Tell me if this rings true. A regulatory instruction lands, including a full-scope CDD remediation to be completed within one year. It’s all hands on deck. The team works diligently and quickly, but the focus, understandably, is on getting the files brought up to the now-required standard.
Step back and look at what that involves. The periodic reviews scheduled across a bank’s usual cycle, say a three-year one, where high-risk files are reviewed annually, medium every two years and low every three, are now squeezed into twelve months. So it’s not only more work than usual, it’s work done to a new standard. It’s easy, with the deadline looming, to lose sight of what comes after.
The clock you reset without noticing
Here is what a remediation can leave behind. The files are uplifted, but if the next periodic review is set on the usual cycle from the point each file was completed, and every file was completed in the same compressed window, you can easily end up with an uneven distribution of review work.
Even if the files were worked through evenly during the remediation, which they rarely are, the problem still builds. Following the usual pattern, year one brings only the high-risk files back round. Year two repeats them and adds the medium-risk files. Year three adds the low-risk files too, the workload peaks, then falls away in year four. The line climbs for three years and collapses, purely because of when the remediation happened. And since the files are rarely worked through at an even rate, you tend to inherit clusters within each year as well. It’s not a slope; it’s a series of spikes.
Why an uneven distribution is its own risk
An uneven distribution of reviews is not just untidy. A team facing a wall of work one month and a quiet stretch the next can’t be staffed sensibly for either: short-handed when the wall arrives, idle when it clears. The wall is where corners are most likely to be cut, because the work still has to be done and the month doesn’t get any longer. So the pattern can become a recurring quality risk, every year, at the same points, for no reason anyone would choose.
A team facing a wall of work one month and a quiet stretch the next can’t be staffed sensibly for either.
Smoothing and doing it on purpose
The fix is CDD smoothing. You look at the population and how the review dates currently fall, and redistribute them across the usual cycle, three years in our example, so the workload is steadier and a team can be built around it. The simple version just spreads the dates by risk. The supercharged version does more in the same exercise: grouping customers who belong together, such as corporate groups, so related files are reviewed on consistent information, and anticipating the months when capacity is thin, the holiday stretches, so less work falls when fewer people are there to do it.
The balance it asks for
Smoothing is, in miniature, what good risk management looks like: not just managing the risk, but balancing it against the operational reality of getting the work done. That balance has two ends, and either can be right. Hold strictly to the review timelines, doing everything on schedule or earlier, and the distribution tends to take longer to even out, prolonging the operational strain. Let some files run beyond the policy timescale and you resolve that strain faster, while arguably carrying more inherent risk on those files meanwhile. Where you land depends on your risk profile and how pressing the operational problem is.
In practice the answer is usually a deliberate blend: hold files on schedule or earlier by default, and let some run later where that buys real operational relief and can be justified from a risk perspective. The controls that don’t sleep between reviews, continuous screening, event-driven reviews, relationship managers close enough to escalate, are always there; a file whose review has been pushed out simply leans on them harder until it comes round, which is why the reasoning for moving it should be documented.
As we all know, the best time to plan for this is at the start of the remediation. With the deadlines and so many spinning plates it’s easily forgotten, and the reassuring part is that smoothing can still be done afterwards. What it isn’t is an excuse to reach for every time periodic reviews start falling behind, whatever those carrying the operational workload might tell you.
Finishing the job
The priority of a financial economic crime programme is managing risk; that much is obvious, it’s what everyone in the field is there to do. Yet, as anyone who has done this work a while knows, it is also about managing the workload that risk management creates, and doing it proportionately. The hardest part of this work is the judgement, the subjective calls, and that is what is most likely to suffer when a team is given too much at once. Pile the work on unevenly and you raise the odds that something gets missed where it matters most.
Which is why smoothing is easy to describe and hard to get right. Spreading dates across a calendar is the simple part; the value is in the judgement of which files can move, how far, and how that is evidenced, the part that keeps a faster, smoother book defensible rather than merely tidier. Get that right and you reduce the stress that can quietly lead to errors of judgement, and you keep a workforce engaged with the work in front of them, neither buried nor idle.