FCA Sanctions Controls and the Multi-Billion-Pound Challenge

What Should Firms Do Following the FCA’s Sanctions Review?

Following the FCA’s sanctions review, firms should assess whether their sanctions risk assessment, due diligence, screening, alert management, governance, and management information are effective. Firms should also review whether sanctions risk is integrated across investor onboarding, counterparty relationships, custody chains, delegation models, and payment flows.

The FCA’s latest sanctions review of more than 150 firms is not simply another best-practice publication. It provides a clear indication of how the regulator is using thematic reviews to drive higher standards across the market.

Rather than focusing solely on identifying weaknesses, the FCA is signalling the standards it increasingly expects firms to meet: robust governance, effective controls, and the ability to respond quickly to changing risks. Sanctions compliance is no longer a standalone financial crime activity, but a core component of market integrity and operational resilience.

This matters because the sanctions landscape has changed significantly in recent years. Regimes have expanded in scope, complexity, and speed, and firms are obliged to respond just as quickly. For CCOs, COOs, and CTOs at buy-side firms globally, the challenge is no longer just understanding the rules. It is designing an operating model that can adapt quickly, maintain effective controls, and provide clear oversight across the sanctions control framework. As the regulator notes, the total value of frozen assets in the UK has increased from £24.4bn in 2023-24 to £37bn in 2024-25.

Beyond the global policy implications, sanctions regimes affect firms at a practical level, creating financial, reputational, and operational risks. Weak controls can lead to regulatory scrutiny, disrupted business operations, delayed transactions, and increased costs, making sanctions compliance an issue that extends well beyond the compliance function.

FCA Sanctions Review Highlights Recurring Control Weaknesses

The findings of the FCA’s review show that some progress has been made across the industry to address these developing challenges. However, the same control failures continue to appear across different business models and sectors, suggesting that underlying issues remain unresolved. The regulator highlights recurring weaknesses in due diligence, alert management, transaction and name screening, frozen asset handling, and licence compliance. These are not isolated gaps. They sit at the centre of day-to-day operations.

When these controls break down, the impact can be serious. Weak ownership data can undermine screening; poor alert handling can create backlogs; and inconsistent governance can delay escalation. As a result, issues become harder to identify before they trigger regulatory, operational, or reputational concerns.

Sanctions risk should not sit in a single function. It runs through investor onboarding, counterparty relationships, delegation models, custody chains, and payment flows. Firms that continue to treat sanctions as a siloed compliance activity risk creating gaps between teams, systems, and governance. As a result, issues become harder to identify before they develop into regulatory problems. Firms are increasingly expected to understand risks linked to goods, services, and end-use, even where visibility is limited. Compared with financial sanctions, controls in this area are often less mature and more fragmented. This creates a new layer of complexity that many firms are still adapting to.

In practice, this requires a shift towards more integrated compliance frameworks. Firms need to connect risk assessment, due diligence, screening, escalation, and reporting into a single operating model. Technology plays a key role here, particularly where it helps link data, automate workflows, and provide audit-ready evidence.

As with other FCA best-practice publications, senior management oversight is a key focus. The regulator makes clear that governance only works when decision-makers have access to meaningful, timely information.

This is not about simply producing more reports. It’s about providing clear insight into exposure, control effectiveness, and emerging risks so senior leaders can make informed decisions.

Boards and senior managers should be able to answer key questions with confidence:

  • Where is the highest exposure?
  • Which alerts are ageing?
  • How reliable is the underlying data?
  • Where are the control gaps?
  • How quickly can the firm respond to a major sanctions event?

If these questions are difficult to answer, that is a sign the framework needs strengthening.

Practical Steps to Improve Sanctions Controls and Governance

Firms should act promptly to assess whether their processes remain fit for purpose and should consider the following actions:

  • Review the firm’s sanctions risk assessment to ensure it covers the firm’s full range of activities, including cross-border exposure, delegation arrangements, and any trade-related touchpoints.
  • Test screening technology and alert management processes end to end, including list management, escalation processes, quality assurance, and manual override review.
  • Review governance and management information to ensure reporting is concise, relevant, and action-oriented, with clear accountability and a structured approach to challenge and escalation.
  • Assess whether the firm’s technology is enabling or constraining compliance, particularly where fragmented systems and manual processes limit visibility and create inconsistency.

The broader lesson is that sanctions compliance is becoming a measure of operational resilience. Firms that can adapt quickly, evidence decisions clearly, and maintain effective oversight will be better positioned to reduce risk and support long-term growth.

For many firms, this is best achieved through a combination of internal capability and external support. Outsourcing elements of the control framework can provide additional specialist capacity, independent challenge, and more consistent monitoring.

Strengthening Sanctions Controls Requires Specialist Support

Many firms have robust compliance teams but lack the capacity, specialist expertise, or technology to respond quickly to evolving regulatory expectations. Independent support can help strengthen existing frameworks, provide objective challenge, and accelerate improvements without requiring firms to build every capability in-house.

Strengthen your sanctions compliance programme with support across:

  • Financial crime advisory: Assess sanctions risk, review governance and control frameworks, and strengthen policies, procedures, and oversight.
  • Managed compliance services: Supplement your internal team with experienced compliance professionals who can support day-to-day activities and help you respond to evolving regulatory demands.
  • AML and financial crime technology: Strengthen screening, monitoring, adverse media review, and watchlist management with technology that improves efficiency, oversight, and regulatory compliance.

Whether you’re reviewing your sanctions framework, responding to evolving regulatory expectations, or looking to strengthen governance and controls, independent expertise can help you identify gaps, prioritise improvements, and build a more resilient compliance programme.

FAQs About the FCA Sanctions Review and Sanctions Controls

The FCA’s sanctions review highlighted recurring weaknesses in areas such as governance, due diligence, screening, alert management, frozen asset handling, and licence compliance.

Sanctions controls are important for buy-side firms because sanctions risk can arise across investor onboarding, counterparties, delegation models, custody arrangements, and payment flows. 

Firms should review their sanctions risk assessment, screening technology, alert management, escalation processes, management information, and governance reporting.

Technology can support sanctions compliance by linking data, automating workflows, improving screening and alert management, and providing evidence for audit, regulatory, and internal review. 

Senior management should receive clear and timely information on sanctions exposure, control effectiveness, alert backlogs, escalation issues, and emerging risks.