← View all articles
Off-the-Shelf Controls Aren't Enough: The Operational Lesson Behind the FCA's Annex 1 Warning
UK Compliance 5 min read By CommsPliant Editorial Team Published 10 August 2026

Off-the-Shelf Controls Aren't Enough: The Operational Lesson Behind the FCA's Annex 1 Warning

Listen to the audio briefing

A short audio version of this article for busy compliance, operations and product teams.

This audio briefing is for general information only and does not constitute legal or regulatory advice.

On 7 August 2026, the Financial Conduct Authority announced increased scrutiny of Annex 1 firms, including unregulated lenders, safe custody providers, money brokers and financial leasing companies.

The FCA's concern is specifically about financial crime risk.

But one part of the statement carries a broader operational lesson for regulated businesses: controls cannot simply be borrowed from another organisation and assumed to work.

The FCA said it had seen firms relying too heavily on the financial crime controls of their parent companies. It stressed that each firm needs to assess whether those controls are appropriate for its own risks, governance and operations. It also warned against relying on off-the-shelf procedures designed for a different company.

That distinction matters.

A policy may be approved centrally. A procedure may look correct on paper. A template may have been reviewed by compliance.

But what happens when those controls move into everyday operations?

What are Annex 1 firms?

Annex 1 firms include certain businesses such as unregulated lenders, safe custody providers, money brokers and financial leasing companies.

They are required to register with the FCA for anti-money laundering purposes, but they are not necessarily authorised firms subject to the FCA's wider rulebook. Earlier this year, the FCA said there were around 1,200 Annex 1 firms registered solely for anti-money laundering supervision.

The FCA has been examining this sector for some time.

In 2024, it identified weaknesses including financial crime controls that had failed to keep pace with business growth, poor risk assessment and inadequate oversight.

The latest statement goes further.

The FCA has now sent information requests to around 900 Annex 1 firms, following work involving another 300 firms in late 2025. It says this means it will have contacted all registered Annex 1 firms.

The important phrase: "tailored to the way they operate"

The FCA's August statement is about financial crime controls, not specifically customer communications.

That distinction is important.

But the operational principle deserves attention beyond the immediate AML context.

A control is only useful if it works within the organisation that is expected to follow it.

Two companies within the same group can have different products, customers, approval structures, technologies and operational risks. Copying a parent company procedure does not automatically reproduce the control environment behind it.

The same problem can appear further downstream.

An organisation might have a carefully approved policy explaining how customers should be informed about a particular decision, payment, obligation or regulatory requirement.

But the actual communication may exist somewhere else entirely:

At that point, the question is no longer only:

"Do we have an approved policy?"

It becomes:

"Can we demonstrate how that policy is being applied in the communications produced by the business?"

From policy to operational communication

Consider a relatively ordinary change.

A firm updates a procedure and compliance approves new wording that needs to appear in a customer notice.

The policy is correct.

The wording is approved.

But implementing it could still involve several disconnected steps:

Policy change → communication update → review → approval → system release → customer output

If those steps happen across email, tickets, documents, code repositories and shared folders, the governance surrounding the original policy can become progressively harder to see.

Several practical questions then appear:

Which communication version contains the approved wording?

Who reviewed it?

Who authorised the change?

When did the new version become active?

Were older versions still being used somewhere else?

Which version would the organisation produce if asked about a communication six months or three years later?

None of these questions means the organisation has done something wrong.

They illustrate something simpler: good policy governance and good operational evidence are not automatically the same thing.

Standardisation is useful. Blind standardisation is not.

There is nothing inherently wrong with using shared procedures, group policies or standard templates.

Standardisation can reduce duplication and improve consistency.

The danger appears when standardisation becomes substitution for understanding the actual operating environment.

A template designed for one company may assume a particular product, customer journey, approval process or regulatory perimeter.

A parent-company procedure may assume controls or systems that do not exist in a subsidiary.

And an approved communication may gradually diverge when different operational teams maintain their own copies.

This is why tailoring does not necessarily mean creating everything from scratch.

It means knowing what is controlled, what may vary and how changes are governed.

The evidence question

The FCA's increased scrutiny of Annex 1 firms also highlights another practical reality.

When a regulator asks questions, organisations may need to move quickly from saying that a control exists to demonstrating how it operates.

For Annex 1 firms, the FCA is currently seeking information about activities, business models and risks as part of its supervision.

For operational communications, an equivalent evidence trail might need to connect:

approved wording → approved version → release → communication event → audit record

The purpose is not to create more paperwork.

Ideally, the evidence should be a consequence of the normal workflow rather than something assembled afterwards.

That is particularly important for high-volume regulated communications, where manually reconstructing the history of individual templates or approvals may become difficult very quickly.

Where a governance layer fits

This is the gap CommsPliant is built to close.

It does not replace a firm's CRM, claims platform or existing communications tooling, and it does not tell a firm what its policy should say. It sits alongside those systems as a governed layer for the templates and wording that produce customer communications, with version control, approval workflows and cryptographically verifiable evidence of what was rendered and when.

The result is an audit-ready evidence chain from approved wording to rendered communication, built into the normal communication workflow.

Instead of assembling an evidence pack after the event from tickets, folders, emails and different systems, teams can trace which version was approved, who approved it, when it became active, what was rendered and when the communication event occurred.

That makes audit readiness part of the process rather than a separate reconstruction exercise.

For teams managing regulated communications at scale, the practical benefit is straightforward: less manual evidence gathering, less operational effort, and a faster path to answering audit or regulatory questions when they arise.

The broader lesson

The FCA's 7 August statement should primarily be read for what it is: a warning about weaknesses in financial crime controls among Annex 1 firms.

But its message about firm-specific controls raises a useful operational question for regulated organisations more generally.

Are the controls described in policy still visible when the organisation actually communicates with customers?

A procedure can be tailored.

A template can be approved.

A policy can be signed off.

The harder challenge is maintaining that control as wording moves through people, systems, versions and releases.

For regulated communications, governance should not end when the policy document is approved.

That is often where the operational part begins.

If this is a live question inside your organisation, particularly where approved wording is managed separately from where it is actually deployed, get in touch to discuss your current workflow.

Let’s Talk

This article is for general information only and does not constitute legal or regulatory advice.

Sources