Definition
Integration is a core building block of an effective AML/CFT programme. This topic breaks it down into how it works in practice, where analysts get it wrong, and how regulators test it.
Why it exists
Regulators expect institutions to demonstrate that integration is applied consistently and evidenced in the file. Without it, controls fail at exactly the moment financial crime risk crystallises.
Real example
A mid-sized bank onboarded a client whose profile looked routine. Applying integration properly surfaced a mismatch between declared activity and observed flows, and the relationship was escalated within 48 hours.
Visual walkthrough
Trigger
An event or risk signal starts the control.
Assess
Evidence is gathered and weighed against policy.
Decide
Accept, escalate, restrict or exit.
Evidence
The rationale is documented for the regulator.
How it works in practice
- Policy defines the standard; procedure defines the evidence.
- Risk rating drives depth — not client seniority or revenue.
- Every decision must be reconstructable months later from the file alone.
Common mistakes
- Treating the control as a form-filling exercise instead of a risk judgement.
- Documenting the conclusion but never the reasoning.
- Failing to refresh when the client's behaviour changes.
Quick summary
— Integration is risk-based, not checklist-based.
— Evidence quality matters as much as the decision itself.
— Escalation paths must be defined before you need them.
Mini quiz
Question 1
What most reliably determines the depth of work required under Integration?