Module 03 | Global Financial Crimes, Risk, and RegTech Library
Research verified: 9 August 2026
Current-source review due: 9 February 2027
Scope: Global enterprise framework, with comparative United States, United Kingdom, European Union, Australia, Canada, Singapore, and Hong Kong lenses.
Source Quality and Currency Note
This module was verified against current official sources on 9 August 2026. Primary sources are used first: laws and regulations, FATF and Basel material, supervisory manuals and guidance, and official enforcement releases and court documents. A source marked as a consultation is used solely as direction of travel and is not represented as binding law. Jurisdiction-specific requirements must be rechecked when the module is applied to a real entity, product, transaction, or market.
Not Legal Advice
This module is educational material, not legal, regulatory, tax, or compliance advice. It does not replace current legal analysis or applicable regulatory guidance.
Learning Objectives
By the end of this module, the reader should be able to:
- Distinguish business-wide, legal-entity, relationship, and event-level financial-crime risk assessments.
- Build a risk statement that separates legal floors, enterprise prohibitions, conditional activity, and residual-risk tolerance.
- Translate a financial-crime risk assessment into policy, controls, decision rights, management information, and evidence.
- Design an exception and risk-acceptance process that is lawful, time-bound, challengeable, and auditable.
- Test whether global standards and local overlays are operating as one enterprise framework.
- Evaluate governance and assurance evidence through current official supervisory and enforcement lenses.
Executive Thesis
Financial-crime risk assessment is not a document-management exercise. It is an evidence-backed argument about how the enterprise could be exploited, what consequence that exploitation could create, which controls are required, what risk remains, and which person can decide whether the remaining risk is acceptable. Risk appetite is the boundary system that the argument must change. Governance is the mechanism that allocates who owns exposure, who operates controls, who challenges, who can approve exceptions, and who can prove the result.
The executive failure mode is a broken translation chain. The business grows into a new risk concentration; the risk assessment remains generic; a policy change is mistaken for a control change; local implementation diverges invisibly; exceptions accumulate; management information focuses on output rather than coverage; and assurance discovers the problem only after the exposure has become material. TD Bank, Crown, Starling, Westpac, and ABN AMRO illustrate different versions of this pattern. [S18] [S20] [S21] [S22] [S24]
The right executive question is not simply, "Do we have a low appetite for financial crime?" It is: Which activities are prohibited, which are conditional, what capability is required to perform them, what residual risk may be held temporarily, and what proof shows the boundaries are operating?
Questions This Module Answers
- What is the right unit of analysis for enterprise financial-crime risk: a customer, product, legal entity, payment route, geography, network, third party, or event?
- How should inherent exposure, control design, operating effectiveness, coverage, and residual risk be kept distinct?
- Which financial-crime risk boundaries are legal floors, which are management choices, and which require board involvement?
- How should risk assessment inform policy hierarchy, controls, staffing, technology change, product governance, and local operating models?
- What evidence proves that a stated boundary is enforced in workflow rather than merely approved in a meeting?
Part I - Executive Layer
1. The Enterprise Risk Statement Is a Strategic Operating Choice
Financial crime is a non-financial risk with legal, regulatory, market-access, customer, operational, and balance-sheet implications. A risk appetite statement that contains only a broad phrase such as "no appetite for financial crime" is directionally sound but operationally insufficient. It needs a boundary model.
- Legal floor. Binding prohibitions, reporting requirements, and other legal obligations are not subject to commercial override. The U.S. AML program rule requires a board-approved compliance program with specified minimum elements; UK rules require business risk assessment and policies, controls, and procedures to manage ML/TF risk. [S05] [S08]
- Enterprise prohibition. An organization may decline activity that is technically lawful but not controllable within its data, capacity, jurisdictional, or reputational limits.
- Conditional activity. An activity may be allowed only after enhanced due diligence, named approval, staffing proof, control validation, or a local legal overlay.
- Monitored residual risk. Some exposure remains only while thresholds, control evidence, and issue status stay within defined bands.
Risk appetite must therefore map to product, customer, payment, corridor, third-party, and legal-entity decisions. A rule is functioning only when a business leader can determine whether a planned activity is prohibited, conditional, inside ordinary control capacity, or outside current tolerance.
2. Risk Appetite Is a Boundary System, Not a Slogan
FATF's risk-based approach requires institutions to identify, assess, understand, and mitigate ML/TF risk proportionately. It does not prescribe one enterprise scoring or risk-appetite format. [S01] The design recommendation in this module is to connect a concise set of risk appetite statements to measurable boundary conditions:
- Exposure boundaries: concentration of higher-risk customers, products, payment routes, countries, third parties, and legal entities.
- Control boundaries: coverage gaps, unvalidated models, data quality defects, queue overload, untested changes, and overdue high-severity issues.
- Outcome boundaries: serious sanctions breach, overdue mandated reporting, material assurance failure, or repeated breach of a risk restriction.
- Capacity boundaries: investigative capacity, quality-control capacity, data remediation capacity, technology release capacity, and local expertise.
An institution may maintain high-risk activities where it can lawfully manage them with proportionate controls. FINTRAC expressly explains that high-risk activity or relationships are not necessarily prohibited, but require documented mitigation and prescribed special measures where applicable. [S15] This is why blanket de-risking is not the same thing as risk-based management.
3. Governance Is a Decision-Rights Map
Good governance does not begin with a committee chart. It begins with an accountable decision. The business owns the exposure it creates and the first-line controls it operates. A financial-crime or compliance function should set standards, challenge, advise, and escalate independently. Risk, legal, operations, data, technology, and local management have defined roles. Independent assurance tests whether the framework is designed and operating effectively. The board or delegated committee oversees material risk posture and management effectiveness.
The exact legal allocation varies by entity and jurisdiction. The core operating questions do not:
- Who owns the risk assessment and its conclusion?
- Who can approve a high-risk or conditional activity?
- Who can decide a temporary exception and at what materiality?
- Who can change a control's configuration, and who independently tests it?
- Who resolves conflict between a global standard and a local legal or data constraint?
- What record survives the decision?
The EBA's AML/CFT compliance-officer guidelines and the EU AML package both reinforce the importance of defined group governance, information, and control arrangements. [S09] [S11] AMLA's 2026 group-wide RTS consultation is not binding, but it usefully illustrates the regulatory direction: documented decision powers, group risk assessment, regular information exchange, and oversight of group-wide implementation. [S12]
Enforcement Lens: TD Bank - Actual Risk Must Beat Assumed Risk
FinCEN stated that TD Bank admitted it willfully failed to maintain a program meeting the BSA's minimum requirements and knew that the program was neither appropriately designed nor adequately resourced for actual illicit-finance risk. [S18] DOJ announced a guilty plea, $1.8869457804 billion in criminal fine and forfeiture, and a three-year monitor. [S19]
The lesson is not simply "spend more on compliance." It is to demonstrate a real connection among the risk assessment, management information, capacity plan, control coverage, escalation, and decision to restrict, remediate, or exit. If management recognizes an actual-risk mismatch but operating limits do not change, governance has failed.
Part II - Operator Layer
4. Build the Assessment Around Risk Scenarios, Not Factor Lists
Customer, product, country, and channel factors are necessary inputs, but they do not by themselves explain the risk. A useful scenario states a threat, an exposure unit, a route of exploitation, a vulnerability, and a plausible impact. For example:
A criminal network could use remotely onboarded opaque legal entities in a defined product and payment corridor to layer illicit funds before detection because ownership evidence, identity data, and behavioral monitoring have specified limitations.
That statement directs the operator to the relevant controls. It identifies what must be tested: onboarding, ownership, data completeness, monitoring, routing, case handoff, and account action. It also makes the risk assessment change-manageable. A change in payment corridor, identity vendor, product feature, legal entity, or data field can be examined for its effect on the scenario.
FFIEC expects a comprehensive analysis of the institution's ML/TF and other illicit-financial-activity risk based on products, services, customers, and geography. It emphasizes that risk assessment is bank-specific, may weight factors differently, and should be updated for changes such as new products, services, customer types, geographic change, mergers, and acquisitions. [S03] AUSTRAC's current guidance similarly frames risk in services, customers, delivery channels, countries, new technology, and planned business change. [S13]
5. Segment for Different Treatment, Then Aggregate for Enterprise Decisions
Segmentation should cause a different control response. If it does not change due diligence, approval, review cadence, monitoring, restriction, capacity, or reporting, it may be labeling rather than risk management. A meaningful segment may combine entity type, ownership opacity, industry, product usage, payment behavior, delivery channel, geography, counterparty type, and adverse-information indicators.
Do not assume that enterprise risk is the sum of customer scores. A payment corridor, correspondent-bank relationship, merchant platform, third party, or product feature may create a material concentration that individual customer scores do not reveal. Conversely, a country-level signal must not automatically classify every customer as high risk. The purpose of nesting is to preserve both enterprise visibility and relationship-level proportionality.
FFIEC recognizes the value of assessing risk within business lines and across activities and legal entities in consolidated programs. [S03] FINTRAC distinguishes business-based and relationship-based assessment and expects the methodology to reflect the size, type, and complexity of the business. [S15]
6. Policy Architecture: Translate Intent into Execution
A policy hierarchy should turn a required outcome into an executable operating rule:
| Layer | Job | Evidence of implementation |
|---|---|---|
| Principle / appetite | States boundaries and non-negotiable posture | Board or executive approval, thresholds, decision records |
| Enterprise policy | States mandatory rules and roles | Applicability map, owner, controlled version |
| Standard | Defines the minimum design | Control specifications, data requirements, target state |
| Procedure / playbook | Explains execution in a team, product, or market | Local overlay, training, workflow steps |
| Configuration / workflow | Implements rule in systems and routing | Change ticket, test, configuration record, rollback plan |
| Evidence | Proves action and review | Logs, records, case file, exception, test report |
AUSTRAC describes AML/CTF policies broadly to include the policies, procedures, systems, and controls used to manage and mitigate risk and comply with obligations. [S14] This is an important practical point: an approved document is only part of the program. The operating test is whether a reviewer can identify the workflow, system, data, executor, exception path, and proof for every material mandatory rule.
7. Exception and Risk-Acceptance Design
Exceptions are not inherently weak. Uncontrolled exceptions are. Distinguish five categories:
- Policy interpretation: clarification of how an existing rule applies.
- Operational exception: a bounded, short-term deviation from procedure.
- Risk acceptance: a documented decision to hold residual risk temporarily while a treatment or exit occurs.
- Control waiver: a decision not to perform a control. This should generally be prohibited if it would defeat a binding requirement.
- Strategic change: a durable change in product, customer, market, or risk posture. This belongs in governance and appetite, not in an exception log.
Every exception should record scope, affected population, legal analysis where appropriate, compensating control, owner, approver, expiry, monitoring, escalation trigger, and closure proof. A risk-acceptance label cannot waive law. The lawful response to an impossible requirement may be to stop the activity, change the design, apply a valid alternative, or seek formal legal and regulatory direction - not to record an informal commercial override.
8. Management Information and Governance Cadence
High-value management information is decision-quality information. It shows risk posture, concentration, coverage, capacity, control health, exception aging, assurance outcome, and decisions needed. It should identify the population, time period, exclusions, data-quality limitation, threshold, accountable owner, and required action.
Do not treat reduced alerts, lower backlog, or faster case closure as automatic evidence of reduced risk. Those outputs may improve because controls are more effective; they may also improve because the population, data, configuration, or investigative quality deteriorated. The relevant question is whether coverage and outcome evidence support the conclusion.
The FCA's 2025 risk-assessment findings describe good practice where financial-crime risk is considered in product development, business strategy, growth, and sales discussions, with MLRO representation. [S07] This is a useful operating benchmark: risk assessment should be an input to growth decisions, not a late-stage approval exercise.
Enforcement Lens: Crown - Documented Is Not the Same as Risk-Based
AUSTRAC reported that Crown admitted its programs were not based on appropriate risk assessments, did not have appropriate systems and controls, and were not subject to appropriate board and senior-management oversight. [S20] The transferability is direct. A risk assessment must identify the actual risk; policies and controls must visibly derive from it; the board and senior management must oversee material trade-offs; and the enterprise must test whether the program is lived in workflow.
Part III - Specialist Layer
9. Keep Inherent Exposure, Control Assessment, and Residual Risk Separate
Inherent risk is the risk before controls. Residual risk is what remains after controls and mitigation. FINTRAC provides this distinction directly and notes that the risk-based approach should be documented and tailored to business activity. [S15] AUSTRAC similarly expects the risk assessment to identify inherent risk before policies and controls. [S13]
For a material scenario, preserve these analytic layers:
- Threat: actor, typology, or illicit objective.
- Vulnerability: exploitable weakness in product, process, data, technology, staffing, governance, or third party.
- Exposure: volume, value, access, cross-border reach, concentration, speed, or complexity.
- Impact: plausible regulatory, legal, financial, customer, national-security, operational, or reputational consequence.
- Control design: whether the control could address the scenario as designed.
- Operating effectiveness: whether the control performed across the relevant population and time period.
- Coverage and data quality: who and what the control did not reach or could not reliably assess.
- Residual risk: a documented conclusion based on the preceding evidence.
Do not use a strong policy, a completed training record, or a low alert number to reduce inherent risk. Those are control or outcome signals. Conflating them creates the illusion that a mature control environment makes exposure disappear.
10. Scoring, Calibration, Overrides, and Aggregation
Use ordinal scales to support priorities and treatment. Do not simulate scientific certainty. A three-band scale can be more effective than a five-band scale if it maps clearly to standard, enhanced, restricted, and prohibited treatment. If using more granular scoring, define each point with evidence conditions, calibration examples, and a required response.
Controls for scoring should include:
- A definition catalog for terms such as high, material, effective, outside appetite, and critical.
- Cross-business challenge to test whether similar facts receive similar treatment.
- Override governance that records reason, approver, duration, and recalibration trigger.
- Sensitivity analysis where a small assumption can change a material approval or exit decision.
- Back-testing from incidents, findings, quality results, and enforcement patterns into the scenario inventory.
- Concentration analysis that tests the minority of exposure units capable of driving a majority of plausible impact.
FINTRAC cautions that there is no prescribed methodology and that a table alone is not a complete risk assessment. The assessment must reach a documented analysis and conclusion that reflects the business. [S15]
11. Effectiveness and Evidence Design
Test control design, implementation, operation, coverage, and outcome. An audit sample can prove that a control worked in sampled records. It cannot by itself prove that the complete intended population was covered, that the configuration was active in every legal entity, or that the control would work after a data or system change.
The evidence chain should preserve:
- source signal or legal requirement;
- risk scenario and rating rationale;
- boundary or treatment decision;
- control object, owner, data, workflow, and configuration;
- execution and population coverage;
- independent test and issue record;
- remediation, exception, or exit decision; and
- re-assessment and learning record.
Westpac's agreed facts show why the existence of independent review is not enough if the review does not satisfy effectiveness requirements or material risk remains insufficiently understood. [S24]
12. Global Core / Local Edge
The global core should include the enterprise risk taxonomy, definitions, scenario grammar, policy hierarchy, minimum control objectives, evidence standard, issue classification, exception rules, and aggregation method. The local edge should include local law, FIU reporting, privacy and localization, local customer documentation, language, products, supervisory expectations, and local accountable ownership.
The enterprise should maintain an overlay register that identifies the local source, exact requirement, owner, conflict with global policy if any, implementation proof, review date, and escalation status. A global standard is not fully implemented if local legal or data constraints are invisible to the parent. The EU's group-wide requirements and AMLA's proposed technical standards both emphasize group assessment, documented roles, information-sharing, and group-level review, while preserving entity-level assessment. [S11] [S12]
Enforcement Pattern: Starling, ABN AMRO, Westpac, and Barclays
- Starling: FCA fined the bank for sanctions-screening failures and repeated breach of a restriction not to onboard high-risk customers. A risk boundary must be encoded into onboarding and tested after implementation. [S21]
- ABN AMRO: Dutch prosecutors stated that the bank accepted a EUR480 million settlement after structural AML/CTF Act shortcomings over years. Persistent lifecycle weakness requires program-level remediation, not isolated fixes. [S22]
- Westpac: AUSTRAC's enforcement and agreed facts highlight the importance of relationship-level and correspondent-bank risk assessment, independent effectiveness review, and concentration visibility. [S23] [S24]
- Barclays: FCA fined Barclays GBP42 million in 2025 for poor handling of financial-crime risks involving two cases. Counterparty and client-money governance belong in the enterprise risk taxonomy, not in a disconnected commercial process. [S25]
What Good Looks Like / What Failure Looks Like
| Dimension | Mature capability | Fragile capability |
|---|---|---|
| Assessment | Scenario-based, current, data-informed, change-triggered, and tied to treatment | Generic annual factor list, stale scores, no link to decisions |
| Appetite | Legal floor, prohibitions, conditions, triggers, and decision rights are explicit | "Zero tolerance" statement with no operational consequence |
| Policies | Rules map to workflow, configuration, data, people, and proof | Document says must; no one can show how it is performed |
| Governance | Material choices, conflicts, and exceptions are owned and recorded | Multiple committees receive information but none owns the decision |
| Exceptions | Time-bound, compensating, monitored, escalated, and closed | Informal workarounds become permanent |
| Assurance | Tests coverage, data, design, operation, and outcome | Checks acknowledgement, document existence, or small samples only |
Common Misconceptions and Contrarian Insights
- "Risk appetite is intent." It is a boundary system. If it does not change a customer, product, market, capacity, or remediation decision, it is not functioning.
- "High risk means prohibited." It may mean enhanced treatment, monitoring, restriction, or exit. High risk is not by itself a legal conclusion. [S15]
- "A policy is proof of control." A policy is one link in the evidence chain. Workflow, configuration, data, performance, coverage, and test evidence complete the control.
- "More data creates better risk assessment." Only material, reliable, interpretable data that changes treatment improves the assessment.
- "A global standard solves local divergence." It establishes common grammar; it does not remove local law, data, FIU reporting, or operational ownership.
- "The second line owns all financial crime." The business owns exposure and first-line control execution. Oversight, challenge, and assurance must be allocated explicitly.
- "Exception volume is administrative." Exception aging and repeat overrides are leading indicators of design, capacity, or policy ambiguity.
- "Lower alerts prove lower risk." They may prove lower coverage. Confirm population, data, configuration, and outcome before drawing a conclusion.
Executive Discussion Questions
- What is our current financial-crime risk posture in terms that distinguish prohibited, conditional, and controllable activity?
- Which exposures are growing faster than our controls, data quality, or investigative capacity?
- Which legal floors are being confused with management choices, and where might a risk acceptance be masking a legal or strategic issue?
- What are our five largest concentrations capable of driving a material event?
- Which product, market, customer, or partner launches were conditional in the last quarter, and did the conditions become real in workflow?
- What do the oldest and most repeated exceptions say about our control design or resource plan?
- Where are local overlays stricter, incompatible, or not yet evidenced against global standards?
- Which external typology, enforcement action, or incident changed our assessment, controls, or capacity plan most recently?
- What evidence supports a conclusion that recent alert, backlog, or closure changes are risk improvements rather than coverage changes?
- What has assurance tested about population coverage, data lineage, and change control?
- Which decisions have ambiguous accountability or duplicate approval rights?
- What material risk statement cannot we currently reconstruct with traceable evidence?
- When a boundary is breached, is the required action clear and actually executed?
- What residual risks should be reclassified as strategic appetite decisions, restrictions, or exits?
- If a supervisor challenged our residual-risk conclusion tomorrow, what record would establish our reasoning and proof?
Practitioner and Specialist Checklists
Executive Checklist
- Distinguish legal requirements, enterprise boundaries, and temporary risk acceptances in material reports.
- Require a concentration view, not only average portfolio scores.
- Require management to state the decision that follows from every material threshold breach.
- Demand proof that conditions, restrictions, and remediation are present in workflow.
Operator Checklist
- Maintain a scenario inventory with owners, treatments, controls, data dependencies, change triggers, and evidence plans.
- Map every mandatory policy rule to global implementation and local overlays.
- Treat product launch, M&A, new market, technology change, material incident, and external typology as risk-assessment triggers.
- Maintain an exception register with population, expiry, compensating control, approver, monitoring, and closure evidence.
- Design management information around decision thresholds and uncertainty, not only process volume.
Specialist Validation Checklist
- Verify the source, transformation, quality, and population coverage of every material risk metric.
- Verify that inherent risk, control design, operation, coverage, and residual risk are separately documented.
- Test score definitions, overrides, calibration, aggregation, and sensitivity.
- Test configuration and workflow in each relevant legal entity, product, and market.
- Test whether assurance samples reach the intended population and whether exceptions are properly represented.
- Retain reconstructable evidence from risk source through remediation closure.
Module Glossary
- Business-wide risk assessment: A documented assessment of the enterprise's exposure across products, customers, channels, geographies, legal entities, and other relevant factors.
- Control objective: The outcome a control is designed to achieve.
- Control coverage: The extent to which the population, data, routes, and timing intended by a control are actually reached.
- Exception: A controlled, time-bound deviation from an approved rule or procedure.
- Global Core / Local Edge: A design principle that standardizes common risk grammar and minimum outcomes while preserving local legal and operating requirements.
- Inherent risk: Risk before controls or mitigation.
- Legal floor: The minimum binding legal and regulatory requirement; not subject to commercial waiver.
- Residual risk: Risk remaining after consideration of control design, operation, coverage, and limitations.
- Risk appetite: The boundary system that distinguishes prohibited, conditional, acceptable, and escalated exposure.
- Risk acceptance: A formal decision to hold defined residual risk temporarily or within stated authority.
- Risk scenario: A structured description of a threat exploiting a vulnerability through a route in the business with plausible impact.
- Segmentation: Grouping exposure units by risk-relevant characteristics so treatment and aggregation can differ meaningfully.
- Source lineage: The trace of where data, legal rules, risk signals, and decisions originated and how they were used.
MLA 9 Works Cited
- [S01] Financial Action Task Force. "The FATF Recommendations." Financial Action Task Force, current text accessed 9 Aug. 2026, https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html. Accessed 9 Aug. 2026.
- [S02] Basel Committee on Banking Supervision. "Sound Management of Risks Related to Money Laundering and Financing of Terrorism." Bank for International Settlements, 2020, consolidated guidance accessed 9 Aug. 2026, https://www.bis.org/basel_consolidated_guidelines/chapter/AFS/10.htm. Accessed 9 Aug. 2026.
- [S03] Federal Financial Institutions Examination Council. "BSA/AML Risk Assessment." BSA/AML Examination Manual, 2020, https://bsaaml.ffiec.gov/manual/BSAAMLRiskAssessment/01. Accessed 9 Aug. 2026.
- [S04] Financial Crimes Enforcement Network. Anti-Money Laundering and Countering the Financing of Terrorism National Priorities. U.S. Department of the Treasury, 30 June 2021, https://www.fincen.gov/sites/default/files/shared/BSA_Priorities_2021.pdf. Accessed 9 Aug. 2026.
- [S05] Electronic Code of Federal Regulations. "31 CFR 1020.210 - Anti-Money Laundering Program Requirements for Financial Institutions Regulated Only by a Federal Functional Regulator." U.S. Government Publishing Office, current text accessed 9 Aug. 2026, https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/section-1020.210. Accessed 9 Aug. 2026.
- [S06] Financial Conduct Authority. A Firm's Guide to Countering Financial Crime Risks. FCA Handbook, current PDF accessed 9 Aug. 2026, https://api-handbook.fca.org.uk/files/sourcebook/FCG.pdf. Accessed 9 Aug. 2026.
- [S07] Financial Conduct Authority. "Risk Assessment Processes and Controls in Firms: Our Findings." Financial Conduct Authority, 11 Nov. 2025, https://www.fca.org.uk/publications/good-and-poor-practice/risk-assessment-processes-and-controls-firms-our-findings. Accessed 9 Aug. 2026.
- [S08] UK Parliament. "The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, Regulations 18 and 19." legislation.gov.uk, current text accessed 9 Aug. 2026, https://www.legislation.gov.uk/uksi/2017/692/regulation/18. Accessed 9 Aug. 2026.
- [S09] European Banking Authority. Guidelines on Policies and Procedures in Relation to Compliance Management and the Role and Responsibilities of the AML/CFT Compliance Officer. EBA/GL/2022/05, 20 Sept. 2022, https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/anti-money-laundering-and-countering-financing-1. Accessed 9 Aug. 2026.
- [S10] European Banking Authority. Final Report: Amending Guidelines on ML/TF Risk Factors. 16 Jan. 2024, https://www.eba.europa.eu/sites/default/files/2024-01/a3e89f4f-fbf3-4bd6-9e07-35f3243555b3/Final%20Amending%20%20Guidelines%20on%20MLTF%20Risk%20Factors.pdf. Accessed 9 Aug. 2026.
- [S11] European Union. Regulation (EU) 2024/1624 on the Prevention of the Use of the Financial System for the Purposes of Money Laundering or Terrorist Financing. Official Journal of the European Union, 31 May 2024, https://eur-lex.europa.eu/eli/reg/2024/1624/oj. Accessed 9 Aug. 2026.
- [S12] Anti-Money Laundering Authority. Consultation Paper on Draft Regulatory Technical Standards under Articles 16(4) and 17(3) of Regulation (EU) 2024/1624. 16 Apr. 2026, https://www.amla.europa.eu/document/download/4ee33b25-2f03-4ed1-938b-a4ca36714d55_en?filename=Consultation%20paper%20RTS%20under%20Articles%2016%284%29%20and%2017%20of%20Regulation%20EU%2020241624.pdf. Accessed 9 Aug. 2026.
- [S13] Australian Transaction Reports and Analysis Centre. "Step 2: Identify and Assess Your Risks." AUSTRAC, 31 Mar. 2026, https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/develop-your-amlctf-programs/step-2-identify-and-assess-your-risks. Accessed 9 Aug. 2026.
- [S14] Australian Transaction Reports and Analysis Centre. "Step 3: Manage and Mitigate Your Risks - AML/CTF Policies." AUSTRAC, 27 Mar. 2026, https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/develop-your-amlctf-programs/step-3-manage-and-mitigate-your-risks-amlctf-policies. Accessed 9 Aug. 2026.
- [S15] Financial Transactions and Reports Analysis Centre of Canada. "Risk Assessment Guidance." FINTRAC, 4 Jan. 2021, https://fintrac-canafe.canada.ca/guidance-directives/compliance-conformite/rba/rba-eng. Accessed 9 Aug. 2026.
- [S16] Monetary Authority of Singapore. Notice 626: Prevention of Money Laundering and Countering the Financing of Terrorism - Banks. Monetary Authority of Singapore, current notice page accessed 9 Aug. 2026, https://www.mas.gov.sg/regulation/notices/notice-626. Accessed 9 Aug. 2026.
- [S17] Hong Kong Monetary Authority. Guideline on Anti-Money Laundering and Counter-Financing of Terrorism (For Authorized Institutions). 25 May 2023, https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20230525-4-EN/AML-2.pdf. Accessed 9 Aug. 2026.
- [S18] Financial Crimes Enforcement Network. "FinCEN Assesses Record $1.3 Billion Penalty against TD Bank." U.S. Department of the Treasury, 10 Oct. 2024, https://www.fincen.gov/news/news-releases/fincen-assesses-record-13-billion-penalty-against-td-bank. Accessed 9 Aug. 2026.
- [S19] U.S. Department of Justice. "TD Bank Pleads Guilty to Bank Secrecy Act and Money Laundering Conspiracy Violations in $1.8B Resolution." Office of Public Affairs, 10 Oct. 2024, https://www.justice.gov/archives/opa/pr/td-bank-pleads-guilty-bank-secrecy-act-and-money-laundering-conspiracy-violations-18b. Accessed 9 Aug. 2026.
- [S20] Australian Transaction Reports and Analysis Centre. "Federal Court Makes Ruling in Crown Matter." AUSTRAC, 11 July 2023, https://www.austrac.gov.au/news-and-media/media-release/federal-court-makes-ruling-crown-matter. Accessed 9 Aug. 2026.
- [S21] Financial Conduct Authority. "FCA Fines Starling Bank GBP29m for Failings in Its Financial Crime Systems and Controls." Financial Conduct Authority, 2 Oct. 2024, updated 5 Dec. 2025, https://www.fca.org.uk/news/press-releases/fca-fines-starling-bank-failings-financial-crime-systems-and-controls. Accessed 9 Aug. 2026.
- [S22] Netherlands Public Prosecution Service. "ABN AMRO Pays EUR 480 Million on Account of Serious Shortcomings in Money Laundering Prevention." Public Prosecution Service, 19 Apr. 2021, https://www.prosecutionservice.nl/latest/news/2021/04/19/abn-amro-pays-eur-480-million-on-account-of-serious-shortcomings-in-money-laundering-prevention. Accessed 9 Aug. 2026.
- [S23] Australian Transaction Reports and Analysis Centre. "Westpac Ordered to Pay $1.3 Billion Penalty." AUSTRAC, 21 Oct. 2020, https://www.austrac.gov.au/new-and-media/news/westpac-ordered-pay-13-billion-penalty. Accessed 9 Aug. 2026.
- [S24] Australian Transaction Reports and Analysis Centre. Westpac Statement of Agreed Facts and Admissions. 24 Sept. 2020, https://www.austrac.gov.au/sites/default/files/2020-09/AUSTRAC%20Westpac%20Statement%20of%20agreed%20facts%20and%20admissions_FILED.pdf. Accessed 9 Aug. 2026.
- [S25] Financial Conduct Authority. "FCA Fines Barclays GBP42 Million for Poor Handling of Financial Crime Risks." Financial Conduct Authority, 16 July 2025, https://www.fca.org.uk/news/press-releases/fca-fines-barclays-42-million-poor-handling-financial-crime-risks. Accessed 9 Aug. 2026.
- [S26] Australian Transaction Reports and Analysis Centre. "AUSTRAC CEO Brendan Thomas Speech - Clubs NSW 2025 Conference." AUSTRAC, 15 Oct. 2025, https://www.austrac.gov.au/austrac-ceo-brendan-thomas-speech-clubs-nsw-2025-conference. Accessed 9 Aug. 2026.
Citation and Interpretation Note
Bracketed source IDs in the module correspond to the Works Cited list and machine-readable source register. Where the module synthesizes sources into an operating recommendation, it is identified as a library recommendation rather than a legal requirement.