Skip to content

Back to Basics: Financial Crime Controls - Are You Getting the Right Outcomes from Your Data?

 Financial services firms are investing heavily in data and newer technology to enhance efficiency and effectiveness of financial crime systems and controls. However, the effectiveness of any financial crime compliance framework ultimately depends on the quality of the data feeding the controls. Thistle Initiatives’ Manager, Elliott Day, considers how data influences core financial crime controls, what we are seeing in practice and the questions firms may wish to be asking themselves.  

Business-Wide Risk Assessments (BWRAs), Customer Risk Assessments (CRAs), screening, transaction monitoring, fraud controls and assurance work all rely on accurate, complete and well-understood data. If the data is incomplete, inconsistent or poorly governed, even a well-designed control can produce weak results.

Most firms already have access to significant amounts of data. The challenge is understanding whether the right data is being used, how it supports key controls and whether it improves financial crime decision-making. So, the question for firms is: are you using the right data, in the right way, to support effective financial crime decision-making?

The first article in this series looked at why data quality, governance and strong control foundations matter before firms start a financial crime transformation programme. As the second article in the series, this article looks at what that means in practice across specific controls, including BWRAs, CRAs, screening, transaction monitoring, fraud and assurance.

Business-Wide Risk Assessments

A BWRA should help a firm identify and assess where financial crime risk exists across its business. In practice, many firms still complete BWRAs using workshops, management judgement and qualitative assessments. Those inputs remain important. Senior management and control owners often understand the business in a way that raw data cannot show on its own. However, firms should also be using data to test and support those judgements – this has specifically been called out by the FCA as poor practice to not utilise quantitative data while identifying and assessing risks. This may include customer risk rating breakdown, customer types, jurisdictional exposure, product usage, transaction volumes, suspicious activity reports, screening alerts, fraud trends, onboarding outcomes and management information.

Where this data is used well, the BWRA becomes more than a compliance document, ticking the Regulation 18 box. It helps the firm explain why one area of the business is higher risk than another and why certain controls have been designed specifically to those risks. For example, if a firm has increased exposure to higher-risk jurisdictions, complex ownership structures or higher transaction volumes, that should be visible in the BWRA. It should also flow through to customer risk assessment, due diligence, monitoring, screening and training.

Where the data is weak, the BWRA can become too generic. It may describe risks at a high level but fail to show whether those risks actually apply to the firm. That can result in controls being designed around assumptions rather than evidence.

In our experience, stronger firms treat the BWRA as a live management tool. They use data to challenge whether the risk assessment still reflects the business, particularly when the firm launches new products, enters new markets, changes its customer base or implements new systems.

Customer Risk Assessments

CRAs help firms decide the level of financial crime risk presented by each customer. Many firms still rely on static scoring models. These often allocate points based on factors such as customer type, geography, product, ownership structure, politically exposed person status, sanctions exposure and adverse media.

That approach can work, but only if the data is accurate and the methodology is consistently applied. If customer information is missing, outdated or held across different systems, the risk rating may not reflect the real risk presented by the customer. This is particularly important where customers have complex structures. If a firm cannot clearly identify who owns or controls the customer, where funds are coming from or why a particular structure is being used, it may struggle to assign the right risk rating. Good data helps firms make better customer risk decisions. It also helps them explain why a customer has been rated low, medium or high risk and why a particular level of due diligence has been applied.

We are increasingly seeing firms strengthen their CRA methodologies by introducing clearer risk factors, more consistent scoring and better documentation of the reasons behind each rating. The better examples do not just calculate a score. They explain what drove the score and what the firm did as a result. Effective CRAs also depend on the quality of the underlying reference data. Risk factor libraries, country risk matrices, industry classifications and other reference data sources should be comprehensive, regularly reviewed and updated to reflect the firm's business activities and financial crime risk exposure.

Screening

Screening is one of the clearest examples of a control that depends on good data. Firms screen customers, connected parties and transactions against sanctions, politically exposed person (PEP) and adverse media data. The quality of the outcome depends on both the screening tool and the data being screened.

If customer names are incomplete, dates of birth are missing, addresses are inconsistent or ownership information is not properly captured, the screening control will become less effective. It will miss relevant matches. It may also generate high volumes of false positives, which creates operational pressure and can make it harder for teams to focus on the alerts that matter.

Good screening is not just about choosing a vendor or adjusting match settings. Firms need to understand what data is being screened, where it comes from, how often it is refreshed and whether connected parties are included where appropriate. In our experience, stronger firms spend time understanding the quality of the data before making changes to screening thresholds or technology settings. That can make a material difference to alert quality and the overall effectiveness of the control. We are also seeing firms now more effectively conduct screening assurance and penetration testing to assess whether screening controls are operating as intended. This has been a key message from the FCA for a number of years. Their expectation is that firms do not simply onboard a screening tool, and ‘assume’ it works, or rely on the vendor to ensure it’s working effectively. This responsibility is with the Firm. This can include using test data and known name variations to assess calibration, fuzzy matching logic, non-Latin character matching and vendor configurations.

The FCA’s recent sanctions systems and controls review highlighted the importance of periodic testing, quality assurance and effective oversight of vendor screening solutions, particularly where firms rely on third-party providers to support sanctions screening processes.

Transaction Monitoring

Along with screening, transaction monitoring is one of the most data-dependent financial crime controls. Monitoring rules, scenarios and thresholds all rely on transaction data. If important fields are missing or inaccurate, the monitoring output can become unreliable. This can happen even where the underlying system is well designed. For example, a monitoring scenario may be designed to identify unusual international payments, rapid movement of funds or activity outside expected customer behaviour. If the system does not receive complete customer, account or transaction data, it may not be able to identify the activity properly.

Many firms are investing in transaction monitoring enhancements. That can include new rules, new systems, behavioural monitoring and more advanced analytics. These changes can be valuable, but successful programmes usually start with a clear understanding of the data flow. Firms should understand where transaction data comes from, how it moves between systems, what transformations take place and whether any fields are lost or changed before they reach the monitoring tool.

In our experience, some of the most important issues in transaction monitoring are not caused by the rules themselves. They are caused by data quality issues, system feeds, poorly documented assumptions or a lack of understanding of how the monitoring output is generated.

Fraud Controls

Following the significant increase in regulatory, and government, focus, fraud controls are becoming more data-led to enhance effectiveness. Firms are increasingly using behavioural data, device information, payment patterns, customer activity, location data and known fraud typologies to identify unusual or suspicious behaviour. Good data can help firms detect fraud earlier. It can also help firms understand whether a customer’s activity is unusual when compared with their normal behaviour or with similar customers.

The challenge is that fraud data often sits across multiple systems. Customer information may sit in one place, payment data in another and case management records somewhere else. If firms cannot bring that information together, they may not see the full picture. This is particularly important where fraud and money laundering risks overlap. A fraud event may also create financial crime concerns, particularly where stolen funds are moved through accounts or where mule activity is suspected.

We are seeing more firms consider how fraud and financial crime data can be better connected. This does not mean every firm needs a single system for everything. It does mean firms should understand where relevant information is held and whether teams can access the data they need to make informed decisions.

In practice, we have seen firms improve fraud outcomes by bringing together transaction monitoring data, fraud alerts and management information to identify trends that were not visible when each data source was reviewed separately. This can help firms identify emerging fraud risks, assess whether controls remain effective and make more informed decisions about where resources should be focused.

Financial Crime Assurance

Assurance helps firms understand whether controls are working as intended. Historically assurance reviews have often relied on sample testing, file reviews and manual assessment. These remain important. However, data can help assurance teams understand control performance more clearly and focus testing where the risk is highest. For example, firms may use data to identify unusual patterns in onboarding decisions, transaction monitoring alerts, screening outcomes, overdue reviews, quality assurance failures or suspicious activity reporting. That can help assurance teams move beyond checking whether a process exists and towards understanding whether it is producing the right outcomes. Good data also helps firms track whether remediation is working. If the same issue appears repeatedly, or if control failures continue after a change has been implemented, that may indicate a deeper problem.

In our experience, stronger assurance work uses data to ask better questions. It does not rely only on whether a sample passed or failed. It considers what the wider data is saying about the control and whether management has enough information to take action.

What Does This Mean for Financial Crime Transformation?

The examples throughout this insight point to a wider challenge facing many firms. Financial crime controls are often developed, tested and enhanced individually. A firm may improve its BWRA, refresh its CRA methodology, invest in screening optimisation or implement new transaction monitoring scenarios. However, these activities do not always form part of a coordinated transformation programme.

In practice, the strongest outcomes are often achieved where firms understand how data flows across the wider framework and how decisions made in one control influence another. A change to customer risk assessment, for example, may affect due diligence requirements, screening outcomes, monitoring activity, management information and assurance testing. This creates an important consideration for firms planning financial crime transformation activity. Before implementing new technology or redesigning controls, firms should understand how data is used across the broader framework, where dependencies exist and whether controls are operating consistently. Addressing these questions early can help firms prioritise investment, identify control weaknesses and avoid undertaking multiple remediation activities for what is ultimately the same underlying data issue.

Next in the series

This insight is the second in our series exploring how data and strong foundational framework controls are an essential cog in a successful financial crime transformation and control project.

In our final insight we will explore how firms can structure and sequence financial crime transformation programmes effectively once strong data foundations and core financial crime controls are in place. We will consider common transformation challenges, how firms can prioritise investment and the practical steps that can help deliver sustainable control improvements and better outcomes.

How Thistle Initiatives Can Help

At Thistle Initiatives, our Financial Crime and Change & Transformation teams work together to help firms design, improve and implement sustainable financial crime capabilities.

We support clients to:

  • Strengthen Financial Crime Risk Assessments by enhancing Business-Wide Risk Assessments (BWRAs) and Customer Risk Assessments (CRAs), making better use of data to identify emerging risks, improve decision-making and evidence regulatory compliance.
  • Improve financial crime controls through reviews of screening, transaction monitoring and customer risk models, including data quality assessments, control testing, threshold calibration and optimisation of supporting technology.

  • Design and embed robust control frameworks by assessing the effectiveness of existing controls, identifying gaps and implementing proportionate governance, control libraries and ongoing assurance processes.

  • Assess capability and maturity through independent maturity assessments, target operating model (TOM) reviews and strategic roadmaps that help firms prioritise investment and align to regulatory expectations and business objectives.

  • Design and deliver Target Operating Models that optimise people, processes, technology, governance and data, ensuring financial crime functions are scalable, efficient and fit for future growth.

  • Provide independent assurance through Skilled Person reviews, internal audit support and control effectiveness assessments, giving Boards and senior management confidence that financial crime frameworks are operating as intended.

  • Strengthen fraud risk management by helping firms better leverage customer, transactional and behavioural data to detect emerging threats, improve investigations and enhance preventative controls.

  • Deliver complex change programmes by leading financial crime and regulatory transformation initiatives, from strategy and mobilisation through to implementation, ensuring technology, operating models and controls remain aligned with regulatory requirements whilst delivering measurable business outcomes.

By combining regulatory expertise with practical delivery experience, we help firms to drive change and transformation and build financial crime frameworks, that are effective today and resilient for the evolving landscape.


Meet the Expert

Elliott Day - Square 1920

Elliot Day, Manager, linkedin-badge-email

Elliott is a Manager within Thistle’s Financial Crime team, supporting fintech and financial services clients to strengthen controls, enhance governance and deliver regulatory remediation. His experience spans AML, sanctions, KYC/KYB, customer onboarding and risk assessment, with a focus on proportionate, risk-based frameworks and practical assurance.