Knowledge Ridge

Financial Crime, Compliance and Investigations

Financial Crime, Compliance and Investigations

September 29, 2026 12 min read Financials
#Financial compliance, RegTech, cybersecurity
Financial Crime, Compliance and Investigations

Q1. Could you start by giving us a brief overview of your professional background, particularly focusing on your expertise in the industry?

I’ve spent over 40 years on the same problem, working out what actually happened, who was involved, and what it means for those who have to live with the outcome of the event in question.

My career began with 16 years as a Police Officer on a specialist Scotland Yard squad tackling organized vice crime, before becoming the lead investigator on the newly formed internet unit. The vice work involved covert investigations into organized coercion, international trafficking, and the money laundering and corruption that sat behind it. The internet work was genuinely pioneering - we were building investigative methodologies in real time, and several of the cases I led became stated cases that helped establish early UK precedent on issues such as jurisdiction and publication. That period taught me something that has shaped everything since: evidence in legal or regulatory proceedings is only as good as the rigor of the process that produced it.
I then moved into the private sector, spending 12 years in Technology Risk and Forensic Services at PwC in the UK, where I led complex multi-jurisdictional investigations, financial crime risk and compliance assessments, and anti-bribery and corruption work. I also built and ran my own information and corporate risk firm before relocating to the Middle East, where I led HSBC’s Group KYC Operations across MENA and Turkey, leading a team of over 140 people conducting complex due diligence investigations. I subsequently led EY’s Forensic Technology practice across the Middle East and served as Lead Regulatory and Investigations Advisor at Clyde & Co, the region’s largest international law firm.

Most recently, I led Deloitte’s Forensic practice in the Philippines, before founding MacNeal-LCB & Partners Inc. in 2024 - an investigations and strategic risk advisory firm based in Manila and operating across Southeast Asia. I am also co-founder of The Coalition of Cyber Investigators, a global think tank uniting leading experts to deliver cutting-edge research, Open-source Intelligence (OSINT), and investigations and cybercrime advisory services worldwide. My expertise spans AML, sanctions, KYC, bribery and corruption, fraud, human trafficking, cyber risk, and corporate malpractice. But my real strength is investigative: the discipline of establishing fact under pressure, in sensitive circumstances, across borders, to a standard that withstands regulatory, legal and boardroom scrutiny.

 

Q2. Which areas of financial crime and compliance are likely to see the fastest increase in technology spending over the next three to five years?

I’d expect the sharpest growth in four areas, and my reasoning comes from what I see going wrong in investigations rather than from vendor roadmaps.

Identity and Onboarding verification

Synthetic identity and document manipulation have become cheap and scalable. In investigations, this shows up late — you find that the counterparty who caused the loss was never who the file said they were, and the KYC record can’t be defended. That gap is expensive enough that firms will pay to close it upfront, particularly around liveness checks, document forensics, and detecting fabricated corporate identities.

Beneficial Ownership and Network Resolution

Sanctions evasion and corruption cases almost never turn on a single entity. They turn on layered structures across jurisdictions with weak registries. The manual work of untangling those layers is where investigation budgets get consumed. Anything that automates entity resolution and relationship mapping across corporate registries, litigation records, and open sources removes real cost and reduces the chance that the exposure is only found after the event.

Transaction Monitoring rebuilt around behavior rather than rules

Rules-based systems generate volume, not insight. I have reviewed too many alert backlogs where the case that mattered was buried under thousands that didn’t. Investment here will be less about new detection claims and more about triage, contextual scoring, and reducing the noise that exhausts investigative capacity.

Data governance, Forensic Readiness and Case Management

This is the least glamorous category and, in my view, the most underrated. When something serious happens, the first question is whether you can prove what happened with intact logs, preserved communications, defensible collection and a clear audit trail. Organizations that have not invested here discover the deficiency at the worst possible moment, usually with a regulator waiting.
Underlying all four is the same pressure: AI has widened the gap between the volume of information available and an organization’s ability to interpret it defensibly. Spending will follow that gap.

One caution. Detection technology is procured far more readily than investigative capability, and detection without the capacity to investigate credibly just produces documented risk you haven’t resolved. The firms that get value from this spending will be those that build the human judgment alongside it.

 

Q3. Where do you expect regulatory requirements around AML, sanctions, KYC and cyber risk to create the biggest increase in spending — and which types of companies stand to benefit most?

The largest increases will come where regulators have shifted from asking whether a control exists to asking whether an organization can prove how it reached a key decision to take one course of action instead of another. That shift is what drives cost, because proof is an evidential standard, not a policy statement.

Sanctions are the clearest example

Compliance expectations now extend well beyond screening a name against a list, into ownership and control analysis, circumvention risk, and third-party intermediaries. Meeting these demands requires not only diligent investigative work but also documenting it in a way that can withstand legal and regulatory scrutiny. In my experience, firms fail here not because they didn’t look, but because they cannot demonstrate how they looked, what they relied on, or why they reached their conclusions.

This is where professional investigative discipline is critical. For example, in high-consequence investigations, experienced investigators grade their intelligence and maintain a decision log. Grading forces an explicit judgment of the source's reliability and the confidence attached to the information, and the decision log records what was known at each point, what was decided, and why. Together they allow you to explain, months or years later, why one piece of intelligence was prioritized over another and why a particular line of enquiry was pursued or closed. Without that, you run the risk of reconstructing your reasoning from memory - and in front of a regulator or a court, that looks both weak and, frankly, unprofessional.

Beneficial ownership and KYC periodic reviews 

This will also continue to absorb heavy spending for the same reason. Data sources in many jurisdictions remain unreliable, so firms are increasingly supplementing them with OSINT. Through The Coalition of Cyber Investigators, I spend considerable time on the unresolved grey areas here: provenance, validation, contextual accuracy and admissibility. Collecting information is easy. Standing behind it under challenge is not - and ungraded, undocumented material rarely survives legal scrutiny.

The company with access to the best data sources usually benefits most. For example, entity resolution and corporate structure data providers; specialist screening and adverse media firms; multi-source OSINT platforms; investigations specialists; and managed service providers, who can deliver outsourced compliance services, particularly across Southeast Asia and other higher-risk corridors. Selecting a provider that can meet the evidential tests that I outlined earlier therefore becomes critical.

 

Q4. In distressed or turnaround situations, what integrity-risk patterns have you seen that create asymmetric alpha — or blow-up risk?

When a business gets into trouble, previously hidden problems tend to surface. While money is plentiful, poor behavior and weak controls are often absorbed and go unnoticed. However, when cash gets tight and spending is restricted, there is often nowhere left to hide problems.

In my experience, most turnaround specialists are not looking for this. Their focus, understandably, is on protecting creditors, reducing liabilities, and stabilizing cash. Integrity risk sits often outside that frame. Those who do factor it in tend to gain a real advantage. They often gain a clearer view of potentially material issues, which allows valuations and recovery assumptions to be built on something more realistic than the financial record alone.

Several patterns recur often enough for experienced investigators to treat them as red flags.

Revenue that depends on relationships rather than product

Disproportionate income concentrated through a small number of intermediaries, agents or consultants is one of the more reliable indicators of an underlying integrity problem.  When you follow the contracts and payments and examine the real ownership behind those counterparties, what was presented as useful business connections often turns out to be something more sinister. That is where deals often face blow-up risk, because bribery usually surfaces long after the money has changed hands.

Poor record-keeping usually comes before poor numbers

Classic examples include missing approvals, retrospective documentation, manual journal adjustments, communications migrating to personal devices or personal messaging apps. These are process red flags, not financial ones, and they are often present long before issues are identified – if you know where to look.

Concentration of authority is a further common scenario

For example, decision-making processes often narrow around one or two individuals, while oversight functions are weakened by cost reduction. This reduction in control and oversight creates the perfect opportunity for fraud and undisclosed related-party transactions. Turnaround specialists are not usually focused on identifying red flags of this nature,

Where the asymmetric alpha lies

Most diligence examines financial and legal records. Far fewer parties do investigative work such as structured OSINT inquiries, lawful human source inquiries, registry work, multi-jurisdictional litigation tracing, or analysis of who actually controls the counterparties. That gap in market practice is precisely where mispricing occurs, in both directions.

 

Q5. What is the most important takeaway you would give to industry experts and investors in 2026 about navigating financial-crime and cyber risk — and why does it matter?

If I had to reduce it to one point: the ability to establish and defend fact is becoming an increasingly scarce commodity.
To experienced investigators, the reason is clear. Generative AI has made fabricated documents, synthetic identities, manipulated media, and highly convincing false narratives cheap to produce at scale, while the volume of available information behind any decision has exploded. It is no longer difficult to find information about a counterparty, a transaction, or an incident. However, it is increasingly difficult to know which of it is true, where it came from, and whether it is capable of being verified so you can rely upon it.

There is a second, less discussed side to this. In the rush to adopt AI, organizations often deploy faster than they assess risk. This matters because the risks are significant and often inadequately considered: hallucinated output presented as fact, disinformation and misinformation absorbed into decision making, sensitive case data exposed through poorly governed tools, and increasing regulatory scrutiny of automated decisions that aren’t evidenced and therefore hard to justify.

I have seen compliance work compromised not by an adversary, but by an internal tool that produced confident, but unverifiable output which was then relied upon. In an evidential context, that can be fatal.

Provenance now matters as much as content

Intelligence that cannot be traced to a reliable source is not optimal. It’s graded intelligence underpinned by a record of decisions made that makes it usable. In legal or regulatory proceedings, when you are asked why you concluded what you did, and why you prioritized one line of inquiry over another, your best friend will be properly graded intelligence and a robustly documented decision log.

The wider point is this - regulators, courts and creditors have never rewarded good intentions -they test process and look for weaknesses in your position. AI has not changed that standard; it has simply added new layers of complexity that many companies are not considering yet.

For investors and advisors, the implication is the same in reverse: in a market where verification is becoming harder, those willing to do the disciplined investigative work will identify risk that others, relying on unverified information, will miss entirely. That is no longer just good practice. It is a genuine advantage.

 

 

Need an expert in this space?

Talk to an Industry Expert

Knowledge Ridge connects decision-makers with carefully vetted subject matter experts for one-on-one calls, research sprints, and advisory engagements — across 11 sectors and 163 sub-industries globally.


Comments

No comments yet. Be the first to comment!

Newsletter

Stay on top of the latest Expert Network Industry Tips, Trends and Best Practices through Knowledge Ridge Blog.

Our Core Services

Explore our key offerings designed to help businesses connect with the right experts and achieve impactful outcomes.

Expert Calls

Get first-hand insights via phone consultations from our global expert network.

Read more →

B2B Expert Surveys

Understand customer preferences through custom questionnaires.

Read more →

Expert Term Engagements

Hire experts to guide you on critical projects or assignments.

Read more →

Executive/Board Placements

Let us find the ideal strategic hire for your leadership needs.

Read more →