FaSQUAL: The BSIA-led Vetting Passport for the UK Security Industry Powered by Neotas Read More →
Generate AI-Powered Audit-Ready Due Diligence Reports instantly. Learn More →
FCA Findings on Risk Assessment Processes

FCA Findings on Risk Assessment Processes: What Firms Need to Know – and How Neotas Can Help

 

Introduction
In November 2025, the Financial Conduct Authority (FCA) released its latest review into how UK firms manage financial-crime risks through their Business-Wide Risk Assessments (BWRA) and Customer Risk Assessments (CRA). The findings reveal a mixed landscape: some firms are demonstrating genuinely robust practice, while many others still fall short of regulatory expectations.

For compliance teams, MLROs and senior managers, the message is unambiguous: risk assessments must be evidence-based, actively governed, and embedded into real decision-making – not static documents prepared for audit purposes alone.

1. What the FCA Reviewed

The FCA assessed risk assessment frameworks across:

  • Banks and building societies
  • Payment services providers and e-money institutions
  • Platforms and fintechs
  • Wealth managers
  • Custody and fund service providers

The review focused on how effectively firms identify, understand and mitigate money-laundering, sanctions, terrorist-financing and proliferation-financing risks, and whether those assessments meaningfully inform operational controls.

2. What Firms Are Doing Well

âś“ Tailored and data-driven assessments

Leading firms balanced qualitative judgement with quantitative indicators, clearly documenting inherent risk, control effectiveness and residual risk. Their assessments reflected the realities of their business models, customer demographics and geographic exposure.

âś“ Regular, meaningful review cycles

These weren’t superficial annual updates. Strong firms performed full annual reassessments, supplemented by interim reviews triggered by business changes, product launches or shifting threat landscapes.

âś“ Integration with strategy and governance

In high-performing firms, risk assessments influenced product decisions, market entry, resource planning and staffing. Senior leaders not only reviewed assessments but actively challenged assumptions and conclusions.

âś“ Clear ownership and documentation

Decisions were well recorded, mitigation actions tracked and responsibilities assigned. Financial-crime risk sat firmly within broader governance structures.

3. Where the FCA Found Weaknesses

Generic or poorly evidenced BWRAs

Many firms relied on boilerplate risk descriptions with limited relevance to their actual customer mix, products or jurisdictions. Quantitative evidence was often missing or incomplete.

Weak linkage between risks and controls

Some assessments identified risks but failed to explain existing controls, their effectiveness or how risk outcomes influenced onboarding, monitoring or resource deployment.

Poor governance and limited senior oversight

The FCA frequently observed weak documentation of approvals, challenge, or ongoing oversight. In several cases, firms could not demonstrate how key decisions were made.

Outdated frameworks unable to keep pace with growth

As firms expanded products or entered new markets, many did not re-evaluate their risk profiles, resulting in misalignment between operations and controls.

4. Why This Matters

Weak BWRAs or CRAs translate into real-world vulnerabilities, including:

  • Insufficient controls for higher-risk customers
  • Missed sanctions, adverse media or behavioural signals
  • Misalignment between growth plans and risk appetite
  • Heightened likelihood of regulatory intervention or enforcement

The FCA has signalled increased scrutiny in this area. Firms should expect follow-up reviews, supervisory questions and potential enforcement where gaps persist.

How Neotas Helps Firms Strengthen Their Risk Assessment Framework

Neotas provides the depth of intelligence, governance clarity and evidential strength that modern FCA-aligned risk assessments require.

Neotas supports firms with:

👉 Bespoke BWRA & CRA frameworks
👉 OSINT-driven Enhanced Due Diligence
👉 Dynamic, trigger-based monitoring
👉 Stronger governance, MI & documentation

If your risk assessments need to move from “paper compliance” to real operational effectiveness, we can help you get there.

The FCA’s latest review underscores a simple truth: financial-crime risk assessments are not regulatory housekeeping – they are the cornerstone of an effective AML framework. Firms that fail to embed evidence-driven, dynamically updated assessments expose themselves to regulatory, operational and reputational risk.

Neotas enables firms to move beyond box-ticking and adopt a modern, intelligence-led approach that meets FCA expectations, anticipates emerging threats and builds long-term resilience.

To strengthen your financial-crime risk framework, operationalise FCA expectations and enhance due-diligence intelligence, connect with Neotas for tailored advisory, BWRA/CRA development and enhanced due-diligence support.

Email: [email protected]
Follow Neotas on LinkedIn for ongoing regulatory insights and risk intelligence updates.

 

Last updated on August 10, 2026

Share:

Picture of Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence covers 600Bn+ Archived web pages, 1.8Bn+ court records, 198M+ Corporate records, Global Social Media platforms, and more than 40,000 Media sources from over 100 countries to help you screen & manage risks.

A detailed guide to TPRM and a downloadable checklist to implement the TPRM Framework in 2025

Book a Demo

Explore Neotas Enhanced Due Diligence