Perspectives
Perspective 011Practice

Why AML remediation programmes fail, and how to keep yours on track.

Successful remediation is not about clearing backlogs. It is about restoring confidence in your financial crime framework, and that begins with clear scope, credible quality assurance, visible capacity assumptions and governance that can explain what changed.

By Everett MorganSummer 202611 min read
Long architectural corridor in a European corporate building at dusk, warm light against navy shadows
Executive brief

Reading time · 11 minutes  ·  Primary audience · Boards, Programme Sponsors, MLROs, Heads of Financial Crime, Chief Operating Officers

Why this matters

Large AML remediation programmes are one of the most exposed pieces of work a regulated firm can undertake. They tend to arise when confidence in the framework has already been questioned, often by a supervisor. They involve large volumes of work, significant external cost, sustained management attention and a Board whose credibility is already under pressure. In my experience across programmes at Deutsche Bank, Morgan Stanley, BNP Paribas and mid-tier European firms, the programmes that struggle rarely struggle because the population was too large or the standard too demanding. They struggle for reasons that are usually visible well before the programme admits them. This Perspective is about those reasons.

Key findings
  1. 01Programme failure is rarely explained by volume alone. The deeper problems usually sit in scope, governance, QA design, capacity assumptions and MI that does not show the full risk position.
  2. 02The scoping workshop shapes much of what follows. If the population, deficiency and completion standard are under-specified at the start, the programme will spend the rest of its life resolving questions that should have been answered earlier.
  3. 03Ambiguity in the definition of completion is one of the fastest ways to create rework, inconsistent outcomes and throughput drift. Completion criteria need to be operational and evidential, so that an analyst can apply them and QA can test them.
  4. 04QA needs to be designed before delivery begins. Its purpose is to test whether the methodology is being applied consistently, whether the relevant evidence is being considered and whether decisions remain within a defensible range. Material differences should feed calibration, but disagreement itself is not the defect.
  5. 05The programme pack should show activity, quality, population, residual risk, material change and the issues that require governance attention. Throughput on its own is not evidence of controlled progress.
Questions Boards should ask
  1. 01Do we have a written definition of completion that analysts and QA can apply against the same methodology and evidential standard, with material judgement differences capable of explanation?
  2. 02If the QA result is improving or deteriorating, do we know whether the change sits in file quality, sample mix, methodology, reviewer interpretation or calibration?
  3. 03If we were asked about one closed file and one QA challenge today, could we explain the original decision, the QA challenge and the evidence supporting the final outcome?

The problem: programmes that were on plan until they were not

A large remediation programme rarely announces its difficulty. The early phase often looks reassuring. Population sizing is signed off. Vendors are appointed. Reviewers are hired. Files move. The dashboard shows throughput. The problem becomes visible later, when quality begins to drift, rework grows, scope questions reappear and the MI no longer tells one coherent story.

That trajectory is not inevitable. But the weaknesses that produce it are usually visible much earlier than the programme admits.

The evidence: what remediation work tends to expose

Five failure modes I see repeatedly

Good practice and poor practice in remediation design

Business impact: the cost of drift

Programme drift is expensive because it compounds. Files processed against a weak standard create rework. Rework absorbs capacity that was meant to reduce the population. Governance then spends more time explaining the old problem while trying to fund the correction.

In the programmes I have worked on, the cost of fixing drift after it has embedded has been materially greater than the relatively unglamorous investment that would have prevented it: better scoping, clearer standards, stronger QA and more useful MI.

Practical actions

The Claritas approach

We are usually asked to help either before delivery scales or after the programme has begun to drift. The work is different in each case.

At the front end, I would test the population, scope, definition of completion, QA design, governance authority, capacity assumptions and MI before the plan is treated as settled.

Where a programme is already in difficulty, I start diagnostically. I compare what the programme says is complete with the operating evidence, test the assumptions underneath the plan, review the QA and governance record and identify the smallest number of changes needed to restore control.

That is diagnostic work unless Claritas has explicitly been commissioned to provide Independent Assurance.

In either case the deliverable is short. Programmes rarely fail for lack of paper. They fail when the important questions about scope, quality, capacity, risk and ownership remain unresolved until delivery pressure forces an answer.

What success looks like
  • 01A written definition of completion exists and is understood consistently across delivery and QA, with material judgement differences explainable through methodology and evidence.
  • 02QA results are interpreted with the sample, defect themes, severity and calibration context rather than reduced to one pass-rate or divergence number.
  • 03Programme MI shows activity, quality, population and residual risk together, and material changes are explained.
  • 04Governance authority is clear. Material scope changes, exceptions, escalation and completion decisions can be traced to the appropriate owner and supporting evidence.
  • 05Where additional challenge or assurance is required, the firm is clear whether it is using second-line challenge, Internal Audit, Independent Assurance or external diagnostic review, and what question that work is intended to answer.
References
  • Financial Conduct Authority, Final Notice: Starling Bank Limited, October 2024 (financial crime controls that did not keep pace with growth, sanctions screening deficiencies, breach of the voluntary requirement and subsequent remediation).
  • Central Bank of Ireland, enforcement action against Coinbase Europe Limited, announced November 2025 and confirmed in the High Court in 2026.
  • Regulation (EU) 2024/1624 (AMLR), customer due diligence and record-keeping requirements relevant to remediation completion standards.
  • SEPBLAC, published guidance and annual reporting on ongoing due diligence expectations.
About the author
Everett Morgan
Founder & Principal Adviser, Claritas Risk Advisory

Everett has more than twenty years' experience in financial crime, AML governance, regulatory compliance and operational risk gained within Deutsche Bank, Morgan Stanley and BNP Paribas. He established Claritas Risk Advisory to provide smaller regulated financial institutions with experienced independent judgement, practical insight and proportionate recommendations.

Need an independent perspective?

Preparing for regulatory change starts with understanding where your organisation stands today.

If you would like to discuss your financial crime framework or explore how Claritas Risk Advisory can help, I would be pleased to arrange a confidential conversation.

Let's start with a conversation