Introduction
When I moved from trade finance into risk and compliance, I expected the main challenge to be learning the regulatory framework. That proved to be the easier part. What I had not anticipated was how often the most difficult conversations in compliance depended on understanding how a product actually worked, and how often that understanding was missing on the second line.
In trade finance, I had spent years examining letters of credit, handling trade-related payments and working with SWIFT messages. In compliance, I began to see alerts, reviews and escalations relating to those same products, assessed by colleagues who knew the regulations thoroughly but had never seen a bill of lading, a cover payment or a transferable credit in practice. Their conclusions were not careless, but they were often limited by what they did not know about the product in front of them.
This article looks at why product knowledge matters for effective compliance oversight, where the gaps tend to appear, and what institutions can do to close them. It draws on my own move between the two functions, and on the view that a second line which does not understand the business cannot provide the challenge that regulators expect of it.
Regulatory context
The expectation that compliance staff should understand the business they oversee is not new. The Basel Committee’s paper on compliance and the compliance function in banks states that compliance staff should have the necessary qualifications, experience and professional and personal qualities to carry out their duties, and should have a sound understanding of compliance laws, rules and standards and their practical impact on the bank’s operations (BCBS, 2005). The final part of that sentence is often overlooked, yet it is the part that requires product knowledge.
In the UK, SYSC 6.1 requires firms to ensure that the compliance function has the necessary authority, resources, expertise and access to all relevant information (FCA, 2024). Under the Senior Managers and Certification Regime, the senior managers responsible for compliance oversight and money laundering reporting are personally accountable for the effectiveness of their functions, which makes the expertise within those functions a matter of individual as well as institutional responsibility.
The Institute of Internal Auditors’ Three Lines Model describes the second line as providing complementary expertise, support, monitoring and challenge on risk-related matters (IIA, 2020). Challenge is the important word. A second line can only challenge what it understands, and in practice the quality of challenge depends heavily on whether compliance staff can tell when a first-line explanation is reasonable and when it is not.
The FCA’s thematic review of banks’ controls over financial crime risk in trade finance is also relevant. It found that anti-money laundering policies and procedures were often weak, and it identified as poor practice both disregarding money laundering risk where a transaction presented little credit risk and relying on experienced trade processing staff who had received no specific training on financial crime (FCA, 2013). That finding describes the reverse of the problem discussed in this article: product knowledge without financial crime knowledge. Taken together, the two problems show that neither kind of knowledge is sufficient alone, and that effective control depends on bringing them together.
Where the gap tends to appear
Trade finance
Trade finance is probably the clearest example. Letters of credit, documentary collections, guarantees and supply chain finance each carry different risks, and the documents involved are specialised. A compliance analyst reviewing a trade-related alert needs to understand what a transport document should show, why goods might be transhipped, what a transferable or back-to-back credit is designed to achieve, and which features of a transaction are routine rather than unusual. The Trade Finance Principles published by the Wolfsberg Group, the ICC and BAFT expect banks to identify and escalate unusual features that are apparent from the information available to them (Wolfsberg Group, ICC and BAFT, 2019), and that expectation assumes the reviewer knows what a usual transaction looks like.
Without this knowledge, two outcomes are common. In the first, the analyst accepts the explanation provided by the business because there is no basis on which to question it. In the second, the analyst escalates or delays legitimate transactions because ordinary features of trade, such as third-country shipment or a change of vessel, appear suspicious to someone who has not seen them before. Both outcomes weaken the control: the first by missing risk, and the second by consuming time and credibility that should be reserved for genuine concerns.
Correspondent banking and payments
Correspondent banking presents a similar challenge. Understanding the difference between serial and cover payments, how nostro and vostro accounts operate, what nested relationships look like in practice and how payment messages are structured is essential for assessing correspondent risk. As I discussed in my previous article on payment transparency, much of what matters happens within the payment message and the operational processes around it.
From what I have observed, compliance reviews of correspondent relationships often focus heavily on the due diligence questionnaire and the respondent’s policies, which are important, while giving less attention to the actual flows through the account. A reviewer who understands how payments move can ask more useful questions, such as why a respondent sends a high proportion of payments with incomplete originator information, or why its activity includes flows that do not fit its stated business.
Treasury and markets
Treasury and markets activity is often treated as lower risk from a financial crime perspective, partly because it involves institutional counterparties and partly because the products are complex. Foreign exchange swaps, money market placements and securities settlement can all be used to move value, and some typologies rely precisely on the assumption that these transactions will not be examined closely. A compliance function that does not understand these products is more likely to apply generic controls that do not fit the activity, or to exclude the activity from review altogether.
What weak challenge looks like in practice
Gaps in product knowledge rarely appear as obvious errors. They are more likely to be seen in the quality of compliance work over time.
Alert closure rationales tend to become general rather than specific, referring to the customer’s established relationship or the absence of adverse information rather than explaining why the particular transaction made sense. Risk assessments describe products in broad terms without identifying how each product could actually be misused. New product approvals are completed on the basis of the business’s description, with compliance comments focusing on policy requirements rather than on the mechanics of the product. In assurance testing, reviewers check whether a procedure was followed without being able to judge whether the procedure was suitable for the product.
In my view, the most telling sign is the type of question that compliance asks the business. A second line with good product knowledge asks questions that the business finds difficult to answer, because they relate to how the product actually operates. A second line without that knowledge tends to ask questions that can be answered by pointing to a policy or a completed form.
An illustrative case
Consider a transaction monitoring alert generated on a corporate customer that acts as an intermediary trader. The customer receives payment under an export letter of credit and, within a few days, makes a payment of a slightly lower amount under an import letter of credit for what appears to be the same goods. The alert is generated because of the rapid movement of funds in and out of the account.
An analyst without trade finance experience reviews the alert, notes that the customer is an established trading company with a long relationship with the bank, confirms that the payments relate to letters of credit, and closes the alert on the basis that the activity is consistent with the customer’s business. The rationale is reasonable on its face, and a quality assurance reviewer with a similar background would be likely to accept it.
An analyst with trade finance experience would recognise the structure as a back-to-back arrangement, which is common and legitimate for intermediary traders. However, that analyst would also look further. The questions would include whether the margin between the two credits is consistent with the goods and the trader’s role, whether the descriptions, quantities and shipping details in the two sets of documents correspond, whether the supplier and the end buyer are located in jurisdictions that make commercial sense, and whether the intermediary adds any value that explains its position in the chain. If the margin is unusually wide, or if the documents for the two credits do not describe the same shipment, the arrangement may be concealing over-invoicing or the movement of value through the intermediary.
Both analysts reach a conclusion, and both conclusions can be documented. The difference is that only one of them has examined the features of the transaction that carry the money laundering risk.
Why the gap persists
From what I have observed, the gap is not usually the result of a lack of ability or effort within compliance teams. It tends to arise from the way compliance functions are recruited, trained and organised.
Compliance recruitment often prioritises regulatory knowledge, professional qualifications and experience in similar compliance roles. These are valuable, but they mean that many compliance professionals have never worked in an operational role within the products they now oversee. Candidates with operational backgrounds are sometimes viewed as lacking the regulatory knowledge required, even though regulatory knowledge is considerably easier to acquire than years of product experience.
Training within compliance also tends to focus on regulation, typologies and internal policy. Typology training explains how a product can be misused, but it rarely explains how the product works when it is used legitimately, which is the knowledge needed to recognise when something is out of place.
There is also a structural separation between the first and second lines. Compliance staff may have limited opportunity to observe operations directly, and the business may be reluctant to spend time explaining its products to a function that it views primarily as a source of control requirements. Where the relationship is distant, compliance relies on the business’s own descriptions, and challenge becomes harder.
Finally, compliance professionals may be reluctant to admit what they do not know. Asking the business to explain a basic feature of a product can feel uncomfortable for a function whose role is to provide oversight. In my experience, however, the most effective compliance colleagues are those who are willing to ask such questions, because the answers often reveal more than a review of documentation would.
Building product knowledge in the second line
Improving product knowledge does not require compliance professionals to become product specialists, but it does require a deliberate effort. In practical terms, institutions should consider the following measures:
- Recruit from operations as well as from compliance. Staff with experience in trade finance, payments or treasury operations bring knowledge that is difficult to teach. Institutions should value this experience when recruiting into compliance and provide the regulatory training needed to complement it.
- Arrange structured time within the business. Short secondments, shadowing or walkthroughs of operational processes allow compliance staff to see how products work in practice. Even a few days observing document examination or payment processing can significantly improve the quality of later reviews.
- Develop product risk profiles. For each significant product, compliance should hold a short profile describing how the product works, its normal features, the indicators that would be unusual and the typologies associated with it. These profiles provide a reference for analysts and a basis for consistent decisions.
- Require product-specific alert rationales. Quality assurance should assess whether closure rationales address the features of the product involved, rather than relying on general statements about the customer relationship.
- Involve product experts in new product approval. Compliance input to new products should be based on an understanding of the product’s mechanics. Where that expertise is not available within compliance, it should be obtained from experienced staff elsewhere in the institution.
- Encourage questions in both directions. Joint sessions in which the business explains its products and compliance explains the risks it is looking for help each function understand the other, and make challenge more constructive.
The FCA’s Financial Crime Guide expects firms to understand the risks associated with their products and services and to apply controls that are appropriate to them (FCA, 2023). That understanding cannot sit only in the first line.
Conclusion
Compliance functions are often assessed on their knowledge of regulation, the completeness of their policies and the volume of reviews they complete. These matters are important, but they do not show whether the function understands the products it oversees, and without that understanding the challenge it provides will remain limited.
The gap is most visible in specialised areas such as trade finance, correspondent banking and treasury, where the features that carry financial crime risk are also the features that require experience to recognise. Institutions that recruit from operations, give compliance staff time within the business and expect product-specific reasoning in compliance work will be better placed to provide the effective challenge that the three lines model is designed to deliver.
Having moved from examining trade documents into reviewing the risks associated with them, I have come to see product knowledge and compliance expertise as two parts of the same capability. A compliance function that brings them together will understand not only what the rules require, but also where, within each product, the risks are most likely to be found.
References
Basel Committee on Banking Supervision (BCBS) (2005) Compliance and the Compliance Function in Banks. Basel: Bank for International Settlements.
Financial Conduct Authority (FCA) (2013) Banks’ Control of Financial Crime Risks in Trade Finance, Thematic Review TR13/3. London: FCA.
Financial Conduct Authority (FCA) (2023) Financial Crime Guide: A Firm’s Guide to Countering Financial Crime Risks. London: FCA.
Financial Conduct Authority (FCA) (2024) FCA Handbook, SYSC 6.1: Compliance. London: FCA.
Institute of Internal Auditors (IIA) (2020) The IIA’s Three Lines Model: An Update of the Three Lines of Defense. Lake Mary, FL: The Institute of Internal Auditors.
Wolfsberg Group, International Chamber of Commerce and BAFT (2019) Trade Finance Principles. Wolfsberg Group.


Leave a comment