Quick Control Effectiveness Check

A short evidence check across the eight FCRisk control-failure lenses.

Sixteen representative questions from the controlled FCRisk Control Effectiveness Diagnostic. Your answers are processed locally in the browser and are not sent to FCRisk.

Published by FCRisk · Last reviewed: 27 August 2026

16 questions

Two representative questions under each of the eight Control Failure Framework lenses.

No aggregate score

A material weakness is not averaged away by stronger evidence elsewhere.

Private by design

No form submission, account or personal data is required for the check.

How to answer

Answer based on evidence you could actually produce today — not on policy intent or what the control is expected to do. Use Evidence indicates weakness where available evidence points to a deficiency, and Not evidenced where the organisation cannot yet demonstrate the position.

1Can the organisation demonstrate that material Financial Crime risks across customers, products, services, channels, legal entities and jurisdictions are identified and translated into explicit control scope?
2Are new products, services, channels, acquisitions, migrations and material business changes assessed before go-live for their Financial Crime control impact?
3Can the organisation evidence that every in-scope customer, account, transaction or event reaches the relevant Financial Crime control population?
4During migrations, releases or material configuration changes, is control-population coverage proven before and after deployment?
5Can the organisation demonstrate that data used for Financial Crime decisions is complete, correct, current and sufficiently precise for the intended control?
6Do transformations, mappings and classifications preserve the business meaning needed by Financial Crime controls?
7Can the organisation demonstrate that monitoring scenarios, screening rules and other preventive/detective controls map to the identified Financial Crime risks and typologies?
8Are design and configuration changes version-controlled, impact-assessed and subject to regression and outcome testing before and after release?
9Do Financial Crime controls operate at the intended frequency and timeliness, with failed runs, missed schedules and degraded processing detected and escalated?
10Is control capacity assessed against current and forecast customer, transaction, alert and change volumes, including credible stress or growth scenarios?
11Are alert, case and customer decisions supported by sufficient evidence, clear rationale and consistent application of policy?
12For potential sanctions exposure, do screening outcomes lead to timely and correctly governed restriction, freezing/blocking/rejecting, escalation, licensing and reporting decisions where applicable?
13Is end-to-end accountability for each material Financial Crime control clear across business, Compliance, Operations, Data and Technology?
14Is assurance sufficiently independent, risk-based and end-to-end to test scope, population, data, design, operation and decision outcomes rather than isolated technical components?
15Does remediation distinguish the underlying root cause from the visible control symptom and document the causal chain that produced the failure?
16Are closure criteria defined in advance and based on evidence of design effectiveness, operating effectiveness and evidence sufficiency rather than completion of remediation activity?
Important: This quick check is indicative only. It is not legal advice, regulatory assurance, audit, model validation, certification or a determination of compliance. The full FCRisk Control Effectiveness Diagnostic uses a wider controlled question set and evidence review.