Financial crime compliance (FCC) is how a firm manages its whole financial crime risk in one function. It brings together anti-money laundering, sanctions, anti-fraud, and anti-bribery controls, so the firm can detect and prevent crime across the board rather than in silos.
Key takeaways
- Financial crime compliance (FCC) is the umbrella function above AML.
- It covers AML, sanctions, fraud, bribery, and terrorist financing.
- AML is one part of FCC, not the whole of it.
- FCC runs risk assessment, screening, monitoring, reporting, and investigations.
- Firms increasingly merge fraud and AML teams, because criminals cross between them.
- Weak FCC is costly: TD Bank paid about $3 billion in 2024.
On this page
What it isWhat FCC coversFCC vs AMLWhat an FCC function doesThe FCC frameworkBuilding the functionRoles in FCCChallenges and trendsFAQsRead more
$800B to $2T
Laundered worldwide each year, one part of financial crime
Source: UNODC
~$300B
Laundered in the United States each year
Source: US Department of the Treasury
$3B
Paid by TD Bank in 2024 after control failures
Source: US Department of Justice
What is financial crime compliance (FCC)?
Financial crime compliance is how a firm manages every kind of financial crime risk in one place. It pulls anti-money laundering, sanctions, fraud, and bribery controls into a single function.
The idea is to stop treating each crime as a separate problem. Many schemes cross between them, so a joined-up function catches what siloed teams miss.
FCC is broader than AML alone. Read more: it is the operating layer above financial crime as a whole.
What FCC covers
FCC covers the full range of financial crime a firm can face. Each area has its own controls, but they share tools and data.
- Anti-money laundering. Stopping criminals disguising dirty money. See money laundering.
- Sanctions. Making sure the firm does not deal with restricted parties or countries.
- Anti-fraud. Preventing deception that takes money from the firm or its customers.
- Anti-bribery and corruption. Stopping improper payments and abuse of position.
- Counter-terrorist financing. Cutting off funds to terrorists. See CTF.
- Market abuse. Preventing insider dealing and market manipulation.
Screen a name across financial crime risks
Run one search across sanctions, PEP, and adverse media data to check a person or company before you deal with them.
FCC vs AML: how they differ
FCC and AML are often used loosely, but they are not the same. AML is one part of FCC.
AML deals specifically with money laundering. FCC is the wider function that also handles sanctions, fraud, bribery, and more. A firm can have a strong AML program and still have gaps in fraud or sanctions if FCC is not joined up.
| AML | FCC | |
|---|---|---|
| Scope | Money laundering | All financial crime |
| Includes | CDD, monitoring, SARs | AML plus sanctions, fraud, bribery |
| Aim | Stop dirty money | Manage the whole crime picture |
Placing AML inside FCC lets a firm share data and staff across crime types, which is where the efficiency comes from.
What an FCC function does
An FCC function runs a set of connected activities across all the crime types it covers. The core work is consistent.
- Risk assessment. Rate the firm’s exposure across money laundering, sanctions, fraud, and bribery.
- Screening. Check customers and payments against sanctions and PEP data.
- Monitoring. Watch transactions and behavior for signs of crime.
- Investigations. Look into alerts and decide whether to escalate or report.
- Reporting. File suspicious activity reports and meet regulatory duties.
Do this: weigh the geographic side of your exposure with our Country Risk Checker.
The FCC framework
A sound FCC function rests on a clear framework, so the pieces work together rather than in isolation. The framework has a few layers.
- Governance. Senior ownership, clear roles, and board oversight of financial crime risk.
- Risk assessment. A firm-wide view that covers every crime type, not just laundering.
- Controls. Screening, monitoring, and due diligence shared across crime types.
- Reporting and record-keeping. Timely reports and evidence that controls ran.
- Assurance. Independent testing that checks the whole function works.
How to build a financial crime compliance function
Standing up an FCC function follows a clear path. The order matters, because each step rests on the one before it.
- Set the scope. Decide which crime types the function will cover, from AML to fraud to sanctions.
- Run one risk assessment. Build a firm-wide view across all of those crime types, not just laundering.
- Name an owner. Give a senior person clear responsibility for the whole function.
- Share the controls. Use common screening and monitoring across crime types rather than duplicating them.
- Test the function. Have an independent party check that the pieces work together.
Bringing the crime types together is the point. A firm that runs sanctions, fraud, and AML on separate systems, with separate data, spends more and sees less. Read more: the AML piece is covered in our guide to building an AML program, which an FCC function extends to other crimes.
Start with a financial crime risk read
See where your money laundering and financial crime risk is concentrated across customers, products, and markets.
Roles in FCC
FCC brings together several roles under one function. A common way to organize them is the three lines of defense.
- First line. The business, which owns the risk it creates and applies front-line checks.
- Second line. Compliance, including the MLRO and FCC team, which sets rules and reviews alerts.
- Third line. Internal audit, which tests that the first two lines work.
Analysts and investigators sit mostly in the second line, working alerts and building cases. Clear ownership across the lines is what keeps the function effective, since a gap between the business and compliance is where most failures begin.
Challenges and trends in FCC
FCC is changing fast, driven by new risks and new tools. A few shifts stand out.
- Fraud and AML convergence. Firms are merging the two, because criminals move between them.
- Regulatory technology. Firms use RegTech to screen and monitor at scale.
- Rising enforcement. Penalties keep climbing, as the TD Bank case in 2024 showed.
- Faster payments. Real-time payments leave less time to catch crime before money moves.
- More data sharing. Firms and authorities share more intelligence, within privacy limits, to see cases whole.
The direction of travel is toward one connected view of financial crime, powered by better data and shared intelligence. Firms that keep their crime types in silos will find that harder to sustain as volumes and enforcement both rise.
Get an indicative financial crime risk rating
See where your money laundering and financial crime risk is concentrated across customers, products, and markets.
Frequently asked questions
What is financial crime compliance (FCC)?
Financial crime compliance is how a firm manages its whole financial crime risk in one function. It brings together anti-money laundering, sanctions, anti-fraud, and anti-bribery controls, so the firm can detect and prevent crime across the board. FCC is broader than AML, which is only one part of it.
What does financial crime compliance cover?
FCC covers anti-money laundering, sanctions, anti-fraud, anti-bribery and corruption, counter-terrorist financing, and market abuse. Each area has its own controls, but they share tools and data such as screening and monitoring. Bringing them into one function helps catch schemes that cross between crime types.
What is the difference between FCC and AML?
AML deals specifically with money laundering, while FCC is the wider function that also handles sanctions, fraud, bribery, and more. AML is one part of FCC. A firm can have a strong AML program and still have gaps in fraud or sanctions if its financial crime compliance is not joined up.
What does a financial crime compliance function do?
An FCC function runs risk assessment, screening, monitoring, investigations, and reporting across all the crime types it covers. It rates the firm’s exposure, checks customers and payments against sanctions and PEP data, watches for signs of crime, looks into alerts, and files reports to meet regulatory duties.
Why are firms merging fraud and AML teams?
Firms merge fraud and AML because the two are often the same crime viewed from two ends. Fraud creates the loss, and laundering conceals the gain, and the same criminals run both. Combining the teams lets a firm share data and see the whole case, which siloed teams tend to miss.
What is the FCC framework?
The FCC framework is the structure that makes a financial crime function work as a whole. It has layers for governance, a firm-wide risk assessment, shared controls such as screening and monitoring, reporting and record-keeping, and independent assurance. The framework keeps the crime types joined up rather than run in isolation.
Who works in financial crime compliance?
FCC brings together compliance staff, the MLRO, analysts, and investigators, usually organized as three lines of defense. The business is the first line and owns its risk. Compliance, including the FCC team, is the second line. Internal audit is the third line and tests that the first two work.
What are the three lines of defense in FCC?
The three lines of defense are a way to organize responsibility. The first line is the business, which owns the risk it creates and applies front-line checks. The second line is compliance, including the FCC team and MLRO, which sets rules and reviews alerts. The third line is internal audit, which tests the other two.
How does RegTech support financial crime compliance?
Regulatory technology, or RegTech, helps FCC teams screen customers, monitor transactions, and manage cases at scale. It automates repetitive checks, reduces manual review, and can improve accuracy. Firms use RegTech to keep pace with rising transaction volumes and faster payments, though human judgment still decides the outcome of alerts.
Is financial crime compliance legally required?
The specific controls within FCC are legally required for regulated firms, including anti-money laundering programs, sanctions screening, and anti-bribery measures. Combining them into a single financial crime function is a management choice rather than a legal requirement, but it helps firms meet all of these duties more effectively.
What is the difference between FCC and an AML compliance program?
An AML compliance program manages money laundering risk specifically. Financial crime compliance is the wider function that includes the AML program alongside sanctions, fraud, and bribery controls. The AML program sits inside FCC, so a firm’s financial crime function covers more ground than its AML program alone.
What are the main challenges in financial crime compliance?
The main challenges include the convergence of fraud and AML, keeping pace with rising transaction volumes using regulatory technology, climbing enforcement penalties, and the spread of real-time payments that leave less time to catch crime. Managing several crime types in one function, without gaps between them, is the central task.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 12, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: financial crime compliance is the umbrella function that brings AML, sanctions, fraud, and bribery controls under one roof.