All enforcement cases
Equifax Limited
FCA enforcement action, 2023
£11m
financial penalty
FraudFRAUDSYSTEMS_CONTROLSCONDUCTFINANCIAL_PROMOTIONSRECORD_KEEPINGPRINCIPLES
Where this fine sits
Rank (largest first)
#13 of 44
Top percentile
Top 50%
vs. median fine
3.1x
smallestlargest
What failed
Outsourced data processing suffered a major breach with weak oversight of the outsourced provider.
Read the final noticeThe controls that would have caught it
These controls map directly to this failure. Open any one in the Control Builder to set your own thresholds, owners and systems, then export an implementation-ready spec.
In short, the firm needed
- Outsourcing and third-party risk due diligence
- Data-security controls and breach monitoring
- Governance over incident handling and customer treatment
Outsourcing & Third-Party Oversight
PreventiveGovernance & Reporting
When financial crime work is outsourced or done by a partner, the firm still owns the risk, so it must check, oversee and be able to evidence the provider is doing the job.
- Starting threshold:
- 100% of outsourced financial crime activities recorded in the register with completed pre-engagement due diligence; SLAs, audit rights and incident-notification clauses contractually in place; provider performance reviewed at least quarterly and assurance performed at a risk-based cadence; material providers re-assessed annually and on any sub-outsourcing change.
- First-line owner:
- Outsourcing / vendor relationship owner in the business
Typologies behind this case
Related enforcement cases
Next steps
Enforcement data is sourced from the FCA fines dataset. The control mapping is an analyst view of what would have addressed the failings described in the public notice, not a statement of the regulator's findings.