Financial Crime Control Effectiveness Diagnostic

Can you demonstrate that your Financial Crime controls are effective?

An evidence-led diagnostic built from the FCRisk Control Failure Framework, enforcement evidence and regulatory-change intelligence. The method separates control design, operating effectiveness and evidence sufficiency — without reducing material weaknesses to a single maturity score.

Published by FCRisk · Last reviewed: 27 August 2026
From intelligence to diagnosis

Evidence should support the control outcome, not just the existence of activity.

The full FCRisk diagnostic is a controlled private methodology. It asks what an organisation should be able to demonstrate about the scope, population, data, design, operation, decisions, governance and remediation of its Financial Crime controls.

The controlled master contains 48 diagnostic questions — six under each of the eight framework lenses — with expected evidence, potential failure indicators, enforcement anchors, regulatory-change links, data/technology dependencies and remediation implications.

Assessment model

Design effectivenessIs the control designed to address the stated risk and objective?
Operating effectivenessDid it operate consistently, timely and at the scale required?
Evidence sufficiencyCan the organisation reproduce evidence that supports the conclusion?
Eight diagnostic lenses

Representative questions from the controlled methodology.

These examples demonstrate the method. The complete question set, evidence mapping and assessment workbook are retained as a controlled advisory asset.

Financial Crime Risk Assessment — how risk conclusions should translate into control architecture →

01

Risk & Scope

Representative question
Can the organisation demonstrate that material Financial Crime risks across customers, products, services, channels, legal entities and jurisdictions are identified and translated into explicit control scope?

Evidence examples: Business-wide and entity risk assessments; product/channel inventories; risk-to-control mapping; control inventory.

02

Population & Boundary

Representative question
Can the organisation evidence that every in-scope customer, account, transaction or event reaches the relevant Financial Crime control population?

Evidence examples: Source inventories; inclusion criteria; source-to-target maps; population reconciliations.

03

Data & Context

Representative question
Can the organisation demonstrate that data used for Financial Crime decisions is complete, correct, current and sufficiently precise for the intended control?

Evidence examples: Critical-data-element inventory; DQ rules; profiling; control results.

04

Design & Configuration

Representative question
Can the organisation demonstrate that monitoring scenarios, screening rules and other preventive/detective controls map to the identified Financial Crime risks and typologies?

Evidence examples: Risk-to-scenario mapping; typology coverage matrix; control objectives; scenario/rule inventory.

05

Operation & Capacity

Representative question
Is control capacity assessed against current and forecast customer, transaction, alert and change volumes, including credible stress or growth scenarios?

Evidence examples: Volume forecasts; capacity model; productivity and quality MI; stress tests.

06

Decision & Escalation

Representative question
Are alert, case and customer decisions supported by sufficient evidence, clear rationale and consistent application of policy?

Evidence examples: Case files; decision standards; rationale templates; QA results.

07

Governance & Assurance

Representative question
Is assurance sufficiently independent, risk-based and end-to-end to test scope, population, data, design, operation and decision outcomes rather than isolated technical components?

Evidence examples: Assurance plan; test methodology; sample design; population completeness testing.

08

Remediation & Sustainability

Representative question
Are closure criteria defined in advance and based on evidence of design effectiveness, operating effectiveness and evidence sufficiency rather than completion of remediation activity?

Evidence examples: Closure criteria; design approval; operating evidence period; independent validation.

Assessment states

No compensating average.

A serious weakness in population coverage, data integrity, decision-making or remediation is not offset because another part of the framework is strong.

Evidenced

Evidenced effective

Available evidence supports the control objective and no material weakness is identified within the reviewed scope.

Incomplete

Partially evidenced

Some evidence supports the objective, but gaps in design, operation or evidence remain.

Assurance gap

Not evidenced

The organisation cannot currently demonstrate the control objective within the agreed scope.

Weakness

Evidence indicates weakness

Available evidence points to a material design, operating or outcome deficiency.

Scope

Not applicable

The question is genuinely outside the agreed diagnostic scope, with the rationale recorded.

Principle

Evidence before closure

Diagnostic conclusions depend on the quality and reproducibility of evidence, not only management assertion.

Diagnostic outputs

Designed to support decisions.

Control-effectiveness view

A lens-by-lens assessment that separates design, operation and evidence sufficiency.

Evidence map

What was reviewed, what is missing, what contradicts the asserted control position and where deeper testing is required.

Prioritised action

Material weaknesses, dependencies and remediation implications organised around the control objective rather than document completion.

Evidence architecture

The diagnostic is informed by the same evidence system used across the FCRisk Intelligence Hub: official sources, reconstructed enforcement actions, the eight-lens Control Failure Framework, cross-case failure intelligence and regulatory-change analysis.

Primary-source anchors include FCA, OFSI, FinCEN, Central Bank of Ireland, AUSTRAC, AMLA/EU and FATF material already mapped within those public intelligence layers.

Public entry point

Quick Control Effectiveness Check

A 16-question browser-only check using two representative questions under each framework lens. No answers are submitted to FCRisk and no aggregate compliance score is produced.

Try the quick check →

Controlled diagnostic

Full evidence-led review

The complete 48-question methodology, evidence requirements and source mappings remain private and are used within a defined advisory mandate rather than published as a downloadable checklist.

Discuss a control effectiveness diagnostic →

Important: The FCRisk Control Effectiveness Diagnostic is an advisory methodology. It is not legal advice, regulatory assurance, statutory audit, model validation, certification or a determination of compliance. Scope, evidence requirements and conclusions must be tailored to the organisation's actual risk profile and obligations.