Handling Priorities for FCC Teams

Image

A control can pass its annual review and still be doing almost nothing. The gap between the two doesn't usually announce itself. It builds through small compromises that never individually trigger an alarm: a review filed a month late, or even a risk tier set three years ago and left untouched since.

MLROs and Heads of Compliance mostly know these gaps exist. What's harder is prioritising them, and having an answer ready when a regulator or the board asks how that priority list was built.

This article maps where financial crime risk actually concentrates, the control weaknesses most likely to be hiding it, and two areas that get less weight in that conversation than they should: data quality, and how AI is actually used in FCC.

‍

Start with where the risk actually sits

Before picking apart individual controls, it helps to ask a blunter question first: where in the business does financial crime risk concentrate? Four lenses tend to cover most of it.

Customer types

Which segments carry more risk than their volume suggests? PEPs and their close associates, high-net-worth individuals with unclear sources of wealth, corporate structures layered with trusts or nominee shareholders, cash-intensive businesses like MSBs or car dealerships, non-resident customers with no real tie to the jurisdiction, correspondent banking relationships, and customers in higher-risk sectors such as precious metals, art, or crypto-asset services. The sharper question isn't "who are our riskiest customers", it's whether the definition of high-risk has kept pace with how those segments actually behave now.

Products

Which products draw bad actors, and has usage drifted somewhere the original risk assessment never anticipated? Correspondent banking and trade finance remain classic exposure points, especially where the underlying trade documentation is hard to verify independently. Trust and company formation services get misused to obscure ownership. Wealth management products carry risk where source-of-wealth checks haven't scaled with client growth. Instant payments, prepaid cards, and open banking rails move money faster than most monitoring windows were designed for. Crypto custody, exchange, and on/off-ramp services carry exposure that a lot of legacy risk models still can't score consistently. Even a plain current account can turn into a money-muling vector if nobody's watching the usage pattern.

Jurisdictions

Where is exposure concentrated geographically, and has that picture moved as the business has grown or sanctions regimes have shifted? This isn't only about customers domiciled in high-risk countries. It's transaction flows that route through them, correspondent relationships with banks headquartered there, and beneficial owners or directors based there even when the customer entity is registered somewhere else entirely. It means staying current on FATF grey and black list additions, EU and OFAC sanctions updates, and countries where corruption or conflict has worsened since the last risk assessment. A jurisdiction rated low-risk three years ago isn't necessarily low-risk today.

Delivery channels

Are digital, remote, or third-party channels creating blind spots that face-to-face relationships don't have? Digital onboarding without strong identity verification opens the door to synthetic identities and document fraud. Introduced or intermediated business — where a broker, agent, or platform brings in the customer — often means the firm never directly verifies who it's actually dealing with. Correspondent and nested relationships can hide the real underlying customer several layers back. Mobile-first onboarding that allows fast account opening and funding can outrun the controls meant to catch problems. White-label and embedded finance arrangements, where a firm's product sits under someone else's brand, weaken the line of sight into who the end customer really is.

‍

Budgeting your focus

None of this is meant to produce four separate risk registers. It's meant to force a prioritisation call. Not every gap deserves the same urgency, and resources are finite. The MLRO has more cross-functional visibility than almost anyone else in the organisation, and that judgment on where to focus review effort should carry real weight in how programmes get scoped.

But judgment on its own doesn't hold up to scrutiny. A confident view without a documented trail behind it collapses the moment an internal auditor, a regulator, or a board member asks "how do you know?"

‍

Where vulnerabilities typically hide

The following is a working list of control areas worth interrogating, paired with the specific signs that a control looks fine on paper but isn't doing its job.

Customer risk assessments

  • Risk ratings frozen for years while customer behaviour and available technology have moved on
  • High-risk customers sitting in the wrong tier with no documented reasoning
  • Scoring models that treat jurisdiction, product usage, or PEP status inconsistently from one case to the next

Ongoing monitoring

  • Review intervals for high-risk customers that have quietly stretched out
  • Trigger events — a large transaction, adverse media, a change in ownership — that don't reliably prompt a fresh look
  • Review cadence that doesn't actually track the customer's assigned risk tier

Sanctions screening

  • Screening applied at onboarding only, with no continuous checks against updated lists through the life of the relationship
  • A backlog of unresolved hits that keeps growing without explanation
  • Tools that miss name variants, aliases, transliteration issues, or recently added designations

Governance records

  • Committee minutes that are missing or half-complete
  • No traceable record of who approved an AML policy change, or when
  • MLRO reports to the board that are thin on substance, or never formally minuted

Outsourcing

  • Third-party KYC or screening vendors brought on without documented due diligence
  • Contracts that stay silent on AML responsibilities and oversight obligations
  • No evidence the firm has ever actually tested the vendor's performance

Training

  • Completion records with visible gaps across staff
  • Generic content that doesn't differentiate a front-line teller from an MLRO
  • No sign that content was updated after a regulatory change or a newly identified typology

Documentation

  • No recorded rationale for SAR decisions, whether filed or not
  • Record-keeping that varies noticeably by branch or business line
  • Policies that have fallen behind current regulation or how the business now actually operates

Beneficial ownership

  • Verification that stops at the first layer, leaving the ultimate owner unconfirmed in layered structures
  • Ownership data captured once and never refreshed
  • Reliance on self-reported ownership with no independent check

Transaction monitoring

  • Alerts closed with thin, templated notes
  • Rules and thresholds that aren't tuned to the customer's actual risk profile or business type
  • Backlogs, or inconsistent time lags between an alert firing and a case being escalated

Escalation decisions

  • Cases resolved at first line that probably warranted MLRO involvement
  • No defined threshold for what should or shouldn't escalate
  • Escalation calls made without documented reasoning, making consistency hard to demonstrate later

‍

The hidden root cause: data quality

Trace almost any finding back far enough and it lands on the same problem: bad underlying data. A risk rating can't reflect current behaviour if the customer record hasn't been refreshed. Sanctions screening misses an alias when the name data feeding it is inconsistent. 

Transaction monitoring rules can't be calibrated properly on customer risk data that's stale or scattered across disconnected systems.

Data quality rarely earns its own line in a risk assessment, yet it's often the real cause behind findings filed under some other control's name. 

Teams looking to fix the source, not just patch individual gaps, should treat data quality, its completeness, accuracy, cross-system consistency, and refresh frequency, as its own area, with its own owner and its own metrics.

‍

Helping To Close the Gap

Data quality gaps like these are exactly what Level Five's platform is built to close, giving FCC teams the completeness, consistency, and cross-system visibility that internal fixes alone can't deliver. 

If this is what your team needs, contact us here.

‍

AI and machine learning in FCC: opportunity versus exposure

AI has earned a place in the FCC toolkit — transaction monitoring models that cut false positives, tools that triage alerts or surface adverse media faster than a manual review ever could. Used well, these tools can close some of the gaps described above, particularly around monitoring calibration and alert backlogs.

But AI brings its own set of questions that a checklist-driven review needs to sit with:

  • Can the model's decisions actually be explained and evidenced, or does it function as a black box that makes escalation reasoning harder to document rather than easier?
  • Has it been validated against the firm's actual customer base and risk profile, rather than a generic training set?
  • Who owns model risk, and is that ownership documented as clearly as it would be for a traditional rule-based system?
  • Is there a defined process for retraining or recalibrating the model as typologies shift, in the same way training content should be refreshed after a regulatory change?

Treating AI tools as exempt from the evidentiary standard applied to every other control here is a mistake. If anything, the newer and less understood the tool, the more scrutiny its output deserves..

‍

Level Five’s Perspective

Most control failures get traced to data quality. Fix the records, the logic goes, and findings resolve themselves.

True, but it misses the harder problem in Southeast Asia.

Take a bank with excellent data hygiene: records current, ownership verified, screening catching aliases. By review standards, it passes.

A mule network can still move funds through its accounts undetected, because that network also touches four banks in three countries, invisible to this one. The customer looks clean because nothing looks unusual from this bank's vantage point. The pattern exists only at network level, outside any single institution's book.

AI governance has the same blind spot. The usual questions get asked: can the model be explained, is it validated against the firm's own customer base, who owns model risk. But that validation is the limit. A model trained on one institution's history gets sharp at spotting yesterday's fraud on that book, while regional syndicates keep moving and rotate patterns faster than any quarterly validation cycle.

Clean data and governed models are prerequisites, not answers. An institution can have both and remain a step behind, blind to activity two banks over.

None of this argues against data quality or AI governance, both remain necessary. But the typology that matters most usually lives in the pattern across institutions, visible only to whoever has sight into more than one. That gap closes through intelligence sharing and cross-industry data, not internal housekeeping.

‍