EMIs, PIs, and challenger banks: the FCA's mule review shows where the risk is now growing fastest

The FCA has now confirmed what compliance teams have long suspected.

Why Are Money Mule Accounts Increasing Among EMIs and Challenger Banks?

The FCA's latest review of money mule activity offers one of the clearest pictures yet of how financial crime is evolving across the UK's regulated sector. While much of the attention following publication focused on the overall scale of the problem, some of the most interesting findings lie within the breakdown of where suspicious activity is being detected and how different types of firms are responding.

Among the most striking figures was the growth in suspected mule account offboarding among Electronic Money Institutions (EMIs). Between 2024 and 2025, EMI offboarding volumes increased by 164.6%, the largest year-on-year increase of any category of firm included in the review. Challenger banks also featured heavily, accounting for 33% of all suspected mule account offboardings despite representing a relatively modest share of the overall UK banking market.

It would be easy to look at those figures and conclude that fintechs, EMIs and challenger banks are becoming increasingly vulnerable to financial crime. However, that would be an oversimplification of what the FCA's data is actually telling us. The regulator is careful to point out that many of these businesses are experiencing rapid customer growth, and that rising offboarding figures can often reflect stronger detection capabilities rather than worsening controls. The fact that firms are identifying and removing suspicious accounts is, after all, a positive outcome. What makes the findings interesting is not that the numbers are increasing, but what those numbers reveal about the changing behaviour of criminal networks.

The most interesting aspect of the FCA's findings is not necessarily where mule accounts are being found. It is what those accounts reveal about how criminal funds are moving through the financial system.

What the FCA's Findings Tell Us About Criminal Behaviour

One of the clearest themes running through the review is that money mule activity does not look the same across every type of financial institution. Retail banks continue to account for the majority of mule-related transactions by volume. Yet the FCA found that EMIs, Payment Institutions (PIs) and challenger banks are often seeing lower transaction volumes combined with higher-value individual payments. That distinction may sound technical, but it has important implications.

Criminals do not move money randomly. They choose routes through the financial system that best support the movement, layering and eventual extraction of funds. The FCA's findings suggest that different institutions may be playing different roles within those journeys. A traditional retail bank may see hundreds of lower-value transactions linked to a mule network, while a challenger bank or EMI may encounter fewer transactions but much larger individual sums. The result is that firms can be facing the same underlying threat while experiencing it in very different ways.

That matters because it challenges one of the most common assumptions in financial crime prevention: that the same controls should work equally well everywhere. A retail bank processing millions of payments every day inevitably approaches risk differently from a fast-growing EMI built around digital onboarding and rapid customer acquisition. The objective may be the same, but the operational reality is completely different. Understanding those differences is becoming increasingly important as criminal networks adapt their tactics to take advantage of changing financial services ecosystems.

Why EMIs and PIs Are Identifying Mule Accounts Earlier

The FCA's findings become even more interesting when examining how quickly suspected mule accounts are being identified. According to the review, 74.1% of EMI account closures occurred within six months of the account being opened. For PIs, the figure stood at 56.9%. Retail banks and building societies, meanwhile, were more likely to identify suspicious activity in accounts that had been established for much longer periods.

At first glance, this should be viewed as an encouraging sign. Detecting suspicious behaviour shortly after onboarding suggests firms are identifying potential risks early rather than allowing them to develop unchecked. Strong onboarding controls remain one of the most effective ways to disrupt criminal activity before significant harm occurs, and the FCA's findings suggest many firms are having success in this area.

However, there is another side to the story. If large numbers of suspected mule accounts are being identified shortly after opening, it also suggests that criminal groups are actively targeting those onboarding journeys. Put differently, the review indicates that many firms are successfully catching suspicious accounts early, but it also implies that substantial numbers of attempts are being made in the first place.

This highlights one of the realities of modern financial crime. There is no such thing as a finished compliance programme. Criminal methodologies change constantly, and controls that work today will eventually be tested by new approaches tomorrow. Success is not about eliminating risk entirely. It is about remaining adaptable enough to identify new forms of risk as they emerge.

Why Onboarding Checks Alone Are No Longer Enough

The FCA's review also reinforces another lesson that compliance teams have been discussing for years: onboarding is only the beginning of the customer relationship. Many firms continue to devote significant attention to customer due diligence at account opening, only to reduce intensity once the customer is established. Yet some of the FCA's findings suggest that financial crime risk often develops long after onboarding has been completed.

Customer behaviour changes. Transaction patterns evolve. Ownership structures shift. New intelligence emerges. An account that appears entirely legitimate on day one may look very different six months or twelve months later. This is particularly relevant in sectors characterised by rapid growth and digital-first customer journeys, where relationships can develop quickly, and transaction activity can scale rapidly.

The FCA's data points to a real pattern about where money mule risk is now concentrated across different types of regulated firms. EMIs and PIs are catching a lot of activity quickly, which is a good sign of onboarding controls working, but the sheer rate of increase suggests these firms are being targeted at scale. Retail banks, by contrast, are catching activity in accounts that had been open for years. Different risks, different response strategies. Neither model is complete without continuous monitoring across the customer lifecycle.

That final point is perhaps the most important takeaway from the entire review. Customer risk is not static, which means neither compliance nor monitoring can be static.

The Growing Importance of Continuous Monitoring

The distinction between onboarding and ongoing monitoring is becoming increasingly important as criminal behaviour evolves. Money mule accounts are rarely static in their activity. Some are used immediately, some lie dormant before becoming active, and others slowly change their behavioural profile over time. A firm that focuses exclusively on onboarding controls risks missing changes that emerge later in the relationship.

For that reason, effective financial crime prevention increasingly depends on the ability to maintain visibility throughout the customer lifecycle. Ongoing due diligence, behavioural analytics and transaction monitoring allow firms to identify risk when it changes rather than relying solely on the assessment made at the point of onboarding. The FCA's findings reinforce the fact that customer monitoring is no longer a supporting control. It is becoming one of the primary mechanisms through which financial institutions identify evolving risk.

Risk profiles are dynamic by nature. Customers move money differently, ownership structures evolve, businesses expand into new markets and external events create new exposures. Financial crime controls need to account for these changes rather than assuming a customer will continue to look exactly as they did at onboarding.

The organisations that perform best are increasingly those that can spot changing behaviour quickly and investigate anomalies before they become larger issues.

Why Information Sharing Matters in the Fight Against Money Mule Networks

The report also serves as a reminder that no individual firm ever sees the entire picture. The FCA's analysis of cash-out activity shows that criminal funds often move through multiple accounts before finally leaving the financial system. One institution may see the initial receipt of funds. Another may see onward movement. A third may encounter the final withdrawal or conversion into another asset. Each firm sees a fragment of the story, but rarely the whole narrative.

This is why information sharing has become such a prominent theme across the UK's economic crime agenda. Criminals do not operate in isolation. Networks exchange information, learn from one another and adapt their methods quickly. Financial institutions have traditionally been far less collaborative. The information-sharing mechanisms introduced through the Economic Crime and Corporate Transparency Act are designed to address that imbalance by helping firms connect intelligence that would otherwise remain fragmented.

For compliance leaders, that has important implications. Financial crime controls can no longer be judged solely by what happens within a firm's own systems. Increasingly, success depends on the ability to understand a broader risk environment and identify connections that may sit beyond organisational boundaries.

Can Compliance Teams Keep Pace with Rapid Customer Growth?

The FCA's findings also raise important questions about scale. Many of the organisations highlighted within the review are experiencing significant customer growth, which naturally creates operational challenges. A control environment that functions effectively for ten thousand customers may face considerable strain when customer volumes increase tenfold. Customer acquisition, transaction monitoring and alert handling all become more complex as businesses expand.

Growth brings increased transaction volumes, larger compliance workloads and more alerts requiring investigation. While these challenges are positive indicators of commercial success, they also create pressure on financial crime controls. Without careful planning, compliance teams can find themselves dealing with significantly more work without a corresponding increase in resources.

This challenge is reflected in SmartSearch's 2026 UK Compliance Reality Check, which found that only 30% of regulated firms currently use, or plan to use, AI-assisted triage for sanctions and PEP screening alerts. That statistic becomes more significant when viewed alongside the FCA's findings. Larger customer populations generate larger volumes of alerts and investigations. Without greater investment in automation and intelligent prioritisation, compliance teams can quickly find themselves overwhelmed by volume rather than focused on risk.

That does not mean replacing human judgement. Far from it. The most effective compliance programmes are those that use technology to support decision-making, enabling specialists to focus their expertise where it has the greatest impact. Automation should reduce noise, not replace expertise.

The Beneficial Ownership Challenge Is Not Going Away

The review highlights the continuing importance of beneficial ownership verification. Business account offboarding increased year-on-year, while challenger banks accounted for a significant proportion of suspected business account mule closures. At the same time, SmartSearch's Compliance Reality Check found that 52% of regulated firms struggle with beneficial ownership verification across complex structures.

This is not simply an onboarding issue. Corporate ownership changes over time. Control shifts. New entities appear. Relationships evolve. Treating beneficial ownership verification as a one-off exercise creates an obvious blind spot in an environment where criminal networks are constantly searching for weaknesses to exploit.

The most effective firms increasingly view beneficial ownership verification as a continuous compliance discipline rather than a one-time check.

Ultimately, the most important conclusion from the FCA's review is not that one category of firm is performing better or worse than another. It is that financial crime continues to evolve alongside financial services itself. EMIs, PIs, challenger banks and traditional institutions are all experiencing different manifestations of the same underlying threat.

The findings reinforce several recurring themes across modern financial crime prevention: onboarding controls remain essential, ongoing monitoring is increasingly critical, intelligence sharing creates stronger outcomes, and automation is becoming necessary to support scale. None of these controls operates effectively in isolation.

The firms that will be most successful in disrupting money mule activity are those that recognise how these elements work together as part of a broader compliance framework.

Different Firms, Shared Responsibilities

The risk profile may vary, and the customer journey may differ. The transaction patterns may look completely different.

But the underlying requirement remains remarkably consistent.

Firms need strong onboarding controls. They need continuous monitoring. They need effective intelligence sharing. And they need the ability to adapt as criminal behaviour evolves.

The profile of money mule activity may differ depending on the organisation involved. The need for vigilance does not.

Want to strengthen your risk assessment processes?

Let’s talk. 

See it in action

Let one of our highly-trained sales team demonstrate the multi-award winning SmartSearch AML product.

Why KYB checks are a win-win