Breadcrumb

  • Home
  • Don't think outside the box: deny there's a box (TM)

Search form

Main navigation

  • Home

Don't think outside the box: deny there's a box (TM)

Friday, 18 April, 2025 - 00:05

If you want a cosy read about financial crime, there are dozens of people who will produce documents, papers and even podcasts peppered with empty or vague words and phrases which basically rephrase and repeat the official line.

But you know me better than that, says Nigel Morris-Cotterill

Others do a deep dive; I live in the deep. 

If I'm not challenging you to think, not badgering you to reject the standardised approaches that create the straight jacket so many willingly don, to question orthodoxies that do exactly the opposite of what they say they do, then I'm failing in my mission to help companies and even governments and regulators to combat financial crime and to do it cheaply and effectively.

Whatever happened to "business as usual"?

I'm one of, literally, a dying breed. We were those who understood that the prime objective of counter-money laundering laws and regulations was to detect and deter and to report suspicions of financial crime. 

I was the first, I think, to specifically look at financial crime risk as a management issue: I was far from the first to look at financial crime as a problem that needed to be solved. But those that had were in law enforcement, many very skilled, but from a very different discipline. I also saw it as a compliance issue before regulators started to become interested in anything more than an in-passing way. Indeed, in the UK, the regulators had a guide and they sent out junior inspectors with - literally - a checklist: does the company do this? Yes or No. 

One company I advised had a follow-up when the answer was "no". It was "no" because what the regulator wanted was, in my opinion, not stringent enough so my client had a higher standard. But the form had no space for "yes/ no/ oh, shit, why didn't we think of that?".

And the reason was that they were regulators, they were not practitioners: we were doing the work; they were fumbling in the dark. We, individually and collectively, had skills, knowledge and experience; they didn't. We designed compliance for each business; they did the opposite - a standardised regime that failed, and continues to fail, everyone. 

When many MLROs came from the law enforcement background, one phrase was repeated over and over: the compliance we created must have one over-riding internal objective. It must not interfere with business as usual.

Business as usual

Critics have taken that expression as meaning that financial institutions would pay lip service to financial crime control measures and just carry on regardless. 

Nothing could be further from the truth: that criticism was disingenuous in the extreme. 

What it meant was to design policies that achieved the prime objective whilst filtering out business that institutions would not want if they knew they had it: shining light in dark corners and removing wilful blindness that might get companies, and responsible officers, into trouble. "Business as usual" related to processes, not to policies or the lack thereof. 

Today, there seems to be remarkably little recognition that the purpose of being in business is to do business. That needs to change. Financial institutions do not exist to meet regulatory requirements nor to support regulators by paying huge financial penalties.

Today, responsible officers go to work not with the objective of protecting their employer from the activities of criminals, but with the objective of avoiding regulatory scrutiny and penalties and, on a personal level, being booted out of their industry or profession. 

Regulation by fear has eroded the prime objective.

One of the results of this is that training, originally intended by those designing law and regulations in the 1980s and 1990s to be about identifying the risk of money laundering and what to do next, coupled with a specific, expressed, requirement that training included "awareness", has become focussed on process and on regulatory compliance. Internal compliance, which is mostly about risk and in which awareness plays a major, some might say THE major, part, went first to the back burner and then off the stove all together. 

Global companies dominate training in which knowledge of the regulations is paramount: knowledge of risk is not even in the box in which most staff now find themselves constrained with no concept of what is outside the box. And no incentive to find out. Indeed, there is every incentive to presume that the box, built as it is by those who want compliance at all costs (but who say that even if you comply and there is actual laundering, it's your fault) and demonstrate hour by hour that resistance is futile. 

SAS is 'created' 50 million times a year, 15 seconds at a time. These 50 million 'moments of truth' are the moments that ultimately determine whether SAS will succeed or fail as a company. They are the moments when we must prove to our customers that SAS is their best alternative. — @Jan Carlzon, SAS 

Risks arise and mutate moment by moment. Whether it's a commercial or a financial crime matter, businesses face challenges all the time. Carlzon's statement is precisely why rigid compliance regimes don't work. Rigid processes do, rigid thinking does not. Regulators who say "this is how it must be done" do not allow for changing circumstances, they design rigid thinking into systems that can only function effectively where there is flexibility of thought. 

That might sound like a contradiction but it isn't. 

When a risk or an opportunity which rigid processes would often miss is identified there should be established processes - often called standard operating procedures or, to be really pretentious, "protocols" - to deal with them. So, systems should look for risk (or opportunity) first and comply with processes second. 

To reverse that, to put the cart before the horse, will inevitably result in a failure in the prime objective. And yet, that is exactly where we are.

The biggest concern of all is that this approach creates, not reduces, risk to regulated businesses and the officers they engage.

The first line of defence; it's not what you think it is.

If, as it should be, the first line of defence is viewed as the formation of suspicion not, as it is commonly expressed to be, persons with particular job functions, then awareness is the central pillar upon which all financial crime risk management is built. And so the systems were designed.

This is what systems were expressed to be:

 

  1. Train staff to recognise circumstances that might indicate that a person was a money launderer
  2. Create a position in the company and appoint a person to whom staff must report their suspicions, look at them in the light of all the information available in (at that time it was "in" not "to") the company.
  3. Design, implement and maintain a system for 2 and 4.
  4. Keep records of everyone who does business with, or applies to do business with, the company including KYC information which includes verified identity and financial information and maintain records of transactions for at least x years
  5. If suspicion arises after review, make a suspicious activity report to the appropriate authority, the FIU.

The regulatory regime under this system was and should be simple. Complexity would be left for the business which should design its policies and procedures to suit the nature, size, location and other factors of the business. 

In short, regulators should not be involved in the qualitative assessment of systems - there was already a solution to systems that were not good enough: prosecution for involvement in laundering.

But that's not what happened. Instead, regulators in cahoots with giant law and consulting companies did exactly the opposite and generated massively complex, and expensive, regimes. Compliance with those became more important than identifying potential crime. 

It is an approach which, aside from falling foul of the "business as usual" concept, actively reduces the chances that crime will be identified.

There is one more factor: as regulatory regimes become more complex and more remote from the actual business of doing business, and as awareness disappears, the risk of a financial institution becoming involved in financial crime increases. 

If we start from my preferred starting point, that the criminal law reflects society's common morality, then that is the reason people form suspicion. Indeed, it is the central thesis of my book "Understanding Suspicion in Financial Crime." If we don't think there is anything wrong, we won't see suspicion, even if there is something wrong. Similarly, if we see something that we think is wrong, we will be suspicious, even if there is nothing wrong.

Nigel Morris-Cotterill is at www.countermoneylaundering.com and on LinkedIn.

As I have written the second volume of Trade Based Financial Crime, a three volume explanation of why the term "Trade Based Money Laundering" is not appropriate and which demonstrates that it is but a small subset of, and derived from, a much broader range of criminal conduct, common themes have been:

 

  1. much conduct that would, under the common morality principle, be regarded as criminal has been decriminalised and converted to civil offences enforced through the regulatory regime.
  2. much conduct which is specifically criminal might be regarded as a moral imperative under the common morality principle and therefore not suspicious.

 

In this, I include offences created for purely political reasons which, almost by definition, a significant proportion of any given population will regard as removing their fundamental rights be it of protest or to support, financially or otherwise, some oppressed or even distressed persons. 

So where a company has been formed for a political purpose which is contradictory to a stated political position where that political position might be to protect domestic business or to pressure a foreign government or to prevent humanitarian aid to those suffering in a battle zone or even to where there has been a natural disaster the law is placed in conflict with our natural view of what is criminal. 

And where that takes place using mechanisms of trade, such term not being narrowly defined, companies, directors and managers can find themselves not only in regulatory hot water but subject to the criminal law.

What we have is a mismatch between the macro view of legislatures and regulators on the one hand and the micro view of real people in real jobs with real consciences and views on the other. Currently, we make it black and white: fall foul of what a government says (always being aware that this might change) and suffer awful consequences or do what we believe to be right. 

Where "national interest" is given as the reason, as I explain in detail in Vol 2 of Trade Based Financial Crime, we are put in the position of suffering consequences if we wish to do the right thing. 

On a macro level, using sanctions etc. as an example, we must ask the difficult question: are at least some sanctions and embargoes really for the political benefit of certain politicians and their parties, and not a matter of national interest at all?


 


Trade Based Financial Crime: https://vortexcentrum.com/elan/vclproductpage-2

Understanding Suspicion in Financial Crime: https://amzn.to/3A7M0PN


Don't think outside the box: deny there's a box is a slogan of Nigel Morris-Cotterill since the 1990s. Don't nick it. 

 

 

About this section

Opinion pieces or "Op-Eds" are the home-made bombs of the publishing world. So long as they meet editorial standards, are not intentionally offensive with a view to causing hurt or insult and are relevant to our field of endeavour, we will look at submissions.

We like contentious, we like contrarian views. We don't like pretty much any -ism . We recognise that Opinion pieces are one person's view and are not balanced (if they are balanced and reach a reasoned conclusion, they are probably more suited to the Articles section). We do not like acronyms and buzzwords.

Op-Eds are the author's personal views and do not necessarily represent the views of World Money Laundering Report or its publishers.

To submit an Opinion piece, please complete the Contact form.

Footer menu

  • Weekly Digest (opens in new tab)
  • Images attribution (opens in new tab)
  • Corporate, privacy, intellectual property and access (opens in new tab)
  • Advertising and Recommendations (opens in new tab)
  • Promote your business (opens in new tab)
  • Enquiries (opens in new tab)


 

BOT AND SCRAPER ACCESS DENIED

 


 

Built with Drupal     |     Hosted by Siteground     |     Template by Alaa Haddad     

Design by Vortex Centrum Limited    |     Some services provided by Google Workspace    

Posters and other merch by ProjectLXX   |   Privacy and security services by Surfshark and Firetrust. 


Nothing in this website is intended to be or shall be taken as legal advice. 

You should always seek advice from a practitioner experienced in this area. 


Everything on this website is copyright Nigel Morris-Cotterill and/or Vortex Centrum Limited for itself or one of its business units. No downloading, printing or other means of replicating or reusing is permitted. In particular, all bot access is denied and all scraping of content will result in the legal action set forth in the terms and conditions in this site. For legal, cookies and privacy see vortexcentrum.com.

Copyright 1999- © 2026 Vortex Centrum Limited - All rights reserved. Bot access denied.