Perspectivas
Perspective 005Practice

Preparing for an AML inspection before you receive the letter.

In my experience, the firms that handle inspections best are rarely the ones making last-minute changes. They are the ones that started looking at the weaknesses before the letter arrived.

El texto completo de este análisis se publica en inglés. La estructura, las cifras y las referencias son las mismas en ambas versiones del sitio.

Por Everett MorganAutumn 20267 min read
European supervisory office building
Executive brief

Reading time · 11 minutes  ·  Primary audience · MLROs, Heads of Compliance, CEOs, Boards, Internal Audit

Why this matters

Inspection preparation is a governance discipline, not an event. The firms that handle scrutiny well are usually the ones that have been strengthening the framework before the inspection becomes an event. Material weaknesses take time to fix properly, and that work rarely compresses into the period after the letter arrives.

Key findings
  1. 01European AML/CFT supervisors can use a range of substantive testing tools, including file review, interviews, walkthroughs and examination of governance evidence, depending on the risk and supervisory objective.
  2. 02Three issues recur often in the inspections and readiness work I have seen: legacy CDD debt, monitoring configuration and MI that reports activity better than it explains risk.
  3. 03The most useful preparation is not documentary. It is addressing the material weaknesses the firm already knows about, evidencing progress and strengthening the underlying controls.
  4. 04I have found that firms engage more effectively when they have already practised explaining difficult issues, answering directly and distinguishing what they know from what they are still fixing. External challenge and internal simulation can be useful ways to test that discipline where proportionate.
Questions Boards should ask
  1. 01If we received an inspection notice tomorrow, what material weaknesses would we most want to have closed or credibly under control before substantive testing began?
  2. 02Do we have a current, honest self-assessment of where our framework is weakest, and can we describe the plan and progress against the material items?
  3. 03Would a proportionate inspection simulation expose anything useful before the real engagement, and if so, what would we want it to test?

Where inspection testing goes beyond documents

Document readiness has always mattered. Inspection testing can go beyond documentary readiness and examine whether the files, processes and decisions support the framework the firm says it operates.

Depending on scope and risk, supervisory testing may include file sampling, process walkthroughs, interviews and detailed review of governance information. The purpose of each is to test whether the framework operates as its documentation implies. Preparation that treats inspection as a presentation exercise misses the point.

Perspective 004 set out three governance tests I use when thinking about whether oversight is working in practice. Inspection is where questions of that kind get asked at the file, meeting and MI level. This Perspective is about the period before an inspection, and how to use it.

Three issues that recur

Across the inspections I have observed or supported, three issues come up often enough that I look at them first.

Legacy customer due diligence

Legacy CDD is one of the issues I see recur most often in readiness and remediation work, particularly on higher-risk customers onboarded before current standards. The issue is not usually a lack of documentation. It is that the documentation on file no longer reflects the customer's current activity, ownership, geography or risk profile. Ongoing review has fallen behind, or has become a calendar exercise that confirms data without genuinely reconsidering the relationship.

Monitoring configuration

Transaction monitoring is the second recurring theme. Among the things that may be tested are whether monitoring coverage reflects the firm's actual products, customers, channels and risks, whether material thresholds or parameters are governed appropriately, and whether closure decisions are defensible against the methodology and evidence.

A common failure mode is a configuration left at vendor defaults and never properly reviewed against the firm's own population. That is a difficult control position to defend. The firm should be able to explain the basis for the current monitoring configuration, who owns material changes, what evidence supports it and how it is reviewed.

Management information

The third area is the MI reaching governance. Perspective 004 set out the properties of effective MI. A useful readiness test is whether accountable senior leaders can explain the firm's principal financial-crime risks and material weaknesses using the same MI they actually receive. If they cannot, the issue is not simply a reporting problem. It is a governance problem.

An illustrative preparation runway

Where a firm has meaningful advance notice, this is broadly how I sequence the work. The phases below are illustrative. The order and duration should follow the risk, materiality and time actually available.

Conduct during the inspection

Preparation is not only about the state of the framework. It is also about the practised discipline of engagement. An inspection may concentrate a lot of judgement into a relatively small number of interviews, file discussions and observed processes. The discipline of how people answer, evidence and escalate therefore matters.

How Claritas approaches inspection readiness

Claritas readiness work is designed around the time actually available and the weaknesses the firm needs to address. I normally think about it in three broad parts.

First, a readiness diagnostic. A focused readiness assessment tests the framework against the firm's material risk areas and known weaknesses. Legacy CDD, monitoring configuration and MI recur often in my work, but the assessment should follow the firm's own risk profile rather than a fixed Claritas template. This is diagnostic work. It is not Independent Assurance.

Second, a remediation runway. A prioritised remediation runway sequences corrective work by materiality, dependency and available capacity. Third, a readiness test. A simulation may be useful once the underlying control work is mature enough to make the exercise meaningful, focusing on live explanation, evidence retrieval and the handling of difficult issues rather than rehearsing a polished presentation.

For many smaller institutions, the direct assessment effort may be measured in weeks rather than months, spread across the wider preparation period. The exact effort should follow the scope and evidence needed.

What success looks like
  • 01The firm has an honest, current baseline of where the framework is weakest and where progress is being made.
  • 02Material known weaknesses are either resolved or on a credible, risk-based remediation trajectory with progress visible in governance MI.
  • 03Material monitoring configuration and control logic are documented, governed and can be explained against the firm's risk profile and operating evidence.
  • 04The governance MI pack gives accountable senior leaders enough information to explain the firm's principal financial-crime risks, material control weaknesses and the actions being taken.
  • 05Where proportionate, the firm has tested its readiness through an internal or externally facilitated simulation and acted on what the exercise exposed.
References
Sobre el autor
Everett Morgan
Founder & Principal Adviser, Claritas Risk Advisory

Everett has more than twenty years' experience in financial crime, AML governance, regulatory compliance and operational risk gained within Deutsche Bank, Morgan Stanley and BNP Paribas. He established Claritas Risk Advisory to provide smaller regulated financial institutions with experienced independent judgement, practical insight and proportionate recommendations.

¿Necesita una opinión independiente?

Preparing for regulatory change starts with understanding where your organisation stands today.

If you would like to discuss your financial crime framework or explore how Claritas Risk Advisory can help, I would be pleased to arrange a confidential conversation.

Empecemos con una conversación