For many firms, the biggest threat in financial crime compliance is not a new typology or a sophisticated criminal network. It is a risk assessment process that everyone assumes is working.
According to Arctic Intelligence, each year the same routine unfolds: spreadsheets are circulated, contributors are chased for inputs, drafts are stitched together and a lengthy report lands in front of the Board. On the surface, nothing looks wrong.
That sense of stability, however, can be deeply misleading, and it often lasts only until a regulator, auditor or new business initiative exposes the cracks.
At the heart of the problem is inertia. Because the process can be completed on time, organisations conclude it must be effective. But finishing a document is not the same as producing an accurate, consistent or defensible assessment. In many cases, it simply shows that teams have learned to live with inefficiency and quietly work around structural flaws.
Over time, the methodology itself becomes inherited rather than designed. Spreadsheets pass from one MLRO to the next, gathering outdated definitions, inconsistent logic and assumptions nobody can explain. Control ratings go unchallenged because questioning them takes time and invites friction. What began as a genuine effort to understand exposure turns into an annual ritual.
Spreadsheets add to the illusion. Neat tables, formulas and colour-coded scores suggest rigour, yet underneath sit broken links, undocumented assumptions, version conflicts, overwritten data and no reliable audit trail. Executives and Boards see polished outputs and mistake the appearance of structure for real governance.
The annual cycle compounds the issue. Financial crime risk shifts constantly as products change, customer behaviour evolves and controls strengthen or weaken. A once-a-year snapshot is often stale by the time the Board reviews it, creating a gap between reported and actual exposure.
Boards themselves may struggle to provide meaningful challenge. Faced with dense information and high-level summaries, directors often lack the specialist knowledge or visibility needed to spot weaknesses. Internal audits, typically run every one to three years and narrow in scope, tend to uncover problems only after they have persisted across several cycles.
Meanwhile, practitioners on the ground frequently know the process is fragile. Without executive backing or modern tools, though, many feel unable to change it, fostering a culture of quiet resignation.
Change usually comes only after a trigger event: a regulator requesting evidence that cannot be produced, an audit revealing understated residual risk, a formula failing mid-consolidation, or an expansion that exposes methodological gaps. At that point, firms discover their process was never sound, just untested.
The lesson is clear. Firms that challenge their assumptions early, engage their Boards properly and invest in platforms offering accuracy, defensibility and continuous visibility will be better placed than those who wait to learn the hard way.
Read the full Arctic Intelligence post here.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





