These are our findings from our engagement with asset management and alternatives firms, highlighting examples of good and poor practice.
Our findings are intended to help firms reflect on the financial crime risks inherent in their business models, and how well their control frameworks are designed to identify, manage and mitigate those risks.
Who this applies to
- Asset management and alternative firms.
What we looked at
As part of our review, we issued a questionnaire to all firms to gather high-level information on their:
- business models (inherent risk)
- financial crime risk systems and controls
We also held interviews with senior staff at a smaller subset of firms who were selected to cover a wide range of questionnaire responses and business models, including:
- Firms investing in public and/or private assets, including firms focused solely on private market activity.
- Firms both within and outside the scope of our annual financial crime return.
- Firms we assessed as either lower risk, or potentially higher risk from an inherent risk and control perspective, based on their responses.
We evaluated firms’ controls against the:
- Money Laundering Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017[2] (MLRs)
- Financial Crime Guide[3] (FCG)
- Senior Management Arrangements, Systems and Controls[4] (SYSC)
- Joint Money Laundering Steering Group (JMLSG) guidance[5]
- Financial Action Task Force (FATF) guidance[6]
Background
There are around 2,500 firms in the asset management and alternatives sector with a wide range of business models, activities and customer bases.
So, firms’ exposure to financial crime risk is not uniform. Some present lower inherent risk profiles. Others operate in areas where heightened and material financial crime risks can arise because of:
- the nature of the products they offer
- the complexity of customer business structures
- the profile of customers and counterparties
- firms’ use of intermediaries
- engagement in certain types of higher-risk transactions
Most firms in the sector are subject to the MLRs.
Our annual financial crime return (REP-CRIM) gathers data from approximately 2,100 of these firms. This gives us a broad view of financial crime risks across the sector.
In 2025/26, we engaged with 242 asset management and alternatives firms.
We wanted to gather firms’ own assessments of the financial crime risks they face and understand their control frameworks.
This summarises our main findings, including examples of good and poor practice. It also reminds firms of our expectations.
The findings centre on:
- How well firms understand their inherent financial crime risk.
- How well firms identify, mitigate and manage financial crime risk (control risks).
This review is part of our wider financial crime supervisory work in support of our 2025–30 strategy[7] and supervisory priorities for the sector.
All percentages in this publication are calculated from the sample of 242 firms we engaged with.
What we found
Overall, firms in the sector engaged constructively with the exercise.
A large proportion of firms (87%) responded to the questionnaire, providing a broad cross-section of views across the sector.
Firms selected for follow-up interviews were open, transparent and responsive during these sessions, providing useful insight that informed our findings.
While the review covered a range of business models, the broad diversity of the sector means that not all findings will be applicable to all firms.
Inherent risks
Some firms in our sample are exposed to heightened financial crime risks, especially those firms active in private markets. These risks are increased by features such as:
- complex ownership structures that can cross jurisdictions
- high-risk customers
- international fund flows
The data collected from our questionnaire indicated that firms active in private markets were more likely to exhibit these characteristics than firms undertaking other activities.
Complex ownership
Customers with complex ownership structures present risks of illicit fund movement, sanctions evasion, and concealment of the origin of funds by obscuring the ultimate beneficial owner.
When firms encounter complex ownership structures, strong due diligence processes are required to adequately establish ultimate beneficial ownership.
We found:
- Around a fifth of firms active in private markets reported that over 30% of their customers use complex ownership structures.
- 85% of firms not active in private markets reported no customers using complex ownership structures.
High-risk customers
Politically exposed persons (PEPs) may present a higher risk of money laundering as their position may make them vulnerable to corruption. Firms should be able to identify PEPs and apply enhanced due diligence where appropriate.
We found that 32% of firms active in private markets reported PEPs in their customer base, compared to 9% for firms not active in private markets.
International transactions
International transactions can be used to move illicit funds across borders, obscuring the origins of wealth and to evade sanctions. Firms that facilitate them should assess and mitigate the associated money laundering and sanctions risks.
We found that 50% of firms reported over 60% of their customer base is domiciled overseas, with firms active in private markets more likely to engage in international fund transfers.
Reminder for firms
Firms that face higher financial crime risks should have established frameworks and appropriate controls to mitigate these risks, as referenced in the MLRs and Senior Management Arrangements, Systems and Controls (SYSC) section of our Handbook.
Control risks
Most firms showed they understood legal and regulatory requirements through their control framework, but others appeared to underestimate their inherent financial crime risks, resulting in an informal approach to evaluating and managing them.
In the sections below are examples of gaps we found, as well as instances of good practice:
- business-wide risk assessment
- customer risk assessment
- customer due diligence and enhanced due diligence
- ongoing monitoring
- screening
- governance
- training
In some instances, the findings were concerning and will require firms to review their financial crime frameworks to make sure they are adequately identifying, managing and mitigating the risk to which they are exposed.
Business wide risk assessment (BWRA)
We found just over a fifth of all firms had either not undertaken a BWRA or that it was incomplete.
We also found that some firms had completed a BWRA, but it was inadequate. For example, some didn’t fully consider the inherent financial crime risk from the firm’s activities.
It’s a legal requirement for firms to have a formal, up-to-date BWRA under Regulation 18 and 18A of the MLRs. It is a fundamental tool in a firm’s anti-money laundering (AML), terrorist financing (TF) and proliferation financing (PF) framework to identify and assess the inherent financial crime risks they face. This enables firms to assess the effectiveness of the systems and controls they have in place to mitigate these identified risks. Without robust systems and controls, firms could unknowingly facilitate financial crime.
Firms should also read publications such as the 2025 National risk assessment (NRA) of money laundering and terrorist financing[8] and the 2021 NRA of proliferation financing[9] – and take account of findings that may affect their individual business risk assessment.
Good practice example
Regular review of BWRA
During the firm interviews, we identified instances where firms had established review cycles for their BWRA to make sure they had an accurate risk assessment, and adequate policies, controls and procedures in place to mitigate the identified risks.
One firm’s business model was considered static with no intended changes, but a regular review of the BWRA was still undertaken and documented.
Poor practice example
Lack of, or ineffective, BWRA
Just over a fifth of all firms either did not have a BWRA or had one that was only partially complete.
18% of firms active in private markets stated that their BWRA did not specifically cover private markets risks.
During the firm interviews we identified instances where a firm’s BWRA did not adequately cover financial crime risk nor consider the risk factors prescribed in Regulation 18 and 18A of the MLRs.
Customer risk assessment (CRA)
We found that not all firms had a formal CRA, suggesting that some aren’t applying appropriate customer due diligence measures.
Some firms we interviewed are communicating with customers frequently as a result of close customer relationships and/or a small customer base. Although this can help firms address changes to their customers’ profiles in real time, and instigate an event-driven review, firms are still required to have formal documented risk assessments.
Some firms active in private markets had not implemented effective controls for the identification of owners within multi-layered/offshore structures, highlighting weaknesses within their controls.
Firms are responsible for conducting formal risk assessments of their customers. Without an assessment of customer risk at onboarding, firms may be unable to comply with the due diligence requirements set out in Regulation 28 (12) and (13) of the MLRs.
Poor practice examples
Missing formal CRA
18% of firms had no formal CRA methodology.
No verification process for ultimate beneficial owner (UBO)
A small number of firms active in private markets had no formal UBO verification process for multi-layered or offshore structures.
Customers not classified for risk
A small number of firms reported that they don’t classify their customers by risk.
Customer due diligence (CDD) and enhanced due diligence (EDD)
Around 40% of firms told us that they outsource CDD and EDD checks, generally to compliance consultants and fund administrators.
We found that some firms with limited oversight of the work carried out by third parties couldn’t explain CDD/EDD processes or demonstrate that oversight of these activities was being conducted.
Outsourcing activities is permitted, but firms remain fully responsible for compliance with the MLRs. Without adequate oversight and monitoring of outsourced CDD and EDD processes, firms won’t be able to demonstrate that they’re meeting obligations under Regulation 28 and 33 of the MLRs.
Poor practice examples
Inadequate oversight of outsourcing activities for CDD processes
Around 40% of all firms outsourced some part of their financial crime compliance function, yet only 36% of them had full oversight of the third party’s AML onboarding processes.
No verification of source of wealth for high-risk customers
10% of firms did not verify high-risk customers’ source of wealth.
Ongoing monitoring
We found that most firms have implemented controls to monitor customer relationships, with over half undertaking periodic reviews, such as quarterly or annual refreshes, to support the effectiveness of ongoing due diligence.
Over a quarter of responding firms indicated that they did not have a formal transaction monitoring process. Through interviews, we established that some of them undertake monitoring by way of manual review due to low transaction volumes. One or two individuals perform these manual reviews with no documented or defined triggers for identifying suspicious activity. We consider that this approach may affect how consistent and effective their monitoring is.
It’s a mandatory requirement under Regulation 28(11) of the MLRs that firms monitor a business relationship, including the scrutiny of transactions and customer relationships.
The absence of transaction monitoring controls increases the risk that firms may be used for illicit fund movement and that suspicious activity may go undetected.
If they fail to conduct ongoing monitoring of customer relationships, firms may be unable to identify changes in customer behaviour, or in complex ownership structures. They’ll equally be unable to assess whether a customer remains in risk appetite and whether they’re applying the correct level of due diligence.
Good practice example
Quality of internal suspicious activity report (SAR) submissions
84% of firms reviewed or audited internal SARs to check the quality of submissions.
Poor practice examples
Failure to undertake adequate ongoing monitoring of customer relationships
7% of firms reported no systematic customer monitoring (continuous/real-time monitoring, periodic review cycles or trigger-based reviews) after customer onboarding.
No formal transaction monitoring
29% reported that they had no formal transaction monitoring process.
Screening
Among a small set of firms, we found weakness in their approach to screening customers for PEPs, sanctions and adverse media.
Firms have a legal obligation under Regulation 35(1) of the MLRs to identify PEP customers and must also comply with UK sanctions requirements. If a firm does not conduct ongoing screening throughout the customer relationship, it may fail to identify significant risk factors.
Poor practice example
Lack of repeated screening checks
7% of firms reported that they do not conduct repeat screening checks for sanctions, PEPs, or adverse media.
Governance
Over half of the firms’ money laundering reporting officers (MLROs) reported that they worked part-time or had shared responsibilities. We found this was often commensurate with the size and nature of the business.
However, more than a quarter of larger firms, with over £10bn in assets under management, also reported they had an MLRO who was part-time or had shared responsibilities. These firms are likely to have a wider customer base and potentially more complex activities.
Larger firms should consider if their MLRO function is sufficient to ensure effective AML oversight and compliance. If not, it could potentially make them less able to respond to emerging financial crime risks.
Although nearly all firms are collecting management information, only just over a third discuss AML risk regularly at governance forums. We were concerned about this as these forums should have sufficient management information to:
- Assess the adequacy of their financial crime systems.
- Address risks.
- Report to the Board to help with good decision-making.
Good practice example
Collecting management information on financial crime risks
88% of firms tracked and used management information relating to financial crime risks, including sanctions, PEPs, adverse media alerts, and key AML metrics.
Poor practice examples
Limited investment in AML systems and controls
Half of firms reported no investment in remediation or system uplift of AML systems and controls in the last 24 months.
Limited senior management oversight of AML risk
We found 36% of firms discussed AML risk annually or less frequently at governance forums.
Lack of formal quality assurance
18% of all firms reported that they had no formal quality assurance process for AML activity (onboarding/alerts/reviews).
Training
The majority of firms provided some level of financial crime training to staff and most firms we interviewed undertook training on a regular or annual basis. The level of training varied from tailored to more generalised financial crime training.
Investing in regular staff training on financial crime helps ensure firms remain aware of legal and regulatory obligations, and that staff maintain a good overview and understanding of evolving financial crime risks. It also reinforces staff accountability for detecting and reporting financial crime concerns.
Good practice example
Financial crime training provided to staff
Nearly all firms stated that they provide staff with financial crime training relevant to their roles.
Some firms’ training was tailored to their AML activity, including financial crime detection, cybercrime, and/or the use of case studies. Additionally, we saw some mandatory testing following training.
Poor practice examples
Gaps in MLRO training
We found some MLROs that may not have received training specific to their legal obligations and responsibilities.
Lack of awareness of financial crime updates
We found that some firms generally lacked awareness of legislative and industry guidance updates on financial crime.
Reminders for firms
Systems and controls
- Make sure your financial crime systems and controls comply with the legal obligations under the MLRs.
- Establish and maintain policies, controls and procedures to mitigate and manage the inherent financial crime risks that your firm faces.
Risk assessments (BWRA and CRA)
- Identify and assess the risks of money laundering, terrorist financing and proliferation financing that your firm is exposed to and document this risk assessment under the MLRs.
- Keep documented assessments of the risks posed by your customers under the MLRs.
Due diligence, ongoing monitoring and screening
- Monitor any outsourced activities to ensure they comply with due diligence obligations under the MLRs.
- Monitor business relationships on an ongoing basis, including transaction monitoring and KYC reviews.
- Maintain effective, up-to-date screening systems appropriate to the nature, size and risk of your business.
Governance and resourcing
- Use financial crime management information for effective governance and decision-making.
- Dedicate time and resource, commensurate with the size and business activities of your firm, to identify and address the financial crime risks it’s exposed to.
Training
- Make your employees aware of the law relating to money laundering, terrorist financing and proliferation financing, and train them regularly on how to recognise and deal with transactions, activities and situations which may be related to these areas of financial crime.
Next steps
We encourage firms to consider our findings in the context of their own business model and activities and continue to address any gaps in their financial crime control frameworks.
We’ll use the questionnaire data as we supervise the asset management and alternatives sector, and intervene where firms fall short, in line with our objective to fight financial crime[7].
We’ll continue to monitor firms through our supervisory work to make sure they are considering the points raised here to drive improvements.