The FCA’s latest sanctions review, covering more than 150 firms, should not be read as just another best-practice paper. It is a clear statement of intent, showing how the regulator is using thematic reviews to push standards higher across the market.
According to ACA Group, instead of simply cataloguing weaknesses, the FCA is setting out the standards it now expects: strong governance, effective controls and the ability to react at pace when risks shift. Sanctions compliance has moved from being a standalone financial crime task to a core pillar of market integrity and operational resilience.
ACA Group recently discussed FCA sanctions controls and the multi-billion-pound challenge ahead.
The urgency reflects a transformed sanctions landscape. Regimes have grown in scope, complexity and speed, and firms must keep up. For CCOs, COOs and CTOs at buy-side firms worldwide, the challenge is no longer merely understanding the rules but building an operating model that can adapt rapidly and offer clear oversight.
The scale of the issue is underlined by the value of frozen assets in the UK, which rose from £24.4bn in 2023-24 to £37bn in 2024-25.
The consequences of getting this wrong are practical as well as regulatory. Weak controls can invite scrutiny, disrupt operations, delay transactions and drive up costs, making sanctions an issue that stretches well beyond the compliance department.
The review found some industry progress, yet the same failures keep surfacing across different business models and sectors, pointing to unresolved structural problems. Recurring weaknesses include due diligence, alert management, transaction and name screening, frozen asset handling and licence compliance.
These gaps sit at the heart of daily operations: poor ownership data undermines screening, weak alert handling breeds backlogs, and inconsistent governance slows escalation.
Crucially, sanctions risk cannot live in one function. It cuts through investor onboarding, counterparty relationships, delegation models, custody chains and payment flows. Firms that treat sanctions as a siloed activity risk gaps between teams, systems and governance.
There is also growing expectation around trade-related exposure, where firms must understand risks tied to goods, services and end-use, even with limited visibility. Controls here are typically less mature than for financial sanctions.
The answer lies in more integrated frameworks that connect risk assessment, due diligence, screening, escalation and reporting into a single operating model, with technology linking data, automating workflows and producing audit-ready evidence.
Senior management oversight is another central theme. Governance only works when decision-makers receive meaningful, timely information. Boards should be able to say where their highest exposure sits, which alerts are ageing, how reliable their data is, where control gaps exist and how quickly they could respond to a major sanctions event. Struggling to answer these questions is itself a warning sign.
Practical next steps include reviewing the sanctions risk assessment to capture cross-border exposure and delegation arrangements, testing screening technology and alert management end to end, tightening governance reporting, and assessing whether fragmented systems and manual processes are constraining compliance.
The broader lesson is that sanctions compliance is fast becoming a proxy for operational resilience. Many firms will benefit from blending internal capability with external specialist support, whether through financial crime advisory, managed compliance services or dedicated AML and screening technology, to close gaps and build a more resilient programme.
Read the full ACA Group post here.
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst





