FF News — The Fintech News Network

fscom 10th Anniversary Report: Proving Control Effectiveness is the New Frontier in Financial Crime Compliance

By Lauren Towner · 9 October 2026

Press Release: fscom 10th Anniversary Report: Proving Control Effectiveness is the New Frontier in Financial Crime Compliance | Featured Image by FF News

Regulated firms are struggling to maintain the effectiveness of financial crime controls as they scale and increase technical complexity. According to fscom’s latest annual report, audit findings are rising, signaling that established frameworks are failing to keep pace with cross-border expansion and the automation of monitoring systems, creating significant regulatory exposure for fintechs.

What was announced

fscom released its 2026 fincrime compliance report, marking the tenth anniversary of the study. The report is based on 104 anti-money laundering (AML), counter-terrorist financing (CTF), and anti-financial crime (AFC) audits conducted between July 2025 and June 2026. This represents a significant increase from the 73 audits analyzed the previous year. The data covers firms across the UK and 16 other jurisdictions, including e-money and payment institutions, merchant acquirers, investment and FX firms, cryptoasset firms, and money service businesses.

The audits identified 484 findings in total. The average number of findings per audit increased from 4.26 to 4.65, while high-impact findings rose from 1.01 to 1.14 per audit. A primary concern identified is the consistency challenge for multi-entity groups, where centrally set transaction monitoring rules often fail to account for individual entity risks. Specific failures in control effectiveness were noted: 16 findings related to screening tools failing to identify known PEPs or sanctions matches, and 15 findings concerned AML training assessments that allowed unlimited attempts, undermining proof of understanding. The Whole Firm Risk Assessment (WFRA) remains the most problematic area with 64 findings, largely due to firms treating it as a static annual task rather than a dynamic process. However, some progress was noted in customer due diligence (CDD) file testing, where findings fell from 9.3% to 5.4% of the total.

"Most of the firms we audit have established financial crime frameworks in place. The next stage of maturity is being able to demonstrate that those controls continue to work effectively in practice."

Nicola Hanratty, UK Payments Specialist at fscom.

The companies involved

fscom is a specialist consulting firm providing governance, risk, and compliance services to the financial services industry. Based in the UK, the firm has established itself as a prominent advisor for regulated entities, particularly within the payments, e-money, and cryptoasset sectors. The company operates across multiple jurisdictions, providing audit and advisory services that help firms navigate the increasingly complex regulatory landscapes of the UK and Europe.

The firm’s leadership includes Philip Creed, who serves as Director and is one of the company's co-founders. Other key specialists within the organization include Nicola Hanratty, who focuses on the UK payments sector, and Stuart Smith, who serves as the EU Payments Specialist. fscom has expanded its market presence through both organic growth and strategic leadership changes, positioning itself as a critical partner for firms needing to demonstrate control effectiveness to supervisors. Its annual fincrime report has become a benchmark for the industry, drawing on a decade of proprietary audit data to highlight emerging trends and common pitfalls in financial crime compliance frameworks.

What FF News has reported before

FF News has followed fscom’s growth and its insights into the regulatory landscape closely. In late 2026, the firm made a significant leadership move when fscom Appoints Former PwC Partner Lynne Rainey as Executive Chair to Lead Strategic Growth. Earlier that year, the company enhanced its technological capabilities, as reported in fscom Strengthens Compliance Offering with the Integration of ComplianceGuard.

The firm’s research often highlights industry-wide gaps in readiness. For instance, FF News covered a report stating 78% of Financial Firms Still Unprepared for New UK Payment Safeguarding Rules. Additionally, fscom’s analysis of the crypto sector revealed that 37% of Payments Leaders Cite Regulatory Clarity as Top Challenge in MiCA Crypto-Asset Compliance, reflecting the ongoing struggle with evolving digital asset frameworks.

What this means

The rise in high-impact audit findings suggests that the "honeymoon period" for fintech compliance—where having a framework on paper was sufficient—is over. Regulators are clearly moving toward a "show your work" era, where the mere existence of an automated screening tool is less important than its proven calibration. The industry is under pressure to move away from static, annual risk assessments toward real-time, dynamic monitoring. For multi-jurisdictional firms, the findings highlight a dangerous gap between group-level policy and local-level execution. This shift places significant pressure on compliance officers to justify their technology spend with tangible evidence of effectiveness and independent assurance.

Companies in this story: fscom

People in this story: Nicola Hanratty, Stuart Smith, Philip Creed

More from News