Services About Our Process Areas Expertise Blog Training AML Threat Intelligence Tool Let us help

Effective Management of AML/CFT/CPF Risks

Analytics charts and data on a laptop screen — assessing and monitoring AML/CFT/CPF risk in practice
Photo by Carlos Muza on Unsplash

When assessors from the Financial Action Task Force (FATF) arrive in Barbados, one of the first questions they are likely to ask businesses will sound deceptively simple: Do you understand your risks? In reality, it is one of the hardest questions to answer convincingly—and one that has exposed weaknesses in the AML/CFT/CPF control environments of businesses in countries examined.

Recent evaluations of Malaysia, Belgium and Kuwait show that many businesses may have believed they understood their risks—until shortcomings were discovered.

When Risk Assessments Fall Short

In several jurisdictions, businesses presented detailed risk assessment documents. They were well-written, professionally formatted, and aligned with regulatory expectations. But there was a problem. When assessors dug deeper, they found that many of these assessments were generic, disconnected from actual business activity, and rarely updated. In some cases, staff could not explain the risks described in their own documents. That gap—between paper and practice—can prove costly.

Key gaps and ineffective implementation issues discovered, along with recommended corrective actions are:

Understanding AML/CFT/CPF Risks

Risk assessments are generic, copied templates, or not aligned to actual business activities. Staff cannot explain risks.

Risk assessments should be tailored to the business model, products, and customers. Staff should be trained to understand and clearly explain key risks and how they are managed

Alignment with the National Risk Assessment (NRA)

Businesses are unaware of national risks or do not reflect them in internal controls.

Businesses should explicitly link their risk assessments to national findings and show how controls address those risks.

Customer Risk Profiling

Customers are incorrectly classified (e.g., high-risk treated as low-risk). Risk ratings have little impact on controls.

Customers should be risk-rated using clear criteria (geography, activity, behaviour etc.). Risk ratings should directly determine due diligence and monitoring levels.

Enhanced Due Diligence (EDD)

EDD is inconsistently applied or treated as a formality. There is frequently weak verification of source of wealth/funds.

EDD should be triggered appropriately for high-risk customers and Source of Wealth and Funds verified using reliable evidence.

Beneficial Ownership

Businesses rely on customer declarations and have difficulty identifying ultimate beneficial owners, especially in complex structures.

Businesses must identify and verify the natural persons who ultimately own/control customers, including through layered structures.

Ongoing Monitoring

CDD is done only at onboarding. Customer information is rarely updated.

Customer relationships should be monitored continuously, and profiles updated when activity or risk changes.

Transaction Monitoring

Over-reliance on automated alerts. Systems focus on thresholds rather than unusual behaviour.

Effective monitoring should combine systems and human analysis. More focus should be placed on identifying behaviour inconsistent with customer profiles.

Suspicious Transaction Reporting (STRs)

Low reporting of STRs. Reports lack detail or are filed defensively. Delays in submission.

STRs should be timely, well-analysed, and clearly explain suspicion. Reporting should reflect real detection of unusual activity.

Staff Awareness

Front-line staff do not recognise suspicious activity or understand risk indicators.

Staff should be trained using practical scenarios and local typologies to identify and escalate suspicious behaviour confidently

Designated Non-Financial Businesses and Professions (DNFBP) Compliance

Lawyers, accountants, and real estate agents show low awareness and minimal reporting.

Regulators need to do more to ensure DNFBPs understand obligations, assess risk, and actively participate in AML/CFT controls and reporting.

Use of Financial Intelligence

STRs are not effectively used by authorities or linked to investigations. Regulators need to do more to ensure financial intelligence is actively analysed and leads to investigations, prosecutions, and asset recovery.

Regulatory Supervision

Inspections are checklist-based. Limited focus on high-risk institutions. Weak enforcement.

Supervisors should apply a risk-based approach, focusing on high-risk sectors and testing real-world effectiveness.

Public–Private Cooperation

Limited feedback from regulators. Weak communication with industry.

Strong engagement between regulators and businesses is recommended. Regular feedback improves reporting quality and risk awareness.

What this means for Barbados

For businesses in Barbados, the implications are clear. It will not be enough to produce a risk assessment document. Businesses must be able to demonstrate that they:

  • understand risks specific to their sector
  • align their assessments with National Risk Assessment (NRA) findings
  • identify high-risk customers and transactions
  • update their assessments regularly
  • apply effective controls to mitigate risk.

More importantly, they must be able to explain and show evidence of these actions in practice.

Louis Parris is an Anti-money laundering Audit, Risk & Training Consultant.

Written by
Louis Parris
Compliance Consultant — AML/CFT/CPF Audits, Enterprise Risk Assessments, Internal Audits & Compliance Training
View profile, more articles & contact →