Regulatory Warning on KYC Deficiencies
The Financial Conduct Authority (FCA) issued a warning in August 2026, highlighting ongoing deficiencies in the financial crime controls of U.K. financial services firms. Despite assurances that Customer Due Diligence (CDD) processes have been improved, the FCA found a disconnect between reported practices and actual system performance. This isn't an isolated issue but a widespread problem identified through the FCA's supervisory activities.
Persistent Issues Over Time
The FCA hasn't provided a detailed timeline, but the pattern is evident:
- Pre-2026: Firms claimed to implement enhanced KYC controls.
- 2026 supervisory cycle: FCA reviews revealed persistent gaps despite these claims.
- August 2026: A public warning was issued about ongoing deficiencies.
The problem is ongoing, with firms claiming improvements while underlying weaknesses remain unaddressed.
Key Areas of Concern
The FCA's findings indicate failures across the CDD lifecycle. Common issues include:
Beneficial Owner Identification: Firms often fail to identify the individuals who ultimately own or control a customer. They accept corporate structures without verifying the individuals behind them. Even when beneficial ownership information is collected, it's not verified against independent sources.
Customer Risk Rating: Risk models rely on checkbox criteria rather than genuine assessments. Customers might appear low risk while exhibiting red flags that models miss. Analysts override risk ratings without proper documentation, leading to inconsistent customer treatment.
Ongoing Due Diligence: CDD is treated as a one-time event rather than a continuous obligation. Firms set periodic review cycles but don't monitor for trigger events that require immediate action. Reviews are often superficial, focusing on outdated documents rather than reassessing relationships.
Source of Wealth and Funds: Documentation is generic and unverified. Firms accept vague statements like "business profits" without evidence. For higher-risk customers, firms don't investigate the economic reality behind stated sources.
Record Keeping: Customer files are incomplete or scattered across systems. When the FCA requests the basis of a risk decision, firms can't provide it due to missing or inaccessible documentation.
Regulatory Standards
The FCA's requirements are based on the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, which implement FATF standards in U.K. law.
Regulation 28 requires CDD measures when establishing a business relationship, conducting transactions of €15,000 or more, suspecting money laundering, or doubting previous identification data.
Regulation 27 includes:
- Identifying and verifying customer identity using reliable sources.
- Identifying beneficial owners and verifying their identity.
- Obtaining information on the business relationship's purpose and nature.
- Conducting ongoing monitoring.
Regulation 33 requires enhanced due diligence for higher-risk situations, examining complex transactions, increasing monitoring, and understanding ownership structures.
The FCA's Handbook, particularly SYSC 6.3, mandates systems and controls to counter financial crime risks, including appropriate CDD procedures.
Action Steps for Your Team
The FCA's warning requires immediate action. Here's how your team can respond:
Audit Beneficial Ownership Processes: Review a sample of 50 corporate customers. Verify identification of individuals owning or controlling more than 25%. Ensure verification against independent sources. Identify process gaps and address root causes.
Evaluate Risk Models: Review low-risk customers for red flags missed by models. Check for unusual transactions, mismatched business activities, and jurisdictional exposure. Recalibrate models as needed and document changes.
Clarify Ongoing Monitoring: Define event-driven triggers and periodic reviews. Develop a checklist for reassessing customer relationships. Ensure reviews are thorough and not completed in under 10 minutes.
Standardize Wealth Documentation: Create a matrix for acceptable evidence. Train your team to reject vague statements. Elevate risk ratings when documentation is inadequate.
Consolidate Customer Files: Work with IT to create a single source for CDD documentation. Ensure all decisions and assessments are accessible in one place.
Review Risk Rating Overrides: Examine the last 20 overrides for approval and justification. Identify patterns and tighten override policies. Increase senior review for consistency.
The FCA's message is clear: intentions and policies aren't enough. Your controls must work in practice, and you need evidence to prove it. If you can't demonstrate effective CDD, the gaps in your program are serious, regardless of board reports.



