Insights & Opinions

From Compliance to Financial Crime Fighting: How AMLA, Data and AI Are Reshaping the Compliance Function

Tue, 11 Aug 2026

assets/site/Andrew-Vorster-sq.jpg
Andrew Vorster Head of Growth The Banking Scene

From compliance to financial crime fighting featured

European banks are entering a new phase in the fight against financial crime. The arrival of the EU Anti-Money Laundering Authority, AMLA, a more harmonised regulatory framework, growing sanctions obligations and rapid advances in artificial intelligence are changing not only what compliance teams are expected to do, but how they do it.

On our Fraud and Compliance stage at The Banking Scene Conference 2026 Brussels, two keynotes followed by a panel discussion explored what this transition means in practice. The recurring message was that the next chapter of compliance will not be defined simply by more regulation. It will be shaped by a move towards greater consistency, better use of data, demonstrable effectiveness and a closer connection between regulation and the underlying purpose of fighting financial crime.

AML compliance is becoming more harmonised, but not less risk-based

Opening the Fraud and Compliance stage, Wendy de Meyer, Deputy Chief Compliance Officer at Belfius, focused on the scale of change now confronting compliance functions.

For institutions accustomed to navigating different national interpretations of European AML requirements, one of the most significant developments is the move towards a more harmonised European framework. The intention is to create greater consistency across the EU while retaining a risk-based approach.

That distinction matters.

Wendy argued that harmonisation does not mean that every institution will approach every risk identically. Risk criteria, customer segmentation and institutional judgement remain important. What changes is the framework within which those decisions are made. Requirements are becoming more explicit and granular, reducing the space for substantially different interpretations of the same underlying rules.

Customer due diligence, or CDD, illustrates the shift.

Institutions will need to recertify customers more systematically, rather than concentrating primarily on higher-risk categories. The number of data points collected is also set to increase substantially. For banks, the operational challenge will therefore be considerable, particularly when regulatory technical standards are still evolving while implementation deadlines are already approaching.

Yet Wendy challenged the idea that this should be viewed purely as an administrative burden. Better customer data can strengthen an institution’s understanding of its risks and provide a more reliable basis for decision-making.

The same applies to the business-wide risk assessment.

Data collection can easily be perceived internally as a compliance exercise undertaken to satisfy a template. Wendy’s argument was that its real value is much greater. Accurate, institution-specific data is what allows banks to understand where their risks actually sit and to determine appropriate mitigating measures.

In other words, data is becoming the foundation of the risk-based approach.

Sanctions compliance moves further into the spotlight

Wendy also highlighted a growing focus on sanctions and embargoes.

European guidance is becoming increasingly explicit about issues such as sanctions circumvention, governance, documented decision-making and the effectiveness of controls. The development also strengthens the position of sanctions compliance as a discipline alongside AML rather than simply a subset of it.

The growing prominence of the sanctions compliance officer reflects this evolution.

Institutions need to be able not only to demonstrate that policies, governance and screening processes exist, but that they work. This becomes particularly demanding as instant payments accelerate transaction speeds and geopolitical developments produce increasingly complex sanctions requirements.

For banks, the challenge is therefore both regulatory and technological. They must identify genuine risks quickly while limiting unnecessary intervention and false positives that damage the customer experience.

AMLA changes the architecture of European supervision

Charlotte le Beau de Hemricourt, Seconded National Expert at AMLA, The EU Anti-Money Laundering Authority, then placed these regulatory developments within the wider transformation being driven by AMLA.

The rationale for the new authority is rooted in a structural weakness of the previous European AML framework. Directives were implemented through national legislation, producing different interpretations across 27 member states. Cross-border institutions consequently faced variations not only in rules but also in supervisory practices.

Financial crime, meanwhile, has become increasingly cross-border, fast-moving and sophisticated.

AMLA is intended to address those weaknesses by bringing policy, supervision and financial intelligence closer together within a European system.

The authority will directly supervise 40 high-risk cross-border groups from 2028. However, its impact will extend much further. Most institutions will remain under national supervision, but AMLA will influence how those national supervisors operate through common methodologies and oversight.

For eligible organisations, the impact begins earlier. A data-driven selection process will require institutions to provide a significant volume of information through their national supervisors before direct supervision begins.

Charlotte’s message to institutions was therefore clear: engagement cannot wait until 2028.

AMLA is developing a large number of policy mandates and institutions have opportunities to contribute through consultations, hearings and stakeholder engagement. Evidence-based feedback, supported by facts, figures and practical alternatives, is more likely to influence the emerging framework than general objections to cost or complexity.

The next chapter of compliance is about effectiveness

We then convened a panel session with the title “Financial Crime, Regulation and Relevance: Writing the Next Chapter for Compliance”, which was moderated by Wendy, who was joined on stage by Charlotte, along with Daniël Meel, Head of Innovation and Design - Detecting Financial Crime, ABN AMRO, Marie-France de Pover, General Manager, Director Group Compliance, KBC Group and Anton Wilsens, Managing Partner, Kyndryl.

The panel opened with a deceptively simple question: what defines the next chapter for compliance?

Marie-France described it as “an evolution, not a revolution”.

Charlotte pointed to the shift from fragmented national approaches towards an integrated, risk-based European framework focused on effectiveness.

Daniël similarly contrasted a compliance environment where institutions demonstrate that controls exist with one where they demonstrate that those controls are effective.

Anton added another dimension: the move from reactive compliance towards proactive, risk-based and continuous compliance.

Together, these perspectives captured perhaps the strongest theme of the discussion: the future of compliance is increasingly about outcomes rather than activity.

That presents institutions with a harder question than whether a control has been implemented. They must be able to show that it actually reduces risk.

Data will determine how effectively banks can respond

Data appeared repeatedly throughout both keynotes and the panel, and for good reason.

For institutions potentially falling within AMLA’s direct supervisory perimeter, data will determine the selection process. For customer due diligence, more extensive and regularly refreshed data will underpin risk assessments. For AI, data quality will ultimately influence the quality of automated decisions.

Marie-France noted that the operational consequences should not be underestimated. IT development is expensive, time-consuming and difficult to plan when some technical standards are still evolving.

There is also a customer dimension.

Not all required information will be available automatically. Banks will therefore need customers to provide additional data and, critically, understand why they are being asked for it.

Anton argued that this creates a broader challenge around data ownership. Information remains fragmented across many institutions, limiting their ability to develop an integrated view of customers and financial crime risks.

The objective should be to make compliance processes as easy as possible for legitimate customers while reserving intervention for situations where information is missing, contradictory or genuinely raises concerns.

Compliance transformation cannot be separated from digital transformation

Daniël widened the discussion beyond regulation itself.

Banks are not implementing the EU AML package in isolation. At the same time, they are adapting to digital identity, digital wallets, AI agents and other technologies that will fundamentally alter financial services.

The result, he argued, requires something more ambitious than adapting individual controls. Banks need to reconsider financial crime processes end to end.

This has significant implications for the workforce.

AI may increasingly generate analysis that employees previously produced themselves. Human roles will consequently shift towards assessing outputs, investigating exceptions and exercising judgement rather than completing every step of a process manually.

Daniël also raised a particularly significant question for customer due diligence: how much should banks continue to trust documents?

Generative AI has made sophisticated document creation and manipulation dramatically easier. If documents themselves can no longer always provide reliable evidence, banks may increasingly need to access information directly from trusted external sources, with the customer providing consent rather than supplying documents.

Such a shift would have major consequences for both banking processes and regulation.

AI needs human oversight, not blind trust

Despite the enthusiasm around automation, the panel strongly rejected the idea that compliance can simply be handed over to machines.

Marie-France argued that institutions should first review their processes before introducing AI. Automating an inefficient process does little to improve the underlying outcome.

The sequence should therefore be: process improvement, automation where appropriate, and then careful application of AI.

Human judgement remains essential.

Depending on whether institutions use traditional machine learning, generative AI or agentic AI, human involvement may occur at different points. But the responsibility to understand, challenge and control automated decisions does not disappear.

Anton emphasised explainability as part of this requirement. Banks need to understand why systems reach particular decisions, especially when the outcome affects a customer. Financial institutions cannot simply tell somebody that a model rejected a transaction without being able to explain the reasoning.

The compliance professional of the future may therefore spend less time performing repetitive controls and more time overseeing technology, analysing risk and questioning whether automated outcomes make sense.

Customer experience must remain part of financial crime prevention

The customer emerged as another recurring theme.

As regulations become more demanding, banks face a difficult balance. They need stronger controls without creating an increasingly frustrating experience for legitimate customers.

Sanctions screening illustrates the problem particularly clearly.

Because sanctions controls often operate before a transaction is completed, ineffective screening can result in legitimate payments being unnecessarily blocked. Thousands of false positives are not simply an operational inefficiency. They undermine the relationship between the bank and its customers.

The answer is not weaker controls. It is better controls.

That means bringing together higher-quality data, more sophisticated technology and appropriate human judgement so that banks become better at identifying genuine financial crime while reducing unnecessary intervention.

It also requires communication.

Customers are more likely to accept questions when they understand why information is required and can see that the institution has already used available, trusted sources before approaching them.

Harmonisation does not mean the end of national differences

AMLA promises greater supervisory convergence, but the panel was realistic about its limits.

Charlotte acknowledged that national differences will remain. AMLA has a clear mandate to drive convergence and is developing methodologies that should accelerate the process, but different supervisory histories, legal environments and practices will not disappear overnight.

Daniël pointed to the Netherlands as an example, where established approaches to reporting unusual transactions differ from practices elsewhere.

For international banking groups, the familiar model of a common group standard supplemented by local requirements is therefore unlikely to disappear completely.

What should change is the degree of divergence between jurisdictions and supervisors.

The private sector also has a role to play. Charlotte argued that banks and other obliged entities can actively push for greater convergence when greater consistency benefits both regulatory effectiveness and operational efficiency.

Sanctions controls need to become smarter, not simply stricter

Returning to sanctions, Marie-France highlighted the difference between relatively straightforward embargo programmes and the much greater complexity associated with geopolitical developments involving countries such as Russia and Iran.

Circumvention, indirect economic links and increasingly sophisticated attempts to evade restrictions make detection difficult.

Again, the risk is that institutions respond through large volumes of alerts and blocked transactions.

Better systems can reduce false positives, but technology alone is insufficient. Anton argued that successful implementation depends on employees understanding why tools and processes are changing and how to work with them.

The regulatory shift towards outcomes therefore requires a corresponding cultural shift inside financial institutions.

Compliance professionals could become financial crime fighters

Perhaps the most interesting reframing of the discussion came when Anton asked whether “compliance officer” still accurately describes the purpose of the role.

He suggested thinking instead in terms of financial crime fighters.

The distinction is more than semantic.

Compliance with regulation is a means to an end. The purpose is to protect customers, institutions and society from financial crime.

Viewing compliance through that lens could also help the profession evolve.

Future teams will require regulatory expertise, but increasingly also data analysts, technology specialists and people capable of understanding and challenging AI systems. Marie-France similarly highlighted the need for broader skill sets alongside the traditional legal, audit and compliance background.

No single individual will possess every capability. Diverse teams will therefore become increasingly important.

A more disciplined risk-based approach

The discussion ultimately returned to the principle at the centre of European AML regulation: the risk-based approach.

Marie-France raised an important concern. Harmonisation and risk-based decision-making can sometimes appear contradictory because the risk-based approach has historically been interpreted too loosely.

Charlotte rejected the idea that risk-based means institutions can simply choose whichever approach suits them.

Future European methodologies should provide a more consistent foundation for risk assessment while still allowing institutions to respond appropriately to their own exposures.

That may be the clearest way to understand the next chapter of compliance.

European regulation is becoming more harmonised, more data-driven and more prescriptive in several areas. At the same time, institutions are still expected to exercise judgement, identify their specific risks and demonstrate that their controls are effective.

For banks and fintechs, the task ahead is therefore not simply to comply with a new set of AML rules.

It is to build a financial crime framework capable of combining regulation, data, technology and human judgement in a way that protects customers and society while remaining workable for the institution itself.

That is a considerably more demanding ambition than ticking a box. It also creates an opportunity for compliance to demonstrate its relevance more clearly than ever.


In case you missed it, you can find more fraud and financial crime fighting insights from industry leaders in our white paper "Fraud Prevention in a Real-Time Economy".

The Banking Scene: Director's Cut

There was a LOT to unpack in this longer than usual summary article and in this episode, Andrew and Rik discuss the sessions and explore why short-term complexity may increase even if long-term harmonisation helps, and why the biggest challenge may be cultural rather than technological. They also dig into how AI could push banks toward better data consistency, fewer silos, and a more effectiveness-driven compliance function. If you prefer to listen, you can find us on your favourite podcast platform here (and don't forget to SUBSCRIBE for regular insights).

Share this via
© Copyright 2026 The Banking Scene - All rights Reserved.