Skip to content

Back to Basics: Data and Financial Crime. Where Is Your Focus?

Financial services firms are investing heavily in financial crime technology, but successful transformation starts long before implementation. In the first article in a new series, Leanda Mark-Ihama explores why data quality, governance and strong control foundations remain critical to effective financial crime frameworks, regulatory compliance and sustainable growth.

Financial crime transformation continues to be high on the agenda for senior management, Money Laundering Reporting Officers (MLROs) and Boards across the financial services industry. Firms are increasingly investing in AI, automation and new technologies to strengthen their financial crime controls, improve customer oversight, increase operational efficiency and drive transformation.

Last month, the FCA’s Mills Review highlighted the transformative potential of AI across financial services, while also highlighting the importance of governance, oversight and responsible implementation. In addition, the FCA’s recent reviews of firms’ financial crime risk assessment and CDD processes are a reminder that an effective financial crime framework still requires getting the fundamentals correct at the outset, highlighting the need for good data.  

 When the FCA acted against Starling Bank in 2024, it demonstrated that whilst the regulator may not act on poor data in isolation, most enforcement results from failures in how a firm collects, governs or acts upon information and data. Poor data drives poor decision-making.

Taken together, this poses an important question for firms: As you accelerate growth and invest in financial crime transformation, are you giving enough attention to the data behind every financial crime decision?

This article is the first in our series exploring the importance of strong foundations, data, and the impact on an effective financial crime transformation project.

Financial Crime Control Development Starts with Good Data

Every financial crime control depends on data.

Business-Wide Risk Assessments (BWRA’s), Customer Risk Assessments (CRAs), customer due diligence, transaction monitoring, screening, fraud detection and management information all rely on accurate and complete data. If the underlying data is inconsistent, incomplete or misunderstood, even well-designed controls can produce poor results.

Many financial crime transformation programmes focus on implementing new technology or redesigning controls. In a landscape full of financial crime vendors promising to create an all-encompassing control eco-system, it can be difficult to focus on the fundamentals of designing controls that comply with regulatory requirements. However, technology cannot compensate for weak data foundations in a firm’s control environment. It simply enables a firm to process poor-quality data faster, increasing operational inefficiency and creating misplaced confidence in the effectiveness of the control environment. This creates a risk that firms may inadvertently facilitate financial crime.

When designing a financial crime compliance framework, it is imperative that firms consider the accuracy and efficacy of data sources prior to any overarching changes.

How the Regulator and the Industry Reinforce the Need for Good Data

The FCA’s thematic findings on financial crime risk assessments identified weaknesses in firms’ approaches to identifying, assessing and managing financial crime risk, including generic BWRAs, insufficient links between risk assessments and controls, and weaknesses in governance and ongoing review. Using quantitative data is no longer a ‘nice to have’ for the FCA, but an ‘expectation’. Firms should utilise existing MI and customer data to drive the inherent risk identification and assessment.

Firms should also map their products, services and risk ratings to external sources such as the National Risk Assessment of Money Laundering and Terrorist Financing or Proliferation Financing National Risk Assessment, for example.

In their Financial Crime Guide, the FCA has warned that when updating transaction monitoring controls, technology is only as effective as the data it receives. System upgrades, migrations or changes to feeder systems can create gaps in control if data is not transferred completely. Ensuring a clear understanding of firms’ end-to-end data flow coupled with strong governance and regular testing is essential in advance of any change programme.

Ultimately, the FCA and industry are pointing to the same conclusion, namely that an effective financial crime transformation programme is not simply about adopting new tech - it is about ensuring that technology is backed up by trusted data and effective governance, which drives risk-based decision-making by senior management. 

Data, Controls, Transformation and AI

Rather than treating financial crime transformation as a technology project, firms should think about it as a connected compliance journey.

Good data is an enabler that facilitates meaningful risk assessments. Better BWRAs and CRAs improve the identification of risk, and subsequently the effectiveness of controls, which in turn can provide reliable assurance on an ongoing basis. When data sits at the centre of a connected compliance journey, firms create an environment where technology and AI can deliver the outcomes needed to support compliance, operational efficiency and regulatory readiness.

Before investing in financial crime transformation, firms should consider the following questions about their data and broader framework:

  • Do we trust the data underpinning our financial crime framework?
  • Are our risk assessments data-driven by evidence or by assumptions?
  • How effective is our data aggregation in combining financial crime-related information from multiple sources? 
  • How is data integration impacting our understanding of financial crime risk and ability to make decisions? 
  • Will financial crime technology transformation solve problems, or simply exacerbate existing data controls gaps?

Successful financial crime transformation is not simply about implementing new technology. It starts with trusted data, effective governance and a framework that supports both regulatory compliance and sustainable growth.

Next in the Series

This article is the first in our series exploring how data and strong foundational framework controls are an essential cog in a successful financial crime transformation and control project.

In our next article, we will examine the hidden cost of poor data across risk assessments, transaction monitoring, screening and financial crime assurance. Stay tuned. 


How Can Thistle Initiatives Help?

 At Thistle Initiatives, our financial crime and change and transformation team helps firms:

  • Enhance financial crime risk frameworks at every juncture of control maturity, including Business-Wide Risk Assessments, Customer Risk Assessments, Screening and Transaction Monitoring.
  • Update firms’ financial crime tooling, calibration and implementation using our industry expertise and partner insights.
  • Assure the financial crime control environment with our Skilled Person and audit services, considering the design and effectiveness across regulatory and industry expectations.
  • Optimise firms’ financial crime operations by improving efficiency, agility, and performance at scale through management of your transformation programme.

By combining regulatory expertise with practical delivery experience, we help firms to build financial crime frameworks that are effective today and resilient for the evolving landscape. 


Meet the expert

TI sq - _0004_Leanda_Mark-Ihama-760670

Leanda Mark-Ihama, Senior Manager, Financial Crime    LinkedIn  Email

Leanda has over 14 years’ financial crime experience, including in the banking industry and at the FCA, and has completed the CAMs certification, ICA Financial Crime Prevention Diploma and ICA Anti-corruption certificate. Leanda has extensive expertise in both AML and ABC, building and assuring frameworks.