Enforcement actions in AML and financial crime rarely contain surprises for compliance professionals who have been paying attention to supervisory communications. What they do provide is something equally valuable: a documented, public record of exactly how and where a firm's AML programme failed, assessed against regulatory standards rather than the firm's own self-assessment. Reading enforcement decisions analytically, rather than treating them as cautionary tales about other organisations, is one of the most direct routes to improving a compliance programme.

The pattern of findings across recent FCA, OFSI and HMRC enforcement activity in 2025 and 2026 reveals a consistent set of failure modes that appear across firms of different sizes, different sectors and different regulatory contexts. That consistency is itself informative: these are not one-off failures or idiosyncratic lapses, but structural weaknesses in how AML programmes are designed and operated.

The documentation gap

The most common single finding across recent enforcement actions is the absence of documented evidence that required compliance activities actually occurred. This is distinct from, and in many ways worse than, the finding that activities occurred but were performed inadequately. Firms that cannot produce evidence of EDD having been conducted, periodic reviews having taken place, or risk assessments having been updated are in the most difficult position from a regulatory standpoint, because the absence of documentation is treated as evidence of absence of the underlying activity.

The FCA's 2025 multi-firm review of CDD and EDD controls found that some firms failed to produce any evidence that EDD had been conducted at all on high-risk customers, not that EDD was conducted poorly or insufficiently, but that there was no record to demonstrate it had occurred. This finding should prompt every compliance team to ask a direct question: if a regulator asked to see the EDD file for our ten most complex or highest-risk customers today, what would those files contain?

Policy without operational substance

A recurring theme in enforcement findings is the gap between what AML policies say and what they require staff to do. Policies that define enhanced due diligence as a regulatory obligation without specifying what additional steps must be taken, which customer types trigger those steps, and how the results must be documented do not constitute effective AML controls. They constitute a framework for apparent compliance that provides neither genuine protection nor regulatory credibility when tested.

The FCA has been explicit that policies must specify what EDD actually involves for different customer types and risk profiles, not merely state that it will be applied. Firms whose EDD policies say "enhanced measures will be applied" without defining those measures have a material policy gap that is likely to be identified in any regulatory review.

Individual accountability and the MLRO role

Recent enforcement cases involving individual accountability across both FCA and OFSI investigations reflect the growing willingness of regulators to hold senior compliance professionals personally responsible for systemic programme failures rather than treating them as organisational issues alone. The pattern of findings in these cases tends to involve a combination of inadequate governance documentation, failures to escalate known weaknesses to senior management or board level, and compliance functions that had identified their own deficiencies in internal testing but had not ensured remediation was completed.

The practical implication for MLROs and CCOs is that the protection offered by a compliance framework depends significantly on the quality of the paper trail behind it. Governance frameworks that exist in policy but cannot be evidenced in practice, escalation processes that are documented but not used, and testing programmes that identify findings without producing tracked remediation plans all represent the kind of structural weakness that personal accountability analysis will focus on.

What the most effectively defended firms do differently

Firms that have emerged from regulatory scrutiny in a materially better position than their peers tend to share a set of operational characteristics that are not complicated but are consistently applied. Their CDD and EDD files contain structured, documented evidence of each step in the process, including the reasoning behind risk ratings and the specific verification steps taken. Their compliance monitoring programmes identify weaknesses systematically and track remediation against clearly defined owners and timelines. Their MLROs have demonstrably engaged with the results of internal testing and can show that governance escalation actually occurred rather than simply existing on paper.

The enforcement record of 2025 and 2026 suggests that regulators are no longer primarily testing whether firms have the right policies. They are testing whether those policies have been implemented in practice and can be evidenced at the individual file level. The distance between those two questions is where most enforcement exposure currently sits.