|
At an ACAMS event in Frankfurt jointly sponsored by Pega and Moody's last week, attendees were asked a deceptively simple question: How many of the 22 predicate offence categories have a dedicated detection scenario in your organisation? The results were striking. Fewer than eight: 11%. Between eight and fourteen: 16%. Between fifteen and twenty-one: 11%. All twenty-two: around 5%. And by far the largest group, 58%, answered "don't know." At one level, that's understandable. Financial crime controls have become increasingly specialised. Transaction monitoring, sanctions screening, fraud detection, cyber monitoring, and customer due diligence often operate in separate systems, managed by different teams, using different methodologies. But the poll raises a more important question: How confidently can a financial institution trace a recognised financial crime risk from detection, through investigation, to an appropriate decision about the customer? That question matters because regulators increasingly expect firms not only to operate controls, but to demonstrate that those controls align with their financial crime risk assessment. The expectation is risk-based rather than checklist-driven. Institutions should be able to explain why certain risks are relevant to their customers, products, geographies, and channels, and show how those risks are reflected in monitoring, investigation, and due diligence processes. The challenge is no longer proving that controls exist. It's proving that they are appropriate, proportionate, and effective. The 22 categories, for those who need a refresher The 22 categories mentioned in the question are the ones identified in Directive (EU) 2018/1673, commonly known as the EU's Sixth Anti-Money Laundering Directive (6AMLD), which harmonised the criminal activities considered predicate offences for money laundering across EU member states. The list broadly aligns with the Financial Action Task Force (FATF) designated categories of offences and includes familiar risks such as fraud, corruption, tax crime, drug trafficking, and terrorism financing, alongside categories such as cybercrime and environmental crime that have taken on greater prominence in recent years. The regulatory logic is straightforward: money laundering is ultimately defined by its predicate. If monitoring programmes are heavily focused on a small number of typologies, institutions may be highly effective at detecting some forms of criminal proceeds while having little visibility into others. Many organisations monitor behaviour effectively. Far fewer can confidently explain how that monitoring maps to the financial crime risks they have identified. Why coverage is patchy, and why nobody knows how patchy Three factors make this question difficult to answer. First, most monitoring scenarios were never designed around predicate offences. They were designed around behaviours: structuring, rapid movement of funds, dormant account activation, unusual cash intensity, mule activity, or anomalous transaction patterns. A single scenario may support the detection of several different predicate offences simultaneously, making direct mapping difficult. Second, detection is fragmented across systems. Transaction monitoring sits in one platform, sanctions screening in another, fraud detection somewhere else, and cyber risk signals in another tool entirely. Each capability has its own ownership, coverage assumptions, and optimisation cycle. Third, and perhaps most importantly, the predicate offence is often identified, if at all, at the end of the investigative process. An alert is generated because of a behaviour. An investigator assesses the activity. A conclusion may eventually be reflected in a case outcome or SAR narrative. But that conclusion rarely feeds back into a structured process capable of showing where controls are working well, where coverage overlaps, and where gaps may exist. The result is that many institutions can describe their individual controls but struggle to explain how those controls collectively support their financial crime risk assessment. Closing the loop: where investigation management comes in This is where the discussion becomes less about detection and more about what sits above it. No financial institution will ever achieve perfect scenario coverage. Criminal methodologies evolve. New threats emerge. Detection technologies are specialised by design. The practical challenge is not achieving complete coverage. It's understanding what is being detected, learning from investigative outcomes, and using those insights to improve future controls. That requires an investigation capability capable of bringing signals together. Investigators need visibility of sanctions hits, fraud alerts, cyber indicators, transaction monitoring events, and customer information in the context of a single customer story rather than a collection of disconnected cases. They also need a consistent way of recording investigative outcomes so those outcomes can be analysed over time. This is where Pega Alert and Investigation Management (AIM) becomes relevant. AIM is designed to orchestrate investigations across multiple alert sources, business lines, and jurisdictions through a unified investigation framework, helping financial institutions consolidate customer risk information and manage investigations consistently across financial crime domains. When investigation outcomes are captured consistently, organisations are far better positioned to understand which risks are generating cases, which controls appear effective, and where optimisation efforts should be focused. The answer to the ACAMS question starts to become evidence-based rather than anecdotal. Knowing your client means knowing their predicate exposure There is a second dimension to this challenge, and it begins long before the first alert is generated. Not every customer carries the same predicate offence exposure. A timber importer carries environmental crime risk in a way a domestic payroll bureau does not. A crypto exchange sits closer to cybercrime and fraud proceeds than many traditional businesses. Clients operating in extractive industries in certain jurisdictions may present elevated corruption and tax crime exposure. Cash-intensive businesses can create exposure across several categories simultaneously. A genuinely risk-based approach means customer risk profiles should influence which risks institutions pay closest attention to and, ultimately, which controls are applied. That depends on KYC data that is rich enough to capture industry, geography, ownership structures, products, and behavioural indicators in a structured and usable way. The same principle applies before an alert is ever generated. Effective financial crime controls depend on understanding which risks are relevant to a customer in the first place. Pega Client Lifecycle Management and KYC (CLM-KYC) provides a framework for orchestrating onboarding, due diligence, and ongoing KYC processes across lines of business and jurisdictions, helping institutions maintain a more consistent and actionable view of customer risk throughout the client lifecycle. When customer risk profiles, monitoring controls, and investigation outcomes contribute to a shared view of risk, predicate offence coverage stops being an abstract compliance question. It becomes a practical one: For this customer, given what we know about them, which financial crime risks are we exposed to, and what are we doing to detect them? A question worth asking internally If your honest answer to the ACAMS question is "don't know," you're clearly not alone. The path to an answer is unlikely to involve building twenty-two new monitoring scenarios. Instead, it starts with connecting customer risk assessments, detection controls, investigative outcomes, and continuous improvement into a single risk-management feedback loop. Once that loop exists, coverage becomes visible. And once coverage becomes visible, the 58% becomes a number organisations can do something about. Recommended resources:
Don't Forget
|
From Capability to Confidence: The 58% Question: Can Financial Institutions Turn Financial Crime Risk into Action?
About the Author
Daniel Lobo is a Senior Customer Risk and Due Diligence Solutions Consultant at Pega, specializing in Pega CLM-KYC and Pega AIM.