On 28 May 2026, the Financial Conduct Authority (“FCA”) published the outcome of a supervisory exercise assessing how over 150 FCA regulated firms manage their sanctions obligations. This latest report builds on the FCA's September 2023 review of firms' responses to the UK's significant expansion of its sanctions against Russia following its 2022 invasion of Ukraine. It draws on proactive and reactive supervisory casework, together with data reported to the FCA, since that earlier publication.
The results are promising: the FCA saw repeated examples of improvement since 2022, with firms putting strong controls in place that, on many occasions, identified potential breaches before they occurred. Nonetheless, as sanctions risk becomes a standing supervisory priority, the FCA has flagged several pervasive weaknesses that firms must still address.
Key Findings
The FCA noted that several firms had built robust frameworks that successfully intercepted possible violations at an early stage. Where breaches did occur, they were most frequently attributed to:
Due diligence and ongoing monitoring deficiencies;
Mixed standards in governance and oversight, policies and procedures, business risk assessments, and alert management systems, including in relation to escalation of screening hits;
Transaction and counterparty screening weaknesses; and
Frozen asset administration, including non-compliance with licence conditions.
Separately, trade sanctions emerged as a distinct area of concern. Trade sanctions concern the cross-border flow of goods, technology and services, including restrictions on services ancillary to that trade, such as financing or technical assistance connected to restricted goods. Financial sanctions, by contrast, focus on the movement of funds and access to financial services, including asset freezes, capital-markets restrictions (for example, dealing in transferable securities or the provision of loans) and prohibitions on providing funds or economic resources to designated persons.
The FCA observed a marked disparity in the sophistication of controls deployed in trade sanctions relative to those governing financial sanctions, with firms adopting a wide and inconsistent range of compliance approaches. Given this, the FCA expects firms to give trade sanctions compliance closer attention and to strengthen their related systems and controls.
Sanctions Regimes in Focus
The FCA's findings are set against significant growth in the scale of UK sanctions activity: the value of UK assets reported frozen rose from £24.4 billion in 2023–24 to £37 billion in 2024–25. While the volume of suspected breach reports from FCA-supervised firms fell across 2023–2025, the figure remains substantial relative to pre-2022 levels, reflecting the expanded scope and complexity of the UK's sanctions regimes. Most reported breaches continue to relate to financial sanctions, with only a small proportion concerning trade sanctions.
Russia-related obligations remain the primary driver of breach reporting across the sector. However, the FCA exercise discovered a growing proportion of reports linked to Libya, Iran, and North Korea. This trend underscores the need for a well-established sanctions compliance framework covering the full spectrum of active UK sanctions programmes and obligations.
Good and Poor Practice
As part of the exercise, the FCA released detailed observations on effective and ineffective practices. The FCA has been clear that it views this publication as a tool for firms to self-assess and improve, not simply as a record of supervisory findings. Firms are therefore encouraged to proactively implement good practice into their business effectively aligning with sanctions compliance.
Accordingly, we have set out a list of practical next steps below for firms to consider when assessing internal sanctions frameworks.
A New Memorandum of Understanding with OTSI
Alongside the report, the FCA signed a Memorandum of Understanding with the Office of Trade Sanctions Implementation (“OTSI”), which is responsible for civil enforcement of UK trade sanctions. The MoU sets out arrangements for cooperation and the sharing of intelligence between the two authorities, on both a proactive and request-based footing, covering suspected sanctions breaches, weaknesses in firms' controls and broader intelligence relevant to either authority's remit. It sits alongside the FCA's existing MoU with the Office of Financial Sanctions Implementation (“OFSI”), meaning both financial and trade sanctions enforcement now have a formal channel for information exchange with the FCA. Taken together with the FCA's framing of sanctions as a standing supervisory priority, the practical message for firms is that intelligence on control weaknesses will increasingly flow between regulators and enforcement bodies — and that financial and trade sanctions can no longer be treated as siloed compliance workstreams.
Recommendations and Practical Next Steps
Maintain up-to-date sanctions and governance documentation. Ensure internal documentation is current, internally consistent and addresses the full range of applicable restrictions, including sectoral, trade, and investment bans.
Oversee compliance arrangements locally. Where compliance arrangements rely on group functions, vendors, or other third parties, firms should document clear local ownership, oversight, assurance, and escalation responsibilities, as well as ensure that the vendor’s offering is sufficiently robust to satisfy the firm’s sanctions obligations.
Strengthen risk assessments. Maintain documented, current and sufficiently granular risk assessments covering customer, product, service, transaction, and jurisdictional exposure, together with an assessment of the strength of related controls.
Review screening tools and alert management. Ensure screening policies define scope, frequency, escalation thresholds, and governance arrangements, and that screening systems cover all relevant customer, counterparty, and transaction data.
Strengthen sanctions list management and vendor controls. Ensure that updates to the UK Sanctions List are captured promptly and completely, and accurately integrated into screening systems, including where screening is performed by a vendor. Firms should periodically calibrate their sanctions tools and test screening logic to identify name formats, such as titles, single-word names or names exceeding character limits that may depress match scores or fall outside system thresholds.
Improve customer and reference data quality. Remediate gaps in customer records, and supplement primary screening lists with internal and external data sources where needed to identify entities owned or controlled by sanctioned persons.
Strengthen customer due diligence frameworks. Integrate sanctions risk explicitly into customer due diligence (“CDD”) and enhanced due diligence processes, with particular attention to beneficial ownership identification and the screening of complex or multi-layered corporate structures. The FCA has re-iterated the importance of robust CDD measures and this is a key focus for it.
Develop intelligence-led evasion detection capabilities. Supplement name and payment screening with additional techniques (e.g., transaction monitoring, data analysis, thematic reviews, open-source research, and intelligence-led investigations) to detect sanctions evasion that messaging data alone does not reveal. Ensure internal documentation and training cover common evasion typologies.
Audit frozen asset and licence compliance procedures. Confirm that clear, documented workflows exist for identifying, segregating, and monitoring frozen assets to prevent movement of frozen funds. Consider recording all activity under OFSI licences with a full audit trail.
Develop dedicated trade sanctions controls. Firms involved in trade finance, export credit, or services connected to controlled goods and dual-use technologies should assess whether their existing financial sanctions controls adequately address trade-specific risks – in many cases, dedicated internal systems and controls will be required.
Embed role-specific sanctions training. Implement sanctions training specific to the firm’s business model, internal processes, and higher-risk control areas, rather than relying solely on generic all-staff modules.
Maintain contingency and operational resilience plans for sanctions controls. Maintain tested contingency arrangements for screening-system outages, list-update failures, and periods of reduced operational coverage.
Formalise breach reporting and root-cause remediation. Firms should maintain well-documented procedures for identifying, escalating and reporting suspected financial and trade sanctions breaches, and for analysing root causes so that findings feed back into controls, risk assessments, and remediation. Note that reporting obligations extend beyond OFSI to OTSI and HMRC — the FCA found many firms lacked procedures for the latter two.
Benchmark against the FCA’s good and poor practice. Use published examples as a diagnostic tool to identify areas where current controls fall short of regulatory expectations and prioritise remediation accordingly.
Prepare for increased inter-agency coordination. The new FCA-OTSI MoU means intelligence sharing between agencies will increase. Ensure compliance teams are structured to address both financial and trade sanctions obligations in a coordinated manner, with clear internal escalation pathways and consistent record-keeping.
Stay Up To Date with Ropes & Gray
Ropes & Gray attorneys provide timely analysis on legal developments, court decisions and changes in legislation and regulations.
Stay in the loop with all things Ropes & Gray, and find out more about our people, culture, initiatives and everything that’s happening.
We regularly notify our clients and contacts of significant legal developments, news, webinars and teleconferences that affect their industries.





