The Financial Conduct Authority (FCA) has published its latest review of financial crime controls within asset management and alternative investment firms, highlighting examples of both good and poor practice across the sector. While most firms demonstrated an understanding of their legal and regulatory requirements through their control frameworks, the FCA also identified recurring weaknesses that could expose firms to financial crime risks and increased regulatory scrutiny.
The findings provide valuable insight into the FCA’s supervisory expectations and serve as a timely reminder that financial crime compliance should be an ongoing, risk-based process. As firms continue to expand into new markets, launch new products and onboard increasingly complex client bases, they should regularly assess whether their financial crime frameworks remain proportionate, effective and aligned with evolving risks.
Good and Poor Practices Identified by the FCA
The FCA’s review found that standards across the sector remain mixed, with some firms demonstrating mature financial crime frameworks while others continue to rely on outdated or inconsistently applied controls.
Examples of good practice included:
- Business-Wide Risk Assessments (BWRAs) that were tailored to the firm’s products, services, customer base and geographical exposure, rather than relying on generic templates.
- Customer Due Diligence (CDD) processes supported by clearly documented customer risk ratings and appropriate application of Enhanced Due Diligence (EDD) for higher-risk relationships.
- Strong governance, with boards and senior management actively overseeing financial crime risks through regular reporting, meaningful management information and appropriate challenge.
- Effective ongoing monitoring frameworks that identified changes in customer risk profiles and ensured reviews remained proportionate throughout the customer lifecycle.
- Regular testing and independent reviews of financial crime controls to assess whether policies and procedures were operating effectively in practice.
The FCA also identified several areas where firms should strengthen their controls, including:
- Generic or outdated Business-Wide Risk Assessments that did not accurately reflect the firm’s activities or emerging financial crime risks.
- Inconsistent customer risk assessments and insufficient evidence supporting due diligence decisions.
- Limited board engagement, with financial crime compliance often viewed as solely the responsibility of the Compliance function rather than a firm-wide governance issue.
- Weak ongoing monitoring processes that failed to identify changes in customer activity, ownership structures or other evolving risk factors.
- Poor record keeping, making it difficult for firms to demonstrate how financial crime risks had been identified, assessed and managed.
The FCA’s message is clear: effective financial crime compliance extends beyond maintaining policies and procedures. Firms should ensure that their controls are embedded across the organisation, supported by robust governance and underpinned by clear evidence of consistent, risk-based decision-making.
Key Observations
The FCA’s findings reflect a broader regulatory trend that we continue to observe across the financial services sector. Increasingly, regulators are assessing not only whether firms have appropriate policies in place, but whether those policies are effectively implemented, regularly reviewed and capable of adapting to changing risks.
This makes governance, documentation and ongoing monitoring more important than ever. Firms should ensure that risk assessments remain up to date, senior management maintain effective oversight, and compliance decisions are supported by clear audit trails. Periodic independent reviews can also provide valuable assurance that financial crime frameworks remain aligned with both regulatory expectations and industry best practice.
The FCA has not specified a separate implementation deadline arising from this review. However, it has encouraged firms to consider the findings in the context of their own business models and activities and to address any gaps in their financial crime control frameworks. The FCA has also confirmed that it will use the information gathered through the review in its ongoing supervision of the sector and may intervene where firms fall short.
How Complyport Can Help
ComplyPort supports asset managers, alternative investment firms and other regulated businesses in strengthening their financial crime frameworks and meeting evolving FCA expectations. Our experienced consultants provide practical, risk-based support across a range of compliance services, including:
- Independent AML and financial crime framework reviews;
- Business-Wide Risk Assessments (BWRAs);
- AML, CTF and sanctions policy drafting and reviews;
- Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) framework assessments;
- Financial crime health checks and gap analyses;
- Compliance monitoring programme reviews;
- Governance and regulatory compliance support;
- MLRO advisory services and tailored financial crime training.
Book a Meeting with a Complyport SME
To learn more and ensure compliance with upcoming regulatory developments, book a consultation with a Complyport Subject Matter Expert today.
Ask ViCA, your Virtual Compliance Assistant.
Access instant answers on regulatory changes.
Claim your complimentary 20 queries today! Register here: https://vica.chat
CPT social media:
#FCA #FinancialCrime #AML #AntiMoneyLaundering #AssetManagement #AlternativeInvestments #Compliance #RiskManagement #FinancialServices #RegulatoryCompliance #Governance #CDD #EDD #MLRO #ComplianceConsulting #ComplyPort






