Skip to section

Copy Link Copied to clipboard

Summary

  • KYC and AML teams are under growing pressure in H2 2026 to demonstrate that controls respond effectively when customer risk changes, not simply prove that controls exist.
  • Periodic reviews alone may no longer be sufficient. Effective perpetual KYC depends on identifying meaningful risk-triggering events, reassessing customers consistently and maintaining a clear audit trail.
  • Sanctions risk increasingly extends beyond screening, requiring firms to connect ownership structures, counterparties, intermediaries, payment flows and other risk signals to uncover hidden exposure.
  • The new benchmark for control effectiveness is an organisation’s ability to keep customer information current, connect relevant data, make risk-sensitive decisions and evidence those decisions when challenged.

Risk does not follow your review calendar

A customer can change before the next scheduled review. Ownership, control, business activity, geography, political exposure, behaviour or sanctions exposure can all move. The implication is straightforward: a periodic review cycle on its own can struggle to keep pace with material changes in customer risk.

That is why perpetual KYC is increasingly an evidence and data challenge. The stronger model is not to refresh everything, all the time. It is to identify the events that matter, work out which customers and data are affected, reassess risk consistently, escalate material changes and record what changed, what evidence was considered and why the decision was made.

Sanctions risk is moving through networks

Screening still matters. But it is not the whole picture. Exposure can sit in ownership or control, directors and intermediaries, vessel identifiers, unusual routing, counterparties, payment providers or links to crypto platforms associated with circumvention.

That makes sanctions response a data-connection problem as well as a screening problem. The more signals you can bring together, the better positioned you are to understand whether an apparent match is a real risk – and what action should follow.

Crypto and AI are widening the challenge

Crypto risk is no longer confined to firms that offer virtual-asset services. FATF’s focus on stablecoins, unhosted wallets, offshore VASPs, cross-chain activity and DeFi points to a broader exposure that compliance teams need to map.

AI creates another two-sided challenge. Criminals can use generative AI, deepfakes and synthetic identities to make fraud harder to spot. Firms can also use AI to support onboarding, screening, monitoring and investigations. But automation is only as trustworthy as the data it can access, which makes data quality, explainability and human oversight essential.

The new measure of control effectiveness

Taken together, these developments point to a bigger shift. Effective KYC and AML is not simply about collecting information. It is about keeping the customer record current, connecting the right signals, making risk-sensitive decisions and being able to explain what happened afterwards.

That is where data and technology need to work together. Experian brings consumer identity and commercial intelligence together with technology across onboarding, screening, monitoring, remediation and customer lifecycle management. The aim is simple: help firms turn new information into the right action, with a clear audit trail behind the decision.

The question to ask now

As H2 2026 gets underway, ask yourself one question: if the risk changed today, how confident are you that your controls would identify it, route it and evidence the response?

Our KYC/AML Outlook: Emerging Priorities for Compliance Teams sets out the developments to watch and the practical actions worth considering now.

Want the detail behind the trends?

Download the full H2 2026 KYC/AML Outlook.

Download the report