Anti-Financial Crime & Financial Crime Compliance
Regulatory Intelligence Leadership | Insight | Network

Compliance, Compliance News, Financial Crime, Regulatory, UK

INSIGHT: Is the UK’s FCA becoming a financial crime regulator in all but name?

File photo of the UK's Financial Conduct Authority offices

By Alan Ward

Partner at London Stephenson Harwood LLP

ENFORCEMENT data published on last month by the UK’s FCA (Finanial Conduct Authority) reveals a regulator whose enforcement function is becoming increasingly defined by one priority: financial crime.

The headline statistic is striking. More than 75% of the FCA’s enforcement work now focuses on fighting financial crime. Beyond that figure, firms can draw valuable lessons from the types of financial crime enforcement cases the FCA is opening; increases in and use of whistleblowing; and the changing balance of enforcement against firms and individuals. 

When read alongside recent supervisory reviews published by the FCA in April and July 2026, the data reveals both the key aspects of financial crime governance on which firms should focus, and the potentially severe consequences of any gaps being left unaddressed. 

Enforcement operations – overall view 

As at 31 March 2026, the FCA had 127 open enforcement operations involving 218 individuals and 108 firms, down slightly from 130 operations the previous year.

The FCA delivered 47 enforcement outcomes in 2025/26, up from 42 in 2024/25. 

The data indicates that most new investigations continue to focus on firms rather than senior individuals. New cases opened solely against individuals remain rare, accounting for fewer than 1% of new matters. More than a decade after the introduction of the Senior Managers and Certification Regime (“SMCR”), the FCA continues to reserve individual accountability investigations for a relatively small number of cases, while concentrating resources on firm-wide issues and financial crime concerns.

The investigation duration data also presents a mixed picture. The FCA highlights faster outcomes in several recent investigations. While newer cases appear to be moving more quickly through the system, complex investigations continue to take several years to conclude.

Financial crime – which aspects are in focus? 

The headline statistic – more than 75% of all enforcement work focusing on financial crime – is broken down as follows: 

  • 96 out of 127 current enforcement operations are focused on “fighting financial crime” (76%). 
  • Of those 96 operations: 
  • 56 concern fraud; 
  • 18 concern financial crime systems and controls; and 
  • 22 concern financial crime in markets. 

Particularly noteworthy is that the FCA opened more ‘financial crime in markets’ cases than ‘financial crime systems and controls’ cases. Whilst a single year of data should be treated cautiously, this may indicate an increasing focus on misconduct occurring within markets themselves, rather than solely on the adequacy of firms’ control frameworks.

One note of caution is required. The FCA states that matters previously categorised under “reducing and preventing financial crime” and “strengthening wholesale markets” are now reported under “fighting financial crime”. Some of the increase may therefore reflect changes in reporting methodology rather than enforcement strategy alone.

Whistleblowing is becoming increasingly influential 

The FCA reports a 20% increase in whistleblowing disclosures. More notably, over 40% of disclosures resulted in “direct action”, while a further 53% informed broader supervisory or harm-prevention work.

That is a reminder that whistleblowing is increasingly functioning as an intelligence-gathering mechanism rather than simply a source of enforcement referrals. Firms should assume that concerns raised internally, or reported directly to the regulator, may influence supervisory engagement even where no formal investigation follows.  

Criminal convictions increase markedly 

The FCA secured 17 criminal convictions during 2025/26, compared with just five the previous year. It also brought criminal charges against 10 individuals.

It has been suggested that delays in the criminal courts system might prompt agencies that have the power to use alternative tools, such as civil enforcement, to move away from pursuing criminal charges. 

The latest figures suggest the opposite. Criminal investigations remain resource-intensive, but the regulator appears increasingly willing to open and prosecute them where they support its broader deterrence objectives. 

Analysis and Comment – Implications for Firms 

The headline message on financial crime is striking. But the more important lesson may be that the FCA is increasingly deploying multiple regulatory tools in pursuit of the same objective. Whistleblowing intelligence, supervisory interventions, skilled person reviews, criminal prosecutions and enforcement investigations all now appear closely aligned around the financial crime agenda.

For firms, the practical question is no longer whether financial crime is an enforcement priority. The question is whether governance, controls and escalation processes are keeping pace with the regulator’s increasingly concentrated focus.

The enforcement statistics are consistent with a broader trend evident across the FCA’s recent supervisory work. During 2026, the regulator published reviews of both asset management firms’ financial crime controls (July 2026) and firms’ customer due diligence processes (April 2026). Although neither publication is an enforcement document, both provide a useful indication of the control weaknesses that FCA supervisors are currently identifying across the market.

Perhaps the most significant message is that the FCA increasingly appears to view financial crime risk as a governance issue rather than solely a compliance issue. Across both reviews, the regulator’s focus extends beyond whether firms possess the required AML policies and procedures. It is examining whether firms understand their own risk profile, whether senior management is actively engaged with financial crime issues and whether control frameworks operate effectively in practice rather than merely on paper.

That emphasis matters because it aligns closely with the direction of travel visible in the FCA’s enforcement portfolio. Where the FCA regards weaknesses in financial crime controls as evidence of broader governance failings, deficiencies that might once have been treated primarily as supervisory concerns can become potential enforcement issues.

The FCA’s findings suggest that firms will face increasing scrutiny regarding how financial crime risks are identified, assessed and escalated. In particular, the reviews highlight instances where firms appeared to underestimate the level of financial crime risk inherent in their business activities or failed to demonstrate a sufficiently rigorous approach to documenting and evidencing risk-based decisions. The issue is therefore not simply whether a firm reaches the correct outcome, but whether it can explain and justify the process through which that outcome was reached.

The publications also contain an important warning for firms that rely heavily on third-party providers. Customer onboarding, identity verification, sanctions screening, adverse media checks and corporate intelligence services are increasingly performed by external vendors. The FCA’s recent work reiterates a familiar regulatory principle: delegation of activity does not amount to delegation of responsibility. In its review of asset managers and alternative firms, the FCA identified examples where firms appeared to rely on outsourced due diligence arrangements without maintaining adequate oversight of the quality and effectiveness of the work being undertaken

In an enforcement environment where financial crime has become the FCA’s clear priority, that observation may take on greater significance. Firms may need to be able to demonstrate not only that third-party providers have been appointed following appropriate due diligence, but that their outputs are subject to ongoing review, challenge and testing. Outsourcing arrangements that reduce visibility over key financial crime controls may attract increasing regulatory attention.

The governance implications are equally important. The FCA’s reviews point towards an expectation that boards and senior management should receive meaningful information about financial crime risks, control deficiencies and remediation activity. They also highlight concerns in relation to resourcing, including examples involving insufficient financial crime expertise and inadequate support for key control functions. Financial crime frameworks that are perceived as under-resourced or insufficiently embedded within decision-making structures may therefore become an area of regulatory focus.

Against that backdrop, firms may wish to revisit a number of practical questions:

  • Does the firm’s financial crime risk assessment accurately reflect the current reality of its customers, products, services, delivery channels, and geographic exposure?
  • Can senior management demonstrate active oversight of financial crime risk and evidence how significant decisions are escalated and challenged?
  • Are outsourced due diligence, screening and monitoring activities subject to meaningful assurance and testing?
  • Is there a sufficiently clear audit trail explaining why higher-risk customers, transactions or relationships were accepted and how those decisions were reviewed?
  • Are control functions adequately resourced to keep pace with the firm’s risk profile and growth strategy?

Taken together, the enforcement statistics and the FCA’s recent supervisory findings suggest that financial crime is becoming one of the principal lenses through which the regulator assesses whether firms are being run effectively.

Firms should therefore view financial crime controls not as a discrete compliance obligation, but as an increasingly important component of governance, risk management and operational resilience. Those that can demonstrate effective oversight, clear accountability and robust control frameworks are likely to be better placed if supervisory scrutiny develops into enforcement action.

Alan Ward is a Partner in the Regulation and Investigations Practice Group at Stephenson Harwood LLP 

AML Intelligence
We hope you enjoyed reading this article

If you would like unlimited access to AML Intelligence premium articles, newsletter delivered twice a week, access to our Global Bank Fines and Penalties database, free access to Boardroom Series events and much more, select one of our subscription options and become a subscriber!