You're in a compliance meeting, staring at your monthly metrics, trying to explain what the numbers actually mean. Your CFO wants to know if the AML/CFT Framework is "working." Your CEO asks whether the risk profile is improving. And you realize your dashboard answers a different question entirely: it shows completed tasks, not changes in exposure.
Here's what you should consider when evaluating your reporting tools.
Do More STRs Mean We're Doing Better or Worse?
It depends on what changed to produce them.
If your STR count jumped 30% year-over-year, that number alone tells you nothing about risk direction. You need context:
- Did you onboard a new customer segment with different risk characteristics?
- Did you adjust transaction monitoring rules to reduce false positives and catch more real signals?
- Did your business volume grow 40%, making a 30% STR increase actually a decline in detection rate?
- Did you implement better typology training, so analysts now recognize patterns they previously missed?
The metric shows activity. The context reveals whether your controls are keeping pace with your actual exposure.
Build your dashboard to answer both. Track STR volume, but also track STRs as a percentage of total transactions, STRs by customer risk tier, and STRs by typology. When senior management asks what the trend means, you'll have an answer grounded in risk, not just counting.
What Should I Actually Put in Front of the Board?
Not a task completion scorecard.
Boards don't need to know that 1,240 alerts were investigated last month. They need to know whether the organization's financial crime risk is stable, increasing, or decreasing, and whether controls are calibrated to that level of risk.
Structure your board reporting around these questions:
- What has changed in our customer base, product mix, or geographic exposure since last quarter?
- Are we seeing new typologies or concentrations of suspicious activity that weren't present before?
- Do our control thresholds still make sense given current transaction patterns?
- Where are we relying on manual processes that can't scale with volume growth?
Include the operational metrics, but frame them as evidence for a risk assessment, not as the assessment itself. If alert volume doubled because you expanded into a new jurisdiction, that's a capacity question. If it doubled because existing customers are behaving differently, that's a risk question.
The FinCEN penalty against UBS Financial Services ($125 million) demonstrates what happens when compliance activity doesn't translate to effective risk management. Regulators don't care that you filed reports on time if you failed to understand what those reports revealed about your control gaps.
How Do I Know if Training Actually Worked?
Completion rates tell you who logged in. They don't tell you whether your analysts can spot layering schemes or your relationship managers understand beneficial ownership red flags.
Test application, not attendance:
- Track the quality of STR narratives before and after training sessions. Are analysts describing the suspicious behavior more clearly? Are they connecting related transactions?
- Measure false positive rates by analyst. If one team member consistently escalates alerts that close as non-suspicious, they may need additional coaching on the typologies you're targeting.
- Review customer onboarding decisions. Are relationship managers applying enhanced due diligence when risk indicators are present, or are they checking boxes?
If you run PEP training and then see no change in how PEP relationships are documented or monitored, the training didn't work, regardless of the completion percentage.
Should My Dashboard Include Regulatory Developments?
Yes, if they affect your risk exposure or control design.
HMRC recently amended the UK Money Laundering Regulations to require certain non-UK trusts holding UK land or property to register, with new exemptions for some low-value trusts. If you serve trust clients, that's not background noise. It's a change that may require you to refresh beneficial ownership information and reassess whether existing customer records remain accurate.
BaFin issued supervisory guidance on virtual IBANs (vIBANs), highlighting money laundering risks when these structures make transaction tracing more difficult. If your institution offers vIBANs or your customers use them, you need enhanced due diligence protocols that address those specific traceability concerns.
Build a section in your management information that flags regulatory updates requiring action, not just awareness. Link each update to a control review or policy change so leadership understands the operational impact.
What's the Difference Between a Compliance Dashboard and a Risk Dashboard?
A compliance dashboard shows you what your team did. A risk dashboard shows you what's happening in your environment.
Compliance metrics:
- Alerts generated and investigated
- SARs filed
- Customer reviews completed
- Training courses finished
Risk metrics:
- New customer segments and their risk distribution
- Transaction pattern shifts (velocity, counterparty concentration, cross-border volume)
- Geographic exposure changes
- Typology trends (are you seeing more trade-based laundering, more nested accounts, more cash structuring?)
You need both, but if you only report compliance metrics, you're telling leadership that the program is busy without telling them whether it's effective.
How Often Should I Update the Dashboard Framework Itself?
At least annually, and whenever your risk profile changes materially.
Review your dashboard structure when:
- You launch a new product or enter a new market
- You acquire another institution or integrate a new customer portfolio
- Regulators issue guidance that changes expectations (like the BaFin vIBAN communication)
- You implement new detection technology that surfaces different data
Your dashboard should evolve with your business. If you're still reporting the same metrics you used three years ago, you're probably measuring the wrong things.
Where to Go for More
Your regulator's supervisory priorities document (FinCEN, FCA, BaFin, etc.) will tell you what they expect to see in management information. FATF Recommendation 1 requires institutions to assess and understand their money laundering and terrorist financing risks; your dashboard should demonstrate that understanding, not just document compliance tasks.
If your current reporting can't answer whether your financial crime risk is improving or deteriorating, it's time to redesign it.



