A Structural Critique of the Global AML Framework: Five Problems and Five Reforms
- A Structural Critique of the Global AML Framework
- Introduction: The Same Pattern, Eleven Times
- Part One: Five Structural Problems
- Part Two: What a Better Framework Would Look Like
- Reform One: Outcome-Based Supervisory Standards
- What Outcome Standards Would Look Like
AML Expert
Get tailored guidance on your compliance obligations, SAR filing, or AML program review.
Introduction: The Same Pattern, Eleven Times
This series began with a simple premise: that the AML compliance challenges facing regulated businesses are not adequately addressed by generic guidance, and that practitioners working in specific sectors deserve analysis of the specific problems they actually encounter. Eleven articles later, the premise has held. Every sector examined (law firms, accountants, TCSPs, DPMS dealers, real estate agents, banks, exchange houses, fintechs, wealth managers, VASPs, and commodity traders) has its own specific challenges, its own unresolved regulatory questions, and its own gap between the framework's formal requirements and what adequate compliance actually demands.
But something else has emerged from writing across all eleven sectors. The specific problems are different. The structural problems are the same. In every sector, we found a framework that measures process rather than outcome. In every sector, we found a supervisory model that collects data useful for demonstrating that the framework exists and is being followed, rather than data useful for assessing whether the framework is working. In every sector, we found obliged entities making individually rational compliance decisions that are collectively counterproductive, de-risking that exports risk, monitoring that generates noise, and CDD that documents identity without understanding wealth. And in every sector, we found practitioners doing their best to build genuinely effective compliance programmes inside a framework that does not always reward them for doing so.
This closing article steps back from the sector-level analysis to examine the structural failures that the series has repeatedly encountered. It does not argue that the AML framework is without value; it is not, and the compliance professionals who implement it are doing important work. It argues that the framework has specific, identifiable structural problems that limit its effectiveness, and that addressing those problems is a legitimate and necessary conversation that the profession should be having openly.
Naming what is wrong is the precondition for fixing it. That is what this article attempts to do.
Part One: Five Structural Problems
1. The Process-Outcome Inversion
The most fundamental structural failure in the global AML framework is that it measures process rather than outcome. This is not an accident. Process measurement is administratively tractable. It produces numbers. It can be assessed in a supervisory examination without requiring the examiner to make complex judgements about risk quality. Does the firm have a CDD policy? Does it conduct transaction monitoring? Does it file STRs? These questions have yes or no answers, and the answers can be verified against documented evidence. They are the questions that supervisory frameworks have been built around, and they are, as a measure of compliance effectiveness, deeply insufficient.
The outcome that the AML framework is supposed to produce is the detection and disruption of money laundering and terrorist financing. A firm that achieves this outcome (that identifies suspicious activity, files reports that contribute to law enforcement investigations, and takes action that prevents criminal proceeds from flowing through its business) is doing what the framework was designed to achieve. A firm that has a policy, runs a monitoring system, and files reports that produce no law enforcement outcomes is compliant in every measurable sense and effective in none.
The process-outcome inversion is not merely academic. It has consequences for how obliged entities allocate their compliance resources. A firm facing a supervisory examination that will assess its processes rationally invests in the things that examiners look for. A firm facing an examination that would assess its outcomes (how many of its STRs produced actionable intelligence, what proportion of its high-risk clients were correctly identified, how many of the suspicious transactions in its portfolio were detected by its monitoring programme) would invest differently. The current framework rewards the former. The outcomes the framework is designed to achieve require the latter.
The annual return, examined in every article in this series, is the most visible expression of the process-outcome inversion. It is a process reporting instrument. It asks whether systems exist. It counts clients and transactions. It records STRs filed. It does not ask whether the systems are effective, whether the client risk ratings are accurate, or whether the filed STRs contributed to any outcome. The information it collects is useful for confirming that firms are going through the required motions. It is of limited use for assessing whether those motions are producing the results the framework exists to achieve.
2. The Perimeter Problem
The AML framework's designated perimeter, the set of obliged entities subject to formal AML obligations, reflects a series of historical decisions about which sectors present sufficient risk to warrant regulation. Financial institutions are in. Most DNFBPs are in. Physical commodity traders are mostly out. Community hawaladars are often out. Small-scale real estate intermediaries operating below commercial thresholds are sometimes out. The distribution of who is in and who is out has not been systematically reviewed in any jurisdiction against a consistent risk-based criterion, and it shows.
The commodity trading sector, examined in the previous article, is the clearest example. Physical commodity traders handling billions of dollars of transactions across high-risk jurisdictions, using pricing mechanisms that are well documented as TBML vehicles, have no specific AML designation in most jurisdictions. DPMS dealers selling gold jewellery worth a few thousand dollars are designated. A clear public risk-profile justification for this asymmetry is rarely available. The DPMS sector was designated because cash purchases of precious metals were identified as a risk. The commodity trading sector was not designated because the political economy of regulating large commodity trading businesses is more complex than the political economy of regulating small jewellery shops.
The perimeter problem compounds across the sectors examined in this series. In the VASP sector, decentralised finance operates largely outside the formal perimeter. In the fintech sector, BNPL products that are functionally credit products may sit outside the consumer credit perimeter. In the remittance sector, community hawaladars who cannot access the formal registration framework operate outside it. In each case, the activities outside the perimeter are not necessarily lower-risk than those inside it; they are simply harder to regulate, more politically complicated to designate, or more recently emerged than the framework's existing categories anticipated.
The perimeter problem is not just a regulatory design failure. It is a strategic failure. A framework that captures some of the entities involved in the financial crime ecosystem and leaves others outside it has a predictable long-term effect: criminal activity migrates to the unregulated portions of the ecosystem, the regulated portions become progressively more burdened without commensurate risk reduction, and the gap between compliance cost and compliance outcome widens. This is not a theoretical prediction. It is the documented experience of the AML framework over the past two decades.
3. The Safe Harbour Deficit
Across the series, one structural failure appeared with striking consistency in sectors as different as correspondent banking, hawala registration, and VASP de-banking: the absence of a safe harbour for good-faith compliance. In every case where this absence was examined, the result was the same. Without protection for genuine, documented, risk-based compliance decisions, the rational response for obliged entities is to make defensive decisions (to exit relationships rather than manage them, to refuse services rather than apply proportionate controls, to over-file rather than exercise judgement) because no safe harbour means that any residual risk is potentially an enforcement liability.
The correspondent banking de-risking problem, examined in the banks' article, is the most extensively documented example. Banks have been explicitly told, by FATF and by supervisors in multiple jurisdictions, that wholesale de-risking is inconsistent with the risk-based approach. They have continued to de-risk because the alternative (maintaining a relationship that carries residual risk, managing that risk through documented controls, and defending the decision to a supervisor if the relationship later becomes associated with a laundering case) requires a safe harbour that does not exist. Public examples of banks being expressly recognised for maintaining difficult correspondent relationships and managing them well are rare. Several have faced significant penalties for maintaining relationships that turned out to be associated with money laundering, regardless of the quality of the risk management applied.
The safe harbour deficit is a direct consequence of the process-outcome inversion. A framework that assesses compliance by examining process cannot readily distinguish between a firm that maintained a difficult relationship because it made a genuine, documented, risk-based judgement that the relationship was manageable, and a firm that maintained the relationship because it did not notice the risk or did not want to lose the revenue. Both decisions produce the same documentary trail. The enforcement environment cannot reliably tell the difference in hindsight, and so it treats both as equivalent risk exposures. The rational response is to eliminate the risk by eliminating the relationship.
The same dynamic operates in every sector where a regulated entity must make a judgment call about whether to accept, maintain, or exit a client relationship that carries some degree of risk. The firm that makes the call wrong faces regulatory consequences. The firm that makes the call unnecessarily conservative (refusing a legitimate client, exiting a relationship that was genuinely manageable) faces no regulatory consequence at all, and imposes costs on the client and on financial inclusion that are not visible in the supervisory framework. The asymmetry produces systematic over-caution, and the cumulative effect of that over-caution (in terms of financial exclusion, market disruption, and the migration of activity to unregulated channels) is a cost of the AML framework that is never measured and rarely acknowledged.
In day-to-day practice, the pressure is rarely to understand a client better; it is to document them faster. A risk-based decision I can defend in an inspection gets treated as safer than one that is actually correct, so the rational move becomes exiting the relationship rather than managing it. Protect honest judgment, and you change what compliance officers are actually willing to do.
Dipali Vora | AML/CFT and Compliance Specialist, AML Guild
4. The Intelligence Loop Failure
The STR filing system is the primary mechanism through which the AML framework generates financial intelligence for law enforcement. An obliged entity that identifies suspicious activity files a report with the national financial intelligence unit. The FIU analyses the report, combines it with other intelligence, and disseminates relevant findings to law enforcement agencies. Investigations are opened. Prosecutions follow. Criminal proceeds are recovered. This is the theory.
The practice is more complicated. The volume of STRs filed in most jurisdictions significantly exceeds the capacity of FIUs to analyse them all in depth. In large jurisdictions, hundreds of thousands of STRs are filed annually. In many jurisdictions, the proportion that contributes to investigations, prosecutions, or asset recovery is substantially lower than the overall volume of reports filed. The investment made by obliged entities in the processes and systems that generate these reports is enormous, and the return on that investment, measured in terms of disrupted criminal activity and recovered criminal proceeds, is, by most objective assessments, disproportionately low relative to the cost.
The intelligence loop has a second failure mode that is less discussed but equally significant: the absence of feedback. In most jurisdictions, the FIU does not routinely provide obliged entities with information about the outcome of their STR filings, whether reports were acted upon, whether they contributed to investigations, or whether the patterns identified were part of a larger picture that the entity should be aware of for future monitoring purposes. The compliance professional who files a report disappears into a void. Either way, the filer learns almost nothing about whether their report was accurate, whether their suspicion was well-founded, or whether their monitoring framework is identifying the right patterns.
The consequence of this feedback absence is a compliance function that cannot learn from its own outputs. A monitoring programme that cannot be validated against its outcomes is a programme that improves only through guesswork and periodic regulatory examination, not through systematic learning. The feedback loop that would allow the compliance function to improve its effectiveness is almost entirely absent from the current framework.
This failure is not invisible to those working in the system. FATF and national FIUs have acknowledged the need for improved feedback mechanisms. Some jurisdictions have experimented with typology feedback, with sanitised case summaries shared with reporting entities, and with sector-specific intelligence briefings. These are valuable but insufficient. A systematic, jurisdiction-wide feedback mechanism, one that tells obliged entities not just what the typologies are but whether their specific filings contributed to outcomes, would transform the STR system from a one-way reporting obligation into a genuine intelligence partnership. That transformation has not yet become a consistent feature across most AML supervisory systems.
5. The Proportionality Distortion
The AML framework imposes broadly equivalent obligations on obliged entities of vastly different sizes and risk profiles. A sole-practitioner accountant providing bookkeeping services to small businesses in a low-risk jurisdiction faces, in principle, the same AML registration requirements, CDD obligations, and STR filing duties as a Big Four firm managing complex cross-border tax structures for multinational clients. A small community exchange house serving a diaspora corridor with known customers faces, in principle, the same monitoring and reporting obligations as a major international bank with millions of accounts and billions in transaction flows.
The risk-based approach is supposed to address this. Proportionality, calibrating the compliance response to the risk, is a core FATF principle. In practice, the risk-based approach operates within an obligation framework that is not itself proportionate. The registration requirement, the policy documentation requirement, the training requirement, the record-keeping requirement, and the STR obligation apply to all obliged entities regardless of size. The compliance cost of meeting these requirements as a fraction of revenue is orders of magnitude higher for a small business than for a large one. And the guidance available has been developed primarily with large financial institutions in mind, creating an additional translation burden for small and medium-sized obliged entities who must adapt guidance written for banks to their very different operating contexts.
The proportionality distortion has two consequences that work in opposite directions. For the smallest obliged entities, the compliance burden is disproportionate to their risk contribution and their commercial capacity. Many of these entities are genuinely compliance-willing but compliance-incapable: they want to meet their obligations but lack the resources to do so at the standard that large-entity guidance implies. The result is either under-compliance, where the obligations are nominally met but the substance is thin, or exit from the sector, as compliance costs make the business commercially unviable.
For the largest obliged entities, the proportionality distortion operates differently. Large financial institutions have the resources to build compliance programmes that meet every process standard. They also have the political and legal resources to manage enforcement actions when they occur. The compliance investment that a large bank makes in AML buys regulatory defensibility. It does not necessarily buy proportionately better risk detection. The framework rewards scale in the wrong direction: the entities best able to demonstrate compliance are not always the ones doing compliance best.
Where does your programme sit on these five problems?
If any of these structural gaps look familiar inside your own framework, treat that as the signal to act. AML Guild's specialists help obliged entities pressure-test their programmes against exactly these failure points, from CDD and STR quality to proportionate design. Explore the full Grey Zone Series and our advisory work at amlguild.com.
Part Two: What a Better Framework Would Look Like
The structural problems identified in this series are not inevitable features of a serious AML regime. They are specific design choices that could be made differently. The following five reforms are drawn directly from the analysis in the preceding articles. None of them is technically complex. Each of them would require significant institutional will to implement.
Reform One: Outcome-Based Supervisory Standards
The most important single change to the supervisory framework would be to add outcome-based standards to the existing process-based ones. This does not mean abandoning process assessment. It means supplementing it with questions that measure what the process is producing.
What outcome standards would look like. An outcome-based standard for transaction monitoring would specify not just that a monitoring system must exist but that it must demonstrate a minimum alert-to-STR conversion rate, validated annually, with the conversion rate calibrated to the firm's risk profile and client base. An outcome-based standard for STR quality would specify that a defined proportion of filed STRs should contain actionable intelligence, assessed by FIU feedback on a sample basis. An outcome-based standard for CDD quality would specify that periodic review must address specific dimensions (source of wealth currency, beneficial owner identification depth, business relationship plausibility), not merely confirm that a review occurred.
Supervisors have resisted outcome standards partly because outcomes are harder to assess than processes and partly because outcome measurement requires the supervisory infrastructure to support it: FIU feedback systems, benchmarking data, and risk-calibrated benchmarks that vary by firm type and sector. These are real costs. They are lower than the cost of continuing to fund a compliance regime that optimises for process defensibility rather than risk detection.
Almost every framework I help build can satisfy an examiner; very few can tell you whether they actually stopped anything. The day supervision starts measuring outcomes instead of artefacts, compliance teams will design for effect rather than for the audit file, and the profession will finally be judged on what it prevents.
Jyoti Maheshwari | AML/CFT and Compliance Specialist, AML Guild
Reform Two: A Systematic Perimeter Review
Every major jurisdiction should conduct a formal, public review of its AML perimeter against a consistent, risk-based criterion. The review should ask, for each sector and activity type: what is the documented financial crime risk associated with this activity; what is the current coverage of that risk by AML obligations; and is the mismatch between the risk and the coverage justified by proportionality considerations or simply by historical inertia?
The review should produce a published outcome that designates previously undesignated high-risk activities, redesignates or simplifies obligations for genuinely low-risk activities, and provides a clear rationale for the resulting perimeter. This is not a request for the AML framework to grow indefinitely. It is a request for the framework to allocate its burden rationally, to place the greatest obligations on the activities that present the greatest risk, not on the activities that were designated first.
The commodity trading sector, the DeFi access layer, and the large-scale hawala operator are the clearest candidates for perimeter extension based on the analysis in this series. The small-scale, low-risk DNFBP (the sole practitioner providing limited services to a known, local client base) is the clearest candidate for proportionality review that might reduce rather than increase the burden.
Reform Three: Sector-Specific Safe Harbour Standards
For each designated sector, the relevant supervisor should publish outcome-based standards that describe what adequate risk management looks like, and should establish that a firm meeting those standards will not face enforcement action solely on the basis that a relationship it managed within the standards later produced a compliance problem.
This is a significant ask. It requires supervisors to commit in advance to treating good-faith, documented risk management as a defence rather than merely as a mitigating factor. But the alternative, the current position in which no safe harbour exists and defensive compliance is the only rational strategy, is producing the de-risking, financial exclusion, and compliance without effectiveness that the framework was designed to prevent.
Safe harbour standards do not need to be comprehensive or definitive. They need to be specific enough to give a compliance professional confidence that their documented, proportionate, risk-based decision will be respected in a supervisory review. A published set of correspondent banking safe harbour standards, for example, would not need to specify every possible scenario. It would need to specify the factors that must be considered, the documentation that must be produced, and the standard of review that would be applied. That specificity is achievable. The institutional will to provide it is what has been lacking.
Reform Four: A Structured Intelligence Feedback Loop
Every jurisdiction that operates an FIU should implement a structured feedback mechanism that tells reporting entities whether their STR filings contributed to outcomes, in terms specific enough to allow those entities to learn and improve.
The legal constraints on this are real. Tipping off provisions, active investigation confidentiality, and cross-border intelligence sharing agreements all limit what FIUs can disclose about specific reports. But these constraints do not prevent the FIU from providing aggregate feedback, telling a reporting entity that a proportion of its filings from a specific period were acted upon, or that filings from a particular customer segment or transaction type produced the most actionable intelligence. They do not prevent the FIU from publishing sector-specific intelligence summaries, or from operating a voluntary feedback programme for entities willing to participate in collaborative intelligence development.
The compliance professional who receives feedback that their monitoring programme is identifying the right patterns, at the right sensitivity, and producing intelligence that is being used is a compliance professional who can invest confidently in improving that programme. The one who receives no feedback is guessing. The current system overwhelmingly produces the second experience. A feedback loop would transform the second into the first, at a cost that is orders of magnitude lower than the compliance investment it would improve.
Reform Five: Proportionate Compliance Frameworks for Small Obliged Entities
Every major jurisdiction should develop and publish sector-specific, proportionate compliance frameworks for small obliged entities, frameworks that specify what adequate compliance looks like for a sole-practitioner DNFBP, a small exchange house, or a community accountant, rather than requiring these entities to adapt guidance written for large financial institutions.
These frameworks should be genuinely different from the frameworks applicable to large entities. They should acknowledge that a sole practitioner's CDD process looks different from a bank's (it involves personal knowledge of the client, face-to-face interaction, and relationship-based judgment rather than automated screening and database verification), and they should specify what documentation and process standards are adequate in that context. They should acknowledge that a small exchange house's transaction monitoring will be based on relationship manager judgment and paper-based records rather than automated monitoring systems, and they should specify what that judgment-based monitoring must address to meet the standard.
The alternative (a single compliance standard that is calibrated to the most capable, best-resourced obliged entities and applied without adaptation to all) produces the proportionality distortion identified in this series. It drives small obliged entities either to under-compliance (because they cannot meet the standard) or to exit (because they cannot afford to try). Neither outcome serves the framework's objectives.
Part Three: What the Compliance Profession Can Do Now
The five reforms proposed in the previous section require regulatory and political will that no individual compliance professional or obliged entity can supply. They are medium-term objectives for a profession that must operate in the short term within the framework as it exists. The question for the practitioner is not only what the system should become, but what genuine compliance looks like inside the system as it is.
Build for Outcomes, Not Just for Process
The process-outcome inversion is a systemic problem, but it does not require a systemic solution at the firm level. An individual compliance function can assess its own programme against outcome standards even when the supervisory framework does not require it to. The alert-to-STR conversion rate, the quality of filed STRs assessed by internal review, and the accuracy of client risk ratings assessed by periodic testing against independent intelligence sources are outcome metrics that any compliance function can develop and track internally. A compliance programme that is monitored against outcome metrics as well as process metrics will, over time, invest its resources more effectively than one that monitors process alone.
Document the Risk-Based Reasoning, Not Just the Risk-Based Conclusion
The safe harbour deficit means that any risk-based compliance decision is a potential enforcement exposure. The only partial mitigation available to individual firms is documentation quality. The difference between a defensible risk-based decision and an indefensible one is not always the quality of the decision itself; it is often the quality of the record that explains how the decision was reached. A firm that declines a client relationship should document why. A firm that accepts a high-risk relationship should document the specific risk factors considered, the controls applied, and the monitoring in place. A firm that maintains a relationship despite a red flag should document the investigation conducted, the explanation obtained, and the rationale for the conclusion reached.
This is not a counsel of documentation for its own sake. It is a recognition that in the current enforcement environment, the quality of the documented reasoning is often what separates a firm that survives a supervisory review from one that does not, even when the underlying compliance decision was sound in both cases.
Engage With the Intelligence System, Not Just the Reporting Obligation
The intelligence loop failure is a systemic problem, but individual firms can contribute to partial solutions. The STR that is filed with a clear, specific, actionable narrative (identifying the pattern, explaining why it is suspicious, connecting it to known typologies, and specifying what the FIU should look for) is more likely to produce a law enforcement outcome than the one filed to meet a process obligation with a generic description of the transaction. Quality filing, not volume filing, is what the intelligence system needs from reporting entities. Where the FIU offers voluntary intelligence sharing, sector-specific briefings, or collaborative programmes, participating in them is a genuine contribution to the effectiveness of the system that no supervisory requirement can compel.
Advocate for Better Standards
The compliance profession has a legitimate and important voice in the reform conversations that the AML framework needs. The practitioners who work inside the framework every day (who encounter its gaps, inconsistencies, and perverse incentives in their daily work) are the people best positioned to identify what a better framework would look like in practice. The series has attempted to give specific, documented form to some of those insights. The profession should use them.
Industry associations, professional bodies, supervisory consultations, and academic partnerships are all channels through which practitioners can contribute to the improvement of the framework. The risk-based approach that the FATF framework espouses is the right approach. The safe harbour standards that the profession needs are achievable. The outcome-based supervisory standards that would transform the framework from a compliance exercise into a genuine risk reduction programme are within the regulatory art of the possible. They require the profession to say clearly, with evidence, what the current framework is not doing, and what it would take to make it work.
- Does your compliance programme track outcome metrics (alert-to-STR conversion rates, quality assessments of filed STRs, client risk rating accuracy) alongside the process metrics required by your supervisor?
- Is there a periodic internal review that asks whether the programme is producing genuine risk detection, not only regulatory defensibility?
- Does your MLRO receive outcome data as well as process data in their regular management information pack?
- Is your monitoring programme calibrated against outcome data, with rules that produce low-quality alerts subject to tuning or retirement?
- Are risk-based compliance decisions (to accept, maintain, exit, or escalate a client relationship) documented with the reasoning, not just the conclusion?
- Is there a standard for the depth of documentation required at each client risk tier, so that higher-risk decisions receive proportionately more detailed records?
- Are the specific risk factors considered, controls applied, and monitoring arrangements documented for high-risk client relationships?
- Is your MLRO's reasoning documented in escalation outcomes, including the analysis conducted and the basis for the conclusion?
- Does your STR filing process include a quality review that assesses whether each report contains a clear, specific, actionable narrative?
- Are staff filing STRs trained in narrative quality, not just in the identification of suspicious activity?
- Does your compliance function participate in FIU-led intelligence sharing programmes, sector briefings, or voluntary feedback mechanisms where available?
- Is your MLRO actively engaged with the financial intelligence community in your jurisdiction, not only as a reporting entity but as a participant in the broader intelligence ecosystem?
- Is your compliance programme designed for your firm's actual size, sector, and risk profile, or does it reflect a template designed for a much larger institution?
- Are small-entity compliance obligations interpreted with appropriate proportionality, with documentation of why the proportionate approach is adequate given the firm's risk profile?
- Does your firm engage with supervisory consultations and industry submissions on framework reform, contributing the practitioner perspective to public policy development?
- Is there a periodic review of whether the compliance programme is proportionate to the firm's current risk profile, not simply maintained from a previous assessment period?
Frequently Asked Questions
Everything you need to know about the structural problems in the AML framework and how AML Guild supports your business.
The framework measures process rather than outcomes. Supervisors largely assess whether obliged entities follow prescribed procedures, not whether those procedures actually detect or disrupt financial crime. This process-outcome inversion allows a programme to be fully compliant while achieving very little, and it shapes most of the other structural weaknesses described in this series.
Outcome-based supervision judges a compliance programme by the results it produces, such as the quality of suspicious transaction reports, the accuracy of client risk ratings, and genuine risk detection, rather than by the completeness of its documentation. It asks whether the programme actually works, not only whether it can be defended in an inspection.
De-risking happens because exiting a relationship is usually safer for an obliged entity than managing it. When good-faith, documented, risk-based judgment is not protected from hindsight enforcement, the rational choice is to avoid difficult clients and sectors altogether. The result is financial exclusion without a corresponding gain in financial crime prevention.
A safe harbour is a protection that shields an obliged entity from penalty when it has made a reasonable, well-documented, risk-based decision in good faith, even if that decision is later questioned. The absence of clear safe harbours pushes firms toward over-caution and de-risking, because defensibility becomes more valuable than getting the decision right.
Pressure-Test Your Programme Against These Failure Points
AML Guild's specialists help obliged entities build for outcomes, not just process, from CDD and STR quality to proportionate programme design and defensible, risk-based decision documentation. Whether you are reviewing your framework against these structural gaps or rebuilding it, Pathik Shah and the AML Guild network bring the practitioner depth the work requires.