An independent AML audit gives a payment firm an opportunity to discover weaknesses while it can still plan the response. Under regulatory scrutiny, that work takes place alongside the demands of explaining the problem, producing evidence and demonstrating progress.
The FCA’s 2025/26 Skilled Person data shows that financial crime accounted for 12 of 31 commissioned reviews. Across all sectors and review subjects, completed Skilled Person reviews averaged £2.5 million. The FCA sets the scope, whilt the firm absorbs the cost.
Published cases and supervisory findings point to five areas worth testing. The suggested tests below are practical applications of those findings and are not descriptions of individual FCA cases.
The FCA’s 2025/26 enforcement data describes an anonymous Skilled Person review that found inadequate CDD, customer risk models, transaction monitoring and sanctions screening. A subsequent voluntary requirement included stopping new client onboarding.
A separate case concerned BeAccount Ltd, an authorised EMI. The FCA imposed requirements stopping payment and electronic money services and requiring customer funds to be returned. Its concerns included the firm’s inability to demonstrate compliance with risk assessment, policy, CDD and EDD requirements. This was a supervisory intervention, not a published Skilled Person report.
The practical implication extends beyond review fees - restrictions can affect onboarding, ongoing commercial activity and service delivery.
The FCA’s November 2025 risk assessment review included electronic money firms. It found poorly tailored assessments, unsupported conclusions about control effectiveness and weak connections between risk assessments and monitoring.
For a payment firm, select a material exposure such as a higher risk corridor, merchant category or complex corporate customer. Where the customer risk rating changes, examine whether the firm considered the consequences for due diligence and monitoring and recorded its reasoning.
The purpose of this test is to establish whether the same risk receives a coherent response across the business.
Trace the same exposure through the business risk assessment, customer rating, due diligence, monitoring and management reporting. Compare the responses at each stage and investigate any gaps or inconsistencies.
The FCA’s April 2026 CDD review found missing relationship information, inadequately evidenced EDD and failures to follow review procedures. Its sample did not include payment firms, but the FCA expressly applies the findings to all firms undertaking CDD.
For a merchant customer, compare the stated business model with the transactions being processed. For a corporate remittance customer, examine the counterparties, corridors and expected volumes. Where activity changes, check whether anyone revisited the original assessment and recorded the resulting decision.
Reconstruct an acceptance or ongoing review decision from the file. Can the evidence and existing records explain the customer’s business, ownership, expected payment flows and risk rating, and why the firm accepted or continued the relationship?
The FCA’s February 2025 payments portfolio letter called for active oversight of agents and distributors and assurance that outsourced functions operate as intended. Its March 2026 Payments Regulatory Priorities report continues the emphasis on effective governance and controls.
If an agent collects CDD, can the firm access and challenge the evidence? If a group team investigates alerts, does the UK entity know what is overdue and how decisions were reached? Processing volumes alone do not establish whether material exceptions were resolved.
Select an exception handled by an agent, outsourced provider or a group team. Trace what happened, what the UK firm knew, who challenged the decision and whether the issue was resolved.
The FCA’s May 2026 sanctions findings identified weaknesses in screening configuration, data coverage and testing. Its September 2026 money mule findings also highlight the need for payment firms and EMIs to assess mule exposure and review their transaction monitoring controls.
Monitoring tests should reflect the business model. Relevant exposures might include rapid movement of funds, unusual transaction frequency, corridor changes or departures from expected customer behaviour.
For screening, trace selected customer and payment records into the system and check data completeness and configuration testing. For transaction monitoring, compare selected scenarios with the firm’s actual exposures, then follow alerts through investigation and decision.
The FCA’s CDD review found variations in review depth and independence, including in some cases same staff performing assurance over customers they had onboarded. Stronger arrangements included independent testing followed by action on findings.
The final report should distinguish a weakness in control design from an execution failure, missing evidence or a discretionary improvement. Each calls for a different response.
Take a previous assurance finding and trace the evidence, conclusion, agreed action and closure. Check the reviewer’s independence and whether the evidence of completion actually demonstrates that the weakness was addressed.
Regulation 21 requires an independent audit function where appropriate to the business’s size and nature. Its responsibilities include evaluating AML policies, controls and procedures, recommending improvements and monitoring compliance with those recommendations.
A concern about merchant EDD may justify a targeted review. Growth across products and corridors may require broader coverage. Agree these points before commissioning:
A documentary review assesses design, whilst testing examines operation. A targeted review can include either or both and can contribute to a wider audit coverage. Its conclusions must reflect the areas and evidence actually examined.
Earlier independent work creates an opportunity to address weaknesses before external pressure dictates the response. Its value depends on asking a sufficiently specific question and doing enough of a deep dive to answer it.
askMLRO provides full framework AML audits and targeted reviews for payment firms and EMIs. Tell us about your business, the concern you want examined and any deadline. We will propose the scope, testing approach, timetable and fee.