Brief
CACEIS and WealthTek: testing the control chain behind client-asset protection
The FCA censured CACEIS UK and recorded a £31.7m voluntary payment after failures to act on information that exposed WealthTek clients to financial-crime risk.
Michaela Clarke
Operations & Compliance Coordinator

At a Glance
The FCA censured CACEIS UK for failing to act on information that left WealthTek clients exposed to financial-crime risk. CACEIS UK agreed to make a voluntary payment of £31.7m, and the FCA said its extensive co-operation and the payment were why it did not impose a fine.
The FCA says CACEIS UK became WealthTek's sub-custodian in November 2020 and was responsible for keeping client assets safe. Register checks showed that WealthTek lacked permissions to hold certain client assets and client money, yet CACEIS UK did not take sufficient action and later failed to review and resolve monitoring alerts promptly. The lesson is an end-to-end control question, not a finding that every custodian has the same facts.
The FCA said CACEIS UK's extensive co-operation and voluntary payment were why it did not impose a fine. That sanction decision is separate from the underlying control lesson: Register information, onboarding decisions, monitoring alerts and escalation need to operate as one connected chain.
Where the control chain failed
Failure to act on Financial Services Register information
CACEIS UK checked the Financial Services Register on three occasions, which showed that WealthTek was not authorised to hold certain client assets and was not permitted to hold client money. Despite this, CACEIS UK opened client accounts for WealthTek and failed to take sufficient remedial action. Firms should assess their onboarding and ongoing due diligence processes to ensure they effectively verify client permissions and escalate discrepancies promptly, distinguishing regulatory requirements from MEMA recommendations for control chain integration.
Inadequate transaction monitoring and alert resolution
CACEIS UK’s transaction monitoring system generated alerts based on thresholds linked to client risk ratings and transaction profiles. However, the firm failed to review and resolve 16 alerts over more than two years, leaving significant risks unaddressed. This highlights the importance of timely and thorough investigation of monitoring alerts. MEMA recommends that firms ensure their monitoring systems are supported by effective governance and escalation protocols, beyond just automated triggers.
Voluntary payment and regulatory cooperation as mitigation
The FCA decided not to impose a financial penalty on CACEIS UK because of its full and significant co-operation and agreement to make a voluntary ex-gratia payment of £31,714,068 to WealthTek clients. Firms should consider the benefits of early cooperation and remediation in enforcement scenarios, while maintaining robust controls to prevent breaches.
Evidence another firm can test
Firms should critically evaluate whether their control chain, from client onboarding and due diligence through transaction monitoring and alert management to client-asset protection, functions as integrated safeguards. The FCA’s findings show that CACEIS UK’s failure was not only in individual control elements but in the lack of connection and escalation between them. Practical steps include verifying that Financial Services Register checks are acted upon promptly, that KYC files are complete and up to date, and that transaction alerts are investigated and resolved within defined timeframes.
The case also highlights the importance of governance and oversight in ensuring controls are effective in practice, not just on paper. Firms should review their policies and procedures to confirm they meet SYSC 6.1.1R and 6.3.1R requirements for financial crime controls, and that ongoing monitoring is proportionate and responsive to risk. MEMA recommends conducting scenario testing and control chain walkthroughs to identify potential gaps in escalation and remediation processes before regulatory scrutiny.
MEMA recommends sampling the hand-offs as well as the individual controls: whether a Register discrepancy changed the onboarding decision, whether missing KYC information affected alert review, whether ageing triggered escalation and whether the final decision and remediation can be reconstructed from the record.
Where the read-across is strongest
This case primarily affects firms providing custody and asset servicing functions, particularly those acting as sub-custodians for other regulated entities. Firms with permissions to hold client money or assets, including those offering transaction monitoring and AML controls, should carefully review their client onboarding, due diligence, and ongoing monitoring frameworks. The WealthTek client journey, from onboarding through transaction processing to client-asset protection, is a critical focus area for CASS oversight leads, MLROs, and operations managers.
Other authorised firms can use the case as a control-design prompt, but should not present CACEIS UK's facts as if they automatically apply to a different business model. The Final Notice expressly limits its criticism to CACEIS UK.
Board challenge after an enforcement case
The FCA’s censure of CACEIS UK for weak financial crime controls in the WealthTek case underscores the critical need for boards to scrutinise the effectiveness of the entire control chain protecting client assets. Boards should ask whether onboarding due diligence, transaction monitoring, alert escalation, and client-asset protection operate as connected and responsive processes rather than isolated checklists. Evidence such as timely alert resolution reports, documented escalation decisions, and updated KYC files can help a firm demonstrate that controls operate with due skill, care and diligence in line with Principle 2.
MEMA recommends that boards also consider the implications of regulatory cooperation and remediation in enforcement outcomes. The FCA’s decision not to impose a financial penalty on CACEIS UK was influenced by its full and significant co-operation and voluntary payment to clients. This highlights the value of proactive engagement with regulators and swift remedial action. Boards should ensure that senior management is empowered and resourced to respond effectively to regulatory inquiries and that lessons from enforcement cases are embedded in firm-wide control improvements.
MEMA helps firms apply regulatory developments through its financial-crime compliance support.
Further reading: a related surveillance-controls case study.
Control Lessons for Firms
| Action | Owner | Status | Timing | Evidence |
|---|---|---|---|---|
| Review and update client onboarding procedures to ensure Financial Services Register checks are promptly acted upon and documented | Head of Compliance | MEMA recommended action | At the next onboarding-control review | CACEIS UK Final Notice, paragraphs 2.3 and 4.1 |
| Test the end-to-end control chain linking onboarding, monitoring, escalation, and client-asset protection for operational effectiveness | Operations Lead | MEMA recommended action | Before the next board assurance report | CACEIS UK Final Notice, overall case analysis |
| Report material exceptions and remediation evidence to the board on client-asset protection controls and financial crime risk management | Head of Risk / Board Secretary | Risk-based action | Next scheduled board meeting | CACEIS UK Final Notice, Principle 2 breach discussion |
Source Evidence
| Source | Document type | Published | Why it matters |
|---|---|---|---|
| CACEIS UK censured and to pay £31.7m to WealthTek clients for weak financial crime controls | FCA enforcement notice | 2026-06-25 | Primary FCA press release and Final Notice for the findings, public censure, voluntary payment and sanction rationale. |
Plain English Glossary
- SYSC - Senior Management Arrangements, Systems and Controls. FCA Handbook section covering governance, risk management, and operational control expectations.
- CASS - Client Assets sourcebook. FCA Handbook section governing how firms must hold, safeguard, and reconcile client money and assets.
- AML - Anti-Money Laundering. Controls and processes firms must operate to detect, prevent, and report money laundering activity.
- KYC - Know Your Customer. Customer identity, ownership, and source-of-funds checks required at onboarding and during the relationship.
Disclaimer
This article is for general information only and does not constitute legal or regulatory advice. Firms should assess the application of regulatory requirements by reference to their permissions, products, customers and operating model.
How MEMA Can Help
MEMA can help firms translate regulatory change into practical controls, policies, monitoring activity and board evidence. Book a free scoping call to discuss what this development means for your firm.
Frequently asked questions
What were the main control failures identified by the FCA in the CACEIS UK case?
The FCA found that CACEIS UK failed to act on information from the Financial Services Register indicating WealthTek was not authorised to hold client money or certain assets. Additionally, CACEIS UK did not adequately monitor or resolve transaction alerts on WealthTek’s client accounts over more than two years. These failures breached Principle 2 by exposing clients to financial crime risks, as detailed in the FCA’s Final Notice dated 25 June 2026.
How did CACEIS UK’s cooperation affect the FCA’s sanction decision?
CACEIS UK's full and significant co-operation, including promptly responding to FCA information requests and agreeing to a voluntary ex-gratia payment of £31,714,068 to WealthTek clients, led the FCA to impose a public censure rather than a financial penalty. The FCA noted this cooperation as a mitigating factor in its Final Notice, illustrating the regulatory benefit of proactive engagement during investigations.
Who should focus on the lessons from the CACEIS and WealthTek case within a firm?
The case is particularly relevant for CASS oversight leads, MLROs, custody and operations leaders, and boards responsible for client-asset protection and financial crime controls. These roles should review client onboarding, transaction monitoring, alert escalation, and client-asset protection processes to ensure they operate as connected controls, as highlighted by the FCA’s findings in the CACEIS UK Final Notice.
Need expert regulatory guidance?
Our ex-regulator team helps firms navigate complex requirements and evidence compliance with confidence.
Book a Free Scoping CallRelated insights
View all insights →
CP26/16 has closed: what firms should prepare for next
CP26/16 closed on 9 July 2026. Its proposals concern safekeeping delegation and the authorised fund registration function, not a new FCA data return.

In-house, outsourced or co-sourced compliance: a governance comparison
A comparison of compliance resourcing models through accountability, capability, information access, provider oversight, continuity and exit planning.

Consumer Duty scope decisions need a documented wholesale boundary
CP26/23 proposes targeted changes to Consumer Duty scope. Mixed retail and wholesale firms should separate the live Duty from changes still under consultation.