Perspectives
Perspective 003Practice

Why independent challenge matters more than another policy review.

Policy reviews have value. But on their own they do not tell you whether controls operate in practice. Good challenge does not have to change the answer. It has to test whether the answer is defensible.

By Everett MorganSummer 20266 min read
European institutional architecture in soft light
Executive brief

Reading time · 9 minutes  ·  Primary audience · Boards, MLROs, Heads of Compliance, Internal Audit, second-line assurance

Why this matters

Policy reviews continue to have value. A document-led review answers a narrow question well: is the documentation adequate. The harder question is whether the framework operates as its documentation implies. Answering that requires evidence, not another reading of the policy. It also requires challenge from someone with enough technical fluency to test what they are being told and enough standing to say when the evidence does not support it.

Key findings
  1. 01Recent European enforcement repeatedly shows firms with documented frameworks but material weaknesses in how controls operated in practice. My conclusion from those cases is not that another policy review would have been useless. It is that documentation alone would not have exposed enough of the problem.
  2. 02Independent challenge and Internal Audit can be complementary, but the distinction is one of mandate and scope, not simply who tests controls and who tests judgement. Internal Audit may test both. A targeted review can add value where the audit plan does not go deeply enough into a particular judgement, population, control or emerging risk.
  3. 03The most useful reviews I have seen or led sample files, sit in operational meetings and read management information from the outside in. Interviews and document review support the work rather than carry it.
  4. 04Challenge without standing produces polite reports. Standing is not the same as seniority. It means enough authority, objectivity appropriate to the role, access, technical credibility and a route to people able to act.
Questions Boards should ask
  1. 01Can we point to a recent material issue where independent challenge changed the evidence requested, sharpened the analysis, altered the action taken or confirmed the original conclusion after proper testing?
  2. 02Do our second-line functions have the standing and authority to challenge the first line, escalate when necessary and exercise any formal decision rights assigned to them, and is that visible in the record?
  3. 03If a supervisor tested the judgement behind our controls rather than only the documentation, who could explain and stand behind those judgements?

The gap that policy review does not close

In this Perspective I use “independent challenge” as an umbrella practitioner term. It is not the same thing as a formal Independent Assurance opinion. The source, mandate and degree of independence matter.

A policy review is a test of what the framework says it does. It checks that documents exist, that they reflect current regulation, that responsibilities are clearly allocated and that procedures cover the material scenarios. It is a necessary exercise and, done well, a useful one.

A document-led policy review can tell a Board a great deal about control design. What it cannot establish on its own is whether those controls are operating as intended. It will not tell the Board whether risk ratings were assigned consistently with the methodology and supported by the evidence on a sample of recently onboarded customers. It will not test whether the alert closure rationales in transaction monitoring reflect genuine analytical judgement or template language, or whether those conclusions are defensible against the methodology and the evidence. It will not answer whether the escalations recorded on paper led to visible consideration, action or a reasoned conclusion.

Perspective 002 set out five questions a Board should be able to answer about its financial crime framework. Policy review can contribute to those answers. It cannot complete them. For that, the Board also needs evidence from files, operations, management information and the decisions the framework has actually produced.

What independent challenge actually means

The term is used loosely, sometimes to describe a peer review, sometimes an audit, sometimes an external consultant reading a policy suite. It is worth being precise about what I mean by it.

Independent challenge is the exercise of professional judgement against evidence. The challenger needs enough separation from the activity being tested to form and report an objective view. The degree of independence will differ depending on whether the challenge comes from second line, Internal Audit, group assurance or an external reviewer. The core of the exercise is not documentary. It is sampling files, sitting in the meetings where decisions are taken, testing the analytical reasoning that produced them, and forming a view of the framework from the outside in. That requires access to the evidence, authority to report what it shows, and technical credibility.

Independent does not automatically mean external. The challenge may come from Internal Audit, second-line assurance, a group function or an external reviewer. Their mandates differ, and so does the weight a Board can place on their conclusions. What matters is whether the challenger is sufficiently separated from the activity being tested, has access to the evidence and can report what they find without it being softened on the way.

It is also worth separating two things that often get merged. Independent Assurance sits outside the accountability chain by design, with its own mandate and reporting route. A fresh external perspective is simply someone outside the normal process looking at the same evidence without the assumptions that come with running it. Both are useful. They are related, but they are not the same thing, and a Board should know which one it has commissioned.

Three characteristics matter more than the label:

Where Internal Audit has the mandate, depth, capacity and independence needed for the question, there may be no case for another review. Audit has a formal mandate, independence by design and, in many firms, real technical depth. The practical question is often scope and capacity rather than capability. An annual plan can only go so deep in so many places. Where a particular judgement, population, control or emerging risk sits outside that plan, or where the depth required is specialist, a targeted review adds something. It does not replace audit and should not be sold as though it does.

Good challenge does not have to change the answer. It has to test whether the answer is defensible.

Why firms resist genuine challenge

In the abstract, no Board resists challenge. When challenge loses force, I usually see one of three things happen.

The first is scope compression. An initial engagement to test file quality becomes, by degrees, a policy readback with a file-sampling appendix. Not every change of scope is improper. Scope moves for sensible reasons. The problem is when scope is reduced in a way that prevents the original question from being answered.

The second is finding softening. Draft findings are shared for factual accuracy and returned with adjustments that dull the language, split composite findings into smaller items and re-classify significance. Management should be able to correct factual errors and challenge conclusions. The problem starts when substantive disagreement is edited out rather than governed.

The third is action-plan absorption. Findings are accepted and translated into a remediation plan of such breadth that control ownership becomes unclear and traceability is lost. Progress is reported in status colours while the evidence of correction is never produced.

How Boards should use independent challenge

Independent challenge is most useful when it is deployed deliberately, on a defined question, with a clear route into governance. These are the disciplines I find most useful.

How Claritas approaches independent challenge

The value of a challenge engagement is measured by whether it produces a reliable answer to the question it was asked and gives governance enough evidence to act, or to decide that no change is required. That has three practical consequences for how we work.

First, we scope tightly. A tightly defined question or small number of linked questions answered against real evidence is usually more useful than a broad framework review that closes with a list of themes. Second, we test against evidence. Interviews and document review inform the work, but conclusions should rest on operating evidence appropriate to the question being tested, whether that is files, system output, data, governance records or management information. Third, we report to the Board in the language the Board uses. Where a finding requires a decision, we say so. Where it requires challenge, follow-up or operational remediation rather than a formal decision, we say that clearly too.

We are useful in a narrower set of situations than the market usually admits. Where Internal Audit or second-line assurance has the objectivity, depth and capacity to do the work, a firm should use them. We add value where the existing challenge lacks sufficient objectivity for the question, capacity is constrained, specialist depth is needed, the issue sits outside the audit plan, or a fresh external perspective would be useful.

Short, focused engagements can be easier for Boards to use because they map cleanly onto specific governance questions. Whether they should be repeated depends on risk and need.

What success looks like
  • 01The firm has a clear route for targeted challenge when the risk, assurance plan or governance need justifies it.
  • 02The second line has the standing and authority to challenge the first line, exercise its formal decision rights where those exist, and escalate material concerns through a route that is visible in the record.
  • 03Challenge engagements are scoped against specific hypotheses linked to the firm's risk assessment, known weaknesses or material control questions rather than generic themes.
  • 04Material findings translate into clear owned actions or reasoned closure, with progress visible through the relevant governance route.
  • 05The firm can demonstrate that challenge has influenced the quality of evidence, analysis, action or governance understanding where the facts required it.
References
About the author
Everett Morgan
Founder & Principal Adviser, Claritas Risk Advisory

Everett has more than twenty years' experience in financial crime, AML governance, regulatory compliance and operational risk gained within Deutsche Bank, Morgan Stanley and BNP Paribas. He established Claritas Risk Advisory to provide smaller regulated financial institutions with experienced independent judgement, practical insight and proportionate recommendations.

Need an independent perspective?

Preparing for regulatory change starts with understanding where your organisation stands today.

If you would like to discuss your financial crime framework or explore how Claritas Risk Advisory can help, I would be pleased to arrange a confidential conversation.

Let's start with a conversation