Skip to main content
FIAU's 2026-2027 Plan Demands Proof, Not PoliciesCompliance Program Governance
4 min readFor AML Compliance Officers

FIAU's 2026-2027 Plan Demands Proof, Not Policies

The Financial Intelligence Analysis Unit (FIAU) has released its AML/CFT Supervisory Plan for 2026-2027, and the message is clear: documented controls aren't enough. The plan emphasizes effective implementation across transaction monitoring, Customer Due Diligence, reporting obligations, and source-of-funds verification. For compliance teams, this means your next inspection won't ask whether you have policies, it'll ask whether those policies actually work.

Shift from Documentation to Performance

The FIAU's third-year supervisory cycle marks a shift from documentation review to performance assessment. The plan, informed by risk data collected through the Compliance and Supervision Platform for Assessing Risks (CASPAR), national and sectoral risk assessments, and evaluations from European and international bodies, directs supervisory resources toward areas presenting higher money-laundering and terrorist-financing risks.

The approach remains risk-based and proportionate, but the tools have expanded. The FIAU will use AML/CFT returns, supervisory meetings, policy and procedure reviews, thematic inspections, full-scope onsite inspections, follow-up inspections, and targeted interventions. The selection depends on your firm's risk profile and circumstances.

Key Areas of Focus

1. Implementation Evidence Over Policy Documents

The FIAU will assess how you identify, understand, and mitigate terrorist- and proliferation-financing risks within your AML/CFT frameworks. The focus is on whether your controls respond to identified risks, not just whether you've drafted a comprehensive policy manual. You'll need audit trails, testing records, alert disposition logs, and escalation documentation that demonstrate your framework operates as designed.

2. Travel Rule Compliance as a Priority

The FIAU will assess Travel Rule compliance among crypto-asset service providers. This reflects the growing importance of digital asset controls within AML/CFT supervision. If you're a virtual asset service provider, expect scrutiny of your originator and beneficiary information collection, verification, and transmission processes. The Travel Rule, FATF Recommendation 16, requires you to obtain, hold, and transmit originator and beneficiary information for virtual asset transfers exceeding USD/EUR 1,000.

3. Enhanced Transaction Monitoring and CDD

The plan highlights transaction monitoring and Customer Due Diligence as key areas of focus. Your transaction monitoring rules must produce actionable alerts, not just volume. Your CDD processes must capture information that informs risk ratings and triggers enhanced measures when appropriate.

4. Source of Wealth and Funds Verification

The FIAU will examine verification of source of wealth and source of funds. Many firms collect this information but fail to verify it meaningfully. Verification means independent corroboration, reviewing bank statements, tax returns, property deeds, or business financials, not accepting customer declarations at face value. If you're applying enhanced due diligence to high-risk customers or politically exposed persons, your source-of-funds documentation must withstand challenge.

5. Aligning Controls with Identified Risks

The supervisory cycle will examine whether your controls respond to the risks you've identified in your business-wide risk assessment. If your assessment flags cash-intensive businesses as high-risk but your transaction monitoring rules don't include cash structuring scenarios, you've created an evidence gap. If you've identified correspondent banking relationships as elevated risk but haven't implemented enhanced ongoing due diligence, the FIAU will notice.

Preparing Your Team

You'll need to shift from a compliance-by-checklist mindset to an evidence-based approach. This requires three things: documentation of what you do, records of how you do it, and proof that it works.

Start by reviewing your most recent business-wide risk assessment. Map each identified risk to a specific control. Then gather evidence that the control operates effectively. For transaction monitoring, this means alert disposition records, false positive rates, and escalation logs. For Customer Due Diligence, this means completed risk profiles, periodic review schedules, and enhanced measures applied to high-risk customers. For reporting obligations, this means Suspicious Activity Report filing records, quality assurance reviews, and escalation to MLRO documentation.

If you're a crypto-asset service provider, prioritize Travel Rule implementation. You'll need systems that capture originator and beneficiary information, processes that verify the information before transmission, and protocols for handling transfers when counterparty VASPs don't comply. The FIAU's focus on Travel Rule compliance signals that technical challenges won't excuse non-compliance.

Technology can support this transition, but only if you deploy it strategically. RegTech solutions can automate alert generation, risk scoring, and periodic review scheduling, but they can't replace human judgment in alert disposition or risk assessment. Your technology should produce audit trails that demonstrate decision-making, not black boxes that obscure it.

Action Items by Priority

Immediate (Next 30 Days):

  • Conduct a gap analysis comparing your documented controls to your implementation evidence.
  • Review your transaction monitoring alert disposition logs for the past six months; identify patterns in false positives and adjust rules accordingly.
  • If you're a crypto-asset service provider, audit your Travel Rule compliance processes and identify technical or operational gaps.

Near-Term (Next 90 Days):

  • Map each risk identified in your business-wide risk assessment to a specific control, then document how that control operates.
  • Review Customer Due Diligence files for high-risk customers and politically exposed persons; verify that source-of-funds documentation includes independent corroboration.
  • Implement periodic testing of transaction monitoring rules to ensure they generate alerts aligned with your risk assessment.
  • Schedule training for compliance staff on evidence-based supervision and documentation practices.

Ongoing:

  • Establish quarterly reviews of control effectiveness metrics: alert disposition rates, periodic review completion rates, Suspicious Activity Report timelines, and enhanced due diligence trigger rates.
  • Create audit trails for all escalations to MLRO, including rationale and outcome.
  • Maintain version control for policy updates and document the risk or regulatory change that prompted each revision.
  • For crypto-asset service providers, monitor Travel Rule technical standards updates from FATF and industry working groups.

You Might Also Like