Financial Crime Oversight: The Board and Senior Managers

Financial Crime Oversight: Why It’s the Board’s Problem, Not Just the MLRO’s

When a regulated firm’s anti-money laundering controls fail, attention often turns first to the MLRO. But financial crime accountability runs much wider. Boards, chief executives and the Senior Managers responsible for customer-facing businesses all have roles to play, and the regulators increasingly expect to see financial crime treated as a whole-firm risk, not a specialist compliance topic.

This article explains where financial crime accountability sits, what good oversight looks like and the questions boards should be asking.

Why Financial Crime Is a Senior Management Issue

Financial crime is one of the FCA’s most consistent priorities, and failures in anti-money laundering and sanctions controls have led to some of the largest penalties in UK financial services. Those cases rarely turn on a single mistake by the MLRO. More often, they involve business growth outpacing controls, under-resourced compliance teams, management information that hid backlogs, or commercial pressure that overrode risk concerns. Those are senior management and board failures.

The Money Laundering Regulations 2017 reflect this. As well as requiring a nominated officer to handle suspicious activity reports, they require firms, where appropriate to their size and nature, to appoint a member of the board or senior management responsible for compliance with the Regulations. Under the Senior Managers and Certification Regime, responsibility for the firm’s policies and procedures for countering the risk that it might be used to further financial crime is one of the Prescribed Responsibilities that must be allocated to a Senior Manager.

Who Is Accountable for What

The MLRO

The SMF17 Money Laundering Reporting Officer, where the firm has one, is responsible for the firm’s anti-money laundering systems and controls, and usually acts as the nominated officer for suspicious activity reporting to the National Crime Agency. They produce the annual MLRO report, which should give the board a candid view of the firm’s financial crime risk and controls.

The Senior Manager With the Financial Crime Prescribed Responsibility

This may be the MLRO, or another Senior Manager such as the chief executive or an executive director. They’re accountable for the firm’s overall policies and procedures on financial crime, which can extend beyond money laundering to fraud, sanctions, bribery and market abuse.

Business Line Senior Managers

The Senior Managers who run customer-facing businesses are accountable for how financial crime risks are managed in their areas, including customer onboarding, due diligence and monitoring. The first line owns the risk, even though the second line oversees it.

The Board

The board sets the firm’s appetite for financial crime risk, approves its approach and oversees whether it’s working. It should receive and challenge the MLRO report, ensure the function is adequately resourced and make sure growth plans take financial crime risk into account.

Financial crime failures are rarely just compliance failures. They usually start with a decision to grow faster than the controls could keep up.

The Areas Regulators Focus On

Business-Wide Risk Assessment

Firms must understand the financial crime risks in their business: customers, products, geographies and delivery channels. A generic risk assessment that doesn’t reflect the firm’s actual business is a common weakness.

Customer Due Diligence

Firms must know who their customers are and understand the nature of their business, with enhanced due diligence for higher-risk customers. Backlogs in periodic reviews are a frequent concern.

Transaction Monitoring

Monitoring systems must be calibrated to the firm’s risks, alerts must be investigated promptly, and backlogs must be visible to senior management.

Sanctions

Firms must screen customers and transactions against sanctions lists and act on matches. The Office of Financial Sanctions Implementation enforces financial sanctions in the UK, and the FCA also expects firms to have effective systems and controls. Sanctions regimes have expanded significantly in recent years, raising the demands on firms.

Resourcing

Regulators look closely at whether financial crime functions have enough people, with the right skills, to deal with the firm’s volumes and risks, particularly at fast-growing firms.

What Good Board Oversight Looks Like

  • A candid MLRO report that the board discusses properly, not just notes.
  • Clear risk appetite for financial crime, including which customers and activities the firm won’t accept.
  • Meaningful management information on due diligence backlogs, alert volumes and ageing, suspicious activity reports, sanctions matches and resourcing.
  • Growth and financial crime considered together, so that new products, markets or customer segments come with the controls to match.
  • Independent assurance, through internal audit or external reviews, of whether controls actually work.
  • Direct access for the MLRO to the board and its committees.

Common Failings

  • Growth outpacing controls. Customer numbers rising faster than onboarding and monitoring capacity.
  • Hidden backlogs. Management information that reports activity but not the growing pile of overdue reviews or alerts.
  • An isolated MLRO. An MLRO without the authority, resources or board access to do the job.
  • Box-ticking risk assessments. Assessments that don’t reflect the firm’s real business.
  • Commercial overrides. Higher-risk customers accepted against compliance advice without proper escalation.

Fraud and Scams

Financial crime oversight isn’t only about money laundering. Fraud, including authorised push payment scams, has become one of the most significant sources of consumer harm in UK financial services, and firms face growing expectations to prevent it and to support victims. Boards should make sure fraud risk is covered in the firm’s financial crime framework, with clear senior ownership, management information on losses and reimbursements, and a view of how fraud controls affect vulnerable customers.

Technology and Data

Modern financial crime controls depend on technology: screening systems, transaction monitoring, identity verification and increasingly machine learning. Senior Managers need to understand how these systems are calibrated, how they’re tested and what happens when they fail. A monitoring system that generates too few alerts may look efficient but miss real risk. One that generates too many can create backlogs that hide genuine concerns.

Fractional MLROs and Smaller Firms

Many smaller firms use a fractional or interim MLRO. That can work well, provided the individual has enough time for the firm’s volumes and risks, genuine access to the business and its data, and the authority to challenge. The board remains responsible for making sure the arrangement is adequate. SMF Capital’s article on when interim and fractional SMF appointments work covers the considerations.

Recruiting Financial Crime Leadership

Experienced MLROs and financial crime leaders are in demand, particularly those with experience in fast-growing firms, payments, crypto-assets or remediation. When recruiting, firms should test not only technical knowledge but the candidate’s ability to challenge, to communicate risk clearly to the board and to lead a team under pressure. For board-level and executive appointments at larger regulated firms, Exec Capital, a sister practice of SMF Capital, runs FCA-regulated executive search, and SMF Capital recruits MLROs and other Senior Managers across the regulated market.

Questions for Boards

  • Which Senior Manager holds the financial crime Prescribed Responsibility, and is that clear to everyone?
  • Does the MLRO report give us a candid view, and do we challenge it?
  • Do we see backlogs in due diligence and monitoring, not just activity volumes?
  • Are our growth plans matched by financial crime controls and resources?
  • When did we last have independent assurance that our controls work?
  • Does the MLRO have direct access to the board?

The Bottom Line

Financial crime is a whole-firm risk, and accountability for it runs from the board through the chief executive and business line Senior Managers to the MLRO. Firms that treat it that way, with honest management information, adequate resources, independent assurance and a board that challenges, are better protected against both financial crime and the regulatory consequences of failing to prevent it. For more on the Senior Manager Functions involved, see SMF Capital’s guide to SMF16 and SMF17.

Related Guides

Guides to financial crime accountability from SMF Capital. Every SMF search is led personally by Adrian Lawrence FCA

Practice Area

Control Functions


Compliance and MLRO roles.

→ SMF16 and SMF17
→ SMF4 Chief Risk


All SMF designations →

Practice Area

Interim & Fractional


MLRO cover for smaller firms.

→ Fractional and interim SMF cover
→ When fractional SMFs work


SMF recruitment services →

Practice Area

Structure


Allocating Prescribed Responsibilities.

→ The Responsibilities Map
→ Governance structure review


SMF Capital home →


Every SMF search is led personally by Adrian Lawrence FCA

About the Author

Adrian Lawrence FCA is the founder of SMF Capital. He is a Chartered Accountant and Fellow of the ICAEW, holds a practising certificate in his own name, and is a former listed-company Finance Director with a BSc from Queen Mary College, University of London. He founded FD Capital in 2018 and has since built a network of five specialist recruitment practices. He leads SMF Capital’s Senior Manager searches, including MLRO and financial crime leadership appointments. View Adrian’s ICAEW profile.

Strengthening Financial Crime Leadership?

SMF Capital recruits MLROs, compliance leaders and board members for regulated firms. Get in touch for a confidential conversation.

Leave a Reply