FCA Increases Scrutiny of Annex 1 Firms
What the FCA's August 2026 intervention means for Annex 1 registration, governance and AML controls

FCA Increases Scrutiny of Annex 1 Firms
The Financial Conduct Authority has moved from warning Annex 1 firms about weak anti-money laundering controls to examining the entire registered population.
On 7 August 2026, the FCA said it had sent an information request to around 900 Annex 1 firms. That follows work with 300 firms in late 2025 and means the regulator will have contacted every registered Annex 1 firm. It is also applying closer scrutiny to new registration applications, particularly from unregulated lenders, and has warned applicants to expect longer determination periods.
This is not an expansion of the FCA's full authorisation regime. Annex 1 firms are registered with the FCA for AML supervision under the Money Laundering Regulations 2017, but they are not necessarily authorised under the Financial Services and Markets Act or subject to the FCA's wider conduct rulebook. The new intervention is narrower than full authorisation, but it is operationally significant: firms must now demonstrate that their AML controls fit the business they actually run.
Why the FCA Has Escalated Its Scrutiny
Annex 1 covers a broad set of financial activities. Depending on the circumstances, it can include commercial lending and factoring, financial leasing, safe custody, money broking, guarantees, certain securities-related services and other activities listed in the regulations. The FCA's registration guidance makes clear that the test follows the services carried on as a business in the UK, not the label a firm gives itself.
The FCA's concerns have developed over several supervisory cycles. In 2024, it identified discrepancies between firms' registered and actual activities, risk assessments that did not properly address the firm or its customers, controls that had failed to keep pace with growth, and inadequate resourcing and oversight. In March 2026, it reminded regulated firms to perform proper due diligence when dealing with Annex 1 lenders, safe custody providers, money brokers and leasing companies.
The August 2026 statement adds two sharper concerns. First, some firms rely too heavily on the financial crime controls of a parent company. A group policy can provide a foundation, but each legal entity must determine whether those controls address its own activities, governance, customers and risks. Second, firms cannot satisfy the FCA with off-the-shelf procedures designed for a different business.
The regulator also singled out unregulated lending conducted through complex structures, including special purpose vehicles. An SPV is not suspicious by itself, but it can separate the registered lender, source of capital, borrower, security and repayment flows across several entities. Without a clear view of ownership, control and commercial purpose, the structure can conceal rather than explain the transaction.
That concern is consistent with the 2025 National Risk Assessment. It describes how bridging finance can be used in property-related money laundering, including arrangements where criminal capital is issued as a loan and later repaid as an apparently legitimate investment. The speed and flexibility that make bridging finance commercially useful also make weak customer and transaction controls easier to exploit.
What Increased Scrutiny Means for Applicants
An Annex 1 application is no longer best approached as an administrative exercise. The FCA says firms must clearly demonstrate how they will comply with the Money Laundering Regulations. A complete application therefore needs to tell one coherent story across the business model, registered activities, governance and controls.
The first test is scope. The application should accurately describe which Annex 1 activities each legal entity performs, where they are carried on, how frequently they occur and how they relate to the rest of the group. For lending structures, that includes identifying the original lender. The FCA states that a lending SPV generally requires Annex 1 registration where it is the original lender, but not merely because a legal or beneficial interest in existing loans was transferred to it.
The second test is accountability. The FCA requires an MLR Individual form for each senior person responsible for Annex 1 activities. It also expects the relevant fitness and propriety evidence, including an appropriate criminal-record check for beneficial owners who are not already approved senior managers. Those forms should align with the firm's governance in practice. Naming an individual who lacks information, authority or resources does not create effective oversight.
The third test is control design. A firm should be able to show how its business-wide risk assessment drives customer risk classifications, customer due diligence, enhanced due diligence, suspicious-activity escalation and ongoing monitoring. Generic policy language is not enough. A commercial lender should address the purpose of the loan, borrower ownership, source of funds and repayment, third-party payments, collateral and unusual changes during the relationship. A safe custody provider needs controls suited to customer access, high-value physical property and changes in account use.
Corporate borrowers also require more than a registry lookup. As our guide to why KYB is different from individual KYC explains, a company check must follow ownership and control through the relevant layers, then connect that structure to the purpose and expected activity of the relationship.
Existing Firms Need Evidence, Not Just Policies
The FCA's information request means existing Annex 1 firms should expect their stated business model to be compared with observable activity. A useful internal review starts by reconciling the register entry against current products, legal entities, customer types and transaction flows. Acquisitions, new funding structures, new distribution arrangements and rapid growth can all make an old description incomplete.
The firm should then test representative customer files. Can it reconstruct who the customer and beneficial owners are, why the relationship was accepted, which risks were identified, what evidence supported the decision and who approved any exception? For a higher-risk relationship, can it show why enhanced due diligence was proportionate and how monitoring was increased?
Ongoing monitoring is central because a clean onboarding file can become misleading. Ownership changes, a new source of repayment, an unexpected third-party payer, a shift into a higher-risk jurisdiction or new adverse information should trigger reassessment. A strong KYC periodic-review process combines scheduled review with event-driven checks when the facts change.
This direction is not limited to Annex 1 firms. The wider shift in AML supervision for UK professional-services businesses reflects the same expectation: a firm must be able to prove that its written framework operates consistently across real customer relationships.
Making the Control Framework Provable
An AI-first compliance workflow can help with the evidential problem, provided human oversight remains clear. Steward brings document collection, corporate verification, beneficial-ownership mapping, risk assessment, ongoing monitoring and screening within the same case history. Missing evidence can be routed to a named reviewer, while approval, escalation and rejection decisions remain attributable to the people responsible for them.
That does not determine whether a firm falls within Annex 1 or replace the firm's responsibility for risk appetite and suspicious-activity decisions. It makes the operating record easier to inspect. When a supervisor asks how a higher-risk borrower was approved, the answer should not depend on reconstructing emails, spreadsheets and separate screening searches after the event.
The FCA's latest action changes the practical standard for Annex 1 firms. Registration establishes the perimeter of supervision. The real test is whether the firm can show that its controls match its activities, its customer risks and the way its business has evolved.
Related Insights

The AML AI Readiness Gap in North America
North American firms allocate funds to AI for AML, yet 54% use 8-10 fragmented systems. Why AI adoption isn't the same as operational readiness.

AML Red Flags for Payroll and Annex 1 Firm
Identify AML red flags in payroll and Annex 1 firms: understand sector-specific risks, connect anomalies to customer context, and build effective controls.

How to Set Up AML Controls for a UK Business
A practical operating model for building AML controls that work across payroll and Annex 1 businesses