On 23 June 2026 the FCA published the findings of a multi-firm review into financial crime systems and controls across the UK insurance market. It covered retail, wholesale and life insurers, scored them against ten control groups, and concluded that the controls were, on the whole, mostly effective. The detail tells a more useful story: almost every weakness the regulator found was a weakness of evidence rather than of design.
Firms were doing sensible things and failing to write down why. The FCA rarely disagreed with the control a firm had chosen. It marked firms down because nobody could show the reasoning behind it.
That distinction changes what you need to do about it. If your controls were badly designed, you would need a remediation programme. If your controls are sound but undocumented, you need a record. This article works through what the review says, area by area, and what a firm needs to hold to answer it.
1. What the review covered, and how firms were scored
The FCA assessed a selection of large insurance firms spanning retail, wholesale and life business, measuring them against the Money Laundering Regulations 2017, the FCA Financial Crime Guide and SYSC, and drawing also on JMLSG and FATF guidance.
Ten control groups were rated: governance and oversight, risk assessment, regulatory reporting and issue management, people and knowledge, third party risk, client due diligence, sanctions, AML transaction monitoring, fraud, and anti-bribery and corruption.
Three ratings were used. Strong meant well-designed controls which fully address risks, alongside clear structures and ownership. Moderate meant controls addressed the risk but had some gaps, partial or outdated documents, or reliance on manual processes. Weak meant controls did not appear to be adequately designed to mitigate the risks in question.
Note what moves a firm from strong to moderate in the FCA’s own wording: partial or outdated documents. Not a missing control. A missing document.
2. Transaction monitoring: choosing not to do it can be right, failing to explain it cannot
What the FCA found. Transaction monitoring was less developed at firms not directly regulated for AML purposes, and most retail and wholesale firms carried out no formal transaction monitoring at all. In life insurance it existed but needed improvement.
What the FCA expects. This is the finding most likely to be misread. The regulator did not say every insurer must monitor transactions. It said firms should consider the risks and benefits of their approach and document their rationale, and that any reduction or simplification in controls should be risk-based. An absence of monitoring can be defensible. An unexplained absence is not.
What good looks like. A written rationale that ties the decision to the business model and to the risk assessment. If you do not monitor transactions because premiums arrive by direct debit from UK bank accounts held in the policyholder’s own name, say so, and say which risk assessment finding supports it. Name the compensating controls. Date it, give it an owner, and revisit it when the business changes.
How Fenchurch One helps. The financial crime attestation asks the ongoing monitoring questions directly, and every answer carries a comment field, a supporting-documents panel and a place to record the reasoning rather than just the outcome. The record itself is dated, owned, RAG-rated and put on a repeat schedule, so the rationale is not a one-off memo that ages quietly in a shared drive. When a supervisor asks why you monitor the way you do, the answer is a record with a date on it.
3. Client due diligence: marked weak for what was not written down
What the FCA found. Client due diligence was weak across most large retail firms. The reason given was not that due diligence was absent. It was that firms had not fully documented their approach.
What good looks like. Where you apply simplified due diligence, the FCA wants the risk basis for that decision recorded and the approach proportionate and documented. Where enhanced due diligence is triggered, the trigger, the additional checks and the outcome all need to sit on the file. The complaint in retail was documentation, so the fix is a record rather than a programme.
How Fenchurch One helps. The attestation carries a full customer due diligence and high-risk customers section covering standard, simplified and enhanced treatment, the triggers that move a customer between them, and how politically exposed persons are identified and reviewed. Alongside it, a politically exposed persons register can be added to your board from the forms catalogue, so the population and its review dates are held as data rather than described in prose.
4. Risk assessment: group level is not business unit level
What the FCA found. Risk assessment was rated weak in retail insurance, and the stated reason was limitations in the evidence provided specific to individual business units. In life insurance, by contrast, risk assessment was one of the strengths.
What good looks like. A single enterprise-wide assessment that treats the whole firm as one undifferentiated risk profile will not satisfy this. The FCA wants the assessment to reach the level at which the business actually operates: separate books, separate distribution channels, separate territories, each with evidence behind the rating rather than an assertion.
How Fenchurch One helps. The attestation’s business and risk profile section records when the enterprise-wide risk assessment was last completed, whether it is still inside twelve months, the overall money laundering and terrorist financing risk rating it produced, and any new or emerging risks identified in the period. It also asks, item by item, which higher-risk activities the firm is actually exposed to, from cross-border payments and cash-intensive services to non-face-to-face onboarding and higher-risk jurisdictions. Firms running more than one book or entity hold a separate board for each, with its own records and its own access, so business unit level is the default rather than an exercise in splitting a group document.
5. Policies and procedures: the distance between the group framework and the desk
What the FCA found. Comprehensive group-level policies existed, but were often not specific enough at business unit or jurisdictional level. In retail, policies were described as less specific to individual firms or business units.
What good looks like. The FCA is explicit: supplement the overarching framework with documented procedures for specific business units and jurisdictions. A group anti-money laundering policy is the starting point, not the answer.
How Fenchurch One helps. The attestation’s policies, procedures and systems section asks when the policies were last reviewed, whether that review is on schedule, whether they are adequate and effective, and whether they have been updated for the specific regulatory changes that have landed recently, including the 2024 amendments to the Money Laundering Regulations on domestic politically exposed persons and the FCA’s subsequent guidance on how they should be treated. Behind it sits the policy template library, whose financial crime set includes anti-money laundering, sanctions, anti-bribery and corruption, anti-fraud, due diligence, market abuse, gifts and entertainment and tax evasion. Policies live per board, so the local procedure sits with the entity it governs.
6. Roles and responsibilities: why the FCA raised RACI
What the FCA found. Many firms lacked a formal RACI matrix clarifying responsibilities, particularly where group policies were operated by UK entities and where third parties performed parts of the control.
What good looks like. The FCA is careful here, and so should you be. Its wording is that a RACI matrix is not mandatory, but firms should consider using one. The underlying obligation is the SYSC requirement for clear apportionment, and for firms in scope, the senior managers regime. What the review is really asking is whether anyone can say, for a given control, who performs it, who answers for it, and who has to be told when it fails.
How Fenchurch One helps. The attestation opens on exactly this ground. It records the MLRO by name, the date of approval for SMF17 where applicable, whether there is a trained deputy, whether the MLRO has unfettered access to the firm’s records, how many people are dedicated to the function, whether resourcing concerns have been escalated, and the board member or senior manager holding overall responsibility. The People module holds statements of responsibility against the FCA’s prescribed responsibilities, and every record on the platform carries an owner and, separately, an approver. If you want the classic four-column matrix as well, it is a document you author and hold in the library, where it is versioned and given a review date like any other.
7. The obligations register: the finding most firms will not have covered
What the FCA found. Most firms did not maintain an obligations register mapping their legal and regulatory requirements to their internal controls. This is the quietest finding in the review and the one that will catch the most firms.
What good looks like. The FCA describes best practice as clearly articulating the firm’s legal and regulatory obligations and mapping them to specific controls. A supervisor should be able to start from a regulation and arrive at the control that discharges it, its owner and its current status.
How Fenchurch One helps. The mapping is built into how the attestation is written rather than kept in a separate spreadsheet. Each section opens by naming the obligation it exists to discharge, from Regulation 18 on the enterprise-wide risk assessment and SYSC 3.2.6R on systems and controls to the Proceeds of Crime Act reporting duties, Regulation 24 on training and SYSC 6.3.3G on assessing control effectiveness. On the Pro plan, the FCA returns tracker holds the financial crime return and the MLRO annual report as dated obligations with a named responsibility and a regulatory source against each.
8. Third parties: the liability you keep, the oversight you tier
What the FCA found. Firms understood that outsourcing does not transfer responsibility. But only one firm in the review operated enhanced, risk-based levels of oversight for higher-risk controls performed by third parties.
What good looks like. Categorise third-party relationships by risk, so more scrutiny goes where more of the control sits outside the firm. Then produce and review information on how those third parties are actually performing. The FCA frames the proportionality directly: oversight should match the risks and materiality of the outsourced activities.
How Fenchurch One helps. The general FCA compliance attestation carries the outsourcing statements, covering the outsourcing register for critical arrangements, written agreements, due diligence, ongoing monitoring, tested exit plans, supplier audit rights and concentration risk reported to senior management, each with a mandatory exceptions box if the statement is not true and a panel to attach the register itself. An outsourcing policy template sits in the library, and firms on the Pro plan can build a supplier register with their own risk-tier and review-date columns using the form builder, after which it reports on the dashboard like any other register.
9. Monitoring and testing: coordinate, or duplicate and still have gaps
What the FCA found. Some firms lacked structured, risk-based monitoring and testing plans, and the review asks firms to coordinate monitoring and testing so as to avoid duplication or gaps.
What good looks like. A plan that says what will be tested, how often, by whom, and why that frequency. Risk-based means the frequency follows the risk assessment rather than habit. Coordinated means compliance monitoring, second-line assurance and audit are not all testing sanctions screening in the same quarter while nobody tests the reporting process at all.
How Fenchurch One helps. The attestation has a dedicated monitoring, audits and control effectiveness section anchored to SYSC 6.3.3G, and every record on the platform carries a due date and a repeat schedule, so the testing cycle is a calendar rather than an intention. On the Pro plan the compliance monitoring plan library adds a financial crime series covering the framework and MLRO appointment, customer due diligence, enhanced due diligence and politically exposed persons, ongoing and transaction monitoring, sanctions screening, reporting, the MLRO annual report, anti-bribery and corruption, fraud prevention and market abuse, each as its own chapter to schedule and evidence.
10. Sector by sector
Retail. Moderate overall. Sanctions, fraud risk management and anti-bribery and corruption were strengths, consistent with lower inherent money laundering risk. Risk assessment and client due diligence were both weak, in each case for reasons of evidence and documentation rather than absence.
Wholesale. Moderate overall. People and knowledge, anti-bribery and corruption and sanctions were the strengths. Fraud management was generally weaker, with limitations in management information and detail, and transaction monitoring was not consistently embedded.
Life. The strongest of the three, rated moderate to good. Risk assessment, client due diligence, people and knowledge, third party risk and sanctions were generally strong, and some firms showed strong design in fraud risk management including automated fraud surveillance. Transaction monitoring still needed improvement.
The pattern worth noticing is that fraud is a strength in retail and a weakness in wholesale, while transaction monitoring is a weakness almost everywhere. If you dismiss this review because your sector scored well overall, you will miss the control where your own sector was marked down.
11. If you were not one of the firms reviewed
The review assessed a selection of larger firms, and the FCA has said it will engage individually with those it looked at. Everyone else is expected to consider the findings, work out how they relate to their own business, and make any improvements needed.
For an insurer, intermediary or broker outside that group, the practical translation is narrower than it looks. You are not being asked to build what a global insurer builds. You are being asked to write down why your controls are calibrated the way they are, to hold the documents that show it, and to produce them without a fire drill. The FCA’s fourth stated expectation is explicitly about proportionality, and proportionality is a defence only when it has been reasoned and recorded.
12. Where to start
If you want a short list from this review, it is this. Write the rationale for your transaction monitoring position, whatever that position is. Document your due diligence approach, including where it is simplified and why. Push the risk assessment down to the level the business actually operates at. Supplement the group policy with local procedure. Map your obligations to your controls. Tier your third parties by risk and keep information on how the ones that matter are performing. Then set a risk-based testing plan and make sure the same control is not being tested twice while another is not tested at all.
None of that is a control redesign. All of it is evidence, and evidence is the thing this review kept finding missing.
Fenchurch One holds that evidence in one place. The financial crime attestation walks through the MLRO function, the risk profile, policies and systems, reporting, customer due diligence, sanctions, bribery and corruption, training, monitoring and control effectiveness, breaches and regulatory matters, and a forward look, explaining as it goes why each question is asked and which rule sits behind it. Answer it once and the record is dated, owned, rated and scheduled to come round again.
See where your firm stands
Fenchurch One puts everything the FCA expects a firm to evidence on one board, from £150 a month, with a 14-day free trial and no minimum term.
Get started