The regulator’s July 22 review separates two questions that are often combined. The first is inherent exposure: the ownership structures, customer profiles and cross-border flows that can make financial crime harder to detect. The second is control risk: whether a firm’s assessments, monitoring and governance are designed to identify those exposures.
Private markets scored higher on the exposure measures that the FCA disclosed by business type. The control gaps, however, were generally reported for the entire 242-firm sample. Treating the latter as private-market-only results would overstate what the publication shows.
PEP Exposure Is 3.6x Higher
The FCA reported that 32% of firms active in private markets had PEPs in their customer base, compared with 9% among firms outside private markets. Dividing the two rates produces a descriptive ratio of 3.6 times.
That ratio does not show how many PEP customers each firm served, the value of their investments or whether enhanced due diligence identified any misconduct. The FCA also did not disclose the number of firms in either subgroup, preventing a test of whether the difference is statistically distinguishable from sampling variation.

Ownership complexity points in the same direction, although the two published measures use different thresholds. Around one-fifth of private-market firms said more than 30% of their customers used complex ownership structures. By comparison, 85% of firms outside private markets reported no customers using such structures.
The values are not complements and should not be placed in a single 100% stack. One measures firms above a 30% customer threshold; the other measures firms at zero.

The distinction matters because layered companies, trusts, funds and special-purpose vehicles can extend the path between an investment and its ultimate beneficial owner. The FCA also found that half of the full sample had more than 60% of its customers domiciled overseas, while private-market firms were more likely to process international fund transfers.
29% Lack Formal Monitoring
Across all 242 firms, 29% reported no formal transaction monitoring process. The FCA’s follow-up interviews found that some low-volume businesses relied on one or two people to review activity manually without documented triggers for suspicious behavior.
Manual review is not equivalent to no control. A documented process applied by a trained reviewer may be proportionate for a small customer base. The supervisory finding instead identifies the absence of formal triggers and repeatable procedures, which can make similar transactions receive different treatment.
Other whole-sample findings included:
- 18% without a formal customer risk assessment methodology;
- 18% without formal quality assurance covering onboarding, alerts or reviews;
- 10% not verifying source of wealth for high-risk customers;
- 7% without systematic post-onboarding customer monitoring;
- 7% without repeat sanctions, PEP or adverse-media screening.

The largest percentage in the control dataset requires a different interpretation. Half of firms reported no investment in AML remediation or system upgrades during the previous 24 months. A period without investment does not demonstrate that an existing system is ineffective. It is therefore a resourcing indicator, not a direct control failure.
Outsourcing Retains the Liability
Around 40% of firms outsourced part of financial-crime compliance, generally CDD or EDD checks performed by consultants and fund administrators. Among that subgroup, only 36% reported full oversight of the third party’s AML onboarding.
The two percentages have nested denominators. The 36% is not a share of all 242 firms, and multiplying two rounded figures to produce an exact whole-sample rate would add precision that the FCA did not publish.

The operational issue is not outsourcing itself. UK anti-money laundering rules allow firms to use external providers, but responsibility remains with the regulated entity. The FCA found that some firms could not explain the outsourced CDD and EDD process or demonstrate how they monitored it.
That creates a division between process execution and accountability. A fund administrator can collect documentation and run screening, while the asset manager remains responsible for the risk classification, escalation decision and evidence that the control worked.
88% Collect Data, Fewer Govern It
Technology coverage was wider than governance cadence. Eighty-eight percent tracked and used financial-crime management information, including sanctions, PEP and adverse-media alerts. Yet only just over one-third discussed AML risk regularly at governance forums, while 36% discussed it annually or less.
These measures do not form exact complements, because the FCA used separate frequency descriptions. They nevertheless identify a gap between producing information and reviewing it at a decision-making level.
The same distinction applies to MLRO resourcing. More than half of MLROs worked part-time or shared the role with other responsibilities, which the FCA said was often proportionate to a firm’s size and activities. More than one-quarter of firms managing over £10 billion also reported a part-time or shared MLRO. The publication does not classify that arrangement as a breach; it asks larger firms to assess whether the time and authority allocated to the function match their customer and transaction complexity.
Exposure Is Not Proven Crime
The review does not measure money-laundering events, suspicious-activity conversion rates, enforcement cases or customer losses. It measures self-reported exposure and the design of controls, supplemented by interviews with a smaller, purposefully selected group.
The questionnaire response rate was 87%, but the publication states that its percentages use the 242 firms engaged by the FCA. It does not provide valid-response counts for individual questions. The sector contains around 2,500 firms, and the sample is not described as random, so the percentages should not be treated as market-wide prevalence estimates.
This also prevents a numerical forecast. There is no prior comparable observation, stable time series or out-of-sample period on which to test a forecasting model. The next measurable step is not a projected 2027 failure rate, but a repeatable monitoring framework: the same definitions, subgroup counts and control metrics collected in a later supervisory round.
The FCA said it will use the questionnaire data in its supervision and intervene where firms fall short. It did not identify firms, enforcement cases, remediation deadlines or expected penalties in this publication.
Data
Methodology: FM Intelligence reviewed the FCA’s July 22, 2026 publication covering 242 asset management and alternatives firms. All percentages are FCA-reported unless identified as a calculation. The 3.6-times PEP ratio is calculated as 32% divided by 9%. Approximate FCA language, including “around,” “over” and “just over,” is retained. No confidence intervals or significance tests were calculated because subgroup counts were not disclosed. No forecast was produced because the source is a single cross-sectional supervisory review.
Sources
1. https://www.fca.org.uk/publications/good-and-poor-practice/asset-management-alternative-firms-financial-crime-controls
2. https://www.fca.org.uk/publication/correspondence/asset-management-alternatives-portfolio-letter-2025.pdf
3. https://www.fca.org.uk/publications/multi-firm-reviews/private-market-valuation-practices
4. https://www.fca.org.uk/markets/pisces-private-intermittent-securities-capital-exchange-system
5. https://www.bankofengland.co.uk/news/2025/december/boe-launches-system-wide-exploratory-scenario-exercise-focused-on-private-markets
