Home » What the FCA’s sanctions report means for law firms (even though it isn’t aimed at you – yet)
What the FCA's sanctions report means for law firms (even though it isn't aimed at you – yet)
Anne Austin
Director
On 28 May 2026, the FCA published its findings from four years of work assessing how financial services firms manage sanctions risk.
At first glance, this looks like a financial services story. But the SRA flagged the report to solicitors directly in its SRA Update, and for good reason: the findings map almost exactly onto the gaps we’ve been warning law firms about since the UK Sanctions List became the sole authority for sanctions designations in January 2026.
A quick note on who regulates what
It’s worth being clear about one thing: the FCA is not currently the supervisory body for AML and sanctions compliance in the legal sector – that remains the SRA’s role. A transfer of AML/CTF supervision for legal and accountancy firms to the FCA has been announced, but the timeline, legislation and detail of how it will work in practice are still to be confirmed. We wrote about this earlier in the year.
That said, “it’s not yet your regulator” is not a reason to ignore this report. The SRA itself chose to draw firms’ attention to it, the underlying obligations (strict liability, screening, reporting) are the same regardless of which body is enforcing them, and if and when AML/sanctions supervision does move to the FCA, firms that have already absorbed this report’s lessons will have a head start. Heeding the guidance now is both good practice and good preparation.
What the FCA found
Drawing on work with over 150 FCA-supervised firms since 2022, the FCA’s report sets out a long list of good and poor practice across governance, risk assessment, due diligence, screening, alert handling, and breach reporting. A few findings stand out as directly relevant to smaller regulated firms, including law firms:
Breach reporting is too slow. In 2025, over a third of reported breaches related to activity from the prior year or earlier, and the average gap between identifying a breach and reporting it was 116 days. OFSI’s own enforcement guidance expects disclosure “as soon as reasonably practicable after discovery” – a 116-day average is not that.
Firms over-rely on third-party screening providers without understanding what they’re buying. Several firms in the FCA’s review could not demonstrate they understood the outputs of their screening vendors, or who within the firm was responsible for monitoring risk on an ongoing basis. This is a near word-for-word echo of what we flagged in March: confirm with your provider that their system has been migrated to use UK Sanctions List Unique IDs, don’t assume it’s automatic, and make sure someone owns oversight of that relationship.
Fuzzy matching failures remain a live risk. The FCA found firms whose screening systems could not reliably identify sanctioned individuals where names weren’t in the Latin alphabet, or where spelling variants, titles, or honorifics threw off the match. In testing, only 75% of alerts correctly identified a sanctioned party where the name appeared in a slightly different form. This is precisely the fuzzy matching issue we discussed in relation to the £160,000 OFSI fine arising from a transliterated Cyrillic name – the FCA’s findings confirm this isn’t a one-off, it’s a systemic weakness across regulated sectors.
Pressure to hit targets can override compliance controls. One case study describes compliance analysts bypassing mandatory sanctions escalation procedures because of pressure to meet internal targets, resulting in missed connections to a designated person. It’s a reminder that good policies on paper mean little if operational pressures incentivise staff to cut corners.
Good practice looks like: up-to-date sanctions policies covering more than just asset freezes, role-specific training for higher-risk teams, clear MI that goes to senior management, robust escalation routes between first and second line, and regular stress-testing of systems after sanctions regime changes.
Where this leaves law firms
If you read our piece on the UK Sanctions List becoming the sole authority back in March, much of this will sound familiar. We flagged then that firms needed to: confirm their screening provider had migrated to the new UK Sanctions List Unique ID system, check that fuzzy matching was properly configured and understood by staff, extend screening to staff as well as clients, and update policies, training and contractual documents to remove references to the retired OFSI Consolidated List.
The FCA’s report doesn’t change any of that advice – but it does confirm, from a much larger sample of regulated firms, that these are exactly the areas where things go wrong in practice. Firms that acted on the earlier guidance are ahead of where many FCA-supervised firms currently stand.
For those who haven’t yet reviewed their position, the FCA’s report is as good a prompt as any. Sanctions compliance operates on a strict liability basis – there is no defence of ignorance, regardless of which regulator is doing the asking.
What to do now
A practical starting point for any firm reviewing its sanctions controls:
- Confirm your screening provider (if you use one) has migrated to the UK Sanctions List Unique ID and can demonstrate how its matching logic handles name variants, transliteration, and honorifics.
- Make sure someone within the firm owns oversight of that third-party relationship – not just at onboarding, but on an ongoing basis.
- Review how quickly your firm would identify and escalate a potential breach, and whether your procedures support reporting “as soon as reasonably practicable.”
- Check that sanctions screening extends to staff onboarding, not just client due diligence.
- Make sure escalation routes are clear, documented, and not so dependent on individual judgement that operational pressure could lead to corners being cut.