Corlytics’ latest Global Enforcement Report reveals an uncomfortable pattern: most organisations hit with enforcement action were not short of controls. They had policies, monitoring systems, governance frameworks, risk assessments, and in many cases, alerts flagging problems. They were fined regardless.
According to Corlytics, this raises a question about how controls actually fail. Rather than collapsing suddenly, they appear to erode gradually, through a sequence of small, defensible decisions. A risk assessment isn’t refreshed because nothing seems to have changed.
Corlytics recently discussed the prescient topic of what is labelled the quiet demise of a control.
An alert is logged but not escalated because someone assumes another team is handling it. A new product launches on an existing control framework because it seems close enough. A merger completes, systems change, responsibilities shift, and the control stays exactly where it was.
None of these decisions look reckless in isolation. But collectively, they open a widening gap between the business as it operates today and the controls built for how it operated yesterday.
The report catalogues this pattern repeatedly. Some firms failed to update customer due diligence after risk profiles changed. Others generated monitoring alerts that were never actioned. Several had fraud controls covering only parts of their payment infrastructure. In a number of cases, senior management simply overrode established controls.
The common thread isn’t regulatory ignorance, it’s organisational drift. Businesses change constantly: staff leave, teams restructure, technology evolves, products expand into new markets, and artificial intelligence is layered on top. The organisation that designed a control is rarely the same organisation still operating it years later, yet controls are too often treated as fixed rather than something that should evolve alongside the business.
This may explain why regulators typically frame failures around governance, oversight and supervision, rather than an outright absence of controls. Firms usually know what good practice looks like. The weakness lies in the gap between knowing and doing.
It also raises questions about how control health is measured. Standard checks, is it documented, has it been tested, did it pass audit, ask yes-or-no questions. They’re necessary, but arguably not the most revealing ones. More useful might be asking when a control was last challenged, what has changed since it was designed, and whether it would be built the same way today.
These are curiosity-driven questions rather than compliance checkboxes. And they point to the real risk: not that a control fails overnight, but that it quietly stops reflecting the organisation it’s meant to protect, unnoticed until someone outside the business spots it first.
Read the daily RegTech news
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst





