KYC/AML Outlook: Emerging Priorities for Compliance Teams
2026 is proving to be a year of implementation for KYC and AML teams. New rules are taking effect, further guidance is still being finalised, and firms are under growing pressure to show that their controls work in practice.
Several reforms that were discussed as future developments in January have now entered into force. Others have moved into detailed consultation or implementation. Meanwhile, new FATF reports, regulatory proposals, sanctions packages and supervisory developments have provided greater clarity about where authorities believe the most serious vulnerabilities lie. For compliance teams, the central challenge in the second half of 2026 is demonstrating that new requirements have been translated into functioning, risk-sensitive and properly evidenced controls. This outlook examines the developments compliance teams should prioritise.
Perpetual KYC Becomes an Evidence and Data Challenge
The direction of travel towards perpetual KYC remains clear. Periodic review cycles alone are increasingly difficult to defend when material customer-risk changes can occur between scheduled reviews. Changes in ownership, control, political exposure, business activity, geographic footprint, transaction behaviour or sanctions exposure can all make an existing risk assessment obsolete. An effective customer lifecycle management framework must therefore be able to identify relevant events, reassess risk and document the resulting decision.
From 10 July 2027, the EU’s Anti-Money Laundering Regulation will require most obliged entities to keep relevant customer documents, data and information up to date, including when customer circumstances or other material facts change.
Ahead of implementation, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) is consulting on draft guidelines covering the maintenance of customer information and the monitoring of transactions and activities. The draft approach is risk-based, proportionate and technologically neutral. It places particular emphasis on event-driven reviews when risk-relevant changes occur, such as changes in ownership, customer activity, PEP status or behaviour that deviates from the expected customer profile. This matters because perpetual KYC should not be interpreted as indiscriminately refreshing every document and data point in real time.
The stronger model is selective and explainable:
-
Identify events that are genuinely relevant to customer risk.
-
Determine which customers and data attributes are affected.
-
Recalculate or reassess risk consistently.
-
Route material changes for investigation or approval.
-
Record what changed, what evidence was considered and why a particular action was taken.
The most difficult part is often not the review workflow itself. It is establishing reliable links between customer records, ownership data, screening results, transaction monitoring, external intelligence and case outcomes. The challenge is not simply detecting that something has changed. It is deciding whether that change affects risk and responding in a way that is proportionate, consistent and auditable.
KYC360 CLM helps firms turn new information into action across the customer lifecycle, refreshing the customer risk assessment, opening a review, requesting targeted evidence or escalating to enhanced due diligence, with decisions and audit history held in one place. But the quality of those decisions depends on the data feeding the process. Experian adds consumer identity and business intelligence, including UBO and ownership information, helping create a fuller and more reliable view of the customer. This allows firms to focus on material risk changes rather than generating more alerts, customer outreach and manual review.
Learn more about KYC360 CLM
Key actions:
-
Document the events that should trigger customer reassessment and explain why each trigger is relevant.
-
Test whether ownership, PEP, sanctions and adverse-media changes consistently reach the appropriate customer record.
-
Measure the time between a risk event being identified and the customer profile being reviewed.
-
Ensure investigators can reconstruct the previous risk rating, the triggering event, the evidence considered and the decision reached.
-
Review the AMLA consultation and assess where existing processes may differ from the emerging EU approach.
Crypto Risk Extends Beyond Crypto Customers
Crypto risk is no longer limited to firms offering virtual-asset services. FATF's 2026 reports and targeted updates have focused on stablecoins, unhosted wallets, offshore VASPs, cross-chain activity and DeFi. It has also highlighted continuing gaps in supervision and enforcement, particularly where transactions take place outside regulated intermediaries.Key actions:
- Map direct and indirect crypto exposure.
- Update controls for stablecoins, unhosted wallets and cross-chain activity.
- Review how missing or incomplete Travel Rule data is handled.
- Feed crypto-related findings into the wider customer risk assessment.
Global Regulatory Developments
Regulatory change remains uneven. The US is seeking to make AML programmes more flexible and risk-focused, while the UK, EU, Australia and several international financial centres are introducing more detailed requirements.
United States
FinCEN has proposed allowing financial institutions to direct more attention and resources towards higher-risk customers and activities. The proposal is intended to move AML programmes away from lower-value, “check-the-box” processes while maintaining expectations around effectiveness and risk-based design. For international firms, this creates greater divergence between the US and jurisdictions taking a more prescriptive approach. Global policies may need clearer local variations around customer reviews, control design and the allocation of compliance resources.
United Kingdom
The UK amended its Money Laundering Regulations in June, including new requirements for firms providing pooled accounts to understand their purpose and intended use, assess the associated risks and apply appropriate controls. The Government is also progressing plans for the FCA to supervise legal, accountancy and trust and company service providers for AML/CTF purposes. Mandatory Companies House identity verification is also being phased in. The 18 November 2025 commencement date marked the start of a 12-month transition, with existing directors and people with significant control required to comply by their individual due dates.
For a closer look at what the reforms mean in practice, watch our latest webinar replay, Navigating UK AML Reforms 2026.
European Union
AMLA is consulting on guidelines for ongoing customer and transaction monitoring. The proposals reinforce the need to keep customer information current and respond when changes in ownership, activity, behaviour or risk make an existing assessment outdated. The consultation gives firms an early indication of how ongoing monitoring will operate under the EU single rulebook. Existing event-driven review processes should be assessed before the final guidelines are published.
Australia
Australia’s Tranche 2 obligations took effect on 1 July, subject to transitional arrangements, bringing designated services provided by lawyers, accountants, conveyancers, real-estate professionals, trust and company service providers, and dealers in precious metals and stones into the AML/CTF regime. The change also affects financial institutions dealing with these sectors. Banks may need to reassess professional intermediaries, client accounts, trust structures and reliance arrangements as newly regulated businesses embed their own controls.
United Arab Emirates
The Central Bank of the UAE issued updated AML/CTF/CPF guidance in April covering proliferation-financing risk, trade-based money laundering and transhipment, correspondent banking, customer due diligence, KYC and record-keeping, institutional risk assessments and role-based training.
International Financial Centres
International financial centres are continuing to tighten expectations around ownership, transparency and governance. Jersey and Guernsey have updated their AML/CFT/CPF handbooks. Jersey’s changes include updated MLCO requirements and clearer guidance on complex structures and enhanced criminal background checks.
Guernsey has strengthened expectations around ownership and control, including the verification of beneficial owners of trusts, and clarified how technology such as electronic verification systems and digital signatures may be used within compliance frameworks.
Meanwhile, the Isle of Man has introduced beneficial-ownership regulations requiring nominated officers to use practices consistent with FATF Recommendation 24 when identifying who ultimately owns or controls a legal entity.
Bermuda has updated AML/ATF/CPF and sanctions guidance for legal and accounting firms. It is also developing explicit requirements for regulated firms to assess and mitigate proliferation-financing risk, alongside revised beneficial-ownership regulations and guidance.
The Cayman Islands amended its beneficial-ownership framework in January. Relevant parties with access to registry information must report identified discrepancies as soon as reasonably practicable and no later than five days after discovery.

Sanctions Risk Is Increasingly Network-Based
Sanctions volatility remains a defining operational challenge for compliance teams. In July, the EU adopted its 21st sanctions package against Russia. It extended transaction bans to 33 additional Russian credit and financial institutions, four banks in non-EU countries and 14 crypto-related service platforms, while adding another 41 shadow-fleet vessels to the port-access ban. In the UK, OFSI’s 2026–29 strategy emphasises evolving circumvention threats, improved threat intelligence, data-led capabilities, enforcement and stronger partnerships with industry.
These developments reinforce why name screening alone is insufficient. A counterparty may not itself be listed but may still create exposure through:
-
Ownership or control by a designated person.
-
Directors, intermediaries or counterparties connected with sanctioned networks.
-
Vessels with changed names, flags, ownership or management.
-
Unusual routing, transhipment or trade documentation.
-
Banks or payment providers in circumvention jurisdictions.
-
Crypto addresses or platforms linked to evasion.
-
Transactions that are inconsistent with the customer’s expected business.
The challenge is compounded by differences between UK, EU, US and other sanctions regimes. A transaction may be prohibited in one jurisdiction, licensed in another and outside scope elsewhere.
Key actions:
- Combine list screening with ownership, control, network and transaction analysis.
- Ensure vessel screening uses persistent identifiers, such as IMO numbers, rather than vessel names alone.
- Link trade-finance, maritime, payment and customer data during investigations.
- Establish rapid processes for assessing new sanctions packages and identifying affected customers and transactions.
- Document the jurisdictional basis for sanctions decisions.
- Test whether customers can be rescreened promptly after material list, ownership or control updates.
- Review exposure to crypto platforms, payment providers and banks identified as facilitating circumvention.
For practical guidance on managing sanctions volatility, indirect ownership risk and rising screening volumes, watch our webinar replay, Balancing Sanctions Volatility and Screening Efficiency in 2026.
AI Creates a Dual Compliance Challenge
AI is creating two distinct risks for compliance teams. The first is external. Criminals are using generative AI, deepfakes and synthetic identities to improve impersonation, document fraud and social engineering, making traditional identity and onboarding controls easier to bypass.
The second is internal. Firms are using AI to support onboarding, screening, monitoring and investigations. As KYC360 founder Stephen Platt argues in his recent article, “The Agentic Frontier: How AI agents are reshaping AML and KYC and why data quality is everything”, agentic AI could take on more of the investigative process by gathering information, cross-checking sources and progressing cases before routing them to analysts. But its effectiveness depends on the quality of the data it can access. Incomplete ownership records, outdated customer information or disconnected systems can lead to faster but incorrect decisions. Firms therefore need stronger defences against AI-enabled fraud while ensuring their own AI systems remain accurate, explainable and subject to human oversight.
Key actions:
- Strengthen controls against deepfakes, synthetic identities and document manipulation.
- Address data-quality gaps before expanding AI use.
- Define which decisions require human approval.
- Maintain clear records of the data and reasoning behind material outputs.
Conclusion
The first half of 2026 has reinforced that KYC and AML controls must be continuous, risk-led and supported by reliable data. Firms should continue to focus on proving that those controls work. This requires current customer information, effective monitoring, clear escalation, explainable automation and clear evidence of decisions. KYC360 helps firms connect onboarding, screening, monitoring, remediation and customer lifecycle management in one auditable framework, keeping risk current and compliance decisions clear. Experian’s distinct consumer and commercial intelligence strengthen the customer record behind those decisions.
Contact KYC360 to see how our industry-leading solutions transform compliance into a competitive advantage.
The KYC360 platform is an end-to-end solution offering slicker business processes with a streamlined, automated approach to Know Your Customer (KYC) compliance. This enables our customers to outperform commercially through operational efficiency gains whilst delivering improved customer experience and KYC data quality.