FINCRIME TECH

What regulators expect after a Financial Crime technology change

Replacing major Financial Crime technology platform is a significant regulatory event for your firm.

A new screening, transaction monitoring, fraud or KYC platform changes how an organisation identifies, assesses and manages risk. Regulators and Internal Audit will want to understand more than whether the system went live on time.

They will want to know why it was selected, how it reflects the firm's risk profile, and whether those accountable are comfortable it provides adequate control for their organisation.

If you are responsible for the decision, the key question is simple.

Can you explain the decision and the system's outcomes in plain English?

Getting this right requires a clear sequence of decisions, supported by evidence, from initial scoping through design, to post-go-live monitoring.

The following steps set out how to approach that journey, where to start, and what should be in place before moving forward.

IMG_5410

Start with the problem

Before assessing vendors, define the environment the organisation needs to control.

Set out what is not working, which risks need to be managed more effectively, and which control outcomes the new platform must improve.

Requirements should reflect your customers, products, channels, jurisdictions, data, risk appetite and operating model.

A list of product features is not enough. Be able to explain why each important capability matters and how it will strengthen the control environment, whilst ensuring it doesn't detract from any controls already in place.

Ownership should also be clear from the outset. Identify who is accountable for selection, design, implementation and ongoing performance.

Assess the options and the vendor

Keep a clear record of the options considered and why the preferred solution was selected.

Product demonstrations usually show technology at its best. Reference checks provide a better understanding of how the vendor performs during implementation and after go-live.

Speak to organisations of a similar size and complexity. Ask about implementation support, defect resolution, response times and whether promised functionality was delivered in practice.

Ongoing support is equally important. Financial Crime technology requires regular tuning, monitoring and change.

The vendor provides the technology and specialist expertise, but accountability for the control outcome always remains with the institution.

Understand the data early

Poor-quality data can undermine any system.

Missing fields, duplicate records, inconsistent customer information and weak data lineage can lead to poor detection, ineffective risk assessments and unnecessary manual work.

Assess data quality early in the programme. Confirm what data is available, whether it is complete and accurate, how it will need to be manipulated or transformed to be useful, and how it will be migrated.

Known weaknesses should have a clear remediation plan or an agreed risk treatment before go-live.

Migration and reconciliation requirements should also be agreed early. This avoids discovering late in the programme that important customer, case or historic data cannot be transferred as needed.

Configure the system for your firm’s risks

Standard vendor settings are unlikely to reflect your organisation's specific risk profile. Some will give you a good starting point, but a regulator will soon recognise an environment that has not been tuned to a specific organisational need.

Rules, thresholds, scores, watchlists and workflows should be assessed against your customers, products, channels, jurisdictions and risk appetite.

If an existing platform is being replaced, avoid simply copying the current configuration without challenge. A new system may use different data fields, scoring methods or assumptions. At best, you will likely carry over legacy issues into the new environment.

The team should decide which controls should be migrated, redesigned or retired, with key configuration decisions supported by evidence.

Make the model explainable 

Artificial intelligence and machine learning can improve detection and reduce manual effort, but this is a different type of model and they require proper understanding and oversight.

The organisation should understand which data informs the model, which factors influence its outputs, how thresholds are applied and how exceptions are handled.

Known limitations, and risks, should be documented and understood.

Vendor documentation can support this work, but it does not replace internal understanding. If an alert is generated, a customer is referred or a transaction is cleared, the responsible teams should be able to explain the underlying logic.

Test before switching off the old system 

Before retiring the existing platform, compare it systematically with the new one.

Back-testing can demonstrate how the new system would have responded to historical alerts, known cases and previous risk events. Running both systems in parallel can provide further assurance before the final cutover but must be managed carefully as not to overwhelm the financial crime analysts handling the alerts.

Look beyond headline alert volumes. Assess detection quality, false positives, case outcomes, customer impact and operational workload.

Differences between the systems should be understood, documented and approved before go-live.

Make an evidence-based-go-live decision  

The accountable executive needs a clear view of readiness, outstanding risks and planned mitigations.

Keep the assurance pack simple. It should answer five questions:

  1. Why was the platform chosen?
  2. How does it control the firm's risks?
  3. What evidence demonstrates that the data, configuration and outputs are reliable?
  4. What limitations and residual risks remain?
  5. Who will monitor performance after go-live?

Supporting evidence should include the decision record, data assessments, configuration rationale, testing results, governance arrangements and the ongoing monitoring plan.

The purpose of the assurance pack is to make the decision clear and defensible, rather than bury it in technical detail.

Monitor performance after go-live

Go-live is not the end of the technology decision.

Alert quality, detection performance, customer impact, operational demand and model behaviour should all be monitored against agreed expectations.

Alert quality, detection performance, customer impact, operational demand and model behaviour should all be monitored against agreed expectations.

Thresholds and workflows may require further tuning as real-world results emerge. Any changes should follow clear governance, with named owners and a reliable audit trail.

Teams also need sufficient training to understand the platform, challenge its outputs and recognise when performance begins to deteriorate.

Where BeyondFS can help 

BeyondFS supports firms at key stages of the technology change journey.

This includes providing independent assurance before major decisions, recovering programmes that have lost direction, strengthening requirements and testing, and helping teams assess calibration, governance and readiness for go-live.

We also help organisations establish the monitoring and oversight needed once the platform is in operation.

If you are accountable for the regulatory outcomes of a Financial Crime technology change and have any doubts about whether the decisions being made will satisfy regulatory expectations, we would be happy to discuss your programme and explore how we can help.

Let's make change happen.

We help Financial Institutions accelerate digital transformation – delivering improved efficiencies, better risk controls and enhanced customer experiences.