Financial crime compliance framework: How to make it work

07 August 2026 | Industry Intel

A financial crime compliance framework is the governance structure that defines how a regulated institution prevents, detects, and reports money laundering, sanctions evasion, terrorist financing, and fraud. It determines who owns each control, how risk decisions get made, and what happens when conditions change.

Most regulated institutions have a framework on paper, but documented controls and functional controls are not the same thing. AML and sanctions penalties in EMEA rose by 767% in 2025, according to Fintech Global, as long-running investigations into programs with documented but non-functional controls reached their conclusions.

The FCA’s Financial Crime Guide (updated November 2024) and the EU’s Anti-Money Laundering Regulation, which applies across all member states from July 10, 2027, reflect the same shift in supervisory expectation: whether controls produce measurable outcomes, not whether they appear in a policy document.

This guide explains what a financial crime compliance framework must include and how its structure determines whether a program withstands regulatory examination.

Key takeaways:

  • Governance on paper is not governance in practice
    Regulators examine whether accountability is named, thresholds are calibrated, and audit trails hold up, not whether a policy document exists.
  • The EWRA must reflect the business as it operates today
    Risk assessments built on last year’s model will not capture current exposure. New products, new markets, and peer enforcement actions each change what the framework needs to address.
  • The three lines of defense model fails when lines collapse
    When the compliance function takes on work that belongs to the business, independent oversight disappears. Examiners identify this regardless of what the organizational chart shows.
  • Technology without governance is still a framework weakness
    Screening and monitoring tools deployed without defined ownership, calibrated thresholds, and documented alert logic create the same examination risk as having no controls at all.
  • Sigma360 keeps framework components connected
    When sanctions screening, adverse media, perpetual KYC, EDD, and AML investigations run from a shared data foundation, the audit trail is consistent, thresholds are maintained, and risk decisions hold up to examiner review.

Framework vs. program: Understanding the difference

A compliance program covers the operational work of screening customers, reviewing alerts, and filing SARs. The framework governs each of those activities, determining who owns each control, how risk appetite translates into thresholds, and what triggers a review when conditions change.

Without a framework, controls exist, but no one is responsible for whether they work together, whether they reflect the institution’s actual risk profile, or whether they hold up when an examiner asks why a decision was made. 

A well-run program built on a weak framework will satisfy a routine review and fail a targeted examination.

What breaks when there is no framework

The core components of an FCC framework

Every financial crime compliance framework covers the same components. What separates strong programs from weak ones is how well each is calibrated, owned, and connected to the others.

 

Component What it covers What regulators examine
Governance and oversight Board accountability, compliance officer authority, escalation paths Whether accountability is documented, named, and tested
Enterprise-wide risk assessment Customer, product, geography, and channel risk Whether the assessment reflects actual business activity and is updated regularly
Policies and procedures AML, sanctions, adverse media, KYC/CDD, SAR filing Whether procedures match regulatory requirements and are understood by staff
KYC and customer due diligence Identity verification, beneficial ownership, risk classification Whether CDD records are complete and EDD is applied to high-risk relationships
Sanctions and watchlist screening Screening against OFAC, UN, EU, and other watchlists Whether match quality, false positive rates, and escalation handling are defensible
Adverse media monitoring Negative news screening for clients and counterparties Whether coverage is broad enough and materiality scoring integrates with risk decisions
Transaction monitoring and SARs Pattern detection, alert review, suspicious activity reporting Whether alert thresholds are calibrated and SAR documentation supports the conclusions filed
Training and testing Staff training, independent audit, control validation Whether training is role-specific and whether independent testing identifies control weaknesses

 

FATF’s 40 Recommendations set the global baseline for all eight components. 

The June 2025 update to Recommendation 16 strengthened cross-border payment transparency requirements, and ongoing FATF work on beneficial ownership and virtual assets continues to raise expectations for how institutions document and evidence their controls.

How governance accountability should be structured

Governance is the component that most frameworks handle least precisely. Stating that the board is “ultimately responsible” for financial crime compliance is not the same as having a functioning governance model.

The structure regulators expect includes three lines of defense. The FATF’s guidance on risk-based supervision confirms that supervisors assess institutions on how effectively this model functions in practice.

 

Line Who owns it Responsibility
First line Business units and relationship managers Identifying and managing financial crime risk in day-to-day operations
Second line Compliance and risk functions Setting policy, overseeing controls, and providing independent challenge
Third line Internal audit Testing and validating the effectiveness of the framework independently

 

The failure mode regulators see most often is first-line ownership that exists only in policy.

When relationship managers do not understand their financial crime obligations, or when the compliance function absorbs responsibilities that belong to the business, the second line loses its independence, and examiners identify that breakdown regardless of what the organizational chart shows.

When the three lines of defense collapse

How risk calibration shapes the framework

The enterprise-wide risk assessment (EWRA) is the mechanism that translates a risk-based approach into specific control decisions. It evaluates exposure across four dimensions (customer type, geography, product and service, and delivery channel) and determines where the most intensive controls should apply.

The output is a risk tier for each relationship, and that tier directly determines control intensity:

 

Risk tier Control intensity Examples
Standard CDD at onboarding, periodic reviews, standard screening thresholds Retail banking customers, low-value transactions
Elevated Enhanced CDD, more frequent monitoring, tighter alert thresholds PEPs and their associates, high-value clients, complex structures
High EDD, senior management approval, continuous monitoring, documented escalation Correspondent banking, high-risk jurisdictions, entities with adverse media history

 

The FATF’s risk-based approach guidance for the banking sector sets the international standard for this methodology. Regulators expect the EWRA to reflect actual business activity and be updated as the institution’s risk profile evolves.

Where financial crime compliance frameworks break down

Regulatory examinations rarely uncover isolated operational failures. The breakdowns that produce enforcement actions are structural, and most follow the same patterns:

  • Unnamed accountability: Policies assign responsibility to functions rather than individuals, so when controls fail, no one owns the outcome.
  • Stale risk assessments: The EWRA reflects the business at the last review cycle, not as it operates today, and new products, markets, and customer segments carry risk the framework has not accounted for.
  • Collapsed line ownership: The compliance function absorbs operational responsibilities that belong to the first line, leaving no independent oversight of the controls it is also running.
  • Technology without governance: Screening and monitoring tools get deployed without defining who sets thresholds, who reviews calibration, and who owns alert disposition logic.
  • No update mechanism: The framework stays unchanged when regulations shift, when peer enforcement actions signal new examiner expectations, or when the business model evolves.

Read more: 

What regulators look for when they examine a framework

Across major jurisdictions, regulators have shifted their examination focus from what controls an institution has to whether those controls produce measurable outcomes.

The FCA’s Financial Crime Guide, updated in November 2024, requires organizations to show that financial crime systems are effective in practice, calibrated to their actual risk profile, and subject to regular independent testing

FinCEN’s proposed AML/CFT program rule replaces a technical compliance standard with a demonstrable effectiveness requirement. The Federal Reserve’s parallel proposal, issued in July 2026, applies the same standard across the banking sector.

For institutions operating across EU markets, the EU’s Anti-Money Laundering Regulation applies directly across all member states from July 10, 2027, with AMLA beginning direct supervision of selected high-risk entities in 2028. 

Organizations that have not assessed how these requirements will affect their compliance architecture are running behind the preparation timeline.

The FFIEC BSA/AML Examination Manual, updated in February 2026, sets out the specific procedures US examiners follow. The areas assessed most closely are:

  • EWRA accuracy relative to actual business activity and current product mix
  • Compliance function independence and its ability to challenge the business without conflict
  • Alert threshold calibration and evidence of ongoing tuning after implementation
  • SAR documentation quality and whether it supports the conclusions filed
  • Role-specific training and evidence of retention testing
  • Audit finding remediation and evidence that identified weaknesses have been resolved

Read more

How a framework examination unfolds

When to review and update a financial crime compliance framework

A framework review should happen at least annually, but waiting for the annual cycle after a material change is itself an examination finding. Several events warrant an out-of-cycle review:

  • Material regulatory changes, including new FATF guidance, updated FCA Financial Crime Guide chapters, or FinCEN rulemaking
  • New products, services, or customer segments not covered by the existing EWRA
  • Significant business events such as an acquisition, geographic expansion, or new correspondent banking relationship
  • Internal audit findings that identify control failures at the framework level
  • Peer institution enforcement actions that signal new examiner expectations

A program reviewed annually but not updated between cycles will drift. By the time an examiner arrives, the framework describes a business that no longer exists.

Read more: Challenges in implementing AI governance frameworks

Putting the framework into practice with Sigma360

Sigma360 Homepage

A financial crime compliance framework defines the governance requirements. Executing against them at the data volumes, alert complexity, and investigation pace that regulated institutions face requires the right operational infrastructure.

The framework components covered in this guide each carry specific governance obligations: defined ownership, calibrated thresholds, documented decision logic, and audit trails that hold up to examiner review.

When those components run on separate tools with separate data, the governance layer fractures. Analysts reconcile rather than decide, thresholds drift after implementation, and the audit trail tells four different stories.

Sigma360 is an AI risk intelligence platform built to keep those components connected through the following capabilities:

  • Sanctions and watchlist screening with entity resolution across global watchlists, PEP databases, and adverse enforcement records, with configurable thresholds, documented alert logic, and exportable audit trails
  • Adverse media monitoring across 4.5M monthly articles with AI-driven materiality scoring, so coverage reaching analysts reflects the institution’s own risk criteria
  • Perpetual KYC replacing point-in-time reviews with continuous portfolio monitoring, triggering reassessment when sanctions exposure, ownership, or adverse media shifts
  • Enhanced due diligence drawing on proprietary intelligence to map beneficial ownership structures and expose indirect risk connections
  • AML investigations with AI-generated entity summaries consolidating watchlist status, registry data, and adverse media into a single structured profile before the analyst opens the case

Institutions using Sigma360 report up to 93% fewer false positives, with analyst capacity redirected from data assembly to the judgment calls that examinations actually test.

Request a demo to see how Sigma360 connects your framework components.

FAQ

Who is responsible for the financial crime compliance framework within an institution?

Responsibility is shared across the board, the compliance function, and business units. The board sets the risk appetite, compliance owns the framework design, and business units apply the controls day-to-day.

What is the difference between financial crime compliance and financial crime risk management?

Financial crime compliance covers the controls and reporting obligations an institution must meet. Financial crime risk management assesses whether those controls are actually working and where real exposure exists in the portfolio.

Does a financial crime compliance framework apply differently to fintechs than to banks?

The regulatory obligations are largely the same, but fintechs often operate at higher onboarding volumes with greater reliance on API-driven screening. The framework components are identical, but the calibration and review cadence need to reflect a faster-moving, digital-first risk profile.

Is transaction monitoring part of a financial crime compliance framework?

Transaction monitoring is one component of the framework. The framework determines who owns the alert logic, how thresholds are set and reviewed, and how SAR decisions are documented.

What happens when a financial crime compliance framework fails a regulatory examination?

Examiners issue findings requiring formal remediation, including rewriting policies, restructuring accountability, or recalibrating controls. In serious cases, regulators impose consent orders or financial penalties, and remediation programs can run for years.

About Sigma360 | The Standard in KYC & Financial Crime Compliance

Sigma360 is an AI-powered, full-stack risk intelligence platform that consolidates operations into one enterprise-grade system, enabling point-in-time risk screening and perpetual client monitoring for financial crime prevention and compliance operations. Sigma360 unifies global risk data, proprietary intelligence, core screening technology and AI automation in a secure cloud environment to find direct and network-based risks at sub-second speed, reduce false positives and strengthen risk and compliance operations.

Sigma360.com / Schedule a Demo / Free Trial / Connect on LinkedIn

Engage with us

Our Risk Intelligence Specialists can get you the answers you need.