Our Expert Commentary

FCA Thematic Review Findings

Written by Suntera Global | Aug 6, 2026, 3:37:33 PM

 Co-authored by Mike Booth, Managing Partner and Max Cunningham, Senior Associate at Suntera UK

FCA’s Message

On 22 July 2026, the FCA published findings from its review of financial crime controls across 242 asset management and alternative investment firms. While the review covered the wider sector, a significant proportion of the FCA’s observations were particularly relevant to private markets, where complex ownership structures, cross-border transactions and higher-risk customer profiles are more common.

The FCA’s findings provide a clear indication of the areas where it believes firms may not be keeping pace with the financial crime ("FinCrime") risks arising from their business models.

For private markets firms, the message is particularly relevant. The FCA recognised that these firms often operate in environments where inherent financial crime risks are higher, but also highlighted that controls have not always developed at the same pace.

Why Private Markets Remain Under the Spotlight

The FCA’s findings highlight several factors that can increase financial crime risk within private markets.

Private markets firms reported higher levels of exposure to politically exposed persons ("PEPs"), more frequent use of complex ownership structures, and a greater proportion of overseas customers and cross-border activity compared with firms outside the sector.

None of these factors are risks by themselves. Private markets often involve international investors, multiple ownership layers and complex transactions as part of normal business activity. However, these features can make it more difficult for firms to clearly identify who ultimately owns or controls a relevant party, understand where wealth and funds have come from, and spot activity that may require further investigation.

The more complex an ownership structure becomes, the more countries involved, or the more frequently money moves across borders, the harder it can be to follow the full picture. This is why firms need to ensure their customer due diligence (“CDD”) and ongoing monitoring arrangements are strong enough to identify and manage these risks effectively.

Shift from Having Controls to Demonstrating Effectiveness

One of the clearest themes from the FCA’s findings is that it is looking beyond whether firms simply have policies and procedures in place. The focus is increasingly on whether those controls actually work in practice.

The FCA identified weaknesses across several areas, including:

  • business-wide risk assessments,
  • customer risk assessments,
  • customer due diligence,
  • ongoing monitoring,
  • governance, and
  • training.

Business-wide Risk Assessments

The FCA found examples of firms relying on generic risk assessments that did not properly reflect the nature of their business.

Where firms operate in private markets, the FCA increasingly expect risk assessments to consider factors such as investor types, ownership structures, jurisdictions, use of intermediaries and transaction flows, rather than relying on broad sector-wide assumptions.

Customer Risk Assessments

The FCA also highlighted weaknesses in customer risk assessment processes.

A well-designed customer risk assessment helps firms determine the level of due diligence, monitoring and review required for different customers. Where risk assessments are incomplete or poorly documented, firms may struggle to demonstrate why a particular level of scrutiny was applied.

Outsourcing Does Not Remove Accountability

Many firms rely on third parties, administrators or consultants to support CDD diligence activities.

The FCA's findings reinforce the principle that firms may outsource tasks, but they cannot outsource responsibility. Where third parties perform AML activities, firms should be able to demonstrate that they maintain appropriate oversight and governance.

Ongoing Monitoring

One of the more notable findings was the absence of formal ongoing monitoring arrangements within a proportion of firms reviewed.

Customer risk profiles can change over time. New sanctions risks emerge, ownership structures evolve and individuals may become PEPs after a relationship has commenced.

Effective financial crime frameworks therefore depend on firms monitoring customer relationships throughout their lifecycle rather than treating onboarding as a one-off event.

Governance and Resources

The FCA also highlighted governance arrangements, particularly where AML responsibilities are concentrated within a small number of individuals or supported by limited systems and processes.

While there is no single model that works for every firm, the FCA's findings suggest increasing focus on whether firms have sufficient oversight, management information and resources to manage financial crime risk effectively.

Training Must Keep Pace with Change

Regulatory expectations, sanctions regimes and financial crime risks continue to change.

The FCA observed examples where training was either outdated or insufficiently tailored to specific roles. Firms should consider whether staff, senior management and MLROs receive training that remains relevant to the risks they encounter in practice. They should also consider methodologies to say abreast of regulatory updates through internal forums.

What Does This Mean for Firms?

The FCA’s publication provides a useful indication of how firms’ FinCrime frameworks are likely to be assessed going forward. Firms should be able to demonstrate that their controls are proportionate to their own business model, investor base, jurisdictions, products and distribution channels.

Firms should also be able to explain why their controls are appropriate, how they operate in practice, and how they monitor whether those controls remain effective.

For private markets firms, this may require a closer review of whether their existing FinCrime framework remains proportionate to the nature, scale and complexity of their business.

As regulatory scrutiny of private markets continues to increase, firms that periodically challenge and enhance their FinCrime controls are likely to be better positioned to demonstrate compliance and manage emerging risks.

Learn More

Suntera's consulting team provides independent financial crime health checks, helping firms identify gaps, benchmark controls against regulatory expectations and enhance governance and oversight frameworks. We also offer a comprehensive AML Managed Service, supporting firms with ongoing AML and financial crime compliance obligations through scalable and practical solutions.

To learn more about how we can support your business, get in touch with our team today via the form below.