The Execution Gap in AML: Why Good Policies Fail in Practice

Introduction

In my previous article, “Why Anti-Money Laundering Is No Longer Optional in the Financial Sector,” I discussed how AML has evolved from a regulatory obligation into a fundamental component of financial system integrity. I also briefly highlighted a critical issue within the industry that the gap between well-documented frameworks and their actual execution in practice. This article builds on that observation. Because in reality, AML frameworks do not fail due to a lack of regulation or guidance. They fail in execution.

The illusion of strong AML frameworks

Across most financial institutions, AML frameworks appear robust when assessed at a surface level. Policies are comprehensive, procedures are clearly defined, and governance structures are formally established. Transaction monitoring systems are in place, and staff undergo periodic training. From a regulatory perspective, this creates the impression of a well-controlled environment. However, when these frameworks are applied in day-to-day operations, a different reality often emerges. Processes are followed mechanically rather than critically, and decisions are influenced by operational pressures rather than risk-based judgment. This disconnect between design and execution is what defines the execution gap. As emphasised by the Financial Action Task Force, technical compliance alone is not sufficient; the effectiveness of implementation is the true measure of an AML regime (FATF, 2021).

Data quality as a fundamental weakness

A key driver of the execution gap is the quality of data underpinning AML controls. Financial institutions rely on customer information, transaction records, and risk indicators to identify suspicious activity. In practice, however, data is often incomplete, inconsistent, or outdated. Customer due diligence records may vary across departments, and legacy systems may operate in silos, preventing a consolidated view of risk. Under such conditions, even advanced monitoring systems produce unreliable outputs. Poor data quality does not simply weaken controls; it creates a false sense of assurance. The Basel Committee on Banking Supervision highlights that effective risk management is dependent on accurate and comprehensive data aggregation, and deficiencies in this area can significantly impair a bank’s ability to manage financial crime risk (BCBS, 2013).

This issue is not merely theoretical. In one instance, during a periodic review of customer profiles, inconsistencies were identified between KYC records maintained by the compliance function and those held within the core banking system, which was managed by a separate team. Several customer risk ratings had not been updated despite evident changes in transaction behaviour. Consequently, the transaction monitoring system continued to operate using outdated risk thresholds, resulting in ineffective alert generation. While the control framework existed in form, its effectiveness was compromised by weak data governance and lack of system alignment. Following the reconciliation of data discrepancies and standardisation of customer profiles, there was a noticeable improvement in the relevance and quality of alerts. This reinforces a fundamental point that AML systems are only as robust as the data that underpins them.

Transaction monitoring and alert fatigue

Transaction monitoring is often positioned as the core of AML control frameworks. However, its effectiveness is frequently constrained by operational realities. Analysts are required to review large volumes of alerts, a significant proportion of which are false positives, within limited timeframes. Over time, this leads to alert fatigue, where the emphasis shifts from thorough investigation to efficient processing. This is not necessarily a failure of individuals, but a structural issue driven by system design and workload expectations. When the focus moves towards clearing alerts rather than understanding them, the effectiveness of monitoring is significantly reduced.

A practical example of this can be observed in environments where repeated alerts are generated for similar customer behaviour without adequate feedback mechanisms. In one case, recurring alerts were triggered for the same patterns of activity, yet previous investigation outcomes were not systematically incorporated into the monitoring logic. This resulted in repeated reviews of low-risk scenarios, consuming analyst capacity while adding limited value. By introducing a structured feedback loop and refining alert parameters, repeat issues were reduced materially, allowing analysts to focus on higher-risk cases. This demonstrates that improving effectiveness is not always about increasing controls, but about making existing controls more intelligent.

Lack of frontline ownership

Another critical factor contributing to the execution gap is the lack of ownership within the first line of defence. In many organisations, AML is still perceived as the responsibility of the compliance function rather than a shared organisational obligation. Frontline teams, who are responsible for onboarding customers and maintaining client relationships, often approach AML requirements as procedural tasks rather than risk management responsibilities. This creates a structural weakness. The first line originates risk, and without its active engagement, the second line is limited to oversight rather than prevention. This misalignment reduces the overall effectiveness of the AML framework and reinforces a culture where compliance is viewed as a checkpoint rather than an embedded discipline.

Policy design vs operational reality

There is also a clear disconnect between how AML policies are designed and how operations function in practice. Policies are typically developed based on ideal conditions, assuming complete information, sufficient time, and consistent application of controls. However, operational environments are shaped by commercial pressures, resource limitations, and competing priorities. This mismatch creates tension between expectations and execution. Over time, this leads to workarounds and informal practices, gradually eroding the effectiveness of controls. While the framework remains intact on paper, its practical application deviates from its intended purpose.

Regulatory perspective and consequences

The consequences of the execution gap are evident in regulatory enforcement actions. Failures in AML frameworks rarely stem from the absence of policies; instead, they arise from weaknesses in implementation, oversight, and control effectiveness. Firms often demonstrate strong documentation but fail to evidence that controls operate effectively in practice. The Financial Conduct Authority has consistently emphasised that firms must ensure their financial crime controls are not only well designed but also operationally effective (FCA, 2023). This distinction is critical, as regulatory expectations increasingly focus on outcomes rather than processes.

Bridging the execution gap

Addressing the execution gap requires a fundamental shift in approach. Institutions must move beyond measuring activity and instead focus on outcomes. This involves assessing the quality of investigations, identifying recurring issues, and ensuring that controls genuinely mitigate risk. Improving data quality should be prioritised, as reliable data forms the foundation of effective AML systems. Strengthening data governance, standardising customer information, and integrating systems are essential steps in this process. Additionally, AML responsibilities must be embedded within the first line of defence. Frontline teams need to understand risk indicators and take accountability for customer-related risks. Compliance functions should support and challenge but not operate in isolation. Finally, effective feedback mechanisms must be established to ensure continuous improvement. Lessons learned from investigations and audits should be systematically incorporated into control enhancements.

Conclusion

The financial industry does not suffer from a lack of AML frameworks; it suffers from inconsistency in execution. Policies, systems, and governance structures are necessary, but they are not sufficient on their own. The effectiveness of AML depends on how these elements operate in practice under real-world conditions. Bridging the execution gap requires discipline, accountability, and a willingness to critically evaluate existing approaches. Ultimately, AML is not defined by what is written in policies, but by how effectively those policies are implemented.


References

Basel Committee on Banking Supervision (BCBS) (2013) Principles for effective risk data aggregation and risk reporting. Bank for International Settlements.

Financial Action Task Force (FATF) (2021) Updated Guidance for a Risk-Based Approach to AML/CFT. Paris: FATF.

Financial Conduct Authority (FCA) (2023) Financial Crime Guide and AML supervisory expectations. London: FCA.

This article is also available on LinkedIn for wider readership

Leave a comment