FIN.

FCA highlights widespread non-compliance in financial crime controls at corporate finance firms

The FCA has set out findings from its survey on financial crime controls in corporate finance firms. The review focussed on the 300 plus firms which are currently not required to submit financial crime data regulatory returns.

The survey found that approximately 2/3s of respondent firms may not be compliant with the MLRs in one or more elements of their anti-financial crime control frameworks.

Key areas for improvement were:

  • Lack of business-wide risk assessment: 11% of respondents reported that they had no documented business-wide risk assessment;
  • Missing evidence of CDD: 10% of respondents said they did not retain documented evidence of CDD; and
  • Gaps in AR risk assessments: 90% of the 31 principal firm respondents reported clear policies governing financial crime risks inherent in their ARs, but 29% did not actually assess the financial crime risks inherent in their ARs, with 2 firms reporting that they did not:
    • Monitor their ARs’ compliance with financial crime regulations; or
    • Conduct on-site visits or audits.

Areas of good practice included regulatory reporting to senior management on financial crime matters (97% of respondents), using a form to assess customer risk (72%), and maintaining risk registers strengthened by management information.

The FCA reminded firms that they must:

  • Take appropriate steps to identify and assess ML and TF risks, and have a documented business-wide risk assessment;
  • Have documented assessments of risks posed by clients, and not simply rely on close relationships with clients to develop an understanding of client risk;
  • Maintain records of CDD and (where appropriate) EDD; and
  • For principal firms, adequately oversee the regulated activities carried out by their ARs, and implement specific policies and procedures to management the financial crime risks associated with the ARs.

Laura Wiles