FCC (Financial Crime and Compliance)
TL;DR
$61 billion — that's what financial crime compliance costs across the U.S. and Canada annually, with 99% of institutions reporting year-over-year increases (LexisNexis Risk Solutions, 2024).
Financial Crime and Compliance (FCC) is the operational backbone your bank runs to detect, investigate, and report money laundering, fraud, and sanctions violations, from identity verification through case resolution.
What Is FCC (Financial Crime and Compliance)?
FCC is the umbrella term for anti-financial-crime operations at a bank. It covers identity verification at onboarding, Anti-Money Laundering (AML) alert triage, sanctions screening, transaction monitoring, investigation, and case resolution.
Think of it this way: your AML program defines the policy. FCC is where that policy meets reality — the people, technology, and workflows that execute it daily. It sits downstream of policy design and upstream of enforcement, the Suspicious Activity Reports (SARs) your institution ultimately files. It's also where the bulk of your headcount and technology budget land.
FCC overlaps with Know Your Customer (KYC) and AML but is broader than either. Rather than covering just identity verification or laundering-specific detection, FCC stitches the full operational lifecycle together — from the moment a customer applies for an account to the moment a case file closes.
Why FCC Costs Keep Climbing
Regulatory expectations expand every year. Sanctions lists grow longer. Criminals adopt new channels — cryptocurrency, instant payments, AI-generated identity fraud — faster than most compliance programs can adapt.
The result? Your FCC function has to do more, with greater accuracy, without a proportional budget increase. That gap between rising demands and flat resources is exactly what AI-assisted triage and investigation tooling closes.
Consider the math: if your team handles 10,000 alerts per month and 95% are false positives, your analysts spend the vast majority of their time clearing noise. Reducing false-positive review time by even 30% frees hundreds of analyst hours for genuine risk investigation.
How It Works
FCC operations follow a clear sequence:
- Verify identity. Customers and counterparties are checked at onboarding and periodically thereafter against identity, sanctions, and Politically Exposed Person (PEP) databases.
- Monitor transactions. Automated rules and behavioral models flag transactions that deviate from expected patterns for a given customer or account type.
- Triage alerts. Flagged activity is scored and prioritized. The overwhelming majority of automated alerts are false positives — without smart triage, they swamp your manual queue.
- Investigate and resolve. Analysts build a case file on genuine risk indicators, determine whether a SAR is required, and document the decision for audit.
Each step feeds the next. Weak identity verification creates downstream noise in transaction monitoring. Poor triage buries real risk under false alerts. The strongest FCC operations treat these as a connected pipeline, not isolated checkpoints.
FCC vs. KYC vs. AML
These three terms get used interchangeably, but they describe different scopes:
- KYC is specifically the identity-verification and risk-classification work done at onboarding.
- AML is the broader regulatory framework targeting one category of financial crime: laundering the proceeds of illegal activity.
- FCC is the operational umbrella that runs AML, sanctions screening, and fraud investigation together.
In practice, the same team, the same case-management system, and often the same analyst handle all three. Treating them as separate functions creates gaps criminals exploit.
FAQ
What does an FCC analyst actually do day to day?
An FCC analyst reviews alerts from transaction monitoring or screening systems, researches customer and transaction context, determines whether activity is genuinely suspicious or a false positive, and either closes the alert or escalates it toward a SAR filing.
Why do most financial crime alerts turn out to be false positives?
Rules-based monitoring systems are deliberately tuned broadly — missing genuine financial crime carries far higher regulatory and reputational risk than reviewing an extra false alert. That tradeoff means the large majority of generated alerts are false positives, which is why triage and prioritization matter as much as detection.
How is AI changing FCC operations?
AI prioritizes which alerts analysts see first, summarizes case context that previously took 20 to 30 minutes to assemble manually, and flags behavioral patterns static rules miss. Regulators still expect a documented, explainable decision trail behind every AI-assisted determination.
What is the difference between a rejection and an FCC hold?
A rejection stops a transaction for a technical reason — a formatting error, for example. An FCC hold pauses a transaction because it triggered a financial-crime rule or model score and requires human review before proceeding.