Great art has never come from certainty. Neither, it turns out, does great compliance.
We had a list of questions prepared. We used almost none of them.
That, in a way, is the most honest way to introduce this conversation with Dirk Findeisen, Managing Partner at msg Rethink Compliance. We’d planned to talk about colour codes and technical frameworks. We ended up talking about Pop Art, an old German word for capability, and why modern compliance is less about designing the perfect framework than building an organisation that can continuously understand changing risk and act on it. Somewhere in between, a genuinely useful answer emerged to the question this whole series keeps circling: what does it actually mean to bring creativity into a discipline built on rules, control and caution?
A palette built for compliance
The Compliance exhibition inside this campaign is painted in calm turquoise, vibrant orange and earthy tones – control sitting right next to market intensity and real-world risk. It turned out to be a fitting place to start: Dirk’s answer to what that palette means for his day-to-day work doubled as his best short explanation of the job itself.
“Honestly, that palette is close to a job description. The turquoise is the part everyone assumes compliance is – controls, transparency, order. The orange and the earth tones are the part that never makes it onto a slide: constant, noisy, real-world risk that you’re managing fresh every day, not from a static model sitting on a shelf.”
Dirk FindeisenManaging Partner at msg Rethink Compliance
What he likes about the palette, he added, is that the colours sit next to each other rather than blending into one calm tone – which is, if anything, more honest than most compliance frameworks manage to be.
„Kunst“, „Können“, and a line borrowed from Sun Tzu
The obvious objection came next, and Dirk didn’t dodge it: compliance is, by design, the opposite of artistic license. It exists to constrain, not to improvise. Isn’t pairing it with “creativity” and “art” actually a contradiction in terms?
His answer started with the word itself, not an exception to it. “Kunst” – the German word for art – is closely associated with “können”, the ability to do something, rather than simply “wollen” – wanting to – he said. It’s a small distinction with a big consequence: art, in this sense, is not only about beautiful brushstrokes. It is about capability – whether an organisation can actually execute, at the pace regulation and risk now demand, with the resources, technology and data it actually has.
“Art, in this sense, isn’t about intentions. It’s about capability – whether you can actually execute the masterstroke you promised. Think about a craft that takes years to master. The point is not inspiration alone. It is the ability to reproduce quality under changing conditions. Compliance needs the same reputation – not as an idea people believe in, but as a capability organisations are actually good at.”
Dirk Findeisen
It’s not so different, he added, from what Sun Tzu meant when he called his own work “the art of war” – not a canvas, but the discipline of reading what is coming, understanding the environment and acting early. Applied to compliance: watching where regulation and risk are heading, and moving before implementation becomes unavoidable. Too many organisations, in his experience, still move only once the deadline has become the strategy.
In organisational terms, that increasingly means allowing technology – including AI – to support prioritisation, pattern recognition and next-best-action, while keeping accountability explicit. The objective is not to automate judgement away. It is to augment decision-making in a way that remains explainable, governable and proportionate, with human authority where it matters.
The capability you have to rebuild every morning
If there is a “masterpiece” in compliance, Dirk’s version of it is not a finished framework. It is the capability to keep the framework effective as the environment changes. Many compliance functions still work reactively: something unusual appears, gets investigated and is classified after the fact. The method itself is not the only problem; the shrinking clock is. Regulation, digital business models and financial crime are all moving faster, while simply adding headcount creates a cost curve few institutions can sustain indefinitely.
“The alternative is changing the system itself. Better data, smarter automation and targeted augmentation can move us from occasional snapshots towards continuous, risk-based review – without pretending that every decision should be automated.”
Dirk Findeisen
“Picture the old way,” Dirk said. “A queue of files, and someone opens them one at a time, days or weeks after the fact. Now picture a system that continuously reads signals across the portfolio, identifies what is actually unusual, and only then brings the relevant cases to a person. That is not simply a better queue. It is a different operating model.”
Strip away the metaphor, and this maps onto two important shifts. The first is a move from periodic snapshots towards entity-centric, perpetual risk understanding – a standing view of the customer, its relationships, behaviour and changing context. The second is convergence: not necessarily merging AML/CFT, fraud, sanctions and customer-risk teams, but connecting their data, signals, decisions and feedback so that the institution sees the risk pattern rather than isolated control events.

Find out more about "the art of modern banking"
A living system, not a finished painting
Asked whether this capability was something you build once, Dirk reached for a different art form: a living installation – something that only works while it is maintained, observed and adapted.
“It is more like a living installation. Unlike a painting, it has to be maintained and rebuilt every day, because the playing field, the risks and the rules keep shifting under it.”
Dirk Findeisen
It is a useful corrective to how compliance often gets discussed – as a system you implement and then leave running. Modern compliance has no meaningful finish line. Models drift, customer behaviour changes, regulations evolve and new typologies emerge. AI may accelerate the ability to see, to connect these changes and can help to build an adaptive risk model, but without trusted data, governance, traceability and accountability it can just as easily automate yesterday’s weaknesses faster.
What Pop Art gets right about scale
Away from the frameworks, Dirk’s own taste in art turned out to be Pop Art – Keith Haring specifically, with Roy Lichtenstein as a close second. But the more useful connection to compliance is not aesthetic. It is scale.
“Not everything Haring made landed equally well, but the level of abstraction, and how he played with colour, still gets me.”
Dirk Findeisen
Pop Art helped make art reproducible at scale through prints and repeated forms. That offers an interesting parallel for compliance: success is not one perfectly handled exception, but an approach that can remain effective across millions of customers, transactions and decisions without reducing every case to the same answer.
Scale, in other words, is not standardisation for its own sake. It is the ability to apply consistent principles while preserving enough context to make proportionate decisions. That is where data, automation and governance have to work together.
Global capability, local context
That question of context becomes even more important internationally. The principles of effective compliance may travel across markets, but implementation cannot simply be copied. Europe, the GCC, Africa and Asia-Pacific differ in regulation, infrastructure, data availability, customer behaviour and financial-crime exposure. A model that works in one market may fail in another for reasons that have little to do with the quality of the technology itself.
“For me, that is where global capability and local context have to meet. You need common standards, governance and technology that can scale – but you also need enough flexibility to understand the market you are actually operating in.”
Dirk Findeisen
Perhaps that is what the art of modern compliance ultimately means: not creating the perfect framework, eliminating uncertainty or automating every decision. It is building an organisation capable of continuously understanding changing risk – and acting on it effectively, proportionately and accountably. In compliance, as in any craft, the difference between intention and mastery is the ability to execute.
For compliance leaders: what to take from this
- Continuous beats periodic snapshots. Move towards entity-centric, perpetual risk understanding – while retaining periodic or sample-based controls where they remain appropriate.
- Converge, don’t simply consolidate. Connect data, signals, decisions and feedback across AML/CFT, fraud, sanctions and customer risk – without assuming every function must be merged.
- Let systems prioritise, keep accountability explicit. Decision-centric, augmented compliance uses machines for triage and next-best-action while people retain authority where judgement and accountability require it.
Go deeper on the frameworks behind this conversation – converged intelligence, entity-centric perpetual risk assessment, decision-centric augmented compliance and trustworthy AI – at msg Rethink Compliance.









