Barclays Bank plc
FCA enforcement action, 2025
What failed
Failed to identify and assess financial-crime risk with due skill, care and diligence over several years.
Read the final noticeThe controls that would have caught it
These controls map directly to this failure. Open any one in the Control Builder to set your own thresholds, owners and systems, then export an implementation-ready spec.
In short, the firm needed
- Documented financial-crime risk assessment refreshed on change
- Clear ownership across the three lines of defence
- Customer risk-rating model validation
- Board MI on residual risk
Firm-Wide Financial Crime Risk Assessment
PreventiveGovernance & Reporting
A written, evidence-based picture of where the firm is most exposed to financial crime, kept current, so money and effort go to the riskiest areas first.
- Starting threshold:
- Refreshed at least annually and on any material change (new product, new market, M&A, regulatory or threat-landscape shift); every residual risk rated above appetite carries a dated remediation action with a named owner.
- First-line owner:
- Business unit heads (owning their inherent risk inputs and remediation actions)
Board & Management Information Reporting
DetectiveGovernance & Reporting
Regular, honest numbers and trends about financial crime risk put in front of senior leaders, so problems are seen and acted on instead of being buried.
- Starting threshold:
- A defined financial crime MI pack delivered to the relevant committee at least quarterly and to the board at least twice a year; every red indicator accompanied by cause, owner and dated remediation; no material adverse trend reported without narrative.
- First-line owner:
- Financial Crime Operations / MI team compiling the pack
Three Lines of Defence & Accountability
PreventiveGovernance & Reporting
A clear split of who owns risk, who oversees it, and who independently checks it, with named senior people accountable, so nothing falls through the gaps.
- Starting threshold:
- Every in-scope financial crime control mapped to a named first-line owner and a second-line overseer; MLRO and the accountable senior manager formally appointed and board-approved; second and third line independent of the first line they oversee and assure; responsibilities reviewed at least annually and on any reorganisation.
- First-line owner:
- Business unit and operations heads (own and run the controls)
Independent Assurance & Control Testing
DetectiveGovernance & Reporting
People independent of the day-to-day teams regularly test whether financial crime controls actually work, so weaknesses are found internally before a regulator finds them.
- Starting threshold:
- A risk-based assurance plan covering all high-residual-risk controls at least annually (lower-risk controls on a multi-year rotation); sampling sized to a defensible confidence level; every finding rated, owned, dated and re-tested at closure; no high-severity finding closed without independent verification.
- First-line owner:
- Control owners (remediate findings); first-line QA where it performs in-line checking
Staff Training & Awareness
PreventiveGovernance & Reporting
Make sure everyone, especially front-line and high-risk roles, knows how to spot financial crime and what to do about it, and prove they have understood it.
- Starting threshold:
- 100% of in-scope staff complete role-appropriate training at induction and at least annually, with a passed assessment (e.g. >= 80% score); new joiners trained before in-scope access; targeted training delivered within an agreed period of a material regulatory change or relevant incident.
- First-line owner:
- Line managers and HR/Learning (delivery and completion in their teams)
Typologies behind this case
Related enforcement cases
Next steps
Enforcement data is sourced from the FCA fines dataset. The control mapping is an analyst view of what would have addressed the failings described in the public notice, not a statement of the regulator's findings.