
A control can pass its annual review and still be doing almost nothing. The gap between the two doesn't usually announce itself. It builds through small compromises that never individually trigger an alarm: a review filed a month late, or even a risk tier set three years ago and left untouched since.
MLROs and Heads of Compliance mostly know these gaps exist. What's harder is prioritising them, and having an answer ready when a regulator or the board asks how that priority list was built.
This article maps where financial crime risk actually concentrates, the control weaknesses most likely to be hiding it, and two areas that get less weight in that conversation than they should: data quality, and how AI is actually used in FCC.
Before picking apart individual controls, it helps to ask a blunter question first: where in the business does financial crime risk concentrate? Four lenses tend to cover most of it.
Which segments carry more risk than their volume suggests? PEPs and their close associates, high-net-worth individuals with unclear sources of wealth, corporate structures layered with trusts or nominee shareholders, cash-intensive businesses like MSBs or car dealerships, non-resident customers with no real tie to the jurisdiction, correspondent banking relationships, and customers in higher-risk sectors such as precious metals, art, or crypto-asset services. The sharper question isn't "who are our riskiest customers", it's whether the definition of high-risk has kept pace with how those segments actually behave now.
Which products draw bad actors, and has usage drifted somewhere the original risk assessment never anticipated? Correspondent banking and trade finance remain classic exposure points, especially where the underlying trade documentation is hard to verify independently. Trust and company formation services get misused to obscure ownership. Wealth management products carry risk where source-of-wealth checks haven't scaled with client growth. Instant payments, prepaid cards, and open banking rails move money faster than most monitoring windows were designed for. Crypto custody, exchange, and on/off-ramp services carry exposure that a lot of legacy risk models still can't score consistently. Even a plain current account can turn into a money-muling vector if nobody's watching the usage pattern.
Where is exposure concentrated geographically, and has that picture moved as the business has grown or sanctions regimes have shifted? This isn't only about customers domiciled in high-risk countries. It's transaction flows that route through them, correspondent relationships with banks headquartered there, and beneficial owners or directors based there even when the customer entity is registered somewhere else entirely. It means staying current on FATF grey and black list additions, EU and OFAC sanctions updates, and countries where corruption or conflict has worsened since the last risk assessment. A jurisdiction rated low-risk three years ago isn't necessarily low-risk today.
Are digital, remote, or third-party channels creating blind spots that face-to-face relationships don't have? Digital onboarding without strong identity verification opens the door to synthetic identities and document fraud. Introduced or intermediated business — where a broker, agent, or platform brings in the customer — often means the firm never directly verifies who it's actually dealing with. Correspondent and nested relationships can hide the real underlying customer several layers back. Mobile-first onboarding that allows fast account opening and funding can outrun the controls meant to catch problems. White-label and embedded finance arrangements, where a firm's product sits under someone else's brand, weaken the line of sight into who the end customer really is.
None of this is meant to produce four separate risk registers. It's meant to force a prioritisation call. Not every gap deserves the same urgency, and resources are finite. The MLRO has more cross-functional visibility than almost anyone else in the organisation, and that judgment on where to focus review effort should carry real weight in how programmes get scoped.
But judgment on its own doesn't hold up to scrutiny. A confident view without a documented trail behind it collapses the moment an internal auditor, a regulator, or a board member asks "how do you know?"
The following is a working list of control areas worth interrogating, paired with the specific signs that a control looks fine on paper but isn't doing its job.
Trace almost any finding back far enough and it lands on the same problem: bad underlying data. A risk rating can't reflect current behaviour if the customer record hasn't been refreshed. Sanctions screening misses an alias when the name data feeding it is inconsistent.
Transaction monitoring rules can't be calibrated properly on customer risk data that's stale or scattered across disconnected systems.
Data quality rarely earns its own line in a risk assessment, yet it's often the real cause behind findings filed under some other control's name.
Teams looking to fix the source, not just patch individual gaps, should treat data quality, its completeness, accuracy, cross-system consistency, and refresh frequency, as its own area, with its own owner and its own metrics.
Data quality gaps like these are exactly what Level Five's platform is built to close, giving FCC teams the completeness, consistency, and cross-system visibility that internal fixes alone can't deliver.
If this is what your team needs, contact us here.
AI has earned a place in the FCC toolkit — transaction monitoring models that cut false positives, tools that triage alerts or surface adverse media faster than a manual review ever could. Used well, these tools can close some of the gaps described above, particularly around monitoring calibration and alert backlogs.
But AI brings its own set of questions that a checklist-driven review needs to sit with:
Treating AI tools as exempt from the evidentiary standard applied to every other control here is a mistake. If anything, the newer and less understood the tool, the more scrutiny its output deserves..
Most control failures get traced to data quality. Fix the records, the logic goes, and findings resolve themselves.
True, but it misses the harder problem in Southeast Asia.
Take a bank with excellent data hygiene: records current, ownership verified, screening catching aliases. By review standards, it passes.
A mule network can still move funds through its accounts undetected, because that network also touches four banks in three countries, invisible to this one. The customer looks clean because nothing looks unusual from this bank's vantage point. The pattern exists only at network level, outside any single institution's book.
AI governance has the same blind spot. The usual questions get asked: can the model be explained, is it validated against the firm's own customer base, who owns model risk. But that validation is the limit. A model trained on one institution's history gets sharp at spotting yesterday's fraud on that book, while regional syndicates keep moving and rotate patterns faster than any quarterly validation cycle.
Clean data and governed models are prerequisites, not answers. An institution can have both and remain a step behind, blind to activity two banks over.
None of this argues against data quality or AI governance, both remain necessary. But the typology that matters most usually lives in the pattern across institutions, visible only to whoever has sight into more than one. That gap closes through intelligence sharing and cross-industry data, not internal housekeeping.