Changing risk profile

Financial crime is now systemic

Financial crime is not a minority problem.

Financial crime is no longer characterised by a small number of dominant threats. Survey responses show organisations are experiencing a broad range of financial crime risks, with relatively little variation in how frequently they occur. This breadth means resources must be spread across multiple priorities, making it harder to concentrate investment on any single area. Against this backdrop, AI-enabled fraud stands apart as the one threat respondents believe is accelerating faster than their ability to respond.

0%

Risk exposure is widespread

Most financial crime risks affect organisations at broadly similar levels, reinforcing the need to manage multiple threats simultaneously.

Exposure is broad across all major financial crime risks, with digital identity and KYC weaknesses reported most frequently.

Digital identity and KYC continue to present a significant operational challenge, particularly for banks, where customer onboarding and identity verification processes create a larger attack surface.

Key statistic

Attack capability is outpacing defence capability

AI-enabled fraud is the one threat respondents believe is evolving faster than their organisations can respond. While it is not the most widely experienced risk, those who have encountered it consistently report that attacker capability is advancing faster than existing controls. This suggests the challenge is less about recognising the threat than adapting quickly enough to keep pace.

0%

Fastest-moving threat

76% say AI-enabled fraud is outpacing organisational response

AI-enabled fraud stands apart from every other threat. Among organisations that have experienced it, over three-quarters say it is evolving faster than they can respond, highlighting a widening gap between attacker capability and organisational controls.

Organisations experiencing AI-enabled fraud are investing sooner and more heavily, particularly in fraud prevention and AI governance.

Industry perspectives

Industry leaders reflect on the report’s key findings.

Alison R Kopra, Director, Financial Crime, Grant Thornton UK Advisory & Tax LLP

"In last year's National Risk Assessment, HMT flagged electronic money institutions and payment service providers as high risk. The FCA has noticeably increased scrutiny, with a surge in thematic reviews, skilled person reviews and voluntary requirements. We've also seen the first payments firm shut down over financial crime failings. Firms must clearly delineate their approach to crypto and e-money, backed by robust due diligence and effective governance. It's a delicate balancing act for fast-growing fintechs."

About Grant Thornton

Ben Cooper, Partner, TLT LLP

"The next frontier in financial crime compliance is not collecting more data, but extracting better intelligence from the data firms already hold. As criminal methodologies become faster and more sophisticated, organisations that can connect signals across fraud, AML, customer behaviour and operational risk will detect emerging threats earlier, respond more effectively and make better strategic decisions."

About TLT LLP

Lukas Reid, Senior Compliance Associate, fscom

"Following the FCA’s sanctions review, firms should focus on developing granular, tailored sanctions risk assessments that reflect their specific geographic and customer exposures. Screening should operate as an end-to-end control across the customer and transaction lifecycle, with clear governance over investigations and escalation. Where controls are outsourced, responsibility is not. Firms must retain ownership of matching logic, thresholds and list coverage. And crucially, data quality remains critical - effective screening depends on reliable inputs.”

About fscom

Executive summary

Previous page

Operational impact

Next page