compliance programme Archives -

Why Risk Management Frameworks Are Failing — And How to Fix Them

Most organisations have risk management frameworks. Very few have risk management frameworks that actually work under operational pressure. The gap between the two is where regulatory penalties, reputational damage, and business disruption live.

In 2026, enterprise risk management is facing a perfect storm: increasingly complex multi-jurisdictional regulatory requirements, faster-moving threat landscapes, and boards demanding more granular visibility into risk exposure than ever before. Against this backdrop, compliance programmes built on legacy structures — outdated policies, siloed risk functions, and reactive mindsets — are simply no longer adequate.

At Baretzky & Partners LLP, we deliver comprehensive risk management programmes designed to identify, assess, and mitigate enterprise-wide exposures — from operational and regulatory risk through to reputational and cyber risk — across 116 countries. Our certified practitioners design bespoke compliance frameworks aligned with ISO 31000, COSO ERM, and sector-specific regulatory requirements, combining deep jurisdictional knowledge with practical implementation experience.

The Four Pillars of Effective Enterprise Risk Management

Effective enterprise risk management is not a single programme — it is an integrated system of interconnected capabilities. Organisations that treat risk management as a box-ticking exercise will find their frameworks failing precisely when they are most needed. Those that build genuine capability across four core areas are positioned to manage risk proactively, demonstrate compliance effectively, and recover rapidly when disruptions occur.

1. Enterprise Risk Framework Design

The foundation of effective risk management is a properly designed risk architecture. This means more than a risk register — it encompasses governance structures, risk appetite statements, escalation protocols, and board-level reporting frameworks that give senior leadership genuine visibility into risk exposure.

Critical components include risk appetite and tolerance frameworks that translate abstract board-level risk tolerance into operational parameters; three lines of defence models that clearly delineate the responsibilities of business functions, risk and compliance, and internal audit; and governance structure design that ensures risk ownership is clearly assigned and accountability mechanisms are functioning.

Without this architectural foundation, even the most sophisticated risk identification processes will generate insights that cannot be effectively acted upon.

2. Compliance Programme Development

Compliance programmes must be built for the regulatory environment organisations actually face — not the one that existed when the programme was last updated. In 2026, this means addressing a dramatically expanded regulatory landscape covering GDPR, DORA (Digital Operational Resilience Act), the EU AI Act, ESG disclosure requirements, and continued expansion of AML and sanctions obligations.

Effective compliance programme development starts with regulatory gap analysis — a systematic assessment of where the organisation’s current policies and procedures fall short of applicable requirements. From this foundation, policy and procedure drafting, cross-jurisdictional mapping, and compliance training programmes can be built on a solid evidential basis rather than assumption.

PCI security compliance, GDPR and data protection obligations, and sector-specific requirements all demand specific attention. Multi-jurisdictional organisations face the additional challenge of reconciling conflicting regulatory requirements — an area where specialist advisory is particularly valuable.

3. Operational and Third-Party Risk Assessment

Some of the most significant risk exposures facing organisations in 2026 are not internal — they sit in the supply chain, in third-party relationships, and in the complex ecosystem of vendors, partners, and counterparties that modern businesses depend on.

Comprehensive operational risk assessment covers internal process vulnerabilities, technology dependencies, and human factors. Third-party due diligence extends this assessment to the organisation’s external relationships — identifying where concentration risk, compliance gaps, or integrity issues in the supply chain could create exposure.

Business continuity planning completes this picture, ensuring that when disruptions occur — whether from operational failures, cyber incidents, regulatory actions, or external shocks — the organisation has tested, credible plans to maintain critical functions and recover effectively.

4. Regulatory Response and Remediation

No compliance programme is perfect, and regulatory inquiries, enforcement actions, and compliance gaps are an inevitable feature of operating in complex regulated environments. When they occur, the quality of the response is as important as the underlying compliance posture.

Effective regulatory response requires rapid assessment of the scope of the issue, transparent and well-structured communication with regulators, and a credible remediation programme that addresses root causes rather than symptoms. Our team supports organisations through regulatory inquiries and enforcement actions — providing regulator liaison expertise, remediation programme management, and the specialist advisory needed to minimise exposure and restore compliance standing as efficiently as possible.

ISO 31000 and COSO ERM: The International Standards Framework

Two frameworks dominate enterprise risk management practice internationally: ISO 31000 and the COSO Enterprise Risk Management Framework. Understanding both — and knowing when to apply which — is fundamental to building programmes that satisfy regulatory expectations while delivering genuine operational value.

ISO 31000:2018 provides principles and guidelines for risk management applicable to any organisation, regardless of sector or size. Its strength is its universality and its focus on integrating risk management into organisational processes and decision-making at every level. For organisations seeking a risk management standard that is recognised globally and applicable across jurisdictions, ISO 31000 is the benchmark.

The COSO ERM Framework (2017 update) integrates enterprise risk management with strategy and performance, emphasising the connection between risk appetite and strategic objectives. Its five components — governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting — provide a structured approach particularly suited to larger organisations with complex governance structures.

Our practitioners are experienced in both frameworks and advise on their application based on organisational context, regulatory requirements, and existing risk infrastructure.

The DORA Challenge: Digital Operational Resilience in Financial Services

For organisations in the financial services sector, the Digital Operational Resilience Act (DORA) represents the most significant new compliance obligation of the current regulatory cycle. In force since January 2025, DORA requires financial entities — including banks, investment firms, insurance companies, and crypto-asset service providers — to implement comprehensive digital operational resilience frameworks covering ICT risk management, incident reporting, operational resilience testing, and third-party ICT risk management.

DORA’s requirements are prescriptive and demanding. ICT risk management frameworks must be documented, tested, and subject to independent review. Significant ICT-related incidents must be reported to competent authorities within defined timeframes. Digital operational resilience testing — including advanced threat-led penetration testing for significant institutions — must be conducted on a regular basis.

Third-party ICT risk management under DORA is particularly significant, as it extends compliance obligations beyond the regulated firm to its critical third-party service providers — creating a new dimension of supply chain risk management that many organisations are still working to address.

Building a Risk Culture That Sustains Compliance

Technical compliance frameworks are necessary but insufficient. Organisations that sustain genuine compliance over time are those that have built a risk culture — where risk awareness is embedded in decision-making at every level, where escalation of concerns is encouraged rather than discouraged, and where the tone from the top communicates genuine commitment to compliance rather than performative adherence.

Building this culture requires more than training programmes, although training is an important component. It requires governance structures that give risk and compliance genuine authority, incentive frameworks that do not reward short-term performance at the expense of risk management, and leadership that models the behaviours it expects from the organisation.

Our risk management advisory includes assessment of organisational risk culture — identifying where cultural barriers to effective risk management exist and advising on the interventions needed to address them.

When to Engage a Risk Management Specialist

Organisations typically engage specialist risk management advisory in several circumstances: when facing a new regulatory requirement that existing capabilities cannot address; when a regulatory inquiry or enforcement action has identified compliance gaps; when entering new markets or jurisdictions that require unfamiliar compliance frameworks; or when an internal review has identified that the existing risk programme is not functioning as intended.

In all of these situations, early engagement is advantageous. The earlier specialist advisory is engaged, the more options are available — whether that means building a compliance programme before a regulatory deadline, engaging proactively with a regulator before an inquiry becomes adversarial, or addressing a compliance gap before it escalates into an enforcement issue.

Baretzky & Partners: Risk Management Across 116 Countries

Our risk management practice combines global reach with local expertise. With coverage across 116 countries and 25+ years of experience in enterprise risk management, our certified practitioners deliver programmes that are not only technically sound but practically implementable in the jurisdictions and sectors where our clients operate.

We work with organisations across financial services, professional services, technology, energy, and government sectors — designing and implementing risk frameworks that meet regulatory requirements while delivering genuine operational value.

Contact Baretzky & Partners LLP to request a risk assessment or discuss your compliance programme needs. Initial consultations are strictly confidential, and our team can deliver a remediation roadmap within days of engagement.

Baretzky & Partners LLP provides strategic risk mitigation, legal affairs and crisis mitigation, and international information policy and compliance specialist counsel. We do not provide litigation services. All investigative services are provided by our European offices only.

Anti-money laundering (AML) enforcement has accelerated dramatically over the past decade. Regulators across the US, UK, EU, and Asia-Pacific are issuing record-breaking fines, expanding personal liability to executives, and publishing deferred prosecution agreements that name institutions and individuals in detail. For compliance officers, risk managers, and banking counsel, understanding the current penalty landscape is no longer optional — it is a core operational requirement.

This article provides a practical overview of how AML penalties and sanctions work in 2026, what triggers enforcement, and how organisations can reduce their exposure.


The Scale of Modern AML Penalties

Global AML fines have reached unprecedented levels. Between 2020 and 2025, regulators issued over $25 billion in AML-related penalties to financial institutions worldwide. The United States remains the most aggressive enforcer, with the Department of Justice (DOJ), Financial Crimes Enforcement Network (FinCEN), and Office of Foreign Assets Control (OFAC) all maintaining active enforcement programmes. The UK’s Financial Conduct Authority (FCA) and the European Banking Authority (EBA) have similarly intensified oversight, particularly post-FATF mutual evaluations.

Common penalty categories include civil monetary penalties, criminal fines, deferred prosecution agreements (DPAs), and non-prosecution agreements (NPAs). In the most serious cases — particularly those involving sanctions violations or terrorist financing — institutions face asset freezes, licence revocations, and the appointment of independent compliance monitors at their own expense.


What Triggers AML Enforcement

Regulatory action is typically triggered by one or more of the following:

  • Failure to file Suspicious Activity Reports (SARs) — Financial institutions are required to report suspicious transactions. Systematic failures to file, or deliberate delays, attract severe penalties.
  • Inadequate Know Your Customer (KYC) procedures — Insufficient customer due diligence, particularly at onboarding, remains the leading cause of enforcement action.
  • Sanctions screening failures — Processing transactions involving OFAC-listed parties, or failing to maintain current screening lists, is treated as a strict liability offence in the US.
  • Correspondent banking negligence — Banks providing services to foreign financial institutions without adequate oversight of those institutions’ AML controls are increasingly liable for downstream violations.
  • Beneficial ownership gaps — Failure to identify and verify ultimate beneficial owners, particularly in corporate and trust structures, is a growing area of enforcement focus.

Personal Liability: The Shift Toward Individual Accountability

A significant enforcement trend is the expansion of personal liability. Regulators in the UK, US, and EU are increasingly pursuing individual executives, compliance officers, and board members alongside institutions. The UK’s Senior Managers and Certification Regime (SMCR) places direct accountability on named individuals for AML failures within their area of responsibility. In the US, the DOJ’s revised corporate criminal enforcement policy explicitly encourages individual prosecutions.

This shift means that compliance professionals must maintain contemporaneous documentation of their decisions, escalations, and recommendations — both to demonstrate good faith and to establish that responsibility was appropriately discharged.


OFAC Sanctions: A Strict Liability Framework

OFAC sanctions violations are particularly consequential because they operate on a strict liability basis — intent is not required for a civil violation. Any transaction involving a Specially Designated National (SDN) or a blocked country, regardless of whether the institution was aware, may result in a penalty. Mitigating factors — such as voluntary self-disclosure, a robust compliance programme, and lack of prior violations — can reduce penalties significantly, but the base exposure remains high.

Organisations operating internationally must maintain real-time sanctions screening, understand the jurisdictional reach of US secondary sanctions, and have documented escalation procedures for potential matches.


The Role of Compliance Programmes in Penalty Mitigation

Regulators consistently apply mitigating treatment to institutions that can demonstrate a robust, risk-based compliance programme. Key elements include:

  • A documented AML/CFT policy reviewed and approved at board level
  • Regular risk assessments calibrated to the institution’s specific client base, geographies, and product mix
  • Independent testing and audit of the AML programme
  • Ongoing training for all relevant staff
  • A clear escalation and reporting structure for suspicious activity

Voluntary self-disclosure to regulators, while not without risk, is generally treated as a significant mitigating factor. Institutions that discover violations and proactively report them — rather than waiting for examination findings — typically receive more favourable resolutions.


Practical Steps for Compliance Teams in 2026

Given the current enforcement environment, compliance teams should prioritise the following:

  1. Update beneficial ownership registers — Ensure all corporate clients have current UBO data, with verification appropriate to risk level.
  2. Review correspondent banking relationships — Conduct enhanced due diligence on correspondent accounts, particularly those in higher-risk jurisdictions.
  3. Test SAR filing processes — Ensure triage, escalation, and filing workflows are functioning and that staff understand thresholds.
  4. Validate sanctions screening coverage — Confirm that all products and payment channels are included in screening and that list updates are applied in real time or near real time.
  5. Document compliance officer decisions — Maintain records of how and why specific decisions were made, particularly in high-risk situations.

Conclusion

AML enforcement in 2026 is more rigorous, more personal, and more cross-border than at any previous point. Financial institutions and their advisors must treat compliance not as a cost centre but as a strategic function — one that protects the organisation’s licence to operate and the careers of those responsible for it. Organisations that invest in robust frameworks, clear documentation, and proactive engagement with regulators are best positioned to manage their exposure in an increasingly unforgiving regulatory environment.

Baretzky and Partners LLP provides AML/CFT advisory services, compliance programme reviews, and regulatory response support to financial institutions and multinationals operating across multiple jurisdictions. Contact our team to discuss your compliance requirements.