01

Start with activities and jurisdictions

Map what the organization actually does, where customers and counterparties are located, and which entities perform each activity. Product labels are less useful than the underlying flow of funds, data, control, and value.

  • Document legal entities and operating regions
  • Map products, assets, counterparties, and transaction paths
  • Identify licensing, registration, reporting, and privacy triggers
02

Connect financial-crime controls

KYC, customer due diligence, sanctions screening, transaction monitoring, investigations, and regulatory reporting should share a common risk model. Fragmented tooling creates gaps precisely where risk crosses teams.

  • Use risk-based customer tiers
  • Define escalation and suspicious-activity workflows
  • Retain defensible evidence for decisions
03

Make governance operational

Policies become useful when ownership, approvals, thresholds, exceptions, and monitoring are embedded in day-to-day work. The same discipline should cover custody, smart contracts, listings, treasury activity, vendors, and incident response.

  • Assign accountable owners
  • Track exceptions and remediation
  • Report indicators to leadership