The FCA's bid for legal and accounting AML supervision: what changes for regulated firms
Steve Smart used the Law Society Economic Crime Conference to signal the FCA is ready to take on anti-money laundering supervision of the legal and accounting sectors. For financial services leaders, the move reshapes the intelligence-sharing perimeter and raises the bar on what 'partnership' with the regulator now requires.
The FCA has put its hand up for a significantly larger AML remit. In a speech at the Law Society Economic Crime Conference on 17 September, Steve Smart, executive director of enforcement and market oversight, declared the regulator ready to supervise the legal and accounting sectors, framing the pitch around expertise, intelligence-led supervision, and a promise to target enablers rather than compliant firms (FCA).
Key Executive Takeaways
- The FCA is positioning to become the AML supervisor for legal and accounting firms, extending its intelligence reach into the professional services that sit alongside banking flows.
- Financial services firms should expect greater regulatory expectation to share intelligence under the Economic Crime and Corporate Transparency Act, with the NCA's data fusion programme cited as the operating model.
- Enforcement posture is hardening in parallel: the FCA's 10 September operation against illegal peer-to-peer crypto trading shows the same intelligence-led approach applied on the ground.
A supervisory expansion with second-order effects
Smart's framing matters as much as the ask. He anchored the case in scale, citing fraud as nearly half of all crime in England and Wales last year and estimates that over £100bn is laundered through or within the UK annually (FCA). If the FCA succeeds in absorbing supervision from the current patchwork of professional body supervisors, banks and asset managers gain a single counterparty for intelligence on the lawyers and accountants who structure client transactions. That is a material change in how suspicious activity flows are triangulated. It also means that the professional advisers sitting between a bank and its client will, over time, be held to a supervisory standard the bank's own MLRO can more readily interrogate.
Partnership is being redefined as an obligation
Smart's repeated emphasis on partnership is not rhetorical. He explicitly backed the NCA's data fusion programme, which combines banking data with law enforcement and regulatory intelligence, and pointed to the Economic Crime and Corporate Transparency Act as the safe route for firm-to-firm information sharing (FCA). Senior leaders should read this as a shift from voluntary cooperation to expected participation. Firms that opt out of intelligence-sharing mechanisms will increasingly look like outliers when supervisory conversations turn to systemic controls.
Enforcement is running in parallel, not sequentially
The same day Smart delivered his speech, the FCA publicised a coordinated operation with HMRC and the Metropolitan Police Service, targeting three London premises suspected of illegal peer-to-peer crypto trading and issuing cease and desist letters on 10 September 2026 (FCA). Smart's warning that 'Anyone running an unregistered peer-to-peer crypto business should assume we are looking at them' is a signal that the intelligence-led model is already producing operational output (FCA). There are currently no FCA-registered peer-to-peer crypto businesses operating in the UK, which sharpens the perimeter considerably (FCA).
What senior leaders should do now
Three practical implications follow. First, banks and insurers should audit their exposure to professional services intermediaries on the assumption that supervisory standards for those firms will rise, and rise under a familiar regulator. Second, boards should ask MLROs whether the firm is an active participant in NCA data fusion and ECCTA information-sharing gateways, or a passive recipient of typologies. Third, given the parallel enforcement cadence on crypto, firms with any exposure to peer-to-peer flows should assume the FCA's operational tempo will continue. The hive metaphor Smart borrowed from the Bank of England Museum is doing real work: the regulator is telling the market that every actor is expected to check what comes through the door, and the cost of not doing so is about to become more visible.
Sources
What this reveals
The FCA's bid signals that supervisory perimeters and intelligence expectations are being redrawn faster than most firms' internal assumptions about what 'partnership with the regulator' means. Leadership teams who still treat information-sharing as discretionary, or who have modelled their financial crime posture around the current supervisory patchwork, may be operating on a picture of the regulatory environment that is already out of date. The deeper issue is that supervisory signalling now moves through speeches, coordinated operations and data fusion programmes well before it appears in rulebooks, and firms reading only the formal text will be late. This matters beyond AML because it illustrates a wider shift: regulators are defining participation, not just compliance, as the standard.
Questions accountable leaders should ask
- 01When did we last test whether our MLRO's view of 'good' intelligence-sharing matches what the FCA and NCA now expect in practice, rather than what the rules literally require?
- 02If the FCA became the AML supervisor for the legal and accounting firms in our client and counterparty base, which of our current control assumptions about those advisers would need to change?
- 03Are we actively participating in ECCTA-enabled information sharing arrangements, or have we defaulted to caution in a way that will make us look like an outlier in the next supervisory conversation?
- 04How would we know if our board's picture of the regulator's posture has drifted from the posture supervisors are actually signalling through speeches, enforcement actions and data programmes?
- 05Where in our financial crime framework are we relying on the current supervisory perimeter holding, and what breaks if it doesn't?
What accountable leaders should do now
- 1Commission a short, dated read of FCA and NCA signalling over the last 12 months on financial crime partnership, and compare it explicitly to the assumptions embedded in your current AML and intelligence-sharing policies.
- 2Ask the MLRO and General Counsel to jointly map where the firm is, and is not, participating in ECCTA-enabled information sharing, and to bring a recommendation to the risk committee on closing any participation gap.
- 3Stress-test the firm's reliance on legal and accounting counterparties by identifying which relationships would be materially reframed if those advisers moved under FCA AML supervision, and what that means for onboarding and ongoing due diligence.
- 4Add a standing item to board or risk committee papers that tracks supervisory signalling (speeches, coordinated operations, data programmes) alongside formal rule changes, so the board is not reading only the codified text.
- 5Before the next supervisory engagement, pressure-test how the firm's financial crime posture would be described by an outsider: as an active partner in the intelligence system, or as a compliant but passive participant.
Explore the practical guide
This guide sets out how senior leaders at FCA regulated firms should identify, assess, and manage stakeholder risk in a way that stands up to supervisory scrutiny. After reading it, you will know how to structure a stakeholder risk framework that aligns with Consumer Duty, SM&CR, and Threshold Conditions, and where firms typically fail.
Read the guideWhere the operating environment may be moving faster than internal reporting reflects
Polar Insight's Signal Briefings translate emerging regulatory, stakeholder, and market developments into a clear implication for accountable leaders.
Explore Signal BriefingsRelated insights
Customs reference documents on a two-month cycle: the compliance load nobody budgeted for
HM Treasury and HMRC have issued another round of updates to the UK's authorised use, tariff suspension and import duty relief reference documents, with new versions taking effect on 1 October 2026. For regulated firms with trade finance, supply chain and treasury exposure, the cadence itself is now the governance issue.
A7 alert and doubled OFSI fines: the new sanctions perimeter for UK finance
The UK has issued its first industry-wide alert against Russia's A7 sanctions evasion network and doubled the maximum OFSI penalty to 100% of breach value. Senior leaders in banking, payments and asset management now face a materially higher enforcement bar and explicit expectations to screen for third-country conduits.
238,000 suspected money mule accounts: why account closures are not the win banks think
The FCA's latest survey shows firms closed 238,396 suspected mule accounts in 2025, but criminals are still cashing out between the second and fifth account in the chain. For senior leaders, the data reframes mule controls as an intelligence-sharing problem, not a volume metric.
Stakeholder Signals
Consequential developments in financial services and other regulated markets, with one implication for accountable leaders.
