HomeEnforcement
All enforcement cases

Equifax Limited

FCA enforcement action, 2023

£11m
financial penalty
FraudFRAUDSYSTEMS_CONTROLSCONDUCTFINANCIAL_PROMOTIONSRECORD_KEEPINGPRINCIPLES
Where this fine sits
Rank (largest first)
#13 of 44
Top percentile
Top 50%
vs. median fine
3.1x
smallestlargest

What failed

Outsourced data processing suffered a major breach with weak oversight of the outsourced provider.

Read the final notice

The controls that would have caught it

These controls map directly to this failure. Open any one in the Control Builder to set your own thresholds, owners and systems, then export an implementation-ready spec.

In short, the firm needed

  • Outsourcing and third-party risk due diligence
  • Data-security controls and breach monitoring
  • Governance over incident handling and customer treatment

Outsourcing & Third-Party Oversight

Preventive

Governance & Reporting

When financial crime work is outsourced or done by a partner, the firm still owns the risk, so it must check, oversee and be able to evidence the provider is doing the job.

Starting threshold:
100% of outsourced financial crime activities recorded in the register with completed pre-engagement due diligence; SLAs, audit rights and incident-notification clauses contractually in place; provider performance reviewed at least quarterly and assurance performed at a risk-based cadence; material providers re-assessed annually and on any sub-outsourcing change.
First-line owner:
Outsourcing / vendor relationship owner in the business
Design this control

Typologies behind this case

Related enforcement cases

Enforcement data is sourced from the FCA fines dataset. The control mapping is an analyst view of what would have addressed the failings described in the public notice, not a statement of the regulator's findings.