Regulatory landscape

Regulation is struggling to keep pace

Jump to findings

Organisations face uncertainty on multiple regulatory fronts

APP fraud emerges as the most significant operational challenge, while insider fraud is experienced more widely across the sector. These findings highlight an important distinction: the most severe risks are not always the most prevalent. Organisations therefore need to balance specialist capabilities for high-impact threats with broad controls that strengthen resilience across the wider financial crime landscape. The following section explores where this creates the greatest operational uncertainty.

Key statistic

Two regulatory changes tie for top concern

AI regulation and AML reform cause equal uncertainty. 19% of respondents name each one as the regulatory or policy change causing them the most operational uncertainty (base: 100). The tie matters because the two point in opposite directions. AML reform revises a mature regime, familiar in substance and demanding in detail. AI regulation introduces a new one, where obligations are still forming and firms must prepare for rules that have not yet settled. Compliance teams absorb both at once, with the same people and the same budget. Both land as the same practical question—what does good practice actually look like in operation. On that question, the industry says it has been left without an answer.

0%

Identify AI regulation as their leading regulatory concern

The findings suggest regulatory pressure is cumulative. AI regulation and AML reform are the leading concerns, but uncertainty is spread across a wide range of policy changes rather than concentrated in one area.

AI regulation is a leading source of uncertainty for both banks and fintechs, suggesting the challenge is shared across the sector rather than confined to one type of organisation.

Case Study: TLT strengthening fraud controls through better data and governance

Several firms operating in the UK payments sector identified a common challenge: fraud typologies were evolving faster than traditional control frameworks. While organisations generated significant volumes of data, they often struggled to connect insights across fraud, compliance, customer service and operational risk.

In response, firms reviewed fraud controls, governance arrangements and management information to develop a more holistic view of risk. By combining behavioural data, customer interactions, transaction activity and emerging fraud intelligence, they were able to improve management information, strengthen governance reporting and refine transaction monitoring controls.

A key lesson emerging across the sector is that effective fraud prevention is no longer solely a technology challenge. Success increasingly depends on turning operational and compliance data into actionable intelligence that strengthens controls, improves customer outcomes and supports better decision-making.

---- This case study is illustrative and based on common issues observed across the UK payments and financial services sector. It does not describe any single client engagement.

About TLT LLP

TPA member case studies

Practical examples from across banking, fintech and payments, showing how organisations are strengthening financial crime controls through governance, technology, operational resilience and compliance.

Case Study: fscom – Independent assurance for sanctions screening

A UK-regulated financial services firm, headquartered overseas, sought independent assurance over its sanctions screening framework amid increasing regulatory scrutiny. The review required validation of both governance arrangements and the technical effectiveness of the firm’s customer screening controls, including an overnight SQL script and API integration. fscom assembled a multidisciplinary team of sanctions, AML and technical specialists to deliver a comprehensive assurance review. Through document analysis, stakeholder interviews and technical testing, the team assessed the design and operation of key controls using a structured methodology with clearly defined test strategies, sampling approaches and reporting criteria. Regular progress updates ensured transparency and alignment with the client’s target completion date. The review provided the board and senior management with independent confidence in the effectiveness of the sanctions screening framework while identifying practical opportunities to further strengthen controls. Beyond the technical validation, the engagement improved collaboration between compliance, risk and technology teams, creating a more joined-up approach to financial crime risk management. The client commended fscom’s collaborative and transparent approach, valuing the clear, actionable recommendations that helped strengthen its control environment.

About fscom

Case Study: Nasdaq Verafin – Global trends reinforce UK survey findings

Many of the themes identified in The Payments Association Survey—including fraud prevention, AI-enabled crime, cross-border fraud, real-time monitoring and data sharing—are reflected in Nasdaq Verafin’s 2026 Global Financial Crime Report, demonstrating that the challenges facing UK organisations are part of a broader global trend.

The report estimates that illicit financial activity reached $4.4 trillion in 2025, increasing by $1.3 trillion in just two years and significantly outpacing global GDP growth. Fraud remains one of the most pressing challenges, with global fraud losses rising to $579.4 billion, including $43.3 billion in the UK. Criminals are increasingly targeting consumers directly, with fraud scams growing at a 19.3% compound annual growth rate, more than twice the rate of traditional bank fraud (8.2%), driven by social engineering, authorised push payment (APP) fraud and increasingly sophisticated scam typologies, many of which are being amplified by AI.

The report also highlights the growing international dimension of financial crime. Cross-border transaction volumes have tripled over the past decade, creating greater opportunities for both global commerce and criminal activity. In 2025, $482.9 billion in illicit funds moved across international borders, including $23.1 billion linked to the UK, as criminal networks exploited faster, more interconnected payment ecosystems.

These findings reinforce the conclusions of this report: as financial crime becomes more sophisticated and interconnected, organisations will need to combine AI-driven detection, stronger governance, network-level intelligence and closer collaboration across industry, regulators and law enforcement.

Read the report

Case Study: MHA – From registry data to verified ownership

A UK payments firm reviewed its corporate onboarding processes after identifying that Companies House filings were being treated as verification rather than as a source of information. Testing across the merchant portfolio found registry data being accepted without independent corroboration, ownership traced only to the immediate parent, and no defined approach to the identity verification regime introduced under the Economic Crime and Corporate Transparency Act.

The firm strengthened its beneficial ownership standard by requiring independent evidence of control at every level of the ownership structure and introducing a controlled process for reporting discrepancies to Companies House with clear ownership and accountability.

The review resulted in a third of legacy merchants requiring remediation, several long-standing relationships being exited, and PSC information now being revalidated as part of every periodic review.

Learn more

Case Study: Guardexia – Strengthening safeguarding through clearer reconciliation

The safeguarding problem wasn’t the reconciliation itself; it was understanding what needed to be reconciled.

A UK-regulated payments firm found that safeguarding reconciliations were taking several hours to complete because key questions around customer funds, unidentified receipts and account treatment were being resolved manually before the process could begin. As delays increased, unidentified funds accumulated, making each subsequent reconciliation more difficult.

The firm first established a clear safeguarding methodology before introducing daily matching between internal and external records. The result was not simply a faster reconciliation process, but greater confidence that customer funds could be identified, evidenced and understood at any point in time, including during a wind-down or insolvency scenario.

About Guardexia

Case Study: Projective Group – Building a consistent approach to fraud risk

A global investment bank engaged Projective Group to conduct an independent review after identifying gaps in its fraud risk assessment approach. While fraud risks were being assessed across individual business units, the bank lacked a common framework, consistent language and a consolidated view of fraud exposure across jurisdictions and business lines.

Using a structured fraud taxonomy aligned to UK and European fraud typologies, Projective Group mapped fraud risks to a standardised set of scenarios, linking them to preventive and detective controls. The review identified previously unassessed fraud exposures, reduced duplication across risk assessments and established a consistent methodology for evaluating fraud risk and control effectiveness.

The bank subsequently adopted the taxonomy as the foundation of its fraud risk assessment framework, improving reporting, supporting clearer stakeholder communication and creating a scalable approach to managing fraud risk across multiple regions and regulatory environments.

Contact Projective Group

Case Study: Worldpay (now Global Payments) – Building trust in agentic commerce

Financial crime is the leading reason consumers hesitate to let AI agents shop and pay on their behalf. In Worldpay’s 2025 Agentic Commerce Report, which surveyed 8,000 consumers across seven markets, the three leading concerns were identity theft (55%), incorrect or unauthorised purchases (55%) and fraud (53%), each cited by more than half of respondents.

Consumers are equally clear about what would build trust. Fraud protection (54%), the ability to cancel a transaction within 24 hours (50%) and a review step before purchase completion (49%) ranked as the most important safeguards. For financial crime teams, the message is clear: consumers are not rejecting AI agents, but they expect the same fraud controls and reassurance they already receive for human-initiated transactions, adapted for a machine-speed environment.

Worldpay, now Global Payments, will publish an updated Agentic Commerce Report in September 2026, exploring how consumer attitudes continue to evolve as adoption grows.

Read the full report

Case Study: RelyComply – Consolidating controls to support growth

Rapid-growth fintechs face a common challenge: the point solutions that support launch often struggle to support scale. This pressure is becoming more acute for UK firms as the APP reimbursement regime and the Failure to Prevent Fraud offence increase the cost of fragmented financial crime controls.

Purple Group, the listed digital investment group behind EasyEquities, encountered this challenge while expanding internationally and serving more than three million customers. Fast digital onboarding was both its competitive advantage and its most exposed risk surface, but a fragmented compliance stack limited visibility of financial crime risk across markets.

The group consolidated its compliance and fraud capabilities into a single anti-financial crime platform, bringing together identity verification, screening and fraud prevention within a scalable framework. This provided more consistent risk oversight across markets and transformed onboarding from a compliance checkpoint into a stronger foundation for growth.

Learn more

Severity & operational uncertainty

Previous page

AI governance

Next page