The problem: a full pack can still leave the question unanswered
Dashboards. Performance indicators. Open actions. Training statistics. Suspicious activity reporting. Customer due diligence metrics. A Board pack in a regulated firm of any scale now carries all of it, quarter after quarter, in detail. And yet Boards often struggle to say what they understood differently, or decided differently, because of what the pack contained.
A metric tells me what happened. Good MI helps me understand why it happened, whether it matters and what needs to happen next.
Activity matters. But without context it tells the Board very little about exposure, control effectiveness or the decisions management needs it to make.
That gap is not a criticism of individual directors. It is usually a design problem. Packs are often built to demonstrate coverage rather than to support discussion. They answer the question a compliance function would ask (what have we done) rather than the question a Board should ask (what should we now understand or decide).
The evidence: Boards that received the numbers and missed the story
Root causes: why volume displaces conversation
Three causes recur, and they compound.
One number, several explanations
Take transaction monitoring. Alert volumes rise sharply one quarter. That could mean the customer base has grown, or the mix of activity has changed. It could mean thresholds were retuned. It could mean a typology rule was switched on. It could also be a data or population issue. It could mean genuinely higher risk.
Now take the opposite. Alert volumes fall. That could be better tuning and fewer false positives. It could be a broken feed, a scope gap or a rule that stopped firing. Both movements look tidy on a dashboard and neither explains itself.
The number is the starting point, not the conclusion.
From information to judgement
Directors should leave the discussion with a clearer understanding of the principal financial-crime risks, what has changed, whether controls are responding as expected and what management intends to do next. Some risks will be stable and well controlled. Some will be moving. Some will be poorly controlled and the pack should say so.
The Board does not need to run the AML function. It does need enough information and collective understanding to challenge the people who do. That means testing assumptions rather than accepting them, asking for the evidence behind a conclusion, and revisiting earlier decisions when circumstances change.
There is another question I like Boards to ask: what is not in this pack? A dashboard is built from choices. Someone decided what to measure, what to aggregate and what to leave out. Sometimes the number that is missing is the one that changes the conversation.
Not every page has to produce a decision at every meeting. Some MI earns its place by showing that risk remains stable, that controls remain effective, or that agreed tolerances have not been breached. But if a section repeatedly produces no insight, no challenge, no comfort and no decision, the Board should ask why it is still in the pack.
Good practice and poor practice in Board conversation
Business impact: what the wrong conversation costs
A Board that reviews and notes a comprehensive pack each quarter is doing what it can with the design it has been given. When enforcement follows, however, the minutes are what the supervisor sees. Minutes that record only that the pack was reviewed and noted, in the face of a deteriorating control environment that the pack in fact contained, are the aggravating factor. That is a design cost, not a governance cost. It falls on the firm.
Practical solutions: redesigning the conversation, not the pack alone
Reporting that evolves with the business
Most reporting is designed around the business as it was. New products, new customer types, geographic expansion, new delivery channels or a material change to a control all change what the Board needs to see. The pack often does not follow.
Governance should move with the business. The reporting should too.
An independent review can help because familiarity is part of the problem. A pack that has looked the same for three years can stop being questioned.
The Claritas approach
When a Board asks us to look at conversation quality, we do not begin by redesigning the pack. We attend a meeting in observer capacity, we read the pack in advance in the time the Board actually has, and we read the last four minutes against the last four packs. The gap between what the pack made available and what the discussion made use of is where the finding sits.
We then draft a two-page note: the three questions the pack should answer each quarter, the slides that should be added or removed to make those answers visible in the first ten minutes, and the changes to the Chair's agenda-setting that would give the conversation room to breathe. We do not, as a rule, propose new metrics. The improvement almost always sits in what the Board is asked to look at first, and in what time is left for the answer.
The test I would apply
If I read the pack and the minutes together, could I see what the Board understood, what it challenged and what it decided?
A supervisor may ask the same question later. The Board should be asking it first.
In closing
A good Board pack does not prove good governance. What matters is what happens because of it.
What did the Board understand? What did it challenge? What did it decide? And what changed afterwards?
That is the difference between reporting financial crime and governing it.
- 01The pack makes clear, in its opening pages, what management needs the Board to understand or decide.
- 02The minutes record what was challenged, what was decided and what evidence the Board relied on.
- 03Follow-up items move quarter on quarter; items that persist across several quarters are treated as governance signals.
- 04MI that shows stability says so explicitly, and MI that produces nothing useful is questioned rather than repeated.
- 05The reporting has changed at least once in response to a change in the business or its risk profile.
- Regulation (EU) 2024/1624 (AMLR), requirements on internal policies, controls and procedures and the role of the compliance function. eur-lex.europa.eu/eli/reg/2024/1624/oj
- EBA Guidelines on internal governance (EBA/GL/2021/05), responsibilities of the management body in its management and supervisory functions.
- EBA Guidelines on the role, tasks and responsibilities of AML/CFT compliance officers and the management body (EBA/GL/2024/01).
- EBA Guidelines on ML/TF risk factors (revised), on risk assessment and ongoing monitoring.
- Financial Conduct Authority, Final Notice: Starling Bank Limited, October 2024 (UK comparison). www.fca.org.uk/publication/final-notices/starling-bank-limited-2024.pdf
- Central Bank of Ireland, Enforcement action: Coinbase Europe Limited, 2025.
- SEPBLAC, Annual Report 2025.


