Module 16 | Global Financial Crimes, Risk, and RegTech Library
Research verification date: 9 August 2026
Important notice: Educational material only; not legal advice. It does not determine obligations in any jurisdiction or replace legal counsel, regulator engagement, institution-specific risk assessment, or a documented decision.
Source Quality and Currency Note
This module uses primary sources first: international standard setters, statutes and regulations, financial-intelligence and supervisory authorities, official technical guidance, public enforcement releases, consent orders, and court or government materials. Time-sensitive statements were verified on 9 August 2026. Requirements, implementation dates, supervisory priorities, vendor features, and individual enforcement proceedings can change. The module distinguishes legal or regulatory requirements from supervisory expectations, observed enforcement themes, and the library's operating recommendations. Dedicated jurisdictional modules provide the local legal analysis that this thematic module cannot replace.
Primary Source Map
The source identifiers used throughout the module point to complete MLA 9 entries at the end. This map makes the primary evidence base explicit before substantive reading:
- [S01] Financial Action Task Force: The FATF Recommendations.
- [S02] Financial Action Task Force: Information Sharing to Combat Illicit Finance: Global Overview of Public and Private Sector Partnerships and Data Protection Arrangements.
- [S03] Basel Committee on Banking Supervision: Principles for Effective Risk Data Aggregation and Risk Reporting (BCBS 239).
- [S04] European Union: Regulation (EU) 2024/1624 on the Prevention of the Use of the Financial System for the Purposes of Money Laundering or Terrorist Financing.
- [S05] European Union: Regulation (EU) 2024/1620 Establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism.
- [S06] European Banking Authority: Guidelines on the Role and Responsibilities of AML/CFT Compliance Officers.
- [S07] Financial Crimes Enforcement Network: Section 314(b) Fact Sheet.
- [S08] Federal Financial Institutions Examination Council: Bank Secrecy Act/Anti-Money Laundering Examination Manual.
- [S09] Financial Conduct Authority: Financial Crime.
- [S10] Monetary Authority of Singapore: Notice 626: Prevention of Money Laundering and Countering the Financing of Terrorism.
- [S11] Australian Transaction Reports and Analysis Centre: AML/CTF Programs.
- [S12] U.S. Department of Justice: Danske Bank Admits to Defrauding U.S. Banks and Agrees to Forfeit $2 Billion.
- [S13] Financial Crimes Enforcement Network: FinCEN Assesses $1.3 Billion Penalty Against TD Bank for Widespread and Systemic Violations of Bank Secrecy Act.
- [S14] Financial Conduct Authority: FCA Fines Starling Bank for Failings in Financial Crime Systems and Controls.
- [S15] Australian Transaction Reports and Analysis Centre: AUSTRAC Commences Civil Penalty Proceedings Against Westpac.
How to Use This Module
- Enterprise leader pass: executive thesis, decision models, Global Core / Local Edge architecture, maturity profile, failure cascade, and executive discussion questions.
- Operator pass: process design, decision rights, data/evidence outputs, workflow handoffs, performance measures, technology and governance dependencies, and checklists.
- Specialist pass: regulatory mechanics, technical and control objects, architecture, analytical boundaries, test methods, assurance evidence, and glossary.
Learning Objectives
- Define Global Core and Local Edge as an operating-model discipline rather than a centralization slogan, and distinguish enterprise standard, shared service, local overlay, legal-entity accountability, and market action.
- Compare centralized, federated, hub-and-spoke, and product-embedded financial-crime models using decision rights, capability, evidence, capacity, data, resilience, regulatory engagement, and customer impact.
- Translate FATF group-wide program, risk-based, and information-sharing concepts; EU AMLR/AMLA developments; and selected U.S., UK, Singapore, and Australia materials into a governed global model.
- Design board, executive, first-line, second-line, compliance, investigations, technology, data, product, legal, privacy, and country roles so risks do not fall into gaps between group and market ownership.
- Use a controlled exception and local-overlay process for products, language, data, reporting, risk factors, operational procedures, third-party arrangements, and customer-treatment differences.
- Build management information, talent models, service levels, testing, and remediation governance that identify whether central capability is enabling local control or obscuring local failure.
Key Terms Used Deliberately
Global Core. The enterprise-wide set of standards, capability, evidence, control taxonomy, governance, and common services that should be reusable across markets.
Local Edge. The controlled local legal interpretation, configuration, data use, workflow, regulator engagement, and accountable action needed to make the global program lawful and effective in a market.
Legal-entity accountability. Responsibility held by the entity and its accountable officers for complying with applicable obligations and managing its actual customer, product, and market risk.
Service catalog. A defined description of a shared service, including scope, customers, owners, input/output, service levels, evidence, exceptions, resilience, and charges or funding where relevant.
Control owner. The named person accountable for the design, operation, monitoring, evidence, and remediation of a defined control outcome.
Delegation. Assignment of activity or decision authority under a defined mandate; it does not erase retained accountability or required oversight.
Executive Thesis
A global financial-crime program must achieve two things that can pull in different directions. It must make risk visible and controllable across the group: common taxonomy, policy, data and evidence standards, technology, supplier governance, testing, management information, and senior challenge. It must also enable each legal entity and market to meet its own legal obligations, interpret local facts, protect customers, communicate with regulators, and make accountable decisions. Neither objective succeeds alone. A strong group standard that ignores local law or operating reality becomes noncompliant or unusable. A collection of locally autonomous programs loses the ability to see connected risk, apply consistent challenge, or prove group-wide effectiveness.
Global Core / Local Edge is a way to resolve the tension. Global Core is not headquarters doing everything. It is the minimum common architecture needed to make controls repeatable, comparable, and evidence-bearing: group policy hierarchy; risk appetite; control taxonomy; customer and transaction data standards; common platforms or interfaces; service catalog; vendor governance; technical and operational resilience patterns; issue taxonomy; metrics; testing methods; training standards; and executive reporting. Local Edge is not a permission to diverge. It is the formal mechanism by which a market documents its local legal perimeter, data restrictions, language, products, risk typologies, reporting, customer treatment, regulatory relationships, and accountable actions. [S01][S03][S04][S06]
The first design variable is legal-entity accountability. A group function can provide a system, policy, managed service, expertise, or decision support. The local entity remains responsible for the obligations and customers within its jurisdiction except to the extent law and governance legitimately allocate responsibilities. The operating model therefore needs a clear chain: enterprise standard; local applicability assessment; implementation and configuration; operating action; monitoring and evidence; escalation and challenge; and accountable remediation. It needs named owners at both global and local levels, with a known process when their views differ.
Effective global design also depends on practical operating capacity. A shared investigations hub may create quality, scale, and better intelligence, but it can be ineffective if it cannot access lawful evidence, speak the language, understand the product and local typology, meet local turnaround expectations, communicate with the regulator, or obtain a local decision in time. A country program can be close to customers and authorities, but it may lack specialist depth, independent challenge, or the ability to see cross-border networks. The correct answer is generally a controlled blend, selected service by service and evidenced through outcomes—not an ideology of centralization or decentralization.
Executive decision rule. Do not centralize, outsource, relocate, or standardize a financial-crime activity until the enterprise has identified the accountable legal entity and market owner, local legal and data constraints, decision and action authority, evidence pathway, service dependency, escalation route, and the test that proves the control remains effective.
The Questions This Module Answers
- Which outcomes, control standards, data definitions, evidence requirements, and services should be global—and why?
- Which legal, regulatory, customer, product, language, data, payment-rail, or operational conditions require a Local Edge overlay?
- Who is accountable when a shared service fails in one market: group, the service owner, the legal entity, the country head, the local MLRO or compliance officer, the product owner, or all under a defined RACI?
- Can the enterprise distinguish a lawful local difference from a convenience-driven workaround, and can it retire the latter?
- Does every material control have clear decision, action, escalation, evidence, and regulator-engagement authority across time zones and lines of defense?
- How does the group know that a central policy or platform is applied to the complete local population and not miscalibrated for a product or market?
- What evidence would demonstrate that performance, culture, incentives, capacity, and remediation are aligned to real financial-crime outcomes rather than local closure statistics?
1. Executive Layer: Choose the Operating Model Through Accountability and Outcome
1.1 Global Core / Local Edge begins with the control outcome
The design discussion should begin with an outcome and a legal entity, not an organization chart. For customer due diligence, the outcome may be a reliable, current, risk-proportionate understanding of the customer, beneficial owner, product, and purpose that supports local onboarding and periodic review. For sanctions, it may be timely and accurate screening of the complete in-scope population with an accountable local hold or release. For monitoring, it may be detection and investigation of relevant behavior across products and borders, followed by locally lawful reporting or action. For fraud, it may be customer protection and rapid disruption within a market's payments ecosystem. Every outcome requires a specific combination of global evidence and local decision rights.
A group should identify which components benefit from common design: definitions, policy minimums, risk taxonomy, data contracts, rules framework, case evidence standard, vendor arrangements, training, testing, issue methodology, and reporting. It should separately identify which components cannot be assumed to be identical: regulatory scope, legal authority, documentation, data use, language, local threat patterns, product flows, regulatory reporting, escalation route, customer communication, and the person who may take action. This results in a service-by-service allocation rather than a broad label such as centralized or local.
The FATF Recommendations establish an international framework but implementation remains jurisdictional. EU AMLR and the establishment of AMLA further illustrate that a common regional rulebook and supervisory architecture do not eliminate the need for legal-entity execution and market facts. The operating recommendation is therefore to maintain a group baseline and a mapped local overlay for every material service. [S01][S04][S05][S06]
| Operating component | Global Core contribution | Local Edge accountability |
|---|---|---|
| Policy and risk appetite | Minimum standard, taxonomy, group prohibition and escalation | Applicability, local legal interpretation, board/senior approval where needed |
| Customer and transaction data | Common definitions, lineage, quality metrics, interfaces | Lawful collection/use, local sources, localization, data-quality remediation |
| Screening and monitoring | Common platform, model/rule framework, testing and evidence | Local scope, thresholds, language, action authority, population reconciliation |
| Investigations and reporting | Methodology, tools, specialist support, quality assurance | Local evidence, report decision, regulator/law-enforcement engagement |
| Management information | Common metrics, issue taxonomy, executive comparison | Local denominator, risk context, management action, accountable certification |
1.2 Retained accountability must survive delegation
Operating models often fail because responsibility is described in job titles rather than decisions. A global chief compliance officer may set a policy; a regional leader may operate a shared service; a local MLRO or compliance officer may own regulatory engagement; a product executive may own a customer journey; a technology team may own a platform; and a country head may be accountable for the legal entity. Unless the enterprise defines which person decides, approves, performs, challenges, escalates, and evidences each material step, every role can reasonably assume another team owns the problem.
The RACI should be tied to named services and events: new product launch, material market change, policy interpretation, customer acceptance, sanctions hold, suspicious-activity reporting, exception approval, data outage, platform release, supplier incident, regulatory examination, backlog breach, and remediation closure. It should identify retained accountability as well as delegated activity. A shared service manager can be responsible for review quality and service level; the local entity can still be accountable for what action follows. A group data team can manage the contract; the market can still be accountable for the lawful use and completeness of local source data.
The EBA's compliance-officer guideline and other official governance materials do not create one universal organizational chart. They are useful reminders that AML/CFT governance requires appropriate authority, independence, information access, resources, and escalation. An entity should not allow a matrix structure to make its accountable compliance owner a passive recipient of group reporting. [S06][S08][S09][S10][S11]
Enforcement Lens: Complex Group Structures Do Not Excuse Control Blindness
The U.S. Department of Justice's 2022 Danske Bank release describes a resolution involving conduct connected to the bank's Estonian branch. It is used here as a bounded global-governance lesson: cross-border products, branches, subsidiaries, correspondent relationships, and group reporting lines need a demonstrable chain of oversight, escalation, and challenge. A local market cannot become invisible because it is organizationally distant. [S12]
2. Operator Layer: Turn the Model Into a Service Catalog and Decision Map
2.2 Decision rights should be fast enough for risk and visible enough for challenge
A decision map should cover predictable tension points. Who can interpret a new local requirement? Who approves a local rule threshold? Who decides that a global product cannot launch in a market? Who can authorize an emergency sanctions hold or fraud block? Who can disclose information to a group team, a public-private partnership, or a regulator? Who accepts a controlled backlog or temporary workaround? Who decides whether a remediation is complete? These questions are often answered informally until a crisis, when different teams make incompatible choices.
The map should set decision classes, required evidence, time limits, and escalation. A local law or regulator direction can require a Local Edge outcome even if it conflicts with a global preference; the local accountable officer should be able to invoke the defined escalation rather than improvise. A group standard can prohibit a market practice even where local law is silent; this should be documented through risk appetite, not asserted through technology control. Where decisions affect customers or regulatory reporting, the operator should see the authority and reason in the workflow, not discover them through e-mail chains.
Financial-crime information sharing shows why gateway design matters. FATF's 2026 overview recognizes different public-private partnership arrangements and safeguards; FinCEN's 314(b) fact sheet describes a U.S. voluntary information-sharing safe harbor framework subject to its conditions. The operating model must distinguish lawful gateways from an assumed right to share. It should preserve permissions, purpose, recipients, restrictions, and local confirmation in the case record. [S02][S07]
3. Specialist Layer: Build the Organization Around Capability, Not Silo Labels
3.1 Combine specialist depth with market knowledge
Financial-crime capability has both specialist and local dimensions. Specialist functions may need deep expertise in sanctions, correspondent banking, virtual assets, trade finance, transaction monitoring, fraud, investigations, analytics, legal interpretation, intelligence, model risk, data, reporting, or cyber-enabled crime. Markets need knowledge of local customer behavior, language, documents, payment rails, criminal typologies, law, regulator expectations, and culture. The organization should build mechanisms for both, rather than force one generalist role to carry the entire burden.
A practical design often includes global centers of expertise, regional or shared operational hubs, country or legal-entity compliance ownership, product embedded risk partners, and disciplined networks of investigators or subject-matter experts. The exact geography is less important than defined competency, access to evidence, decision rights, escalation, quality assurance, continuity, and accountability. A center of expertise should not become a remote advisory service with no operational feedback; local teams should not become isolated generalists who cannot access specialist challenge.
Workforce plans should therefore segment activities by authority and risk. Routine, well-defined, evidence-backed tasks may be safely shared or automated under quality controls. High-impact decisions, legal reporting, customer restrictions, regulator engagement, and novel risk interpretation may require local or senior specialist involvement. The capacity model should measure not only headcount, but language, jurisdictional knowledge, shift coverage, review time, approvals, absence resilience, demand volatility, training, and rework caused by weak upstream data or product design. [S06][S08][S09][S10][S11]
| Capability | Where common scale helps | Where local expertise is indispensable |
|---|---|---|
| KYC / KYB operations | Common evidence standards, tooling, QA, workload management | Local documents, registries, language, lawful data use, customer contact |
| Sanctions and screening | Shared lists, matching methods, specialist escalation | Local action authority, product/payment flow, regulator or law-enforcement response |
| Monitoring and investigations | Common scenarios, analytics, case platform, peer challenge | Local typologies, source evidence, report decision, local law and language |
| Fraud and customer harm | Shared intelligence, device/behavior analytics, 24/7 response | Local payment rails, consumer rules, reimbursement and communications |
| Regulatory engagement | Common policy, evidence, examination playbook | Local regulator relationship, disclosure, filing, remediation commitments |
3.2 Culture, incentives, and challenge are operating controls
A financial-crime operating model can look complete on paper and still fail if its incentives reward speed, growth, alert closure, cost transfer, or local silence over accurate escalation and durable remediation. Group leadership must make clear that product launch, revenue growth, and operational efficiency are constrained by the ability to identify risk, act lawfully, protect customers, and evidence the result. Local leadership must be able to surface inconvenient risk without being judged as resistant to central transformation. Shared-service leadership must be accountable for quality and capacity, not only unit cost.
Challenge should be structured. The first line owns product and process control. Compliance or financial-crime second line provides independent oversight and may own regulated responsibilities depending on the jurisdiction. Internal audit supplies independent assurance. Legal, privacy, cyber, technology, data, HR, procurement, and finance each have relevant roles; their presence does not replace the control owner. A group committee should hear material cross-market risks, while a local committee should hear local risk, performance, incidents, regulatory matters, and exceptions. The committees need compatible information and a route for matters that cannot be resolved locally.
Learning must travel both ways. Local incidents, intelligence, regulator feedback, emerging typologies, customer complaints, data problems, and enforcement themes should shape Global Core services and standards. Global testing, assurance, and cross-market comparison should challenge local optimism. If group reports only extract metrics upward and never return improvement or specialist support to the market, the model becomes extractive rather than effective. [S01][S02][S03][S06]
Enforcement Lens: Growth and Operational Pressure Require Real Challenge
FinCEN's TD Bank action and the FCA's Starling Bank action are used as limited reminders that growth, scale, systems, resources, governance, and escalations are linked. They do not prescribe one model. They show why senior leaders should seek evidence that a global or shared model can handle the actual risk and volume reaching each market. [S13][S14]
4. Market Accountability: Local Legal Truth, Regulatory Engagement, and Customer Consequence
4.1 Market accountability must be explicit at the point of action
Global management often has the best aggregate view of risk, while local teams have the closest view of the legal entity, customer, product, regulator, and operational consequence. The operating model should join those views at the point of action. A case, product approval, policy exception, incident, report, or remediation should identify the market, legal entity, local accountable owner, relevant global service, local legal basis or constraint, affected population, required action, reporting or communication responsibility, and escalation contacts.
This is particularly important where an action cannot be taken centrally. A local entity may need to file a report, make a regulatory notification, place an account restriction, decide an enhanced-due-diligence outcome, respond to law enforcement, communicate with a customer, or retain records in a prescribed way. A global team may supply evidence, methodology, specialist advice, or a platform, but should not obscure the local authority. Conversely, local ownership should not block group visibility of material risk, systemic issue, cross-border network, or customer harm. The design needs a lawful evidence package that allows escalation without forcing every raw record across the group.
Country or entity financial-crime officers need access to the information, staff, and governance forums needed to discharge their responsibilities. They should receive relevant performance, exceptions, data-quality concerns, serious incidents, supplier changes, product changes, audit findings, and remediation status. They should be able to challenge a group service and trigger a defined response. A title without access, authority, or evidence is not accountability. [S04][S06][S09][S10][S11]
| Event | Global responsibility | Local market responsibility | Evidence retained |
|---|---|---|---|
| New product / market | Common standards, risk expertise, platform/service assessment | Legal applicability, customer/product risk, local approval and regulator engagement | Risk assessment, decision record, conditions, launch test |
| Material alert / investigation | Shared analytics, specialist support, consistent case method | Local evidence, decision, reporting, restriction, communication | Sources, analysis, authority, filing/action confirmation |
| Data or service outage | Common incident coordination, vendor/escalation support | Local impact assessment, contingency, customer/regulator actions | Population impact, workaround, reconciliation, closure validation |
| Policy conflict | Group baseline and risk appetite | Local legal interpretation and proposed overlay | Conflict record, advice, decision, approval, review date |
| Examination / enforcement matter | Group evidence coordination and executive oversight | Local regulator relationship, response and commitment | Request log, response, commitments, remediation proof |
4.2 Local overlays must have a lifecycle and a sunset test
A local overlay can be necessary and healthy. It can also become a durable workaround after a legal change, platform limitation, resource shortage, or historical preference has disappeared. The enterprise should therefore treat local overlays as controlled objects. Each should identify the global standard, local reason, legal or risk source, products and population, data or configuration difference, owner, approval, testing, monitoring, start date, review date, service impact, and retirement condition. A central exception register alone is insufficient if country teams cannot challenge an entry or if it is not connected to the actual system configuration and workflow.
The review should ask hard questions. Is the local requirement still current? Does it apply to all the stated products or only some? Is the variation genuinely legally required, or could Global Core deliver a better common feature? Does it create an evidence gap, customer inconsistency, delayed action, or cross-border blind spot? Is there a compensating control, and has it been tested? Does the market have capacity to own the variation? The answers should influence the enterprise roadmap: a repeated local overlay may signal that a global capability needs to change.
A controlled Local Edge design can also protect the firm against improper central pressure. It gives country owners a formal way to say that a product, data use, automation, or target operating model cannot proceed without a local assessment, condition, or alternative. This protects customers and regulators while giving group leadership a visible, evidence-based decision rather than a hidden delay.
Supervisory Lens: The Program Must Fit the Entity and Its Actual Risk
AUSTRAC's guidance on AML/CTF programs and selected UK, Singapore, and U.S. supervisory materials are different in legal form. They support a common operating insight: a program must be tailored to the business, legal framework, and risk it actually faces. A group template is valuable only when it is demonstrably applied and adapted under accountable local governance. [S08][S09][S10][S11][S15]
5. Governance Layer: Measure the Model, Resolve Tension, and Allocate Resources
5.1 Management information needs common metrics and local meaning
Common management information allows the group to compare control performance, identify concentration, allocate specialist support, and challenge anomalous results. It should include scope and population, customer and transaction risk, screening and monitoring coverage, alert/case flow, aged high-risk work, reporting timeliness, quality assurance, action completion, data and system incidents, vendor performance, local overlays, policy exceptions, training/competency, audit findings, and remediation. However, a metric is meaningful only with its local denominator and context. A country with a different payment rail, customer mix, regulatory threshold, language, product, or investigative process should not be judged solely against a global average.
The data model should permit enterprise comparison while retaining local explanations. A global alert closure rate should be accompanied by risk stratification, reopen rates, QA outcomes, case population, rule/model version, backlog, action type, and local legal process. A decline in reports may be positive, negative, or simply a data issue. A lower cost per case may reflect better workflow or a dangerous transfer of work to an unmeasured local team. Management should ask what changed in the population, service, data, policy, product, staff, and risk—not simply whether a traffic light is green.
BCBS 239 is a useful governance discipline because it emphasizes accurate, complete, timely, and adaptable risk data and reporting. The Global Core should provide common definitions and controls; Local Edge should certify the local population, exceptions, limitations, and actions. The result is a credible single view with visible uncertainty rather than a falsely uniform dashboard. [S03][S06][S08]
| MI layer | Group needs to see | Local owner must explain |
|---|---|---|
| Scope and coverage | In-scope population, missing feeds, excluded products/entities | Why an exclusion exists, duration, compensating control, remediation |
| Operations and quality | Work volumes, ageing, QA, rework, service levels | Risk priority, language/market effects, action bottlenecks, staffing |
| Risk and outcomes | Trends, typologies, reports, customer harm, losses, sanctions/fraud action | Local legal thresholds, regulatory context, product/customer drivers |
| Change and dependency | Releases, vendor incidents, data changes, local overlays | Impact assessment, approval, testing, fallback, closure evidence |
| Governance | Issues, exceptions, audit findings, open commitments | Accountable owner, due dates, residual risk, escalation and regulator communication |
5.2 Resource allocation is a risk decision, not a budgeting afterthought
A global model must allocate scarce specialists, technology capacity, and management attention according to risk and legal requirement, not merely revenue or cost-center preference. The annual plan should link country and enterprise risk assessments to demand forecasts, control changes, customer growth, new products, regulatory commitments, remediation, data and technology investment, and contingency capacity. It should identify no-single-point-of-failure roles, language gaps, time-zone coverage, critical outsourced services, and the capacity needed for spikes such as sanctions events, fraud waves, law-enforcement requests, or system remediation.
Funding should also follow ownership. If a central service is expected to support a local legal entity, the service catalog should describe what it provides and what the market must fund or retain. If a local overlay is necessary, the cost and risk should be visible rather than silently absorbed by an operations team. If a global platform does not meet a local requirement, the decision whether to build, buy, accept residual risk, restrict the product, or exit the market should be made at the right governance level with evidence.
Resource risk often presents as a quality problem: rushed investigations, incomplete evidence, ageing work, weak oversight, failure to test, over-reliance on vendor support, or reluctance to escalate because no one can absorb the work. These are not merely efficiency matters. They are indicators that the operating model does not match its risk. [S01][S06][S08][S13][S14]
Executive Lens: Force the Trade-off Into the Open
When a market lacks capacity or a global service cannot meet a local requirement, the organization should make an explicit choice: add resources, change the service, restrict the product/population, introduce a time-bound compensating control, accept governed residual risk where permissible, or stop the activity. Leaving the issue in a backlog is not a neutral option. This is a library operating recommendation. [S01][S03][S06]
6. Assurance Layer: Test Whether the Operating Model Works in Practice
6.1 Test the full cross-border path, not the org chart
Operating-model testing should start with real journeys. Select a customer, beneficial owner, payment, alert, case, suspicious activity, sanctions event, fraud incident, product launch, data defect, supplier outage, or regulator request that crossed a group-market boundary. Trace the scope, source data, legal permission, global service, local overlay, analyst or decision maker, action, evidence, reporting, and escalation. Ask whether the process was timely, complete, lawful, understandable, and recoverable. The test will reveal gaps that RACI charts hide: a local user cannot access a global case; a shared service lacks a language capability; a platform excludes a product; a global policy change was not locally implemented; an alert requires a local action but no one owns it overnight.
Testing should be segmented by market and risk. Group controls may perform strongly in large markets and weakly in small or newly acquired entities. An organization may centralize one function successfully but struggle with a different product or reporting regime. The assurance approach should compare the design intent with the actual configuration, work allocation, population, sample evidence, local law/policy overlay, and outcome. It should include adverse scenarios, such as a regional outage, urgent sanctions event, surge in fraud, conflict in legal interpretation, data transfer restriction, loss of a key country officer, or regulatory demand for a local evidence package.
The result should be a specific issue or a verified control conclusion, not a vague statement that the model is "globally aligned." Evidence-led alignment means the enterprise can prove the shared standard, local adaptation, accountable decision, and outcome in the tested case. [S01][S03][S04][S06][S08]
| Test | Question | Evidence of a pass |
|---|---|---|
| Applicability test | Was the global policy/service correctly mapped to the local entity, product, and obligation? | Local assessment, approved overlay, configuration and training evidence |
| Population test | Did every intended local record reach the group/shared control? | Expected/received reconciliation, exceptions, historic remediation |
| Decision-rights test | Could the right person act and escalate at the required time? | Workflow, authority, time stamps, action confirmation, escalation record |
| Evidence test | Can the group and local entity explain the same decision from lawful records? | Source package, permissions, analysis, local action/reporting proof |
| Resilience test | Can global/local services continue or fail safely together? | Contingency run, communication, manual work, recovery and reconciliation |
| Challenge test | Did local and global oversight identify and resolve a material tension? | Minutes, issue/exception record, advice, decision, monitoring |
6.2 Mature operating models learn and rebalance
A low-maturity global program distributes a policy and measures attestation. A workflow-led program centralizes some operations but cannot show why local differences exist or whether service coverage is complete. A control-led program has mapped services, decision rights, local overlays, risk data, escalation, and quality measures. An evidence-led program can select any material market journey and demonstrate its group standard, local legal application, input data, decision authority, action, evidence, issue history, and recovery path. It also uses that evidence to improve the model.
Maturity requires a learning loop. Repeated local exceptions should influence the global roadmap. Recurrent data or service defects should be investigated across markets. Regulatory feedback should be shared in a controlled way. Group assurance should identify where the common model is not usable locally; local issues should be elevated when they indicate a systemic design weakness. Talent and funding should move toward demonstrated risk and control gaps, not only toward the loudest business sponsor.
The objective is not uniformity. It is consistent accountability and evidence across different markets. When the model is mature, employees know what is globally mandatory, what may be adapted, who can decide, how to request an exception, how to escalate a conflict, and how to prove that a real customer or transaction received a lawful and effective control outcome.
Maturity Lens: Global Consistency With Local Truth
A mature group can be globally comparable without forcing fiction into local processes. It maintains common capability, taxonomy, evidence, testing, and challenge; it makes local legal and operational truth visible; and it assigns decision and action to people with genuine authority. That is the practical promise of Global Core / Local Edge. [S01][S03][S04][S06]
What Good Looks Like, What Fails, and Why
A document-led model has a global policy and country attestations but little proof of actual scope, authority, or action. A workflow-led model has shared services and local teams but relies on informal relationships to resolve conflicts. A control-led model maps services, legal entities, decision rights, data, local overlays, measures, and escalation. An evidence-led model can demonstrate any material end-to-end journey through the group and market, including what was globally standard, what was locally adapted, who acted, and how a failure was corrected.
The objective is not to make every market identical. It is to make global capability and local accountability equally visible. That allows a board, regulator, auditor, customer-protection team, or internal investigator to see where risk is truly owned and whether the organization can act before harm becomes a cross-border enforcement issue.
Common Misconceptions and Contrarian Insights
- Global Core means central headquarters owns every decision: Global Core owns the common capability and standard; Local Edge retains lawful market judgment and accountable action.
- Local Edge is permission to customize freely: Local variation must be justified, approved, tested, monitored, and retired when no longer needed.
- A shared service transfers legal-entity accountability: A service can perform work, but the entity and its accountable officers retain required oversight and action responsibilities.
- One global metric is automatically comparable: Metrics require local population, legal threshold, product, language, and workflow context.
- A RACI is enough: Decision rights must be embedded in services, workflows, evidence, escalation, capacity, and governance forums.
- Centralization always reduces cost and risk: It can create scale and consistency, but also new data, language, capacity, resilience, and action-authority gaps.
Executive Discussion Questions
- Which financial-crime outcomes and evidence standards are genuinely global, and which require a formal local overlay?
- For each critical service, who is accountable at enterprise, service, legal-entity, market, product, and customer-action levels?
- Can we trace a material customer, transaction, or incident from global policy through local legality to final action and evidence?
- Which local variations are legally necessary, which are risk-based choices, and which are accumulated convenience debt?
- Does every shared service have a service catalog, population scope, decision boundary, service level, evidence output, resilience plan, and exit route?
- What local constraints—data, language, reporting, payment rail, customer treatment, regulator engagement—can make a global design ineffective?
- How do we know that central monitoring, screening, or investigation coverage is complete in every market and product?
- What authority does a local MLRO/compliance officer, country leader, or product owner have to challenge a global launch or service design?
- Which management metrics compare performance credibly, and which need market-level denominators and narrative?
- Where do incentives or cost allocation encourage risky closure, under-escalation, or hidden local workarounds?
- Can we respond coherently to a cross-border issue while preserving local legal requirements and local regulator relationships?
- Do our staffing and specialist models cover language, local law, shifts, approvals, surge capacity, and no-single-point-of-failure risk?
- What proves that remediation is owned and effective at both group and local levels rather than simply closed centrally?
Practitioner and Specialist Checklists
Executive Operating-Model Checklist
- Define the enterprise financial-crime outcomes, group minimum standard, risk appetite, prohibited practices, and evidence required across all legal entities.
- Approve a service-by-service Global Core / Local Edge allocation with named enterprise, service, legal-entity, and market accountability.
- Require material centralization, outsourcing, product, platform, and market changes to include local applicability, data, action-authority, and regulator-engagement assessment.
- Review country and service performance with population, risk, quality, customer, data, capacity, resilience, and issue context.
- Fund local legal, language, reporting, investigative, and continuity capability where common services cannot safely replace it.
- Escalate and decide cross-border conflicts through a documented authority rather than informal hierarchy.
Operator Service and Market Checklist
- Maintain a service catalog with scope, input/output, decision/action boundary, legal entities, owners, local dependencies, service level, evidence, fallback, and escalation.
- Map every material workflow from group standard to local configuration, local user/decision maker, action channel, report, and evidence retention.
- Maintain approved local overlays and exception records with reason, owner, test, review date, monitoring, and retirement condition.
- Reconcile in-scope populations by legal entity, product, market, and data source; explain exclusions and delayed records.
- Train staff on their actual authority, local escalation, information-sharing gateway, customer-treatment, and regulator-engagement responsibilities.
- Surface capacity, language, access, backlog, quality, local regulatory, and service-dependency concerns before they become a hidden workaround.
Specialist Assurance Checklist
- Test customer, transaction, alert, report, data, change, incident, and supplier journeys across global and local boundaries.
- Compare policy, legal applicability, configuration, population, case evidence, action confirmation, and local report/communication in samples.
- Validate role competence, access, independence, workload, approvals, shift coverage, and ability to challenge or stop a process.
- Segment MI by market, entity, product, language, risk, rule/model version, and local overlay; avoid undifferentiated averages.
- Review recurring local exceptions for promotion to Global Core capability or controlled retirement.
- Verify that group and local remediation records align on scope, owner, evidence, residual risk, regulatory commitments, and closure validation.
Module Glossary
Accountable action. A decision or operational act made by a person or permitted function with authority, evidence, and responsibility for its consequences.
Applicability assessment. A documented determination of how a global standard, legal requirement, policy, product, or service applies to a local entity or market.
Control owner. The named person accountable for a control's design, operation, monitoring, evidence, and remediation.
Delegation. Assignment of an activity or decision authority under a defined mandate while retained accountability and oversight remain clear.
Global Core. The reusable enterprise standard, capability, evidence, and governance framework shared across markets.
Legal-entity accountability. Responsibility of an entity and its accountable officers for applicable obligations and its actual customer, product, and market risk.
Local Edge. The controlled local adaptation, legal interpretation, data/use boundary, and accountable action needed in a market.
Local overlay. An approved and tested market-specific requirement, configuration, process, data use, or evidence pattern layered on the Global Core.
Operating model. The arrangement of people, decision rights, processes, services, systems, evidence, and governance used to deliver outcomes.
Population reconciliation. Comparison of records expected to enter a service or control with those received, processed, excepted, and resolved.
RACI. A role map identifying who is responsible, accountable, consulted, and informed for a decision or activity.
Service catalog. A controlled description of a service's customer, scope, owners, inputs, outputs, evidence, levels, dependencies, and fallback.
Shared service. A capability performed for more than one entity or market under defined scope, performance, governance, and evidence.
Tension escalation. The controlled process for resolving a conflict between global standard, local legal obligation, risk appetite, capability, or market action.
Workaround debt. Accumulated informal local processes or exceptions that obscure scope, reduce evidence, and increase change and assurance risk.
MLA 9 Works Cited
[S01] Financial Action Task Force. "The FATF Recommendations." 2025 consolidated text, https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html. Accessed 9 Aug. 2026.
[S02] Financial Action Task Force. "Information Sharing to Combat Illicit Finance: Global Overview of Public and Private Sector Partnerships and Data Protection Arrangements." July 2026, https://www.fatf-gafi.org/content/dam/fatf-gafi/reports/information-sharing-ppp-data-protection-arrangements-2026.pdf.coredownload.inline.pdf. Accessed 9 Aug. 2026.
[S03] Basel Committee on Banking Supervision. "Principles for Effective Risk Data Aggregation and Risk Reporting (BCBS 239)." Jan. 2013, https://www.bis.org/publ/bcbs239.htm. Accessed 9 Aug. 2026.
[S04] European Union. "Regulation (EU) 2024/1624 on the Prevention of the Use of the Financial System for the Purposes of Money Laundering or Terrorist Financing." 31 May 2024, https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng. Accessed 9 Aug. 2026.
[S05] European Union. "Regulation (EU) 2024/1620 Establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism." 31 May 2024, https://eur-lex.europa.eu/eli/reg/2024/1620/oj/eng. Accessed 9 Aug. 2026.
[S06] European Banking Authority. "Guidelines on the Role and Responsibilities of AML/CFT Compliance Officers." 14 June 2022, https://www.eba.europa.eu/sites/default/files/document_library/Publications/Guidelines/2022/EBA-GL-2022-05%20GL%20on%20AML%20CFT%20compliance%20officers/Translations/1207548/Final%20Report%20on%20Guidelines%20on%20AML%20CFT%20compliance%20officers.pdf. Accessed 9 Aug. 2026.
[S07] Financial Crimes Enforcement Network. "Section 314(b) Fact Sheet." Dec. 2020, https://www.fincen.gov/sites/default/files/shared/314bfactsheet.pdf. Accessed 9 Aug. 2026.
[S08] Federal Financial Institutions Examination Council. "Bank Secrecy Act/Anti-Money Laundering Examination Manual." current page accessed 2026, https://bsaaml.ffiec.gov/manual. Accessed 9 Aug. 2026.
[S09] Financial Conduct Authority. "Financial Crime." current page accessed 2026, https://www.fca.org.uk/firms/financial-crime. Accessed 9 Aug. 2026.
[S10] Monetary Authority of Singapore. "Notice 626: Prevention of Money Laundering and Countering the Financing of Terrorism." current page accessed 2026, https://www.mas.gov.sg/regulation/notices/notice-626. Accessed 9 Aug. 2026.
[S11] Australian Transaction Reports and Analysis Centre. "AML/CTF Programs." current page accessed 2026, https://www.austrac.gov.au/business/how-comply-and-report-guidance-and-resources/amlctf-programs. Accessed 9 Aug. 2026.
[S12] U.S. Department of Justice. "Danske Bank Admits to Defrauding U.S. Banks and Agrees to Forfeit $2 Billion." 13 Dec. 2022, https://www.justice.gov/opa/pr/danske-bank-admits-defrauding-us-banks-and-agrees-forfeit-2-billion. Accessed 9 Aug. 2026.
[S13] Financial Crimes Enforcement Network. "FinCEN Assesses $1.3 Billion Penalty Against TD Bank for Widespread and Systemic Violations of Bank Secrecy Act." 10 Oct. 2024, https://www.fincen.gov/news/news-releases/fincen-assesses-13-billion-penalty-against-td-bank. Accessed 9 Aug. 2026.
[S14] Financial Conduct Authority. "FCA Fines Starling Bank for Failings in Financial Crime Systems and Controls." 2 Oct. 2024, https://www.fca.org.uk/news/press-releases/fca-fines-starling-bank-failings-financial-crime-systems-and-controls. Accessed 9 Aug. 2026.
[S15] Australian Transaction Reports and Analysis Centre. "AUSTRAC Commences Civil Penalty Proceedings Against Westpac." 20 Nov. 2019, https://www.austrac.gov.au/news-and-media/media-release/austrac-commences-civil-penalty-proceedings-against-westpac. Accessed 9 Aug. 2026.