The landscape of anti-money laundering and regulatory compliance is undergoing a profound structural evolution. Gone are the days when static, tick-box onboarding could adequately shield an organisation from modern financial threats. To explore this vital shift, we spoke with Oumesha Pirthy, ACCA, MIPA, Head of Compliance, MLRO and Data Protection Officer at ONS FinServ Ltd, who shares her expert insights on transitioning from traditional KYC to dynamic financial-crime risk intelligence, managing personal liability, and turning compliance into a strategic business enabler.
Traditional anti-money laundering and counter-terrorist financing frameworks have long relied on static tick-box KYC processes, but the modern risk environment demands a much more agile approach. Addressing why static onboarding is no longer sufficient, Oumesha explains: “KYC remains essential, but it is only the opening snapshot of a client relationship. Financial-crime risk intelligence means continually asking whether the activity, counterparties, ownership changes and source of wealth story still make sense in the real world. A file may look entirely satisfactory on day one, yet become higher risk after a change in control, an unusual payment pattern or new adverse information. Static onboarding cannot capture that evolution. The goal is not to replace sound documentation with technology. It is to combine credible documentation, human judgement and ongoing intelligence so that compliance understands the relationship, rather than merely holding a completed file.”
Moving from reactive compliance to proactive risk intelligence requires contextual data, yet compliance teams frequently risk drowning in false positives. Solving this operational challenge requires precision rather than brute force. Oumesha notes, “The answer is not to monitor everything with the same intensity. A well-designed programme starts by understanding what normal should look like for each client, structure and service line. For example, a holding company, an investment vehicle and an operating business should not be assessed against identical behavioural expectations. Alerts should be risk-weighted and supported by clear escalation logic, with thresholds reviewed regularly using actual outcomes. Technology can identify patterns, but experienced compliance professionals must decide whether there is a credible commercial explanation. We also need to measure false positives honestly. If an alert is repeatedly producing no meaningful risk insight, the rule should be refined, not blindly retained.”
As regulatory scrutiny intensifies, the role of the Money Laundering Reporting Officer continues to evolve, particularly regarding personal liability and decision-making under pressure. Discussing the evaluation of Suspicious Transaction Reports, she highlights: “The MLRO’s obligation has always been to make an independent and properly documented and informed assessment of suspicion. What has changed is the volume and speed of information available when that decision is made. That makes disciplined judgement more important, not less. I do not view an STR decision as a mechanical exercise or as a choice between protecting the business and protecting the regulator. The task is to assess the facts, challenge gaps in the explanation, preserve confidentiality and act within the applicable reporting timelines. Personal accountability means being able to demonstrate why a decision was reached, what information was considered and what follow-up action was taken.”
For firms operating across multiple jurisdictions, harmonising regional AML standards with global financial-crime intelligence models presents another layer of complexity. Oumesha outlines how organisations can achieve consistency without breaking local compliance, she says, “We begin with a group-wide standard that reflects the strongest common principles: beneficial ownership transparency, source-of-wealth substantiation, sanctions screening, ongoing monitoring and clear escalation. That provides consistency across the business. Each jurisdiction then has a local overlay for its specific legal requirements, reporting channels, data rules and risk priorities. Harmonisation should not mean forcing one jurisdiction’s approach onto another. It means ensuring that no local team falls below the group’s risk standard while respecting local law. In practice, this requires shared methodologies, quality assurance, regular training and close communication between compliance teams. A client should receive a consistent risk-based experience, even where the local compliance obligations differ.”
Investment due diligence has similarly expanded far beyond traditional financial performance and legal standing, with non-financial vectors dictating the success or failure of an investment case – Oumesha notes, “They are now central to the investment case. A strong financial model can be undermined quickly by weak governance, an unresolved regulatory issue, a cyber breach or a business model exposed to conduct risk. The weight given to each factor should remain proportionate to the investment, sector and jurisdiction. We do not treat ESG or cybersecurity as a generic checklist attached at the end of a transaction. We assess how those risks could affect valuation, reputation, operational continuity, investor confidence and eventual exit. The best diligence identifies issues early enough to influence pricing, conditions precedent, governance rights or remediation plans. That is where compliance becomes genuinely useful to the investment decision.”
Unmasking multi-tiered corporate structures remains one of the toughest obstacles in this process. Detailing the intelligence frameworks required to tackle opaque entities, Oumesha emphasises structural curiosity, she said, “No single database or screening tool can resolve a complex ownership structure. The strongest approach is to build the ownership map from reliable primary documents, then test it against independent corporate registries, credible intelligence sources, sanctions and adverse-media screening, and the client’s own commercial narrative. We focus on control as well as shareholding. Voting rights, nominee arrangements, protector roles, side agreements and financing arrangements may reveal influence that a simple percentage chart does not. We also look for inconsistencies: a structure that is unnecessarily opaque, a source of wealth that does not match the investment size, or jurisdictions that do not fit the stated purpose. Good diligence is structured curiosity, supported by evidence.”
Too often, compliance is viewed as an operational bottleneck or a roadblock to deals. Overcoming this perception requires early engagement and commercial pragmatism, against this backdrop, she says, “Compliance becomes a bottleneck when it is brought in after commercial commitments have been made. The better approach is early engagement. If we understand the proposed investor, structure, timeline and jurisdictions at the outset, we can identify requirements, potential risks and workable alternatives before they become last-minute issues. We should be clear about what is mandatory, what is a risk appetite decision and what can be remediated through conditions, disclosures or enhanced monitoring. I believe in helping businesses find a compliant route forward, not simply presenting a list of prohibitions. At the same time, there must be a point where the risk cannot be responsibly managed. Being commercial never means compromising that judgement.”
Looking ahead to the next three to five years, institutional investors and compliance professionals must adapt to an increasingly data-driven, complex environment. Concluding with advice for the future, Oumesha shares her final perspective on core capabilities saying, “They should build the ability to turn fragmented information into sound, explainable decisions. The future of compliance will not belong solely to firms with the most data or the most sophisticated tools. It will belong to those that can connect data with sector knowledge, commercial context and accountable human judgement. This means investing in better data governance, practical technology, cross-functional teams and people who can challenge assumptions confidently. Compliance professionals also need to understand the business model they are overseeing. When they do, they can identify financial-crime and investment risks earlier, communicate them more clearly and help shape solutions that protect both the institution and its clients.”
As financial crime grows increasingly sophisticated, the message from the frontline is clear: the future of compliance lies in marrying advanced risk intelligence with deeply human insight. By treating regulatory oversight not as a box-ticking exercise, but as a dynamic, strategic partner to business growth, leaders like Oumesha Pirthy are reshaping how institutions protect their integrity while navigating a complex global marketplace.



