Annex 1 firms under the microscope: the FCA industrialises AML scrutiny
The FCA has contacted all registered Annex 1 firms as part of a sector-wide financial crime review, warning that group controls and off-the-shelf procedures will not suffice. For senior leaders at regulated firms doing business with unregulated lenders, safe custody providers, money brokers and financial leasing companies, the due diligence bar has just risen.
The FCA has moved from sampling to saturation. With an information request now issued to around 900 Annex 1 firms, following earlier work with 300 firms in late 2025, the regulator has effectively contacted every registered firm in the sector (FCA). The message to boards is blunt: registration is not a formality, and reliance on parent company controls will not hold.
Key Executive Takeaways
- The FCA has written to all registered Annex 1 firms, including unregulated lenders, safe custody providers, money brokers and financial leasing companies, and is scrutinising new registration applications more closely, meaning longer approval timelines and higher evidential bars.
- Regulated firms transacting with Annex 1 counterparties are expected to conduct enhanced due diligence and seek direct confirmation of registration status, shifting AML risk assessment onto the wholesale and lending relationships desk.
- Group-level financial crime controls and generic procedures are explicitly insufficient: each entity must demonstrate tailored controls proportionate to its own business model and risks.
A supervisory posture, not a one-off exercise
The FCA's statement, published on 7 August 2026, frames the intervention as ongoing intelligence-gathering rather than a discrete thematic review (FCA). The regulator's concerns cluster around two axes: firms leaning on parent company frameworks without local calibration, and unregulated lending routed through special purpose vehicles and other complex structures. Both are recognisable patterns in private credit, asset-backed finance and bespoke lending arrangements that have expanded materially in recent years.
The operational consequence is that firms should expect registration applications to take longer, and that intelligence from the 900-firm information request will feed disruption activity (FCA). For boards, that means the population of counterparties a regulated firm deals with today may look different in twelve months, either because firms exit voluntarily or because the FCA acts on what it finds.
The counterparty due diligence problem
The more immediate question sits with regulated firms doing business with the Annex 1 population. The FCA has explicitly told regulated firms to continue due diligence and to seek direct confirmation of registration status (FCA). That is a higher standard than checking a public register: it implies live confirmation, documented enquiry, and an assessment of the counterparty's own controls rather than trust in its group affiliation.
Banks providing warehouse lines to unregulated lenders, custodians onboarding safe custody providers, and prime brokers or clearing banks servicing money brokers should read this as a direct instruction. The exposure is twofold: reputational, if a counterparty is later disrupted, and supervisory, if the firm's own AML controls are judged to have accepted comfort where scrutiny was warranted.
Governance implications for group structures
The insistence that each entity assess whether parent controls are appropriate to its own financial crime risks cuts against a common cost-efficiency model in financial services groups (FCA). Shared services and centralised MLRO functions remain permissible, but the burden of proof has shifted. Boards of subsidiaries within a group perimeter need documented evidence that the controls they inherit are calibrated to their specific activities, customers and geographies.
The wider signal is that the FCA is willing to use its AML supervisory tools to reach parts of the market that sit outside conduct authorisation. For senior leaders, the practical implication is that counterparty risk and financial crime risk are converging, and the diligence file needs to reflect that.
What this reveals
The FCA's shift from sampling to saturation exposes a widespread assumption in regulated firms that registration status and group affiliation are adequate proxies for counterparty financial crime risk. Many leadership teams have delegated Annex 1 counterparty oversight to onboarding checklists and public register checks, and have not tested whether their own AML framework would withstand a supervisor asking what they actually know about each counterparty's tailored controls. The deeper issue is a divergence between the regulator's live posture and the firm's static assumptions about what 'registered' means, which is precisely the kind of gap that hardens into a supervisory finding before internal teams notice it has opened.
Questions accountable leaders should ask
- 01When did we last test whether our due diligence on Annex 1 counterparties goes beyond register checks and group-level assurances to look at the specific entity's own controls?
- 02If the FCA asked us tomorrow to evidence how we confirm registration status and assess tailored AML controls for each Annex 1 counterparty, what would the record actually show?
- 03Where in our own group do we rely on parent-level financial crime frameworks without local calibration, and would that reliance survive the same scrutiny the FCA is now applying?
- 04Do we know which of our current counterparties are most exposed to the FCA's disruption activity over the next twelve months, and what our exit or remediation path looks like if they fall away?
- 05Who inside the firm owns the assumption that our counterparty AML risk is stable, and when was that assumption last challenged with external evidence?
What accountable leaders should do now
- 1Commission a rapid gap analysis of Annex 1 counterparty due diligence against the FCA's stated expectations, focusing on evidence of direct registration confirmation and entity-level control assessment rather than group reliance.
- 2Identify the subset of counterparties whose loss or restriction would create material commercial or operational disruption, and pressure-test contingency arrangements before the FCA's disruption activity reaches them.
- 3Require the MLRO and relevant business heads to jointly present, to the board or risk committee, a refreshed view of Annex 1 counterparty risk, including where existing frameworks lean on group controls that would not withstand supervisory challenge.
- 4Update onboarding and periodic review procedures to embed live confirmation of registration status and documented enquiry into entity-specific controls, and set a deadline for retrofitting this to the existing counterparty book.
- 5Establish a standing intelligence line on FCA financial crime supervisory posture so that shifts in expectation reach the accountable executive before they surface in correspondence.
Explore the practical guide
This guide sets out how senior leaders at FCA regulated firms should identify, assess and manage stakeholder risk in a way that stands up to supervisory scrutiny. After reading, you will know how to structure a stakeholder risk framework that connects to Consumer Duty, SM&CR accountability and board-level reporting.
Read the guideWhere internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder ProximityRelated insights
Dunne and Fenech: the Tribunal recalibrates FCA penalties, not principles
The Upper Tribunal upheld the FCA's bans on two individuals central to a £126m defined benefit pension transfer scandal, but cut their fines after finding only 18% of advice was unsuitable, not all of it. For senior leaders, the ruling clarifies how enforcement outcomes will be tested on evidence, and reinforces that dishonesty toward the regulator remains a career-ending line.
Vertical integration in insurance: the FCA puts ownership structures on notice
The FCA's new insurance director has written to firms whose vertically integrated business models create heightened conflicts of interest, warning that disclosure alone is insufficient. For boards of insurers, brokers and their private equity backers, the letter marks a shift from theoretical concern to active supervisory pressure on ownership design itself.
Prosper's collapse: when the appointed representative bill comes due
Prosper Capital LLP has entered creditors' voluntary liquidation after the Financial Ombudsman upheld complaints against property investments sold by its appointed representative, Crowd2Let Capital. The failure crystallises a pattern regulators have been signalling for two years: principals cannot outsource accountability, and boards that treat AR oversight as a compliance formality are underwriting a contingent liability.
Stakeholder Signals
Consequential developments in financial services and other regulated markets, with one implication for accountable leaders.
