If the central argument of this series is that the financial crime industry has focused too heavily on optimising efficiency, the obvious question is whether there is evidence to support that conclusion.
I believe there is.
In fact, the evidence has been available for years.
Every regulatory enforcement action, public consent order and supervisory finding provides an opportunity to understand not only where an individual institution failed, but also what regulators consistently expect from financial crime compliance programmes. Viewed collectively, these actions tell a far more important story than any single enforcement case could reveal.
They show patterns.
Those patterns deserve far more attention than they often receive.
Looking Beyond Individual Enforcement Actions
When a significant enforcement action is announced, the industry's attention is understandably drawn to the institution involved. Headlines focus on the size of financial penalties, public criticism and reputational impact. Compliance teams review the details, compare them against their own control frameworks and frequently conduct gap assessments to determine whether similar weaknesses exist within their organisations.
This is an entirely appropriate response.
However , it is also incomplete.
An enforcement action should not be viewed solely as an isolated failure.
It should be viewed as a data point.
Taken individually, these actions describe the circumstances surrounding a particular institution. Examined collectively over many years and across multiple jurisdictions, they reveal something considerably more valuable: a remarkably consistent picture of the industry's recurring weaknesses.
The names of the institutions change.
The products change.
The jurisdictions change.
The underlying themes rarely do.
A Consistent Regulatory Message
Whether reviewing enforcement actions published by U.S. regulators, European supervisory authorities, the Monetary Authority of Singapore, AUSTRAC in Australia or regulators elsewhere, similar observations appear repeatedly.
Transaction monitoring models fail to keep pace with changing customer behaviour .
Customer due diligence is insufficiently dynamic.
Risk assessments are not updated as business models evolve.
Governance does not challenge long-standing assumptions effectively enough.
Management information focuses on operational activity without adequately demonstrating whether controls remain effective.
The consistency of these observations is striking.
It suggests that regulators are not simply identifying operational failures. They are identifying weaknesses in how organisations understand, govern and adapt to financial crime risk.
This distinction is significant.
Many enforcement actions are interpreted as evidence that institutions need better controls.
Increasingly, I believe they demonstrate the need for better governance around those controls.
Compliance Is an Adaptive Problem
Financial crime is fundamentally different from many other forms of operational risk.
Most operational processes are designed for environments where consistency is desirable. If payroll is processed correctly today, organisations expect it to be processed in much the same way tomorrow.
Manufacturing quality, financial reporting and operational resilience all benefit from stable, repeatable processes.
Financial crime operates differently.
It is adversarial.
Every improvement made by a financial institution changes the incentives facing criminal organisations.
Controls that prove effective today encourage new methods of circumvention tomorrow. Emerging technologies create legitimate commercial opportunities while simultaneously creating new opportunities for abuse. Geopolitical events alter sanctions exposure almost overnight, while new products continuously reshape customer behaviour and transaction patterns.
In this environment, the effectiveness of any control is temporary unless it is supported by governance capable of recognising when circumstances have changed.
That is why recurring regulatory findings should not surprise us.
The environment regulators supervise changes continuously.
If governance does not evolve at the same pace, similar weaknesses will inevitably reappear .
What Regulators Are Really Asking
One of the most interesting aspects of modern regulatory supervision is that expectations have gradually shifted.
Historically, examinations focused heavily on whether required controls existed.
Today, regulators increasingly seek evidence that those controls remain appropriate over time.
Institutions are expected to demonstrate that models continue to perform as intended, that customer risk methodologies reflect current business activities and that governance identifies emerging weaknesses before they become material failures.
This represents a subtle but important evolution.
The question is no longer simply, "Did you implement an effective transaction monitoring programme?"
Increasingly, it is, "How do you know that programme is still effective today?"
Answering that question requires considerably more than periodic validation exercises or historical performance reporting.
It requires organisations to demonstrate that governance itself has become adaptive.
Learning from the Industry Rather Than Reacting to It
Perhaps the greatest missed opportunity within financial crime compliance is the way enforcement actions are consumed.
Most institutions read them defensively.
Could this happen to us?
Do we have the same issue?
Should we implement another control?
These are sensible questions, but they are tactical.
Adaptive organisations ask different questions.
What assumptions failed?
Why were those assumptions not challenged earlier?
What changes in governance might have identified these weaknesses before regulators did?
What does this tell us about the future rather than the past?
These questions transform enforcement actions from compliance obligations into strategic intelligence.
Instead of becoming retrospective exercises in gap assessment, they become opportunities to improve organisational learning.
The Lesson Hidden in Plain Sight
Viewed individually, regulatory findings can appear highly specific, reflecting the unique circumstances of individual institutions.
Viewed collectively, they tell a remarkably consistent story.
The industry's greatest challenges are rarely the result of inadequate technology.
Nor are they typically caused by a lack of regulatory requirements.
More often, they arise because governance fails to recognise that the environment has changed while existing controls continue to operate exactly as they were designed.
The controls did not necessarily fail.
The assumptions behind them became outdated.
That distinction lies at the heart of adaptive compliance.
The organisations that consistently outperform their peers will not simply implement stronger controls.
They will develop stronger capabilities for recognising when those controls need to evolve.
That is the lesson regulators have been communicating for years.
The evidence has been there all along.
The question is whether we have been listening.