Guest article by Lea Hungerbühler
Compliance makes headlines when it fails. Are you prepared?
Compliance usually only attracts attention when something goes wrong – but by then, the consequences can be far-reaching. International business models, complex sanctions regulations, and new technologies such as artificial intelligence are fundamentally changing the requirements for compliance. Effective compliance now means much more than simply knowing the rules and ticking off controls. Lea Hungerbühler, program director for the CAS in International Compliance Management HWZ, explains why there is a need for professionals who can identify risks early on, use technology effectively, translate regulatory requirements into practical action, and foster dialogue about risks within an organization.
Knowledge · September 18, 2026
Compliance rarely makes headlines when it works. When it fails, however, the consequences can be significant: regulatory investigations, substantial fines, reputational damage – and, in extreme cases, even the loss of a company’s licence to operate.
Recent cases demonstrate just how high the stakes have become.
In August 2026, a large international bank headquartered in Switzerland was fined USD 125 million by the U.S. Financial Crimes Enforcement Network (FinCEN) for repeated violations of anti-money laundering requirements. According to the authorities, deficiencies included inadequate monitoring of more than USD 10 billion in foreign currency transactions as well as shortcomings in the due diligence applied to high-risk clients.
Closer to home, the case of a Swiss-based bank provides an even more striking example. In February 2026, the Swiss Financial Market Supervisory Authority FINMA announced that it had identified serious and systematic shortcomings relating to anti-money laundering obligations, organisational structures and risk management. The deficiencies included the bank’s handling of sanctioned clients and transactions involving frozen assets. Ultimately, FINMA withdrew the bank’s licence and ordered its liquidation.
Cases such as these raise an important question for companies and their compliance professionals: What does effective compliance actually require in practice today?
Compliance is no longer just about knowing the rules
For a long time, compliance was primarily associated with regulations, policies, controls and reporting obligations. These remain essential. But the role of the modern compliance professional has become considerably broader.
International business models, increasingly complex sanctions regimes, cross-border financial flows and rapidly developing technologies mean that compliance professionals must understand not only what the rules require, but also how risks emerge within an organisation.
You need to ask the right questions:
Are our controls actually detecting the risks they were designed to identify?
Do we understand who our customers and business partners really are?
Can our systems recognise unusual transactions?
How should we respond when technology develops faster than regulation?
And how do we create a culture in which employees raise concerns before they become regulatory problems?
Effective compliance therefore requires a combination of legal and regulatory knowledge, technological understanding, sound judgement and leadership.
Technology changes both the risks and the solutions
Technology is transforming compliance at remarkable speed. Artificial intelligence and data analytics can help organisations identify patterns and risks that would previously have been difficult to detect. Modern compliance tools can automate monitoring, support risk assessments and process vast amounts of information.
At the same time, these technologies create entirely new challenges. How can AI be used responsibly in compliance processes? How can organisations ensure that automated decisions remain explainable and auditable? What new risks arise when companies rely on algorithms, large datasets or third-party technology providers?
Tomorrow’s compliance professionals therefore need to understand technology from two perspectives: technology as a compliance risk and technology as a compliance tool.
Compliance is ultimately about people
Yet even the best compliance system cannot succeed through technology and regulation alone. Behind every policy, transaction, escalation and business decision are people.
Compliance professionals must therefore be able to communicate effectively with management, challenge decisions constructively and translate complex regulatory requirements into solutions that work in practice. Just as importantly, they need to understand the business they are advising and build relationships that allow compliance concerns to be raised early – before they develop into larger problems.
The latest enforcement cases are a reminder that compliance cannot be treated as a box-ticking exercise. Organisations need professionals who can recognise risks early, navigate increasingly complex regulatory environments, make effective use of technology and communicate confidently with stakeholders across the organisation.
Ultimately, effective compliance is not measured by the number of policies an organisation has in place. It is measured by whether those policies, systems and controls work when it matters.
For compliance professionals, this means continuously developing their expertise, challenging established approaches and learning from the experiences of others. Because in an environment where regulation, technology and business models are constantly evolving, standing still is itself a risk.
And while successful compliance may never make the headlines, it can help ensure that your organisation does not make them for the wrong reasons.
CAS International Compliance Management HWZ
The CAS International Compliance Management HWZ provides practical knowledge on key international compliance topics such as data protection, cyber security, ESG, and cross-border financial regulation. You will learn from internationally renowned experts.
Sources

