Skip to main content
Category: Compliance Program Governance

Financial Crime Compliance (FCC) Program

Also known as: FCC, Financial Crimes Compliance Program, Financial Crime and Compliance Program
Simply put

A Financial Crime Compliance (FCC) program is the set of frameworks, policies, and processes that a financial institution puts in place to detect, deter, and report financial crime such as money laundering, fraud, and sanctions breaches. It typically brings together related control areas, such as customer due diligence, anti-money laundering, and sanctions screening, into a coordinated enterprise function. It is designed to help manage financial crime risk and meet regulatory expectations, though it does not guarantee that crime will be prevented.

Formal definition

An FCC program is an enterprise-wide framework of policies, controls, and processes deployed by an obliged entity, most commonly a financial institution such as a bank, NBFI, or FinTech, to identify, mitigate, and report financial crime risks. In practice it commonly encompasses component disciplines including Know Your Customer (KYC) and customer due diligence, anti-money laundering (AML), and sanctions screening, and may extend to fraud and other misuse of the firm's products and services. Scope, structure, and the specific obligations imposed on such a program vary by jurisdiction and by the regulatory regime applicable to the entity; the evidence provided here describes the concept at a general level rather than specifying the requirements of any particular regulator, and applicable rules should be confirmed against the relevant regime.

Why it matters

A Financial Crime Compliance (FCC) program matters because financial crime rarely confines itself to a single control area. Money laundering, fraud, and sanctions breaches can move through the same customer relationships, products, and payment channels, and a siloed approach, where anti-money laundering, sanctions screening, and customer due diligence operate in isolation, can leave gaps that expose an institution to both criminal misuse and regulatory scrutiny. By coordinating these disciplines into an enterprise function, an FCC program is intended to give a firm a more coherent view of the risks running across its products and services.

For obliged entities such as banks, NBFIs, and FinTechs, an FCC program is also the operational expression of the institution's commitment to detect, deter, and report financial crime. It is designed to help the firm manage financial crime risk and meet the expectations of the applicable regulatory regime. It is important to stress, however, that no program guarantees prevention: an FCC framework is a set of measures to detect, deter, and mitigate risk, not a guarantee that crime will be stopped, and the specific obligations imposed vary by jurisdiction and by the regime applicable to the entity.

Who it's relevant to

Banks and other financial institutions
Banks operate the most established FCC programs, coordinating KYC and customer due diligence, AML, and sanctions screening across the enterprise. Because such institutions handle high volumes of customers, products, and payment flows, an integrated FCC function helps them manage risk and align with the expectations of their applicable regulatory regime, though it does not eliminate financial crime risk.
Non-bank financial institutions (NBFIs) and FinTechs
NBFIs and FinTech companies are increasingly expected to maintain FCC programs suited to their products and services. Individuals pursuing careers in these firms are a core audience for FCC training and knowledge, and the applicable obligations should be confirmed against the regime governing the particular entity and jurisdiction.
FCC and compliance professionals
Compliance officers, analysts, and other professionals who design, run, or work within these programs rely on a clear understanding of how KYC/CDD, AML, and sanctions screening fit together into a coordinated enterprise function, and of the boundaries between managing risk and guaranteeing prevention.
Institutions protecting against product and service misuse
Firms committed to a strong enterprise-wide FCC program use it to protect against the misuse of their products and services. This is relevant to any organization seeking to detect, deter, and report financial crime across its operations, with the specific scope shaped by the regulatory regime it is subject to.

Inside FCC

Governance and Accountability Framework
The internal structure that assigns responsibility for the FCC program, typically including board and senior management oversight and a designated compliance function. In many jurisdictions, obliged entities are expected to appoint a nominated officer or compliance officer (for example, an MLRO under the UK Money Laundering Regulations or a BSA Officer under US FinCEN rules), though the exact title, seniority, and duties vary by regime and should be confirmed against applicable law.
Risk Assessment
A documented assessment of the money laundering, terrorist financing, and related financial crime risks the entity is exposed to, generally considering factors such as customers, products and services, delivery channels, and geographies. This underpins the risk-based approach reflected in the FATF Recommendations (which are standards, not binding law) and transposed differently across regimes such as the EU AML framework and the US Bank Secrecy Act.
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD)
Policies and procedures for identifying and verifying customers and, where applicable, understanding the purpose of the relationship. CDD is the baseline process, while EDD applies additional measures to higher-risk situations. These are distinct from KYC as a broader onboarding concept; the specific triggers, thresholds, and beneficial ownership requirements differ by jurisdiction and obliged-entity category.
Ongoing Monitoring
Processes to monitor transactions and customer activity over the life of the relationship to detect activity that may be unusual or inconsistent with the customer's expected profile. This is a measure to detect and manage risk, not a guarantee that all illicit activity will be identified.
Screening Controls
Measures to screen customers and, in many cases, transactions against sanctions lists and against politically exposed person (PEP) status. Sanctions screening and PEP screening are separate functions addressing different risks: sanctions screening concerns prohibited or restricted parties, while PEP screening identifies individuals who may warrant enhanced scrutiny. A screening match is an indicator requiring review, not proof of wrongdoing.
Suspicious Activity Reporting
Procedures for identifying, escalating, and reporting suspicious activity to the relevant financial intelligence unit or authority. Terminology and mechanics differ by regime, for example a SAR under US FinCEN rules versus an STR in many other jurisdictions. A report reflects a compliance obligation to escalate suspicion and does not itself establish that a crime has occurred.
Record-Keeping
Requirements to retain due diligence records, transaction records, and reporting documentation for periods specified by the applicable regime. Exact retention periods vary by jurisdiction and should be confirmed against the relevant regulation.
Training and Awareness
Programs to ensure relevant staff understand their obligations, can recognize potential indicators of financial crime, and know escalation procedures. Indicators and typologies should be treated as illustrative rather than exhaustive or as proof of criminality.
Independent Testing and Assurance
Independent review or audit of the FCC program to assess whether controls are designed and operating effectively. The frequency and independence expectations vary by regime and entity size.

Common questions

Answers to the questions practitioners most commonly ask about FCC.

Does having a financial crime compliance program guarantee that my institution will prevent money laundering and other financial crime?
No. An FCC program is a set of measures designed to detect, deter, mitigate, and manage financial crime risk, not a guarantee of prevention. Because financial crime typologies evolve and no control eliminates risk entirely, an effective program is generally expected to take a risk-based approach that identifies, assesses, and manages residual risk rather than promising to stop all illicit activity. Supervisors in many jurisdictions assess the reasonableness and effectiveness of the program, not whether any wrongdoing ever occurs.
Is a financial crime compliance program the same as an AML program?
Not exactly. AML compliance is a core component of an FCC program, but the two are not interchangeable. FCC is typically used as a broader umbrella that may encompass anti-money laundering, counter-terrorist financing, sanctions compliance, anti-bribery and corruption, fraud, and related areas, depending on how an institution scopes its framework. The precise boundaries vary by institution and jurisdiction, and some regimes address these components under separate legal instruments rather than a single unified obligation, so the scope of any given FCC program should be defined against the applicable requirements.
What are the typical core components of an FCC program?
While the exact requirements differ by jurisdiction and obliged-entity type, FCC programs generally include a governance and accountability structure, a risk assessment, internal policies, procedures and controls, customer due diligence and ongoing monitoring processes, transaction monitoring and screening, suspicious activity reporting mechanisms, training, and independent testing or audit. The specific elements, and how they are documented and supervised, should be confirmed against the relevant framework applicable to the entity, such as the FATF Recommendations as standards or the binding rules of a particular regime.
Who within an institution is generally responsible for the FCC program?
Responsibility is typically distributed across governance layers. Senior management and the board generally hold overall accountability for the program and its risk appetite, while a designated compliance officer or equivalent role (the title and statutory basis vary by jurisdiction) usually oversees day-to-day operation. Many programs also rely on a three-lines model, with the business as the first line, compliance and risk functions as the second, and internal audit or independent testing as the third. The precise roles and any mandatory appointments should be confirmed against applicable regulation.
How should the FCC program be tailored to the institution's risk profile?
Under a risk-based approach, the program is generally expected to be proportionate to the institution's assessed exposure across factors such as customer types, products and services, delivery channels, and geographies. This typically means allocating greater resources and enhanced measures to higher-risk areas and applying more streamlined measures where risk is lower, subject to any regulatory minimums. The institution's risk assessment usually informs how components such as due diligence and monitoring are calibrated, and it is generally reviewed and updated over time rather than treated as static.
How is the effectiveness of an FCC program typically tested and maintained?
Effectiveness is generally assessed through independent testing or audit, ongoing quality assurance, management information and metrics, and periodic review of the risk assessment and controls against emerging threats and regulatory change. Many frameworks expect the program to be dynamic, meaning it is updated in response to findings, new typologies, and changes in the institution's business or applicable rules. The specific frequency, scope, and documentation expectations for independent review vary by jurisdiction and should be confirmed against the applicable requirements.

Common misconceptions

An effective FCC program prevents financial crime.
An FCC program consists of measures to detect, deter, mitigate, and manage financial crime risk; no single control or program eliminates that risk or guarantees prevention. Programs are assessed on the reasonableness and effectiveness of their risk-based measures, not on achieving a zero-incident outcome.
There is one global set of FCC rules that applies identically everywhere.
The FATF Recommendations are international standards rather than binding law, and they are implemented differently across regimes such as the EU AML Directives and AML Regulation, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations and Proceeds of Crime Act. Obligations, thresholds, and terminology diverge, so requirements must be confirmed against the applicable jurisdiction.
Filing a suspicious activity report or generating a screening match confirms that a customer has committed a crime.
A SAR or STR filing reflects a compliance obligation to escalate suspicion, and a sanctions or PEP screening match is an indicator requiring review. Neither establishes wrongdoing as a matter of criminal law; that is a separate determination for competent authorities.

Best practices

Ground the program in a documented, periodically refreshed risk assessment covering customers, products, channels, and geographies, and ensure controls are proportionate to the risks identified.
Map each control to its correct source obligation and jurisdiction, rather than assuming a single global rule, and confirm specific thresholds and retention periods against the applicable regulation.
Maintain clear governance with a designated compliance officer and documented senior management and board oversight, consistent with the titles and duties required in the relevant regime.
Apply CDD as the baseline and reserve EDD for higher-risk situations, keeping KYC, CDD, and EDD distinct and clearly triggered within policy.
Operate sanctions screening and PEP screening as separate functions with defined review and escalation workflows, treating matches as indicators for investigation rather than conclusions of wrongdoing.
Subject the program to independent testing and update training so staff treat typologies and red flags as illustrative indicators, not exhaustive lists or proof of criminality.