Why these five questions
Perspective 001 examined recent Spanish enforcement and set out the direction European supervision is now taking: from the review of documents to the evidencing of outcomes. That shift changes what a Board actually needs to be able to do. It is no longer sufficient to approve a policy suite once a year and receive a quarterly MLRO report. Supervisors now expect Boards to demonstrate active oversight, informed challenge and documented judgement.
The questions that follow are the ones I have found most useful during Board effectiveness reviews and pre-inspection readiness work. Each one is straightforward. Each one is difficult to answer well. Taken together they will tell a Board, quickly, whether the framework it oversees is holding together.
01. Can we describe our financial crime risk in plain terms?
This is the question I ask first. Not because it tests technical expertise, but because it tests whether the Board has genuinely absorbed the Business-Wide Risk Assessment, or whether the BWRA has become a document maintained by the second line and approved once a year by the first.
My own test is a simple one, and it is mine rather than anything a regulator prescribes. Can each director, without notes, describe the three highest financial crime exposures currently carried by the firm? A Board that has absorbed the BWRA can describe, in its own language, which products carry the most exposure, which customer segments draw the most attention from the MLRO team, which jurisdictions create the greatest exposure and why, and where the residual risk is trending. The Chair should be able to give that answer to a supervisor without opening the pack.
Where that answer is hesitant or generic, the diagnosis is rarely that the Board is uninterested. It is usually that the BWRA has become a technical artefact rather than a governance tool. It contains the right analysis, but it is not written for, or discussed with, the people who need to act on it.
02. How do we know the controls are working, not just running?
Most firms can produce a management information pack showing alerts raised, cases closed, files reviewed and training completed. Very few can produce management information showing whether the controls those numbers describe actually worked.
The distinction matters because substantive testing asks a different question from activity reporting. A pack can tell me how many alerts were raised or files reviewed. It still has not told me whether the decisions underneath those numbers were good ones. SEPBLAC's emphasis on substantive testing rather than procedural review points in the same direction. Useful MI shows whether higher-risk files were reviewed to the standard the policy requires, whether alert closure rationales evidenced genuine analytical judgement, and whether the issues raised last quarter were resolved in substance or only in status.
This is where independent challenge, examined in Perspective 003, becomes practically important. It is difficult for a function to grade its own homework. It is harder still for a Board to receive that grade and know how far to trust it.
03. Where are we weakest, and who is willing to say so?
Every framework has weak points. The question is whether the Board can see them before the supervisor does, and whether anyone in the room feels safe enough to name them.
A firm with a known weakness, a credible assessment of its significance and a governed plan to fix it is in a very different position from a firm that discovers the weakness with the supervisor in the room.
The way to test this at Board level is to watch how the MLRO answers the question in front of the Chair. A direct answer, even an uncomfortable one, is usually a good sign. An answer that sounds polished but does not actually answer the question is not.
04. If a supervisor asked, could we explain why?
The hardest questions in an inspection are not about what the firm did. They are about why.
Why was this customer accepted at onboarding. Why was that relationship kept when the risk rating moved to high. Why was the monitoring scenario adjusted last summer. Why did the Committee accept the remediation plan for the SAR backlog in October, and what evidence did it rely on. Eighteen months later, the only surviving evidence is the paper trail: Board papers, committee minutes, the MI relied upon and the challenge recorded against it.
This is not an exercise in defensive documentation. It is an exercise in the discipline of decision-making. Boards that write clearly about why they decided something also tend to decide it more carefully.
05. Are we ready for what is already coming?
The new EU framework is no longer an abstract future project. AMLA is already operating, the single-rulebook work is under way, and the first entities for direct supervision will be selected in 2027 ahead of supervision beginning in 2028.
For most firms, the point is not whether AMLA will supervise them directly. It is that the supervisory framework around them is becoming more consistent.
Most of the work required has very little to do with the technical standards still to be published. It is the work of tightening legacy files, sharpening risk assessments, rebuilding management information around risk rather than activity, and ensuring the second line has the standing to challenge the first. That work takes time to do well.
How Claritas approaches these questions
When a Board asks us to help, we do not begin by proposing new policies. We begin by testing how well the framework already answers the five questions above.
That work typically has three phases. First, a short evidence review: the BWRA, the last four Board packs, the MLRO reports, the second-line QA output and internal audit findings, read against each other rather than in isolation. Second, a small number of structured conversations with the Chair, the CEO, the MLRO, the Head of Risk and internal audit, focused on the same five questions. Third, a short findings note written for the Board, distinguishing between issues that require a decision and issues that require a change in practice.
The output is intentionally short. Boards rarely need more paper. What they need is a document that is honest about where the framework stands and specific about what to do about it.
- 01Directors can describe, in plain terms, the firm's principal financial crime exposures and how they have changed in the last year.
- 02Management information tells the Board whether the controls worked, not only that the team was busy. Trend and outlier data are more prominent than volumes.
- 03The Board knows where the framework is weakest and can describe what is being done about it, on what timeline, and by whom.
- 04Material financial crime decisions are minuted with sufficient specificity that a supervisor could reconstruct them even eighteen months later without help.
- 05Preparation for AMLR, AMLD6 and AMLA is under way, sequenced by materiality, with clear owners and a realistic timeline.
- Financial Conduct Authority, Final Notice: Starling Bank Limited (October 2024). www.fca.org.uk/publication/final-notices/starling-bank-limited-2024.pdf
- Central Bank of Ireland, Enforcement action against Coinbase Europe Limited, 6 November 2025. www.centralbank.ie/news/article/press-release-central-bank-of-ireland-reprimands-and-fines-coinbase-europe-limited-21-46-million-6-november-2025
- SEPBLAC. Memoria 2025 (Annual Report, May 2026). www.sepblac.es/wp-content/uploads/2026/06/MemoriaSepblac2025_ES.pdf
- European Banking Authority, Guidelines on the role and responsibilities of the AML/CFT compliance officer and the management body (EBA/GL/2022/05).
- Anti-Money Laundering Authority (AMLA), official material on operational status, the 2027 selection of entities for direct supervision and the commencement of direct supervision in 2028.


