The Financial Conduct Authority (FCA) recently issued a formal censure against asset servicing bank CACEIS UK, following its failure to act on critical red flags that left clients exposed to financial crime. As part of the resolution, CACEIS UK agreed to make a £31.7m voluntary payment to clients of collapsed wealth management firm WealthTek (formerly Vertus Asset Management LLP).
This enforcement action brings total recoveries secured by the FCA for WealthTek clients to over £57m in just over a year, highlighting both the regulatory body’s accelerated enforcement pace and a stark warning for financial institutions: gaps in entity onboarding, KYB (Know Your Business) verification, and continuous monitoring carry astronomical costs.
What went wrong?
In November 2020, CACEIS UK became WealthTek’s sub-custodian, taking on the responsibility of keeping client assets safe. However, regulatory findings revealed major system and operational oversights rooted in poor entity verification and ongoing monitoring:
- Flawed entity verification & register checks: On three separate occasions, CACEIS UK checked the Financial Services Register and saw that WealthTek lacked authorisation to hold certain client assets. Yet, because these checks weren't integrated into an automated, actionable verification workflow, no sufficient action was taken.
- Failure to verify regulatory credentials during onboarding: CACEIS UK failed to properly verify WealthTek's operational permissions, missing the fact that WealthTek was explicitly prohibited from holding client money altogether. Despite this massive red flag, CACEIS UK proceeded to onboard the entity and open client accounts for them.
- Unresolved alerts & ineffective monitoring: Once accounts were open, CACEIS UK failed to monitor them properly by not promptly reviewing or resolving automated system alerts triggered by their own compliance systems.
As Therese Chambers, joint Executive Director of Enforcement and Market Oversight at the FCA, noted:
"Strong financial crime controls keep clients’ assets safe. CACEIS UK’s failures exposed clients to serious risk."
Because CACEIS UK fully cooperated and agreed to the £31.7m voluntary redress payment, the FCA opted not to impose an additional financial penalty. However, the reputational damage and financial hit serve as a crucial wake-up call across the sector.
3 critical compliance takeaways for financial services
The CACEIS UK enforcement underscores three operational vulnerabilities that every bank, sub-custodian, and regulated firm must address:
1. Entity & individual verification must be automated and actionable
Conducting a manual check on a register or accepting documentation at face value is useless if red flags aren't automatically flagged and escalated before account setup. Robust Know Your Business (KYB) and Know Your Customer (KYC) workflows must validate regulatory status and permissions in real time.
2. Onboarding gatekeeping prevents downstream financial crime
Financial crime controls start at the front door. If an entity or individual fails verification standards or lacks valid credentials, automated safeguards must stop onboarding instantly, preventing unauthorised accounts from being created in the first place.
3. Verification & alert systems need end-to-end auditability
Alert generation means nothing without swift resolution and clean records. Automated verification platforms that maintain clear, tamper-evident audit trails ensure compliance teams can instantly review, verify, and evidence their actions to regulators.
How Goidentity prevents onboarding & compliance failures
Whether you are onboarding corporate entities, institutional partners, or individual clients, preventing regulatory fallout requires moving away from manual, fragmented checks.
At Goidentity, we empower financial services, wealth managers, and enterprise institutions to automate and strengthen their overall AML, KYB, and KYC controls:
- Automated KYB & KYC checks: Streamline entity and individual verification workflows with instant cross-checks against global registries, official document databases, and regulatory standards.
- Instant PEPs, sanctions & file checks: Automatically screen entities and associated individuals across global watchlists to ensure no unauthorised or high-risk accounts slip through the cracks.
- Tamper-evident audit trails: Every check run through Goidentity generates a complete, time-stamped audit report, providing clear, immutable proof of compliance for internal teams and the FCA.
- Zero-trust security framework: Powered by enterprise-grade biometric scanning, document verification, and encryption, Goidentity eliminates reliance on unverified documentation and manual error.
- Flexible, scalable onboarding: Pay only for the checks you run with our flexible top-up model, no long-term lock-ins, complex setups, or missed red flags.
Protect your firm from regulatory fallout
The FCA completed its investigation into CACEIS UK in just 13 months, signalling a new era of swift, decisive regulatory intervention in the UK. Relying on disconnected manual register checks or slow alert resolution is no longer a viable strategy.
Ensure your onboarding workflows, entity verification, and AML checks are robust, automated, and audit ready.