Double-Hatting in Financial Crime Compliance: Practical Reality or Governance Risk?
In South Africa’s financial crime compliance environment, many accountable institutions are trying to answer a practical question: how do we meet our Financial Intelligence Centre Act obligations when the same people are often responsible for multiple parts of the control environment?
This question is especially relevant for smaller accountable institutions, fintechs, crypto asset service providers, high-value goods dealers, estate agencies, legal practices, trust and company service providers, motor dealers, gambling businesses and other DNFBPs. It is also relevant for larger group-owned entities where compliance, legal, operations, procurement and internal audit responsibilities may sit partly at group level and partly at local entity level.
Double-hatting is common. Triple-hatting is not unusual. In many businesses, one person may be responsible for operations, customer onboarding, compliance coordination, suspicious activity escalation, policy maintenance and reporting to senior management.
This is not automatically inappropriate.
The issue is not whether one person performs more than one role. The issue is whether the combination creates an unmanaged conflict of interest, weakens independent challenge, or results in the same person effectively reviewing their own work.
Role combination is not the same as role conflict
There is an important distinction between role combination and role conflict.
Role combination may be practical where an institution has a simple business model, a limited number of staff, lower transaction complexity or access to external support. A small accountable institution may not have the resources to maintain separate first-line, second-line and third-line teams in the way a large bank would.
Role conflict arises when the same person or function is expected to perform responsibilities that should be separated, challenged or independently reviewed.
For example, concerns arise where the same person:
- accepts or approves a high-risk client;
- operates the customer due diligence control;
- approves exceptions or overrides;
- monitors compliance with the control;
- validates remediation; and
- reports independently to management or the governing body that the control environment is effective.
That is not proportionality. That is self-review risk.
In the South African context, accountable institutions are expected to develop, document, maintain and implement a risk management and compliance programme. That programme should not only describe policies and procedures. It should also reflect how responsibility, escalation, oversight and control execution work in practice.
When double-hatting may be acceptable
Some role combinations may be acceptable, provided they are deliberate, documented and supported by safeguards.
For example, a senior manager in a small DNFBP may act as the AML Compliance Officer, provided the person has sufficient competence and authority, and provided there is a clear escalation route to senior management or the governing body.
A group compliance function may support a subsidiary, provided local accountability is not lost. Group support can be helpful, but the local accountable institution must still understand and implement its own obligations.
Compliance may advise on high-risk customer matters, provided the business retains formal ownership of the customer relationship and the decision is properly documented.
Operations may perform onboarding controls, provided Compliance has the authority to monitor, challenge and escalate where weaknesses are identified.
The key is that the institution should be able to explain why the arrangement is appropriate and how independence concerns are mitigated.
When double-hatting requires safeguards
Some arrangements may be tolerable, but only if additional safeguards are in place.
This may include situations where an operations manager coordinates AML reporting, where Compliance temporarily assists with operational activity due to limited capacity, or where the AML Compliance Officer supports remediation activity.
These arrangements should not be left informal. They should be risk-assessed, approved and reviewed.
Possible safeguards include:
- documented role allocation;
- senior management or governing body approval;
- independent review of high-risk decisions;
- separate approval of exceptions;
- periodic external compliance review;
- group compliance oversight;
- internal audit involvement;
- independent validation of remediation;
- clear escalation routes outside the conflicted function.
Where a small institution does not have an internal audit function, it may need to consider an external independent review. Where a group-owned entity relies on group compliance or group internal audit, it should still confirm that the review is relevant to the local entity’s specific financial crime risk profile.
When double-hatting becomes difficult to defend
Some role combinations are difficult to defend because they compromise independence directly.
Examples include:
- Internal Audit designing AML controls and later auditing those same controls;
- Compliance operating all financial crime controls and then certifying their effectiveness;
- a commercial executive overriding sanctions, suspicious activity or high-risk customer escalations without independent review;
- the same person approving high-risk customers and monitoring whether high-risk customer controls are being followed;
- an external service provider designing the financial crime framework and then performing an “independent” review of its own work.
These arrangements create self-review risk. They also make it difficult for the institution to demonstrate effective oversight and assurance.
Why this matters for fintechs and DNFBPs
Fintechs and DNFBPs should not be assessed only by headcount or institutional label.
A fintech may have a small team but high transaction volumes, automated onboarding, cross-border exposure, vendor-managed systems and rapid customer growth. In that environment, financial crime governance needs to scale with risk, not just with staff numbers.
A DNFBP may also be more complex than its label suggests. A high-value goods dealer, motor group, property group, gambling operator, trust and company service provider or mining-related business may have significant exposure through high-value assets, politically exposed persons, procurement, third parties, beneficial ownership complexity, sanctions risk, bribery and corruption risk, or cross-border counterparties.
The question is not whether the entity looks like a bank. The question is whether its financial crime risk profile requires stronger oversight, clearer accountability and more independent review.
A practical role conflict test
Institutions should ask a simple set of questions:
- Does the same person create or accept the financial crime risk?
- Does the same person design or operate the control?
- Does the same person approve exceptions?
- Does the same person monitor compliance?
- Does the same person validate remediation?
- Does the same person report independently on effectiveness?
- Is there an escalation route outside that person’s authority?
- Has the arrangement been documented and approved?
- Has the arrangement been independently reviewed?
If the same person or function answers “yes” to too many of these questions, the institution should pause and assess whether it has moved from practical role combination into unmanaged role conflict.
The FCRMC view
Double-hatting is not automatically a governance failure. In many institutions, it is a practical reality.
The failure arises when role combination becomes role conflict, and the conflict is undocumented, unchallenged and unmitigated.
Proportionality may justify simplified structures. It does not justify informal accountability or self-review.
Institutions should be able to show who owns the risk, who operates the control, who challenges the business, who provides assurance, and how material issues are escalated.
FCRMC provides training on financial crime governance, AML/CFT/CPF obligations, role clarity, double-hatting, internal controls and the practical application of the lines of defence. Our training can be tailored for boards, executives, Compliance, AML Compliance Officers, Internal Audit, fintechs, DNFBPs and operational control owners.
Access to FCRMC’s full white paper on financial crime role clarity and the lines of defence can be granted by contacting us.
