Industries
Retail / CPG
Financial Services
Industrial
Enterprise IT
Media
Platform
Eureka AI Platform
Make your data AI ready
Build AI Agent
Responsible AI
Resources
All Resources
Blog
Case study
Glossary
Video
White paper
Analyst report
Byline
Data sheet
Podcast
Webinar
Company
About us
Vertical AI
Newsroom
Events
Customer
Recognition
Partners
Leadership
Careers
Contact us
Get a demo
AML/FinCrime effectiveness maturity assessment tool
Let’s get started
Contact details
Share your contact details, please
Key contact name
Institution name
Email
Domain weights
How would you weight each domain?
Slider values total must equal 100%
Process and Policy
Risk and Controls
Transaction Monitoring
Suspicious Activity Reports (SARs)
Know Your Customer/Due Diligence
People-training
Data
Technology
Metrics-reporting
Process and Policy
How would you describe your change management process?
Risk-based/Outcomes
Fragmented, with no documentation and highly manual process
Very little documentation; significant amount of inconsistency; mostly manual
Partly documented; some consistency; mostly completed online with some manual steps
Consistent, repeatable, and explainable; fully documented; facilitated with an online management system
To what extent does your overarching AML/FinCrime policy address FinCEN’s Priorities?
Priorities/Useful
Priorities are not addressed in our current policy
We are holding meetings to consider how to address the Priorities in our policy.stly manual
We have updated some components of our policy, but gaps remain
We have updated all components of our policy (e.g. Risk Assessment, KYC, Transaction Monitoring, etc).
To what extent does your overarching AML/FinCrime policy focus on risk mitigation and providing highly useful information to law enforcement?
Risk-based/Useful
Very few risk-based controls; highly subjective risk assessment process; risks are not quickly addressed; no metrics or discussion around usefulness of info
Some risk-based controls; subjective and quantative risk assessment process; some internal discussion around usefulness of info but no metrics used
Many risk-based controls; subjective and quantitative risk assessment process; some internal discussion around usefulness of info, some metrics used, no outreach to regulators
Large inventory of risk-based controls that are often recalibrated; highly quantitative risk assessment process; use series of metrics to measure/assess usefulness of info, regularly hold internal meetings to discuss, and regular outreach to regulators
To what extent is your AML/FinCrime policy updated based on changes in your risk assessment?
Risk-based/Outcomes
Infrequent updates only when required by regulator
Some updates but usually takes an extended period of time to complete
Updated with changes in risk assessment but can take an extended period of time to complete
Updated with changes in the risk assessment in a short timeframe
Risk and Controls
To what extent have you investigated threats related to FinCEN’s National Priorities and how they may appear within your offered products/services?process?
Priorities/Useful
We have not reviewed the Priorities and have not investigated our exposure to those threats.
We have reviewed the Priorities but have not investigated our exposure to threats.
We have reviewed the Priorities and have investigated our exposure to some of those threats.
We have reviewed the Priorities and have investigated our exposure to all of those threats.
To what extent does your risk assessment address FinCEN’s National Priorities?
Priorities/Useful
Our risk assessment does not take into account our exposure to those threats.
Our risk assessment includes factors related to SOME of the Priorities but only for certain business units.
Our risk assessment includes factors related to ALL of the Priorities but only for certain business units.
Our risk assessment includes factors related to ALL of the Priorities across the entire enterprise.
How would you describe your process to adjust your control inventory based on the results of a revised risk assessment?
Risk-based
We do not have a documented process in place and adjustments are very rare.
We have a documented process in place but adjustments are infrequent.
We have a documented process in place but adjustments are not made for every revision in the risk assessment.
We have a documented process in place and controls are adjusted in tandem with all revisions to the risk assessment.
To what extent have you adjusted your control inventory to address FinCEN’s National Priorities?
Priorities/Outcomes
We have not reviewed the Priorities and have not changed our control inventory.
We have reviewed the Priorities but have not changed our control inventory.
We have reviewed the Priorities and have made some changes to our control inventory.
We have reviewed the Priorities and have systematically evaluated our control inventory and have made all necessary changes.
How would you describe your process to maintain your control inventory’s focus on higher risk areas?
Risk-based/Outcomes
We rarely make changes to our control inventory and have not systematically evaluated them relative to risks.
We sometimes make changes to our control inventory but have not systematically evaluated them relative to risks.
We sometimes make changes to our control inventory based on some level of systematic evaluation relative to risks.
We regularly make changes to our control inventory and regularly conduct systematic evaluations relative to risks.
Transaction Monitoring
To what extent have you recalibrated your TM detection scenario/models to address FinCEN’s National Priorities?
Useful/Priorities
Our detection scenarios are legacy and have not been revised to address FinCEN’s National Priorities yet.
We are aware of FinCEN’s National Priorities and are considering how to address them but haven’t made any changes yet.
We have begun to make some changes to our detection scenarios to address FinCEN’s National Priorities.
We have reviewed our entire detection scenario inventory and have made revisions where appropriate to address FinCEN’s National Priorities.
How often do you recalibrate your TM detection scenarios/models as a result of changes in your risk assessment?
Risk-based/Outcomes
We sometimes make ad hoc changes to our detection scenarios every few years.s yet.
Our detection scenarios only change when a matter has been raised by audit or a regulator.
We make changes to our detection scenarios only when new risks are identified within the risk assessment.
Our detection scenarios are regularly reviewed and tuned, not only to achieve better results but also in response to changes and new risks identified in the risk assessment.
To what extent have your case and SAR conversion rates increased in response to changes in detection scenarios in response to FinCEN’s National Priorities and your risk assessment?
Outcomes
Our case and SAR conversion rates have not improved in some time and remain low.
Our case and SAR conversion rates have improved slightly, but still remain lower than we’d like.
Our case and SAR conversion rates have improved, but we need to do more to better model and detect latent/emerging/shifting risks.
Our case and SAR conversion rates have improved and are higher than industry standards.
Suspicious Activity Reports (SARs)
To what extent are trends from SARs used to inform changes in your AML/FinCrimes program?
Risk-based/Outcomes
We do not extract trends from SARs, so can’t make changes based on trends.
We are in the process of designing a policy and procedure around this but haven’t really done it in the past.
We have started using SAR data to make some changes, but our process needs improvement.
We have a fully documented policy and procedure to regularly evaluate SAR data and make program changes where appropriate.
How often do your SARs involve threats included in FinCEN’s National Priorities?
Useful/Priorities
0-20% of SARs filed
21-40% of SARs filed
41-60% of SARs filed
>60% of SARs filed
How often does law enforcement express interest in SARs that have been filed?
Useful/Priorities
0-10% of SARs filed
11-20% of SARs filed
21-30% of SARs filed
>30% of SARs filed
To what extent is feedback on SARs used to enhance future SARs?
Useful/Priorities
We do not have any process for this.
We are in the process of designing a policy and procedure around this but haven’t really done it in the past.
We have started using a process for this, but it needs improvement.
We have a fully documented policy and procedure to regularly review feedback and leverage that for future SARs.
Know Your Customer/Due Diligence
To what extent is the information collected as part of developing a risk profile during KYC/onboarding used to help mitigate risks associated with FinCEN’s National Priorities?
Useful/Priorities
We only collect required data to comply with current KYC regulations and do not explicitly take into account FinCEN’s National Priorities.
We have begun considering a policy for information collection to align with FinCEN’s National Priorities and enhance customer risk profiles.
We have begun developing a policy for information collection to align with FinCEN’s National Priorities and enhance customer risk profiles.
We have developed and implemented a policy for information collection to align with FinCEN’s National Priorities and enhance customer risk profiles.
To what extent do your KYC policies & procedures change as a result of changes in your risk assessment?
Risk-based/Outcomes
We very rarely make changes as a result of changes in our risk assessment.
We sometimes make changes but we do not have a documented change process for this.
We make changes where required but we do not have a documented change process for this.
We have a documented change process in place to make changes whenever required based on changes in our risk assessment.
To what extent have you adjusted your customer risk rating to take into account FinCEN’s National Priorities?
Useful/Priorities
We have not made any changes to our customer risk rating and currently are not planning to.
We are considering how to re-calibrate our customer risk rating to design and policy to align with FinCEN’s National Priorities.
We have begun to revise our customer risk rating design and policy to align with FinCEN’s National Priorities but have not yet implemented it.
We have documented and implemented a new design and policy for our customer risk rating to align with FinCEN’s National Priorities.
To what extent do your KYC policies & procedures (e.g. onboarding, risk rating, periodic review, offboarding, etc) differ based on risk level?
Risk-based/Outcomes
We use the same KYC policy/procedures across our institution and for all clients regardless of risk level.
We are in the process of revising our KYC policy/procedures to be based on risk level.
Certain parts of our KYC policy/procedures are tied to risk level.
All of our KYC policy/procedures are risk-based across all business lines.
People-training
To what degree is staff trained and re-trained on FinCEN’s National Priorities and associated risks?
Priorities/Outcomes
We do not have training on this.
This is a short component of our annual general AML training.
We are developing a dedicated training module that will be required annually.
We’ve implemented a dedicated training module that will be required yearly and whenever Priorities change.
How often do you revise training based on risk?
Risk-based/Outcomes
We only make changes to our training based on legislation or regulation changes.
We make some changes based on risk but only on an ad hoc basis.
We make some changes based on risk but only on and ad hoc basis, but we are designing a process to make risk-based updates systematically in the future.
Most of our training that is not purely focused on applicable legislation and regulation is risk-based and risk-driven and we make regular updates to it based on changes in our risk profile.
To what degree are your training resources directed to higher risk customers and activities?
Risk-based/Outcomes
All of our training is the same and focuses on applicable legislation and regulation.
We do have some risk-focused training but not customer type risk specifically.
We have risk-focused training, in general, and are in the process of designing training focused on risks associated with different customer types.
We have training modules focused on specific risk categories, including customer types.
To what extent do you deliver AML training to staff in the 1LOD?
Risk-based/Outcomes
The 1LOD receives the annual training required for all staff.
The 1LOD receives the annual training required for all staff and we are considering options to design additional training for those staff.
The 1LOD receives the annual training required for all staff and we are in the process of developing additional tailored, risk-based modules for those staff.
The 1LOD receives the annual training required for all staff and regularly also receives tailored, risk-based modules specific to applicable risk categories.
Data
To what degree have you investigated external sources of data that could help inform your program and controls?
Risk-based/Outcomes
We have not investigated this.
We currently are looking into external data sources but have not begun to use any yet.
We have chosen several external data providers but have not yet implemented their data into our current operations.
We have implemented several external data sources into our current operations.
To what degree is the data underlying your primary contols (TM, screening) reliable?
Risk-based/Outcomes
Our data is fractured and in many different formats.
Our data is fractured and in many different formats but we have started a project to improve quality.
We have begun to normalize our data but it remains fractured across the institution.
We have normalized and centralized our data and believe it to be highly reliable.
Technology
To what degree have you considered technology/analytics (e.g. machine learning, network analytics, simulation, etc.) that can help you better understand and detect your overall risk profile and threats?
Risk-based/Outcomes
We have not considered this type of technology.
We have begun to explore this type of technology.
We have explored this type of technology and have chosen a solution/s but we have not yet implemented it.
We have chosen a solution/s and it is operational.
To what degree have you considered technology/analytics that can help you better detect typologies related to FinCEN’s National Priorities?
Risk-based/Priorities
We have not considered this type of technology.
We have begun to explore this type of technology.
We have explored this type of technology and have chosen a solution/s but we have not yet implemented it.
We have chosen a solution/s and it is operational.
To what degree have you considered technology that can help you better estimate/evaluate risk associated with your customers?
Risk-based/Outcomes
We have not considered this type of technology.
We have begun to explore this type of technology.
We have explored this type of technology and have chosen a solution/s but we have not yet implemented it.
We have chosen a solution/s and it is operational.
Metrics-reporting
To what extent do you measure and report metrics related to FinCEN’s National Priorities?
Useful/Priorities
We do not have any metrics or reports on this.
We are in the process of adding some of these metrics into our regular management reporting.
We have certain metrics but need to improve their value and include them in regular management reporting.
We have several metrics at different levels of the institution and include them in regular management reporting.
To what extent do you measure and report metrics or examples of value of/feedback on reporting to law enforcement?
Useful/Outcomes
We do not systematically track this, except to review as it’s received.
We do not currently track this but are in the process of designing a tracking system and reporting.
We do track this but do not regularly assess and report it.
We have a process in place for tracking this information and including it in regular management reporting.