FCA Enforcement

FCA AML Enforcement Trends in 2025: What Payment Firms Need to Know

FCA AML Enforcement Trends in 2025: What Payment Firms Need to Know

The FCA's supervision of financial crime controls at payment firms and e-money institutions has shifted markedly over the past two years. Where the regulator once signalled concerns through thematic reviews and Dear CEO letters, the 2024–2025 enforcement cycle produced a wave of formal action — restriction notices, skilled person reviews under s.166, and substantial financial penalties — that payment compliance teams cannot afford to treat as background noise.

This article examines the patterns visible across FCA enforcement activity in 2024 and 2025, the deficiencies consistently cited, and the practical implications for MLROs building or overhauling their transaction monitoring programmes in 2026.

The Regulatory Backdrop

The FCA's current approach to payment firm supervision has three statutory anchors: the Money Laundering Regulations 2017 (as amended), the Payment Services Regulations 2017, and the FCA's own SYSC sourcebook requirements. In practice, the regulator's focus has sharpened on two obligations that many firms still treat as aspirational rather than mandatory: the adequacy of automated transaction monitoring against documented typologies, and the completeness and timeliness of SAR submissions to the National Crime Agency.

The Financial Action Task Force's 2018 Mutual Evaluation of the United Kingdom identified transaction monitoring at payment firms as a structural gap. The FCA's subsequent thematic reviews — most recently its 2023 review of money service businesses and e-money institutions — documented persistent weaknesses. Enforcement actions are, in effect, the regulator applying the conclusions of those thematic reviews to specific firms.

What the Enforcement Patterns Tell Us

Across publicly available FCA enforcement decisions and supervisory correspondence made available under freedom of information requests, several deficiency themes appear repeatedly.

1. Transaction Monitoring Rules Not Updated to Reflect Business Change

The MLR 2017 Regulation 19 obligation requires firms to ensure that their systems and controls remain appropriate as the firm's business model evolves. The FCA's enforcement cases consistently identify firms that deployed transaction monitoring rule sets at launch and did not subsequently revise thresholds, peer groups, or typology coverage when the firm's transaction profile changed materially — for example, when adding new payment corridors, launching a new customer segment, or onboarding a high-risk business client.

The JMLSG Guidance (Part I, Section 6) is explicit: monitoring rules must be calibrated to the firm's specific risk profile. A rule threshold appropriate for a low-volume business account is not appropriate for a high-frequency consumer payments business. Firms that used out-of-box vendor configurations without documented calibration decisions have been particularly exposed.

2. Alert Disposition Without Documented Rationale

The FCA's inspection teams examine alert management records closely. Specifically, they look for evidence that alerts were reviewed by a suitably qualified person and that the decision to clear, escalate, or file was documented with contemporaneous reasoning. Firms where compliance analysts were closing large volumes of alerts with single-line or no-text notes — effectively using the system as a tick-box exercise — have faced criticism under the MLR 2017 Regulation 26 requirement to maintain adequate records.

The NCA's SARs Annual Report has flagged the quality of information in filed SARs as a persistent concern. A SAR that simply states "unusual pattern of transactions" without specificity about counterparties, amounts, timing, or typology adds limited intelligence value and may expose the filing firm to FCA scrutiny for inadequate investigation practices.

3. Late and Incomplete SAR Filing

Under the Proceeds of Crime Act 2002 (POCA), the obligation to file a SAR arises when a person knows or suspects, or has reasonable grounds to know or suspect, that a person is engaged in money laundering. The FCA has been critical of firms where the period between the transaction monitoring alert being generated and the SAR being filed ran to weeks or months — particularly where the firm's own audit trail showed that alerts were placed in a review queue and remained uninvestigated for extended periods.

The "consent SAR" mechanism under POCA s.336 — where firms seek a defence against the money laundering tipping-off offence before proceeding with a transaction — has been invoked late in several enforcement cases, after the underlying transactions had already completed. Timing compliance is a core element of an adequate SAR programme.

4. Customer Risk Assessment Not Driving CDD Intensity

A risk-based approach requires that the intensity of customer due diligence (CDD) and the stringency of transaction monitoring reflect the assessed risk of each customer relationship. The FCA has found firms where a formal risk-scoring system existed on paper, but high-risk scores did not automatically trigger enhanced due diligence (EDD), did not adjust transaction monitoring thresholds for that customer, and did not result in increased review frequency for that customer's alerts.

Particularly in the PEP (Politically Exposed Person) screening context, firms have been cited for failing to apply EDD to customers who were identified as PEPs during periodic review, either because the screening system had missed name variants or because the MLRO had not been notified of the match status when making CDD decisions.

5. Inadequate Board and Senior Management Oversight

The FCA's Senior Managers and Certification Regime (SM&CR) — which applies to most FCA-regulated payment firms — creates individual accountability for financial crime controls at the SMF level. Enforcement decisions have noted firms where the MLRO or Compliance Director was not providing the board with adequate management information on SAR volumes, false positive rates, or rule change activity. Without that information flow, senior managers cannot discharge their SM&CR obligations to have reasonable grounds to be satisfied that controls are adequate.

The Transaction Monitoring Gap

Underneath these specific findings is a structural problem that the FCA has acknowledged in its supervisory correspondence: many payment firms are operating transaction monitoring systems that generate far more alerts than their compliance teams can meaningfully review. Industry estimates suggest alert-to-analyst ratios at payment processors of 500 to 1,000 alerts per analyst per day — a volume at which qualitative investigation is physically impossible without automated triage support.

This is the context in which the FCA has criticised firms for inadequate investigation quality. The regulator's position is not that firms must review every alert manually, but that the systems and controls for automated triage must be documented, risk-justified, and subject to ongoing tuning. A suppression decision — the decision to not escalate a category of alert for human review — requires documented rationale and periodic review.

What MLROs Should Do Now

The enforcement pattern points towards four immediate priorities for payment firm compliance teams heading into 2026.

Document your calibration decisions. Every threshold, every peer grouping, every suppression rule needs a documented rationale tied to your specific transaction risk profile. This documentation is what the FCA will ask to see first in a s.166 skilled person review.

Audit your alert disposition records. Pull a sample of alerts from the past six months — particularly those cleared without SAR filing. Can each one be supported by a sufficiently specific investigation note? If not, that is a training and process issue that needs addressing before the next supervisory visit.

Review SAR filing timestamps. Measure the elapsed time from initial alert generation to SAR filing for your last 50 filed SARs. If the median is above seven days, investigate the bottlenecks. Document any delays caused by queue volume rather than genuine investigation complexity — this is important audit trail evidence.

Test your PEP and sanctions screening coverage. Use name variants for known PEP profiles to test whether your screening system would have matched them. OFSI and NCA guidance note that screening systems must handle name transliterations, particularly for politically exposed persons from jurisdictions with non-Latin scripts.

A Note on Technology

Firms should approach technology solutions with the same documentation discipline the FCA applies to manual processes. Using a third-party transaction monitoring system does not transfer regulatory responsibility; it transfers operational execution. The MLRO remains accountable for the configuration, the calibration decisions, and the adequacy of the alert triage process — regardless of which platform is used.

RegSynq does not provide legal or regulatory advice, and this article does not constitute guidance on how any specific firm should structure its compliance programme. MLROs should consult qualified legal counsel and review FCA supervisory correspondence directly. The observations in this article are drawn from publicly available FCA enforcement notices, NCA SARs Annual Reports, and JMLSG published guidance.

This article is published for informational purposes. RegSynq Ltd is not authorised or regulated by the Financial Conduct Authority. Nothing in this article constitutes legal advice. Firms should seek independent legal and compliance counsel for advice specific to their regulatory situation.