I was going through Natalie Dawson’s content on leadership and organizational design. Not compliance. Not AML. Pure business management.
She describes how effective CEOs assess their organizations through three lenses: People, Process, and Financial goals. The idea is simple that most organizational problems trace back to a gap in one of these three areas.
Halfway through, I stopped. Because I recognized the structure. Not from a leadership book. From an EBA supervisory methodology. If you’re working on AML inspection preparation, this parallel is worth understanding, because it reframes how you think about a program review.
How People, Process, and Financial Goals Map to AML Supervisory Assessment
People – Governance and Human Resourcing
Supervisors assess MLRO qualifications, reporting lines, and actual authority. They look at team headcount relative to business volume, customer complexity, and risk profile. They ask whether the MLRO has real independence – or whether compliance is structurally subordinate to business decisions.
This is explicit in EBA’s Risk-Based Supervision Guidelines (EBA/GL/2021/16). Adequacy of human resourcing is linked directly to supervisory risk scores. An understaffed function, or one where the MLRO lacks direct board access, generates findings regardless of how well-written the procedures are.
This is often the first place an AML inspection preparation begins with assessing whether your governance structure actually supports
effective decision-making.
The CEO question and the supervisor question are the same: Do you have the right people, and do they have the authority to actually do the job?
Process – Operational Effectiveness of Controls
Here supervisors go beyond the policy document. They look at how alerts are handled in practice — not what the procedure says, but what actually happens. Average resolution time. Escalation patterns. Whether analysts understand the business model behind a customer’s activity, or mainly move cases through workflow.
This is where most programs show gaps during inspections. Procedures are written at a point in time. Operations drift. The gap between documented controls and operational reality is almost always larger than compliance teams expect, not because of bad intent, but because no one went back to check.
Consider a mid-size payment institution with solid written procedures for high-risk customer monitoring. Their policy says alerts are reviewed within 48 hours. In practice, a backlog has built up over six months, quietly tolerated until an internal audit flagged it. The supervisor, during inspection, asked a simple question: “Show me the last 20 closed alerts and how long each took.” The gap between policy and reality became the primary finding.
The bridge between documentation and reality matters a lot during AML inspection preparation. In that case, the payment institution supervisors didn’t criticize the “written” procedures, but they critiqued the operational reality that the procedures failed to address.
The CEO question and the supervisor question: Is your process working in practice, or just documented?
Financial – ML/TF Risk Exposure and Risk Appetite
Supervisors assess whether institutions understand their own ML/TF risk exposure by product, customer segment, geography, and delivery channel. They check whether this exposure is proportional to the risk appetite formally approved by the board. They look for blind spots: areas where de-risking in one segment shifted risk elsewhere without adequate visibility.
Most MLROs can describe their controls. Fewer can articulate their institution’s ML/TF risk profile in financial terms – the way a CFO would describe credit exposure. This is the lens compliance teams answer least well, and it often shows in the quality of risk assessments submitted to supervisors.
The CEO question and the supervisor question: Do you understand the financial shape of your risk, and is it within the limits your leadership has formally accepted?
What This Means for MLRO Inspection Readiness
The MLRO who prepares for inspections by reviewing documentation – procedures, training logs, SAR counts – is starting from the right place. But documentation review answers the question “do we have this?” It rarely answers “does this work?”
The People / Process / Financial frame shifts the question to operational reality. Before your next program review, consider these:
People:
- If my MLRO left tomorrow, could the deputy run an inspection without external help?
- Is my team headcount justified against current alert volume and customer risk profile – or against last year’s numbers?
- When did I last document the rationale for my team structure in terms a supervisor would accept?
Process:
- What is our actual average alert resolution time over the last 90 days – not the SLA target?
- In the last 20 escalations to senior AML, how many were genuine uncertainty versus transferred accountability?
- Which controls have we not tested operationally in the last 12 months?
Financial:
- Can I articulate our top three ML/TF risk exposures in one page by product, segment, and geography?
- When did the board last formally review and approve our risk appetite statement?
- Where did we de-risk in the last year, and did we assess whether that shifted risk elsewhere?
One Practical Starting Point
Before your next internal AML review, write nine sentences: three for People, three for Process, three for Financial. Not from existing reports. From what you know about operations.
Where you can’t write a concrete sentence that’s a gap worth examining before a supervisor does. AML inspection preparation isn’t primarily about documentation. It’s about knowing your program well enough that the inspection confirms what you already know, rather than revealing what you’ve been avoiding.
Sources:
- EBA Guidelines on Risk-Based Supervision of Credit and Financial Institutions for AML/CFT Purposes (EBA/GL/2021/16): https://www.eba.europa.eu/regulation-and-policy/anti-money-laundering-and-e-money/guidelines-on-risk-based-supervision






Leave a Reply