EU's AMLA Era Pushes Banks From Periodic KYC to Continuous Monitoring
With the EU's AMLA now live and UK regulators handing out nine-figure fines for stale customer files, compliance teams are re-architecting KYC as an event-driven system instead of a calendar-driven checklist.
By TRAGenX Desk
From snapshot to stream
For two decades, KYC has run on a calendar: onboard a customer, score their risk, then re-review the file every one, two, or three years depending on tier. That model is now colliding with two regulatory forces. In the EU, the new Anti-Money Laundering Authority (AMLA) has been operational since July 2025, and the AML Regulation (AMLR) — the bloc's first directly applicable "single rulebook" for AML/CFT — takes effect uniformly across all member states on 10 July 2027, replacing a patchwork of national transpositions. In the UK, the FCA has made clear through enforcement, not just guidance, that a point-in-time file review isn't enough.
The fines that made this concrete
This isn't abstract regulatory pressure. The FCA fined NatWest £264.8 million in 2021 — its first criminal conviction for AML failings — over a commercial customer whose deposits ballooned from thousands to millions without triggering adequate monitoring. A year later, Santander UK was fined £107.7 million for AML gaps affecting over 560,000 business accounts. And the pattern hasn't stayed confined to legacy banks: the FCA fined Starling Bank £29 million in 2024 after its sanctions screening quietly missed most of the actual watchlist for years, and Monzo £21 million in 2025 for onboarding controls that didn't scale with customer growth — including accounts registered to addresses like Buckingham Palace.
Why fixed-cycle reviews fail by design
A periodic review answers "was this customer low-risk when we last looked?" It says nothing about a sanctions list update last Tuesday, a sudden change in transaction pattern, or an adverse-media hit that dropped an hour after the file was closed. Risk is continuous; the old review model is discrete. The FCA's own 2025 CDD review found that many firms couldn't even say clearly when a periodic review was supposed to trigger versus an event-driven one — the definitions themselves were inconsistent, before you even get to execution.
This is an architecture problem, not a policy problem
The compliance teams writing these new policies are, whether they realize it or not, specifying a distributed system: a set of trigger events (sanctions-list deltas, transaction-pattern shifts, address or beneficial-ownership changes, adverse-media signals) that need to fire a re-scoring pipeline, update a customer risk profile, and leave an audit trail a regulator can reconstruct months later. That's an event-driven backend, not a spreadsheet with a due-date column. Firms bolting an LLM onto adverse-media screening or transaction narrative review face the same discipline as any other AI-in-the-loop production system: the model's output has to be logged, explainable, and reviewable by a human — because "the AI flagged it as low risk" will not survive a supervisory examination on its own.
What regulators are actually asking for
- Clear, documented definitions of what triggers a re-review — not left to individual analyst judgment
- Consistent application of those triggers across the customer book, not just for a sampled subset
- A traceable link between a trigger event, the resulting risk re-score, and the action taken
- For any automated or ML/LLM-assisted scoring step, an explainable rationale a human reviewer — and later an examiner — can audit
FAQ
Frequently asked questions
- What is continuous KYC and how does it differ from periodic review?
- Continuous (or perpetual) KYC re-scores a customer's risk whenever a relevant event occurs — a sanctions-list update, an unusual transaction pattern, an address change — rather than only at fixed intervals like an annual or triennial review. Periodic review can leave a high-risk change undetected for months; event-driven monitoring is designed to catch it close to when it happens.
- Why are regulators pushing this now rather than earlier?
- Two things converged: the EU stood up AMLA (operational since July 2025) and its AMLR single rulebook (applying across all member states from 10 July 2027) to end inconsistent national AML enforcement, while the FCA's 2025 customer due diligence review found firms' review cycles were often undefined or inconsistently applied — on top of a string of nine-figure fines against NatWest and Santander UK that showed the cost of getting it wrong.
- Does continuous KYC only matter for large banks?
- No. The FCA's fines against Starling (£29 million, 2024) and Monzo (£21 million, 2025) show supervisors applying the same expectations to fast-growing challenger banks whose financial crime controls didn't scale with their customer growth, not just to established institutions like NatWest and Santander.
Sources
- Regulators raise the bar: is your AML stack ready? — FinTech Global
- NatWest fined £264.8million for anti-money laundering failures — FCA
- FCA fines Santander UK £107.7 million for repeated anti-money laundering failures — FCA
- FCA fines Starling Bank £29m for failings in their financial crime systems and controls — FCA
- FCA fines Monzo £21m for failings in financial crime controls — FCA