Welcome to this month’s Briefing on topical AML matters where I have picked a few of the most recent developments which are impacting AML compliance the most.
There is a version of AML compliance that looks exactly right on paper and achieves almost nothing in practice. Firms that built that version are finding out this month that the FCA has run out of patience with it. The pattern across this edition is not coincidental. The regulator is no longer asking whether policies exist. It is asking whether anyone in a position of authority actually understood their firm’s risk profile, and whether the controls they had in place would have caught a problem before it became an enforcement case. In most of the cases landing this month, the answer was no. The question for every reader is whether they can honestly say their firm’s answer would be different.
01FCA · Enforcement
FCA is now a financial crime regulator in all but name
As at 31 March 2026, the FCA had 127 open enforcement operations involving 218 individuals and 108 firms, and delivered 47 enforcement outcomes in 2025/26, up from 42 the previous year. More than 75% of that activity now focuses on financial crime. The message from both the July 2026 asset management review and the April 2026 CDD review is consistent: the FCA is no longer primarily testing whether firms have the right policies. It is examining whether senior management understands the firm’s own risk profile, and whether controls work in practice rather than on paper.
What this means: Firms that treat AML as a documentation exercise are operating with material exposure. If your MLRO cannot demonstrate active engagement with the firm’s risk profile rather than sign-off on documentation someone else produced then that is the gap the FCA is now finding and acting on.
Read: AML Intelligence →
02UK Gambling Commission · Enforcement
QuinnBet ordered to pay £609,104 for AML and controls failures
The UK Gambling Commission ordered QuinnBet (Gibraltar) Limited to pay £609,104 on 20 August 2026 following a compliance assessment identifying AML and social responsibility failures spanning March 2023 to August 2025. The case details are operationally instructive: a customer with monthly earnings of around £2,000 deposited and lost £9,000 in four days without intervention; another placed approximately 7,000 bets in two days without triggering any internal alert. The Commission’s enforcement director was precise — relying on systems that cannot identify and respond to indicators quickly enough is the failure, not simply having inadequate written policies. QuinnBet cooperated early and voluntarily reported some failings, resulting in a settlement rather than a contested penalty.
What this means: A system that cannot respond quickly enough is not really a compliance system. If your monitoring parameters have not been stress-tested against scenarios like these, they have not been tested at all.
Read: Gambling Commission →
03FCA · Cryptoassets
FCA publishes final rules for UK cryptoasset regime — AML obligations confirmed
The FCA published its final rules for the UK cryptoasset regime on 30 June 2026, with the full regime coming into force from 25 October 2027. The rules cover admissions and disclosures, market abuse, stablecoin issuance, regulated cryptoasset activities and prudential requirements. For compliance functions, the relevant signal is in what the FCA confirmed it will consult on later in 2026: updates to the Financial Crime Guide specifically addressing cryptoasset firms. Until October 2027, the FCA’s oversight of crypto remains limited to financial promotions and AML controls. Firms with any cryptoasset exposure should be treating the published rules as a compliance programme starting point now, not when the authorisation window opens.
What this means: Firms with any cryptoasset exposure and treating October 2027 as the start date for compliance preparation are already behind. The AML obligations are not new, and the FCA’s supervisory expectations are not waiting for the full regime to land. Get ahead and act now.
Read: FCA →
04
AI IN AML
FCA · AI Governance
AI governance in compliance functions is the gap regulators are now examining
Three in four UK financial services firms are already using AI, according to the FCA’s own survey data. The regulatory question has moved on from whether firms can use it to whether they can prove it is working correctly. The FCA has made clear it will not introduce AI-specific rules; instead it expects firms to demonstrate that existing frameworks — Consumer Duty, SM&CR, SYSC and operational resilience requirements — already cover their AI use. The gap the FCA is finding is not in AI deployment but in AI governance: firms have deployed tools without integrating them into model risk or compliance governance frameworks. For MLROs, the practical priority is a documented AI use policy covering which tasks AI assists with, what review process applies before AI-assisted outputs are used, and how that review is evidenced.
What this means: The accountability sits with senior management now, under existing frameworks. The gap is more internal than regulatory. A documented AI use policy covering what AI assists with, what review process applies, and how that review is evidenced is essential.
Read: SureCloud →
05
One to Watch
Egmont Group · Typologies
Egmont Group flags money laundering risks across environmental crime
The Egmont Group published a typologies alert on 21 August 2026 flagging money laundering risks associated with environmental crime — covering illegal wildlife trafficking, illegal logging, illegal mining and waste crime. Environmental crime generates an estimated $110 to $281 billion in criminal proceeds annually and is the fourth largest criminal enterprise globally. For regulated firms the relevance is real and present: the same correspondent banking channels, trade finance structures and shell company mechanisms used to launder proceeds from other predicate offences are used here. If your transaction monitoring and customer risk assessment processes do not include environmental crime typologies as a recognised risk category, they have a gap.
What this means: If your transaction monitoring and customer risk assessment processes do not include environmental crime typologies as a recognised risk category, you have a category of risk with no detection coverage. Worth checking now to see if a gap in your coverage might exist.
Read: Egmont Group →
The Bigger Picture
The thread running through this edition is the gap between what firms have on paper and what they can demonstrate in practice. The FCA is closing that gap by force. The Gambling Commission is closing it by scrutinising individual transactions. The Egmont Group is widening the definition of what practice needs to cover. I do not think this is a temporary period of heightened scrutiny that will ease. I think it is the permanent operating environment for compliance functions.
The firms that are comfortable in this environment built compliance programmes that actually work, not programmes that satisfy a checklist. The question worth sitting with is which one yours is.
News from Clients and Associates
The organisations I work with are adapting to the same governance-led compliance environment this edition covers. Here is what is happening in our network.
Neotas
Named Best-of-Breed in the Chartis Watchlist and Adverse Media Monitoring Solutions 2026 report and recognised as an Enterprise Solution in the Chartis RiskTech Quadrant for TPRM Solutions 2026, Neotas is an AI-led due diligence and third-party risk platform covering 600 billion archived web pages, 1.8 billion court records and 40,000 media sources globally. As third-party risk shifts from a periodic compliance exercise to a continuous governance obligation, Neotas is built for that operating environment. neotas.com
LGCA
The London Governance and Compliance Academy, delivered through the EIMF platform, provides accredited professional qualifications and CPD-eligible courses in AML, KYC, sanctions and compliance governance. Its AML Regulatory Compliance Updates course specifically tracks the EU’s AMLA package and its implications for practitioners across EU financial centres — directly relevant to the AMLA developments covered in our August edition. Courses are recognised for CPD by CISI, ACAMS and CySEC. lgca.uk
AccountingCPD
For over twenty years, AccountingCPD has served accountants across IFAC-registered professional bodies with high-quality verifiable online learning. As the FCA moves toward consolidated AML supervisory responsibility for the accountancy sector, AccountingCPD’s compliance and AML course catalogue — covering regulatory frameworks, customer due diligence, financial crime and practice management — is directly relevant to the professionals now facing that supervisory transition. accountingcpd.com
LearnFormula
A global professional development marketplace registered with over 327 associations and regulatory bodies across 29 markets, LearnFormula provides CPD courses, podcasts and programmes for compliance, risk, legal and finance professionals. Its automatic credit-mapping across regulatory bodies and real-time compliance tracking makes it practical for professionals managing designation requirements across multiple jurisdictions. learnformula.com. I recently recorded three one-hour, CPD-accredited talks on how AI is being used in practice in AML compliance frameworks including the governance challenge discussed above. The talks can be found here.
If anything in this edition raises a question for your firm, feel free to get in touch directly.
Michael Harris
Founder, The Compliance Briefing