Navigating financial crime compliance in a changing landscape

The FCA is set to become the single AML/CTF supervisor for professional services, and its 2025/26 work programme signals a move to continuous, data-led supervision of financial crime, meaning firms need to reassess their due diligence frameworks now.

What happened?

Following a consultation by HM Treasury, the government has confirmed that the FCA will become the single anti-money laundering and counter-terrorist financing (AML/CTF) supervisor for professional services, taking on oversight of law firms, accountancy firms and trust company service providers. This replaces the current fragmented system of professional body and public authority supervisors.

Alongside this, the FCA’s Annual Work Programme 2025/26 names financial crime as one of its four strategic priorities, with the regulator moving from periodic checks to continuous, intelligence-driven oversight and a new data-led detection capability.

Why does it matter?

Full implementation of the new supervisory arrangements requires primary legislation and a phased transition, but firms cannot afford to wait to ensure their controls are in order. The pressing question for firms is not what the FCA will do, but whether their customer due diligence (CDD) and enhanced due diligence (EDD) frameworks can withstand closer regulatory scrutiny.

Some firms may find that their controls have evolved reactively, with layered processes, manual workarounds or inconsistent escalation thresholds that no longer reflect the pace of financial crime risk in a real-time digital environment.

Who is affected?

Firms across professional and financial services, including those newly brought within FCA AML/CTF supervision, and compliance, risk and financial crime teams responsible for CDD and EDD frameworks.

Key risks

  • Risk assessments that are procedural rather than genuinely risk-based.
  • An inability to evidence how and why due diligence decisions were made.
  • Inconsistent application of enhanced due diligence between similar high-risk cases.
  • Automated systems influencing risk ratings without a clear audit trail or human oversight.

Actions to take

  1. Revisit risk segmentation so that triggers for escalation to enhanced due diligence are clearly defined and consistently applied.
  2. Map decision journeys end-to-end so that each judgment has an evidential trail that can be produced on request.
  3. Clarify escalation triggers, strengthen documentation standards and embed quality assurance that tests whether checks were completed and applied effectively.
  4. Review management information so it gives a clear view of volumes, risk segmentation, escalations, turnaround times and quality assurance outcomes.

Wider implications

As the FCA moves towards data-led, intelligence-driven supervision, firms will increasingly be expected to demonstrate how customer risk ratings are informed by live data, rather than fixed at onboarding and revisited only on a set timetable.

Where technology, such as workflow tools, screening platforms and AI-supported reviews, is used to support CDD and EDD, it must strengthen governance rather than dilute it, with clear audit trails explaining how automated outputs influence decisions.

Recommendations

Firms should treat this as an opportunity to step back and ask whether their risk assessments are genuinely risk-based, whether decisions are evidenced, and whether the framework can scale under regulatory pressure without compromising quality.

TCC and Momenta can provide specialist interim leaders, including experienced Chief Risk Officers and Chief Compliance Officers, alongside skilled resource and managed services, to help firms run CDD and EDD programmes consistently and in line with regulatory expectations.

Supporting sources

  1. Navigating financial crime compliance in a changing landscape

Frequently asked questions

What change is happening to AML/CTF supervision in the UK?

The FCA will become the single AML/CTF supervisor for professional services, taking on oversight of law firms, accountancy firms and trust company service providers, replacing the current fragmented system.

When will the new supervisory arrangements take effect?

Full implementation requires primary legislation and a phased transition, though firms are advised not to wait before reviewing their controls.

What is the difference between CDD and EDD?

Customer due diligence (CDD) is the standard process for establishing and monitoring customer risk, while enhanced due diligence (EDD) applies additional, more detailed checks where a customer presents a higher risk.

How can firms demonstrate their financial crime controls work in practice?

Firms should maintain management information covering volumes, risk segmentation, escalations, turnaround times and quality assurance outcomes, aligned with risk appetite and board oversight.

Ready to strengthen your compliance?

Speak to our experts about your regulatory challenges.