Skip to content
Marc CotterillOct 2, 2026, 1:11:40 PM15 min read

10 Signs Your Financial Crime Controls Haven’t Kept Pace with Growth

INTRODUCTION

10 SIGNS YOUR FINANCIAL CRIME CONTROLS haven’t kept pace with growth

You don’t work this hard to grow a business to risk being told to stop.

We’re a growing business ourselves – recognised in The Sunday Times Hundred fastest-growing companies, in fact – yet never along the way have we ever thought “that’ll do.” We want more. More customers, bigger and better opportunities to showcase what makes us different – and to keep delivering a better (and better) service.

We understand ambition. It is in our DNA.

But place that ambition inside a regulated business and things start to get serious. Winning new customers is one thing, but evidencing that you are capable of managing the financial crime risks they bring is part of earning the right to keep winning them.

“But we’re growing fast” is no defence for controls that can’t cope. Sorry.

Unresolved weaknesses can mean remediation programmes, restrictions on new business or worse, enforcement. [See FCA: 'Our approach to supervision'.]

Your growth plan can quickly become a recovery plan. And the people you’ve attracted to help build the future can all of a sudden find themselves spending a disproportionate amount of time fixing the past.

"Scale - on rails" is a phrase we like to use...

But to do so, your financial crime capability must be part of the growth plan – and budget.

If the plan’s objectives and key results talk about more customers, new markets and more complex products, they also depend on the expertise, capacity and controls to support them. These are part of the investment required to grow – not just problems for Ops to deal with later.

The ten signs below are designed to make you think and hold up a mirror. They’re designed to challenge you – and ask whether your underlying controls and operating model 'are' keeping pace.

None is an automatic verdict of regulatory failure. But each is a reason to look more closely – while you still have room to act.

10 SIGNS TEXT IN FUCHSIA AND A FADED MAP ON A DARK BLUE BACKGROUND
SIGN I

YOUR RISK ASSESSMENT DESCRIBES the business you used to be

New customers. New markets. Significantly more volume. Same risk assessment?

A business-wide financial crime risk assessment sets out where your business could be exposed to financial crime and informs how you manage that exposure. It should help you decide where controls, expertise and resources are needed.

If the business has changed substantially but the assessment barely has, challenge it. A new approval date on the front page tells you very little about the thinking underneath.

The FCA’s Financial Crime Guide links risk assessment to customers, products, locations, transactions and distribution channels. It also calls for regular review. SYSC 6.3.7G specifically addresses money-laundering risk arising from new products, new customers and changes in business profile.


Ask Yourself: Would someone reading our risk assessment today recognise the business we are actually running - and understand what we are doing about its risks?


References:

  • FCA Financial Crime Guide: FCG 2.2.4G: Risk assessment
  • FCA Handbook: SYSC 6.3.7G[4]: Financial Crime
SIGN II

CUSTOMER DUE DILIGENCE IS BECOMING increasingly one-size-fits-all

Growth often creates pressure to grease the wheels of onboarding.

Standardisation can be valuable, but not where it removes meaningful differentiation between customer risk profiles. Remember operational excellence is about more than fast – it is about quality too.

Customer due diligence (CDD) is about establishing who you are dealing with, including relevant beneficial owners, and understanding the relationship. Enhanced due diligence (EDD) adds further scrutiny where required, including higher-risk situations.

Standardisation can help you scale, but the problem starts when materially different risks are absorbed by the same process. A high-risk label achieves very little if it changes nothing about the work and scrutiny that follows.

The FCA's 2026 CDD work found stronger firms tailoring CDD to customer risk, while weaker examples did not demonstrate clearly enough how treatment differed between lower- and higher-risk customers or adequately evidence EDD.


Ask Yourself: Can we take two customers with different risk profiles and demonstrate why [and how] the checks applied to them differ? Can we show how customer risk actually changes the information, checks, review, approval or monitoring applied?


References:

  • FCA Financial Crime Guide: FCG 3.2.4G: Customer due diligence
  • FCG 3.2.7G–3.2.8G: Higher-risk situations and enhanced due diligence
  • FCA Firms’ customer due diligence processes and controls
SIGN III

CUSTOMER REVIEWS ARE BECOMING a permanent backlog

The customer base keeps growing, along with the overdue review queue.

Customer due diligence doesn’t finish at onboarding. Reviews help firms keep customer information current and reassess risk as circumstances change. When those reviews remain overdue, you may be making decisions using an increasingly outdated picture of who you are dealing with.

A persistent backlog therefore deserves more than a standing item on the ops report. It can be a sign that review processes, capacity or specialist capability have not kept pace with the growth of the business.

The FCA’s Financial Crime Guide describes ongoing monitoring as risk-sensitive and includes keeping customer information up to date. Its 2026 CDD review identified unclear review arrangements and firms failing to carry out reviews required by their own policies.


Ask Yourself: Are overdue reviews a temporary pressure - or a growing gap in our understanding of customer risk?


References:

  • FCA Financial Crime Guide: FCG 3.2.5G: Ongoing monitoring
  • FCA Firms’ customer due diligence processes and controls: our findings
SIGN IV

MONITORING WAS CALIBRATED FOR AN earlier version of the business

The monitoring system is triggering alerts and cases are closing. That proves activity – but what is giving you confidence in the coverage?

Transaction monitoring looks for activity that may warrant investigation. Its rules, thresholds and supporting data need to make sense for the business using it. FCG 3.2.5G explicitly challenges firms to review monitoring effectiveness and understand the rationale behind their rules.

Test it. Pick something material that has changed - a product, customer group or transaction pattern. Ask what testing followed and what it showed.

The FCA's high-growth review found stronger firms investing in scalable technology and enhancing transaction monitoring as they grew. FCA sanctions work similarly emphasises configuration, calibration, data coverage, testing and alert management rather than assuming an installed system remains effective indefinitely.


Ask Yourself: When did we last test whether our monitoring genuinely reflects today's customers, products and transaction behaviour? What evidence shows that our monitoring can identify the risks in today’s business - including the activity it might currently miss?


References:

  • FCA Financial Crime Guide: FCG 3.2.5G and FCG 3.2.5AG: Ongoing monitoring and the use of transaction monitoring
  • FCA Sanctions systems and controls in our firms: our findings
  • FCA High-growth firms: good and poor practice, seciotn 3.3
READY SET GROW

EVEN THE BEST
need back-up

Growth is great, but your controls need to grow with you. It's easy to focus on where the business is heading and overlook whether your operating model can keep up. Sometimes it takes a fresh pair of eyes to spot the gaps before they become problems.

SIGN V

TOO MUCH CONFIDENCE RESTS WITH A vendor or inherited configuration

Scaling firms often rely more heavily on external support - vendors, group systems, agents and outsourced providers. The control may be outsourced; accountability is not.

You still need enough understanding to judge its suitability, challenge its performance and act when something changes.

The UK National Risk Assessment specifically warns that AML outsourcing can create vulnerabilities for EMIs and PSPs when third parties do not properly understand the firm's products or risks, and states that the principal firm remains responsible for compliance. FCA sanctions work has similarly identified over-reliance on screening vendors and historic vendor settings without adequate reassessment or oversight.

You don’t need to recreate your supplier’s business in-house, but you do need an informed owner of the relationship.


Ask Yourself: Could we explain - and evidence - why our configuration is appropriate for our risks, what its limitations are and how we know it is delivering, rather than relying solely on the vendor’s assurances?


References:

  • HM Treasury and Home Office - National Risk Assessment of Money Laundering and Terrorist Financing 2025, paragraph 5.68
  • FCA Sanctions systems and controls in our firms: our findings
SIGN VI

MI TELLS YOU YOU’RE BUSY BUT NOT WHETHER controls are working

Alert numbers, case volumes and onboarding turnaround times can be MI. On their own, however, they may say little about control effectiveness - would they tell you if the team were getting faster at making the wrong decisions?

Management information (MI) is the reporting leaders use to understand performance and make decisions. For financial crime, FCG 2.2.2G points to reporting on risk exposure and control effectiveness, alongside operational information.

FCA financial-crime guidance identifies useful MI as including emerging risks, changes in risk assessment, control effectiveness, higher-risk relationships and relevant alert or reporting information. The FCA's sanctions review similarly points to MI combining quantitative and qualitative information about risk, controls, outcomes and trends.

Complement volume figures with adequate evidence of quality. What are file checks finding? Which problems keep returning? Where are important actions overdue? What decisions does leadership need to make?


Ask Yourself: Does our MI help senior management understand risk and control effectiveness — or mainly operational throughput? If a control were becoming less effective while productivity improved, would our MI make that visible?


References:

  • FCA Financial Crime Guide: FCG 2.2.2G: Management information
  • FCA Sanctions systems and controls in our firms: our findings, section 6.3: Management information

SUPERCHARGE YOUR
fin crime team

Access on-demand, pre-vetted financial crime practitioners to unlock bandwidth and scale delivery at pace.

 

Super Banner - Web MR-1

 

SIGN VII

CRITICAL KNOWLEDGE IS CONCENTRATED in too few people

‘Sarah’ knows the monitoring rules. ‘Sarah’ handles the awkward cases. ‘Sarah’ remembers why the exception exists.

‘Sarah’ is excellent, but she would also quite like a holiday at some point.

Look inside your operation - perhaps one person understands the monitoring rules. One analyst knows how a particular high-risk customer type is handled. One senior manager is the route for almost every difficult decision.

The FCA's 2026 high-growth review specifically identified key-person reliance, insufficient contingency planning, succession and knowledge transfer as weaknesses in some growing firms.


Ask Yourself: What would become difficult, slow or unsafe if one or two key people were unavailable tomorrow - who could genuinely step in?


References:

  • FCA High-growth firms: good and poor practice, section 3.2: Risk management frameworks
SIGN VIII

POLICIES AND PROCEDURES ARE INCREASINGLY different from what happens in practice

“That’s what the procedure says. But here’s how we actually do it.”

Back in the day in my first role we had something called “The Red Book” – a printed file full of every operational process and work instruction. Problem is, the second a new page was printed, it was out of date with reality – the process had already evolved.

Rapidly changing firms often have a similar issue - people find ways to get the work done while the documentation struggles to keep up. Sometimes they’ve found a better way, and sometimes they just think they have - when in reality an important control has been missed, or worse, entirely wiped out.

Over time, the documented framework and the operational process can become two very different things.

Policies set the boundaries and expectations. Procedures explain how people put them into practice. But when the two drift apart, training, supervision, accountability and control become harder.

The FCA’s recent high-growth and customer due diligence reviews picked up related issues: frameworks that hadn’t evolved with the business, procedures lacking practical detail and weak document version control.

“Go to the Gemba” [as the Japanese improvement gurus would say]. - the place where the work actually happens. Walk a real case through the written procedure in your organisation today, sit with the person doing the work and see whether things line up.

From my Ops Excellence upbringing I specifically remember learning about Gauge R&R – mainly because the tutor shouted the "R&R" bit in a pirate’s accent… anyway, I digress. It talked about two different tests: ‘repeatability' and 'reproducibility’, and there’s a useful parallel with casework here:

  • Repeatability: give the same person the same case twice with the same evidence, policy and procedure in place [space them out a little so they don’t recognise it]. Do they reach a consistent decision?
  • Reproducibility: give that same case to two different people, again with the same evidence, policy and procedure. Do their decisions line up?

Then ask a third question: are the decisions right?

Of course, judgement matters. Two defensible decisions can differ. The useful work is understanding whether that difference comes from legitimate judgement, an unclear instruction, a training gap or a control being missed.

If there are material gaps, you have work to do. Investigate each difference and ask “why” [the second principle of going to Gemba - the third component being ‘show respect’] – and decide whether to change the document, the practice or both.


Ask Yourself: If we followed the written procedure exactly, would it reproduce how the control actually operates today? Could a competent new starter follow our procedure and deliver the control we intend - without relying on unwritten instructions?


References:

  • FCA High-growth firms: good and poor practice, sections 3.2–3.3
  • FCA Firms’ customer due diligence processes and controls: our findings
SIGN IX

YOUR CONTROLS AREN’T GETTING independent challenge

Growth can consume assurance capacity just as quickly as operational capacity.

Quality assurance checks whether work meets the required standard. Independent assurance adds challenge from people sufficiently separate from the activity being examined. Both help you test the difference between what should happen and what actually does.

The FCA’s 2026 CDD review found stronger firms carrying out regular reviews and independent testing, then acting on the findings. In weaker examples, staff performed second-line assurance on customers they had onboarded - effectively marking their own homework.


Ask Yourself: Are we testing whether controls remain effective - or mainly investigating issues once something has gone wrong? Who challenges whether our controls work, how independent is that challenge, and what evidence shows identified weaknesses have been resolved?


References:

  • FCA Firms’ customer due diligence processes and controls: our findings
SIGN X

CHANGE MOVES FASTER than financial-crime governance

New products. New markets. Automation. A new onboarding platform. A new data source. An acquisition. A new outsourced provider.

Financial crime governance is about how responsibility, challenge and decisions shape the way the business manages risk – and it needs a meaningful place in your change decisions.

The above examples also change financial-crime exposure. SYSC 6.3.7G addresses money-laundering risk in product development, customer acquisition and changes to business profile. FCG 2.2.4G also identifies considering financial crime risk during product design as good practice.

Where a change creates new exposure, the plan should include the controls, expertise and capacity to manage it. Leadership needs that information while there are still choices to make. Impact-assess the change and feed it into your control plan.


Ask Yourself: Can financial-crime risk influence a change before it goes live - or does the control function adapt or just inherit the consequences afterwards?


References:

  • FCA Handbook: SYSC 6.3.7G(4): Financial crime
  • FCA Financial Crime Guide FCG 2.2.4G: Risk assessment, including product design

SCALE WITHOUT
losing control

Keep Reading: Access our full guide to explore the FCA’s 2026 high-growth findings in more detail:

 

Scale without losing control - Blog Social Share-2

 

SCALE on rails...

You’ve set out where the business is going. But can you show that the capability behind it is ready?

Your anti-financial crime capability belongs in the decisions and budgets that make growth possible - leaving it to catch up later is a commercial gamble.

The FCA’s high-growth review – and the other references in this piece - reinforce that position. Strong firms invest in people and tech, and develop their controls as they grow.

In some cases, firms make the difficult decision to delay expansion into new regulated activities until controls supporting the existing business are stronger.

Those decisions take good judgement - and the confidence to challenge a growth plan before the business commits to it.

If any of these ten signs feels familiar, put it on the leadership agenda. Establish what needs to change, who owns it and what evidence will show it is working.

As I said up front, we want more growth. We want it for our customers, too. Big, bold ambition. New opportunities. The satisfaction of building something that keeps getting better.

That’s why we ask the awkward questions. When you’re serious about growth, you have to be serious about what is required to sustain it.

You’ve worked hard for your growth - give it the backing it needs.

References:

  • FCA High-growth firms: good and poor practice, section 3.3
Map Room Primary Logotype Transparent Sized-1
GO DEEPER

ACCESS OUR full guide

This article provides a useful high-level overview about the recent FCA findings, but only scratches the surface about what high-growth firms might think about whilst scaling - without losing control.

Map Room supports some of the UK’s best-known fintech and financial-services brands through periods of rapid growth, regulatory change and operating-model redesign - so we wanted to turn some of that experience into something practical others can use.

In our full 'Scale Without Losing Control' guide, we get into the FCA’s findings in more detail – what they mean in practice, exploring how scaling firms can identify where growth is beginning to put pressure on the operating model behind it.

The guide covers:

  • Five practical implications of the FCA’s findings for scaling fintechs
  • How to test whether governance is becoming a bottleneck
  • Why capacity is a control question, not simply a hiring question
  • How historic growth can create future CDD and review demand
  • What human-in-the-loop means for AI-enabled controls
  • A practical growth-trigger test for leadership teams
  • How to identify whether you have a capacity problem or a wider operating-model problem

SCALE WITHOUT
losing control

Access the full guide to explore the FCA’s 2026 high-growth findings in more detail - and the practical questions Operations, Risk and Financial Crime leaders should be asking as their businesses scale.

 

Take the growth-trigger pressure test and assess your firm.

 

Scale Without Losing Control - MockUp for Landing Page

 

NEED MORE THAN the guide?

If you're already feeling growing pains, we'd be happy to walk you through how we're supporting similar firms through growth, change and increasing operational complexity.


 

Note: These 10 signs are Map Room’s practitioner observations, informed by the sources cited. The FCA reviews describe examples of good and poor practice; they are not a separate rulebook. Applicable requirements depend on the firm’s activities and regulatory status.

COMMENTS