Investigating financial fraud: the signals that precede the numbers
ArticleFraud rarely appears overnight. Learn the early warning signs auditors and CFOs should watch for, using the a real life case study.
By: Sam Haskins
23 Sep 2026 7 min read

Existing MLR registration will not automatically convert into authorisation under the Financial Services and Markets Act (FSMA). Firms carrying on activities within the new cryptoasset perimeter will need to secure the appropriate FSMA permissions, including firms already registered under the MLRs. Firms already authorised under FSMA for other activities will need to vary their permissions where necessary. The application window opens on 30 September 2026 and closes on 28 February 2027, ahead of the new regime starting on 25 October 2027.
For financial crime teams, however, the more interesting point is what the FCA has said about the standard firms will need to meet. The FCA describes the financial crime assessment under the new regime as broader than MLR registration, covering governance, systems and controls, resources and readiness. It also says firms should be able to evidence an approach calibrated to their transaction flows and typology exposure rather than relying on generic documentation. For pre-launch firms, that evidence might include process maps, system configuration, scenario testing, user acceptance testing, governance sign-off and mobilisation plans.
The practical implication is that authorisation preparation cannot be treated primarily as a policy-writing exercise. A firm will need to be able to explain how its business model creates financial crime risk, where that risk arises in the customer and transaction journey, what controls respond to it and how it knows those controls work – or, for a pre-launch firm, are ready to work.
The Business-Wide Risk Assessment (BWRA) remains the foundation of the financial crime framework, but a generic catalogue of crypto risks will not be enough. The FCA says a strong BWRA should be grounded in the firm’s transaction flows and exposure points and should consider its products and services, customer types and expected use cases, geographic exposure, delivery channels, transaction risk, and its interaction with counterparties and third parties. Firms should also be able to explain which typologies are relevant to their own model and how their controls mitigate them.
Rather than beginning with policies, firms should map how customers and value actually move through the business: onboarding; fiat funding and withdrawal; crypto transfers and custody; counterparties; Travel Rule touchpoints; sanctions exposure; fraud risk; and the systems and third parties supporting each stage.
A credible framework should allow someone to trace a reasonably clear line from business model to transaction flows to risks to controls to monitoring and escalation to MI and assurance.
This is particularly important for integration-led, non-custodial and partner-heavy models. A firm may outsource onboarding, wallet infrastructure, blockchain analytics, payment processing or other activities, but responsibility does not move with the activity. Firms relying on third parties should be able to explain which controls are performed by whom, what information is exchanged, how risk is managed end-to-end and what oversight and assurance the firm retains.
A second point in the FCA’s Q&A is the relationship between AML and the wider financial crime framework. The FCA says AML/CTF/CPF controls sit alongside sanctions and fraud and that this should be reflected in governance, risk assessment, monitoring, escalation and the way controls operate across the customer journey.
One transaction might involve unusual customer behaviour, a high-risk wallet, a sanctions connection, a fraud indicator and a Travel Rule issue. A data problem affecting a common platform might weaken transaction monitoring, sanctions screening and fraud detection at the same time.
Customer risk factors should inform CDD and EDD but also the way subsequent activity is monitored. Blockchain analytics alerts should be considered alongside the customer profile, fiat payment activity and other financial crime information rather than treated as an isolated on-chain signal. Travel Rule exceptions may also warrant consideration as part of the wider risk picture rather than being handled solely as technical exceptions.
The FCA expects governance over screening data and tools, with testing or quality assurance to assess whether screening continues to work effectively. This does not require every financial crime control to sit in the same team, but the firm should be able to explain how information moves between them, who makes decisions when risks overlap and what senior management sees.
The Q&A also draws a direct connection between operational resilience and financial crime. The FCA says disruption to systems and processes, ineffective change management and weak oversight of third-party arrangements can create or amplify financial crime exposure. It also points firms towards the implications of common infrastructure and concentrated third-party providers.
For many crypto firms, this matters because the same provider or internal platform may support customer verification, transaction data, wallet screening or monitoring. If that dependency fails, produces incomplete data or is changed without adequate testing, the effect may extend across several controls.
Authorisation preparation should therefore examine the dependencies underneath the financial crime framework, not only the controls visible at the surface. That includes understanding data lineage, system interfaces, vendor responsibilities, configuration, change controls, incident handling and the firm’s ability to identify when a control has stopped operating as intended.
The evidential question is different for a firm that already has customers and one that has not yet launched. That could include CDD decisions, transaction-monitoring alerts, blockchain analytics outputs, sanctions-screening results, fraud cases, Travel Rule exceptions, internal suspicious-activity escalations, SARs, QA findings, MI, remediation and third-party oversight.
For these firms, the assessment is likely to move quickly from design into performance. What has the framework identified? What happened next? What does the data say about its effectiveness? What weaknesses have emerged, and what has management done about them? The quality of the underlying policies still matters, but operating evidence provides a much clearer view of whether those policies translate into an effective control framework.
Instead, firms can demonstrate readiness through control-design documentation, process maps, configuration evidence, scenario testing and UAT, management information, governance approval and a credible mobilisation plan. The standard is not to produce historical alerts where none can exist, but to provide enough evidence to show that the framework has been properly designed, implemented and tested and is capable of operating when customers arrive.
That also applies to governance. The FCA expects clear senior ownership, effective escalation and management information, and people in important AML roles - including the MLRO - with appropriate experience, competence, time and resources. Where responsibilities are combined, firms need to explain how conflicts are managed and how effective challenge is maintained. They should also be able to explain when roles will need to separate as the business grows.
A lean model can therefore be proportionate. What matters is whether it is credible for the business at launch and whether the firm understands what will trigger additional people, controls or governance as volumes and risk increase.
With the application window opening on 30 September, perimeter analysis and permissions remain the starting point: firms should confirm which activities fall within the new regime and what permissions they will need. But financial crime preparation should go further than assembling the application pack.
Firms should map their customer and transaction flows; identify the financial crime risks at each stage; test whether the BWRA accurately describes those risks; map controls and ownership; and identify the systems, data and third parties on which those controls depend. They should then ask a harder question: what evidence could we show the FCA today?
For an operating firm, that means testing what its actual control outcomes, MI, escalations and assurance say about the framework. For a pre-launch firm, it means showing that the framework has moved beyond design into configuration, testing, governance approval and operational readiness.
That is the practical shift from MLR registration to FSMA authorisation. Policies will still matter, but the stronger application will be the one in which the FCA can see how the financial crime framework follows the actual business: where the risk arises, how the controls respond, who owns them, what happens when something goes wrong and how the firm knows the framework remains effective.
Sam Haskins is a Partner in Grant Thornton UK’s Financial Crime practice who leads major advisory and transformation engagements for global and mid-tier financial institutions, including banks, payments firms and FinTechs, working alongside senior management, boards and regulators.
Fraud rarely appears overnight. Learn the early warning signs auditors and CFOs should watch for, using the a real life case study.
Nested relationships in correspondent banking can expose firms to hidden financial crime risks. Learn how to improve oversight, transparency and monitoring.
Practical guidance on preparing for an FCA sanctions compliance review, covering regulatory expectations, programme readiness and how to respond effectively.