Professional Personal Claims Limited
FCA enforcement action, 2019
What failed
The firm misled consumers in the claims management sector, breaching conduct of authorised persons rules.
Read the final noticeThe controls that would have caught it
This case has no bespoke control mapping yet, so the controls below are drawn from its risk themes. Open any one in the Control Builder to adapt it to your firm.
In short, the firm needed
- Staff Training & Awareness
- Independent Assurance & Control Testing
- Three Lines of Defence & Accountability
Customer Identification & Verification (CIP/CDD)
PreventiveCustomer Due Diligence
Before a customer can use the account, prove they are who they say they are using reliable, independent evidence, not just what they typed into the form.
- Starting threshold:
- 100% of mandatory identity attributes matched to >=1 independent source before activation; for individuals require 2 of 3 attributes from electronic verification OR 1 authenticated photo-ID document plus a passing liveness check; document image quality / face-match confidence >= 90%.
- First-line owner:
- Onboarding / KYC Operations team
Expected Activity Profiling at Onboarding
PreventiveCustomer Due Diligence
At sign-up, ask and record what normal looks like for this customer (how much, how often, to where) so monitoring can later spot when they behave nothing like that.
- Starting threshold:
- Profile mandatory for all customers; for higher-risk customers require itemised expected monthly turnover, expected corridors and expected counterparties. Flag for review where declared turnover exceeds 3x the income/turnover implied by occupation or filed accounts, or where declared geographies include high-risk jurisdictions not explained by the stated business.
- First-line owner:
- Onboarding / KYC Operations team
Activity vs Expected Profile Monitoring
DetectiveTransaction Monitoring
Compares what a customer actually does on the account with what they told you they would do at sign-up, and flags when the two no longer match.
- Starting threshold:
- Monthly throughput > 3x declared expected throughput in a rolling 30 days, OR appearance of a transaction dimension not in the declared profile (e.g. first international payment on a 'domestic only' account, or first business-pattern flow on a personal account).
- First-line owner:
- Financial Crime Operations Analyst (transaction monitoring team)
Rapid Movement / Pass-Through Detection
DetectiveTransaction Monitoring
Spots money that arrives and leaves almost immediately, where the account is being used as a channel to move funds on rather than to hold or spend them.
- Starting threshold:
- Outbound >= 90% of a qualifying inflow within 24 hours, with residual balance returning to < 10% of the inflow, occurring 2+ times in a rolling 7 days.
- First-line owner:
- Financial Crime Operations Analyst (transaction monitoring team)
Money-Mule & Network Detection
DetectiveTransaction Monitoring
Finds accounts being used by other people to receive and pass on dirty or stolen money, and links them together when they are part of the same ring.
- Starting threshold:
- Account receiving from 3+ unrelated payers and forwarding >= 80% within 48 hours, scored higher where account age < 90 days; cluster alert where 3+ accounts share a device/IP and forward to a common beneficiary within a rolling 14 days.
- First-line owner:
- Fraud / Financial Crime Operations Analyst (mule investigations)
Crypto Blockchain Analytics Monitoring
DetectiveTransaction Monitoring
Uses blockchain analytics to check where crypto sent or received by a customer has been, and flags links to mixers, illicit services or sanctioned addresses.
- Starting threshold:
- Any direct exposure to a sanctioned or darknet address; OR indirect high-risk exposure > 25% of transaction value within 5 hops; OR aggregate mixer-attributed exposure > 10% of a customer's 30-day crypto volume.
- First-line owner:
- Crypto Financial Crime Analyst (on-chain investigations)
Typologies behind this case
Related enforcement cases
Next steps
Enforcement data is sourced from the FCA fines dataset. The control mapping is an analyst view of what would have addressed the failings described in the public notice, not a statement of the regulator's findings.