On 22 July 2026 the FCA reported that some firms active in private markets had no formal process for verifying ultimate beneficial ownership in multi‑layered or offshore structures. It is the sharpest finding in the review, and the hardest to fix — partly because a UK‑supervised firm cannot legally reach several of the registers involved. This is what a defensible UBO verification process looks like in practice: how far the corporate chain can be traced from official sources, where each jurisdiction stops, and what the FCA is actually testing when it asks to see the file.
The short version
The UBO finding is the one with teeth. A small number of firms active in private markets had no formal UBO verification process for multi‑layered or offshore structures. Around a fifth of private markets firms say more than 30% of their customers use complex ownership structures — against 85% of other firms reporting none at all. The exposure is concentrated exactly where the process is weakest.
Get the denominator right before you quote it. There are around 2,500 firms in the sector. The FCA engaged with 242 of them in 2025/26, and states explicitly that every percentage in the publication is calculated from that 242‑firm sample. The findings apply to the sector; the statistics describe the sample.
Four of the seven control findings are data problems, not policy problems. Customer risk assessment, ownership verification in layered structures, oversight of outsourced due diligence, and ongoing monitoring all fail for the same underlying reason: no current, sourced, re‑derivable record of who the counterparty is and who stands behind it.
Private markets carry the concentration. Firms active in private markets were markedly more likely to report PEPs, complex cross‑jurisdictional ownership and international fund flows — and were the firms where the FCA found missing UBO verification processes for multi‑layered and offshore structures.
Outsourcing does not move the liability. Around 40% of firms outsource part of financial crime compliance. Only 36% of those demonstrated full oversight of the third party’s onboarding process. Under the MLRs, the firm remains responsible either way.
And there is a trap underneath that. Jersey, Guernsey and Ireland restrict beneficial ownership register access to locally supervised firms. A UK‑supervised asset manager cannot reach those registers directly — only its administrator can. So the firm depends on the third party for the very facts it is required to independently verify.
What the FCA actually published — and what it did not
The publication is a “good and poor practice” output, not a consultation and not enforcement. The FCA issued a questionnaire to firms in the asset management and alternatives portfolio covering business model (inherent risk) and financial crime systems and controls, then interviewed senior staff at a smaller subset chosen to span the range of responses — public and private markets, firms in and out of scope of the annual financial crime return, and firms it had assessed as lower and potentially higher risk.
Controls were evaluated against the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, the FCA’s Financial Crime Guide, SYSC, JMLSG guidance and FATF guidance.
The scope numbers are worth holding in your head, because they are the first thing a sceptical MLRO will check.
Before you put this in a deck
Several summaries circulating this week attach the review’s percentages to the full 2,500‑firm sector. The FCA’s own wording is unambiguous: all percentages are calculated from the sample of 242 firms it engaged with. Use “18% of the 242 firms in the FCA’s sample” rather than “18% of UK asset managers”. The finding is still material — and the precision is what makes it credible in front of a compliance audience.
Seven findings. Four of them are data problems.
The FCA groups its control findings into seven areas: business‑wide risk assessment, customer risk assessment, customer and enhanced due diligence, ongoing monitoring, screening, governance and training. Read them together and a split appears.
Three are organisational: governance forums that rarely discuss financial crime, MLROs stretched across other responsibilities, uneven training. Those are fixed with time, headcount and committee discipline.
The other four fail for a shared, mechanical reason. A firm cannot risk‑rate a customer it cannot describe. It cannot verify ownership it cannot trace. It cannot supervise an outsourced check it cannot independently reproduce. And it cannot monitor a relationship whose underlying facts it only captured once, at onboarding. Each of those is a data problem wearing a policy label.
Because that split is the whole argument, here it is as a working reference — each finding, the regulation behind it, and the evidence that actually closes it.
| FCA finding | Sample | MLR obligation | Evidence that closes it |
|---|---|---|---|
| No BWRA, or BWRA only partially complete | Just over a fifth | Regulations 18 and 18A | A dated, documented assessment covering the risk factors the regulations prescribe, with a defined review cycle |
| No formal customer risk assessment methodology | 18% | Regulation 28(12) and (13) | A written methodology, plus a file trace showing every rating factor resolving to a source and a capture date |
| No UBO verification process for layered or offshore structures | A small number of private markets firms | Regulations 28 and 33 | A per‑jurisdiction stopping rule: what the register gives, what needs an access application, what must come from the client |
| Outsourced CDD or EDD without full oversight | ~40% outsource; 36% of those oversee fully | Regulations 28 and 33 | A sample of the third party’s files independently reproduced from a source the firm controls, with exceptions logged |
| Source of wealth not verified for high‑risk customers | 10% | Regulation 33 | Documented SoW evidence and the reasoning that made it adequate for the risk level |
| No formal transaction monitoring process | 29% | Regulation 28(11) | Documented triggers defining suspicious activity, applied consistently — including where review is manual |
| No systematic customer monitoring after onboarding | 7% | Regulation 28(11) | Event‑driven refresh of entity, status and ownership attributes, not only a calendar review cycle |
| No repeat sanctions, PEP or adverse‑media screening | 7% | Regulation 35(1) | Screening that runs throughout the relationship, with a retained record of each pass |
| No formal quality assurance process for AML activity | 18% | SYSC / Financial Crime Guide | A QA sample across onboarding, alerts and reviews, with findings routed to a governance forum |
Sample column reflects the FCA’s 242‑firm engagement. Evidence column is our reading of what demonstrates compliance, not FCA guidance.
Gap 1: ownership in multi‑layered and offshore structures
This is the finding with the sharpest commercial edge, and it lands almost entirely on private markets.
The FCA found that customers with complex ownership structures create risks of illicit fund movement, sanctions evasion and concealment of the origin of funds by obscuring the ultimate beneficial owner — and that when firms encounter these structures, strong due diligence is required to establish ultimate beneficial ownership adequately. It then found that a small number of firms active in private markets had no formal UBO verification process for multi‑layered or offshore structures at all.
The inherent‑risk data shows how unevenly this is distributed.
Read that alongside the control finding and the shape of the problem is clear. The firms most exposed to layered, cross‑border ownership are the ones least likely to have a repeatable method for resolving it — because resolving it is genuinely hard, and because the honest answer is that no single source can do it end to end.
Where registry data reaches — and where it stops
Any vendor who tells you they will hand you a verified ultimate beneficial owner for a Cayman feeder fund is selling you a future audit finding. The law does not permit it, and pretending otherwise is precisely the kind of black‑box answer that makes a UBO file indefensible.
What good data does is different, and more useful: it resolves the corporate chain as far as the law allows, records exactly where it stopped and why, and tells you which layer needs documentary evidence from the client. That distinction — between what was verified from an official source and what was asserted by the counterparty — is the thing an FCA reviewer is looking for.
The access question nobody is asking: who is allowed to look?
Most discussion of beneficial ownership registers asks whether the data is public. That is the wrong question in 2026. The register layer has quietly reorganised itself around a different axis: not what you need, but who supervises you.
Jersey opened its Obliged Entity Beneficial Owner register in February 2025 — to Jersey‑regulated obliged entities. Guernsey did the same from August 2025, for Bailiwick‑supervised obliged entities. Ireland’s RBO grants restricted Tier Two access to “designated persons” as defined by the Irish Criminal Justice (Money Laundering and Terrorist Financing) Act 2010. In each case the access class is defined by local supervision.
A UK‑supervised asset manager is not a Jersey obliged entity, not a Bailiwick obliged entity, and not an Irish designated person. It sits outside the access class for three of the jurisdictions its fund structures are most likely to sit in.
| Jurisdiction | Access model | Who can reach beneficial ownership | Direct access for a UK‑supervised firm? |
|---|---|---|---|
| United Kingdom | Public register | Anyone — PSC data is open and machine‑readable | Yes |
| Ireland | Tiered, restricted | Competent authorities; Irish designated persons for CDD; legitimate interest case by case | No |
| Jersey | Obliged entity access | Competent authorities; Jersey‑regulated obliged entities via myJFSC | No |
| Guernsey | Obliged entity access | Competent authorities; Bailiwick‑supervised obliged entities | No |
| Luxembourg | Legitimate interest | Competent authorities; applicants meeting the AMLD6 access conditions | Application |
| Cayman Islands | Legitimate interest | Applicants demonstrating legitimate interest; fee‑based single or annual search | Application |
| British Virgin Islands | Legitimate interest | Applicants demonstrating an AML, CTF or CPF purpose; live since 1 April 2026 | Application |
Positions as published at July 2026. Jersey and Guernsey both ran legitimate‑interest consultations that closed in January and April 2026 respectively; neither framework was enacted at the time of writing. Entity‑level data — name, number, status, directors, filings — is separately available in all seven jurisdictions and is not affected by these restrictions.
The circular dependency
Follow this through. A UK asset manager cannot reach the Jersey, Guernsey or Irish beneficial ownership registers directly. Its administrator in those jurisdictions can. So the firm depends on the administrator for exactly the ownership facts the FCA says it must be able to stand behind — while the FCA simultaneously says the firm must independently oversee that administrator’s due diligence, and that liability never transfers.
That is not a gap you close by buying register access, because the access is not available to you. You close it by being able to reproduce everything around the restricted layer — the entity, the corporate chain, the directors, the filings, the changes — well enough to know when the administrator’s file has drifted from reality. Then you know which questions to ask, and when.
The register layer is also moving. In the UK, Companies House identity verification became mandatory for newly appointed directors and PSCs on 18 November 2025, with existing directors and PSCs required to verify during a twelve‑month transition closing on 18 November 2026 — which will make the PSC register materially more reliable as a verification input than it was two years ago. In the EU, the AMLD6 provisions on beneficial ownership registers carried a transposition deadline of 10 July 2026, with the substantive AMLR single rulebook applying from 10 July 2027. In the BVI, the legitimate‑interest access framework became operational on 1 April 2026. Cayman confirmed in March 2026 that it will retain a legitimate‑interest model rather than open its register publicly.
None of that changes the obligation. It changes the plumbing you need behind it, and the frequency at which a static UBO file goes out of date.
Gap 2: a customer risk assessment with nothing underneath it
Ownership is the hardest of the four gaps. The next one is the most basic, and it is what makes the ownership work usable. 18% of firms in the sample had no formal customer risk assessment methodology. A small number said they do not classify customers by risk at all.
The FCA is explicit about why this matters: without a customer risk assessment at onboarding, a firm may be unable to comply with the due diligence requirements in Regulation 28(12) and (13) of the MLRs. It also addresses the most common defence directly. Several interviewed firms argued that close relationships and small customer bases let them pick up changes in real time. The FCA accepted that this can help — and restated that firms are still required to hold formal, documented risk assessments.
The practical failure is rarely the absence of a scoring model. It is that the inputs are unverifiable. A risk rating built on jurisdiction, sector, structure complexity and PEP exposure is only defensible if each of those inputs traces to something a reviewer can re‑pull two years later. If the jurisdiction came from a fund administrator’s spreadsheet and the ownership picture came from a one‑off email attachment, the methodology exists but the evidence does not.
The test that matters
Pick any customer file at random. Can you show, for each factor that drove the risk rating, the source it came from, the date it was captured, and whether it has changed since? If the answer requires someone to go and ask a third party, the control is a process, not a record.
Gap 3: outsourced due diligence with no way to check it
Around 40% of firms told the FCA they outsource CDD and EDD checks, generally to compliance consultants and fund administrators. Of those, only 36% had full oversight of the third party’s AML onboarding processes. The FCA found firms that could not explain the CDD or EDD process being run in their name, or demonstrate that any oversight was taking place.
Its position is one sentence long: outsourcing is permitted, but firms remain fully responsible for compliance with the MLRs. Without adequate oversight and monitoring of outsourced CDD and EDD, a firm cannot demonstrate it is meeting Regulation 28 and Regulation 33.
Oversight of an outsourced check is not a questionnaire and an annual service review. It is the ability to independently reproduce a sample of the third party’s conclusions. If your administrator says an entity is active, incorporated in Ireland, with a particular director set and a particular parent, you need a second, sourced view you control — one that lets you spot the file where the administrator’s record is eighteen months stale, or where a director resigned and nobody noticed.
That is a data problem with a data answer. It does not require insourcing the whole function.
If you are the administrator, this finding is about you too
Every UK asset manager that reads this review has just been told to sample‑test its outsourced due diligence provider. If you run fund administration or outsourced compliance, the practical consequence arrives in your inbox over the next two quarters: clients asking you to evidence work you have been doing quietly for years.
Two things change for you. First, file quality becomes a commercial risk rather than an operational one — a client who cannot demonstrate oversight of you has a supervisory problem, and will solve it by either intensifying scrutiny or moving. Second, in Jersey, Guernsey and Ireland you hold register access your clients structurally cannot obtain. That is a genuine service advantage, and it is also concentration of responsibility. The firm that holds the only route to the data owns the consequences when the data is stale.
The defensible position for an administrator is the same one we would argue for the manager: consistent, sourced entity and ownership data across every jurisdiction you administer, with a capture date on each field, so that when a client asks you to prove a file you can produce the evidence rather than the assertion.
We don’t sell UBO conclusions. We supply the registry layer underneath them — company, ownership and financial data from official registries across 200+ countries, with the source and capture date on every field.
- Ownership chains as far as each register discloses, and an explicit stop where it does not.
- Daily ingestion, so an onboarding snapshot becomes ongoing monitoring.
- An independent second view for sample‑testing an outsourced provider.
Gap 4: monitoring that stopped at onboarding
Over half of firms in the sample run periodic reviews such as quarterly or annual refreshes. But 29% reported no formal transaction monitoring process, 7% reported no systematic customer monitoring after onboarding, and 7% do not conduct repeat screening for sanctions, PEPs or adverse media.
Some firms explained that low transaction volumes mean monitoring is handled by manual review. The FCA found that one or two individuals were performing these reviews with no documented or defined triggers for identifying suspicious activity, and said plainly that this may affect how consistent and effective the monitoring is. Ongoing monitoring of a business relationship, including scrutiny of transactions, is mandatory under Regulation 28(11). Identifying PEP customers is a legal obligation under Regulation 35(1).
The FCA also connects monitoring back to ownership: firms that fail to monitor cannot identify changes in customer behaviour or in complex ownership structures, and cannot assess whether a customer remains within risk appetite or whether the right level of due diligence is still being applied.
That sentence is the operational crux. A private markets customer’s ownership is not a static attribute. Shares transfer, holding companies are inserted, directors resign, entities are struck off and restored, and a PSC who was clean at onboarding becomes politically exposed eighteen months later. If your only refresh mechanism is an annual review cycle, your average detection lag on an ownership change is around six months. For the FCA’s stated concern — sanctions evasion through layered structures — six months is not a lag. It is the whole opportunity.
This is the argument for moving from periodic review to event‑driven refresh, and we have written about the mechanics of that shift in our guide to why KYB and KYC need separate workflows.
The register layer is changing under the obligation
None of the FCA’s requirements are new. What is changing is the availability and reliability of the underlying registers — in both directions. UK register data is getting more trustworthy as identity verification bites. Offshore and EU beneficial ownership data is becoming more structured but more gated, moving to request‑based legitimate‑interest models rather than open lookup.
What good looked like
The review is not a list of failures. The FCA reported that firms engaged constructively, and it published good practice alongside the gaps. These are the benchmarks worth taking to your own governance forum, because they are what the regulator has said it wants to see.
Management information
88% track financial crime MI
Firms tracked and used management information covering sanctions, PEPs, adverse media alerts and key AML metrics.
Internal reporting
84% audit internal SARs
Firms reviewed or audited internal suspicious activity reports to check the quality of submissions.
Training
Nearly all firms train staff
Training relevant to staff roles, with some firms tailoring it to their AML activity and adding mandatory testing.
Ongoing due diligence
Over half run periodic reviews
Quarterly or annual refresh cycles supporting the effectiveness of ongoing due diligence.
The FCA also singled out firms that had established review cycles for their business‑wide risk assessment — including one whose business model was static with no intended changes, and which still reviewed and documented its BWRA regularly. That is the cheapest good‑practice example in the entire publication to copy.
Read the good practice and the gaps together and a pattern emerges that is worth naming: firms are good at collecting and reporting, and weak at verifying. 88% gather management information. Only just over a third discuss AML risk regularly at a governance forum. Nearly all train staff. 18% have no methodology for the assessment that training is supposed to support. The sector has built the reporting layer and skipped the evidence layer underneath it.
What happens to firms that do nothing
This publication carries no penalty. It is what comes next that matters, and the FCA was specific: it will use the questionnaire data as it supervises the sector, and intervene where firms fall short.
Supervisory intervention in the UK follows a recognisable ladder, and each rung costs more than the one below it.
- Supervisory correspondence. A request for information, or a portfolio letter setting expectations. Cheap, and the last point at which you control the timetable.
- Attestation. A named senior manager personally confirms to the regulator that a control is in place. The exposure moves from the firm to an individual.
- Skilled person review under section 166 FSMA. The FCA appoints, or approves, an independent reviewer to examine the firm’s controls. The FCA’s own guidance is explicit that its rules allow it to require the regulated firm to pay the costs of the review as a fee. The scope is set by the regulator. The panel the FCA uses for directly commissioned reviews runs across twelve subject categories under a framework effective from April 2026.
- Requirements and undertakings. Restrictions on business activity, or voluntary commitments given to avoid worse. These become public.
- Enforcement. Investigation, and potentially penalties against the firm and against individuals under the Senior Managers and Certification Regime.
Two details from the findings connect directly to that ladder. More than a quarter of firms with over £10bn in assets under management reported an MLRO who was part‑time or carrying shared responsibilities — and the MLRO is an accountable individual, not just a role. And half the sample reported no investment in remediation or system uplift of AML systems and controls in the last 24 months, which is precisely the profile that reads, from a supervisor’s desk, as a firm that has been told and has not moved.
The budget case, for the person who has to make it
Half the sample invested nothing in AML systems in two years. That is not a knowledge problem. Every MLRO in that half already knew. It is a budget‑authority problem, and the finding does not solve it — it just gives you better material to argue with.
Reduce it to first principles. The remediation spend happens either way. The only variable is who scopes it, who times it, and whether you pay for a reviewer on top.
Three numbers will carry an internal paper further than any argument about principle. None of them require a vendor to produce.
- How many of your customers sit behind two or more corporate layers? This sizes the exposure the FCA flagged. If you cannot answer it today, that is itself the finding.
- How many customer files depend on a fact you cannot independently reproduce? This sizes the outsourcing oversight gap in your own book, in your own terms.
- What is the median age of the ownership data in your live files? If it is measured in quarters, your detection lag on an ownership change is measured in quarters.
Frame the request as data infrastructure rather than headcount. Headcount scales linearly with the book and gets cut in the next cost review. A sourced, monitored entity and ownership layer is a fixed cost that makes the existing team defensible — which is the argument a CFO will actually accept.
What to do in the next 90 days
The FCA said it will use the questionnaire data in its supervision of the sector and will intervene where firms fall short. If your firm was in the 242, assume your responses are now a baseline you will be measured against. If it was not, the findings still describe the expectations being applied to you.
- Re‑read your BWRA against Regulations 18 and 18A. If you are active in private markets, check specifically that it addresses private markets risk rather than treating the firm as a single undifferentiated business. 18% of private markets firms in the sample failed this test.
- Document the customer risk assessment methodology, then trace one file end to end. Every factor driving the rating should resolve to a source and a date. Close relationships and event‑driven reviews do not substitute for a formal documented assessment.
- Inventory the customers with layered or offshore ownership. You cannot fix what you have not counted. Establish how many customers sit behind two or more corporate layers, and which jurisdictions those layers sit in.
- Define the stopping rule for UBO tracing. Write down, per jurisdiction, what is obtainable from the register, what requires a legitimate‑interest application, and what must come from the client as documentary evidence. Then apply it consistently.
- Sample‑test your outsourced provider. Take twenty files the administrator or consultant completed and independently reproduce the entity and ownership facts from a source you control. Record the exceptions. This single exercise is the most direct evidence of oversight you can produce.
- Close the screening loop. Repeat sanctions, PEP and adverse media screening throughout the relationship, not once at onboarding. Regulation 35(1) does not have an expiry date.
- Add triggers to manual monitoring. If low volumes mean review is manual, document the triggers that define suspicious activity so the process is consistent and reviewable rather than dependent on two people’s judgement.
- Put financial crime on a regular governance agenda. 36% of the sample discussed AML risk annually or less. Management information is being collected by 88% of firms — the gap is that it is not reaching a forum that acts on it.
The uncomfortable one
Half the sample reported no investment in remediation or system uplift of AML systems and controls in the last 24 months. If that is your firm, the finding you should be worried about is not any single percentage. It is that the FCA now has your questionnaire response on file, has told you what good looks like, and has said it will intervene where firms fall short.
600M+ company profiles from official registries across 200+ countries, delivered three ways.
- Bulk feeds — risk models, portfolio remediation, internal entity masters.
- API — verification, ownership, financials and monitoring endpoints.
- Platform — search, monitoring and export, without an engineering ticket.