THE AML COMPLIANCE BRIEFING PRACTICAL INTELLIGENCE FOR COMPLIANCE PROFESSIONALS |
THE BRIEFING |
|
| 1 October 2026 |
|
Welcome to this month’s Briefing on topical AML matters, where I’ve picked the September developments I think will have the most impact on your compliance programme. One figure from September has stayed with me. Reviewing a single client file at Euro Exchange Securities, the FCA found 4,968 transaction monitoring alerts closed as not suspicious, and 3,294 of them had no documented rationale. Only one alert in that file had ever been escalated. In the same month the government published a three-year AML strategy that promises to cut low-value "box-ticking" work, and OFSI fined Citibank’s London branch £4.73m in a case where an escalation about a designated person’s ownership went to the wrong team and was closed without further action. I think those stories belong together. The strategy wants firms to spend less effort on process for its own sake. The enforcement cases show what regulators actually test when they open a file: whether anyone can show the reasoning behind each decision. If the burden does ease over the next three years, I expect the scrutiny of that reasoning to rise with it. |
Six items this month across AML policy, sanctions, enforcement, cryptoassets and two takes on AI in AML. Each item links to the primary source. |
|
01 |
HOME OFFICE · HM TREASURY · POLICY
The new AML strategy commits the money to enforcement now and the relief to consultation later On 15 September the Home Office and HM Treasury published the Anti-Money Laundering and Asset Recovery Strategy 2026–2029. It’s backed by at least £550m over three years, £520m of it from the Economic Crime Levy and £30m from the high streets package announced at Budget 2025, together with more than 500 new officers. The strategy is built on three pillars: Target, Integrate and Empower. For regulated firms, the Target pillar is the chapter to read. The government says too much private-sector activity is still focused on low-value tick-box compliance, and it holds up July’s narrowing of mandatory EDD for high-risk jurisdictions as the model, estimating that change alone saves the regulated sector £178.1m a year. Next come consultations on further MLR changes to reduce low-value activity, a review of the SARs regime that will examine raising the suspicion threshold (for example to "reasonable grounds to suspect"), and a review of Companies House discrepancy reporting. For context, the UKFIU received 866,616 SARs in 2024–25. The same chapter tightens as well as eases. HM Treasury will consult on stronger supervisory enforcement powers, including unannounced visits and a greater ability to hold directors accountable for MLR breaches. A separate consultation will look at bringing property developers, offshore virtual asset service providers, antiques and antiquities dealers, football clubs and agents, and donation-based crowdfunding into scope, alongside changes for letting agents and higher-risk high-value goods dealers. Under Integrate, a new National Financial Intelligence Service in the NCA will bring together JMLIT and Data Fusion, work alongside the UKFIU, and extend the banks’ partnership model to cryptoasset firms, money service businesses and electronic money institutions. The UKFIU is also to get a power to compel information from firms without court approval.
What this means: Nothing in the strategy changes your obligations today. The enforcement money and officers are committed now, while every reduction in burden arrives as a consultation. I’d use the time to identify where your programme spends effort on activity you couldn’t defend as risk-reducing, so you have evidence ready when HM Treasury consults on the MLRs. If you’re an EMI, MSB or crypto firm, expect to be drawn into national intelligence-sharing partnerships, and if you sit on a board, note the director accountability proposals. Worth reading the Target chapter now.
Read: GOV.UK → |
|
|
02 |
OFSI · SANCTIONS
OFSI’s £4.73m Citibank penalty shows where screening breaks under pressure OFSI imposed a £4,732,830.58 penalty on Citibank, N.A., London Branch on 11 August and published the notice on 2 September. The branch processed 970 payments worth £19.72m that OFSI considers breached the Russia Regulations and the Global Anti-Corruption Sanctions Regulations, mostly between February and November 2022. OFSI found no intent to breach sanctions but rated the case Level 4, the top of its seriousness framework, and set a baseline penalty of £7.89m before discounts. The notice is worth reading in full because the failures were ordinary configuration and process gaps that most firms could find in their own systems. The screening system didn’t treat the Russian corporate prefix "PAO" as part of a match, so no alerts fired on PAO Sovcomflot and 328 transactions worth around £5.4m went through. The payment processor screened payments before correspondent banks were added to the chain and never rescreened the full chain. Internal list entries for designated banks lacked their BICs, when the BIC was the only identifier in the payment message. And in May 2022, to manage alert volumes, the bank changed its guidance so that accounts under investigation were restricted only where there was evidence of 50% or greater ownership by a designated person. Two further details stood out to me. An internal money laundering alert identified that a remitter might be owned by a person designated under the anti-corruption regime, but the sanctions escalation went to the wrong team, wasn’t redirected, and the case was closed with no further action. On discounts, the bank received 20% for voluntary disclosure and co-operation, short of the 30% maximum, because breaches worth about £6.9m came to light only after OFSI wrote to it, others were disclosed seven to ten months late, and some initial disclosures were materially incomplete. The 20% settlement discount took the total reduction to 40%.
What this means: Test your screening against legal-form prefixes and transliterations, confirm the full payment chain is rescreened after routing or correspondent insertion, and check that internal lists such as routing tables are themselves screened. Then trace what happens when an AML investigation turns up a sanctions concern: who receives the escalation, and how does the sender know it arrived? If you ever have to disclose, OFSI’s reasoning here shows that completeness and speed decide whether you get 20% or 30%. Worth checking now.
Read: OFSI (GOV.UK) → |
|
|
03 |
FCA · ENFORCEMENT
Euro Exchange Securities: what the FCA found in ten client files On 16 September the FCA announced an investigation into potential offences by Euro Exchange Securities UK Ltd (EES) under the Money Laundering Regulations between 1 February 2020 and 4 June 2026. The electronic money institution was stopped from providing regulated services in June and placed into special administration, and the FCA stresses it hasn’t yet reached any conclusions. Bloomberg, reporting on High Court filings, said the firm handled at least £2bn in payments, almost all of it for 14 clients it had itself rated high risk, and operated more like a correspondent bank than a typical payments firm. The First Supervisory Notice sets out what the FCA found when it requested ten client files in December 2025. Every file was assessed as inadequate. In several, no customer risk assessment was completed before onboarding. Six customers had been rated high risk, yet the firm hadn’t obtained or verified source of funds or source of wealth for any of them. Screening was deficient in six of the ten files; in one, adverse media searches used a misspelling of the customer’s name, and the FCA itself found reporting of an alleged money laundering scheme and an FBI investigation that the firm had missed. Monitoring tells the same story. In one file, 4,968 alerts were closed as not suspicious, 3,294 with no documented rationale, and 294 remained open. The firm confirmed that a single individual was responsible for reviewing alerts. When asked for its records, it produced around 180,000 documents that the FCA found largely unusable, and in system walkthroughs it couldn’t locate evidence of risk assessments, due diligence or monitoring. The FCA concluded that the documentation was either never obtained or never kept, and under regulation 28(16) a firm that can’t demonstrate its CDD was appropriate has failed the test.
What this means: The EES notice reads like a checklist of what a file review looks for. Pull a handful of your own high-risk files and ask whether you could produce the risk assessment, the EDD evidence, the screening results and a rationale for each closed alert within a day. If you bank EMIs or payment firms, look at whether any are acting as de facto correspondents for high-risk clients of their own. The FCA CDD/EDD Action Checklist on The Compliance Briefing’s Resources page covers the same ground. Worth checking now.
Read: FCA → |
|
|
04a |
AI IN AML HOME OFFICE · AI STRATEGY
The AML strategy puts AI on both sides of the ledger The new AML strategy treats AI as threat and tool at once. Drawing on the 2025 National Risk Assessment, it says criminal use of AI remains limited for now, but that the pace of development is expected to give criminals significantly greater capability to evade AML controls. On the government side, the new National Financial Intelligence Service will use AI tools to process large datasets and spot suspicious patterns, and the NCA will build AI into its intelligence workflows alongside the SARs Digital Service. The part that affects firms directly is what the supervisors have signed up to. The FCA will publish examples of good and poor practice on the use of AI during 2026–27 and update its Financial Crime Guide with good practice on AI tools and information sharing. HMRC will run outreach on AI and tech-based compliance tools, and the Gambling Commission will develop policies on AI and new technologies. The strategy ties this to the FCA’s Mills Review, published in July, and to wider use of digital ID in customer due diligence.
What this means: Once the FCA’s good and poor practice examples appear, they’ll become the benchmark supervisors use. If you already use AI in screening, monitoring triage or alert disposition, write down now who owns each model, how its outputs are validated, where a person makes the final call, and how you’d explain a disposition to a supervisor. It’s far easier to document that today than to reconstruct it after the examples are published. Get ahead and act now.
Read: GOV.UK → |
|
|
04b |
AI IN AML FCA · AI GOVERNANCE
The FCA’s frontier AI review asks questions every AML team should answer On 2 September the FCA published findings from a multi-firm review of how frontier AI is affecting cyber resilience, aimed particularly at small and medium-sized firms. It followed the joint statement on frontier AI from the Bank of England, the FCA and HM Treasury in May, and the Bank published a companion article the same day. The review reports what firms told the FCA and sets no new rules. Its central finding is that vulnerability discovery is accelerating faster than firms’ ability to respond, and that governance and human judgement remain critical. The review is about cyber, but its questions transfer directly to AI in AML. The FCA asks who owns decisions about the use of frontier AI, and whether a firm can tell the difference between outputs that are technically plausible and findings that are genuinely exploitable. Swap "exploitable" for "suspicious" and you have the central governance question for any AI-assisted screening or monitoring tool. The warning about volume applies too: a model that surfaces more issues than the team can work through simply moves the backlog somewhere else.
What this means: If you’re introducing AI into AML, use the FCA’s questions as your governance test: named ownership, a way to separate plausible outputs from real findings, and the resource to act on what the tool surfaces. The EES case in Story 03 shows what an unworked alert queue looks like when the FCA opens the file. Worth checking now.
Read: FCA → |
|
|
05 |
ONE TO WATCH FCA · CRYPTOASSETS
The crypto authorisation gateway is open until 28 February Following the final cryptoasset rules covered in last month’s Briefing, the FCA’s authorisation gateway opened at 7am on 30 September and closes on 28 February 2027. The new regime takes effect on 25 October 2027. The FCA published its perimeter guidance, PS26/18, on 16 September, setting out which activities need authorisation. The point that matters for AML teams is that an existing MLR registration doesn’t convert into FSMA authorisation. Registered firms have to apply through the gateway like everyone else. Those that apply within the window can rely on a saving provision and keep operating while the FCA assesses them, while those that miss it face running off their UK business.
What this means: If you bank, pay or partner with cryptoasset businesses, add a question to your periodic reviews: has this firm applied, and when? A counterparty that hasn’t applied by 28 February is one whose UK business may have to wind down. Worth putting 28 February in the diary now.
Read: FCA → |
|
|
THE BIGGER PICTURE The strategy’s promise to cut tick-box work is welcome, and I think it’s sincere. This month’s enforcement cases suggest where the line will be drawn. OFSI’s criticism of Citibank centred on a screening configuration nobody had stress-tested and an escalation nobody followed up. The FCA’s case against EES rests largely on files where the reasoning had never been written down. If supervisors are going to accept less activity, they’ll want more evidence that the activity left is the right activity. That’s the trade I expect over the next three years, and it applies with even more force once AI is making the first pass at alerts. A model can close an alert in seconds. It still has to leave behind a reason a person can read and defend. The firms that come out well will be the ones that can show their judgement, file by file. |
ABOUT THE COMPLIANCE BRIEFING The Compliance Briefing is an intelligence publication for MLROs, compliance officers and financial crime teams at UK-regulated firms. On the 1st of every month I publish The Briefing, a newsletter on the AML developments that matter most in practice, alongside Insights articles and practical Resources such as checklists and reference guides. I also deliver AML and financial crime training as an AGRC Approved Training Partner, and work directly with firms on their financial crime controls. For more information, or to subscribe to The Briefing, visit thecompliancebriefing.com. |
More analysis at thecompliancebriefing.com In-depth articles on AML enforcement, EDD, sanctions, AI governance and UBO identification, written for practitioners. |
Read Insights |
|
If anything in this edition raises a question for your firm, feel free to get in touch directly. Michael Harris Founder, The Compliance Briefing |
HOW I CAN HELP YOUR FIRM
Consultancy AML programme review, gap analysis, MLRO support and financial crime advisory through FCC Consulting Ltd. | | Training Courses Accredited CPD courses covering AML & KYC with AI, AML Technology, TPRM and UBO Identification, via LGCA. | | Intelligence & Content Bespoke compliance intelligence, newsletters and thought leadership for firms and professional bodies. |
|
THE COMPLIANCE BRIEFING This briefing is prepared for information purposes only and does not constitute legal or regulatory advice. Recipients should seek independent advice on specific matters.
You are receiving this because you subscribed at thecompliancebriefing.com. To unsubscribe, reply with ‘Unsubscribe’ in the subject line. |
| |