£186 million. That's what the FCA collected in fines during 2024-25 - a 337% jump on the year before.1 Barclays, Monzo, Nationwide. Each fine traced back to the same failure: compliance systems that didn't scale with the business.
What strikes me, having worked with hundreds of firms on their training programmes, is that most of those companies had training. They had completion records, policy documents, annual e-learning modules. What they didn't have was training that changed what people actually did when a suspicious transaction came through, or when a client triggered an EDD flag.
There's a difference between compliance training that satisfies an audit trail and compliance training that reduces real risk. This guide is about the second kind - what UK regulated firms need to cover in 2026, where training programmes typically fall down, and what a better approach looks like in practice.
- FCA fines hit £186 million in 2024-25 - most tied to AML controls and financial crime failures.1
- Having training records is not the same as having training that works. The FCA looks for evidence of embedded competence, not completion certificates.
- Traditional compliance e-learning averages around 20% self-paced completion in financial services. Microlearning platforms consistently hit 95%+.11
- SMCR means senior managers carry personal liability - their training records need to be part of the audit trail too.
- The biggest risk after a regulatory change is the gap between when it came into force and when all relevant staff completed updated training.
- Role-specific pathways matter: AML training for a client-facing relationship manager and a back-office analyst are genuinely different programmes.
What the FCA Actually Expects From Compliance Training
Most firms understand they need compliance training. Fewer have a clear picture of what the FCA considers adequate - and the gap between "we did the training" and "we can demonstrate competence" is where enforcement cases are won and lost.
The FCA's Training and Competence (TC) sourcebook is the baseline. Firms must show that staff have the knowledge and skills to perform their roles competently, that training reflects the nature and scale of individual roles, and that records evidence ongoing competence - not just initial sign-off during onboarding.
That last part matters. The FCA does not want to see a certificate from three years ago.
Under the Senior Managers and Certification Regime (SMCR), the stakes are personal. Senior managers can face individual fines, regulatory bans, and in serious cases criminal prosecution for conduct failures that happened on their watch. This is not a risk that sits with HR. It sits with whoever signed off on the training programme and whoever had oversight of the people involved.
The four areas that come up in enforcement cases most often
These are not the only areas the FCA scrutinises. But they are the ones I see most frequently behind the fines and investigations.
AML and KYC. The Money Laundering Regulations 2017 (MLR 2017) require AML training proportionate to the firm's activities. In practice, that means Customer Due Diligence (CDD), Enhanced Due Diligence (EDD) for higher-risk clients, Suspicious Activity Report (SAR) filing procedures, and sanctions screening. The Starling Bank case - £29 million fine in September 2024 for "shockingly lax" sanctions controls - showed what happens when a business scales from 43,000 to 3.6 million customers without scaling its compliance training to match.2
Record-keeping and audit trails. FCA rules require accurate records of transactions, client communications, and compliance activities - generally for a minimum of five years. During an enforcement investigation, the FCA wants to see who received training, on which version of which policy, and when. Firms that can't produce that quickly are at a significant disadvantage.
Consumer Duty. Since coming into force in 2023, Consumer Duty has become a growing enforcement priority. It requires firms to evidence that everyone who interacts with or influences outcomes for retail customers has been trained on what "good outcomes" actually means in practice. That extends beyond front-line staff into product, communications, and post-sale teams.
Risk management and conduct. The majority of FCA enforcement operations in 2024-25 related to financial crime and governance failures.1 Staff at all levels need to understand how to identify, assess, and escalate risk - and that understanding needs to be documented.
Total FCA financial penalties rose 337% in 2024-25 to £186.4 million. The majority of enforcement operations that year related to financial crime - and the FCA's stated strategy is "impactful deterrence," not just reactive investigation.9
The Training Failures That Keep Coming Up
Across the firms I've worked with - and across the FCA enforcement cases I've read - compliance training fails in predictable ways. It's rarely one catastrophic gap. It's usually several smaller ones compounding.
Completion rates that look fine on paper
A firm with 80% completion looks compliant. But that 20% gap - if it falls consistently in certain teams, roles, or locations - is exactly where regulators look. And 80% completion for traditional self-paced e-learning is actually good. The industry average in financial services is closer to 20%.11
Brandon Hall Group research found that firms with completion rates below 70% for compliance training are 3.5 times more likely to face compliance violations.7 Format is the biggest driver of that gap. A two-hour annual module and a five-minute daily lesson targeting the same content will not achieve the same completion rates.
Annual cycles versus regulatory reality
The FCA issues updated guidance, new rules, and revised expectations continuously throughout the year. A training cycle that runs once a year creates a structural problem: there is almost always a gap between when a regulatory change takes effect and when all relevant staff have been trained on it.
That gap is exposure. Not theoretical exposure - the kind the FCA has cited specifically in enforcement cases as evidence that controls were inadequate.
The forgetting curve nobody talks about
Hermann Ebbinghaus's research on memory retention is over a century old, but it remains one of the most reliable findings in learning science. 50% of newly learned content is forgotten within 20 minutes. Only 24% survives to 31 days without reinforcement.8
A compliance training programme built around annual sessions cannot overcome this. It is not a content problem or an engagement problem. It is a delivery model problem.
Documentation gaps under FCA scrutiny
40% of compliance teams still manage training records with spreadsheets and word processors.12 That creates two problems: it's slow to produce evidence when the FCA asks for it, and it's hard to demonstrate that records reflect the current version of a policy rather than a version from two years ago.
After a regulatory change, you need to show not just that staff were trained - but that they were trained on the updated content, with a timestamp. Version control in a spreadsheet is not the same as an automated audit trail.
One-size-fits-all content for genuinely different risk profiles
A client-facing relationship manager handling high-net-worth accounts has different AML exposure than a back-office settlements analyst. Training that treats them identically satisfies neither the FCA's requirement for proportionate training nor the employees' need for relevant content. Generic training is also harder to complete - people disengage from material that doesn't connect to their actual job.
7 Practices That Actually Make a Difference
These are not theoretical best practices. They are what I see working when I watch firms go from a compliance training programme that causes them stress to one that holds up under FCA scrutiny.
1. Match training frequency to how regulations actually change
Stop thinking about compliance training as a project with a start and end date. It is an operational function that needs to move when regulations move. Build a continuous learning pathway with short modules that can be updated and redeployed within days of a regulatory change - not months.
This also addresses retention. Five minutes daily, spaced across the year, builds significantly more durable knowledge than five hours once a year. The Association for Talent Development found microlearning increases retention rates by 20% compared to traditional e-learning formats.9
2. Build genuinely different pathways by role
"All staff complete the same AML module" is a compliance floor, not a ceiling. AML training for a client-facing relationship manager should include judgement calls on EDD triggers and SAR thresholds. The same training for operations staff might focus on transaction monitoring and escalation procedures. For a structured approach to this, see how role-based training works in practice.
3. Build your audit trail into the training system, not around it
Every training completion should be automatically logged: who completed it, which version of the content, when, and what they scored. When the FCA requests evidence - and under the current enforcement approach this is increasingly a "when", not an "if" - you need to produce it quickly and cleanly.
The version-control piece is critical after regulatory changes. You need a timestamp showing when the updated content was deployed and when each staff member completed it.
4. Train on the CDD judgement calls, not just the CDD process
KYC and CDD come up in more AML enforcement cases than any other area. The reason is usually not that staff didn't know the process. It's that they didn't know when to escalate, how to document their reasoning, or what constitutes a SAR threshold.
Scenario-based training - presenting realistic client situations and asking staff to apply CDD judgement - is significantly more effective than policy-description modules. For more on building programmes that change actual behaviour, see our Compliance Training 101 guide.
5. Senior managers need training records too
Under SMCR, a senior manager who can't demonstrate their own compliance training is in a difficult position. When leadership completes the same modules as front-line staff - and their records are part of the audit trail - it serves two purposes. It demonstrates firm-wide commitment to the FCA, and it sends an unambiguous signal internally that compliance is a priority rather than a junior-employee problem.
6. Take communications compliance seriously
The FCA's scrutiny of encrypted messaging and off-channel communications reflects a consistent finding: unapproved channels create compliance gaps that firms can't monitor or document. Training staff on what counts as an approved channel - and why the requirement exists, not just what it is - reduces the risk of exactly these violations. People who understand the "why" are more likely to apply the rule in ambiguous situations.
7. Fix the format before you fix the content
The most underrated insight about compliance training completion rates: it is a format problem before it is a content problem. An employee who knows a certification is due in three months will keep deprioritising a two-hour e-learning module. The same employee will complete a five-minute lesson during a commute or between calls - because the friction is low enough.
For more on how bite-sized delivery reshapes compliance engagement, see our piece on why compliance training needs a makeover. And for how to keep training relevant as your headcount grows, our guide to role-specific compliance training covers the scaling questions I hear most often.
Traditional Training vs. Microlearning: Where the Gap Shows Up
I want to be straightforward about something: microlearning is not a magic fix. If your compliance content is inaccurate, incomplete, or poorly designed, delivering it in five-minute segments will not rescue it.
But for firms where the content is sound and the problem is engagement and completion - which is most firms - the format difference is significant. Here's what that looks like in practice:

| Factor | ![]() |
Traditional training |
|---|---|---|
| Completion rates | 95%+ | <20% (self-paced) |
| Training delivery | 5-min daily bite-sized lessons | Annual classroom/e-learning |
| Content updates after reg change | Auto-updated & redeployed | Manual - weeks of rework |
| FCA audit trail | Automated, real-time dashboards | Manual CSV exports |
| Employee experience | TikTok-style, gamified, mobile | Passive, watch-and-click |
| Admin burden | Zero - auto-enrollment | High - chase completions manually |
5Mins.ai delivers CPD-accredited compliance training through AI-powered microlearning - AML, anti-bribery, Consumer Duty, SMCR, GDPR, and more. Automated enrollment, auto-reminders, and real-time dashboards take the admin burden off your team entirely. See what's in the compliance training catalogue.
FAQ
Questions I Get Asked Most Often
Real questions from HR directors and compliance officers - not textbook definitions.
We have compliance training. How do I know if it's actually adequate for the FCA?
How often should we be updating our compliance content?
What does AML training actually need to cover for the FCA?
Why do our staff keep not finishing compliance training?
Do senior managers really need to complete the same training as front-line staff?
Is microlearning actually FCA-compliant? The FCA doesn't mention it anywhere.
Where to Start If You Need to Improve Your Programme
The firms that come through FCA scrutiny well are not always the ones with the most sophisticated training programmes. They're the ones who can answer three questions quickly:
- Which regulations are our staff trained on, and when was that training last updated?
- What are our completion rates by team and role, and what's driving any gaps?
- If the FCA asked us tomorrow for evidence that everyone was retrained after the last regulatory change, how long would that take to produce?
If the answers to those three questions are uncertain, that's where to start. Not with a major programme rebuild - with an audit of what you currently have and where the documentation and completion gaps are.
That audit usually makes the case for moving to an automated, microlearning-based platform more clearly than any product comparison. It's harder to argue for the status quo when you can see exactly which teams have 35% completion rates and which regulatory changes still have staff who haven't been retrained.
5Mins.ai works with thousands of HR and compliance teams on exactly this transition. The compliance training catalogue covers everything from AML to Consumer Duty to SMCR - all CPD-accredited, auto-updated when regulations change, and with the audit trails built in. For a longer read on building a training culture that goes beyond checkbox compliance, the continuous learning guide is a useful starting point.
- FCA Enforcement Data 2024/2025 Unpacked, Macfarlanes, July 2025. 337% increase in financial penalties to £186.4 million.
- FCA Reveals Costliest Enforcement Actions of 2025, Alessa, February 2026. Starling Bank £29 million fine for sanctions screening failures.
- Fresh Set of FCA Fines, Their Implications and Impact, Complyport, February 2026. FCA fines £176 million in 2024, up 230% year-on-year.
- Compliance Fines in 2025: A Mid-Year Review, ComplianceHub. Global AML/KYC fines $263 million in H1 2024, +31% (Fenergo).
- The Biggest AML Fines in 2025, ComplyAdvantage, December 2025. Regulatory fines to financial institutions up 417% in H1 2025.
- FCA Training and Competence (TC) Sourcebook, FCA. Requirements for staff knowledge and competence. fca.org.uk
- Compliance Training Research 2022-2024, Brandon Hall Group. Sub-70% completion correlates with 3.5x higher violation risk.
- Ebbinghaus, H., Forgetting Curve Research. 50% of content forgotten within 20 minutes; 24% retained at 31 days.
- Association for Talent Development. Microlearning increases retention by 20%; completion reaches 82% vs traditional e-learning. td.org
- Corporate Compliance Training Market, Mordor Intelligence, 2026. BFSI accounts for 17.55% of global compliance training market.
- Training Completion Rate Benchmarks by Industry, Zahan, February 2026. Financial services self-paced ~20%; interactive formats 85-95%.
- Financial Services Compliance Training Guide, Calibr.ai, October 2025. 40% of compliance teams rely on spreadsheets/word processors.
This article is for informational purposes only and does not constitute legal or compliance advice. Organizations should seek qualified legal advice for matters specific to their circumstances.
All content is researched and written by the 5Mins team.


