Share
What the FCA's 2026 sanctions review is really telling you
Sept 14, 2026
The FCA's 2026 sanctions multi-firm review provides fresh clarity on the FCA’s expectations for sanctions controls at financial organisations. A follow-up to their 2023 review, this one covers the practices of around 150 firms over 18 months and defines good and poor practice, including specific examples.
The headline takeaway is simple: the bar for what constitutes an effective sanctions compliance programme has been raised significantly.
In 2023, regulatory evaluations focused on whether the right inputs were in place, such as policies written, vendors selected, and lists being screened. Today, this is taken a step further: are those inputs producing functional performance and measurable outcomes?
So what exactly changed, and what does it mean in practice?
Breaches are not anomalies — they are patterns
One of the more striking findings in the report is on sanctions breaches themselves. Despite progress being made in £37 billion in frozen assets, the FCA concluded that breaches are not unpredictable events, but rather the predictable outputs of recurring control failures.
The most common drivers are:
- Weaknesses in customer due diligence
- Poor alert management
- Gaps in transaction screening
- Screening systems that aren't calibrated to the actual data being passed through them
Rather than treating a breach as a one-off incident to investigate and close, firms should conduct root cause analysis that demonstrates understanding of the structural gap that produced the breach and evidence that the gap has been closed.
The vendor reliance problem
The 2023 report noted a concerning tendency toward heavy vendor dependency. The 2026 report describes something worse: blind reliance.
Firms that can't explain the configuration of their screening system and reasoning behind alerts are in trouble. Deferring to a vendor that calibrated the system and fed data into it is not the same as documentation of decisions and defensible reasoning. The same principle applies to group outsourcing arrangements: delegating sanctions functions to another entity within a corporate group is not an excuse for weak oversight. It demands the same contractual rigour, the same governance, and the same accountability.
What good looks like, according to the FCA:
- Strong contractual terms with vendors that specify data update frequency, quality benchmarks, and escalation pathways when anomalies arise
- Supplementary vendor data with internal intelligence and curated watch lists.
Sanctions evasion: static screening is not enough
The review marks a step-change in how the FCA thinks about evasion and circumvention. Simply running names against a list is insufficient. The FCA noted that sophisticated proxies, corporate layering, and opaque ownership structures are the mechanisms through which sanctions evasion actually happens.
To carry out sufficient screening, the FCA identified the following good practices:
- Specialised sanctions evaluation questionnaires designed to probe complex corporate arrangements and surface indirect links to designated persons
- Intelligence-led reviews that proactively investigate unusual patterns before a breach occurs
- Scenario testing mapped to the firm's specific customer base and transaction types
- Proactive use of transaction monitoring data to detect evasion typologies, not just to process alerts.
- For offboarding sanctioned individuals, work through asset freezing obligations in addition to freezing or closing accounts
In summary: what good looks like
The review's good practice section provides a concrete picture of what the FCA wants to see overall.
Dynamic, up-to-date policies. Not an annual review cycle, but living guidance updated when the landscape changes, with specific line items on the business lines, jurisdictions, and customer profiles the firm has no appetite for, all clearly documented with senior accountability.
Actionable MLRO reporting. Not a static metrics pack, but reporting that interprets global sanctions developments through the lens of the firm's specific exposure and business model, producing decisions, not just information.
Role-specific training. General sanctions awareness training is table stakes. The FCA wants training calibrated to what different teams actually do, with particular emphasis on roles involved in alert handling, investigations, and high-risk customer reviews.
Regular internal and external testing. This includes both structured second-line assurance and periodic external validation. Annual AML audits alone often don't reach the level of detail sanctions controls require. Dedicated sanctions control testing, including synthetic data exercises, is increasingly expected.
Well-structured screening procedures. Not just a policy that references screening, but documented procedures that leave no room for interpretation: how alerts are handled, what data fields are screened, how auto-closures are justified, how non-Latin names are handled, what the escalation path looks like, and how SLAs are governed.
Making use of the review
The question every compliance team should be asking right now is: how do we benchmark ourselves against this?
The practical answer is to treat the good and poor practice examples in the review as an audit checklist. Go through each one, identify where you sit, and document your position. Where you're in the poor practice column, build a remediation plan with explicit senior ownership over closing the gap. And if you have external auditors coming in, make sure these findings are explicitly in scope.
The FCA’s multi-firm reviews set a strong de facto standard, sitting alongside formal regulations and financial crime handbooks. Firms that incorporate best practices from the FCA’s most recent sanctions review will be in a strong position to pass their next audit and avoid scrutiny from regulators.
Learn more about the FCA's sanctions review
To learn more, hear from James Nurse, UK AML/FinCrime Thought Leader and Strategic Advisor to Alloy, and Sara Cerminara, Group Sanctions Lead at Wise, on the Alloy webinar “Sanctions under the microscope: Unpacking the FCA's latest findings”. Watch on-demand.