A policy, training course or public commitment does not prove that a compliance programme works. Nor does one violation prove that the entire programme was cosmetic. Investigators should test design, resources, independence, operation and results against the company’s actual risks.
Map the programme to real risks
Collect risk assessments, policies, control maps and implementation dates. Compare them with the company’s products, countries, customers, agents and payment channels. Generic rules copied across unrelated businesses may indicate weak design, but the decisive question is whether controls address foreseeable misconduct.
Test authority and resources
Identify who leads compliance, reports to whom and can stop transactions or escalate concerns. Review staffing, qualifications, budget, data access and board contact. The US Department of Justice’s Evaluation of Corporate Compliance Programs asks whether a programme is well designed, adequately resourced and empowered, and effective in practice.
Follow an alert from start to finish
Select representative alerts, complaints or due-diligence cases and reconstruct intake, review, escalation, decision and remediation. Compare written procedures with audit logs and case files. A high closure rate may reflect efficient screening or premature dismissal; sample evidence is needed.
Examine incentives and consequences
Review targets, bonuses, promotions, discipline and clawbacks. Determine whether commercial staff are rewarded for conduct that compliance is meant to prevent. DOJ guidance on compensation incentives and clawbacks highlights both rewards for compliant behaviour and financial consequences for violations.
Test independence under pressure
Look for overridden decisions, delayed suspicious-activity reviews, withheld documents, retaliation or management exceptions. Interview former as well as current personnel and corroborate accounts. A compliance officer’s title is less important than evidence that the function could challenge revenue-generating decisions.
Measure outcomes and adaptation
Track repeat breaches, investigation time, substantiated complaints, control failures, remediation and independent testing. Check whether lessons from incidents changed risk assessments, technology or training. Completion statistics alone do not show that behaviour improved.
Check third parties and acquisitions
Examine onboarding and monitoring of agents, affiliates, distributors, payment providers and acquired companies. Trace who approved exceptions and whether contracts allowed audit or termination. Our high-risk compliance investigation provides a broader framework for testing these gaps.
Malta Media’s assessment of whether Curaçao’s AML framework has substance in practice illustrates the difference between formal requirements and empowered, supervised implementation. Its claims should be checked against legislation, regulator action and responses from affected organisations.
Report proportionately
Build a table covering stated control, responsible owner, resources, sampled operation, failures, remediation and outcome. Distinguish an immature programme, isolated non-compliance, management override and a deliberately deceptive “paper programme.” Give the company an opportunity to produce evidence that contradicts the preliminary assessment.