‘Almost compliant’ still means non-compliant

Written by Justin Joannides
Posted on August 18, 2026

Table Of Contents

From CompliNEWS | Financial Services Intelligence Watch

‘Almost compliant’ still means non-compliant

Masthead reports that many accountable institutions mistakenly equate having an RMCP, approved policies and completed training records with full FICA compliance. In practice, regulators are increasingly focused on whether those controls are applied consistently, kept current and supported by evidence. Generic RMCPs, inconsistent customer due diligence, weak beneficial ownership verification, poorly documented risk ratings and unclear escalation processes can all leave an institution exposed, even where the formal paperwork appears complete.

The practical lesson is that FICA compliance must be operational, not merely documented. Institutions should regularly test whether their RMCP reflects the actual business, whether enhanced due diligence is applied to higher-risk clients, whether decisions are properly recorded and whether staff receive meaningful, ongoing training. Responsibility cannot rest with the compliance function alone: operational teams and senior management must be able to demonstrate that AML, CFT and proliferation-financing controls are embedded in everyday business activities.

Read the Full Masthead report here

Categories:

Recent Comments

Comments are closed