Proportion, not Scale

A financial economic crime programme is not built by copying the largest version available. It is built by knowing what the institution needs, what it does not, and being able to evidence the difference.

A sculptor is said to work not by adding to the stone but by taking away from it. The finished figure is already there in the block, and the task is to remove everything that is not part of it. The idea has stayed with me, because it is close to how I think about building a financial economic crime programme.

We tend to picture that work as assembly, adding controls and checks until the thing is complete. In my experience it runs the other way. The full range of controls a programme could contain, the shape you might find at an international bank serving individuals and corporates across many products, is the block. It is a starting point to carve from, not a template to roll out unchanged.

What an institution needs is not settled by size alone. Size affects volume, reach and the systems behind a programme, but what a firm does, who it banks and where its exposure sits usually matter more. A small, specialist firm handling intricate trade finance in higher-risk markets may need more depth than a much larger domestic bank serving straightforward retail customers. So there are two ways to get it wrong: to impose the full shape on an institution that does not need it, or to strip parts away without reasoning through what each one was for. The first is wasteful. The second leaves gaps no one chose to accept.

The judgement has two dimensions. One is which controls belong in the programme at all. The other is how intensely the necessary controls need to run, how often, how deeply, how widely. The two examples that follow take one each, and each shows where the line sits between what comes away and what has to stay.

The first cut: the weight of review

Take the review of a CDD file, in the shape many will recognise. One person prepares it, another checks it, a risk owner signs it off, and quality assurance, compliance and internal audit sit beyond that. Every step may have a purpose. The question is whether each falls where the judgement actually is.

A sign-off is worth having when the person giving it has both the seniority to carry the risk and enough knowledge of the customer to stand behind the decision. Put it there and it is a control. Put it too low, with someone who cannot carry the risk, or too high, with someone too far from the customer to stand behind the decision, and then it’s just a signature. Lower-risk files are typically managed within the operational team rather than escalated for individual senior sign-off, and are not re-reviewed unless something triggers it, which is proportionate and right. The question at each layer is the same one: is this adding judgement, or adding weight?

The question at each layer is the same one: is this adding judgement, or adding weight?

Taking away a layer that adds only weight isn’t cutting a corner. It gives the team you actually have the room to do the remaining controls properly. An over-built review chain doesn’t make an institution safer. It tends to make it slower at the things that matter, and a slow control carries its own risk.

The second cut: the depth of testing

The harder judgement is in how deeply the controls themselves are tested. The instinct to scale back is strong here, and knowing where that’s safe and where it isn’t is where the skill sits. Transaction monitoring is the clearest place to show it, but the same is true of sanctions screening and other controls.

Some things should not come away, whatever the institution. Every scenario the system runs has to be covered. Parameter testing has to cover both above and below the line. Rules that automatically close alerts need governance and ongoing monitoring. Investigations have to evidence who is behind the money and where it came from.

What can flex is not the coverage but the rhythm and the reach. Where one institution re-validates its scenarios often, another can run a longer, risk-based cycle, with reviews triggered by changes in the law or by findings when they land. A testing sample can be sized to the volume it is drawn from. The judgement runs a long way down, further than most expect, right to how a testing sample is put together. No rule makes that choice for you, and a wrong turn can quietly weaken everything resting on it. What stays fixed is the coverage. What flexes is how hard it is worked.

Show that what you do is enough

None of this holds up unless it’s written down, and the discipline is narrower than it first sounds. It is not to justify the absence of every control you could in theory have run; that is an endless task and nobody does it. It is to record why the controls in operation are enough, and, where a reader would expect the usual thing, why it has been done differently. When mapping against a supervisor’s published red flags, those that are not relevant to the institution are recorded as such. A smaller firm may fold quality checking and quality assurance into a single layer. In that case, explaining why the arrangement is proportionate is enough. None of this changes the position where a control is required by law, licence or a binding supervisory expectation; no sufficiency rationale excuses its absence. Without a rationale recorded against it, a gap left by accident and an exclusion chosen on purpose look identical on a control list. They are opposites, and only the record tells them apart.

What is left is the programme

Done well, what remains after the carving isn’t a cut-down copy of another institution’s programme. It’s the right one for this institution, shaped by a team that knew the whole and could say why this version didn’t need the rest. The parts that came away were never part of this figure. The discipline is knowing what to take away, and being able to show it was the right thing to take.