Skip to main content
Who Decides When Fraud and AML Disagree?Compliance Program Governance
5 min readFor Fraud Managers

Who Decides When Fraud and AML Disagree?

The Challenge

Your fraud team flags a customer for unusual card activity. Meanwhile, your AML team sees transaction patterns that don't quite meet the thresholds for filing a Suspicious Activity Report (SAR). Payments operations note the account has been active for years with no prior issues. Each team holds a piece of the puzzle, but no one has the full picture.

The pressing question is: who makes the call?

This isn't a hypothetical issue. It's a governance gap that arises when organizations confuse shared responsibility with distributed authority. The idea that "financial crime risk is everyone's responsibility" sounds good, but it sidesteps a crucial operational question: when responsible teams reach different conclusions about the same customer, who has the authority to decide what happens next?

The Environment and Constraints

Consider your typical structure. Your fraud team operates on velocity rules and behavioral analytics, optimized to stop losses quickly. Your AML function works within regulatory timelines for investigation and reporting under the Bank Secrecy Act, focusing on thoroughness over speed. Payments operations measure success by transaction completion rates and customer satisfaction.

Each team has different mandates, metrics, and risk tolerances. That's intentional. The problem arises when a customer triggers concerns across multiple functions simultaneously.

The regulatory environment adds complexity. The FCA's recent action against Howard Roland Duckett highlights what happens when governance accountability becomes unclear. Duckett, who held both the SMF3 Executive Director and SMF16 Compliance Oversight functions at Beauforce Corporation Limited, was banned after the High Court found he repeatedly lied and relied on fabricated evidence. He also failed to disclose his director disqualification to the FCA. This case shows that senior management functions carry personal accountability, but only when decision authority is clearly defined.

Regulatory requirements are also shifting. FinCEN's final rule on August 11 permanently removed Beneficial Ownership Information (BOI) reporting requirements for U.S. companies under the Corporate Transparency Act. U.S. companies no longer submit BOI reports to FinCEN. Only certain foreign companies registered to do business in the U.S. remain subject to BOI reporting, and only for foreign beneficial owners. These changes demand governance structures that can adapt quickly without losing clarity about who owns which decisions.

The Approach Required

Effective governance in multi-team financial crime programs requires three key elements:

Clear escalation paths. When fraud identifies suspicious behavior and AML sees potential money laundering indicators on the same customer, there must be a documented process for bringing that information together. This isn't about creating another committee; it's about defining who consolidates the information and within what timeframe.

Defined decision authority. For material financial crime issues, one function must have final authority. Typically, this should sit with the AML function or the MLRO, as they carry regulatory accountability for SAR decisions and customer due diligence. The critical point isn't which function holds authority; it's that everyone knows who does.

Structured challenge rights. Other teams must have the ability to formally challenge decisions they believe create unacceptable risk. If fraud believes AML is underestimating account takeover risk, or if payments operations see customer impact that wasn't considered, they need a documented mechanism to escalate that view. The decision authority doesn't change, but the decision-maker must address the challenge on the record.

What Doesn't Work

Consensus-based decision-making is a common alternative. It sounds collaborative, but it creates three problems:

First, it slows decisions to the speed of the most cautious team. When fraud wants to block a transaction immediately and AML needs three days to complete an investigation, consensus means either fraud waits or AML is pressured to shortcut their process.

Second, it diffuses accountability. If a decision later proves wrong, whether that's a missed SAR or an inappropriate customer exit, no single person or function owns the outcome. That's exactly what regulators look for during examinations.

Third, it breaks down entirely when commercial pressure enters the equation. If the relationship generates significant revenue, consensus models allow commercial considerations to override risk assessments without anyone explicitly making that call.

Results That Matter

Organizations with clear governance structures can measure specific outcomes:

Decision speed. Time from initial flag to final decision on customer action. Clear authority typically cuts this timeline by 40-60% compared to consensus models, though your results will depend on your current state.

Escalation transparency. Count of formal challenges raised and how they were resolved. If no challenges occur, your process likely isn't working; teams should feel empowered to raise concerns.

Regulatory examination findings. Examiners consistently note governance clarity in their reports. The absence of governance findings is itself a meaningful metric.

The European Commission's recent report on AMLD6 transposition shows that 23 Member States have fully transposed the Sixth Anti-Money Laundering Directive, while Croatia, Estonia, and Poland had not communicated transposition measures. Slovakia had only partially transposed it. Infringement proceedings remain pending against 10 Member States. This uneven implementation across jurisdictions means your governance framework must account for varying regulatory expectations across markets.

What to Do Differently

If you're building or revising your governance structure, avoid these common mistakes:

Don't create governance by job title alone. "The MLRO decides" is incomplete. You need to specify what the MLRO decides, what information they must consider, and what timeline applies.

Don't assume governance is static. As FinCEN's permanent removal of BOI reporting requirements for U.S. companies demonstrates, regulatory obligations shift. Your governance framework should include a defined process for updating decision authorities when requirements change.

Don't skip documentation. Every material decision should create a record showing who made it, what information they considered, what alternatives were evaluated, and what challenges were raised. This isn't bureaucracy; it's evidence of functioning governance.

Takeaways for Your Team

Map your current state. For your last five material financial crime decisions, identify who actually made the call. If the answer varies, or if it's unclear, you have a governance gap.

Define decision authority in writing. Your AML/CFT framework should specify who has final authority for customer due diligence decisions, transaction restrictions, SAR filings, and relationship exits. If multiple teams are involved, document who consolidates information and who decides.

Test the framework under pressure. Run a tabletop exercise where fraud and AML reach different conclusions about the same customer. See whether your documented process actually resolves the disagreement or whether people default to informal negotiation.

Build challenge rights into your procedures. Create a formal mechanism for any team to escalate concerns about a decision they believe creates unacceptable risk. Track these challenges and how they're resolved.

Shared responsibility for financial crime risk is necessary. But responsibility without clear decision authority isn't governance. It's a gap waiting to surface during your next regulatory examination.

You Might Also Like