UBO Verification in Private Markets: What the FCA Expects After Its 2026 Findings

07/27/2026 07:00 · 20 min read
UBO Verification in Private Markets: What the FCA Expects After Its 2026 Findings

On 22 July 2026 the FCA reported that some firms active in private markets had no formal process for verifying ultimate beneficial ownership in multi‑layered or offshore structures. It is the sharpest finding in the review, and the hardest to fix — partly because a UK‑supervised firm cannot legally reach several of the registers involved. This is what a defensible UBO verification process looks like in practice: how far the corporate chain can be traced from official sources, where each jurisdiction stops, and what the FCA is actually testing when it asks to see the file.

The short version

The UBO finding is the one with teeth. A small number of firms active in private markets had no formal UBO verification process for multi‑layered or offshore structures. Around a fifth of private markets firms say more than 30% of their customers use complex ownership structures — against 85% of other firms reporting none at all. The exposure is concentrated exactly where the process is weakest.

Get the denominator right before you quote it. There are around 2,500 firms in the sector. The FCA engaged with 242 of them in 2025/26, and states explicitly that every percentage in the publication is calculated from that 242‑firm sample. The findings apply to the sector; the statistics describe the sample.

Four of the seven control findings are data problems, not policy problems. Customer risk assessment, ownership verification in layered structures, oversight of outsourced due diligence, and ongoing monitoring all fail for the same underlying reason: no current, sourced, re‑derivable record of who the counterparty is and who stands behind it.

Private markets carry the concentration. Firms active in private markets were markedly more likely to report PEPs, complex cross‑jurisdictional ownership and international fund flows — and were the firms where the FCA found missing UBO verification processes for multi‑layered and offshore structures.

Outsourcing does not move the liability. Around 40% of firms outsource part of financial crime compliance. Only 36% of those demonstrated full oversight of the third party’s onboarding process. Under the MLRs, the firm remains responsible either way.

And there is a trap underneath that. Jersey, Guernsey and Ireland restrict beneficial ownership register access to locally supervised firms. A UK‑supervised asset manager cannot reach those registers directly — only its administrator can. So the firm depends on the third party for the very facts it is required to independently verify.

What the FCA actually published — and what it did not

The publication is a “good and poor practice” output, not a consultation and not enforcement. The FCA issued a questionnaire to firms in the asset management and alternatives portfolio covering business model (inherent risk) and financial crime systems and controls, then interviewed senior staff at a smaller subset chosen to span the range of responses — public and private markets, firms in and out of scope of the annual financial crime return, and firms it had assessed as lower and potentially higher risk.

Controls were evaluated against the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, the FCA’s Financial Crime Guide, SYSC, JMLSG guidance and FATF guidance.

The scope numbers are worth holding in your head, because they are the first thing a sceptical MLRO will check.

Who the review coveredFindings apply to the sector. Percentages describe the sample.~2,500 firmsin the asset management & alternatives sectorPopulation~2,100 firmsreport through the annual financial crime returnREP‑CRIM242 firmsengaged in 2025/26The sample87%responded to the questionnaireResponse rate
Source: FCA, “Asset management and alternative firms’ financial crime controls: our findings”, 22 July 2026.

Before you put this in a deck

Several summaries circulating this week attach the review’s percentages to the full 2,500‑firm sector. The FCA’s own wording is unambiguous: all percentages are calculated from the sample of 242 firms it engaged with. Use “18% of the 242 firms in the FCA’s sample” rather than “18% of UK asset managers”. The finding is still material — and the precision is what makes it credible in front of a compliance audience.

Seven findings. Four of them are data problems.

The FCA groups its control findings into seven areas: business‑wide risk assessment, customer risk assessment, customer and enhanced due diligence, ongoing monitoring, screening, governance and training. Read them together and a split appears.

Three are organisational: governance forums that rarely discuss financial crime, MLROs stretched across other responsibilities, uneven training. Those are fixed with time, headcount and committee discipline.

The other four fail for a shared, mechanical reason. A firm cannot risk‑rate a customer it cannot describe. It cannot verify ownership it cannot trace. It cannot supervise an outsourced check it cannot independently reproduce. And it cannot monitor a relationship whose underlying facts it only captured once, at onboarding. Each of those is a data problem wearing a policy label.

Control gaps reported by the FCA’s 242‑firm sampleData‑dependent controlGovernance / investment0%10%20%30%40%50%No investment in AML systems in last 24 months50%AML discussed annually or less at governance forums36%No formal transaction monitoring process29%No BWRA, or BWRA only partially complete21%*No formal customer risk assessment methodology18%No formal QA process for AML activity18%Source of wealth not verified for high‑risk customers10%No systematic monitoring after onboarding7%No repeat sanctions, PEP or adverse‑media checks7%
All figures calculated from the FCA’s sample of 242 firms. *The FCA’s wording is “just over a fifth”; shown here as 21% for scale.

Because that split is the whole argument, here it is as a working reference — each finding, the regulation behind it, and the evidence that actually closes it.

FCA findingSampleMLR obligationEvidence that closes it
No BWRA, or BWRA only partially completeJust over a fifthRegulations 18 and 18AA dated, documented assessment covering the risk factors the regulations prescribe, with a defined review cycle
No formal customer risk assessment methodology18%Regulation 28(12) and (13)A written methodology, plus a file trace showing every rating factor resolving to a source and a capture date
No UBO verification process for layered or offshore structuresA small number of private markets firmsRegulations 28 and 33A per‑jurisdiction stopping rule: what the register gives, what needs an access application, what must come from the client
Outsourced CDD or EDD without full oversight~40% outsource; 36% of those oversee fullyRegulations 28 and 33A sample of the third party’s files independently reproduced from a source the firm controls, with exceptions logged
Source of wealth not verified for high‑risk customers10%Regulation 33Documented SoW evidence and the reasoning that made it adequate for the risk level
No formal transaction monitoring process29%Regulation 28(11)Documented triggers defining suspicious activity, applied consistently — including where review is manual
No systematic customer monitoring after onboarding7%Regulation 28(11)Event‑driven refresh of entity, status and ownership attributes, not only a calendar review cycle
No repeat sanctions, PEP or adverse‑media screening7%Regulation 35(1)Screening that runs throughout the relationship, with a retained record of each pass
No formal quality assurance process for AML activity18%SYSC / Financial Crime GuideA QA sample across onboarding, alerts and reviews, with findings routed to a governance forum

Sample column reflects the FCA’s 242‑firm engagement. Evidence column is our reading of what demonstrates compliance, not FCA guidance.

Gap 1: ownership in multi‑layered and offshore structures

This is the finding with the sharpest commercial edge, and it lands almost entirely on private markets.

The FCA found that customers with complex ownership structures create risks of illicit fund movement, sanctions evasion and concealment of the origin of funds by obscuring the ultimate beneficial owner — and that when firms encounter these structures, strong due diligence is required to establish ultimate beneficial ownership adequately. It then found that a small number of firms active in private markets had no formal UBO verification process for multi‑layered or offshore structures at all.

The inherent‑risk data shows how unevenly this is distributed.

Firms active in private markets
32%report PEPs in their customer base
~1 in 5say more than 30% of their customers use complex ownership structures
18%have a BWRA that does not specifically cover private markets risks
Firms not active in private markets
9%report PEPs in their customer base
85%report no customers using complex ownership structures at all
Across the whole sample, 50% of firms said over 60% of their customer base is domiciled overseas

Read that alongside the control finding and the shape of the problem is clear. The firms most exposed to layered, cross‑border ownership are the ones least likely to have a repeatable method for resolving it — because resolving it is genuinely hard, and because the honest answer is that no single source can do it end to end.

Where registry data reaches — and where it stops

Any vendor who tells you they will hand you a verified ultimate beneficial owner for a Cayman feeder fund is selling you a future audit finding. The law does not permit it, and pretending otherwise is precisely the kind of black‑box answer that makes a UBO file indefensible.

What good data does is different, and more useful: it resolves the corporate chain as far as the law allows, records exactly where it stopped and why, and tells you which layer needs documentary evidence from the client. That distinction — between what was verified from an official source and what was asserted by the counterparty — is the thing an FCA reviewer is looking for.

A private markets ownership chain, layer by layerIllustrative structureUK fund vehicle / LPCompanies House · PSC register · filingsResolved from the registerEntity, officers, PSCs and filing history are public and machine‑readable.Luxembourg SPVRCS entity data public · RBE access restrictedPartial — legitimate interestEntity and directors available; beneficialownership sits behind AMLD6 access rules.Cayman feeder fundBeneficial ownership register · not publicPartial — legitimate interestCayman has confirmed it will keep alegitimate‑interest, fee‑based model.BVI holding companyBOSS filings · access regime live 1 April 2026Partial — request by requestCase‑by‑case applications only, withobjection and exemption routes for the owner.Ultimate beneficial ownerNatural person · nominee or trust arrangementsDocumentary evidence requiredStructure charts, share certificates,trust deeds and client attestations.The control the FCA is testing is not whether you reached the bottom. It is whether you can show where you stopped, why, and what evidence covers the rest.
Access regimes reflect published positions as at July 2026 and vary by jurisdiction and applicant type. Verify current access rules before relying on any single route.

The access question nobody is asking: who is allowed to look?

Most discussion of beneficial ownership registers asks whether the data is public. That is the wrong question in 2026. The register layer has quietly reorganised itself around a different axis: not what you need, but who supervises you.

Jersey opened its Obliged Entity Beneficial Owner register in February 2025 — to Jersey‑regulated obliged entities. Guernsey did the same from August 2025, for Bailiwick‑supervised obliged entities. Ireland’s RBO grants restricted Tier Two access to “designated persons” as defined by the Irish Criminal Justice (Money Laundering and Terrorist Financing) Act 2010. In each case the access class is defined by local supervision.

A UK‑supervised asset manager is not a Jersey obliged entity, not a Bailiwick obliged entity, and not an Irish designated person. It sits outside the access class for three of the jurisdictions its fund structures are most likely to sit in.

JurisdictionAccess modelWho can reach beneficial ownershipDirect access for a UK‑supervised firm?
United KingdomPublic registerAnyone — PSC data is open and machine‑readableYes
IrelandTiered, restrictedCompetent authorities; Irish designated persons for CDD; legitimate interest case by caseNo
JerseyObliged entity accessCompetent authorities; Jersey‑regulated obliged entities via myJFSCNo
GuernseyObliged entity accessCompetent authorities; Bailiwick‑supervised obliged entitiesNo
LuxembourgLegitimate interestCompetent authorities; applicants meeting the AMLD6 access conditionsApplication
Cayman IslandsLegitimate interestApplicants demonstrating legitimate interest; fee‑based single or annual searchApplication
British Virgin IslandsLegitimate interestApplicants demonstrating an AML, CTF or CPF purpose; live since 1 April 2026Application

Positions as published at July 2026. Jersey and Guernsey both ran legitimate‑interest consultations that closed in January and April 2026 respectively; neither framework was enacted at the time of writing. Entity‑level data — name, number, status, directors, filings — is separately available in all seven jurisdictions and is not affected by these restrictions.

The circular dependency

Follow this through. A UK asset manager cannot reach the Jersey, Guernsey or Irish beneficial ownership registers directly. Its administrator in those jurisdictions can. So the firm depends on the administrator for exactly the ownership facts the FCA says it must be able to stand behind — while the FCA simultaneously says the firm must independently oversee that administrator’s due diligence, and that liability never transfers.

That is not a gap you close by buying register access, because the access is not available to you. You close it by being able to reproduce everything around the restricted layer — the entity, the corporate chain, the directors, the filings, the changes — well enough to know when the administrator’s file has drifted from reality. Then you know which questions to ask, and when.

The register layer is also moving. In the UK, Companies House identity verification became mandatory for newly appointed directors and PSCs on 18 November 2025, with existing directors and PSCs required to verify during a twelve‑month transition closing on 18 November 2026 — which will make the PSC register materially more reliable as a verification input than it was two years ago. In the EU, the AMLD6 provisions on beneficial ownership registers carried a transposition deadline of 10 July 2026, with the substantive AMLR single rulebook applying from 10 July 2027. In the BVI, the legitimate‑interest access framework became operational on 1 April 2026. Cayman confirmed in March 2026 that it will retain a legitimate‑interest model rather than open its register publicly.

None of that changes the obligation. It changes the plumbing you need behind it, and the frequency at which a static UBO file goes out of date.

Gap 2: a customer risk assessment with nothing underneath it

Ownership is the hardest of the four gaps. The next one is the most basic, and it is what makes the ownership work usable. 18% of firms in the sample had no formal customer risk assessment methodology. A small number said they do not classify customers by risk at all.

The FCA is explicit about why this matters: without a customer risk assessment at onboarding, a firm may be unable to comply with the due diligence requirements in Regulation 28(12) and (13) of the MLRs. It also addresses the most common defence directly. Several interviewed firms argued that close relationships and small customer bases let them pick up changes in real time. The FCA accepted that this can help — and restated that firms are still required to hold formal, documented risk assessments.

The practical failure is rarely the absence of a scoring model. It is that the inputs are unverifiable. A risk rating built on jurisdiction, sector, structure complexity and PEP exposure is only defensible if each of those inputs traces to something a reviewer can re‑pull two years later. If the jurisdiction came from a fund administrator’s spreadsheet and the ownership picture came from a one‑off email attachment, the methodology exists but the evidence does not.

The test that matters

Pick any customer file at random. Can you show, for each factor that drove the risk rating, the source it came from, the date it was captured, and whether it has changed since? If the answer requires someone to go and ask a third party, the control is a process, not a record.

Gap 3: outsourced due diligence with no way to check it

Around 40% of firms told the FCA they outsource CDD and EDD checks, generally to compliance consultants and fund administrators. Of those, only 36% had full oversight of the third party’s AML onboarding processes. The FCA found firms that could not explain the CDD or EDD process being run in their name, or demonstrate that any oversight was taking place.

Its position is one sentence long: outsourcing is permitted, but firms remain fully responsible for compliance with the MLRs. Without adequate oversight and monitoring of outsourced CDD and EDD, a firm cannot demonstrate it is meeting Regulation 28 and Regulation 33.

The oversight gapFirms that outsource part of financial crime compliance~40% outsourceof all firms in the sampleOf those firms, how many had full oversight of the third party36% did64% did notliability stays with the firmRegulation 28 and Regulation 33 obligations cannot be delegated to a fund administrator or compliance consultant.
Source: FCA findings, 22 July 2026. Percentages calculated from the 242‑firm sample.

Oversight of an outsourced check is not a questionnaire and an annual service review. It is the ability to independently reproduce a sample of the third party’s conclusions. If your administrator says an entity is active, incorporated in Ireland, with a particular director set and a particular parent, you need a second, sourced view you control — one that lets you spot the file where the administrator’s record is eighteen months stale, or where a director resigned and nobody noticed.

That is a data problem with a data answer. It does not require insourcing the whole function.

If you are the administrator, this finding is about you too

Every UK asset manager that reads this review has just been told to sample‑test its outsourced due diligence provider. If you run fund administration or outsourced compliance, the practical consequence arrives in your inbox over the next two quarters: clients asking you to evidence work you have been doing quietly for years.

Two things change for you. First, file quality becomes a commercial risk rather than an operational one — a client who cannot demonstrate oversight of you has a supervisory problem, and will solve it by either intensifying scrutiny or moving. Second, in Jersey, Guernsey and Ireland you hold register access your clients structurally cannot obtain. That is a genuine service advantage, and it is also concentration of responsibility. The firm that holds the only route to the data owns the consequences when the data is stale.

The defensible position for an administrator is the same one we would argue for the manager: consistent, sourced entity and ownership data across every jurisdiction you administer, with a capture date on each field, so that when a client asks you to prove a file you can produce the evidence rather than the assertion.

Where we fit

We don’t sell UBO conclusions. We supply the registry layer underneath them — company, ownership and financial data from official registries across 200+ countries, with the source and capture date on every field.

  • Ownership chains as far as each register discloses, and an explicit stop where it does not.
  • Daily ingestion, so an onboarding snapshot becomes ongoing monitoring.
  • An independent second view for sample‑testing an outsourced provider.
We will tell you where our coverage stops before you buy.

Gap 4: monitoring that stopped at onboarding

Over half of firms in the sample run periodic reviews such as quarterly or annual refreshes. But 29% reported no formal transaction monitoring process, 7% reported no systematic customer monitoring after onboarding, and 7% do not conduct repeat screening for sanctions, PEPs or adverse media.

Some firms explained that low transaction volumes mean monitoring is handled by manual review. The FCA found that one or two individuals were performing these reviews with no documented or defined triggers for identifying suspicious activity, and said plainly that this may affect how consistent and effective the monitoring is. Ongoing monitoring of a business relationship, including scrutiny of transactions, is mandatory under Regulation 28(11). Identifying PEP customers is a legal obligation under Regulation 35(1).

The FCA also connects monitoring back to ownership: firms that fail to monitor cannot identify changes in customer behaviour or in complex ownership structures, and cannot assess whether a customer remains within risk appetite or whether the right level of due diligence is still being applied.

That sentence is the operational crux. A private markets customer’s ownership is not a static attribute. Shares transfer, holding companies are inserted, directors resign, entities are struck off and restored, and a PSC who was clean at onboarding becomes politically exposed eighteen months later. If your only refresh mechanism is an annual review cycle, your average detection lag on an ownership change is around six months. For the FCA’s stated concern — sanctions evasion through layered structures — six months is not a lag. It is the whole opportunity.

This is the argument for moving from periodic review to event‑driven refresh, and we have written about the mechanics of that shift in our guide to why KYB and KYC need separate workflows.

The register layer is changing under the obligation

None of the FCA’s requirements are new. What is changing is the availability and reliability of the underlying registers — in both directions. UK register data is getting more trustworthy as identity verification bites. Offshore and EU beneficial ownership data is becoming more structured but more gated, moving to request‑based legitimate‑interest models rather than open lookup.

What changes in the register layerNov 2025UK: ID verificationmandatory for newdirectors and PSCsApr 2026BVI legitimate‑interestaccess frameworkbecomes operationalJul 2026EU: AMLD6 beneficialownership registertransposition deadlineNov 2026UK: transition closesfor existing directorsand PSCs to verifyJul 2027EU: AMLR singlerulebook appliesacross member statesDates as published. Implementation timetables have already moved once and may move again — verify before relying on any single date.
UK, EU and BVI register milestones relevant to firms running cross‑border due diligence.

What good looked like

The review is not a list of failures. The FCA reported that firms engaged constructively, and it published good practice alongside the gaps. These are the benchmarks worth taking to your own governance forum, because they are what the regulator has said it wants to see.

Management information

88% track financial crime MI

Firms tracked and used management information covering sanctions, PEPs, adverse media alerts and key AML metrics.

Internal reporting

84% audit internal SARs

Firms reviewed or audited internal suspicious activity reports to check the quality of submissions.

Training

Nearly all firms train staff

Training relevant to staff roles, with some firms tailoring it to their AML activity and adding mandatory testing.

Ongoing due diligence

Over half run periodic reviews

Quarterly or annual refresh cycles supporting the effectiveness of ongoing due diligence.

The FCA also singled out firms that had established review cycles for their business‑wide risk assessment — including one whose business model was static with no intended changes, and which still reviewed and documented its BWRA regularly. That is the cheapest good‑practice example in the entire publication to copy.

Read the good practice and the gaps together and a pattern emerges that is worth naming: firms are good at collecting and reporting, and weak at verifying. 88% gather management information. Only just over a third discuss AML risk regularly at a governance forum. Nearly all train staff. 18% have no methodology for the assessment that training is supposed to support. The sector has built the reporting layer and skipped the evidence layer underneath it.

What happens to firms that do nothing

This publication carries no penalty. It is what comes next that matters, and the FCA was specific: it will use the questionnaire data as it supervises the sector, and intervene where firms fall short.

Supervisory intervention in the UK follows a recognisable ladder, and each rung costs more than the one below it.

  1. Supervisory correspondence. A request for information, or a portfolio letter setting expectations. Cheap, and the last point at which you control the timetable.
  2. Attestation. A named senior manager personally confirms to the regulator that a control is in place. The exposure moves from the firm to an individual.
  3. Skilled person review under section 166 FSMA. The FCA appoints, or approves, an independent reviewer to examine the firm’s controls. The FCA’s own guidance is explicit that its rules allow it to require the regulated firm to pay the costs of the review as a fee. The scope is set by the regulator. The panel the FCA uses for directly commissioned reviews runs across twelve subject categories under a framework effective from April 2026.
  4. Requirements and undertakings. Restrictions on business activity, or voluntary commitments given to avoid worse. These become public.
  5. Enforcement. Investigation, and potentially penalties against the firm and against individuals under the Senior Managers and Certification Regime.

Two details from the findings connect directly to that ladder. More than a quarter of firms with over £10bn in assets under management reported an MLRO who was part‑time or carrying shared responsibilities — and the MLRO is an accountable individual, not just a role. And half the sample reported no investment in remediation or system uplift of AML systems and controls in the last 24 months, which is precisely the profile that reads, from a supervisor’s desk, as a firm that has been told and has not moved.

The budget case, for the person who has to make it

Half the sample invested nothing in AML systems in two years. That is not a knowledge problem. Every MLRO in that half already knew. It is a budget‑authority problem, and the finding does not solve it — it just gives you better material to argue with.

Reduce it to first principles. The remediation spend happens either way. The only variable is who scopes it, who times it, and whether you pay for a reviewer on top.

If you move first
Youset the scope, and can start with the highest‑risk segment rather than the whole book
Youchoose the timetable and phase the cost across budget periods
Youselect the vendors, run a proper evaluation, and negotiate
Niladditional cost of an independent reviewer
If the regulator moves first
Theyset the scope, and it will be broader than the one you would have chosen
Theyset the timetable, and it will not respect your budget cycle
Limitedchoice, under time pressure, with no leverage on price
Plusthe cost of the skilled person review itself, which the firm bears

Three numbers will carry an internal paper further than any argument about principle. None of them require a vendor to produce.

  1. How many of your customers sit behind two or more corporate layers? This sizes the exposure the FCA flagged. If you cannot answer it today, that is itself the finding.
  2. How many customer files depend on a fact you cannot independently reproduce? This sizes the outsourcing oversight gap in your own book, in your own terms.
  3. What is the median age of the ownership data in your live files? If it is measured in quarters, your detection lag on an ownership change is measured in quarters.

Frame the request as data infrastructure rather than headcount. Headcount scales linearly with the book and gets cut in the next cost review. A sourced, monitored entity and ownership layer is a fixed cost that makes the existing team defensible — which is the argument a CFO will actually accept.

What to do in the next 90 days

The FCA said it will use the questionnaire data in its supervision of the sector and will intervene where firms fall short. If your firm was in the 242, assume your responses are now a baseline you will be measured against. If it was not, the findings still describe the expectations being applied to you.

  1. Re‑read your BWRA against Regulations 18 and 18A. If you are active in private markets, check specifically that it addresses private markets risk rather than treating the firm as a single undifferentiated business. 18% of private markets firms in the sample failed this test.
  2. Document the customer risk assessment methodology, then trace one file end to end. Every factor driving the rating should resolve to a source and a date. Close relationships and event‑driven reviews do not substitute for a formal documented assessment.
  3. Inventory the customers with layered or offshore ownership. You cannot fix what you have not counted. Establish how many customers sit behind two or more corporate layers, and which jurisdictions those layers sit in.
  4. Define the stopping rule for UBO tracing. Write down, per jurisdiction, what is obtainable from the register, what requires a legitimate‑interest application, and what must come from the client as documentary evidence. Then apply it consistently.
  5. Sample‑test your outsourced provider. Take twenty files the administrator or consultant completed and independently reproduce the entity and ownership facts from a source you control. Record the exceptions. This single exercise is the most direct evidence of oversight you can produce.
  6. Close the screening loop. Repeat sanctions, PEP and adverse media screening throughout the relationship, not once at onboarding. Regulation 35(1) does not have an expiry date.
  7. Add triggers to manual monitoring. If low volumes mean review is manual, document the triggers that define suspicious activity so the process is consistent and reviewable rather than dependent on two people’s judgement.
  8. Put financial crime on a regular governance agenda. 36% of the sample discussed AML risk annually or less. Management information is being collected by 88% of firms — the gap is that it is not reaching a forum that acts on it.

The uncomfortable one

Half the sample reported no investment in remediation or system uplift of AML systems and controls in the last 24 months. If that is your firm, the finding you should be worried about is not any single percentage. It is that the FCA now has your questionnaire response on file, has told you what good looks like, and has said it will intervene where firms fall short.

Get the data in the shape your stack needs

600M+ company profiles from official registries across 200+ countries, delivered three ways.

  • Bulk feeds — risk models, portfolio remediation, internal entity masters.
  • API — verification, ownership, financials and monitoring endpoints.
  • Platform — search, monitoring and export, without an engineering ticket.
Coverage varies by jurisdiction. Ask us for the country breakdown.

Frequently asked questions

What did the FCA’s July 2026 asset management financial crime review find?
The FCA published findings on 22 July 2026 covering seven control areas: business‑wide risk assessment, customer risk assessment, customer and enhanced due diligence, ongoing monitoring, screening, governance and training. Key gaps included 18% of firms with no formal customer risk assessment methodology, around 40% outsourcing due diligence with only 36% of those demonstrating full oversight, 29% with no formal transaction monitoring process, 7% conducting no repeat sanctions or PEP screening, and a small number of private markets firms with no formal UBO verification process for multi‑layered or offshore structures.
How many firms did the FCA review, and do the percentages apply to all 2,500 firms?
No. There are around 2,500 firms in the asset management and alternatives sector and around 2,100 report through the annual financial crime return, but the FCA engaged with 242 firms in 2025/26 and states that all percentages in the publication are calculated from that 242‑firm sample. 87% of those firms responded to the questionnaire. The findings and expectations apply sector‑wide; the statistics describe the sample.
Which Money Laundering Regulations does the FCA reference in the findings?
Regulations 18 and 18A for the business‑wide risk assessment; Regulation 28(12) and (13) for customer due diligence measures tied to the customer risk assessment; Regulations 28 and 33 for customer and enhanced due diligence including outsourced arrangements; Regulation 28(11) for ongoing monitoring including scrutiny of transactions; and Regulation 35(1) for identifying politically exposed persons. Controls were also assessed against the FCA’s Financial Crime Guide, SYSC, JMLSG guidance and FATF guidance.
Does outsourcing CDD to a fund administrator transfer AML liability?
No. The FCA states that outsourcing is permitted but firms remain fully responsible for compliance with the MLRs. Without adequate oversight and monitoring of outsourced CDD and EDD processes, a firm cannot demonstrate it is meeting its obligations under Regulations 28 and 33. In practice, demonstrating oversight means being able to explain the third party’s process and independently reproduce a sample of its conclusions — not simply holding a service agreement and an annual attestation.
What is a business‑wide risk assessment and who needs one?
A BWRA is the formal, documented assessment of the money laundering, terrorist financing and proliferation financing risks a firm is exposed to through its own activities, products, customers, jurisdictions and delivery channels. It is a legal requirement under Regulations 18 and 18A of the MLRs and must be kept up to date. Just over a fifth of firms in the FCA’s sample either had no BWRA or one that was only partially complete, and 18% of private markets firms had a BWRA that did not specifically cover private markets risks.
How do you verify a UBO in a multi‑layered or offshore structure?
By resolving the corporate chain layer by layer from official sources as far as each jurisdiction permits, then covering the remainder with documentary evidence from the client — structure charts, share registers, trust deeds and attestations. The critical discipline is recording which facts came from a register and which were asserted by the counterparty, plus the date and source for each. The FCA is testing whether a firm has a repeatable, documented process, not whether it always reaches a natural person from public data alone.
Can a UK firm access beneficial ownership registers in Jersey, Guernsey, Ireland, BVI or Cayman?
Not directly, in most cases. Jersey opened its Obliged Entity Beneficial Owner register in February 2025 to Jersey‑regulated obliged entities; Guernsey did the same from August 2025 for Bailiwick‑supervised obliged entities; Ireland’s RBO grants restricted access to “designated persons” under its 2010 Act. A UK‑supervised firm falls outside all three access classes. The BVI and Cayman operate legitimate‑interest models — BVI live since 1 April 2026, assessed case by case with per‑request fees and owner objection rights; Cayman confirmed in March 2026 it will retain legitimate‑interest access rather than open its register. Entity‑level data such as name, number, status and directors remains separately available in all of these jurisdictions. Any provider claiming to supply bulk verified UBO for them should be asked to explain the legal basis first.
What does the FCA expect for ongoing monitoring and screening?
Ongoing monitoring of the business relationship, including scrutiny of transactions and customer relationships, is mandatory under Regulation 28(11). Screening for sanctions and PEPs must continue throughout the relationship rather than being performed once at onboarding, and firms have a legal obligation to identify PEP customers under Regulation 35(1). Where low transaction volumes mean monitoring is manual, the FCA expects documented and defined triggers for identifying suspicious activity so the process is consistent rather than dependent on individual judgement.
Is registry data enough to satisfy the FCA’s customer risk assessment expectations?
Registry data is the evidential spine, not the whole control. It establishes entity identity, status, officers, filing history and, where the jurisdiction publishes it, ownership and corporate structure — each attached to a source and a date, which is what makes a risk rating defensible on review. A complete customer risk assessment also requires sanctions, PEP and adverse media screening, source of funds and source of wealth work for higher‑risk customers, and a documented methodology for turning those inputs into a rating.
What should asset managers do first after the FCA findings?
Three things, in order. Confirm the BWRA exists, is current and addresses the firm’s actual business model including private markets activity. Trace one customer file end to end and check that every factor behind the risk rating resolves to a source and a date. Then sample‑test any outsourced due diligence provider by independently reproducing twenty of their files. The FCA has said it will use the questionnaire data in its supervision of the sector and intervene where firms fall short. Intervention escalates from supervisory correspondence to attestations, then to a skilled person review under section 166 FSMA — where the regulator sets the scope and the FCA’s rules allow it to require the firm to pay the cost. Moving first is the only version of this where you control the scope and the timetable.