FCA enforcement actions: what 44 cases tell us about AML failure
Analysis of 44 FCA enforcement actions against UK financial institutions reveals consistent patterns: weak transaction monitoring, inadequate CDD and governance failures. Here is what the cases show and the controls that would have caught them.
The Financial Conduct Authority has brought 44 enforcement actions for financial crime failures against UK-regulated firms. The fines range from tens of thousands to over GBP 100 million, but the failures that led to them share a recognisable pattern. Looking across the cases reveals where controls consistently break down and what firms that avoided enforcement did differently.
This analysis draws on the mapped enforcement data in the FinCrime Control Lab dataset, which attributes root causes and preventative controls to each case. Three failure modes account for the majority of outcomes: transaction monitoring that was absent, miscalibrated or not genuinely reviewed; customer due diligence that did not keep pace with changing risk; and governance structures where the MLRO lacked the authority or resource to do their job.
The three failure modes are connected
These are not independent failures. Weak CDD produces inaccurate customer profiles, which makes transaction monitoring less effective because the expected-activity baseline is wrong. Where governance is weak, neither problem gets fixed because nobody is accountable for identifying or escalating them. The FCA's enforcement record shows these three failures co-occurring far more often than any one of them appears alone.
Firms that structured their remediation around a single fix, typically adding monitoring rules after an FCA visit, without addressing the underlying CDD quality or governance accountability, frequently appeared in follow-up regulatory correspondence or later actions.
Transaction monitoring
The most common technical failure across the FCA's enforcement cases is transaction monitoring that was either not in place for all products and accounts, covered gaps the firm had not identified, or generated alerts that accumulated without being reviewed in a consistent or timely way.
The JMLSG Guidance and the FCA Financial Crime Guide both treat ongoing transaction monitoring as a mandatory control. The FCA expects it to cover the full scope of a firm's activity, to be calibrated to the risk profile of the customer base, and to generate alerts that are genuinely reviewed and closed within a documented timeframe. In several enforcement cases, firms had monitoring in place but alert backlogs had grown to the point where the control had effectively ceased to function.
The lesson is that a monitoring system is only as effective as the process behind it. Coverage gaps and unreviewed alerts are treated by the FCA as seriously as having no monitoring at all.
Customer due diligence
A recurring finding in enforcement cases is that CDD was applied at onboarding but did not evolve with the customer relationship. Customers whose risk profile changed, whose transactions became inconsistent with their original declared purpose, or who should have triggered EDD reviews were allowed to continue without further scrutiny.
The MLR 2017 requires firms to apply ongoing CDD proportionate to risk. In practice this means periodic reviews, trigger-based reviews when transaction patterns change, and a process for upgrading a customer's risk rating when new information warrants it. Firms that had no mechanism for doing any of these things on an existing customer book featured in a disproportionate share of enforcement outcomes.
The cases involving high-risk customers, particularly PEPs and customers linked to higher-risk jurisdictions, were especially consistent in showing that initial onboarding controls were applied but that no ongoing monitoring framework was in place to catch deterioration in the relationship.
Governance and the MLRO function
Several enforcement actions noted that the MLRO was not sufficiently senior, did not have adequate resource, or was not consulted on high-risk decisions. The FCA Financial Crime Guide is clear that the MLRO must have sufficient seniority and independence to exercise genuine judgment, and must have access to the management information needed to fulfil their role.
Where the MLRO role is filled by someone without real authority, or where the function is understaffed relative to the volume of alerts and SARs it generates, the result is a compliance team that processes paperwork rather than exercises judgment. That distinction matters in an FCA supervisory assessment and in any subsequent enforcement outcome.
What the controls look like
Looking across the mapped controls for the 44 cases, the most frequently required interventions are activity-versus-expected-profile monitoring, ongoing CDD and periodic review, and SAR processes that ensure the MLRO receives adequate information to make a decision. Each of these addresses one of the three core failure modes described above.
Firms that want to understand how their own control environment compares to the patterns in enforcement can explore the individual cases filtered by firm type or risk theme. Each case shows what failed and the specific controls that would have prevented it.
Try the tool
Browse all 44 cases, filtered by risk theme and firm type. Each case shows the root cause and the controls that would have caught it.
Explore the enforcement trackerSources
- JJMLSG · JMLSG Guidance
- FFCA · FCG
- MMLR · MLR 2017