FCA Findings on Risk Assessment Processes: What Firms Need to Know – and How Neotas Can Help
Introduction
In November 2025, the Financial Conduct Authority (FCA) released its latest review into how UK firms manage financial-crime risks through their Business-Wide Risk Assessments (BWRA) and Customer Risk Assessments (CRA). The findings reveal a mixed landscape: some firms are demonstrating genuinely robust practice, while many others still fall short of regulatory expectations.
For compliance teams, MLROs and senior managers, the message is unambiguous: risk assessments must be evidence-based, actively governed, and embedded into real decision-making – not static documents prepared for audit purposes alone.
1. What the FCA Reviewed
The FCA assessed risk assessment frameworks across:
- Banks and building societies
- Payment services providers and e-money institutions
- Platforms and fintechs
- Wealth managers
- Custody and fund service providers
The review focused on how effectively firms identify, understand and mitigate money-laundering, sanctions, terrorist-financing and proliferation-financing risks, and whether those assessments meaningfully inform operational controls.
2. What Firms Are Doing Well
âś“ Tailored and data-driven assessments
Leading firms balanced qualitative judgement with quantitative indicators, clearly documenting inherent risk, control effectiveness and residual risk. Their assessments reflected the realities of their business models, customer demographics and geographic exposure.
âś“ Regular, meaningful review cycles
These weren’t superficial annual updates. Strong firms performed full annual reassessments, supplemented by interim reviews triggered by business changes, product launches or shifting threat landscapes.
âś“ Integration with strategy and governance
In high-performing firms, risk assessments influenced product decisions, market entry, resource planning and staffing. Senior leaders not only reviewed assessments but actively challenged assumptions and conclusions.
âś“ Clear ownership and documentation
Decisions were well recorded, mitigation actions tracked and responsibilities assigned. Financial-crime risk sat firmly within broader governance structures.
3. Where the FCA Found Weaknesses
Generic or poorly evidenced BWRAs
Many firms relied on boilerplate risk descriptions with limited relevance to their actual customer mix, products or jurisdictions. Quantitative evidence was often missing or incomplete.
Weak linkage between risks and controls
Some assessments identified risks but failed to explain existing controls, their effectiveness or how risk outcomes influenced onboarding, monitoring or resource deployment.
Poor governance and limited senior oversight
The FCA frequently observed weak documentation of approvals, challenge, or ongoing oversight. In several cases, firms could not demonstrate how key decisions were made.
Outdated frameworks unable to keep pace with growth
As firms expanded products or entered new markets, many did not re-evaluate their risk profiles, resulting in misalignment between operations and controls.
4. Why This Matters
Weak BWRAs or CRAs translate into real-world vulnerabilities, including:
- Insufficient controls for higher-risk customers
- Missed sanctions, adverse media or behavioural signals
- Misalignment between growth plans and risk appetite
- Heightened likelihood of regulatory intervention or enforcement
The FCA has signalled increased scrutiny in this area. Firms should expect follow-up reviews, supervisory questions and potential enforcement where gaps persist.
How Neotas Helps Firms Strengthen Their Risk Assessment Framework
Neotas provides the depth of intelligence, governance clarity and evidential strength that modern FCA-aligned risk assessments require.
Neotas supports firms with:
👉 Bespoke BWRA & CRA frameworks
👉 OSINT-driven Enhanced Due Diligence
👉 Dynamic, trigger-based monitoring
👉 Stronger governance, MI & documentation
If your risk assessments need to move from “paper compliance” to real operational effectiveness, we can help you get there.
The FCA’s latest review underscores a simple truth: financial-crime risk assessments are not regulatory housekeeping – they are the cornerstone of an effective AML framework. Firms that fail to embed evidence-driven, dynamically updated assessments expose themselves to regulatory, operational and reputational risk.
Neotas enables firms to move beyond box-ticking and adopt a modern, intelligence-led approach that meets FCA expectations, anticipates emerging threats and builds long-term resilience.
To strengthen your financial-crime risk framework, operationalise FCA expectations and enhance due-diligence intelligence, connect with Neotas for tailored advisory, BWRA/CRA development and enhanced due-diligence support.
Email: [email protected]
Follow Neotas on LinkedIn for ongoing regulatory insights and risk intelligence updates.











