Hi, I'm Farhad.

I build risk and compliance functions from the ground up, get them licensed across borders, and put AI where it actually works so they scale without scaling headcount.

Twenty years of it. Banks first, fintechs now. Everything I build, write and argue about ends up here.

London · 40 yrsDubai
Now

Head of Risk & Compliance

Cross-border payments across Africa, the UK and Canada. Building the risk and compliance function up from close to nothing, with a small team. Licensing included, which takes longer than anyone expects.

Dubai · 2025—
What I do · 01

Ground-up builds

Standing up a risk and compliance function where there isn't one. Framework, controls, operating model, people, all while the product is already live and taking customers.

Four so far
What I do · 02

Global licences

Getting regulated and staying regulated in more than one place at once. Applications, supervisory relationships, board attestation, and the awkward questions before the regulator asks them.

UK · EU · UAE · US · Africa · Canada
What I do · 03

AI that earns its place

Pointing it at the gathering, never the judgement. Done properly it takes cost out and improves quality at the same time, which is not the trade-off most people expect.

40%+ efficiency gain
Why AI belongs in this function 80% gathering 20% judgement

Compliance work has always split roughly like this. AI is very good at the first part and nowhere near the second. Build around that and the function stops being the thing that slows the business down.

Scale I've worked at
24mcustomers monitored 1m+alerts a month

Big teams did that, I was one part of it. I've also been the entire function on my own at a startup. A control that works with two hundred analysts behind it is a different animal when it's one person and a deadline, and most guidance is quietly written for the first case.

How I got here

I flagged a payment I couldn't explain

First job, payments officer. Something looked wrong and I had no idea why.

Where I've done it
2025—Head of Risk & Compliance
2023—25UK MLRO, Africa oversight
2021—23Head of Financial Crime, consulting
2019—20Deputy Head of Financial Crime
2017—18MLRO, board level
Free, no email required

Regulatory Horizon Scanner

Turns the week's regulator output into one page. What changed, who owns it, what we do by when. Most firms run this off eleven mailing lists and hope.

horizon-scanner-spec-v1.md
Also building

KYB Triage Assistant

Local · Oct

Fuzzy-Match Playground

Synthetic data · Nov

MLRO First 90 Days

Checklist · Nov
Free course · no sign-up · 5 modules

Learn KYC properly

Twenty-four lessons across five modules. What financial crime is and who makes the rules, what to collect for every entity type, a real file worked end to end with the mistakes left in, how screening thresholds actually behave, and how to build a career out of it. Mostly things to click rather than things to read.

Start with module 1 →
Modules 2–5

KYC in Practice

Document matrix builder, a worked file, a screening threshold sandbox, and what actually gets you promoted.

Open →
Interactive map

What a compliance and financial crime framework actually looks like

Thirty components across three lines of defence, governance and the enablers underneath. KYC, AML, sanctions, Consumer Duty, horizon scanning, licensing, audit. Click any box for who owns it, what it looks like on day one against at scale, and how it usually fails. There is a toggle for what you genuinely need on day one, which is the question I get asked most.

Open the map →
Watch first

Two short films, then the tools they are about

One on what a whole compliance operating model looks like. One on the free KYC course. Both under forty seconds, both with a link straight to the thing itself.

Film 01 · 37 seconds

What a compliance framework actually looks like

Governance on top, three lines holding it up, enablers underneath. Thirty components, and only five of them can wait until after day one.

Open the interactive map →
Film 02 · 34 seconds

The free KYC course, in 34 seconds

Thresholds you move yourself, a document hunt, an ownership chain you unpick. Five modules, no sign-up, no email.

Start module 1 → Modules 2–5
Follow along in Farhad Chowdhury

Three posts and one video a week. Building functions, getting licensed, and where AI actually helps rather than just sounding good.

Posts

Nobody missed the rule

Operating model

A risk-based approach is a testing schedule, not a policy

AML/CFT

Your fuzzy-match threshold is a business decision

Sanctions
Things I believe

Compliance should not be the reason nothing ships. A function that can only say no has failed at its job. The work is building one that can say yes quickly, for the right things, and evidence why.

Say hello
so what do you actually do?
I build the risk and compliance side of banks and fintechs. Usually from nothing.
like the people who say no?
like the people who work out how to say yes without breaking the law. and get you licensed while we're at it

Standing up a function, chasing a licence, or working out where AI actually fits? Or you think one of my specs is wrong. Either way, the useful messages tell me what broke.