Policy Pros
Written by Joanne Hughes, Policy & Compliance SpecialistLast reviewed

Policies and Procedures for Financial Services

This page is for FCA-regulated firms, fintechs and financial advisers that need their compliance documentation written properly. Policy Pros writes anti-money laundering policies, sanctions screening procedures, complaints handling procedures and the wider regulatory compliance documentation the FCA expects to see.

That covers authorised firms of every size, from a directly authorised adviser to an e-money institution, along with fintechs working towards authorisation or registration. If a supervisor, auditor or banking partner has asked to see your policies, this is the documentation we produce.

Bespoke, audit-ready policies from £65 + VAT per document. Get a quote or call 020 3951 2875 for a free scoping conversation.

Policies Financial Services Firms Need

Required by Regulation

  • Firm-Wide AML Risk Assessment - regulation 18 of the Money Laundering Regulations 2017 requires a written assessment of your money laundering and terrorist financing risks
  • AML Policies, Controls and Procedures - regulation 19 requires written policies proportionate to your size and nature, approved by senior management
  • Customer Due Diligence and Enhanced Due Diligence Procedures - regulations 27 to 35 set out when standard and enhanced checks apply, including for politically exposed persons
  • AML Training Programme - regulation 24 requires relevant employees to be trained in money laundering law and how to recognise suspicious activity
  • Sanctions Screening Procedure - UK financial sanctions apply to every UK business, and OFSI expects screening arrangements proportionate to your exposure
  • Complaints Handling Procedure - the FCA's DISP rules require written complaints procedures, final responses within eight weeks, or 15 business days for payment services and e-money complaints, and signposting to the Financial Ombudsman Service
  • Data Protection Policy - UK GDPR and the Data Protection Act 2018 require you to demonstrate compliance with the data protection principles

Expected by the FCA and Counterparties

  • Consumer Duty Framework - the governance document behind your fair value assessments, outcomes monitoring and annual board report
  • Compliance Monitoring Plan - the practical schedule showing how you check your own controls through the year
  • Conflicts of Interest Policy - SYSC requires firms to identify and manage conflicts and to keep a record of them
  • Financial Promotions Procedure - sign-off and record keeping for promotions under section 21 of the Financial Services and Markets Act 2000
  • Whistleblowing Policy - mandatory arrangements for banks and insurers under the FCA's SYSC 18 rules, and treated as good practice for other firms
  • Senior Managers and Certification Regime records - statements of responsibilities, fitness and propriety assessments and conduct rules training
  • Business Continuity Plan - expected by the FCA and asked for in banking partner and enterprise client due diligence

The Money Laundering Regulations 2017 Demand Written Controls

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 are the backbone of UK AML compliance. Regulation 18 requires a written firm-wide risk assessment, and regulation 19 requires policies, controls and procedures built on it, kept up to date and approved by senior management.

Our anti-money laundering policy service writes the full set, from the risk assessment through customer due diligence to record keeping. If you are unsure whether the regulations catch your business at all, our guide to which businesses need an AML policy walks through the sectors in scope.

Sanctions Screening Is a Separate Obligation

UK financial sanctions apply to every UK business, whether FCA-regulated or not, and the Office of Financial Sanctions Implementation can impose civil penalties for breaches. Screening customers and payments against the UK sanctions list needs its own documented procedure rather than a paragraph buried in the AML policy.

Our sanctions compliance policies service writes that procedure, covering screening, escalation and reporting routes.

The Consumer Duty Sets the Conduct Standard

The FCA's Consumer Duty requires firms to act to deliver good outcomes for retail customers, measured across four outcomes: products and services, price and value, consumer understanding and consumer support. It has applied to open products and services since 31 July 2023 and to closed products since 31 July 2024.

The Duty is evidenced in documents: product governance records, fair value assessments, consumer understanding testing and an annual board report. Firms without that paper trail struggle to answer the FCA's information requests.

Complaints Handling Under the FCA's DISP Rules

The FCA's dispute resolution rules require regulated firms to have written complaints procedures, to investigate complaints competently and impartially, and to issue a final response within eight weeks, cut to 15 business days for payment services and e-money complaints, with referral rights to the Financial Ombudsman Service. Root cause analysis of complaints also feeds directly into Consumer Duty monitoring.

Our complaints policies service writes procedures that satisfy DISP while staying usable for the people actually handling the complaint.

The Wider Financial Policy Set

AML and complaints sit inside a bigger documentation framework: payment controls, expenses, anti-bribery, fraud prevention and financial authority limits. Our finance policies and procedures page covers that wider set for regulated and unregulated businesses alike.

Fintechs deploying AI in credit decisions, fraud detection or customer service also face growing governance expectations from the FCA and partner banks. Our AI governance policies service covers the documentation that due diligence is starting to ask for.

Financial Services Policy and Procedure Writers

Policy Pros writes bespoke financial services documentation around your actual permissions, products and customer base, not a generic template with your logo on it. Every engagement starts with a fixed-price quote before any work begins.

  • Bespoke documents written around your permissions, business model and risk assessment
  • A fixed-price quote before any work starts
  • Review rounds included, so the final documents say what you need them to say
  • Documents delivered on professionally branded templates, ready for a supervisor, auditor or banking partner

Tell us whether you need a single AML policy or the full compliance library and we will scope exactly what you need, with no obligation. Get a quote or call 020 3951 2875.

Frequently Asked Questions

What policies does an FCA-regulated firm legally need?

If the Money Laundering Regulations 2017 apply to your firm, you need a written firm-wide risk assessment, AML policies, controls and procedures, customer due diligence procedures and a training programme. The FCA's DISP rules require a written complaints procedure, and SYSC requires documented systems and controls including conflicts of interest records.

On top of that sit the general legal requirements every employer has, such as a written health and safety policy statement once you have 5 or more employees and data protection documentation under UK GDPR.

Do fintechs need an AML policy before FCA authorisation?

In practice, yes. E-money institutions, payment institutions and registered cryptoasset businesses are within scope of the Money Laundering Regulations 2017, and the FCA expects to see your firm-wide risk assessment and AML controls as part of the application itself.

Writing the risk assessment and policy before you apply is far cheaper than having the application bounced back for weak financial crime arrangements.

What is the difference between an AML policy and a firm-wide risk assessment?

The firm-wide risk assessment, required by regulation 18, identifies where your business is exposed to money laundering and terrorist financing risk across customers, products, geography and delivery channels. The AML policy, required by regulation 19, sets out the controls you run in response.

Supervisors expect the policy to visibly flow from the risk assessment, which is why a bought-in template that ignores your actual risk profile tends to fail review.

Does the Consumer Duty require a specific policy document?

The FCA does not mandate a single named document, but the Duty has to be evidenced somewhere: fair value assessments, product governance records, outcomes monitoring and an annual board report. Most firms adopt a Consumer Duty framework document that ties those pieces together and assigns ownership.

Without it, answering an FCA information request means reconstructing your approach from scratch under time pressure.

Trustpilot Reviews - 5 Stars