I build risk and compliance functions from the ground up, get them licensed across borders, and put AI where it actually works so they scale without scaling headcount.
Twenty years of it. Banks first, fintechs now. Everything I build, write and argue about ends up here.
Cross-border payments across Africa, the UK and Canada. Building the risk and compliance function up from close to nothing, with a small team. Licensing included, which takes longer than anyone expects.
Dubai · 2025—Standing up a risk and compliance function where there isn't one. Framework, controls, operating model, people, all while the product is already live and taking customers.
Four so farGetting regulated and staying regulated in more than one place at once. Applications, supervisory relationships, board attestation, and the awkward questions before the regulator asks them.
UK · EU · UAE · US · Africa · CanadaPointing it at the gathering, never the judgement. Done properly it takes cost out and improves quality at the same time, which is not the trade-off most people expect.
40%+ efficiency gainCompliance work has always split roughly like this. AI is very good at the first part and nowhere near the second. Build around that and the function stops being the thing that slows the business down.
Big teams did that, I was one part of it. I've also been the entire function on my own at a startup. A control that works with two hundred analysts behind it is a different animal when it's one person and a deadline, and most guidance is quietly written for the first case.
First job, payments officer. Something looked wrong and I had no idea why.
I took it to someone senior expecting to be told I was wasting his time. I wasn't. That was the moment this stopped being a job about forms.
Since then it's been KYC, transaction monitoring and AML risk, then MLRO, head of financial crime, and head of risk and compliance. Investment banks, commercial banks, asset managers, and latterly fintechs.
Somewhere in the middle the job changed. It stopped being about working files and became about designing the thing that works the files, getting it licensed wherever the business wants to operate, and deciding what a team of nine should be doing that a team of ninety used to do.
That is the work now. Build it, license it, and make it scale without it becoming the reason nothing ships.
Banks, asset managers, fintechs. UK, EU, UAE, Africa, North America. Regulators including the FCA, CBUAE, FINTRAC, BaFin-aligned regimes, COBAC and BCEAO.
Turns the week's regulator output into one page. What changed, who owns it, what we do by when. Most firms run this off eleven mailing lists and hope.
# Regulatory Horizon Scanner (spec v1.0) ## 1. What it's for A weekly process that turns regulator output into a single page. What changed, what it means for us, who owns it, by when. It isn't a news feed. The output is a decision record. ## 2. Scope, do this first Scope creep is what kills a scanner. - Jurisdictions we're licensed or operating in: - Products in scope: - Domains: AML/CFT, sanctions, fraud, conduct, data, payments, AI - Explicitly out of scope: Anything outside scope is Tier 3, or nothing. Don't widen the scope because something looks interesting. ## 3. Sources Primary sources only. Use a law firm briefing to find the rule, then go and read the rule. - FATF, Wolfsberg, Egmont - UK: FCA, HM Treasury, OFSI, UKFIU - EU: EBA, AMLA, European Commission - UAE: CBUAE, local FIU, DFSA / FSRA - US: OFAC, FinCEN. Canada: FINTRAC - Africa as applicable: BCEAO, COBAC, national central banks Sanctions list updates are a separate daily automated feed. Don't put them in here. ## 4. What you log per item id, date_published (from the source), source, url, jurisdiction, domain, instrument type, 3-sentence summary, what it affects, tier, effective_date, response_due, owner, action, status. Two of those are human only: tier and action. ## 5. Tiering, fixed criteria - Tier 1: changes an obligation we're subject to, and has a date. - Tier 2: shifts supervisory expectations, no deadline. - Tier 3: directional, awareness only. If two people disagree, it's the higher tier until the committee says otherwise. ## 6. The extraction prompt Paste the primary source text, not a summary of it. --- You are helping a financial crime compliance team with horizon scanning. Extract ONLY what the document states. Do not infer, advise, or assess impact. Return these and nothing else: 1. issuing_body 2. date_published, as printed 3. instrument_type 4. jurisdictions_named 5. summary, 3 sentences max, plain English 6. obligations_created, each on its own line, quoting the operative wording. If none, write NONE. 7. dates_stated, every date and what it applies to 8. entities_in_scope 9. explicitly_excluded 10. uncertainty, anything you could not determine from the text If the document doesn't state something, write NOT STATED. Never fill a gap with background knowledge. --- Fields 9 and 10 matter most. A model that says NOT STATED is useful. A model that quietly fills gaps is a liability. ## 7. The weekly rhythm - Monday, 30 min. Collect, run the extraction, log the records. - Wednesday, 45 min. A human tiers everything, names an owner, writes the action line. This is the step you can't automate and the only one that really matters. - Friday, 20 min. Publish the brief. Under two hours a week. If it's taking longer, your scope is too wide. ## 8. The brief --- HORIZON BRIEF, week ending [date] ACTION REQUIRED [Tier 1: one line each. What changed, owner, due by] WATCH [Tier 2: one line each, owner named] NOTED [Tier 3: title and link] NOTHING THIS WEEK IN: [domains with no items] --- That last line is the one people skip and the one that builds trust. It's how silence reads as checked rather than forgotten. ## 9. Guardrails - The AI never assigns a tier and never writes the action line. - Every Tier 1 item is confirmed by a human against the source. - No item without a primary source URL and publication date. - Public documents only. Never paste customer or case data into an assistant that isn't approved for it. - Version the spec. If the tiering criteria change, say so in that week's brief. ## 10. What I'd do differently My first version had eleven domains and four jurisdictions we had no licence in. It collapsed in six weeks because the Wednesday triage became a two-hour job nobody wanted. Narrow it until the weekly ritual sits comfortably under two hours, then widen it only when somebody complains that something got missed.
KYB Triage reads a corporate pack, builds the ownership chain and tells you exactly what's missing from it. Runs locally so nothing leaves the laptop. It won't rate risk or approve anything, and that's on purpose.
Fuzzy-Match lets you throw the transliterations and reversed name orders that actually break screening at your own threshold, and see what 85% catches that 92% doesn't.
First 90 Days is the list of awkward questions that are much easier to ask in week one than in month six.
Twenty-four lessons across five modules. What financial crime is and who makes the rules, what to collect for every entity type, a real file worked end to end with the mistakes left in, how screening thresholds actually behave, and how to build a career out of it. Mostly things to click rather than things to read.
Start with module 1 → Modules 2–5Document matrix builder, a worked file, a screening threshold sandbox, and what actually gets you promoted.
Open → Interactive mapThirty components across three lines of defence, governance and the enablers underneath. KYC, AML, sanctions, Consumer Duty, horizon scanning, licensing, audit. Click any box for who owns it, what it looks like on day one against at scale, and how it usually fails. There is a toggle for what you genuinely need on day one, which is the question I get asked most.
Open the map →One on what a whole compliance operating model looks like. One on the free KYC course. Both under forty seconds, both with a link straight to the thing itself.
Governance on top, three lines holding it up, enablers underneath. Thirty components, and only five of them can wait until after day one.
Open the interactive map →Thresholds you move yourself, a document hunt, an ownership chain you unpick. Five modules, no sign-up, no email.
Three posts and one video a week. Building functions, getting licensed, and where AI actually helps rather than just sounding good.
Compliance should not be the reason nothing ships. A function that can only say no has failed at its job. The work is building one that can say yes quickly, for the right things, and evidence why.
If nobody owns it, it isn't a control. Pick one at random and ask who gets the call at 11pm. More than five seconds to answer and what you have is documentation.
Automate the triage, never the judgement. Most AI disappointment in this field comes from pointing it at the 20% instead of the 80%.
Design for the licence you want next. Retrofitting a framework for a new jurisdiction costs far more than building it to stretch in the first place.
Standing up a function, chasing a licence, or working out where AI actually fits? Or you think one of my specs is wrong. Either way, the useful messages tell me what broke.