How familiarity, institutional inertia and spreadsheet dependency create blind spots that expose organisations to regulatory, operational and strategic risk
Introduction: The most dangerous risk is the one you don’t see
Most organisations have no idea their financial crime risk assessment process is already failing them. It feels familiar, predictable and deceptively stable. Year after year, the same cycle repeats: spreadsheets circulate, contributors submit inputs, drafts are consolidated, and the Board receives a lengthy document that appears comprehensive. Nothing seems visibly wrong, until something goes very wrong. A regulatory review, an unexpected negative audit finding, or a strategic initiative that pushes the business into new territory suddenly reveals that the process the organisation trusted was never fit for purpose. Familiarity creates the illusion of safety, which when the stakes have never been higher is a risky game to play.
Routine masks fragility. Comfort becomes the most dangerous form of risk. This blog explores why organisations misjudge the health of their financial crime risk assessments and how leading institutions finally break free from the trap.
The illusion of competence: “it’s worked this way for years, so it must be fine”
One of the most powerful forces holding organisations back is simple inertia. Teams follow the same annual pattern because it is what they know, they don’t really have to think. Spreadsheets are gathered, contributors are chased, ratings are copied forward and the final document is assembled just in time for the Board meeting, which often involves ratification rather than robust challenge.
Because the financial crime risk assessment process can be completed, the organisation assumes it must be effective. But completion is not the same as competence. The ability to produce a document does not guarantee accuracy, consistency, defensibility or efficiency. It simply may mean that the organisation has learned to tolerate inefficiencies and paper over structural weaknesses.
The process becomes “institutional folklore”
In many institutions, the financial crime risk assessment process is not designed, it is inherited. People repeat steps because “that’s how we’ve always done it.” Spreadsheets become legacy artefacts passed from one MLRO to the next, accumulating outdated definitions, inconsistent logic and historical assumptions that no one remembers or challenges. The methodology fossilises over time. Control ratings remain unchanged because questioning them requires time and conflict. The financial crime risk assessment becomes ritualised – a tradition rather than a genuine attempt to understand exposure. Institutional folklore replaces methodological integrity.
Spreadsheet dependency hides systemic weaknesses
Spreadsheets create an appealing illusion of order. Rows, formulas, colours and scoring tables make the financial crime risk assessment look structured, even scientific. But beneath the surface, spreadsheets conceal fragility: broken formulas, undocumented assumptions, inconsistent logic, version conflicts, accidental overwrites, missing evidence and unauditable change histories. Executives never see this instability, they see tidy outputs that mask the chaos underneath. Boards, too, mistake the appearance of structure for actual governance.
Spreadsheet dependency is the most common and most dangerous, blind spot in financial crime risk management.
The annual cycle trap: why once-a-year financial crime risk assessments breed complacency
When risk is only assessed once a year, the assessment inevitably becomes disconnected from reality. Risk is dynamic – products evolve, customer behaviours shift, typologies emerge, threats escalate and controls strengthen or erode. But the financial crime risk assessment captures a single snapshot, then freezes it in time for twelve months. By the time the Board reads it, much of it may already be out of date. Annual processes produce stale insights, delayed responses and outdated assumptions. They guarantee misalignment between actual exposure and reported exposure.
Weak Board challenge allows problems to persist
Many Boards, overwhelmed with information and reliant on high-level summaries, are not equipped to interrogate the weaknesses hidden in spreadsheet-driven financial crime risk assessments. They assume controls operate as described, ratings are accurate and methodologies are consistent. They do not see the inconsistencies, governance gaps or fragility of the underlying process. Without meaningful Board challenge, the organisation unconsciously endorses a flawed system. Boards do not intentionally overlook weaknesses – they may simply lack domain expertise to ask the right questions or lack visibility into the true gaps.
Audit findings often arrive way too late
Internal audits are essential, but they are not continuous. They occur on cycles, every one to three years and often focus on narrow slices of the overall process. When audit findings do surface, they reveal problems that have been present for multiple financial crime risk assessment cycles. By then, outdated methodologies, inconsistent scoring and governance failures have become deeply embedded. Audits expose the past, not the present.
Staff know the process is weak, but feel unable or unempowered to fix It
Inside risk, compliance and financial crime teams, frustration is common. Many MLROs and risk practitioners privately acknowledge that the financial crime risk assessment process is brittle, the spreadsheets are fragile, the methodology inconsistent and the workload overwhelming. They know the process gets reperformed every year because nothing is structured for reuse. But without executive sponsorship and modern tooling, they feel powerless to drive the needed changes. This creates a culture of silent resignation, where everyone sees the weaknesses, but no one has the will or the authority to fix them.
What finally breaks the cycle: a trigger event
Most organisations modernise their financial crime risk assessment approach only when forced to. A regulator asks for evidence that cannot be produced. Audit uncovers inconsistencies, control deficiencies or understated residual risks. A spreadsheet formula breaks during consolidation and nobody understands how to fix it. A jurisdictional expansion reveals methodological gaps. A partner or product launch stalls because financial crime risk cannot be assessed quickly enough. A Board member demands real-time visibility that the existing process simply cannot deliver. There is no audit history on prior decisions made or the rationale behind these decisions. These events make staying in the collective comfort zone untenable. They expose the truth: the process was never “fine”, it was simply untested and when it was tested, it was found wanting.
Conclusion: The comfort zone is the most dangerous place for financial crime risk
Organisations do not cling to outdated processes because they reject progress; they do so because comfort hides risk. But modern financial crime threats are fast-moving, interdependent and unforgiving. The institutions that thrive are those that proactively challenge their assumptions, confront hidden weaknesses, engage Boards meaningfully and invest in financial crime risk assessment platforms that provide accuracy, defensibility and continuous risk visibility.
The comfort zone may feel safe, but it is the place where weaknesses grow unnoticed. Those who modernise early avoid the consequences. Those who stay comfortable eventually learn the hard way.