Policies, Procedures and Controls
Policies, procedures and controls are the written rules and practical steps an organization uses to run its compliance program. Policies set out what management expects and intends, procedures describe how those expectations are carried out in day-to-day work, and controls are the mechanisms that enforce or verify that the rules are actually being followed. Together they help an organization detect, deter and manage financial crime risk, though they cannot on their own guarantee that risk is eliminated.
"Policies, procedures and controls" is a governance framework in which three distinct but related components operate together within a compliance program. Policies are high-level statements that establish management's intent and define the organization's expected structure and conduct. Procedures translate those policies into action by specifying the operational steps that put the expected outcomes into practice. Controls are the enforcement and verification mechanisms; notably, policies, procedures and standards are not themselves controls until something enforces or validates them, at which point they function as control activities. In AML/CFT contexts these components are typically documented, approved, and periodically tested for effectiveness, and their specific content and required elements vary by jurisdiction and by the obligations applicable to a given obliged entity; exact regulatory requirements should be confirmed against the applicable regime.
Why it matters
Policies, procedures and controls form the operational backbone of a compliance program. Without documented policies that establish management's intent, staff have no authoritative statement of what the organization expects; without procedures that translate those expectations into concrete steps, front-line employees are left to improvise; and without controls that enforce or verify adherence, an organization has no reliable way of knowing whether its rules are actually being followed. Treating any one of these components as a substitute for the others is a common weakness, because a policy or procedure that is never enforced or validated does not function as a control at all.
Getting these components right supports an organization's ability to detect, deter and manage financial crime risk in a consistent and repeatable way, and helps demonstrate to regulators and internal stakeholders that a program is more than aspirational. Clear policies and procedures bring clarity to internal processes and help employees carry out their responsibilities consistently, while control activities provide the verification that gives management assurance the framework is operating as intended.
It is important to keep expectations calibrated, however. A well-designed set of policies, procedures and controls can strengthen an organization's defenses, but no framework can guarantee that financial crime risk is eliminated. The specific content and required elements of these components vary by jurisdiction and by the obligations applicable to a given obliged entity, so exact requirements should always be confirmed against the applicable regime.
Who it's relevant to
Inside PPC
Common questions
Answers to the questions practitioners most commonly ask about PPC.