Skip to main content

Call us today +971 - 56411 3575 or +971 - 58914 9282 | Email: info@vertexcompliance.com

Sanctions Screening Mistakes That Can Create Compliance Risk

Sanctions screening

Sanctions screening looks easy until something slips through. A misspelt name, an outdated sanctions list, or a hastily cleared alert can escalate into a significant compliance issue later. And in most cases, the issue is that a business’s screening process is inadequate and the process is not working as well as everyone assumes.

The UAE Central Bank has placed clear emphasis on effective sanctions screening, including the quality of customer and transaction data used by screening systems. CBUAE has also conducted thematic reviews of sanctions screening controls across regulated institutions. 

That is why effective sanctions screening is less about running more checks and more about getting the right checks, data, and decisions in place.

What Are the Most Common Sanctions Screening Mistakes?

A few fairly ordinary problems can weaken sanctions screening without being obvious at first.

Using Outdated Sanctions Lists

Sanctions lists do not stay the same for long. Names are added, details are changed, and some individuals or entities are removed altogether.

If your screening tool uses outdated information, a customer can pass a check simply because the latest data is missing. Automatic updates are beneficial, but they should not be assumed to be reliable. Someone still needs to know that updates are arriving properly and that the system is actually using them.

Depending Too Much on Exact Name Matches

Real-world customer data is rarely perfect. A name may be spelt differently, shortened, translated from another language, or entered with a small mistake.

That matters because a system looking only for exact matches can easily miss a genuine connection. Effective screening needs some flexibility around name variations and aliases. At the same time, the settings should not be so broad that every common surname creates another alert.

Screening With Incomplete Customer Information

A name on its own often tells you very little. If you do not have enough supporting information, even a reliable screening tool will struggle to separate a real match from a false positive.

Details such as date of birth, nationality, address, company registration information, and beneficial ownership can make a big difference. They give reviewers something useful to compare when an alert appears. Better customer data also means fewer cases where someone has to guess what the alert actually means.

Screening Customers Only Once

A customer may be clear when they first open an account or start a business relationship. That does not mean they will stay clear indefinitely.

They may later appear on a sanctions list, change ownership, appoint a new director, or start dealing with different counterparties. This is why screening should continue after onboarding. How often it happens should depend on the level of risk and the type of relationship involved.

Why Do Sanctions Screening Alerts Become Mishandled?

The screening system can find the right alert, and the process can still fail during the review.

Too Many False Positives

Most compliance teams have seen the problem: the system produces hundreds of alerts, and almost all of them turn out to be nothing.

That volume is not just inconvenient. It can make reviewers tired, encourage rushed decisions, and bury the alert that genuinely needs attention. The answer is not simply to reduce sensitivity until alerts disappear. Matching rules need to be tested and tuned so the team is dealing with useful alerts rather than constant noise.

Clearing Alerts Too Quickly

Not every similar name is a sanctions match, but that does not mean it should be dismissed after a quick look.

A reviewer may need to compare dates of birth, locations, aliases, nationalities, company details, or other identifiers before reaching a reasonable conclusion. When information is limited, the case may need another level of review. A quick clearance saves time in the moment, but it becomes difficult to defend if someone later asks why the alert was closed.

Having No Clear Escalation Route

Some alerts are simple to clear. Others are not.

The trouble starts when the person reviewing the alert does not know who should make the next decision. A successful process should make it clear when more information is needed, who handles higher-risk cases, and who has authority to close or escalate the matter. Without that structure, similar alerts can end up being treated very differently across the same organisation.

What Sanctions Risks Are Easy to Overlook?

Sanctions exposure may not always be directly associated with the customer name you are screening.

Missing Beneficial Owners and Connected Parties

A company may not appear on a sanctions list even though someone behind it does. That is why checking only the legal entity name can leave an important gap.

Depending on the relationship, businesses may also need to consider beneficial owners, directors, shareholders, counterparties, intermediaries, or other connected parties. This is where sanctions screening and customer due diligence overlap. If ownership changes, the screening picture may need to be reviewed again.

Ignoring Transaction and Geographic Risk

A customer may seem low risk on paper, but their activity may suggest otherwise.

Where money is being sent, which countries are involved, who the counterparties are, and what type of transaction is taking place can all change the level of sanctions exposure. Cross-border activity may deserve closer attention than a straightforward domestic relationship. Screening should therefore reflect what the business actually does, not just who the customer says they are.

Keeping Poor Screening Records

Sometimes the decision is right, but the evidence behind it is weak.

If an alert is cleared, there should be enough information to show what was checked and why the reviewer reached that conclusion. The same applies when a case is escalated. Clear records make internal reviews easier and give the business something concrete to show if a regulator later asks how the decision was made.

How Can Businesses Improve Sanctions Screening?

Improving screening usually comes down to getting the basics right and checking that they still work as the business changes.

Use a Risk-Based Approach

Not every customer, country, transaction, or business relationship deserves exactly the same level of scrutiny.

A customer with simple domestic activity may present a very different sanctions risk from a company with complex ownership and regular cross-border payments. A risk-based process helps teams spend more time where the exposure is higher. It also avoids turning sanctions screening into a blanket exercise where every case is handled in the same way.

Test the Screening System Regularly

Screening software should not be configured once and then forgotten.

Businesses should verify if the system is accurately identifying expected matches and if the current settings are generating excessive irrelevant alerts. It should also check whether the current settings are creating too many irrelevant alerts. This matters especially after changes to thresholds, matching logic, customer data, or sanctions sources. Testing also gives the compliance team evidence that the system is being reviewed rather than simply trusted.

Review the Matching Rules as the Business Evolves

Matching settings that worked two years ago may no longer suit the business today.

Perhaps the company now deals with more international customers, has entered new markets, or processes more transactions than before. Those changes can affect the type and volume of sanctions the system needs to identify. Reviewing matching rules regularly helps keep screening relevant instead of letting an old configuration quietly become less effective.

Keep the Process Easy to Follow

A sophisticated tool does not resolve a confusing process.

People still need to know when screening happens, what to do with an alert, when a case requires escalation, and what needs to be recorded. Those steps should be easy enough to follow consistently, even when the team is busy. If the process only works when one experienced compliance officer is available, it is a weak process.

When Should Sanctions Screening Controls Be Reviewed?

You do not need to wait for a regulator or a screening failure before checking whether your controls still make sense.

When Alert Volumes Suddenly Increase

A sharp rise in alerts usually deserves a closer look.

It may be caused by a change in screening rules, poor customer data, a new sanctions list update, or simply settings that are too broad for the type of customers being screened. Adding more people to clear the backlog may address the symptom without resolving the underlying cause of the issue. Identify the factors that are generating the additional alerts.

When the Business Enters New Markets

New countries often mean new sanctions risks.

You may be dealing with different customer types, ownership structures, payment routes, counterparties, or regional restrictions. The controls that worked for your old market may not cover those risks properly. Screening settings and risk assessments should therefore be reviewed as part of expansion, not several months after it.

Before a Regulatory Inspection

An inspection is a poor time to discover that no one can explain why alerts were cleared six months ago.

Before a regulatory review, it is worth checking whether sanctions lists are current, matching settings make sense, alert decisions are documented, and escalation procedures are actually being followed. This is also a beneficial opportunity to look for inconsistencies between written procedures and day-to-day practice. Fixing those gaps beforehand is far easier than explaining them during an inspection.

Conclusion

Fairly simple issues, such as outdated data, weak matching rules, rushed alert reviews, or poor records, often cause sanctions screening problems. None of these looks problematic on its own, but together they can create a serious compliance gap.

Vertex Compliance’s Sanctions Screening Software helps businesses screen customers and related parties, manage alerts, and keep a clearer record of screening decisions. If your current process is creating too much noise or leaving unanswered questions, take a closer look and assess sanctions risk with us.

How to Know If Your AML Software Is Not Working Well

AML Software

Anti-money laundering (AML) software helps simplify day-to-today compliance operations, by enabling them to spot risks easily, and review customers. However, it is simply not enough to just have a system in place as it does not automatically mean that it is working well. Poor data, excessive alerts and changes can make software less useful.

This matters because compliance is already expensive. A LexisNexis Risk Solutions study found that financial crime compliance costs increased for 98% of financial institutions surveyed in EMEA in 2023, reaching an estimated $85 billion.

Why AML Software Stops Working Properly

AML software does not usually stop working overnight. Problems often build slowly as the business changes.

You may start serving new types of customers, enter different markets, introduce new products, or process different transaction volumes. If the software rules, thresholds, customer information, and workflows are not reviewed alongside those changes, the system may no longer reflect your actual risk.

Even regulators have highlighted this issue. In one enforcement case, the UK’s Financial Conduct Authority found weaknesses in HSBC’s transaction monitoring controls, including problems around keeping monitoring scenarios up to date and ensuring data was accurate.

How to Know Your AML Software Is Not Working Well

There is rarely one single sign that tells you the system is failing. Instead, look at how the software performs during everyday compliance work.

1. You Are Getting Too Many False Positive Alerts

Are most alerts turning out to be normal business activities? If yes, then your AML software is increasing your work load. A false positive happens when legitimate activity is flagged as suspicious. 

While some false positives are expected, constant flow of low-value alerts make it difficult for your team to focus on the priorities.

2. Not Prioritising Important Activity 

If your compliance team notices unusual transactions or customer behaviour manually, then it is concerning. If it happens regularly, check whether the monitoring rules match your current customers, product, locations and transaction patterns. FATF guidance continues to emphasise a risk-based approach rather than treating every customer or activity in the same way.

3. Customer Risk Scores Do Not Make Sense

A customer marked as low risk should not repeatedly show behaviour that clearly requires closer review. Likewise, ordinary customers should not constantly receive high-risk ratings without a clear reason.

Compare the software’s rating with your team’s assessment. Frequent differences could point to incomplete customer information or weak scoring rules. 

4. Sanctions Screening Produces Poor Matches

If searching a common name creates a long list of unrelated matches, your screening process may be too broad. But settings that are too narrow may increase the risk of missing a relevant match.

OFAC itself recognises that automated screening can produce false positives and recommends evaluating the quality of a potential match using additional identifying information.

5. Your Rules and Thresholds Have Not Been Reviewed

Ask a simple question: when were your transaction monitoring rules last checked?

If nobody knows, that is a warning sign. Rules and thresholds should still make sense for the business you operate today, and monitoring systems may need recalibration as customer behaviour and risk exposure change.

6. Your Team Still Does Too Much Work Manually

Good AML software will not remove human judgement, nor should it. But employees should not have to repeatedly copy information between systems, update spreadsheets, or manually perform tasks the software is supposed to support.

Look at how much time your team spends on administration compared with actual review and investigation. Too much manual work may point to poor setup, weak integration, or software that no longer suits the business.

7. You Cannot Explain Why an Alert Appeared

An investigator should be able to understand why a transaction or customer was flagged.

If an alert simply appears without a clear reason, reviewing it becomes unnecessarily difficult. The same applies to risk ratings: your team should be able to understand the main factors behind a high-, medium-, or low-risk result.

8. Customer Data Is Missing or Outdated

AML software functions on the basis of the information it is fed. Old KYC records, missing customer details or incorrect transaction data can affect  the quality of screening and monitoring.  

Before you blame the software, check the data you are feeding. A capable system does not function properly without the right information. 

How Often Should You Review AML Software?

There is no specific review schedule that works for every business. It depends on your risk level, customer base, transaction activity, products, and regulatory requirements. 

What matters is that the review is not treated as a one-time exercise. The system should also be checked when there is a meaningful business change, such as entering a new market, offering a new product, changing customer types, or seeing a major shift in transaction behaviour.

A review should look beyond whether the software is technically running. Check alert quality, customer risk ratings, screening results, rules, thresholds, data quality, and how much manual work your team still performs.

Can You Fix Poor AML Software Performance?

Not every problem means you need new software.

Sometimes the system is okay, but the setup isn’t. Much of the problem may be solved by adjusting rules, cleaning customer data, reviewing risk-scoring logic, improving system connections, or training users.

Begin by finding the biggest gaps. Track practical metrics like false positive alerts, time taken to review cases, overdue customer reviews, and number of manual steps in typical compliance tasks.

If performance improves after these changes, then replacing the platform may not be necessary.

When To Replace Your AML Software?

Replacement should be considered when the existing platform cannot accommodate how your business now works.

For example, the system may not cope with your current transaction volumes, have limited options for customer risk assessment, not have the right screening capabilities, or require too much manual work. It can also be difficult to change if your risk profile changes.

Don’t just pick a replacement because it has more features. Find software that fits your actual AML workflow, customer types, business risks, and compliance requirements.

FATF has also acknowledged that technology may improve the effectiveness of AML/CFT when it is implemented responsibly and as part of a risk-based approach.

Conclusion

AML software should make compliance work clearer and more manageable. If your team is dealing with endless false alerts, questionable risk scores, missed activity, outdated rules, or too much manual work, it is worth reviewing how the system is performing. Sometimes a few changes are enough; in other cases, a different solution may be needed.

Looking for a better way to manage customer checks and AML risks? Explore Vertex Compliance’s KYC & AML Software or contact us to discuss your requirements.

What Is a Business Risk Assessment, and Why Does It Matter?

Business Risk Assessment

A business can have anti-money laundering (AML) policies, customer checks, and monitoring systems in place and still overlook where its biggest risks actually sit. A business risk assessment helps bring those risks into view. It looks across the organisation to understand where exposure to money laundering, terrorist financing, and other financial crimes may come from.

This matters in the UAE, where regulators follow a risk-based approach to AML/CFT (Counter-Financing of Terrorism) supervision. The CBUAE’s sectoral risk assessment, for example, looks at factors such as customers, products and services, delivery channels, geographic exposure, and business activities when assessing financial crime risk.

What Is a Business Risk Assessment?

A business risk assessment reviews the money laundering, terrorist financing, and other financial crime risks faced by the organisation. It considers areas such as customer types, products and services, geographic exposure, transactions, and delivery channels. The assessment looks at the risk before controls are applied, checks how well existing controls reduce that risk, and identifies what risk remains. This gives the business a clearer basis for deciding whether its AML/CFT controls are proportionate to the risks it actually faces.

Why Is a Business Risk Assessment Important?

A useful business risk assessment does more than produce a risk score. It helps management understand which risks deserve more attention and where current controls may need to change.

It Shows Where the Highest Risks Sit

A business rarely distributes risk evenly. One customer group may present very little concern, while another could involve complex ownership structures, high-risk jurisdictions, or unusual transaction activity.

A business risk assessment helps separate those areas instead of treating everything the same. Management can then see which parts of the organisation need closer attention. That makes AML risk management much more focused.

It Supports a Risk-Based Approach

A risk-based approach means applying stronger controls where the risk is higher rather than using the same level of scrutiny everywhere. Financial Action Task Force (FATF) describes this approach as identifying, assessing, and understanding money laundering and terrorist financing (ML/TF) risks and applying measures that match the level of exposure.

The assessment gives businesses the information needed to make those decisions. Higher-risk areas may need enhanced due diligence or closer monitoring, while lower-risk areas may be managed through standard controls.

It Helps Compliance Teams Use Resources Better

Compliance teams have limited time and resources. If every customer, transaction, and business activity receives the same attention, teams can end up spending too much time on low-risk areas.

A clear risk assessment helps prioritise the work. Staff can focus more closely on areas where a control failure would create greater regulatory or financial crime risk. FATF also notes that a risk-based approach can help organisations focus their resources where the risks are greatest.

What Should a Business Risk Assessment Cover?

A standardised assessment is not effective in all situations. The risk factors should reflect how the organisation operates, who it deals with, and where its exposure comes from.

Customer Risk

Start with the people and businesses you deal with.

Look at the types of customers you serve, their business activities, ownership structures, and overall risk profiles. Politically exposed persons, complex legal structures, cash-intensive businesses, or customers operating in higher-risk sectors may require closer consideration. CBUAE guidance also treats customer risk as an important part of institutional-level risk assessment.

The point is not to label an entire customer group as risky. It is to understand where additional controls may be appropriate.

Products and Services Risk

Certain products or services inherently face a higher risk of financial crime than others.

Think about whether a service allows rapid movement of money, large-value payments, international transfers, cash transactions, or complex financial arrangements. New products can also introduce risks that existing controls were never designed to manage.

For relevant UAE financial institutions, AML/CFT requirements specifically call for ML/TF risks linked to new products, practices, and technologies to be identified and assessed.

Geographic Risk

Where the business operates matters, but so does where its customers and transactions are connected.

A company may need to consider customer locations, the source and destination of funds, counterparties, and exposure to higher-risk jurisdictions. Geographic risk does not automatically make a relationship unacceptable. It tells the business when closer review may be needed.

The risk should also be considered alongside other factors rather than in isolation.

Delivery Channel Risk

How a customer reaches your business can affect the level of risk.

Remote onboarding, digital platforms, intermediaries, agents, and face-to-face relationships can each create different challenges. For example, a fully remote relationship may require stronger identity verification than a straightforward in-person interaction.

The assessment should look at whether existing controls are suitable for each channel and whether new technology has changed the exposure.

Transaction Risk

The way money moves through the business can reveal risks that are not obvious from the customer profile alone.

Consider transaction size, volume, frequency, payment method, cross-border activity, and whether behaviour matches what the business knows about the customer. Large or complicated transactions are not automatically suspicious, but they may require stronger monitoring depending on the circumstances.

This is why transaction information should feed into the wider business risk picture rather than being reviewed separately.

How Do You Conduct a Business Risk Assessment?

A good assessment needs a clear method, but it does not need to become an unnecessarily complicated exercise.

Identify the Inherent Risks

Start with the risks that exist because of the nature of the business, before considering the controls already in place.

Use real business information wherever possible. Customer profiles, transaction volumes, geographic exposure, products, services, previous incidents, and internal data can all help.

CBUAE’s sectoral assessment model similarly considers inherent risk factors before assessing control effectiveness and residual risk.

Review Your Existing Controls

Once the risks are clear, look at what the organisation is doing to manage them.

This may include KYC and customer due diligence, enhanced due diligence, sanctions screening, transaction monitoring, staff training, internal approvals, and suspicious transaction reporting processes. The important question is not simply whether the control exists.

You also need to consider whether it is working properly in day-to-day practice.

Assess the Remaining Risk

Even good controls do not remove every risk.

After considering the strength of existing controls, the business can assess the residual risk, which is the exposure that remains. The CBUAE’s sectoral methodology follows this general approach by considering inherent risk together with control effectiveness to arrive at residual risk.

If the remaining risk is higher than the organisation is prepared to accept, further controls or changes may be needed.

Document the Findings and Actions

The assessment should leave a clear record of what was reviewed and what happens next.

Document the risk factors considered, the reasoning behind the ratings, existing controls, any weaknesses found, and actions that need to be taken. CBUAE guidance expects risk assessment methodologies and findings to be documented for relevant regulated institutions.

This also makes the assessment much easier to explain during an internal audit or regulatory inspection.

Business Risk Assessment vs Customer Risk Assessment: What Is the Difference?

The two are closely related, which is why they are often confused, but they answer different questions.

A Business Risk Assessment Looks at the Organisation

A business risk assessment asks, ‘Where is our organisation exposed to financial crime risk?’

It takes a broad view across customers, products, services, transactions, jurisdictions, and delivery channels. The results help shape AML policies, controls, monitoring, and the organisation’s overall risk-based approach.

It is about understanding the risk profile of the business rather than one individual relationship.

A Customer Risk Assessment Looks at One Customer

A customer risk assessment asks a narrower question: How much risk does this particular customer present?

It may look at factors such as the customer’s occupation or business, ownership, location, expected activity, transaction behaviour, and other relevant information. Customers can then be placed into suitable risk categories and receive the appropriate level of due diligence.

Customer risk assessment results can also provide useful data for the wider business risk assessment.

What Happens If a Business Risk Assessment Is Weak?

A poorly designed or outdated assessment can affect far more than the risk rating itself.

High-Risk Areas Can Be Missed

If the assessment does not reflect the real business, important risks may never receive the attention they need.

For example, the organisation may expand into a new market but continue using a risk assessment based on its old customer base. Controls could then remain unchanged even though the underlying exposure has increased.

The problem is not simply an inaccurate document. It can influence the controls that come after it.

Controls May Not Match the Risk

AML controls should make sense for the risks they are supposed to manage.

If risk has been assessed poorly, the business may apply unnecessary controls in some areas while leaving genuine weaknesses elsewhere. That can create extra work for staff without actually improving compliance.

A stronger assessment helps connect controls to a clear reason for using them.

Regulatory Reviews Become Harder to Defend

During a regulatory inspection, simply saying that the organisation considers itself low risk is unlikely to be enough.

The business should be able to show how risks were identified, what information was used, how controls were assessed, and why particular ratings were reached. CBUAE’s supervisory approach itself uses risk assessments and control assessments to guide regulatory attention.

A clear methodology makes those discussions much easier.

When Should You Update a Business Risk Assessment?

A business risk assessment should reflect the business you operate today, not the business you had when the document was first written.

When the Business Changes

Review the assessment when you launch a new product, enter a new market, change your customer base, introduce a new delivery channel, or significantly change how transactions are handled.

These changes can create risks that were not included in the previous assessment. Updating the assessment early gives the compliance team time to decide whether existing controls remain suitable.

Risk should be considered as part of the change, not months afterwards.

When New Risks Emerge

Financial crime methods, sanctions exposure, technology, regulations, and sector risks continue to change.

New information from regulators, national or sectoral risk assessments, FATF publications, internal incidents, or industry trends may all affect the organisation’s risk profile. CBUAE guidance also expects relevant external information, including national and sectoral assessments, to feed into risk assessment methodology.

If new information changes your view of the risk, the assessment should change too.

During Regular Compliance Reviews

Even if nothing dramatic has happened, the business risk assessment should still be reviewed periodically.

Customer behaviour can shift gradually. Transaction volumes may grow. A product that once represented a small part of the business may become much more important.

Regular reviews help catch those changes before the assessment becomes disconnected from what the organisation actually does.

Conclusion

A business risk assessment gives your AML/CFT programme a starting point. It shows where financial crime exposure sits, whether existing controls are doing enough, and which areas need more attention. More importantly, it helps the business make risk decisions based on evidence rather than assumptions.

Vertex Compliance provides business risk assessment services for organisations that need a clearer view of their AML risks, controls, and remaining exposure. Its approach uses business, customer, geographic, transaction, and other relevant risk information to support practical risk management.

KYC, CDD & EDD: What’s the Difference?

KYC VS CDD VS EDD

Compliance practitioners know KYC (Know Your Customer), CDD (Customer Due Diligence) and EDD (Enhanced Due Diligence), but sometimes these terms are used interchangeably. Each plays a different role in helping businesses understand customers and manage financial crime risk.

KYC is all about who the customer is. CDD is a look at the overall risk of the customer and EDD is used when the risk is higher and needs to be looked at more closely.

Compliance teams can apply the right checks at the right time by understanding the difference between KYC, CDD and EDD. This also helps standardise onboarding and ongoing monitoring. Keep reading to explore more about KYC vs CDD vs EDD. 

What is Know Your Customer (KYC)?

Know Your Customer, often shortened to KYC, is the process of verifying a customer’s identity. It helps businesses ensure that the person or the company is legit.

For individuals, it needs verification of his / her name, date of birth, address and identity documents. For a business, it can include company registration details, directors, shareholders and beneficial owners.

KYC answers who is the customer, and is generally done at the time of onboarding. But customer information may also need to be refreshed later when important details change.

Business KYC often requires more than just verifying a company name. Compliance teams may need to know who owns, controls or benefits from the company.

This is particularly so where ownership is split between a number of companies or jurisdictions. It is easier to correctly assess the customer when the ownership information is clear.

What is Customer Due Diligence (CDD)?

Customer Due Diligence (CDD) is more than checking a customer’s identity. It helps a business to understand the customer, their relationship and what risk is involved.

It reviews the customer’s business activity, occupation, ownership structure, expected transactions, and geographic exposure. The idea is to know what normal activity should look like.

The underlying question CDD answers is: How risky is this customer?

This is where KYC and CDD are different. KYC verifies the identity and CDD uses more data to build a customer risk profile.

CDD also helps a company to understand how the customer is likely to use its products or services. This provides a useful baseline for future monitoring.

For example, a small local business would be expected to have very different transaction patterns than an international trading company. Major deviations from expected activity may require further review.

What Is Enhanced Due Diligence (EDD)?

Enhanced Due Diligence or EDD is a more detailed review for higher risk customers when standard CDD doesn’t give enough information to understand or manage the risk. EDD might require additional documents, more independent checks, or a closer look at ownership and financial activity. The review should focus on the specific risks that led to the customer being treated as higher risk.

The main question EDD asks is: Is this increased risk understood and reduced?

EDD does not necessarily mean rejection of the customer. This gives the business more information before they make that decision.

It may also involve additional due diligence on the customer’s background, business activities, ownership, source of funds or source of wealth. Independent information may also be used to verify the information provided by the customer. Customers with a higher risk may need to be monitored more frequently. It helps businesses to detect changes or anomalies earlier. Monitoring should be related to the already identified risks. It is not a review of every minor activity which is not a need.

When is EDD Needed?

EDD may be necessary where the customer presents factors that are a higher level of financial crime risk. These factors should be defined in the risk framework and the internal procedures of the organisation.

Examples include complex ownership, unusual transaction activity, links to higher risk jurisdictions, politically exposed persons or information that is difficult to verify.

EDD may be required in cases where regular CDD has been a cause for concern. If the customer information doesn’t make sense or you can’t confirm important details, it may be appropriate to do a deeper review.

Just because there’s a higher risk factor doesn’t mean suspicious activity is happening. It simply means that the business needs more information to make a good decision.

KYC, CDD and EDD: What’s the difference?

AspectKYCCDDEDD
Full FormKnow Your CustomerCustomer Due DiligenceEnhanced Due Diligence
Main PurposeConfirm who the customer isUnderstand the customer and their riskLook more closely at higher-risk customers
Level of ReviewBasic checksStandard checksMore detailed checks
When It Is UsedMainly during onboardingDuring onboarding and ongoing reviewsWhen higher-risk factors are found
Typical ChecksName, address, date of birth, ID documentsIdentity, ownership, business activity, expected transactionsSource of funds, source of wealth, ownership details, extra verification
Risk FocusConfirms identityHelps decide the customer’s risk levelLooks more closely at higher-risk areas
Information NeededBasic identity detailsMore information about the customerAdditional details and proof
MonitoringMainly initial checksOngoing customer reviewsCloser or more frequent reviews
Key QuestionWho is the customer?What risk does this customer present?Do we understand this higher risk well enough?
Role in ComplianceConfirms customer identityBuilds an understanding of customer riskHelps investigate higher-risk customers

The best way to understand KYC, CDD and EDD is to look at the purpose of each process. They are closely interconnected, but each performs a different degree of review.

The three processes should not be viewed as separate exercises. All of these are part of one customer risk management process.

How Does It Work?

The process starts with KYC. The business collects and verifies enough information to establish that the customer is who he says he is.

Then CDD helps the business understand why the customer needs the service, what activity is expected, and what risks might be present.

The information obtained can then be used to assign a risk rating to the customer. Lower risk customers can stay with standard controls and higher risk customers can move to EDD.

Onboarding is not the end of the process. Customer risk can be affected by changes such as to ownership, transaction behavior, business activity or location.

Common Mistakes of KYC, CDD and EDD

Avoid these mistakes to prevent bigger compliance gaps down the line:

Document-Only Checks

Some teams are of the perception that KYC is just collecting identity documents. That misses the bigger picture of knowing who the customer is and does this information make sense.

Uniform Checks

The same checks applied to every customer can be inefficient. Customers with lower risks may suffer unwarranted delays, and those with a real higher risk may not receive enough attention.

Weak Justification

You should not use EDD simply because a customer looks unusual. Any request for further information should be clearly justified on a risk basis.

Poor Documentation

Compliance teams should note why a customer received a particular risk rating. They should also record what checks were carried out and the reasons for the decision.

Outdated Information

Customer risk is time-dependent. If the ownership, business or transaction information becomes outdated, the original risk assessment may no longer be valid.

Missed Changes

A customer could appear to be low risk at onboarding but turn out to be higher risk later. Major changes in behavior or ownership should be reviewed.

Get KYC, CDD, and EDD Right

KYC, CDD and EDD are related but they are for different purposes. KYC is verifying the customer identity, CDD is knowing the customer and risk profiling and EDD is extra checks when there are high risk factors.

The best way is to not put the most checks on each customer. This means applying the right level of review based on the level of actual risk, keeping clear records and revising the assessment if customer circumstances change.

Frequently Asked Questions 

1. When should a customer’s risk profile be reviewed?

Customer risk should be reviewed periodically and whenever there is a significant change in activity, ownership, location, transaction behaviour, or other relevant risk factors.

2. What can trigger additional customer verification?

Triggers may include unusual transactions, changes in beneficial ownership, links to high-risk jurisdictions, sanctions exposure, inconsistent information, or unexpected changes in customer behaviour.

3. What records should businesses keep during customer checks?

Businesses should maintain identification records, verification evidence, risk assessments, screening results, supporting documents, review notes, and records explaining important compliance decisions.

4. Can customer due diligence processes be automated?

Parts of the process can be automated using identity verification, screening, risk scoring, and monitoring tools. However, higher-risk cases may still require manual assessment and compliance judgement.

5. What happens if customer information becomes outdated?

Outdated information can affect the accuracy of a customer’s risk assessment. Businesses may need to obtain updated documents, repeat relevant checks, and reassess the relationship.

6. How often should businesses update customer information?

There is no single review frequency suitable for every customer. Review schedules are generally determined by the customer’s risk level, regulatory requirements, and changes identified during ongoing monitoring.

Top 10 Tips for AML Inspection Preparation

AML Inspection Preparation

Anti-Money Laundering (AML) inspections are an important part of the UAE’s efforts to reduce financial crime and ensure businesses follow regulatory requirements, as highlighted in the FATF–MENAFATF Mutual Evaluation Report of the UAE. They help regulators confirm that businesses are not just meeting legal requirements but also applying proper controls in daily operations.

For regulated entities, inspection readiness must not begin only after receiving a notice. Strong AML compliance needs clear policies, trained staff, accurate records and regular risk reviews throughout the year. The guide explains what to review, which documents to organise for AML inspection preparation, and how to help your team respond confidently.

What is an AML Inspection?

An AML inspection is a regulatory review conducted to evaluate whether a business is meeting its Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) obligations. Inspectors may review whether the company can identify suspicious customers and transactions and report them efficiently. AML supervisors may use on-site visits, transaction sampling, desk-based reviews and interviews with staff.

Why is an AML Inspection Preparation Important?

Preparation is important because regulators assess both your written policies and whether controls work effectively in day-to-day operations. It can help detect if any missing KYC records are there, along with other key details such as owner information and outdated risk assessments. Businesses maintaining strong compliance frameworks are usually better prepared for inspections.

How to Prepare for an AML Inspection?

Regulators want to understand whether your controls work consistently in daily operations. Clear documentation and a clear process for those who understand their responsibilities will make the inspection far more manageable. Here is an AML inspection checklist. 

  1. Review your AML policies and procedures

Verify if your AML policies reflect current regulations, products, business activities, customers and geographical risks. Make sure that the written procedures clearly explain how customer checks, monitoring, reporting and escalation are handled. The process described in the policy must match employees’ responsibilities.

  1. Run a Mock Inspection

Test how your business would respond to a real inspection. Ask your team to find requested documents, explain key processes, and walk through sample customer files and transaction cases. This can reveal delays, missing records, and unclear responsibilities before the regulator does.

  1. Review Customer Files

Audit a sample of customer files to identify missing or outdated information. Names, identity documents, addresses, ownership details, and risk levels should be clearly registered. Proper approval and extra checks should also be in place for higher-risk customers.

  1. Revisit your Risk Assessment

Your risk assessment should identify what are likely to be your most significant money laundering risks. This could be specific customers, countries, services or means of payment. Make it practical, showing how your business deals with each risk you have identified.

  1. Check Transaction Monitoring and Alerts

Make sure unusual transactions are identified and checked on time, whether your process is manual or automated. Each decision should clearly show what was examined and why the activity was closed or reported.

  1. Verify how Suspicious Activity is Reported

Employees should know who to contact when something looks unusual. Your records should show when a concern was raised, how it was reviewed, and what decision was made. Even when no report is submitted, the reason should still be written down.

  1. Check Sanctions and PEP Screening

Make sure customers and relevant connected parties are checked against sanctions and politically exposed person lists. Screening should continue throughout the customer relationship, and possible matches should be investigated and recorded.

  1. Keep AML Training Records Up to Date

Keep a clear record of who completed AML training and when. Training should be easy to understand and relevant to each employee’s role. Staff should know how to recognise warning signs and what to do when they notice something unusual.

  1. Prepare Your Team for Questions

Inspectors may speak directly with employees, so staff should understand their responsibilities. They do not need to memorise formal answers. They should simply be able to explain what they do, what warning signs they look for, and who they contact when they have concerns.

  1. Be Open about Existing Gaps

Don’t hide issues you already know about. What’s the problem? How did it get there? What are you going to do about it? As a rule, pretending that you have no weaknesses is worse than having a clear plan for improvement.

What Happens During an AML Inspection?

During the inspection, the regulator may review your AML policy, records of customers, risk assessments, training documents and reports of unusual activity. They may also ask staff how they handle customer cheques or concerns. The aim is to test your AML process on paper and in practice.

What are the Documents Required for an AML Inspection Preparation?

The documentation you’ll be asked to produce will depend on your business, but inspectors will generally want to see AML policies, customer files, risk assessments, training records and evidence of internal checks. Keep these records in full, current and accessible. Disorganised AML documents can make a functioning AML process look unreliable.

What Are the Common AML Inspection Mistakes?

Common mistakes include missing customer information, outdated policies, unclear risk ratings, weak written explanations, and incomplete training records. Another major issue is when employees follow a different process from the one described in the company’s policy. A practice inspection can help uncover these gaps before the regulator finds them.

Stay Ready with AML Periodic Inspections

Regular AML inspections help you spot weak controls before they become regulatory problems. With Vertex Compliance’s AML Periodic Inspection service, you can review your policies, customer records, risk assessments, and reporting process against current UAE requirements. You also receive practical guidance on what needs attention and how to address it. Do not wait for a regulator to uncover avoidable gaps. Request inspection support and prepare your business with greater clarity, control, and confidence before the next inspection.

Frequently Asked Questions

Will I be notified before an AML inspection?

Some inspections are scheduled; others can be unannounced. This is why it is important to keep your records and processes organised throughout the year. If you wait until you receive the inspection notice to review everything, you’ll end up with rushed fixes and missing information.

What documents should be prepared for an AML audit?

Your AML policies, customer records, risk assessments, training records, internal review reports and reporting documents should be current and easy to find. Inspectors may request records from a variety of dates, so don’t simply prepare the latest files.

Will the inspectors talk directly with the employees?

Yes, employees could be questioned about how they check customers, identify irregular activity and report concerns. Staff don’t need rehearsed answers, but they do need to understand their role and be able to describe the process in their own words.

What happens if an inspector finds gaps?

You may be asked to explain the issue and provide a plan for correcting it. Trying to hide a weakness can create a bigger problem. It is better to show that the gap has been identified, someone is responsible for fixing it, and corrective work has started.

How can Vertex Compliance support inspection readiness?

Vertex Compliance can review your AML controls, identify missing or weak areas, and help organise the records needed during an inspection. The team can also prepare employees for likely questions and provide a practical action plan so your business knows what to fix first.

Common AML Compliance Gaps Found During Reviews

AML Compliance Gaps

An AML programme may look complete on paper and still fail when reviewed in practice. The UK Financial Conduct Authority’s 2025 report found that most reviewed firms had a business-wide risk assessment, but very few had properly adapted it to their actual risks. The review found that some firms were unable to clearly explain how they were managing the risks they had identified. And these results indicate a bigger problem. AML weaknesses are more about poor implementation than lack of policies. Keep reading to explore the common AML compliance gaps. 

Why AML Gaps Appear During Reviews

Many businesses treat AML compliance as a document exercise. They write policies, collect IDs, perform training, but they don’t test those controls to see how they’re working in the real world on a day-to-day basis.

Compliance review includes review of customer files, risk ratings, screening results, alerts, internal reports, training records and management oversight.

A thorough review will show that AML controls are risk-based, applied consistently and supported by evidence. Reviewers must see a clear trail from the identified risk to the action taken, the person responsible and the final decision. Clear the train when there is a change of staff, systems or responsibilities.

What are the Common AML Compliance Gaps Found During Reviews?

1. Generic or Old Risk Assessments

What Reviewers Find

The business risk assessment could be a copy of a template or based on old information. This assessment may not reflect current customers, products, locations, channels or transaction patterns. Some of the assessments list risks but do not explain how the risks were scored or controlled.

How to Repair

Review it from time to time and update the assessment as the business changes. Keep clear records of inherent risk, control effectiveness and residual risk. Each major risk must have a control, owner and review date.

2. Low-risk Customer Ratings

What Reviewers Find

Customers are often labelled low, medium or high risk with no clear rationale. Staff may rely on personal judgment instead of approved risk factors. A change in ownership, activity or transaction behaviour may also leave ratings unchanged.

How to Repair

Use documentable factors such as customer type, geography, ownership, products and expected activity. Determine when a high-risk rating is required. Look for big changes, strange activity or new screener results.

3. Incomplete Customer Due Diligence

What Reviewers Find

Files may have expired IDs, unavailable addresses, or unclear relationship information. Ownership documents or beneficial-owner evidence may not be in company files. Getting papers is not enough. The staff must check that the information is complete, consistent and reliable.

How to Repair

Use a checklist appropriate to the customer’s legal form and level of risk. Verify the information through a reliable person who ultimately owns or controls the entity. Use a chart for complex structures.

4. Poor Beneficial Ownership Checks

What Reviewers Find

Some firms accept the shareholder named on the first company document and do not follow the chain of ownership. The file may not represent the ultimate owner or controller of the customer. Screening checks can also fail to detect beneficial owners.

How to Repair

Trace the chain of ownership to the natural person who ultimately owns or controls the entity. A chart may be useful for complex structures. Verify facts with reliable sources and keep it simple.

5. Inconsistent Enhanced Due Diligence

What Reviewers Find

A high-risk customer may receive the same checks as a low-risk customer. There may be no source of the funds, or senior approval, or more robust monitoring. You can collect more documents without checking the coherence of the information.

How to Repair

Carry out stronger identity checks, verify the source of funds or wealth, obtain senior approval and review the customer more often. Document why the business relationship is acceptable despite the higher risk.

6. Sanction and PEP Screening Gaps

What Reviewers Find

Screening is only available at onboarding. Ownership details or political exposure are subject to change, and customers are not always re-checked. Extra documents may be collected without deciding whether the information makes sense.

How to Repair

Screen customers, beneficial owners and related parties at onboarding and throughout the relationship. Save the date, result, lists checked and decision. Define clear escalation rules and train staff to review aliases, ownership links and possible matches.

7. Ineffective Transaction Monitoring

What Reviewers Find

Rules for monitoring are frequently too broad, too narrow, or irrelevant to the business. This situation leads to many weak alerts and serious activity. Many weak alerts arise from this situation, resulting in the loss of serious activity. It can also make it challenging to spot unusual transactions when there is an absence of expected customer activity.

How to Repair

Monitor real products, customers, channels and risks. Review thresholds as behaviour, services and threats change. Find out why there is each rule and see if it works.

8. Weak Suspicious Activity Escalation

What Reviewers Find

Employees can see suspicious activity but cannot report it. They may assume automated monitoring, or the compliance team will identify the issue. Investigations may remain open without deadlines, evidence or clear decisions.

How to Repair

Establish a transparent internal reporting channel for employees and emphasise role-specific warning signs. Any concerns should be reported promptly to the MLRO or the compliance officer. Use a standard investigation record covering the activity, decision, evidence and reasoning.

9. Policies That Don’t Match Practice

What Reviewers Find

Policies may refer to systems, approval levels, review periods or roles that no longer exist. Employees may do something different than what is written. They do this by comparing policies with files and interviewing staff.

How to Repair

Map every policy requirement to an actual task, owner and record. Update documents when systems, services or responsibilities change. Ask employees to explain the process. There is no room for any gap between policy and practice.

10. Generic Training & Lack of Oversight

What Reviewers Find

Annual training may cover basic AML terminology but may ignore the risks employees face. The staff can get a quiz right and still miss a real red flag. Management reports could omit overdue reviews, high-risk customers, open alerts and unresolved findings.

How to Repair

Provide role-based training with examples from the business. Track attendance, test understanding, and refresh training as risks change. Provide management with clear reports of trends, exceptions and overdue actions. The MLRO should have sufficient authority, information and support.

How to Prepare for an AML Compliance Audit?

Conduct an internal gap assessment using samples of real customer files, alert and transaction samples. Ensure that the written policies align with actual practices.

Interviewing employees reviewing management information and checking that previous findings had been acted upon. Focus on weaknesses that might prevent the business from identifying high-risk customers or suspicious activity.

Close AML Gaps Before They Become Findings

Gaps in AML controls typically occur where risk assessments, customer checks, monitoring, reporting, training and oversight all fail. You can’t fix a bigger control problem by fixing one document.

Vertex Compliance offer services such as finding gaps in AML/CFT, conducting independent evaluations, assessing risks, helping with sanctions compliance, creating policies, performing internal audits, managing KYC services, and providing AML training tailored to specific roles. We can identify weaknesses, develop remedial actions, and prepare your AML programme for independent or regulatory review.

Contact us today to discuss your AML requirements and improve your controls before your next compliance review.

Frequently Asked Questions 

What should we do after AML gaps are found?

Start by creating a clear action plan. Write down what needs to be fixed, who will handle it, and when it should be completed. Keep records of every change so you can show that the business has acted on the review findings. 

Which AML gaps should be fixed first?

Deal with the issues that create the greatest risk first. For example, a serious weakness in customer checks or suspicious activity reporting should not be treated the same as a minor filing error. Prioritising the work helps prevent important problems from being delayed.

Who is responsible for fixing AML compliance gaps?

The compliance officer usually coordinates the work, but fixing the gaps may involve several teams. Senior management should also follow the progress and make sure the right people, time, and resources are available. AML compliance cannot be left to one employee alone. 

How can we prevent the same gaps from appearing again?

Do not treat the review as a one-time exercise. Check that the new process is actually being followed, provide refresher training, and review the corrected areas again. Regular checks help confirm that the problem has been properly fixed rather than temporarily covered up. 

How can Vertex Compliance help close AML gaps?

Vertex Compliance can review your existing AML framework, identify areas that need attention, and provide a practical roadmap for improvement. The support is tailored to your business, helping your team understand what to fix and how to strengthen its compliance process.

What is AML/CFT Compliance in the UAE?

AML/CFT Compliance UAE

The UAE market is fast moving and tightly regulated. Opportunities take time to develop quickly, but so can exposure to financial crime. A customer that looks legitimate, but has a complex ownership structure, can trigger red flags that your business can’t afford to ignore. 

That’s where AML/CFT compliance begins. It is not just a file prepared for an inspection, but how a company understands risk and protects its license, reputation, and commercial relationships. Let us explore what AML/CFT compliance UAE means, why it matters and where the responsibility really begins. 

What is AML?

Money laundering is the process of disguising the proceeds of crime as legitimate funds. In the UAE this might mean moving money through businesses, bank accounts, property deals, trade transactions or high value goods to disguise the source of the money. The activity is frequently staged, and difficult to detect without proper checks. 

Money laundering is a crucial issue for UAE businesses, even an unintentional failure to flag suspicious activity can result in significant regulatory and reputational risk. AML or anti money laundering refers to a global framework that carries out stringent customer due diligence, transaction monitoring and timely reporting to protect businesses against financial crime.

What is CFT?

CFT stands for Countering the Financing of Terrorism. The money is from illegal or legitimate sources (money laundering is always illegal money) so may be harder to spot. 

It involves identifying who their customers and beneficial owners are, where their funds come from, monitoring transactions for suspicious activity and reporting concerns through the appropriate channels. These controls help to protect businesses from legal and reputational harm, as well as supporting the UAE’s efforts to maintain a secure and trusted financial system globally.

Why does AML/CFT Compliance UAE matters for banking organisations?

Here is why compliance matters.

1. Banking professionals are the first line of protection

The Central Bank of the UAE considers banking professionals as the first line of defence. They can spot problems easily and prevent suspicious activity from worsening. 

2. Accurate customer due diligence helps

UAE licensed financial institutions are not permitted to accept anonymous accounts or fictitious identities. Banking professionals must also understand ownership structures, beneficial owners, business activities and the expected source of funds. This allows the bank to make the right decisions based on proper due diligence, not just the documents gathered at onboarding.

3. Spots suspicious activity

Suspicious activity may always not look like a large cash deposit or an illegal transaction. Frequent movement of cash without any clear ground, sudden changes in the behaviour of the account can all be accounted for by suspicious activity. Early identification helps banks to investigate well and escalate concerns faster.  

4. Enables timely and accurate reporting

In case of any suspicious matters, it should be referred to the relevant internal team without delay. The compliance function or MLRO can then decide if a report should be submitted to the UAE Financial Intelligence Unit. Employees must provide clear facts, details of the transaction, customer information and why the activity seemed unusual. 

5. Makes sanctions stronger and blocks terrorist funding

Banks shall ensure that funds and financial services are not made available to sanctioned individuals, organisations or parties linked to terrorist financing. Banking professionals must be alert to transactions that could imitate the real beneficiary.

Who must follow AML/CFT regulations in the UAE?

The following businesses and professionals may be exposed to the risks of money laundering or CFT. 

  • Banking, money changing and financial houses
  • Insurance companies and insurance personnel
  • Payments service providers
  • Hawala providers (licensed)   
  • Real estate agents & brokers
  • Dealers in precious metals and stones 
  • Independent public accountants and auditors
  • Trustees & corporate service lawyers and legal advisers  
  • Providers in connection with certain financial or commercial transactions licensed crypto exchanges, brokers and custodians (virtual asset service providers) 

Compliance requirements are specific to the business activity, the licence and the supervisory authority.

What happens if a business is non-compliant?   

Failure to comply with the AML/CFT requirements may lead to severe consequences, including:

Regulatory action

The supervisory authorities may inspect, take corrective measures, limit operations, suspend operations or act against the company’s licence. 

Financial penalties

Companies could be hit with large administrative fines. According to the Central Bank of UAE report 2024, UAE regulators have imposed multi-million-dirham penalties on businesses who have failed to comply with the AML/CFT systems and controls. 

Reputational damage

Public enforcement actions can reduce confidence among customers, banks, investors and business partners.   

Business disruption

The company may need to review customer files, tighten controls, retrain staff and make significant investment in urgent remediation. This raises the cost and disrupts routine.

In extreme cases the breach may also be subject to criminal penalties depending on the nature of the offence.

Does your AML/CFT framework work in practice?

Understanding AML/CFT requirements is only the first step. It will be the real test for UAE banks and financial institutions as to whether customer due diligence, sanctions screening, transaction monitoring, risk assessments and internal reporting processes work consistently across the organisation.

Teams managing these processes on a day-to-day basis don’t always see the gaps in compliance. An independent review can help find weaknesses before they become regulatory findings, financial losses or reputational damage.

Vertex Compliance provides UAE organisations with AML/CFT gap assessments, independent assessments, ML/TF risk assessments, sanctions compliance, typology assessments and monitoring-rule optimisation. Our approach is customised to the institution’s risk profile, operations and regulatory requirements.

Are you confident in your existing controls to hold up to regulatory scrutiny? Book a compliance consultation to review your AML/CFT framework and identify areas for improvement. 

FAQs

1. What is AML/CFT compliance UAE?

AML/CFT means anti-money laundering and counter terrorist financing systems and controls. In the UAE, financial institutions must understand their exposure to financial crime, verify customers, monitor transactions, screen relevant parties and report suspicious activity. The framework should be commensurate with the size of the institution, the services it offers, the customers it serves, its delivery channels and its geographical risks.

2. Who is regulated by the AML/CFT regulations in the UAE?

Licensed banks and other financial institutions supervised by the CBUAE are subject to the relevant UAE AML/CFT requirements. These include exchange houses, finance companies, payment service providers, registered hawala providers and other regulated financial institutions. This is not just the responsibility of the MLRO or compliance department. Accountability extends to senior management, onboarding teams, relationship managers, operations staff and employees involved in customer transactions.

3. What are the main AML/CFT obligations imposed on banks in the UAE?

UAE banks have to adopt a risk-based approach for customer due diligence, beneficial ownership verification, transaction monitoring, sanctions screening, record-keeping and suspicious activity reporting. More risky relationships might need more due diligence and more frequent ongoing monitoring. Banks should have adequate governance, staff training, internal reporting and independent testing arrangements; The CBUAE AML/CFT Rulebook is the single point of reference for licensed financial institutions.

4. What are the consequences if a financial institution does not comply?

Weak AML/CFT controls can have serious consequences for a UAE financial institution including regulatory findings, remediation requirements, financial penalties, operational restrictions and reputational damage. Monitoring of compliance is done through on-site examinations, off-site supervision, thematic reviews and enforcement actions. Paper policies are not enough anymore. Institutions need to demonstrate that their controls are not only in place but also work in practice.

5. How can Vertex Compliance help you on AML/CFT compliance?

Vertex Compliance gives UAE financial institutions the means to determine whether their AML/CFT controls are aligned with their regulatory requirements and true risk profile. Services include AML/CFT gap assessments, independent assessments, ML/TF risk assessments, sanctions compliance reviews, typology assessments, proliferation financing risk assessments and monitoring rule optimisation. A focused review will uncover vulnerabilities that internal teams miss.