You can be fully compliant with every applicable rule and still be operating inside a conflicted system that regulators cannot see. This is the defining compliance problem of the current era — and it is one that most professional risk frameworks are not equipped to address.
The compliance function exists to ensure adherence to rules. Rules, however, are written by people — and in the United Kingdom, many of the people who write or influence regulatory rules have a direct financial interest in how those rules are drawn.
Consider the architecture of influence around the UK's water utility sector. Firms advising private water companies on regulatory strategy while former executives sit on the boards of those same companies — and while political allies simultaneously hold positions of public accountability — represent a conflict of interest that no single regulator owns. Ofwat regulates economic outcomes. The FCA regulates financial conduct. The Charity Commission regulates charitable purpose. None of them regulates the intersection where former ministers, corporate advisers, private equity and public contracts converge.
The result is a system where every individual transaction passes a compliance check while the aggregate effect — the systematic transfer of regulatory favour and public-sector value to private capital — remains entirely invisible to any single oversight body.
For MLROs and compliance professionals, this is not an abstract concern. If your institution is engaged with counterparties, advisers or intermediaries who operate in this space, you are exposed to reputational, legal and regulatory risk that your standard conflict-of-interest protocols were not built to capture. The problem belongs on your risk register even when it belongs in no regulator's inbox.
Modern regulatory-evasion conflicts of interest share a recognisable structural pattern. Four components appear, in varying combinations, in almost every case. Understanding the anatomy is the first step toward detection.
The network anchors on one or more individuals with significant prior public service — a former minister, a senior regulator, a government communications chief. Their value is not technical expertise. It is relational capital: the ability to pick up the phone, to be taken to lunch, to be read as a credible and authoritative voice by people still inside the machine.
Former officials rarely operate as lobbyists by legal definition. Instead, they join vehicles that fall outside the statutory definition: think tanks registered as charities, strategic advisory firms that do not directly communicate with ministers on behalf of named clients, or global consultancies with broad mandates that make it impossible to determine which representations constitute lobbying.
The institutional capital that pays for access. This may be domestic private equity, US technology corporations seeking NHS or government data contracts, financial institutions managing regulated assets, or infrastructure investors seeking favourable regulatory outcomes. Their need is not illegal — they want regulatory environments and policy frameworks that protect their returns. The adviser network exists to deliver this legally, invisibly and at considerable cost to the public interest.
Perhaps the most sophisticated element: the deliberate use of language to maintain political cover while serving the network's interests. A politician who refuses precise language on matters of regulatory consequence is not simply being cautious — they are maintaining optionality. When counterparties consistently decline to describe their activities in terms that would trigger regulatory attention, that pattern is a detection signal, not an eccentricity.
In AML, professionals are trained to treat unusual transaction structuring — transactions designed to stay below reporting thresholds — as a red flag. The same logic applies to influence risk. When an entity is an "adviser" rather than a lobbyist, a "charitable institute" rather than a policy influence firm, a "strategic partner" rather than a commercial intermediary — and when this labelling is consistent and deliberate — the pattern warrants scrutiny, not deference. Who benefits from the ambiguity?
Charitable registration provides tax advantages, reputational legitimacy and — critically — exemption from lobbying disclosure requirements. Several of the most influential policy-influencing organisations in the UK operate as charities. The Charity Commission's remit is to ensure organisations pursue their stated charitable purposes. It has neither the mandate nor the investigative capacity to examine whether charitable activity is being used as cover for commercial influence operations.
Where a think tank or policy organisation receives material income from corporate sources with a direct financial interest in the policy positions it promotes, and where that organisation is structured as a charity, the compliance question is whether the arrangement constitutes undisclosed lobbying. The charitable wrapper does not resolve the conflict — it obscures it.
The statutory lobbying register — established under the Transparency of Lobbying Act 2014 — only captures consultant lobbyists who communicate directly with ministers or permanent secretaries on behalf of third-party clients. It does not capture introductions, facilitated access, background briefings, speaking engagements or the ambient relationship maintenance that is, in practice, the most valuable and most common form of influence. Strategic advisory firms can operate for years without triggering a single disclosure obligation.
Registration on the lobbying register is not a clean bill of health — it is evidence that an entity's influence activity was obvious enough to fall within the definition. Absence from the register tells you almost nothing about the actual volume or nature of influence being exercised.
The Advisory Committee on Business Appointments (ACOBA) is the UK's primary mechanism for managing the revolving door between senior public roles and the private sector. It has no statutory enforcement powers. It cannot sanction breaches of its own recommendations. Its guidance is advisory. In practice, it functions as a reputational laundry: former officials receive a cooling-off recommendation, the recommendation is breached or creatively interpreted, and ACOBA has no remedy beyond issuing a statement.
When onboarding a counterparty or adviser with significant prior public service, do not treat ACOBA compliance as the test of acceptable conduct. Map the specific regulatory decisions and policy areas the individual oversaw in their public role against the interests of their current or prospective clients. The conflict is in the overlap, not in the ACOBA filing.
The most consequential structural gap is the absence of any regulator with a cross-cutting mandate to examine systemic conflicts of interest. The FCA, Ofwat, the CMA, the ICO and the Charity Commission each operate within defined sectoral boundaries. A conflict of interest that operates across those boundaries — a private equity firm that owns a lobbying consultancy that advises a regulated utility whose board includes a former regulator — is, in regulatory terms, nobody's problem.
Cross-boundary conflicts are precisely the ones most likely to go undetected. Where a single network of individuals and institutions operates across multiple regulated sectors simultaneously, the compliance obligation is to map the entire network, not just the part of it that touches your own regulatory perimeter.
The United States Foreign Agents Registration Act requires individuals and entities acting on behalf of foreign principals to register and disclose their activities. The UK has no equivalent with real enforcement. Organisations that receive funding from foreign governments, sovereign wealth funds or foreign corporations in exchange for UK policy influence operate in a near-disclosure-free environment. Given the scale of US technology and private equity interest in UK public contracts — from NHS data infrastructure to defence procurement — this gap is no longer merely theoretical.
The UK's Foreign Influence Registration Scheme (FIRS) under the National Security Act 2023 is a step toward closing this gap, but its scope remains contested and enforcement untested. Until it is operationally effective, compliance professionals should treat undisclosed foreign funding of policy-influencing activity as a material risk that FIRS does not yet reliably surface.
There is a layer of the British state's commercial operations that exists behind redacted ink. Contracts worth hundreds of millions of pounds — to manage NHS patient data, police surveillance systems, military logistics platforms and civil service digital infrastructure — are published, in theory, under freedom of information and procurement transparency obligations. In practice, the most consequential terms are blacked out. The parties' obligations are invisible. The pricing is concealed. The exit clauses — the ones that would tell you whether the public can ever extricate itself from these arrangements — do not appear. The redaction is not accidental. It is architectural.
Public contracts law — the Procurement Act 2023 and its predecessor the Public Contracts Regulations 2015 — requires open, competitive tendering for contracts above defined thresholds. In practice, a well-understood set of exemptions is routinely deployed to bypass competition entirely: emergency procurement, single-source justifications, framework agreements that route new work to pre-approved suppliers without fresh competition, and direct awards dressed in the language of "strategic partnership." The result is a procurement system in which the same companies win the same contracts, year after year, in sectors that affect the most sensitive areas of public life.
NHS. MOD. Police. HMRC. Civil service digital. The same shortlist appears across all of them. The tender was never opened. The market was never tested. The price was never compared. And when a journalist or parliamentary committee requests the contract under FOI, what arrives is a document in which the operative terms — the ones that would allow meaningful scrutiny — have been removed.
Palantir — the US intelligence-community contractor with CIA venture-capital origins [In-Q-Tel/Palantir investment: Palantir S-1 prospectus, SEC, September 2020] — won the NHS Federated Data Platform contract to process the health records of 56 million patients [NHS England contract award, October 2023]. UnitedHealth Group's Optum subsidiary acquired EMIS Health, the software running in approximately one in three GP surgeries [EMIS Group market share: CMA Phase 2 Merger Inquiry, January 2023], giving a US health insurance giant data infrastructure across the UK's primary care system. Serco, Capita and G4S have collected billions in public contracts across prisons, immigration detention, test-and-trace and back-office services — while accumulating a collective record of contract failure that, in any competitive market, would have ended their relationship with government decades ago. Accenture, IBM and Leidos occupy the defence and intelligence procurement space. The common thread: these are not the cheapest options, not always the most capable, but they are always available — and they have invested heavily in the relationships that matter.
Sitting above the contractors — shaping the policy environment that determines what gets procured, on what terms, from whom — is a tier of advisory firms whose conflicts of interest are structural, pervasive and almost entirely unmanaged.
The Tony Blair Institute for Global Change advises governments around the world on digital transformation, health data systems and national identity infrastructure — precisely the areas where Palantir, UnitedHealth and their peers are seeking contracts. [Tony Blair Institute publicly disclosed advisory relationships: UK Government digital strategy engagement, Cabinet Office, 2021–2023; Blair's personal advisory work for foreign governments publicly reported by The Times, Financial Times and The Guardian] Blair's own commercial relationships with foreign governments and technology corporations create a web of interests that the Institute's charitable status neither discloses nor resolves. McKinsey — which has collected hundreds of millions in UK government advisory fees including a leading role in NHS test-and-trace [McKinsey NHS test-and-trace contracts: reported by The Sunday Times, 2021; Cabinet Office contract award notices; Public Accounts Committee evidence sessions, 2021] — simultaneously advises the private health, defence and financial services industries whose regulatory treatment it is also shaping. Deloitte, PwC, KPMG and Ernst & Young audit the private companies bidding for public contracts while advising the government departments awarding them. The structural conflict is not incidental to the Big Four model — it is the model. The same firm that signs off a contractor's accounts is advising the client department on whether to award that contractor the next billion-pound deal.
For a compliance professional, any one of these firms in your counterparty or adviser book represents a live conflict-of-interest risk. They are not neutral advisers. They are participants in the market they are purporting to analyse.
Behind every redacted contract is a law firm. The contracts that govern the UK's most sensitive public-private arrangements — NHS data platforms, police facial recognition systems, MOD logistics infrastructure — are drafted by a small number of firms from the magic circle and silver circle: Freshfields, Linklaters, Clifford Chance, Allen & Overy, Slaughter and May. These firms act for both sides of the relationship. They draft the contract for the government department. They act for the contractor on the other side. Sometimes they act in both capacities across different matters simultaneously, in different practice groups of the same firm.
The "commercial sensitivity" exemption under section 43 of the Freedom of Information Act 2000 is the mechanism. It allows public authorities to withhold information where disclosure would prejudice commercial interests. It was designed to protect genuine trade secrets. In practice, it has become the standard instrument for ensuring that the substantive terms of major public contracts — the pricing, the data access rights, the liability caps, the exit terms — never reach public scrutiny. The lawyers who draft the contracts also advise on what can be withheld when the FOI request arrives. They draft for opacity from the beginning, knowing that the redaction will follow.
The Solicitors Regulation Authority has no specific regime for managing conflicts of interest in government procurement. The Bar Standards Board has no enforcement mechanism for systemic conflicts across major public contracts. Professional conduct rules require individual conflict checks — not the systemic analysis that would be required to identify that a single firm is simultaneously shaping the legal terms on which an entire sector is procured and acting for the dominant players in that sector.
When a compliance professional encounters Palantir, Optum, a major management consultancy or a magic circle law firm in their institution's counterparty book, they are not looking at a neutral commercial relationship. They are looking at a participant in a shadow procurement system — one that has been deliberately structured to resist transparency, operates across the boundary of every sectoral regulator, and is serviced by lawyers whose professional obligations do not extend to the public whose money funds the contracts. The counterparty risk is not just commercial. It is reputational, regulatory and, in some cases, national security in nature.
A pattern runs through the collapse of local government in England with a consistency that rules out coincidence. Councils were systematically steered into catastrophically bad technology contracts by a combination of consultants with undisclosed vendor relationships, internal officers who lacked the technical competence to challenge vendor claims, cabinet members who rubber-stamped recommendations without scrutiny, and central government frameworks that created false reassurance where none existed. The vendors knew the procurement process had no meaningful technical due diligence. They acted accordingly.
Largest local authority bankruptcy in UK history. A £100m+ Oracle Fusion ERP implementation that became a black hole — payroll and accounts payable stopped working. Nobody inside the council had the technical capability to know they were being sold an implementation grossly beyond their organisational capacity. External auditors Grant Thornton flagged concerns. They were ignored.
Post Office middle management knew Horizon had bugs — internal evidence is damning. Fujitsu engineers documented faults internally while the Post Office prosecuted subpostmasters for losses those faults created [Post Office Horizon IT Inquiry — published evidence sessions and disclosed documents, 2021–2024]. Over 900 people were wrongly convicted [Criminal Cases Review Commission referrals; Court of Appeal judgments 2021 and 2024]. The board either did not know or did not want to know. Both are catastrophic governance failures. One is criminal.
Almost unheard of. Part technology failure, part reckless commercial investment through the Brick by Brick property subsidiary. Consultants and advisers collected substantial fees throughout every phase of the council's lurching approach to insolvency. The advice was expensive. The consequences were absorbed by residents.
IT and financial systems so degraded the council could not produce audited accounts. External auditors eventually issued a disclaimer — they could not form an opinion at all. The systems had been failing for years before the Section 114. The audit regime that should have caught this was itself captured by the same optimism bias it existed to correct.
External consultants advised the council into increasingly exotic commercial investment structures over several years. The Section 151 officer — the statutory guardian of financial propriety, the council-level equivalent of an MLRO — was either complicit or negligent. In either case, nobody stopped it. The losses were realised by taxpayers.
Robin Hood Energy — a council-owned energy company — collapsed with £38 million in losses. External advisers throughout. The council's leadership pursued a commercial model that no private energy company of that scale would have funded. The advisers who recommended it moved on. The residents absorbed the deficit.
Management consultants, system integrators and legal advisers are frequently conflicted in local authority procurement. A consultant recommending Oracle or SAP may hold a partner relationship with that vendor — receiving referral income, shared project fees or co-selling arrangements that are not disclosed to the council client. The council's procurement process has no mechanism to surface this. The framework agreement that awarded the consulting contract did not require disclosure. The cabinet member who approved the recommendation never knew to ask.
Undisclosed vendor commissions paid to advisers recommending specific technology contracts is not a procurement irregularity. It is commercial bribery under the Bribery Act 2010. Where a pattern of the same advisers appearing across multiple failed deals can be established, the question for any MLRO whose institution is financing, auditing or advising these bodies is whether a SAR obligation has arisen.
The Section 151 officer is the statutory guardian of a council's financial propriety — the closest equivalent in local government to an MLRO in a regulated firm. In almost every council collapse examined here, the S151 officer was either overruled by political leadership, sidelined from the key decisions, or had themselves been captured by the same optimism bias as the leadership. The statutory protections that should make the S151 officer untouchable were insufficient against sustained political pressure in a culture that did not want to hear a dissenting voice.
An S151 officer who identifies unlawful expenditure and does not act — or who is prevented from acting — faces personal liability under the Local Government Finance Act 1988. The pattern of S151 officers moving quietly to other councils after issuing a Section 114 notice, with no regulatory investigation of their conduct, mirrors the individual accountability gap seen in Woodford and Greensill.
Being on a Crown Commercial Service framework gave councils — and their elected members — false assurance that due diligence had been conducted upstream. It had not. Framework inclusion is a commercial negotiation between the Cabinet Office and the vendor. It is not a technical fitness assessment, a conflict-of-interest check, or a suitability evaluation for any specific council's organisational capacity. The framework said: this supplier has agreed commercial terms with central government. Councils read it as: this supplier is trustworthy. The vendors understood the distinction. The councils did not.
If a vendor or consultant actively cultivates this misunderstanding — encouraging councils to rely on framework inclusion as a substitute for independent due diligence — while knowing their product is unsuitable for the council's capacity, that begins to approach fraudulent misrepresentation.
External auditors — largely the same small pool of firms rotating through local authority appointments — issued clean or qualified opinions for years before collapse in every case examined here. The local audit market is broken. The National Audit Office has said so explicitly. Audit firms in local government face the same structural problem as auditors in financial services: they are paid by the entity they are supposed to challenge. The Big Four who sit on both sides of government procurement also conduct many of these audits.
An audit firm that issues a clean opinion on a council's accounts while that council is engaged in unlawful commercial activity — and where that audit firm also advises the vendors supplying the council — faces questions about whether its audit independence was compromised. The same audit firm appearing across multiple failed councils warrants systemic review, not just firm-level accountability.
Fujitsu is currently holding over £3.5 billion in UK government contracts. [Cabinet Office spend data; National Audit Office; reported by The Guardian and Financial Times, 2023–2024] The Cabinet Office has declined to exclude them from public procurement following the Post Office Horizon scandal — in which Fujitsu engineers documented software faults internally while the company's evidence was used to secure wrongful criminal convictions against over 900 people. No Fujitsu executive has been prosecuted. The contracts continue. This is not negligence. It is vendor capture: the condition in which a supplier has become so embedded in critical government infrastructure that the state calculates it cannot afford to hold the supplier accountable. The compliance implication is stark. Any institution that treats government contract award as a proxy for reputational due diligence should revisit that assumption immediately.
MLROs and compliance functions in financial services rarely examine procurement. But where a council, NHS trust or housing association is being advised into a catastrophic technology deal — with undisclosed commission, undisclosed relationships and the same advisers recurring across multiple failed outcomes — that pattern starts to look less like negligence and more like a systemic extraction mechanism. That is squarely in financial crime territory. The SAR obligation does not require proof of a predicate offence. It requires reasonable grounds for suspicion. The pattern described in this section provides them.
Given these structural limitations, what can MLROs and compliance professionals actually do when they encounter or suspect a conflict of interest the formal framework cannot see? The following four steps provide a practical starting point.
Standard conflict-of-interest protocols focus on the transaction — is this counterparty on a sanctions list? Does this adviser have a declared financial interest? These checks are necessary but insufficient. The question that modern conflicts require is structural: who else is connected to the principal parties, and what are their interests? Map board memberships, advisory roles, political connections and corporate affiliations of key counterparties — not just at onboarding but on a rolling basis. A counterparty that was clean at onboarding may have appointed a new board member with a material conflict twelve months later.
The first question most compliance frameworks ask is: does this breach any rule? The more useful question — the one that catches conflicts the rules cannot see — is: who benefits from this arrangement, and is that benefit disclosed? Follow the economic and reputational incentives rather than the legal structure. An advisory firm may be technically outside the lobbying register, but if its principals financially benefit from regulatory outcomes their client base is trying to influence, the conflict is real regardless of how the firm is classified.
In AML, professionals treat unusual structuring — transactions designed to stay below reporting thresholds — as a red flag. The same logic applies to influence and conflict-of-interest risk. When counterparties, advisers or institutional partners consistently decline to characterise their activities in terms that would trigger regulatory attention — when they are an "adviser" not a lobbyist, a "charitable institute" not a policy influence firm — this pattern warrants scrutiny. Ask: who benefits from keeping these descriptions imprecise?
When internal analysis reveals a conflict of interest outside formal regulatory definitions but material to your institution's risk profile, the compliance obligation is to document the analysis, escalate to appropriate seniority and — where the conflict involves potential public interest harm — consider whether external reporting obligations apply. In an AML context, this may mean filing a SAR even where no specific predicate offence can be identified, on the basis that the overall pattern raises reasonable grounds for suspicion. Ensure your institution's risk register reflects the reality of the operating environment, not just the categories regulators have explicitly defined.
Your firm is considering engaging a policy advisory firm to support a regulatory submission. Research reveals that the firm's senior partner chairs a charity think tank that has publicly advocated the same regulatory outcome your firm is seeking, and that the think tank receives substantial funding from two of your firm's largest competitors. The advisory firm is not on the lobbying register. How do you assess this?
Map the benefit flows. The think tank's advocacy benefits the competitors funding it and potentially your firm. The advisory firm's principal controls the narrative on both sides. This is a classic intermediary vehicle structure. The absence of lobbying registration is not reassurance — it is a characteristic of the model. Require full disclosure of all funding sources before engagement. Consider whether the conflict can be managed or must be declined.
A new counterparty's board includes a former senior regulator who, until 18 months ago, oversaw the regulatory framework your firm operates under. The former regulator is within their ACOBA cooling-off period but is listed as a "non-executive adviser" rather than an executive director. The counterparty is seeking a significant commercial arrangement with your firm. What is your compliance assessment?
ACOBA compliance is not the test — it is the minimum. Map specifically what regulatory decisions the individual oversaw against the commercial interests of the counterparty. "Non-executive adviser" is a label, not a description of actual influence. Require a full conflicts declaration from the counterparty. Consider whether the arrangement creates a reasonable perception of impropriety even if technically compliant, and escalate to senior management with that framing.
During EDD on a UK policy consultancy, you identify that approximately 40% of its income derives from a sovereign wealth fund via a series of intermediary structures. The consultancy is not registered under FIRS. It regularly produces policy papers that align with the foreign government's stated UK policy objectives. The consultancy is not on any sanctions list. Is there a compliance concern?
Absence from sanctions lists tells you the entity is not prohibited — it tells you nothing about the nature of the relationship. Undisclosed foreign funding of UK policy influence activity is a reputational, regulatory and potentially national security risk. Apply the benefit test: who benefits from the consultancy's policy positions, and is that benefit visible? Consider whether engagement would expose your institution to association with undisclosed foreign influence activity. Take legal advice before proceeding.
Your firm's legal team has confirmed that a complex counterparty arrangement is compliant with FCA rules. The risk team has confirmed it is compliant with Ofwat obligations. No single regulator has jurisdiction over the arrangement as a whole. You believe the aggregate effect — a private equity firm gaining effective influence over a regulated utility's pricing strategy via an intermediary advisory structure — represents a material public interest risk. What do you do?
The fact that no single regulator owns the risk does not mean the risk is not real — it means it is yours to manage. Document your analysis of the aggregate risk. Escalate to board level with an explicit statement that individual regulatory sign-offs do not constitute clearance of the systemic conflict. Consider whether a SAR is appropriate on the basis that the overall pattern raises reasonable grounds for suspicion of abuse of position. The absence of a responsible regulator heightens, not reduces, your institution's own obligation.
A senior public official repeatedly declines to use specific regulatory or legal terminology when discussing a matter of policy consequence — consistently choosing language that avoids characterising a situation in terms that would trigger formal investigation. Several of your firm's counterparties have a direct financial interest in the ambiguity being maintained. Is this a compliance concern?
Deliberate language choice by public officials around matters of regulatory consequence is a detection signal, not a stylistic preference. Apply the benefit test: who benefits from the terminology remaining imprecise? If the answer is a set of counterparties with whom your firm has commercial relationships, you have an undisclosed conflict of interest risk in your counterparty book. Map who benefits, document your analysis and escalate. The semantic evasion is the symptom — the conflict is the underlying condition.
| Reform | What It Requires |
|---|---|
| Foreign Influence Registration Scheme | The FIRS under the National Security Act 2023 must capture all material foreign-funded policy influence activity regardless of the vehicle used. Current scope is contested; enforcement is untested. Without mandatory disclosure of beneficial funding sources, the gap remains exploitable. |
| ACOBA: Statutory Powers | ACOBA must be given statutory authority, the power to sanction breaches and a mandate to publish investigations with findings. Without enforcement powers, the revolving door regime is theatre — a process that launders reputational risk without controlling actual conduct. |
| Cross-Cutting Conflicts Commissioner | The UK needs a regulator with a mandate that crosses sectoral boundaries — authority to investigate conflicts that span the FCA, Ofwat, the Charity Commission and public procurement simultaneously. This is the single most important structural gap in the current architecture. |
| Beneficial Ownership of Advisory Firms | The beneficial ownership registers that apply to companies must be extended to advisory firms, think tanks and policy-influencing organisations receiving material income from corporate or foreign government sources. Opacity of funding is the foundation of the model. |
| Lobbying Register Reform | The statutory lobbying register must be expanded beyond direct ministerial contact to capture introductions, facilitated access, background briefings and the ambient relationship maintenance that constitutes most actual influence activity. The current definition is known to be inadequate and has not been revised since 2014. |
The most important shift this paper asks of compliance professionals is to treat regulatory compliance not as the definition of acceptable conduct but as the minimum baseline below which you must not fall.
The networks of advisers, lobby groups and former public officials that currently operate around the UK's most consequential regulatory decisions are — for the most part — legal. The problem is not individual corruption. The problem is a system architecture that converts legitimate professional relationships into systematic extraction, and that has constructed a compliance framework too narrow to see it.
When you encounter a conflict of interest the rules don't quite capture, ask not "is this allowed?" but "who benefits, who bears the cost, and is that visible?" If the answer to the last part is no — the conflict is real, and it is your professional responsibility to surface it.