What happened
The Financial Conduct Authority has warned that UK financial services firms still have potentially serious gaps in their financial crime controls, even as those firms assure the regulator they have beefed up their checks. The warning, reported by Compliance Week, lands after a year in which the FCA ran multi-firm reviews across the sector, covering sanctions systems, client due diligence, insurance and asset management.
The finding is consistent across those reviews: what firms say about their controls and what reviewers find do not match. In its client due diligence review findings published earlier this year, the FCA pointed to policies that lacked practical guidance for staff, unclear triggers for periodic and event-driven reviews, and weak version control over compliance documentation. Its sanctions review, covering more than a hundred authorized firms, concluded that controls had improved since 2022 but that significant gaps remain and continue to drive breaches.
The regulator's enforcement posture reinforces the point. The FCA has said it is increasing the pace of its enforcement work to deliver deterrence, and financial crime accounts for a large share of its open enforcement cases.
Why this is a GRC story
KYC is the front-line control for financial crime, and the FCA keeps finding the same thing in sector after sector: the control environment is weaker than the reporting suggests. That gap between asserted and actual controls is the classic self-assessment problem. A GRC program built on attestation and checklists will produce exactly this surprise when a regulator or auditor actually tests the controls.
The specific weaknesses named in the reviews are telling. Policies without practical guidance, unclear review triggers, poor document version control. These are not exotic failures. They are documentation and process hygiene issues that any compliance team can fix, which is why the regulator reads them as evidence that the underlying program is not being operated seriously.
There is also a governance angle for senior management. The FCA expects firms to evidence effectiveness, not just claim it. When findings from a multi-firm review are published, every firm in that sector should read them as a preview of its own examination.
What to watch
Watch whether the FCA escalates from findings to enforcement action against specific firms. Multi-firm review findings have historically fed directly into case work, and the regulator's stated focus on deterrence suggests control gaps found now become penalties later.
For compliance teams, the practical move is to treat published review findings as a checklist before the regulator arrives: confirm your KYC and CDD policies give staff concrete guidance, your review triggers are defined and tracked, and your documentation has real version control. Assurances are cheap. Evidence is what gets examined.
Attribution: Analysis based on Compliance Week's reporting and related public reporting. This article is original commentary, not a repost of the source material.
