Maxime Vermeir, Vice President of AI Strategy at ABBYY, on how organisations can build a faster and more resilient approach to KYC compliance

“Know Your Customer” (KYC) used to feel as painfully slow as dial-up internet, but it doesn’t have to be that way any more.

KYC is the process organisations use to verify the identity of their customers, assess risk, and ensure compliance with regulations such as AML (Anti-Money Laundering) and counter-terrorist financing laws.

Today, it’s about more than compliance. It’s a critical trust and customer-experience driver. Financial institutions, insurers, and fintechs use KYC to build confidence, protect their brand, and deliver frictionless onboarding experiences that feel more like Apple Store checkout than DMV purgatory.

However, organisations face an increasingly challenging landscape.

Regulatory pressure is intensifying. The July 2027 EU AML Regulation, for example, will harmonise standards across all member states, introducing stricter requirements for beneficial ownership data and ongoing due diligence.

At the same time, customer expectations have shifted dramatically. People expect to open accounts or complete onboarding in minutes, not days. Fraud and identity theft are growing. Deepfakes, synthetic IDs, and digital manipulation make verification more complex and costly than ever.

Against this backdrop, many organisations struggle to keep pace. Inefficient processes, fragmented systems, and manual checks create delays, increase risk, and damage the customer experience. We examine the six deadly sins of KYC compliance and how organisations can address them to build a faster and more resilient approach.

Fragmented, Siloed KYC Workflows

    KYC processes often span multiple systems, from CRM to AML, to onboarding portals and case management. A lack of integration between these different areas creates more work, with data capture often duplicated, and SLAs missed. Teams have no unified view of onboarding performance.

    Disconnected databases, inconsistent standards, and repetitive customer documentation cause onboarding friction, high operational costs, and gaps that fraudsters can exploit with alarming speed.

    To combat these risks, organisations need to implement end-to-end visibility across fragmented workflows. The easiest way to achieve this is through AI-powered Process Intelligence tools. These tools can reveal bottlenecks, improve communication between teams, and avoid the risk of repeating time-consuming work.

    Manual Document Handling and Validation Bottlenecks

    Most onboarding delays occur during document intake and validation. Human review teams spend hours checking IDs, proof of address, and corporate records, often working across multiple systems and formats. This introduces inconsistencies, with decisions likely varying between reviewers, and increases the likelihood of errors or missed details.

    The process is also resource-intensive and difficult to scale. As volumes increase, manual reviewers either become bottlenecks or require additional headcount, pushing up operational costs. Long cycle times mean customers wait, which can lead to drop-off, frustration, and reputational risk to the organisation.

    Automating document classification, extraction, and validation can mean the difference between success and failure, even for complex, multi-page corporate KYC packs. These systems leverage intelligent workflows and advanced data processing to accurately sort documents, extract critical information, and standardise it in real time.

    This not only reduces manual effort but also significantly minimises human error, identifying missing fields and inconsistencies before submission. AI tools for regulatory automation and fraud checks enable higher rates of first-pass compliance and faster document processing. This means less time spent on manual reviews and a faster overall process.

    Lack of Process Visibility and Control

    Compliance and operations teams at financial services organisations often lack real-time visibility into where a customer’s onboarding file sits in the process or how long it has been at each stage. Information typically spreads across systems, inboxes, and manual trackers, making it difficult to build a clear view of progress.

    As a result, it’s difficult to pinpoint the problem when delays happen. This lack of transparency makes it harder to meet SLAs or prepare for audits. Teams may only realise there’s an issue once deadlines are missed or escalations occur.

    Process Intelligence provides real-time monitoring of onboarding KPIs, including time per stage, rework rates, and failure points, and allows teams to simulate process improvements. It creates a complete digital audit trail of every step, supporting both operational management and regulatory compliance.

    Better visibility makes it easier for organisations to maintain control, prove compliance, and deliver a predictable customer experience.

    Inconsistent Execution Across Regions and Business Lines

    In many businesses, each branch or business unit follows slightly different onboarding procedures, often shaped by local practices, legacy systems, or different interpretations of compliance requirements. While these variations may seem small individually, together they increase fragmentation across the organisation.

    This can lead to inconsistent customer experiences and non-uniform compliance documentation. One customer may be onboarded quickly, while another similar customer faces delays or repeats because a different team or location handles them. Over time, this erodes trust and makes the organisation look disjointed and unpredictable.

    Best-practice workflows must be standardised enterprise-wide, and all data and documentation should adhere to consistent formats and validation rules across jurisdictions. This is where Process Intelligence excels, benchmarking and comparing process execution across teams, countries, and products, and highlighting deviations from policy.

    Slow Remediation and Periodic Review Cycles

    When periodic reviews or remediation campaigns begin, teams struggle to find and validate the information they need. Customer records may be spread across multiple systems or stored in inconsistent formats, making it difficult to quickly identify what is missing.

    Manual checks only make things worse. Reviewing large volumes of records is time-consuming and repetitive, increasing the likelihood of human error. As workloads increase during remediation campaigns, these risks multiply.

    A better approach is event-driven (pKYC) automation. Instead of relying on periodic reviews, it detects changes in customer data and automatically triggers the right review workflows. Intelligent document processing (IDP) can quickly revalidate and update documents, while process intelligence tools track progress, flag exceptions, and ensure tasks are completed on time.

    Proving Compliance and Audit Readiness

    Regulators increasingly expect organisations to demonstrate full transparency across their KYC processes, including clear data lineage, time-stamped actions, and explainable decision-making. This is particularly true where AI or automation is involved.

    It is no longer sufficient to show that checks were completed. Firms must be able to evidence exactly how data was collected, transformed, verified, and used at every stage of the customer lifecycle. However, many organisations lack this end-to-end audit view. KYC processes are often fragmented across multiple systems, and as a result, audit trails are incomplete or difficult to reconstruct.

    Process Intelligence maintains a comprehensive record of every process step, decision, and exception, while IDP provides field-level traceability, showing where each data point came from and how it was verified.

    Using AI-powered tools that combine process intelligence with document processing makes KYC faster, easier, and more accurate. It means customers can be onboarded more quickly and mistakes are reduced, making the whole KYC process easier to track and audit. Organisations can trust that they comply with regulations while building trust among customers and giving them a smoother, better experience.

    Learn more at abbyy.com

    • Cybersecurity in FinTech
    • Digital Payments

    Karen Allan, Head of FinTech at HaysMac, on why building a company that can scale and stay ahead of regulation needs an auditor

    In August 2025, the FCA launched a considerable overhaul of the safeguarding regime for payments and e-money firms. The result? PS12/25, a policy statement that makes clear the significant new expectations under CASS 15.

    CASS 15 covers any firms which hold relevant funds above the qualifying threshold of more than £100,000, within a 53-week period, or expect to. As the May 7th deadline nears, firms can no longer ‘wait and see’. The requirement for a first CASS 15 audit is on its way, and for a firm to put its best foot forward, the preparation needs to start now.

    Be Prepared for CASS 15

    The new regulation is a big shift from the existing regime, and the requirement for a regulatory audit by a statutory auditor will make a considerable impact. The FCA has outlined extensive rules, and firms must comply with these ahead of the 7 May.

    These changes include the need for daily reconciliations, as well as monthly reporting requirements on safeguarding funds. Planning for firm failures will also be a requirement, via a CASS 15 resolution pack. Similarly, there is the clear provision for the first CASS 15 audit to be completed within 6 months.

    Many FinTech firms are run with as few employees as possible, as a way to stay agile. Under CASS 15, this won’t be as simple. Firms need to make sure they are structured correctly, with the right people in the right positions. Management also needs to lead by example, by supporting on regulatory oversight and compliance. The right tone and messaging from the top is particularly important.

    Making the Right Partnerships

    The new changes make a significant difference, and firms should start working with both a compliance advisor, to support with preparedness reviews, and a statutory auditor, to deliver CASS 15 audits. Finding a team of advisors who understand the rules and requirements in the new world of CASS 15 is key. By establishing strong partnerships now, firms can have a valuable outsourced ‘head of compliance’ to support further down the line. These can be crucial through rule mapping, for example, to identify problems, propose solutions, and deal with structural concerns a firm may have.

    The best time to bring in an auditor before CASS 15 would’ve been when the policy was first launched, but the second-best time is now. Management should be engaging with auditors now who provide CASS 15 audits, to ensure they perform the right due diligence in identifying and bringing in the right partners for the job.

    Compliance teams and directors should also be asking the right questions. Resources are an important concern, and when choosing an auditor, working out whether they can perform regular audits well, at all stages of a business scaling up, is vitally important. It may seem obvious, but is still foundational. Whether an auditor has the know-how to perform in the new CASS 15 world is key to consider.

    Communication is the Key

    These conversations should be starting now. Multiple advisors should be in the conversation to find the right match. Each firm is unique, and the audit and financial challenges they face will be different. Setting up a foundation of collaboration now makes sure that this will continue going forward.

    The first year of a CASS 15 audit will not be easy. There will likely be a learning curve for the sector as a whole. Most likely, there will be breaches across the industry, and these will be reportable to the FCA. There are therefore likely to be difficult conversations needed with auditors.

    Setting up advice and compliance partnerships now is important to avoid disappointment once we reach the 7 May. Starting the groundwork early, and allowing auditors to understand the firm’s entity, means they will more easily be able to recognise risk areas. This helps in developing a CASS 15 audit strategy, which in itself can be an advantage. All stakeholders can ensure that audit work is completed well within the deadline.

    CASS 15 is not just an exercise for compliance. It’s an opportunity to use robust governance as an advantage ahead of the rest of the market. The new rules will be an unknown to both firms and investors, and getting your house in order first shows reliability and discipline to investors. In an industry where actions are louder than words, this is very important.

    Many firms are now looking to strengthen their compliance at the cutting edge of fintech. If you want to stay ahead of the curve on regulation, and build a company that scales with confidence, approaching an auditor is an obvious next step.

    Learn more at haysmac.com

    • Digital Payments

    Richard May, director of product development at virtualDCS, on navigating cyber regulation, assessing risk, and building digital resilience in a cloud-first financial landscape

    In 2025, financial services are deeply reliant on digital infrastructures. Cloud services, especially, are reshaping how the sector operates.

    The cloud offers both established and challenger companies the ability to improve flexibility, efficiency, and analytics capabilities. When deployed properly, it can deliver integrated security across an organisation, but also introduces new vulnerabilities.

    Due to the sensitive nature of financial data, the sector remains a target for cyberattacks. This, combined with strict regulatory oversight, means firms must continuously align with evolving legislation while enhancing service functionality.


    Which regulations do financial services need to be aware of?

    There are several specific regulatory requirements that financial institutions must follow. These pieces of legislation are designed to ensure customer data is protected from attackers:

    Payment card information and PCI-DSS

    For businesses that handle payment card information, PCI DSS requirements dictate security and operational requirements for protecting cardholder information during storage, processing, and transmission. In practice, these requirements are 12 mandatory security controls that cover network security, data protection, vulnerability management, access control, monitoring and logging, physical security, testing, and policy enforcement. Failure to comply with the 12 security controls can lead to severe financial penalties and even liability for compensation costs.

    GDPR implications

    GDPR regulations categorise financial data as sensitive personal data. This refers to bank details, transaction histories, assets, credit scores, and anything else that might concern the overall financial health of an individual. Firms must take measures to prevent unauthorised access or risk facing fines.

    Basel III considerations

    The third Basel Accord, Basel III, sets the international standards for capital requirements, stress tests, liquidity regulations, and leverage. It is designed to reduce the risks of phenomena such as bank runs and bank failures, as we saw in the 2008 financial crash. Due to this, most of Basel III focuses on financial requirements such as liquidity to ensure banks are more resilient to changes in the international financial markets. However, it still communicates standards in relation to information and communication technology (ICT),‍ cyber incident response and reporting, and‍ third-party risk management (TPRM).

    Digital Operational Resilience Act (DORA)

    Introduced in January 2025 by the European Union (EU), DORA addresses rising digital dependency in finance. It covers ICT risk management, third-party oversight, operational resilience, incident reporting, and information sharing.

    Compliance with these regulations is essential. Beyond avoiding penalties or criminal charges, it strengthens protection against growing cyber threats.

    Assessing Vulnerability and Risk in the Financial Services Industry

    Risk assessments are critical to business continuity and reducing the impact of cybersecurity breaches. A task of identifying threats and vulnerabilities, and quantifying the consequences of threats if they were to materialise, enables firms to rank services and ensure the most critical systems are protected first.

    The Financial Services Information Sharing and Analysis Center (FS-ISAC) identified several key threats to the global financial sector in its latest report, including: 

    Supply Chain Incidents

    Businesses should remain alert to the competencies and overall security of service providers they utilise. As reliance on external providers is increasingly integral to many core business strategies, firms cannot afford to overlook the cyber maturity of their partners. To mitigate potential security risks, organisations should ensure and verify that all service providers meet robust cyber-security standards.

    Fraud

    The universality of real-time payments has led to a surge in fraud action in all sectors for which financial channels and services are used. The immediacy of payment has also created a scenario where it is almost impossible to retrieve stolen funds. Online scammers are building complex operations to take advantage of this. Fraud prevention and detection are becoming more and more important to companies in the sector. Increasing friction for payments through two-factor authorisation, along with other strategic obstacles, reduces fraud risks. Without cross-border partnerships tackling this global issue, however, this is set to remain a growing threat for businesses.

    Ransomware

    Ransomware has long been a cybersecurity threat. Many victims are often opportunistically targeted by hackers, rather than chosen specifically. Incidents of spear phishing are also on the rise – attackers research individuals or organisations to create personalised messages to convince them to click on infected links. Creating barriers to stop or delay ransomware attacks is therefore essential to reduce the threat. Ransomware’s targeting of customer data also means detection and recovery protocols are critical for firms that want to reduce the threat from malicious actors.

    Distributed Denial-of-Service

    The FS-ISAC revealed that financial services accounted for a third of all distributed denial-of-service (DDoS) attacks in 2023. DDoS attackers bring down an area of a network or application and extort the affected organisation for financial gain. Motivations may also include political statement-making, competitor sabotage, and cyber vandalism, simply to cause chaos and disruption. The increasing use of application programming interfaces (APIs) in the sector means that denial of service can have a devastating effect on financial service businesses. Firms should implement mitigation strategies to protect customer trust and service availability. 

    When, Not If: Building Cyber Resilience Through Disaster Recovery

    While cybersecurity defences are essential, effective disaster recovery is vital to reduce the impact of incidents and maintain operations.

    Speed of recovery has become the main point of difference for organisations attempting to recover from cyber incidents. Prolonged downtime can lead to reputational damage, regulatory penalties, and lost customers. Without effective disaster recovery, continuity efforts are undermined.

    Firms should develop a ‘when’, not ‘if’, mindset when it comes to disaster recovery. A comprehensive disaster playbook provides a manual in the event of a cyber incident. This plan must incorporate tools to allow for early detection of malicious action. Your plan for disaster recovery should be printed as a hard copy or saved on an external device (to ensure it remains accessible if your primary system is compromised). It must consider the first steps of: documenting evidence for cyber insurance and law enforcement, identifying and isolating infected systems, and informing relevant stakeholders an attack has taken place. Furthermore, the plan should contain information around communication and key contacts, an agreed chain of command and designated person to lead the ransomware response, and assurance the plan comes under regular review with ‘fire drill’ rehearsals.

    Financial institutions face some of the most severe cyber risks in the world. Abiding by regulatory requirements goes some way to protect against threats, but organisations must go further – by proactively assessing threats, incorporating security measures, and preparing for disruptions. Resilience isn’t just about avoiding breaches. It is about ensuring trust, safeguarding sensitive data, and maintaining the ability to deliver reliable services in a digital-first landscape.

    Learn more at virtualDCS

    • Cybersecurity in FinTech
    • Risk & Resilience

    Ben Parker, CEO at eflow Global, on how consolidating information can help organisations achieve a comprehensive view of their regulatory compliance

    When it comes to compliance, financial institutions are constantly navigating a landscape that is not only highly complex, but also in a state of perpetual flux. Firms must ensure that they are meeting the current standards set by regulators. Furthermore, they must also stay ahead of the curve in a world where regulations are continuously evolving. It’s about keeping up with the rapid advancement of technology, particularly in areas like artificial intelligence. It reshapes both the methods of regulatory enforcement and the strategies employed by those who seek to circumvent the rules.

    Accordingly, the importance of technology and data in compliance strategies is ever increasing. Traditional approaches, such as manual data entry and analysis, are increasingly inadequate in meeting the demands of modern regulations. Just look at the frequency and granularity of data reporting that is needed for the EMIR Refit regulations as a practical example.

    However, as financial firms have recognised this shift and turned to technology as the solution, the transition has brought new problems of its own. Namely, the fragmentation of data across disparate, siloed systems. So, how do firms solve this issue?

    The data fragmentation problem in compliance

    The issue of data fragmentation has become a common occurrence in compliance. Firms are often deploying multiple technology solutions to manage their regulatory obligations. Across areas such as trade surveillance, eComms surveillance, best execution and transaction reporting. As a result, they often find themselves grappling with data silos caused by using multiple, disconnected systems.

    While these tools are often very good at specific tasks, a lack of data integration between systems will harm a firm’s overarching compliance efforts. These platforms, if sourced from different vendors, may not be able to share data between one another. This ultimately undermines their effectiveness, negating the operational efficiency technology is supposed to add.

    The use of multiple systems by firms can happen for a variety of reasons. For example, legacy technology that has been in place for a number of years, the need to comply with different regulations as the business has scaled and changes in regulatory strategy. Moreover, you also need to consider that reporting formats can differ between regions, as can protocols for monitoring market abuse. When you combine all of these variables, it means only one thing – identifying non-compliant activity is trickier for firms to achieve, as is demonstrating compliance to regulators.

    This is a major problem as, perhaps more than ever before, different areas of compliance overlap. For example, being able to monitor suspicious messages shared through digital communications channels could help identify instances of market abuse. Or predict when it might take place. This relies on a firm being able to map its trade data over eComms surveillance data to create a complete picture of the activity. Without being able to do this, firms would have to spend huge amounts of time and resources manually cross-referencing data from separate systems. In turn this increases the risk of human error and the danger of breaching regulations.

    Why a holistic system supports compliance

    Rather than having to implement complex and costly integrations between in-house and third party apps, a holistic compliance platform can provide the seamless flow of data between various sources via straight-through processing. This creates a real-time overview of compliance processes and streamlines workflows, reducing human errors and enhancing efficiency.

    With such technology in place, firms have a central digital hub from which to manage their holistic regulatory strategy. If chosen wisely, additional modules can be easily added and integrated to meet new regulatory requirements as they emerge. This allows firms to scale more effectively.

    This ‘single source of truth’ also enables compliance professionals to have a broader understanding of trading activity taking place across their organisation. It also facilitates improved sharing of information between different departments, trading desks and regional offices. This ‘joined up’ approach is likely to become even more important. As the financial landscape becomes increasingly interconnected this will be incredibly challenging to achieve without a centralised digital platform.

    New regulations such as EMIR Refit require significant extra reporting requirements. The sheer amount of data and the speed with which it needs to be processed means such automation and integration tools are crucial. Moreover, in such a digitally diverse landscape, a holistic system allows companies to assess the numerous data points needed to be compliant without any regulatory gaps. 

    A future non-negotiable

    While many firms are currently grappling with multiple compliance systems and data silos, employing a centralised system will become a non-negotiable in the future of compliance. Not only are regulations constantly changing, but trading strategies are evolving even quicker. This means that instances of market abuse, driven by trends like growing interest in digital assets and AI-powered trading, are only likely to increase. If firms are hindered by disparate compliance systems, they leave themselves open to significant regulatory risk.

    The underlying challenge for companies is to find ways to maintain compliance and keep on top of changing regulations while also ensuring these efforts do not place an unnecessary strain on resources. In the face of these challenges, a holistic compliance system offers the simple solution to striking this balance – it enhances the efficiency, accuracy, adaptability and overall effectiveness of regulatory processes. Crucially, it is clear that regulators have growing expectations of firms to take a proactive approach to this challenge.

    A centralised regulatory system also sets firms up to integrate more advanced tools like AI. There are already highly sophisticated compliance tools that have integrated features like natural language processing to ‘translate’ messages and link suspicious communication to abusive trading. The more comprehensive and diverse the data, the better these models work at analysing trends and spotting abuse.

    A holistic solution to a complex compliance challenge

    While a firm’s intention may be to drive efficiency, the adoption of compliance technology without a coherent strategy can in fact create more issues. If compliance systems can’t communicate effectively with each other, errors creep into datasets and gaps in regulatory processes appear. This means firms risk breaching regulations and suffering greater market abuse, with both outcomes bringing financial and reputational damage. 

    The key lies in integrating these disparate data sources into a single, cohesive, holistic system. By consolidating information, businesses can achieve a comprehensive view of their regulatory compliance. Therefore, reducing the need for cumbersome IT infrastructure and ensuring they remain agile in the face of ongoing regulatory changes. Ultimately, a holistic system simplifies a regulatory and trading landscape that is increasingly varied and complex.

    Gabe Hopkins, Chief Product Officer at Ripjar, on how GenAI can transform compliance

    Generative AI (GenAI) has proven to be a transformational technology for many global industries. Particularly those sectors looking to boost their operational efficiency and drive innovation. Furthermore, GenAI has a range of use cases, and many organisations are using it to create new, creative content on demand – such as imagery, music, text, and video. Others are using the new tools at their disposal to perform tasks and process data. This makes previously tedious activities much more manageable, saving considerable time, effort, and finances in the process.

    However, compliance as a sector has traditionally shown hesitancy when it comes to implementing new technologies. Taking longer to implement new tools due to natural caution about perceived risks. As a result, many compliance teams will not be using any AI, let alone GenAI. This hesitancy means these teams are missing out on significant benefits. Especially at a time when other less risk-averse industries are experiencing the upside of implementing this technology across their systems.

    To avoid falling behind other diverse industries and competitors, it’s time for compliance teams to seriously consider AI. They need to understand the ways the technology – specifically GenAI – can be utilised in safe and tested ways. And without introducing any unnecessary risk. Doing so will revolutionise their internal processes, save work hours and keep budgets down accordingly.

    Understanding and overcoming GenAI barriers

    GenAI is a new and rapidly developing technology. Therefore, it’s natural compliance teams may have reservations surrounding how it can be applied safely. Particularly, teams tend to worry about sharing data, which may then be used in its training and become embedded into future models. Moreover, it’s also unlikely most organisations would want to share data across the internet. Strict privacy and security measures would first need to be established.

    When thinking about the options for running models securely or locally, teams are likely also worried about the costs of GenAI. Much of the public discussion of the topic has focussed on the immense budget required for preparing the foundation models.

    Additionally, model governance teams within organisations will worry about the black box nature of AI models. This puts a focus on the possibility for models to embed biases towards specific groups, which can be difficult to identify.

    However, the good news is that there are ways to use GenAI to overcome these concerns. This can be done by choosing the right models which provide the necessary security and privacy. Fine-tuning the models within a strong statistical framework can reduce biases.

    In doing so, organisations must find the right resources. Data scientists, or qualified vendors, can support them in that work, which may also be challenging.

    Overcoming the challenges of compliance with AI

    Despite initial hesitancy, analysts and other compliance professionals are positioned to gain massively by implementing GenAI. For example, teams in regulated industries – like banks, fintechs and large organisations – are often met with massive workloads and resource limits. Depending on which industry, teams may be held responsible for identifying a range of risks. These include sanctioned individuals and entities, adapting to new regulatory obligations and managing huge amounts of data – or all three.

    The process of reviewing huge quantities of potential matches can be incredibly repetitive and prone to error. If teams make mistakes and miss risks, the potential impact for firms can be significant. Both in terms of financial and reputational consequences.

    In addition, false positives – where systems or teams incorrectly flag risks and false negatives – where we miss risks that should be flagged, may come from human error and inaccurate systems. They are hugely exacerbated by challenges such as name matching, risk identification, and quantification.

    As a result, organisations within the industry quite often struggle to hire and retain staff. Moreover, this leads to a serious skills shortage amongst compliance professionals. Therefore, despite initial hesitancy, analysts and other compliance professionals stand to gain massively by implementing GenAI without needing to sacrifice accuracy.

    Generative AI – welcome support for compliance teams

    There are numerous useful ways to implemented GenAI and improve compliance processes. The most obvious is in Suspicious Activity Report (SAR) narrative commentary. Compliance analysts must write a summary of why a specific transaction or set of transactions is deemed suitable in a SAR. Long before the arrival of ChatGPT, forward thinking compliance teams were using technology based on its ancestor technology to semi-automate the writing of narratives. It is a task that newer models excel at, particularly with human oversight.

    Producing summarised data can also be useful when tackling tasks such as Politically Exposed Persons (PEP) or Adverse Media screenings. This involves compliance teams performing reviews or research on a client to check for potential negative news and data sources. These screenings allow companies to spot potential risks. It can prevent them from becoming implicated in any negative relationships or reputational damage.

    By correctly deploying summary technology, analysts can review match information far more effectively and efficiently. However, like with any technological operation, it is essential to consider which tool is right for which activity. AI is no different. Combining GenAI with other machine learning (ML) and AI techniques can provide a real step change. This means blending both generalised and deductive capabilities from GenAI with highly measurable and comprehensive results available in well-known ML models.

    Profiling efficiency with AI

    For example, traditional AI can be used to create profiles, differentiating large quantities of organisations and individuals separating out distinct identities. The new approach moves past the historical hit and miss where analysts execute manual searches limiting results by arbitrary numeric limits.

    Once these profiles are available, GenAI can help analysts to be even more efficient. The results from the latest innovations already show GenAI-powered virtual analysts can achieve, or even surpass, human accuracy across a range of measures.

    Concerns about accuracy will still likely impact the rate of GenAI adoption. However, it is clear that future compliance teams will significantly benefit from these breakthroughs. This will enable significant improvements in speed, effectiveness and the ability to respond to new risks or constraints.

    Ripjar is a global company of talented technologists, data scientists and analysts designing products that will change the way criminal activities are detected and prevented. Our founders are experienced technologists & leaders from the heart of the UK security and intelligence community all previously working at the British Government Communications Headquarters (GCHQ). We understand how to build products that scale, work seamlessly with the user and enhance analysis through machine learning and artificial intelligence. We believe that through this augmented analysis we can protect global companies and governments from the ever-present threat of money laundering, fraud, cyber-crime and terrorism.

    • Artificial Intelligence in FinTech
    • Cybersecurity in FinTech

    Henry Balani, Global Head of Industry & Regulatory Affairs at Encompass Corporation, on meeting the demand for improved risk management, operational efficiency, and customer service with pKYC

    The traditional banking and finance industry is evolving. Processes are experiencing a digital transformation as a result of perpetual Know Your Customer (pKYC). The pKYC approach enables modern banks to continuously update and verify customer information in real time. Banks are moving away from the reliance on periodic reviews. This change is driven by technological advancements. And the increasing demand for dynamic and responsive regulatory compliance mechanisms.

    Perpetual KYC

    Conventional KYC processes commonly involve periodic reviews of customer information at fixed intervals. These reviews are typically conducted every one, three, or five years. While these reviews are thorough and comprehensive, they are also static. This can result in outdated information, potentially overlooking changes in customer risk profiles or new compliance requirements.

    On the other hand, perpetual KYC is dynamic and event driven. Through its continuous and automated approach, pKYC enables financial institutions to address risks and compliance needs in real-time. These risks can be determined by continuously monitoring customer activities. Furthermore, automatically updating profiles in response to specific triggers, including changes in personal information, significant transactions, or alterations in beneficial ownership.

    Gaining a competitive advantage with pKYC

    By leveraging pKYC, banks, and other regulated financial institutions can take advantage of a range of benefits. These are crucial in the modern digital era to gain a competitive edge. Through continuous monitoring, pKYC enables financial institutions to identify and address potential risks promptly. This real-time approach helps mitigate risks associated with financial crimes. Moreover, it ensures compliance with the latest regulatory standards.

    pKYC will lead to operational efficiency and cost reduction. By automating many of the manual processes involved in KYC, pKYC significantly reduces the time and resources needed for compliance. This allows financial institutions to focus their efforts on high-risk cases, rather than conducting blanket reviews for all customers, resulting in substantial cost savings.

    This process also enables many banks to improve their customer service and management. It also enhances the customer’s experience. With pKYC, customers are not subjected to frequent, intrusive reviews if their profiles remain stable. This results in a smoother and more positive customer experience, potentially increasing overall customer satisfaction and loyalty. Additionally, automated systems minimise human error and ensure consistency in applying KYC policies. This enhances overall regulatory compliance and reduces the risk of non-compliance penalties.

    Perpetual KYC implementation: Challenges and considerations

    Implementing a pKYC operating model is not straightforward. It requires the right blend of infrastructure and operating process. Every firm’s pKYC journey and ecosystem will be unique and cut across people, processes and technologies.

    Data is central to the success of pKYC as reviews based on event changes (aka event driven triggers) will not be effective if client information is outdated, missing or incorrect. Without consistent access to relevant and accurate client information, pKYC is impossible. Corporate Digital Identity (CDI) is fast emerging as a foundation for ensuring valid customer information is collected for successful pKYC operations.

    Being able to leverage this data requires an ecosystem of technology, which may be developed in house, utilising third-party RegTech providers, or a combination of both. This technology should drive how data is stored, structured and accessed so that pKYC triggers can be comprehensively managed. Customer lifecycle management systems (CLMs) are particularly relevant to pKYC as they connect all components along the workflow processes.

    Importantly, overarching executive sponsorship is needed to ensure a successful outcome in transformation initiatives. Recognising the structural and cross departmental challenge, influential sponsors will align the multiple stakeholders involved in driving this change and will champion a firm’s pKYC strategy and approach to regulators and other key stakeholders.

    Ultimately, pKYC must be future-proof and scalable, ready to adapt in line with business strategy and regulation to keep firms competitive.

    The future of pKYC

    The adoption of pKYC is growing, driven by regulatory pressures and the increasing complexity of financial crimes. Financial institutions are recognising the benefits of a proactive, real-time approach to compliance and risk management. The move towards pKYC is seen as a necessary evolution to stay ahead in a highly regulated and competitive financial environment.

    As the technological landscape continues to evolve, integrating advanced technologies such as blockchain and further developments in AI and ML will likely enhance pKYC systems’ capabilities. Ensuring higher levels of compliance and risk mitigation, these technologies are able to provide more robust and secure mechanisms for customer verification and monitoring.

    Blockchain technology can be utilised to further improve the initial customer authentication and validation process. As a result, we can expect improvements and advancements in the quality of customer data collected during initial customer onboarding processes. Financial institutions can then leverage AI-enhanced tools that can identify and collect the necessary attributes during document processing stages. This ensures that pKYC will utilise relevant, accurate, and up-to-date data. Perpetual KYC represents a significant departure from traditional, periodic KYC, as it offers a wide range of benefits in real-time risk management, operational efficiency, and customer experience. Although the implementation of pKYC poses certain challenges, it also provides numerous advantages, making it an increasingly attractive solution for financial institutions aiming to enhance their compliance and risk management frameworks and maintain a competitive edge in a rapidly evolving regulator landscape.

    • Cybersecurity in FinTech

    Mayank Sharma, Senior Product Marketing Manager, FinScan on managing the changing face of risk in financial services

    Today, companies are expected to have a holistic view of financial crime risk. They must consider the entire ecosystem of their counterparty relationships including suppliers, vendors, employees, and customers. Failure to do so can result in organisations breaching regulatory requirements, leading to fines and reputational damage. Assessing complex ownership structures, expanding overseas operations, and managing increasing amounts of data places strain on limited resources and capabilities.

    Many businesses grapple with multiple systems housing different data and information. Without an integrated view or calculation of risk or the ability to dynamically obtain data to update risk ratings, compliance and onboarding teams are operating ineffectively. What obstacles do businesses face in reaching a comprehensive view of their risk exposure? And how can technological advances help companies take a more proactive approach to financial crime risk management?

    The changing face of risk

    The last decade has seen a notable shift in how companies are expected to understand and manage risk. Traditionally, the focus was on performing due diligence on new customers during onboarding and at discrete intervals over the customer lifecycle. Today, companies are expected to adopt a more comprehensive perspective and take into account their entire network of counterparty relationships. This includes assessing extended relationships, encompassing customers, beneficial owners, customer’s customers, suppliers, employees, and other stakeholders. This includes distributors and other counterparties.

    It also entails understanding the nature of the geographies reached, the products and services used, and from whom they send and receive funds. For example, a community bank might have domestic customers with clear backgrounds but are exposed to indirect sanctions and money laundering risks through the customers’ supplier or vendor relationships based on sanctioned geographies or beneficial owners.

    Organisations must monitor sanctions and suspicious activity risk for direct and indirect client relationships. Failure to do so can result in large financial penalties. As seen in the high-profile examples of companies receiving fines for having customer or vendor relationships in sanctioned jurisdictions, and from overall weaknesses in their AML controls. However, the larger issue, from a risk perspective, especially in the context of geo-political changes and complex ownership structures, is even beyond AML and sanctions that bleeds over to reputational risk, i.e., who you are doing business with.

    Companies need to develop their financial crimes analysis and risk assessment processes across all risk monitoring systems. They need to make sure they identify all the parties down to the level necessary to determine the compliance risk of doing business. Such an analysis “future proofs” the organisation from undue reputational damage. It also keeps them proactively compliant with sanctions and AML failures.

    Process and technology challenges

    From a technological standpoint, AML and sanctions risk from customers, vendors, employees, and supply chains are typically distributed across multiple processes. These include onboarding, due diligence, screening, and monitoring, which use different systems that are not integrated. This makes it difficult to get a holistic overview of the risk exposure.

    Furthermore, many models are not sufficiently robust and fail to consider the relevant elements at the appropriate times. Most due diligence is performed at the point of onboarding. This presents a snapshot in time but does not accommodate dynamic updates such as alerts to situational changes, potentially impacting a customer’s risk score. There may be periodic Know Your Customer (KYC) updates or event-driven triggers, which influence the risk rating. However, these are typically retrospective, driven by customer interactions, and prioritised by the current rating. As such, low-risk customers who start displaying high-risk activity, which is not part of the trigger events, would not even be subject to an updated review based on that activity. Rather, they would only be reviewed at the next scheduled update for that batch of low-risk customers. This could be some years after they were first onboarded or last reviewed.

    Consequently, risk ratings may misclassify customers, pushing up operating costs. A study from McKinsey & Co found that banks changing approaches to reviewing low-risk customers based on trigger events, rather than a schedule, reduced KYC operating costs by 20 percent.

    Adopting an integrated and dynamic approach

    As the understanding and expectations surrounding risk change, so does the technology supporting risk scoring. Integrated risk scoring dynamically calculates a score from all critical source systems used by compliance and business functions. These include external sources such as news outlets and social media. This provides a robust approach more valuable for financial institutions as it uncovers scenarios not driven by interactions with the customer. This also has an impact, perhaps a more significant one, on a customer risk rating. Adverse media or changes in beneficial ownership, for example, will not necessarily be items brought to the financial institution by the customer. But these can impact the nature of the ongoing customer relationship.

    Artificial intelligence (AI) and machine learning (ML) are also likely to play an increasingly important role. As regulators become more open to innovative approaches and technologies, AI and ML will be used to enable real-time checks, such as integrated adverse media or identification checks. However, caution must be exercised regarding explainability, and the decision-making process must be understandable to human operators. Organisations must maintain clear documentation of how AI models work and the criteria they use for risk scoring. They must also monitor for and mitigate any biases in the AI models. They must enusre deployment doesn’t lead to unfair treatment of any ethnic or racial groups. Ultimately, new technology should realise a net reduction in residual risk.

    Facilitating a proactive approach to risk

    Companies are faced with an increasingly complex risk landscape. Today, they are expected to have a detailed understanding of their business relationships and assess the risks these relationships present. With geopolitical turmoil increasing, a wave of new sanctions, and the resulting implications for AML checks, companies need to ensure they have robust profiling processes and systems. To enable this, businesses should look for integrated solutions that bring together the various indicators and allow for dynamic updates of risk profiles.

    FinScan offers advanced Anti-Money Laundering (AML) compliance technology and consulting solutions. Built on decades of experience in data management and proprietary matching technologies, FinScan provides a data-first, risk-based approach to ensure unparalleled accuracy and efficiency in identifying and reducing risk, accelerating AML compliance workflows, and optimising team productivity.

    • Cybersecurity in FinTech