FCA Money Mule Review: Look Beyond the First Receiving Account

The FCA money mule review published on 23 September 2026, “Money mules: mule activity and cashing out findings”, reports that the 35 retail banks, building societies, challenger banks, payment institutions (PIs) and e-money institutions (EMIs) it surveyed offboarded 238,396 suspected money mules in 2025, up from 184,935 in 2023 and 233,269 in 2024. Its sharper finding comes from a public/private cell that traced fraud proceeds: criminals usually cashed out between the second and fifth mule account, by which stage payments are harder to detect and trace.

The review’s findings sit alongside existing AML and financial-crime requirements under the Money Laundering Regulations 2017 (MLRs) and the Proceeds of Crime Act 2002 (POCA) and, where the FCA Handbook’s application provisions make it applicable to the firm, SYSC 6.3, and add no legal duty of their own. The FCA expects firms to use the findings in their own assessment of money mule risk, to consider indicators beyond the initial receiving account and, where appropriate, to use the information-sharing provisions of the Economic Crime and Corporate Transparency Act 2023 (ECCTA). An alert issued with the National Economic Crime Centre (NECC) will carry further findings, and supervisory monitoring continues.

Related reading: The FCA’s June 2026 Financial Crime Speech: What It Means for AML Reporting in UK-Regulated Firms

What the FCA money mule review measured, and what its numbers cannot show

Two data sets sit behind the findings. The survey covered suspected mule offboarding across 2023 to 2025; the FCA says no reliable estimate of the number of mules affecting FCA-regulated firms existed before it. The cell, a working group of 22 regulated firms set up in 2025, examined 140 cases across seven fraud types and followed high-value payments through chains of accounts.

The headline count measures firm action. The FCA cautions that rising closures could reflect customer growth and better identification, and do not necessarily mean mules make up a larger share of firms’ business. Growth also slowed: 2025 closures were 5,127 above 2024, against a rise of 48,334 the year before. The tenure figure carries its own denominator: the 114,984 accounts offboarded within a year of opening in 2025 were 47.1% of the accounts with tenure data. Tenure records account age at closure, so it cannot show when misuse began, a limit the FCA states itself.

Age needs the same care. Customers aged 26 to 39 were the largest group (91,073 closures), but the sharpest increase came among 40 to 49 year olds, from 25,760 in 2024 to 37,274 in 2025. A model that treats youth as the main mule marker will under-weight the fastest-growing band.

Firm type decides where the mule pattern surfaces

The survey splits by business model. EMIs and PIs tended to exit accounts soon after opening: 74.1% of EMI and 56.9% of PI offboarded accounts closed within six months. Retail banks and building societies more often exited long-standing accounts, 45.4% after more than two years, and accounted for 56.1% of 2025 offboardings; challenger banks accounted for 33%. EMIs recorded the steepest year-on-year rise, 164.6%.

In the cell data, retail banks carried most transactions through mule accounts while other firms saw lower volumes but higher values, which the FCA reads as different cash-out strategies and risk concentrations. Controls, it says, should be proportionate to the particular risks each firm faces.

My reading is that the weak point differs by firm type. For an EMI it sits in onboarding and early account life. For a retail bank, the data cannot say when long-tenure accounts were first misused, but a monitoring set that relaxes once an account has a clean history would be poorly placed to catch that group. The FCA’s 2023 review, “Proceeds of fraud: detecting and preventing money mules” (updated December 2025), had already found some firms onboarding several customers on the same device or at the same physical address.

Cash-out between the second and fifth account

The cell followed the money past the first hop. Proceeds were usually cashed out between the second and fifth mule account, with the highest concentration at the second. Card payments were the most common method: many low-value transactions, or higher-value payments to local businesses and retailers, which can resemble legitimate consumer spending. International routes recurred to South Asia, West Africa and the Middle East, and crypto cash-outs were lower in volume but larger in value. Some accounts were used for mule activity multiple times before closure and across several scam and fraud types, which the FCA reads as established criminal infrastructure.

Regulation 28(11) of the MLRs requires ongoing monitoring, including scrutiny of transactions to ensure they are consistent with the firm’s knowledge of the customer and its risk profile. Where the FCA Handbook’s application provisions make it applicable to the firm, SYSC 6.3.1R requires systems and controls to identify, assess, monitor and manage money laundering risk, and SYSC 6.3.3R a regular assessment of their adequacy. The review makes the test concrete: firms should understand how criminals move funds between accounts and consider linked accounts, payment characteristics and the broader transaction context.

The FCA has named the one-ended gap before: its 2023 review found some firms focusing on outbound monitoring without adequate inbound controls. A rule set built around the first receiving account sees the credit and loses the trail by the time the money is spent at a card terminal. Unresolved alerts carry their own risk, as the FCA’s CACEIS UK censure over financial crime controls showed.

Offboarding, SARs and the NFD: where the reporting chain thins

Closing a mule account and reporting it are separate decisions. Under section 330 POCA, a person in the regulated sector commits the failure-to-disclose offence only where the statutory conditions are met: information obtained in the course of regulated-sector business causes them to know or suspect, or gives reasonable grounds for knowing or suspecting, that another person is engaged in money laundering; they can identify that person or the whereabouts of laundered property, or believe, or can reasonably be expected to believe, that the information will or may assist in doing so; and they fail to make the required disclosure to their nominated officer or an NCA-authorised person as soon as practicable. Statutory defences and exceptions also apply. The reasonable-grounds limb therefore requires the recorded facts to be assessed against the section 330 conditions rather than treating a mule exit as automatically reportable.

The NFD figures show where the chain thins. Firms made 113,655 filings to the National Fraud Database, which Cifas operates, across 2023 to 2025, and the share of offboarded customers filed fell from 17.4% in 2024 to 15.3% in 2025. A dedicated “funds received for money muling” category arrived in 2025, which the FCA notes makes year-on-year comparison difficult. Its January 2025 review found one firm reporting only 6% of offboarded mules to the NFD between January 2022 and September 2023, against more than 66% at some firms, and described submitting every case that meets the required standard of proof as good practice.

An NFD filing and a POCA disclosure sit in different regimes. Cifas membership is voluntary, and an NFD filing is appropriate for member firms only where the relevant Cifas category criteria and evidential standard are met; closing an account does not determine whether those conditions are satisfied. Any separate POCA disclosure duty must be assessed under the statutory POCA test. APP scam reimbursement data is a third stream, covered in our PSR Specific Direction 20 reporting guide.

Returning the balance has its own route. Section 327(2D) POCA (inserted by section 182 ECCTA from 26 October 2023; sections 328(6) and 329(2D) mirror it) covers a regulated-sector business, other than excluded business, transferring money owing to a customer to terminate the relationship, where the criminal property transferred totals less than the threshold amount and CDD duties were complied with beforehand. Since 31 July 2025, SI 2025/877 has set that threshold, in section 339A(6A), at GBP 3,000, up from GBP 1,000, and raised the section 339A(2) account-operating threshold for deposit-taking bodies, EMIs and PIs to the same figure. The CDD condition deserves a check on any exit that followed a failed due diligence refresh.

Sharing intelligence under the ECCTA 2023

Sections 188 and 189 ECCTA have been fully in force since 15 January 2024. Section 188 can protect a direct disclosure about a customer or former customer between businesses within its scope where the request condition or warning condition is met, the discloser is satisfied that the information will or may assist the recipient in carrying out relevant actions, and the disclosure is not privileged. The warning condition is that the discloser, due to concerns about risks of economic crime, has decided to take safeguarding action (ending the relationship, refusing a product or service, or restricting access to elements of one), or would have so decided had the customer not already left. Where the section 188 conditions are satisfied, the disclosure does not breach an obligation of confidence and does not create civil liability to the person concerned under those provisions; data protection legislation continues to apply. Section 189 covers indirect disclosure through a third-party intermediary, and the Explanatory Notes cite a database akin to the NFD.

The FCA calls these voluntary provisions and sees room for firms to share more on suspected mules; because data protection law is untouched, each disclosure still needs a documented lawful basis. The repeat-account finding is the case for using them: timely sharing between firms can help identify linked accounts, recurring cash-out routes and laundering methods. Our note on FATF public-private partnerships and AML information sharing covers the wider design questions.

Frequently Asked Questions

Does the review apply to a firm that was not one of the 35 surveyed?

Its stated audience is banks, building societies, PIs and EMIs and their MLROs and nominated officers, and firms are asked to weigh the findings against their own business models and exposure to money mule risk. Nothing limits that to survey respondents.

What if the balance on a suspected mule account is above GBP 3,000 at exit?

The section 327(2D) exemption requires the criminal property transferred for termination purposes to total less than the threshold amount. Above it, the exemption is unavailable and the firm’s position under sections 327 to 329 is assessed in the ordinary way, including whether to make an authorised disclosure. The exemption sits inside those offence provisions and leaves the separate section 330 duty untouched.

Key Takeaways

  • Next regulation 18 risk assessment update: record which published mule patterns fit your book (early-life exits, long-tenure exits, card cash-outs, crypto and international routes) and the control answering each.
  • Monitoring test: can a rule link each account from the second to the fifth in a chain held inside your institution back to the first receiving account?
  • Exit file: CDD status at the balance transfer, the value transferred and the nominated officer’s disclosure decision, recorded together.
  • NFD diagnostic: compare your offboarded-mule filing rate with the FCA survey’s 15.3% 2025 aggregate only as contextual information, not as a filing target; each NFD filing depends on the applicable Cifas category criteria and evidential standard.
  • ECCTA section 188: decide who approves a warning disclosure to another firm and where its data protection basis is recorded.

Sources and References

Before the NECC alert: the mule-control review to run now

The FCA has set no deadline, and the NECC alert is still to come. The MLRO’s work can start first: an updated regulation 18 record, a gap list of monitoring rules measured against the second-to-fifth account window and card-based spending, and a reconciliation of offboarded suspected mules against NFD filings and nominated-officer disclosure decisions. Start with the reconciliation, because it draws only on records the firm already holds and shows whether each exit, filing and disclosure decision lines up.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • BoE Systemic Stablecoin Rules: What UK Issuers and E-Money Firms Must Prepare For

    Updated September 2026In this guideWhy the BoE systemic stablecoin rules sit in two different statutesWhat changed between the November 2025 consultation and the June 2026 policy statementThe backing-asset and reserve model issuers have to build toRedemption, capital and the obligations behind the returnsWhere the FCA regime ends and the Bank’s beginsHow the UK regime diverges…

  • MONEYVAL Bulgaria AML Follow-Up: The Correspondent Banking Read

    On 17 June 2026, MONEYVAL published its third enhanced follow-up report on Bulgaria, and the headline is clear: Bulgaria is now rated compliant or largely compliant on all 40 FATF Recommendations, and no further reporting is required under MONEYVAL’s fifth-round evaluation. For anyone who runs country-risk models or approves correspondent relationships, the MONEYVAL Bulgaria AML…

  • ECB Digital Euro Pilot: BCL and Two Luxembourg PSPs Join

    On 14 July 2026 the Banque centrale du Luxembourg (BCL) confirmed it will take part in the European Central Bank’s digital euro pilot, joining the ECB and 18 other Eurosystem national central banks in a controlled test of a beta version of the digital euro. The same day the ECB named the 36 payment service…

  • FATF Travel Rule Implementation: The Enforcement Gap

    Updated September 2026In this guideThe dates that anchor this updateWhat the seventh targeted update actually measuresWhere FATF Travel Rule implementation now standsThe distance between a rule and a working controlOffshore VASPs and the edge of the licensing perimeterStablecoins, unhosted wallets and the P2P edgeHow the EU sits against the FATF baselineWhat compliance and reporting teams…

  • Next-Generation UK Retail Payments Infrastructure: What the RPIB Consultation Means for PSPs and Direct Participants

    Updated July 2026In this guideWhat the RPIB consultation actually asksThe governance stack: PVDC, RPIB, Design Authority, Delivery CompanyWhere Faster Payments and Bacs sit during the transitionDesign choices that shape UK retail payments infrastructureWhat PSPs and direct participants should do nowThe regulatory backdrop firms should not ignoreFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesWhy the design phase…

  • FCA censures CACEIS UK over WealthTek: a financial crime controls reckoning for UK custodians

    Updated July 2026In this guideWhat the FCA found about CACEIS UK’s financial crime controlsThe legal basis, and what Principle 2 is doing hereThe pooled client account trapChecking the Register is not the controlWhy open alerts cost more than missing onesA censure with a price tag, and where the money wentFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and…