ILLUSTRATIVE SAMPLE — synthetic data, fictional institution, for format demonstration only

AML/CFT Control Matrix

Harborview Financial Group — a fictional mid-size financial institution

Fictional institution · Assessment date 2026-06-10 · Context: examination readiness · Framework: 27-control reference, 6 domains

Program posture: PARTIALLY EFFECTIVE — transaction-monitoring domain drives the gap register
27Controls
6Domains
13Effective
8Partially Effective
2Ineffective
4Not Assessed
8Open Gaps
01 Executive Summary

Harborview Financial Group is a fictional mid-size financial institution invented to demonstrate the control matrix output format. The synthetic profile: retail and commercial banking, domestic wires and correspondent payments, no cash-intensive branch network, and a small digital-asset custody pilot launched in 2025. The matrix below inventories 27 controls across the six-domain reference framework — customer due diligence, transaction monitoring, sanctions screening, regulatory reporting, governance, and technology — in examination-readiness context.

In this illustrative scenario the program is structurally complete: every reference control exists in some form, and 13 of 27 rate EFFECTIVE on recent operating evidence. The weakness is concentrated, not pervasive. The transaction-monitoring domain carries both INEFFECTIVE ratings — rule tuning has not run since a 2024 system migration (TM-03) and no typology-to-rule coverage assessment exists (TM-05) — and the alert-disposition backlog (TM-02) compounds the exposure. Four controls rate NOT ASSESSED because no testing or operating evidence was available; under the matrix rules that is the honest rating, never an inferred one.

The gap register lists 8 gaps: 1 CRITICAL, 3 HIGH, 3 MEDIUM, 1 LOW. The CRITICAL gap (untuned monitoring thresholds on a live transaction population) is the remediation priority; the matrix is the inventory, the gap register is the action list.

Program Snapshot — Synthetic
Institution typeMid-size bank (fictional)
ProductsRetail, commercial, payments
Digital-asset exposureCustody pilot (2025)
Cash channelLimited — excluded
Assessment contextExamination readiness
Evidence basisProvided documentation only
Headline
Concentrated weakness in transaction monitoring
22 of 27 controls rate EFFECTIVE or PARTIALLY EFFECTIVE. Both INEFFECTIVE ratings and the CRITICAL gap sit in one domain.
Overall confidence
MODERATE
4 of 27 ratings rest on no operating evidence (NOT ASSESSED).
Controls rated on evidence
23/27
4 NOT ASSESSED
Preventive / Detective
15 / 12
Type mix across the matrix
Weakest domain
TM
2 of 5 controls INEFFECTIVE
Strongest domain
SAN
3 of 4 EFFECTIVE
Critical gaps
1
GAP-01 · 90-day horizon
Scope exclusions
2
Cash thresholds, trade finance
02 Effectiveness Overview

Effectiveness Mix

27 controls by rating. NOT ASSESSED means no evidence — never a guess.

Effectiveness by Domain

Stacked count of controls per domain. The transaction-monitoring bar carries both INEFFECTIVE ratings.

03 Control Inventory — 27 Controls

Type: PREV preventive · DET detective. Owners are roles, never named individuals. Testing method is one of inquiry / observation / inspection / re-performance.

IDControl objectiveMechanism (who / what / how often / evidence) TypeFrequencyOwner (role)TestingEffectiveness
04 Domain Coverage Summary
DomainControlsEffective PartiallyIneffective Not assessedCoverage read

Reading the Coverage Table

Coverage is structural completeness; effectiveness is operating reality. In this synthetic scenario every reference control exists, so the program would pass a checklist review — the table shows why that is not the same as passing an examination. Transaction monitoring has full structural coverage and the worst operating record in the matrix.

The digital-asset custody pilot expands TM and SAN expectations (wallet screening, on-chain monitoring). Those expansions are inventoried under TM-04 and SAN-04 rather than as new control IDs, and both carry gaps in the register.

Scope exclusions (stated, justified)
Cash-threshold controls — no material cash channel. Trade-finance controls — product not offered. Exclusions inventoried so an examiner sees a decision, not an omission.
05 Gap Register
Gap Severity Mix
Reading the register

Every gap ties to a control ID, carries exactly one severity, and names a remediation owner by role and a target horizon. The CRITICAL tag is reserved for absent-or-ineffective controls with material exposed risk — here, untuned monitoring on a live transaction population. "No gaps identified" would also be a valid, stated result; this scenario simply is not that.

Remediation Horizon
Within 90 daysGAP-01
Within 120 daysGAP-02 · GAP-03 · GAP-05
Within 180 daysGAP-04 · GAP-06 · GAP-07
Within 270 daysGAP-08
06 Scope, Method & Confidence

Method

01Scope the program from the description; state exclusions and why each is justified.
02Build the inventory against the 27-control, six-domain reference framework; state the final count.
03Specify all nine attributes per control — a control a tester cannot fail is rewritten until it can fail.
04Map provided documentation to the framework: matched / partial / absent.
05Rate effectiveness only where evidence exists; otherwise NOT ASSESSED.
06Log every gap with severity, remediation, role owner, and target horizon.

Assumptions & Gaps

A1Synthetic evidence base. Ratings assume the fictional testing results described in the scenario; in a live run every EFFECTIVE rating cites the test or operating evidence behind it.
A2Custody pilot scale. The digital-asset pilot is assumed immaterial by volume; if it scales, TM-04 and SAN-04 split into dedicated on-chain controls.
A3Four controls unassessed. TM-04, GOV-05, TECH-01, TECH-03 have no operating evidence in the scenario — rated NOT ASSESSED, not inferred.

Overall Confidence

MODERATE

23 of 27 ratings rest on (synthetic) testing or operating evidence; 4 rest on none and are flagged NOT ASSESSED. The inventory itself is complete against the reference framework, so structural confidence is high — effectiveness confidence is what caps the overall rating at MODERATE.

Scope note. Owners are roles, never people. All content is generic to a financial institution — no proprietary or institution-identifying detail.