Financial Risk

FCA Centralised AML Supervision: What Professional Services Firms Should Change Now

ICA’s July 2026 analysis of centralised FCA AML supervision highlights a significant structural change for UK professional services. Firms accustomed to professional-body supervision should expect a more consistent and data-driven supervisory environment.

By Jonas Adam Mohamed Osman AbdelghafourPublished 27 August 2026Last reviewed 27 August 2026

Why this matters

ICA’s July 2026 analysis of centralised FCA AML supervision highlights a significant structural change for UK professional services. Firms accustomed to professional-body supervision should expect a more consistent and data-driven supervisory environment.

Risk assessment

Professional services firms should reassess whether their business-wide risk assessment reflects the actual risks of clients, jurisdictions, services, trust and company structures, property transactions and professional enablers.

Evidence culture

A more centralised supervisor is likely to place weight on comparability, management information and evidence. Firms should therefore ensure that policies, training, quality assurance and case files support the risk claims made in governance documents.

Senior management accountability

AML should not sit only with the nominated officer. Boards and partners need clear information on high-risk clients, overdue remediation, suspicious activity reporting, control failures and resource constraints.

Consistency

Where firms operate multiple offices or practice areas, inconsistent customer risk treatment can become a significant weakness. Central standards should allow justified exceptions but not uncontrolled local variation.

Conclusion

The shift toward centralised supervision raises the value of consistency, evidence and accountable governance. Professional services firms should prepare by treating AML as an enterprise control framework rather than a compliance-file requirement.

Practical actions for compliance leaders

  • Assign clear ownership and document decision rights.
  • Test control effectiveness using actual case outcomes rather than policy completion alone.
  • Escalate ambiguous or high-consequence cases to appropriately skilled reviewers.
  • Track exceptions, overrides, quality assurance findings and recurring root causes.
  • Ensure board and senior management reporting focuses on risk and control effectiveness, not only volumes.
  • Maintain evidence showing how the firm reached material compliance decisions.

Related reading

See AML & Financial Crime, Regulatory Compliance and Governance, Risk and Compliance.

About the author

Jonas Adam Mohamed Osman Abdelghafour writes about governance, risk and compliance, anti-money laundering, financial crime prevention, sanctions, customer due diligence, AI governance, model risk and regulatory risk. His work focuses on practical control design, risk-based decision-making and the interaction between regulation, technology and financial services. See About and Qualifications.

Source and editorial context

This article is original analysis informed by a current compliance theme highlighted by the International Compliance Association. The ICA is cited as an editorial/current-issue source; no affiliation with or endorsement by the ICA is claimed or implied.

Frequently asked questions

Why this matters?

ICA’s July 2026 analysis of centralised FCA AML supervision highlights a significant structural change for UK professional services. Firms accustomed to professional-body supervision should expect a more consistent and data-driven supervisory environment.

What should risk leaders know about risk assessment?

Professional services firms should reassess whether their business-wide risk assessment reflects the actual risks of clients, jurisdictions, services, trust and company structures, property transactions and professional enablers.

What should risk leaders know about evidence culture?

A more centralised supervisor is likely to place weight on comparability, management information and evidence. Firms should therefore ensure that policies, training, quality assurance and case files support the risk claims made in governance documents.

What should risk leaders know about senior management accountability?

AML should not sit only with the nominated officer. Boards and partners need clear information on high-risk clients, overdue remediation, suspicious activity reporting, control failures and resource constraints.

What should risk leaders know about consistency?

Where firms operate multiple offices or practice areas, inconsistent customer risk treatment can become a significant weakness. Central standards should allow justified exceptions but not uncontrolled local variation.