Breaking into financial crime compliance without a banking background
Most advice about breaking into financial crime tells you to get certified and network. That advice is not wrong, but it skips the part that actually decides the hire: whether you can reason on paper. This note is about what I look for when I open a CV from someone who has never worked in a bank, and how to build the evidence before anyone has paid you to have it.
I have hired analysts from retail management, teaching, law enforcement, casino floors, insurance claims, hospitality and one memorable case from air traffic control. The proportion of my teams who arrived with a banking CV has fallen steadily over about twenty years. That is not charity. It is because the job at analyst level is a reasoning job wearing a domain costume, and the domain can be taught in weeks while the reasoning cannot.
So the question is not really "how do I get into financial crime compliance with no experience". It is "how do I show a hiring manager that I already think the way the job requires, using material I can get hold of without a job". That is a solvable problem. Most candidates never attempt it.
What I am actually reading when I open your CV
I am reading for three things, and only one of them is on the qualifications line.
The first is whether you have ever had to write down a decision that someone else would be held to. A shift manager who documented a stock discrepancy, a nurse who wrote incident notes, a claims handler who set out why a payment was declined, a police officer who wrote statements — all of these people have done the core motion of the job. They have taken messy facts, decided what mattered, and committed it to a record that would be read by someone with different incentives. If your CV says "excellent communication skills" I learn nothing. If it says you wrote about forty incident reports a month and two of them went to a tribunal, I learn a great deal.
The second is whether you can hold ambiguity without collapsing it. Analysts who cannot do this either escalate everything, which floods the queue, or close everything, which is worse and quieter. In interview I probe this with a scenario that has no clean answer and watch whether the candidate reaches for more information or reaches for a verdict.
The third is whether you understand that an alert is arithmetic. A monitoring rule fired because a number crossed a line that a model owner drew. It is a question, not a finding about a person. Candidates who arrive talking about catching criminals worry me slightly. Candidates who arrive curious about why a rule was calibrated where it was do not.
Credentials come fourth. They are a filter for the recruitment screen, not a signal to the hiring manager. Understand that distinction and you will spend your money better.
Which certifications earn back their fee, and which do not
I will be direct, with the caveat that this is my read of the market and reasonable people disagree.
The generalist AML certification from a recognised body does earn its fee at entry level, for one specific reason: it gets your CV past automated and agency filters that are looking for a keyword. It does not make you employable. It makes you visible. If a certification costs you a few hundred pounds and moves you from the discard pile to the read pile, that is a return worth having. Do not expect it to change what happens in the interview room, because it will not — I have interviewed certified candidates who could not explain what a beneficial owner is and uncertified candidates who could reason through a three-layer holding structure on a whiteboard.
Sanctions-specific and fraud-specific certifications are a different proposition. I would not buy one before your first role. They pay off when you already know which specialism you want and you are trying to move sideways into it from a generalist seat, because at that point they are evidence of direction rather than evidence of enthusiasm.
The certifications I would not buy at all, at least not first: anything that is essentially a paid webinar with a badge, anything sold with urgency, and anything promising placement. Placement is not a thing anyone can sell you.
Free reading beats most paid training at this stage. The FATF recommendations and its mutual evaluation reports tell you how the standards are actually assessed country by country, which is more useful than any syllabus. In the UK, the JMLSG guidance is the closest thing to a practitioner's handbook and it is free. The Wolfsberg Group papers on correspondent banking and monitoring effectiveness will teach you more about how large institutions actually think than a certification module will.
Building demonstrable judgement before anyone has paid you for it
This is the part almost nobody does, and it is the part that works.
Judgement is demonstrated in writing. So write. Take a company registry — Companies House in the UK, the equivalent open registers elsewhere — pick a structure with three or four layers and offshore elements, and write two pages setting out who you believe the ultimate beneficial owner is, what your evidence is, where the chain goes dark, and what you would ask the customer. Then do it again with a different structure. That exercise is the whole of reading an ownership structure to find the beneficial owner, and it is available to you today for nothing.
Do the same with narrative writing. Take a published enforcement action or a court judgment with facts in it, and draft the suspicious activity report narrative that the institution should have written at the time. Nobody will grade it. That is fine. The point is that when I ask you in interview to walk me through how you would structure a narrative, you will have done it eleven times rather than zero. If you want a scaffold to work against, our note on how to write a SAR narrative takes a full example from alert to filed text.
Bring the artefacts to interview. Not as a portfolio in a folder, which reads as odd, but as material you can reference naturally. "I had a go at mapping a Cypriot holding chain last month and lost the trail at a nominee shareholder — how do your teams handle that?" is worth more than any line on a CV.
Case note
A composite from two hires I made at a payments firm. The candidate had spent six years managing a mid-sized letting agency and had no financial services experience at all. What she did have was a habit: over about four months, from roughly January to April, she had written up fourteen ownership structures pulled from open registers, each one two to three pages, each ending with an explicit statement of what she could not establish.
We hired her into a KYC refresh seat on £29,500 in a regional office. In her first quarter she cleared 312 periodic reviews against a team average of 280, which was unremarkable. What was not unremarkable: three of her escalations concerned entities where the registered activity and the account behaviour diverged — in one, a consultancy structure receiving eleven inbound payments totalling around £840,000 over five weeks against a stated annual turnover of £120,000. Two of the three progressed to reportable outcomes. Within eighteen months she was on £41,000 as an investigator. The habit, not the CV, is what did it.
The realistic entry routes
There are three doors that actually open, and one that mostly does not.
KYC refresh and periodic review is the most reliable entry point in the market. The work is high volume and process-heavy, which is exactly why teams hire from outside. You will be pulling documents, checking they match, chasing customers for updated information and building files. It teaches you what a good file looks like, and our note on what an EDD file should contain will make you unusually credible in the interview for one of these seats.
Outsourced providers and managed service firms hire in cohorts, often twenty or thirty at a time, and they hire on aptitude tests rather than background. The pay is lower and the work is narrower. I would still take it. Eighteen months at a provider working remediation gives you volume exposure that would take three years to accumulate in a small in-house team, and hiring managers know it.
Operations seats adjacent to compliance — payment investigations, chargebacks, customer due diligence support, complaints — are underrated. You are inside the institution, you can see the systems, and internal moves are dramatically easier than external ones. I have promoted more people from ops into financial crime than I have hired from the open market.
The door that mostly does not open: applying directly to investigator or analyst roles at a large bank with no experience and a fresh certification. Those roles are competitive, filled internally or via agency pipelines, and the screen is brutal. It is not impossible. It is a poor use of your first two hundred applications.
Money, candidly
Salary bands vary sharply by jurisdiction, city and firm type, so treat what follows as a shape rather than a promise, and note that these numbers move.
In the UK market as I have seen it recently, a KYC or refresh analyst outside London typically starts somewhere in the high twenties to mid thirties. London adds perhaps four to eight thousand. Outsourced providers sit below that, sometimes meaningfully. Transaction monitoring analyst roles tend to sit slightly above KYC refresh. Investigator and senior analyst roles, once you have two or three years and can write a narrative that survives review, move into the forties and low fifties. Sanctions specialists and financial crime systems people command more, because supply is genuinely tight.
The steep part of the curve is between year one and year three. That is where writing quality separates people. It is not where certifications separate people.
What to do in your first ninety days once you are in
Get fast at the mechanical parts so you have attention left for the thinking. Learn your firm's systems properly rather than well enough. Read closed cases — old ones, especially the escalations that were stood down, because the reasoning in a well-written no-further-action is often better than the reasoning in an escalation.
Ask what the rule was that fired your alert and what its false positive rate looks like. Most analysts never ask. The ones who do become the ones who get consulted when the model is tuned. Our transaction monitoring alert triage checklist is written for exactly this window.
And read your regulator's published work. In the UK the FCA publishes enforcement notices and thematic reviews that tell you plainly what supervisors found wanting; equivalents exist in most jurisdictions. Understanding what your supervisor thinks good looks like is a career skill, not a compliance chore.
Twenty years in, the analysts I remember are not the ones with the longest qualification strings. They are the ones whose files I could pick up cold, two years later, and understand without ringing anyone.
Bottom line: Nobody hires a certificate — they hire someone who can write down why they reached a conclusion, and you can start proving that this week.