Summer 2026 is making one AML question harder to avoid: do a firm's fraud, sanctions, KYC, transaction-monitoring and investigation controls produce one current view of risk, or do they simply coexist?
That distinction is becoming more important than the number of tools, rules or alerts a firm owns. Recent enforcement has exposed controls that existed on paper but were incomplete, static or disconnected in practice. At the same time, supervisors are putting more emphasis on effectiveness, risk-based design, current customer understanding and consistent evidence of decisions.
For compliance leaders, the immediate task is not to replace every system. It is to test whether the existing control environment can connect a material signal to the right risk decision, owner and evidence record.
The Summer 2026 AML outlook: effectiveness over control inventory
The direction of travel is clear. In April 2026, FinCEN proposed refocusing AML/CFT program expectations on effectiveness, including a clearer distinction between weaknesses in program design and implementation. The proposal is not final regulation, but it reflects a supervisory priority that compliance output volume should not be confused with an effective response to illicit-finance risk.
In Europe, AMLA published final draft standards for a common approach to assessing AML/CFT breaches in July 2026. The standards consider factors such as duration, repetition and impact when determining the gravity of a breach. They will become directly applicable and legally binding only after adoption by the European Commission. Their direction nevertheless puts more pressure on firms to show that controls work as designed, remain current and produce proportionate outcomes.
This is the practical shift: a compliance framework should be judged not only by whether it contains sanctions screening, KYC, monitoring and case management, but also by whether those functions create a coherent and defensible response when risk changes.
Why integration has become an AML control issue
Financial crime is increasingly cross-functional. Fraud can generate the proceeds that later enter a money-laundering chain. A suspicious payment can reveal a mule-account pattern. A change in PEP status, beneficial ownership or adverse media can alter the risk of a relationship after onboarding.
When each signal remains in its original queue, a firm may technically complete every individual process while still missing the relationship between them. That is the integration problem: a risk signal is only as useful as the decision it can influence.
For the wider threat context, see our guide to connected financial-crime controls. This article focuses on the next question: how to test whether a control environment is effective in practice.
What recent enforcement shows
Coverage gaps are not minor configuration issues
The U.S. Department of Justice found that TD Bank did not automatically monitor several transaction types, leaving 92% of its transaction volume unmonitored between January 2018 and April 2024—approximately $18.3 trillion of activity. DOJ also found that the bank added no new monitoring scenarios or material changes to existing scenarios from at least 2014 through late 2022. The case ended in a $1.8 billion resolution. Read the DOJ announcement.
The lesson is direct: a policy that says transactions are monitored is not enough. Teams must be able to show exactly which transaction types, corridors, products, customers and behaviors are covered—and which are not.
Screening needs tested list and data coverage
The FCA found that Starling Bank's automated system had screened customers against only a fraction of the relevant sanctions list for years. Its subsequent review identified broader issues around sanctions risk assessment, procedures, system testing and calibration, and management information on alert volumes and trends. Read the FCA enforcement notice.
The lesson is not merely “screen more.” It is to verify list completeness, update timing, data quality, matching configuration, payment coverage and the evidence that proves those controls are operating as intended.
Five tests for an effective control environment
1. Can you prove actual coverage?
Start with an evidence-led coverage map. It should answer which customer populations, transaction types, payment flows, products, sanctions lists, PEP sources, ownership relationships and adverse-media sources are in scope for each control.
This is more useful than a high-level system inventory. It reveals whether monitoring is genuinely comprehensive, whether a screening feed is current, and whether a new product or payment flow has fallen outside the established control perimeter. Real-time screening and integration workflows can help teams apply checks consistently when new events enter their systems.
2. Can a material event change the customer-risk decision?
Risk should not wait for the next calendar review when meaningful information has changed. A new PEP status, sanctions exposure, credible adverse media, ownership change, fraud indicator or unusual transaction pattern should be capable of triggering review, reprioritization or a different monitoring response.
The test is simple: follow one real or simulated event from detection to the updated customer-risk assessment. Can the firm show what changed, who evaluated it, what action followed and why?
3. Do fraud and AML teams see the same relevant signals?
Fraud and AML do not need to become one department. They do need shared typologies, defined escalation points and a way to connect relevant cases. A fraud indicator that suggests mule activity, account takeover or coordinated payments may change an AML investigation; an AML pattern may reveal a network that helps fraud teams prevent further loss.
Use connected case management to make relevant alerts, prior cases, notes and outcomes available to the people deciding what happens next. The objective is not every team seeing every data point. It is ensuring that the data capable of changing a decision is visible when it matters.
4. Does monitoring learn from investigations?
Static scenarios become less reliable as products, payment behavior and criminal typologies change. Investigation outcomes should feed back into rules, thresholds, typologies and risk indicators. That feedback loop can identify duplicate alerts, missing scenarios, unnecessary friction and emerging patterns that merit closer review.
This is where ongoing monitoring becomes more than repeat screening. It becomes a process for keeping the customer understanding current as risk signals evolve.
5. Can you reconstruct the decision later?
For any material alert, escalation or closure, an internal reviewer or supervisor should be able to see:
- what information was available at the time;
- which rule, model or source created the signal;
- which version, threshold or matching setting applied;
- what the analyst reviewed;
- whether someone overrode a recommendation and why; and
- when the decision and any escalation occurred.
An audit trail and evidence workflow turns this from a free-text closure exercise into a defensible decision record. AI can assist with research, triage and case preparation, but its use should remain governed, tested and reviewable. For authorized AI-agent access to controlled AML capabilities, see Agentic AML via MCP.
A 90-day operating agenda for compliance leaders
The most useful starting point is a short, evidence-based control review rather than a wholesale technology program.
Days 1–30: establish coverage and ownership
- Map which systems, data sources, products, payment types and customer segments each control actually covers.
- Trace representative PEP, sanctions, fraud, ownership, adverse-media and transaction events from detection to the resulting risk decision.
- Assign an owner to every material control, handoff and identified coverage gap.
Days 31–60: test handoffs and decisions
- Run end-to-end walkthroughs using representative risk events and confirm that each signal reaches the right team and customer record.
- Test which fraud and AML signals must move between teams, who owns each escalation and what evidence travels with the case.
- Inspect decisions, overrides and closures to confirm that another reviewer can reconstruct what happened and why.
Days 61–90: close gaps and create feedback loops
- Prioritize remediation according to exposure, customer impact and the likelihood that a gap could hide material risk.
- Feed investigation outcomes into monitoring scenarios, source improvements, matching settings and customer-risk rules.
- Track coverage, timeliness, escalation quality, repeat alerts, overrides and evidence completeness—not alert volume alone.
The result should be a prioritized backlog of coverage gaps, broken handoffs and missing evidence. That is a more useful investment case than an abstract request for “more AI” or “a new AML platform.”
Frequently asked questions
What does AML effectiveness mean in 2026?
AML effectiveness means that a firm's program can identify higher-risk activity, respond proportionately when risk changes, connect relevant information across controls and demonstrate why material decisions were made. It is not measured by alert volume alone.
How can a firm test transaction-monitoring coverage?
Create a coverage map that identifies every transaction type, payment flow, product, customer segment and geography, then compare it with the scenarios and data feeds actually in production. Test changes to products and payment flows so new activity does not fall outside monitoring.
Why should fraud and AML teams share signals?
Fraud indicators can reveal mule accounts, compromised identities, suspicious counterparties and illicit proceeds. AML patterns can reveal connected customers or transactions that help prevent further fraud. Defined information sharing helps both teams make more complete risk decisions.
Does effective AML require replacing every legacy system?
No. The first priority is knowing what each system covers, connecting the signals that change decisions, defining cross-team ownership and retaining evidence. Replacement may be justified where a material gap cannot be controlled or evidenced, but it is not the starting assumption.
How should AI be governed in AML operations?
Use AI where it improves triage, research, entity resolution or case preparation, and retain human accountability for consequential decisions. Keep the sources, model or prompt version, outputs, overrides and decision rationale available for review.
Primary sources
- FinCEN — Proposed rule to reform financial institution AML/CFT programs (7 April 2026)
- AMLA — Common EU approach to enforcing anti-money-laundering rules (8 July 2026)
- U.S. Department of Justice — TD Bank guilty plea and $1.8 billion resolution (10 October 2024)
- Financial Conduct Authority — Starling Bank financial-crime systems and controls fine (2 October 2024)