Fraud and Financial Crime · Session Eight
Building and Running the Financial Crime Programme
Programme architecture, governance, three lines of defence, policies, due diligence, training, monitoring, MI and audit. What a working programme looks like across the four offence areas.
Disclaimer
This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation.
Session Eight: Building and Running the Financial Crime Programme
The risk assessment defines the problem. The programme is the response. This session turns the risk assessment from Session Seven into a working programme for fraud, bribery and corruption, market abuse where relevant, and money laundering and terrorist financing where relevant.
This is what organisations are judged on. Not the policies on the shelf, but whether the controls work, who applies them, who monitors them, and who fixes them when they fail. The architecture is recognisable across organisations and offence areas. The discipline lies in making it work in practice.
Who this session is for. Compliance officers, MLROs, financial crime leads, second line risk teams, internal audit, senior managers with programme oversight, board members reviewing programme reporting, and transformation teams building or remediating the framework.
The programme architecture
A functioning financial crime programme has six components. They are not a sequence to complete. They are a system that must work together.
| Governance | The board and senior management framework that owns the programme. Top-level commitment, named accountability, programme reporting, board engagement, and the link between programme outputs and senior manager responsibilities. |
| Policies and procedures | The documented standards that translate the risk assessment and the regulatory framework into operational instructions. Calibrated to the role, accessible where it is needed, written for use rather than display. |
| Due diligence | The screening and risk assessment processes applied to customers, counterparties, employees and associated persons. The depth of review is calibrated to risk, refreshed periodically and updated when trigger events occur. |
| Training and communication | The activity that turns policies into capability. Training is differentiated by role, refreshed periodically and tested for understanding, not only for completion. |
| Monitoring and detection | The systems and human processes that identify exceptions to the expected pattern, including transaction monitoring, surveillance, gifts and hospitality reviews, exception reports and whistleblowing channels. |
| Review, audit and MI | The mechanisms that test whether the programme is working, including internal audit, second line assurance, management information and board reporting. This is the feedback loop that keeps the programme accountable. |
Governance and senior management
Top-level commitment appears first in statutory failure to prevent guidance for a reason. Without it, the programme does not hold. Senior management owns the risk, the response and the consequences.
In a UK regulated firm, governance will usually be allocated in a familiar way. The board approves the financial crime risk appetite, the firm-wide risk assessment and the programme designed to address the assessed risks. A board committee, often audit and risk, receives regular reporting and provides more detailed oversight. The senior manager holding SMF16, and in many firms SMF17, carries day-to-day accountability for the framework. Other senior managers remain accountable for risk and control in their own areas.
Outside the regulated sector, the structure is usually similar even where the SMCR labels do not apply. There should still be a named board-level owner, a senior manager with day-to-day responsibility, clear allocation of ownership across business lines and a documented reporting line. That matters in any organisation. It matters even more now that the senior manager attribution model has moved from a listed economic crime model under section 196 of the Economic Crime and Corporate Transparency Act 2023 to the broader statutory attribution route in section 250 of the Crime and Policing Act 2026.
The three lines
Most organisations operate the three lines model in some form. For the financial crime programme, the lines do specific work.
The first line is the business. It owns the risk, applies the controls, makes the customer-facing decisions, exits the relationships that cannot be managed. First line ownership of financial crime is not a compliance fiction; it is the reality that controls only work where the people closest to the risk apply them. A first line that treats financial crime as a compliance problem is a first line that is not managing the risk.
The second line is the financial crime function. It designs the framework, sets policy, sets standards, oversees the application of those standards, provides advice on complex cases, and reports to senior management. It does not own the risk on the business's behalf. It owns the framework. In supervised firms, the second line is the natural home of the MLRO function and the compliance oversight function.
The third line is internal audit. It provides independent assurance to the board on the effectiveness of the framework, the operation of controls, and the credibility of management's representations. The third line tests both the first and the second lines.
The most common breakdown in this model is the first line not owning what it should, and the second line ending up running the controls rather than overseeing them. Both compromise the integrity of the system.
Policies and procedures
Policies exist to translate the risk assessment and the regulatory framework into operational instructions. Done well, they tell people what to do, how to do it, when to escalate and when to walk away. Done badly, they sit unread on an intranet.
Three features distinguish a working policy framework from a performative one.
First, the policies are role-calibrated. A policy on customer due diligence written for the AML team is not the same document as the procedure that customer-facing staff actually follow. The framework needs a hierarchy: high-level policy approved by the board, supporting standards approved at senior management level, and operational procedures that drive day-to-day work.
Second, the policies are accessible. They are searchable. They are written in plain English. They are referenced in the systems people actually use. If a policy takes too long to find, it will not be used.
Third, the policies are kept current. Each policy needs a named owner, a review cycle and a process for updating it when legislation, guidance or the business changes. A framework that cannot show active maintenance will not be treated as adequate.
Due diligence
Due diligence is the operational front line of the programme. It is where the framework meets the customer, counterparty, employee or associated person, and produces a documented decision.
Three categories of due diligence appear across the offence areas.
Customer and counterparty due diligence
For AML purposes, customer due diligence is set out in regulations 27 to 38 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 and covered in detail in the AML Compliance course. Outside AML, the equivalent work includes sanctions screening, PEP screening, adverse media screening, credit checks where relevant, and broader know-your-counterparty work that informs the relationship. The depth of the diligence should match the risk identified in the risk assessment.
Associated person due diligence
This is the diligence on which the failure to prevent regimes turn. Agents, consultants, distributors, joint venture partners, higher-risk suppliers and others performing services for or on behalf of the organisation may all fall within scope. The diligence should be proportionate to risk. For higher-risk associated persons, verified ownership information, integrity checks, a clear understanding of the commercial rationale for the engagement and a documented decision on whether the relationship should proceed are all appropriate.
In practice, this is where the gap most often appears. Procurement runs a standard onboarding check. Financial crime is not brought in. The contract is signed. Later, when the issue surfaces, no one can show who approved the relationship or on what basis. The records do not support a defence built on reasonable or adequate procedures because the diligence was never designed for that purpose.
Employee due diligence
This covers pre-employment screening, monitoring in role for relevant populations, and periodic refresh. For roles with significant financial crime exposure, such as payment authorisation, financial reporting, higher-risk customer activity or privileged systems access, the screening should be deeper. The senior manager attribution model makes senior management screening and ongoing monitoring more important, not less.
Training and communication
Training turns policy into capability. Regulation 24 of the MLR 2017 requires it for AML purposes. Statutory failure to prevent guidance treats communication and training as core elements of an effective framework. The FCA's Financial Crime Guide assumes it. A senior manager cannot credibly oversee a programme that the business has not been equipped to run.
Three features of a working training programme are worth highlighting.
First, the training is role-calibrated. A finance team in head office does not need the same training as a sales team in an emerging market. A board director does not need the same training as a customer service representative. Generic mandatory training applied uniformly to every employee is one of the most reliable indicators of a programme that has chosen volume over effect.
Second, the training tests understanding. Completing a module is not the same as understanding what to do in a realistic scenario. Scenario-based testing, periodic refreshment and structured assessment for high-risk populations all matter.
Third, training is supported by communication. Training is periodic. Communication is continuous. Tone from the top, business-line messages, case discussions and short internal updates keep financial crime visible between formal sessions.
Monitoring and detection
Monitoring and detection is where the programme tests itself in practice. The systems and human processes that identify the cases that did not match the expected pattern.
Across the four offence areas, monitoring takes different forms.
| AML transaction monitoring | Automated and manual monitoring of customer transactions against typologies and customer-expected behaviour. Coverage, calibration, false-positive management, alert quality and SAR pipeline are the standard supervisory testing areas. |
| Market surveillance | Order and trade surveillance against market abuse typologies. STORs filed where reasonable suspicion is established. Cross-reference to wall crossing records and inside information project lists. |
| Payments and fraud surveillance | Detection of fraudulent payment patterns. Authorised push payment scams. Identity fraud. First-party fraud. The detection layer that supports the controls expected of regulated firms under PSR rules and FCA expectations. |
| Gifts, hospitality and conflicts registers | The active use of the gifts and hospitality register, the conflicts of interest register, and related disclosures. Reviewed by someone with authority and inclination to question what they see. |
| Whistleblowing | The independent channel for raising concerns. Anonymous reporting routes, protected disclosure, escalation to the board. Often the single most important detection mechanism for senior manager misconduct. |
| Exception reports | The recurring management information that flags departures from expected patterns: outliers, threshold breaches, override patterns, approval patterns. The first line of detection in many parts of the programme. |
The principle that runs across all of these is the same. A monitoring system that produces alerts which are not actioned consistently is worse than no monitoring at all, because it generates the evidence trail of unmanaged risk. The test of the monitoring layer is what happens to alerts, not what alerts are generated.
MI, audit and the closing of the loop
Management information closes the programme loop. The board cannot exercise oversight without it. The senior managers cannot meet their accountability without it. The supervisors cannot test the programme without it.
Good financial crime MI has four features. It is timely, presented soon enough after the period to inform decisions. It is calibrated, with the volume, level of detail and choice of metric suited to the audience. It is contextualised, with numbers presented alongside trend, peer comparison where available, and narrative interpretation. And it is actionable, with each report ending in a clear view of what is being done about what the data shows.
Internal audit provides the third line assurance. The standard cycle for a financial crime audit programme covers governance and the firm-wide risk assessment, customer onboarding and CDD, transaction monitoring and SARs, or the equivalent for non-AML offences, training and communication, third party due diligence, sanctions and PEP screening, gifts and hospitality, and the programme management information itself. Each component should be tested on a risk-based cycle, with findings tracked through to remediation.
Records are the evidence. Whatever the programme does, it must be capable of being shown to have done it. Customer files, third party files, training records, monitoring outputs, audit reports, board minutes, senior manager attestations: all of these together are the documented basis on which the organisation can demonstrate that its programme is adequate, reasonable, or whatever the relevant standard requires.
Programme maturity
Financial crime programmes do not arrive fully formed. They develop over time. A useful way to think about the trajectory is in three stages.
Compliance stage. The organisation has identified the regulatory obligations, written policies that meet them, completed training, and put in place baseline controls. The programme exists. The evidence is on paper.
Operational stage. The programme is being used. People know what to do. Controls are operating. Monitoring produces alerts that are actioned. The MI reaches the board. Internal audit tests the framework. The evidence is in records.
Embedded stage. Financial crime control is part of how the business actually thinks and operates. Senior managers ask the right questions. Business heads escalate the right cases. Front line staff exit the relationships that cannot be managed. The risk culture supports the framework rather than working around it. The evidence is in behaviour.
Few organisations are embedded across every offence area. Many are mixed: mature in AML, less mature in fraud, and still strengthening their response to the newer failure to prevent model. That is realistic. The task is to know where the gaps are and close them on a defensible timetable.
Jurisdiction equivalents
New Zealand
The Anti-Money Laundering and Countering Financing of Terrorism Act 2009 requires reporting entities to maintain an AML/CFT programme under section 56. The Act's programme requirements, including section 57, and supervisor guidance set out the expected content and operation of that programme. In practice, the same core elements appear: risk assessment, policies and procedures, customer due diligence, ongoing monitoring, suspicious activity reporting, record keeping, and a designated compliance officer. Outside the AML/CFT regime, programme expectations are shaped by sector regulation and established good practice.
Australia
Australia's Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 require reporting entities to maintain a risk-based programme covering due diligence, monitoring, training, reporting and record keeping. AUSTRAC supervises the regime. Current reforms have expanded the regime to additional higher-risk sectors on a staged timetable. AUSTRAC guidance and implementation material are therefore the main practical reference point for firms building or updating their programmes.
Key takeaways
- A working financial crime programme has six components: governance, policies and procedures, due diligence, training and communication, monitoring and detection, and review/audit/MI. They are a system, not a sequence.
- Top-level commitment is the foundation. The board and senior management own the risk and the response. Section 196 of ECCTA 2023 introduced a listed economic crime attribution model; section 250 of the Crime and Policing Act 2026 provides the broader statutory attribution route.
- Policies have to be role-calibrated, accessible and current. A policy that is not read or applied is not an effective control.
- Due diligence is the operational front line. Customer and counterparty diligence, associated person diligence under the failure to prevent regimes, and employee diligence calibrated to role.
- Training is differentiated, tested for understanding, and supported by ongoing communication. Generic uniform training across the workforce is a sign of a programme that has chosen volume over effect.
- Monitoring works only if the alerts are actioned. MI works only if it is timely, calibrated, contextualised and actionable. Internal audit closes the loop. Records are the evidence.
Coming up in Session Nine
Session Nine is the implementation summary. A consolidated obligations checklist drawing on the whole course, cross-referenced to the underlying legislation and guidance. It is designed as a working reference for compliance officers and senior managers building or testing their programme, and as a self-assessment tool for any organisation that wants to take a structured view of where it sits.
Further reading and resources
The following primary sources are the most useful companions to this session. All are publicly available.
- FCA Financial Crime Guide. The FCA guide is the single most useful UK regulatory source for programme design in supervised firms.
- Ministry of Justice guidance under section 9 of the Bribery Act 2010. The six principles in full.
- HMRC guidance on the Criminal Finances Act 2017 corporate offences. The statutory guidance on prevention procedures for the corporate offences of failure to prevent the criminal facilitation of tax evasion.
- Home Office guidance on the failure to prevent fraud offence. The statutory guidance on reasonable fraud prevention procedures.
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. Available at legislation.gov.uk.
- JMLSG Guidance, Parts I and II. Available at jmlsg.org.uk.
- FCA Handbook, SYSC 6 and related sourcebooks. The starting point for governance and programme design in the regulated sector.
- Joint SFO-CPS Corporate Prosecution Guidance. A practical enforcement reference when programme design is tested in an investigation or prosecution.
- ISO 37001 and ISO 37301. International standards for anti-bribery management systems and compliance management systems. Available through ISO and BSI.
- AML Compliance: Legislation, Regulation and Practical Implementation. The companion course on this site. Sessions Six and Eight provide additional depth on the AML programme. Available at araitika.com.
- New Zealand. Anti-Money Laundering and Countering Financing of Terrorism Act 2009, section 56, and supervisor guidance.
- Australia. Anti-Money Laundering and Counter-Terrorism Financing Act 2006, Anti-Money Laundering and Counter-Terrorism Financing Rules 2025, and AUSTRAC reform guidance.
Ārai Tika