From governance architecture to governance evidence
The architecture still matters. A firm without clear governance, defined AML/CFT roles and appropriate oversight has a basic problem. But the existence of the architecture does not prove that it is working. The harder test is whether the information, the challenge and the accountability show that the structure is being used.
Recent enforcement repeatedly shows that the existence of governance architecture does not, by itself, establish control effectiveness. Firms have had the forums, the charters and, in some cases, reasonable policy on paper. What was in question was whether the framework operated.
Very few firms describe their own governance as weak. The statement is easy to make. Proving it is harder. In practice, a firm should be able to show how material issues were considered, what information reached governance, what challenge occurred, what outcome followed and who was accountable for it.
This is the context in which the term "effective governance" is now used. Perspective 002 set out the questions a Board should be able to answer. Perspective 003 examined the role of independent challenge in testing those answers. This Perspective describes what I look for when governance is tested directly.
Three tests I use when reading governance in practice
Recent supervisory and enforcement material reinforces these themes, but they are practitioner lenses rather than a prescribed EU test.
Information quality
The first test is whether the information reaching governance supports understanding, challenge, decisions and follow-up. Board MI needs to explain risk and what is changing, not simply count activity. A report that counts alerts, completed reviews or training hours tells the Board that work has been done. It does not necessarily explain whether risk is being managed.
The MI I find useful is risk-oriented. It says where residual exposure sits and how the firm believes it is moving, using qualitative and quantitative measures as appropriate. It interprets rather than recites. And it gives enough trend context for the direction of travel to be visible instead of inferred.
Challenge quality
The second test is whether material issues are genuinely understood and tested rather than simply passed through governance. I do not need challenge for the sake of proving the Board is active. I do need evidence that material issues were considered properly.
Agreement after proper challenge is perfectly legitimate. The issue is not whether people disagreed. It is whether the conclusion was tested.
Minutes are where this shows. A minute that only says "discussed" or "noted" may be perfectly adequate for a routine item. For a material issue, I would expect the record to show more of the substance. For material items, the record should be sufficient for someone who was not in the room to understand the substance of the challenge, the conclusion and the follow-up. If nothing much happened, the honest minute is short.
Accountability traceability
The third test is whether accountability is clear through the applicable management-body and control structure, with named role-holders where the framework assigns individual responsibility. The point is not to allocate blame after the fact. It is to know who owned the issue, who had authority to act and how escalation worked. A committee that meets regularly but does not influence real governance outcomes is a structure, not an accountability mechanism.
Where accountability is diffuse, either between the first and second line or between the executive and the management body, the framework is weaker than the sum of its parts. Clear accountability supports better governance and makes the firm's decisions easier to explain under scrutiny.
The habits that produce effective governance
Effective governance is not installed. It is practised. The habits below are the ones I find most useful when testing whether governance is alive rather than simply documented.
Governance has to stay fit for the business
A governance framework does not need to change simply because time has passed. But it does need to be reviewed against the business and risks it now supports. What was proportionate when the firm was smaller or differently structured may no longer be enough.
Regular review gives the firm a chance to adjust before weaknesses become embedded, and leaves a clear record that governance has been tested against the current risk profile. The prompts are often visible once someone looks: a new product, a new distribution channel, a jurisdiction added quietly, growth in a customer segment the framework was never designed around.
What AMLA will inherit
AMLA is already operating. Direct supervision of selected cross-border financial institutions begins in 2028. AMLA's first selection process will identify eligible cross-border financial institutions for direct supervision based on the legal criteria and a harmonised risk assessment, so this is not a question of size alone.
For most smaller firms, the more immediate effect will come through the Single Rulebook and increasing supervisory convergence at national level rather than direct AMLA supervision. The governance expectations described in this Perspective are, in substance, the expectations AMLR sets out. Firms that already have these habits will be in a stronger position as the new framework beds in. Firms that postpone known governance work will have less room to absorb it later.
How Claritas approaches governance work
Governance reviews in the Claritas model are diagnostic rather than architectural. We do not start by redesigning the architecture. We first test whether the existing structure is clear, proportionate and actually being used.
The work usually involves a cold read of a recent run of Board and committee papers, the associated MI and minutes, looking at the material financial-crime issues considered and the trail behind them. Then structured conversations with the role-holders relevant to the firm's governance model, focused on the three lenses described above. Where necessary, a proportionate, deliberate sample of operating evidence to test whether the governance narrative survives contact with the underlying control. The findings note, written for the Board, distinguishes what requires management-body understanding or challenge, what needs a governance decision and what belongs in operational remediation.
The intended output is not a redesign. It is specific, named-owner improvements that move the framework from documented to demonstrable.
Paperwork matters. But it only tells me how governance is supposed to work. The evidence is in the governance outcomes, the challenge, the information people acted on and whether the people responsible for the risk can explain it without reaching for the policy.
That is the difference between having a governance structure and having governance.
- 01Board packs make the material financial-crime risk position and significant changes visible before activity volumes obscure them.
- 02The governance record is sufficient to trace material challenge, evidence and outcomes where they mattered.
- 03Material escalations remain traceable to owners, status and evidence of resolution.
- 04The Board can point to material issues where challenge changed the evidence requested, the action taken, the conditions applied or the understanding of the risk, where the facts required it. Challenge can be effective even where the final conclusion remains unchanged.
- 05Governance improvements progress as part of normal business and are not driven principally by supervisory events.
- Regulation (EU) 2024/1624 of the European Parliament and of the Council on the prevention of the use of the financial system for money laundering or terrorist financing (AMLR). eur-lex.europa.eu/eli/reg/2024/1624/oj
- Regulation (EU) 2024/1620 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA). eur-lex.europa.eu/eli/reg/2024/1620/oj
- European Banking Authority, Guidelines on Internal Governance (EBA/GL/2021/05).
- European Banking Authority, Guidelines on Policies and Controls for the Effective Management of ML/TF Risks (EBA/GL/2022/05).
- SEPBLAC. Memoria 2025 (Annual Report, June 2026). www.sepblac.es/wp-content/uploads/2026/06/MemoriaSepblac2025_ES.pdf
- Financial Conduct Authority, Final Notice: Starling Bank Limited (October 2024), cited as a UK comparison. www.fca.org.uk/publication/final-notices/starling-bank-limited-2024.pdf
- Perspective 002, Five questions every Board should ask about its financial crime controls
- Perspective 003, Why independent challenge matters more than another policy review
- Perspective 005, Preparing for an AML inspection before you receive the letter
- Perspective 008, Waiting for AMLA won't make preparation any easier


