← All articles

Blog · AML

Sanctions Systems and Controls: What the FCA Found in 150 Firms — and How to Prove You’ve Got It Covered

Sanctions Systems and Controls: What the FCA Found in 150 Firms — and How to Prove You’ve Got It Covered

Sanctions used to be a back-office afterthought for many firms: a name-screening tick at onboarding and little else. That era is over. Since February 2022 the FCA has assessed the sanctions systems and controls of more than 150 supervised firms, across both financial and trade sanctions, and in its report Sanctions systems and controls: our firms, our findings it set out — in unusual detail — exactly what good and poor practice look like.

The backdrop tells you why. The value of frozen UK assets rose from £24.4bn in 2023–24 to £37bn in 2024–25, the designated-persons list keeps expanding, and sectoral and trade restrictions have broadened well beyond the old military and dual-use lists. The regulator is no longer asking whether you screen. It is asking how well your screening is calibrated, how quickly you act on an alert, whether you can spot evasion that name-screening alone will never catch, and whether you can evidence all of it on demand.

This article walks the FCA’s findings area by area — what the regulator found, and how Fenchurch One’s financial-crime attestations and registers help a small or mid-sized firm meet the obligation and prove it. It is a practitioner’s read of the report, not legal advice; the rule references (SAMLA 2018, OFSI, FCA SYSC 6.3, JMLSG, FCG Ch 7) are there so you can go to the source.

One caveat up front: the FCA assessed everyone from global banks to payments firms. A handful of findings — overseas-branch MI, real-time transaction screening at bank scale — will not apply to a ten-person IFA. The principles underneath them do.

1. Governance, policies and management information

What the FCA found. Standards were mixed. Some firms ran outdated, inaccurate or inconsistent policies; some leaned on group arrangements without documented local oversight; and some sanctions policies covered only asset freezes, ignoring investment bans and sectoral restrictions. Management information was just as variable — strong on financial sanctions, thin on trade sanctions, and with overseas branches under-represented.

Good practice. A sanctions policy kept up to date that gives staff clear guidance on the business relationships and activities the firm will not undertake; role-specific training for higher-risk teams; internal and external audit used for assurance; and an MLRO who reports clearly on regulatory developments, with documented responses. MI that carries both quantitative numbers and qualitative trend commentary.

How Fenchurch One helps. Fenchurch One’s financial-crime attestations give the MLRO a governance spine: each one is mapped to the FCA Handbook and the relevant legislation, so recording your sanctions governance — the MLRO (SMF17) and deputy, reporting lines, board reporting cadence, three lines of defence — teaches the standard as it captures the evidence. Your own Sanctions Policy sits alongside them in Documents, anchored to SAMLA 2018. The dashboard is your MI: what is on track, what needs attention and what is overdue. The compliance calendar then schedules the annual Sanctions Compliance Policy review (owned by MLRO/Board) and annual sanctions training so neither drifts out of date, and the AI Compliance Report turns the raw records into board-ready narrative.

2. Risk assessment — and the part firms keep missing

What the FCA found. Some firms had no documented business-wide risk assessment at all; others were out of date or methodologically unclear. Sanctions risk was often indistinct from broad AML risk, proliferation-financing risk received minimal consideration, jurisdictional ratings leaned heavily on third-party vendor data with little internal challenge, and firms frequently failed to assess their own systems and controls. Exposures were quantified with no supporting rationale.

Good practice. A risk assessment that clearly and separately considers financial sanctions, trade sanctions and proliferation financing; detailed product and jurisdictional assessments that consider how each could be used to circumvent sanctions; and using the assessment to identify, prioritise and remediate gaps with clear ownership.

How Fenchurch One helps. Fenchurch One’s financial-crime attestations record the business-wide risk assessment across customer, product, geographic and delivery-channel risk, each answer mapped to the FCA Handbook and the relevant legislation and carrying its own evidence field — so you are documenting a structured framework, with a risk-appetite statement and a board-approval date, rather than staring at a blank page. On the monitoring side, the 74-chapter Compliance Monitoring Plan library (Pro) and the compliance calendar schedule an annual proliferation-financing screening and risk assessment, and a correspondent-banking and third-party exposure review. Proliferation financing sits in the assessment in its own right (MLR 2017 reg 18A), and a register captures your goods and trade exposure — controlled and dual-use categories, export-licence reliance and end-user checks — together with the OTSI / HMRC reporting route. The goods-level matching still sits with your specialist screening tools, but the assessment, the documentation and the reporting route now live in one place. The AI Compliance Report then reads what you have recorded and flags where the framework falls short.

3. Customer due diligence and ongoing monitoring

What the FCA found. Enhanced due diligence and sanctions-exposure questions were applied inconsistently; firms struggled to identify entities owned or controlled by designated persons, and to understand beneficial ownership in complex structures; third-party CDD was poorly overseen; EDD often went unrecorded for high-risk and PEP customers; and file documentation and audit trails were weak.

Good practice. Risk-based CDD review frequencies tied to sanctions exposure; comparing a customer’s actual activity against their stated business model during ongoing monitoring; and corroborating documentation with publicly available data.

How Fenchurch One helps. Fenchurch One’s register suite gives you the CDD and EDD records the FCA wanted to see: a Customer Risk Register carrying sanctions, jurisdiction, EDD and next-review detail, a PEP Register, an EDD case-file register (trigger, source of funds and wealth, approver, monitoring plan) and a beneficial-ownership register for holdings above 25%, including trusts. Every entry is dated, owned and evidenced, and every field carries a named-attestor audit trail — the supporting documentation the FCA found so many firms could not produce. The compliance calendar adds scheduled, owned, evidenced reviews for PEP screening and for onboarding and ongoing or triggered re-screening. And a financial-crime attestation captures each customer’s sanctions exposure — direct, indirect, trade and vulnerable-industry — rolling up to an overall sanctions-risk rating.

4. Screening: policies, lists and calibration

What the FCA found. Screening policies were sometimes unclear or inconsistently applied; firms and vendors excluded categories of sanctions-list data with no documented rationale or senior oversight; many firms had limited understanding of how lists were ingested; and poorly calibrated systems missed obfuscated, variant or non-Latin-alphabet names. Over-reliance on vendor assurances, and too little internal testing, recurred throughout.

Good practice. A clear, up-to-date screening policy that defines scope, frequency, escalation thresholds and governance; fuzzy-matching logic that stays effective even where titles or extra name elements are present; periodic validation and testing after any material list or system change; root-cause analysis after a screening mismatch; and supplementing primary lists with additional internal and external data.

How Fenchurch One helps. A financial-crime attestation documents your screening programme in one place: vendor and tool, fuzzy-match threshold, the lists screened (OFSI Consolidated, UN, EU, OFAC SDN, UK HMT), onboarding / transaction / re-screen cadence, the list-update SLA and the alert-investigation SLA — so your screening policy lives in the system, not in one person’s head, and, because each attestation is mapped to the rules, it teaches the FCA minimum as it records it: screening against OFSI, UN, EU and OFAC, real-time transaction screening with fuzzy matching, and applying list updates promptly. The 74-chapter Compliance Monitoring Plan library (Pro) and the compliance calendar then make calibration a scheduled discipline rather than a good intention — applicable-list coverage, a quarterly screening-system adequacy and coverage review, a monthly new-designations and list-update check, and a transaction-screening review, each with an owner (MLRO / IT), a next-due date and an evidence trail. The register suite adds the pieces the FCA found most firms could not evidence: a screening assurance and calibration register that records your test results — name-variant, transliteration, non-Latin and obfuscation results, and the root cause of any mismatch — a governed screening-exclusions register for anything you leave out, and a screening contingency and outage register for when the vendor goes down. The honest framing still holds: your screening engine does the matching; Fenchurch One is the policy, governance, testing-record and evidence layer around it — which, on the FCA’s findings, is precisely the layer most firms could not produce.

5. Alerts, asset freezing and licences

What the FCA found. Alert handling was one of the most common causes of reported breaches — failures to act on alerts and freeze accounts before assets moved, missed internal SLAs, weak escalation, undefined freezing timeframes, accounts left unrestricted during investigation, and licence requirements not met. Some firms did not even consider freezing obligations at offboarding.

Good practice. Documented escalation policies that are actually embedded in day-to-day practice; internal SLAs with quality assurance over alert investigations; clear, documented routes for when and how to restrict an account; and clear controls for sanctions licences, including client education and pre-notification.

How Fenchurch One helps. The register suite carries exactly these records: a sanctions hit log (match score, investigator, disposition, approver, outcome), a frozen-assets register, an OFSI licence register (conditions, expiry, reporting) and a sanctions breach and incident register that tracks OFSI 24-hour and FCA SUP 15.3 notifications through to status — every entry dated, owned and evidenced, so nothing quietly stalls “in review”. A financial-crime attestation sets the statutory clocks against your own practice — frozen-funds report within one month, breach notification within 24 hours and a detailed report within 21 days. The compliance calendar then schedules the match-review investigation, the confirmed-match freeze and OFSI reporting, and OFSI-licence compliance as owned, recurring reviews, alongside an OFSI frozen-funds cycle and a daily list-refresh so the dates never slip.

6. Detecting evasion — not just matching names

What the FCA found. Name and payment screening alone will never catch every breach. Training often lacked evasion typologies; those typologies were not reflected in firms’ risk assessments, policies or controls; and firms were reactive rather than proactive. The common tactics were familiar — transfers shortly after designation, access through ownership chains and associates, intermediaries and correspondent banks, crypto and e-money routing, and misrepresented trade documentation.

Good practice. Training that spells out red flags and evasion typologies and how to escalate them; proactively stress-testing controls against new sanctions regimes and emerging typologies; targeted investigations on high-risk customers; reviewing transaction activity before and after major sanctions events; and tailored transaction-monitoring scenarios.

How Fenchurch One helps. A financial-crime attestation covers transaction-monitoring red flags and evasion typologies — transaction-pattern and customer-behaviour indicators — mapped to the rules, so the typologies the FCA listed are captured in your controls rather than left in last year’s slide deck, and a register logs the emerging regimes you are watching, with an owner and a target date against each. The 74-chapter Compliance Monitoring Plan library (Pro) and the compliance calendar schedule the recurring new-designations and list-monitoring checks and the annual sanctions training, so the picture stays current and evidenced. The AI Compliance Report reads your live records and flags where an evasion typology is not yet reflected in your controls. The proactive investigation work is still yours to do — but the structure, the record and the evidence trail around it are built in.

7. Reporting and assessing breaches

What the FCA found. The good news first: firms are reporting faster — the average time between identifying and reporting a breach fell to 116 days in 2025. But many firms were unaware of the reporting routes for trade-sanctions breaches; escalation to senior management was often unclear in policy; and reporting to the competent authorities was sometimes missing from process documentation altogether.

Good practice. Well-documented breach-reporting procedures, and considering the necessary remedial action when you assess a suspected breach — not just filing it and moving on.

How Fenchurch One helps. The sanctions breach and incident register classifies every incident and tracks its OFSI and FCA SUP 15.3 notifications through to closure. The AI Compliance Report and Executive Summary pull together the sanctions figures your board and your REP-CRIM return need — frozen assets, OFSI notifications, potential breaches and true-positive matches — and the FCA Dry Run interrogates your programme the way a supervisor would, answering fourteen questions from your own records — “show me your sanctions screening last quarter” — and pointing to where you fall short. The compliance calendar schedules breach self-reporting and voluntary disclosure as a standing review, and the downloadable FCA proof pack gives an auditor or the regulator a dated, referenced export of it all. Each breach record carries its reporting route — OFSI for financial sanctions, OTSI and HMRC for trade sanctions — so the right authority is named from the start.

8. The real difference: having controls vs proving them on a schedule

Read the FCA’s report end to end and one demand runs through every section: evidence, on a schedule. “Show me your impact tolerances.” “When did you last test your screening?” “Show me the records.” A control you cannot evidence on the day they ask is, to a supervisor, a control you do not have. This is exactly where most of the assessed firms came unstuck — not on intent, but on proof.

The 74-chapter Compliance Monitoring Plan library (Pro) is built for that demand. It turns the whole sanctions programme into a planned, dated, owned and evidenced schedule — policy review, applicable-list coverage, screening-system adequacy, real-time list updates, onboarding and ongoing screening, match investigation, freeze and OFSI reporting, licences, breach self-reporting, correspondent-banking exposure, proliferation financing and training — each chapter carrying an owner, a frequency, a last-review and next-due date, an evidence trail and a findings log. The compliance calendar surfaces every one of those tasks as it falls due, the dashboard shows what is on track, what needs attention and what is overdue, and the AI Compliance Report drafts the board narrative from your live records. When the FCA asks to see your sanctions monitoring, the answer is a screen, not a scramble.

9. What the FCA expects next

The report closes by asking every firm — not just the 150 it assessed — to review its systems for comprehensiveness and robustness against both financial and trade sanctions, and to be able to identify, investigate, mitigate and report suspicious sanctions activity in good time.

The takeaway is not “go and buy a bank-grade screening engine”. It is far more achievable than that: write the policy down, assess your real exposure, calibrate and test what you screen, act on alerts against a clock, keep the evidence, and review the whole thing on a schedule. That is precisely the shape Fenchurch One gives a one- or two-person compliance team — the structure of a large firm’s sanctions function, without the large firm’s headcount. The day the FCA asks becomes a five-minute job instead of a five-day scramble. That is the whole idea.

See where your firm stands

Fenchurch One puts everything the FCA expects a firm to evidence on one board, from £150 a month, with a 14-day free trial and no minimum term.

Get started

The Fenchurch Newsletter

One email a month: straightforward FCA guidance, product updates and the dates worth knowing. No noise.

You’re subscribed — check your inbox!