Perspectives
Perspective 002Governance

Five questions every Board should ask about its financial crime controls.

Simple questions that move a board conversation from policy compliance to genuine oversight, and reveal whether the framework holds together under scrutiny.

By Everett MorganSummer 20268 min read
A modern European executive boardroom at dusk
Executive brief

Reading time · 8 minutes  ·  Primary audience · Non-Executive Directors, Chairs, Audit and Risk Committees, MLROs

Why this matters

Recent European enforcement actions point to the same practical problem from different directions: having a framework is not enough if the controls do not keep pace with the business or produce the outcome expected of them. For a Board, that changes the question. Approval tells me the framework reached the Board. It does not tell me whether the Board understood what was changing, challenged it or acted when the control environment stopped keeping pace.

Key findings
  1. 01European supervisors are moving from documentary review to evidence-based testing. The existence of an approval trail is no longer sufficient.
  2. 02In Board reviews, the warning signs I look for are remarkably consistent: directors struggling to describe the principal risks in plain language, minutes that record acknowledgement rather than challenge, and MI that tells the Board how busy the function was rather than what happened to the risk.
  3. 03One of the questions I find most revealing is whether a financial crime discussion has changed a decision. Not because the Board needs to overturn management regularly, but because challenge that can never change an outcome is worth examining.
  4. 04In my experience, the firms that answer these questions well are usually the ones that have been doing the work before an inspection letter arrives. The firms that struggle are often trying to build the evidence after the clock has already started.
Questions Boards should ask
  1. 01Can we describe our financial crime risk in plain terms?
  2. 02How do we know the controls are working, not just running?
  3. 03Where are we weakest, and who is willing to say so?
  4. 04If a supervisor asked, could we explain why?
  5. 05Are we ready for what is already coming?

Why these five questions

Perspective 001 examined recent Spanish enforcement and set out the direction European supervision is now taking: from the review of documents to the evidencing of outcomes. That shift changes what a Board actually needs to be able to do. It is no longer sufficient to approve a policy suite once a year and receive a quarterly MLRO report. Supervisors now expect Boards to demonstrate active oversight, informed challenge and documented judgement.

The questions that follow are the ones I have found most useful during Board effectiveness reviews and pre-inspection readiness work. Each one is straightforward. Each one is difficult to answer well. Taken together they will tell a Board, quickly, whether the framework it oversees is holding together.

01. Can we describe our financial crime risk in plain terms?

This is the question I ask first. Not because it tests technical expertise, but because it tests whether the Board has genuinely absorbed the Business-Wide Risk Assessment, or whether the BWRA has become a document maintained by the second line and approved once a year by the first.

My own test is a simple one, and it is mine rather than anything a regulator prescribes. Can each director, without notes, describe the three highest financial crime exposures currently carried by the firm? A Board that has absorbed the BWRA can describe, in its own language, which products carry the most exposure, which customer segments draw the most attention from the MLRO team, which jurisdictions create the greatest exposure and why, and where the residual risk is trending. The Chair should be able to give that answer to a supervisor without opening the pack.

Where that answer is hesitant or generic, the diagnosis is rarely that the Board is uninterested. It is usually that the BWRA has become a technical artefact rather than a governance tool. It contains the right analysis, but it is not written for, or discussed with, the people who need to act on it.

02. How do we know the controls are working, not just running?

Most firms can produce a management information pack showing alerts raised, cases closed, files reviewed and training completed. Very few can produce management information showing whether the controls those numbers describe actually worked.

The distinction matters because substantive testing asks a different question from activity reporting. A pack can tell me how many alerts were raised or files reviewed. It still has not told me whether the decisions underneath those numbers were good ones. SEPBLAC's emphasis on substantive testing rather than procedural review points in the same direction. Useful MI shows whether higher-risk files were reviewed to the standard the policy requires, whether alert closure rationales evidenced genuine analytical judgement, and whether the issues raised last quarter were resolved in substance or only in status.

This is where independent challenge, examined in Perspective 003, becomes practically important. It is difficult for a function to grade its own homework. It is harder still for a Board to receive that grade and know how far to trust it.

03. Where are we weakest, and who is willing to say so?

Every framework has weak points. The question is whether the Board can see them before the supervisor does, and whether anyone in the room feels safe enough to name them.

A firm with a known weakness, a credible assessment of its significance and a governed plan to fix it is in a very different position from a firm that discovers the weakness with the supervisor in the room.

The way to test this at Board level is to watch how the MLRO answers the question in front of the Chair. A direct answer, even an uncomfortable one, is usually a good sign. An answer that sounds polished but does not actually answer the question is not.

04. If a supervisor asked, could we explain why?

The hardest questions in an inspection are not about what the firm did. They are about why.

Why was this customer accepted at onboarding. Why was that relationship kept when the risk rating moved to high. Why was the monitoring scenario adjusted last summer. Why did the Committee accept the remediation plan for the SAR backlog in October, and what evidence did it rely on. Eighteen months later, the only surviving evidence is the paper trail: Board papers, committee minutes, the MI relied upon and the challenge recorded against it.

This is not an exercise in defensive documentation. It is an exercise in the discipline of decision-making. Boards that write clearly about why they decided something also tend to decide it more carefully.

05. Are we ready for what is already coming?

The new EU framework is no longer an abstract future project. AMLA is already operating, the single-rulebook work is under way, and the first entities for direct supervision will be selected in 2027 ahead of supervision beginning in 2028.

For most firms, the point is not whether AMLA will supervise them directly. It is that the supervisory framework around them is becoming more consistent.

Most of the work required has very little to do with the technical standards still to be published. It is the work of tightening legacy files, sharpening risk assessments, rebuilding management information around risk rather than activity, and ensuring the second line has the standing to challenge the first. That work takes time to do well.

How Claritas approaches these questions

When a Board asks us to help, we do not begin by proposing new policies. We begin by testing how well the framework already answers the five questions above.

That work typically has three phases. First, a short evidence review: the BWRA, the last four Board packs, the MLRO reports, the second-line QA output and internal audit findings, read against each other rather than in isolation. Second, a small number of structured conversations with the Chair, the CEO, the MLRO, the Head of Risk and internal audit, focused on the same five questions. Third, a short findings note written for the Board, distinguishing between issues that require a decision and issues that require a change in practice.

The output is intentionally short. Boards rarely need more paper. What they need is a document that is honest about where the framework stands and specific about what to do about it.

What success looks like
  • 01Directors can describe, in plain terms, the firm's principal financial crime exposures and how they have changed in the last year.
  • 02Management information tells the Board whether the controls worked, not only that the team was busy. Trend and outlier data are more prominent than volumes.
  • 03The Board knows where the framework is weakest and can describe what is being done about it, on what timeline, and by whom.
  • 04Material financial crime decisions are minuted with sufficient specificity that a supervisor could reconstruct them even eighteen months later without help.
  • 05Preparation for AMLR, AMLD6 and AMLA is under way, sequenced by materiality, with clear owners and a realistic timeline.
References
About the author
Everett Morgan
Founder & Principal Adviser, Claritas Risk Advisory

Everett has more than twenty years' experience in financial crime, AML governance, regulatory compliance and operational risk gained within Deutsche Bank, Morgan Stanley and BNP Paribas. He established Claritas Risk Advisory to provide smaller regulated financial institutions with experienced independent judgement, practical insight and proportionate recommendations.

Need an independent perspective?

Preparing for regulatory change starts with understanding where your organisation stands today.

If you would like to discuss your financial crime framework or explore how Claritas Risk Advisory can help, I would be pleased to arrange a confidential conversation.

Let's start with a conversation