us

216.73.216.180

The Context Gap in AML Risk Assessment — report cover showing sanctions, adverse-media, watchlist and PEP screening feeding a magnifying-glass over a compliance file
Shufti · Report

The Context Gap in AML Risk Assessment

A financial crime practitioner view of AML screening and ongoing monitoring.

The Voice of AML Compliance Professionals: what 600+ organisations told us about manual alert handling, sanctions and PEP screening, ongoing monitoring, and the architectural gap between screening and decision, with a vendor assessment checklist for live evaluations.

Schedule a Demo

Challenge of AML Screening and Decisioning

Cost-effective AML compliance requires more than powerful screening capabilities. AML solutions must enable compliance teams to make accurate, context-rich risk decisions throughout the customer lifecycle. The bottleneck in modern AML operations is not screening but the decision that has to follow each match.

The gap emerges after screening. The customer’s identity, verified and documented at onboarding, may not flow to the screening system, and the screening result, once a customer’s risk has changed, may not flow to transaction monitoring. Transaction alerts that point to genuine risk never flow back to update the customer’s continuous risk profile either. Each system operates as an island, answering its own narrow question over incomplete data, so the information required to turn a screening result into a sound risk decision has to be reconstructed by hand, one alert at a time. Even the data behind AI-powered AML screening is often out of date and out of step with regulatory logic, which leaves the resulting risk assessment misleading.

This is why 32% of organisations name manual alert handling as their single largest operational challenge, and why, even as agentic AI improves screening, the decisioning that depends on customer context takes longer than ever. A model that inherits the same context gap inherits the same failure, because screening without context is never a decision in itself, only a task that still has to be passed to a person.

THE HEADLINE NUMBERS

Voice of AML Compliance Professionals

32%

named manual handling their single largest difficulty

45%

of sanctions-screening organisations say clearing a match is manual and slow

50%

of PEP-screening organisations say checks are manual or ad hoc

51%

of ongoing-monitoring frictions are manual workarounds, not automated triggers

Where the findings come from

This report is based on an analysis of anonymised market intelligence derived from Shufti’s customer and prospect base, comprising more than 600 organisations across the globe actively evaluating anti-financial crime solutions, including identity verification, fraud prevention, AML compliance, and transaction monitoring technologies.

All responses were anonymised prior to analysis and reviewed using thematic analysis to identify recurring patterns and emerging trends. Findings are presented in aggregate to provide a broader view of market priorities while ensuring that no individual organisation or respondent can be identified.

600+
Organisations analysed
Customer and prospect base, worldwide
Global
Industries, regions, org types
Actively evaluating anti-financial crime solutions
Thematic
Analysis, multi-coded
Anonymised before analysis, reported in aggregate

Regulators are now measuring the cost of compliance itself

In September 2025 the United States Financial Crimes Enforcement Network (FinCEN) opened a formal Survey of the Costs of AML/CFT Compliance. That a regulator has judged it necessary to measure the cost of compliance at all is itself a signal. The industry responses submitted to it already describe the pattern this report examines, naming personnel and technology as the largest components of compliance cost, and manual workflows and the difficulty of integrating multiple vendor systems among the principal operational burdens.

A Federal Reserve Bank of St. Louis study of 1,091 community banks found total regulatory compliance costs near 10% of non-interest expense at the smallest banks, roughly double the largest, with the Bank Secrecy Act the single most burdensome area at about a fifth of that total.

A 2026 PwC survey of more than five hundred financial institutions across Europe, the Middle East, and Africa found AML compliance costs rising structurally, customer due diligence now the largest operational bottleneck, confidence in transaction monitoring roughly halved since 2024, and data quality the leading barrier to AI adoption at up to 89%. Those figures measure the problem from the outside. The findings that carry this report, drawn from a proprietary dataset, explain it from the inside.

Why AML compliance becomes costly and inefficient

The customer’s identity is verified once, at onboarding, and the information captured there, date of birth, nationality, document details, is exactly what is needed to resolve a screening match. Yet when a screening alert arrives at the desk of a compliance officer, that information is not there. It was collected, verified, and paid for, but it sits behind a different vendor’s interface. This is not a staffing problem. It is an architectural problem. The cost lands in four connected places, all driven by the same root cause.

01

Decision time

Every alert requires manual context gathering because the information needed to resolve it does not arrive with the alert itself. Officers search for dates of birth, nationality, document numbers, transaction history: data that exists but is not connected.

02

Analyst hours and headcount

Manual context gathering is the largest operational cost because it scales with alert volume. When alert volume outruns the team, cost increases by hiring, so spending scales with noise rather than actual risk.

03

Backlog and delay

Unresolved alerts pile up because context gathering is slow. Approvals and transaction clearance wait for manual resolution of alerts that should resolve automatically if context were preserved.

04

Regulatory risk

Under pressure to clear a growing backlog, teams clear faster, which weakens the control. Because decisions are made by individuals with access to fragmented context, those decisions are inconsistent, undocumented, and unapproved.

The bottleneck in AML Compliance is resolution of alerts not just screening

Practitioners describe officers spending time manually gathering context because the information required to resolve a screening match is not present when the alert arrives. That context, verified identity data from onboarding, transaction history, previous risk assessments, exists within the organisation’s systems but does not flow to the point where decisions must be made.

45%

of Sanctions screening

Clearing an individual match is manual and slow because decision context does not arrive with the alert.

50%

of PEP screening

Exposure is established by hand because the system cannot close the check against a verified record.

51%

of Ongoing monitoring

Work meant to run continuously runs as scheduled re-screening instead because false alerts are not resolved.

20%

of Transaction monitoring

Practitioners cited lack of vendor consolidation as a risk-assessment challenge, leaving officers to merge three risk views by hand.

46%

of Lack of context

Common-name noise drives false positives, which points to the context available at the point of matching.

27%

of Regulatory pressure

Obligation is rising faster than the capacity absorbing it.

Why solving AML alerts becomes manual work

  1. 01

    The data going into the match is weak

    A record built from a verified document carries the name as printed, a date of birth, a nationality, and machine-readable data, while one built from a sign-up form carries whatever the customer typed.

  2. 02

    The matching logic is a blunt trade-off

    Matching narrowly misses the genuine hit whose name was spelled differently, while matching loosely returns a flood of alerts.

  3. 03

    The alert arrives without the context to resolve it

    The system hands the officer a possible match, not an answer. When the identifiers needed to decide do not arrive with the alert, the officer searches for them manually, which is why AML screening became manual work.

  4. 04

    The systems do not share what they know

    Most businesses verify identity with one supplier, screen with a second, monitor transactions with a third, and check company ownership with a fourth. None shares a record with the others.

  5. 05

    The system only answers when asked

    A screening query is a one-off, and nothing watches the customer or the lists. When a customer becomes a PEP or adverse media appears, no alert follows.

How the five compound

That is not five separate problems but one architectural problem with five manifestations. The solution is not to hire more analysts. It is to preserve customer context across the AML lifecycle so that screening flows directly to decision.

AML Screening needs a decisioning layer

The question that decides whether a programme can meet the standard regulators have already set is not which lists it screens against, but whether the system that establishes who the customer is and the system that decides what that customer’s name signifies are the same system. Where they are, the customer’s context is preserved across the whole AML lifecycle, and that is what makes an assessment accurate, explainable, and aligned with the institution’s own risk appetite.

Ask one question of every vendor: is the verifying system and the deciding system the same system?

Use this in a live evaluation

Each question surfaces a specific operational weakness found common in deployed systems. The full report carries the complete checklist across these areas.

01
On alignment to risk exposure and appetite

Can thresholds be configured and evidenced by risk tier, rather than to a fixed vendor default? Can screening sensitivity be tuned without a vendor change request, with every change logged for audit?

02
On data quality entering screening

Are identifiers (date of birth, nationality, document number) drawn from the same platform that verified the customer’s identity? How does the solution handle transliteration and name variants for non-Latin scripts?

03
On context delivered with alerts

Does an alert deliver the source of the listing, identifiers behind the match, and a rationale? What proportion of alerts can be resolved from the information delivered in the alert itself?

04
On explainability and consolidation

Can the solution produce a documented rationale for each decision showing why a match was cleared or escalated? How many separate suppliers underlie identity, screening, monitoring, and corporate-structure functions?

05
On continuity between screening and transactions

Does the solution assess identity screening and transaction activity against a single, shared understanding of customer risk? When a customer newly appears on a list, does the system automatically re-evaluate risk?

06
On AI-based alert triage

Does the solution offer Agentic-AI alert triage and own the AML risk data layer? Does it immediately update risk data when a customer’s sanctions or PEP status changes?

Use this in a live evaluation

Each question surfaces a specific operational weakness found common in deployed systems. The full report carries the complete checklist across these areas.

The Context Gap in AML Risk Assessment — report cover
Report page — findings
Report page — findings
Report page — findings
Previous
01 - 04
Next

Certifications

Independently audited and certified for enterprise-grade security and data protection.

  • GDPR
  • GDPR Fundamentals
  • ISO/IEC 27001:2022 Certified
  • CCPA
  • iBeta Level 3 — ISO 30107-3 Compliant
  • PCI DSS Compliant
  • Shufti SOC 2 Type 2 Compliant

Frequently asked questions (FAQs)

The context gap is the structural disconnect between the system that verifies a customer’s identity and the systems that screen and monitor that customer. The identity data captured and verified at onboarding, date of birth, nationality, document details, does not flow to the screening system, so when an alert arrives, a compliance officer must manually reconstruct context the organisation already holds. The gap also widens when the data and risk logic are not tuned to the organisation’s own risk exposure and the alert does not explain its own relevance, which pushes decisioning time up further. Screening works well enough, and it is the decision-making that has to follow which becomes the real bottleneck.

Was this content helpful?

32% of organisations name manual alert handling their single largest operational challenge, and that manual context gathering is where most of the cost sits. Because the work scales with alert volume, adding analysts only makes spending scale with noise rather than actual risk.

Was this content helpful?

Accuracy depends on context, and in most stacks context is fragmented across separate vendors for identity, screening, monitoring, and corporate structure, none of which shares a record with the others. The verified identifiers needed to resolve a match sit behind a different interface from the one raising it, so the assessment is made over incomplete data. The report also notes that the data behind AI-powered screening is often out of date and out of step with regulatory logic, which leaves even automated assessments misleading.

Was this content helpful?

Transaction monitoring is where fragmentation between suppliers becomes most visible: 20% of organisations named it their principal operational difficulty, with officers manually reconciling three vendors’ separate risk views of the same customer. When identity screening and transaction activity are not assessed against one shared understanding of customer risk, genuinely high-risk behaviour is diluted across systems that each answer only their own narrow question.

Was this content helpful?

Context is what turns a screening result into a decision. The identity captured and verified at onboarding, date of birth, nationality, and document identifiers, is exactly what is needed to resolve a match, yet it does not travel with the alert. Without it, an officer cannot tell whether a matched name is the sanctioned individual or an unrelated customer who happens to share it, which is why 46% of false positives trace back to common-name noise, a context problem rather than a detection one.

Was this content helpful?

The report finds 50% of PEP-screening organisations resolve checks manually or ad hoc because the system cannot close them against a verified record. False positives fall when the verified date of birth, nationality, and document identifiers from onboarding are matched against the listing inside a single system, so a non-PEP customer sharing a name with a politically exposed person is separated automatically rather than sent to an officer for open-source research.

Was this content helpful?

In the findings, 51% of ongoing-monitoring friction is manual workaround, with work meant to run continuously performed as scheduled re-screening because false alerts are never truly resolved. False alerts happen for several reasons, which can include poor-quality AML data that even treats low-risk customers as high-risk.

Was this content helpful?

Because automation has solved screening and not the decisioning. Screening reliably raises a possible match, but the alert arrives without the identifiers, sanctions or PEP context, and rationale needed to close it, so AML compliance officers may manually investigate those alerts. Until the verifying system and the deciding system are the same system, automated screening simply hands a task to a person, which is how screening became manual work.

Was this content helpful?

    search_cross_mobile

    Please complete the information below 
to download the whitepaper

    By clicking the "Submit" button, you are agreeing 
to the Terms & Conditions and Privacy Policy

    n-img-roi-cross

    Form submitted successfully!

    Thank you for your interest — your report is loading now.

    Resolve AML alerts with context, save on decision time

    The information required to decide already exists, captured and verified at onboarding. The question is whether your architecture lets it reach the system that needs it. Find out why your AML decisioning is taking longer than it should, or start with a short conversation about your own alert queue.

      Let’s Tailor Your Journey

      Which products would you like to check out?

      VideoIdent

      Address Verification

      eIDV (Docless)

      KYB

      AML Screening

      Deepfake Detection

      Face and ID Verification

      Age Verification

      Others

      What is your expected yearly verification volume?

      1 to 1,000

      1,001 to 5,000

      5,001 to 20,000

      20,001 to 50,000

      50,001 to 100,000

      100,001 to 1,000,000

      1,000,000+

      Valid Invalid number

      By clicking Submit, you accept our Privacy Policy and consent to marketing communications.

      Product Guide

      Customizable KYC Solution for KYC Product Owners

      Product Guide

      Docless KYC Verification in APAC to Onboard More Genuine Users

      Product Guide

      EU AMLR Guide 2027: Requirements, Scope, Deadlines | Shufti

      Product Guide

      APAC Child Safety Age Verification Regulations

      apac-child-safety-age-verification-regulations-ftr-img
      Product Guide

      Docless Identity Verification in the Middle East

      docless-identity-verification-middle-east
      Product Guide

      The Future of Docless Verification in Europe

      docless-identity-verification-europe=ftr-img
      Product Guide

      Cyprus 2026 KYC Operators Guide to Improve First Pass Rate

      Cyprus KYC Pass Rate Guide Ftr Img
      Product Guide

      Philippines KYC & Account-Owner Verification Playbook | Shufti

      philippines-account-owner-verification-ftr-image
      Product Guide

      Digital Lending KYC Guide for Mexico: INE/IFE, CURP, RFC, Liveness and AML Controls

      Mexico Digital Lending KYC Ftr Img
      Product Guide

      CySEC Forex KYC Compliance Handbook 2026 | Shufti

      Cysec Forex KYC Compliance Feature Image
      Product Guide

      Singapore KYC & AML Compliance Guide 2026 | Shufti

      Webinar banner for Redefining AML Decisioning The Future is Contextual Screening
      Product Guide

      Mexico 2026 KYC Handbook to Improve First Pass Rate

      Mexico 2026 KYC Pass Rate Handbook Featured Image
      Product Guide

      Where Can Identity Data Legally Live? 2026 Guide | Shufti

      Data Residency Guide Feature Image
      Product Guide

      Shufti Deepfake Fraud Index Report: Deepfake Fraud Set to Surge 495% in 2026

      Deepfake Identity Fraud Index Report 2026 Featured Image
      Whitepaper

      KYC Compliance and Identity Fraud Challenge Across APAC

      Product Guide

      Brazil Bets KYC Playbook for .bet.br Operators 2026 | Shufti

      Venn diagram showing overlap of Fraud and AML with operator liability
      Product Guide

      Malta iGaming KYC & AML Readiness Guide 2026| Shufti

      Globe topped with Malta landmark buildings and a Malta flag label
      Product Guide

      Brazil 2026 KYC Playbook to Improve First Pass Rate

      Featured Image
      Product Guide

      Malta 2026 KYC Playbook to Improve First Pass Rate

      Malta 2026 KYC Playbook To Improve First Pass Rate Feature Image
      Whitepaper

      The Deepfake Detection Gap

      Product Guide

      Choosing the Right Identity Verification Vendor for the Forex Sector

      Forex Guide Feature Image
      Product Guide

      A Comprehensive Guide to Address Verification in Complex Markets

      A comprehensive guide to address
      Whitepaper

      Beyond Benchmark Accuracy: Making Deepfake Detection Work for IDV Systems

      Sphere Cover Whitepaper
      Product Guide

      Human – Assisted Video KYC for Regulated Businesses:

      Video KYC Guide
      Whitepaper

      Re-Thinking RegTech for KYC Compliance

      Product Guide

      Enterprise Guide to Choose Right Identity Verification Solution

      Guide Feature Image
      report

      Global Age-Verification Laws 2025 Snapshot

      Global Age
      Whitepaper

      The Backbone of Global Trust

      The Backbone of global trust
      report

      State of Global AML Compliance 2025

      AML Laws Insight Image
      Product Guide

      Strategic ID Verification Vendor for Crypto Industry

      Feature Image Buyers Guide
      report

      Market Positioning and Commercial Assessment Results Presentation

      Report Market
      Whitepaper

      Preventing Account Takeover Fraud with Multilayered Defense

      Preventing Account Takeover
      Whitepaper

      The Critical 1% Closing Systemic Gaps In Global Identity Verification

      Shifti Whitepaper 1 Percent
      Whitepaper

      Outsmarting the Deepfake Threat to Identity Trust

      n-img-outstand
      Product Guide

      Scale Without Borders

      n-img-scale-without
      report

      Streamlining Identity Verification: How Shufti Secure Capture Enhances Accuracy and Trust

      new report feature iamge
      report

      Top 10 Most Difficult Countries for Identity Verification

      n-img-report-top-10
      Whitepaper

      KYC & AML IN THE MENA Region White Paper 2023

      Whitepaper

      Shufti’s iGaming White Paper 2023

      report

      Shufti Identity Fraud Report 2022

      Frame 953
      report

      Shufti Fraud Report 2021

      Frame 953 (1)
      report

      Holiday Season – The Prime Time for ID Thieves and Financial Criminals

      Frame 996
      report

      Shufti Completes 4 Years of Fighting ID Fraud

      Frame 997
      Product Guide

      On-premises Identity Verification for the Banking Sector

      Frame 998
      Whitepaper

      Shrinking the Space for Travel Industry Scams with Biometric Verification

      Frame 999
      Product Guide

      Global Gambling Compliance: Regulations, Age Checks & Financial Safety

      Frame 1000
      report

      A comprehensive guide to KYC and AML compliance in Canada

      Frame 1001
      n-img-roi-cross

      Form submitted successfully!

      Thank you for your interest — your report is loading now.

      Take the next steps to better security.

      Contact us

      Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

      Contact us

      Get the Shufti newsletter

      Stay ahead of the curve with fresh takes on the latest identity innovations.

        Take the next steps to better security.

        Contact us

        Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

        Contact us

        Request demo

        Get free access to our platform and try our products today.

        Get started

        Pitch a piece and get a verified byline in the Media room.

        Partnership Inquiries?
        Email us at [email protected]

        iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
        Copyright © 2026 Shufti. All rights reserved.