The firms reporting the most risk to the FCA report the widest control gaps.
The FCA asked 242 asset management firms about financial crime controls. Private-markets firms report the most risk and several of the widest control gaps.
The Financial Conduct Authority asked 242 asset management and alternatives firms about their financial crime controls and published the answers on 22 July 2026. Private-markets firms reported more politically exposed customers, more complex ownership and more offshore structures. A fifth of them also said their own risk assessment does not address private-markets risk.
The short version
01
The Financial Conduct Authority engaged 242 asset management and alternatives firms during 2025/26 and published the findings on 22 July 2026. 87% answered the questionnaire.
02
32% of private-markets firms reported politically exposed persons among their customers. Outside private markets the figure was 9%.
03
29% reported no formal transaction monitoring process. 18% had no formal customer risk assessment method. 10% did not verify source of wealth for high-risk customers.
04
40% outsource customer due diligence checks. Only 36% of those keep full oversight of what the third party does.
05
Over half of money laundering reporting officers are part-time or share the role, including at more than a quarter of firms running over £10bn.
06
Every percentage is a share of the 242 firms surveyed, self-reported. The FCA named no firms and announced no enforcement.
Private-markets firms report a customer base built from the things AML rules exist for
In findings published on 22 July 2026, the Financial Conduct Authority (FCA) reported that 32% of firms active in private markets reported politically exposed persons among their customers, against 9% of firms outside private markets. A politically exposed person, or PEP, is someone holding a prominent public position, whose accounts carry a higher bribery and corruption risk.
Private markets means investing in assets that are not publicly traded: private equity, private credit, real estate, infrastructure. The money is locked up for years, the assets are hard to value, and the ownership behind an investor is often several layers deep.
That last point is the one the FCA quantified. Around a fifth of firms active in private markets reported that over 30% of their customers use complex ownership structures. Among firms outside private markets, 85% reported no such customers at all. Half of all firms said more than 60% of their customers are domiciled overseas.
None of that is wrongdoing. It is a description of a business model that produces exactly the conditions anti-money laundering rules were written to address: opacity about who ultimately benefits, distance from the jurisdiction supervising the firm, and customers whose position makes them worth checking. It is the same question supervisors keep arriving at in sectors with very little else in common. The one the review then asks is whether the controls match.
Nearly three in ten firms told the FCA they run no formal transaction monitoring
Of the 242 firms the FCA engaged during 2025/26, 29% reported having no formal transaction monitoring process, meaning no systematic way of watching customer activity for patterns that look wrong. The FCA also found firms relying on manual review with, in its words, "no documented or defined triggers for identifying suspicious activity".
Transaction monitoring is the control that catches what onboarding missed. A customer verified correctly at the start can still behave in ways that do not fit the profile, and monitoring is how a firm notices. Running none of it formally means the picture of a customer is fixed at the moment they joined.
Controls firms reported not having — Source: FCA, 22 July 2026 · share of 242 firms surveyed
| Control | Share of firms |
|---|---|
| No formal transaction monitoring | 29% |
| No formal risk method for customers | 21% |
| No customer risk assessment method | 18% |
| No formal quality assurance process | 18% |
| No source of wealth check on high-risk customers | 10% |
| No repeat sanctions, PEP or adverse media screening | 7% |
Read the denominator
Two things about these numbers before anyone quotes them. The FCA states plainly that "all percentages in this publication are calculated from the sample of 242 firms we engaged with". They are not sector-wide rates.
They are also self-reported. Firms described their own controls on a questionnaire. A figure like 29% is therefore best read as a floor: it counts the firms willing to write down that they have no formal process, which is unlikely to exceed the number that actually do not.
The 21% above covers firms that had either not completed a business-wide risk assessment or had one the FCA judged incomplete. That assessment is the document from which every other control is supposed to follow, which is the same logic EU law applies when it makes review frequency depend on risk.
Forty per cent outsource the checks and most cannot see what the third party did
Around 40% of the 242 firms in the FCA's 2025/26 review said they outsource customer due diligence and enhanced due diligence, generally to compliance consultants and fund administrators. Only 36% of those firms maintained full oversight of the third party's anti-money laundering onboarding. The FCA reported that some "couldn't explain CDD/EDD processes".
Customer due diligence, usually shortened to CDD, is the set of checks a firm runs to establish who a customer is and what to expect from them. Enhanced due diligence, or EDD, is the deeper version applied to higher-risk customers.
Outsourcing either is permitted. The obligation is not transferable, which is why the oversight figure matters more than the outsourcing figure. A firm that cannot describe the checks carried out in its name has not delegated the work so much as lost sight of it.
One finding sits directly on top of the private-markets risk profile. The FCA reported that "a small number of firms active in private markets had no formal UBO verification process for multi-layered or offshore structures". The ultimate beneficial owner, or UBO, is the real person who ultimately owns or controls a customer. Those are precisely the structures the same firms reported holding most of.
Over half of money laundering reporting officers do the job part-time
More than half the firms in the FCA's 2025/26 sample reported that their money laundering reporting officer works part-time or shares the role with other responsibilities. The FCA noted this includes "more than a quarter of larger firms, with over £10bn in assets under management". The money laundering reporting officer is the person legally accountable for a firm's anti-money laundering programme.
Two further figures describe the same picture from different angles. Half the sample reported no investment in anti-money laundering system remediation in the previous 24 months. Only just over a third discuss financial crime risk regularly at governance forums, while 36% discuss it annually or less.
Set against the risk profile in section one, the review documents a sector where the firms holding the most complex customers are frequently running the function on shared time and unchanged systems. The FCA does not draw a causal link between the two, and neither does this piece. It is what the same questionnaire reported.
The review is not uniformly critical. 88% of firms tracked and used management information on financial crime risk, covering sanctions, PEP and adverse media alerts. 84% reviewed or audited their own suspicious activity reports for quality, which is the discipline that keeps a reporting regime useful rather than merely busy. Anyone who has worked through what a suspicious matter report actually has to contain will recognise why that check matters.
What this publication is, and is not
A findings paper, not an enforcement action
The FCA published examples of good and poor practice. It did not name firms, announce enforcement cases, set remediation deadlines or state expected penalties. It assessed controls against the Money Laundering Regulations 2017, specifically Regulations 18, 18A, 28, 33 and 35, alongside its own Financial Crime Guide and the SYSC Handbook. Firms comparing themselves to it are reading a supervisory benchmark rather than a rule change.
Key takeaways
- The risk and the gaps sit in the same firms. Private-markets firms reported three and a half times the PEP exposure of other firms, more complex ownership and more offshore customers. A fifth said their own risk assessment does not address private-markets risk.
- 29% is a floor, not a rate. Every percentage is a share of the 242 firms surveyed, self-reported. It counts firms willing to record that they have no formal process.
- Outsourcing did not transfer the obligation. 40% outsource due diligence; only 36% of those keep full oversight. Some could not explain the processes carried out in their name.
- The resourcing picture is part of the finding. Over half of money laundering reporting officers are part-time or share the role, and half the sample has not invested in AML systems for two years.
- No firms were named. This is a good and poor practice publication. No enforcement, no deadlines, no penalties. It is a benchmark to compare against.
Using Didit for the gaps the FCA counted
Three of the gaps in this review are checks rather than judgements. Ongoing AML Monitoring addresses the 7% reporting no repeat screening for sanctions, politically exposed persons and adverse media, by rescreening an existing customer base rather than only at onboarding. Transaction Monitoring is the formal process 29% said they do not run. Business Verification (KYB) and Person AML cover the ownership chain behind a corporate investor, which is where the private-markets UBO finding sits.
Published rates are $0.07 per user per year for Ongoing AML Monitoring, $0.02 per transaction for Transaction Monitoring, $2.00 per Business Verification (KYB) bundle and $0.20 for Company AML Screening or Person AML. Current module prices are listed on the pricing page.
Most of what the FCA reviewed is not a product at all. The business-wide risk assessment, the customer risk methodology, the governance forum that discusses financial crime, the quality assurance process and the decision to give the money laundering reporting officer enough time are all internal. No vendor supplies any of them. A firm that bought every check in this paragraph would still hold every finding in section four.
Common questions
What did the FCA review and when?
The Financial Conduct Authority engaged 242 asset management and alternatives firms during 2025/26 about their financial crime controls, and published its findings on 22 July 2026. It used a questionnaire, which 87% of firms answered, followed by interviews with a selected subgroup.
Do the percentages describe the whole sector?
No. The FCA states that all percentages in the publication are calculated from the sample of 242 firms it engaged with. The figures are also self-reported by firms about their own controls, so a figure such as 29% with no formal transaction monitoring is a floor rather than a measured population rate.
What did the FCA find specifically about private markets?
32% of private-markets firms reported politically exposed persons among their customers, against 9% of firms outside private markets. Around a fifth said more than 30% of their customers use complex ownership structures, while 85% of non-private-markets firms reported none at all. 18% said their business-wide risk assessment did not specifically address private-markets risks.
Has the FCA named firms or opened enforcement?
No. The publication identifies good and poor practice and does not name firms, announce enforcement cases, set remediation deadlines or state expected penalties.
Related reading
- EU law lets five years pass before you recheck who owns a customer — What the EU requires on review frequency, and why it depends on risk.
- The new AUSTRAC SMR form (2026) — What a suspicious matter report has to contain once monitoring surfaces something.
- AUSTRAC Tranche 2 for dealers in precious metals & stones — The same controls, in a sector meeting them for the first time.
- Regulators are asking prediction markets about identity, not trading — Another supervisor arriving at the same question about who the customer is.
Sources
- Asset management and alternative firms’ financial crime controls: our findings — Financial Conduct Authority · 22 July 2026
Who wrote this
Tuan Nguyen — Growth · Didit
Writes about identity verification, fraud and compliance at Didit. Every figure here comes from the FCA’s own publication, including its statement that the percentages describe the 242 firms surveyed rather than the sector.
Last reviewed 28 July 2026 against the sources above
Related articles
- Europe's deepfake rule is now in force, and it lands on the tool, not the fraud
- AI is now on both sides of the gambling identity check
- The stablecoin identity rule covers issuance and redemption, not what happens next
- Egypt is absorbing the cost of a KYC refresh instead of passing it to the customer
- Unico Partners with Didit to Expand Access to State-of-the-Art Identity Verification for SMEs in Brazil
- Didit vs Onfido: coverage, pricing, automation, and migration