FCA Smarter Regulation Strategy: What the Latest Announcement Means for Regulated Firms
MoreCall: 0845 139 4444
Email: [email protected]
Call: 0845 139 4444
Email: [email protected]
Financial crime remains a significant regulatory and operational risk for UK financial services firms. It encompasses a broad range of risks, including money laundering, terrorist financing, proliferation financing, fraud, sanctions breaches, bribery and corruption, and the facilitation of tax evasion.
The precise risks and legal obligations applying to a firm will depend on its activities, products, customers, delivery channels and regulatory status. Effective financial crime frameworks should therefore be proportionate to the firm’s business model and the threats it faces. Square 4 helps financial services firms design, review and strengthen financial crime frameworks that meet regulatory expectations and work in practice. Our support ranges from risk assessments, governance and policy development through to customer due diligence, screening, transaction monitoring, training, regulatory engagement, remediation and independent assurance. Whether you are responding to regulatory findings, preparing for supervisory scrutiny, addressing identified weaknesses or developing a more mature risk-based approach, we provide practical support tailored to your firm.

Why Effective Financial Crime Controls Matter
Financial crime can cause significant harm to customers, firms and the wider financial system. It can result in financial loss, regulatory intervention, remediation costs, reputational damage and the exploitation of financial products and services by criminals.
The legal and regulatory framework is not the same for every firm. Businesses within the scope of the Money Laundering Regulations 2017, as amended, must comply with requirements relating to risk assessment, customer due diligence, ongoing monitoring, internal controls, record keeping and training. Other regulated firms are also expected to maintain appropriate systems and controls to identify, assess and manage the financial crime risks relevant to their business.
Regulators increasingly expect firms to demonstrate more than the existence of policies and controls. Firms should be able to evidence that their arrangements are risk-based, proportionate, embedded and operating effectively in practice.
Strong financial crime frameworks help firms protect customers, support informed senior management oversight, respond effectively to emerging risks and demonstrate that identified weaknesses are addressed in a controlled and sustainable way.
Money Laundering Regulations 2017
For firms within scope, the Money Laundering Regulations 2017, as amended, require a risk-based approach to money laundering, terrorist financing and proliferation financing risk. Relevant requirements include conducting and documenting a business-wide risk assessment, applying customer due diligence, identifying and verifying beneficial owners, carrying out enhanced due diligence where required, maintaining ongoing monitoring, establishing appropriate internal controls, retaining records and providing relevant staff training. Enhanced due diligence and enhanced ongoing monitoring are required in circumstances prescribed by the Regulations and where a firm identifies a higher risk. Relevant factors may include the customer, ownership structure, product, delivery channel, geography, transaction activity and the involvement of politically exposed persons or higher-risk jurisdictions. Relevant firms must also maintain appropriate internal arrangements for identifying and escalating knowledge or suspicion of money laundering or terrorist financing. Where the applicable legal threshold is met, disclosures may need to be made to the National Crime Agency.
FCA Requirements and Expectations
The FCA expects firms to maintain effective systems and controls to identify, assess and manage the financial crime risks relevant to their business. The precise requirements will depend on the firm’s regulatory status and the FCA Handbook provisions applying to it. Firms should be able to demonstrate that their approach is risk-based, proportionate and supported by clear governance, senior management accountability, effective management information, appropriate escalation arrangements, training and assurance. FCA reviews and enforcement action have repeatedly identified weaknesses in areas such as business-wide and customer risk assessment, customer due diligence, ongoing monitoring, transaction monitoring, screening, suspicious activity reporting and governance. The FCA’s expectations also extend beyond AML. Depending on the firm’s activities, relevant risks may include fraud, sanctions, bribery and corruption, and other forms of financial crime.
Framework Reviews, Gap Analyses and Maturity Assessments
We independently review financial crime frameworks across the three lines of defence to assess alignment with relevant legal requirements, regulatory expectations and industry practice. Our reviews can include a structured gap analysis, an assessment of control design and effectiveness, and a maturity assessment to help firms understand where improvement is required. We focus not only on whether a framework exists, but on whether it is consistently applied, adequately evidenced and operating effectively in practice. Our findings are prioritised to help firms identify the areas requiring the most urgent or significant enhancement.
Governance and Oversight
Strong governance is central to effective financial crime risk management. We support firms in reviewing and designing governance arrangements that provide clear accountability, appropriate oversight and effective escalation. This can include committee structures, reporting lines, roles and responsibilities, senior management accountability and the quality of financial crime management information. Our approach balances regulatory expectations with arrangements that are proportionate and workable for the size, scale and complexity of the firm.
Policies, Standards and Control Frameworks
We support firms in developing and enhancing financial crime policies, supporting standards, procedures and control frameworks. Our focus is on ensuring that documentation is clear, coherent and aligned with both regulatory requirements and the way controls operate in practice. We can also assess whether policies and procedures are consistently applied and embedded across relevant business areas. Support may include a full documentation refresh programme or targeted enhancements following regulatory change, internal findings, business growth or changes to the firm’s risk profile.
Business-Wide and Customer Risk Assessments
We design, review and enhance business-wide risk assessments to ensure that they reflect the risks arising from the firm’s business model, products and services, customers, delivery channels, geographies and other relevant exposures. We also support firms with customer risk assessment methodologies and tools, helping ensure that they are risk-based, evidence-driven and capable of being explained to senior management, auditors and regulators. Our support can include methodology design, risk factor selection, scoring, weighting, documentation, governance, implementation and periodic review. Where a new or revised customer risk assessment generates remediation activity, we can also support the resulting programme.
Customer Due Diligence and Enhanced Due Diligence
We review and strengthen customer due diligence and enhanced due diligence frameworks across onboarding, trigger events, ongoing monitoring and periodic review. Our work can include customer and beneficial owner identification and verification, source of funds and source of wealth, politically exposed persons, higher-risk customers, complex structures, escalation, approvals, record keeping and quality assurance. We focus on how due diligence operates in practice, including the quality of risk assessment, evidence, decision-making and documentation. We can also support remediation where backlogs or control weaknesses have been identified.
Screening and Transaction Monitoring
We support firms in reviewing and enhancing screening and transaction monitoring arrangements. This can include sanctions, politically exposed person and adverse media screening, customer and payment screening, alert generation, thresholds, scenario design, investigation processes, escalation, governance and management information. We help firms assess whether systems and controls are appropriately calibrated to the firm’s risks, whether alerts are investigated consistently and whether decisions are adequately documented and subject to effective oversight.
Fraud Risk Management
Fraud is a key component of the wider financial crime framework and should be assessed in the context of a firm's products, customers, delivery channels and operating model. We help firms assess and manage risks including identity and application fraud, account takeover, payment and APP fraud, internal fraud, intermediary fraud, commission abuse and cyber-enabled fraud. Our support covers fraud risk assessments, governance, prevention and detection controls, investigations, customer interventions, complaints, management information and training. We also help in-scope payment service providers comply with mandatory APP scam reimbursement requirements and support organisations in strengthening their arrangements for the corporate offence of failure to prevent fraud.
Sanctions, Bribery and Wider Financial Crime Risks
We support firms in developing and reviewing proportionate arrangements for sanctions compliance, anti-bribery and corruption, and the prevention of the facilitation of tax evasion. This may include risk assessments, policies and procedures, screening arrangements, third-party and associated person risk, gifts and hospitality controls, escalation and reporting, governance, training and assurance.
Regulatory Engagement and Remediation
We support firms in preparing for and managing engagement with the FCA and other relevant authorities. This can include preparing for supervisory visits, responding to information requests, supporting responses to regulatory findings or skilled person reviews, and advising on remediation plans, governance and communications. Our approach helps firms explain their arrangements clearly, demonstrate how controls operate in practice and respond to identified issues in a structured and credible way.
Training and Capability Development
Effective financial crime frameworks rely on staff understanding their responsibilities and applying controls consistently. We design and deliver practical, engaging training tailored to the firm’s business model, risk profile and employee population. This may include mandatory training, role-specific training, Board and Senior Manager training, workshops and supporting guidance. We can also review existing training frameworks, identify gaps, help firms develop appropriate training plans and support the assessment of training effectiveness.
MLRO and Annual Reporting Support
We provide advisory support to MLROs, financial crime teams and senior management. This may include developing or reviewing MLRO reports, supporting Board-level reporting, advising on management information and governance, and providing technical input on complex financial crime matters. We also support firms in preparing and reviewing FCA financial crime returns, including REP-CRIM. This can include interpretation of the reporting requirements, data review, documentation of methodology and consideration of material changes or variances.
Financial Crime Change and Transformation
We support firms in delivering financial crime change programmes driven by internal findings, regulatory expectations, growth, restructuring, acquisition or changes to products and services. Our work can include target operating model design, policy and control enhancement, governance, implementation support, remediation, integration and capability development. We focus on practical and sustainable solutions that can be embedded within the firm and demonstrated to senior management, auditors and regulators.

Sectors We Support – Our financial crime expertise spans:
Banks and building societies
Consumer credit, mortgage and specialist lending firms
Motor and asset finance providers
Wealth and investment management firms
Payment services and e-money firms
Insurance firms and insurance intermediaries
Pensions and retirement providers
Annex I financial institutions and other businesses supervised for AML purposes
Fintechs and firms developing or launching new financial products.
Each sector has different financial crime risks, legal requirements and regulatory expectations. We tailor our approach to the firm’s size, complexity, business model and risk profile rather than applying a standard framework to every organisation.
Our team brings together experienced regulatory consultants and financial crime practitioners. We combine detailed knowledge of UK legal and regulatory expectations with practical experience of reviewing, designing and implementing controls within financial services firms. Square 4 was named Compliance Consultancy Firm of the Year 2024 by the International Compliance Association, demonstrating our wider experience in delivering effective regulatory and compliance support.
We help firms develop arrangements that are proportionate to their risks, regulatory obligations and operating environment.Our work is designed to meet regulatory expectations without introducing unnecessary complexity, customer friction or cost. We also help firms document the rationale for their decisions and demonstrate how the risk-based approach is applied in practice.
We can support firms from initial review and risk assessment through to framework design, implementation, remediation, training and independent assurance. Our engagement models include defined projects, targeted reviews, retained advisory support and, where appropriate, access to wider interim resource capability.
What does financial crime include?
What is a risk-based approach to financial crime?
A risk-based approach requires firms to identify and assess the financial crime risks relevant to their business and apply proportionate controls. Higher-risk relationships may require enhanced due diligence, additional evidence, senior management approval and enhanced monitoring, while lower-risk circumstances may permit simplified due diligence where legally appropriate. Square 4 helps firms implement proportionate, risk-based frameworks that meet regulatory expectations, document key decisions and minimise unnecessary customer friction.
What is APP fraud and what are firms’ responsibilities?
Authorised Push Payment (APP) fraud occurs when a customer is deceived into authorising a payment to a fraudster, for example through impersonation, investment, romance, invoice or purchase scams. Since 7 October 2024, mandatory reimbursement requirements have applied to qualifying APP scam payments made through Faster Payments, with comparable protections for CHAPS, placing obligations on both sending and receiving payment service providers. Square 4 helps firms assess APP fraud risks, strengthen prevention and detection controls, improve customer warnings, investigations and reimbursement processes, and enhance governance, management information and oversight as part of a broader fraud and financial crime framework.
What is the role of the MLRO?
When should a firm carry out a financial crime framework review?
What is a business-wide financial crime risk assessment?
Whether you need an independent review, a stronger risk assessment, revised policies and controls, support with regulatory engagement or access to additional specialist capability, we can help. Contact us for a confidential, no-obligation discussion about your firm’s financial crime requirements.
Sign up to our Insights