Where inspection testing goes beyond documents
Document readiness has always mattered. Inspection testing can go beyond documentary readiness and examine whether the files, processes and decisions support the framework the firm says it operates.
Depending on scope and risk, supervisory testing may include file sampling, process walkthroughs, interviews and detailed review of governance information. The purpose of each is to test whether the framework operates as its documentation implies. Preparation that treats inspection as a presentation exercise misses the point.
Perspective 004 set out three governance tests I use when thinking about whether oversight is working in practice. Inspection is where questions of that kind get asked at the file, meeting and MI level. This Perspective is about the period before an inspection, and how to use it.
Three issues that recur
Across the inspections I have observed or supported, three issues come up often enough that I look at them first.
Legacy customer due diligence
Legacy CDD is one of the issues I see recur most often in readiness and remediation work, particularly on higher-risk customers onboarded before current standards. The issue is not usually a lack of documentation. It is that the documentation on file no longer reflects the customer's current activity, ownership, geography or risk profile. Ongoing review has fallen behind, or has become a calendar exercise that confirms data without genuinely reconsidering the relationship.
Monitoring configuration
Transaction monitoring is the second recurring theme. Among the things that may be tested are whether monitoring coverage reflects the firm's actual products, customers, channels and risks, whether material thresholds or parameters are governed appropriately, and whether closure decisions are defensible against the methodology and evidence.
A common failure mode is a configuration left at vendor defaults and never properly reviewed against the firm's own population. That is a difficult control position to defend. The firm should be able to explain the basis for the current monitoring configuration, who owns material changes, what evidence supports it and how it is reviewed.
Management information
The third area is the MI reaching governance. Perspective 004 set out the properties of effective MI. A useful readiness test is whether accountable senior leaders can explain the firm's principal financial-crime risks and material weaknesses using the same MI they actually receive. If they cannot, the issue is not simply a reporting problem. It is a governance problem.
An illustrative preparation runway
Where a firm has meaningful advance notice, this is broadly how I sequence the work. The phases below are illustrative. The order and duration should follow the risk, materiality and time actually available.
Conduct during the inspection
Preparation is not only about the state of the framework. It is also about the practised discipline of engagement. An inspection may concentrate a lot of judgement into a relatively small number of interviews, file discussions and observed processes. The discipline of how people answer, evidence and escalate therefore matters.
How Claritas approaches inspection readiness
Claritas readiness work is designed around the time actually available and the weaknesses the firm needs to address. I normally think about it in three broad parts.
First, a readiness diagnostic. A focused readiness assessment tests the framework against the firm's material risk areas and known weaknesses. Legacy CDD, monitoring configuration and MI recur often in my work, but the assessment should follow the firm's own risk profile rather than a fixed Claritas template. This is diagnostic work. It is not Independent Assurance.
Second, a remediation runway. A prioritised remediation runway sequences corrective work by materiality, dependency and available capacity. Third, a readiness test. A simulation may be useful once the underlying control work is mature enough to make the exercise meaningful, focusing on live explanation, evidence retrieval and the handling of difficult issues rather than rehearsing a polished presentation.
For many smaller institutions, the direct assessment effort may be measured in weeks rather than months, spread across the wider preparation period. The exact effort should follow the scope and evidence needed.
- 01The firm has an honest, current baseline of where the framework is weakest and where progress is being made.
- 02Material known weaknesses are either resolved or on a credible, risk-based remediation trajectory with progress visible in governance MI.
- 03Material monitoring configuration and control logic are documented, governed and can be explained against the firm's risk profile and operating evidence.
- 04The governance MI pack gives accountable senior leaders enough information to explain the firm's principal financial-crime risks, material control weaknesses and the actions being taken.
- 05Where proportionate, the firm has tested its readiness through an internal or externally facilitated simulation and acted on what the exercise exposed.
- Regulation (EU) 2024/1624 (AMLR), on the prevention of the use of the financial system for money laundering or terrorist financing. eur-lex.europa.eu/eli/reg/2024/1624/oj
- Regulation (EU) 2024/1620 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA). eur-lex.europa.eu/eli/reg/2024/1620/oj
- European Banking Authority, Guidelines on risk-based supervision (EBA/GL/2021/16), applicable until replaced or superseded under the AMLA framework. www.eba.europa.eu/
- SEPBLAC, Memoria 2025 (Annual Report, published June 2026). www.sepblac.es/wp-content/uploads/2026/06/MemoriaSepblac2025_ES.pdf
- Central Bank of Ireland, Anti-Money Laundering and Countering the Financing of Terrorism supervisory material. www.centralbank.ie/regulation/anti-money-laundering-and-countering-the-financing-of-terrorism
- Financial Conduct Authority, Final Notice: Starling Bank Limited (October 2024). UK comparison. www.fca.org.uk/publication/final-notices/starling-bank-limited-2024.pdf


