Articles on KYC and AML.

Ongoing compliance guide: ongoing monitoring and perpetual KYC for fund administrators and ManCos
Ongoing monitoring (the AMLR's term) means keeping a customer's file current for as long as the relationship lasts. Perpetual KYC, or pKYC, is the market's name for the same practice. This page collects everything we have written on it for fund administrators, management companies and corporate service providers.
· 2 min read
Read the articleAll articles

What triggers a KYC review? AMLA's event list for fund administrators and ManCos
A KYC review is triggered when something relevant about the customer changes, not only when the calendar says so. AMLA's draft guidelines on ongoing monitoring group those changes into four kinds: identity, ownership or legal status; unusual behaviour or transactions; adverse media or PEP status; and financial situation or business activity.
· 7 min read
Read the article
AI Can Rank Your KYC Alerts. Who Checks What It Leaves at the Bottom?
AI models that score and rank KYC screening alerts can remove a large share of false positives. For management companies and TCSPs, the harder questions are who reviews the alerts ranked lowest, what historical decisions the model learned from and whether AI-written summaries match the evidence.
· 5 min read
Read the article
What is ongoing monitoring under the AMLR? Article 26 explained for fund administrators and ManCos
Ongoing monitoring under the AMLR is the duty to keep a customer's file current for as long as the relationship lasts: update it when something relevant changes, and re-check it on a risk-based schedule that cannot stretch past five years, or one year for higher-risk customers. From 10 July 2027 it is a direct obligation under Article 26 of Regulation (EU) 2024/1624.
· 8 min read
Read the article
Socure's $5.2 Billion Round Reveals What Compliance AI Agents Are Really Worth
Socure's $5.2bn growth round and acquisition of agentic AI startup Fravity reveal that proprietary, first-party decisioning data, not funding size, is what differentiates compliance AI agents. Argues that TCSPs, management companies, and fund administrators should evaluate vendor 'agentic AI' claims on domain-specific data provenance rather than aggregate decision volume.
· 6 min read
Read the article
RegTech's Capital Is Splitting Between Platforms and Point Agents. Compliance Teams Inherit Both Bets.
Cleversoft's 13 August acquisition of FS Assist and a wave of narrow AI agent funding rounds (Bretton AI, Sinpex, Diligent AI) show RegTech capital splitting between platform roll-ups and single-task agents. Argues neither thesis solves the compliance evidence coherence problem, and that buyers should evaluate every vendor on evidence portability regardless of category.
· 7 min read
Read the article
The $5bn RegTech Market Was Built for the Wrong Regulator
The Global State of RegTech 2026 report shows $5bn raised in 2025, with 63% going to US companies. This article argues that EU compliance teams are selecting from a vendor landscape optimized for US regulatory architecture, and that the evidence standard AMLR requires is architecturally different from what most platforms were built to produce.
· 6 min read
Read the article
AMLA Has Defined the STR Format. The Compliance Question Is Whether Your Data Fits.
AMLA opened consultation on July 2 on the STR format ITS, defining data templates obliged entities must use to automate suspicious transaction reporting. This article argues the template is not a reporting convenience but a data infrastructure specification, and that management companies and TCSPs must assess now whether their compliance systems can populate it.
· 7 min read
Read the article
The FATF Grey List Changed on June 19. Your CDD System Probably Didn't.
The June 2026 FATF Plenary added Iraq and Bosnia and Herzegovina to the grey list. For TCSPs and fund administrators, this is not just a news update. It is a data task that most CDD systems are not equipped to run automatically. This article explains why the gap matters and what adequate ongoing monitoring requires.
· 6 min read
Read the article
RegTech Deployment Is Not Compliance Implementation. The Market Has Started Measuring the Difference.
Analysis of the Global State of RegTech 2026 adoption index alongside the RegTech Association's 2026 Best RegTech Implementation award category. Argues that near-universal RegTech adoption has produced a 68/100 maturity score in the best domain because deployment and implementation quality are different variables, with specific implications for management companies and TCSPs under AMLR.
· 7 min read
Read the article
OFAC Is a Risk Factor, Not a Decision: What the CJEU's Jenec Ruling Changes About CDD Documentation
Analysis of CJEU Case C-81/24 (Jenec), decided 11 June 2026, which held that an OFAC listing cannot automatically justify refusing a basic payment account under EU AML law. Confirms the legal requirement for documented individual risk assessment, not list-matching, as the basis for CDD decisions. Implications for management companies, TCSPs, and fund administrators.
· 6 min read
Read the article
The RegTech Pricing Gap Is Closing. The Data Ownership Question Is Not.
Analysis of Q1 2026 European FinTech funding data alongside the KYCP managed service launch, arguing that managed service compliance infrastructure closes the pricing gap for smaller regulated firms but does not resolve the data portability and ownership questions that AMLR will test.
· 6 min read
Read the article
The AI Transparency Deadline That Wasn't Moved
The Digital Omnibus moved the high-risk AI deadline 16 months. Article 50 transparency obligations were not deferred. For management companies and TCSPs using biometric verification in digital KYC, AI-powered client tools, or AI-generated content, August 2026 is a live compliance deadline eight weeks away.
· 6 min read
Read the article
The AMLA Selection Exercise Has Started. Luxembourg Fund Managers Are in the Dataset.
The AMLA reporting package for its first direct supervision selection was published on 12 May 2026. CSSF formally notified investment fund managers and TCSPs on 1 June. Explains why every Luxembourg fund manager is in the dataset used to build the list of 40 directly supervised entities, and what the template's data requirements reveal about AMLR readiness.
· 6 min read
Read the article
The EU's Sovereign Cloud Has a Google Problem. Yours Might Too.
The EU's €180M sovereign cloud tender awarded a contract to a Thales-Google JV at SEAL-2 while three others achieved SEAL-3. This piece argues compliance teams must document their cloud providers' actual sovereignty risk profile using the EU's SEAL framework, not rely on marketing labels.
· 6 min read
Read the article
The RegTech Platform Bet: What Five Acquisitions in 18 Months Mean for Your Compliance Stack
Analysis of the accelerating RegTech vendor consolidation wave in Q1 2026, anchored in CUBE's five-acquisition sprint and the Parker & Lawrence $245bn TAM estimate. Argues that management companies and TCSPs are unknowingly making decade-long platform bets, and that data portability is the only durable defence.
· 6 min read
Read the article
The AI Act Window and the Classification Error: What the May 19 Guidelines Actually Resolve
Analysis of the May 7 Digital Omnibus deal that delayed high-risk AI Act enforcement 16 months, and the Commission's May 19 draft classification guidelines that define which AI systems are actually in scope. Argues that most AML/KYC AI at management companies and TCSPs falls outside the high-risk definition under Recital 58, but that AMLR documentation obligations apply regardless.
· 7 min read
Read the article
DORA Compliance as Data Plumbing: Why Cloud Sovereignty Became Infrastructure
An analysis of DORA compliance as a data infrastructure problem rather than a policy one. Covers exit strategy obligations under Article 28(8), the convergence of EU and global data-portability and messaging standards (ISO 20022, FAPI), and the architectural patterns (Kubernetes, IaC, S3-compatible storage) that make six-month exits actually executable. Aimed at Luxembourg TCSPs, management companies, and fund administrators evaluating cloud strategy under DORA. This is an edited replacement for the earlier draft of the same title.
· 7 min read
Read the article
The MiCA Review Opens While Luxembourg's Licensing Model Is Under Threat: What Compliance Teams Should Actually Watch
Analysis of the European Commission's MiCA review consultation launched on 20 May 2026, set against the parallel proposal to centralise CASP supervision under ESMA. For Luxembourg management companies, fund administrators, and TCSPs touching tokenised assets, the convergence of MiCA, AMLR, and the Transfer of Funds Regulation is becoming a single compliance surface that depends entirely on the data layer underneath.
· 7 min read
Read the article
When the Group Compliance Manager Is an AI: What AMLR Article 16 Looks Like in a World Where Most CDD Decisions Are Made by Agents
AMLR Article 16(2) requires a compliance manager at group level. When most CDD work moves to AI agents at the subsidiary level, the role of that compliance manager changes structurally. This piece argues that the future of enterprise KYC under AI automation is not a story about replacing compliance officers, but about elevating one specific role into the convergence point for AMLR, the EU AI Act, and AMLA's supervisory expectations.
· 8 min read
Read the article
AI Agents Are Coming to KYC. Here's What They Will Need from the Platforms They Run On.
Anthropic's 5 May 2026 announcement of ten agent templates for financial services, including a KYC screener and a partnership with FIS on AML investigation agents, marks the moment AI agents become a real part of the compliance stack. The article argues that the firms that benefit will not be the ones that deploy agents fastest, but the ones whose data infrastructure is ready to make agentic decisions defensible.
· 7 min read
Read the article
AMLA's New BWRA Guidelines: Why Your Self-Assessment Should Mirror the Supervisor's Scorecard
Analysis of AMLA's 16 April 2026 consultation on draft BWRA Guidelines under Article 10(4) AMLR, and how the cross-reference to the supervisor RTS under Article 40(2) AMLD reshapes how management companies, TCSPs, and fund administrators should structure their business-wide risk assessment.
· 7 min read
Read the article
What's Actually in AMLA's Article 28 CDD Standards: A Read of the Draft RTS Before the Window Closes
AMLA's draft RTS under Article 28(1) of the AMLR closes for consultation on 8 May 2026. Three provisions in the draft (on intermediary ownership layers, senior managing officials, and verification sources) reveal the structural shape of CDD under the new regime, and confirm that AMLR readiness is a data problem rather than a policy problem.
· 6 min read
Read the article
Synthetic Identity Fraud: Why Manual KYC Cannot Catch What It Was Not Designed to See
AI-generated synthetic identities are designed to defeat exactly the manual checks most firms still rely on. This article examines what the 2026 SmartSearch Compliance Report reveals about the gap between awareness and action, and what an effective response actually looks like.
· 5 min read
Read the article
Perpetual KYC: What It Means and Whether Your Firm Is Ready
Perpetual KYC promises to replace periodic reviews with continuous, event-driven monitoring. This article explains what pKYC actually involves, what infrastructure it requires, and whether the technology and regulatory environment are ready for it.
· 8 min read
Read the articleDocument-Driven KYC: Why Documents Are the Foundation of Effective Compliance
Document-driven KYC puts verified documents at the centre of every compliance decision. This article explains why this approach produces stronger compliance outcomes than form-based or interview-driven alternatives.
· 6 min read
Read the article
UBO Identification: Why Compliance Teams Still Struggle with Layered Ownership Structures
Identifying the ultimate beneficial owner behind complex holding structures, trusts, and SPVs remains one of the most time-consuming tasks in KYC compliance. This article explores why layered ownership creates persistent challenges for compliance teams on both sides of the KYC relationship, what regulators actually expect including variable thresholds and the board fallback rule, and how automation can eliminate the spreadsheet-driven recalculations that slow firms down.
· 12 min read
Read the article
KYC Software for Management Companies: What to Look for in 2026
Management companies face unique KYC challenges — complex entity structures, multi-jurisdictional requirements, and high document volumes. This guide explains what to look for when choosing KYC software purpose-built for the sector.
· 7 min read
Read the articleWhat Regulators Actually Look for During KYC Document Audits
Regulatory examinations focus on evidence, consistency, and risk-proportionate decision-making, not just process completion. This article explains what examiners actually scrutinise and how to prepare.
· 7 min read
Read the article
Why Your KYC Platform Needs a Policy Engine, Not Just a Risk Score
Risk scores tell you how risky a customer is. A policy engine tells the AI how to think about risk in the first place. This article explains why configurable compliance policies are the missing layer in most KYC platforms, and how they transform AI-driven risk assessments from generic outputs into institution-specific intelligence.
· 9 min read
Read the article