Skip to main content
Are Your Controls Actually Working? A Balkans Enforcement Gap AuditInternational Bodies & Standards
5 min readFor AML Compliance Officers

Are Your Controls Actually Working? A Balkans Enforcement Gap Audit

You've implemented customer due diligence. Your transaction monitoring rules run daily. Your staff files suspicious activity reports. But here's the uncomfortable question: does any of that stop money laundering, or does it just satisfy an auditor?

The Western Balkans financial sector offers a stark lesson. Despite adopting FATF standards and EU AML directives, banks and financial service providers in the region remain highly vulnerable to illicit finance. The issue isn't missing controls. It's the gap between compliance documentation and practical enforcement. If your institution operates in or transacts with high-risk jurisdictions, this checklist helps you audit whether your AML/CFT framework actually works, or just looks good on paper.

Prerequisites

Before using this checklist, confirm you have:

  • A documented AML/CFT framework that aligns with your jurisdiction's regulatory requirements
  • Access to your FIU feedback records from the past 24 months (or documentation explaining why none exists)
  • Transaction monitoring rule performance data, including alert volumes, investigation outcomes, and SAR filings
  • Authority to interview front-line staff who handle customer due diligence and alert investigations

If you lack any of these, start there. You can't audit enforcement effectiveness without baseline data.

Enforcement Effectiveness Checklist

1. FIU Feedback Loop

Status: Your institution receives systematic, actionable feedback from your financial intelligence unit on filed SARs.

What good looks like: You get written feedback within 90 days on at least 20% of your SARs, indicating whether the report contributed to an investigation, what typologies were involved, or why it wasn't actionable. This feedback informs your transaction monitoring rule tuning and staff training priorities.

Regulatory reference: FATF Recommendation 29 (FIUs should provide guidance and feedback to reporting entities)

2. Cryptocurrency Service Provider Oversight

Status: If your institution offers crypto exchange, wallet custody, or facilitates crypto-to-fiat conversions, you apply the same customer due diligence and transaction monitoring standards as traditional banking services.

What good looks like: Crypto customers undergo enhanced due diligence. You screen wallet addresses against known illicit addresses. Your monitoring rules flag structuring patterns across multiple small crypto transactions. You've documented how you identify beneficial owners of corporate crypto accounts.

Note: Cryptocurrencies provide anonymity to criminals, and regulatory frameworks in many jurisdictions remain incomplete. Don't assume your crypto services are lower risk because transaction volumes are smaller.

3. Non-Bank Financial Service Provider Gaps

Status: If your institution includes money transfer services, foreign exchange offices, or payment institutions, you've assessed whether these channels receive equivalent AML/CFT scrutiny as your core banking operations.

What good looks like: Your money transfer service doesn't rely solely on volume-based monitoring. You've implemented velocity checks, beneficiary pattern analysis, and geographic risk flags. Foreign exchange offices maintain transaction records with verified customer identification for amounts below your CTR threshold. You audit these channels quarterly, not annually.

Reality check: Criminals exploit money transfer services and foreign exchange offices because of large cash transaction volumes and limited verification. If your monitoring treats these as lower risk than wire transfers, you've created a blind spot.

4. Cross-Border Transaction Intelligence

Status: When your transaction monitoring flags cross-border activity, your investigators have access to correspondent banking relationship details, intermediary bank information, and destination jurisdiction risk ratings.

What good looks like: Your case management system automatically appends Grey List and Black List status for destination countries. Investigators can see whether correspondent banks have recent enforcement actions. You've documented your process for escalating transactions involving multiple high-risk jurisdictions, even when individual transaction amounts fall below your monitoring thresholds.

Why this matters: The Western Balkans cases involved criminals moving substantial sums through multiple jurisdictions. Your monitoring must connect the dots across borders, not just flag individual transactions.

5. Staff Competency Beyond Checkbox Training

Status: Your compliance staff and front-line employees demonstrate practical understanding of money laundering typologies relevant to your customer base and transaction patterns.

What good looks like: During interviews, staff can describe the three-stage money laundering process (placement, layering, integration) and explain how it manifests in your institution's services. They can identify at least three red flags specific to your business model without consulting a manual. Your training includes case studies from actual SARs filed by your institution (anonymized), not just generic examples.

The enforcement gap: The Western Balkans research found limited understanding of illicit finance across the juridical chain. If your staff can't explain why a control matters, they can't apply it effectively.

6. Foreign-Owned Bank Coordination

Status: If your institution is foreign-owned or part of a banking group, you've documented how group-level AML/CFT standards translate to local enforcement, and where local regulations impose stricter requirements.

What good looks like: You maintain a conflicts matrix showing where local law exceeds group standards. Your escalation procedures specify when to involve group compliance versus local MLRO. You've tested whether group-level name screening tools cover local politically exposed persons lists and sanctions regimes.

Context: A substantial proportion of Western Balkans banks are foreign-owned. Group standards provide a floor, not a ceiling.

Common Mistakes

Treating compliance as a documentation exercise. You have policies. Criminals have money. If your last internal audit found "no significant deficiencies," that might mean your controls work. Or it might mean your audit didn't test whether staff actually follow the policies under pressure.

Assuming banks are lower risk than other financial service providers. The evidence shows banks are frequently used for money laundering despite strong AML controls. Better controls don't eliminate risk; they shift criminal behavior toward exploiting gaps in enforcement.

Waiting for FIU feedback instead of creating internal feedback loops. If your FIU provides limited feedback (a common problem), build your own. Track SAR outcomes internally. Interview investigators quarterly about typology trends. Share sanitized case studies across your compliance team.

Ignoring cash-intensive channels. If your monitoring focuses on wire transfers and ACH but treats foreign exchange offices as low-priority, you've missed where criminals actually operate.

Next Steps

If you found gaps:

  1. Prioritize FIU engagement. Request a meeting to discuss feedback mechanisms. If systematic feedback doesn't exist in your jurisdiction, propose a pilot program or join an industry working group to advocate for it.

  2. Audit your crypto and non-bank channels within 30 days. Don't wait for your annual review cycle.

  3. Test staff competency through scenario-based interviews, not multiple-choice tests. Ask: "A customer makes five foreign exchange transactions over two weeks, each under the reporting threshold, to three different beneficiaries in countries on the Grey List. What do you do?" The answer reveals whether training stuck.

  4. Document what you don't know. If you can't assess whether your correspondent banks have enforcement actions, or whether your crypto wallet screening is effective, write it down. Unknown risks beat undocumented risks.

Compliance on paper means nothing if criminals still move money through your institution. This checklist won't catch every vulnerability, but it identifies the enforcement gaps that matter most.

You Might Also Like