Many organisations believe their financial crime risk assessment is working simply because it gets done every year. The routine is well rehearsed. Spreadsheets are sent round, contributors file their inputs, drafts are stitched together and a weighty report lands in front of the Board.
According to Arctic Intelligence, on the surface, nothing looks wrong. Yet that sense of stability can be deceptive, and it often holds only until a regulatory review, a damaging audit finding or a push into a new market exposes a process that was never truly fit for purpose.
The core problem is inertia. When a process can be completed, it is easy to assume it is effective. But finishing a document is not proof of accuracy, consistency or defensibility. In many firms, the methodology is not designed so much as handed down. Spreadsheets pass from one MLRO to the next, gathering outdated definitions, contradictory logic and assumptions nobody can explain.
Control ratings go unchallenged because questioning them takes time and invites friction. Over the years, the assessment hardens into ritual rather than a real effort to understand exposure.
Spreadsheets themselves deepen the illusion. Neat tables, colour coding and scoring grids give an impression of rigour, while broken formulas, version clashes, accidental overwrites and missing evidence sit out of sight. Executives and Boards see polished outputs, not the fragility underneath, making spreadsheet reliance perhaps the most widespread blind spot in financial crime risk management.
Timing compounds the issue. Risk shifts constantly as products change, customer behaviour evolves and new typologies emerge.
An annual snapshot cannot keep pace, meaning the picture presented to the Board may already be stale by the time it is read. Boards, frequently stretched and dependent on summaries, may lack the expertise or visibility to probe these weaknesses, so a flawed system is endorsed by default.
Internal audit offers only partial protection. Reviews tend to run on one to three year cycles and focus on narrow areas, so by the time problems are flagged, they have often been embedded across several assessment rounds. Meanwhile, practitioners on the ground frequently know the process is brittle but lack the executive backing or tools to fix it, creating a culture of quiet resignation.
Change usually arrives only after a trigger event. A regulator requests evidence that cannot be produced, a formula collapses during consolidation, an expansion reveals methodological gaps, or there is simply no audit trail explaining past decisions. At that point, the comfort zone becomes untenable.
The lesson is clear. Financial crime threats are fast moving and unforgiving. Firms that challenge their assumptions, engage their Boards meaningfully and invest in RegTech platforms offering continuous, defensible risk visibility will stay ahead. Those that remain comfortable are likely to learn the hard way.
Read the full Arctic Intelligence post here.
Copyright © 2026 FinTech Global









