Financial Crime Intelligence Hub

The FCRisk Financial Crime Control Failure Framework.

A back-tested analytical model for understanding where Financial Crime controls fail — and how failures propagate across scope, data, technology, decisions, governance and remediation.

Published by FCRisk · Last reviewed: 27 August 2026
FCRisk methodology

Eight lenses for understanding how Financial Crime controls fail.

The framework is not a regulatory standard and it is not a rigid process flow. It is an FCRisk analytical model for locating failure across the complete Financial Crime control chain.

It has been back-tested against the 25 reconstructed enforcement actions in the private Control Failure Knowledge Matrix. Each case can map to several lenses, but the framework asks where the primary failure sits and which dependencies allowed it to become consequential.

Back-test conclusion

All 25 reconstructed actions mapped defensibly to one or more of the eight lenses. No ninth failure category was required.

Important: this is an analytical fit test within a selected evidence set. It is not a claim that these cases represent the prevalence of failure across the industry.

Control Failure Framework

From risk definition to sustainable remediation.

01

Risk & Scope

Failure to identify, assess or include the relevant risk, customer, product, channel, geography or exposure in the control architecture.

02

Population & Boundary

Failure of relevant customers, accounts, transactions, events or external reference populations to enter the effective control perimeter.

03

Data & Context

Failure of information to be complete, correct, current, semantically accurate or usable for the control decision.

04

Design & Configuration

Failure of rules, scenarios, models, thresholds, matching logic or workflows to address the intended risk.

05

Operation & Capacity

Failure to operate the designed control consistently, timely or at sufficient scale, including staffing, backlogs and growth-driven capacity constraints.

06

Decision & Escalation

Failure to interpret outputs, investigate, decide, restrict, escalate, disclose or report appropriately.

07

Governance & Assurance

Failure of ownership, oversight, challenge, testing, MI, audit, verification or accountability to demonstrate and sustain effectiveness.

08

Remediation & Sustainability

Failure to remove the underlying cause, assess retrospective impact, evidence closure or maintain the fix after an issue is identified.

Why these distinctions matter

Different defects can produce the same failed outcome.

Boundary

A functioning control can receive the wrong population.

Metro, Danske and Starling show why completeness of the effective control perimeter needs to be tested separately from the operation of the downstream system.

Meaning

The record can arrive but still carry the wrong risk meaning.

NatWest and Santander illustrate how classification or missing customer context can change the control decision even when records are present.

Sustainability

Issue completion is not the same as risk removal.

UBS, Santander and GT Bank illustrate why remediation requires evidence that underlying weaknesses have been removed and remain removed.

Framework principles

Three propositions that follow from the evidence.

The control perimeter is part of the control.Coverage and boundaries must be governed and evidenced, not assumed.
Operational does not mean effective.A control can run as configured while failing because scope, inputs, design or downstream decisions are wrong.
Closure requires evidence of risk removal.Remediation activity is not sufficient unless the underlying control outcome is demonstrably sustainable.

Primary-source anchors

The framework is derived from cross-case synthesis rather than any single regulator. Representative evidence includes FCA findings on Metro, HSBC, Monzo, Starling and Santander; FinCEN's UBS action; and AUSTRAC's Crown matter.

Apply the framework

Cross-Case Failure Intelligence

See how the framework is used to synthesise recurring mechanisms across independent enforcement actions.

Explore Cross-Case Intelligence →

Evidence base

Control Failure Library

Trace the analytical lenses back to reconstructed case-specific regulatory findings.

Explore Enforcement Intelligence →