and decision making, firms should ensure they are doing so, and that they are able to demonstrate this to the FCA if necessary. For some firms this will include making sure that oversight of AML risk is higher on senior management agendas,” he added.
“Asset management and alternatives firms should now assess their business models and financial crime control frameworks in light of relevant findings and the reminders in the FCA’s review and make the necessary improvements. This is particularly pressing, given the FCA has stated it will continue supervisory scrutiny to ensure firms are doing so.”
Firms failing in their regulatory duties may face supervisory intervention, such as through voluntary requirement agreements or direction agreements, or face enforcement action.
“Concerns related to financial crime controls continue to represent a significant proportion of the FCA’s enforcement pipeline. We have also seen this trend reflected in the FCA’s increasing use of supervisory interventions,” said Ferrière.
Laura Dobie, an investment funds and asset management specialist with Pinsent Masons, added the FCA's findings underline the need for asset managers and alternatives firms to ensure financial crime controls evolve alongside their business models and investor bases.
“Many of the features associated with sophisticated asset management businesses, such as global investor bases and complex ownership arrangements, also create potentially greater financial crime risk,” she warned.
“The FCA's findings are a reminder that commercial growth and regulatory risk can increase in parallel, requiring firms to scale their controls at the same pace as their business."
She added that, with the findings indicating where the FCA expects firms to focus their attention, senior management should now assess their firm’s financial crime risk controls to determine whether they meet the legal and regulatory requirements, and are adequate, effective and proportionate to their business model.