Perspectives
Perspective 006Practice

How to conduct an effective financial crime readiness assessment.

A readiness assessment is not another report. It starts with a clear question: where would the framework hold up under scrutiny, where would it come under pressure and what do we need to understand now?

By Everett MorganAutumn 20267 min read
Elegant European operational dashboard environment
Executive brief

Reading time · 7 minutes  ·  Primary audience · MLROs, Heads of Compliance, Chief Risk Officers, Audit and Risk Committees

Why this matters

I see more firms using readiness assessments before supervisory engagement. The problem is that too many become another report. A readiness assessment is only useful when it is built around a clear diagnostic objective, tested against real evidence rather than documentation alone, and reported into governance in a form that makes clear what needs to be understood, challenged, decided or followed up. This Perspective sets out how to do that.

Key findings
  1. 01A readiness assessment is a diagnostic instrument, not an assurance opinion. It identifies where the framework is likely to come under pressure and where the evidence needs to be understood more deeply. It does not provide an assurance conclusion.
  2. 02One of the fastest ways to weaken a readiness assessment is scope inflation. A useful readiness assessment concentrates on the areas that matter most for that firm, based on its risk profile, known weaknesses, regulatory commitments and any relevant supervisory themes.
  3. 03The evidence base has to go beyond documents and interviews. For customer and case-based controls that usually means file sampling; for other areas it may mean data, system evidence, governance records, walkthroughs or control testing. A readiness assessment that never gets beyond what people say and what the policies describe has not tested enough.
  4. 04The output should be short, honest and structured around the material governance response. I would rather give a Committee a short report it can understand, challenge and act on than a hundred pages that bury the point.
Questions Boards should ask
  1. 01If we commissioned a readiness assessment tomorrow, do we know precisely what we need it to tell us?
  2. 02If the last readiness assessment had gone missing, what would governance have understood, challenged or done differently, or was it treated mainly as an assurance artefact?
  3. 03Are we willing to let the assessment reach an uncomfortable conclusion, preserve management's response and put both into the governance record?

What a readiness assessment is for

The term is used loosely. In its useful sense, a readiness assessment is a targeted diagnostic exercise designed around a clear diagnostic objective. If the firm's principal supervisor reviewed the framework tomorrow, where would the evidence be strongest, where would it come under pressure and what do we need to understand before external scrutiny exposes it for us?

A readiness assessment may sit alongside Internal Audit, Compliance Monitoring, external assurance or annual AML and CFT reporting. The difference is purpose. Readiness is a targeted diagnostic against likely pressure points. It is not a substitute for Internal Audit, Compliance Monitoring or Independent Assurance. The testing techniques described in Perspective 005 are useful examples of the kinds of supervisory pressure a firm may face.

A maturity score can be useful context. I would not let it substitute for evidence. A firm can score itself as developed and still have a file sample that tells a very different story. A readiness assessment is intentionally uncomfortable. Its purpose is to identify, quickly and honestly, where the firm would come under pressure if scrutiny began next week.

Getting the scope right

Get the scope wrong and the assessment weakens quickly. Trying to cover the whole framework by default usually weakens the assessment. For a smaller or tightly scoped business, a broader review may still be proportionate. The scope should follow the risk, not a template.

Four areas frequently deserve attention in the firms I work with:

Sanctions, adverse media, SAR quality and specific product or channel risks may be added to scope where the firm's risk profile warrants it. The BWRA should inform the scope, alongside known weaknesses, regulatory commitments and the specific diagnostic objective. What rarely helps is a comprehensive review of every element of the framework by default, particularly where the risk points somewhere more specific.

The evidence base

A readiness assessment concludes on the evidence it gathered. Its credibility rises and falls on that evidence.

Interviews and document review are necessary but not sufficient. They tell the assessor what the framework believes about itself. The assessment needs evidence that can challenge the firm's own narrative. Depending on the control, that may mean file sampling, data analysis, process walkthroughs, governance records, system evidence or MI review. The method should follow the risk being tested.

Where file sampling is relevant, I would build the sample around the population and the risk rather than a fixed number. The sample needs enough coverage to test the question being asked, with deliberate representation of the cohorts most likely to expose weakness. For some smaller firms the appropriate sample may be relatively small. The number should follow the scope, population and question being tested. Where operational judgement is material to the assessment, I often want to observe the relevant forum rather than rely only on its minutes. I also want a structured MI walk-through with a member of executive or Board management, testing whether the pack gives governance enough information to understand, challenge, decide and follow up.

Reporting the results

Good fieldwork can still fail to produce change if the reporting is weak. The most rigorous sampling can be diluted into inaction by a report that softens findings, buries recommendations or presents the framework as more defensible than the evidence supports.

The report should be as short as the evidence allows. It opens with a plain-language statement of the firm's current readiness position and the specific items likely to come under pressure. It should distinguish what requires management-body understanding or challenge, what needs a governance decision and what belongs in operational remediation. It attaches evidence, either as anonymised file excerpts or as MI extracts, that supports the material findings.

The report should reach the governance forum with authority over the material issues, in many firms the Audit or Risk Committee, alongside the executive response. The response should itself be brief, name accountable owners and specify the evidence that will demonstrate closure. Where there is a substantive disagreement about a material finding, the disagreement, supporting evidence and governance outcome should remain visible in the record.

Common failure modes

When readiness assessments fail to produce useful change, the failure modes are usually recognisable.

Scope inflation dilutes conclusions. Framing as reassurance produces a report designed to comfort rather than to challenge. Excessive reliance on interviews produces conclusions that reflect what the framework believes about itself. Softening for the executive audience produces action plans that never quite land on individual owners. RAG status is useful only if the colour sits on top of evidence. A green box without the closure evidence underneath it tells the Committee very little.

None of these failures is caused by bad faith. Each is caused by design choices made early and adjusted too late. Naming them explicitly at scoping makes them much harder to ignore later.

How Claritas approaches readiness assessments

A Claritas readiness assessment is designed around the diagnostic objective above: where the evidence would be strongest, where it would come under pressure and what the firm needs to understand first. That framing shapes every design decision that follows.

Scope is agreed against the firm's risk assessment, known weaknesses, regulatory commitments and the specific diagnostic objective, and stays as narrow as the risk allows. The assessment is evidence-led. Where customer or case decisions are material, files become a central part of that evidence; elsewhere the evidence may sit in data, systems, governance records or control testing. The reporting route is agreed at the outset with the governance sponsor, so material findings reach the right forum without being diluted on the way.

For many smaller firms, a focused assessment can often be delivered over weeks rather than months. The exact duration should follow the scope and the evidence needed. Its purpose is to give the Board a credible diagnostic baseline and a specific runway of improvements. It is not designed to accumulate on a shelf.

What success looks like
  • 01The Board holds an honest, current view of the firm's readiness position, with specific material weaknesses identified, owned and placed on a clear remediation timetable.
  • 02The remediation runway is sequenced by materiality and executable within the firm's available capacity and any relevant regulatory commitments.
  • 03The MI pack gives accountable senior leaders enough information to explain the firm's principal risks, material control weaknesses and the actions being taken.
  • 04Readiness is maintained through the firm's normal governance, assurance and remediation cycle rather than recreated only when supervisory pressure appears.
  • 05The governance record shows that material findings produced visible challenge, action or decision where needed, and that the resulting change can be evidenced.
References
About the author
Everett Morgan
Founder & Principal Adviser, Claritas Risk Advisory

Everett has more than twenty years' experience in financial crime, AML governance, regulatory compliance and operational risk gained within Deutsche Bank, Morgan Stanley and BNP Paribas. He established Claritas Risk Advisory to provide smaller regulated financial institutions with experienced independent judgement, practical insight and proportionate recommendations.

Need an independent perspective?

Preparing for regulatory change starts with understanding where your organisation stands today.

If you would like to discuss your financial crime framework or explore how Claritas Risk Advisory can help, I would be pleased to arrange a confidential conversation.

Let's start with a conversation