How MyComplianceOffice is rethinking KYC

Daragh Tracey on KYC’s growing importance for financial crime compliance.

Financial crime prevention rarely collapses because one control fails. Problems tend to develop in the spaces between processes built for a slower regulatory environment. As financial institutions expand across jurisdictions and onboard customers at greater speed, the systems responsible for detecting who these customers are have come under increasing strain.

That pressure has pushed know your customer (KYC) from a compliance checkpoint into a central pillar of financial crime prevention.

The shift is reflected in the growing prominence of companies working to modernise compliance infrastructure, including MCO (MyComplianceOffice), which has been recognised in FinTech Global’s FinCrime50, highlighting firms shaping the future of financial crime technology.

For Daragh Tracey, Director of Product Management at MCO, the evolution of KYC reflects a broader shift in how financial institutions understand risk.

“Financial crime compliance has become a board-level problem because it’s no longer just about avoiding fines,” he says. “Weak controls can trigger enforcement actions, reputational damage, financial loss and operational disruption, particularly for firms trying to grow quickly or expand across jurisdictions.

“KYC sits at the centre because it anchors the rest of the program. Firms need to understand who they are doing business with, verify key data points such as beneficial ownership, geography, industry and PEP status, and maintain records that can withstand regulatory scrutiny.

“Regulators also expect KYC to operate across the full customer lifecycle rather than as a one-off onboarding step, particularly as risk signals evolve through adverse media, corporate structure updates and changing activity patterns.”

The operational challenge of continuous

KYC For many institutions, however, the shift toward lifecycle monitoring has exposed structural weaknesses in how KYC programs were originally designed.

Historically, KYC processes were built around periodic reviews, where customer files were revisited on a fixed schedule. That model becomes difficult when new information can emerge at any moment.

Tracey says the impact today lies in the gap between regulatory expectations and operational reality.

“The biggest challenge I see is that KYC has expanded from a checklist at onboarding into a continuous operating model, but many firms are still staffed, tooled and organised for periodic manual reviews,” he explains.

“That creates friction. Teams end up chasing alerts, repeating work across related entities and struggling to maintain a single current view of risk for the customer and their network.

“Regulators and customers expect institutions to react instantly to bad actors. If a criminal organisation launders funds through an institution, it becomes a scandal, and nobody will accept that the next periodic review was still weeks away. Risk signals must be constantly monitored and actioned quickly, which requires a transformation in KYC automation.”

Operating across jurisdictions adds further complexity.

“Different rules across countries make it difficult to standardise KYC processes globally, and that lack of harmonisation can create gaps criminals exploit,” Tracey says.

“At the same time firms are managing more data sources, more counterparties and faster-moving risk signals while still needing to evidence decisions through reporting and maintain a defensible audit trail.”

In practice, those pressures surface in three areas.

“First is automated flexibility, meaning the ability to support different regulatory regimes within a single process. “Second is signal versus noise. Firms need to minimise false positives while improving identification of genuine risk.

“Third is lifecycle coverage, keeping profiles current from onboarding through trigger events, periodic reviews and ultimately offboarding.”

The limits of static compliance models

Many institutions have attempted to respond by increasing the frequency of screening checks. Tracey believes that approach often misses the underlying design problem.

“A lot of traditional KYC is still fundamentally static,” he says. “One example is firms running daily sanctions or PEP checks and calling that perpetual KYC.

“The difficulty is that this approach can generate duplication across related entities, create too many false positives and still provide an incomplete view of risk because it does not incorporate the broader signals that change a customer profile over time.”

Attempts to introduce continuous monitoring without restructuring workflows can produce new operational burdens.

“When firms try to move to continuous monitoring without the right framework they often end up with more alerts, more fragmented data and more strain on under-resourced teams,” Tracey says.

“The objective should not be more monitoring. The objective is to identify the changes that genuinely alter the risk profile, escalate them appropriately and tie them back to a defensible workflow.”

KYC therefore needs to operate as a lifecycle process.

“It should evolve from a point-in-time identity check into an ongoing discipline that updates risk as customer behaviour and related activity change.”

Building a unified compliance platform

MCO’s response to this challenge has focused on the architecture behind compliance systems. Many institutions rely on separate tools to manage different regulatory responsibilities, which can create fragmented data and duplicated workflows.

Tracey says the company’s platform was designed to bring those processes together.

“The core advantage of MCO’s approach is that compliance is managed most effectively on a single integrated platform rather than across multiple disconnected systems,” he explains.

“In many organisations compliance data and workflows are fragmented across tools for employees, transactions, customers, third parties and regulatory obligations. That fragmentation increases operational complexity and makes it harder to maintain consistent controls or produce defensible evidence for regulators.”

MCO’s platform is built around a shared architecture and data model.

“All products operate on the same underlying architecture, so firms can manage employee compliance, communications surveillance, transaction monitoring, third-party risk and governance within the same system.”

Within that environment, KYC is treated as a lifecycle process rather than a series of separate activities.

“Our approach is to manage KYC from onboarding and screening through risk assessment, periodic reviews and event-driven updates within one connected workflow,” Tracey says.

“When those elements operate inside one system firms are better positioned to identify meaningful changes in risk and maintain a clear audit trail.”

The future of KYC

Looking ahead, Tracey expects financial crime prevention to continue moving toward continuous monitoring supported by structured workflows.

“The direction of travel is already clear,” he says. “Firms are moving away from treating KYC as a static point-intime exercise and toward models that support ongoing assessment across the full customer lifecycle.”

He believes the key challenge will be improving how institutions interpret risk signals rather than increasing the number of checks performed.

“Too often firms equate progress with running sanctions or PEP checks more frequently,” Tracey says. “That tends to increase alert volumes without improving the understanding of risk.

“The expectation is shifting toward understanding how risk changes over time and being able to evidence why and when action was taken.”

From a product perspective, MCO’s focus remains on strengthening the operational foundations that allow institutions to manage KYC processes at scale, including integrating AI-driven capabilities to enhance efficiency, accuracy, and decision-making.

“Our goal is not to add more checks,” Tracey says. “It is to make KYC and third-party risk processes workable at scale through structured workflows that support escalation, review and documentation as risk evolves.”

MCO was recently named in this year’s FinCrimeTech50, which identifies the companies leading tech companies fighting money laundering, fraud and financial crime in financial services. The full FinCrimeTech50, including profiles on each company, can be found here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.