Articles on KYC and AML.

Guides on KYC and AML for compliance teams.
A linen index box of cream cards on a stone table, with one mint tab at the front

Ongoing compliance guide: ongoing monitoring and perpetual KYC for fund administrators and ManCos

Ongoing monitoring (the AMLR's term) means keeping a customer's file current for as long as the relationship lasts. Perpetual KYC, or pKYC, is the market's name for the same practice. This page collects everything we have written on it for fund administrators, management companies and corporate service providers.

· 2 min read

Read the article

All articles

A row of cream and grey cards in a wooden rack on a stone table, with four orange cards standing taller

What triggers a KYC review? AMLA's event list for fund administrators and ManCos

A KYC review is triggered when something relevant about the customer changes, not only when the calendar says so. AMLA's draft guidelines on ongoing monitoring group those changes into four kinds: identity, ownership or legal status; unusual behaviour or transactions; adverse media or PEP status; and financial situation or business activity.

· 7 min read

Read the article
Dark bronze trays of index cards on a stone desk, with one stack held apart under a thick glass block

AI Can Rank Your KYC Alerts. Who Checks What It Leaves at the Bottom?

AI models that score and rank KYC screening alerts can remove a large share of false positives. For management companies and TCSPs, the harder questions are who reviews the alerts ranked lowest, what historical decisions the model learned from and whether AI-written summaries match the evidence.

· 5 min read

Read the article
A metal flip calendar beside a long row of upright cream cards on a stone table, with one orange card at the front

What is ongoing monitoring under the AMLR? Article 26 explained for fund administrators and ManCos

Ongoing monitoring under the AMLR is the duty to keep a customer's file current for as long as the relationship lasts: update it when something relevant changes, and re-check it on a risk-based schedule that cannot stretch past five years, or one year for higher-risk customers. From 10 July 2027 it is a direct obligation under Article 26 of Regulation (EU) 2024/1624.

· 8 min read

Read the article
Socure's $5.2 Billion Round Reveals What Compliance AI Agents Are Really Worth

Socure's $5.2 Billion Round Reveals What Compliance AI Agents Are Really Worth

Socure's $5.2bn growth round and acquisition of agentic AI startup Fravity reveal that proprietary, first-party decisioning data, not funding size, is what differentiates compliance AI agents. Argues that TCSPs, management companies, and fund administrators should evaluate vendor 'agentic AI' claims on domain-specific data provenance rather than aggregate decision volume.

· 6 min read

Read the article
RegTech's Capital Is Splitting Between Platforms and Point Agents. Compliance Teams Inherit Both Bets.

RegTech's Capital Is Splitting Between Platforms and Point Agents. Compliance Teams Inherit Both Bets.

Cleversoft's 13 August acquisition of FS Assist and a wave of narrow AI agent funding rounds (Bretton AI, Sinpex, Diligent AI) show RegTech capital splitting between platform roll-ups and single-task agents. Argues neither thesis solves the compliance evidence coherence problem, and that buyers should evaluate every vendor on evidence portability regardless of category.

· 7 min read

Read the article
The $5bn RegTech Market Was Built for the Wrong Regulator

The $5bn RegTech Market Was Built for the Wrong Regulator

The Global State of RegTech 2026 report shows $5bn raised in 2025, with 63% going to US companies. This article argues that EU compliance teams are selecting from a vendor landscape optimized for US regulatory architecture, and that the evidence standard AMLR requires is architecturally different from what most platforms were built to produce.

· 6 min read

Read the article
AMLA Has Defined the STR Format. The Compliance Question Is Whether Your Data Fits.

AMLA Has Defined the STR Format. The Compliance Question Is Whether Your Data Fits.

AMLA opened consultation on July 2 on the STR format ITS, defining data templates obliged entities must use to automate suspicious transaction reporting. This article argues the template is not a reporting convenience but a data infrastructure specification, and that management companies and TCSPs must assess now whether their compliance systems can populate it.

· 7 min read

Read the article
The FATF Grey List Changed on June 19. Your CDD System Probably Didn't.

The FATF Grey List Changed on June 19. Your CDD System Probably Didn't.

The June 2026 FATF Plenary added Iraq and Bosnia and Herzegovina to the grey list. For TCSPs and fund administrators, this is not just a news update. It is a data task that most CDD systems are not equipped to run automatically. This article explains why the gap matters and what adequate ongoing monitoring requires.

· 6 min read

Read the article
RegTech Deployment Is Not Compliance Implementation. The Market Has Started Measuring the Difference.

RegTech Deployment Is Not Compliance Implementation. The Market Has Started Measuring the Difference.

Analysis of the Global State of RegTech 2026 adoption index alongside the RegTech Association's 2026 Best RegTech Implementation award category. Argues that near-universal RegTech adoption has produced a 68/100 maturity score in the best domain because deployment and implementation quality are different variables, with specific implications for management companies and TCSPs under AMLR.

· 7 min read

Read the article
OFAC Is a Risk Factor, Not a Decision: What the CJEU's Jenec Ruling Changes About CDD Documentation

OFAC Is a Risk Factor, Not a Decision: What the CJEU's Jenec Ruling Changes About CDD Documentation

Analysis of CJEU Case C-81/24 (Jenec), decided 11 June 2026, which held that an OFAC listing cannot automatically justify refusing a basic payment account under EU AML law. Confirms the legal requirement for documented individual risk assessment, not list-matching, as the basis for CDD decisions. Implications for management companies, TCSPs, and fund administrators.

· 6 min read

Read the article
The RegTech Pricing Gap Is Closing. The Data Ownership Question Is Not.

The RegTech Pricing Gap Is Closing. The Data Ownership Question Is Not.

Analysis of Q1 2026 European FinTech funding data alongside the KYCP managed service launch, arguing that managed service compliance infrastructure closes the pricing gap for smaller regulated firms but does not resolve the data portability and ownership questions that AMLR will test.

· 6 min read

Read the article
The AI Transparency Deadline That Wasn't Moved

The AI Transparency Deadline That Wasn't Moved

The Digital Omnibus moved the high-risk AI deadline 16 months. Article 50 transparency obligations were not deferred. For management companies and TCSPs using biometric verification in digital KYC, AI-powered client tools, or AI-generated content, August 2026 is a live compliance deadline eight weeks away.

· 6 min read

Read the article
The AMLA Selection Exercise Has Started. Luxembourg Fund Managers Are in the Dataset.

The AMLA Selection Exercise Has Started. Luxembourg Fund Managers Are in the Dataset.

The AMLA reporting package for its first direct supervision selection was published on 12 May 2026. CSSF formally notified investment fund managers and TCSPs on 1 June. Explains why every Luxembourg fund manager is in the dataset used to build the list of 40 directly supervised entities, and what the template's data requirements reveal about AMLR readiness.

· 6 min read

Read the article
The EU's Sovereign Cloud Has a Google Problem. Yours Might Too.

The EU's Sovereign Cloud Has a Google Problem. Yours Might Too.

The EU's €180M sovereign cloud tender awarded a contract to a Thales-Google JV at SEAL-2 while three others achieved SEAL-3. This piece argues compliance teams must document their cloud providers' actual sovereignty risk profile using the EU's SEAL framework, not rely on marketing labels.

· 6 min read

Read the article
The RegTech Platform Bet: What Five Acquisitions in 18 Months Mean for Your Compliance Stack

The RegTech Platform Bet: What Five Acquisitions in 18 Months Mean for Your Compliance Stack

Analysis of the accelerating RegTech vendor consolidation wave in Q1 2026, anchored in CUBE's five-acquisition sprint and the Parker & Lawrence $245bn TAM estimate. Argues that management companies and TCSPs are unknowingly making decade-long platform bets, and that data portability is the only durable defence.

· 6 min read

Read the article
The AI Act Window and the Classification Error: What the May 19 Guidelines Actually Resolve

The AI Act Window and the Classification Error: What the May 19 Guidelines Actually Resolve

Analysis of the May 7 Digital Omnibus deal that delayed high-risk AI Act enforcement 16 months, and the Commission's May 19 draft classification guidelines that define which AI systems are actually in scope. Argues that most AML/KYC AI at management companies and TCSPs falls outside the high-risk definition under Recital 58, but that AMLR documentation obligations apply regardless.

· 7 min read

Read the article
DORA Compliance as Data Plumbing: Why Cloud Sovereignty Became Infrastructure

DORA Compliance as Data Plumbing: Why Cloud Sovereignty Became Infrastructure

An analysis of DORA compliance as a data infrastructure problem rather than a policy one. Covers exit strategy obligations under Article 28(8), the convergence of EU and global data-portability and messaging standards (ISO 20022, FAPI), and the architectural patterns (Kubernetes, IaC, S3-compatible storage) that make six-month exits actually executable. Aimed at Luxembourg TCSPs, management companies, and fund administrators evaluating cloud strategy under DORA. This is an edited replacement for the earlier draft of the same title.

· 7 min read

Read the article
The MiCA Review Opens While Luxembourg's Licensing Model Is Under Threat: What Compliance Teams Should Actually Watch

The MiCA Review Opens While Luxembourg's Licensing Model Is Under Threat: What Compliance Teams Should Actually Watch

Analysis of the European Commission's MiCA review consultation launched on 20 May 2026, set against the parallel proposal to centralise CASP supervision under ESMA. For Luxembourg management companies, fund administrators, and TCSPs touching tokenised assets, the convergence of MiCA, AMLR, and the Transfer of Funds Regulation is becoming a single compliance surface that depends entirely on the data layer underneath.

· 7 min read

Read the article
Overhead view of a printed AI compliance agent reasoning trace on cream paper, with five numbered decision steps and pencil annotations in the right margin by a human reviewer.

When the Group Compliance Manager Is an AI: What AMLR Article 16 Looks Like in a World Where Most CDD Decisions Are Made by Agents

AMLR Article 16(2) requires a compliance manager at group level. When most CDD work moves to AI agents at the subsidiary level, the role of that compliance manager changes structurally. This piece argues that the future of enterprise KYC under AI automation is not a story about replacing compliance officers, but about elevating one specific role into the convergence point for AMLR, the EU AI Act, and AMLA's supervisory expectations.

· 8 min read

Read the article
Two compliance professionals reviewing a printed report together at an oak table, one pointing to a specific line while the other reads in profile, in soft north-facing window light.

AI Agents Are Coming to KYC. Here's What They Will Need from the Platforms They Run On.

Anthropic's 5 May 2026 announcement of ten agent templates for financial services, including a KYC screener and a partnership with FIS on AML investigation agents, marks the moment AI agents become a real part of the compliance stack. The article argues that the firms that benefit will not be the ones that deploy agents fastest, but the ones whose data infrastructure is ready to make agentic decisions defensible.

· 7 min read

Read the article
AMLA's New BWRA Guidelines: Why Your Self-Assessment Should Mirror the Supervisor's Scorecard

AMLA's New BWRA Guidelines: Why Your Self-Assessment Should Mirror the Supervisor's Scorecard

Analysis of AMLA's 16 April 2026 consultation on draft BWRA Guidelines under Article 10(4) AMLR, and how the cross-reference to the supervisor RTS under Article 40(2) AMLD reshapes how management companies, TCSPs, and fund administrators should structure their business-wide risk assessment.

· 7 min read

Read the article
What's Actually in AMLA's Article 28 CDD Standards: A Read of the Draft RTS Before the Window Closes

What's Actually in AMLA's Article 28 CDD Standards: A Read of the Draft RTS Before the Window Closes

AMLA's draft RTS under Article 28(1) of the AMLR closes for consultation on 8 May 2026. Three provisions in the draft (on intermediary ownership layers, senior managing officials, and verification sources) reveal the structural shape of CDD under the new regime, and confirm that AMLR readiness is a data problem rather than a policy problem.

· 6 min read

Read the article
Synthetic Identity Fraud: Why Manual KYC Cannot Catch What It Was Not Designed to See

Synthetic Identity Fraud: Why Manual KYC Cannot Catch What It Was Not Designed to See

AI-generated synthetic identities are designed to defeat exactly the manual checks most firms still rely on. This article examines what the 2026 SmartSearch Compliance Report reveals about the gap between awareness and action, and what an effective response actually looks like.

· 5 min read

Read the article
Perpetual KYC: What It Means and Whether Your Firm Is Ready

Perpetual KYC: What It Means and Whether Your Firm Is Ready

Perpetual KYC promises to replace periodic reviews with continuous, event-driven monitoring. This article explains what pKYC actually involves, what infrastructure it requires, and whether the technology and regulatory environment are ready for it.

· 8 min read

Read the article
Document-Driven KYC: Why Documents Are the Foundation of Effective Compliance

Document-Driven KYC: Why Documents Are the Foundation of Effective Compliance

Document-driven KYC puts verified documents at the centre of every compliance decision. This article explains why this approach produces stronger compliance outcomes than form-based or interview-driven alternatives.

· 6 min read

Read the article
Layered corporate ownership structure diagram tracing indirect paths to an ultimate beneficial owner

UBO Identification: Why Compliance Teams Still Struggle with Layered Ownership Structures

Identifying the ultimate beneficial owner behind complex holding structures, trusts, and SPVs remains one of the most time-consuming tasks in KYC compliance. This article explores why layered ownership creates persistent challenges for compliance teams on both sides of the KYC relationship, what regulators actually expect including variable thresholds and the board fallback rule, and how automation can eliminate the spreadsheet-driven recalculations that slow firms down.

· 12 min read

Read the article
KYC Software for Management Companies: What to Look for in 2026

KYC Software for Management Companies: What to Look for in 2026

Management companies face unique KYC challenges — complex entity structures, multi-jurisdictional requirements, and high document volumes. This guide explains what to look for when choosing KYC software purpose-built for the sector.

· 7 min read

Read the article
What Regulators Actually Look for During KYC Document Audits

What Regulators Actually Look for During KYC Document Audits

Regulatory examinations focus on evidence, consistency, and risk-proportionate decision-making, not just process completion. This article explains what examiners actually scrutinise and how to prepare.

· 7 min read

Read the article
Diagram showing how a policy engine combines factor scores and regulatory triggers like PEP status to produce an explainable risk assessment with audit trail

Why Your KYC Platform Needs a Policy Engine, Not Just a Risk Score

Risk scores tell you how risky a customer is. A policy engine tells the AI how to think about risk in the first place. This article explains why configurable compliance policies are the missing layer in most KYC platforms, and how they transform AI-driven risk assessments from generic outputs into institution-specific intelligence.

· 9 min read

Read the article

Put these guides into practice.

See how Fidify runs onboarding, screening and ongoing reviews on a real file.