Join our Newsletter — 33% off our NHI Course

What are the signs that a FICA compliance programme is not working as intended?

Warning signs include weak identity verification, inconsistent risk scoring, poor sanctions screening, missing transaction records, and gaps in reporting suspicious activity. If staff cannot explain procedures, customer due diligence is incomplete, or records are not retrievable for regulators, the programme is failing in practice. Those gaps usually point to control design problems, not just isolated mistakes.

What the breakdown tells you about a failing FICA programme

When a FICA programme stops working, the problem is usually not a single missed check. The control chain is breaking at several points, from onboarding and verification through screening, recordkeeping, escalation and retention. A healthy programme should produce consistent decisions, auditable evidence, and explainable outcomes, not ad hoc judgment that varies by staff member or branch.

One practical way to read the warning signs is to separate control failure from control noise. If the same weaknesses keep appearing across customer files, the issue is structural. If outcomes differ only because a case is genuinely high-risk, that is normal. The question is whether the programme still produces reliable, repeatable compliance outcomes under routine operating conditions.

  • Weak identity checks usually show up as documents accepted without reliable validation, stale customer data, or inconsistent proof of ownership and control.
  • Inconsistent risk scoring often means the risk model is not being applied the same way across customers, products, or front-line teams.
  • Poor sanctions screening appears when alerts are routinely mishandled, thresholds are unclear, or false positives are not being tuned in a controlled way.
  • Missing records and failed retrieval are especially serious because they mean the organisation cannot prove what happened, when it happened, or who approved it.

Where compliance failures become operational failures

A FICA programme can look acceptable on paper while failing in practice if staff do not understand the procedures or if the workflow depends on informal judgment. That is often visible in incomplete customer due diligence, inconsistent escalation of suspicious activity, and poor handoff between onboarding, operations and compliance teams. At that point, the programme is no longer just underperforming, it is unreliable.

The clearest sign of maturity is not zero exceptions, but controlled exceptions. If case notes, evidence packs, and reporting trails are missing or scattered, the organisation cannot demonstrate that it met its obligations. For a programme that must withstand internal audit, regulator review, or remediation testing, that absence of traceability is a material defect.

  • Retrievability matters as much as collection, because compliance evidence that cannot be produced on demand is effectively unusable.
  • Procedure knowledge matters because staff who cannot explain the process usually cannot apply it consistently under pressure.
  • Escalation quality matters because suspicious activity handling is only useful when cases move cleanly from detection to decision to reporting.

Risk and Threat Considerations

A failing FICA programme creates exposure in two directions: regulatory failure and abuse by bad actors. Weak verification, inconsistent screening, or poor recordkeeping can allow prohibited relationships to progress, suspicious activity to go unreported, and regulators to conclude that the firm does not have effective controls in place.

Failure mechanism: Control gaps accumulate across onboarding, screening, record retention and escalation, so the programme cannot reliably detect, explain, or evidence compliance decisions.

Impact: The organisation may face failed audits, remediation orders, enforcement action, delayed customer onboarding, and a higher chance that suspicious or illicit activity passes through undetected.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 6 — Access Control Management A failing programme often reflects weak operational control over who can approve or bypass checks.
8 — Audit Log Management Auditability and retrievability are central when FICA evidence cannot be reconstructed.
Recommendation — Restrict approval and override paths so compliance decisions stay bounded and reviewable. Centralise and protect logs so customer decisions and escalations are reconstructable.
ISO/IEC 42001:2023 A.2 — Leadership and Accountability FICA programmes fail when ownership for compliance steps is unclear.
Recommendation — Assign clear accountability for onboarding, screening, escalation, and evidence retention.
NIST CSF 2.0 PR.AA — Identity Management, Authentication, and Access Control Identity verification and access to compliance evidence are core failure points in this programme.
Recommendation — Apply strong identity and access controls around customer onboarding and compliance evidence.

Practitioner Guidance

What to prioritise: Start with the controls that create evidence, not just the controls that create decisions. If you cannot prove identity verification, risk scoring, screening outcomes, and suspicious activity handling from retained records, the programme is already operationally weak even if some cases are being handled correctly.

What to verify: Test a sample of real cases end to end. Confirm that each file contains the expected evidence, the decision is explainable, the risk rating is consistent with policy, and the case can be reconstructed without relying on tribal knowledge. If any step depends on one person remembering the process, the control is fragile.

Practitioner takeaway: The best indicator of a functioning FICA programme is not policy completeness, but whether ordinary cases can be processed, escalated and evidenced consistently enough to survive scrutiny from compliance, audit and regulators.