HomeEnforcement
All enforcement cases

Barclays Bank plc

FCA enforcement action, 2025

£39m
financial penalty
Money LaunderingAMLPRINCIPLES
Where this fine sits
Rank (largest first)
#7 of 44
Top percentile
Top 25%
vs. median fine
10.8x
smallestlargest

What failed

Failed to identify and assess financial-crime risk with due skill, care and diligence over several years.

Read the final notice

The controls that would have caught it

These controls map directly to this failure. Open any one in the Control Builder to set your own thresholds, owners and systems, then export an implementation-ready spec.

In short, the firm needed

  • Documented financial-crime risk assessment refreshed on change
  • Clear ownership across the three lines of defence
  • Customer risk-rating model validation
  • Board MI on residual risk

Firm-Wide Financial Crime Risk Assessment

Preventive

Governance & Reporting

A written, evidence-based picture of where the firm is most exposed to financial crime, kept current, so money and effort go to the riskiest areas first.

Starting threshold:
Refreshed at least annually and on any material change (new product, new market, M&A, regulatory or threat-landscape shift); every residual risk rated above appetite carries a dated remediation action with a named owner.
First-line owner:
Business unit heads (owning their inherent risk inputs and remediation actions)
Design this control

Board & Management Information Reporting

Detective

Governance & Reporting

Regular, honest numbers and trends about financial crime risk put in front of senior leaders, so problems are seen and acted on instead of being buried.

Starting threshold:
A defined financial crime MI pack delivered to the relevant committee at least quarterly and to the board at least twice a year; every red indicator accompanied by cause, owner and dated remediation; no material adverse trend reported without narrative.
First-line owner:
Financial Crime Operations / MI team compiling the pack
Design this control

Three Lines of Defence & Accountability

Preventive

Governance & Reporting

A clear split of who owns risk, who oversees it, and who independently checks it, with named senior people accountable, so nothing falls through the gaps.

Starting threshold:
Every in-scope financial crime control mapped to a named first-line owner and a second-line overseer; MLRO and the accountable senior manager formally appointed and board-approved; second and third line independent of the first line they oversee and assure; responsibilities reviewed at least annually and on any reorganisation.
First-line owner:
Business unit and operations heads (own and run the controls)
Design this control

Independent Assurance & Control Testing

Detective

Governance & Reporting

People independent of the day-to-day teams regularly test whether financial crime controls actually work, so weaknesses are found internally before a regulator finds them.

Starting threshold:
A risk-based assurance plan covering all high-residual-risk controls at least annually (lower-risk controls on a multi-year rotation); sampling sized to a defensible confidence level; every finding rated, owned, dated and re-tested at closure; no high-severity finding closed without independent verification.
First-line owner:
Control owners (remediate findings); first-line QA where it performs in-line checking
Design this control

Staff Training & Awareness

Preventive

Governance & Reporting

Make sure everyone, especially front-line and high-risk roles, knows how to spot financial crime and what to do about it, and prove they have understood it.

Starting threshold:
100% of in-scope staff complete role-appropriate training at induction and at least annually, with a passed assessment (e.g. >= 80% score); new joiners trained before in-scope access; targeted training delivered within an agreed period of a material regulatory change or relevant incident.
First-line owner:
Line managers and HR/Learning (delivery and completion in their teams)
Design this control

Typologies behind this case

Related enforcement cases

Enforcement data is sourced from the FCA fines dataset. The control mapping is an analyst view of what would have addressed the failings described in the public notice, not a statement of the regulator's findings.