Rethinking financial crime controls in a system-wide risk environment

The FCA is raising expectations for financial crime controls, focusing on whether firms can evidence that they reduce real-world risk as fraud, money laundering, sanctions evasion and cyber-enabled crime become more interconnected.

Fin-Crime-TCC

What happened?

The FCA’s recent speech on working together against financial crime calls for greater collaboration between firms, regulators and law enforcement. Taken in context, it points to a broader shift: financial crime can no longer be understood as something contained within a single firm, but as a system-level issue shaped by how risks move across firms, sectors and jurisdictions.

The regulator highlights the increasingly organised, technologically enabled and cross-border nature of financial crime, where fraud, money laundering, sanctions evasion and cyber-enabled activity often form part of the same chain of events.

Why does it matter?

Suspicious activity rarely presents in neat categories. A fraud case may raise anti-money laundering concerns, while a cyber incident can expose weaknesses in due diligence or transaction monitoring. Many financial crime frameworks are still structured around separate risk types with different systems, processes and governance, which can create blind spots where no single view of risk exists.

The FCA is also moving beyond checking whether appropriate policies and processes are in place, to asking whether those controls actually reduce financial crime risk in practice. A framework can be technically compliant and still fall short if it does not reflect how financial crime is occurring today.

Who is affected?

The message applies across banking, wealth management, payments, lending, general insurance and motor finance, and to any firm relying on financial crime frameworks built around separate risk categories rather than a connected view of risk.

Key risks

  • Financial crime frameworks structured around separate risk types, with no single view of how risks connect.
  • Risk assessments that are static or refreshed only periodically, creating a disconnect between documented risk and reality.
  • Reliance on external intelligence and industry information-sharing that is not embedded in day-to-day monitoring and escalation decisions.
  • Controls that remain technically compliant on paper but have not been revisited in light of changing threats.

Actions to take

  1. Review financial crime risk assessments to ensure they reflect evolving threats and capture how different risk types connect.
  2. Assess whether external intelligence and information-sharing initiatives are embedded in day-to-day monitoring, escalation and risk decisions.
  3. Confirm that policies and controls remain effective against how financial crime is occurring today, not how it was previously understood.
  4. Check that staff training reflects how different types of financial crime interact in practice.

Wider implications

The FCA’s direction of travel suggests financial crime effectiveness will increasingly be judged at a system level, depending not only on what an individual firm does but on how well the wider ecosystem functions.

Firms will need to show how they decide which risks matter most and how they direct resources accordingly, rather than simply demonstrating that a broad framework exists.

Recommendations

Firms should review their financial crime risk assessments and controls now, rather than waiting for a regulatory request, and should be able to evidence how they prioritise risks and adapt frameworks as threats evolve.

Where internal teams are stretched or oversight gaps have emerged, specialist support can help stabilise and strengthen financial crime programmes through senior interim leadership, managed remediation, framework strengthening and technology-enabled workflows.

TCC’s financial crime solutions help firms stabilise, scale and improve their financial crime programmes through senior interim leadership, managed remediation, framework strengthening and techenabled workflows. Whether internal teams are stretched, backlogs are growing or oversight gaps need urgent attention, TCC can provide prevetted interim professionals, trained analysts and experienced specialists to support effective, compliant delivery. 

Supporting sources

  1. Rethinking financial crime controls in a system-wide risk environment
  2. Why financial crime needs a team sport approach

Frequently asked questions

What is the FCA's key message on financial crime?

That financial crime is a system-level issue and firms need to show that their controls reduce real-world risk, not just that a framework exists.

Why are firm-level controls no longer enough?

Because financial crime increasingly moves across firms, sectors and jurisdictions, so effectiveness depends on collaboration and information-sharing as well as internal controls.

What should firms do about static risk assessments?

Move to a more dynamic approach that reflects evolving threats and captures how different risks connect, rather than relying on periodic reviews.

Ready to strengthen your compliance?

Speak to our experts about your regulatory challenges.