CACEIS censure: the sub-custodian's register check becomes a board-level control
The FCA has censured CACEIS UK and secured a £31.7m voluntary payment to WealthTek clients for failing to act on Financial Services Register information showing the firm was not authorised to hold client assets. The case redraws supervisory expectations for asset servicers and forces boards to treat permissions monitoring as a frontline financial crime control.
The FCA's censure of CACEIS UK closes a thirteen-month investigation that should unsettle every asset servicing bank in the UK. The regulator confirmed on 25 June that CACEIS UK will make a £31.7m voluntary ex-gratia payment to WealthTek clients after checking the Financial Services Register on three occasions, seeing that WealthTek was not authorised to hold certain client assets, and still opening client accounts without sufficient action (FCA). The FCA would otherwise have imposed a £23,091,000 penalty after a 30% settlement discount (FCA). With Barclays already fined £3,093,600 and Sapia Partners also actioned, total recoveries for WealthTek clients now exceed £57m (FCA).
The permissions perimeter as a financial crime control
The substantive finding is the more important one for boards. CACEIS UK became WealthTek's sub-custodian in November 2020 and was responsible for keeping client assets safe (FCA). The FCA's case is not that the firm missed an exotic typology. It is that CACEIS UK looked at the public register, saw a permissions mismatch, and proceeded anyway, then failed to monitor alerts its own systems generated (FCA). Therese Chambers, joint executive director of enforcement and market oversight, framed it bluntly: "Strong financial crime controls keep clients' assets safe. CACEIS UK's failures exposed clients to serious risk" (FCA). Permissions verification has moved from onboarding hygiene to a recurring control whose failure now carries eight-figure consequences.
Cooperation arithmetic and the new enforcement tempo
The second message is procedural. The FCA closed this investigation in thirteen months and explicitly cited it as evidence of improving pace (FCA). The cooperation premium is also clearer than before: CACEIS UK avoided a fine entirely by agreeing to a voluntary payment roughly 37% above what a settled penalty would have produced, with the money routed to harmed clients rather than the Treasury. For general counsels and heads of enforcement response, the calculus is now legible. Early, extensive cooperation plus direct consumer redress buys a censure rather than a Final Notice headline penalty, but the cash outlay is larger and goes to the people affected. Boards weighing settlement strategy in live investigations should model both branches explicitly.
What this changes for asset servicers and their clients
The ripple effects extend beyond custody. Any firm that relies on another's regulatory permissions, prime brokers, platform providers, payment institutions banking smaller firms, fund administrators, now operates under a clearer standard: a Register check that surfaces a discrepancy is not a record to file, it is a trigger to act. Distribution of the £31.7m reinforces the point. WealthTek's administrators will receive £30.9m and the FSCS £800,000, with surplus to be distributed under the Compensation Sourcebook (FCA). The criminal trial of John Dance, WealthTek's former principal partner, is scheduled for September 2027 at Southwark Crown Court (FCA), meaning the supervisory narrative will be live for another eighteen months.
For senior leaders, the practical implication is narrow and uncomfortable: the cheapest financial crime control in the building, checking the public register and acting on what it says, is now one the FCA will price at tens of millions when it fails.
Sources
What this reveals
CACEIS UK had the disconfirming evidence in hand three separate times and still proceeded, which is the signature of a control that exists on paper but has lost its authority to stop a commercial relationship in motion. The underlying failure is not technical: it is that a routine operational check was never treated as a decision gate with the standing to override onboarding momentum, and internal alerts were allowed to accumulate without escalation. Other asset servicers and sub-custodians almost certainly hold the same assumption, that permissions verification is a compliance formality rather than a frontline financial crime control, and will only discover the divergence when a supervisor asks why the register was checked but not acted upon. The broader point is that regulators now treat the gap between what a firm knew and what it did as the enforcement trigger, and cooperation arithmetic has shifted the calculus toward voluntary redress rather than settled fines.
Questions accountable leaders should ask
- 01When one of our operational teams checks an external register or data source and finds a mismatch, who has the standing to halt the relationship, and has that authority ever actually been exercised?
- 02How many alerts generated by our own monitoring systems are currently unresolved, and does the board see that figure or only the ones that were closed?
- 03If a regulator asked us to reconstruct every permissions check performed on our top twenty counterparties in the last three years, could we produce the evidence and the decisions that followed?
- 04Do we treat permissions verification as onboarding hygiene that expires at go-live, or as a recurring control with defined review triggers and escalation paths?
- 05Where else in our control environment does the same pattern exist, a check that is performed, logged, and then not acted upon because the commercial relationship is already in motion?
What accountable leaders should do now
- 1Commission an immediate review of every control where the firm relies on external register or authorisation data, mapping who performs the check, who receives the output, and who has authority to stop or unwind a relationship on the basis of what it shows.
- 2Audit the backlog of unresolved internal alerts across custody, client assets and financial crime systems, and require the executive committee to see aging and disposition data at every meeting until it is cleared.
- 3Reclassify permissions monitoring as a recurring control with defined refresh cadence, board-level metrics, and named senior manager accountability under SM&CR, rather than an onboarding task that closes at go-live.
- 4Stress-test the cooperation posture in advance by agreeing, at board level, the criteria under which the firm would move to voluntary redress rather than contested settlement, so the decision is made deliberately rather than under enforcement pressure.
- 5Run a pre-mortem on the three or four counterparty relationships where commercial momentum is most likely to override a control signal, and identify what evidence would need to surface for the firm to act on it rather than rationalise past it.
Explore the practical guide
This guide explains what regulators actually look for when they test whether a decision was sound, and how to build that evidence before you need it. After reading, you will know how to structure, document, and stress-test decisions so they hold up under supervisory scrutiny or enforcement review.
Read the guideWhere internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder ProximityRelated insights
Bailey's Daily Mail letter: cyber resilience becomes a public accountability test
Governor Andrew Bailey has taken the unusual step of publishing an open letter defending the Bank of England's cyber defences while escalating warnings about frontier AI risks to the financial sector. For senior leaders, the letter reframes cyber and AI resilience as a matter of public accountability, not just supervisory compliance.
The £4.2m data lesson: PRA signals reporting integrity is a board matter
The PRA has fined HDI Global SE £4,165,000 for three years of inaccurate FSCS Liabilities and Fee Tariff submissions, citing failures in process, accountability and oversight. For senior leaders, the case reframes regulatory reporting from a back-office chore into a governance test with direct financial and reputational consequences.
Motor finance in limbo: the Tribunal reshapes the redress calendar
The Upper Tribunal has partially suspended the FCA's motor finance redress scheme pending legal challenges to be heard in December 2026 or February 2027. For lenders, brokers and their boards, the pause changes the sequencing of provisioning, communications and operational readiness without removing the underlying exposure.
Stakeholder Signals
Consequential developments in financial services and other regulated markets, with one implication for accountable leaders.
