The FCA’s latest review of money mule activity paints a detailed picture of how financial crime is shifting across the UK’s regulated sector.
Beyond the headline scale of the problem, the most revealing findings concern where suspicious activity is surfacing and how different kinds of firms are responding, according to SmartSearch.
Electronic Money Institutions (EMIs) recorded the sharpest rise of any firm category, with suspected mule account offboarding climbing 164.6% between 2024 and 2025. Challenger banks were responsible for 33% of all suspected mule offboardings, despite holding a comparatively small slice of the UK banking market.
It would be tempting to read this as evidence that FinTechs and challenger banks are growing more exposed.
The FCA cautions against that interpretation. Many of these firms are adding customers rapidly, and higher offboarding numbers can signal sharper detection rather than weaker controls. The more significant story is what the data reveals about how criminal networks move money.
Retail banks still handle most mule-linked transactions by volume. EMIs, Payment Institutions (PIs) and challenger banks, however, tend to see fewer transactions of higher individual value.
This suggests different institutions play different roles in the layering and extraction of illicit funds, undermining the assumption that a single set of controls works equally well everywhere.
Timing also varies. The review found that 74.1% of EMI closures happened within six months of account opening, compared with 56.9% for PIs. Retail banks and building societies more often flagged accounts that had been open far longer. Early detection points to effective onboarding, yet it also shows that criminals are deliberately targeting digital onboarding journeys in large numbers.
The lesson is that onboarding is only the start. Mule accounts may be used immediately, sit dormant, or change behaviour gradually. Ongoing due diligence, behavioural analytics and transaction monitoring are becoming primary controls rather than supporting ones, because customer risk is never static.
No single firm sees the whole journey of criminal funds, which often pass through several accounts before cash-out. Information-sharing provisions in the Economic Crime and Corporate Transparency Act aim to help institutions join up intelligence that would otherwise stay fragmented.
Scale is a further pressure point. Rapid growth brings more alerts and heavier workloads, yet SmartSearch’s 2026 UK Compliance Reality Check found only 30% of regulated firms use, or plan to use, AI-assisted triage for sanctions and PEP screening alerts. Automation should cut noise and let specialists focus on genuine risk, not replace human judgement.
Beneficial ownership remains a stubborn challenge. Business account offboarding rose year-on-year, with challenger banks accounting for a large share, while 52% of firms reported difficulty verifying ownership across complex structures. Treating this as a one-off check leaves an obvious blind spot.
The overarching message is that EMIs, PIs, challenger banks and traditional lenders face different expressions of the same threat. Strong onboarding, continuous monitoring, intelligence sharing and adaptable controls must work together.
Read the full SmartSearch post here.
Copyright © 2026 FinTech Global









