Financial services sector is at a threshold that feels both inevitable and under-examined, in equal measures. The very architecture of how institutions perceive risk, steward data and reach conclusions carrying regulatory and societal weight is being forced into the open. The question that presses itself upon boards and executives is whether the heavy investment in systems, frameworks and regulatory responses has merely papered over the more stubborn origins of failure that still lie in human judgement, organisational culture and fragmented governance. Technology has marched forward, regulation has tightened its grip and expectations have climbed, yet the industry remains entangled in the basic mechanics of how decisions are formed, tested and put into practice, which raises an uncomfortable possibility: have we been solving the wrong problem all along?
Nowhere does this become clearer than in financial crime compliance, where recent enforcement actions across jurisdictions form a pattern that any careful observer can trace if willing to look past the surface explanations.
Institutions are not collapsing under the weight of missing technology; they are found wanting it because clarity itself is absent so maybe AI can bring that, because data quality and documentation discipline are treated as secondary, and because the professional scepticism required to interpret risk signals is too often diluted by inconsistent pathways, siloed structures or commercial pressures that override sound judgement. These are cognitive, organisational and cultural ones, and the cascade that follows is almost mechanical in its predictability: a weak onboarding decision seeds a weak monitoring decision, which in turn produces a weak reporting decision, until regulatory action arrives as the inevitable consequence of choices that might have been different had decision intelligence been designed into the system from the start.
Is compliance still best understood as a process to be executed, or has it always been a decision system whose quality rests on the integrity of its inputs, the reliability of its data and the maturity of the people who operate it?
Boards and executive management now faces the harder recognition that financial crime compliance has ceased to be a technical function and has become a strategic capability, an expression of institutional integrity and a direct measure of how thoroughly an organisation understands its customers, its data and its obligations.
The institutions that will thrive are those that stop treating compliance as a cost centre and begin designing, governing and continuously refining it as a decision system behind business decisions, shifting from reactive obligation to a proactive discipline that underpins trust, resilience and long-term profitability;
Yet, the deeper realisation waiting for those prepared to confront it is that the greatest risk may no longer be the crime itself, but the unexamined assumptions still guiding how we decide.
Extended commentary by Martin Woods, Chair of GCI
Clara’s argument is not only accurate - it is overdue. And from where I sit, after decades in financial crime investigations, whistleblowing, and advising institutions around the world, I can say plainly: the industry has been treating symptoms while ignoring the disease. Too many practitioners have tolerated a failing status quo. We have built bigger systems, hired larger teams, and written longer policies, yet we still see the same failures repeated with almost ritualistic predictability. The problem is not that compliance lacks resources. The problem is that compliance lacks coherence.
The truth is uncomfortable but simple: far too many institutions do not understand how their own decisions are made. They cannot explain why one customer was onboarded and another rejected. They cannot articulate why one alert was escalated and another dismissed. They cannot demonstrate why one SAR was filed and another was not. And when regulators ask for the rationale, some institutions scramble to reconstruct logic that should have been present from the start.
This is not a technology problem. It is a thinking problem.
In some institutions, financial crime compliance has become a maze of disconnected tasks - onboarding, monitoring, screening, reporting - each carried out by different teams with different pressures and different interpretations of risk. What we have not done is design the decision pathways that connect these tasks into a coherent system. Without those pathways, institutions are left with fragmented judgement, inconsistent outcomes, and a governance structure that cannot see the whole picture.
Decision intelligence is not a fashionable phrase. It is the missing discipline in financial crime compliance. It demands that institutions understand the architecture of their decisions: who makes them, what information they rely on, how they are validated, and how they are documented. It requires clarity, consistency, and accountability - three qualities that are often promised but not always delivered.
Across enforcement actions, the same failures appear again and again. Institutions did not understand their customers. They did not interpret their data. They did not escalate concerns. They did not document decisions. They did not challenge assumptions. They did not connect the dots. These are failures of judgement, not failures of software.
Some practitioners within the industry have become obsessed with activity - number of alerts processed, number of customers reviewed, number of reports filed - as if volume were a proxy for quality. It is not. Regulators do not care how busy an institution is. They care how intelligent it is. They care whether decisions are sound, defensible, and aligned with risk. They care whether institutions can explain themselves.
Compliance has always been a decision system, but some institutions have treated it as a production line. They have trained people to complete tasks, not to think critically. They have rewarded speed, not scepticism. They have built dashboards that count things, not dashboards that illuminate risk. And they have allowed commercial pressure to override professional judgement, often quietly, sometimes blatantly.
The next era of financial crime compliance will not be defined by more controls. It will be defined by better decisions. AI will play a role, but not the role many imagine. AI will not replace judgement; it will expose the absence of it. It will highlight inconsistencies, surface anomalies, enforce documentation discipline, and reveal where decision pathways are broken. It will make poor thinking visible. And that visibility will be uncomfortable for institutions that have relied on opacity.
Boards must stop asking how many alerts were closed and start asking how decisions were made. They must stop treating compliance as a defensive function and start treating it as a strategic capability. They must recognise that financial crime compliance is now a measure of institutional integrity, not a regulatory obligation. The institutions that thrive will be those that embed decision intelligence into every layer of their operations - from onboarding to monitoring to reporting to governance.
The greatest risk facing the industry is not criminals. It is complacency. It is the belief that more technology will solve problems rooted in human judgement. It is the assumption that compliance is a cost centre rather than a decision engine. It is the refusal to confront the cognitive, cultural, and organisational weaknesses that undermine decision quality.
Financial crime compliance is entering a new era, one where clarity is currency and decision intelligence is the differentiator. Institutions that embrace this shift will build trust, resilience, and long‑term profitability. Those that do not will continue to repeat the same failures, incur the same penalties, and wonder why nothing changes.
The status quo is not acceptable, the future of compliance will be shaped not by the systems we build, but by the decisions we make - and by our willingness to examine the assumptions that guide them.
