Resources

Proving the programme is working, not just running

Part 3 of a 3-part series. Part 1 set out the six cogs; Part 2 covered rebuilding the programme (audit, redesign, delivery). This post covers what it takes to prove it's actually holding: data, technology, and the culture conversation most firms avoid.

You can't manage what you don't measure

You can't hold a conversation about non-compliance on the basis of a feeling. Three documented instances of the same issue are far harder to dismiss than a general concern.

The monitoring loop is simple to describe and hard to run in full: take steps, detect breaches, record and report them, analyse the pattern, take steps again. Most firms manage the first two. The analysis step, where the actual learning happens, usually gets dropped because nobody's been given the time for it.

This is where the bar is rising. The SRA currently checks whether things were done. The FCA, which supervises financial services and looks set to take on oversight of the legal sector too, asks whether controls were effective. That's a higher bar, and it needs data to clear.

The knowledge already exists. It just doesn't reach the right person in time.

Jonny Coleman, First AML's UK Country Manager, puts it directly: most compliance failures aren't caused by not knowing what to do. The knowledge is in the policies, the experienced staff, the risk frameworks already written down. The problem is timing, not knowledge.

Three failure points come up repeatedly. Risk ratings applied inconsistently because they rely on individual judgement, fixable by digitising the risk matrix so MLROs review exceptions instead of every case from scratch. Screening hits assessed with no oversight of how matter teams are handling them, fixable by surfacing hits before they're marked true or false so compliance has visibility without reviewing every case personally. And policies sitting in a file nobody opens, fixable by surfacing the relevant procedure at the point of need, based on the entity type, jurisdiction, and CDD level in front of the user.

The shift is from static to systematic: risk scoring applied automatically, full visibility across screening decisions, procedures that show up when they're needed instead of waiting to be found.

The conversation nobody wants to have

This is the hardest part, not because it's complicated, but because it means having conversations firms would rather avoid.

If leadership doesn't visibly prioritise compliance, the compliance team can't hold the line alone. If non-compliance carries no consequences, the policy is aspirational. If support staff don't feel safe raising concerns, the people closest to the problem stay quiet.

The legal sector has had 23 years with the AML regime. Most firms have invested in meeting it. The ones where it's actually working made culture the foundation, not the footnote.


About First AML

First AML comes from the perspective of both a technology provider, but also as compliance professionals. Prior to releasing, First AML’s all-in-one AML workflow platform, we processed over 2,000,000 AML cases ourselves. Understanding the acute problem that faces firms these days as they try to scale their own AML, is in our DNA.

That's why First AML now powers thousands of compliance experts around the globe to reduce the time and cost burden of complex and international entity KYC. First AML stands out as a leading solution for organisations with complex or international onboarding needs. It provides streamlined collaboration and ensures uniformity in all AML practices.

Keen to find out more? Book a demo today!

Related