Financial Crime Diagnostic

Find the gaps before they become remediation problems.

A focused, evidence-led review of the Financial Crime control chain — designed to show where weaknesses sit, how they connect and what decisions should follow.

What does a Financial Crime diagnostic assess?

It assesses whether the organisation can explain, evidence and operate the complete chain from customer understanding and risk assessment through monitoring, investigation, QA, escalation and governance.

Financial Crime Risk Assessment — connect BWRA/CRA conclusions to control scope →

When is it useful?

Before a major transformation, after an audit or regulatory concern, when controls are fragmented, or when senior management needs an independent view before committing to remediation.

What evidence is reviewed?

Policies, control descriptions, governance papers, customer-risk logic, KYC/UBO/PEP artefacts, TM and screening design, investigation and QA processes, data controls, MI, issues and remediation evidence.

What does the client receive?

A prioritised view of material gaps, dependencies, target-state choices and practical next actions — not simply a maturity score.

Typical diagnostic domains
  • Governance, ownership and decision rights
  • Customer risk, KYC, UBO, PEP and ongoing due diligence
  • Transaction Monitoring and screening coverage
  • Investigations, QA and escalation
  • Financial Crime data, reconciliation and control evidence
  • Technology, AI readiness and provider dependencies
  • Remediation governance and sustainability

Diagnostic outputs should enable decisions.

The purpose is not to produce another report. The purpose is to make the control chain clearer and help leadership decide what must be fixed, what can wait, what requires evidence and where specialist assurance is needed.

Prioritised gaps

Material weaknesses separated from noise and mapped to the affected decision chain.

Target-state choices

Practical options on control, data, operating model, technology and governance.

Actionable roadmap

Sequenced recommendations with dependencies, evidence needs and accountable decisions.

Control effectiveness

Go deeper where the question is not simply “what is missing?”

The FCRisk Control Effectiveness Diagnostic tests what the organisation can demonstrate about the control objective across eight failure lenses.

It separates design effectiveness, operating effectiveness and evidence sufficiency, with the full controlled methodology retained as a private advisory asset.

Explore the Control Effectiveness Diagnostic →

Three distinct questions

Designed?Does the control architecture address the stated Financial Crime risk?
Operating?Did the control actually work at the required scale and timeliness?
Evidenced?Can the organisation reproduce evidence sufficient to support that conclusion?
Indicative route

Start with a bounded review.

FCRisk can structure the work as a bounded gap assessment, a deeper control-effectiveness diagnostic, or a focused review of a particular control chain; then remain involved through remediation design, independent assurance or fractional senior support if required.