HomeMethodology

Methodology

How the lab produces its results, what drives real decisions in your workspace, and where the limits are. Every weight, factor, threshold, band and default value below is imported directly from the module that computes it, not retyped, so this page cannot quietly drift from what the product does. Worked examples (e.g. a residual score of 45) are illustrative narrative, not module output.

Typology matching (no AI)

TypologyIQ scores every typology against your selections on four dimensions. Each dimension awards its full weight when any of your selections applies to that typology; there is no partial credit and no dilution for broadening your selection.

Firm type
30
Product
25
Customer
20
Risk theme
25

The four weights sum to 100. The "Why this matched" panel on a result shows exactly which of your selections contributed which points.

Screening control matching (no AI)

The Screening Designer matches your inputs to a screening control the same deterministic way, on three dimensions that sum to 100:

Category
50
Firm type
25
Trigger
25

Controls Maturity

Each control area is scored against a five-level maturity framework, from initial to optimised. Every level carries a fixed points value used to size the gap between where you are and where you are targeting, and to order the remediation actions that close it:

Initial
20
Developing
40
Defined
60
Managed
80
Optimised
100

Residual risk: how a control earns mitigation credit

Once a workspace has real controls with a coverage (full, partial or gap) and an effectiveness rating (strong, adequate, weak or not assessed), residual risk is inherent risk after crediting those controls, on a fixed factor table:

CoverageStrongAdequateWeakNot assessed
Full0.700.500.250
Partial0.450.300.150
Gap0000

Each cell is the fraction of inherent risk that control removes on its own. Full coverage at strong effectiveness is the single best a control can do (0.70), never full elimination by itself. A control that is reference-only, marked as a gap, or has never been tested ("not assessed") earns zero mitigation credit, no matter how much of the risk it claims to cover on paper: you cannot be credited for a control you have not actually proven.

Multiple controls compound with diminishing returns rather than adding up. Each control removes its share of whatever risk is still standing after the controls before it, not a share of the original inherent score, so a second and third control still help even after a strong first one, but the combined set can never reach zero. Once at least one control earns any mitigation credit, residual risk is floored at 5 rather than driven all the way down; a risk with no controls, or only gap or untested ones, keeps its raw inherent value exactly. The floor is itself capped by the inherent score (it can never lift a residual score above what the risk started at), so a very low inherent risk with a floored control is never artificially inflated past its own inherent value.

Risk appetite

A residual score is compared against two thresholds to produce a within, tolerated, or outside appetite result. The defaults are:

Tolerated from
40
Outside from
60

A workspace can override both thresholds; every assessment records which thresholds it was judged against.

At assessment level, the appetite result is judged against the single worst residual risk on the register (the maximum), not the average across every risk. A mean is also computed and shown for context, but it never decides the verdict: one severe risk puts the whole assessment outside appetite even if every other risk on the register is comfortably within it.

The residual rating shown alongside a score (low, medium, high, critical) comes from a separate band table used across the lab, not from these two appetite thresholds, and the two do not align: the bands sit at 25, 50 and 75, while appetite sits at 40 and 60. A residual score of 45, for example, rates "medium" on the band table while already being "tolerated" rather than "within" on the appetite result; a score of 65 rates "high" while being "outside" appetite. Treat the band as a general severity label and the appetite result as the actual governance verdict; the bands are:

Low Risk
0-24
Medium Risk
25-49
High Risk
50-74
Critical Risk
75+

Operational load

For a control with an expected monthly volume and an expected alert rate, operational load is worked forward through a fixed chain: volume and alert rate give alerts per month; alerts per month and handling minutes give analyst hours per month; analyst hours convert to headcount using a 160-hour full-time-equivalent month; and analyst hours multiplied by an hourly cost give a monthly cost. The default hourly cost, when none is supplied, is £35, an indicative UK compliance-analyst rate.

An assessment-level total sums the already-rounded per-control figures (each control's alerts, hours, headcount and cost are rounded to 2 decimal places before the sum), not the raw unrounded values, so the displayed total can differ from summing exact per-control figures yourself by a fraction of a cent or a minute.

Control testing

Testing a live control records a sample size split into passed, failed and partial results, plus any findings raised. The pass rate counts a partial sample as half a pass. That rate, combined with finding severity, decides both the test result and the effectiveness rating written back onto the control:

  • No samples recorded at all: not assessed.
  • Any high-severity finding, or a pass rate below 70%: fail, rated weak. A high-severity finding always forces a fail, regardless of how good the raw pass rate looks.
  • Pass rate at or above 90% with no medium or high-severity findings: pass, rated strong.
  • Otherwise: pass with findings, rated adequate.

The next test due date is derived by scanning the library control's free-text review cadence for every recognised cadence word (daily, weekly, monthly, bi-monthly, quarterly, semi-annually, annually, biennially, and their variants) and using the shortest interval found, the conservative choice when a control's stated cadence mixes more and less frequent language. Cadence text with no recognised word defaults to 12 months.

Cited to authoritative frameworks

Typologies, controls and KYC requirements map to primary sources. Every citation can be opened in place to read and copy the reference; the lab does not navigate you off-site. The standards used:

FATFFATF RecommendationsJMLSGJMLSG Guidance (current)WolfsbergWolfsberg Principles & StandardsOFSIOffice of Financial Sanctions ImplementationFCAFCA Financial Crime Guide (FCG)MLRUK Money Laundering Regulations 2017FinCENFinCEN CDD Rule (31 CFR 1010.230) & CIP (1020.220)EUEU AMLD5 (Dir. 2015/849) & AMLR (Reg. 2024/1624)BaFinGermany Geldwäschegesetz (GwG)ACPRFrance Code monétaire et financier (LCB-FT)AMFAMF guidance on client & beneficial-owner identificationMASMAS Notice 626 (AML/CFT, Banks)HKMAHK AMLO (Cap. 615) & HKMA AML/CFT GuidelineSFCSFC AML/CFT Guideline for Licensed Corporations

A bounded role for AI

Every score, match, weight, residual-risk figure, appetite result, operational-load number and test rating above is produced by the deterministic modules described on this page. AI is used only to write plain-English narrative summaries that accompany a result, for example the "Risk Intelligence" summary or a firm-research draft. It restates and explains a deterministic output; it never introduces a new fact or citation, and it never sets or changes a score, a rating, an appetite result or a test outcome. AI output is labelled as AI-assisted and is not legal advice; treat it as a starting point and verify against the cited sources. AI narratives can be slow, occasionally wrong in phrasing, or unavailable, none of which affects the numbers, because the numbers do not depend on AI at all.

How a decision is defensible

A workspace decision needs to be reconstructable later, not just correct today. Every live control is versioned: an edit bumps its version number and writes a snapshot to an append-only object_versions table, so you can see exactly what a control said at the time a decision referenced it, not just what it says now. Approvals and rejections are signed by a named workspace person, not an anonymous login, and can carry conditions with their own owner and due date. Every mutation also writes an audit_log entry recording what changed, when, and by which actor (a named person or the workspace itself). Together, this is the trail an assessment, a control change, or an incident can be defended against later: which control version was relied on, who approved it, under what conditions, and what evidence and actions followed.

Real enforcement data

The evidence and benchmark views draw on 44 real FCA enforcement cases from the public fines dataset (regactions.com / fcafines), each linked to its final notice. Where a case is annotated, the lab also shows the controls that would have caught the failure and lets you turn that lesson directly into a control change, an incident, a product risk assessment, or a follow-up action in your workspace. This data was last refreshed on 2026-06-04.

Limits

The lab is a design and education aid, not legal advice and not a substitute for your firm's own risk assessment. Coverage is broad but not exhaustive, regulation changes, and you should always verify against the cited primary source and your own policies before relying on an output. The scoring is deliberately simple and transparent rather than a black-box model; that is a design choice, not an oversight, because a number you cannot explain is not one you can defend.