Perspectivas
Perspective 004Governance

What regulators mean by effective AML governance.

Governance is not established by organisation charts alone. The evidence sits in the information people received, the challenge they exercised, the accountability they understood and what happened afterwards.

El texto completo de este análisis se publica en inglés. La estructura, las cifras y las referencias son las mismas en ambas versiones del sitio.

Por Everett MorganAutumn 20267 min read
European executive boardroom interior
Executive brief

Reading time · 10 minutes  ·  Primary audience · Chairs, Non-Executive Directors, CEOs, MLROs, Heads of Compliance

Why this matters

Organisation charts and committee structures tell a supervisor how governance is meant to work. The harder question is whether the decisions, the information and the challenge show that it actually does. Very few firms describe their own governance as weak. The statement is easy to make. Proving it is harder. That is where substantive supervisory testing can go beyond the organisation chart.

Key findings
  1. 01Organisation charts and committee structures are the starting point. Evidence of how governance operates is what tells you whether the structure works.
  2. 02Board MI needs to explain risk and what is changing, not simply count activity. Minutes and governance records should make material challenge and outcomes traceable where they mattered.
  3. 03When I test governance in practice, three areas repeatedly tell me whether the structure is doing real work: information quality, substantive challenge and accountability.
  4. 04Governance habits are difficult to manufacture under pressure. Firms that already have them are in a stronger position when scrutiny arrives.
  5. 05Constructive challenge is a sign of healthy governance, not a weakness.
  6. 06Governance needs to remain fit for the business as financial-crime risk, products, customers and regulatory expectations change.
Questions Boards should ask
  1. 01If someone read a recent run of our Board packs cold, would they understand our financial-crime risk position and what has materially changed?
  2. 02For a recent material financial-crime issue, can we trace the evidence, challenge, governance outcome and accountable owner?
  3. 03If our regulator asked us to demonstrate effective governance, could we show how the structure translates into information, challenge, accountability and action?

From governance architecture to governance evidence

The architecture still matters. A firm without clear governance, defined AML/CFT roles and appropriate oversight has a basic problem. But the existence of the architecture does not prove that it is working. The harder test is whether the information, the challenge and the accountability show that the structure is being used.

Recent enforcement repeatedly shows that the existence of governance architecture does not, by itself, establish control effectiveness. Firms have had the forums, the charters and, in some cases, reasonable policy on paper. What was in question was whether the framework operated.

Very few firms describe their own governance as weak. The statement is easy to make. Proving it is harder. In practice, a firm should be able to show how material issues were considered, what information reached governance, what challenge occurred, what outcome followed and who was accountable for it.

This is the context in which the term "effective governance" is now used. Perspective 002 set out the questions a Board should be able to answer. Perspective 003 examined the role of independent challenge in testing those answers. This Perspective describes what I look for when governance is tested directly.

Three tests I use when reading governance in practice

Recent supervisory and enforcement material reinforces these themes, but they are practitioner lenses rather than a prescribed EU test.

Information quality

The first test is whether the information reaching governance supports understanding, challenge, decisions and follow-up. Board MI needs to explain risk and what is changing, not simply count activity. A report that counts alerts, completed reviews or training hours tells the Board that work has been done. It does not necessarily explain whether risk is being managed.

The MI I find useful is risk-oriented. It says where residual exposure sits and how the firm believes it is moving, using qualitative and quantitative measures as appropriate. It interprets rather than recites. And it gives enough trend context for the direction of travel to be visible instead of inferred.

Challenge quality

The second test is whether material issues are genuinely understood and tested rather than simply passed through governance. I do not need challenge for the sake of proving the Board is active. I do need evidence that material issues were considered properly.

Agreement after proper challenge is perfectly legitimate. The issue is not whether people disagreed. It is whether the conclusion was tested.

Minutes are where this shows. A minute that only says "discussed" or "noted" may be perfectly adequate for a routine item. For a material issue, I would expect the record to show more of the substance. For material items, the record should be sufficient for someone who was not in the room to understand the substance of the challenge, the conclusion and the follow-up. If nothing much happened, the honest minute is short.

Accountability traceability

The third test is whether accountability is clear through the applicable management-body and control structure, with named role-holders where the framework assigns individual responsibility. The point is not to allocate blame after the fact. It is to know who owned the issue, who had authority to act and how escalation worked. A committee that meets regularly but does not influence real governance outcomes is a structure, not an accountability mechanism.

Where accountability is diffuse, either between the first and second line or between the executive and the management body, the framework is weaker than the sum of its parts. Clear accountability supports better governance and makes the firm's decisions easier to explain under scrutiny.

The habits that produce effective governance

Effective governance is not installed. It is practised. The habits below are the ones I find most useful when testing whether governance is alive rather than simply documented.

Governance has to stay fit for the business

A governance framework does not need to change simply because time has passed. But it does need to be reviewed against the business and risks it now supports. What was proportionate when the firm was smaller or differently structured may no longer be enough.

Regular review gives the firm a chance to adjust before weaknesses become embedded, and leaves a clear record that governance has been tested against the current risk profile. The prompts are often visible once someone looks: a new product, a new distribution channel, a jurisdiction added quietly, growth in a customer segment the framework was never designed around.

What AMLA will inherit

AMLA is already operating. Direct supervision of selected cross-border financial institutions begins in 2028. AMLA's first selection process will identify eligible cross-border financial institutions for direct supervision based on the legal criteria and a harmonised risk assessment, so this is not a question of size alone.

For most smaller firms, the more immediate effect will come through the Single Rulebook and increasing supervisory convergence at national level rather than direct AMLA supervision. The governance expectations described in this Perspective are, in substance, the expectations AMLR sets out. Firms that already have these habits will be in a stronger position as the new framework beds in. Firms that postpone known governance work will have less room to absorb it later.

How Claritas approaches governance work

Governance reviews in the Claritas model are diagnostic rather than architectural. We do not start by redesigning the architecture. We first test whether the existing structure is clear, proportionate and actually being used.

The work usually involves a cold read of a recent run of Board and committee papers, the associated MI and minutes, looking at the material financial-crime issues considered and the trail behind them. Then structured conversations with the role-holders relevant to the firm's governance model, focused on the three lenses described above. Where necessary, a proportionate, deliberate sample of operating evidence to test whether the governance narrative survives contact with the underlying control. The findings note, written for the Board, distinguishes what requires management-body understanding or challenge, what needs a governance decision and what belongs in operational remediation.

The intended output is not a redesign. It is specific, named-owner improvements that move the framework from documented to demonstrable.

Paperwork matters. But it only tells me how governance is supposed to work. The evidence is in the governance outcomes, the challenge, the information people acted on and whether the people responsible for the risk can explain it without reaching for the policy.

That is the difference between having a governance structure and having governance.

What success looks like
  • 01Board packs make the material financial-crime risk position and significant changes visible before activity volumes obscure them.
  • 02The governance record is sufficient to trace material challenge, evidence and outcomes where they mattered.
  • 03Material escalations remain traceable to owners, status and evidence of resolution.
  • 04The Board can point to material issues where challenge changed the evidence requested, the action taken, the conditions applied or the understanding of the risk, where the facts required it. Challenge can be effective even where the final conclusion remains unchanged.
  • 05Governance improvements progress as part of normal business and are not driven principally by supervisory events.
References
Sobre el autor
Everett Morgan
Founder & Principal Adviser, Claritas Risk Advisory

Everett has more than twenty years' experience in financial crime, AML governance, regulatory compliance and operational risk gained within Deutsche Bank, Morgan Stanley and BNP Paribas. He established Claritas Risk Advisory to provide smaller regulated financial institutions with experienced independent judgement, practical insight and proportionate recommendations.

¿Necesita una opinión independiente?

Preparing for regulatory change starts with understanding where your organisation stands today.

If you would like to discuss your financial crime framework or explore how Claritas Risk Advisory can help, I would be pleased to arrange a confidential conversation.

Empecemos con una conversación