Session Nine: Implementation Summary

Session Nine: Implementation Summary | Ārai Tika

Fraud and Financial Crime · Session Nine

Implementation Summary

A consolidated obligations checklist across the four offence areas. The legislation, the guidance, the controls. A working reference for compliance officers and senior managers.

Course: Fraud and Financial Crime: Legislation, Regulation and Practical Implementation Reading time: around 40 minutes Jurisdictions: UK primary, with New Zealand and Australia addressed throughout

Disclaimer

This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation.

Session Nine: Implementation Summary

The earlier sessions set out the legislative framework, the four offence areas, the failure to prevent regime, the senior manager test, the risk assessment, and the working programme. This session draws those strands together into a structured implementation checklist.

The checklist is designed to be used in two ways. First, as a working reference when building or remediating a programme: a list of the core obligations and the legislation that sits behind each. Second, as a self-assessment tool: a structured way for a senior manager, compliance officer or audit team to assess where the organisation stands in practice.

The checklist is not exhaustive. The underlying statutes and guidance contain the full picture. This is a working reference, not a substitute for the source material. Where a checkpoint is engaged for a particular organisation, the right next step is to read the relevant legislation and guidance, not to rely on this summary alone.

Who this session is for. Compliance officers, MLROs, financial crime leads, senior managers, board members, internal audit, second line risk teams, in-house counsel, and others who need a consolidated view of what the programme needs to cover.

How to use this checklist

Read the checklist in two passes.

On the first pass, use it to confirm that each core requirement is covered somewhere in the programme. The legislation reference indicates where the obligation comes from. If the organisation cannot point to where it addresses the requirement, the programme has a gap.

On the second pass, use it to test whether the control works in practice. A documented policy is not the same as an applied control. A completed training module is not the same as understood capability. A populated register is not the same as a register that is reviewed and used. This second pass is where most programmes are tested.

Where the answer to either pass is not clearly yes, record the gap, give it an owner, and track it through to remediation. That tracking is part of the programme. The records are the evidence.

Part 1. Governance and senior management

Source: Bribery Act 2010, section 7, and Ministry of Justice guidance under section 9. Criminal Finances Act 2017, and HMRC guidance on the corporate offences for failure to prevent the criminal facilitation of tax evasion. Home Office guidance on failure to prevent fraud. Money Laundering Regulations 2017, regulation 21. FCA Handbook, SYSC 6.1. Economic Crime and Corporate Transparency Act 2023, section 196. Crime and Policing Act 2026, section 250.

Board-level ownership A named board director or board committee with overall accountability for the financial crime programme. Board approval of the risk appetite, the firm-wide risk assessment and the programme. Documented and minuted.
Senior management responsibility A named senior manager with day-to-day accountability for the programme. In SMCR firms, this is typically SMF16. Risk ownership is allocated across business areas to other senior managers.
Tone from the top Visible, documented commitment from the board and executive. Communications, decisions, walk-away cases all demonstrate that the leadership treats financial crime control as a priority. Not just policy statements.
Risk appetite A documented risk appetite that addresses each of the four offence areas relevant to the organisation. Approved by the board and reflected in the programme.
Senior manager mapping A documented list of the individuals who fall within the senior manager attribution provisions in ECCTA section 196 and section 250 of the Crime and Policing Act 2026, with the basis on which each qualifies.

Part 2. Risk assessment

Source: Money Laundering Regulations 2017, regulation 18. Ministry of Justice guidance, Principle 3. HMRC guidance on the corporate offences for failure to prevent the criminal facilitation of tax evasion, Principle 3. Home Office guidance on failure to prevent fraud, Principle 2. FCA Financial Crime Guide, chapters 2 and 3. HM Treasury national risk assessment material on money laundering and terrorist financing.

Firm-wide risk assessment A documented assessment covering each offence area in scope: fraud, bribery and corruption, market abuse where relevant, money laundering and terrorist financing where relevant. Inherent and residual risk, with control environment documented.
Risk dimensions Risk assessed across the common dimensions: customer/counterparty, product/service, geographic, channel, third party, and internal.
Specificity The assessment reflects the actual characteristics of the organisation, its markets, its products, its customers and its associated persons. Generic assessments will not meet the standard.
External inputs The assessment draws on relevant external sources: national risk assessments, supervisory guidance, sector typologies, enforcement actions, peer firm material.
Refresh The assessment is reviewed on a defined cadence and refreshed when triggered by material business or regulatory change.
Board approval The firm-wide risk assessment is reviewed and approved at board or appropriate senior committee level. Documented and minuted.

Part 3. Policies and procedures

Source: Money Laundering Regulations 2017, regulation 19. FCA Handbook, SYSC 6.1 and SYSC 18. Ministry of Justice guidance, Principle 2. HMRC guidance on the corporate offences for failure to prevent the criminal facilitation of tax evasion, Principle 2. Home Office guidance on failure to prevent fraud, Principle 3.

Policy framework A documented hierarchy of policy, standards and procedures covering each offence area. Board-approved policy, senior management-approved standards, operational procedures owned at the appropriate level.
Currency Each policy has a named owner, a review date, and a process for updating it. Policies are updated to reflect legislative change, commencement of relevant provisions, and material updates to official guidance.
Accessibility Policies and procedures are written in plain English, accessible to the people who need to use them, and embedded in the workflows where they apply.
Coverage Specific policies covering: anti-bribery and corruption, gifts and hospitality, conflicts of interest, anti-fraud and whistleblowing, anti-tax evasion facilitation, AML and CTF (where in scope), sanctions, market abuse (where in scope), and personal account dealing (where in scope).

Part 4. Customer due diligence and onboarding

Source: MLR 2017, regulations 27 to 38. JMLSG Guidance, Part I, Chapter 5. FCA Financial Crime Guide, chapter 3. OFSI sanctions guidance.

Risk-based CDD CDD calibrated to the risk identified in the risk assessment. SDD, standard and EDD applied consistently where the assessment supports the rating.
Beneficial ownership Identification and verification of ultimate beneficial owners. Documented assessment of the ownership structure, particularly where it is complex or opaque.
Sanctions and PEP screening Screening at onboarding and on an ongoing basis against the relevant sanctions lists and PEP databases. Documented procedures for managing alerts and false positives.
Ongoing monitoring Ongoing review of the customer relationship, with periodic refresh of CDD calibrated to risk and trigger-based update on material change.

Part 5. Associated person due diligence

Source: Ministry of Justice guidance, Principle 4. HMRC guidance on the corporate offences for failure to prevent the criminal facilitation of tax evasion, Principle 4. Home Office guidance on failure to prevent fraud, Principle 4.

Identification A documented register of associated persons within the meaning of the relevant failure to prevent regime. Distinction between standard and high-risk associated persons.
Risk-based diligence Due diligence calibrated to the risk presented by each associated person. Integrity references, ownership verification, business model plausibility for higher-risk relationships.
Approval Higher-risk associated persons subject to documented approval at the appropriate level before engagement. Compliance review embedded in the onboarding workflow.
Contracting Standard contractual provisions in place addressing anti-bribery, anti-facilitation of tax evasion, anti-fraud and information rights. Right to terminate for breach.
Ongoing monitoring Periodic refresh of associated person diligence calibrated to risk. Renewal of contractual provisions on a defined cycle.

Part 6. Training and communication

Source: Money Laundering Regulations 2017, regulation 24. Ministry of Justice guidance, Principle 5. HMRC guidance on the corporate offences for failure to prevent the criminal facilitation of tax evasion, Principle 5. Home Office guidance on failure to prevent fraud, Principle 5. FCA Financial Crime Guide.

Role-calibrated training Training differentiated by role and risk. Specific modules for high-risk populations (sales teams in high-risk markets, finance teams with payment authorisation, customer-facing roles). Board and senior management receive targeted training.
Refresher cycle Periodic refresher training on a defined cadence, typically annual for the general population, more frequent for high-risk roles.
Comprehension testing Training tests understanding, not just completion. Scenario-based assessment for higher-risk populations.
Ongoing communication Continuous communication reinforces training between formal sessions. Tone from the top, business communications, case discussions.
Coverage Training covers each offence area relevant to the organisation: fraud, bribery and corruption, tax evasion facilitation, market abuse where in scope, AML/CFT where in scope, sanctions, and the senior manager test.

Part 7. Monitoring and detection

Source: MLR 2017, regulation 19(4). POCA 2002, sections 330 to 333A. UK MAR, Articles 11, 12, 16, 17, 18 and 19. FCA Handbook, SYSC 18 and DEPP. Payment systems reimbursement requirements and related supervisory communications for firms in scope.

AML transaction monitoring Where in scope, automated and manual monitoring of customer transactions against typologies. SAR pipeline. NCA reporting workflow. Tipping-off controls.
Market surveillance Where in scope, order and trade surveillance against UK MAR Article 12 typologies. STOR reporting under Article 16. Insider list and wall-crossing controls under Articles 18 and 11.
Payments and fraud surveillance Detection of fraudulent payment patterns. APP fraud controls. Compliance with reimbursement and payment systems requirements for firms in scope.
Gifts and hospitality register Active register, accessible, actually used by the populations that should be using it, and reviewed periodically by someone with authority.
Whistleblowing Independent channel for raising concerns. Anonymous reporting option. Protected disclosure framework. Escalation to the board.
Exception reports Recurring MI flagging departures from expected patterns. Override patterns, threshold breaches, approval anomalies.

Part 8. Reporting and escalation

Source: POCA 2002, sections 330, 331 and 338. UK MAR, Article 16. Public Interest Disclosure Act 1998. FCA Handbook, SYSC 18. Joint SFO-CPS Corporate Prosecution Guidance. SFO Corporate Guidance.

SARs (where in scope) Suspicious Activity Reports filed with the NCA on the SAR Portal. DAML and DATF requests where required. Tipping-off controls maintained throughout.
STORs (where in scope) Suspicious Transaction and Order Reports filed with the FCA where reasonable suspicion is established. Internal escalation route for ambiguous cases.
Failure to prevent escalation Internal escalation route for suspected breaches of bribery, tax evasion facilitation and fraud, with a documented decision framework on self-reporting to the SFO, HMRC or other prosecutor.
Senior manager misconduct Clear escalation route, independent of the senior manager in question, for suspected misconduct that could engage senior manager attribution. A privileged investigation framework should be available at short notice.

Part 9. Record keeping

Source: MLR 2017, regulation 40. UK MAR, Articles 18 and 19. FCA Handbook, SYSC 9. UK GDPR and Data Protection Act 2018 (records retention duration).

CDD and onboarding records Customer due diligence records retained for five years from the end of the business relationship or the date of the occasional transaction, where MLR 2017 applies.
Transaction records Transaction records retained for five years where MLR 2017 applies. Equivalent records of payment authorisations, approvals and exception decisions for non-AML purposes.
Associated person records Documented diligence on associated persons, contractual provisions, periodic refresh, ongoing monitoring. Retained for the duration of the relationship and beyond, calibrated to the offence and the risk.
Training records Records of training completion, content, comprehension testing, by population. Retained for a defined period sufficient to demonstrate the historical position.
Programme records Risk assessments, programme reviews, audit reports, board minutes, senior manager attestations. The documented evidence that the programme has been operating.
Insider lists and PDMR records Where UK MAR applies, the records required under Articles 18 and 19, maintained event-by-event.

Part 10. Audit, review and assurance

Source: Ministry of Justice guidance, Principle 6. HMRC guidance on the corporate offences for failure to prevent the criminal facilitation of tax evasion, Principle 6. Home Office guidance on failure to prevent fraud, Principle 6. Money Laundering Regulations 2017, regulation 21(1)(c). FCA Handbook, SYSC 4 and SYSC 6.2.

Internal audit cycle A risk-based internal audit cycle covering each component of the programme over a defined period. Findings tracked through to remediation.
Second line assurance Second line monitoring and assurance activity that tests the operation of first-line controls. Independent of the first line.
External review Periodic external review, regulatory examination, third-party benchmarking, ISO 37001 certification audits if used, where proportionate.
Programme refresh Documented annual refresh of the firm-wide risk assessment, with material change triggers for interim refresh.
Senior management certification Annual senior management attestation that the programme is operating as designed and that residual risks are within risk appetite. Caveats documented where they apply.

The failure modes supervisors and prosecutors most often find

Across the four offence areas, supervisors and prosecutors tend to find the same failure modes. Understanding them is as useful as understanding the obligations themselves, because the gap between a compliant programme and an effective one is usually found here.

The risk assessment is treated as a document rather than a tool. The firm produces one, updates the date each year, and does not use it to drive decisions. Controls are not aligned to what the assessment says. EDD is not applied consistently where the assessment says it is required. The assessment and the programme drift apart.

CDD and associated person diligence are applied uniformly rather than proportionately. Each customer or associated person goes through the same process regardless of risk. The risk-based approach is described in policy but not reflected in execution. Cases that should receive deeper scrutiny are processed at the same depth as routine ones.

Policies exist but are not understood. The framework is in place. The training is complete. The register is populated. When tested, the people who should apply the policy do not know what it requires. The gap between paper and behaviour is often the first gap supervisors look for.

Monitoring generates alerts, but the alerts are not handled consistently. A system that produces detections that are not investigated can become an evidence trail of unmanaged risk.

Senior managers are not engaged. The board sees an annual report. The senior manager with programme accountability has not challenged the framework for months. In practice, the programme is run by a small compliance team without the senior management challenge the framework assumes.

Records do not support the position. The programme may be operating well, but the evidence is thin. When a defence has to be built, or a supervisor asks for the basis of a decision, the records are not there or do not hold together. The records are the evidence.

A final thought

The financial crime framework is demanding and still moving. Four offence areas may need attention. Three failure to prevent offences may need procedures that can be evidenced. The senior manager attribution rules have widened the range of cases in which a corporate may be fixed with criminal liability for the acts of a senior manager. Regulators and prosecutors are focused on effectiveness, not technical compliance alone.

The framework is manageable if it is built in a disciplined way. Across offence areas, the architecture is familiar: a documented risk assessment, controls calibrated to that risk, clear senior management ownership, and records that show what was done and why.

Where an organisation treats this as a live control framework rather than a paperwork exercise, it is in a stronger position to explain and evidence its approach if tested. Where it does not, that weakness is usually visible in the records, the escalation trail, and the operation of the controls.

Jurisdiction equivalents

New Zealand

The implementation framework for AML/CFT in New Zealand is set out in the AML/CFT Act 2009 and supervisor guidance from DIA, FMA and the Reserve Bank of New Zealand. Bribery and corruption obligations follow from the Crimes Act 1961, sections 99 to 106. Insider conduct is addressed in the Financial Markets Conduct Act 2013, Part 5. Fraud and dishonesty offences are addressed under the Crimes Act 1961, principally sections 240 and following. New Zealand has not introduced a failure to prevent regime or a senior manager attribution regime equivalent to ECCTA section 196 or section 250 of the Crime and Policing Act 2026.

Australia

The implementation framework for AML/CTF in Australia is set out in the AML/CTF Act 2006 and the AML/CTF Rules, with reforms extending coverage to additional professional and business sectors through staged commencement. AUSTRAC is the supervisor. The bribery framework is set out in the Criminal Code Act 1995 (Cth), Division 70 (foreign bribery) and sections 141 and 142 (Commonwealth public officials). The corporate failure to prevent foreign bribery offence under section 70.5A is now in force. Insider trading and market misconduct fall under the Corporations Act 2001 (Cth), Part 7.10. The Australian framework now has several features that are closer to the UK model than they were previously.

Key takeaways

  • The implementation framework spans ten components: governance, risk assessment, policies and procedures, customer due diligence, associated person due diligence, training and communication, monitoring and detection, reporting and escalation, record keeping, and audit/review/assurance.
  • Each component has a source in legislation, regulation or statutory guidance. The cross-references in this session are a starting point, not a substitute for reading the underlying material.
  • The checklist is used in two passes: first to confirm coverage, then to test effectiveness. The gap most programmes have is between the two.
  • The common failure modes are consistent across offence areas: the risk assessment is not used; diligence is applied uniformly; policies are not understood; alerts are not actioned; senior managers are not engaged; records do not support the position.
  • The senior manager attribution provisions in ECCTA section 196 and section 250 of the Crime and Policing Act 2026 require organisations to understand who falls within the senior manager population, the scope of their authority, and the risk that authority creates.
  • Strong programmes are built on documented risk assessments, controls calibrated to risk, clear senior management ownership, and records that show what was done and why. The records are the evidence.

Course complete

This is the ninth and final session of Fraud and Financial Crime: Legislation, Regulation and Practical Implementation. For anti-money laundering compliance in depth, the companion AML Compliance course is available on this site. For further reading on individual topics covered across this course, see the resource guides listed below.

Further reading and resources

The primary sources referenced through this course, gathered together for ease of reference. All are publicly available.

UK legislation

Fraud Act 2006. Theft Act 1968. Computer Misuse Act 1990. Bribery Act 2010. Criminal Justice Act 1993, Part V. Proceeds of Crime Act 2002. Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. Criminal Finances Act 2017. Economic Crime and Corporate Transparency Act 2023. Crime and Policing Act 2026. Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026. UK legislation is available through legislation.gov.uk.

UK guidance

Ministry of Justice guidance on the Bribery Act 2010. HMRC guidance on the Criminal Finances Act 2017 offences. Home Office guidance on failure to prevent fraud. FCA Financial Crime Guide. FCA Market Watch. JMLSG Guidance. HM Treasury national risk assessment material on money laundering and terrorist financing. Joint SFO-CPS corporate prosecution guidance. SFO corporate guidance. FCA consultation and policy material relevant to cryptoasset market abuse. Public guidance is available through gov.uk, fca.org.uk, sfo.gov.uk and jmlsg.org.uk.

International standards

OECD Anti-Bribery Convention. UN Convention against Corruption. FATF 40 Recommendations and typologies reports. ISO 37001 anti-bribery management systems. ISO 37301 compliance management systems. Available at oecd.org, unodc.org, fatf-gafi.org, and through ISO and BSI.

New Zealand

Crimes Act 1961, sections 99 to 106 (bribery and corruption) and sections 240 and following (fraud and dishonesty). Financial Markets Conduct Act 2013, Part 5 (insider conduct and market manipulation). AML/CFT Act 2009. Available at legislation.govt.nz. Supervisor guidance from DIA, FMA and the Reserve Bank of New Zealand.

Australia

Criminal Code Act 1995 (Cth), Division 70 and sections 141 and 142 (bribery), Part 2.5 (corporate criminal liability) and section 70.5A (failure to prevent foreign bribery). Corporations Act 2001 (Cth), Part 7.10 (insider trading and market misconduct). AML/CTF Act 2006 and AML/CTF Rules. Available at legislation.gov.au. AUSTRAC and Australian Attorney-General's Department guidance.

Companion guides on this site

The Scam Shield: Fortifying Against Fraud. Bribery, Corruption and the Modern Compliance Challenge. Insider Dealing: An Operational Briefing. AML in Practice: A Risk-Based Approach. AML: Core Principles and Practice. All available at araitika.com.

Ārai Tika

Written by Russel Fielding — LLM (Distinction), Fraud and Financial Crime · PMP · CIPM · PRINCE2 Practitioner