The dominant language in today’s Anti Money Laundering (AML) landscape is the language of quiet surrender. It sounds like pragmatism and data fluency. Give me variables, ratios, network metrics and I will build something that runs at scale. What is often presented as engineering discipline is, in reality, capitulation. It accepts the regulatory perimeter, misaligned incentives, and institutional mythology as fixed constraints and then optimises aggressively inside them.
This article was prompted by a recent proposal I made to an organisation to restructure a product’s business model in order to escape a level of regulatory scrutiny that was actively suppressing innovation, frustrating customers, and costing more in compliance overhead than the product generated in revenue. The default response was familiar. The organisation was already evaluating RegTech tools to make compliance cheaper, faster, and more defensible. The idea of changing the business model itself in order to avoid unnecessary regulatory exposure was initially treated as unconventional, even risky. Yet the moment an alternative was proposed, one that stepped outside the logic of compliance optimisation and addressed the regulatory perimeter itself, the effect was immediate. Conversations opened up, defensive assumptions were relaxed, and teams reengaged with the product as something that could be shaped rather than merely defended. That reaction is telling. It reveals how starved many organisations are for strategic intervention rather than incremental compliance engineering.
From Strategy to Feature Factory
In a healthy industry, strategic product management sits upstream of engineering and performance metrics. It begins with first order questions. What harms/problems are we actually trying to reduce? Where do those harms/problems materialise? What would a measurable reduction in harms/problems look like? It forces confrontation with law, policy, incentives, and business models before anyone opens a delivery ticket.
AML products almost never start there. Most are conceived not from observed crime behaviour they should disrupt, but from compliance obligations they must demonstrate to regulators and auditors. Strategic product thinking is displaced by a feature factory. Regulators and consultants define checklists. Banks translate those into internal control requirements. Former bank product managers at RegTech vendors harden those requirements into roadmaps that include alert engines, sanctions modules, KYC utilities, workflow layers, and explainability wrappers. The output is cheaper, faster, more defensible compliance. The input remains unchallenged.
Empirical work is unambiguous. The primary value proposition sold by RegTech vendors is not measurable disruption of economic crime. It is lower cost compliance, cleaner documentation, smoother regulatory examinations, reduced unit costs, and defensible audit trails. This is where strategic product management dies. Product vision is outsourced to regulators and risk committees, and product managers become delivery managers for specifications that were never theirs to define.
The Metrics Reflex
A familiar practitioner response follows. To convert ideas into code, something must be counted, ratioed, or scored. At scale, quantitative triage is unavoidable. Millions of customers and billions of transactions require prioritisation. But the reflex reveals what is missing.
There is rarely a pause to ask whether the organisation is structurally capable of disrupting money laundering at all, or whether risk based frameworks as implemented actively prevent that outcome. The discussion jumps straight to what can be calculated on the existing data pipeline. Engineering proceeds in a vacuum. Clever features are built for a problem that has never been properly scoped. A genuinely strategic product manager would stop the conversation and state plainly that the problem is not understood.
The evidence supports this critique. Traditional AML systems routinely generate false positive rates in excess of ninety percent. Compliance teams are overwhelmed by alerts tied to legitimate activity. The response is not to rethink detection models or incentive structures. Instead, dashboards are added, machine learning layers are wrapped around existing rules, and the result is branded as innovation. The underlying architecture remains intact. Incentives remain misaligned. Governance remains examination driven.
How RegTech and Consultants Captured Product Management
The global AML framework, shaped by FATF standards and national regulators, has entrenched an examination centric and deeply risk averse culture. Programmes are evaluated on whether they appear robust, not on whether they measurably reduce illicit activity. Board mandates collapse into alignment with guidance, avoidance of enforcement action, and benchmarking against peers.
RegTech and consulting have grown precisely to serve this demand. Its dominant worldview is relentlessly solution driven. Automate rules. Standardise data. Industrialise reporting. Declare success because compliance is faster, cheaper, and marketed as real time. Advanced analytics are deployed to optimise existing processes and make them more auditable, not to reimagine what effective disruption would require.
Within this ecosystem, the product manager’s role, particularly for those from banks, regulators, or consultancies, becomes narrowly operational, a path frequently dictated by circumstance rather than choice. Their mandate is constrained by commercial realities where a vendor challenging a bank’s core risk approach is a vendor that loses the sale, and by procurement and legal teams focused on liability and contractual safety. The role becomes: translate regulatory expectations into backlog items; assemble vendor capabilities into a defensible control stack; prove that the platform is risk-based and modern using the right vocabulary. This is not strategic product management. It is regulatory requirements engineering with a marketing layer.
The Strategic Questions That Are Avoided
If strategic product management existed in AML, product leaders would begin with a different set of questions grounded in harm reduction rather than institutional mythology. These questions do arise in internal debates, but the tragedy is that the intellectual energy they generate is almost always consumed by friction, rarely translating into vendor roadmaps or core redesign due to immense cost, risk, and inertia.
Take, for instance, the very questions that define a harm-reduction approach. The first and most fundamental “what harms are actually being targeted?” reveals an immediate disconnect. For example, trade finance is frequently cited by regulators as a hotspot for laundering risk. Yet evidence from banks suggests a different reality. Trade finance operations are often highly transparent, staffed by relationship managers, subject to layered documentation checks and sanctions screening, and viewed internally as unattractive to sophisticated criminals. Several major institutions conclude that there is little evidence trade finance is favoured by money launderers, yet regulatory pressure to automate and expand controls continues. Strategic product leadership would insist on defining target harms before building solutions.
The second question concerns incentives. Practitioners across banks and vendors openly acknowledge incentives that favour symbolic compliance. These include SAR volumes, documentation completeness, policy coverage, and peer comparison. They do not favour measurable crime disruption. A product manager whose career and vendor revenue depend on regulatory comfort is unlikely to propose a roadmap that destabilises this equilibrium. This conflict is well known and almost never addressed.
The third question is where to go beyond regulatory minimums. Regulators often default to prescriptive guidance. Banks adopt peer practice as an informal standard. Strategic product managers could treat regulatory expectations as a floor rather than a ceiling. Doing so would challenge both regulators and internal control functions. Former bank product managers (and those from the regulators themselves) are uniquely positioned to navigate this tension. In practice, they rarely attempt to do so.
What Strategic Product Management Would Actually Do
In many RegTech firms, senior product roles are held by individuals whose previous mandates were shaped by remediation plans, regulatory findings, and procurement processes rather than independent assessments of laundering risk. Their roadmaps, therefore, track regulatory change logs and alert metrics. Their influence rarely extends to the business side on the core banking product design, client selection, or pricing, despite intimate knowledge of where risk concentrates.
Strategic product management in AML would behave differently. It would reject briefs that exist purely for optics, such as requests to layer advanced analytics on top of unchanged rules in order to appear modern. It would engage regulators with evidence when expectations diverge from observed risk and work collectively to reorient guidance toward systemic harm. It would treat regulatory constraints as design problems rather than reasons to reproduce the same architecture with better interfaces. It would define success in terms of reduced illicit flows rather than compliance theatre, recognising that alert volumes, false positive rates, and audit outcomes are lagging indicators of structural failure.
The Uncomfortable Question
AML does not lack technological capabilities, engineers, data scientists, or vendors. It lacks strategic product managers who are willing and empowered to say that the industry is building the wrong things.
Former bank, regulator and consultant product managers now sit at the centre of the RegTech ecosystem. They understand how little impact legacy tooling had when they worked inside financial institutions. Yet they continue to rebuild the same systems with improved interfaces, more integrations, and stronger marketing narratives, a path often dictated by the market’s demand for regulatory appeasement over genuine crime detection.
The real question is not where the strategic product managers are. They exist, at least in title. The real question is why so many people in those roles choose to act as custodians of a failing compliance imaginary rather than architects of a different one.


Leave a comment