Why Firms Get the Outlook on AML Recommendations Backwards

HaloAML Social Pic Larger

Why Firms Get the Outlook on AML Recommendations Backwards

Most firms treat an independent AML review the way they’d treat a school inspection: something to survive, not something to want. If the report comes back with recommendations, that gets read as a scorecard and is seen as proof the firm wasn’t good enough.

That reading has it backwards. Recommendations Are the Point, Not the Problem.

A firm-wide risk assessment and a set of policies, controls and procedures existing on paper is conformity. Whether they actually hold up against how the firm really operates — its client base, its work types, its risk exposure — is scrutiny. An independent review is one of the few points where a firm voluntarily submits itself to that second test, before a regulator does it involuntarily.

Recommendations are what a review is supposed to produce. If an independent firm looks closely at your CDD, your matter risk assessments, your ongoing monitoring, and hands back a clean sheet with nothing to say, that’s not necessarily reassuring. It’s more likely a sign the review didn’t dig hard enough. Genuine scrutiny finds something to say, because no firm’s practice ever fully matches its policy document. Gaps between the two are normal. They’re also exactly what proactive supervision is designed to catch. The only choice a firm has is whether it catches them first.

There’s a version of this that firms already understand instinctively in other parts of the business. Nobody expects a financial audit to come back with zero adjustments and call that success. An audit that finds nothing to flag either means the finances are flawless or the audit wasn’t rigorous. AML review recommendations work the same way.

What changes if the framing shifts

Treated as a report card, recommendations get filed away, half-actioned, or quietly disputed. Treated as the intended output of scrutiny, they become a working list, something to close down methodically, matter by matter, with the MLRO or COLP able to show a supervisor exactly what was found and what was done about it.

That distinction matters more than it might seem, because it’s precisely what a thematic review or SRA inspection is looking for. Not a firm with no gaps (no firm has no gaps!) but a firm that can demonstrate it looks for them, finds them, and closes them down. A file showing you commissioned an independent review, received recommendations, and acted on them is stronger evidence of a functioning AML framework than a firm-wide risk assessment nobody has stress-tested since it was written.

The recommendations you don’t act on are the risk

The actual exposure isn’t having recommendations. It’s having them sit in an inbox for a year. A recommendation acted on becomes part of the firm’s compliance history. A recommendation ignored becomes the paper trail showing the firm knew and didn’t act — the single worst position to be in if a regulator later asks the same question the reviewer already raised.

So the next time a review comes back with a list, it’s worth resisting the urge to read it as a mark against the firm. It’s closer to being handed the exam questions before the exam.