FINDINGS FROM AN FCA REVIEW
As part of their wider financial-crime supervisory work, the Financial Conduct Authority (FCA), have set forth their findings following a multi-firm review focusing on Business Wide Risk Assessment (BWRA), together with Consumer Risk Assessment (CRA), carried out over the course of 2025.
The firms evaluated in the review included a blend of building societies, platforms, custody, and wealth management, comparing each of their BWRA and CRA processes, systems, and controls. The review was executed utilising questionnaires, desk-based analysis of policies and procedures, together with firm interviews. In addition, the FCA incorporated findings from other, recent individual firms’ reviews.
The three primary targeted areas were how firms:
1. Identify, understand and assess risk.
Here, the FCA discovered that where a majority of firms have BWRA, there were a few examples of purely tailoring the BWRA to the specific business area and omitting relevant further potential risks business-wide.
It was noted that larger firms appeared to integrate risk-assessment undertakings into business functions and forming aggregated view across the entire firm.
The regulator airs concerns though that some firms could not explain adequately how they are managing and mitigating identified risks.
On the flip side, the FCA was impressed and encouraged to find that several firms displayed how they utilised risk-appetite, BWRA and CRA processes working together in order to identify and assess firm risk.
Some further good practice points noted and expected by the regulator within Comprehensive Risk Assessments were:
-Where the assessment was both quantitative and qualitative.
-The firm taking into account a relevant range of internal and external factors.
-The firm ensuring that the assessment is weighted accordingly
Additionally, within its BWRA, a firm must observe:
-Inherent risks
-Effectiveness of controls and procedures
-Residual risks.
Furthermore, firms must carefully assess their BWRAs on an annual basis as opposed to simply refreshing the current BWRA, as has occurred on several occasions, thus displaying an element of carelessness and languor.
Risk Assessments should be bespoke to the individual firm, their products and customers, not employing general templates that are obscure in many places, whilst also making sure that the firm documents how they are managing said risk/s.
Some further inadequate practices noted by the FCA, which will need to be addressed
immediately they are brought to the attention of the firm/s, included lack of attention to detail.
Some of the BWRAs reviewed, oversimplified the potential risks that they could be exposed to by focusing wholly on fraud or generic risk whilst paying little or no attention to vital elements suchlike specific money-laundering, sanctions, anti-bribery and corruption, proliferation financing and terrorist financing.
Firms were also discovered to omit clarification as to how each risk could/would affect the company.
A portion of firms were guilty also of providing obscure methods as to how they identify and assess inherent risks, in the process displaying very little clarity or confidence in their procedures.
In addition, several companies were declaring themselves as low-risk firms without appropriate evidence or explanations to underpin said statement, plus some proclaimed that their controls and systems were ample without evidence to support this.
2. Appropriately mitigate risk.
Under this category, one of the glaring oversights noticed by the regulator was the fact that a minimal number of firms documented what measures they have in place, if they indeed do have any, to mitigate harm within their risk assessments.
However, they did observe some firms concentrating on whether their staff, technology and training were suitable for the size of the business, risks posed and whether it can all be scaled up as the business evolves.
Some other positive signs discovered included, as previously mentioned, firms contemplating the capacity of their compliance and financial crime functions to reinforce the current and future growth strategy.
Another plus point was where firms included their BWRA flowing into their risk-appetite, controls testing and the overall risk-based approach.
Alongside this were instances of the CRAs directly impacting the firms: -Customer due diligence. -Transaction monitoring. -Other processes and controls used to mitigate identified risks.
Some firms formally monitor BWRA actions and explore recommendations on how the firm plans to mitigate, or at the very least, reduce the overall risk, on top of appraising crime risks in product development, business strategy and growth.
Some noted poor practices discovered included a lack of development in the CRAs to operate in line with business growth, thus failing to achieve scalability, consistency and accuracy. In addition, there were examples of firms keeping no records of BWRA actions, no consideration regarding controls remaining suitable in the face of rapid expansion.
3. Effectively manage risk.
Although a majority of firms reviewed appreciated the importance of appropriate governance and oversight to ascertain risk awareness and rigorous risk assessment, in most cases it appeared that the senior management of these firms displayed only better understanding of fraud risk to the detriment of the many other mutations of financial crime dangers.
Some of the decent practices of note included, in addition to consideration of documentation of their risk assessments and the method of sharing it, were where the firm has recorded risk assessment debates and discussions, approvals and changes.
Furthermore, it was happily noted where BWRA and CRA documents are submitted to senior management and committees for review and approval, as should be the case, highlighting trends, conclusions, recommendations and actions forthwith.
Additionally, a good few companies were seen to be conducting regular evaluations of their risk assessment models, processes and procedures. These must be undertaken at least quarterly, or on any occasion when a trigger has been activated, ensuring that the firm is ready and able, and shall be responsive to any emerging risks, along with any alterations in regulatory requirements.
On the other hand, poor practices included not documenting senior management forums, challenges, approvals and disapprovals of BWRAs.
Testing reared its ugly head once again too, with numerous firms actioning little or limited testing, or indeed initiating no testing at all, of their risk assessment processes when they have introduced enhancements and/or upgrades.
Some approaches to assessment were severely lacking also, with insufficient dynamics, in turn resulting in outmoded risk profiles which could then lead to misinformation drip feeding into the firm’s business strategy.
CHECKLIST
✓ Do ensure that the comprehensive risk assessment is both quantitative and qualitative, considering internal and external factors. being certain that it is weighted accordingly.
✓ Do ensure that the BWRAs include inherent and residual risks and are formally assessed on an annual basis, not simply refreshing the current BWRA.
✓ Do clarify and display that your risk assessment is bespoke to your firm and not constructed using a general template.
✓ Do be sure to document how you are managing risk, in a clear and concise manner, without oversimplifying it.
✓ Do be clear and confident regarding the methods used when identifying and assessing risk.
✓ Do have in place comprehensive methods of mitigation, ensuring to document it in full.
✓ Do ensure that senior management are knowledgeable in all aspects of financial crime and not just concentrated on certain areas, i.e. fraud.
✓ Do ensure regular reviews of the firm’s risk assessment model. These should be at least annually or if there are any changes in regulations or in the firm’s business model.
If you would like further information or clarity regarding the above, please contact either myself chris@ossconsult.co.uk or rod@ossconsult.co.uk
Chris Watts November 2025