FCA AML Enforcement: Lessons from the Euro Exchange Securities Investigation and London Crypto Crackdown
The UK Financial Conduct Authority (FCA) has spent the past several years steadily sharpening its anti-money laundering (AML) enforcement posture. That trend is now visible in two distinct but related actions: an investigation into Euro Exchange Securities UK Ltd (EES) for potential offences under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, and enforcement against an unregistered peer-to-peer crypto trading operation in London. Together they illustrate a single regulatory message — AML compliance is no longer a paperwork exercise, and transaction monitoring failures carry existential consequences.
This article examines what the FCA has alleged, the regulatory framework behind these actions, and what financial institutions and crypto firms should do now to avoid becoming the next enforcement headline.
Case Details: What the FCA Is Investigating
The Euro Exchange Securities Investigation
The FCA has opened an investigation into Euro Exchange Securities UK Ltd for potential offences under the Money Laundering Regulations 2017 (MLRs). The alleged failures are broad and structural, centering on:
- Inadequate money laundering risk assessments — including customer, geographic, service, transaction, and delivery channel risks — and insufficient documentation or updating of those assessments.
- Failure to establish and maintain effective policies, controls, and procedures to mitigate money laundering risk, particularly in customer due diligence (CDD), ongoing monitoring, internal governance, resourcing, record-keeping, and escalation/reporting.
The investigation follows earlier supervisory action. According to the FCA's published supervisory notices, the firm was required to cease regulated e-money and payment services, interim managers were appointed by the court, and a First Supervisory Notice subsequently confirmed restrictions and imposed an assets requirement to safeguard customer funds, including ringfencing in a designated account. No conclusions have been reached in the investigation, and the firm has not been found liable. Readers should verify the latest status directly on the FCA register and in the FCA's supervisory notices.
The EES case is notable less for any single allegation than for its breadth. The FCA is not claiming one control failed — it is alleging the entire AML operating model was deficient, from risk assessment through to escalation. That is the pattern regulators increasingly target.
The London Crypto Trading Crackdown
Separately, the FCA has taken action against an illegal peer-to-peer crypto trading operation operating from three suspected premises across London. The action reflects the FCA's growing scrutiny of unregistered crypto businesses and its mandate to protect consumers and maintain market integrity in the digital asset space.
Details of the enforcement mechanism remain limited, and readers should treat characterizations of the operation with caution. What is defensible is the broader pattern: the FCA and law-enforcement partners have repeatedly targeted unregistered peer-to-peer and crypto ATM operators that bypass AML and know-your-customer (KYC) requirements. Unregistered crypto firms pose well-documented risks to consumers and the financial system, and the FCA has warned consistently that firms operating outside the registration regime face shutdown.
Regulatory Context: Why This Matters Now
A Principles-Based Regime With Sharp Teeth
The FCA operates a principles-based approach, but that flexibility is paired with prescriptive AML obligations. The Money Laundering Regulations 2017 implement the UK's transposition of the EU's Fourth Anti-Money Laundering Directive (4AMLD). The Fifth Anti-Money Laundering Directive (5AMLD) was implemented separately through the Money Laundering and Terrorist Financing (Amendment) Regulations 2019, with further amendments in 2020. Understanding this lineage matters because the MLRs are not a single static instrument — they have been layered and updated, and firms must track those changes.
Under the MLRs, regulated firms must appoint a nominated officer (MLRO) responsible for oversight of AML compliance and internal suspicious activity reporting. The UK's Suspicious Activity Report (SAR) regime, administered by the National Crime Agency's UK Financial Intelligence Unit (UKFIU), is a central pillar — and it places real weight on defensive reporting, where firms file SARs proactively rather than waiting for certainty. Record-keeping obligations under the MLRs require retention of CDD and transaction records for five years after the end of the business relationship or the transaction.
Crypto as a Financial Crime Vector
The rise of crypto-related financial crime has pushed digital assets firmly into the regulatory perimeter. Unregistered peer-to-peer trading, crypto ATMs, and mixers are recurring enforcement targets because they can operate outside AML/KYC controls entirely. For registered firms, the challenge is different but no less serious: crypto exposure can appear on the customer side, the counterparty side, or through payment rails, and it must be caught by transaction monitoring rather than discovered during an FCA visit.
Geographic Balance: How the UK Compares
For firms building a global AML programme, the UK regime sits alongside two other major frameworks. In the United States, the Bank Secrecy Act (BSA), administered by FinCEN, requires Currency Transaction Reports for cash transactions over $10,000 and Suspicious Activity Reports with dollar thresholds of $5,000 for banks and $2,000 for money services businesses, filed within 30 days (60 if no suspect is identified). Critically, US SARs are confidential — their existence must not be disclosed to the subject. In the EU, the 2024 AML Package established the Anti-Money Laundering Authority (AMLA) in Frankfurt, operational from mid-2025, with direct supervision of the highest-risk entities expected from 2028. Firms operating across all three jurisdictions should map controls to the strictest common denominator rather than treating them as separate silos.
Compliance Lessons: What Went Wrong and What to Do
The EES allegations map onto a familiar set of control failures. Each has a practical countermeasure.
- Risk assessments must be documented, current, and specific. Generic, template-driven assessments are a red flag. Firms should assess customer, geographic, service, transaction, and delivery channel risk — and evidence when they were last updated and why.
- Enhanced due diligence (EDD) must be risk-triggered. High-risk customers, PEPs, and complex ownership structures require EDD that is actually applied, not just policy language.
- Transaction monitoring must be tuned, not just switched on. Alert volumes that overwhelm analysts create backlogs and missed true positives. Monitoring rules should be calibrated to the firm's actual risk profile.
- SAR filing must be timely and defensible. Defensive reporting is expected. A firm that waits for certainty before filing is a firm that will be criticized.
- Governance and resourcing are control issues. The FCA explicitly cited internal governance and resourcing in the EES matter. Understaffed compliance functions are a supervisory finding waiting to happen.
- Training must be role-specific. Front-line staff, relationship managers, and analysts need different training. One annual e-learning module does not satisfy the MLRs' spirit.
The common thread in AML enforcement is not a single missed alert — it is the absence of a coherent, documented, and resourced control environment.
How Technology Supports AML Compliance and Transaction Monitoring
Technology is not a substitute for governance, but it is increasingly the only realistic way to operate effective transaction monitoring at scale. Three categories of tooling matter most:
- Transaction monitoring and customer risk scoring — rules engines and machine-learning models that score customers and flag anomalous activity.
- SAR automation and case management — tools that generate evidence briefs in FinCEN-compatible formats and maintain audit trails.
- Cross-domain risk intelligence — platforms that correlate signals across HR, finance, security, and communications to surface compound risk that siloed systems miss.
Platforms such as RisksRadarAI (risksradarai.com) fall into this space, offering AI-powered AML transaction monitoring, customer risk scoring, and automated SAR/STR generation with evidence briefs and immutable audit logs. Customer-reported reductions in false positives are one of the reasons firms evaluate such tools, though buyers should validate vendor claims through proof-of-concept testing against their own data rather than relying on marketing figures.
It is worth being clear-eyed about alternatives. Firms can build in-house monitoring using open-source rules engines, buy from incumbent AML vendors with long track records in banking, or adopt newer AI-native platforms. The right choice depends on portfolio complexity, data residency requirements, and existing ERP and core banking integrations. A build-vs-buy assessment should be documented as part of the AML programme itself.
For teams evaluating the broader compliance technology stack, AIGovHub's vendor marketplace lets you compare AML and financial crime solutions across categories with standardized due diligence assessments, and the platform's interactive compliance tools can support risk assessment and program reviews.
Actionable Steps for Financial Institutions
Whether you are a payments firm, a crypto business, or a traditional financial institution, the EES matter and the crypto crackdown suggest the same checklist:
- Review your AML programme against the MLRs line by line. Confirm your risk assessment covers all five required risk categories and is documented and dated.
- Test your transaction monitoring. Run a sample of historical alerts and assess whether true positives were caught and escalated.
- Audit your SAR process. Measure filing timeliness and whether defensive reporting is genuinely encouraged.
- Confirm your nominated officer (MLRO) has authority and resourcing. Governance failures are enforcement triggers.
- Verify record-keeping. Ensure CDD and transaction records are retained for the full five-year period required by the MLRs.
- Assess crypto exposure. Understand where digital assets touch your customer base, counterparties, or payment rails.
- Leverage technology where it genuinely helps. Automation should reduce analyst burden, not obscure accountability.
Key Takeaways
- The FCA has opened an investigation into Euro Exchange Securities UK Ltd for potential offences under the Money Laundering Regulations 2017, alleging systemic failures in risk assessment, CDD, monitoring, governance, and reporting.
- Enforcement against an unregistered peer-to-peer crypto trading operation in London underscores the FCA's focus on AML/CFT compliance in digital assets.
- The MLRs implement 4AMLD in the UK; 5AMLD was implemented through the 2019 Amendment Regulations — firms must track this layered framework.
- Global AML programmes should align UK requirements with the US BSA/FinCEN regime (confidential SARs, 30/60-day timelines, $5,000/$2,000 thresholds) and the EU AML Package (AMLA operational from mid-2025, direct supervision from 2028).
- Effective transaction monitoring, documented risk assessments, timely SAR filing, and adequate MLRO resourcing are the practical defenses against enforcement.
- Technology can support — but not replace — governance, and vendor claims should be validated through testing.
Where to Start
If this article has prompted a review of your AML programme, start with a structured self-assessment. AIGovHub's compliance toolkit and AML resources can help you benchmark your controls, and our vendor marketplace lets you compare transaction monitoring and SAR automation platforms side by side.
To explore how AI-powered AML transaction monitoring, customer risk scoring, and SAR automation can strengthen your financial crime defenses, learn more about RisksRadarAI and its cross-domain risk intelligence capabilities. For a broader view of the regulatory landscape, visit AIGovHub's compliance guides.
This content is for informational purposes only and does not constitute legal advice. Regulatory timelines and enforcement statuses change; always verify current requirements with the FCA, FinCEN, or your qualified adviser.