In 2023, Singaporean authorities uncovered a large-scale money laundering operation involving billions of dollars channelled through a network of businesses, including gambling establishments and online gaming platforms. The scheme demonstrated a high level of sophistication, using shell companies, layered ownership structures and complex financial transactions to obscure the origins and movement of illicit funds. Widely regarded as Singapore’s largest money laundering case, commonly referred to as the “Fujian gang” case, the incident sent shockwaves across Singapore’s corporate and financial ecosystem. Authorities seized more than SGD 3 billion in assets, while 10 individuals linked to Fujian, China were arrested, prosecuted, and convicted. (Refer to Appendix for Infographic.)

The case highlights a critical lesson for financial institutions: AML/CFT failures rarely arise from the absence of controls, but rather from weaknesses in how those controls are applied in practice. While policies, procedures and documentation may exist, they often fall short in effectively identifying complex ownership structures, evolving customer behaviour and risk patterns that require professional judgement rather than checklist compliance. In many instances, institutions have implemented the required processes, customer due diligence (CDD), screening, and transaction monitoring, but these controls are applied in a manner that prioritises procedural completion over substantive risk understanding.

As regulatory expectations continue to evolve, the focus has shifted from whether controls exist to whether they are effective. This distinction is critical. Firms are increasingly expected to demonstrate that their AML/CFT frameworks are capable of identifying complex ownership structures, challenging inconsistencies and responding decisively when risks emerge. The ability to transform information into meaningful judgement is now a defining characteristic of a strong control environment.

 

Addressing gaps in beneficial ownership understanding

Beneficial ownership remains one of the most challenging and vulnerable areas in AML/CFT. Criminals exploited layered entities, shell companies, and fragmented cross-border structures to obscure ownership and the movement of funds, while financial institutions have often failed to sufficiently challenge the commercial rationale of complex structures, verify source of wealth or connect risk indicators across related parties.

While most firms have formal processes to identify beneficial owners, the quality and depth of execution often varies. In practice, there remains a tendency to focus on formally documented parties, such as investors, directors, or authorised signatories, without fully understanding who ultimately owns, controls or benefits from the assets.

To strengthen this area, firms need to move beyond a document-driven approach and adopt a more substance-over-form mindset. This includes:

  • Assessing whether ownership structures are commercially reasonable
  • Challenging unusual or overly complex arrangements
  • Corroborating source of wealth and source of funds using independent evidence

Ultimately, the objective is not simply to “identify” beneficial ownership, but to understand it within the broader context of the customer's business activities and risk profile.

 

From identifying red flags to acting on them

Another recurring observation is that red flags are often identified, but not acted upon effectively. Warning signs such as unusual transaction volumes, rapid movement of funds, inconsistencies in customer profiles or reluctance to provide information may be recognised individually, yet not connected, escalated or investigated holistically.

This reflects a gap not in detection, but in aggregation, escalation, and decision-making.

A well-designed escalation framework should clearly define:

  • Trigger points for escalation, including potential and emerging risks
  • Responsibilities for review and decision-making
  • Timelines for investigation and resolution
  • Documentation standards supporting conclusions and outcomes

Without these elements, issues risk being addressed inconsistently or resolved at a superficial level. Conversely, a structured escalation process enables timely intervention, strengthens governance and provides a clear audit trail, an increasingly important expectation during regulatory reviews.

 

Enhancing training to build judgement

Training is another area where design and effectiveness often diverge. Many institutions have established AML/CFT training programmes. However, these often focus more on awareness rather than practical application. Staff may understand procedural requirements but lack the confidence and judgement needed to apply them in complex or ambiguous situations.

For AML/CFT frameworks to be truly effective, training must move beyond policy familiarisation and develop professional judgement, critical thinking and healthy scepticism. This is particularly important for personnel involved in onboarding, ongoing monitoring, and client-facing activities.

Institutions should therefore reassess how they measure training effectiveness. Rather than relying solely on completion rates, firms should consider:

  • Scenario-based assessments
  • Case study discussions
  • Targeted training for higher-risk functions
  • Practical testing using real-world situations to identify gaps and inconsistencies

The emphasis should be on whether staff can meaningfully apply regulatory requirements, rather than simply demonstrate awareness of them.

 

Clarifying accountability in delegated environments

In many operating models, particularly within fund structures, elements of onboarding and ongoing monitoring may be performed by third parties or group entities. While these arrangements can improve operational efficiency, they may also introduce potential gaps in accountability and oversight.

A fundamental principle remains that delegation does not transfer accountability.

The regulated entity remains ultimately responsible for ensuring that AML/CFT controls operate effectively, even where activities are performed by another party. This requires clear definition of roles and responsibilities, supported by robust oversight and review mechanisms over the AML/CFT measures undertaken by third parties or group entities.

Without these safeguards, fragmented processes can lead to fragmented risk visibility, increasing the likelihood that material issues go undetected.

 

From procedural compliance to effective risk management

The overarching lesson is that AML/CFT compliance should not be treated as a checklist exercise. While documentation and procedural consistency remain essential, they must be complemented by professional judgement, effective oversight, and a willingness to challenge assumptions.

Financial crime risks today are becoming increasingly sophisticated, often involving multi-jurisdictional structures, layered transactions and evolving customer behaviours. In this environment, controls that rely solely on static processes or formal documentation are unlikely to be sufficient.

Instead, firms should focus on building AML/CFT frameworks that are:

  • Dynamic – capable of adapting to changes in customer behaviour and emerging risks
  • Integrated – able to connect information across multiple control points
  • Accountable – supported by clear ownership and escalation pathways
  • Intelligence-driven – focused on understanding risk, not merely documenting it 

 

How RSM can help strengthen your AML/CFT framework

RSM helps organisations strengthen their AML/CFT frameworks through independent, risk-based assessments of the design and operating effectiveness of controls across the customer lifecycle.

Our reviews cover key areas including customer due diligence, beneficial ownership identification, source of wealth verification, transaction monitoring and escalation processes to identify gaps, inconsistencies and opportunities for improvement. Leveraging industry insights and evolving  regulatory expectations, we benchmark existing practices against leading standards and recommend practical enhancements to improve control effectiveness.

Beyond independent reviews, RSM also supports organisations in the development and implementation of AML/CFT frameworks, policies, procedures and controls that are tailored to their specific business activities, customer profiles, products, delivery channels and risk exposure. Drawing on our deep experience across the financial services sector, we work with organisations to establish practical and scalable AML/CFT processes that align with regulatory expectations while remaining operationally effective.

Our support includes the designing of customer risk assessment methodologies, customer onboarding and due diligence procedures, transaction monitoring frameworks, suspicious transaction reporting processes, governance structures and staff training programmes.

In addition, RSM performs targeted thematic reviews (e.g. high-risk clients, complex structures), assess training effectiveness, and performs end-to-end testing to ensure AML/CFT measures are not only documented but operating effectively.  
Through these services, organisations are better positioned to move beyond checklist-based compliance and build a more robust, intelligence-driven AML/CFT framework that strengthens governance, meets regulatory expectations and mitigates financial crime risks.

 

Conclusion

As regulatory expectations continue to evolve, the distinction between having controls and demonstrating their effectiveness will become increasingly important. Organisations that succeed will be those that move beyond procedural compliance and embed a thoughtful, risk-based approach throughout their AML/CFT frameworks.

Ultimately, the objective is not to implement more controls, but to implement better ones, supported by sound judgement, strong governance, and an organisational culture that prioritises substance over form.

Reach out to our specialist to learn how RSM can help strengthen your AML/CFT framework through practical, risk-based solutions tailored to your organisation.