us

216.73.216.122

Back
Blogs

AML in banking: what it is and where bank programmes fail

AML in banking: what it is and where bank programmes fail
Amir RizwanAmir Rizwan JUNE 13, 2026 7 minutes read

AML in banking is the framework banks use to detect, stop and report illicit funds. Regulators now fine banks whose controls worked but whose reporting was late, so the real risk sits in the handoffs between detection and filing.

On 6 November 2025, Germany’s financial regulator BaFin announced a €45 million administrative fine against J.P. Morgan SE. BaFin found that between 4 October 2021 and 30 September 2022 the bank systemically failed to submit suspicious transaction reports without undue delay. The fine notice became final and binding on 30 October 2025.

They had the controls in place, and their detection systems worked, but the bank was penalised anyway, because there was too much time being spent between spotting the problem and reporting it.

This article explains what AML in banking means, what an AML compliance programme has to contain, which rules apply in 2026, and where bank programmes tend to fail.

What is AML in banking?

AML in banking is the set of laws, controls and procedures a bank uses to stop criminals from moving illegally obtained money through the financial system, and to report it to auditors in a clear manner when they ask for it. 

How AML and KYC differ

KYC sits inside AML as one part of it. KYC is the identity work a bank does at onboarding and at later review points, and it answers the question of who the customer is. On the other hand, AML is the wider programme that decides what the bank does with that information. It analyzes and rates the customer’s risk, watches their behaviour over time, and reports anything suspicious to the regulator. A bank can run strong KYC and still breach its AML obligations, which is broadly what happened in the BaFin case.

The five parts of an AML banking compliance programme

An AML banking compliance programme is usually split into five working parts. Each one has to pass its output cleanly to the next, and that is where most of the risk sits.

  1. Customer due diligence and risk rating. The bank identifies and verifies the customer, establishes the purpose of the relationship, and assigns a risk rating that shapes every subsequent step. Customers rated as high risk receive enhanced due diligence, which means deeper checks on the sources of their money and closer monitoring afterwards.
  2. Sanctions, PEP and adverse media screening. The bank checks customer names against sanctions lists, against records of politically exposed persons and their close relatives and associates, and against negative news coverage. These checks run at onboarding and again whenever the underlying lists change.
  3. Transaction monitoring. The bank watches actual behaviour against the profile set at onboarding. A customer who described modest activity and then starts moving large sums to high-risk countries should raise an alert. Transaction screening does most of this work.
  4. Suspicious activity reporting. Once suspicion is established, the bank files a report with its national financial intelligence unit, the government body that collects and analyses these reports, within the deadline its regulator sets. Some countries call these suspicious activity reports, and others call them suspicious transaction reports. They do the same job.
  5. Governance, training and independent testing. A named senior officer owns the programme, staff are trained to escalate concerns, and the whole thing is tested by someone independent of the team that runs it.

Detection sits in parts one to three. The J.P. Morgan fine landed on part four, after detection had already worked.

Which AML rules apply to banks in 2026?

Three regimes cover most banks reading this, and the European one is changing fastest.

Region Core rules Who supervises, and where reports go Status in 2026
EU Anti-Money Laundering Regulation (EU) 2024/1624 National supervisors, coordinated centrally by AMLA The EBA transferred its anti-money laundering mandates to AMLA on 1 January 2026. The Regulation applies from 10 July 2027, and AMLA starts directly supervising up to 40 high-risk institutions in 2028
UK Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 The FCA supervises most banks. A nominated officer files suspicious activity reports with the National Crime Agency No comparable overhaul under way. The 2017 Regulations remain the core instrument
US Bank Secrecy Act Federal banking agencies supervise. Reports go to FinCEN Every bank must maintain a written BSA and AML programme

The EU is moving from a directive model, where each member state had its own version of the rules, to a single regulation that applies the same way in all 27 countries. For a bank, that means local supervisory custom will become irrelevant, and they’ll need something that’ll have to meet the wording of the Regulation itself.

Where bank AML programmes fail

Bank AML programmes rarely fail because of a missing control. They mostly fail where one team hands its work to another, and no single person owns the handover.

The gap between detecting and reporting

Detection and filing are usually run by separate teams on separate systems, so a correctly raised alert can sit in a review queue while the regulator’s filing deadline runs down. In the J.P. Morgan case, BaFin did not dispute the quality of the reports. It penalised how long they took to arrive.

From the Shufti roundtable

“For the most part they said: you had appropriate systems and did the right things, but you didn’t do them consistently, reliably or quickly enough. JP Morgan reported everything they had to, with nothing wrong in the reports … they just weren’t filed without undue delay.”

Ray Blake, The Dark Money Files, former Head of Compliance and MLRO, speaking on Shufti’s “If Your Verification System Is 99% Accurate” session

The gap between the alert and the evidence pack

The second break happens after an analyst decides to file. The report needs an evidence chain showing what the bank knew, when it knew it, and why the decision followed. If the identity record sits in the onboarding system, the screening hit sits in a second tool, and the transaction history sits in a third, the analyst spends the filing window gathering that evidence together. Every hour spent assembling evidence comes out of the hours available to file.

What an AML failure costs a bank

The fine is the most visible cost, but often not the largest. A public enforcement action usually brings a remediation programme, a historic review of past files, external legal costs, and closer supervisory attention that continues long after the payment clears.

From the Shufti roundtable

“Direct fraud losses might be a small part; the real bill is the hidden ledger … investigation, remediation, look-backs, and fines. Losing a customer to friction is a small portion compared with a licensing or reputational hit with the regulator.”

Syed Khalid, CEO and Founder, FinCheck, speaking on Shufti’s “Friction vs Fraud” session

That changes how the spend should be judged. Money put into shortening the gap between an alert and a filing works on the whole of that bill, because the same delay that triggers the fine is what pulls in the remediation and the look-back behind it.

Where Shufti fits in a bank’s AML workflow

If your analysts spend the filing window pulling records out of three systems, the delay is built into the architecture. The onboarding record, the screening hit and the transaction history were never designed to arrive together.

Shufti’s ongoing monitoring keeps verified customers, businesses and beneficial owners under continuous re-screening after onboarding. Sanctions, PEP screening, adverse media screening and transaction checks run as the underlying source data updates, and each change raises an alert with an evidence package already attached. Suspicious patterns across a customer’s transaction history are flagged using rule-based triggers and machine learning models, and suspicious activity report packages are generated with the evidence chain assembled and ready for filing. The analyst reviews the case instead of rebuilding it.

Review how long your alerts take to become filings, then see an assembled evidence chain on Shufti’s AML screening workspace.

Frequently Asked Questions

What is AML in banking?

AML in banking is the set of laws, controls and procedures banks use to prevent, detect and report money laundering. It covers customer due diligence, sanctions and PEP screening, transaction monitoring, suspicious activity reporting, and the governance that holds those parts together.

What is the difference between AML and KYC in banking?

KYC is one part of AML. KYC verifies who a customer is at onboarding and at later review points. AML is the wider programme that risk-rates that customer, monitors their behaviour over time, and reports suspicious activity to the regulator.

What changes for EU banks under AMLA?

AMLA took over the EBA's anti-money laundering mandates on 1 January 2026. The Anti-Money Laundering Regulation applies from 10 July 2027, and AMLA begins directly supervising up to 40 high-risk institutions in 2028. Every other bank stays under its national supervisor.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.