The FCA’s latest sanctions review, spanning more than 150 firms, is far more than another best-practice publication.
According to ACA Group, it signals how the regulator is deploying thematic reviews to raise standards across the market, and it comes with a stark backdrop: the total value of frozen assets in the UK jumped from £24.4bn in 2023-24 to £37bn in 2024-25.
ACA Group recently discussed FCA sanctions controls and the multi-billion-pound challenge ahead.
Rather than simply cataloguing weaknesses, the regulator is setting out the standards it now expects firms to meet, including robust governance, effective controls and the ability to respond rapidly to shifting risks. Sanctions compliance is no longer a standalone financial crime task; it has become a core component of market integrity and operational resilience.
The stakes are practical as well as regulatory. Sanctions regimes have expanded in scope, complexity and speed, and weak controls can trigger regulatory scrutiny, disrupted operations, delayed transactions and rising costs. For CCOs, COOs and CTOs at buy-side firms globally, the challenge is designing an operating model that adapts quickly and provides clear oversight across the entire control framework.
The review found that while some industry progress has been made, the same failures keep recurring across different business models and sectors. The regulator flagged persistent weaknesses in due diligence, alert management, transaction and name screening, frozen asset handling and licence compliance.
These sit at the heart of daily operations, and when they break down the consequences escalate quickly: poor ownership data undermines screening, weak alert handling breeds backlogs, and inconsistent governance delays escalation.
A central message is that sanctions risk cannot live in a single function. It runs through investor onboarding, counterparty relationships, delegation models, custody chains and payment flows.
Firms treating sanctions as a siloed compliance activity risk creating gaps between teams, systems and governance. Firms are also increasingly expected to understand risks tied to goods, services and end-use, an area where controls are typically less mature than financial sanctions frameworks.
Senior management oversight is another key focus. Governance only works when decision-makers receive meaningful, timely information. Boards should be able to answer with confidence where the highest exposure lies, which alerts are ageing, how reliable underlying data is, where control gaps exist, and how quickly the firm could respond to a major sanctions event. Difficulty answering those questions is itself a warning sign.
In response, firms should review their sanctions risk assessments against their full range of activities, test screening technology and alert processes end to end, sharpen governance and management information, and assess whether fragmented technology is constraining compliance. Many firms may also benefit from external specialist support, including financial crime advisory, managed compliance services and RegTech tools spanning screening, monitoring, adverse media review and watchlist management.
The broader lesson is clear: sanctions compliance is becoming a measure of operational resilience, and firms that can adapt quickly and evidence decisions clearly will be best positioned for long-term growth.
Copyright © 2026 FinTech Global









