What a policy can and cannot do
Firms spend considerable time writing, reviewing and approving AML policies and procedures through their governance arrangements. A policy can set the standard, fix the methodology, allocate responsibility and record what the firm has decided to do. What it cannot do is guarantee that those standards are applied consistently across the business. That depends on people, data, systems, supervision and judgement.
A policy can be perfectly adequate on paper and still sit above a control that performs poorly in practice. A firm can have a well-drafted business-wide risk assessment, a coherent customer risk methodology, EDD and monitoring procedures aligned to applicable EU requirements and EBA guidance, a clear reporting playbook and a training curriculum approved through the right forum. It can still, at the same time, be onboarding customers whose risk profile has not been genuinely assessed, closing monitoring alerts on rationales that would not survive re-review, and reporting to the Board in a way that describes activity rather than effectiveness.
That gap is where governance becomes visible. It is also where supervisory testing of operating effectiveness can expose a framework that looks stronger on paper than it behaves in practice. Two firms can have almost identical policies and very different control outcomes because one has embedded the standards into everyday decision-making and the other has not.
The EU framework already makes this distinction. Regulation (EU) 2024/1624 requires obliged entities to establish internal policies, procedures and controls, keep them up to date, enhance them where weaknesses are identified, and subject them to internal control and, where applicable, independent audit testing. The obligation is not satisfied by writing the framework. Firms also need to know whether the controls built around it are operating effectively.
Where the framework is actually decided
AML frameworks are shaped by the small decisions made every day, not only by the documents that describe them. A customer is assigned a risk rating. A transaction alert is closed. A source of wealth explanation is accepted. An exception is approved. None of those moments feels like governance at the time. Together they are the framework.
This can be particularly visible in smaller firms, where experienced people often carry a great deal of operational knowledge in their heads. That is not automatically a defect. Good judgement is often held informally and works perfectly well day to day. The difficulty comes later. Where judgement is exercised without enough evidence or record, the firm may struggle to show what it decided and why.
Why substantive testing matters
Policy review remains part of supervision. But substantive testing matters because it shows whether the framework operates as the policy describes. That can mean testing how customer risk ratings were reached, why EDD was applied in one case and not another, or how an unusual transaction was analysed before the reporting decision.
Those conversations are not only about documentation. They are about judgement, evidence and whether the control produced a defensible outcome. The two examples below come from published enforcement decisions. They are not a universal inspection script. They are useful because in each case the framework existed and the evidence of how it operated told a different story.
Different cases, different failures, but the same broader lesson: the existence of a framework tells you much less than the evidence of how the controls actually operated.
Root causes: why the gap persists
When I see a persistent gap between policy and practice, four causes come up repeatedly, and they compound. Understanding which of them a firm is carrying is the first step in closing it.
Good practice and poor practice, side by side
The clearest way to test a firm's exposure is to compare, on a specific control, what good practice looks like and what poor practice looks like. The examples below are drawn from recent readiness reviews. They are ordinary. That is the point. A risk-based framework should not be expected to produce identical outcomes for superficially similar customers. It should produce a consistently applied methodology, appropriate judgement, differences grounded in evidence and outcomes the firm can explain.
The question a Board should be asking
If I could ask the Board one question, it would be this. Are our controls producing the outcomes we expect?
Underneath it sit four more. Are similar customers being assessed using the same methodology, and can we explain material differences in outcome? Are high-risk relationships subject to the required level of scrutiny across teams, and are differences supported by risk and evidence? Do our management reports show meaningful trends rather than volumes of activity? Can we explain how judgement-based decisions were reached, months later, to someone who was not in the room?
Those questions tell a Board something an annual policy review cannot tell it on its own: whether the framework is behaving as intended in practice. That is one of the things substantive supervisory testing can expose: whether the methodology is being applied consistently in comparable circumstances and whether material differences can be explained.
Business impact: what the gap actually costs
Where the gap becomes an enforcement matter, the fine may be the most visible cost. It is rarely the only one. In remediation work, the fine is often only part of the cost. Remediation itself, assurance work, first-line and second-line capacity, management attention, customer disruption, business restrictions where they apply and the reputational effect on institutional counterparties all sit alongside it. Closing the gap under enforcement pressure can be materially more disruptive than addressing the weakness before it becomes a formal finding.
Where to start
Good policies remain essential. They are the foundation, not the finished control. Closing the gap between the two is not another policy exercise. The following steps, done in order, tend to produce the largest shift for the least disruption.
The Claritas approach
We do not begin an engagement by proposing a new policy. We start with a small, deliberate sample of real control outcomes chosen to expose the areas where inconsistency is most likely to matter. The size and composition depend on the population, risk, complexity and the question we are trying to answer. In practice that can mean customer files across the relevant teams, closed alerts across the relevant typologies, recent Board and committee packs, governance minutes and other control outcomes relevant to the diagnostic. The exercise is short. It is diagnostic work, not an Independent Assurance opinion.
The output is a note that names the specific gaps we saw, the pattern behind them, the fixes we would sequence first, and the indicators by which the Board could measure whether the gap is closing. The note should be concise enough for a non-executive audience and evidenced well enough that the firm can stand behind it if challenged.
The quality of an AML framework becomes visible in the decisions people make, the oversight management provides and the evidence that controls operate as intended. Paper tells you what should happen. The operating evidence tells you whether it did.
- 01Similar customers are assessed using the same methodology, and where outcomes differ, the file explains why.
- 02Closed alerts are subject to risk-informed QA, and the review tests whether the original decision remains defensible against the methodology and evidence.
- 03Governance MI shows activity, quality and residual risk together rather than reporting activity volumes alone.
- 04QA and second-line challenge make recurring control weaknesses and material differences in assessment visible, with clear ownership of the response.
- 05Material financial-crime decisions are traceable to the evidence, challenge and governance record that supported them.
- Regulation (EU) 2024/1624 on the prevention of the use of the financial system for money laundering or terrorist financing: internal policies, procedures and controls, and internal audit. eur-lex.europa.eu/eli/reg/2024/1624/oj
- Regulation (EU) 2024/1620 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA). eur-lex.europa.eu/eli/reg/2024/1620/oj
- European Banking Authority, Guidelines on policies and controls for the effective management of ML/TF risks (EBA/GL/2022/05). www.eba.europa.eu/regulation-and-policy/anti-money-laundering-and-countering-financing-terrorism
- European Banking Authority, Guidelines on customer due diligence and ML/TF risk factors (revised, 2023).
- Central Bank of Ireland, Enforcement action: Coinbase Europe Limited, 2025. www.centralbank.ie/news/article/press-release-central-bank-of-ireland-reprimands-and-fines-coinbase-europe-limited
- UK comparison: Financial Conduct Authority, Final Notice: Starling Bank Limited, October 2024. www.fca.org.uk/publication/final-notices/starling-bank-limited-2024.pdf



