AML verification confirms who a customer is, screens them against sanctions, PEP, and adverse media data, then repeats those checks for as long as the relationship lasts. Here are the four steps and the three places where it goes wrong.
AML verification is a record the firm must keep current and has to be able to explain, for as long as the relationship lasts. The European Union’s Anti-Money Laundering Regulation applies directly in all 27 member states from 10 July 2027. It sets one standard for how regulated firms identify customers, verify who really owns a business, and keep that information current. That last part is where most of the work sits.
What Is AML Verification?
AML verification is the process of confirming who your customer is, checking them or their business against sanctions lists, politically exposed person (PEP) records, adverse media, meaning negative news coverage, and other risk data, then repeating those checks for as long as the relationship lasts.
It entails four steps that come from Recommendation 10 of the FATF Standards, which is the international benchmark that countries follow. It obligates regulated firms to identify the customer, identify the beneficial owner who really controls or profits from the relationship, understand what the relationship is for, and monitor it on an ongoing basis. The UK Money Laundering Regulations and the EU rules both follow that structure.
Is AML Identity Verification the Same as Identity Verification?
No. AML identity verification is the first step inside a wider risk process, and the two produce different things. Firms that confuse the two end up treating a passed ID check as though it had settled the money laundering question.
| Identity verification | AML verification | |
| What it asks | Is this person who they say they are? | Does this customer carry financial crime risk? |
| What it produces | Confidence that the document is genuine and belongs to the person presenting it | A risk rating, a written reason for it, and a route for escalation |
| When it runs | At sign-up, and again whenever the customer is re-verified | At sign-up and continuously afterwards |
| What ends it | A pass or fail result | Nothing ends it. It runs until the relationship closes |
Identity verification tells you the person in front of you is real. AML verification tells you whether that real person should be your customer. One cannot stand in for the other.
How Does the AML Verification Process Work?
The AML verification process runs in four steps. Each one works on its own, and each one has a common way of going wrong.
- Identify and verify the customer. Collect and check the identifying details. For an individual, that means name, date of birth, address, and a government-issued document. For a business, it means legal registration, ownership structure, and the real people behind it. The common failure is treating what the customer typed in as something you have verified, because every step after this one inherits that mistake.
- Screen against sanctions, PEP and adverse media data. Run the verified identity against sanctions regimes, PEP and close associate registers, watchlists and negative news. The common failure is screening a name as text rather than screening a person, which buries genuine matches under a queue of people who happen to share a surname.
- Risk-rate the relationship and write down what it is for. Assign a risk rating and record what the account is expected to do, meaning the type of activity, the expected volumes and the source of the funds. The common failure is treating this as form filling, because if nobody writes the purpose down, nobody can later check the customer’s behaviour against it.
- Monitor, rescreen and escalate. Rescreen the customer as lists change, screen transactions against the expected pattern, and escalate when the two diverge. The common failure is timing. Sanctions and PEP lists change throughout the year, so a customer screened once at sign-up and rescreened once a year sits unscreened for most of that year.

Where AML Verification Goes Wrong
AML Compliance Programmes rarely fail because a step is missing. They fail at the handovers, where one team produces a correct result, and the next team never receives it.
A Screening Match Is Only a Lead
A screening hit means a possible connection exists, and nothing more. It does not tell you whether the listed person and your customer are the same human being. Name matching alone cannot settle that, because transliteration, which is the conversion of a name from one alphabet into another, produces several valid spellings of the same name, and because name order and common surnames vary widely between cultures.
Teams that treat the match as the decision pay for it twice. Analysts spend their days clearing alerts about people who were never the customer, and real risk waits in the queue behind those alerts. To settle a match, you need data the name-matching engine does not hold on its own, such as date of birth, nationality, document number, and whether the record belongs to a person or a company.
The Onboarding Record Never Reaches the Monitoring Team
Step three produces something useful, a written expectation of what the account should do. In most setups, that expectation stays inside the onboarding system and never reaches the people watching transactions. Those people are then left to work out what normal looks like from the account’s own history, so an account that was wrong from its first day looks perfectly normal to them.
Tom Gadsden, VP of Product at Shufti, argues that KYC, fraud and AML are converging into a single flow. Establish the nature and purpose of the account as you onboard it, then pass that record to transaction monitoring, so a customer who described themselves as a small occasional trader cannot move far larger sums before anyone looks. He adds that many enforcement actions have come down to this kind of disconnect between a firm’s front-line staff, its compliance function and its auditors. Source: Friction vs Fraud, Shufti and Biometric Update, 4 June 2026
The Audit Trail Gets Built Only When Someone Asks for It
An inspection factors in several things, other than just looking at where the alerts were raised from. It asks whether they were handled appropriately, whether similar cases were handled the same way, and whether the firm can explain why. A decision that was right but undocumented is hard to defend two years later, and two analysts reaching different conclusions on near-identical files tells a lot.
The practical answer is to capture the reasoning at the moment of the decision rather than hunt for it afterwards. That means recording which fields were compared, which threshold applied on the day, which version of the policy was in force, and who signed it off. Rebuilt later from memory and email, that record is slow to produce and usually incomplete.
How Shufti Handles AML Verification
If your queue fills with alerts about people who merely share a name with someone on a list, while genuine risk clears without challenge, your screening probably never knew who it was screening. Shufti’s AML Screening ties every hit to an identity already verified by face match, document check, and OCR, which is the automated reading of text off a document. The engine weighs who the person is rather than how the name is spelled. Date of birth, nationality, document number, and entity type feed straight into the risk score, and matches that contradict those details are discarded before an analyst sees them. Sanctions, PEP, adverse media, and crypto wallet sources refresh every 15 minutes, and name matching handles 80+ languages natively. Your onboarding already establishes who the customer is. Your screening should start from the same answer.
Frequently Asked Questions
Is AML verification the same as KYC?
No. KYC is the identification and due diligence work that establishes who the customer is. AML verification uses that verified identity to assess and monitor financial crime risk across the whole relationship. KYC is one input into AML verification, not another word for it.
How long does AML verification take?
Screening a verified identity is automated and quick. The time goes on resolving possible matches, because a person has to compare the customer's details against the listed entity before the alert can be closed. Ongoing monitoring has no endpoint, since it continues until the relationship closes.
What happens if a customer fails AML verification?
A confirmed sanctions match generally means you cannot proceed, and depending on the jurisdiction, you may be required to freeze assets and report. Other outcomes, such as a PEP hit, trigger enhanced due diligence rather than refusal. Every decision, including approvals, needs a written reason.
















