Measuring What Matters During the Regulatory Reset

This is Part 4 of SEDA Experts’ 5-part series: From Remediation to Resilience: you can find Part 1 here, Part 2 here and Part 3 here.
"What matters during the Regulatory Reset is not how efficiently an institution performs yesterday's controls, but how effectively it adapts those controls for tomorrow's risks."
Introduction

Financial institutions have never had a shortage of Anti-Money Laundering (AML) metrics.
Executive management and Boards routinely receive reports containing dozens of operational statistics describing alert volumes, investigation timeliness, Suspicious Activity Reports (SARs), Currency Transaction Reports (CTRs), customer risk ratings, quality assurance results, staffing levels, and training completion. These reports provide valuable operational insights and demonstrate that important compliance activities are taking place.
Unfortunately, they often answer the wrong questions.
The Regulatory Reset has fundamentally changed what regulators expect institutions to measure. Updated National Risk Assessments, evolving financial crime typologies, sanctions developments, digital assets, artificial intelligence, and increasingly sophisticated criminal organizations have shifted supervisory attention beyond operational performance toward organizational adaptability. Regulators continue to expect institutions to demonstrate that required AML activities are being performed, but they now place greater emphasis on whether those activities remain effective as risks evolve.
Activity alone no longer demonstrates effectiveness.
An institution may investigate every alert within established service levels while consistently failing to identify emerging criminal methodologies. Another may reduce investigation backlogs while unknowingly increasing investigator error rates. A third may report declining SAR volumes because outdated monitoring scenarios are generating fewer meaningful alerts. In each case, management can point to impressive operational statistics while overlooking deteriorating control effectiveness.
This represents one of the defining challenges of the Regulatory Reset.
The objective is no longer to measure how efficiently the AML program operates. The objective is to determine whether the institution is becoming more resilient, more adaptive, and better prepared to identify tomorrow's financial crime risks.
Articles One through Four in our series introduced the AML Controls Effectiveness Assessment (CEA), Root Cause Analytics, and governance practices that transform operational findings into executive intelligence. This article completes that framework by introducing a measurement model that enables management and Boards to determine whether remediation efforts are producing sustainable improvements in control effectiveness and organizational resilience.
Ultimately, the question is no longer: Are we doing the work?
The question has become: Are our controls becoming more effective as financial crime risks continue to evolve?
What Matters During the Regulatory Reset
Governance Effectiveness - whether governance identifies emerging risks before regulators do.
Control Effectiveness - whether controls continue to detect today's financial crime typologies.
Organizational Adaptability - the institution's ability to adjust controls as risks evolve.
Risk Intelligence - understanding changing inherent and residual risks.
Root Cause Reduction - eliminating systemic weaknesses rather than recurring deficiencies.
Quality of Decision-Making - improving risk decisions, not merely operational efficiency.
Sustainable Remediation - strengthening the control environment beyond closing findings.
Predictive Capability - identifying deteriorating controls before they become examination issues.
Organizational Resilience - maintaining effective controls amid changing threats.
Board Readiness - equipping directors with governance intelligence rather than operational statistics.
Closing Perspective
During the Regulatory Reset, institutions will no longer be distinguished by the volume of data they collect or the number of reports they produce. They will be distinguished by their ability to recognize change before it becomes regulatory criticism. Measurement is no longer simply a management function. It is a governance discipline. Institutions that measure control effectiveness, organizational adaptability, and emerging risk will be positioned to anticipate supervisory expectations rather than react to them. Measuring what matters ultimately means measuring an institution's capacity to adapt.
The opinions, views, and statements expressed in this article are solely those of the individual authors and do not represent, reflect, or constitute the views or opinions of SEDA Experts.
EXPERT INVOLVED
Kenneth Simmons - Managing Director
Kenneth Simmons is one of the nation's leading experts in Bank Secrecy Act (BSA), Anti-Money Laundering (AML), and OFAC sanctions compliance. As a former Functional Examiner-in-Charge (EIC) for both the FDIC and OCC, he has extensive experience evaluating institutions ranging from community banks to some of the country's largest financial organizations.
In addition to serving in executive compliance leadership roles within the banking industry, Ken is a Faculty Member and Review Board Member for ACAMS, where he helps educate compliance professionals worldwide. He advises financial institutions on regulatory compliance, independent audits, risk management, and building effective BSA/AML programs.
Contact Us
+1 646-626-4555





Comments