Are AML and KYC creating blind spots for banks?

Are AML and KYC creating blind spots for banks?

Financial crime is becoming faster, more connected and increasingly difficult to detect through isolated compliance checks. As financial institutions add more AML, KYC, fraud and sanctions tools, experts warn that fragmented customer risk data could itself become vulnerable.

For years, financial institutions have responded to increasingly sophisticated financial crime by adding another control, another screening capability or another specialist platform.

KYC verifies identity, sanctions screening checks prohibited lists, transaction monitoring flags unusual activity and fraud teams investigate suspicious behaviour, while adverse media and ownership checks add further intelligence.

The individual components are rarely the problem. The difficulty lies between them.

A customer can pass identity verification at onboarding, clear sanctions screening and trigger no transaction monitoring alert, while the combined picture tells a very different story. Customer risk does not remain static. Ownership changes, behaviour shifts, new sanctions exposure emerges and transactions move across jurisdictions.

If those signals remain in separate systems, no single team necessarily sees the complete picture.

That disconnect is becoming more significant as criminal networks themselves become increasingly connected, moving between products, accounts, entities and jurisdictions without respecting the organisational boundaries that separate compliance functions.

Financial crime does not happen in silos, but compliance still often does. Criminal networks can exploit connections between customers, accounts, transactions, counterparties and jurisdictions that individual controls may not be designed to see.

Dr. Sebastian Hetzler, co-CEO at IMTF, said, “Financial crime has evolved beyond the silos that were built to detect it. Criminals do not operate within the boundaries of KYC, AML, sanctions or fraud departments, yet financial crime defences often remain fragmented along those same lines. The future of financial crime compliance is a connected risk picture where every relevant signal helps identify the patterns that siloed controls will inevitably miss.”

Where fragmentation creates the biggest blind spots

Michael Joseph, head of product strategy, Americas at Napier AI, believes fragmentation needs to be understood on several levels.

“Fragmentation has three layers, and they are not equally damaging. Organisational fragmentation — separate anti-money laundering (AML), fraud, sanctions and know your customer (KYC) teams with different mandates and performance measures — creates the blind spots criminal networks actually exploit, because those networks move across the domains our organisation charts separate.”

“Data fragmentation is more damaging still, because it is invisible: the same customer carries a different risk profile in the onboarding system, the screening system and the monitoring system, and no single function sees the composite. The most consistent blind spot we encounter is the gap between onboarding and behaviour, where a customer verified at account opening generates activity that never feeds back into their risk score. Regulatory fragmentation across jurisdictions is real and expensive, but it is a compliance overhead rather than a detection gap, and the two are often conflated,” Joseph said.

That gap between onboarding and ongoing behaviour is particularly important.

Traditional KYC processes can establish whether a customer is who they claim to be at a particular point in time. But the risk associated with that customer can change considerably afterwards. A new beneficial owner, unusual payment activity, exposure to a sanctioned entity or a sudden change in geography could all alter the risk profile.

Zurab Kotaria, co-founder and COO at Identomat, sees the customer journey as a key fault line.

“The biggest blind spots appear when different parts of the customer journey are assessed in isolation,” he said.

“A customer may pass identity verification at onboarding, but that does not mean their risk remains unchanged afterwards. New sanctions exposure, suspicious transaction activity, changes in ownership structures, unusual behaviour, or other risk signals can emerge later. If KYC, AML screening, transaction monitoring, fraud detection, and ongoing customer reviews operate in separate systems, those signals may never be connected quickly enough to reveal the full picture.”

This creates an important distinction between compliance completion and risk visibility. A firm can complete the required checks and still struggle to understand how the results interact.

Bradley Elliot, CEO at RelyComply, argues that organisational structures can make that problem worse.

“Existing organisational structures have not helped with this. Traditional compliance departments have independent AML, risk and fraud functions. That means customer data and workflows do not cross – even if they share similar trigger alerts. Strange customer payment behaviours could be missed or negated completely simply by landing into the ‘wrong’ team’s hands.”

The result can be both a detection problem and an efficiency problem, with fragmented workflows increasing false positives and creating additional manual work.

Elliot argues that this is particularly problematic given the way modern criminal networks operate.

“Modern crime today is expanding through organised networks able to share digital data in a flash. Fragmented KYC, AML, fraud and risk teams just do not stand up to the threat levels they are tasked with mitigating.”

For financial institutions, the challenge is therefore no longer simply whether each individual compliance function works effectively. It is whether those functions can work together quickly enough to identify risks that emerge between them.

AI needs connected data

Artificial intelligence is increasingly being positioned as a way to manage the growing volume and complexity of financial crime data. But across the five experts, there is a consistent warning: AI cannot solve a data problem that remains fundamentally fragmented.

Joey Padot, director, product development at ACA Group, said, “AI has a huge potential to make AML and KYC programs more effective, but only when it is supported by high-quality, connected data. If organisations are feeding fragmented or incomplete information into AI tools, the output will be fragmented as well.”

Joseph makes a similar point about the order in which firms should approach the technology.

“AI and better data integration can close much of this, but the order matters. Integration closes gaps; AI applied over unintegrated data does not. It produces confident conclusions from an incomplete picture, which is a worse position to defend than an obvious blind spot.”

The distinction is important. An AI model can process vast amounts of information at speed, but it cannot identify a relationship if the relevant data never reaches it.

The opportunity becomes greater when KYC, screening, transaction monitoring and fraud data can be connected. Joseph points to entity resolution and network analytics as areas where firms can identify relationships between customers, counterparties and accounts across jurisdictions that may remain invisible to individual compliance teams.

Padot said, “When data is integrated across onboarding, monitoring, screening, and customer reviews, AI can help identify patterns that would be difficult for analysts to spot manually. It can prioritise higher-risk alerts, streamline investigations, reduce false positives, and surface emerging risks more quickly. Equally important, it can help compliance teams focus their resources where they are needed most.”

That does not mean AI removes the need for experienced investigators.

“Organisations are finding the most success with AI when it complements, rather than replaces, human expertise. AI can rapidly analyse large volumes of data, identify patterns, and prioritise potential risks, but experienced compliance professionals are still essential for interpreting context, investigating complex scenarios, and making risk-based decisions.

“This human-in-the-loop approach combines the speed and scale of AI with the judgment and regulatory understanding that technology alone cannot provide, helping firms improve efficiency while maintaining the transparency, consistency, and accountability regulators expect,” Padot added.

For Andrew Davies, global head of financial crime compliance strategy at ComplyAdvantage, the same principle extends to explainability.

“Yes, but order matters. AI applied on top of fragmented data worsens the problem, as models trained on partial views give confident answers to incomplete questions. Integration has to come first, bringing screening, monitoring, and KYC data together or at least at the same time, so that models can analyse the whole customer rather than just part of their activity.”

Davies argues that firms also need to ensure AI does not become another silo.

“The caveat is that AI must not become the next silo. A model that closes data gaps but cannot show its reasoning just moves the blind spot from the data to the decision.”

That creates a dual requirement for firms: connect the underlying intelligence and ensure the technology used to analyse it can produce decisions that investigators and regulators can understand.

From periodic checks to continuous customer risk

The implications extend beyond technology architecture. A more connected approach could change how firms fundamentally assess customer risk.

Rather than treating onboarding, due diligence, sanctions screening, transaction monitoring and periodic reviews as separate compliance exercises, the customer could have one continuously evolving risk profile.

Padot said, “A unified approach starts with a single, continuously updated view of the customer. Rather than treating onboarding, due diligence, sanctions screening, and periodic reviews as separate compliance exercises, all of these activities contribute to a centralised risk profile.”

This moves customer risk away from a static assessment and towards a continuous process.

“In this model, risk assessments become dynamic instead of static. Changes in customer behavior, ownership structures, geography, or adverse media can automatically influence a customer’s risk rating and trigger additional review when necessary. Compliance teams can make decisions based on current information instead of relying solely on point-in-time assessments.”

Kotaria sees the future of KYC as a continuous assessment throughout the customer relationship.

“A unified approach would mean moving away from separate compliance checks and toward a continuous view of the customer throughout the entire relationship.”

The objective is not necessarily to increase scrutiny across the board. Instead, monitoring and verification can adapt to the evidence available.

“Instead of treating identity verification, AML screening, transaction monitoring, fraud prevention, and ongoing KYC as independent processes, firms should bring these signals together within a single risk framework. The level of verification or monitoring can then adapt based on the customer, their behaviour, and changes in their risk profile.”

Joseph describes this model as perpetual client risk assessment (pCRA).

“One risk score per customer, continuously recalculated from every available signal — KYC data, screening outcomes, payment behaviour, fraud events — and measured against segment-level behavioural baselines, so that “unusual” means unusual for that customer rather than unusual in the abstract.”

This contextual approach changes how firms can interpret alerts. A transaction does not necessarily need to be suspicious in isolation. It may become significant because it represents a sharp departure from a customer’s established behaviour, connects them to a higher-risk network or coincides with another change in their profile.

That requires compliance teams to move beyond the question of whether an individual alert has been triggered and towards whether the customer’s overall risk has changed.

Unification also strengthens the audit trail

The case for a more connected approach is not solely about detection. It is also about accountability.

Davies identifies three characteristics that should underpin a unified customer risk model: a single dynamic view of the customer, risk assessment as a continuum rather than an event, and end-to-end traceability.

The latter could become particularly important as regulators increasingly scrutinise firms’ use of technology and their ability to demonstrate how financial crime decisions are made.

Davies said, “Fragmentation used to be the price of adopting a best-of-breed approach. Now it’s the reason compliance teams struggle to answer a regulator’s simplest questions, including why we made this decision and what data the decision is based on.”

“Our research shows leaders have stopped accepting that trade-off; they don’t want ten systems each holding a piece of a customer’s risk data; they want one picture, one model they can explain, and one audit trail that holds up to regulatory scrutiny. That’s not a feature we added to ComplyAdvantage Mesh; it’s the reason Mesh exists as a single platform instead of another module bolted onto an already crowded stack,” he added.

The point is that a fragmented risk decision can be difficult to reconstruct.

If KYC information sits in one system, sanctions results in another and transaction activity in a third, a compliance team may need to piece together the rationale behind a decision after the fact.

A unified risk architecture can instead create a clearer record of what the firm knew, when it knew it and how that information influenced the decision.

Elliot believes firms can move towards this model without necessarily replacing their entire compliance infrastructure.

“AML integrations with RegTech providers ensures that existing frameworks and data can be pulled together, where any high-risk alerts are raised to the relevant parties for further investigation. In one dashboard view, this is all evidenced for supervisory audits: understanding who was accountable for checking automated alerts, and escalating them for due diligence or relevant reporting to authorities.”

He also sees AI as an increasingly important component of real-time decisioning.

“AI models are increasingly becoming a quality facilitator of this real-time decisioning. These can process vast volumes of incoming, instant transactional data (when connected to watchlists, adverse media, and UBO information) to inform analysts of any suspicious activity as it happens. A unified compliance team can continually work with continuously updated risk profiles, where gaps caused by reactive, periodic reviews become null and void.”

Closing the gaps between compliance functions

There is broad agreement among the experts that fragmentation has become a material challenge for financial crime compliance. But unification does not necessarily mean eliminating every specialist system or forcing every compliance function onto a single platform.

The more immediate requirement is connectivity.

Risk information needs to move across the customer lifecycle, allowing onboarding, screening, monitoring, fraud and ongoing reviews to contribute to a consistent understanding of the customer.

Padot said, “Making this approach work requires more than implementing new technology. Organisations need to align their data, processes, and governance so risk information can flow across the entire customer lifecycle. The goal is not simply to collect more data, but to connect the right data points in meaningful ways, giving compliance teams a more complete view of customer risk. When risk indicators are linked across onboarding, monitoring, screening, and ongoing reviews, firms are better positioned to identify emerging threats earlier, respond more effectively, and strengthen their overall financial crime compliance program.”

The central lesson is that adding another control, alert or AI model will not necessarily close the gaps created by fragmented compliance.

AI can provide scale. Integrated data can provide context. Human investigators can provide judgement.

But the effectiveness of all three depends on whether they are connected.

The strategic question for financial institutions is therefore no longer simply whether their AML and KYC frameworks are sophisticated enough. It is whether they are connected enough to see the risk hiding between them. As financial crime becomes faster, more networked and more adaptive, those gaps could become one of the most important compliance risks firms need to close.

Subscribe to FinTech Global’s newsletter for the strategic intelligence and early insight decision-makers need to navigate the evolving financial crime landscape.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.