# Compliance Stack for a Licensed Operator: Roles, Policies, Systems and Audit

> How a regulated firm's AML/CTF and sanctions programme works in the UK, EU, Hong Kong, Singapore, the UAE and the US: roles, BWRA, scoring, monitoring, SARs, records, audit and fines.

Author: Maria Plotnikova — Lawyer, Family Office (https://wiki.private.law/en/authors/plotnikova)
Last modified: 2026-09-28T00:00:00.000Z
Canonical: https://wiki.private.law/en/compliance-stack
Publisher: wiki.private.law (https://wiki.private.law)
Version: c2388c9e8f7b794c48fccb7b2e639c4b6afeef0974df0ac7439c4cbaefb6bdec
Cite as: Compliance Stack for a Licensed Operator: Roles, Policies, Systems and Audit. wiki.private.law. https://wiki.private.law/en/compliance-stack. Version c2388c9e8f7b794c48fccb7b2e639c4b6afeef0974df0ac7439c4cbaefb6bdec.
Topics: banking
Jurisdictions: global, uk, eu, usa, hong-kong, singapore, uae
Product tags: compliance, banking, crypto
Semantic tags: compliance, banking, crypto

---

A regulated firm's compliance programme is a system of roles, risk assessments, policies, controls and evidence that lets the licensee show a supervisor, an auditor or a correspondent bank, at any moment, how it knows its customers, how it spots what is suspicious and what it does next. A licence is granted once; the programme is tested continuously — by inspections, independent audit, bank questionnaires and requests from the financial intelligence unit.

The basic construction is the same in the UK, the EU, Hong Kong, Singapore, the UAE and the United States. The divergence sits in the detail — who signs, how quickly a report is filed, how many years records are kept, whether a function can be handed to a contractor — and the detail is what firms are fined for.

## Concept

The common denominator is set by the FATF. [Recommendation 18](https://www.fatf-gafi.org/content/dam/fatf-gafi/recommendations/FATF%20Recommendations%202012.pdf.coredownload.inline.pdf) requires financial institutions to implement programmes against money laundering and terrorist financing, and its interpretive note spells out the content: a compliance officer at management level, screening of staff on hiring, ongoing training and an independent audit function. Alongside sit Recommendations 10 (CDD), 11 (records kept for at least five years), 20 (prompt reporting of suspicion to the FIU) and 21 (safe harbour for good-faith reporters and a prohibition on tipping off). National law turns the standard into obligations with dates and penalties.

Inside the firm the programme works as a chain in which each link rests on the one before. There are seven links:

1. Business-wide risk assessment (BWRA, also called EWRA) — the risk of the business as a whole.
2. Risk appetite and written policies approved by the management body.
3. Customer risk assessment — a risk rating for each customer at onboarding.
4. CDD, SDD or EDD according to that rating, and periodic file refresh.
5. Transaction monitoring and sanctions screening.
6. Escalation of suspicion and reporting to the FIU (SAR/STR).
7. Records, training, independent review and reporting to the management body.
A break in any link devalues the rest: monitoring without a BWRA cannot be justified, a SAR without records cannot be substantiated, and a review that never reaches the board changes nothing.

### There are no five pillars

The "five pillars of AML" is a convenient formula for a slide and useless for a review: there are several statutory constructions, they almost coincide, and the gaps between them matter.

A US money services business is built on [31 CFR 1022.210](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1022): four elements — internal controls, a designated person, training and independent review. A bank under [31 CFR 1020.210](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.210) adds a fifth — risk-based CDD covering beneficial owners and ongoing monitoring. A risk assessment is formally not on the list. It appears in [FinCEN's NPRM of 10 April 2026](https://www.federalregister.gov/documents/2026/04/10/2026-07033/anti-money-laundering-and-countering-the-financing-of-terrorism-programs) inside internal controls, together with CDD.

Canada runs six elements under FINTRAC guidance, with training split into a programme and a written plan. The effectiveness review must start "no later than 2 years (24 months) from the start of the previous review"; the reviewer is an internal or external auditor or, if there is none, the operator itself.

The EU changes the architecture wholesale on 10 July 2027. Article 9 AMLR lists ten mandatory policy areas — from the BWRA, CDD and STRs through outsourcing, good-repute screening on hiring and training — "recorded in writing", and article 9(3) introduces an independent audit function. How AMLR, AMLD6 and AMLA fit together is set out in the piece on the [EU AML package](https://wiki.private.law/en/eu-aml-package).

The UK is built differently. [Reg 21(1) MLR 2017](https://www.legislation.gov.uk/uksi/2017/692/regulation/21) requires a responsible board member, employee screening and an independent audit function, but each of the three is qualified by "where appropriate with regard to the size and nature of its business". A nominated officer under reg 21(3) is mandatory without qualification, and the supervisor must be told of the appointment within 14 days.

Hence the conclusion that breaks most group-wide policies: a firm of identical risk must be reviewed every 24 months in Toronto, at its discretion in Dublin until 2027, must sign a personal annual certification in New York, and can justify having no audit function in London on grounds of size.

The key parameters the article returns to below are gathered in one table.

| Parameter | Value |
| --- | --- |
| International standard | FATF R.10, 11, 18, 20, 21; October 2025 edition |
| Programme skeleton | US — 4 elements (banks — 5 with CDD); Canada — 6; EU — 10 policy areas plus an audit function; UK — reg 21 qualified by size |
| AMLR (EU) 2024/1624 applies | 10 July 2027 |
| Customer data refresh (art. 26 AMLR) | at least every year for customers under EDD, at least every five years for the rest |
| SAR in the US | 30 days from detection, up to 60 where no suspect is identified |
| Record retention | at least 5 years in all six jurisdictions |
| US programme reform | FinCEN NPRM of 10 April 2026; no final rule as of September 2026 |
| MLRO cost, London | £140–300k base salary in the payments sector |

## Why the programme exists

The FATF was created in 1989, and its Recommendations follow a simple logic: money cannot be laundered without a financial intermediary, so the intermediary is obliged to watch its customers. A compliance programme makes that watching systematic and independent of any one employee's instinct. In February 2025 the FATF revised R.1 and the interpretive notes to R.1, 10 and 15: "commensurate" became "proportionate", and the standard now expressly encourages simplified measures where risk is low, for the sake of access to financial services. The risk-based approach became a requirement in both directions — towards relief and towards tightening.

The US has moved the same way. After the AML Act of 2020 FinCEN set national AML/CFT Priorities, and in April 2026 it [withdrew the 2024 proposal](https://www.federalregister.gov/documents/2026/04/10/2026-07033/anti-money-laundering-and-countering-the-financing-of-terrorism-programs) and replaced it: the programme must be "effective", resources go to higher-risk customers, and supervisory criticism targets "significant or systemic failures". Comments closed on 9 June 2026. On [9 July 2026](https://www.federalregister.gov/documents/2026/07/09/2026-13919/anti-money-laundering-and-countering-the-financing-of-terrorism-programs) the Federal Reserve published a parallel proposal for its supervised banks, with comments to 8 September and effect twelve months after a final rule.

A licensee has four examiners: the supervisor checks the programme against the rules, the FIU judges report quality, the auditor tests whether what is written actually works, and the correspondent bank decides whether to keep the account — fastest of all. The price of failure is a fine for the firm, a personal sanction for the officer, loss of the licence or loss of banking. Two other requirements hold a licence up alongside the programme, and supervisors test them just as continuously: [regulatory capital](https://wiki.private.law/en/regulatory-capital) and the [fitness of owners and managers under the qualifying-holding and fit and proper rules](https://wiki.private.law/en/qualifying-holding-fit-proper).

## Roles and responsibilities

### The management body

The Basel Committee places ["principal responsibility"](https://www.bis.org/fsi/fsisummaries/aml_cft_banking.htm) for ML/TF risk on the board of directors: the board approves policy and allocates resources. The UK requires a responsible board member (reg 21(1)(a) MLR), the EU a compliance manager on the management body (art. 11 AMLR), FinCEN's 2026 proposal board approval of the programme, and the UAE policies approved by senior management ([art. 19(1)(d) of Federal Decree-Law No. 10/2025](https://uaelegislation.gov.ae/en/legislations/3314/download)).

Banks test this directly. The CBDDQ asks: "Does the Board receive, assess, and challenge regular reporting on the status of the AML, CTF, & Sanctions programme?" Minutes recording debate and actions answer that question better than minutes recording "noted".

### The AML officer across six jurisdictions

The role commonly called the MLRO is anchored in a different rule in each jurisdiction and carries its own features.

| Jurisdiction | Role | Rule | Feature |
| --- | --- | --- | --- |
| UK | nominated officer (MLRO); SMF17 in SM&CR firms | MLR reg 21(3)–(4); SYSC 6.3.9R; SUP 10C.4.3R | supervisor notified within 14 days; EMIs and PIs also need a person under reg 21(7) |
| EU | compliance manager and compliance officer | art. 11 AMLR; EBA/GL/2022/05 | roles may be combined in small firms; supervisor notified of the officer's removal |
| Hong Kong | CO and MLRO | SFC and HKMA guidelines; C&ED for MSOs | senior management, independent of business; for MSOs an employee or the owner |
| Singapore | AML/CFT compliance officer | MAS Notices 626, SFA04-N02, PSN01, PSN02 | "at the management level" |
| UAE | compliance officer | art. 22 Cabinet Resolution 134/2025 | management level, independence in decision-making |
| US | BSA / AML/CFT officer | 31 CFR 1020.210, 1022.210 | appointed without regulatory approval; 2026 proposal — located in the US |

Behind the same label sit three incompatible legal constructions, and they determine where personal risk lands.

**Regulatory approval of the individual.** In UK firms under SM&CR the money laundering reporting function is [SMF17 under SUP 10C.4.3R](https://www.handbook.fca.org.uk/handbook/SUP/10C/4.html); [SYSC 6.3.9R](https://www.handbook.fca.org.uk/handbook/SYSC/6/3.html) requires authority, independence, resources and, normally, UK residence, and SYSC 6.3.7G an MLRO report at least annually. Ireland's equivalent is PCF-15; the status is publicly checkable. Payment and e-money institutions outside SM&CR appoint a nominated officer under the MLR and a separate person under reg 21(7).

**The EU's two-tier construction.** [Article 11 AMLR](https://eur-lex.europa.eu/eli/reg/2024/1624/oj) separates a compliance manager — a member of the management body — from a compliance officer "with sufficiently high hierarchical standing". The officer reports directly, is protected "against retaliation, discrimination and any other unfair treatment", and the supervisor is notified of any removal; in small firms the roles may be combined. The detail sits in [EBA/GL/2022/05](https://www.eba.europa.eu/sites/default/files/document_library/Publications/Guidelines/2022/EBA-GL-2022-05%20GLs%20on%20AML%20compliance%20officers/1035126/Guidelines%20on%20AMLCFT%20compliance%20officers.pdf): ¶28 — the officer is "normally contracted and work in the country in which the institution is established"; ¶31(a) — no reporting line to a business-line head; ¶50 — an annual activity report.

**The US "designated person".** [31 CFR 1022.210(d)(2)](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1022) involves no approval at all: the firm simply names someone. That individual is the one fined personally. The 2026 proposal adds a requirement that the AML/CFT officer be located in the United States and available to FinCEN and supervisors.

Asia adds its own detail. The [SFC](https://www.sfc.hk/-/media/EN/assets/components/codes/files-current/web/guidelines/guideline-on-anti-money-laundering-and-counter-financing-of-terrorism-for-licensed-corporations/AML-Guideline-for-LCs-and-SFC-licensed-VASPs_Eng_1-Jun-2023.pdf) requires the CO and MLRO to come from senior management (¶3.5), to be independent of the business subject to size, "normally based in Hong Kong" and to have a deputy (¶3.7). The [Customs licensing guide](https://eservices.customs.gov.hk/MSOS/download/guideline/Licensing_Guide_en.pdf) for MSOs (§4.15(a)) requires the CO and MLRO to be the applicant's employees under the Employment Ordinance unless the owner, partner or director takes the roles. MAS AML/CFT notices (for example [Notice 626](https://www.mas.gov.sg/regulation/notices/notice-626)) require an "AML/CFT compliance officer at the management level", and [Basel d505](https://www.bis.org/bcbs/publ/d505.pdf) ¶23–24 requires the chief AML officer to carry no business responsibilities.

### Personal liability

Personal liability materialised first in the United States and Singapore. FinCEN [fined BSA officer Gyanendra Kumar Asre $100,000 and barred him for five years from participating in the affairs of any BSA-covered institution](https://www.fincen.gov/news/news-releases/fincen-assesses-100000-civil-money-penalty-against-gyanendra-kumar-asre) (31 January 2024).

On 4 July 2025, as part of its [actions against nine financial institutions for AML-related breaches](https://www.mas.gov.sg/regulation/enforcement/enforcement-actions/2025/mas-takes-regulatory-actions-against-9-financial-institutions-for-aml-related-breaches), MAS issued prohibition orders against four people at the fund manager Blue Ocean Invest: six years for its then chief executive Tsao Chung-Yi and five years for its chief operating officer, both from 1 August 2025, and three years each for an executive director and relationship manager and for a former relationship manager. MAS found that the two senior managers had failed to ensure that AML/CFT policies and controls kept pace with significant growth in the business. The vector runs both ways: towards the officer and towards operational management.

### Three lines of defence

The three-lines model describes who in the firm does the work, who controls it and who checks the controller. In the [Basel Committee's](https://www.bis.org/fsi/fsisummaries/aml_cft_banking.htm) formulation the first line is the business units, which identify, assess and control risk through CDD. The second is the chief AML/CFT officer and the compliance function: independent of the business, advising management and acting as the main contact point for the authorities. The third is independent internal audit. Conflicts between the first and second lines are resolved "at the highest level".

In a twenty-person firm the lines compress: onboarding and alert review are the first line, the MLRO with a quality-assurance function the second, and the third can be given to an external auditor. What cannot happen is an MLRO checking their own work and calling it independent review. The Quality Assurance / Compliance Testing section of the CBDDQ shows the bank who re-checks second-line decisions before the auditor arrives.

## Risk assessment: BWRA, customer scoring, risk appetite

### The BWRA as the load-bearing element

The business-wide risk assessment is usually treated as one document among many. In fact everything else derives from it: monitoring tuning (NYDFS 504.3(a)(1) expressly requires the TM programme to be "based on the Risk Assessment"), file-review frequency, the depth of independent testing, audit scope. Without it there is nothing on which to justify either the scenarios chosen or those rejected, and the proportionality of the whole programme becomes unprovable.

Article 10 AMLR sets the inputs: Annexes I–III, the supranational and national assessments, AMLA and supervisory material, the firm's own customer data, and a prior assessment before launching a new product, technology or geography. There is no fixed frequency, only "documented, kept up-to-date and regularly reviewed". The first EU-wide content standard will come out of [AMLA's consultation on Guidelines on the BWRA](https://www.amla.europa.eu/policy/public-consultations/consultation-draft-guidelines-business-wide-risk-assessment_en), which ran from 16 April to 15 July 2026 and introduces "four minimum requirements".

Other regimes supply their own numbers and emphases. Hong Kong requires review "at least every 2 years, or more frequently upon trigger events" (SFC ¶2.9). The UAE, in [art. 5 of Cabinet Resolution 134/2025](https://uaelegislation.gov.ae/en/legislations/3857/download), requires risks to be identified and assessed "in a manner proportionate to the nature and size of their business". In the US a risk assessment becomes a mandatory programme element only with a final rule.

The working methodology is the same everywhere: inherent risk in each area, an assessment of controls, residual risk, the management body's signature and the date of the next review. A document without residual risk describes the business and says nothing about the programme.

### Customer risk scoring

Customer risk assessment takes the BWRA down to the individual customer. The most detailed European methodology is in the [EBA risk factors guidelines](https://www.eba.europa.eu/sites/default/files/document_library/Publications/Guidelines/2023/EBA-GL-2023-03/1061654/Guidelines%20ML%20TF%20Risk%20Factors_conslidated.pdf.pdf) (EBA/GL/2021/02, consolidated), which divide factors into four groups.

| Factor group | What is assessed | Typical risk-increasing signs |
| --- | --- | --- |
| Customer | activity of the customer and beneficial owner, reputation, behaviour | PEP, complex structure without evident purpose, cash-intensive business, adverse media |
| Country | jurisdictions of residence of customer and owner, business and personal links | FATF lists, sanctions regimes, weak AML supervision |
| Product and transaction | transparency, complexity, size | anonymity, cross-border flows, cryptoassets, third-party payers |
| Channel | non-face-to-face relationships, intermediaries | remote onboarding, introduction by an agent |

Scoring is a model, and model requirements apply to it. EBA ¶3.6 requires the result not to be "unduly influenced by just one factor" and profit not to influence the rating; ¶3.7 requires a firm using a bought-in scoring system to understand how scores are allocated and to be able to show the supervisor. Customers are usually rated high, medium or low (¶3.8).

A manual downgrade (override) is permitted but documented with reasons and a second-line signature. PEP checks are covered in the piece on [politically exposed persons](https://wiki.private.law/en/pep), the logic of country lists in the piece on the [FATF](https://wiki.private.law/en/fatf).

### Risk appetite

A risk appetite statement fixes the boundaries: which customers, countries and products are closed to the firm entirely and which are acceptable only with EDD and senior approval. Without it every exception is argued afresh, and within a year policy and practice drift apart. The management body approves it and reviews it together with the BWRA.

A telling detail from the TD Bank case: the [FinCEN consent order](https://www.fincen.gov/system/files/enforcement_action/2024-10-10/FinCEN-TD-Bank-Consent-Order-508FINAL.pdf) quotes self-assessments by the Global Head of AML and the BSA Officer citing as an achievement the ability to "develop \[the AML\] program within a flat cost paradigm without compromising risk appetite". A line about holding compliance costs flat became evidence against the bank.

## Policies and procedures: CDD, SDD, EDD, relationship monitoring

The written policy set describes what the firm does with a customer at each risk level. CDD covers identifying and verifying the customer, establishing the beneficial owner, understanding the purpose and nature of the relationship, and ongoing monitoring. In the US that content is written into 31 CFR 1020.210 for banks.

SDD under [art. 33 AMLR](https://eur-lex.europa.eu/eli/reg/2024/1624/oj) is allowed where risk is low, but the firm must check regularly that the conditions still hold and stop simplifying on doubt, suspicion or signs of sanctions evasion. EDD applies to PEPs, customers from high-risk countries, correspondent relationships and anyone the scoring places at the top. Its core is corroborating [source of funds and source of wealth](https://wiki.private.law/en/source-of-funds).

### Periodic refresh

The derivative of the BWRA most often underestimated is article 26 AMLR: customer data must be updated at least every year for customers under EDD and at least every five years for everyone else, plus re-verification of sanctions status on every new designation. These are ceilings. From 10 July 2027 a "review every N years per firm policy" model ceases to be lawful in the EU wherever N exceeds the maximum. Article 26 effectively legislates perpetual KYC.

Other regimes set the principle without hard periods: SFC ¶2.14 — the level and type of ongoing monitoring follow the customer risk assessment; the UAE ([art. 8 of Cabinet Resolution 134/2025](https://uaelegislation.gov.ae/en/legislations/3857/download)) — CDD documents kept "up to date and relevant"; the US — ongoing CDD. Beyond the calendar a file is reviewed on events: a change of beneficial owner, a turnover spike, a new country, adverse media.

## Transaction monitoring

### Scenarios and thresholds

Monitoring consists of scenarios, each describing a typology: structuring cash, pass-through flows without economic purpose, sudden turnover growth, circular transfers. Scenarios are chosen from the BWRA and thresholds calibrated on the firm's own data. The [FCA Financial Crime Guide](https://www.fca.org.uk/publication/policy/ps24-17.pdf) (PS24/17, in force since 29 November 2024) requires that "the firm tailors the monitoring system rules to its business, risk and relevant typologies. The system and rules are tested and reviewed".

The EBA guidelines add two things. The firm decides which transactions are reviewed in real time and which after the event (¶4.74), and it regularly performs ex-post reviews of a sample drawn from all processed transactions to spot trends and test the system's reliability (¶4.75). A sample from the "clean" flow is the only way to learn what the system misses.

The key metric is coverage: the share of flow that actually passed through each live scenario. Its absence created the TD Bank, UBS and Coinbase Europe cases: the system worked on paper and was absent in fact.

### Tuning and validation: Part 504

The only regime that writes monitoring-model governance into a rule is NYDFS Part 504. It also reaches non-banks: §504.2 captures "all check cashers and money transmitters licensed pursuant to the Banking Law".

504.3(a) requires a programme based on the risk assessment, with documented scenarios and thresholds, "end-to-end, pre-and post-implementation testing" including "model validation", and "on-going analysis to assess the continued relevancy of the detection scenarios". Sub-paragraphs (c)–(d) add data validation, vendor protocols and "qualified personnel". §504.4 closes the construction with a signature: a board resolution or senior officer compliance finding is filed by 15 April each year, with supporting material kept for five years.

In US banking, model risk is governed by the Federal Reserve's [SR 26-2](https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm) of 17 April 2026, which superseded SR 11-7 and SR 21-8 and calls for an approach commensurate with a bank's model-risk profile. In the EU, since 2 August 2026, the [deployer's obligations under the AI Act](https://wiki.private.law/en/eu-ai-act-law-firms) sit on top of model validation.

### The alert lifecycle

An alert follows a fixed route, and every step leaves a trail in case management:

1. Initial review (L1): obvious false positives are discarded with a short rationale.
2. Investigation (L2): documents, linked accounts and counterparties, comparison with the customer profile.
3. Internal report to the MLRO, who under reg 21(5) MLR considers it in the light of all relevant information.
4. Decision: SAR/STR, a DAML or consent request, enhanced monitoring, exit.
5. Closure and retention of the case with its evidence.
Internal policy sets the time allowed for each step; missed deadlines become a backlog. NYDFS [fined Block $40 million](https://www.dfs.ny.gov/reports_and_publications/press_releases/pr202504101) on 10 April 2025 for "failure to effectively and timely monitor transactions" and an accumulated alert backlog, and appointed an independent monitor.

### The cost of false positives and quality metrics

[BIS Project Aurora](https://www.bis.org/publ/othp66.pdf) records that "It is estimated that 90–95% of all alerts generated are false positives"; a rule-based approach detected no more than 25% of launderers in a siloed scenario, a graph neural network with a cross-border view of the data around 80%.

Wolfsberg calls the traditional approach a "drag net" producing "low quality, questionably suspicious filings" and proposes different metrics: priority risk coverage, precision, recall and SAR quality. The tension with NYDFS, which mandates "model validation" by rule, is unresolved: the new approach "may result in an approach that does not detect everything historically considered suspicious", and no regulator has yet accepted that reduction in coverage in writing. The QA function re-checks a sample of closed alerts and "no file" decisions, and its results go into the report to the management body.

## SARs and STRs: where, when and what the customer cannot be told

FATF Recommendation 20 requires suspicion to be reported to the FIU "promptly". Inside the firm the route is the same everywhere: employee — MLRO — FIU. Outside, the recipient, the channel and the timing regime differ.

| Jurisdiction | Recipient and channel | Timing and regime |
| --- | --- | --- |
| UK | NCA (UKFIU), SAR Portal | DAML: 7 working-day notice period, 31-day moratorium on refusal |
| EU | national FIU; from 2027 art. 69 AMLR | "promptly" regardless of amount; FIU requests answered within 5 working days, under 24 hours if urgent |
| Hong Kong | JFIU, STREAMS 2 | "as soon as it is reasonable"; consent or letter of no consent |
| Singapore | STRO, SONAR | [duty under s.45 CDSA and ss.8 and 10 TSOFA](https://www.police.gov.sg/Advisories/Commercial-Crimes/Suspicious-Transaction-Reporting-Office/Suspicious-Transaction-Reporting); failure to report may constitute a criminal offence |
| UAE | FIU, goAML | "without delay and directly" (art. 18 Decree-Law No. 10/2025) |
| US | FinCEN, BSA E-Filing | 30 days from detection, up to 60 without a suspect; banks from $5,000, MSBs from $2,000 |

The main difference in the table is the consent regime. In the UK and Hong Kong a firm that suspects a forthcoming transaction involves criminal proceeds asks the FIU for permission and waits.

### Consent regimes: the UK and Hong Kong

Under [s.335 POCA](https://www.legislation.gov.uk/ukpga/2002/29/section/335) a DAML request starts a notice period of seven working days from the first working day after disclosure. If the [NCA](https://www.nationalcrimeagency.gov.uk/who-we-are/publications/776-ukfiu-chapter-3-understanding-damls-and-datfs/file) has not refused, consent is deemed given. On refusal a 31-day moratorium begins, which a court may extend under [s.336A](https://www.legislation.gov.uk/ukpga/2002/29/section/336A) in steps of up to 31 days, but by no more than 186 days in total beyond the original period. A customer payment can therefore sit for more than seven months, and the firm may not tell the customer why.

In Hong Kong an STR is filed under s.25A OSCO, s.25A DTROP or s.12 UNATMO through STREAMS 2, which is mandatory for regulated entities. The JFIU responds with consent or a letter of no consent (SFC ¶7.20), and in the second case the funds are in practice frozen.

### FinCEN timing and practice

In the US [31 CFR 1020.320](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-C/section-1020.320) gives a bank 30 calendar days from initial detection, plus a further 30 if no suspect is identified, but no more than 60 in total. Ongoing violations must be notified to law enforcement immediately by telephone. In its [FAQs of 9 October 2025](https://www.fincen.gov/system/files/2025-10/SAR-FAQs-October-2025.pdf) FinCEN clarified that no separate continuing-activity review is required after a SAR (firms may follow the "day 30 initial SAR, day 150 continuing activity SAR" timeline if they choose) and that there is no requirement to document a decision not to file. In other regimes such a rationale remains standard supervisory practice.

### Tipping off

The prohibition on telling the customer about a report is universal (FATF R.21); the penalties differ. In the UK [s.333A POCA](https://www.legislation.gov.uk/ukpga/2002/29/section/333A) punishes disclosure in the regulated sector with up to two years' imprisonment, in Hong Kong up to three years and a fine (SFC ¶1.34). In the EU the prohibition sits in art. 73 AMLR, in the UAE in art. 29 of Decree-Law No. 10/2025 and art. 19 of Cabinet Resolution 134/2025, in the US in 31 CFR 1020.320(e). The standard bank line "we cannot comment on the reasons" is dictated by exactly this prohibition.

## Sanctions controls and the travel rule

Sanctions screening sits next to AML technically but works differently in law: there is no threshold, in the US and the UK civil liability for a breach arises regardless of intent, and a match is either discounted or leads to a freeze and a report to the sanctions authority. Customers and counterparties are screened at onboarding, on list updates and in the payment flow. The mechanics are covered in the piece on [sanctions screening](https://wiki.private.law/en/sanctions-screening), the regimes in the [sanctions map](https://wiki.private.law/en/sanctions-map).

The cost of getting it wrong is shown by Starling Bank. On [2 October 2024 the FCA fined the bank £28,959,426](https://www.fca.org.uk/news/press-releases/fca-fines-starling-bank-failings-financial-crime-systems-and-controls): since its 2017 launch its automated system had screened customers against only part of the sanctions list, which came to light in January 2023. Meanwhile the bank opened more than 54,000 accounts for around 49,000 high-risk customers in breach of a voluntary restriction, while its base grew from 43,000 to 3.6 million customers.

For crypto businesses and payment firms the [travel rule](https://wiki.private.law/en/travel-rule) is added to screening: originator and beneficiary data travel with the transfer, and their absence is a monitoring signal in its own right.

## Records, training, independent review

### Record retention periods

Five years is the common FATF minimum (R.11), but the starting point and upper limit differ.

| Jurisdiction | Period | Starting point and caveats | Rule |
| --- | --- | --- | --- |
| UK | 5 years | from end of relationship or occasional transaction; no more than 10 years | [MLR reg 40](https://www.legislation.gov.uk/uksi/2017/692/regulation/40) |
| EU (from 2027) | 5 years | from end of relationship; extendable by up to 5 years on the authorities' request | art. 77 AMLR |
| Hong Kong | at least 5 years | from end of relationship or transaction | AMLO, Schedule 2 s.20 |
| Singapore | at least 5 years | CDD records from the end of the relationship, transaction records from completion; longer where STRO or another authority so requests for a matter under investigation or reported in an STR | [MAS Notice 626](https://www.mas.gov.sg/regulation/notices/notice-626) ¶12.3–12.5 and parallel notices |
| UAE | at least 5 years | from completion of transaction or end of relationship | art. 25 Cabinet Resolution 134/2025 |
| US | 5 years | SARs and supporting documents — also 5 years | [31 CFR 1010.430(d)](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-D/section-1010.430) |

A group policy aligns with the longest period, but UK and EU rules require personal data to be deleted when it expires: indefinite retention breaches data protection just as early deletion breaches AML rules.

### Training

Training is mandatory everywhere and judged by results: the Basel Committee expects audit to assess the "effectiveness of training". A good programme is role-specific: onboarding staff, alert analysts, the front office and the board learn different things and sit tests.

### Independent review

In the US the frequency test is "commensurate with the risk", and the [FFIEC](https://bsaaml.ffiec.gov/manual/AssessingTheBSAAMLComplianceProgram/03) states plainly that there is "no regulatory requirement establishing BSA/AML independent testing frequency", giving 12–18 months as an example; a qualified employee not involved in the function tested may perform it. Canada is a hard 24 months. In the EU art. 9(3) AMLR makes the audit function mandatory from 2027. In Hong Kong SFC ¶3.11 requires regular independent audit, in the UAE art. 21 of Cabinet Resolution 134/2025, in the UK reg 21(1)(c) "where appropriate".

A review report is only as valuable as its remediation log. In Canaccord Genuity part of the finding was that "through 2022, independent audits failed to identify apparent gaps". Correspondent banks ask separately about the reputation of the audit firm.

### Reporting to the management body and the supervisor

Internal reporting is required almost everywhere. SYSC 6.3.7G expects an annual MLRO report to the board, EBA/GL/2022/05 ¶50 an annual activity report from the officer, NYDFS Part 504 an annual certification by 15 April.

Periodic reporting to supervisors is targeted. In the UK [SUP 16.23](https://www.handbook.fca.org.uk/handbook/SUP/16/23.html) requires the Annual Financial Crime Report (REP-CRIM) from banks, building societies, mortgage lenders, life insurers, investment firms holding client money or assets, and certain firms with revenue of £5m or more. It is due within 60 business days of the accounting reference date. Payment and e-money institutions are not named in the SUP 16.23 list.

## The RegTech stack: system categories

No regime prescribes vendors, but a working programme is assembled from bought systems, and at onboarding the bank asks what was bought and who configures it.

| Category | What it covers | What supervisors and banks ask |
| --- | --- | --- |
| IDV and KYC/KYB | identity and company verification, registries, beneficial owners, refresh | share of manual exceptions, handling of documents from high-risk countries |
| Screening | sanctions, PEPs, adverse media, rescreening on list updates | lists, frequency, fuzzy-matching settings, free-text field coverage |
| Transaction monitoring | scenarios and ML scoring, alert generation | scenario inventory, validation, flow coverage |
| Blockchain analytics | address and VASP-counterparty screening, tracing the origin of funds | how platform reports are used when cryptoassets come in and go out |
| Case management | alert and investigation files, decision trail | backlog, timings, QA sample |
| Report filing | integration with the FIU channel | registration with the FIU system, filing times |
| Travel rule | exchange of originator and beneficiary data | protocol, handling of transfers missing data |

The vendor takes no liability off the licensee: the customer decision and the filing stay with the licensee, and the vendor lands in its third-party register — in the EU with [DORA](https://wiki.private.law/en/dora-eu) consequences. A bank accepts a crypto-wallet history when it is backed by an analytics platform report; an explorer screenshot is not evidence.

Filing channels are part of the stack too: BSA E-Filing in the US, STREAMS 2 in Hong Kong, SONAR in Singapore, the FINTRAC Web Reporting System in Canada, goAML in the UAE. There [goAML registration](https://rulebook.centralbank.ae/en/rulebook/34-how-submit-str-and-other-report-types) is mandatory for every institution supervised by the Central Bank, and a new licensee registers immediately on licensing.

## What cannot be outsourced

Until 2027 EU law had no closed list of non-outsourceable decisions, only EBA guidance (¶68(e): "Strategic decisions in relation to AML/CFT should not be outsourced"). Article 18 AMLR makes the list binding and closes six functions to outsourcing:

1. proposing and approving the BWRA;
2. approving policies, procedures and controls;
3. assigning a customer's risk profile;
4. deciding to enter a relationship or carry out a transaction;
5. filing STRs with the FIU;
6. approving the criteria for detecting suspicious transactions.
The obliged entity remains "fully liable". The "MLRO as a service" model popular with smaller EMIs does not survive this: there is no express prohibition, but an external contractor structurally cannot meet the requirements on the officer's standing and reporting line. The adjacent logic is covered in the piece on [renting a licence](https://wiki.private.law/en/license-for-rent). In Hong Kong the Customs licensing guide rules the model out for MSOs. External consultants keep the drafting of the programme, systems configuration and independent review, while the signature and personal risk sit with an insider with real authority.

The vendor contract is one document for all regimes: audit rights under EBA/GL/2019/02, supervisory access, an exit plan, the DORA register, model validation and data lineage under NYDFS 504.3(c)–(d) and SR 26-2. The six decisions in article 18 AMLR cannot enter that contract. The general rules on what an EU licensed firm may outsource, and on what terms, are set out in [outsourcing by licensed firms](https://wiki.private.law/en/outsourcing-licensed-firms).

## How programmes are tested

### Supervisors

An inspection starts with documents — the BWRA, policies, MLRO reports, board minutes — and moves on to samples of files and alerts: the supervisor checks whether the firm does what it has written. A systemic gap leads to remediation at the firm's expense. The FCA can appoint a skilled person under [s.166 FSMA](https://www.legislation.gov.uk/ukpga/2000/8/section/166), US regulators order lookbacks and independent monitors. UBS was given 180 days under its FinCEN order for a SAR Lookback Report and a further 90 to file what it found; Block received an NYDFS monitor.

### Typical findings and fines

The 2024–2026 fines show that firms are punished for controls that do not work behind documents that formally exist.

| Firm | Regulator | Amount | Date |
| --- | --- | --- | --- |
| [TD Bank](https://www.fincen.gov/news/news-releases/fincen-assesses-record-13-billion-penalty-against-td-bank) | FinCEN | $1.3 billion | 10 October 2024 |
| [Starling Bank](https://www.fca.org.uk/news/press-releases/fca-fines-starling-bank-failings-financial-crime-systems-and-controls) | FCA | £28,959,426 | 2 October 2024 |
| [Monzo](https://www.fca.org.uk/news/press-releases/fca-fines-monzo-21m-failings-financial-crime-controls) | FCA | £21,091,300 | 8 July 2025 |
| [Coinbase Europe](https://www.centralbank.ie/news/article/press-release-enforcement-action-against-coinbase-europe-limited-6-November-2025) | Central Bank of Ireland | €21,464,734 | 6 November 2025 |
| [Paxful](https://www.fincen.gov/system/files/2025-12/PaxfulConsentOrder.pdf) | FinCEN | $3.5 million | 9 December 2025 |
| [Nationwide](https://www.fca.org.uk/publication/final-notices/nationwide-building-society-2025.pdf) | FCA | £44,078,500 | 11 December 2025 |
| [Canaccord Genuity](https://www.fincen.gov/system/files/2026-03/Canaccord-Consent-Order-No-2026-01.pdf) | FinCEN | $80 million | 6 March 2026 |
| [UBS Financial Services](https://www.fincen.gov/system/files/2026-07/UBS-Consent-Order.pdf) | FinCEN | $125 million | 3 August 2026 |

Behind each figure is a specific control defect. At TD Bank domestic ACH went unmonitored from at least 2012, and over $100 billion of peer-to-peer transfers were knowingly left outside monitoring. Paxful ran 974 days unregistered and, in the order's words, "without a qualified individual to assure day-to-day compliance with the BSA". At Canaccord Genuity at least 160 SARs went unfiled and reports sat unreviewed for up to four years.

At UBS Financial Services more than 61,500 foreign-currency wires worth roughly $10.5 billion went unmonitored across 2019–2023; part of the gap traced to an Excel formula error, and "validation testing did not include data lineage mapping and testing".

The FCA fined Monzo for onboarding on "obviously implausible information — such as customers using well known London landmarks as an address" while its base grew from 600,000 to 5.8 million customers, and Nationwide because only around 2,000 of 18 million customers were rated high risk. Coinbase Europe paid for a single configuration defect: 30,442,437 transactions worth more than €176 billion were not properly monitored, and 2,708 STRs had to be filed retrospectively.

Meanwhile FCA fine totals are falling: £568m in 2021, £176m in 2024, £124m in 2025 and [£18,013,399 as at 22 September 2026](https://www.fca.org.uk/news/news-stories/2026-fines). Records are being set elsewhere: FINTRAC imposed CAD 176,960,190 on Xeltox Enterprises (Cryptomus), and MAS penalised nine financial institutions S$27.45 million. Details are in the pieces on the [Canadian MSB regime](https://wiki.private.law/en/rpaa-canada) and [FinCEN MSBs](https://wiki.private.law/en/msb-license-usa).

The price can be the licence itself. The Bank of Lithuania revoked [PayrNet's](https://www.lb.lt/en/news/licence-of-uab-payrnet-revoked-for-serious-violations-bankruptcy-proceedings-to-be-initiated) EMI licence on 22 June 2023 — customer risk assessment "in some cases was not carried out at all", STRs filed late — and [Foxpay's](https://www.lb.lt/en/news/lietuvos-bankas-revoked-uab-foxpay-licence-due-to-serious-and-systematic-breaches) on 22 November 2024 for "serious and systematic" AML and safeguarding breaches. The [OCC consent order](https://www.occ.gov/static/enforcement-actions/eaAA-ENF-2025-21.pdf) against Community Federal Savings Bank of 24 April 2026 showed the cascade: a sponsor bank to dozens of fintech programmes received a remediation plan, a SAR lookback and an independent BSA programme assessment, and its clients received hardened questionnaires and frozen onboarding.

### The correspondent bank and the CBDDQ

A correspondent bank tests the programme more often than the supervisor: at onboarding, on limit reviews and after every warning sign. The base instrument is the Wolfsberg CBDDQ version 1.4, with 14 sections running from ownership and the AML/CTF programme through risk assessment, monitoring, sanctions, QA, audit and fraud. How the questionnaire and its non-bank counterpart are completed is covered in the piece on [Wolfsberg questionnaires](https://wiki.private.law/en/wolfsberg-questionnaires).

For payment firms Wolfsberg issued in 2026 its [Guidance on the Provision of Banking Services to non-bank PSPs](https://wolfsberg-group.org/resources/general/206). The bank asks about the qualifications of the MLRO and CCO, "the scalability of the non-bank PSP's compliance programme with business growth", real-time screening and free-text fields, "any existing or recent backlogs in transaction monitoring, KYC renewal or other areas of operations", "any independent assessment of their ML and AI use cases" and, as a separate item, "the reputation of the auditing firm". Where risks cannot be sufficiently mitigated, "particularly given reduced end-to-end visibility", the guidance tells the bank to consider exiting.

The regulatory minimum and the banking minimum differ, and the second is harder: it is what determines whether [the operator keeps its account](https://wiki.private.law/en/bank-account-closure). How client money is protected along the correspondent chain is covered in the piece on [correspondent banking and safeguarding](https://wiki.private.law/en/correspondent-banking-safeguarding), the bank's full question list for a payments company in [banking for MSBs](https://wiki.private.law/en/banking-for-msb).

### Six questions that test a programme

Both the bank and the inspector start from the same six questions:

1. **BWRA date and signature.** Under art. 10 AMLR management-function approval is mandatory; without a signature the document is defective in substance.
2. **Backlogs** in monitoring and KYC renewal — Wolfsberg tells banks to ask about them directly.
3. **MLRO status.** SMF17 and PCF-15 are publicly checkable; having no deputy in Hong Kong breaches SFC ¶3.7(h).
4. **The latest independent review report** and the remediation log.
5. **Part 504 certification**, where the counterparty holds a New York money transmitter licence.
6. **The coverage metric** — the share of flow that passed through each live scenario in the period.
## What the programme means for the customer

From the other side of the desk the same programme looks like a series of requests. A refresh letter once a year or once every five years is a scheduled consequence of art. 26 AMLR and its equivalents. A source-of-funds request on a large inflow is a monitoring scenario and EDD at work. A request to explain the ownership chain is beneficial-owner identification under CDD. The fuller the file at onboarding, the fewer the requests later.

A bank's silence over a blocked payment often means a consent regime or the tipping-off prohibition. An account closed without explanation usually means an exit under risk appetite. How to go through these procedures predictably is covered in the pieces on [AML/KYC for private clients](https://wiki.private.law/en/aml-kyc-private-client), [corporate KYC](https://wiki.private.law/en/corporate-kyc) for a company as the customer, [investor onboarding](https://wiki.private.law/en/investor-onboarding) and [proving source of funds](https://wiki.private.law/en/source-of-funds).

## Programme economics

[BIS](https://www.bis.org/publ/othp66.pdf) puts aggregate financial-institution compliance costs at roughly $274 billion — 28% above the roughly $214 billion of 2020; average costs over 2019–2022 rose 54% in the United States and 80% in Canada. Meanwhile 2–5% of global GDP is laundered and less than 1% recovered.

Headcount becomes concrete in the UK payments sector: Barclay Simpson gives base salaries excluding bonus.

| Role | Range |
| --- | --- |
| Analyst, London | £30–50k |
| VP and senior manager | £80–120k |
| Director | £100–160k |
| Head of Financial Crime / MLRO, London | £140–300k |
| Head of Financial Crime / MLRO, regions | £110–250k |
| Global head | £230–600k |
| Interim MLRO, London | £1,000–1,600 a day (roughly £250–400k annualised) |

On top sits a direct regulatory tax: from the financial year beginning April 2026 the Economic Crime (AML) Levy is charged by UK revenue band.

| Band | UK revenue | Levy |
| --- | --- | --- |
| [Band A](https://www.legislation.gov.uk/ukpga/2022/3/section/54) | over £10.2m up to £36m | £10,200 |
| Band B | up to £500m | £36,000 |
| Band C | up to £1bn | £500,000 |
| Band D | over £1bn | £1,000,000 |

Firms below £10.2m of UK revenue are outside the levy, and the levy itself is not deductible for corporation tax.

## Calendar to 2028

The key regulatory milestones to keep in the programme calendar:

| Date | Milestone |
| --- | --- |
| 17 January 2025 | DORA applies; ICT contract registers collected by supervisors by 30 April 2025 |
| February 2025 | FATF: "commensurate" becomes "proportionate"; simplified measures encouraged where risk is low |
| 14 October 2025 | UAE: Federal Decree-Law No. 10/2025 in force, replacing Decree-Law No. 20/2018 |
| 2 January 2026 | FinCEN delays the investment adviser AML rule to 1 January 2028 |
| 10 April 2026 | FinCEN AML/CFT programme NPRM; comments to 9 June |
| 15 April annually | NYDFS Part 504 certification |
| 9 July 2026 | Parallel Federal Reserve NPRM for supervised banks; comments to 8 September |
| 16 April – 15 July 2026 | AMLA consultation on Guidelines on the BWRA |
| 3 June – 3 September 2026 | AMLA consultation on Guidelines on ongoing monitoring |
| 1 February 2027 | Reg 34A MLR 2017 — EDD for cryptoasset providers and correspondent relationships (SI 2026/621) |
| 10 July 2027 | AMLR (EU) 2024/1624 starts to apply |
| 25 October 2027 | New Schedule 6B MLR — changes in control of registered cryptoasset businesses |
| January 2028 | AMLA begins direct supervision of up to 40 institutions and groups active in at least six member states |
| 1 January 2028 | FinCEN AML/CFT rule for RIAs and ERAs takes effect |

A separate variable outside the calendar is article 52 AMLR: the beneficial ownership threshold is "25% or more", but until 10 July 2029 the Commission may lower it for higher-risk categories to "a maximum of 15%, unless risk justifies a higher threshold that remains below 25%". Hong Kong counts "more than 25%" (SFC ¶4.3.6). The threshold is therefore kept as a configurable parameter in the data model.

## Popular, but it ends badly

The most expensive programme failures repeat from case to case.

> ⚠️ Controls fail to keep pace with customer growth (Monzo, Starling, Blue Ocean Invest). Screening checks against part of the list and monitoring misses part of the flow (Starling, TD Bank, Coinbase Europe, UBS). Alerts pile up into a backlog (Block). Audit fails to find what the regulator later finds (Canaccord). An MLRO on a services contract signs off what they do not control. EBA/GL/2022/05 ¶40 offers a tool against the first failure: a new product does not launch until resources exist to manage its risks.

Build order matters: BWRA → policies → customer risk rating → monitoring scenarios → thresholds → testing. The reverse order — "buy the vendor, write the policy later" — is what Monzo, Nationwide and Block were fined for. A first independent review commissioned in year one is cheaper than one imposed as a condition of an enforcement order.

> 🍓 A compliance programme is a chain: BWRA, risk appetite and policies, customer scoring, CDD/EDD, monitoring and screening, SARs/STRs, records and independent review. The skeletons differ: four elements in the US (five for banks), ten policy areas plus an audit function in the EU from 10 July 2027, size-dependent elements in the UK. Reporting deadlines and consent regimes vary; records are kept for at least five years everywhere. Programmes are tested on facts: backlogs, flow coverage, board signatures.

## Q/A

### **Can the MLRO role be outsourced**

Most regimes do not prohibit it outright, but an external contractor structurally cannot meet the requirements: UK MLR reg 21(3) speaks of "an individual in the relevant person's firm", the EBA of working in the country of establishment, article 11 AMLR of a direct reporting line to the management body. For a Hong Kong MSO it must be an employee or the owner. What can be outsourced is drafting the programme, systems and independent review.

### **How often is an independent review needed**

There is no single answer. The US says "commensurate with the risk", with the FFIEC offering 12–18 months as an example; Canada requires the next review to start no later than 24 months after the previous one began; in the EU from 2027 the function is mandatory with no set frequency. A practical benchmark for a new licence is a first review within the first year of operation.

### **How long must KYC files and transaction records be kept**

At least five years in all six jurisdictions, usually from the end of the relationship or the occasional transaction. In the EU the authorities may extend the period by up to five more years; in the UK the ceiling for part of the records is ten years. After the period, personal data in the UK and the EU is deleted unless another legal basis for retention exists.

### **Must a decision not to file a SAR be documented**

Not in the US: in its FAQs of 9 October 2025 FinCEN stated that the BSA contains no such requirement, although a firm may record the decision briefly. In the UK, the EU and Asia a rationale for closing an alert remains standard supervisory practice, and auditors and inspectors treat a missing decision trail as a missing decision.

### **Why does a bank not explain why it has held a payment**

Because the law forbids disclosing that a report has been made or that an investigation is under way. In the UK tipping off in the regulated sector carries up to two years' imprisonment, in Hong Kong up to three. If the bank has requested a DAML, the payment waits at least seven working days and, if the NCA refuses, up to a further 31 days, with possible court extensions.

### **How does a correspondent bank differ from a regulator in assessing a programme**

The bank is harder and asks about operating facts: backlogs, the reputation of the audit firm, independent assessment of ML and AI models, screening of free-text fields, nested activity. Where risks cannot be sufficiently mitigated, Wolfsberg recommends that the bank consider exiting, so a programme that formally meets the rules can still fail bank acceptance.

### **What changes for an EU operator on 10 July 2027**

Policies cover the ten areas of article 9 and are approved in writing by the management body. A compliance manager and compliance officer pair appears (article 11). The six decisions in article 18 can no longer be outsourced. Article 26 fixes ceilings for refreshing customer data, article 69 a five-working-day deadline for answering FIU requests, article 77 five-year record retention.

---

## Factual claims

- A US money services business is built on 31 CFR 1022.210: four elements — internal controls, a designated person, training and independent review.
- The key parameters the article returns to below are gathered in one table.
- The FATF was created in 1989, and its Recommendations follow a simple logic: money cannot be laundered without a financial intermediary, so the intermediary is obliged to watch its customers.
- The US "designated person". 31 CFR 1022.210(d)(2) involves no approval at all: the firm simply names someone.
- Article 10 AMLR sets the inputs: Annexes I–III, the supranational and national assessments, AMLA and supervisory material, the firm's own customer data, and a prior assessment before launching a new product, technology or geography.
- SDD under art. 33 AMLR is allowed where risk is low, but the firm must check regularly that the conditions still hold and stop simplifying on doubt, suspicion or signs of sanctions evasion.
- The only regime that writes monitoring-model governance into a rule is NYDFS Part 504. It also reaches non-banks: §504.2 captures "all check cashers and money transmitters licensed pursuant to the Banking Law".
- In US banking, model risk is governed by the Federal Reserve's SR 26-2 of 17 April 2026, which superseded SR 11-7 and SR 21-8 and calls for an approach commensurate with a bank's model-risk profile.

---

Source: wiki.private.law — the private.law legal knowledge base. When quoting, cite the canonical page URL.
Consultation with a lawyer: https://t.me/private_law_bot
