Skip to main content

Sanctions controls: the FCA's £37bn reality check for boards

The FCA's latest review of sanctions systems credits firms with progress but flags persistent weaknesses in screening, due diligence and frozen-asset management, alongside a new MoU with the trade sanctions regulator. For senior leaders, the message is that sanctions compliance is shifting from a financial-sector discipline to a cross-border trade and intelligence-sharing exercise that boards have not yet fully absorbed.

The FCA has put a number on the UK's sanctions effort - £37bn of assets frozen as of last year - and used it to reset expectations for the firms doing the freezing (FCA). The regulator's latest review, drawing on proactive assessments of more than 150 firms since February 2022, finds genuine improvement in controls but a familiar set of failures: weak due diligence, poor alert management, gaps in transaction and name screening, and sloppy handling of frozen assets and licence conditions (FCA). Published the same day as a new Memorandum of Understanding with the Office of Trade Sanctions Implementation, the review signals that the FCA now expects firms to treat sanctions as a single, integrated discipline rather than a financial crime sub-function (FCA).

A widening perimeter

The most consequential line in the review is almost throwaway: reports still concentrate on Russia, but the FCA is seeing more activity tied to Libya, Iran and North Korea (FCA). That diversification matters because the typologies differ. Russia-related screening has been industrialised over four years; Iran and DPRK exposures tend to involve more complex ownership structures, dual-use goods and trade finance touchpoints where financial controls bleed into export compliance. The FCA itself notes that the range of controls used for trade sanctions is wider than for financial sanctions, and that firms find trade breaches harder to detect and prevent (FCA). Boards that have benchmarked their programmes against Russia-era playbooks should assume those benchmarks are now insufficient.

The OTSI MoU changes the intelligence picture

The new FCA-OTSI MoU, sitting alongside the existing OFSI arrangement, formalises intelligence sharing across the financial and trade sanctions regulators (FCA). For regulated firms, this closes a gap that compliance teams have quietly relied on: the assumption that a trade-side concern raised with a corporate client would not automatically surface in financial supervisory dialogue. It will now. Senior leaders should expect supervisors to arrive with a more complete picture of client behaviour across goods, services and payment flows, and should pressure-test whether their own internal lines - financial crime, trade finance, client onboarding, export controls advisory - share data with anything like the same fluency.

The cost of getting it wrong is operational, not just regulatory

The same week's news that small payment institution SB Remit entered administration after a voluntary undertaking restricting its activities is a reminder that the FCA is willing to constrain firms quickly when controls are inadequate, and that customers of payment firms have no FSCS protection to fall back on (FCA). Sanctions breaches sit in the same category of risk: a single material failure can trigger restrictions that strand customer funds, damage correspondent relationships and force a rapid wind-down. The FCA's decision to publish good and poor practice rather than enforcement statistics is deliberate - it is inviting firms to self-correct before supervisory tools are used.

For C-suites and boards, the practical implication is narrow and immediate. The sanctions function can no longer be governed as a financial-crime sub-committee item benchmarked against 2022 controls. It needs a refreshed mandate covering trade exposures, a tested data-sharing protocol with export-control advisers, and a board-level view of which jurisdictions - Iran and DPRK in particular - are now drawing supervisory attention. Firms that wait for the next thematic review to find out will be doing so on the regulator's timetable, not their own.

What this reveals

The FCA's review exposes a governance lag: firms have industrialised sanctions controls around a Russia-shaped threat model while the regulatory perimeter has quietly widened to Iran, DPRK, Libya and trade sanctions, where the typologies and control requirements differ materially. The underlying problem is that boards are still treating sanctions as a financial crime sub-function, when supervisors, through the new OTSI MoU, now expect an integrated view across financial flows, goods and services. Other leadership teams are likely to assume their controls are 'mature' because Russia-era investment was significant, without testing whether that maturity translates to the new exposures supervisors are actually looking at. This matters because the intelligence-sharing architecture around firms has changed faster than most internal control frameworks have absorbed.

Questions accountable leaders should ask

  • 01Can we evidence that our sanctions screening, due diligence and frozen-asset controls have been recalibrated for Iran, DPRK and Libya exposures, or are we still benchmarking against Russia-era design?
  • 02Do our financial crime, trade finance, onboarding and export controls functions share data with the fluency that supervisors, now armed with cross-regulator MoUs, will expect to see?
  • 03When did the board last receive an assessment of sanctions control effectiveness that distinguished between financial and trade sanctions, rather than treating them as one topic?
  • 04How confident are we that our alert management, licence condition handling and frozen-asset reporting would withstand a proactive FCA assessment tomorrow, not the one we prepared for two years ago?
  • 05Have we tested whether our internal read of 'good' sanctions compliance matches what OFSI, OTSI and the FCA are now jointly looking for, or are we relying on our own maturity narrative?

What accountable leaders should do now

  1. 1Commission a targeted gap assessment that maps current sanctions controls against the specific weaknesses the FCA has flagged: name and transaction screening, alert management, due diligence, and frozen-asset and licence handling, differentiated by jurisdiction and by financial versus trade sanctions.
  2. 2Pressure-test data and intelligence flows between financial crime, trade finance, onboarding and export controls advisory, on the assumption that supervisors will arrive with a joined-up picture and expect the firm to have one too.
  3. 3Refresh the board's sanctions MI so it distinguishes Russia-era exposures from emerging Iran, DPRK and Libya typologies, and surfaces where control coverage is thinner than the aggregate maturity narrative suggests.
  4. 4Validate externally how supervisors are interpreting 'integrated' sanctions compliance in practice, rather than relying on internal legal reading of the review and the MoU, before committing further investment.
  5. 5Set an explicit expectation, recorded in board minutes, that sanctions compliance is now governed as a cross-border trade and intelligence discipline, with named accountability spanning financial crime and trade controls.

Explore the practical guide

This guide identifies the specific points at which board-level strategic thinking diverges from what regulators actually care about, and how those gaps become visible too late. After reading, you will be able to diagnose the drift inside your own organisation and reset the communication flow before it creates supervisory friction.

Read the guide

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity

Stakeholder Signals

Consequential developments in financial services and other regulated markets, with one implication for accountable leaders.