The gap that policy review does not close
In this Perspective I use “independent challenge” as an umbrella practitioner term. It is not the same thing as a formal Independent Assurance opinion. The source, mandate and degree of independence matter.
A policy review is a test of what the framework says it does. It checks that documents exist, that they reflect current regulation, that responsibilities are clearly allocated and that procedures cover the material scenarios. It is a necessary exercise and, done well, a useful one.
A document-led policy review can tell a Board a great deal about control design. What it cannot establish on its own is whether those controls are operating as intended. It will not tell the Board whether risk ratings were assigned consistently with the methodology and supported by the evidence on a sample of recently onboarded customers. It will not test whether the alert closure rationales in transaction monitoring reflect genuine analytical judgement or template language, or whether those conclusions are defensible against the methodology and the evidence. It will not answer whether the escalations recorded on paper led to visible consideration, action or a reasoned conclusion.
Perspective 002 set out five questions a Board should be able to answer about its financial crime framework. Policy review can contribute to those answers. It cannot complete them. For that, the Board also needs evidence from files, operations, management information and the decisions the framework has actually produced.
What independent challenge actually means
The term is used loosely, sometimes to describe a peer review, sometimes an audit, sometimes an external consultant reading a policy suite. It is worth being precise about what I mean by it.
Independent challenge is the exercise of professional judgement against evidence. The challenger needs enough separation from the activity being tested to form and report an objective view. The degree of independence will differ depending on whether the challenge comes from second line, Internal Audit, group assurance or an external reviewer. The core of the exercise is not documentary. It is sampling files, sitting in the meetings where decisions are taken, testing the analytical reasoning that produced them, and forming a view of the framework from the outside in. That requires access to the evidence, authority to report what it shows, and technical credibility.
Independent does not automatically mean external. The challenge may come from Internal Audit, second-line assurance, a group function or an external reviewer. Their mandates differ, and so does the weight a Board can place on their conclusions. What matters is whether the challenger is sufficiently separated from the activity being tested, has access to the evidence and can report what they find without it being softened on the way.
It is also worth separating two things that often get merged. Independent Assurance sits outside the accountability chain by design, with its own mandate and reporting route. A fresh external perspective is simply someone outside the normal process looking at the same evidence without the assumptions that come with running it. Both are useful. They are related, but they are not the same thing, and a Board should know which one it has commissioned.
Three characteristics matter more than the label:
Where Internal Audit has the mandate, depth, capacity and independence needed for the question, there may be no case for another review. Audit has a formal mandate, independence by design and, in many firms, real technical depth. The practical question is often scope and capacity rather than capability. An annual plan can only go so deep in so many places. Where a particular judgement, population, control or emerging risk sits outside that plan, or where the depth required is specialist, a targeted review adds something. It does not replace audit and should not be sold as though it does.
Good challenge does not have to change the answer. It has to test whether the answer is defensible.
Why firms resist genuine challenge
In the abstract, no Board resists challenge. When challenge loses force, I usually see one of three things happen.
The first is scope compression. An initial engagement to test file quality becomes, by degrees, a policy readback with a file-sampling appendix. Not every change of scope is improper. Scope moves for sensible reasons. The problem is when scope is reduced in a way that prevents the original question from being answered.
The second is finding softening. Draft findings are shared for factual accuracy and returned with adjustments that dull the language, split composite findings into smaller items and re-classify significance. Management should be able to correct factual errors and challenge conclusions. The problem starts when substantive disagreement is edited out rather than governed.
The third is action-plan absorption. Findings are accepted and translated into a remediation plan of such breadth that control ownership becomes unclear and traceability is lost. Progress is reported in status colours while the evidence of correction is never produced.
How Boards should use independent challenge
Independent challenge is most useful when it is deployed deliberately, on a defined question, with a clear route into governance. These are the disciplines I find most useful.
How Claritas approaches independent challenge
The value of a challenge engagement is measured by whether it produces a reliable answer to the question it was asked and gives governance enough evidence to act, or to decide that no change is required. That has three practical consequences for how we work.
First, we scope tightly. A tightly defined question or small number of linked questions answered against real evidence is usually more useful than a broad framework review that closes with a list of themes. Second, we test against evidence. Interviews and document review inform the work, but conclusions should rest on operating evidence appropriate to the question being tested, whether that is files, system output, data, governance records or management information. Third, we report to the Board in the language the Board uses. Where a finding requires a decision, we say so. Where it requires challenge, follow-up or operational remediation rather than a formal decision, we say that clearly too.
We are useful in a narrower set of situations than the market usually admits. Where Internal Audit or second-line assurance has the objectivity, depth and capacity to do the work, a firm should use them. We add value where the existing challenge lacks sufficient objectivity for the question, capacity is constrained, specialist depth is needed, the issue sits outside the audit plan, or a fresh external perspective would be useful.
Short, focused engagements can be easier for Boards to use because they map cleanly onto specific governance questions. Whether they should be repeated depends on risk and need.
- 01The firm has a clear route for targeted challenge when the risk, assurance plan or governance need justifies it.
- 02The second line has the standing and authority to challenge the first line, exercise its formal decision rights where those exist, and escalate material concerns through a route that is visible in the record.
- 03Challenge engagements are scoped against specific hypotheses linked to the firm's risk assessment, known weaknesses or material control questions rather than generic themes.
- 04Material findings translate into clear owned actions or reasoned closure, with progress visible through the relevant governance route.
- 05The firm can demonstrate that challenge has influenced the quality of evidence, analysis, action or governance understanding where the facts required it.
- Regulation (EU) 2024/1624 (AMLR), internal policies, controls and procedures, compliance function and independent audit arrangements. eur-lex.europa.eu/eli/reg/2024/1624/oj
- Regulation (EU) 2024/1620 establishing the Anti-Money Laundering Authority (AMLA). eur-lex.europa.eu/eli/reg/2024/1620/oj
- European Banking Authority, Guidelines on Internal Governance (EBA/GL/2021/05), where still applicable.
- Financial Conduct Authority, Final Notice: Starling Bank Limited (October 2024). UK comparison. www.fca.org.uk/publication/final-notices/starling-bank-limited-2024.pdf
- Basel Committee on Banking Supervision, Sound Management of Risks related to Money Laundering and Financing of Terrorism. www.bis.org/bcbs/publ/d505.pdf


