Skip to main content

The state of financial crime model risk management

Viki Styrbaek

The fight against financial crime is increasingly waged on a digital battlefield, where banks rely on sophisticated models as their primary line of defence. Over the past decade, banks and financial institutions across the Middle East have significantly accelerated their adoption of advanced Anti-Money Laundering (AML), fraud detection, sanctions screening, and transaction monitoring models.

This transformation has been driven by rapid digitalization, growing transaction volumes, increasingly sophisticated financial crime typologies, and heightened regulatory expectations. Regulators across the region, including the Central Bank of the UAE (CBUAE), Saudi Central Bank (SAMA), and other supervisory authorities have introduced comprehensive AML/CFT frameworks, governance requirements, and risk-based compliance expectations that encourage the use of advanced analytics, artificial intelligence, and machine learning in financial crime risk management.

As institutions continue to invest in these capabilities, the complexity and criticality of these models have increased substantially. However, alongside this progress, organizations face persistent challenges related to model governance, explainability, data quality, regulatory scrutiny, talent availability, and the effective validation and monitoring of increasingly sophisticated financial crime models. As reliance on these models grows, how effectively are financial institutions managing their inherent risks?

The findings point to a growing maturity of use and governance of models in Financial Crime across the board, however a closer look at the results for Financial Crime models reveals a landscape of nuanced challenges. It is a story of progress met with new complexities, shifting the focus from whether to govern Financial Crime models to how to do so effectively. As the sophistication of both criminal threats and defensive models accelerates, the survey’s finding signal a crucial moment for organizations to ensure their governance practices are not just current but fit for the future. The survey also reveals that while model usage and technical sophistication are accelerating, governance practices are struggling to keep pace, particularly for financial crime models.

The Path Forward

To bridge these gaps, institutions must move from simple inventory tracking to specialised Model Risk Management. The priority areas for MRM functions are investing in domain-specific specialists, designing sophisticated effectiveness metrics beyond basic alert ratios, and re-evaluating whether standard risk-tiering frameworks adequately capture financial crime exposures.
For insights into the survey results, you can read the survey report here.

To answer this, the Deloitte 2025 EMEA Model Risk Management (MRM) Survey provides a detailed snapshot of the industry's progress. Conducted between July and September 2025, the survey gathers insights from

87 banks

across Europe, the Middle East, and South Africa. The participants represent, roughly, an even split among large, medium, and small banks, offering a robust and balanced view of current practices across the sector.

A vast majority of banks (83%) apply the exact same risk-tiering methodology to financial crime models as they do to other models. While this “one-size-fits-all” approach provides enterprise-wide comparability, it often fails to account for unique financial crime dynamics, such as reputational risk, ethical bias, and rapidly evolving criminal tactics. 

A clear theme exists between large institutions (with balance sheets over EUR 100 billion) and their small, medium-sized peers. Over two-thirds of large banks incorporate financial crime models into their MRM frameworks and manage validations for up to 100+ models. In contrast, smaller banks face severe resource constraints; only about a third include these models in their frameworks, and many validate 15 or fewer models, if any at all. 

As institutions shift from rigid, rule-based systems to advanced Artificial Intelligence and Machine Learning models, new Model Risk Management challenges emerge. Large banks report significant friction surrounding technical complexity (22%), inherent AI/ML risks (20%), and rigid existing processes (17%). Regulators, such as the Bank of England under SS1/23, are increasingly demanding proportionate validation, while innovation-driven environment emphasise continuous effectiveness assessment and ongoing monitoring, along with addressing challenges such explainability and potential biases inherent in complex algorithms. 

Did you find this useful?

Thanks for your feedback