Internal audit flagged it. The board ignored it. The FCA fined it.

Internal audit flagged it. The board ignored it. The FCA fined it.

A new report from the Chartered IIA reveals that UK financial firms have faced £1.02bn in fines for internal control failures since 2021. With the new Internal Controls Declaration now in force, boards can no longer rely on boilerplate compliance to satisfy the FCA.

The Financial Conduct Authority (FCA) has a long memory, but it seems many UK financial services firms do not. A new deep-dive report from the Chartered Institute of Internal Auditors (IIA), Internal Control Failure! has quantified a trend that has been simmering in enforcement notices for years: a fundamental disconnect between identifying a risk and actually fixing it.

Between 2021 and 2025, more than £1.02 billion in fines were levied against firms for internal control failures. This represents 54% of all FCA enforcement action by volume. While a billion-pound headline is eye-catching, the more alarming detail for the accounting and audit profession is the “why.” These weren’t sophisticated, invisible crimes; they were often basic failures in anti-money laundering (AML), fraud prevention, and data governance that had been flagged months or years internally before the regulator stepped in.

The Remediation Gap

The IIA’s analysis of 97 final notices suggests a recurring theme of “stalled” remediation. It is a scenario familiar to many internal auditors: a deficiency is identified, it’s added to the risk register, and then it sits there.

In several cases highlighted in the report, firms were fined years after serious weaknesses had been identified. Warnings from internal audit and compliance teams were ignored, or the “pace” of change was deemed insufficient by the regulator. This highlights a critical failure in the governance chain if the audit committee is receiving reports on control weaknesses, but the executive team isn’t empowered (or pressured) to fix them, the entire three-lines-of-defence model collapses.

The report also identifies a glaring structural void: at least 13 of the firms hit with major fines appeared to be operating without an internal audit function entirely. In an era of heightened scrutiny, attempting to navigate the UK’s regulatory landscape without a dedicated assurance function is increasingly seen by the FCA not just as a risk, but as a red flag for poor culture.

Provision 29: From ‘Best Practice’ to Legal Liability

This data arrives just as the UK Corporate Governance Code’s new Internal Controls Declaration, Provision 29 takes full effect. For accounting periods beginning on or after 1 January 2026, boards must now explicitly sign off on the effectiveness of their “material controls.”

Historically, annual report statements regarding internal controls have been criticized for being “boilerplate” vague, optimistic, and largely indistinguishable from one company to the next. The IIA’s findings suggest that for over half of the firms recently fined, such statements would have been factually inaccurate.

Under the new regime, the stakes for the CFO and the Board are significantly higher. A failure to disclose a known material weakness that later leads to an FCA fine could lead to more than just a penalty for the firm; it could lead to personal accountability issues under the Senior Managers and Certification Regime (SMCR).

The Escalating Cost of ‘Doing Nothing’

We often focus on the headline fine, but the £1.02bn figure is merely the tip of the iceberg. For an accountant looking at the balance sheet, the secondary costs of control failure are often ruinous:

Arleen McGichen, President of the Chartered IIA, notes that this should be a “wake-up call” for boards. However, the data suggests that many boards are already awake, they just haven’t been getting out of bed to fix the problems.

A Shift in Regulatory Patience

The FCA’s shift toward “assertive supervision” means the grace period for fixing legacy systems is over. Whether it’s a challenger bank struggling to scale its compliance or an established high-street name failing to monitor suspicious transactions, the regulator’s patience for “work in progress” remediations has evaporated.

For those sitting in audit committees or advising on risk, the priority has shifted from simply identifying a problem to proving its resolution. If the remediation isn’t sustained and verifiable, the fine isn’t a possibility it’s an eventual certainty.

Share

Resources & Whitepapers

The importance of UX in accounts payable: Often overlooked, always essential
AP

The importance of UX in accounts payable: Often overlooked, always essentia...

2y Kloo

The importance of UX in accounts payable: Often ov...

Embracing user-friendly AP systems can turn the tide, streamlining workflows, enhancing compliance, and opening doors to early payment discounts. Read...

View article
The power of customisation in accounting systems
Accounting Software

The power of customisation in accounting systems

2y Kloo

The power of customisation in accounting systems

Organisations can enhance their financial operations' efficiency, accuracy, and responsiveness by adopting platforms that offer them self-service cust...

View article
Turn Accounts Payable into a value-engine
Accounting Firms

Turn Accounts Payable into a value-engine

5y Accountancy Age

Turn Accounts Payable into a value-engine

In a world of instant results and automated workloads, the potential for AP to drive insights and transform results is enormous. But, if you’re still ...

View resource
8 Key metrics to measure to optimise accounts payable efficiency
AP

8 Key metrics to measure to optimise accounts payable efficiency

2y Kloo

8 Key metrics to measure to optimise accounts paya...

Discover how AP dashboards can transform your business by enhancing efficiency and accuracy in tracking key metrics, as revealed by the latest insight...

View article