Skip to content
Insights

The Future of Compliance Isn't Continuous KYC. It's Continuous Risk Awareness.

Continuous risk awareness is reshaping AML/KYC and compliance. See how AI, automation and ongoing monitoring help firms detect risk earlier and act faster.

 

 

"... most AML officers and  practitioners understand that risk does not move on a defined schedule; it's dynamic." 

Financial institutions have spent decades building compliance programs around a simple assumption: risk can be evaluated on a schedule.

At the time, that approach made sense. Customer due diligence happened during onboarding; periodic reviews were conducted every few years; and risk assessments followed well-defined operating procedures. Firms established policies, assigned risk ratings, completed required reviews, and demonstrated that processes were being followed.

The challenge is, risk never agreed to operate on the same schedule.

Fraud schemes evolve overnight. Ownership structures change. Sanctions regimes shift. New adverse information can emerge in hours, not years. Yet many compliance frameworks were designed for an era when operational constraints, technology limitations, and data accessibility made continuous oversight impractical. Today, those constraints are rapidly disappearing.

Technology advances such as business process automation, artificial intelligence, and other data curation capabilities have changed posture and execution techniques, moving most programs to some form of continuous risk awareness by monitoring Know Your Customer (KYC) and due diligence.

Legacy KYC checks were completed at account opening and then scheduled for re-review based on a formulaic assessment of client risk attributes shaped by risk tolerance and a policy position declaration. Programs were deemed adequate if they had a written policy, defined risk stratification, and executed on their common practice often in one, three, or five-year intervals. It was always an administrative task that in practice rarely achieved the right balance of scheduling adherence, efficient task completion, and effectiveness of identifying risk changes. The design itself implemented explicit gaps that sometimes resulted in high-visibility exposures.

Programs built over that period, which necessitated policy carve-outs and boundaries in coverage were driven by operational capacity limitations, data accessibility costs, technology limits, and policy positions set by anti-money laundering (AML) officers and influenced heavily by regulatory observations and geographic locations of customers. Success was the defined risk-scheduling philosophy, not true risk identification.

However, most AML officers and practitioners understand that risk does not move on a defined schedule; it's dynamic. For years, some organizations lacked the tools necessary to monitor risk dynamically at scale. That is changing.

[Related: See how Saifr supports always-on adverse media monitoring]

 

The shift to continuous risk monitoring, and what it looks like in practice

Today, almost every vendor and firm has capitalized on the marketing power position of stating continuous monitoring of something.

In discussion with practitioners, and upon direct observation with many clients, there are clearly a large range of practices. The labels “ongoing KYC,” “continuous monitoring,” or “perpetual” may describe the same objective, but they do not mean the same from firm to firm or vendor to vendor solution execution.

The ability to reduce cycle time, lessen the manual nature (cost and swivel chair concepts), and incorporate more risk signals are significant and drive the most excitement in potential. This is important as risk is not present in clean, defined timeframes or along functional boundaries. Firms are also testing how newer AI-based tools that use advanced language and signal intelligence across datasets can help surface potential risks that would otherwise remain fragmented or undetected across silos.

The ongoing KYC, due diligence, and enhanced due diligence still employ a set of risk insights from initial account opening and risk tolerance rules to drive any perpetual sequencing and orchestration of task and customer attributes for analysis. For instance, for a business, teams can establish and set a trigger review for the business license or incorporation date. A periodic review of a business license being revoked, a business not in good standing, etc., can come from a static structured list or database or as an ongoing risk signal, should adverse media be present.

Changes to beneficial ownership, account signatories, address/email changes are often automatic triggers for rescreening, and with automation this sometimes has straight-through review processing. Some foreign jurisdictions are establishing more ongoing checks of central registries or defining explicit attributes of what KYC may include, but many large financial institutions have clients in hundreds of countries, so defining a single standard is operationally challenging and not always customer friendly. The orchestration and consistent execution of triggers are demanding and critical.

Some firms have automated KYC/due diligence to refresh when transactional activity exceeds a certain threshold. For instance, clients that have not previously had incoming or outgoing wires and that now receive one, may trigger a KYC refresh and some enhanced due diligence (EDD) as part of the parallel transaction review by the investigative team. Perpetual KYC, which accompanies or is an available updated risk input signal as the investigative team reviews consideration to file a potential Suspicious Activity Report (SAR), can be an efficient use for all parties.

For firms that monitor organizational hierarchy, ownership, and structure, ongoing KYC is extremely helpful in detecting/adjudicating risk exposure to international sanctions, ownership, and control percentages. As we know, creating complex webs and changes in ownership and control is common with high visibility cases surfacing the window of vulnerability and latency in detecting changing risk signals. The speed at which geopolitical events occur and frequent changes in required responses for certain business and product channels demand stronger and capable technologies. They cannot be completed manually to achieve today’s effectiveness and legal expectations.

 

AI’s role and fraud’s “cat and mouse” game

AI can improve risk signal detection at scale and frequency but...let us not forget that AI is also a tool for bad actors as well. The ability to hide or use AI in creating more believable indicia, fraudulent documents, historic company histories, financial and social media enabled visuals, and supplier contracts can also be signals that lead to legitimacy or potentially exacerbate hallucination vulnerabilities helping bad actors blend into the common pack.

Recently, discussions have also centered on the impact of complacency and over-reliance on AI. Some professionals are employing the “just trust the machine and outcome” and have stopped questioning the output. I put the equivalent to historic lending and credit scores. If the scores were absolute, higher credit scores would never default on a loan. Conditions change and high-credit worthiness without monitoring loan performance degradation is potentially as bad as thinking no customer ever turns bad even when signals are present. This is why some form of continuous monitoring is needed. It reduces your window of vulnerability and minimizes longer periods of undetected exploitation.

Some senior executives believe AI and continuous monitoring are the "holy grail" and will reduce cost without the emergence of unforeseen hidden exposures or execution errors. This is likely the next point of conflict with compliance officers and the likely reason why some adoption is slower to mature.

Tests and early exploration are occurring, but so too are behind-the-scenes examples (not highly publicized) where the desired outcomes are not full proof. When that happens, it creates tension and anxiety. It also likely impacts more the junior and operational execution points where apprehensiveness and not rocking the boat will grow. Ultimately, this is an evolving risk category requiring constant monitoring and human-in-the-loop reality checks.

 

Courage and candor at all compliance levels are essential 

Senior leaders should embrace and encourage exploration but be clear-eyed in acknowledging risk can be presented by an overreliance that AI, automation, and continuous monitoring eliminate all the risk. Risk and exploitation will still occur.

Many professionals talk about model monitoring, tuning, and checking for bias and model drift. Successful firms will likely be on top of this as a priority. The ability to detect and react to this earlier in the cycle will limit exposure from a negative event. Importantly, firms must evaluate their ability to respond and to change items and processes that require near-real-time adjustment like sanctions or other evolving risk events.

It is almost always a single event manifestation that highlights a defect in design or execution that regulators will call to account. At that point, it is too late to describe or create what your oversight is. Best practice is to define these possible outcomes, document how the potential risk is monitored, and then do it with a fit-for-purpose and fit-for-performance transparent mindset.

 

Ready or not, the shift to real-time risk awareness is happening—responsible growth will be key

From the activities I’ve seen in the industry, real-time compliance and risk awareness operations are both inevitable and necessary. The question is no longer whether firms will move in this direction. The more important question is how they will do so responsibly.

Strong real-time compliance building blocks can include:

  • Defining fit-for-purpose use cases, priorities, and pace of change
  • Upfront parallel evaluation of current process versus challenger model
  • Establishing metrics and performance standards
  • Documenting ongoing monitoring and effectiveness
  • Contingencies similar to business resiliency impacts and emergency change management should be considered and rehearsed. These are particularly important when automated, continuous control does not work or has disparate impact.
  • Establishing transparency and communication plans across the ecosystem
  • Consideration for human capacity job shift, upskilling, and cultural acceptance anxiety

The ultimate goal: Better outcomes, not more activity

Opportunities to reimagine and apply AI and technology advances in compliance execution areas are plentiful. Emphasis is on AML-related subcategories like onboarding, continuous KYC philosophy, adverse media due diligence, and closely related AML investigation tasks. This trend will continue, and early results are promising.

Some early explorers have noted caution in redesigning philosophy, expectations, and results. Many have achieved greater capacity and less false positives than legacy processes but have merely filled new capacity gains with other attribute data and tasks that may or may not be truly additive to overall effectiveness and often negate some of the gains. Doing more for more's sake does not always mean it is a better process.

The current challenge is also when to stop the review and conclude, versus gathering more and more results. Anticipate and challenge your team’s thinking, and always focus on fit-for-purpose and overall effectiveness.



The opinions provided are those of the author and not necessarily those of Saifr or its affiliates. The information is general and educational in nature, is for informational purposes only, and should not be construed as legal advice.

 1276261.1.0

Jon Elvin

Strategic Risk Advisor
Jon Elvin is a Strategic Risk Advisor with over three decades of experience in compliance, risk management, AML, BSA, and sanctions. In addition, he is a Certified Fraud Examiner (CFE) and Certified Anti-Money Laundering Specialist (CAMS). He has previously held numerous executive roles in various sectors of the financial industry, including banking, US government, consulting, and commercial adverse media software.

Check out our latest blogs

The Future of Compliance Isn't Continuous KYC. It's Continuous Risk Awareness.

The Future of Compliance Isn't Continuous KYC. It's Continuous Risk Awareness.

Continuous risk awareness is reshaping AML/KYC and compliance. See how AI, automation and ongoing monitoring help firms detect risk earlier...

How Contextual AI Is Helping Transform Pre- and Post-Marketing Compliance Review Workflows

How Contextual AI Is Helping Transform Pre- and Post-Marketing Compliance Review Workflows

The problem: More channels, evolving regulations, and the need for speed

Survey: Top 3 Challenges Driving AI Adoption in Electronic Communications Surveillance

Survey: Top 3 Challenges Driving AI Adoption in Electronic Communications Surveillance

Chief compliance officers are turning to AI to reduce noise, improve context, and modernize surveillance. Explore what’s driving the shift.