Content Library
Back
Share

The FCA's CDD review: Good intentions aren't enough

What the FC As 2026 Sanctions Review Is Really Telling You blog image

The FCA's April 2026 multi-firm review of customer due diligence (CDD), enhanced due diligence (EDD), and ongoing monitoring found something more uncomfortable than a single dramatic failure: many firms had the right policies in place, they simply weren't implementing them.

The review spanned obscure technical gaps and plain-vanilla basics alike and covered a broad cross-section of FCA-supervised firms, not just banks or fintechs. Its three areas of focus were policies and procedures, CDD and EDD execution, and compliance monitoring and oversight.

Here is a breakdown of what the FCA found across each area — and what it looks like to get it right.

Policies and procedures: writing them is the easy part

The FCA identified insufficient detail in policies and procedures, as well as lackluster execution, as a common failure.

Failing to be explicit about where CDD ends and EDD begins

Firms that scale quickly often find their labelling hasn't kept pace with how their processes have evolved. Being deliberately specific about what is CDD versus a separate EDD step matters both for guiding analysts and for demonstrating to the FCA that the distinction is meaningful in practice.

Periodic review cycles that exist on paper but aren't executed

A sensible approach is to set conservative cadences at the outset (for example, more frequent reviews for higher-risk customers while controls are still maturing) and to extend them as monitoring capabilities improve and the customer base stabilises. However, the reviews have to actually happen. Firms that have accumulated customers for years should ensure they have a systematic periodic review process going forward, but also should work through their entire back book.

Alternative forms of identity verification

The FCA is increasingly focused on financial inclusion, and firms that rely exclusively on standard ID documents will find themselves unable to verify, and therefore unable to serve, customers who don't have them. A practical response is to give a specialist team or a more experienced analyst cohort a clear framework for assessing non-standard documentation.

CDD and EDD execution: where policy meets reality

The FCA’s execution findings were about what actually happens when a customer lands in a queue.

Trigger-based monitoring

The FCA is explicit that ongoing monitoring means more than periodic reviews. It also means responding to change events, such as a new director, a change of ownership, an industry code update, or a company name change. Effective programmes define a set of triggers for both the business and the individuals behind it and integrate trigger-based reviews with the periodic refresh calendar to track what was reviewed and when, reset due dates when a trigger-based review has already covered the ground a periodic refresh would have, and surface the right signals to analysts without drowning them in noise or letting something material slip through.

Lack of EDD documentation

One of the FCA's most consistent findings across its financial crime reviews is that EDD, when performed, often isn't documented. Analysts run checks, make decisions, and speak to customers, but then the rationale doesn't make it into the file, leaving a major gap in audit trails. Organisations should build the documentation requirement into the case management workflow, rather than leaving it to individual analyst discipline.

Generic EDD that doesn't address the risk

This is a subtler failure. Standard EDD such as source of funds, source of wealth, and proof of address is just the baseline. If a customer has been flagged for a PEP connection or complex ownership, asking for a source of funds or issuing a generic questionnaire doesn't meaningfully address that risk. Effective EDD is tailored to what the customer risk assessment actually found, investigating the specific risk factors that elevated the customer in the first place.

Record keeping on the purpose of the relationship

The FCA has long expected firms to capture the intended nature and purpose of the business relationship for ongoing monitoring. In practice, this has limits. For example, asking a retail customer how they intend to use their account often yields "as an account." The requirement isn't wrong, but firms need to think carefully about what information they collect to demonstrate their understanding of their customers to inform ongoing oversight.

Senior manager approvals

The FCA found firms lacking clear documentation of which customer types or risk scenarios require senior manager sign-off. This poses a challenge for high-volume businesses in particular, since the MLRO cannot personally approve every high-risk account. Firms should be able to provide a documented delegation of authority. While high-risk PEPs should always reach MLRO or senior management approval, below that, a clear and documented hierarchy should specify who is authorised to decide at each level based on risk thresholds, and how those decisions are being spot-checked and quality-assured.

Compliance monitoring and audit: independence, depth, and version control

The third area in the FCA’s review includes structural and technical aspects of compliance monitoring.

Lack of independence between the first and second lines in conducting reviews

This is a foundational principle of compliance governance: if the team being assessed is also the team doing the assessment, the value of the assessment is compromised. While very small firms often lack bandwidth to reconcile this, for larger firms it's harder to excuse.

External audits as opportunities rather than a threat

An external audit provides fresh eyes and deep subject-matter expertise to areas the second line can't always reach. For firms with known concerns such as a recent regulatory change, a system implementation, or an area flagged in previous reviews, a focused, topic-specific CDD audit is worth commissioning independently - on top of conducting a standard annual AML audit.

Version control

Financial crime policies are living documents, sometimes updated monthly. When changes accumulate without a clear audit trail of what changed, who approved it, and when, the policy stops telling a coherent story. As a result, internal practice can quietly diverge from what the document actually says. Compliance teams should periodically step back to review the policy as a whole to confirm it still reflects real practice, and make sure the people whose work it governs have read and understood the current version.

Treat the FCA's findings as the standard

A muti-firm review, in practice, should be treated as seriously as AML regulations or the FCA's financial crime handbook. A supervisory review benchmarks what the FCA finds against what it has already told firms to do, setting a de facto standard for the industry.

The recommended action is straightforward: conduct a gap analysis. For each good practice and poor practice item in the review, document where you sit specifically. Is your EDD documentation sufficient? Can you point to examples of tailored EDD that addressed the specific risk factor? Is your senior manager approval framework documented and tested? Can you evidence independence in your compliance monitoring?

The best-run compliance teams treat this as a governance event, not a box-ticking exercise. Firms that approach FCA multi-firm reviews this way — as an opportunity to understand the regulator's expectations and risk appetite — are the ones with far less explaining to do when the regulator eventually shows up.

Dive deeper

To learn more, hear from James Nurse, UK AML/FinCrime thought leader and Strategic Advisor to Alloy, and Rebecca Marriott, Chief Risk Officer at Tide, on the Alloy webinar “CDD under the microscope: Unpacking the FCA's latest multi-firm review”. Watch on-demand.

Related content

Back